Electronic Thesis/Dissertation
 

Implementing Machine Learning to achieve dynamic Zero-Trust Intrusion Detection Systems (ZT-IDS) in 5G based IoT Networks

Open Access

The Internet of Things (IoT) pertains to devices that link to a network to gather and exchange data. With the increasing quantity of such devices, so do the associated security risks. With the growth of IoT and the increase in sophisticated intrusions, research is being conducted to enhance attack detection capabilities. However, IoT devices' limited energy capacity and scalability present significant challenges in addressing privacy and security concerns. Limited energy capacity can impact encryption by restricting the processing power available for implementing robust encryption algorithms and authentication mechanisms, which need processing power, increasing the risk of unauthorized access and compromising privacy. Weaker security measures, such as shorter encryption keys or less frequent security updates, could make IoT devices more susceptible to attacks. Furthermore, it can make it challenging for IoT devices to receive regular firmware and software updates, including security patches. Outdated software leaves devices exposed to known vulnerabilities, Limited energy capacity may also lead to less secure physical components, which can be more easily tampered with or compromised. Furthermore, the widespread integration of IoT devices across diverse industries has led to an increase in cyberattacks targeting these devices and their networks. The lack of a zero-trust approach further exacerbates the security risks associated with IoT devices. Zero trust is a security design approach that requires strict authentication and authorization measures for every access attempt, regardless of the source or location. Intruders can access IoT devices and networks without such measures, potentially compromising sensitive data and systems. Hence, by adopting a zero-trust strategy, the impact of IoT intrusions can be mitigated by reducing the attack surface and enhancing control over resource access. IoT devices' storage and processing capabilities are often limited, making it difficult for them to support advanced Intrusion Detection Systems. Consequently, cyber attackers leverage these device vulnerabilities to gain access to other systems linked to the same network. To overcome this problem, many organizations opt for Edge layer data centers that process IoT user traffic closer to the end user, reducing latency. These smaller facilities are interconnected to a larger central data center at the backend network's core. Nevertheless, the Edge layer also encounters power and processing limitations that must be addressed. 5G represents the most recent advancement in cellular network technology, offering several benefits, with one of the key advantages being low latency. Low latency refers to the time data travels between endpoints. With 5G, latency can be reduced to below one millisecond, enabling near real-time communication between devices. However, this low latency also means that intrusion detection systems must be fast enough to keep up with the high-speed data transfer rates of 5G networks. If the intrusion detection system is too slow, it can become a bottleneck in the network, causing delays and reducing the overall data transfer speed. Therefore, intrusion detection systems must be designed to be fast and efficient enough to operate seamlessly in 5G networks and ensure that security risks are identified and addressed on time. In order to address these challenges, a proposed solution involves implementing an ML Intrusion Detection System within a zero-trust framework. This system aims to enhance security for IoT devices connected to 5G networks through the Edge layer. (HaddadPajouh et al., 2020). This system can detect and classify malicious network traffic in real-time while operating in a power-constrained environment like a 5G Edge layer data center. The system monitors the traffic of end-user IoT devices before sending it to the 5G core network for further processing. Several datasets representing multiple IoT industries have been used to train and test the system, which contains over 5 million records of simulated traffic and real one. The goal is to develop an effective intrusion detection system that can work within the constraints of the Edge layer environment while providing adequate security for IoT devices. Seven supervised ML models are developed and evaluated to classify several types of attacks. These models include bagging, boosting and neural networks algorithms. The research concludes that a machine learning model can accurately detect and classify intrusions in real time. The Decision Tree (DT-CART) and Extreme Gradient Boosting (XGB) classifiers outperforms the other models, with the combined performance accuracy metrics, lowest false alarm rate, and shortest classification time per record, making it suitable for processing-constrained environments like 5G IoT devices connected to Edge layers.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Nour_gwu_0075A_16505.pdf Nour_gwu_0075A_16505.pdf 2023-11-14 Open Access