arrow
Return

ShieldRNN: A Distributed Flow-Based DDoS Detection Solution for IoT Using Sequence Majority Voting

delete2022-01-01
delete13
delete
OA
AI
F
Faris Alasmary *
S
Sulaiman Alraddadi
S
Saad Al-Ahmadi
J
Jalal Al‐Muhtadi
DOI:10.1109/ACCESS.2022.3200477delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The Distributed Denial of Service (DDoS) attack is considered one of the most critical threats on the Internet, blocking legitimate users from accessing online services. Botnets have exploited insecure IoT devices and used them to launch DDoS attacks. Providing IoT devices with the ability to detect DDoS attacks will prevent them from becoming contributors to these attacks. This paper presents an efficient solution to defend IoT devices against such inevitable attacks. The proposed solution consists of two parts: an IoT node detector and a server detector. The IoT node detector is a lightweight classifier to monitor egress traffic. The server detector is a more accurate classifier that is used by the IoT node if it suspected itself to be a contributor to a DDoS attack. To develop an accurate server detector, this paper proposes ShieldRNN: a novel training and prediction approach for RNN/LSTM models. We compare ShieldRNN with other supervised and unsupervised models on the CIC-IDS2017 dataset and show that it outperforms them. Also, we set baseline results for DDoS detection on the CIC IoT 2022 dataset.
Keywords:
Internet of Things
Denial-of-service attack
IP networks
Computer crime
Servers
Detectors
Protocols
Anomaly detection
Intrusion detection
Machine learning
Computer security
Distributed denial of service (DDoS)
anomaly detection
intrusion detection system (IDS)
machine learning
majority voting

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

K
King Saud University
Scholars:
3.4W
Papers: 3.8W
Citations: 815