DOI: https://doi.org/10.1016/j.dsm.2025.02.005
تاريخ النشر: 2025-02-28
المؤلف: Mourad Benmalek وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل
نظرة عامة
تتناول الورقة الحاجة الملحة لأنظمة كشف التسلل الفعالة (IDS) في مواجهة التهديدات السيبرانية المتزايدة التي تستهدف أجهزة إنترنت الأشياء (IoT). تقدم نظام كشف التسلل القائم على الشذوذ المبتكر الذي يستخدم تقنيات التعلم الآلي (ML) والتعلم العميق (DL)، مستفيدًا من مجموعة بيانات RT_IoT2022، التي تشمل سيناريوهات هجوم معقدة على إنترنت الأشياء. تتضمن الدراسة تحسين سرب الجسيمات (PSO) لاختيار الميزات، مما يقلل من العبء الحاسوبي ويعزز أداء النموذج. تم تقييم مجموعة متنوعة من النماذج، بما في ذلك آلة الدعم الناقل (SVM)، الجيران الأقرب (KNN)، التعزيز الفئوي (CatBoost)، باي البسيط (NB)، الشبكة العصبية التلافيفية (CNN)، وذاكرة طويلة وقصيرة الأجل (LSTM)، حيث أظهر CatBoost المدمج مع PSO أداءً متفوقًا عبر جميع المقاييس مقارنة بالطرق الحالية.
في الختام، تؤسس البحث نظام كشف التسلل القائم على الشذوذ القوي المصمم لبيئات إنترنت الأشياء، مع تسليط الضوء على فعالية PSO في اختيار الميزات والمزايا المميزة لمختلف نماذج ML وDL. برز CatBoost كنموذج الأكثر فعالية لكشف الشذوذ، متفوقًا بشكل كبير على نموذج QAE-f16 عبر جميع مقاييس الأداء. تؤكد النتائج على أهمية أوقات الاستجابة السريعة في بيئات إنترنت الأشياء، التي تم تحقيقها من خلال كفاءة اختيار الميزات المعزز بـ PSO. تشمل اتجاهات البحث المستقبلية استكشاف النماذج الهجينة، وتحسين تقنيات معالجة البيانات، ومعالجة التحديات في كشف الشذوذ في الوقت الحقيقي لتعزيز أداء النموذج بشكل أكبر.
مقدمة
تسلط مقدمة هذه الورقة البحثية الضوء على أهمية إنترنت الأشياء (IoT) كعنصر محوري في إنترنت المستقبل، مع تطبيقات تمتد عبر قطاعات متنوعة مثل المدن الذكية والرعاية الصحية وإدارة سلسلة التوريد. إن انتشار أجهزة إنترنت الأشياء، المتوقع أن يزيد بنسبة 21% بحلول عام 2030، يثير المخاوف بشأن ثغرات الأمن السيبراني، حيث تتبادل هذه الأجهزة البيانات بشكل متكرر عبر الإنترنت، مما يجعلها عرضة لمجموعة متنوعة من الهجمات السيبرانية، بما في ذلك هجمات الحرمان الموزع من الخدمة (DDoS) وبرامج الفدية. إن قيود تدابير الأمن السيبراني التقليدية في معالجة هذه الثغرات تستدعي تطوير أساليب متخصصة، لا سيما أنظمة كشف التسلل المتقدمة (IDS) التي يمكن أن تتكيف مع التهديدات المتطورة.
تهدف الدراسة إلى تعزيز كشف التسلل في شبكات إنترنت الأشياء من خلال الاستفادة من تقنيات التعلم الآلي (ML) والتعلم العميق (DL). تتناول الفجوات الموجودة في الأدبيات، مثل الاعتماد على مجموعات بيانات قديمة ومقاييس أداء غير كافية. من خلال استخدام مجموعة بيانات RT_IoT2022، التي تعكس أنماط حركة مرور إنترنت الأشياء الحديثة، تقدم البحث طريقة مبتكرة لاختيار الميزات باستخدام تحسين سرب الجسيمات (PSO) لتحسين دقة النموذج وتقليل وقت التدريب. يدمج إطار عمل IDS المقترح نماذج متعددة من ML وDL، مما يظهر أداءً متفوقًا في كشف وتصنيف الشذوذ مقارنة بالدراسات السابقة. تم هيكلة الورقة لمراجعة الأعمال السابقة، وتحديد الإطار المقترح، وعرض النتائج التجريبية، ومناقشة الآثار الإدارية، مما يسهم في تقديم رؤى قيمة في مجال الأمن السيبراني لإنترنت الأشياء.
طرق
استخدم الإعداد التجريبي لهذه الدراسة محطة عمل تحتوي على معالج Intel Core i7-8650U، و16 جيجابايت من الذاكرة العشوائية، ورسومات Intel UHD، تعمل على نظام Microsoft Windows 11 Pro. تم تدريب النماذج واختبارها ضمن بيئة Jupyter Notebook باستخدام Python 3.8.10، مستفيدًا من مكتبات مثل TensorFlow (الإصدار 2.17.0)، Scikit-Learn (1.5.1)، Pandas (2.2.2)، وNumPy (1.26.4).
تشير النتائج التجريبية إلى أن إطار كشف التسلل المقترح يقيم بفعالية نماذج متعددة من التعلم الآلي (ML) والتعلم العميق (DL) على مجموعة بيانات RT_IoT2022. شمل تقييم الأداء كل من مهام التصنيف الثنائي والمتعدد الفئات، مما يبرز قدرة الإطار على كشف وتصنيف التسللات بدقة ضمن شبكات إنترنت الأشياء.
نتائج
تُعرض نتائج التجارب التي أجريت على مجموعة بيانات RT_IoT2022، مع التركيز على نهجين تصنيفيين متميزين. النهج الأول، التصنيف الثنائي، يصنف البيانات بنجاح إلى فئتين: “هجوم” و”طبيعي”. هذه الطريقة تميز بفعالية بين الأنشطة الحميدة والضارة ضمن مجموعة البيانات.
النهج الثاني، التصنيف متعدد الفئات، يهدف إلى تحديد أنواع معينة من الهجمات، مما يوفر تحليلًا أكثر تفصيلاً للبيانات. يعزز هذا التصنيف المفصل من فهم مختلف متجهات الهجوم، مما يسمح بتحسين استراتيجيات الكشف والاستجابة. تؤكد النتائج على فعالية كلا الطريقتين التصنيفيتين في تحليل تهديدات أمن إنترنت الأشياء.
مناقشة
تسلط قسم المناقشة في الورقة الضوء على الاهتمام المتزايد في أنظمة كشف التسلل لإنترنت الأشياء (IDS) وتستعرض نماذج التعلم الآلي (ML) والتعلم العميق (DL) المختلفة المستخدمة في الدراسات الحديثة. تتضمن جدول ملخص يوضح النتائج الرئيسية، بما في ذلك النماذج المستخدمة، مجموعات البيانات، مقاييس الأداء، والقيود. على سبيل المثال، استخدم جان وآخرون (2019) آلة الدعم الناقل (SVM) التي حققت دقة تزيد عن 98% لكنها واجهت صعوبة مع الهجمات ذات الكثافة المنخفضة. نفذ ياو وآخرون (2019) LightGBM، الذي أظهر كفاءة جيدة في الموارد ولكنه كان لديه دقة واسترجاع أقل، مما يشير إلى خطر فقدان التهديدات الحرجة. قارن فيتورينو وآخرون (2022) بين نماذج متعددة، ووجدوا أن الطرق الخاضعة للإشراف، وخاصة LightGBM، تتفوق في السيناريوهات متعددة الفئات، بينما اكتشفت النماذج غير الخاضعة للإشراف البرمجيات الضارة النادرة بفعالية. ومع ذلك، واجهت العديد من الدراسات قيودًا بسبب مجموعات بيانات قديمة أو بيانات تدريب غير كافية، مما أثر على قابليتها للتطبيق في بيئات إنترنت الأشياء الحديثة.
يهدف الإطار المقترح إلى معالجة هذه الفجوات من خلال الاستفادة من مجموعة بيانات RT_IoT2022، التي تلتقط مجموعة شاملة من السلوكيات الطبيعية والمعادية عبر أجهزة إنترنت الأشياء المختلفة. يتضمن الإطار عملية تفصيلية لجمع البيانات، وخطوات معالجة مسبقة لضمان سلامة البيانات، ومنهجية اختيار الميزات التي تجمع بين تحسين سرب الجسيمات (PSO) مع نموذج الغابة العشوائية (RF) لتعزيز دقة التنبؤ. تؤكد الدراسة على أهمية اختيار الميزات ذات الصلة لتحسين أداء النموذج مع تقليل الإفراط في التكيف. تم تصميم نماذج ML وDL التي تم مناقشتها، بما في ذلك SVM، باي البسيط، الجيران الأقرب، والشبكات العصبية التلافيفية، لتحليل مجموعة البيانات بفعالية، مع إمكانية تحقيق دقة عالية في كشف التسللات في بيئات إنترنت الأشياء.
DOI: https://doi.org/10.1016/j.dsm.2025.02.005
Publication Date: 2025-02-28
Author(s): Mourad Benmalek et al.
Primary Topic: Network Security and Intrusion Detection
Overview
The paper addresses the urgent need for effective intrusion detection systems (IDS) in the face of rising cyber threats targeting Internet of Things (IoT) devices. It introduces an innovative anomaly-based IDS that employs machine learning (ML) and deep learning (DL) techniques, utilizing the RT_IoT2022 dataset, which encompasses complex IoT attack scenarios. The study incorporates particle swarm optimization (PSO) for feature selection, which not only reduces computational overhead but also enhances model performance. A variety of models, including support vector machine (SVM), K-nearest neighbors (KNN), categorical boosting (CatBoost), naïve Bayes (NB), convolutional neural network (CNN), and long short-term memory (LSTM), were evaluated, with CatBoost combined with PSO demonstrating superior performance across all metrics compared to existing methods.
In conclusion, the research establishes a robust anomaly-based IDS tailored for IoT environments, highlighting the effectiveness of PSO in feature selection and the distinct advantages of various ML and DL models. CatBoost emerged as the most effective model for anomaly detection, significantly outperforming the QAE-f16 model across all performance metrics. The findings emphasize the importance of rapid response times in IoT settings, achieved through the efficiency of PSO-enhanced feature selection. Future research directions include exploring hybrid models, improving data handling techniques, and addressing challenges in real-time anomaly detection to further bolster model performance.
Introduction
The introduction of this research paper highlights the significance of the Internet of Things (IoT) as a pivotal element of the future Internet, with applications spanning various sectors such as smart cities, healthcare, and supply-chain management. The proliferation of IoT devices, projected to increase by 21% by 2030, raises concerns regarding cybersecurity vulnerabilities, as these devices frequently exchange data over the Internet, making them susceptible to various cyberattacks, including Distributed Denial of Service (DDoS) and ransomware. The limitations of traditional cybersecurity measures in addressing these vulnerabilities necessitate the development of specialized approaches, particularly advanced Intrusion Detection Systems (IDS) that can adapt to evolving threats.
The study aims to enhance intrusion detection in IoT networks by leveraging machine learning (ML) and deep learning (DL) techniques. It addresses existing gaps in the literature, such as reliance on outdated datasets and insufficient performance metrics. By utilizing the RT_IoT2022 dataset, which reflects modern IoT traffic patterns, the research introduces an innovative feature selection method using particle swarm optimization (PSO) to improve model accuracy and reduce training time. The proposed IDS framework integrates multiple ML and DL models, demonstrating superior performance in detecting and classifying anomalies compared to previous studies. The paper is structured to review prior works, outline the proposed framework, present experimental results, and discuss managerial implications, ultimately contributing valuable insights to the field of IoT cybersecurity.
Methods
The experimental setup for this study utilized a workstation featuring an Intel Core i7-8650U CPU, 16 GB of RAM, and Intel UHD Graphics, operating on Microsoft Windows 11 Pro. The models were trained and tested within a Jupyter Notebook environment using Python 3.8.10, leveraging libraries such as TensorFlow (version 2.17.0), Scikit-Learn (1.5.1), Pandas (2.2.2), and NumPy (1.26.4).
The experimental results indicate that the proposed intrusion detection framework effectively evaluates multiple machine learning (ML) and deep learning (DL) models on the RT_IoT2022 dataset. The performance assessment covered both binary and multiclass classification tasks, highlighting the framework’s capability in accurately detecting and classifying intrusions within IoT networks.
Results
The results of the experiments conducted on the RT_IoT2022 dataset are presented, focusing on two distinct classification approaches. The first approach, binary classification, successfully categorizes the data into two classes: “attack” and “normal.” This method effectively distinguishes between benign and malicious activities within the dataset.
The second approach, multiclass classification, aims to identify specific types of attacks, providing a more granular analysis of the data. This detailed classification enhances the understanding of various attack vectors, allowing for improved detection and response strategies. The findings underscore the efficacy of both classification methods in analyzing IoT security threats.
Discussion
The discussion section of the paper highlights the growing interest in IoT intrusion detection systems (IDS) and reviews various machine learning (ML) and deep learning (DL) models employed in recent studies. A summary table outlines key findings, including the models used, datasets, performance metrics, and limitations. For instance, Jan et al. (2019) utilized a support vector machine (SVM) achieving over 98% accuracy but struggled with low-intensity attacks. Yao et al. (2019) implemented LightGBM, which demonstrated good resource efficiency but had lower accuracy and recall, indicating a risk of missing critical threats. Vitorino et al. (2022) compared multiple models, finding supervised methods, particularly LightGBM, to excel in multiclass scenarios, while unsupervised models effectively detected rare malware. However, many studies faced limitations due to outdated datasets or insufficient training data, impacting their applicability to modern IoT environments.
The proposed framework aims to address these gaps by leveraging the RT_IoT2022 dataset, which captures a comprehensive range of normal and adversarial behaviors across various IoT devices. The framework includes a detailed data acquisition process, preprocessing steps to ensure data integrity, and a feature selection methodology that combines particle swarm optimization (PSO) with a random forest (RF) model to enhance prediction accuracy. The study emphasizes the importance of selecting relevant features to improve model performance while minimizing overfitting. The ML and DL models discussed, including SVM, Naive Bayes, K-Nearest Neighbors, and Convolutional Neural Networks, are tailored to effectively analyze the dataset, with the potential for high accuracy in detecting intrusions in IoT environments.
