Engine for Malware Technology (EMT): An IoT- Data Smart Virtual Research Environment for High- Performance Computing for Innovation in Malware Detection Discovery using an Interactive, Attention- engaging Model and Machine Learning
Authors/Creators
- 1. North Dakota State University
- 2. Indiana University - Bloomington
- 3. University of Washington
Description
Introduction: Internet of Things (IoT) devices have revolutionized homes, offices, and cities, where IoT devices have given better visibility, security, and control. However, not all have adequate protection to fend off cyberattacks like IoT botnets that are possible on their specifications. Furthermore, progress in network security is hindered as these security processes need to manage large datasets and are more complex, especially in scenarios involving many sensors, such as a smart city. Given this, no general-purpose cyberinfrastructures exist for real-time data analysis of malicious network traffic in IoT devices.
Methods: To address these barriers, we present a Virtual Research Environment (VRE) "Engine for Malware Technology" (EMT) to simplify the development and use of standardized workflows for real-time detection of malware in IoT devices. EMT is a platform that manages IoT devices, collects network traffic, provides visualization tools for collected data, and provides tools to build machine learning pipelines to control the malicious traffic circulating through those devices. In this proposed platform, we have packed all required software, including a variety of state-of-the-art open-source middleware, into containers and deployed it in a cloud environment. In addition, EMT manages computational jobs by enabling high-performance concurrent processing of messages from devices, reducing the required computation time and costs for execution and deployment.
EMT is interactive and engages the user's attention by triggering alarms upon detection of injected malware in the received network traffic. Moreover, EMT facilitates researchers to team up to solve challenging malware detection problems by sharing cloud-based data sources and software tools. EMT exchanges messages with a data-centric Publish-Subscribe model, which supports one-to-one and one-to-many communication, and notifies users with updated and accessible information. In addition, we provide mutual authentication and encryption for the device connections so that the VRE cannot exchange data with the devices without verification of identity. To further increase the interactivity, we have provided a rule-based intelligence system in EMT, which allows users to define customized rules to manage data from IoT devices and employ standard machine learning (ML)-based predictive models for detecting malware. The rule-based framework implemented in the VRE also allows users to build their own IoT tools and ML pipelines for collecting, analyzing, and controlling network data without users needing the expertise to manage any infrastructure.
Results: To evaluate the capabilities of the integrated framework, we carried out an experiment using this VRE to study different algorithms on an IoT network traffic dataset “IoT-23” to find the differences in the types of malware and to design a method to develop a malware detection system based on the botnet Okiru. We further evaluated the malware detection performance using Random Forest, Naïve Bayes, and Decision Tree, with Random Forest showing the best performance among the three.
Discussion: The preliminary findings suggest that EMT is beneficial in detecting malware in IoT devices. Future work incorporating analysis of user behavior patterns and complex situations would be of interest as the VRE would be able to make spontaneous decisions to deal with existing issues related to large datasets.
Files
Gateways2022_paper_8609.pdf
Files
(115.1 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:06c878e094fd9b0da2cb3c84f4ce7f6b
|
115.1 kB | Preview Download |