MedBIoT: Generation of an IoT botnet dataset in a medium-sized IoT network

Alejandro Guerra-Manzanares, Jorge Medina-Galindo, Hayretdin Bahsi, Sven Nõmm

Research output: Chapter in Book/Conference proceedingConference contributionpeer-review

97 Citations (Scopus)

Abstract

The exponential growth of the Internet of Things in conjunction with the traditional lack of security mechanisms and resource constraints associated with these devices have posed new risks and challenges to security in networks. IoT devices are compromised and used as amplification platforms by cyber-attackers, such as DDoS attacks. Machine learning-based intrusion detection systems aim to overcome network security limitations relying heavily on data quantity and quality. In the case of IoT networks these data are scarce and limited to small-sized networks. This research addresses this issue by providing a labelled behavioral IoT data set, which includes normal and actual botnet malicious network traffic, in a medium-sized IoT network infrastructure (83 IoT devices). Three prominent botnet malware are deployed and data from botnet infection, propagation and communication with C&C stages are collected (Mirai, BashLite and Torii). Binary and multi-class machine learning classification models are run on the acquired data demonstrating the suitability and reliability of the generated data set for machine learning-based botnet detection IDS testing, design and deployment. The generated IoT behavioral data set is released publicly available as MedBIoT data set.

Original languageEnglish
Title of host publicationICISSP 2020 - Proceedings of the 6th International Conference on Information Systems Security and Privacy
EditorsSteven Furnell, Paolo Mori, Edgar Weippl, Olivier Camp
PublisherSciTePress
Pages207-218
Number of pages12
ISBN (Electronic)9789897583995
DOIs
Publication statusPublished - 2020
Externally publishedYes
Event6th International Conference on Information Systems Security and Privacy, ICISSP 2020 - Valletta, Malta
Duration: 25 Feb 202027 Feb 2020

Publication series

NameICISSP 2020 - Proceedings of the 6th International Conference on Information Systems Security and Privacy

Conference

Conference6th International Conference on Information Systems Security and Privacy, ICISSP 2020
Country/TerritoryMalta
CityValletta
Period25/02/2027/02/20

Keywords

  • Anomaly detection
  • Botnet
  • Dataset
  • Internet of Things
  • Intrusion detection
  • IoT

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Information Systems
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'MedBIoT: Generation of an IoT botnet dataset in a medium-sized IoT network'. Together they form a unique fingerprint.

Cite this