<b>DDoSViT: IoT DDoS Attack Detection for Fortifying Firmware Over-The-Air (OTA) Updates Using Vision Transformer</b>
收藏资源简介:
The widespread adoption of Internet of Things (IoT) devices has introduced numerous vulnerabilities, particularly in firmware over-the-air (OTA) updates. These updates are essential for improving device functionality and addressing security vulnerabilities. However, they have increasingly become the focus of distributed denial of service (DDoS) attacks designed to disrupt the update process. Historically, the infamous Mirai botnet and its variants have exploited IoT vulnerabilities to carry out successful DDoS attacks. In recent years, deep learning models, especially Vision Transformers, have gained significant attention due to their exceptional performance in image classification tasks. To optimize detection and alert mechanisms, this novel study proposes a DDoSViT framework. This Vision Transformer (ViT)-based multi-vector DDoS and DoS attack detection framework converts attack flows into images and trains Vision Transformers on an attack image dataset. To validate the proposed framework, this study extensively reviewed diverse datasets and selected CICIoT2023 and CICIoMT2024 datasets ensuring these contain real-world attack scenarios and multi-vector real attacks. The proposed methodology and rigorous experimentation demonstrated 99.50\% accuracy in multi-class classification across 23 different variants of DDoS and DoS attacks, outperforming contemporary models. The model's performance was assessed using metrics such as accuracy, precision, recall, and F1-score. This research provides significant benefits to security practitioners and administrators, offering reduced false positives and reliable alerts during firmware over-the-air updates in IoT-edge devices.
随着物联网(Internet of Things, IoT)设备的大规模普及,诸多安全漏洞随之涌现,其中尤以固件空中下载(firmware over-the-air, OTA)更新场景下的问题最为突出。此类更新对于优化设备功能、修复安全漏洞至关重要,但近年来却日益成为旨在破坏更新流程的分布式拒绝服务(distributed denial of service, DDoS)攻击的目标。历史上臭名昭著的米拉伊僵尸网络(Mirai botnet)及其衍生变种,便曾利用物联网设备漏洞发起多起成功的DDoS攻击。近年来,深度学习模型,尤其是视觉Transformer(Vision Transformer),凭借其在图像分类任务中的卓越性能获得了广泛关注。为优化攻击检测与预警机制,本研究提出了一种新型DDoSViT框架。该基于视觉Transformer的多向量DDoS与拒绝服务(Denial of Service, DoS)攻击检测框架,将攻击流量转换为图像形式,并基于攻击图像数据集对视觉Transformer模型进行训练。为验证所提框架的有效性,本研究广泛调研了多款公开数据集,最终选取CICIoT2023与CICIoMT2024数据集,因其涵盖真实攻击场景与多向量真实攻击样本。通过所提方法与严谨的实验验证,该框架在针对23种不同变种的DDoS与DoS攻击的多分类任务中实现了99.50%的准确率,优于当前主流模型。本研究采用准确率、精确率、召回率以及F1值作为模型性能评估指标。此项研究为安全从业者与设备管理员提供了显著助力,可有效降低物联网边缘设备在固件OTA更新过程中的误报率,并输出可靠的攻击预警信号。




