期刊文献+

CREBAD:基于芯片辐射的物联网设备异常检测方案 被引量:7

CREBAD:Chip Radio Emission Based Anomaly Detection Scheme of IoT Devices
下载PDF
导出
摘要 随着物联网的飞速发展,物联网设备的安全问题受到了广泛的关注.物联网设备的软硬件特性导致其极易遭受各类攻击.对物联网设备的异常检测成为近年的热点,传统的基于入侵检测、流量分析等防护方式无法适用于物联网设备的软硬件环境.针对这一问题,提出了基于芯片辐射的异常检测方案,以物联网设备在工作时向外辐射的电磁波信号作为检测依据,采用遗传算法和近似熵理论对原始信号进行特征提取和选择后,利用一类支持向量机对正常行为产生的辐射信号进行训练.该方案具有无侵入的特性,无需对原有系统进行任何软硬件改造,适用于现有物联网设备.最后的实验结果表明:与其他常用的异常检测方案相比,该方案能够更有效地检测物联网设备的异常行为,具有较高的准确性和较低的误报率. with the rapid development of the Internet of things(IoT),IoT security issues have received widespread attention.The hardware and software features of IoT devices make them extremely vulnerable to all types of attacks.Anomaly detection of IoT devices has become a hot spot in recent years.The traditional protection methods based on intrusion detection and traffic analysis can not adapt to the hardware and software environment of IoT devices.In order to solve this problem,an anomaly detection scheme based on chip radiation is proposed. By using the electromagnetic wave signals of IoT devices radiating outwards during operation as detection basis,the original signals are extracted and selected by genetic algorithm and approximate entropy.Finally,the signal of normal behavior radiation is trained using a one-class support vector machine algorithm.The program has non-invasive features,without the need for any transformation of the original system hardware and software,applying to the existing IoT devices.The final experimental results show that compared with other commonly used anomaly detection schemes,this scheme can detect the abnormal behavior of IoT devices more effectively,with higher accuracy and lower false alarm rate.
作者 倪明涛 赵波 吴福生 樊佩茹 Ni Mingtao;Zhao Bo;Wu Fusheng;Fan Peiru(School of Cyber Science and Engineering,Wuhan University,Wuhan 430072;Key Laboratory of Aerospace Information Security and Trusted Computing(Wuhan University),Ministry of Education,Wuhan 430072;School of Computer Science,Leshan Normal University,Leshan,Sichuan 614000)
出处 《计算机研究与发展》 EI CSCD 北大核心 2018年第7期1451-1461,共11页 Journal of Computer Research and Development
基金 国家"八六三"高技术研究发展计划基金项目(2015AA016002) 国家"九七三"重点基础研究发展计划基金项目(2014CB340600 2014CB340601)~~
关键词 异常检测 物联网设备 无线电辐射 一类支持向量机 聚类 anomaly detection IoT device radio emission one class SVM clustering
  • 相关文献

参考文献3

二级参考文献59

  • 1周东华,孙优贤,席裕庚,张钟俊.一类非线性系统参数偏差型故障的实时检测与诊断[J].自动化学报,1993,19(2):184-189. 被引量:26
  • 2李渭华,萧德云,方崇智.一种基于自适应滑动窗格形滤波算法的故障检测器[J].自动化学报,1996,22(2):251-253. 被引量:7
  • 3Stouffer K, Falco J, Scarfone K. SP 800--82 Guide to Industrial Control Systems ( ICS ) Security [S] Gaithersburg, MD: National Institute of Standards and Technology (NIST), 2011.
  • 4EricD.Knapp.工业网络安全:智能电网.SCADA和其他工业控制系统等关键基础设施的安全[M].周秦,郭冰逸,贺惠民,等译.北京:国防工业出版社,2014.
  • 5US Department of Homeland Security. Executive Order 13636--Improving Critical Infrastructure Cybersecurity [EB/OL]. [2015-05 -31]. http://www, dhs. gov/publication eo 13636-improving-cVcybersecurity Office of the Press Secretary, The White House.
  • 6Presidential Policy Directive--Critical Infrastructure Security and Resilience [EB/OI.]. [2015-05-313. http://www, whitehouse. gov/the-press office/2013/O2/12/presidential-policy-directive- critical-infrastructure seeurity-and-resil Industrial Control Systems Cyber Emergency Response Team.
  • 7ICS-CERT year in review 2013, 13-50369 [R/OL]. Arlington County, Virginia, USA: National Cyberseeurity and Communications Integration Center, 2013 [2015-05-31]. https ://ics-eert. us-cert, gov/ICS-CERT Year-Review-2013.
  • 8Cheminod M, Durante L, Valenzano A. Review of security issues in industrial networks [J]. IEEE Trans on Industrial Informatics, 2013, 9(1): 277-293.
  • 9OPC Foundation. OPC unified architecture specification [S]. Scottsdale, Arizona, USA: OPC Foundation, 2006.
  • 10Computer security [EB/OL]. [ 2015-05-31 ]. http://en. wikipedia, org/wiki/Comput er security.

共引文献181

同被引文献50

引证文献7

二级引证文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部