A Network-Based Event Detection Module Using NTP for Cyber Attacks on IoT

Tamotsu Kawamura, Masaru Fukushi, Yasushi Hirano, Y. Fujita, Y. Hamamoto
{"title":"A Network-Based Event Detection Module Using NTP for Cyber Attacks on IoT","authors":"Tamotsu Kawamura, Masaru Fukushi, Yasushi Hirano, Y. Fujita, Y. Hamamoto","doi":"10.1109/CANDARW.2018.00025","DOIUrl":null,"url":null,"abstract":"Developing countermeasures against cyber attacks is an urgent issue in Internet of Things (IoT) environment, and event detection is becoming increasingly important to detect events as the presages of a security incident. This paper proposes an event detection module which can be embedded into IoT devices. The proposed module focuses on the system behavior under cyber attacks and detects events utilizing information from Network Time Protocol (NTP) commonly used in network time synchronization service. This module works under a wireless access point (AP) and detects events on IoT devices linked to the AP. Different from the existing modules, it does not require any additional appliances nor periodic maintenance involving technical knowledges. We conducted demonstration experiments with the developed module generating pseudo cyber attacks. The result shows that the proposed module achieves high recall and precision values, indicating its usefulness in the real time event detection on IoT.","PeriodicalId":329439,"journal":{"name":"2018 Sixth International Symposium on Computing and Networking Workshops (CANDARW)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 Sixth International Symposium on Computing and Networking Workshops (CANDARW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CANDARW.2018.00025","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Developing countermeasures against cyber attacks is an urgent issue in Internet of Things (IoT) environment, and event detection is becoming increasingly important to detect events as the presages of a security incident. This paper proposes an event detection module which can be embedded into IoT devices. The proposed module focuses on the system behavior under cyber attacks and detects events utilizing information from Network Time Protocol (NTP) commonly used in network time synchronization service. This module works under a wireless access point (AP) and detects events on IoT devices linked to the AP. Different from the existing modules, it does not require any additional appliances nor periodic maintenance involving technical knowledges. We conducted demonstration experiments with the developed module generating pseudo cyber attacks. The result shows that the proposed module achieves high recall and precision values, indicating its usefulness in the real time event detection on IoT.
基于网络的NTP事件检测模块用于物联网网络攻击
在物联网环境下,制定应对网络攻击的对策是一个紧迫的问题,而事件检测对于检测作为安全事件前兆的事件变得越来越重要。本文提出了一种可嵌入物联网设备的事件检测模块。该模块关注系统在网络攻击下的行为,利用网络时间同步服务中常用的网络时间协议(NTP)信息检测事件。该模块在无线接入点(AP)下工作,检测与AP相连的物联网设备上的事件。与现有模块不同,它不需要任何额外的设备,也不需要涉及技术知识的定期维护。我们使用开发的模块进行了演示实验,生成伪网络攻击。结果表明,该模块在物联网实时事件检测中具有较高的查全率和查准率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信