Related Experiment Video
Updated: Jan 21, 2026

Flying Insect Detection and Classification with Inexpensive Sensors
Published on: October 15, 2014
IoTDS: A One-Class Classification Approach to Detect Botnets in Internet of Things Devices
Vitor Hugo Bezerra1, Victor Guilherme Turrisi da Costa1, Sylvio Barbon Junior1
1Computer Science Department, State University of Londrina (UEL), Londrina PR 86057-970, Brazil.
This study introduces a security system designed to identify malicious botnet activity on smart devices. Instead of monitoring network traffic, the system tracks internal device metrics like processor usage and temperature to spot unusual behavior. By focusing on normal device patterns, it avoids the need for extensive manual data labeling. The researchers tested four different mathematical models to see which best identified compromised devices. Their findings suggest that this host-based approach effectively detects various botnets while keeping the device running smoothly. This method offers a lightweight alternative for securing interconnected hardware against large-scale cyber threats.
Area of Science:
- Cybersecurity research within Internet of Things (IoT) systems
- Machine learning applications for IoTDS anomaly detection
Background:
No prior work had resolved the security vulnerabilities inherent in the rapidly expanding ecosystem of interconnected smart hardware. These devices frequently lack robust protection, creating opportunities for malicious actors to organize massive botnet networks. That uncertainty drove the need for lightweight, host-based monitoring solutions that do not rely on traditional network traffic analysis. It was already known that manual labeling of malicious data is a labor-intensive and often impractical task for large-scale deployments. This gap motivated the development of systems that can learn legitimate operational patterns without requiring pre-existing examples of attacks. Prior research has shown that monitoring internal hardware metrics can provide insights into device health and potential compromises. However, existing frameworks often impose heavy computational burdens that degrade the performance of resource-constrained hardware. This study addresses these challenges by proposing a specialized architecture designed to maintain security without overloading the host device.
Purpose Of The Study:
The aim of this study is to introduce a host-based detection system for identifying botnets within smart hardware environments. The researchers seek to address the security vulnerabilities of these devices without relying on traditional network traffic analysis. They propose a method that models only legitimate device behavior to detect deviations, thereby eliminating the need for manual data labeling. The study investigates whether internal hardware metrics can serve as reliable indicators of malicious activity. A secondary goal is to design an architecture that prevents the device from being overloaded by training activities. The authors intend to evaluate the predictive performance of four different one-class classification algorithms. They also aim to assess the impact of their system on device energy, memory, and processor utilization. This research is motivated by the need for lightweight, efficient security solutions for resource-constrained hardware.
Main Methods:
The review approach involved evaluating a host-based detection system using an experimental setup with compromised hardware. Researchers tested four distinct one-class classification algorithms to identify the most effective model for anomaly detection. The design utilized an agent-manager architecture to facilitate secure communication via HTTPS protocols. This structure ensured that training processes remained separated from the primary device operations to minimize performance interference. Data collection focused on internal hardware metrics rather than external network traffic patterns. The team analyzed CPU utilization, temperature, memory consumption, and the total count of running tasks during testing. Three different device profiles were subjected to seven unique botnet scenarios to validate the system. The team compared the predictive accuracy and resource impact of each algorithm to determine overall system viability.
Main Results:
Key findings from the literature demonstrate that the proposed system achieves a mean F1-score of 94% using the Local Outlier Factor algorithm. This model outperformed the other three evaluated algorithms in detecting various botnet threats. The system successfully identified malicious activity across all three tested device profiles and seven different botnet scenarios. Results indicate that the approach maintains a low impact on device energy consumption during active monitoring. CPU utilization remained within acceptable limits throughout the testing phases for all evaluated configurations. Memory consumption also showed minimal deviation, confirming the efficiency of the agent-manager architecture. The data show that the system effectively models legitimate behavior to flag deviations without requiring manual labeling. These findings suggest that host-based monitoring provides a reliable alternative to network-dependent security measures for smart hardware.
Conclusions:
The authors propose that their host-based architecture effectively identifies malicious activity without requiring network traffic analysis. They suggest that modeling legitimate behavior allows for the detection of deviations without the need for manual labeling. The findings indicate that the Local Outlier Factor algorithm achieves superior predictive performance compared to other evaluated models. The researchers claim that their system maintains a low impact on essential hardware resources like memory and processor usage. They conclude that the agent-manager design successfully offloads training activities to prevent device strain during operation. The study shows that the system performs reliably across various device profiles and different types of botnet threats. The authors imply that this approach offers a viable path for securing resource-constrained hardware against large-scale cyber attacks. The evidence suggests that one-class classification is a robust strategy for identifying anomalies in smart device environments.
Frequently Asked Questions
The researchers propose a host-based detection system that monitors internal hardware metrics like CPU utilization, temperature, memory consumption, and running task counts. This approach identifies botnets by modeling normal device behavior and flagging deviations, rather than analyzing external network traffic data.
The system utilizes an agent-manager architecture based on HTTPS. This design is necessary to ensure that the training activities do not overload the IoT device, thereby maintaining its operational performance while the security monitoring occurs.
The study evaluated four one-class algorithms: Elliptic Envelope, Isolation Forest, Local Outlier Factor, and One-class Support Vector Machine. The Local Outlier Factor demonstrated the best predictive performance, achieving a mean F1-score of 94% across the tested scenarios.
The researchers used an experimental setup containing a device compromised by bot malware. They tested the system across three distinct device profiles and seven different botnet variants to ensure the robustness of their detection approach.
The system measures internal hardware performance indicators, specifically CPU utilization, temperature, memory consumption, and the number of active tasks. These metrics allow the system to detect anomalies without inspecting network traffic.
The authors propose that their system provides a lightweight security solution that avoids the need for manual data labeling. They suggest that this host-based approach is effective for protecting resource-constrained devices from large-scale botnet threats.
More Related Videos
05:25Author Spotlight: Expanding the Scope of Multiplex Immunoassays for Lyme Borreliosis Diagnostics and Pathogen Research
Published on: July 14, 2023
13:10In Situ Detection of Autoreactive CD4 T Cells in Brain and Heart Using Major Histocompatibility Complex Class II Dextramers
Published on: August 1, 2014
Related Concept Videos
Drug Classes and Categories
Antibody Structure and Classes
The basic structure of an antibody consists of four protein chains: two identical heavy chains and two identical light chains. These chains are held together by disulfide bonds and other non-covalent interactions, forming a Y-shaped structure.
Classification of Neurotransmitters
Classification of Leukocytes
Neutrophils are the most abundant type of granular leukocytes, comprising 50-70% of all leukocytes. They feature small, evenly distributed granules and a...
Classification of Bones
Long and Short Bones
The appendicular skeleton, particularly the upper and lower limbs, is primarily made of long and short bones. The...
Force Classification
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...