TARU PUBLICATIONS
Journal of Discrete Mathematical Sciences and Cryptography cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0065·ISSN (Print): 0972-0529

Publishes theoretical and applied research in all areas of Discrete Mathematical Sciences, Cryptography, Combinatorics, Elliptic Curves and Information Security.

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

Attention-based deep learning approach for detecting IoT botnet-based distributed denial of service attacks

, , *

* Corresponding author · click or hover a name for details

pp. 1785–1815Vol. 27Issue 6September 2024DOI: 10.47974/JDMSC-1729 Crossmark XML
Received:
09 Aug 2022
Published Online:
16 Sep 2024
Article type:
Research Article
Language:
EN
Article no.:
JDMSC-1729
Pages:
1785–1815

Abstract

Internet of Things (IoT) technology has evolved rapidly to become an integral part of our daily life. The numerous number of IoT devices and the limited security measures that could be applied on such devices attracted attackers to exploit these devices to act as botnets, generating massive Distributed Denial of Service (DDoS) attacks. IoT botnet-based DDoS attacks are growing dramatically both in frequency and sophistication and thus call for urgent development of powerful detection mechanism and deploy those mechanisms in an efficient way.In this paper, we propose attention-based deep learning approach for IoT botnet-based DDoS attacks. Specifically, we apply deep learning attention mechanism on two popular deep learning models LSTM and CNN for detection of IoT botnet DDoS attacks. We also examine the effect of using the deep Autoencoder for feature reduction and examine its effect on training time and data size needed to be exchanged through the network for training and updating the model, especially for solutions deployed at the Edge computing network. Performance evaluation shows that combining attention mechanism with LSTM model achieves superior performance with an accuracy reaching 100% which is due to combining the memorizing ability by the LSTM and the focusing ability of the attention in one model. In addition, results show that using Autoencoder for feature reduction resulted in reducing the training time up to 66.25%, 64.39%, 72.30% and 78.64% for ALSTM, LSTM, ACNN, CNN models respectively. Also achieved reduction in size of the dataset up to 67%.

Keywords

Subject Classifications

68T07 Artificial neural networks and deep learning

References

[1] A. Al-Fuqaha, M. Guizani, M. Mohammadi, M. Aledhari, M. Ayyash, Internet of things: A survey on enabling technologies, protocols, and applications, IEEE Communications Surveys Tutorials 17, 2347–2376 (2015). doi:10.1109/COMST.2015.2444095.
[2] S. Analytics, Number of internet of things (iot) connected devices worldwide in 2018, 2025 and 2030 (in billions) (2019).
[3] I. Lee, K. Lee, The internet of things (iot): Applications, investments, and challenges for enterprises, Business Horizons 58, 431–440 (2015).
[4] S. Sicari, A. Rizzardi, L. A. Grieco, A. Coen-Porisini, Security, privacy and trust in internet of things: The road ahead, Computer networks 76, 146–164 (2015).
[5] M. Hron, Are smart homes vulnerable to hacking?, URL https://blog. avast. com/mqtt-vulnerabilitieshacking-smart-homes (2018).
[6] B. Krebs, Krebsonsecurity hit with record ddos, KrebsOnSecurity, Sept 21 (2016).
[7] C. Kolias, G. Kambourakis, A. Stavrou, J. Voas, Ddos in the iot: Mirai and other botnets, Computer 50, 80–84 (2017).
[8] E. Bertino, N. Islam, Botnets and internet of things security, Computer 50, 76–79 (2017).
[9] G. Caspi, Introducing deep learning: Boosting cybersecurity with an artificial brain (2017).
[10] A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. Kaiser, I. Polosukhin, Attention is all you need, in: Advances in neural information processing systems, pp. 5998–6008 (2017).
[11] E. A. McCullough, Lightweight Deep Learning for Botnet DDoS Detection on IoT Access Networks, Master’s thesis, Missouri State University, USA (2020).
[12] V. H. Bezerra, V. G. T. da Costa, S. Barbon Junior, R. S. Miani, B. B. Zarpel˜ao, Iotds: A one-class classification approach to detect botnets in internet of things devices, Sensors 19, 3188 (2019).
[13] K. Bhardwaj, J. C. Miranda, A. Gavrilovska, Towards iot-ddos prevention using edge computing, in: {USENIX} Workshop on Hot Topics in Edge Computing (HotEdge 18), pp. 1–7(2018).
[14] A. Wang, W. Chang, S. Chen, A. Mohaisen, Delving into internet ddos attacks by botnets: characterization and analysis, IEEE/ACM Transactions on Networking 26, 2843–2855 (2018).
[15] G. Kambourakis, C. Kolias, A. Stavrou, The mirai botnet and the iot zombie armies, in: MILCOM 2017-2017 IEEE Military Communications Conference (MILCOM), IEEE, pp. 267–272 (2017).
[16] K. Scarfone, P. Mell, et al., Guide to intrusion detection and prevention systems (idps), NIST special publication 800, 94 (2007).
[17] E. Khoshhalpour, H. R. Shahriari, Botrevealer: Behavioral detection of botnets based on botnet lifecycle, The ISC International Journal of Information Security 10, 55–61 (2018).
[18] I. Butun, B. Kantarci, M. Erol-Kantarci, Anomaly detection and privacy preservation in cloud-centric internet of things, in: 2015 IEEE International Conference on Communication Workshop (ICCW), IEEE, pp. 2610–2615 (2015).
[19] D. Midi, A. Rullo, A. Mudgerikar, E. Bertino, Kalis—a system for knowledge-driven adaptable intrusion detection for the internet of things, in: 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), IEEE, pp. 656–666 (2017).
[20] K. Kumar, R. Joshi, K. Singh, A distributed approach using entropy to detect ddos attacks in isp domain, in: 2007 International Conference on Signal Processing, Communications and Networking, IEEE, pp. 331–337 (2007).
[21] S. Yu, W. Zhou, Entropy-based collaborative detection of ddos attacks on community networks, in: 2008 Sixth Annual IEEE International Conference on Pervasive Computing and Communications (PerCom), IEEE, pp. 566–571 (2008).
[22] A. Lakhina, M. Crovella, C. Diot, Mining anomalies using traffic feature distributions, ACM SIGCOMM computer communication review 35, 217–228 (2005).
[23] B. Al-Duwairi, W. Al-Kahla, M. A. AlRefai, Y. Abdelqader, A. Rawash, R. Fahmawi, Siem-based detection and mitigation of iot-botnet ddos attacks, International Journal of Electrical & Computer Engineering (2088-8708) 10 (2020).
[24] M. M. Shurman, O. M. Al-Jarrah, S. B. Esoh, S. H. Alnabelsi, An enhanced cross-layer approach based on fuzzy-logic for securing wireless ad-hoc networks from black hole attacks, International Journal on Communications Antenna and Propagation (IRECAP) (2017).
[25] Z. Xia, S. Lu, J. Li, J. Tang, Enhancing ddos flood attack detection via intelligent fuzzy logic, Informatica 34 (2010).
[26] S. Hemalatha, S. Qaiyum, S. L. A. Haleem, et al., Protection from distributed denial of service attack using fuzzy logic (2021). Https://www.researchsquare.com/article/rs-349667/v1.
[27] H. Rahmani, N. Sahli, F. Kammoun, Joint entropy analysis model for ddos attack detection, in: 2009 Fifth International Conference on Information Assurance and Security, volume 2, IEEE, pp. 267–271 (2009).
[28] Z. Al-Qudah, B. Al-Duwairi, O. Al-Khaleel, Ddos protection as a service: hiding behind the giants, International Journal of Computational Science and Engineering 9, 292–300 (2014).
[29] P. Kamboj, M. C. Trivedi, V. K. Yadav, V. K. Singh, Detection techniques of ddos attacks: A survey, in: 2017 4th IEEE Uttar Pradesh Section International Conference on Electrical, Computer and Electronics (UPCON), IEEE, pp. 675–679 (2017).
[30] M. F. B. Abbas, T. Srikanthan, Low-complexity signature-based malware detection for iot devices, in: International Conference on Applications and Techniques in Information Security, Springer, pp. 181–189 (2017).
[31] H. Wang, J. Gu, S. Wang, An effective intrusion detection framework based on svm with feature augmentation, Knowledge-Based Systems 136, 130–139 (2017).
[32] P. Barford, J. Kline, D. Plonka, A. Ron, A signal analysis of network traffic anomalies, in: Proceedings of the 2nd ACM SIGCOMM Workshop on Internet measurment, pp. 71–82 (2002).
[33] K. A. Bradley, S. Cheung, N. Puketza, B. Mukherjee, R. A. Olsson, Detecting disruptive routers: A distributed network monitoring approach, IEEE network 12, 50–60 (1998).
[34] S. T. Zargar, J. Joshi, D. Tipper, A survey of defense mechanisms against distributed denial of service (ddos) flooding attacks, IEEE Communications Surveys & Tutorials 15, 2046–2069 (2013).
[35] A. Patcha, J.-M. Park, An overview of anomaly detection techniques: Existing solutions and latest technological trends, Computer networks 51, 3448–3470 (2007).
[36] S. Basumallik, R. Ma, S. Eftekharnejad, Packet-data anomaly detection in pmu-based state estimator using convolutional neural network, International Journal of Electrical Power & Energy Systems 107, 690–702 (2019).
[37] K. Fu, D. Cheng, Y. Tu, L. Zhang, Credit card fraud detection using convolutional neural networks, in: International Conference on Neural Information Processing, Springer, pp. 483–490 (2016).
[38] M. Nasr, A. Bahramali, A. Houmansadr, Deepcorr: Strong flow correlation attacks on tor using deep learning, in: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 1962–1976 (2018).
[39] F. Feng, X. Liu, B. Yong, R. Zhou, Q. Zhou, Anomaly detection in ad-hoc networks based on deep learning model: A plug and play device, Ad Hoc Networks 84, 82–89 (2019).
[40] A. A. Ahmed, W. A. Jabbar, A. S. Sadiq, H. Patel, Deep learning-based classification model for botnet attack detection, Journal of Ambient Intelligence and Humanized Computing, 1–10 (2020).
[41] G. D. L. T. Parra, P. Rad, K.-K. R. Choo, N. Beebe, Detecting internet of things attacks using distributed deep learning, Journal of Network and Computer Applications 163, 102662 (2020).
[42] M. Alsoufi, S. Razak, M. M. Siraj, A. Ali, M. Nasser, S. Abdo, et al., Anomaly intrusion detection systems in iot using deep learning techniques: A survey, in: International Conference of Reliable Information and Communication Technology, Springer, pp. 659–675 (2020).
[43] M. Delakis, C. Garcia, text detection with convolutional neural networks., in: VISAPP (2), pp. 290–294 (2008).
[44] H. I. Fawaz, B. Lucas, G. Forestier, C. Pelletier, D. F. Schmidt, J. Weber, G. I. Webb, L. Idoumghar, P.-A. Muller, F. Petitjean, Inceptiontime: Finding alexnet for time series classification, Data Mining and Knowledge Discovery 34, 1936–1962 (2020).
[45] M. Z. Alom, T. M. Taha, C. Yakopcic, S. Westberg, P. Sidike, M. S. Nasrin, M. Hasan, B. C. Van Essen, A. A. Awwal, V. K. Asari, A state-of-the-art survey on deep learning theory and architectures, Electronics 8, 292 (2019).
[46] I. Aljarrah, D. Mohammad, Video content analysis using convolutional neural networks, in: 2018 9th International Conference on Information and Communication Systems (ICICS), IEEE, pp. 122–126 (2018).
[47] X. Zhang, J. Zhao, Y. LeCun, Character-level convolutional networks for text classification, arXiv preprint arXiv:1509.01626 (2015).
[48] A. Krizhevsky, I. Sutskever, G. E. Hinton, Imagenet classification with deep convolutional neural networks, Advances in neural information processing systems 25, 1097–1105 (2012).
[49] S. Hochreiter, The vanishing gradient problem during learning recurrent neural nets and problem solutions, International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems 6, 107–116 (1998).
[50] Y. Bengio, P. Simard, P. Frasconi, Learning long-term dependencies with gradient descent is difficult, IEEE transactions on neural networks 5, 157–166 (1994).
[51] G. I. Winata, O. P. Kampman, P. Fung, Attention-based lstm for psychological stress detection from spoken language using distant supervision, in: 2018 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), IEEE, pp. 6204–6208 (2018).
[52] A. Samy, H. Yu, H. Zhang, Fog-based attack detection framework for internet of things using deep learning, IEEE Access 8, 74571–74585 (2020).
[53] N. Koroniotis, N. Moustafa, E. Sitnikova, B. Turnbull, Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset, Future Generation Computer Systems 100, 779–796 (2019).
[54] S. Patro, K. K. Sahu, Normalization: A preprocessing stage, arXiv preprint arXiv:1503.06462 (2015).
[55] D. P. Kingma, J. Ba, Adam: A method for stochastic optimization, arXiv preprint arXiv:1412.6980 (2014).
[56] N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, R. Salakhutdinov, Dropout: a simple way to prevent neural networks from overfitting, The Journal of Machine learning research 15, 1929–1958 (2014).

Views: 192Downloads: 2Citations: 0