DC FieldValueLanguage
dc.contributor.authorJovanović, Đorđeen_US
dc.contributor.authorVuletić, Pavleen_US
dc.date.accessioned2025-01-30T09:59:16Z-
dc.date.available2025-01-30T09:59:16Z-
dc.date.issued2025-
dc.identifier.issn1863-1703-
dc.identifier.urihttp://researchrepository.mi.sanu.ac.rs/handle/123456789/5431-
dc.description.abstractThis paper, presents a new methodology for IoT botnet detection based on network intra-flow parameter time series analysis and supervised machine learning classification. The study focuses on time series feature extraction and machine learning pipeline improvements and methods to solve the problem of heavily imbalanced datasets, characteristics of many information security use cases. Another side result is the inference of key distinguishing malware behavior features that make them detectable with large precision. The research is based on real-world IoT malware dynamic behavior analysis, The samples were collected over 4 years (2019–2023), presenting one of the most recent IoT malware datasets and a unique long-term malware behavior analysis. The analysis suggests the type and rate of changes in IoT botnet malware behavior and some invariant features that can be used to reliably detect even previously unseen malware samples (so-called zero-day cases). Presented experimental results prove that the synthetic sample generation methodologies used in this study do not overfit the classifiers, but can detect zero-day malware samples with 0.9706 accuracy and 0.9041 f1 score.en_US
dc.publisherSpringer Linken_US
dc.relationThis research was partially financially supported by the Ministry of Science, Technological Development, and Innovation of the Republic of Serbia (Contract No. 451-03-68/2024-03/200103).en_US
dc.relation.ispartofSignal, Image and Video Processingen_US
dc.rightsAttribution 4.0 International*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/*
dc.subjectIoT botnet | Imbalanced datasets | Zero-day detectionen_US
dc.titleMachine learning pipelines for IoT botnet detection and behavior characterization in heavily imbalanced settingsen_US
dc.typeArticleen_US
dc.identifier.doi10.1007/s11760-025-03813-5-
dc.contributor.affiliationComputer Scienceen_US
dc.contributor.affiliationMathematical Institute of the Serbian Academy of Sciences and Artsen_US
dc.relation.firstpage254-
dc.relation.volume19-
dc.description.rank~M22-
item.cerifentitytypePublications-
item.openairecristypehttp://purl.org/coar/resource_type/c_18cf-
item.grantfulltextopen-
item.fulltextWith Fulltext-
item.openairetypeArticle-
crisitem.author.orcid0000-0003-1222-1292-
Files in This Item:
File Description SizeFormat
DJovanovic.pdf499.84 kBAdobe PDFView/Open
Show simple item record

Page view(s)

4
checked on Jan 31, 2025

Download(s)

2
checked on Jan 31, 2025

Google ScholarTM

Check

Altmetric

Altmetric


This item is licensed under a Creative Commons License Creative Commons