Distributed Denial of Service Attack Detection in Internet of Things
Loading...
Date
item.page.authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
The exponential growth of the Internet of Things (IoT) has transformed industries and everyday
newlinelife, offering increased automation, real-time monitoring, and intelligent decision-making.
newlineHowever, this rapid expansion has also exposed IoT systems to a wide range of security
newlinethreats particularly Distributed Denial of Service (DDoS) attacks. Due to the resourceand#65534;constrained and heterogeneous nature of IoT devices, these systems are highly susceptible to
newlinemalicious intrusions that can cripple networks. As a result, the need for efficient, scalable, and
newlineaccurate DDoS attack detection solutions tailored to IoT ecosystems has become more critical
newlinethan ever.
newlineTo address these challenges, this research introduces an ensemble-based classification
newlineframework leveraging tree classifiers Decision Tree, Extra Tree, Random Forest, and
newlineXGBoost integrated with hybrid feature selection techniques including Step Forward Feature
newlineSelection and average feature importance. Dynamic ensemble methods such as stacking and
newlinevoting were employed, with hyperparameter optimization via RandomizedSearchCV. The
newlineEnsemble Stacking Classifier and Ensemble Voting classifier with XGBoost as a meta-learner
newlinegive 99.92% and 99.5% accuracy for the BoT-IoT dataset. Hyperparameter tuning is done using
newlineRandomizedSearchCV. Experimental findings ensure the effectiveness and performance of the
newlinesuggested system for intrusion classification based on Bot-IoT, CICIoT2023.
newlineThe research also introduces a novel hybrid feature selection framework that integrates
newlineexplainableAI SHAP feature importance with metaheuristic optimization algorithms Binary
newlineGrey Wolf Optimization (BGWO) and Particle Swarm Optimization (PSO) for ferature
newlineselection and machine learning and deep learning classifiers for detection of DDoS. This twoand#65534;stage process reduces feature dimensionality while preserving classification power. KMeans++
newlineis used for effective data sampling, ensuring balanced and representative training sets. In
newlineaddition, hyperparameter tuning is conducted using Bayesian Optimization with Treeand#65534;structured Parzen Estimator (TPE), optimizing model performance through efficient parameter
newlinesearch. The performance is assessed using the BoT-IoT and CICIoT2023 Dataset.Results are
newlinecompared with the State of Art DOS and DDOS Attack Detection Techniques. Overall the
newlineproposed Random Forest Machine Learning Model and Bi-LSTM Deep Learning Model when
newlineevaluated for Feature Subset selected by SHAP-BGWO outperforms all the other models
newlineexhibiting an accuracy of 99.9% and 98% with high precision, and minimal false positive rates .
newlinei
newlineThe framework also incorporates Conditional Tabular Generative Adversarial Networks
newline(CTGAN) along with hybrid feature selection Anova and random forest importance and deep
newlinelearning models Variational Autoencoders (VAE), Stacked Autoencoders (SAE), and
newlineDenoising Autoencoders (DAE) for classification and detection of DDoS attacks. Classifiers
newlineare evaluated for their effectiveness in various scenarios, with SAE showing the most consistent
newlineresults across different datasets and conditions. The proposed frameworks are validated using
newlinethree publicly available IoT datasets BoT-IoT, CICIoT2023, and CICDDoS2019
newlinedemonstrating their capability to accurately detect and classify DDoS attacks. This research
newlinedemonstrates that hybrid models coupling explainable feature selection, ensemble learning,
newlineand data augmentation offer a powerful approach to DDoS attack detection in IoT, addressing
newlinekey challenges such as high false positives and data imbalance.
newlineFuture work will focus on using more IoT datasets for evaluation and should explore more
newlinesophisticated strategies and develop advanced defence mechanisms for DDoS attack detection
newlinein IoT.
newline