Journals / Eskişehir Osmangazi Üniversitesi mühendislik ve mimarlık fakültesi dergisi (online) / 2022 / Cilt: 30 - Sayı: 2
ATTACKS ON THE MQTT-BASED IOT SYSTEM DETECTION USING MACHINE LEARNING
- Pages
- 159–170
- DOI
- —
Abstract
Almost all devices today have the potential to connect to the internet. Therefore, the use of IoT devices is increasing day by day. Most of the devices connected to the internet are vulnerable to cyber-attacks. In networks where a large number of devices are connected, attacks are critical to the security of the network and devices. Due to high success rates, machine learning approaches appear to be at the forefront of detecting attacks affecting IoT security. In this study, it was aimed to detect attacks on the MQTT protocol, which is one of the most commonly used protocols on the IoT platform. For this purpose, first of all, studies in the literature have been examined, attack types have been determined and the necessary test environment has been created. Then, cyber-attacks were applied to the network using the MQTT protocol and their performance in Intrusion Detection was tested and evaluated with machine learning algorithms. In the presented study, it was shown that realizable dataset improvement contributed to increased success rate in detection of MQTT attacks.
Özet
Günümüzde cihazların neredeyse tümü internete bağlanma potansiyeli taşımaktadır. Bu nedenle IoT cihazların kullanımı gün geçtikçe artmaktadır. İnternete bağlı cihazların büyük bir kısmı siber saldırılara karşı savunmasız olmaktadır. Çok sayıda cihazın bağlı olduğu ağlarda saldırılar, ağ ve cihazların güvenliği için kritik bir konudur. Yüksek başarı oranları sayesinde makine öğrenmesi yaklaşımları, IoT güvenliğini etkileyen saldırıların tespit edilmesinde ön plana çıktığı görülmektedir. Bu çalışmada, IoT platformunda en sık kullanılan protokollerden biri olan MQTT protokolüne gerçekleşen saldırıların tespit edilmesi hedeflenmiştir. Bu amaçla, öncelikle literatürdeki çalışmalar incelenerek, saldırı tipleri belirlenmiş ve gerekli test ortamı oluşturulmuştur. Ardından MQTT protokolünü kullanan ağa, siber saldırılar uygulanarak makine öğrenimi algoritmaları ile saldırı tespitinde performansları test edilerek değerlendirilmiştir. Sunulan çalışmada, gerçekleştirilen veri kümesi iyileştirmesinin MQTT saldırılarının tespitinde başarı oranının artmasına katkı sağladığı görülmüştür.