
Critical role of Internet of Things (IoT) in various domains like smart city, healthcare, supply chain and transportation has made them the target of malicious attacks. Past works in this area focused on centralized Intrusion Detection System (IDS), assuming the existence of a central entity to perform data analysis and identify threats. However, such IDS may not always be feasible, mainly due to spread of data across multiple sources and gathering at central node can be costly. Also, the earlier works primarily focused on improving True Positive Rate (TPR) and ignored the False Positive Rate (FPR), which is also essential to avoid unnecessary downtime of the systems. In this paper, we first present an architecture for IDS based on hybrid ensemble model, named PHEC, which gives improved performance compared to state-of-the-art architectures. We then adapt this model to a federated learning framework that performs local training and aggregates only the model parameters. Next, we propose Noise-Tolerant PHEC in centralized and federated settings to address the label-noise problem. The proposed idea uses classifiers using weighted convex surrogate loss functions. Natural robustness of KNN classifier towards noisy data is also used in the proposed architecture. Experimental results on four benchmark datasets drawn from various security attacks show that our model achieves high TPR while keeping FPR low on noisy and clean data. Further, they also demonstrate that the hybrid ensemble models achieve performance in federated settings close to that of the centralized settings.
Bot-IoT is a recent and publicly available dataset that depicts attack traffic launched by BotNets against internet of things (IoT) networks. Normal (non-attack) traffic is represented by over 9,000 of the approximately 73,000,000 instances of big data that constitute this dataset. We present an easy-to-learn Bot-IoT approach, centred on the use of a minimum number of dataset features and a simple machine learning algorithm. Our contribution is defined by decision tree models built from derived Bot-IoT datasets with no more than three features. As per our definition of easy-to-learn, we require that predictive models have area under the receiver operating characteristic curve (AUC) mean scores greater than 0.99. According to our results, all the derived datasets produce easy-to-learn models. To the best of our knowledge, this work, in terms of its simplicity, interpretability, and performance, is an improvement over Bot-IoT classification approaches in existing literature.
Researchers must often decide whether to use destination port as an input feature when building predictive models for intrusion detection systems. To evaluate this feature, we use the Bot-IoT dataset with three different sets of input features. The first and second set of input features comprise all Bot-IoT features (26 variables) and all Bot-IoT features excluding destination port (25 variables), respectively, while the third includes destination port as the only feature. Our results show that classification models trained on the first (26 variables) and second (25 variables) set of input features generally yield favourable results. We note that several destination port values are associated with disproportionate label distributions. Hence, it is possible in some cases, that the classifiers have been trained to closely correlate specific attack types with specific values of destination port. To the best of our knowledge, this is the first Bot-IoT study based on the destination port feature.
As machine learning continues to be a promising tool for cyber security, industry and researchers have continued to develop datasets for research. These datasets often contain multiple emulated exemplars for common attacks seen in real-world networks. The datasets provide researchers with the necessary samples to train and test the detection capabilities of their machine learning models. This paper contains an in-depth analysis of the composition of one of the newest datasets, Bot-IoT. The full dataset contains about 73 million instances (big data), three dependent features, 26 independent features, and four primary attack categories. The purpose of this paper is to provide researchers with an understanding of the environment used to create Bot-IoT and how that environment effected its composition. A detailed analysis of the dataset's composition can provide additional insight into the dataset's suitability for machine learning.
Abstract The authors have requested that this preprint be removed from Research Square.
With the rapid growth and utilization of IoT devices around the world, attacks on these devices are also increasing thereby posing a security and privacy issue for industry providers and end-users alike. A common way to detect anomaly behaviour is to analyze the network traffic and categorize the outcome into benign and malignant traffic. With an increase in network traffic and sophistication of attacking techniques daily, there is a need for a state-of-the-art pattern recognition technique that can handle this ever increasing and ever-changing traffic and can also improve over time as attacks become more sophisticated. This research paper proposes a hybrid model for anomaly detection at the IoT fog layer using an ANN as a base model and several binary classifiers (which served as meta-classifiers) connected in series. The proposed model was tested and evaluated on a dataset of ‘x’ observations, demonstrating that such a model is both highly effective and efficient in detecting IoT network traffic anomalies.
Machine-to-machine (M2M) is an ecosystem which is used to describe any technology deploying and creating a network of devices to perform actions and exchange information. This new class of communicating devices have very diverse traffic characteristics and pose unique challenges. This paper surveys the state-of-the-art operating system technologies, architectures and available networking stack protocols on it, and explore their potential to support the growth of related applications. Moreover, the diversity of applications and internet of things (IoT) devices also necessitate the investigation of middleware framework and specifications to cater the current existing challenges. Therefore, we also discuss different challenges and issues in developing rich applications by using available operating systems. The paper concludes after providing recommendations for future enhancement in existing operating systems.
Internet of things (IoT) as a popular technology plays an important role in the future of the economy. Current literature highlights that IoT has different applications and will change human interaction with the virtual world. As IoT will be a key enabling technology in the future, it is important for all countries to be aware of this development and its applications, and to support related research and investments. In this paper, we aim to inspect the current status of IoT related research in Iran and present a short and brief overview on current IoT related research areas in Iran. We used Scopus as the scientific citation base to access papers published by Iranian authors in this area. Our analysis shows that Iran is in the emerging stage of IoT. Thus, Iranian scholars and institutions should pay more attention to this highly relevant topic and try to create a good body of knowledge to migrate in the maturity stage as soon as possible. Founding an especial Iranian society on internet of thing or a journal, which focuses on IoT in Iran, could be first steps in this direction.
Intelligent transport systems (ITS) play a key role in our daily activities. ITS development over the last decades has been based on the rapid evolution of information and communication technologies (ICT), which include processing capabilities, availability of hardware and communication technologies. However, as the development of ITS services increases so does the users' awareness regarding the degree of trust that they demonstrate on adopting this kind of services. This has brought to light several security and privacy concerns that ITS analysts should consider when designing and implementing various IT related services. This paper identifies how risk analysis can interact with security and privacy requirements' engineering world, in order to provide a holistic approach for reasoning about security and privacy in such complex environments like ITS systems.
This research focuses on secure software development of mobile applications by developing knowledge graphs for threats reported by the Open Web Application Security Project (OWASP). OWASP maintains best practices on the current industry top ten security threats to mobile and web applications. We develop knowledge graphs based on the two most recent top ten OWASP threat reports. We, then, show how the knowledge graph relationships can be discovered in mobile application source code, specifically Android. From the developed knowledge graph, we analyse 200+ healthcare applications posted on GitHub to gain insights into the cyber-assurance of these mobile software. We specifically examine the source code for one of the OWASP top ten mobile threats, the threat of insecure communications. We find that many of the analysed applications are communicating with potential personal identifying information employing insecure methodologies leaving users exposed to higher risks.
The internet of things (IoT) is undertaking the prodigiously important task of transforming existing systems' capabilities from traditional application stovepipes to a new internet paradigm that enables processes and services in a fast-changing environment. These internet-connected devices (ICD) or 'things' can be sensors, radiofrequency identification (RFID), TVs, etc. As the IoT continues to combine new transmission and processing technologies (e.g., satellite communications networks, mobile communications networks) into one high-integrated network, many access connection points become easy targets for hacker's. In many situations, it is very difficult to find out the position or the source(s) of cyber-attacks making it very complex to correctly determine the intention of the attack. Therefore, once IoT devices and networks are attacked and neutralised, its processing capabilities may be severely harmed. This article provides additional details of an ICD embedded sensor agent for IoT architectures and discusses the opportunity of ICD's automatically securing themselves against attacks.
Numerous applications are deployed on the web with the increasing popularity of internet. The applications include, 1) Banking applications, 2) Gaming applications, 3) E-commerce web applications. Different applications reply on OLTP (Online Transaction Processing) systems. OLTP systems need to be scalable and require fast response. Today modern web applications generate huge amount of the data which one particular machine and Relational databases cannot handle. The E-Commerce applications are facing the challenge of improving the scalability of the system. Data partitioning technique is used to improve the scalability of the system. The data is distributed among the different machines which results in increasing number of transactions. The work-load aware incremental repartitioning approach is used to balance the load among the partitions and to reduce the number of transactions that are distributed in nature. Hyper Graph Representation technique is used to represent the entire transactional workload in graph form. In this technique, frequently used items are collected and Grouped by using Fuzzy C-means Clustering Algorithm. Tuple Classification and Migration Algorithm is used for mapping clusters to partitions and after that tuples are migrated efficiently.
In this paper, we proposed a model of the infection phenomenon of an IoT malware called Mirai. We regarded the infection phenomenon as a multi-agent system and expressed it with agent-oriented Petri net called as Petri nets in a Petri net (PN2 for short). Some mitigation methods have been proposed such as rebooting infected devices and using an IoT worm called as Hajime which blocks Mirai. We reflected the methods into the PN2 model, and evaluated the methods of the model. Our results show that: 1) by rebooting the infected devices, we can drastically reduce Mirai's infection rate when the delay is zero. The effect, however, is rapidly lost with the increase of the delay; 2) Hajime reduces Mirai's infection rate to less than half without depending on the delay of reboot. The reduction rate, however, gradually decreases with the increase of the initial number of Hajime.
The presented research looks into information security and privacy risk related to using mobile and embedded devices for learning in the K-12 environment.Bring Your Own Device (BYOD) program and Internet of Things (IoT) for learning are the two focus areas discussed in this paper.The NIST privacy risk management framework (NIST-8062) template was used to illustrate the privacy impact factors K-12 ecosystem participants should consider while developing BYOD/IoT programs.The key factors involved in the decisions include reputation costs, direct business costs and non-compliance costs.Key security issues and risks such as network access, server and end-user device malware, application risks, and privacy risks were identified.The analysis of the risks suggested to recommend some good practices derived from various documents suggested by ISACA, IIA, SANS, and NIST.The proposed good practices were subsequently incorporated into BYOD guide for the K-12 system in two Canadian provinces (Alberta and Manitoba) in an attempt to increase its effectiveness in terms of addressing relevant risks.Although the good practices compiled in this research are proposed to be incorporated into the Alberta and Manitoba's BYOD guide for K-12 schools, the same process is applicable to any similar K-12 environment.
Semantics for the IoT domain have been already introduced for the (semi-)automated deployment of heterogeneous entities.Depending on the level of interoperability and the ability of dynamic expansion of the IoT environment, an application may have to 'decide' (and then select) which devices in that environment are trustworthy for ensuring and securing effective deployment.In the open and distributed IoT, where a large number of heterogeneous entities will be registered, the need to ensure and secure their selection and deployment tasks is highly important.In this paper, an effective modelling approach towards supporting the selection and deployment of IoT entities is presented, based on the notion of trust semantics.Using fuzzy ontologies as an enabler of trust semantics in IoT, this work demonstrates that such semantics, when seamlessly integrated in IoT ontologies, serve as a secure selection key to an IoT application (or service) for selecting, among the available entities, the one(s) that the application should trust for its effective deployment in the specific environment/context.