用AI+零信任+零接触框架自动防御物联网DDoS攻击
A Novel Zero-Touch, Zero-Trust, AI/ML Enablement Framework for IoT Network Security
- 集成零信任与零接触理念,结合AI/ML实现安全自动化
- 集成方法在检测各类DDoS攻击中表现最佳,准确率超95%
- 适合需要自适应安全防护的5G/6G物联网系统部署
物联网推动智能可持续社会的发展,亟需保障其生态安全。基于5G/6G的物联网将更广泛使用机器学习与人工智能(ML/AI),以构建自主协同的安全网络。本文提出一种新型零触控、零信任、由AI/ML驱动的物联网安全框架,用于检测、缓解和预防现代物联网生态系统中的分布式拒绝服务(DDoS)攻击。重点在于对所有物联网流量(包括固定与移动5G/6G)实施零信任策略,并实现数据安全(隔离-零触控与动态策略执行)。通过对比五种机器学习模型——XGBoost、随机森林、K近邻、随机梯度下降和朴素贝叶斯——评估其在准确率、精确率、召回率、F1分数及ROC-AUC上的表现。结果表明,集成学习方法在检测和缓解不同类型的DDoS攻击方面表现最优。
原文摘要 · Abstract (English)
The IoT facilitates a connected, intelligent, and sustainable society; therefore, it is imperative to protect the IoT ecosystem. The IoT-based 5G and 6G will leverage the use of machine learning and artificial intelligence (ML/AI) more to pave the way for autonomous and collaborative secure IoT networks. Zero-touch, zero-trust IoT security with AI and machine learning (ML) enablement frameworks offers a powerful approach to securing the expanding landscape of Internet of Things (IoT) devices. This paper presents a novel framework based on the integration of Zero Trust, Zero Touch, and AI/ML powered for the detection, mitigation, and prevention of DDoS attacks in modern IoT ecosystems. The focus will be on the new integrated framework by establishing zero trust for all IoT traffic, fixed and mobile 5G/6G IoT network traffic, and data security (quarantine-zero touch and dynamic policy enforcement). We perform a comparative analysis of five machine learning models, namely, XGBoost, Random Forest, K-Nearest Neighbors, Stochastic Gradient Descent, and Native Bayes, by comparing these models based on accuracy, precision, recall, F1-score, and ROC-AUC. Results show that the best performance in detecting and mitigating different DDoS vectors comes from the ensemble-based approaches.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。