PPT term paper presentation about any topic in information security/cyber security
Project 1: Securing IoT‐based Cyber‐Physical Human Systems using ML
David Eastman and Sathish A.P. Kumar, “A Simulation Study to Detect Attacks on Internet of Things”, in Proceedings of the 15th IEEE International Conference on Dependable, Autonomic and Secure Computing (IEEE DASC), Orlando, FL, USA, 2017
Sathish A.P. Kumar, B. Bhargava, R. Macedo, and G. Mani , “Securing IoT-based Cyber-Physical Human Systems against Collaborative Attacks”, in Proceedings of the IEEE International Congress on Internet of Things (IEEE ICIOT), Honolulu, HI, USA, 2017
Kumar, Sathish Alampalayam, Tyler Vealey, and Harshit Srivastava. "Security in Internet of Things: Challenges, Solutions and Future Directions." In Proceedings of the 2016 49th Hawaii International Conference on System Sciences (HICSS), pp. 5772-5781. IEEE Computer Society, 2016.
Project 1 ‐ Outline
• Introduction
• Motivation for Security in IoT‐Based CPHS
• Security Framework for IoT‐Based CPHS
• Preliminary Experimentation Results
• Future Work
• Summary
6
7
• CPHS is Integration of Cyber, Physical, and Human Elements
• Internet of Things as an enabler to deploy CPH Systems
• Due to their unpredictability, human behavior is difficult to model
Introduction
• Human entities add uncertainty and vulnerability to CPH Systems – Intentional (malicious) errors – Malicious collaborative attacks – Unintentional mistakes/errors – Identity compromise – Privacy breach
8
Threats due to Human Entities
• What % of all Security incidents are caused by human factors ?
- Nearly 95% [2014 IBM Study]
• Intrusion tolerance, prevention, and detection should work in coordinated and integrated fashion
– Need advanced security frameworks and machine learning capabilities
• Study and contain dynamic human interactions in IoT‐based CPHS security issues and collaborative attacks – Requires proper modeling and tools
9
CPHS Security Motivation
Measure Predict Mitigate
• Introduction and Background
• Motivation for Security in IoT‐Based CPHS
• Security Framework for IoT‐Based CPHS
• Preliminary Experimentation Results
• Summary
• Future Work
10
Project 1 ‐ Outline
• Framework uses a feedback control scheme
• Analogous to the human biological model – where virus attack is detected by measuring body parameters
– antibodies are generated to stabilize the body parameters
Security Framework for IoT‐Based CPHS Environment
IoT Based CPHS Environment f(x1(t),x2(t),…xn(t), v1(t), v2(t)…vn(t), h1(t), h2(t),…hn(t), k(t), u(t))
Attack k(t)
Vulnerability Assessment and Threat Detection TI(t) TI (t) = f(x1’(t) x2’(t),…xn’(t))
f(x1’(t), x2’(t),…xn’(t))
Response and Protection Framework
(Controller)
Threat Index thresholds TI’ trained from
thresholds of network parameters
TI (t)
TI’
e(t) +
-
u(t) Control Input
Identification of Significant Parameters
Identification of thresholds for network
parameters
Training Data
Security Framework for IoT‐CPHS
1
23
4
1
2
3
4
TI Estimation Architecture
• Crisp input values are transformed into membership values of the fuzzy sets using the developed Multivariate Membership Function Optimization Algorithm
• For ‘n’ Input variables and ‘m’ grades of membership, Rule base has k=nm rules
• Mamdani Inference engine calculates the fuzzy output using the fuzzy rules in the rule base
• Threat Index, TI(t) quantifies the threat of network or node and detect if a node is under attack or not
• For all k rules, rule strength [wj] and rule output [yj] are used to calculate TI
• For example if only one rule has Wj to be 0.25, whose output yj is 7 and the rest of Wj are 0
–TI will be 1.75 / 0.25 = 7 (VS)
14
m
j j
m
j jj
w
yw
1
1 TI =
TI Estimation
15
N1
M1,1 M1,2
M1,3
M1,4
M1,5 N1
M1,j Neighboring nodes for N1
Node under threat
Intrusion Detection ‐ Example
• Values of PD, QL and EC are observed and fed to TI evaluation framework
• If value of TI is 7, it indicates node is under threat
• TI < 4 is no threat, TI > 6 is threat, TI between 4 and 6 is vulnerable
• For ‘3’ Input variables and ‘3’ grades of membership, k=3 3 rules are generated
• If a node is under threat (N1), – neighboring nodes (M1,j ) are subjected to response and protection algorithm
– To identify intruder and isolate intruder from the CPHS network
16
Coordinated Intrusion Response
N1
M1,1 M1,2
M1,3
M1,4
M1,5 N1
M1,j Neighboring nodes for N1
Node under threat
17
Coordinated Intrusion Response Example
18
• Introduction and Background
• Motivation for Security in IoT‐Based CPHS
• Security Framework for IoT‐Based CPHS
• Preliminary Experimentation Results
• Future Work
• Summary
Project 1 ‐ Outline
• Contiki OS with the Cooja simulation • Simulated 1 sink and 25 collect nodes • Experiment was repeated 3 times for each attack • Parameters Observed ‐ Packet Loss and Energy Consumption • The total running time of each simulation was 5 minutes
Experimentation Setup
• Selective forwarding attacks – Malicious node only forwards the packets
necessary to remain a viable node (e.g. control packets)
– Drops or re‐directs other packets (e.g. data packets) as the attacker desires
20
Sinkhole and Selective Forwarding Attack‐Introduction
• By keep forwarding the control packets • Malicious node remain attractive to its
neighboring nodes. • Resulting in Sinkhole attacks
• To implement the sinkhole attack – A malicious sink node that advertised itself as the root node in its routing
control messages was introduced to the default network. – This caused the malicious node to become favored among neighboring nodes.
• To implement the selective forwarding of collect data packets – The malicious sink node used altered code to drop all packets that were not
routing control messages 21
Sinkhole / Selective Forwarding Attack‐Implementation
malicious sink node
• Energy Usage – The mean duty cycle remained around 5% and the individual collect nodes did not fluctuate beyond the range of the control nodes
22
Sinkhole / Selective Forwarding Attack ‐ Results
• Packet Loss – An average of 60% were received by the non‐malicious sink node – 40% were intercepted and dropped by the malicious sink node
• Here node’s logical attributes are copied to another node
– Other nodes cannot discern the difference
– Packets will be sent to the clone as if it were a legitimate node
Jack Clone “Jack”
Clone profile Friend request
Jack’s Friends
Clone Attacks ‐ Introduction
24
Clone Attacks ‐ Implementation
Duplicate sink node sink node
• Disabled the simulator’s check for duplicate nodes, and then added a duplicate sink node with the same node id
• The resulting network treats the cloned node as an additional node and does not distinguish it as a cloned node
• Packet loss appears to vary widely depending on trial
• Since the sink node is being cloned – that two sink nodes are sending out contradictory messages to control the topology of the DODAG
25
Clone Attacks – Packet Drop Experimentation Results
26
Clone Attacks – Energy usage experimentation results
• As the sink node is being cloned, there was a commensurate rise in the mean duty cycle of the network from around 5% to 9%
• The duty cycles of several nodes neighboring the sink nodes also rose to levels around 3.5%
• A malicious node bombards the sink node with packets – Sink node is unable to serve the legitimate nodes – An attacker can take advantage of resource asymmetry in IoT
• In existing approaches there is a trade‐off between the detection rate and the overhead involved in detection of attack
• Due to resource‐constraints in IoT, efficient processing to detect an attack is essential 27
Denial of Service (DoS) Attacks ‐ Introduction
28
Denial of Service Attacks ‐ Implementation
• Node 24 was compromised with malicious code so that it sends 100 data packets per second towards the sink node instead of 1 data packet per minute
• This results in the sink node being sent 24,000 packets from the malicious node over the course of the simulation
• Attacked sink node received around 92 legitimate packets
• While the sink node should theoretically have processed 24,000 packets from the malicious node – in actuality, it only processed around 1500 or 6%
29
DoS Attacks – Packet Drop Experimentation Results
30
• The sink node operated at 100% duty cycle
• Average duty cycle for the intermediary nodes increased from approximately 1% to between 4 to 8%
• The mean duty cycle for the entire network rose from around 5% to 5.5%
DoS Attacks – Energy Usage Experimentation Results
Results DoS Attacks TI with and without response
Threat Index At Node 1 Without and With Response
0
2
4
6
8
10
20 10 0
18 0
26 0
34 0
42 0
50 0
58 0
66 0
74 0
Time (s)
Th re
at In
de x TI without Response
TI with Response
32
• Introduction and Background
• Motivation for Security in IoT‐Based CPHS
• Security Framework for IoT‐Based CPHS
• Preliminary Experimentation Results
• Future Work
• Summary
Project 1 ‐ Outline
33
• Experiments to determine physical and human parameters to autonomically calculate TI
• Experiment using other machine learning and deep learning techniques for threat detection
• Threat Modeling (TI calculation) involving human and physical components in CPHS environment
• Autonomic Intrusion Response for integrated IoT‐based CPHS environment
Project 1 ‐ Future Work
• Holistic framework to mitigate IoT‐based CPHS attacks
• Simulations of common threat models for IoT are implemented
• Parameter data is collected and analyzed to detect threat and respond to attacks
• Threat modeling and detection involving human elements and CPS parameters is critical
• Human involvement deepens security issues in CPHS
34
Project 1 ‐ Summary