ML Based Rank Attack Detection for Smart Hospital Infrastructure
33
attack is considered one of dangerous attacks in dynamic IoT networks since
the attacker controls an existing node (being one of the internal attack that can
affect the RPL) in the DODAG or he can identify the network and insert his
own malicious node and that node will act as the attack node as shown in Fig. 4.
Fig. 4. The rank attack scenario.
4 Proposed Approach
The key features required for our solution are to be adaptive, lightweight, and
able to learn from the past. We design an IoT IDS and we implement and evaluate
it as authors did in [18,20].
Placement Choice: one of the important decision in intrusion detection is the
placement of the IDS in the network. We use a centralized approach by installing
the IDS at the border router. Therefore, it can analyze all the packets that pass
through it. The choice of the centralized IDS was done to avoid the placement of
IDS modules in constrained devices which requires more storage and processing
capabilities [15,16]. However, theses devices have limited resources.
Detection Method Choice: An intrusion detection system (IDS) is a tool
or mechanism to detect attacks against a system or a network by analyzing
the activity in the network or in the system itself. Once an attack is detected
an IDS may log information about it and/or report an alarm [15,16]. Broadly
speaking, we aim to choose the anomaly based detection mechanisms: it tries to
detect anomalies in the system by determining the ordinary behavior and using
it as baseline. Any deviations from that baseline is considered as an anomaly.
This technique have the ability to detect almost any attack and adapt to new
environments. We chose Support Vector Machines (SVM) as an anomaly based
machine learning technique. It is a discriminating classifier formally defined by
a separating hyper-lane. Given labeled training data (supervised learning), the
Précédent

- 46/446

Suivant