An Empirical Benchmarking Framework for IoT Traffic Anomaly Detection Using Elastic Stack SIEM

Authors

  • Ferdiansyah Ferdiansyah Universitas Indo Global Mandiri
  • Reynaldi Rizki Billanivo Universitas Indo Global Mandiri
  • M Ardiansyah Universitas Indo Global Mandiri
  • Tegar Putra Universitas Indo Global Mandiri
  • M. Habibullah Amin Universitas Indo Global Mandiri

DOI:

https://doi.org/10.24076/intechnojournal.2026v8i1.2808

Keywords:

Machine Learning, Network Anomaly Detection, K-Nearest Neighbors, Support Vector Machine, Naive Bayes

Abstract

Purpose: This study aims to construct a realistic IoT-MQTT benchmark dataset and evaluate supervised machine learning classifiers for detecting network traffic anomalies, specifically Distributed Denial of Service (DDoS) and spoofing attacks, within a live Security Information and Event Management (SIEM) environment.

Methods: An empirical benchmarking framework based on a live Elastic (ELK) Stack SIEM environment was developed, and supervised machine learning classifiers were evaluated for IoT network traffic anomaly detection.

Result: KNN and SVM achieved the highest accuracy (0.99), whereas Naive Bayes achieved 0.96. Further analysis revealed that the superior performance of KNN and SVM was largely influenced by data leakage caused by the _attacker_ip feature, while Naive Bayes demonstrated better generalization without relying on identity-based features.

Conclusion: The findings highlight the importance of rigorous feature engineering and data leakage analysis when developing machine learning models for IoT traffic anomaly detection, particularly in live SIEM environments. Moreover, the proposed framework contributes to the achievement of Sustainable Development Goals (SDGs) 9 by supporting resilient digital infrastructure and secure IoT-based innovation.

References

[1] Makdis Nasrul, “PEMANFAATAN INTERNET UNTUK PERKULIAHAN Nasrul Makdis PENERBIT CV. PENA PERSADA,” pp. 1–20, 2020.

[2] A. H. Kelechi, U. A. Samson, M. Simeon, O. Obinna, A. Alex, and A. A. Aderemi, “The quality of service of the deployed LTE technology by mobile network operators in Abuja-Nigeria,” Int. J. Electr. Comput. Eng., vol. 11, no. 3, pp. 2191–2202, 2021, doi: 10.11591/ijece.v11i3.pp2191-2202.

[3] S. W. Nourildean, M. D. Hassib, and Y. A. Mohammed, “Internet of things based wireless sensor network: a review,” Indones. J. Electr. Eng. Comput. Sci., vol. 27, no. 1, pp. 246–261, 2022, doi: 10.11591/ijeecs.v27.i1.pp246-261.

[4] Tri Ginanjar Laksana and Sri Mulyani, “Pengetahuan Dasar Identifikasi Dini Deteksi Serangan Kejahatan SiberUntuk Mencegah Pembobolan Data Perusahaan,” J. Ilm. Multidisiplin, vol. 3, no. 1, pp. 109–122, 2024.

[5] Janet Julia Ang’udi, “Security challenges in cloud computing: A comprehensive analysis,” World J. Adv. Eng. Technol. Sci., vol. 10, no. 2, pp. 155–181, 2023, doi: 10.30574/wjaets.2023.10.2.0304.

[6] A. D. Afifaturahman and F. MSN, “Perbandingan Algoritma K-Nearest Neighbour (KNN) dan Naive Bayes pada Intrusion Detection System (IDS),” Innov. Res. Informatics, vol. 3, no. 1, pp. 17–25, 2021, doi: 10.37058/innovatics.v3i1.2852.

[7] Abbas A. Mahdi, “Machine learning applications of network security enhancement: review,” Comput. Sci. IT Res. J., vol. 5, no. 10, pp. 2283–2300, 2024, doi: 10.51594/csitrj.v5i10.1635.

[8] F. Stodt, F. Theoleyre, and C. Reich, “Advancing Network Survivability and Reliability: Integrating XAI-Enhanced Autoencoders and LDA for Effective Detection of Unknown Attacks,” 20th Int. Conf. Des. Reliab. Commun. Networks, DRCN 2024, pp. 9–16, 2024, doi: 10.1109/DRCN60692.2024.10539141.

[9] A. B. Nassif, M. A. Talib, Q. Nasir, and F. M. Dakalbab, “Machine Learning for Anomaly Detection: A Systematic Review,” 2021. doi: 10.1109/ACCESS.2021.3083060.

[10] M. D. Ogah, J. Essien, M. Ogharandukun, and M. Abdullahi, “Machine Learning Models for Heterogenous Network Security Anomaly Detection,” J. Comput. Commun., vol. 12, no. 06, pp. 38–58, 2024, doi: 10.4236/jcc.2024.126004.

[11] M. Mujiono, D. A. Larasati, M. Hemansyah, and F. Fatimatuzzahra, “Deteksi Anomali dalam Sistem Keamanan Jaringan Menggunakan Teknik Supervised Machine Learning,” J. Esensi Infokom J. Esensi Sist. Inf. dan Sist. Komput., vol. 9, no. 1, pp. 65–69, 2025, doi: 10.55886/infokom.v9i1.971.

[12] A. S. M. Kayes, W. Rahayu, T. Dillon, A. Salehi Shahraki, and H. Alavizadeh, “Safeguarding Individuals and Organizations From Privacy Breaches: A Comprehensive Review of Problem Domains, Solution Strategies, and Prospective Research Directions,” IEEE Internet Things J., vol. 12, no. 2, pp. 1247–1265, 2025, doi: 10.1109/JIOT.2024.3481316.

[13] K. M. D. Pertiwi, N. A. Hasibuan, and D. P. Rahmawati, “Denial of Service (DOS) Attack Detection on MQTT Protocol Using the Random Forest Method,” J. Online Inform., vol. 11, no. 1, pp. 48–59, 2026, doi: 10.15575/join.v11i1.1784.

[14] D. B. Negesse, K. A. Gemeda, and G. Gianini, “DDoS attack detection and classification for the MQTT-IoT protocol using LSTM models,” Discov. Appl. Sci., vol. 8, no. 5, 2026, doi: 10.1007/s42452-026-08563-8.

[15] R. R. Billanivo, “IoT-MQTT ELK Benchmark Dataset,” Kaggle. [Online]. Available: https://www.kaggle.com/datasets/rrbillanivo/iot-mqtt-elk-benchmark-dataset

Downloads

Published

2026-07-31

Issue

Section

Articles

Categories