Return
An Effective Hierarchical Anomaly Based Intrusion Detection System for IoT Using Ant Colony Optimization Based Feature Selection
H
Z
H
DOI:10.1007/s10586-026-06475-1.png)
Abstract
En 中文
With the rapid growth of the Internet of Things (IoT), security threats have become a major concern. Accurate detection of network attacks with minimal computational complexity in resource-constrained IoT environments is an urgent challenge. Anomaly-based intrusion detection system (IDS) is a promising solution for IoT security; however, they often face the issues of high-dimensional traffic features and imbalanced datasets, leading to increased training and detection time. To address these issues, this study proposes a feature selection approach based on Ant Colony Optimization (ACO) to identify the most relevant features. The proposed method is evaluated on the BoT-IoT and UNSW-NB15 datasets using three classifiers: Random Forest (RF), Decision Tree (DT), and XgBoost. Synthetic Minority Oversampling Technique (SMOTE) is applied to balance the datasets. The classification process is organized into two hierarchical stages. In the first stage, network traffic is classified as either normal or attack. In the second stage, misclassified normal samples from the first stage are filtered, and attack traffic is further categorized into specific attack types. The proposed system successfully reduces the feature set to 10 from the original datasets while achieving 100% detection accuracy and minimal training and detection times. Compared with other anomaly-based IDS methods and approaches, the proposed method demonstrates superior performance in both classification stages in terms of detection accuracy and computational efficiency.
Keywords:
Internet of Things
Anomaly Based Intrusion Detection Systems
Machine Learning
Ant Colony Optimization
Synthetic Minority Oversampling Technique
Binary Classification
Multiclass Classification.
Journal
C
IF:
4.1
Papers:
4.8K
Citations:
7.5K
