Rule-Based DDoS Attack Detection Using Machine Learning for the Internet of Things

0Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The rapid growth of Internet of Things (IoT) deployments introduces serious cybersecurity challenges, particularly for resource-constrained devices that are highly vulnerable to Distributed Denial-of-Service (DDoS) attacks. In Zigbee/IEEE 802.15.4– based IoT networks, association flooding attacks exploit the device association mechanism, severely degrading network availability. This study presents a hybrid intrusion detection system (IDS) that integrates rule-based feature extraction with machine learning classifiers to detect DDoS attacks efficiently and accurately. Network traffic datasets were collected using the KillerBee framework and the ATAVRRZUSBSTICK hardware in controlled laboratory scenarios under normal, attack, and mixed conditions. Rule-based techniques were applied to extract protocol-specific features related to packet frequency, packet length, and source–destination attributes, which were subsequently classified using Naïve Bayes, Decision Tree, and k-Nearest Neighbor algorithms. Experimental results demonstrate highly stable detection performance, with the proposed rule-based and Naïve Bayes combination achieving accuracies, precisions, and recalls of up to 100%, and false-positive and false-negative rates approaching zero across multiple datasets. These results are further supported by k-fold cross-validation, which indicates consistent performance across different data partitions. In addition, Naïve Bayes exhibits lower execution time than other classifiers, highlighting its suitability for lightweight, near-real-time IoT intrusion detection. While the achieved performance is influenced by the controlled experimental environment and the focus on a single associate flood attack, the findings confirm the effectiveness of integrating rule-based knowledge with probabilistic machine learning for DDoS detection in Zigbee-based IoT networks.

Author supplied keywords

Cite

CITATION STYLE

APA

Stiawan, D., Susanto, S., Wahyudi, J., Afifah, N., Idris, M. Y., Alghamdi, T. A., & Budiarto, R. (2026). Rule-Based DDoS Attack Detection Using Machine Learning for the Internet of Things. International Journal on Informatics Visualization, 10(3), 1042–1055. https://doi.org/10.62527/joiv.10.3.4157

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free