Your browser doesn't support javascript.
loading
An Aggregated Mutual Information Based Feature Selection with Machine Learning Methods for Enhancing IoT Botnet Attack Detection.
Al-Sarem, Mohammed; Saeed, Faisal; Alkhammash, Eman H; Alghamdi, Norah Saleh.
Afiliação
  • Al-Sarem M; College of Computer Science and Engineering, Taibah University, Medina 42353, Saudi Arabia.
  • Saeed F; College of Computer Science and Engineering, Taibah University, Medina 42353, Saudi Arabia.
  • Alkhammash EH; School of Computing and Digital Technology, Birmingham City University, Birmingham B4 7XG, UK.
  • Alghamdi NS; Department of Computer Science, College of Computers and Information Technology, Taif University, P.O. Box 11099, Taif 21944, Saudi Arabia.
Sensors (Basel) ; 22(1)2021 Dec 28.
Article em En | MEDLINE | ID: mdl-35009725
ABSTRACT
Due to the wide availability and usage of connected devices in Internet of Things (IoT) networks, the number of attacks on these networks is continually increasing. A particularly serious and dangerous type of attack in the IoT environment is the botnet attack, where the attackers can control the IoT systems to generate enormous networks of "bot" devices for generating malicious activities. To detect this type of attack, several Intrusion Detection Systems (IDSs) have been proposed for IoT networks based on machine learning and deep learning methods. As the main characteristics of IoT systems include their limited battery power and processor capacity, maximizing the efficiency of intrusion detection systems for IoT networks is still a research challenge. It is important to provide efficient and effective methods that use lower computational time and have high detection rates. This paper proposes an aggregated mutual information-based feature selection approach with machine learning methods to enhance detection of IoT botnet attacks. In this study, the N-BaIoT benchmark dataset was used to detect botnet attack types using real traffic data gathered from nine commercial IoT devices. The dataset includes binary and multi-class classifications. The feature selection method incorporates Mutual Information (MI) technique, Principal Component Analysis (PCA) and ANOVA f-test at finely-granulated detection level to select the relevant features for improving the performance of IoT Botnet classifiers. In the classification step, several ensemble and individual classifiers were used, including Random Forest (RF), XGBoost (XGB), Gaussian Naïve Bayes (GNB), k-Nearest Neighbor (k-NN), Logistic Regression (LR) and Support Vector Machine (SVM). The experimental results showed the efficiency and effectiveness of the proposed approach, which outperformed other techniques using various evaluation metrics.
Assuntos
Palavras-chave

Texto completo: 1 Coleções: 01-internacional Base de dados: MEDLINE Assunto principal: Internet das Coisas Tipo de estudo: Diagnostic_studies / Prognostic_studies Idioma: En Revista: Sensors (Basel) Ano de publicação: 2021 Tipo de documento: Article País de afiliação: Arábia Saudita

Texto completo: 1 Coleções: 01-internacional Base de dados: MEDLINE Assunto principal: Internet das Coisas Tipo de estudo: Diagnostic_studies / Prognostic_studies Idioma: En Revista: Sensors (Basel) Ano de publicação: 2021 Tipo de documento: Article País de afiliação: Arábia Saudita