تشخیص هوشمند حملات DDoS در دستگاههای اینترنت اشیا با استفاده از رویکرد ترکیبی شبکههای عصبی CNN، LSTM و FFNN
ماندانا رستمی
1
(
گروه مهندسی کامپیوتر و مهندسی فناوری اطلاعات واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران.
)
پویا درخشان برجوئی
2
(
مرکز تحقیقات هوش مصنوعی و تجزیه و تحلیل داده، گروه مهندسی برق، واحد علوم و تحقیقات، دانشگاه آزاد اسلامی، تهران، ایران.
)
الهه مرادی
3
(
گروه مهندسی برق، دانشگاه آزاد اسلامی واحد یادگار امام خمینی (ره) شهرری، تهران، ایران.
)
کلید واژه: شبکه عصبی پیشخور, حافظه طولانی کوتاهمدت, اینترنت اشیا, یادگیری عمیق, شبکه عصبی کانولوشن,
چکیده مقاله :
با گسترش استفاده از دستگاههای اینترنت اشیا (IoT)، حملات سایبری، بهویژه DDoS، پیچیدهتر و تشخیص آنها به چالشی اساسی تبدیل شده است. تحقیقات نشان میدهد شبکههای عصبی عمیق به دلیل سازگاری با دادههای حجیم، عملکرد مطلوبی دارند. در این پژوهش، عملکرد مدلهای یادگیری عمیق در تشخیص حملات سایبری در شبکههای توزیعشده بررسی و مقایسه شده است. چهار مدل یادگیری عمیق شامل شبکه های عصبی CNN ،LSTM ،FFNN و ترکیبهای آنها (CNN+FFNN و CNN+LSTM) برای تحلیل دادههای ترافیک شبکه ارزیابی شدند. مدلها با دیتاست Bot-IoT آموزش دیدند و عملکردشان بر اساس معیار دقت سنجیده شد. نتایج نشان میدهد ترکیب CNN و LSTM با بهرهگیری از ویژگیهای مکانی و وابستگیهای زمانی، بالاترین دقت را در تشخیص حملات پیچیده مانند DDoS دارد. این مدل میتواند ویژگیهای پنهان را از دادههای خام استخراج و روابط زمانی حملات را شبیهسازی کند که در محیطهای IoT و محاسبات Fog برای شناسایی تهدیدات تدریجی و پیچیده حائز اهمیت است. همچنین ترکیب CNN و FFNN نیز در تشخیص تهدیدات سریعتر و پیچیدگی کمتر، عملکرد قابلتوجهی داشته است. در نهایت این پژوهش بر اهمیت ترکیب مدلهای یادگیری عمیق در بهبود دقت سیستمهای تشخیص حملات سایبری تأکید کرده و راهکارهایی مبتنی بر معماریهای توزیعشده برای امنیت شبکههای IoT و Fog پیشنهاد میدهد.
چکیده انگلیسی :
As the use of Internet of Things (IoT) devices expands, cyber-attacks, especially DDoS, have become more sophisticated, making their detection a fundamental challenge. Research shows that deep neural networks perform well due to their compatibility with large volumes of data. This study investigates and compares the performance of deep learning models for detecting cyber-attacks in distributed networks.Four deep learning models, including the CNN, LSTM, and FFNN neural networks, as well as their combinations (CNN+FFNN and CNN+LSTM), were evaluated for analyzing network traffic data. The models were trained on the Bot-IoT dataset, and their performance was measured based on accuracy. The results show that the combination of CNN and LSTM, by leveraging both spatial features and temporal dependencies, achieves the highest accuracy in detecting complex attacks like DDoS.This model can extract hidden features from raw data and simulate the temporal relationships of attacks, which is crucial for identifying gradual and complex threats in IoT and Fog computing environments. The combination of CNN and FFNN also demonstrated a notable performance in detecting faster threats with less complexity. Ultimately, this research emphasizes the importance of combining deep learning models to improve the accuracy of cyber-attack detection systems and proposes solutions based on distributed architectures for the security of IoT and Fog networks.
[1] K. Alieyan, M. M. Kadhum, M. Anbar, S. U. Rehman, and N. K. Alajmi, “An overview of DDoS attacks based on DNS,” Proc. 2016 Int. Conf. Inf. Commun. Technol. Converg. (ICTC), pp. 276–280, Oct. 2016.
[2] H. Tyagi and R. Kumar, "Attack and Anomaly Detection in IoT Networks Using Supervised Machine Learning Approaches," Rev. d'Intelligence Artif., vol. 35, no. 1, pp. 11-21, 2021.
[3] J. Li, Z. Xue, C. Li, and M. Liu, "RTED-SD: A Real-Time Edge Detection Scheme for Sybil DDoS on the Internet of Vehicles," IEEE Access, vol. 9, pp. 11296-11305, 2021.
[4] R. K. Gupta et al., “An Improved Secure Key Generation Using Enhanced Identity-Based Encryption for Cloud Computing in Large Scale 5G”, Wireless Communications and Mobile Computing 2022.
[5] M. M. Inuwa and R. Das, “A comparative analysis of various machine learning methods for anomaly detection in cyber attacks on IoT networks,” Internet Things, vol. 26, p. 101162, 2024.
[6] Y. Cherdantseva and J. Hilton, “A reference model of information assurance security,” in Proc. 2013 Int. Conf. Availability, Reliab. Secur. (ARES), pp. 546–555, 2013.
[7] D. Kwon, H. Kim, J. Kim, S. Suh, I. Kim, and J. Kim, “A survey of deep learning-based network anomaly detection,” Clust. Comput., vol. 22, no. 5, pp. 949–961, 2019.
[8] J. Anderson, J. Carbonell, T. Mitchell, R. Michalski, S. Amarel, T. Tecuci, and Y. Kodratoff, Machine Learning: An Artificial Intelligence Approach. Los Altos, CA: M. Kaufmann, 1983.
[9] I. Kilincer, F. Ertam, and A. Sengur, “Machine learning methods for cyber security intrusion detection: datasets and comparative study,” Comput. Netw. vol. 188, p. 107840, 2021.
[10] Z. M. Fadlullah, F. Tang, B. Mao, N. Kato, O. Akashi, T. Inoue, and K. Mizutani, “State-of-the-art deep learning: evolving machine intelligence toward tomorrow’s intelligent network traffic control systems,” IEEE Commun. Surv. Tutor, vol. 19, no. 4, pp. 2432–2455, 2017.
[11] S. Tsimenidis, T. Lagkas, and K. Rantos, “Deep learning in IoT intrusion detection,” J. Netw. Syst. Manag, 2022.
[12] A. A. Diro and N. Chilamkurti, “Distributed attack detection scheme using deep learning approach for Internet of Things,” Futur. Gener. Comput. Syst, vol. 82, pp. 761–768, 2018.
[13] M. Roopak, G. Y. Tian, and J. Chambers, “Deep learning models for cyber security in IoT networks,” in Proc. IEEE 9th Annu. Comput. Commun. Workshop Conf. (CCWC), pp. 452–457, 2019.
[14] M. Shalaka, P. M. Pawar, and R. Muthalagu, “Efficient intelligent intrusion detection system for heterogeneous Internet of Things (HetIoT),” J. Netw. Syst. Manag, vol. 2023, 2023.
[15] T. Mahjabin, Y. Xiao, G. Sun, and W. Jiang, “A survey of distributed denial-of-service attack, prevention, and mitigation techniques,” Int. J. Distrib. Sensor Networks, vol. 13, no. 12, pp. 1550147717741463, 2017.
[16] University of California, I.,“KDD Cup’99,” [Online]. Available: http://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html. Accessed: Mar. 17, 2021.
[17] Cibersecurity, C. I., “NSL-KDD,”[Online].Available: http://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html. Accessed: Mar. 17, 2021.
[18] H. Ramchoun, M. J. Idrissi, Y. Ghanou, and M. Ettaouil, “Multilayer perceptron: architecture optimization and training,” nt. J. Interact. Multimed. Artif. Intell. vol. 4, no. 1, pp. 26–30, 2016.
[19] S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural Comput. vol. 9, no. 8, pp. 1735–1780, https://doi.org/10.1162/neco.1997.9.8.1735, 1997.
[20] M. Z. Alom, V. Bontupalli, and T. M. Taha, “Intrusion detection using deep belief networks,” National Aerospace and Electronics Conference (NAECON), pp. 339–344, 2015.
[21] J. Kim, J. Kim, H. L. Thi Thu, and H. Kim, “Long short term memory recurrent neural network classifier for intrusion detection,” International Conference on Platform Technology and Service (PlatCon), pp. 1–5, 2016.
[22] N. Shone, T. N. Ngoc, V. D. Phai, and Q. Shi, “A deep learning approach to network intrusion detection,” IEEE Trans. Emerg. Topics Comput. Intell. vol. 2, no. 1, pp. 41–50, 2018.
[23] D. Kwon, H. Kim, J. Kim, S. Suh, I. Kim, and J. Kim, “A survey of deep learning-based network anomaly detection,” Clust. Comput. vol. 22, no. 5, pp. 949–961, 2019.
[24] M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion detection: approaches, datasets, and comparative study,” J. Inform. Secur. Appl, vol. 50, 102419, 2020.
[25] S. Yadav and S. Subramanian, “Detection of application layer DDoS attack by feature learning using Stacked AutoEncoder,” International Conference on Computational Techniques in Information and Communication Technologies (ICCTICT), pp. 361–366, 2016.
[26] M. Lopez-Martin, B. Carro, A. Sanchez-Esguevillas, and J. Lloret, “Conditional variational Autoencoder for prediction and feature recovery applied to intrusion detection in IoT,” Sensors (Basel), vol. 17, no. 1967, pp. 1–17, 2017.
[27] T. Luo and S. G. Nagarajan, “Distributed anomaly detection using autoencoder neural networks in WSN for IoT,” IEEE Int. Conf. Commun. (ICC), pp. 1–6, 2018.
[28] A. A. Diro and N. Chilamkurti, “Distributed attack detection scheme using deep learning approach for Internet of Things,” Futur. Gener. Comput. Syst. vol. 82, pp. 761–768, 2018.
[29] M. Roopak, G.Y.Tian, and J.Chambers, “Deep learning models for cyber security in IoT networks,” IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), pp. 452–457, 2019.
[30] S. Abbas, S. Alsubai, S. Ojo, G. A. Sampedro, A. Almadhor, A. A. Hejaili, and I. Bouazzi, “An efficient deep recurrent neural network for detection of cyberattacks in realistic IoT environment,” The Journal of Supercomputing, vol. 80, no. 10, pp. 13557–13575, 2024.
[31] Abbas, Sidra, Shtwai Alsubai, Stephen Ojo, Gabriel Avelino Sampedro, Ahmad Almadhor, Abdullah Al Hejaili, and Imen Bouazzi. "An efficient deep recurrent neural network for detection of cyberattacks in realistic IoT environment." The Journal of Supercomputing 80, no. 10 (2024): 13557-13575.