Title :
Ultra-lightweight deep packet anomaly detection for Internet of Things devices
Author :
Douglas H. Summerville;Kenneth M. Zach;Yu Chen
Author_Institution :
Department of Electrical and Computer Engineering, State University of New York at Binghamton, NY, USA
Abstract :
As we race toward the Internet of Things (IoT), small embedded devices are increasingly becoming network-enabled. Often, these devices can´t meet the computational requirements of current intrusion prevention mechanisms or designers prioritize additional features and services over security; as a result, many IoT devices are vulnerable to attack. We have developed an ultra-lightweight deep packet anomaly detection approach that is feasible to run on resource constrained IoT devices yet provides good discrimination between normal and abnormal payloads. Feature selection uses efficient bit-pattern matching, requiring only a bitwise AND operation followed by a conditional counter increment. The discrimination function is implemented as a lookup-table, allowing both fast evaluation and flexible feature space representation. Due to its simplicity, the approach can be efficiently implemented in either hardware or software and can be deployed in network appliances, interfaces, or in the protocol stack of a device. We demonstrate near perfect payload discrimination for data captured from off the shelf IoT devices.
Keywords :
"Payloads","Feature extraction","Detectors","Computational complexity","Performance evaluation","Hidden Markov models","Hardware"
Conference_Titel :
Computing and Communications Conference (IPCCC), 2015 IEEE 34th International Performance
Electronic_ISBN :
2374-9628
DOI :
10.1109/PCCC.2015.7410342