Original title:
Detekce anomálního síťového provozu IoT zařízení
Translated title:
Detection of Anomalous Network Traffic of IoT Devices
Authors:
Cempírek, Jaroslav ; Tran, Minh (referee) ; Ilgner, Petr (advisor) Document type: Bachelor's theses
Year:
2026
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[cze][eng]
Tato bakalářská práce se zabývá detekcí anomálií v síťovém provozu zařízení internetu věcí (IoT) v domácím prostředí s důrazem na ochranu soukromí uživatelů. V teoretické části jsou popsány architektura IoT sítí, typické komunikační protokoly, metody detekce anomálií od statistických přístupů po algoritmy strojového učení a právní aspekty zpracování síťových dat podle nařízení GDPR. V praktické části je realizováno testovací prostředí se třemi IoT zařízeními (IP kamera, chytrá žárovka, teplotní senzor), jehož provoz je zrcadlen ze směrovače MikroTik na Raspberry Pi pomocí protokolu TZSP. Z více než 21 000 zachycených síťových toků byly extrahovány statistické charakteristiky nástrojem CICFlowMeter a pro každé zařízení byl natrénován samostatný model Isolation Forest. Funkčnost detekce byla ověřena jak na simulovaných anomáliích, tak v rámci tříměsíčního nasazení v reálné domácí síti, během kterého systém zachytil jevy jako concept drift po aktualizaci firmwaru zařízení. Systém je doplněn o webový dashboard, automatickou identifikaci nových zařízení podle MAC adres a mechanismus přetrénování modelů. Práce uzavírá diskusí omezení přístupu a doporučení pro zvýšení ochrany soukromí uživatelů.
This bachelor's thesis addresses anomaly detection in network traffic of Internet of Things (IoT) devices in a home environment, with emphasis on user privacy protection. The theoretical part describes the architecture of IoT networks, typical communication protocols, anomaly detection methods ranging from statistical approaches to machine learning algorithms, and legal aspects of network data processing under the GDPR regulation. The practical part implements a test environment with three IoT devices (IP camera, smart bulb, temperature sensor) whose traffic is mirrored from a MikroTik router to a Raspberry Pi using the TZSP protocol. Statistical features were extracted from more than 21 000 captured network flows using CICFlowMeter, and a separate Isolation Forest model was trained for each device. The detection capability was validated both on simulated anomalies and during a three-month deployment in a real home network, during which the system captured phenomena such as concept drift following device firmware updates. The system is complemented by a web dashboard, automatic identification of new devices by MAC address, and a model retraining mechanism. The thesis concludes with a discussion of the limitations of the approach and recommendations for enhancing user privacy.
Keywords:
anomaly detection; CICFlowMeter; concept drift; GDPR; Internet of Things; IoT; Isolation Forest; machine learning; network traffic; privacy protection; Raspberry Pi; CICFlowMeter; concept drift; detekce anomálií; GDPR; internet věcí; IoT; Isolation Forest; ochrana soukromí; Raspberry Pi; strojové učení; síťový provoz
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258279