Return
Classification of reconnaissance attacks in IoT networks by leveraging machine learning
O
N
B
DOI:10.1007/s10586-026-06426-w.png)
Abstract
En 中文
Reconnaissance (Recon) attacks represent an important early stage of cyberattacks, particularly in Internet of Things (IoT) environments where heterogeneous and resource-constrained devices increase the attack surface. This study provides a reconnaissance-focused comparative evaluation of machine learning models using the CICIoT2023 dataset. The dataset was filtered to include five reconnaissance classes: Recon-HostDiscovery, Recon-OSScan, Recon-PortScan, Recon-PingSweep, and VulnerabilityScan. A leakage-free experimental pipeline was applied using stratified train-test splitting and training-only feature scaling. Several machine learning models were evaluated using accuracy, precision, recall, and F1-score, with emphasis on per-class behavior due to severe class imbalance. Experimental results show that XGBoost achieved the highest accuracy of 0.89, followed by Random Forest with 0.88 and Decision Tree with 0.85. The analysis also shows that Recon-PingSweep is the most difficult class to detect because of its limited representation and overlap with other scanning-based reconnaissance behaviors. Class weighting improved PingSweep recall, although its effect differed across classifiers and may affect the precision-recall balance. Feature-importance analysis further indicates that temporal and flow-level attributes, especially inter-arrival time, packet rate, flow duration, and TCP flag-related counts, play a key role in distinguishing reconnaissance attack types. These findings provide practical insight into the behavior of reconnaissance traffic in IoT intrusion detection.
Keywords:
IoT Security
Machine learning
Reconnaissance attacks
XGBoost
CICIoT2023 dataset
Intrusion detection
Journal
C
IF:
4.1
Papers:
4.8K
Citations:
7.5K
