With the growth of internet of things (IoT) devices, cyberattacks, such as distributed denial of service, that exploit vulnerable devices infected with malware have increased. Therefore, vendors and users must keep their device firmware updated to eliminate vulnerabilities and quickly handle unknown cyberattacks. However, it is difficult for both vendors and users to continually keep the devices safe because vendors must provide updates quickly and the users must continuously manage the conditions of all deployed devices. Therefore, to ensure security, it is necessary for a system to adapt autonomously to changes in cyberattacks. In addition, it is important to consider network-side security that detects and filters anomalous traffic at the gateway to comprehensively protect those devices. This paper proposes a self-adaptive anomaly detection system for IoT traffic, including unknown attacks. The proposed system comprises a honeypot server and a gateway. The honeypot server continuously captures traffic and adaptively generates an anomaly detection model using real-time captured traffic. Thereafter, the gateway uses the generated model to detect anomalous traffic. Thus, the proposed system can adapt to unknown attacks to reflect pattern changes in anomalous traffic based on real-time captured traffic. Three experiments were conducted to evaluate the proposed system: a virtual experiment using pre-captured traffic from various regions across the world, a demonstration experiment using real-time captured traffic, and a virtual experiment using a public dataset containing the traffic generated by malware. The experimental results indicate that a system adaptable in real time to evolving cyberattacks is a novel approach for ensuring the comprehensive security of IoT devices against both known and unknown attacks.
翻译:随着物联网设备数量的增长,利用受恶意软件感染的脆弱设备发起的网络攻击(例如分布式拒绝服务攻击)日益增多。因此,供应商和用户必须持续更新设备固件以消除漏洞,并快速应对未知网络攻击。然而,供应商需及时提供更新,用户需持续管理所有已部署设备的状态,这使得双方都难以持续保障设备安全。为确保安全性,系统需要能够自主适应网络攻击的变化。此外,在网关端检测并过滤异常流量的网络安全措施对于全面保护这些设备至关重要。本文提出了一种面向物联网流量的自适应异常检测系统,可应对包括未知攻击在内的威胁。该系统由蜜罐服务器和网关组成:蜜罐服务器持续捕获流量,并利用实时捕获的流量自适应生成异常检测模型;随后,网关使用该模型检测异常流量。因此,所提系统能够通过基于实时捕获的流量反映异常流量模式的变化,从而适应未知攻击。为评估系统性能,我们进行了三项实验:基于全球不同地区预捕获流量的虚拟实验、基于实时捕获流量的演示实验,以及使用包含恶意软件生成流量的公开数据集的虚拟实验。实验结果表明,能够实时适应不断演变的网络攻击的系统,是确保物联网设备全面抵御已知及未知攻击的一种创新方法。