COLIDE: a collaborative intrusion detection framework for Internet of Things

Internet of Things (IoT) represent a network of resource‐constrained sensor devices connected through the open Internet, susceptible to misuse by intruders. Traditional standalone intrusion detection systems (IDS) are tasked with monitoring device behaviours to identify malicious activities. These s...

Full description

Bibliographic Details
Main Authors: Junaid Arshad, Muhammad Ajmal Azad, Mohammad Mahmoud Abdellatif, Muhammad Habib Ur Rehman, Khaled Salah
Format: Article
Language:English
Published: Wiley 2019-01-01
Series:IET Networks
Subjects:
Online Access:https://doi.org/10.1049/iet-net.2018.5036
id doaj-df1e3597278d4c269287e07fb7b9d926
record_format Article
spelling doaj-df1e3597278d4c269287e07fb7b9d9262021-08-26T05:35:40ZengWileyIET Networks2047-49542047-49622019-01-018131410.1049/iet-net.2018.5036COLIDE: a collaborative intrusion detection framework for Internet of ThingsJunaid Arshad0Muhammad Ajmal Azad1Mohammad Mahmoud Abdellatif2Muhammad Habib Ur Rehman3Khaled Salah4School of Computing and Engineering, University of West LondonLondonUKSchool of Computing, Newcastle UniversityNewcastle Upon TyneUKFaculty of EngineeringThe British University in EgyptCairoEgyptDepartment of Computer ScienceNational University of Computer and Emerging SciencesLahorePakistanECE DepartmentKhalifa UniversityAbu DhabiUnited Arab EmiratesInternet of Things (IoT) represent a network of resource‐constrained sensor devices connected through the open Internet, susceptible to misuse by intruders. Traditional standalone intrusion detection systems (IDS) are tasked with monitoring device behaviours to identify malicious activities. These systems not only require extensive network and system resources but also cause delays in detecting a malicious actor due to unavailability of a comprehensive view of the intruder's activities. Collaboration among IoT devices enables considering knowledge from a collection of host and network devices to achieve improved detection accuracy in a timely manner. However, collaboration introduces the challenge of energy efficiency and event processing which is particularly significant for resource‐constrained devices. In this paper, we present a collaborative intrusion detection framework (COLIDE) for IoT leveraging collaboration among resource‐constrained sensor and border nodes for effective and timely detection of intruders. The paper presents a detailed formal description of the proposed framework along with analysis to assess its effectiveness for a typical IoT system. We implemented the COLIDE framework with Contiki OS and conducted thorough experimentation to evaluate its performance. The evaluation demonstrates efficiency of COLIDE framework with respect to energy and processing overheads achieving effectiveness within an IoT system.https://doi.org/10.1049/iet-net.2018.5036collaborative intrusion detection frameworkresource‐constrained sensor devicesintrudersnormal service deliverymalicious activitiessystem resources
collection DOAJ
language English
format Article
sources DOAJ
author Junaid Arshad
Muhammad Ajmal Azad
Mohammad Mahmoud Abdellatif
Muhammad Habib Ur Rehman
Khaled Salah
spellingShingle Junaid Arshad
Muhammad Ajmal Azad
Mohammad Mahmoud Abdellatif
Muhammad Habib Ur Rehman
Khaled Salah
COLIDE: a collaborative intrusion detection framework for Internet of Things
IET Networks
collaborative intrusion detection framework
resource‐constrained sensor devices
intruders
normal service delivery
malicious activities
system resources
author_facet Junaid Arshad
Muhammad Ajmal Azad
Mohammad Mahmoud Abdellatif
Muhammad Habib Ur Rehman
Khaled Salah
author_sort Junaid Arshad
title COLIDE: a collaborative intrusion detection framework for Internet of Things
title_short COLIDE: a collaborative intrusion detection framework for Internet of Things
title_full COLIDE: a collaborative intrusion detection framework for Internet of Things
title_fullStr COLIDE: a collaborative intrusion detection framework for Internet of Things
title_full_unstemmed COLIDE: a collaborative intrusion detection framework for Internet of Things
title_sort colide: a collaborative intrusion detection framework for internet of things
publisher Wiley
series IET Networks
issn 2047-4954
2047-4962
publishDate 2019-01-01
description Internet of Things (IoT) represent a network of resource‐constrained sensor devices connected through the open Internet, susceptible to misuse by intruders. Traditional standalone intrusion detection systems (IDS) are tasked with monitoring device behaviours to identify malicious activities. These systems not only require extensive network and system resources but also cause delays in detecting a malicious actor due to unavailability of a comprehensive view of the intruder's activities. Collaboration among IoT devices enables considering knowledge from a collection of host and network devices to achieve improved detection accuracy in a timely manner. However, collaboration introduces the challenge of energy efficiency and event processing which is particularly significant for resource‐constrained devices. In this paper, we present a collaborative intrusion detection framework (COLIDE) for IoT leveraging collaboration among resource‐constrained sensor and border nodes for effective and timely detection of intruders. The paper presents a detailed formal description of the proposed framework along with analysis to assess its effectiveness for a typical IoT system. We implemented the COLIDE framework with Contiki OS and conducted thorough experimentation to evaluate its performance. The evaluation demonstrates efficiency of COLIDE framework with respect to energy and processing overheads achieving effectiveness within an IoT system.
topic collaborative intrusion detection framework
resource‐constrained sensor devices
intruders
normal service delivery
malicious activities
system resources
url https://doi.org/10.1049/iet-net.2018.5036
work_keys_str_mv AT junaidarshad colideacollaborativeintrusiondetectionframeworkforinternetofthings
AT muhammadajmalazad colideacollaborativeintrusiondetectionframeworkforinternetofthings
AT mohammadmahmoudabdellatif colideacollaborativeintrusiondetectionframeworkforinternetofthings
AT muhammadhabiburrehman colideacollaborativeintrusiondetectionframeworkforinternetofthings
AT khaledsalah colideacollaborativeintrusiondetectionframeworkforinternetofthings
_version_ 1721196052008140800