Abstract
Cloud Internet of Things (CIoT) environments, as the essential basis for computing services, have been subject to abuses and cyber threats. The adversaries constantly search for vulnerable areas in such computing environments to impose their damages and create complex challenges. Hence, using intrusion detection and prevention systems (IDPSs) is almost mandatory for securing CIoT environments. However, the existing IDPSs in this area suffer from some limitations, such as incapability of detecting unknown attacks and being vulnerable to the single point of failure. In this paper, we propose a novel distributed multi-agent IDPS (DMAIDPS) that overcomes these limitations. The learning agents in DMAIDPS perform a six-step detection process to classify the network behavior as normal or under attack. We have tested the proposed DMAIDPS with the KDD Cup 99 and NSL-KDD datasets. The experimental results have been compared with other methods in the field based on Recall, Accuracy, and F-Score metrics. The proposed system has improved the Recall, Accuracy, and F-Scores metrics by an average of 16.81%, 16.05%, and 18.12%, respectively.
| Original language | English |
|---|---|
| Pages (from-to) | 367-384 |
| Number of pages | 18 |
| Journal | Cluster Computing |
| Volume | 26 |
| Issue number | 1 |
| DOIs | |
| State | Published - Feb 2023 |
| Externally published | Yes |
Keywords
- CIoT
- DMAIDPS
- Intrusion detection and prevention system
- Learning agent
Fingerprint
Dive into the research topics of 'DMAIDPS: a distributed multi-agent intrusion detection and prevention system for cloud IoT environments'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver