MétaCan
Menu
Back to cohort
Record W7063809788

AI-driven solutions for safeguarding IoT environments: an intrusion detection and prevention study

2024· other· en· W7063809788 on OpenAlexfundno aff

Bibliographic record

VenueEspace École de technologie supérieure (École de technologie supérieure) · 2024
Typeother
Languageen
FieldPhysics and Astronomy
TopicMagnetic confinement fusion research
Canadian institutionsnot available
FundersNatural Sciences and Engineering Research Council of Canada
KeywordsIntrusion detection systemSafeguardingInternet of ThingsAutomationIntrusion prevention systemInformation securityBlock (permutation group theory)
DOInot available

Abstract

fetched live from OpenAlex

The progress in information and communication technologies (ICT) made in recent years has led to new revolutionary concepts where one of the most important ones is the Internet of Things (IoT). IoT, through low-cost connected objects, enables abundant and real-time data collection and smart automation of information and operation systems. The tremendous innovation opportunity opened by IoT has triggered its massive adoption in multiple business domains. Meanwhile, the impact of cyber-attacks has become more alarming for three main reasons: (1) critical weaknesses in IoT security mechanisms, (2) valuable data that attract cyber-attacks, and (3) the level of control that successful attacks could open in IoT-based automated systems. In this context, intrusion detection and prevention, which is essential in cyber-security, has become one of the most active research areas for securing IoT applications. Intrusion detection systems (IDSs) can analyze real-time activities to detect and report cyber-attacks to security administrators or automated intrusion prevention systems (IPSs) that initiate response measures to block the threats or attenuate their impact. However, given the changing and expanding nature of cyber-attacks, it is essential to design and implement new IDSs that are intelligent, accurate, fast, and scalable. In this vein, machine learning (ML), and particularly deep learning (DL), has emerged as a suitable approach to meet these requirements. \n \nIn this thesis, three main objectives essential for the design of an intelligent intrusion detection system are considered. These objectives are the detection of a wide range of IoT attacks, including zero-day attacks, the enhancement of the detection accuracy, and the minimization of the detection and response latency. To achieve these objectives, we analyze the cyber-attacks that target IoT systems and propose diverse features that can be used in ML algorithms to detect each of these attacks efficiently. Then, we implement and compare different learning algorithms, including shallow, deep, and ensemble learning methods, to propose models that enhance the detection accuracy. Furthermore, we design a collaborative learning scheme that enables low-latency detection and response to mitigate detected attacks. \n \nChapter 2 mainly studies the behaviors of different IoT attacks in a smart home scenario, and analyzes the quality of the features that can be extracted and employed in ML algorithms to detect each of these attacks efficiently. We propose various features that can improve the performance of ML-based IDSs. Specifically, transmission control protocol/internet protocol (TCP/IP) packet headers, time-based statistics, connection-based statistics, and TCP/IP packet content features are proposed. Furthermore, to detect attacks that exploit the wireless communication channel, more features are discussed, including the distance from the radio transmitter, radio-frequency fingerprint, received signal strength, signal-to-noise ratio, and the system’s energy profile. \n \nChapter 3 proposes a hybrid multistage deep neural networks (DNNs)-based intrusion detection and prevention system (IDPS) with improved accuracy for critical industrial control systems (ICSs) that cannot afford to compromise the security to improve latency. The learning models are trained sequentially with diverse algorithms, and each model in the sequence focuses on the limitations of the previous models. The resulting multistage DNN uses each stage’s decision in a combination function to produce a final decision with improved accuracy. \n \nIn contrast to Chapter 3 which considers a high-risk ICS scenario where enforced security is preferable even at the cost of latency, chapter 4 considers a mission-critical ICS scenario where latency is also a crucial requirement. In this context, first and foremost, we conduct a time complexity analysis of DNNs to illustrate how the structures of these models impact the training and prediction latency. Then, we design a low latency and robust deep learning-based collaborative IDPS that employs two levels of classifications. The first level performs a lightweight DNN-based anomaly detection in local servers to allow faster attack detection and emergency response measures. The second level performs attack classification of the anomalous traffic in cloud servers to guide complementary intrusion prevention tasks. Moreover, an SDN-based deployment architecture of the proposed collaborative IDPS in ICS networks is provided.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.001
metaresearch head score (Gemma)0.002
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Simulation or modeling · Consensus signal: none
GenreCandidate signal: Empirical · Consensus signal: none
Teacher disagreement score0.002
Threshold uncertainty score0.008

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0010.002
Meta-epidemiology (narrow)0.0000.000
Meta-epidemiology (broad)0.0000.000
Bibliometrics0.0010.001
Science and technology studies0.0000.001
Scholarly communication0.0020.002
Open science0.0010.001
Research integrity0.0010.002
Insufficient payload (model declined to judge)0.0020.001

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.019
GPT teacher head0.301
Teacher spread0.282 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designSimulation or modeling
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations0
Published2024
Admission routes1
Has abstractyes

Explore more

Same venueEspace École de technologie supérieure (École de technologie supérieure)Same topicMagnetic confinement fusion researchFrench-language works237,207