أمان عدم الثقة في شبكات كشف التسلل: كشف التهديدات المدعوم بالذكاء الاصطناعي في بيئة السحابة
Zero-Trust Security in Intrusion Detection Networks: An AI-Powered Threat Detection in Cloud Environment

شارك:
المجلة: International Journal of Scientific Research and Modern Technology.
DOI: https://doi.org/10.38124/ijsrmt.v4i5.542
تاريخ النشر: 2025-06-11
المؤلف: Zhenyun Du وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل

نظرة عامة

تستكشف ورقة البحث دمج الذكاء الاصطناعي (AI) في تعزيز أمان السحابة من خلال نموذج أمان عدم الثقة (Zero-Trust)، مع التركيز بشكل خاص على أنظمة كشف التسلل (IDS) لشبكات إنترنت الأشياء (IoT) وإنترنت الأشياء الصناعي (IIoT). تقدم الدراسة نظام كشف التسلل القائم على التعلم الآلي باستخدام خوارزمية XGBoost، التي تظهر أداءً متفوقًا في اكتشاف تهديدات إلكترونية متنوعة، بما في ذلك هجمات DDoS، والتعداد، والبرامج الضارة. يحقق النموذج المقترح دقة مثيرة للإعجاب تبلغ 94.55%، متفوقًا بشكل كبير على النماذج التقليدية مثل الجيران الأقرب (K-Nearest Neighbors) (79.18%)، وأدا بوست (AdaBoost) (86.29%)، والشبكات العصبية المتكررة (Recurrent Neural Networks) (91%).

تؤكد النتائج على أهمية نهج عدم الثقة، حيث يتم التعامل مع جميع المستخدمين والأجهزة على أنها غير موثوقة بشكل افتراضي، مما يتطلب التحقق المستمر للوصول إلى موارد الشبكة. تؤكد البحث على فعالية نموذج XGBoost، الذي يستخدم تقنيات معالجة البيانات مثل مقياس Min-Max وSMOTE لتحقيق توازن الفئات، مما يؤدي إلى دقة عالية (95.46%)، واسترجاع (98.38%)، ودرجة F1 (94.22%). بشكل عام، تدعو هذه الدراسة إلى اعتماد أنظمة كشف التسلل القائمة على التعلم الآلي ضمن إطار عدم الثقة لتعزيز تدابير الأمن السيبراني ضد التهديدات المتطورة في الأنظمة الرقمية الحديثة.

مقدمة

تناقش مقدمة ورقة البحث المشهد المتطور للأمن السيبراني في سياق العمل عن بُعد، والتكنولوجيا المحمولة، والحوسبة السحابية، التي جعلت الشبكات الإلكترونية أكثر تعقيدًا بشكل كبير. أصبحت طرق الأمان التقليدية المعتمدة على المحيط غير كافية بشكل متزايد، خاصة في ضوء التهديدات الداخلية المتزايدة والهجمات الإلكترونية المتطورة مثل التصيد الاحتيالي، وبرامج الفدية، وهجمات سلسلة التوريد. من الجدير بالذكر أن المنظمات التي اعتمدت فقط على الدفاعات المحيطية، بما في ذلك نماذج عدم الثقة (Zero Trust)، شهدت زيادة بنسبة 40% في التسللات الناجحة في عام 2024، مما يبرز الحاجة الملحة لتدابير أمان أكثر قوة.

تدعو الورقة إلى اعتماد نموذج أمان عدم الثقة، الذي يعمل على مبدأ “لا تثق أبدًا، تحقق دائمًا”، مع التأكيد على إعادة تقييم الثقة المستمرة والوصول بناءً على مبدأ أقل امتياز. يتم تقديم دمج أنظمة كشف التسلل (IDS) ضمن أطر عدم الثقة كتحسين حاسم، مما يمكّن من التعرف السريع على الأنشطة المشبوهة وتعزيز مرونة أنظمة الشبكة ضد التهديدات المتطورة. علاوة على ذلك، يتم التأكيد على دور الذكاء الاصطناعي (AI) كعنصر محوري في أتمتة المراقبة في الوقت الحقيقي والتقييمات الأمنية الديناميكية، خاصة في أنظمة كشف التسلل البحرية (NIDS). من خلال الاستفادة من خوارزميات الذكاء الاصطناعي، يمكن لهذه الأنظمة تحسين دقة وسرعة اكتشاف الهجمات الإلكترونية، مما يعزز الدفاعات السيبرانية البحرية ويعالج التحديات المتعلقة بالشفافية والموثوقية في الأمن السيبراني.

الطرق

تشمل المنهجية لاكتشاف هجمات الشبكة في مجموعة بيانات Edge-IIoTset عدة خطوات رئيسية: معالجة البيانات، والتطبيع، وتوازن الفئات، وتدريب النموذج، وتقييم الأداء. في البداية، يتم تنظيف مجموعة البيانات لمعالجة القيم المفقودة والمكررة باستخدام مكتبة Pandas، تليها ترميز التسمية للميزات الفئوية. لضمان توحيد مقياس الميزات، يتم تطبيق تطبيع Min-Max، مما يعزز أداء النموذج. لمواجهة عدم توازن الفئات، يتم استخدام تقنية الزيادة الاصطناعية للأقليات (SMOTE)، مما يؤدي إلى مجموعة بيانات متوازنة للتدريب.

تستخدم مراحل التدريب والاختبار تقسيم البيانات بنسبة 80:20، مع الاستفادة من نموذج XGBoost، الذي يعتمد على تعلم تجميع أشجار القرار. تعمل هذه الطريقة على تحسين دقة التنبؤ من خلال الاستفادة من نقاط القوة لعدة أشجار قرار. يتم تقييم أداء النموذج باستخدام مقاييس متنوعة، بما في ذلك الدقة، والدقة، والاسترجاع، ودرجة F1، ومنحنى ROC، ومصفوفة الالتباس، لتقييم قدرته بشكل فعال في تحديد جميع أنواع الهجمات ضمن مجموعة البيانات.

النتائج

تشير نتائج نموذج XGBoost المقترح المطبق على مجموعة بيانات Edge-IIOT لأمان عدم الثقة إلى مستوى عالٍ من الأداء في اكتشاف التهديدات. حقق النموذج دقة تبلغ 94.55%، ودقة 95.46%، واسترجاع 98.38%، ودرجة F1 تبلغ 94.22%، كما هو موضح في الجدول II. تؤكد هذه المقاييس على فعالية النموذج في تحديد التهديدات بدقة ضمن بيئة Edge-IIOT. من الجدير بالذكر أنه بينما تعتبر الدقة العامة مثيرة للإعجاب عند 0.94، أظهر النموذج دقة أقل قليلاً تبلغ 0.82 لفئة هجمات حجب الخدمة الموزعة (DDoS)، والتي تعزى إلى التصنيفات الخاطئة التي تتعلق بهجمات التعداد والبرامج الضارة.

تم التحقق من مقاييس التقييم، بما في ذلك الدقة، والاسترجاع، ودرجة F1، من خلال طرق المتوسطات الماكرو والمرجحة، مما يعزز موثوقية النموذج. يوفر عمود الدعم في النتائج نظرة ثاقبة على توزيع العينة عبر فئات الهجمات المختلفة، مما يعزز فهم أداء النموذج. بالإضافة إلى ذلك، يتم توضيح قوة نموذج XGBoost في حماية بيئات Edge-IIOT من خلال منحنى خصائص التشغيل المستقبلية (ROC)، مما يؤكد قدرته على اكتشاف التهديدات بشكل فعال.

المناقشة

تناقش ورقة البحث تقديم مجموعة بيانات Edge-IIoTset ونظام كشف التسلل القائم على عدم الثقة (IDS) الذي يستخدم التعلم الآلي (ML) لتعزيز أمان شبكات إنترنت الأشياء (IoT) وإنترنت الأشياء الصناعي (IIoT) ضد الهجمات الإلكترونية. تشمل المساهمات الرئيسية تنفيذ إطار أمان عدم الثقة، وتقنيات معالجة البيانات مثل التعامل مع القيم المفقودة والتطبيع، واستخدام تقنية الزيادة الاصطناعية للأقليات (SMOTE) لمعالجة عدم توازن الفئات في مجموعة البيانات. تستخدم الدراسة XGBoost، وهي طريقة تعلم تجميعية، لتحقيق دقة تصنيف متفوقة، حيث تحقق دقة ملحوظة تبلغ 94.55%، ودقة 95.46%، واسترجاع 98.38%، ودرجة F1 تبلغ 94.22%. تشير هذه النتائج إلى أن النموذج المقترح يتفوق بشكل كبير على النماذج التقليدية مثل AdaBoost وKNN وRNN في اكتشاف أنواع مختلفة من التهديدات الإلكترونية.

تكمن أهمية هذا البحث في استجابته للثغرات الموجودة في شبكات IIoT، التي غالبًا ما تكون محمية بشكل غير كافٍ بواسطة تدابير الأمان التقليدية بسبب تعقيدها وتنوعها. من خلال الدعوة إلى بنية عدم الثقة التي تحقق باستمرار من هوية المستخدمين وتراقب السلوكيات الشاذة، تؤكد الدراسة على ضرورة وجود حلول متقدمة وقابلة للتكيف في الأمن السيبراني. تؤكد النتائج على أهمية دمج أنظمة كشف التسلل القائمة على التعلم الآلي مع مبادئ عدم الثقة لتعزيز الدفاعات ضد التهديدات السيبرانية المتطورة، خاصة في القطاعات الحيوية مثل التصنيع والرعاية الصحية والمدن الذكية. قد تستكشف الأعمال المستقبلية ضبط معلمات النموذج واستراتيجيات التعلم الفيدرالي لتعزيز قدرات الكشف للنموذج مع الحفاظ على سلامة البيانات.

Journal: International Journal of Scientific Research and Modern Technology.
DOI: https://doi.org/10.38124/ijsrmt.v4i5.542
Publication Date: 2025-06-11
Author(s): Zhenyun Du et al.
Primary Topic: Network Security and Intrusion Detection

Overview

The research paper explores the integration of artificial intelligence (AI) in enhancing cloud security through a Zero-Trust security model, particularly focusing on intrusion detection systems (IDS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks. The study introduces a machine learning-based IDS utilizing the XGBoost algorithm, which demonstrates superior performance in detecting various cyber threats, including DDoS attacks, enumeration, and malware. The proposed model achieves an impressive accuracy of 94.55%, significantly outperforming traditional models such as K-Nearest Neighbors (79.18%), AdaBoost (86.29%), and Recurrent Neural Networks (91%).

The findings underscore the importance of a Zero-Trust approach, where all users and devices are treated as untrustworthy by default, necessitating continuous verification for access to network resources. The research emphasizes the effectiveness of the XGBoost model, which employs data preprocessing techniques like Min-Max scaling and SMOTE for class balancing, resulting in high precision (95.46%), recall (98.38%), and F1-score (94.22%). Overall, this study advocates for the adoption of machine learning-based IDS within a Zero-Trust framework to bolster cybersecurity measures against evolving threats in modern digital systems.

Introduction

The introduction of the research paper discusses the evolving landscape of cybersecurity in the context of remote work, mobile technology, and cloud computing, which have significantly complicated cyber networks. Traditional perimeter-based security methods are increasingly inadequate, particularly in light of rising internal threats and sophisticated cyberattacks such as phishing, ransomware, and supply chain attacks. Notably, organizations that relied solely on perimeter defenses, including Zero Trust (ZT) models, experienced a 40% increase in successful intrusions in 2024, highlighting the urgent need for more robust security measures.

The paper advocates for the adoption of the Zero Trust security paradigm, which operates on the principle of “never trust, always verify,” emphasizing continuous trust reassessment and access based on the least privilege principle. The integration of Intrusion Detection Systems (IDS) within ZT frameworks is presented as a critical advancement, enabling rapid identification of suspicious activities and enhancing the resilience of network systems against evolving threats. Furthermore, the role of Artificial Intelligence (AI) is underscored as pivotal in automating real-time monitoring and dynamic security assessments, particularly in maritime Network Intrusion Detection Systems (NIDS). By leveraging AI algorithms, these systems can improve the accuracy and speed of cyberattack detection, thereby fortifying maritime cyber defenses and addressing challenges related to transparency and trustworthiness in cybersecurity.

Methods

The methodology for detecting network attacks in the Edge-IIoTset dataset involves several key steps: data preprocessing, normalization, class balancing, model training, and performance evaluation. Initially, the dataset is cleaned to address missing and duplicate values using the Pandas library, followed by label encoding for categorical features. To ensure uniform feature scaling, Min-Max normalization is applied, which enhances the model’s performance. To tackle class imbalance, the Synthetic Minority Over-sampling Technique (SMOTE) is utilized, resulting in a balanced dataset for training.

The training and testing phases employ an 80:20 data split, utilizing the XGBoost model, which is based on decision-tree ensemble learning. This approach improves prediction accuracy by leveraging the strengths of multiple decision trees. The model’s performance is assessed using various metrics, including accuracy, precision, recall, F1 score, ROC curve, and confusion matrix, to effectively evaluate its capability in identifying all types of attacks within the dataset.

Results

The results of the proposed XGBoost model applied to the Edge-IIOT dataset for Zero-Trust security indicate a high level of performance in threat detection. The model achieved an accuracy of 94.55%, precision of 95.46%, recall of 98.38%, and an F1-score of 94.22%, as detailed in Table II. These metrics underscore the model’s effectiveness in accurately identifying threats within the Edge-IIOT environment. Notably, while the overall accuracy is commendable at 0.94, the model exhibited a slightly lower accuracy of 0.82 for the Distributed Denial of Service (DDoS) class, attributed to misclassifications involving Enumeration and Malware attacks.

The evaluation metrics, including precision, recall, and F1-score, were further validated through macro and weighted averaging approaches, reinforcing the model’s reliability. The support column in the results provides insight into the sample distribution across different attack categories, enhancing the understanding of the model’s performance. Additionally, the robustness of the XGBoost model in safeguarding Edge-IIOT environments is illustrated through the Receiver Operating Characteristic (ROC) curve, confirming its capability for effective threat detection.

Discussion

The research paper discusses the introduction of the Edge-IIoTset dataset and a Zero-Trust-based Intrusion Detection System (IDS) that utilizes machine learning (ML) to enhance the security of Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks against cyberattacks. Key contributions include the implementation of a Zero-Trust security framework, data preprocessing techniques such as handling missing values and normalization, and the use of Synthetic Minority Over-sampling Technique (SMOTE) to address class imbalance in the dataset. The study employs XGBoost, an ensemble learning method, to achieve superior classification accuracy, achieving a notable accuracy of 94.55%, precision of 95.46%, recall of 98.38%, and an F1-score of 94.22%. These results indicate that the proposed model significantly outperforms traditional models like AdaBoost, KNN, and RNN in detecting various types of cyber threats.

The significance of this research lies in its response to the vulnerabilities inherent in IIoT networks, which are often inadequately protected by conventional security measures due to their complexity and heterogeneity. By advocating for a Zero-Trust architecture that continuously authenticates users and monitors for anomalous behavior, the study emphasizes the necessity for advanced, adaptable cybersecurity solutions. The findings underscore the importance of integrating ML-based IDS with Zero-Trust principles to bolster defenses against evolving cyber threats, particularly in critical sectors such as manufacturing, healthcare, and smart cities. Future work may explore hyperparameter tuning and federated learning strategies to further enhance the model’s detection capabilities while safeguarding data integrity.

شارك: