The Internet of Things (IoT) has been introduced as a breakthrough technology that integrates intelligence into everyday objects, enabling high levels of connectivity between them. As the IoT networks grow and expand, they become more susceptible to cybersecurity attacks. A significant challenge in current intrusion detection systems for IoT includes handling imbalanced datasets where labeled data are scarce, particularly for new and rare types of cyber attacks. Existing literature often fails to detect such underrepresented attack classes. This paper introduces a novel intrusion detection approach designed to address these challenges. By integrating Self Supervised Learning (SSL), Few Shot Learning (FSL), and Random Forest (RF), our approach excels in learning from limited and imbalanced data and enhancing detection capabilities. The approach starts with a Deep Infomax model trained to extract key features from the dataset. These features are then fed into a prototypical network to generate discriminate embedding. Subsequently, an RF classifier is employed to detect and classify potential malware, including a range of attacks that are frequently observed in IoT networks. The proposed approach was evaluated through two different datasets, MaleVis and WSN-DS, which demonstrate its superior performance with accuracies of 98.60% and 99.56%, precisions of 98.79% and 99.56%, recalls of 98.60% and 99.56%, and F1-scores of 98.63% and 99.56%, respectively.
翻译:物联网(IoT)作为一项突破性技术被引入,将智能集成到日常物品中,使其之间实现高度互联。随着物联网网络不断发展和扩展,其更容易遭受网络安全攻击。当前物联网入侵检测系统面临的一项重大挑战包括处理标注数据稀缺的不平衡数据集,尤其是针对新型和罕见类型的网络攻击。现有文献通常无法检测此类代表性不足的攻击类别。本文提出了一种新颖的入侵检测方法以应对这些挑战。通过整合自监督学习(SSL)、少样本学习(FSL)和随机森林(RF),我们的方法在利用有限且不平衡的数据进行学习以及增强检测能力方面表现出色。该方法首先使用Deep Infomax模型从数据集中提取关键特征,然后将这些特征输入原型网络以生成判别性嵌入。随后,采用RF分类器检测并分类潜在恶意软件,包括物联网网络中常见的一系列攻击。所提出的方法通过两个不同数据集(MaleVis和WSN-DS)进行评估,分别实现了98.60%和99.56%的准确率、98.79%和99.56%的精确率、98.60%和99.56%的召回率以及98.63%和99.56%的F1分数,展现出卓越性能。