Skip to main content

Machine learning DDoS detection for consumer internet of things devices

Author(s): Doshi, R; Apthorpe, N; Feamster, Nick

Download
To refer to this page use: http://arks.princeton.edu/ark:/88435/pr1f53b
Abstract: © 2018 IEEE. An increasing number of Internet of Things (IoT) devices are connecting to the Internet, yet many of these devices are fundamentally insecure, exposing the Internet to a variety of attacks. Botnets such as Mirai have used insecure consumer IoT devices to conduct distributed denial of service (DDoS) attacks on critical Internet infrastructure. This motivates the development of new techniques to automatically detect consumer IoT attack traffic. In this paper, we demonstrate that using IoT-specific network behaviors (e.g., limited number of endpoints and regular time intervals between packets) to inform feature selection can result in high accuracy DDoS detection in IoT network traffic with a variety of machine learning algorithms, including neural networks. These results indicate that home gateway routers or other network middleboxes could automatically detect local IoT device sources of DDoS attacks using low-cost machine learning algorithms and traffic data that is flow-based and protocol-agnostic.
Publication Date: 2-Aug-2018
Citation: Doshi, R, Apthorpe, N, Feamster, N. (2018). Machine learning DDoS detection for consumer internet of things devices. Proceedings - 2018 IEEE Symposium on Security and Privacy Workshops, SPW 2018, 29 - 35. doi:10.1109/SPW.2018.00013
DOI: doi:10.1109/SPW.2018.00013
Pages: 29 - 35
Type of Material: Journal Article
Journal/Proceeding Title: Proceedings - 2018 IEEE Symposium on Security and Privacy Workshops, SPW 2018
Version: Author's manuscript



Items in OAR@Princeton are protected by copyright, with all rights reserved, unless otherwise indicated.