Visible to the public An Architecture for Resilient Intrusion Detection in IoT Networks

TitleAn Architecture for Resilient Intrusion Detection in IoT Networks
Publication TypeConference Paper
Year of Publication2020
AuthorsQurashi, Mohammed Al, Angelopoulos, Constantinos Marios, Katos, Vasilios
Conference NameICC 2020 - 2020 IEEE International Conference on Communications (ICC)
Date PublishedJune 2020
PublisherIEEE
ISBN Number978-1-7281-5089-5
KeywordsComputer architecture, Intrusion detection, Monitoring, Peer-to-peer computing, Protocols, pubcrawl, resilience, Resiliency, Resilient Security Architectures, Wireless communication, Wireless sensor networks
AbstractWe introduce a lightweight architecture of Intrusion Detection Systems (IDS) for ad-hoc IoT networks. Current state-of-the-art IDS have been designed based on assumptions holding from conventional computer networks, and therefore, do not properly address the nature of IoT networks. In this work, we first identify the correlation between the communication overheads and the placement of an IDS (as captured by proper placement of active IDS agents in the network). We model such networks as Random Geometric Graphs. We then introduce a novel IDS architectural approach by having only a minimum subset of the nodes acting as IDS agents. These nodes are able to monitor the network and detect attacks at the networking layer in a collaborative manner by monitoring 1-hop network information provided by routing protocols such as RPL. Conducted experiments show that our proposed IDS architecture is resilient and robust against frequent topology changes due to node failures. Our detailed experimental evaluation demonstrates significant performance gains in terms of communication overhead and energy dissipation while maintaining high detection rates.
URLhttps://ieeexplore.ieee.org/document/9148868
DOI10.1109/ICC40277.2020.9148868
Citation Keyqurashi_architecture_2020