Related Experiment Video
Updated: Jun 3, 2025

08:05
Design and Analysis for Fall Detection System Simplification
Published on: April 6, 2020
10.6K
Extracting Optimal Number of Features for Machine Learning Models in Multilayer IoT Attacks
Badeea Al Sukhni1, Soumya K Manna1, Jugal M Dave2
1School of Engineering, Technology and Design, Canterbury Christ Church University, Canterbury CT1 1QU, UK.
Sensors (Basel, Switzerland)
|January 8, 2025
Summary
This study introduces a Semi-Automated Intrusion Detection System (SAIDS) to combat sophisticated multilayer attacks in Internet of Things (IoT) systems. The SAIDS framework effectively identifies these complex threats with over 94% accuracy using optimized features.
Area of Science:
- Cybersecurity
- Network Security
- Internet of Things (IoT) Security
Background:
- Internet of Things (IoT) systems face escalating security risks from multilayer attacks, leading to data breaches and financial losses.
- Existing intrusion detection methods for IoT often lack real-world applicability due to outdated datasets and limited adaptive capabilities.
- Over-reliance on fully automated processes can hinder the reliability of intrusion detection models, highlighting the need for human-machine interaction.
Purpose of the Study:
- To develop a Semi-Automated Intrusion Detection System (SAIDS) for detecting and identifying multilayer attacks in IoT environments.
- To enhance mitigation strategies by integrating efficient feature selection, weighting, normalization, visualization, and human-machine interaction.
- To address the limitations of current research by focusing on adaptive, dynamic approaches and real-world applicability.
Main Methods:
- Development of a SAIDS framework incorporating feature selection, feature weighting, normalization, visualization, and human-machine interaction.
- Extraction of an optimal subset of 13 significant features from the 64 available in the Edge-IIoT dataset.
- Comparative analysis of machine learning classifiers for multilayer attack detection, focusing on the K-Nearest Neighbors (KNN) model.
Main Results:
- The SAIDS framework successfully identified an optimal set of 13 critical features for multilayer attack detection and classification.
- The KNN algorithm demonstrated superior performance compared to other classifiers in binary classification tasks.
- The KNN model achieved an average accuracy exceeding 94% in detecting various multilayer attacks, including UDP, ICMP, HTTP flood, MITM, TCP SYN, XSS, and SQL injection.
Conclusions:
- The proposed SAIDS framework effectively enhances the detection and classification of multilayer IoT attacks.
- Integrating human expertise with automated processes improves the reliability of intrusion detection models.
- The optimized feature set and KNN model provide a robust solution for securing IoT systems against sophisticated cyber threats.

