Attention-based deep learning approach for detecting IoT botnet-based distributed denial of service attacks
Maha Al-JarahDepartment of Computer Engineering Jordan University of Science and TechnologyIrbid, JordanView full profile → , Mohammad Al-ShurmanDepartment of Network Engineering & Security Jordan University of Science and TechnologyIrbid, JordanView full profile → , *Basheer Al-DuwairiCorresponding authorbasheer@just.edu.joDepartment of Network Engineering & Security Jordan University of Science and TechnologyIrbid, JordanView full profile →
* Corresponding author · click or hover a name for details
- Received:
- 09 Aug 2022
- Published Online:
- 16 Sep 2024
- Article type:
- Research Article
- Language:
- EN
- Article no.:
- JDMSC-1729
- Pages:
- 1785–1815
Abstract
Keywords
Subject Classifications
References
[1] A. Al-Fuqaha, M. Guizani, M. Mohammadi, M. Aledhari, M. Ayyash, Internet of things: A survey on enabling technologies, protocols, and applications, IEEE Communications Surveys Tutorials 17, 2347–2376 (2015). doi:10.1109/COMST.2015.2444095.
[2] S. Analytics, Number of internet of things (iot) connected devices worldwide in 2018, 2025 and 2030 (in billions) (2019).
[3] I. Lee, K. Lee, The internet of things (iot): Applications, investments, and challenges for enterprises, Business Horizons 58, 431–440 (2015).
[4] S. Sicari, A. Rizzardi, L. A. Grieco, A. Coen-Porisini, Security, privacy and trust in internet of things: The road ahead, Computer networks 76, 146–164 (2015).
[5] M. Hron, Are smart homes vulnerable to hacking?, URL https://blog. avast. com/mqtt-vulnerabilitieshacking-smart-homes (2018).
[6] B. Krebs, Krebsonsecurity hit with record ddos, KrebsOnSecurity, Sept 21 (2016).
[7] C. Kolias, G. Kambourakis, A. Stavrou, J. Voas, Ddos in the iot: Mirai and other botnets, Computer 50, 80–84 (2017).
[8] E. Bertino, N. Islam, Botnets and internet of things security, Computer 50, 76–79 (2017).
[9] G. Caspi, Introducing deep learning: Boosting cybersecurity with an artificial brain (2017).
[10] A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. Kaiser, I. Polosukhin, Attention is all you need, in: Advances in neural information processing systems, pp. 5998–6008 (2017).
[11] E. A. McCullough, Lightweight Deep Learning for Botnet DDoS Detection on IoT Access Networks, Master’s thesis, Missouri State University, USA (2020).
[12] V. H. Bezerra, V. G. T. da Costa, S. Barbon Junior, R. S. Miani, B. B. Zarpel˜ao, Iotds: A one-class classification approach to detect botnets in internet of things devices, Sensors 19, 3188 (2019).
[13] K. Bhardwaj, J. C. Miranda, A. Gavrilovska, Towards iot-ddos prevention using edge computing, in: {USENIX} Workshop on Hot Topics in Edge Computing (HotEdge 18), pp. 1–7(2018).
[14] A. Wang, W. Chang, S. Chen, A. Mohaisen, Delving into internet ddos attacks by botnets: characterization and analysis, IEEE/ACM Transactions on Networking 26, 2843–2855 (2018).
[15] G. Kambourakis, C. Kolias, A. Stavrou, The mirai botnet and the iot zombie armies, in: MILCOM 2017-2017 IEEE Military Communications Conference (MILCOM), IEEE, pp. 267–272 (2017).
[16] K. Scarfone, P. Mell, et al., Guide to intrusion detection and prevention systems (idps), NIST special publication 800, 94 (2007).
[17] E. Khoshhalpour, H. R. Shahriari, Botrevealer: Behavioral detection of botnets based on botnet lifecycle, The ISC International Journal of Information Security 10, 55–61 (2018).
[18] I. Butun, B. Kantarci, M. Erol-Kantarci, Anomaly detection and privacy preservation in cloud-centric internet of things, in: 2015 IEEE International Conference on Communication Workshop (ICCW), IEEE, pp. 2610–2615 (2015).
[19] D. Midi, A. Rullo, A. Mudgerikar, E. Bertino, Kalis—a system for knowledge-driven adaptable intrusion detection for the internet of things, in: 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), IEEE, pp. 656–666 (2017).
[20] K. Kumar, R. Joshi, K. Singh, A distributed approach using entropy to detect ddos attacks in isp domain, in: 2007 International Conference on Signal Processing, Communications and Networking, IEEE, pp. 331–337 (2007).
[21] S. Yu, W. Zhou, Entropy-based collaborative detection of ddos attacks on community networks, in: 2008 Sixth Annual IEEE International Conference on Pervasive Computing and Communications (PerCom), IEEE, pp. 566–571 (2008).
[22] A. Lakhina, M. Crovella, C. Diot, Mining anomalies using traffic feature distributions, ACM SIGCOMM computer communication review 35, 217–228 (2005).
[23] B. Al-Duwairi, W. Al-Kahla, M. A. AlRefai, Y. Abdelqader, A. Rawash, R. Fahmawi, Siem-based detection and mitigation of iot-botnet ddos attacks, International Journal of Electrical & Computer Engineering (2088-8708) 10 (2020).
[24] M. M. Shurman, O. M. Al-Jarrah, S. B. Esoh, S. H. Alnabelsi, An enhanced cross-layer approach based on fuzzy-logic for securing wireless ad-hoc networks from black hole attacks, International Journal on Communications Antenna and Propagation (IRECAP) (2017).
[25] Z. Xia, S. Lu, J. Li, J. Tang, Enhancing ddos flood attack detection via intelligent fuzzy logic, Informatica 34 (2010).
[26] S. Hemalatha, S. Qaiyum, S. L. A. Haleem, et al., Protection from distributed denial of service attack using fuzzy logic (2021). Https://www.researchsquare.com/article/rs-349667/v1.
[27] H. Rahmani, N. Sahli, F. Kammoun, Joint entropy analysis model for ddos attack detection, in: 2009 Fifth International Conference on Information Assurance and Security, volume 2, IEEE, pp. 267–271 (2009).
[28] Z. Al-Qudah, B. Al-Duwairi, O. Al-Khaleel, Ddos protection as a service: hiding behind the giants, International Journal of Computational Science and Engineering 9, 292–300 (2014).
[29] P. Kamboj, M. C. Trivedi, V. K. Yadav, V. K. Singh, Detection techniques of ddos attacks: A survey, in: 2017 4th IEEE Uttar Pradesh Section International Conference on Electrical, Computer and Electronics (UPCON), IEEE, pp. 675–679 (2017).
[30] M. F. B. Abbas, T. Srikanthan, Low-complexity signature-based malware detection for iot devices, in: International Conference on Applications and Techniques in Information Security, Springer, pp. 181–189 (2017).
[31] H. Wang, J. Gu, S. Wang, An effective intrusion detection framework based on svm with feature augmentation, Knowledge-Based Systems 136, 130–139 (2017).
[32] P. Barford, J. Kline, D. Plonka, A. Ron, A signal analysis of network traffic anomalies, in: Proceedings of the 2nd ACM SIGCOMM Workshop on Internet measurment, pp. 71–82 (2002).
[33] K. A. Bradley, S. Cheung, N. Puketza, B. Mukherjee, R. A. Olsson, Detecting disruptive routers: A distributed network monitoring approach, IEEE network 12, 50–60 (1998).
[34] S. T. Zargar, J. Joshi, D. Tipper, A survey of defense mechanisms against distributed denial of service (ddos) flooding attacks, IEEE Communications Surveys & Tutorials 15, 2046–2069 (2013).
[35] A. Patcha, J.-M. Park, An overview of anomaly detection techniques: Existing solutions and latest technological trends, Computer networks 51, 3448–3470 (2007).
[36] S. Basumallik, R. Ma, S. Eftekharnejad, Packet-data anomaly detection in pmu-based state estimator using convolutional neural network, International Journal of Electrical Power & Energy Systems 107, 690–702 (2019).
[37] K. Fu, D. Cheng, Y. Tu, L. Zhang, Credit card fraud detection using convolutional neural networks, in: International Conference on Neural Information Processing, Springer, pp. 483–490 (2016).
[38] M. Nasr, A. Bahramali, A. Houmansadr, Deepcorr: Strong flow correlation attacks on tor using deep learning, in: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 1962–1976 (2018).
[39] F. Feng, X. Liu, B. Yong, R. Zhou, Q. Zhou, Anomaly detection in ad-hoc networks based on deep learning model: A plug and play device, Ad Hoc Networks 84, 82–89 (2019).
[40] A. A. Ahmed, W. A. Jabbar, A. S. Sadiq, H. Patel, Deep learning-based classification model for botnet attack detection, Journal of Ambient Intelligence and Humanized Computing, 1–10 (2020).
[41] G. D. L. T. Parra, P. Rad, K.-K. R. Choo, N. Beebe, Detecting internet of things attacks using distributed deep learning, Journal of Network and Computer Applications 163, 102662 (2020).
[42] M. Alsoufi, S. Razak, M. M. Siraj, A. Ali, M. Nasser, S. Abdo, et al., Anomaly intrusion detection systems in iot using deep learning techniques: A survey, in: International Conference of Reliable Information and Communication Technology, Springer, pp. 659–675 (2020).
[43] M. Delakis, C. Garcia, text detection with convolutional neural networks., in: VISAPP (2), pp. 290–294 (2008).
[44] H. I. Fawaz, B. Lucas, G. Forestier, C. Pelletier, D. F. Schmidt, J. Weber, G. I. Webb, L. Idoumghar, P.-A. Muller, F. Petitjean, Inceptiontime: Finding alexnet for time series classification, Data Mining and Knowledge Discovery 34, 1936–1962 (2020).
[45] M. Z. Alom, T. M. Taha, C. Yakopcic, S. Westberg, P. Sidike, M. S. Nasrin, M. Hasan, B. C. Van Essen, A. A. Awwal, V. K. Asari, A state-of-the-art survey on deep learning theory and architectures, Electronics 8, 292 (2019).
[46] I. Aljarrah, D. Mohammad, Video content analysis using convolutional neural networks, in: 2018 9th International Conference on Information and Communication Systems (ICICS), IEEE, pp. 122–126 (2018).
[47] X. Zhang, J. Zhao, Y. LeCun, Character-level convolutional networks for text classification, arXiv preprint arXiv:1509.01626 (2015).
[48] A. Krizhevsky, I. Sutskever, G. E. Hinton, Imagenet classification with deep convolutional neural networks, Advances in neural information processing systems 25, 1097–1105 (2012).
[49] S. Hochreiter, The vanishing gradient problem during learning recurrent neural nets and problem solutions, International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems 6, 107–116 (1998).
[50] Y. Bengio, P. Simard, P. Frasconi, Learning long-term dependencies with gradient descent is difficult, IEEE transactions on neural networks 5, 157–166 (1994).
[51] G. I. Winata, O. P. Kampman, P. Fung, Attention-based lstm for psychological stress detection from spoken language using distant supervision, in: 2018 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), IEEE, pp. 6204–6208 (2018).
[52] A. Samy, H. Yu, H. Zhang, Fog-based attack detection framework for internet of things using deep learning, IEEE Access 8, 74571–74585 (2020).
[53] N. Koroniotis, N. Moustafa, E. Sitnikova, B. Turnbull, Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset, Future Generation Computer Systems 100, 779–796 (2019).
[54] S. Patro, K. K. Sahu, Normalization: A preprocessing stage, arXiv preprint arXiv:1503.06462 (2015).
[55] D. P. Kingma, J. Ba, Adam: A method for stochastic optimization, arXiv preprint arXiv:1412.6980 (2014).
[56] N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, R. Salakhutdinov, Dropout: a simple way to prevent neural networks from overfitting, The Journal of Machine learning research 15, 1929–1958 (2014).




