ARP Spoofing Attack Detection Model in IoT Network using Machine Learning: Complexity vs. Accuracy
Abstract
Spoofing attacks targeting the address resolution protocol, or the so-called ARP, are common cyber-attacks in IoT environments. In such an attack, the attacker sends a fake message over a local area network to spoof the users and interfere with the communication transferred from and into these users. As such, to detect such attacks, there is a need to check the network gateways and routers continuously to capture and analyze the transmitted traffic. However, there are three major problems with such traffic data: 1) there are substantial irrelevant data to the ARP attacks, 2) there are massive patterns in the way by which the spoof can be implemented, and 3) there is a need for fast processing of such data to reduce any delay resulting from the processing stage. Accordingly, this paper proposes a detection approach using supervised machine learning algorithms. The focus of this paper is to show the tradeoff between speed and accuracy to offer various solutions based on the demanded quality. Various algorithms were tested to find a solution that balanced time requirements and accuracy. As such, the results using all features and with various feature selection techniques were reported. Besides, the results using simple classifiers and ensemble learning algorithms were also reported. The proposed approach is evaluated on an IoT network intrusion dataset (IoTID20) collected from different IoT devices. The results showed that the highest accuracy is obtained using the RF classifier with a subset of features produced by the wrapper technique. In such a case, the accuracy obtained was 99.74%, with running time equal to 305 milliseconds. However, If time is more critical for a given application, then DT can be used with the whole feature set. In such a case, the accuracy was 99.41%, with running time equal to 11 milliseconds.
Keywords
Full Text:
PDFReferences
W. a. Kassab and K. A. Darabkh, "A–Z survey of Internet of Things: Architectures, protocols, applications, recent advances, future directions and recommendations," Journal of Network and Computer Applicationsvol. 163, p. 102663, 2020.
A. Saaidah, O. Almomani, L. Al-Qaisi, N. Alsharman, and F. Alzyoud, "A comprehensive survey on node metrics of RPL protocol for IoT," Mod. Appl. Sci, vol. 13, no. 1, 2019.
R. Chataut, A. Phoummalayvane, and R. Akl, "Unleashing the power of IoT: A comprehensive review of IoT applications and future prospects in healthcare, agriculture, smart homes, smart cities, and industry 4.0," Sensors, vol. 23, no. 16, p. 7194, 2023.
O. Almomani, A. Alsaaidah, A. A. A. Shareha, A. Alzaqebah, and M. Almomani, "Performance Evaluation of Machine Learning Classifiers for Predicting Denial-of-Service Attack in Internet of Things," International Journal of Advanced Computer Science Applications, vol. 15, no. 1, 2024.
M. Kolhar, F. Al-Turjman, A. Alameen, and M. M. Abualhaj, "A three layered decentralized IoT biometric architecture for city lockdown during COVID-19 outbreak," IEEE Access, vol. 8, pp. 163608-163617, 2020.
Q. Y. Shambour, M. M. Abu-Alhaj, and M. M. Al-Tahrawi, "A hybrid collaborative filtering recommendation algorithm for requirements elicitation," International Journal of Computer Applications in Technology, vol. 63, no. 1-2, pp. 135-146, 2020.
H. F. Atlam and G. B. Wills, "IoT security, privacy, safety and ethics smart cities," in Digital twin technologies 2020, pp. 123-149.
S. SMADI, M. ALAUTHMAN, O. ALMOMANI, A. SAAIDAH, and F. ALZOBI, "Application layer denial of services attack detection based on stacknet," Int. J, vol. 3929, no. 3936, pp. 2278-3091, 2020.
D. Javeed, U. MohammedBadamasi, C. O. Ndubuisi, F. Soomro, and M. Asif, "Man in the middle attacks: Analysis, motivation and prevention," International Journal of Computer Networks Communications Security vol. 8, no. 7, pp. 52-58, 2020.
S. Zaman et al., "Security threats and artificial intelligence based countermeasures for internet of things networks: a comprehensive survey," IEEE Access, vol. 9, pp. 94668-94690, 2021.
S. Banyal and D. K. Sharma, "Security vulnerabilities, challenges, and schemes in IoT-enabled technologies," in Blockchain Technology for Data Privacy Management: CRC Press, 2021, pp. 81-108.
N. M. Karie, N. M. Sahri, and P. Haskell-Dowland, "IoT threat detection advances, challenges and future directions," in 2020 workshop on emerging technologies for security in IoT (ETSecIoT), Sydney, Australia, 2020, pp. 22-29: IEEE.
M. A. Almaiah et al., "Performance investigation of principal component analysis for intrusion detection system using different support vector machine kernels," Electronics, vol. 11, no. 21, p. 3571, 2022.
O. Almomani, M. A. Almaiah, A. Alsaaidah, S. Smadi, A. H. Mohammad, and A. Althunibat, "Machine learning classifiers for network intrusion detection system: comparative study," in 2021 International Conference on Information Technology (ICIT), Amman , Jordan, 2021, pp. 440-445: IEEE.
O. Almomani, M. A. Almaiah, M. Madi, A. Alsaaidah, M. A. Almomani, and S. Smadi, "Reconnaissance attack detection via boosting machine learning classifiers," in AIP Conference Proceedings, Amman , Jordan, 2023, vol. 2979, no. 1: AIP Publishing.
A. Almomani et al., "Ensemble-Based Approach for Efficient Intrusion Detection in Network Traffic," Intelligent Automation Soft Computing, vol. 37, no. 2, 2023.
A. Heidari and M. A. Jabraeil Jamali, "Internet of Things intrusion detection systems: a comprehensive review and future directions," Cluster Computing, vol. 26, no. 6, pp. 3753-3780, 2023.
P. K. Keserwani, M. C. Govil, E. S. Pilli, and Applications, "An effective NIDS framework based on a comprehensive survey of feature optimization and classification techniques," Neural Computing Applications, vol. 35, no. 7, pp. 4993-5013, 2023.
S. Venkatesan, "Design an intrusion detection system based on feature selection using ML algorithms," Mathematical Statistician Engineering Applications, vol. 72, no. 1, pp. 702-710, 2023.
O. Almomani, "A feature selection model for network intrusion detection system based on PSO, GWO, FFA and GA algorithms," Symmetry, vol. 12, no. 6, p. 1046, 2020.
O. Almomani, "A Hybrid Model Using Bio-Inspired Metaheuristic Algorithms for Network Intrusion Detection System," Computers, Materials, Continua, vol. 68, no. 1, 2021.
M. Alsharaiah et al., "A new phishing-website detection framework using ensemble classification and clustering," International Journal of Data and Network Science, vol. 7, no. 2, pp. 857-864, 2023.
S. T. Revathi and N. Ramaraj, "A brief study about nature inspired optimisation algorithms," International Journal of Advanced Intelligence Paradigms, vol. 28, no. 1-2, pp. 1-15, 2024.
X.-S. Yang, "Firefly algorithm, stochastic test functions and design optimisation," International journal of bio-inspired computation, vol. 2, no. 2, pp. 78-84, 2010.
H. Xu, S. Yu, J. Chen, and X. Zuo, "An improved firefly algorithm for feature selection in classification," Wireless Personal Communications, vol. 102, no. 1, pp. 2823-2834, 2018.
K. Chaudhary, "A Modified Firefly Algorithm for Solving Optimization Problems," International Journal of Computational Intelligence and Applications, p. 2450012, 2024.
M. Alsoul, H. Zaher, N. Ragaa, and E. M. Oun, "A New Efficient Hybrid Approach for Machine Learning-Based Firefly Optimization," Iraqi Journal of Science, pp. 4600-4612, 2023.
A. Song, H. Qiao, Y. Huang, S. Ai, W. Xu, and H. Li, "Dynamic economic dispatch based on improve firefly optimization algorithm," presented at the 6th International Electrical and Energy Conference (CIEEC), Hefei · China, 12-14 May, 2023.
B. Selvakumar and K. Muneeswaran, "Firefly algorithm based feature selection for network intrusion detection," Computers & Security, vol. 81, pp. 148-155, 2019.
S. Rajabi, S. Jamali, and J. Javidan, "An intrusion detection system in computer networks using the firefly algorithm and the fast learning network," International Journal of Web Research, vol. 3, no. 1, pp. 50-56, 2020.
P. Ghosh, D. Sarkar, J. Sharma, and S. Phadikar, "An intrusion detection system using modified-firefly algorithm in cloud environment," International Journal of Digital Crime Forensics, vol. 13, no. 2, pp. 77-93, 2021.
A. H. Mohammad, T. Alwada'n, O. Almomani, S. Smadi, and N. ElOmari, "Bio-inspired Hybrid Feature Selection Model for Intrusion Detection," Computers, Materials, Continua, vol. 73, no. 1, pp. 133-150, 2022.
Hyunjae Kang, Dong Hyun Ahn, Gyung Min Lee, Jeong Do Yoo, Kyung Ho Park, and H. KangKim. (2019). IoT Network Intrusion Dataset. 2019. Available online: https://ieee-dataport.org/open-access/iot-network-intrusion-dataset (accessed on 9 February 2023).
K. Albulayhi, Q. Abu Al-Haija, S. A. Alsuhibany, A. A. Jillepalli, M. Ashrafuzzaman, and F. T. Sheldon, "IoT intrusion detection using machine learning with a novel high performing feature selection method," Applied Sciences, vol. 12, no. 10, p. 5015, 2022.
I. Ullah and Q. H. Mahmoud, "A scheme for generating a dataset for anomalous activity detection in iot networks," in Canadian conference on artificial intelligence, Ottawa (virtual), 2020, pp. 508-520: Springer.
DOI: https://doi.org/10.47738/jads.v5i4.374
Refbacks
- There are currently no refbacks.

Journal of Applied Data Sciences
| ISSN | : | 2723-6471 (Online) |
| Publisher | : | Bright Publisher |
| Website | : | http://bright-journal.org/JADS |
| : | taqwa@amikompurwokerto.ac.id (principal contact) | |
| support@bright-journal.org (technical issues) |
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0




.png)