IoT intrusion detection method for unbalanced samples

In recent years, network traffic increases exponentially with the iteration of devices, while more and more attacks are launched against various applications.It is significant to identify and classify attacks at the traffic level.At the same time, with the explosion of Internet of Things (IoT) devic...

Full description

Bibliographic Details
Main Author: ANTONG P, Wen CHEN, Lifa WU
Format: Article
Language:English
Published: POSTS&TELECOM PRESS Co., LTD 2023-02-01
Series:网络与信息安全学报
Subjects:
Online Access:https://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2023005
_version_ 1797262594588803072
author ANTONG P, Wen CHEN, Lifa WU
author_facet ANTONG P, Wen CHEN, Lifa WU
author_sort ANTONG P, Wen CHEN, Lifa WU
collection DOAJ
description In recent years, network traffic increases exponentially with the iteration of devices, while more and more attacks are launched against various applications.It is significant to identify and classify attacks at the traffic level.At the same time, with the explosion of Internet of Things (IoT) devices in recent years, attacks on IoT devices are also increasing, causing more and more damages.IoT intrusion detection is able to distinguish attack traffic from such a large volume of traffic, secure IoT devices at the traffic level, and stop the attack activity.In view of low detection accuracy of various attacks and sample imbalance at present, a random forest based intrusion detection method (Resample-RF) was proposed, which consisted of three specific methods: optimal sample selection algorithm, feature merging algorithm based on information entropy, and multi-classification greedy transformation algorithm.Aiming at the problem of unbalanced samples in the IoT environment, an optimal sample selection algorithm was proposed to increase the weight of small samples.Aiming at the low efficiency problem of random forest feature splitting, a feature merging method based on information entropy was proposed to improve the running efficiency.Aiming at the low accuracy problem of random forest multi-classification, a multi-classification greedy transformation method was proposed to further improve the accuracy.The method was evaluated on two public datasets.F1 reaches 0.99 on IoT-23 dataset and 1.0 on Kaggle dataset, both of which have good performance.The experimental results show that the proposed model can effectively identify the attack traffic from the massive traffic, better prevent the attack of hackers on the application, protect the IoT devices, and thus protect the related users.
first_indexed 2024-04-24T23:59:36Z
format Article
id doaj.art-b1dd642c9b124ae59b899990ed0fe6ad
institution Directory Open Access Journal
issn 2096-109X
language English
last_indexed 2024-04-24T23:59:36Z
publishDate 2023-02-01
publisher POSTS&TELECOM PRESS Co., LTD
record_format Article
series 网络与信息安全学报
spelling doaj.art-b1dd642c9b124ae59b899990ed0fe6ad2024-03-14T08:29:57ZengPOSTS&TELECOM PRESS Co., LTD网络与信息安全学报2096-109X2023-02-019113013910.11959/j.issn.2096-109x.2023005IoT intrusion detection method for unbalanced samplesANTONG P, Wen CHEN, Lifa WUIn recent years, network traffic increases exponentially with the iteration of devices, while more and more attacks are launched against various applications.It is significant to identify and classify attacks at the traffic level.At the same time, with the explosion of Internet of Things (IoT) devices in recent years, attacks on IoT devices are also increasing, causing more and more damages.IoT intrusion detection is able to distinguish attack traffic from such a large volume of traffic, secure IoT devices at the traffic level, and stop the attack activity.In view of low detection accuracy of various attacks and sample imbalance at present, a random forest based intrusion detection method (Resample-RF) was proposed, which consisted of three specific methods: optimal sample selection algorithm, feature merging algorithm based on information entropy, and multi-classification greedy transformation algorithm.Aiming at the problem of unbalanced samples in the IoT environment, an optimal sample selection algorithm was proposed to increase the weight of small samples.Aiming at the low efficiency problem of random forest feature splitting, a feature merging method based on information entropy was proposed to improve the running efficiency.Aiming at the low accuracy problem of random forest multi-classification, a multi-classification greedy transformation method was proposed to further improve the accuracy.The method was evaluated on two public datasets.F1 reaches 0.99 on IoT-23 dataset and 1.0 on Kaggle dataset, both of which have good performance.The experimental results show that the proposed model can effectively identify the attack traffic from the massive traffic, better prevent the attack of hackers on the application, protect the IoT devices, and thus protect the related users.https://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2023005traffic analysisiotintrusion detectionrandom forestunbalanced sample
spellingShingle ANTONG P, Wen CHEN, Lifa WU
IoT intrusion detection method for unbalanced samples
网络与信息安全学报
traffic analysis
iot
intrusion detection
random forest
unbalanced sample
title IoT intrusion detection method for unbalanced samples
title_full IoT intrusion detection method for unbalanced samples
title_fullStr IoT intrusion detection method for unbalanced samples
title_full_unstemmed IoT intrusion detection method for unbalanced samples
title_short IoT intrusion detection method for unbalanced samples
title_sort iot intrusion detection method for unbalanced samples
topic traffic analysis
iot
intrusion detection
random forest
unbalanced sample
url https://www.infocomm-journal.com/cjnis/CN/10.11959/j.issn.2096-109x.2023005
work_keys_str_mv AT antongpwenchenlifawu iotintrusiondetectionmethodforunbalancedsamples