PPT term paper presentation about any topic in information security/cyber security

profileVarshini
ExampleofExperimentationPaperPresentation.pdf

Project 1: Securing IoT‐based Cyber‐Physical  Human Systems using ML

David Eastman and Sathish A.P. Kumar, “A Simulation Study to Detect Attacks on Internet of Things”, in Proceedings of the 15th IEEE International Conference on Dependable, Autonomic and Secure Computing (IEEE DASC), Orlando, FL, USA, 2017

Sathish A.P. Kumar, B. Bhargava, R. Macedo, and G. Mani , “Securing IoT-based Cyber-Physical Human Systems against Collaborative Attacks”, in Proceedings of the IEEE International Congress on Internet of Things (IEEE ICIOT), Honolulu, HI, USA, 2017

Kumar, Sathish Alampalayam, Tyler Vealey, and Harshit Srivastava. "Security in Internet of Things: Challenges, Solutions and Future Directions." In Proceedings of the 2016 49th Hawaii International Conference on System Sciences (HICSS), pp. 5772-5781. IEEE Computer Society, 2016.

Project 1 ‐ Outline

• Introduction  

• Motivation for Security in IoT‐Based CPHS

• Security Framework for IoT‐Based CPHS

• Preliminary Experimentation Results  

• Future Work

• Summary

6

7

• CPHS is Integration of Cyber, Physical, and Human Elements

• Internet of Things as an enabler to deploy CPH Systems

• Due to their unpredictability, human behavior is difficult to model

Introduction

• Human entities add uncertainty and vulnerability to CPH Systems  – Intentional (malicious) errors – Malicious collaborative attacks – Unintentional mistakes/errors – Identity compromise – Privacy breach

8

Threats due to Human Entities

• What % of all Security incidents are caused by human factors ?

- Nearly 95% [2014 IBM Study]

• Intrusion tolerance, prevention, and detection should work in  coordinated and integrated fashion

– Need advanced security frameworks and machine learning capabilities

• Study and contain dynamic human interactions in IoT‐based CPHS  security issues and collaborative attacks – Requires proper modeling and tools

9

CPHS Security Motivation

Measure Predict Mitigate

• Introduction and Background

• Motivation for Security in IoT‐Based CPHS

• Security Framework for IoT‐Based CPHS

• Preliminary Experimentation Results 

• Summary

• Future Work

10

Project 1 ‐ Outline

• Framework uses a feedback control scheme 

• Analogous to the human biological model   – where virus attack is detected by measuring body parameters 

– antibodies are generated to stabilize the body parameters  

Security Framework for IoT‐Based CPHS Environment

IoT Based CPHS Environment f(x1(t),x2(t),…xn(t), v1(t), v2(t)…vn(t), h1(t), h2(t),…hn(t), k(t), u(t))

Attack k(t)

Vulnerability Assessment and Threat Detection TI(t) TI (t) = f(x1’(t) x2’(t),…xn’(t))

f(x1’(t), x2’(t),…xn’(t))

Response and Protection Framework

(Controller)

Threat Index thresholds TI’ trained from

thresholds of network parameters

TI (t)

TI’

e(t) +

-

u(t) Control Input

Identification of Significant Parameters

Identification of thresholds for network

parameters

Training Data

Security Framework for IoT‐CPHS  

1

23

4

1

2

3

4

TI Estimation Architecture

• Crisp input values are transformed into membership values of the fuzzy sets using the  developed Multivariate Membership Function Optimization Algorithm  

• For ‘n’ Input variables and ‘m’ grades of membership, Rule base has k=nm rules 

• Mamdani Inference engine calculates the fuzzy output using the fuzzy rules  in the rule base 

• Threat Index, TI(t) quantifies the threat of network or node and detect if a node is under  attack or not

• For all k rules, rule strength [wj] and rule output [yj] are  used to calculate TI

• For example if only one rule has Wj to be 0.25, whose  output  yj is 7 and the rest of Wj are 0

–TI will be 1.75 / 0.25 = 7 (VS)

14

 m

j j

m

j jj

w

yw

1

1 TI =

TI Estimation

15

N1

M1,1 M1,2

M1,3

M1,4

M1,5 N1

M1,j Neighboring nodes for N1

Node under threat

Intrusion Detection ‐ Example

• Values of PD, QL and EC are observed and fed to TI evaluation framework

• If value of TI is 7, it indicates node is under threat

• TI < 4 is no threat, TI > 6 is threat, TI between 4 and 6 is vulnerable

• For ‘3’ Input variables and ‘3’ grades of membership, k=3 3 rules are generated

• If a node is under threat (N1), – neighboring nodes (M1,j ) are subjected to response and  protection algorithm

– To identify intruder and isolate intruder from the CPHS network

16

Coordinated Intrusion Response

N1

M1,1 M1,2

M1,3

M1,4

M1,5 N1

M1,j Neighboring nodes for N1

Node under threat

17

Coordinated Intrusion Response Example

18

• Introduction and Background

• Motivation for Security in IoT‐Based CPHS

• Security Framework for IoT‐Based CPHS

• Preliminary Experimentation Results

• Future Work 

• Summary

Project 1 ‐ Outline

• Contiki OS with the Cooja simulation   • Simulated 1 sink and 25 collect nodes   • Experiment was repeated 3 times for each attack • Parameters Observed ‐ Packet Loss and Energy Consumption • The total running time of each simulation was 5 minutes

Experimentation Setup

• Selective forwarding attacks  – Malicious node only forwards the packets 

necessary to remain a viable node (e.g.  control packets) 

– Drops or re‐directs other packets (e.g.  data packets) as  the attacker desires

20

Sinkhole and Selective Forwarding Attack‐Introduction

• By keep forwarding the control packets • Malicious node remain attractive to its 

neighboring nodes. • Resulting in Sinkhole attacks

• To implement the sinkhole attack – A malicious sink node that advertised itself as the root node in its routing 

control messages was introduced to the default network.  – This caused the malicious node to become favored among neighboring nodes.

• To implement the selective forwarding of collect data packets – The malicious sink node used altered code to drop all packets that were not 

routing control messages   21

Sinkhole / Selective Forwarding Attack‐Implementation

malicious sink node

• Energy Usage  – The mean duty cycle remained around 5% and the individual  collect nodes did not fluctuate beyond the range of the control  nodes

22

Sinkhole / Selective Forwarding Attack ‐ Results

• Packet Loss  – An average of 60% were received by the non‐malicious sink node – 40% were intercepted and dropped by the malicious sink node

• Here node’s logical attributes are copied to another node 

– Other nodes cannot discern the difference  

– Packets will be sent to the clone as if it were a legitimate node

Jack Clone “Jack”

Clone  profile Friend request

Jack’s Friends

Clone Attacks ‐ Introduction

24

Clone Attacks ‐ Implementation

Duplicate sink node sink node

• Disabled the simulator’s check for duplicate nodes, and then added a  duplicate sink node with the same node id  

• The resulting network treats the cloned node as an additional node and  does not distinguish it as a cloned node 

• Packet loss appears to vary widely depending on trial

• Since the sink node is being cloned  – that two sink nodes are sending out contradictory messages to  control the topology of the DODAG 

25

Clone Attacks – Packet Drop Experimentation Results

26

Clone Attacks – Energy usage experimentation results

• As the sink node is being cloned, there was a commensurate rise in  the mean duty cycle of the network from around 5% to 9%

• The duty cycles of several nodes neighboring the sink nodes also rose  to levels around 3.5% 

• A malicious node bombards the sink node with packets – Sink node is unable to serve the legitimate nodes – An attacker can take advantage of resource asymmetry in IoT 

• In existing approaches there is a trade‐off between the detection rate  and the overhead involved in detection of attack

• Due to resource‐constraints in IoT, efficient processing to detect an  attack is essential 27

Denial of Service (DoS) Attacks ‐ Introduction

28

Denial of Service Attacks ‐ Implementation

• Node 24 was compromised with malicious code so that it sends 100 data packets  per second towards the sink node  instead of 1 data packet per minute

• This results in the sink node being sent 24,000 packets from the malicious node  over the course of the simulation

• Attacked sink node received around 92 legitimate packets  

• While the sink node should theoretically have processed 24,000  packets from the malicious node  – in actuality, it only processed around 1500 or 6% 

29

DoS Attacks – Packet Drop Experimentation Results

30

• The sink node operated at 100% duty cycle

• Average duty cycle for the intermediary nodes  increased from approximately  1% to between 4 to 8%

• The mean duty cycle for the entire network rose from around 5% to 5.5% 

DoS Attacks – Energy Usage Experimentation Results

Results DoS Attacks TI with and without response

Threat Index At Node 1 Without and With Response

0

2

4

6

8

10

20 10 0

18 0

26 0

34 0

42 0

50 0

58 0

66 0

74 0

Time (s)

Th re

at In

de x TI without Response

TI with Response

32

• Introduction and Background

• Motivation for Security in IoT‐Based CPHS

• Security Framework for IoT‐Based CPHS

• Preliminary Experimentation Results 

• Future Work

• Summary

Project 1 ‐ Outline

33

• Experiments  to determine physical and human parameters to  autonomically calculate TI

• Experiment using other machine learning and deep learning  techniques for threat detection

• Threat Modeling (TI calculation) involving human and physical  components in CPHS environment  

• Autonomic Intrusion Response for integrated IoT‐based CPHS  environment

Project 1 ‐ Future Work

• Holistic framework to mitigate IoT‐based CPHS attacks  

• Simulations of common threat models for IoT are implemented

• Parameter data is collected and analyzed to detect threat and respond  to attacks

• Threat modeling and detection involving human elements and CPS  parameters is critical

• Human involvement deepens security issues in CPHS 

34

Project 1 ‐ Summary