Monshizadeh and Khatri
258
● IoT Data Classifier: big data algorithms are applied to label the data. Data classification refers to association of collected data to different classes based on the purpose of
anomaly detection. The classes are defined based on different features. The features
are either predefined or extracted based on training data or they would be dynamically defined during analysis processing.
In the IoT anomaly detection module, different linear and learning algorithms are
combined in a wide range to investigate a hybrid model for achieving high detection
performance and yet relatively low detection time, and will be deployed to detect
intrusion attempts on IoT robots. The anomaly detection could be either for attack
detection or other applications, such as traffic safety, etc. In principle, it would be
possible to use the described data‐mining mechanisms to detect all types of anomalies and to feed the information, for example to Public Warning System (PWS) [20],
to send a warning as a cell broadcast to alarm any robots in an affected area of a
potential threat.
As shown in Figure 11.7, robot traffic, after being analyzed in the local robot controller, reaches the IoT anomaly detection module in the related MVNO’s cloud. At first, a
vulnerable protocol, such as HTTP, would be filtered and packets carried over vulnerable protocols would be sent to the next module for analysis. In this stage, traffic would
be clustered and suitable features would be extracted in order to label the attack.
Through an error check mechanism, the actual result would be compared with the
expected result to evaluate the detection accuracy. As malicious traffic is detected, the
mitigation mechanism would be applied to block the malicious robot and inform
the rest of the network.
● IoT Application: refers to an application layer and provides interfaces for various IoT
domains, i.e. such as smart parking, smart home automation and security;
● IoT Orchestrator: distributes the information about malicious robots to MVNOs
using orchestration module. Once the attack is detected, the prevention action should
be performed. Prevention includes sending information to Local Robot Collector
(LRC) to identify the malicious robot. LRC traces back the malicious robot and blocks
it from authenticating to MCR. The above‐mentioned mitigation strategy can be
safely applied if the malicious robot is authenticated either to the same IoT service
provider (MVNO) or other cloud service providers (MVNOs). Therefore, an IoT
IoT Data Classifier
IoT Data Miner
IoT Anomaly Detection
Filter
vulnerable
protocols
Detect
abnormal
patterns
from robot
traffic
Mitigate by
blocking
malicious
robot
automated
actions
Deviations
from
expected
IoT traffic
profiles
Figure 11.7 Detection dimensions.
Précédent

- 300/483

Suivant