Loading...
Local Light-weight Detection and Mitigation of DDoS Attack for Internet of Things at Network Edge
Rezaei, Zohreh | 2024
58
Viewed
- Type of Document: M.Sc. Thesis
- Language: Farsi
- Document No: 57121 (19)
- University: Sharif University of Technology
- Department: Computer Engineering
- Advisor(s): Jalili, Rasoul
- Abstract:
- In recent years, Internet of Things (IoT) devices have been rapidly increasing. The large number of these devices, along with their lower memory and processing power compared to other internet-connected devices, can expose IoT networks to various security threats. These threats undermine the data and communication infrastructure of these networks. Detecting attacks can be an effective factor in protecting IoT devices and networks. Among these attacks, Distributed Denial of Service (DDoS) attacks, which exploit vulnerabilities in the IoT infrastructure, can prevent users' access to network services through resource exhaustion, end-node saturation, and bandwidth saturation. This issue can be particularly critical in services related to healthcare, leading to disasters. Therefore, early detection of attacks plays a vital role in preventing damages. So far, various detection methods have been proposed for DDoS attacks in IoT networks, some of which only focus on detecting DDoS attacks, while others not only detect but also classify and mitigate these attacks using methods such as anomaly detection, software-defined networking approaches, and machine learning models. In general, the proposed solutions have certain assumptions or require specific resources in addition to the IoT network infrastructure, which limits their performance. In this thesis, a solution is presented for detecting Distributed Denial of Service (DDoS) attacks in IoT networks using software-defined networks. By detecting and mitigating attacks locally at the network edge, the solution avoids imposing communication overhead on the network and remains lightweight. It also enables the storage of resources in IoT devices and preserves accessibility. The proposed solution employs real-time monitoring of network traffic statistics and resources of the target device to detect anomalies. Additionally, besides detecting distributed DDoS attacks in IoT devices, it aims to reduce attacks by bandwidth reduction and temporary blocking of potential attack sources, striving to provide better service quality to minimize the consumption of resources at the target device and preserve accessibility. To evaluate the proposed solution, metrics such as accuracy, detection precision, recall, F1-score, specificity, false positive rate, false negative rate, bandwidth, consumption of resources at the target device, and the magnitude of the experimental environment in terms of the number of devices in the IoT environment have been examined. On average, with traffic consisting of 30% normal traffic and 70% attack traffic, it achieves 78.8% accuracy, 100% precision, 70% recall, 82.4% F1-score, 100% specificity, 0% false positive rate, and 30% false negative rate
- Keywords:
- Distributed Denial of Service (DDOS)Attack ; Internet of Things ; Software Defined Networks (SDN) ; Accessibility ; Resources Consumption
-
محتواي کتاب
- view
- فصل۱ مقدمه
- فصل ۲ مفاهیم پایه
- فصل ۳ پژوهشهای پیشین
- فصل ۴ راهکار پیشنهادی
- فصل ۵ پیادهسازی و ارزیابی
- فصل ۶ نتیجهگیری و کارهای آتی
- مراجع
- واژهنامه
