Abstract
The rapid growth of Internet of Things (IoT) deployments introduces serious cybersecurity challenges, particularly for resource-constrained devices that are highly vulnerable to Distributed Denial-of-Service (DDoS) attacks. In Zigbee/IEEE 802.15.4– based IoT networks, association flooding attacks exploit the device association mechanism, severely degrading network availability. This study presents a hybrid intrusion detection system (IDS) that integrates rule-based feature extraction with machine learning classifiers to detect DDoS attacks efficiently and accurately. Network traffic datasets were collected using the KillerBee framework and the ATAVRRZUSBSTICK hardware in controlled laboratory scenarios under normal, attack, and mixed conditions. Rule-based techniques were applied to extract protocol-specific features related to packet frequency, packet length, and source–destination attributes, which were subsequently classified using Naïve Bayes, Decision Tree, and k-Nearest Neighbor algorithms. Experimental results demonstrate highly stable detection performance, with the proposed rule-based and Naïve Bayes combination achieving accuracies, precisions, and recalls of up to 100%, and false-positive and false-negative rates approaching zero across multiple datasets. These results are further supported by k-fold cross-validation, which indicates consistent performance across different data partitions. In addition, Naïve Bayes exhibits lower execution time than other classifiers, highlighting its suitability for lightweight, near-real-time IoT intrusion detection. While the achieved performance is influenced by the controlled experimental environment and the focus on a single associate flood attack, the findings confirm the effectiveness of integrating rule-based knowledge with probabilistic machine learning for DDoS detection in Zigbee-based IoT networks.
Author supplied keywords
Cite
CITATION STYLE
Stiawan, D., Susanto, S., Wahyudi, J., Afifah, N., Idris, M. Y., Alghamdi, T. A., & Budiarto, R. (2026). Rule-Based DDoS Attack Detection Using Machine Learning for the Internet of Things. International Journal on Informatics Visualization, 10(3), 1042–1055. https://doi.org/10.62527/joiv.10.3.4157
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.