Skip to main navigation Skip to search Skip to main content

AI-driven solutions for safeguarding IoT environments: an intrusion detection and prevention study

  • Poulmanogo Illy

Student thesis: Doctoral thesisDoctorate in Engineering: Engineering

Abstract

The progress in information and communication technologies (ICT) made in recent years has led to new revolutionary concepts where one of the most important ones is the Internet of Things (IoT). IoT, through low-cost connected objects, enables abundant and real-time data collection and smart automation of information and operation systems. The tremendous innovation opportunity opened by IoT has triggered its massive adoption in multiple business domains. Meanwhile, the impact of cyber-attacks has become more alarming for three main reasons: (1) critical weaknesses in IoT security mechanisms, (2) valuable data that attract cyber-attacks, and (3) the level of control that successful attacks could open in IoT-based automated systems. In this context, intrusion detection and prevention, which is essential in cyber-security, has become one of the most active research areas for securing IoT applications. Intrusion detection systems (IDSs) can analyze real-time activities to detect and report cyber-attacks to security administrators or automated intrusion prevention systems (IPSs) that initiate response measures to block the threats or attenuate their impact. However, given the changing and expanding nature of cyber-attacks, it is essential to design and implement new IDSs that are intelligent, accurate, fast, and scalable. In this vein, machine learning (ML), and particularly deep learning (DL), has emerged as a suitable approach to meet these requirements. In this thesis, three main objectives essential for the design of an intelligent intrusion detection system are considered. These objectives are the detection of a wide range of IoT attacks, including zero-day attacks, the enhancement of the detection accuracy, and the minimization of the detection and response latency. To achieve these objectives, we analyze the cyber-attacks that target IoT systems and propose diverse features that can be used in ML algorithms to detect each of these attacks efficiently. Then, we implement and compare different learning algorithms, including shallow, deep, and ensemble learning methods, to propose models that enhance the detection accuracy. Furthermore, we design a collaborative learning scheme that enables low-latency detection and response to mitigate detected attacks. Chapter 2 mainly studies the behaviors of different IoT attacks in a smart home scenario, and analyzes the quality of the features that can be extracted and employed in ML algorithms to detect each of these attacks efficiently. We propose various features that can improve the performance of ML-based IDSs. Specifically, transmission control protocol/internet protocol (TCP/IP) packet headers, time-based statistics, connection-based statistics, and TCP/IP packet content features are proposed. Furthermore, to detect attacks that exploit the wireless communication channel, more features are discussed, including the distance from the radio transmitter, radio-frequency fingerprint, received signal strength, signal-to-noise ratio, and the system’s energy profile. Chapter 3 proposes a hybrid multistage deep neural networks (DNNs)-based intrusion detection and prevention system (IDPS) with improved accuracy for critical industrial control systems (ICSs) that cannot afford to compromise the security to improve latency. The learning models are trained sequentially with diverse algorithms, and each model in the sequence focuses on the limitations of the previous models. The resulting multistage DNN uses each stage’s decision in a combination function to produce a final decision with improved accuracy. In contrast to Chapter 3 which considers a high-risk ICS scenario where enforced security is preferable even at the cost of latency, chapter 4 considers a mission-critical ICS scenario where latency is also a crucial requirement. In this context, first and foremost, we conduct a time complexity analysis of DNNs to illustrate how the structures of these models impact the training and prediction latency. Then, we design a low latency and robust deep learning-based collaborative IDPS that employs two levels of classifications. The first level performs a lightweight DNN-based anomaly detection in local servers to allow faster attack detection and emergency response measures. The second level performs attack classification of the anomalous traffic in cloud servers to guide complementary intrusion prevention tasks. Moreover, an SDN-based deployment architecture of the proposed collaborative IDPS in ICS networks is provided.
Date18 Mar 2024
Original languageAmerican English
Awarding Institution
  • École de technologie supérieure
SupervisorGeorges Kaddoum (Supervisor)

Cite this

'