开发一种混合特征选择方法来检测物联网设备中的僵尸网络攻击

IF 1.2 4区 综合性期刊 Q3 MULTIDISCIPLINARY SCIENCES Kuwait Journal of Science Pub Date : 2024-04-04 DOI:10.1016/j.kjs.2024.100222
Hyder Yahya Alshaeaa , Zainab Mohammed Ghadhban
{"title":"开发一种混合特征选择方法来检测物联网设备中的僵尸网络攻击","authors":"Hyder Yahya Alshaeaa ,&nbsp;Zainab Mohammed Ghadhban","doi":"10.1016/j.kjs.2024.100222","DOIUrl":null,"url":null,"abstract":"<div><p>The Internet of Things, or IoT, is an important technology applied in various applications such as smart homes and innovative healthcare. Due to its architecture, IoT-based devices suffer from various security challenges, most commonly, botnet attacks. This article aims to develop a hybrid feature selection method to find the most influential features based on three feature selection methods, correlation, generalized normal distribution optimization, and lasso, to detect botnet attacks in IoT devices. The UNSW-NB15 dataset is used to assess the proposed system. Several classification models including decision tree (DT), random forest (RF), k-nearest neighbors (KNN), adaptive boosting (AdaBoost), and bagging are utilized for the classification purpose. The proposed system was evaluated using several performance metrics. The results showed the correlation feature selection method had the most accurate botnet attack detection rate. RF also outperformed other models with a 95.11% detection rate in binary classification and 83.96% in multi-classification. On the other hand, results showed that the proposed hybrid method outperformed the feature selection methods with an increase of about 3% in both classifications. The AdaBoost model achieved an accuracy of 99.28% with binary classification by using 18 features, and the RF model achieved an accuracy of 86.62% with multi-classification by using 22 features. The robustness and efficacy of the proposed approach were demonstrated by comparing the study's results with several other studies that have used the same dataset. The results of the study can be implemented in real applications to detect network interference of a dynamic nature in real-time and assist intrusion detection systems (IDS) in addressing these attacks.</p></div>","PeriodicalId":17848,"journal":{"name":"Kuwait Journal of Science","volume":"51 3","pages":"Article 100222"},"PeriodicalIF":1.2000,"publicationDate":"2024-04-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2307410824000476/pdfft?md5=ce90eb711b9d3aebb22f9f7d68cbdffc&pid=1-s2.0-S2307410824000476-main.pdf","citationCount":"0","resultStr":"{\"title\":\"Developing a hybrid feature selection method to detect botnet attacks in IoT devices\",\"authors\":\"Hyder Yahya Alshaeaa ,&nbsp;Zainab Mohammed Ghadhban\",\"doi\":\"10.1016/j.kjs.2024.100222\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>The Internet of Things, or IoT, is an important technology applied in various applications such as smart homes and innovative healthcare. Due to its architecture, IoT-based devices suffer from various security challenges, most commonly, botnet attacks. This article aims to develop a hybrid feature selection method to find the most influential features based on three feature selection methods, correlation, generalized normal distribution optimization, and lasso, to detect botnet attacks in IoT devices. The UNSW-NB15 dataset is used to assess the proposed system. Several classification models including decision tree (DT), random forest (RF), k-nearest neighbors (KNN), adaptive boosting (AdaBoost), and bagging are utilized for the classification purpose. The proposed system was evaluated using several performance metrics. The results showed the correlation feature selection method had the most accurate botnet attack detection rate. RF also outperformed other models with a 95.11% detection rate in binary classification and 83.96% in multi-classification. On the other hand, results showed that the proposed hybrid method outperformed the feature selection methods with an increase of about 3% in both classifications. The AdaBoost model achieved an accuracy of 99.28% with binary classification by using 18 features, and the RF model achieved an accuracy of 86.62% with multi-classification by using 22 features. The robustness and efficacy of the proposed approach were demonstrated by comparing the study's results with several other studies that have used the same dataset. The results of the study can be implemented in real applications to detect network interference of a dynamic nature in real-time and assist intrusion detection systems (IDS) in addressing these attacks.</p></div>\",\"PeriodicalId\":17848,\"journal\":{\"name\":\"Kuwait Journal of Science\",\"volume\":\"51 3\",\"pages\":\"Article 100222\"},\"PeriodicalIF\":1.2000,\"publicationDate\":\"2024-04-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.sciencedirect.com/science/article/pii/S2307410824000476/pdfft?md5=ce90eb711b9d3aebb22f9f7d68cbdffc&pid=1-s2.0-S2307410824000476-main.pdf\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Kuwait Journal of Science\",\"FirstCategoryId\":\"103\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2307410824000476\",\"RegionNum\":4,\"RegionCategory\":\"综合性期刊\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"MULTIDISCIPLINARY SCIENCES\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Kuwait Journal of Science","FirstCategoryId":"103","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2307410824000476","RegionNum":4,"RegionCategory":"综合性期刊","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"MULTIDISCIPLINARY SCIENCES","Score":null,"Total":0}
引用次数: 0

摘要

物联网(IoT)是一种重要的技术,可应用于智能家居和创新医疗等各种领域。由于其架构,基于物联网的设备面临着各种安全挑战,其中最常见的是僵尸网络攻击。本文旨在开发一种混合特征选择方法,基于相关性、广义正态分布优化和 lasso 三种特征选择方法找到最有影响力的特征,以检测物联网设备中的僵尸网络攻击。UNSW-NB15 数据集被用来评估所提出的系统。在分类过程中使用了多种分类模型,包括决策树 (DT)、随机森林 (RF)、k-近邻 (KNN)、自适应提升 (AdaBoost) 和袋集 (bagging)。使用多个性能指标对所提出的系统进行了评估。结果显示,相关特征选择法的僵尸网络攻击检测率最为准确。RF 的二元分类检测率为 95.11%,多分类检测率为 83.96%,也优于其他模型。另一方面,结果表明,所提出的混合方法的性能优于特征选择方法,在两种分类中都提高了约 3%。AdaBoost 模型使用 18 个特征进行二元分类,准确率达到 99.28%;RF 模型使用 22 个特征进行多元分类,准确率达到 86.62%。通过将研究结果与使用相同数据集的其他几项研究结果进行比较,证明了所建议方法的稳健性和有效性。研究结果可在实际应用中实施,以实时检测动态性质的网络干扰,并协助入侵检测系统(IDS)应对这些攻击。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Developing a hybrid feature selection method to detect botnet attacks in IoT devices

The Internet of Things, or IoT, is an important technology applied in various applications such as smart homes and innovative healthcare. Due to its architecture, IoT-based devices suffer from various security challenges, most commonly, botnet attacks. This article aims to develop a hybrid feature selection method to find the most influential features based on three feature selection methods, correlation, generalized normal distribution optimization, and lasso, to detect botnet attacks in IoT devices. The UNSW-NB15 dataset is used to assess the proposed system. Several classification models including decision tree (DT), random forest (RF), k-nearest neighbors (KNN), adaptive boosting (AdaBoost), and bagging are utilized for the classification purpose. The proposed system was evaluated using several performance metrics. The results showed the correlation feature selection method had the most accurate botnet attack detection rate. RF also outperformed other models with a 95.11% detection rate in binary classification and 83.96% in multi-classification. On the other hand, results showed that the proposed hybrid method outperformed the feature selection methods with an increase of about 3% in both classifications. The AdaBoost model achieved an accuracy of 99.28% with binary classification by using 18 features, and the RF model achieved an accuracy of 86.62% with multi-classification by using 22 features. The robustness and efficacy of the proposed approach were demonstrated by comparing the study's results with several other studies that have used the same dataset. The results of the study can be implemented in real applications to detect network interference of a dynamic nature in real-time and assist intrusion detection systems (IDS) in addressing these attacks.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Kuwait Journal of Science
Kuwait Journal of Science MULTIDISCIPLINARY SCIENCES-
CiteScore
1.60
自引率
28.60%
发文量
132
期刊介绍: Kuwait Journal of Science (KJS) is indexed and abstracted by major publishing houses such as Chemical Abstract, Science Citation Index, Current contents, Mathematics Abstract, Micribiological Abstracts etc. KJS publishes peer-review articles in various fields of Science including Mathematics, Computer Science, Physics, Statistics, Biology, Chemistry and Earth & Environmental Sciences. In addition, it also aims to bring the results of scientific research carried out under a variety of intellectual traditions and organizations to the attention of specialized scholarly readership. As such, the publisher expects the submission of original manuscripts which contain analysis and solutions about important theoretical, empirical and normative issues.
期刊最新文献
Optimization of fermentation conditions for 3-methylthio-1-propanol production by Saccharomycopsis fibuligera Y1402 in tobacco matrix Bayesian estimation strategy for multi-component geometric life testing model under doubly type-1 censoring scheme In silico analysis of point mutation (c.687dupC; p. Met230Hisfs∗6) in PGAM2 gene that causes Glycogen Storage Disease (GSD) Type X Innovative synthesis and performance enhancement of yttria-stabilized zirconia nanocrystals via hydrothermal method with Uncaria gambir Roxb. leaf extract as a capping agent Bayesian estimation under different loss functions for the case of inverse Rayleigh distribution
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1