Skip to main content
QUICK REVIEW

[論文レビュー] A Review of Intrusion Detection Systems and Their Evaluation in the IoT

Luca Arnaboldi, C. Morisset|arXiv (Cornell University)|May 17, 2021
Network Security and Intrusion Detection参考文献 86被引用数 5
ひとこと要約

この論文は2008年から2018年までのインターネット・オブ・シングス(IoT)向け侵入検知システム(IDS)に関する51件の研究をレビューし、検知技術、評価手法、実装上の課題を分析している。コード共有、データセット標準化、相互評価の欠如が顕著であることが判明し、IoT IDS研究における統一されたベンチマークと再現可能性の向上が求められている。

ABSTRACT

Intrusion Detection Systems (IDS) are key components for securing critical infrastructures, capable of detecting malicious activities on networks or hosts. The procedure of implementing a IDS for Internet of Things (IoT) networks is not without challenges due to the variability of these systems and specifically the difficulty in accessing data. The specifics of these very constrained devices render the design of an IDS capable of dealing with the varied attacks a very challenging problem and a very active research subject. In the current state of literature, a number of approaches have been proposed to improve the efficiency of intrusion detection, catering to some of these limitations, such as resource constraints and mobility. In this article, we review works on IDS specifically for these kinds of devices from 2008 to 2018, collecting a total of 51 different IDS papers. We summarise the current themes of the field, summarise the techniques employed to train and deploy the IDSs and provide a qualitative evaluations of these approaches. While these works provide valuable insights and solutions for sub-parts of these constraints, we discuss the limitations of these solutions as a whole, in particular what kinds of attacks these approaches struggle to detect and the setup limitations that are unique to this kind of system. We find that although several paper claim novelty of their approach little inter paper comparisons have been made, that there is a dire need for sharing of datasets and almost no shared code repositories, consequently raising the need for a thorough comparative evaluation.

研究の動機と目的

  • 2008年から2018年までのIoT侵入検知システム(IDS)分野における最新状況を分析すること。
  • IoT IDS研究で用いられる一般的な技術、評価指標、展開戦略を特定すること。
  • 既存の研究における再現性および相互評価の欠如を調査すること。
  • 共有データセット、コードリポジトリ、標準化された評価フレームワークの欠如を強調すること。
  • 新しいIDS技術の開発から、ツールの使いやすさ、相互運用性、再現可能性の向上へのシフトを提唱すること。

提案手法

  • 2008年から2018年までに発表されたIoTシステムを対象とした51件のIDS論文を対象に系統的文献レビューを実施した。
  • 実装および評価アプローチ(例:シミュレーション、実際のテストベッド、コードの可用性)に基づいて論文を4つのカテゴリーに分類した。
  • 84名の著者にカスタマイズされたメールテンプレートを送信し、ソースコードおよびデータセットへのアクセスを要請した。
  • 構造的なアプローチキャンペーンを通じて、ツールの可用性と使いやすさを評価した。
  • 文献で用いられた評価指標を分析し、正確性、偽陽性率、実際の展開可能性に注目した。
  • Etalle(2019)が提唱する標準化された評価指標の使用を提案し、比較可能性およびツールの適正性評価を向上させた。

実験結果

リサーチクエスチョン

  • RQ12008年から2018年までのIoT IDS研究で、主流の検知技術およびアーキテクチャは何か?
  • RQ2コードおよびデータセットの共有が不足しているため、既存のIoT IDSツールの再現性はどの程度に制限されているか?
  • RQ3類似した研究目的を持つにもかかわらず、異なるIDSアプローチ間での相互評価がなぜ稀であるのか?
  • RQ4特に使いやすさおよび実世界での展開に伴うオーバーヘッドを考慮した場合、現在のIoT IDS評価手法における主な制限要因は何か?
  • RQ5標準化された評価フレームワークは、今後のIoT IDSソリューションの開発および比較をどのように改善できるか?

主な発見

  • 調査された51件のIDS論文のうち、わずか4件しか公開コードを提供しておらず、そのうち1つのツールのみが公開リポジトリ(GitHub)を通じて入手可能であった。
  • 84名の著者に連絡したが、返信があったのは1名のみで、そのコード実装も公開されていなかった。
  • 大多数の研究(51件中46件)はコードやデータセットを一切提供しておらず、再現性および比較評価が著しく制限されていた。
  • 多くの研究が古く、標準でないデータセットに依存しており、KDD99データセットでさえ、そのリリースから約20年も経っても依然として使用されていた。
  • 統一された評価手法が著しく欠如しており、指標の不一致と、実用的な使いやすさや展開オーバーヘッドへの注目が極めて少なかった。
  • 共有ツールやデータセットの欠如により、研究コミュニティは先行研究を十分に発展させられておらず、科学的進展の蓄積が妨げられていた。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。