Abstract
With the advances in Internet of Things (IoT) technologies, more and more smart sensors and devices are connected to the Internet. Since the original idea of smart devices is better connection with each other, very limited security mechanism has been designed. Due to the diverse behaviors for various types of devices, it would be costly to manually design separate security mechanism. To prevent these devices from potential threats, It would be helpful if we could learn the characteristics of diverse device types based on the network packets generated. In this paper, we propose a machine learning approach to device type identification through network traffic analysis for anomaly detection in IoT. First, characteristics of different types of IoT devices are extracted from the generated network packets and learned using unsupervised and supervised learning methods. Second, we apply feature selection methods to the model learned from device type identification module to improve the performance of classification. In our experiments, the performance of device type identification on real data in a smart factory using supervised learning is better than unsupervised learning. The best performance can be achieved by XGBoost with an accuracy of 97.6% and micro-averaging F1 score of 97.6%. This shows the potential of the proposed approach for automatically identifying devices for anomaly detection in smart factories. Further investigation is needed to verify the proposed approach using more types of devices.
| Original language | English |
|---|---|
| Title of host publication | Machine Learning for Networking - Third International Conference, MLN 2020, Revised Selected Papers |
| Editors | Éric Renault, Selma Boumerdassi, Paul Mühlethaler |
| Publisher | Springer Science and Business Media Deutschland GmbH |
| Pages | 337-348 |
| Number of pages | 12 |
| ISBN (Print) | 9783030708658 |
| DOIs | |
| State | Published - 2021 |
| Event | 3rd International Conference on Machine Learning for Networking, MLN 2020 - Paris, France Duration: 24 Nov 2020 → 26 Nov 2020 |
Publication series
| Name | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
|---|---|
| Volume | 12629 LNCS |
| ISSN (Print) | 0302-9743 |
| ISSN (Electronic) | 1611-3349 |
Conference
| Conference | 3rd International Conference on Machine Learning for Networking, MLN 2020 |
|---|---|
| Country/Territory | France |
| City | Paris |
| Period | 24/11/20 → 26/11/20 |
Bibliographical note
Publisher Copyright:© 2021, Springer Nature Switzerland AG.
Keywords
- Anomaly detection
- Device identification
- IoT security
- Machine learning
Fingerprint
Dive into the research topics of 'Identifying Device Types for Anomaly Detection in IoT'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver