Cargando...
Fecha
2024-10-08
Derechos de acceso
info:eu-repo/semantics/openAccess
Título de la revista
ISSN de la revista
Título del volumen
Editorial
Resumen
La ciberseguridad establece mecanismos para garantizar la seguridad de las redes de comunicaciones. Es un elemento fundamental para asegurar la integridad de la información, la disponibilidad de servicios y la confidencialidad. El auge del internet de las cosas (IoT) ha supuesto la aparición de nuevos desafíos para los sistemas de seguridad. La heterogeneidad, el volumen y la capacidad de cómputo de los dispositivos IoT requieren técnicas específicas de seguridad. Existen diversas líneas de investigación a propósito de sistemas de detección de intrusiones (IDS) adecuados para este tipo de redes.
Una línea de investigación actual propone modelar el comportamiento normal de una red a partir de métricas de centralidad calculadas desde los grafos que representan sus comunicaciones. Este enfoque reduce el volumen de información a procesar por el IDS y permite distribuir el análisis de intrusiones entre los dispositivos conectados, delegando inclusive esta función a los dispositivos IoT u otros próximos al perímetro de la red. Sin embargo, la elección de métricas apropiadas y el tiempo necesario para su obtención suponen un desafío. Este trabajo ha profundizado en la eficiencia de la obtención de las métricas y la influencia en la eficacia de la predicción de ataques con modelos de aprendizaje automático. Se han comparado diferentes agrupaciones de métricas de centralidad y cuantificado la eficiencia y eficacia de estas combinaciones con el objetivo de facilitar la selección de métricas para los IDS.
Se ha comprobado que la utilización de métricas que puedan calcularse en los propios dispositivos supone una ventaja de eficiencia sobre algoritmos de cálculo globales. Se dispone más rápidamente de la métrica en el dispositivo, se distribuye la carga computacional y se aumenta la tolerancia a errores. Igualmente, se ha verificado que incluir un conjunto adecuado de métricas para una red afecta a la eficacia de los modelos de predicción de ataques. La combinación de todas VII las métricas bajo estudio ha supuesto la aparición de ruido que ha disminuido la precisión y sensibilidad en la detección de ataques. A su vez, la métrica Closeness aumenta significativamente la capacidad de predicción de ataques, en comparación con el resto de métricas evaluadas, para el conjunto de datos utilizado.
Cybersecurity establishes mechanisms to ensure the security of communications within networks. It is a fundamental element for guaranteeing the integrity of information, the availability of services, and confidentiality. The rise of the Internet of Things (IoT) has introduced new challenges for security systems. The heterogeneity, volume, and computing capacity of IoT devices require specific security techniques. New intrusion detection systems (IDS) have been proposed to adapt to these types of networks. A current line of research aims to model the normal behavior of a network using centrality metrics calculated from graphs that represent its communications. This approach reduces the volume of information processed by the IDS and allows the distribution of intrusion analysis among connected devices, potentially delegating this function to IoT devices or others near the network edge. However, the selection of appropriate metrics and the time required to obtain them pose a challenge. This work delves into the efficiency of metric calculation and their influence on the effectiveness of attack prediction using machine learning models. Different groupings of centrality metrics have been compared, and the efficiency and effectiveness of these combinations have been quantified with the goal of facilitating metric selection for IDS. It has been demonstrated that the use of metrics that can be computed directly on the devices provides an efficiency advantage over global computation algorithms. The metric is available more quickly on the device, the computational load is distributed, and error tolerance is increased. Additionally, it has been verified that including an appropriate set of metrics for a network impacts the effectiveness of attack prediction models. The combination of all metrics under study resulted in noise, which decreased the precision and recall of attack detec- IX tion. Furthermore, Closeness metric significantly enhances the attack prediction capability compared to the other metrics evaluated, for the dataset used.
Cybersecurity establishes mechanisms to ensure the security of communications within networks. It is a fundamental element for guaranteeing the integrity of information, the availability of services, and confidentiality. The rise of the Internet of Things (IoT) has introduced new challenges for security systems. The heterogeneity, volume, and computing capacity of IoT devices require specific security techniques. New intrusion detection systems (IDS) have been proposed to adapt to these types of networks. A current line of research aims to model the normal behavior of a network using centrality metrics calculated from graphs that represent its communications. This approach reduces the volume of information processed by the IDS and allows the distribution of intrusion analysis among connected devices, potentially delegating this function to IoT devices or others near the network edge. However, the selection of appropriate metrics and the time required to obtain them pose a challenge. This work delves into the efficiency of metric calculation and their influence on the effectiveness of attack prediction using machine learning models. Different groupings of centrality metrics have been compared, and the efficiency and effectiveness of these combinations have been quantified with the goal of facilitating metric selection for IDS. It has been demonstrated that the use of metrics that can be computed directly on the devices provides an efficiency advantage over global computation algorithms. The metric is available more quickly on the device, the computational load is distributed, and error tolerance is increased. Additionally, it has been verified that including an appropriate set of metrics for a network impacts the effectiveness of attack prediction models. The combination of all metrics under study resulted in noise, which decreased the precision and recall of attack detec- IX tion. Furthermore, Closeness metric significantly enhances the attack prediction capability compared to the other metrics evaluated, for the dataset used.
Descripción
LÍNEA 11: Tecnología Electrónica Avanzada, Comunicaciones y Computadores
Categorías UNESCO
Palabras clave
ciberataque, IoT, grafo de comunicación, métricas de centralidad, cyberattack, IoT, communication graph, centrality metrics
Citación
Concejal Muñoz, David. Trabajo Fin de Máster: Evaluación comparativa de métricas de centralidad para la detección de intrusiones en redes IoT. Universidad Nacional de Educación a Distancia (UNED) 2024
Centro
E.T.S. de Ingenieros Industriales
Departamento
Sistemas de Comunicación y Control

