Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol

Prior 6LoWPAN intrusion detection system (IDS) utilized several features to detect various malicious activities. However, these IDS methods only detect specific attack but fails when the attacks are combined. In this paper, we propose an IDS known as compression header analyzer intrusion detection s...

Full description

Bibliographic Details
Main Authors: Mohamad Nazrin Napiah, Mohd Yamani Idna Bin Idris, Roziana Ramli, Ismail Ahmedy
Format: Article
Language:English
Published: IEEE 2018-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8270652/
_version_ 1819163069771677696
author Mohamad Nazrin Napiah
Mohd Yamani Idna Bin Idris
Roziana Ramli
Ismail Ahmedy
author_facet Mohamad Nazrin Napiah
Mohd Yamani Idna Bin Idris
Roziana Ramli
Ismail Ahmedy
author_sort Mohamad Nazrin Napiah
collection DOAJ
description Prior 6LoWPAN intrusion detection system (IDS) utilized several features to detect various malicious activities. However, these IDS methods only detect specific attack but fails when the attacks are combined. In this paper, we propose an IDS known as compression header analyzer intrusion detection system (CHA-IDS) that analyzes 6LoWPAN compression header data to mitigate the individual and combination routing attacks. CHA-IDS is a multi-agent system framework that capture and manage raw data for data collection, analysis, and system actions. The proposed CHA-IDS utilize best first and greedy stepwise with correlation-based feature selection to determine only significant features needed for the intrusion detection. These features are then tested using six machine learning algorithms to find the best classification method that able to distinguish between an attack and non-attack and then from the best classification method, we devise a rule to be implemented in Tmote Sky. To ensure the reliability of our proposed method, we evaluate the CHA-IDS with three types of combination attacks known as hello flood, sinkhole, and wormhole. We also compare our results in term of accuracy of detection, energy overhead, and memory consumption with the prior 6LoWPAN-IDS implementation such as SVELTE and Pongle’s IDS. The results show that CHA-IDS performs better than the aforementioned methods with 99% true positive rate and consumed low energy overhead and memory that fit in constrained device such Tmote Sky.
first_indexed 2024-12-22T17:38:16Z
format Article
id doaj.art-ea9cad7e10754e5c8d983ef80e1086e2
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-22T17:38:16Z
publishDate 2018-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-ea9cad7e10754e5c8d983ef80e1086e22022-12-21T18:18:28ZengIEEEIEEE Access2169-35362018-01-016166231663810.1109/ACCESS.2018.27986268270652Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication ProtocolMohamad Nazrin Napiah0https://orcid.org/0000-0002-0118-6543Mohd Yamani Idna Bin Idris1https://orcid.org/0000-0003-4894-0838Roziana Ramli2Ismail Ahmedy3Department of Computer System and Technology, Faculty of Computer Science and Information Technology, University of Malaya, Kuala Lumpur, MalaysiaDepartment of Computer System and Technology, Faculty of Computer Science and Information Technology, University of Malaya, Kuala Lumpur, MalaysiaDepartment of Computer System and Technology, Faculty of Computer Science and Information Technology, University of Malaya, Kuala Lumpur, MalaysiaDepartment of Computer System and Technology, Faculty of Computer Science and Information Technology, University of Malaya, Kuala Lumpur, MalaysiaPrior 6LoWPAN intrusion detection system (IDS) utilized several features to detect various malicious activities. However, these IDS methods only detect specific attack but fails when the attacks are combined. In this paper, we propose an IDS known as compression header analyzer intrusion detection system (CHA-IDS) that analyzes 6LoWPAN compression header data to mitigate the individual and combination routing attacks. CHA-IDS is a multi-agent system framework that capture and manage raw data for data collection, analysis, and system actions. The proposed CHA-IDS utilize best first and greedy stepwise with correlation-based feature selection to determine only significant features needed for the intrusion detection. These features are then tested using six machine learning algorithms to find the best classification method that able to distinguish between an attack and non-attack and then from the best classification method, we devise a rule to be implemented in Tmote Sky. To ensure the reliability of our proposed method, we evaluate the CHA-IDS with three types of combination attacks known as hello flood, sinkhole, and wormhole. We also compare our results in term of accuracy of detection, energy overhead, and memory consumption with the prior 6LoWPAN-IDS implementation such as SVELTE and Pongle’s IDS. The results show that CHA-IDS performs better than the aforementioned methods with 99% true positive rate and consumed low energy overhead and memory that fit in constrained device such Tmote Sky.https://ieeexplore.ieee.org/document/8270652/Internet of Thingssecuritymachine learningcompression header6LoWPANRPL
spellingShingle Mohamad Nazrin Napiah
Mohd Yamani Idna Bin Idris
Roziana Ramli
Ismail Ahmedy
Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
IEEE Access
Internet of Things
security
machine learning
compression header
6LoWPAN
RPL
title Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_full Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_fullStr Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_full_unstemmed Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_short Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_sort compression header analyzer intrusion detection system cha ids for 6lowpan communication protocol
topic Internet of Things
security
machine learning
compression header
6LoWPAN
RPL
url https://ieeexplore.ieee.org/document/8270652/
work_keys_str_mv AT mohamadnazrinnapiah compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol
AT mohdyamaniidnabinidris compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol
AT rozianaramli compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol
AT ismailahmedy compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol