PAMS: Um Arcabouço para Detecção de Intrusão em Internet das Coisas

  • Jan Martins Teixeira UFF
  • Ian Vilar Bastos UERJ
  • Dalbert M. Mascarenhas CEFET-RJ
  • Igor Monteiro Moraes UFF

Resumo


A detecção de intrusão em Internet das Coisas baseada em aprendizado de máquina supervisionado enfrenta um gargalo crítico: o sobreajuste às assinaturas de ataque do domínio de treino, que impede a generalização para redes com perfis de protocolo distintos. Este trabalho investiga as causas dessa fragilidade e propõe o arcabouço Protocol-Aware Modeling System (PAMS), que modela exclusivamente o comportamento benigno e sinaliza como anomalia qualquer desvio desse padrão. O PAMS combina um Autoencoder Variacional e um Deep SVDD, cujos scores são integrados por rank-based fusion invariante à escala e calibrados por grupo de protocolo. Avaliado em quatro conjuntos do Canadian Institute for Cybersecurity sob regime de rodízio interdomínio, o PAMS foi o único modelo a manter desempenho consistente nos três domínios de teste, superando modelos supervisionados e métodos clássicos de detecção de anomalia.

Referências

Baena, E., Yang, H., Koutsonikolas, D., and Haque, I. (2025). A comprehensive survey on smart home iot fingerprinting: From detection to prevention and practical deployment.

Bezerra, V. H., da Costa, V. G. T., Martins, R. A., Junior, S. B., Miani, R. S., and Zarpelão, B. B. (2018). Providing iot host-based datasets for intrusion detection research. In Anais do XVIII Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSEG), pages 15–28, Porto Alegre, RS, Brasil. SBC.

Bochie, K., Gonzalez, E., Giserman, L., Campista, M., and Costa, L. (2020). Detecção de ataques a redes iot usando técnicas de aprendizado de máquina e aprendizado profundo. In Anais do XX Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais (SBSEG), pages 257–270, Porto Alegre, RS, Brasil. SBC.

chethuhn (2021). Network intrusion dataset. [link]. Acesso em: 23-11-2025.

Chu, H.-C. and Lin, Y.-J. (2023). Improving the iot attack classification mechanism with data augmentation for generative adversarial networks. Applied Sciences, 13(23).

Churcher, A., Ullah, R., Ahmad, J., ur Rehman, S., Masood, F., Gogate, M., Alqahtani, F., Nour, B., and Buchanan, W. J. (2021). An experimental analysis of attack classification using machine learning in iot networks. Sensors, 21(2).

Croux, C. and Haesbroeck, G. (1999). Influence function and efficiency of the minimum covariance determinant scatter matrix estimator. Journal of Multivariate Analysis, 71(2):161–190.

Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., and Janicke, H. (2022). Edge-iiotset: A new comprehensive realistic cyber security dataset of iot and iiot applications: Centralized and federated learning.

Gao, X., Xie, D., Zhang, Y., Wang, Z., He, C., Yin, H., and Zhang, W. (2025). A comprehensive survey on imbalanced data learning. [link]. arXiv preprint arXiv:2502.08960.

Habibi Lashkari, A. (2018). Cicflowmeter-v4.0: A network traffic bi-flow generator and analyser for anomaly detection.

Hayashi, T., Cimr, D., Fujita, H., and Cimler, R. (2026). Critical review for one-class classification: Recent advances and reality behind them. WIREs Data Mining and Knowledge Discovery, 16(1).

Hozouri, A., Mirzaei, A., and Effatparvar, M. (2025). A comprehensive survey on intrusion detection systems with advances in machine learning, deep learning and emerging cybersecurity challenges. Discover Artificial Intelligence, 5(1):314.

KimiNewt (2025). Pyshark: A python wrapper for tshark, allowing python packet analysis using wireshark dissectors. [link].

Kingma, D. P. and Welling, M. (2013). Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114.

Koroniotis, N., Moustafa, N., Sitnikova, E., and Turnbull, B. (2018). Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset.

Liu, F. T., Ting, K. M., and Zhou, Z.-H. (2008). Isolation forest. In 2008 eighth ieee international conference on data mining, pages 413–422. Ieee.

Lopes, D., Marotta, M., Ladeira, M., and Gondim, J. (2022). Detecção de botnets baseada na análise de fluxos de rede utilizando estatística inversa. In Anais do XL Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos, pages 182–195, Porto Alegre, RS, Brasil. SBC.

Manzini, S. C., Fernandes, B. d. S., de Souza, N. B. P., and Servare Junior, M. W. J. (2025). Revisão da literatura nacional sobre o uso da inteligência artificial no contexto do lean manufacturing. South American Development Society Journal, 11(32):331–350.

Miranda, B. and Braga, J. (2025). Iot e a gestão de recursos hídricos na agricultura de precisão: Uma revisão sistemática. In Anais da XIII Escola Regional de Informática de Goiás, pages 195–204, Porto Alegre, RS, Brasil. SBC.

Morshedi, R. and Matinkhah, S. M. (2025). A comprehensive review of deep learning techniques for anomaly detection in iot networks: Methods, challenges, and datasets. Engineering Reports, 7(9):e70415.

Moustafa, N. (2019a). The bot-iot dataset.

Moustafa, N. (2019b). Toniotdatasets.

Neto, E. C. P., Dadkhah, S., Ferreira, R., Zohourian, A., Lu, R., and Ghorbani, A. A. (2023). Ciciot2023: A real-time dataset and benchmark for large-scale attacks in iot environments. Sensors, 23(13).

Pekar, A. and Jozsa, R. (2024). Evaluating ml-based anomaly detection across datasets of varied integrity: A case study. Computer Networks, 251:110617.

Pereira, R., Costa, Y., and Jr., C. S. (2021). Lidando com o desbalanceamento em problemas de classificação hierárquica com reamostragem de dados. In Anais Estendidos do XXI Simpósio Brasileiro de Computação Aplicada à Saúde, pages 13–18, Porto Alegre, RS, Brasil. SBC.

Rabbani, M., Gui, J., Nejati, F., Zhou, Z., Kaniyamattam, A., Mirani, M., Piya, G., Opushnyev, I., Lu, R., and Ghorbani, A. A. (2025). Device identification and anomaly detection in iot environments. IEEE Internet of Things Journal, 12(10):13625–13643.

Rehman, A. U., Lu, S., Bin Heyat, M. B., Iqbal, M. S., Parveen, S., Bin Hayat, M. A., Akhtar, F., Ashraf, M. A., Khan, O., Pomary, D., and Sawan, M. (2025). Internet of things in healthcare research: Trends, innovations, security considerations, challenges and future strategy. International Journal of Intelligent Systems, 2025(1):8546245.

Ruff, L., Vandermeulen, R., Goernitz, N., Deecke, L., Siddiqui, S. A., Binder, A., Müller, E., and Kloft, M. (2018). Deep one-class classification. In International Conference on Machine Learning (ICML), pages 4393–4402. PMLR.

scikit-learn (2025). scikit-learn: Machine learning in python. [link].

Sharafaldin, I., Lashkari, A. H., and Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In International Conference on Information Systems Security and Privacy.

Silva, B. R., Silveira, R. J., Silva Neto, M. G. d., Cortez, P. C., and Gomes, D. G. (2021). A comparative analysis of undersampling techniques for network intrusion detection systems design. Journal of Communication and Information Systems, 36(1):31–43.

SolarMainframe (2021). Ids intrusion dataset (csv). [link]. Acesso em: 23-11-2025.

Suresh, H. and Guttag, J. (2021). A framework for understanding sources of harm throughout the machine learning life cycle. In Proceedings of the 1st ACM Conference on Equity and Access in Algorithms, Mechanisms, and Optimization, EAAMO ’21, New York, NY, USA. Association for Computing Machinery.

Vitorino, J., Pinto, D., Maia, E., Amorim, I., and Praça, I. (2025). Revisiting network traffic analysis: Compatible network flows for ml models.
Publicado
01/09/2026
TEIXEIRA, Jan Martins; BASTOS, Ian Vilar; MASCARENHAS, Dalbert M.; MORAES, Igor Monteiro. PAMS: Um Arcabouço para Detecção de Intrusão em Internet das Coisas. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 897-912. DOI: https://doi.org/10.5753/sbseg.2026.29090.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 > >>