Scinovex
articleTop 1% cited

A Supervised Intrusion Detection System for Smart Home IoT Devices

IEEE Internet of Things Journal · 2019 · Vol. 6(5) · pp. 9042–9053
Eirini AnthiLowri WilliamsMalgorzata SlowinskaGeorge TheodorakopoulosPete Burnap

Abstract

The proliferation in Internet of Things (IoT) devices, which routinely collect sensitive information, is demonstrated by their prominence in our daily lives. Although such devices simplify and automate every day tasks, they also introduce tremendous security flaws. Current insufficient security measures employed to defend smart devices make IoT the “weakest” link to breaking into a secure infrastructure, and therefore an attractive target to attackers. This paper proposes a three layer intrusion detection system (IDS) that uses a supervised approach to detect a range of popular network based cyber-attacks on IoT networks. The system consists of three main functions: 1) classify the type and profile the normal behavior of each IoT device connected to the network; 2) identifies malicious packets on the network when an attack is occurring; and 3) classifies the type of the attack that has been deployed. The system is evaluated within a smart home testbed consisting of eight popular commercially available devices. The effectiveness of the proposed IDS architecture is evaluated by deploying 12 attacks from 4 main network based attack categories, such as denial of service (DoS), man-in-the-middle (MITM)/spoofing, reconnaissance, and replay. Additionally, the system is also evaluated against four scenarios of multistage attacks with complex chains of events. The performance of the system's three core functions result in an F-measure of: 1) 96.2%; 2) 90.0%; and 3) 98.0%. This demonstrates that the proposed architecture can automatically distinguish between IoT devices on the network, whether network activity is malicious or benign, and detect which attack was deployed on which device connected to the network successfully.

Network Security and Intrusion DetectionAdvanced Malware Detection TechniquesIoT-based Smart Home SystemsComputer scienceIntrusion detection systemInternet of ThingsIntrusion prevention systemComputer networkComputer securityEmbedded system

Funding

  • Engineering and Physical Sciences Research Council
Citations
570
FWCI
47.67
field-weighted impact
References
47
Percentile
100%
vs. same field & year
Citations per year
Cited by
References
The Lack of A Priori Distinctions Between Learning Algorithms
Neural Computation · 1996 · 1,625 citations
Intrusion detection by machine learning: A review
Expert Systems with Applications · 2009 · 949 citations
Induction of Decision Trees
Machine Learning · 1986 · 14,589 citations
Induction of decision trees
Machine Learning · 1986 · 12,326 citations
Citation Network

How this paper connects to the literature. Drag to explore, click any node to open that paper.