In this paper, we propose an optimized lightweight Federated Deep Learning (FDL) method for botnet attack detection in smart critical infrastructure. First, an optimization method is developed to determine the most appropriate combination of model hyperparameters for local Deep Learning (DL) at the edge nodes. Then, an oversampling algorithm is combined with the optimal DL model to improve the classification performance when the training data is highly imbalanced, without a significant increase in the overall computation time. Furthermore, a feature dimensionality reduction method is used to reduce the amount of memory space required to store the network traffic data at the edge nodes.
Deep learning (DL) has been widely proposed for botnet attack detection in Internet of Things (IoT) networks. However, the traditional centralized DL (CDL) method cannot be used to detect the previously unknown (zero-day) botnet attack without breaching the data privacy rights of the users. In this article, we propose the federated DL (FDL) method for zero-day botnet attack detection to avoid data privacy leakage in IoT-edge devices. In this method, an optimal deep neural network (DNN) architecture is employed for network traffic classification. A model parameter server remotely coordinates the independent training of the DNN models in multiple IoT-edge devices, while the federated averaging (FedAvg) algorithm is used to aggregate local model updates. A global DNN model is produced after a number of communication rounds between the model parameter server and the IoT-edge devices. The zero-day botnet attack scenarios in IoT-edge devices is simulated with the Bot-IoT and N-BaIoT data sets. Experiment results show that the FDL model: 1) detects zero-day botnet attacks with high classification performance; 2) guarantees data privacy and security; 3) has low communication overhead; 4) requires low-memory space for the storage of training data; and 5) has low network latency. Therefore, the FDL method outperformed CDL, localized DL, and distributed DL methods in this application scenario.
Cyber attackers exploit a network of compromised computing devices, known as a botnet, to attack Internet-of-Things (IoT) networks. Recent research works have recommended the use of Deep Recurrent Neural Network (DRNN) for botnet attack detection in IoT networks. However, for high feature dimensionality in the training data, high network bandwidth and a large memory space will be needed to transmit and store the data, respectively in IoT back-end server or cloud platform for Deep Learning (DL). Furthermore, given highly imbalanced network traffic data, the DRNN model produces low classification performance in minority classes. In this paper, we exploit the joint advantages of Long Short-Term Memory Autoencoder (LAE), Synthetic Minority Oversampling Technique (SMOTE), and DRNN to develop a memory-efficient DL method, named LS-DRNN. The effectiveness of this method is evaluated with the Bot-IoT dataset. Results show that the LAE method reduced the dimensionality of network traffic features in the training set from 37 to 10, and this consequently reduced the memory space required for data storage by 86.49%. SMOTE method helped the LS-DRNN model to achieve high classification performance in minority classes, and the overall detection rate increased by 10.94%. Furthermore, the LS-DRNN model outperformed state-of-the-art models.
Nowadays, hackers take illegal advantage of distributed resources in a network of computing devices (i.e., botnet) to launch cyberattacks against the Internet of Things (IoT). Recently, diverse Machine Learning (ML) and Deep Learning (DL) methods were proposed to detect botnet attacks in IoT networks. However, highly imbalanced network traffic data in the training set often degrade the classification performance of state-of-the-art ML and DL models, especially in classes with relatively few samples. In this paper, we propose an efficient DL-based botnet attack detection algorithm that can handle highly imbalanced network traffic data. Specifically, Synthetic Minority Oversampling Technique (SMOTE) generates additional minority samples to achieve class balance, while Deep Recurrent Neural Network (DRNN) learns hierarchical feature representations from the balanced network traffic data to perform discriminative classification. We develop DRNN and SMOTE-DRNN models with the Bot-IoT dataset, and the simulation results show that high-class imbalance in the training data adversely affects the precision, recall, F1 score, area under the receiver operating characteristic curve (AUC), geometric mean (GM) and Matthews correlation coefficient (MCC) of the DRNN model. On the other hand, the SMOTE-DRNN model achieved better classification performance with 99.50% precision, 99.75% recall, 99.62% F1 score, 99.87% AUC, 99.74% GM and 99.62% MCC. Additionally, the SMOTE-DRNN model outperformed state-of-the-art ML and DL models.
In recent years, IoT has developed into many areas of life including smart homes, smart cities, agriculture, offices, and workplaces. Everyday physical items such as lights, locks and industrial machineries can now be part of the IoT ecosystem. IoT has redefined the management of critical and non-critical systems with the aim of making our lives more safe, efficient and comfortable. As a result, IoT technology is having a huge positive impact on our lives. However, in addition to these positives, IoT systems have also attracted negative attention from malicious users who aim to infiltrate weaknesses within IoT systems for their own gain, referred to as cyber security attacks. By creating an introduction to IoT, this paper seeks to highlight IoT cyber security vulnerabilities and mitigation techniques to the reader. The paper is suitable for developers, practitioners, and academics, particularly from fields such as computer networking, information or communication technology or electronics. The paper begins by introducing IoT as the culmination of two hundred years of evolution within communication technologies. Around 2014, IoT reached consumers, early products were mostly small closed IoT networks, followed by large networks such as smart cities, and continuing to evolve into Next Generation Internet; internet systems which incorporate human values. Following this evolutionary introduction, IoT architectures are compared and some of the technologies that are part of each architectural layer are introduced. Security threats within each architectural layer and some mitigation strategies are discussed, finally, the paper concludes with some future developments.
The rapid growth of Internet-of-Things (IoT) in the current decade has led to the development of a multitude of new access technologies targeted at low-power, wide area networks (LP-WANs). However, this has also created another challenge pertaining to technology selection. This paper reviews the performance of LP-WAN technologies for IoT, including design choices and their implications. We consider Sigfox, LoRaWAN, WavIoT, random phase multiple access (RPMA), narrowband IoT (NB-IoT), as well as LTE-M and assess their performance in terms of signal propagation, coverage and energy conservation. The comparative analyses presented in this paper are based on available data sheets and simulation results. A sensitivity analysis is also conducted to evaluate network performance in response to variations in system design parameters. Results show that each of RPMA, NB-IoT, and LTE-M incurs at least 9 dB additional path loss relative to Sigfox and LoRaWAN. This paper further reveals that with a 10% improvement in receiver sensitivity, NB-IoT 882 MHz and LoRaWAN can increase coverage by up to 398% and 142%, respectively, without adverse effects on the energy requirements. Finally, extreme weather conditions can significantly reduce the active network life of LP-WANs. In particular, the results indicate that operating an IoT device in a temperature of -20 degrees C can shorten its life by about half; 53% (WavIoT, LoRaWAN, Sigfox, NB-IoT, and RPMA) and 48% in LTE-M compared with environmental temperature of 40 degrees C.
The success and widespread adoption of the Internet of Things (IoT) has increased many folds over the last few years. Industries, technologists and home users recognise the importance of IoT in their lives. Essentially, IoT has brought vast industrial revolution and has helped automate many processes within organisations and homes. However, the rapid growth of IoT is also a cause for significant concern. IoT is not only plagued with security, authentication and access control issues, it also doesn't work as well as it should with fourth industrial revolution, commonly known as Industry 4.0. The absence of effective regulation, standards and weak governance has led to a continual downward trend in the security of IoT networks and devices, as well as given rise to a broad range of privacy issues. This paper examines the IoT industry and discusses the urgent need for standardisation, the benefits of governance as well as the issues affecting the IoT sector due to the absence of regulation. Additionally, through this paper, we are introducing an IoT security framework (IoTSFW) for organisations to bridge the current lack of guidelines in the IoT industry. Implementation of the guidelines, defined in the proposed framework, will assist organisations in achieving security, privacy, sustainability and scalability within their IoT networks.
Corporations and end users are finding it hard to keep their devices safe from the ever evolving and complicated threat of cyber attacks. Currently, with the widespread adoption of the Internet of Things (IoT), cyber threat is becoming an even greater challenge for both technology providers and consumers. This paper presents a review of the recent and significant cyber security issues affecting many areas of digital technology. From IoT devices and smart automobiles to commonly used computers and typical corporate servers, we focus our analysis on current attack trends and the effects of intrusion on Small and Medium sized Enterprises(SMEs). This paper helps to build awareness among non-technical experts, practitioners and researchers about attack and defense strategies in the current digital market. We have created a guide with input from our in-house security researchers and information gathered from the literature to help the reader understand the challenges faced by the IT industry in the future.
Abstact The complexity and high cost of building retrofitting for improved energy performance can be overwhelming for many SMEs. Tailor-made frameworks, are therefore, required to deliver long term energy reduction benefits, for relatively small commercial buildings. This paper presents a low cost energy monitoring and reporting solution for SMEs, which includes a system architecture, a baseline data generation strategy that significantly reduces the retrofitting timeline and a sensor network strategy that incorporates existing ICT infrastructure and minimises the number of IoT sensors. The system reports the energy monitoring data to building users in real time in an easy to understand format allowing building users to quickly analyse the affect of changes in their energy behaviour, encouraging them to try different low cost energy reduction strategies, before choosing more expensive solutions.