A Device-Centric and Temporal Learning Framework for Malicious IoT Traffic Detection

  • Mustafa Daraghmeh
  • , Islam Obaidat
  • , Yaser Jararweh
  • , Anjali Agarwal
  • , Kuljeet Kaur

Research output: Contribution to Book/Report typesContribution to conference proceedingspeer-review

Abstract

The rapid increase of Internet of Things (IoT) devices has introduced substantial security risks, necessitating robust security solutions to detect malicious traffic. In this paper, we propose a machine-learning solution to identify malicious IoT traffic while adhering to the constraints of the IoT environment. Our solution segments network packets into time windows and groups them by source IP. This approach enables the extraction of statistical, behavioral, and entropy-based features that preserve important temporal and device-level characteristics. To address data imbalance, we employ synthetic oversampling (SMOTE), followed by a suite of standard classification models (such as k-nearest Neighbors and Random Forest) calibrated via a sigmoid function to refine probabilistic predictions. Our pipeline is evaluated on Edge-IIoTset, a comprehensive dataset encompassing traffic from multiple IoT devices and 14 different attacks. Results indicate that k-Nearest Neighbors outperforms alternative classifiers, achieving an F1 score of up to 0.8696 and demonstrating high robustness to complex traffic patterns. These findings highlight the effectiveness of time-segmented, IP-based feature aggregation and underline the importance of calibrated classifiers in enhancing IoT network security.

Original languageEnglish
Title of host publication2025 5th Intelligent Cybersecurity Conference, ICSC 2025
EditorsMohammad Alsmirat, Fahed Alkhabbas, Muhammad Al-Abdullah, Yaser Jararweh
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages130-136
Number of pages7
ISBN (Electronic)9798350392920
DOIs
Publication statusPublished - 2025
Event5th Intelligent Cybersecurity Conference, ICSC 2025 - Tampa, United States
Duration: 19 May 202522 May 2025

Publication series

Name2025 5th Intelligent Cybersecurity Conference, ICSC 2025

Conference

Conference5th Intelligent Cybersecurity Conference, ICSC 2025
Country/TerritoryUnited States
CityTampa
Period19/05/2522/05/25

!!!Keywords

  • Cyber Attack Detection
  • Feature Extraction
  • IoT Traffic Classification
  • Network Traffic Analysis

Fingerprint

Dive into the research topics of 'A Device-Centric and Temporal Learning Framework for Malicious IoT Traffic Detection'. These topics are generated from the title and abstract of the publication. Together, they form a unique fingerprint.

Cite this