you will also need to justify using this dataset. For example you could say that its new and it contain the most known botnet malware in IoT, its also generated in real environment etc..

profileMichelle_Michy
Methodology.edited.docx

Running Head: METHODOLOGY 1

METHODOLOGY 7

Methodology

Name

Course

Tutor

Date

Methodology

The motivation for the Research

Large volumes of IoT devices have been the main driving factor of the worrying internet attacks and infection currently being witnessed. This has been blamed on the rising numbers of the use of IoT devices as well as vulnerabilities that continue to occur in these devices. On the other hand, attacks are ever on the lookout trying to get a weak link that can grant them easy access networks and target devices believed to be of critical use in these systems. In standard cases, the infected IoT devices become the most difficult to detect, thus creating numerous unprotected networks (Albin, 2011). The extent of the crisis is so high that F-Secure Company issued a report indicating a total of 2.9 billion events of traffic attacks in 2019, representing a sevenfold increase from the findings of similar research in 2018.

A targeted attack on an IoT device exposes its resources and actions to bad actors that use them to cause other more damages. The attackers mainly use malware to do access to these devices as well as controlling their actions. On the other hand, the malware is controlled through a control and command channel, which simply refers to means and ways the attackers remotely simultaneously control devices. Several devices whose command and control are at the behest of an attacker form known as botnets. A botnet comprises bots (individually infected devices) and some servers that issue instructions to these bots. It should be noted that bots are just regular computers or any other IoT device that has been infected. Now, it is highly customizable to the extent it can carry any activity as commanded by the attackers through the infected command and control servers (Albin, 2011).

There are a number of techniques and tools that can be used to detect IoT botnets malware. Some of these include Snort, Internet Relay Chat (IRC) protocol, Suricata, and others. In this research paper, an experiment is carried out to help compare and contrast Snort and Suricata's effectiveness as far as intrusion detection of IoT botnet malware such as bashlite, mirai, and tori are anything to go by. Snort (www.snort.org) is an open-source product that is currently being regarded as the industry’s de-facto leader of signature-based network intrusion detection engines. Sucirata, on the other hand, Suricata is also an open-source network intrusion-detection engine believed to be the next big thing and is seen as an IPS engine.

Research Methodology

There are many types of research methodologies that are often used. Some of the common methodological approaches include qualitative or quantitative methodologies, collecting primary data or using secondary data collected by a separate entity, experimental approach carried out through manipulating and controlling variables, and descriptive approaches that involve making observations without intervening.

An experimental methodology was suitable for this research work because there was a need to collect data and use it for the assessment of theoretical standpoints, which in this case border function-based similarities and differences of intrusion detection systems (Snort and Suricata) in detecting IoT botnet malwares (bashlite, mirai, and tori). It is true that this is not the only method that can be used to arrive at a desirable conclusion; experiments to a greater extent provide the most convincing success evidence or exposes the long-held theoretical positions (Albin, 2011). Compared to other types of research methodologies, the experiments produce extremely direct and relevant data to the theoretical perspectives or propose most conclusive causality. Finally, on investigations, they have the highest replicability in that another research group can exactly arrive at the same conclusions.

Methodology Description and Experiment

The experiment tested and compared Snort and Suricata intrusion-detection engines. The experiment evaluated, among others, issues such as CPU utilization sin both Snort and Suricata, memory consumption, and the time taken to analyze the pcap files. Speed between the two engines was measured by running similar pcap files in controlled tests then monitoring both the applications for generated alerts.

Dataset Information

The data used in the experiment originated from the MedBIoT dataset created by Alejandro Guerra Manzannares Jorge Alberto Medina Galindo, Hayretdin Bahsi, and Sven Nõmm from the Department of Software Science, Center for Digital Forensics and Cyber Security; Tallinn University of Technology; Estonia. Captured on January 30th, 2020, the data was used in an experiment performed as part of the creator's thesis for a master's degree. The dataset was suitable for any research work related to IoT botnet as well as intrusion detection systems, to be specific. Real devices and virtual ones were combined and used in a medium-sized network. The devices included a TPLink light bulb, Sonoff Tasmota smart switch, and TPLink smartwatch as real devices. The virtual ones included fan, switch, light, and lock (Guerra-Manzanares, et al., 2020).

The structure and files contained in the dataset included pcap files existing in two formats. These include the bulk and fine-grained ones. The former include Mirai, BashLite, legitimate, and Torii, while the latter is also pcap files sourced for device type and botnet phase. The examples for this include mirai_mal_CC_lock.pcap, which is Mirai botnet malware data that correspond to C&C communication for the lock's devices. When it comes to labeling, every pcap file had a label indicating whether a file is legitimate/benign traffic or as a malicious file. Every bit of the network traffic was collected at the time of malware deployment.

Experiment Set-Up

The experiments were carried out in a VMware ESXr 4.4 virtual machine. A Dell hardware machine served as the server. It was an R710 dual quad-core Poweredge of 88 Gb RAM and CPUs, each of which was an Intel Xenon E5630 of processor speed 2.4Ghz. The virtual machine utilized 4 CPU cores, each of which had a RAM of 16GB. The selected OS for this experiment was the famed CentOS 6.2. Suricata installation was not only non-complex but also lasted for a few minutes. We also installed Snort version 2.9 on the CentOS since Linux has several distributions to the effect.

The Experiments

Since the comparative analysis was based on a few objects such as evaluating CPU utilization sin both Snort and Suricata, memory consumption, and the time is taken to analyze the pcap files, we carried out experiments for each comparable objective, meaning at the end of the day we ended up with three experiments. The first experiment independently investigated the real-time performance of every system, thereby paying attention to the backbone traffic in real-time (Albin, 2011). Data related to the performance from RAM, CPU, and interface of the network was recorded evaluated and a comparison characteristic drawn. In the first experiment, both the detection engines were simultaneously engaged.

The second experiment engaged the Suricata on a supercomputer (NPS Hamming). Given that the NPS High-Performance Computing Center runs 144 blades of a Sun Microsystem 6048 and slightly over 1152 CPU cores, work was even made easier. Also, the center ran CentOS 5.5 as the main operating system (Guerra-Manzanares, et al., 2020).Our experiment only utilized only a single compute node comprising 48 12 Core processors of AMD Opteron that contained 125GB RAM. We measured memory utilization when at the time the Suricata was running on the high- performing computer. The same is repeated with the Snort engine and measurements recorded. The main objective here was to examine if how memory was being used in the Suricata engine.

The third and last experiment involved a comparison of Snort and Suricata with respect to the time taken to analyze the pcap files. Basically, the experiment measured how efficient the Snort intrusion detection system managed to detect malicious packets sent on its way. On the other hand, the experiment also measured how efficient the Snort intrusion detection system managed to detect malicious packets sent on its way. The experiment used the labeled pcap files, some of which contained malware while some were just legitimate files to generate alerts while inside the intrusion detection systems.

In conclusion, the three experiments carried out reliably informed us of the three comparison objectives; evaluating CPU utilization sin both Snort and Suricata, memory consumption, and the time taken to analyze the pcap files.

References

Albin, E., (2011) A COMPARATIVE ANALYSIS OF THE SNORT AND SURICATA INTRUSION-DETECTION SYSTEMS NAVAL POSTGRADUATE SCHOOL MONTEREY, CALIFORNIA

Guerra-Manzanares, A.; Medina-Galindo, J.; Bahsi, H. and Nõmm, S. (2020). MedBIoT: Generation of an IoT Botnet Dataset in a Medium-sized IoT Network. In Proceedings of the 6th International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-399-5, pages 207-218. DOI: 10.5220/0009187802070218