Machine Learning based Malware Traffic Detection on IoT Devices using Summarized Packet Data

Masataka Nakahara, Norihiro Okui, Yasuaki Kobayashi, Yutaka Miyake

2020

Abstract

As the number of IoT (Internet of Things) devices increases, the countermeasures against cyberattacks caused by IoT devices become more important. Although mechanisms to prevent malware infection to IoT devices are important, such prevention becomes hard due to sophisticated infection steps and lack of computational resource for security software in IoT devices. Therefore, detecting malware infection of devices is also important to suppress malware spread. As the types of IoT devices and malwares are increasing, advanced anomaly detection technology like machine learning is required to find malware infected devices. Because IoT devices cannot analyze own behavior by using machine learning due to limited computing resources, such analysis should be executed at gateway devices to the Internet. This paper proposes an architecture for detecting malware traffic using summarized statistical data of packets instead of whole packet information. As this proposal only uses information of amount of traffic and destination addresses for each IoT device, it can reduce the storage space taken up by data and can analyze number of IoT devices with low computational resources. We performed the malware traffic detection on proposed architecture by using machine learning algorithms of Isolation Forest and K-means clustering, and show that high accuracy can be achieved with the summarized statistical data. In the evaluation, we collected the statistical data from 26 IoT devices (9 categories), and obtained the result that the data size required for analysis is reduced over 90% with keeping high accuracy.

Download


Paper Citation


in Harvard Style

Nakahara M., Okui N., Kobayashi Y. and Miyake Y. (2020). Machine Learning based Malware Traffic Detection on IoT Devices using Summarized Packet Data.In Proceedings of the 5th International Conference on Internet of Things, Big Data and Security - Volume 1: IoTBDS, ISBN 978-989-758-426-8, pages 78-87. DOI: 10.5220/0009345300780087


in Bibtex Style

@conference{iotbds20,
author={Masataka Nakahara and Norihiro Okui and Yasuaki Kobayashi and Yutaka Miyake},
title={Machine Learning based Malware Traffic Detection on IoT Devices using Summarized Packet Data},
booktitle={Proceedings of the 5th International Conference on Internet of Things, Big Data and Security - Volume 1: IoTBDS,},
year={2020},
pages={78-87},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0009345300780087},
isbn={978-989-758-426-8},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 5th International Conference on Internet of Things, Big Data and Security - Volume 1: IoTBDS,
TI - Machine Learning based Malware Traffic Detection on IoT Devices using Summarized Packet Data
SN - 978-989-758-426-8
AU - Nakahara M.
AU - Okui N.
AU - Kobayashi Y.
AU - Miyake Y.
PY - 2020
SP - 78
EP - 87
DO - 10.5220/0009345300780087