An Online Adaptive Approach to Detecting Zero-day Attacks in IoT and IIoT Systems
Promise Ricardo Agbedanu, Shanchieh Jay Yang, Richard Musabe, Ignace Gatare, James Rwigema · 2024
Traditional intrusion detection systems (IDS) struggle to detect zero-day attacks because they rely on pre-defined signatures. This paper proposes an online adaptive machine learning approach, Self Adjusting Memory K-Nearest Neighbors (Adaptive SAMKNN), to detect zero-day attacks in Internet of Things (IoT) and Industrial IoT (IIoT) environments. The method dynamically adjusts memory allocation, enabling real-time detection with minimal memory usage. Experimental results, conducted using two datasets (NF-BoT-IoT and NF-ToN-IoT), show that Adaptive SAMKNN consistently outperforms traditional offline machine learning models in accuracy and memory efficiency. The system also successfully detects synthetic zero-day attacks created through generative adversarial networks (GANs). This approach demonstrates the feasibility of deploying lightweight, resource-efficient intrusion detection systems in resource-constrained IoT/IIoT environments.