R-IDPS: Real Time SDN-based IDPS system for IoT security

Mazhar, Noman and Salleh, Rosli and Zaba, Reza and Zeeshan, Muhammad and Hameed, M. Muzaffar and Khan, Nauman (2022) R-IDPS: Real Time SDN-based IDPS system for IoT security. CMC-Computers Materials & Continua, 73 (2). pp. 3099-3118. ISSN 1546-2218, DOI https://doi.org/10.1109/HONET53078.2021.9615449.

Full text not available from this repository.


The advent of the latest technologies like the Internet of things (IoT) transforms the world from a manual to an automated way of lifestyle. Meanwhile, IoT sector open numerous security challenges. In traditional networks, intrusion detection and prevention systems (IDPS) have been the key player in the market to ensure security. The challenges to the conventional IDPS are implementation cost, computing power, processing delay, and scal-ability. Further, online machine learning model training has been an issue. All these challenges still question the IoT network security. There has been a lot of research for IoT based detection systems to secure the IoT devices such as centralized and distributed architecture-based detection systems. The centralized system has issues like a single point of failure and load balancing while distributed system design has scalability and heterogeneity hassles. In this study, we design and develop an agent-based hybrid prevention system based on software-defined networking (SDN) technology. The system uses lite weight agents with the ability to scaleup for bigger networks and is feasible for heterogeneous IoT devices. The baseline profile for the IoT devices has been developed by analyzing network flows from all the IoT devices. This profile helps in extracting IoT device features. These features help in the development of our dataset that we use for anomaly detection. For anomaly detection, support vector machine has been used to detect internet control message protocol (ICMP) flood and transmission control protocol synchronize (TCP SYN) flood attacks. The proposed system based on machine learning model is fully capable of online and offline training. Other than detection accuracy, the system can fully mitigate the attacks using the software-defined technology SDN technology. The major goal of the research is to analyze the accuracy of the hybrid agent-based intrusion detection systems as compared to conven-tional centralized only solutions, especially under the flood attack conditions generated by the distributed denial of service (DDoS) attacks. The system shows 97% to 99% accuracy in simulated results with no false-positive alarm. Also, the system shows notable improvement in terms of resource utilization and performance under attack scenarios. The R-IDPS is scalable, and the system is suitable for heterogeneous IoT devices and networks.

Item Type: Article
Funders: Universiti Malaya [Grant No:GPF017D-2019]
Uncontrolled Keywords: Machine learning; Internet of things; Software defined networking; Distributed denial of service attacks
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
T Technology > TA Engineering (General). Civil engineering (General)
Divisions: Faculty of Computer Science & Information Technology
Depositing User: Ms. Juhaida Abd Rahim
Date Deposited: 13 Oct 2023 03:04
Last Modified: 13 Oct 2023 03:04
URI: http://eprints.um.edu.my/id/eprint/42097

Actions (login required)

View Item View Item