提出黑盒攻击方法,成功欺骗物联网入侵检测系统。
Targeted Adversarial Traffic Generation : Black-box Approach to Evade Intrusion Detection Systems in IoT Networks
- 设计黑盒攻击策略,无需模型细节即可生成欺骗流量。
- 在真实IDS上实现高成功率逃避,验证攻击可行性。
- 提出新防御方案,有效识别多数对抗流量,适合安全研究者。
机器学习算法在物联网应用中的集成带来了显著优势,但也引入了对抗攻击的漏洞,尤其在基于物联网的入侵检测系统(IDS)中。尽管理论上的对抗攻击已被广泛研究,但实际实施中的约束常被忽视。本研究通过一种新颖的黑盒对抗攻击,评估了针对物联网网络入侵检测系统的逃逸攻击可行性。研究旨在弥合理论漏洞与现实应用之间的差距,增强对现代物联网生态系统中复杂威胁的理解与防御能力。此外,我们提出了一种针对性的防御方案,以减轻逃逸攻击的影响,从而提升基于机器学习的入侵检测系统的韧性。实验结果表明,所提攻击能成功规避主流入侵检测系统,凸显其脆弱性;而提出的防御机制表现出色,可有效检测大部分对抗流量,性能优于现有先进防御方案。本研究为提升物联网安全提供了关键洞见,助力构建更可靠的入侵检测系统。
原文摘要 · Abstract (English)
The integration of machine learning (ML) algorithms into Internet of Things (IoT) applications has introduced significant advantages alongside vulnerabilities to adversarial attacks, especially within IoT-based intrusion detection systems (IDS). While theoretical adversarial attacks have been extensively studied, practical implementation constraints have often been overlooked. This research addresses this gap by evaluating the feasibility of evasion attacks on IoT network-based IDSs, employing a novel black-box adversarial attack. Our study aims to bridge theoretical vulnerabilities with real-world applicability, enhancing understanding and defense against sophisticated threats in modern IoT ecosystems. Additionally, we propose a defense scheme tailored to mitigate the impact of evasion attacks, thereby reinforcing the resilience of ML-based IDSs. Our findings demonstrate successful evasion attacks against IDSs, underscoring their susceptibility to advanced techniques. In contrast, we proposed a defense mechanism that exhibits robust performance by effectively detecting the majority of adversarial traffic, showcasing promising outcomes compared to current state-of-the-art defenses. By addressing these critical cybersecurity challenges, our research contributes to advancing IoT security and provides insights for developing more resilient IDS.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。