A Dual-Function Dataset for IoT Device Identification and Anomaly Detection by Dr. Mahdi Rabbani

THE SUMMARYAI-generated

Key Concepts

  • IoT Device Identification
  • Anomaly Detection
  • Behavioral-based Features
  • HTTPS and User Agent Features
  • Stream Features
  • Channel Features
  • Jitter
  • Zero-day Attack Detection
  • Integrated Model
  • Feature Selection

Research Objectives and Data Set Overview

Dr. Madi Rabani discusses the CIC IoT A 2024 data set, a dual-function data set designed for both IoT device identification and anomaly detection. The research objectives are twofold:

  1. IoT Device Identification: Classifying different types of IoT devices based on their behavioral patterns.
  2. Anomaly Detection: Detecting individual attacks and abnormal behaviors against benign traffic.

Phase 1: IoT Device Identification

Behavioral-Based Features

The approach involves collecting network traffic data from various IoT devices, extracting features specifically for device identification, and using machine learning models for classification. The features are categorized as follows:

  • Network Protocol Features: Characteristics of network protocols used by the devices.
  • Handshake and TLS Features: Features related to the handshake process and TLS encryption.
  • Timing Features: Timing-related characteristics of network traffic.
  • User Agent Features: Information extracted from the user agent string, including browser, operating system, and device details.
  • Statistical Features: Statistical measures derived from the above features.

HTTPS and User Agent Features

Specific features are extracted from HTTPS traffic and user agent strings to aid in identifying IoT devices.

Phase 2: Anomaly Detection

Individual Attack Detection

This phase focuses on detecting seven main attack categories:

  • Distributed Denial of Service (DDoS)
  • Web-based Attacks
  • Reconnaissance (Recon) Attacks
  • Denial of Service (DoS) Attacks
  • Malware Attacks
  • Spoofing
  • Brute Force

Each main attack category has subcategories, and the data set includes folders for each main category with subfolders for the subcategories.

Anomaly Detection Against Benign Traffic

The goal is to identify abnormal behaviors that deviate from normal benign traffic patterns.

Feature Extraction for Anomaly Detection

  • Stream Features: A sequence of packet exchanges between a specific source and destination, representing a single communication session. Unexpected speed in traffic or changes in session duration can signal a security incident.
  • Channel Features: The communication pathway between two devices, representing the logical connection for data transmission. Sudden increases in unexpected communication paths can indicate a compromised device or unauthorized data transfer.
  • Jitter: The variability in packet arrival time, measuring the difference in the delay of packets. Sudden increases in jitter can indicate network congestion, faulty devices, or deliberate attacks.

These features are extracted over different time periods (1 second, 5 seconds, 10 seconds, 30 seconds, and 60 seconds) to enhance anomaly detection and capture comprehensive behavior.

Statistical Features

New statistical features (count, mean, variance, and sum) are calculated for all extracted features to further differentiate between benign traffic and attack categories.

Data and Statistics

The presentation includes comparisons of feature values (e.g., average total packets in a stream, jitter) between benign traffic and different attack categories. These comparisons highlight the differences in network behavior under normal and malicious conditions.

Zero-Day Attack Detection

A scenario is presented for zero-day attack detection, where the model is trained without brute force attack data and then tested against it. The results show that while the performance is not as good as with known attacks, the model still achieves over 90% accuracy.

Integrated Model

An integrated model is developed for both device identification and anomaly detection. This model first classifies the IoT device and then detects anomalies against benign samples.

Conclusion

The CIC IoT A 2024 data set provides a valuable resource for developing fast and accurate models for IoT device identification and anomaly detection. The use of behavioral-based features, combined with statistical analysis and time-series analysis, enables effective classification and detection with minimal computational overhead. The unified model allows for robust IoT security by first identifying the device type and then detecting anomalies.

Question and Answer

In response to a question about feature selection, Dr. Madi confirms that feature selection techniques were applied to reduce the dimensionality of the feature space. The specific techniques and results are available in the published paper associated with the data set.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.