[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119206-en":3,"doc-seo-119206-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119206,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","BEHAVIOUR-BASED SECURITY WITH MACHINE LEARNING ON IOT NETWORKS - Doctor of Philosophy Thesis","Internet of Things (IoT) deployments have expanded human connectivity while introducing serious security risks caused by device heterogeneity and limited on-device resources. This thesis develops reliable, reproducible IoT security measures for device identification (DI) and attack detection (AD), aiming to overcome shortcomings in prior work regarding heterogeneity handling, leakage-feature analysis, interpretability, and reproducibility. For DI, it proposes a novel aggregation algorithm for IP and non-IP devices with an optimal feature set validated on diverse datasets. For AD, it introduces packet-level expanding and rolling windows for earlier detection and evaluates adaptability on isolated first-time-seen attacks. The research links DI and AD to mutually reinforce network safety.","BEHAVIOUR-BASED SECURITY WITH MACHINE LEARNING ON IOT NETWORKS  \nby  \nKahraman Kostas  \nSubmitted for the degree of  \nDoctor of Philosophy  \nDepartment of Computer Science  \nSchool of Mathematical and Computer Sciences Heriot-Watt University  \nOctober 2023  \nSupervised by Dr Mike Just & Dr Michael A. Lones  \nThe copyright in this thesis is owned by the author. Any quotation from the thesis or use of any of the information contained in it must acknowledge this thesis as the source of the quotation or information.  \nAbstract  \nThe proliferation of Internet of Things (IoT) devices has transformed various aspects of human life, yet has brought forth significant security challenges due to device heterogeneity and limited resources. Addressing this, the thesis focuses on reliable and reproducible IoT security measures, specifically device identification (DI) and attack detection (AD) . With over 10 billion devices currently connected and a projected 80 billion by 2026, securing IoT devices is critical. Traditional security approaches face hurdles due to device diversity, while IoT devices are prone to rapid attacks. Behaviour-based methods, particularly utilising machine learning, offer potential solutions for both DI and AD. However, existing studies suffer from limitations in addressing IoT heterogeneity, analysing information leakage features, understanding machine learning insights, and ensuring reproducibility.  \nThis research aims to bridge these gaps by developing robust, transparent, and generalizable solutions for IoT DI and AD. For DI, a novel aggregation algorithm addresses IP and non-IP device challenges, significantly improving accuracy. Comprehensive featureselection results in an optimal feature set, validated across diverse datasets. In AD, a packet-level expanding and rolling windows method detects attacks earlier, outperforming conventional flow methods. The models are evaluated on isolated first-time-seen attack datasets, showcasing their adaptability to novel attacks. Furthermore, machine learning models and features are analysed for deeper attack insights.  \nThe thesis underscores the interdependence of device identification and attack detection within IoT security, emphasising their mutual reinforcement for network safety. By offering reproducible methodologies, transparent analyses, and adaptable models, this work contributes to enhancing the security of IoT devices and networks. Ultimately, this research paves the way for a more secure IoT ecosystem by addressing the unique challenges posed by IoT heterogeneity, resource limitations, and dynamic attack patterns.  \nKeywords: IoT security, fingerprinting, machine learning, device identification, attack detection  \nbenem ol kahram¯an-ı p¨ur-h¨uner kim elimde ˆh¯amed¨ur ¸sem¸s¯ir-i g˙amg˙am  \nSabri (Divan: K. 14/24) [249]  \nAcknowledgements  \nI would like to extend my heartfelt gratitude to the Turkish Ministry of National Education for their unwavering support, covering my living expenses and tuition fees during my PhD. This scholarship was not only a financial aid but a testament to their belief in my potential. I would also like to express my profound appreciation to my guarantorsand dear friends, Zehra, Fadime, and Hatice, who took on a considerable responsibility to ensure my academic journey. Your trust and support were invaluable.  \nI am deeply indebted to my exceptional supervisors, Dr Mike Just and Dr Michael Lones, who not only guided my PhD studies but also served as remarkable mentors and friends. Their continuous support and expertise significantly contributed to the quality and depth of my research.  \nDr Wei Pang played a pivotal role by diligently reviewing my studies during my PhD journey, and offering valuable advice and guidance that enhanced the quality of my work.  \nDuring my industrial internship, I had the privilege of working under the guidance of Dr Firas Alsehly and Dr Francisco Zampella. Their mentorship and camaraderie made the experien","cbCaiezIpkRKLJO3","https://ap.wps.com/l/cbCaiezIpkRKLJO3","pdf",20962686,1,287,"English","en",105,"# Abstract\n# Keywords\n## Device identification (DI)\n## Attack detection (AD)\n## Model evaluation and insights\n# Acknowledgements\n# Declaration","[{\"question\":\"Why does the thesis focus on behaviour-based security for IoT networks?\",\"answer\":\"IoT devices differ widely and have constrained resources, while attackers can act quickly. Behaviour-based machine learning aims to address these challenges through more adaptable security mechanisms for identification and detection.\"},{\"question\":\"What approach does the thesis propose for device identification (DI)?\",\"answer\":\"It introduces a novel aggregation algorithm to handle both IP and non-IP devices, combined with comprehensive feature selection to produce an optimal feature set validated across diverse datasets.\"},{\"question\":\"How does the thesis detect attacks in attack detection (AD)?\",\"answer\":\"It uses a packet-level method based on expanding and rolling windows to detect attacks earlier than conventional flow-based approaches, and evaluates models on isolated first-time-seen attack datasets.\"}]","BEHAVIOUR-BASED SECURITY WITH MACHINE LEARNING ON IOT NETWORKS - Doctor of Philosophy Thesis | PDF",1785723099,723,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"behaviour-based-security-with-machine-learning-on-iot-networks-doctor-of-philosophy-thesis","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/behaviour-based-security-with-machine-learning-on-iot-networks-doctor-of-philosophy-thesis/119206/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why does the thesis focus on behaviour-based security for IoT networks?","Question",{"text":75,"@type":76},"IoT devices differ widely and have constrained resources, while attackers can act quickly. Behaviour-based machine learning aims to address these challenges through more adaptable security mechanisms for identification and detection.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What approach does the thesis propose for device identification (DI)?",{"text":80,"@type":76},"It introduces a novel aggregation algorithm to handle both IP and non-IP devices, combined with comprehensive feature selection to produce an optimal feature set validated across diverse datasets.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the thesis detect attacks in attack detection (AD)?",{"text":84,"@type":76},"It uses a packet-level method based on expanding and rolling windows to detect attacks earlier than conventional flow-based approaches, and evaluates models on isolated first-time-seen attack datasets.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]