An Attack-Resilient Architecture for the Internet of Things

Hussain M.J. Almohri, Layne T. Watson, David Evans

Research output: Contribution to journalArticlepeer-review

17 Scopus citations

Abstract

With current IoT architectures, once a single device in a network is compromised, it can be used to disrupt the behavior of other devices on the same network. Even though system administrators can secure critical devices in the network using best practices and state-of-the-art technology, a single vulnerable device can undermine the security of the entire network. The goal of this work is to limit the ability of an attacker to exploit a vulnerable device on an IoT network and fabricate deceitful messages to co-opt other devices. The approach is to limit attackers by using device proxies that are used to retransmit and control network communications. We present an architecture that prevents deceitful messages generated by compromised devices from affecting the rest of the network. The design assumes a centralized and trustworthy machine that can observe the behavior of all devices on the network. The central machine collects application layer data, as opposed to low-level network traffic, from each IoT device. The collected data is used to train models that capture the normal behavior of each individual IoT device. The normal behavioral data is then used to monitor the IoT devices and detect anomalous behavior. This paper reports on our experiments using both a binary classifier and a density-based clustering algorithm to model benign IoT device behavior with a realistic test-bed, designed to capture normal behavior in an IoT-monitored environment. Results from the IoT testbed show that both the classifier and the clustering algorithms are promising and encourage the use of application-level data for detecting compromised IoT devices.

Original languageEnglish
Article number9093828
Pages (from-to)3940-3954
Number of pages15
JournalIEEE Transactions on Information Forensics and Security
Volume15
DOIs
StatePublished - 2020

Keywords

  • Internet of Things
  • intrusion detection
  • network security
  • unsupervised learning

Funding Agency

  • Kuwait Foundation for the Advancement of Sciences

Fingerprint

Dive into the research topics of 'An Attack-Resilient Architecture for the Internet of Things'. Together they form a unique fingerprint.

Cite this