Beyond Packets: Unmasking IoT Attacks Through Flow-based Features by Arun Kaniyamattam

THE SUMMARYAI-generated

Key Concepts

  • Flow-based features
  • Anomaly detection
  • IoT security
  • CIC IoT 2023 dataset
  • Feature extraction pipeline
  • Machine learning classifiers (XGBoost, Decision Tree, Random Forest, Multi-Layer Perceptron, Logistic Regression)
  • Recursive Feature Elimination (RFE)
  • Privacy-preserving approach
  • Edge deployment

1. Motivation for Flow-Based Metrics

  • Stealthy and Diverse Threats: Modern IoT threats are increasingly stealthy, exploiting encrypted or proprietary payloads.
  • Heterogeneous IoT Environments: A "one-size-fits-all" deep packet inspection approach doesn't scale well in diverse IoT deployments.
  • Resource Constraints: IoT devices often have limited resources, making large models infeasible for live environments.
  • Data Set Gaps: Few publicly available data sets capture both benign and attack scenarios at flow granularity.

2. Corpus: CIC IoT 2023 Data Set

  • Real-World Data: Constructed from real-world IoT devices deployed in a large-scale testbed.
  • Compromised Devices: A subset of devices were compromised to execute various attacks, captured in PCAP format.
  • Attack Categories: Attacks were grouped into seven categories based on tactics: flooding (DoS, DDoS), probing (reconnaissance), web-based attacks, brute force, spoofing, malware, etc.
  • Benign Traffic: The data set included extensive periods of normal traffic, providing necessary contrast for anomaly detection.

3. Flow Extraction Process

  • Metadata Analysis: Flow-based analysis collects metadata rather than actual payloads, providing scalable and privacy-preserving visibility.
  • Trade-off: Forensic depth of full payload inspection is traded for speed and scalability.
  • Real-Time Anomaly Detection: Enables real-time anomaly detection across environments with a huge number of devices.
  • Flow Definition: A flow is a group of packets transmitted between two endpoints (client and server) over a protocol, defined by a five-tuple: source IP, destination IP, source port, destination port, and protocol.
  • Wireshark Example: A Wireshark screenshot of HTTPS interaction illustrates the TCP handshake, TLS key exchange, encrypted application data, and TCP four-way tear down.
  • CIC Flow Meter: An open-source tool created by CIC that converts raw packet capture files into bidirectional flow records.
  • Bidirectional Flow Analysis: Calculates statistical time-related features separately for forward and backward directions.
  • Data Dimensionality Reduction: CIC Flow Meter collapses dozens of packet lines into a single flow record.
  • Fixed Feature Length Vector: Each flow is represented as a fixed feature length vector (e.g., flow ID, f1 to f76).
  • CSV Output: CIC Flow Meter exports flow records into CSV files for inspection or ingestion into data science toolkits.

4. Pre-processing Flow

  • PCA Files to Flow Records: PCA files are processed by CIC Flow Meter to generate flow records.
  • Feature Extraction: Feature extraction scripts compute over 80 statistical features per flow.
  • Pre-processing and Data Cleansing: Descriptors undergo pre-processing and data cleansing to produce a streamlined feature set.
  • Input to Machine Learning Models: Resulting CSV tables serve as input to machine learning models for anomaly attack detection.

5. Data Set Features

  • 80+ Statistical Features: Every flow record has over 80 statistical features.
  • Basic Flow Identifiers: Includes the five-tuple (source IP, destination IP, source port, destination port, and protocol).
  • Inter Arrival Time Features: Based on time intervals between sequential packets within a network flow.
    • Inter arrival times between two packets sent in the flow.
    • Inter arrival time features for two packets sent in the forward direction.
    • Inter arrival time features for two packets sent in the backward direction.
  • Flag Features: Measure the existence and frequency of specific TCP flags in the packets.
    • Number of PSH flags sent in the forward and backward direction.
    • Urgent flag that are being sent in the forward and backward direction.
  • Active Idle Features: Collect features from both active and idle TCP flows.
    • Active mean: Helps identify abnormally idle or active duration.
    • Active max: Identifies insights about the upper limit of flow activities.
  • Segment Bulk and Byte Features: Provide insights about the size of the data flows.
    • Segment size averages for forward and backward direction.
    • Bytes per bulk average in forward and backward direction.
    • Packet per bulk in forward and backward direction.
    • Bulk rate average and forward and backward direction.
  • Other Statistical Features: Provide additional information about the flow.
  • Total Features: A total of 84 features are generated using this process.

6. Experiments and Results

  • Data Set Size: The data set had about 2.3 million flows, including both benign traffic and seven kinds of attacks.
  • Detection Tasks: Two detection tasks were framed:
    • Binary anomaly detection of attacks (benign vs. any attack).
    • Binary classification of one kind of attack against benign.
  • Classifiers: Five off-the-shelf classifiers were trained: XGBoost, Decision Tree, Random Forest, Multi-Layer Perceptron, and Logistic Regression.
  • Recursive Feature Elimination (RFE): RF recursive feature elimination was applied to retain the top 40 most informative features.
  • Evaluation Metrics: Standard metrics like accuracy, precision, recall, and F1 score were used.
  • Results Against All Attacks: XGBoost performed best with about 95.92% accuracy using all features and 95.85% with 40 features.
  • Key Takeaway: Flow-based feature representation enables high accuracy across millions of encrypted flows.
  • Feature Selection: Recursive feature elimination halved the feature set with negligible loss, making real-time edge deployment practical.
  • Per Attack Classification: XGBoost was used for per-attack classification with both the full set of features and the 40 features selected by RFE.
  • Observation: Pruning to 40 features barely changed accuracy or F1 score.
    • Brute force stays at 99.6% accuracy.
    • DoS and malware remain about 99.8%.
  • Test Time Reduction: Using RFE, test times shrank by roughly half.
  • Demonstration: A carefully chosen subset of flow-based metrics delivers the same detection power as the full set while cutting the computational cost.

7. Conclusion

  • Leveraging Existing Data: The existing flow data in the CIC IoT data set was leveraged.
  • Compact Data Set: By focusing on flow-based features, IoT traffic was condensed into a compact set of actionable data.
  • Peak Detection Accuracy: Trimming to the top 40 features using RFE maintained peak detection accuracy while slashing the computation cost.
  • Validation: Flow aggregation is a powerful privacy-preserving approach for IoT anomaly attack detection.

8. Future Directions

  • Sophisticated Modeling Techniques: Explore more sophisticated modeling techniques that capture relationships across devices and flows.
  • Explanability Layers: Adding explanability layers would help in speeding incident response.
  • Edge Deployment: Aim to push detection models down to the edge to score flows in real time on IoT with minimal overhead.
  • Temporal Flow Graphs: Constructing temporal flow graphs and applying graph embedding techniques may reveal more slow-burn threats.

9. Synthesis/Conclusion

The presentation highlights the effectiveness of flow-based features for anomaly detection in IoT environments. By leveraging the CIC IoT 2023 data set and employing techniques like CIC Flow Meter and Recursive Feature Elimination, the research demonstrates that a compact set of flow-based metrics can achieve high accuracy in detecting various attacks while maintaining privacy and reducing computational costs. The future directions outlined aim to further enhance the approach by incorporating more sophisticated modeling techniques, explanability layers, edge deployment, and temporal flow analysis.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.