CRLGMay 9, 2018

N-BaIoT: Network-based Detection of IoT Botnet Attacks Using Deep Autoencoders

arXiv:1805.03409v11327 citations
Originality Incremental advance
AI Analysis

This addresses the threat of IoT botnet attacks for network security, but it is incremental as it applies deep autoencoders to a specific domain.

The paper tackles the problem of detecting IoT botnet attacks by proposing a network-based anomaly detection method using deep autoencoders, which accurately and instantly detected attacks from nine commercial IoT devices infected with Mirai and BASHLITE botnets.

The proliferation of IoT devices which can be more easily compromised than desktop computers has led to an increase in the occurrence of IoT based botnet attacks. In order to mitigate this new threat there is a need to develop new methods for detecting attacks launched from compromised IoT devices and differentiate between hour and millisecond long IoTbased attacks. In this paper we propose and empirically evaluate a novel network based anomaly detection method which extracts behavior snapshots of the network and uses deep autoencoders to detect anomalous network traffic emanating from compromised IoT devices. To evaluate our method, we infected nine commercial IoT devices in our lab with two of the most widely known IoT based botnets, Mirai and BASHLITE. Our evaluation results demonstrated our proposed method's ability to accurately and instantly detect the attacks as they were being launched from the compromised IoT devices which were part of a botnet.

Code Implementations2 repos
Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes