تقييم أنظمة كشف التسلل المدفوعة بالتعلم الآلي في إنترنت الأشياء: الأداء واستهلاك الطاقة
Evaluating machine learning-driven intrusion detection systems in IoT: Performance and energy consumption

شارك:
المجلة: Computers & Industrial Engineering، المجلد: 204
DOI: https://doi.org/10.1016/j.cie.2025.111103
تاريخ النشر: 2025-04-15
المؤلف: Saeid Jamshidi وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل

نظرة عامة

تستكشف ورقة البحث آثار الأداء لأنظمة كشف التسلل المعتمدة على التعلم الآلي (ML) في بيئات إنترنت الأشياء (IoT) ذات الموارد المحدودة، مع التركيز بشكل خاص على نشرها في حافة بنى تحتية إنترنت الأشياء. تسلط الدراسة الضوء على الدور الحاسم لأنظمة كشف التسلل المعتمدة على ML في تعزيز الأمان، خاصة في سياق التهديدات السيبرانية في الوقت الحقيقي. تقيم الدراسة مقاييس الأداء الرئيسية مثل تحميل وحدة المعالجة المركزية، واستهلاك الطاقة، واستخدام وحدة المعالجة المركزية، مقارنةً بين نماذج ML التقليدية (مثل K-Nearest Neighbors وDecision Trees) مع نماذج التعلم العميق (مثل الشبكات العصبية التلافيفية وشبكات الذاكرة طويلة وقصيرة الأجل) في كل من السيناريوهات القياسية والمدمجة مع الشبكات المعرفة بالبرمجيات (SDN). تكشف النتائج أن نماذج ML التقليدية تظهر زيادات كبيرة في استهلاك الموارد خلال سيناريوهات الهجمات السيبرانية، مما يشير إلى قيودها في الإعدادات ذات الموارد المحدودة، بينما تظهر نماذج DL كفاءة محسنة.

تخلص الورقة إلى أن اختيار أنظمة كشف التسلل المعتمدة على ML يجب أن يسترشد باعتبارات الكفاءة الحاسوبية واستهلاك الطاقة لتحسين الأداء في الشبكات المقيدة. وتؤكد على الحاجة إلى مزيد من البحث لتقييم قابلية التوسع والموثوقية لهذه الأنظمة في بيئات الشبكات الأكثر تعقيدًا، خاصة مع ظهور تقنيات جديدة مثل 5G والحوسبة على الحافة. يجب أن تركز التحقيقات المستقبلية على تعزيز قابلية التوسع، وقدرات المعالجة في الوقت الحقيقي، وكفاءة الطاقة لأنظمة كشف التسلل المعتمدة على ML، مع معالجة التحديات المتعلقة بدمج هذه الأنظمة في بنى تحتية موجودة لإنترنت الأشياء وSDN.

مقدمة

تسلط مقدمة هذه الورقة البحثية الضوء على التأثير التحويلي لإنترنت الأشياء (IoT) على اتصالات الأجهزة، مع التأكيد على دمج الشبكات المعرفة بالبرمجيات (SDN) كتحسين محوري. يهدف هذا الدمج إلى معالجة التحديات التي تطرحها الموارد المحدودة لأجهزة إنترنت الأشياء، مثل الذاكرة وعمر البطارية، مع تعزيز إدارة الشبكة والأمان. تؤكد الورقة على الأهمية المتزايدة لأنظمة كشف التسلل المعتمدة على التعلم الآلي (ML) في حماية شبكات إنترنت الأشياء من التهديدات السيبرانية، مشيرةً إلى الفجوات الموجودة في فهم أدائها في البيئات الديناميكية وفي الوقت الحقيقي، خاصة عند دمجها مع SDN.

تحدد الدراسة هدفين رئيسيين: تقييم مقاييس الأداء لسبعة أنظمة كشف التسلل المعتمدة على ML المتطورة التي تم نشرها في بوابات الحافة تحت تهديدات سيبرانية في الوقت الحقيقي، وتقييم تأثير دمج SDN مع هذه الأنظمة في نفس السياق. يهدف المؤلفون إلى توضيح كيف يمكن لـ SDN تحسين إدارة الموارد وزيادة مرونة شبكات إنترنت الأشياء. تشمل المساهمات الرئيسية تحليلًا مقارنًا لمقاييس أداء أنظمة كشف التسلل المعتمدة على ML، واقتراح مجموعة اختبار قائمة على المكونات الإضافية لأنظمة كشف التسلل المعتمدة على ML للباحثين، وهيكل منظم لتنظيم الورقة، والذي يتضمن مراجعة الأدبيات، وتصميم التجارب، والنتائج، والأعمال المستقبلية.

طرق البحث

في هذه الدراسة، صمم المؤلفون بيئة اختبار باستخدام وحدتين من Raspberry Pi 4 Model B لتقييم التأثير الحاسوبي لأنظمة كشف التسلل المعتمدة على التعلم الآلي (ML-based IDS) في بوابة الحافة. كل وحدة، مزودة بذاكرة وصول عشوائي سعة 8 جيجابايت ومعالج رباعي النواة بتردد 1.5 جيجاهرتز، سهلت تقييم سبعة نماذج من أنظمة كشف التسلل المعتمدة على ML: شجرة القرار (DT)، K-Nearest Neighbors (KNN)، الغابة العشوائية (RF)، الذاكرة طويلة وقصيرة الأجل (LSTM)، الشبكة العصبية التلافيفية (CNN)، نموذج كشف التسلل الجماعي (EIDM)، ونموذج هجين من LSTM-CNN. قامت التجارب بمحاكاة تهديدات سيبرانية متنوعة، بما في ذلك حركة المرور الحميدة، وهجمات حجب الخدمة الموزعة (DDoS)، وحجب الخدمة (DoS)، وهجمات القوة الغاشمة، وفحص المنافذ، باستخدام Kali Linux. تم تحليل مقاييس الأداء الرئيسية مثل استخدام وحدة المعالجة المركزية، وتحميل وحدة المعالجة المركزية، واستهلاك الطاقة لمعالجة السؤال البحثي الأول (RQ1).

لاستكشاف السؤال البحثي الثاني (RQ2)، تم تحسين بيئة الاختبار من خلال دمج بوابة الحافة مع وحدة التحكم Ryu، مما خلق بيئة شبكة معرفة بالبرمجيات (SDN). استخدم هذا الإعداد Mininet لمحاكاة بنية تحتية واقعية لـ SDN تتكون من ثمانية عشر مضيفًا وستة محولات، مما يتيح إدارة مركزية لحركة المرور وتحسين تخصيص الموارد. خضعت نتائج التجارب لتحليل إحصائي متعمق باستخدام ANOVA، والذي يهدف إلى توضيح آثار النتائج وتقييم فعالية كل نموذج من نماذج IDS تحت سيناريوهات التهديد السيبراني في الوقت الحقيقي. تمت مناقشة النتائج التجريبية لكل من RQ1 وRQ2 بالتفصيل، مع تسليط الضوء على أداء أجهزة إنترنت الأشياء في الحافة مع دمج SDN في مواجهة التهديدات السيبرانية.

النتائج

تشير نتائج تحليلات ANOVA إلى وجود اختلافات كبيرة في تحميل وحدة المعالجة المركزية واستهلاك الطاقة بين أنظمة كشف التسلل المعتمدة على التعلم الآلي (IDS) المختلفة تحت تهديدات سيبرانية مختلفة، وخاصة هجمات DDoS. أسفرت التحليلات عن إحصائية F قدرها 60.40 (p < 0.05) لتحميل وحدة المعالجة المركزية، مما يدل على أن اختيار IDS يؤثر بشكل كبير على أداء وحدة المعالجة المركزية. لوحظت نتائج مماثلة عبر أنواع الهجمات الأخرى، بما في ذلك القوة الغاشمة وDoS، مما يعزز الاستنتاج بوجود اختلافات ملحوظة في تحميل وحدة المعالجة المركزية بين IDS. ومن الجدير بالذكر أن أنظمة كشف التسلل المعتمدة على التعلم العميق، مثل CNN وLSTM، أظهرت كفاءة متفوقة في إدارة المتطلبات الحاسوبية مقارنةً بالطرق التقليدية مثل KNN وDT وRF، التي تتطلب موارد حاسوبية أكبر أثناء الاستدلال. فيما يتعلق باستهلاك الطاقة، كشفت نتائج ANOVA عن إحصائية F قدرها 57.44 (p < 0.05) تحت ظروف DDoS، مما يشير إلى اختلافات كبيرة في استخدام الطاقة بين IDS. تم تحديد نماذج LSTM وDT كأكثر النماذج كفاءة في استهلاك الطاقة، بينما أظهرت KNN أعلى استهلاك للطاقة، مما يجعلها أقل ملاءمة للبيئات ذات القيود الطاقية. تشير هذه النتائج إلى أن المزايا المعمارية لنماذج التعلم العميق تساهم في كفاءتها في كل من تحميل وحدة المعالجة المركزية واستهلاك الطاقة، مما يجعلها مناسبة بشكل خاص للتطبيقات في الوقت الحقيقي في مجال الأمن السيبراني.

المناقشة

تسلط قسم المناقشة في ورقة البحث الضوء على التحديات المستمرة في فهم مقايضات الأداء لأنظمة كشف التسلل المعتمدة على التعلم الآلي (ML) في بيئات إنترنت الأشياء (IoT)، خاصة داخل بوابات الحافة ذات الموارد المحدودة. بينما ركزت الدراسات السابقة بشكل أساسي على دقة الكشف، هناك نقص ملحوظ في الأبحاث التي تعالج التأثيرات الحاسوبية في الوقت الحقيقي لهذه الأنظمة، خاصة عند دمجها مع الشبكات المعرفة بالبرمجيات (SDN). يستعرض القسم مختلف أساليب IDS المعتمدة على ML، مع التركيز على نقاط قوتها وقيودها، خاصة فيما يتعلق باستهلاك الطاقة والكفاءة الحاسوبية.

تم الاستشهاد بعدة دراسات، تعرض نماذج ML المختلفة مثل أشجار القرار (DT)، والغابات العشوائية (RF)، وشبكات الذاكرة طويلة وقصيرة الأجل (LSTM)، التي أظهرت دقة عالية في كشف أنواع مختلفة من الشذوذ في الشبكة. على سبيل المثال، أظهر نموذج كشف التسلل المعزز القائم على التعلم العميق (EIDM) ونماذج أخرى مثل الشبكة العصبية العميقة ذات التغذية الأمامية (FFDNN) وعدًا في تصنيف حركة المرور الشبكية بدقة وتعزيز تدابير الأمان. ومع ذلك، يشير القسم أيضًا إلى فجوة كبيرة في الدراسات التجريبية التي تقيم الأداء في الوقت الحقيقي لهذه النماذج من حيث تحميل وحدة المعالجة المركزية، واستخدام وحدة المعالجة المركزية، واستهلاك الطاقة أثناء التهديدات السيبرانية. يهدف المؤلفون إلى معالجة هذه الفجوة من خلال تحليلهم الشامل لأنظمة كشف التسلل المعتمدة على ML، مع التركيز على آثارها التشغيلية في كل من بوابات الحافة المفعلة بـ SDN وغير المفعلة بـ SDN، مما يوفر رؤى حاسمة حول جدواها للنشر في شبكات إنترنت الأشياء.

Journal: Computers & Industrial Engineering, Volume: 204
DOI: https://doi.org/10.1016/j.cie.2025.111103
Publication Date: 2025-04-15
Author(s): Saeid Jamshidi et al.
Primary Topic: Network Security and Intrusion Detection

Overview

The research paper investigates the performance implications of Machine Learning (ML)-based Intrusion Detection Systems (IDS) in resource-constrained Internet of Things (IoT) environments, particularly focusing on their deployment at the edge of IoT infrastructures. The study highlights the critical role of ML-based IDS in enhancing security, especially in the context of real-time cyber threats. It evaluates key performance metrics such as CPU load, energy consumption, and CPU usage, comparing traditional ML models (e.g., K-Nearest Neighbors and Decision Trees) with deep learning (DL) models (e.g., Convolutional Neural Networks and Long Short-Term Memory networks) in both standard and Software-Defined Networking (SDN) integrated scenarios. The findings reveal that traditional ML models exhibit significant increases in resource consumption during cyberattack scenarios, indicating their limitations in resource-limited settings, while DL models demonstrate improved efficiency.

The paper concludes that the choice of ML-based IDS should be guided by considerations of computational efficiency and energy consumption to optimize performance in constrained networks. It emphasizes the need for further research to assess the scalability and robustness of these systems in more complex network environments, particularly as new technologies like 5G and edge computing emerge. Future investigations should focus on enhancing the scalability, real-time processing capabilities, and energy efficiency of ML-based IDS, while also addressing the challenges of integrating these systems into existing IoT and SDN infrastructures.

Introduction

The introduction of this research paper highlights the transformative impact of the Internet of Things (IoT) on device communication, emphasizing the integration of Software-Defined Networking (SDN) as a pivotal advancement. This integration aims to address the challenges posed by the limited resources of IoT devices, such as memory and battery life, while enhancing network management and security. The paper underscores the growing importance of Machine Learning (ML)-based Intrusion Detection Systems (IDS) in safeguarding IoT networks against cyber threats, noting existing gaps in understanding their performance in dynamic, real-time environments, particularly when integrated with SDN.

The study sets forth two primary objectives: to evaluate the performance metrics of seven state-of-the-art ML-based IDS deployed at edge gateways under real-time cyber threats, and to assess the impact of integrating SDN with these IDS in the same context. The authors aim to elucidate how SDN can optimize resource management and improve the resilience of IoT networks. Key contributions include a comparative analysis of ML-based IDS performance metrics, a proposal for a plugin-based ML-based IDS test suite for researchers, and a structured outline of the paper’s organization, which includes literature review, experimental design, results, and future work.

Methods

In this study, the authors designed a testbed using two Raspberry Pi 4 Model B units to evaluate the computational impact of machine learning-based intrusion detection systems (ML-based IDS) at the edge gateway. Each unit, equipped with 8GB of RAM and a 1.5GHz quad-core CPU, facilitated the assessment of seven ML-based IDS models: Decision Tree (DT), K-Nearest Neighbors (KNN), Random Forest (RF), Long Short-Term Memory (LSTM), Convolutional Neural Network (CNN), an Ensemble Intrusion Detection Model (EIDM), and a hybrid LSTM-CNN model. The experiments simulated various cyber threats, including benign traffic, Distributed Denial of Service (DDoS), Denial of Service (DoS), brute force attacks, and port scans, using Kali Linux. Key performance metrics such as CPU usage, CPU load, and energy consumption were analyzed to address the first research question (RQ1).

To explore the second research question (RQ2), the testbed was enhanced by integrating the edge gateway with the Ryu controller, creating a Software-Defined Networking (SDN) environment. This setup utilized Mininet to simulate a realistic SDN infrastructure comprising eighteen hosts and six switches, enabling centralized traffic management and improved resource allocation. The results of the experiments were subjected to an in-depth statistical analysis using ANOVA, which aimed to elucidate the implications of the findings and assess the effectiveness of each IDS model under real-time cyber threat scenarios. The experimental results for both RQ1 and RQ2 are discussed in detail, highlighting the performance of IoT-edge devices with SDN integration in the face of cyber threats.

Results

The results of the ANOVA analyses indicate significant differences in CPU load and energy consumption among various machine learning-based Intrusion Detection Systems (IDS) under different cyber threats, particularly DDoS attacks. The analyses yielded an F-statistic of 60.40 (p < 0.05) for CPU load, demonstrating that the choice of IDS significantly influences CPU performance. Similar findings were observed across other attack types, including brute force and DoS, reinforcing the conclusion of marked differences in CPU load among the IDSs. Notably, deep learning-based IDS, such as CNN and LSTM, exhibited superior efficiency in managing computational demands compared to traditional methods like KNN, DT, and RF, which are more computationally intensive during inference. In terms of energy consumption, the ANOVA results revealed an F-statistic of 57.44 (p < 0.05) under DDoS conditions, indicating significant variances in energy usage among the IDSs. The LSTM and DT models were identified as the most energy-efficient, while KNN demonstrated the highest energy consumption, making it less suitable for energy-constrained environments. These findings suggest that the architectural advantages of deep learning models contribute to their efficiency in both CPU load and energy consumption, making them particularly well-suited for real-time applications in cybersecurity.

Discussion

The discussion section of the research paper highlights the ongoing challenges in understanding the performance trade-offs of machine learning (ML)-based Intrusion Detection Systems (IDS) in Internet of Things (IoT) environments, particularly within resource-constrained edge gateways. While previous studies have primarily focused on detection accuracy, there is a notable lack of research addressing the real-time computational impacts of these systems, especially when integrated with Software-Defined Networking (SDN). The section reviews various ML-based IDS approaches, emphasizing their strengths and limitations, particularly concerning energy consumption and computational efficiency.

Several studies are cited, showcasing different ML models such as Decision Trees (DT), Random Forests (RF), and Long Short-Term Memory (LSTM) networks, which have demonstrated high accuracy in detecting various types of network anomalies. For instance, the Enhanced Intrusion Detection Deep Learning Multi-class Classification Model (EIDM) and other models like the Feed-Forward Deep Neural Network (FFDNN) have shown promise in accurately classifying network traffic and enhancing security measures. However, the section also notes a significant gap in empirical studies that evaluate the real-time performance of these models in terms of CPU load, CPU usage, and energy consumption during cyber threats. The authors aim to address this gap through their comprehensive analysis of ML-based IDS, focusing on their operational impacts in both SDN-enabled and non-SDN edge gateways, thereby providing critical insights into their feasibility for deployment in IoT networks.

شارك: