Affiliation:
1. School of Electrical and Data Engineering, University of Technology Sydney, Sydney, NSW 2007, Australia
2. Data61, CSIRO, Sydney 2122, Australia
Abstract
This research introduces a novel framework utilizing a sequential gated graph convolutional neural network (GGCN) designed specifically for botnet detection within Internet of Things (IoT) network environments. By capitalizing on the strengths of graph neural networks (GNNs) to represent network traffic as complex graph structures, our approach adeptly handles the temporal dynamics inherent to botnet attacks. Key to our approach is the development of a time-stamped multi-edge graph structure that uncovers subtle temporal patterns and hidden relationships in network flows, critical for recognizing botnet behaviors. Moreover, our sequential graph learning framework incorporates time-sequenced edges and multi-edged structures into a two-layered gated graph model, which is optimized with specialized message-passing layers and aggregation functions to address the challenges of time-series traffic data effectively. Our comparative analysis with the state of the art reveals that our sequential gated graph convolutional neural network achieves substantial improvements in detecting IoT botnets. The proposed GGCN model consistently outperforms the conventional model, achieving improvements in accuracy ranging from marginal to substantial—0.01% for BoT IoT and up to 25% for Mirai. Moreover, our empirical analysis underscores the GGCN’s enhanced capabilities, particularly in binary classification tasks, on imbalanced datasets. These findings highlight the model’s ability to effectively navigate and manage the varying complexity and characteristics of IoT security threats across different datasets.
Reference31 articles.
1. Cisco (2020, March 09). Cisco Annual Internet Report (2018–2023). Available online: https://www.cisco.com/c/en/us/solutions/collateral/executive-perspectives/annual-internet-report/white-paper-c11-741490.html.
2. Evaluating critical security issues of the IoT world: Present and future challenges;Frustaci;IEEE Internet Things J.,2018
3. A survey on internet of things: Architecture, enabling technologies, security and privacy, and applications;Lin;IEEE Internet Things J.,2017
4. A survey on security and privacy issues in internet-of-things;Yang;IEEE Internet Things J.,2017
5. Benzarti, S., Triki, B., and Korbaa, O. (2017, January 8–10). A survey on attacks in Internet of Things based networks. Proceedings of the 2017 International Conference on Engineering & MIS (ICEMIS), Monastir, Tunisia.