Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol

Prior 6LoWPAN intrusion detection system (IDS) utilized several features to detect various malicious activities. However, these IDS methods only detect specific attack but fails when the attacks are combined. In this paper, we propose an IDS known as compression header analyzer intrusion detection s...

Full description

Bibliographic Details
Main Authors: Napiah, Mohamad Nazrin, Idris, Mohd Yamani Idna, Ramli, Roziana, Ahmedy, Ismail
Format: Article
Published: Institute of Electrical and Electronics Engineers 2018
Subjects:
_version_ 1796961378996584448
author Napiah, Mohamad Nazrin
Idris, Mohd Yamani Idna
Ramli, Roziana
Ahmedy, Ismail
author_facet Napiah, Mohamad Nazrin
Idris, Mohd Yamani Idna
Ramli, Roziana
Ahmedy, Ismail
author_sort Napiah, Mohamad Nazrin
collection UM
description Prior 6LoWPAN intrusion detection system (IDS) utilized several features to detect various malicious activities. However, these IDS methods only detect specific attack but fails when the attacks are combined. In this paper, we propose an IDS known as compression header analyzer intrusion detection system (CHA-IDS) that analyzes 6LoWPAN compression header data to mitigate the individual and combination routing attacks. CHA-IDS is a multi-agent system framework that capture and manage raw data for data collection, analysis, and system actions. The proposed CHA-IDS utilize best first and greedy stepwise with correlation-based feature selection to determine only significant features needed for the intrusion detection. These features are then tested using six machine learning algorithms to find the best classification method that able to distinguish between an attack and non-attack and then from the best classification method, we devise a rule to be implemented in Tmote Sky. To ensure the reliability of our proposed method, we evaluate the CHA-IDS with three types of combination attacks known as hello flood, sinkhole, and wormhole. We also compare our results in term of accuracy of detection, energy overhead, and memory consumption with the prior 6LoWPAN-IDS implementation such as SVELTE and Pongle's IDS. The results show that CHA-IDS performs better than the aforementioned methods with 99% true positive rate and consumed low energy overhead and memory that fit in constrained device such Tmote Sky.
first_indexed 2024-03-06T05:53:22Z
format Article
id um.eprints-21169
institution Universiti Malaya
last_indexed 2024-03-06T05:53:22Z
publishDate 2018
publisher Institute of Electrical and Electronics Engineers
record_format dspace
spelling um.eprints-211692019-05-08T06:52:46Z http://eprints.um.edu.my/21169/ Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol Napiah, Mohamad Nazrin Idris, Mohd Yamani Idna Ramli, Roziana Ahmedy, Ismail QA75 Electronic computers. Computer science Prior 6LoWPAN intrusion detection system (IDS) utilized several features to detect various malicious activities. However, these IDS methods only detect specific attack but fails when the attacks are combined. In this paper, we propose an IDS known as compression header analyzer intrusion detection system (CHA-IDS) that analyzes 6LoWPAN compression header data to mitigate the individual and combination routing attacks. CHA-IDS is a multi-agent system framework that capture and manage raw data for data collection, analysis, and system actions. The proposed CHA-IDS utilize best first and greedy stepwise with correlation-based feature selection to determine only significant features needed for the intrusion detection. These features are then tested using six machine learning algorithms to find the best classification method that able to distinguish between an attack and non-attack and then from the best classification method, we devise a rule to be implemented in Tmote Sky. To ensure the reliability of our proposed method, we evaluate the CHA-IDS with three types of combination attacks known as hello flood, sinkhole, and wormhole. We also compare our results in term of accuracy of detection, energy overhead, and memory consumption with the prior 6LoWPAN-IDS implementation such as SVELTE and Pongle's IDS. The results show that CHA-IDS performs better than the aforementioned methods with 99% true positive rate and consumed low energy overhead and memory that fit in constrained device such Tmote Sky. Institute of Electrical and Electronics Engineers 2018 Article PeerReviewed Napiah, Mohamad Nazrin and Idris, Mohd Yamani Idna and Ramli, Roziana and Ahmedy, Ismail (2018) Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol. IEEE Access, 6. pp. 16623-16638. ISSN 2169-3536, DOI https://doi.org/10.1109/ACCESS.2018.2798626 <https://doi.org/10.1109/ACCESS.2018.2798626>. https://doi.org/10.1109/ACCESS.2018.2798626 doi:10.1109/ACCESS.2018.2798626
spellingShingle QA75 Electronic computers. Computer science
Napiah, Mohamad Nazrin
Idris, Mohd Yamani Idna
Ramli, Roziana
Ahmedy, Ismail
Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_full Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_fullStr Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_full_unstemmed Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_short Compression Header Analyzer Intrusion Detection System (CHA - IDS) for 6LoWPAN Communication Protocol
title_sort compression header analyzer intrusion detection system cha ids for 6lowpan communication protocol
topic QA75 Electronic computers. Computer science
work_keys_str_mv AT napiahmohamadnazrin compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol
AT idrismohdyamaniidna compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol
AT ramliroziana compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol
AT ahmedyismail compressionheaderanalyzerintrusiondetectionsystemchaidsfor6lowpancommunicationprotocol