EDIMA is a modular distributed system using machine learning for early detection of IoT malware network activity in large-scale networks via traffic classification at edge devices, evaluated in testbed experiments.
N-BaIoT: Network-based Detection of IoT Botnet Attacks Using Deep Autoencoders
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
The proliferation of IoT devices which can be more easily compromised than desktop computers has led to an increase in the occurrence of IoT based botnet attacks. In order to mitigate this new threat there is a need to develop new methods for detecting attacks launched from compromised IoT devices and differentiate between hour and millisecond long IoTbased attacks. In this paper we propose and empirically evaluate a novel network based anomaly detection method which extracts behavior snapshots of the network and uses deep autoencoders to detect anomalous network traffic emanating from compromised IoT devices. To evaluate our method, we infected nine commercial IoT devices in our lab with two of the most widely known IoT based botnets, Mirai and BASHLITE. Our evaluation results demonstrated our proposed method's ability to accurately and instantly detect the attacks as they were being launched from the compromised IoT devices which were part of a botnet.
fields
cs.CR 1years
2019 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
EDIMA: Early Detection of IoT Malware Network Activity Using Machine Learning Techniques
EDIMA is a modular distributed system using machine learning for early detection of IoT malware network activity in large-scale networks via traffic classification at edge devices, evaluated in testbed experiments.