<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CSSE</journal-id>
<journal-id journal-id-type="nlm-ta">CSSE</journal-id>
<journal-id journal-id-type="publisher-id">CSSE</journal-id>
<journal-title-group>
<journal-title>Computer Systems Science &#x0026; Engineering</journal-title>
</journal-title-group>
<issn pub-type="ppub">0267-6192</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">34095</article-id>
<article-id pub-id-type="doi">10.32604/csse.2023.034095</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>An Efficient Intrusion Detection Framework for Industrial Internet of Things Security</article-title><alt-title alt-title-type="left-running-head">An Efficient Intrusion Detection Framework for Industrial Internet of Things Security</alt-title><alt-title alt-title-type="right-running-head">An Efficient Intrusion Detection Framework for Industrial Internet of Things Security</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Alshathri</surname><given-names>Samah</given-names></name>
<xref ref-type="aff" rid="aff-1">1</xref>
</contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>El-Sayed</surname><given-names>Ayman</given-names></name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<contrib id="author-3" contrib-type="author" corresp="yes">
<name name-style="western"><surname>El-Shafai</surname><given-names>Walid</given-names></name>
<xref ref-type="aff" rid="aff-3">3</xref>
<xref ref-type="aff" rid="aff-4">4</xref><email>walid.elshafai@el-eng.menofia.edu.eg</email>
</contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Hemdan</surname><given-names>Ezz El-Din</given-names></name>
<xref ref-type="aff" rid="aff-2">2</xref>
</contrib>
<aff id="aff-1"><label>1</label><institution>Department of Information Technology, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University</institution>, <addr-line>P.O.Box 84428, Riyadh, 11671</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science and Engineering, Faculty of Electronic Engineering, Menoufia University</institution>, <addr-line>Menouf, 32952</addr-line>, <country>Egypt</country></aff>
<aff id="aff-3"><label>3</label><institution>Security Engineering Lab, Computer Science Department, Prince Sultan University</institution>, <addr-line>Riyadh, 11586</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Electronics and Electrical Communications Engineering, Faculty of Electronic Engineering, Menoufia University</institution>, <addr-line>Menouf, 32952</addr-line>, <country>Egypt</country></aff>
</contrib-group><author-notes><corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Walid El-Shafai. Email: <email>walid.elshafai@el-eng.menofia.edu.eg</email></corresp></author-notes>
<pub-date date-type="collection" publication-format="electronic"><year>2023</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>17</day><month>1</month><year>2023</year></pub-date>
<volume>46</volume>
<issue>1</issue>
<fpage>819</fpage>
<lpage>834</lpage>
<history>
<date date-type="received"><day>07</day><month>7</month><year>2022</year></date>
<date date-type="accepted"><day>07</day><month>11</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Alshathri et al.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Alshathri et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CSSE_34095.pdf"></self-uri>
<abstract><p>Recently, the Internet of Things (IoT) has been used in various applications such as manufacturing, transportation, agriculture, and healthcare that can enhance efficiency and productivity via an intelligent management console remotely. With the increased use of Industrial IoT (IIoT) applications, the risk of brutal cyber-attacks also increased. This leads researchers worldwide to work on developing effective Intrusion Detection Systems (IDS) for IoT infrastructure against any malicious activities. Therefore, this paper provides effective IDS to detect and classify unpredicted and unpredictable severe attacks in contradiction to the IoT infrastructure. A comprehensive evaluation examined on a new available benchmark TON_IoT dataset is introduced. The data-driven IoT/IIoT dataset incorporates a label feature indicating classes of normal and attack-targeting IoT/IIoT applications. Correspondingly, this data involves IoT/IIoT services-based telemetry data that involves operating systems logs and IoT-based traffic networks collected from a realistic medium-scale IoT network. This is to classify and recognize the intrusion activity and provide the intrusion detection objectives in IoT environments in an efficient fashion. Therefore, several machine learning algorithms such as Logistic Regression (LR), Linear Discriminant Analysis (LDA), K-Nearest Neighbors (KNN), Gaussian Naive Bayes (NB), Classification and Regression Tree (CART), Random Forest (RF), and AdaBoost (AB) are used for the detection intent on thirteen different intrusion datasets. Several performance metrics like accuracy, precision, recall, and F1-score are used to estimate the proposed framework. The experimental results show that the CART surpasses the other algorithms with the highest accuracy values like 0.97, 1.00, 0.99, 0.99, 1.00, 1.00, and 1.00 for effectively detecting the intrusion activities on the IoT/IIoT infrastructure on most of the employed datasets. In addition, the proposed work accomplishes high performance compared to other recent related works in terms of different security and detection evaluation parameters.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Attacks</kwd>
<kwd>intrusion detection</kwd>
<kwd>machine learning</kwd>
<kwd>deep learning</kwd>
<kwd>industrial IoT</kwd>
<kwd>TON_IoT dataset</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label><title>Introduction</title>
<p>In recent years, superlative modern systems like the Internet of Things (IoT) [<xref ref-type="bibr" rid="ref-1">1</xref>] and cloud computing generally depend on network and Internet connectivity for data sharing. Therefore, cybersecurity turns out to be one of the key arenas for plentiful researchers around the world in diverse subjects such as cloud and IoT forensics [<xref ref-type="bibr" rid="ref-2">2</xref>], big healthcare data security [<xref ref-type="bibr" rid="ref-3">3</xref>], data hiding [<xref ref-type="bibr" rid="ref-4">4</xref>], and critical IoT infrastructure Security [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>The IoT has recently rewarded interest in various real-world applications such as healthcare, manufacturing, and agriculture. The IoT is a connected network of several types of systems and technology involving cloud computing, intelligent sensors, the Internet, and many other modern systems. As a result, the IoT becomes more exposed to severe incidents and malicious activities that can cause breaches of IoT security and privacy. These attacks can be from both inside and outside of enterprise IoT-based infrastructure. The typical IoT system consists of several levels, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref> as the following:<list list-type="simple"><list-item><label>&#x25CB;</label>
<p><bold>Level 0:</bold> IoT sensors are used for collecting and observing IoT infrastructure.</p>
</list-item><list-item><label>&#x25CB;</label>
<p><bold>Level 1:</bold> The edge devices in this level are operated among the sensor network and cloud system for effective data processing near the IoT sensors.</p></list-item><list-item><label>&#x25CB;</label>
<p><bold>Level 2:</bold> The cloud system is employed for storing and processing the collected data from level 0.</p></list-item><list-item><label>&#x25CB;</label>
<p><bold>Level 3:</bold> Console and web-based monitoring applications that communicate with cloud systems for visualizing and presenting obtained results from applying data analytics models to help make suitable decisions by staff in smart IoT systems.</p></list-item></list></p>
<fig id="fig-1">
<label>Figure 1</label>
<caption><title>Typical IoT system</title></caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_34095-fig-1.tif"/>
</fig>
<p>Intrusion Detection Systems (IDSs) are commonly used as a backline of defense to supervise and examine network events to detect possible nasty actions that profitably evade security perimeters, such as firewalls. To evaluate the performance of intrusion detection systems, it is necessary to use IoT-based datasets that reflect real-world IoT scenarios. Consequently, it can provide an efficient evaluation for developing an efficient intrusion system for IoT applications. In the last years, many machine learning (ML) approaches have been commonly used for detecting and classifying malicious attacks against network infrastructure in an automatic fashion. However, a variety of challenges arise due to malicious attacks that are recurrently changing. In addition, numerous malware datasets are widely available for further cybersecurity study and research.</p>
<p>However, few present studies have indicated the detailed performance analysis of several machine learning algorithms on a dataset for a realistic representation of medium-scale IoT infrastructure. Therefore, this work focuses on classifying and recognizing the intrusion and malicious activity based on several machine learning algorithms using the new open-source TON_IoT dataset [<xref ref-type="bibr" rid="ref-6">6</xref>]. The contribution of this paper is summarized as the following:<list list-type="bullet"><list-item>
<p>Review of the perception of intrusion detection methods on IoT applications.</p></list-item><list-item>
<p>Proposes an intelligent intrusion detection framework for detecting malicious actions in the industrial IoT environment.</p></list-item><list-item>
<p>The system is applied to different types of data, such as IoT/IIoT, based telemetry data involving operating system logs and IoT-based traffic networks collected from a realistic medium-scale IoT network.</p></list-item><list-item>
<p>The techniques in the proposed framework were carefully chosen based on their broad use in the security realm, as they have verified a good performance in the design of intrusion detection systems.</p></list-item><list-item>
<p>Conducting different experiments and analyses for metrics such as accuracy, F1 score, precision, and recall, along with the Receiver Operating Characteristic (ROC) curve, to evaluate the effectiveness of the proposed work for efficiently detecting intrusion trials.</p></list-item><list-item>
<p>Performing a detailed comparative analysis to compare the security and detection performance of the proposed IDS and the other related IDSs.</p></list-item></list></p>
<p>The rest of this paper is organized as follows. First, Section 2 presents the existing work regarding intrusion detection systems, while Section 3 provides candidate machine learning methods. Then, Section 4 defines the proposed intrusion detection system in IoT infrastructure, while the experimental environment with results assessment is given in Section 5. Finally, the conclusion and future scope of this manuscript are introduced in Section 6.</p>
</sec>
<sec id="s2">
<label>2</label><title>Related Work</title>
<p>Recently, the security of the IoT has become perilous; therefore, different studies are related to this area [<xref ref-type="bibr" rid="ref-7">7</xref>&#x2013;<xref ref-type="bibr" rid="ref-19">19</xref>]. Several works have been proposed for detecting intrusion using intelligent approaches like classification and detection [<xref ref-type="bibr" rid="ref-20">20</xref>&#x2013;<xref ref-type="bibr" rid="ref-30">30</xref>].</p>
<p>In [<xref ref-type="bibr" rid="ref-7">7</xref>], they used classification methods on the water data where they accomplished different scenarios on the selected features in the water dataset that were gathered from real critical infrastructure with calculated only the accuracy of the classification methods. In [<xref ref-type="bibr" rid="ref-8">8</xref>], they presented a review on detecting Cyber-Physical Systems (CPS) intrusion actions. Their work classified the CPSs into two types based on the potential detection system. In [<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>], they presented a security analysis of a critical cyber-physical system. This assessment comprises various layers like supervisory and control networks, where they presented a methodology of grey-box penetration testing to penetrate an attack on the target system to perform as an intrusion detection system (IDS).</p>
<p>In [<xref ref-type="bibr" rid="ref-11">11</xref>], they developed an Intrusion detection system using Naive Bayesian networks. In this work, a class of a connection is represented by a root node, while the leaf nodes present features of a connection. In [<xref ref-type="bibr" rid="ref-12">12</xref>], the authors proposed a network-based IDS using a genetic algorithm to recognize anomalous behavior. In [<xref ref-type="bibr" rid="ref-13">13</xref>], they proposed host-based IDS using an ensemble approach and language modeling to decrease the false alarm rates. In [<xref ref-type="bibr" rid="ref-14">14</xref>], they presented a dataset to recognize Denial-of-Service (DoS) attacks in an IoT system. Their system classified the traffic into two types: normal and several DoS attacks.</p>
<p>In [<xref ref-type="bibr" rid="ref-15">15</xref>], they proposed a novel type of anomaly intrusion detection algorithm for unlabeled data clustering to detect new-found intrusions. Reference [<xref ref-type="bibr" rid="ref-16">16</xref>] presented an effective method based on hybrid classifiers to classify the data with high detection and low false alarm rates. In [<xref ref-type="bibr" rid="ref-17">17</xref>], they introduced an optimal feature selection algorithm to help in detecting network intrusion. In [<xref ref-type="bibr" rid="ref-18">18</xref>], they provided an online attack detection model to collect evidence related to the attack that can be used in computer forensics. In [<xref ref-type="bibr" rid="ref-19">19</xref>], they presented an intrusion detection approach using 10&#x0025; of the knowledge discovery and data mining (KDD) cup&#x2019;99 dataset to compare the attack types and the protocol used by the attackers.</p>
</sec>
<sec id="s3">
<label>3</label><title>Machine Learning Approaches</title>
<p>In the last years, several ML techniques have been used for detecting intrusion activities [<xref ref-type="bibr" rid="ref-31">31</xref>]:<list list-type="bullet"><list-item>
<p><bold>Gaussian Naive Bayes (NB):</bold> The NB uses probability to categorize the features, where it uses normal probability distributions and presumes that the data are normally distributed. This method is used for efficiently performing the classification process.</p></list-item><list-item>
<p><bold>Linear Discriminant Analysis (LDA):</bold> To reduce the dimensions of a provided classification job, the LDA is used by focusing on maximizing the separability among identified types.</p></list-item><list-item>
<p><bold>K-Nearest Neighbors (KNN):</bold> The KNN is used for the regression and classification. The KNN does not have a training phase like the other machine learning algorithms. Instead, the key idea of KNN is to detect the <italic>K</italic> number of neighbors, and various predefined classes assign a class to the unspecified point.</p></list-item><list-item>
<p><bold>Random Forest (RF):</bold> The RF is used for combining multiple decision trees that use arbitrarily picked data points as their input, so it is known as ensemble learning. It classifies the data according to the results of a decision tree collection. The last result of the classification process can be decided by majority or weighted voting.</p></list-item><list-item>
<p><bold>Classification and Regression Tree (CART):</bold> A decision tree is defined as a structure in which every node indicates a test feature, every branch indicates a test result, and every leaf or node contains a class name. The CART can be used with both numerical and categorical data.</p></list-item></list></p>
</sec>
<sec id="s4">
<label>4</label><title>Proposed System</title>
<p>The projected intelligent intrusion detection system for malicious activities analysis and classification for IoT structure is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>. The proposed framework is accomplished in the following phases:<list list-type="bullet"><list-item>
<p><bold>Phase 1:</bold> The data is gathered from the IoT/IIoT testbed (TON_IoT dataset) that contains IoT/IIoT services-based Telemetry data that involves logs of Operating Systems and IoT-based traffic network logs collected from a realistic medium-scale IoT network.</p>
</list-item><list-item>
<p><bold>Phase 2:</bold> The TON_IoT dataset is used for applying the experimental study for intrusion detection and classification in IoT systems.</p></list-item><list-item>
<p><bold>Phase 3:</bold> Pre-processing process is performed on the datasets, and the features (date, time, timestamp, and type) in IoT datasets were removed from feature vectors as they may cause some machine learning methods to over-fit the training data.</p></list-item><list-item>
<p><bold>Phase 4:</bold> The data has been split into training and testing data, where the training data has 80&#x0025; while the testing data has 20&#x0025; of the entire dataset.</p></list-item><list-item>
<p><bold>Phase 5:</bold> Categorizing the accumulated data and splitting it into normal or attack.</p></list-item><list-item>
<p><bold>Phase 6:</bold> Customary performance metrics such as accuracy, precision, recall, and F1-score are used to evaluate the methods employed in the proposed framework.</p></list-item><list-item>
<p><bold>Phase 7:</bold> Demonstrating the accomplished results to decide if there is any malicious action from criminals appearing in the collected data in the IoT environment.</p></list-item><list-item>
<p><bold>Phase 8:</bold> Present a comparative study evaluation and analysis amongst different scenarios using various selected ML algorithms for binary classification for normal or intrusion activity.</p></list-item></list></p>
<fig id="fig-2">
<label>Figure 2</label>
<caption><title>Proposed IoT-based intrusion detection system</title></caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_34095-fig-2.tif"/>
</fig>
</sec>
<sec id="s5">
<label>5</label><title>Experimental Study and Results Analysis</title>
<p>This division delivers the evaluation and analysis of experimental results of the planned intrusion system on the Internet of Things.&#x200f;</p>
<sec id="s5_1">
<label>5.1</label><title>Datasets and Experimental Environment</title>
<p>The planned model estimates the experimental IoT/IIoT data. Then, the TON_IoT datasets are applied within the proposed system for intrusion detection objectives. Finally, the comprehensive information of these datasets, like the name of attributes and their numbers for training and testing, is highlighted in <xref ref-type="table" rid="table-1">Table 1</xref>. The test scenarios are executed using machine learning algorithms written in Python running on Windows 8.1 with Intel&#x00AE; Core&#x2122; i5-4288U CPU @ 2.60&#x2005;GHz processor and 12.00&#x2005;GB RAM.</p>
<table-wrap id="table-1"><label>Table 1</label>
<caption><title>Datasets description</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Datasets</th>
<th align="left">Attributes names</th>
<th align="left">Number of attributes</th>
</tr>
</thead>
<tbody valign="top">
<tr>
<td align="left">Dataset 1 (Train_Test_IoT_Fridge)</td>
<td align="left">ts, date, time, fridge_temperature, temp_condition, label</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">Dataset 2 (Train_Test_IoT_Garage_Door)</td>
<td align="left">ts, date, time, door_state, sphone_signal, label</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">Dataset 3 (Train_Test_IoT_GPS_Tracker)</td>
<td align="left">ts, date, time, latitude, longitude, label</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">Dataset 4 (Train_Test_IoT_Modbus)</td>
<td align="left">ts, date, time, FC1_Read_Input_Register, FC2_Read_Discrete_Value, FC3_Read_Holding_Register, FC4_Read_Coil, label</td>
<td align="left">8</td>
</tr>
<tr>
<td align="left">Dataset 5 (Train_Test_IoT_Motion_Light)</td>
<td align="left">ts, date, time, motion_status, light_status, label</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">Dataset 6 (Train_Test_IoT_Thermostat)</td>
<td align="left">ts, date, time, current_temperature, thermostat_status, label</td>
<td align="left">6</td>
</tr>
<tr>
<td align="left">Dataset 7 (Train_Test_IoT_Weather)</td>
<td align="left">ts, date, time, temperature, pressure, humidity, label</td>
<td align="left">7</td>
</tr>
<tr>
<td align="left">Dataset 8 (Train_Test_Linux_disk)</td>
<td align="left">ts, PID, RDDSK, WRDSK, WCANCL, DSK, CMD, label</td>
<td align="left">8</td>
</tr>
<tr>
<td align="left">Dataset 9 (Train_Test_Linux_memory)</td>
<td align="left">ts, PID, MINFLT, MAJFLT, VSTEXT, VSIZE, RSIZE, VGROW, RGROW, MEM, CMD, label</td>
<td align="left">12</td>
</tr>
<tr>
<td align="left">Dataset 10 (train_Test_Linux_process)</td>
<td align="left">ts, PID, TRUN, TSLPI, TSLPU, POLI, NICE, PRI, RTPR, CPUNR, Status, EXC, State, CPU, CMD, label</td>
<td align="left">16</td>
</tr>
<tr>
<td align="left">Dataset 11 (Train_Test_Network)</td>
<td align="left">ts, src_ip, src_port, dst_ip, dst_port, proto, service, duration, src_bytes, dst_bytes, conn_state, missed_bytes, src_pkts, src_ip_bytes, dst_pkts, dst_ip_bytes, dns_query, dns_qclass, dns_qtype, dns_rcode, dns_AA, dns_RD, dns_RA, dns_rejected, ssl_version, ssl_cipher, ssl_resumed, ssl_established, ssl_subject, ssl_issuer,http_trans_depth, http_method, http_uri, http_version,http_request_body_len, http_response_body_len, http_status_code, http_user_agent, http_orig_mime_types, http_resp_mime_types, weird_name, weird_addl, weird_notice, label</td>
<td align="left">44</td>
</tr>
<tr>
<td align="left">Dataset 12 (Train_Test_Windows_7)</td>
<td align="left">Processor(_Total) DPC Rate, Processor(_Total) pct_ Idle Time, Processor(_Total) pct_ C3 Time, Memory Pool Paged Resident Bytes, label</td>
<td align="left">134</td>
</tr>
<tr>
<td align="left">Dataset 13 (Train_Test_Windows_10)</td>
<td align="left">Processor_DPC_Rate, Processor_pct_ Idle_Time, Processor_pct_ C3_Time, Processor_pct_ Interrupt_Time, Processor_pct_ C2_Time, label</td>
<td align="left">126</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s5_2">
<label>5.2</label><title>Performance Evaluation Metrics</title>
<p>The performance assessment of the proposed system in a precise classification process is calculated by various metrics like accuracy, precision, recall, and F-score can be used. First, the remarks are accomplished by considering true negatives (TN), true positives (TP), false positives (FP), and false negatives (FN). After assessing the parameters in the confusion matrix as tabulated in <xref ref-type="table" rid="table-2">Table 2</xref>. Then, the evaluation metrics are calculated as in <xref ref-type="disp-formula" rid="eqn-1">Eqs. (1)</xref> to <xref ref-type="disp-formula" rid="eqn-4">(4)</xref>:</p>

<p><disp-formula id="eqn-1"><label>(1)</label>
<mml:math id="mml-eqn-1" display="block"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>c</mml:mi><mml:mi>u</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:mstyle></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-2"><label>(2)</label>
<mml:math id="mml-eqn-2" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>P</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:mstyle></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-3"><label>(3)</label>
<mml:math id="mml-eqn-3" display="block"><mml:mrow><mml:mi mathvariant="normal">R</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mi mathvariant="normal">l</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:mstyle></mml:math>
</disp-formula></p>
<p><disp-formula id="eqn-4"><label>(4)</label>
<mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:mi mathvariant="normal">F</mml:mi></mml:mrow><mml:mn>1</mml:mn><mml:mspace width="thinmathspace" /><mml:mo>&#x2212;</mml:mo><mml:mspace width="thinmathspace" /><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>2</mml:mn><mml:mspace width="thinmathspace" /><mml:mo>&#x00D7;</mml:mo><mml:mspace width="thinmathspace" /><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mrow><mml:mfrac><mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mspace width="thinmathspace" /><mml:mo>&#x00D7;</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow><mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo>+</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:mfrac></mml:mrow></mml:mstyle></mml:math>
</disp-formula></p>
<table-wrap id="table-2"><label>Table 2</label>
<caption><title>Representation of confusion matrix (CM)</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left"/>
<th align="left">Predicted (&#x2212;)</th>
<th align="left">Predicted (&#x002B;)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Actual (&#x2212;)</td>
<td align="left">TP</td>
<td align="left">FN</td>
</tr>
<tr>
<td align="left">Actual (&#x002B;)</td>
<td align="left">FP</td>
<td align="left">TN</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The intrusion detection model in the IoT system, which is consists of four essential phases, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref> like the following:<list list-type="simple"><list-item><label>1)</label>
<p><bold>Data Preparation Phase (DPP):</bold> In this phase, the real dataset from the IoT system was pre-processed to be organized during the training and testing stages. The key procedure achieved in this stage is data handling. Most instances for every situation have been certain from the collected data. The collected data is in the form of a TON_IoT dataset containing IoT/IIoT services-based Telemetry data that includes operating systems logs and IoT traffic network gathered from a realistic medium-scale IoT network. The data are split into two cliques; the first is 80&#x0025;, and the second is 20&#x0025; for training and testing.</p>
</list-item><list-item><label>2)</label>
<p><bold>Preprocessing Phase (PP):</bold> This phase includes the pre-processing process that is accomplished on the data with selected features like date, time, and timestamp, type in the IoT datasets which are uninvolved from feature vectors as they may cause some machine learning algorithms to over-fit the training data.</p></list-item><list-item><label>3)</label>
<p><bold>IoT-based Intrusion Detection Phase (I2DP):</bold> This phase concerns classifying the collected data and splitting it into normal or attacks for the used datasets. Then, utilizing the obtained results to decide if any intrusion activity from attackers can happen in the IoT infrastructure.</p></list-item><list-item><label>4)</label>
<p><bold>Performance Assessment Phase (PAP):</bold> This phase uses common evaluation metrics like accuracy, precision, recall, and F1-score to estimate the candidate approaches within the proposed system. Finally, effectively perform a comparison analysis between particular circumstances using nominated machine learning methods for normal or intrusion actions classification.</p></list-item></list></p>
<fig id="fig-3">
<label>Figure 3</label>
<caption><title>Phases of the proposed intrusion detection model</title></caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_34095-fig-3.tif"/>
</fig>
<p>The projected intrusion detection approach can be described in a comprehensive Framework for smart IoT/IIoT infrastructure, as shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>, which includes three main stages as follows:<list list-type="bullet"><list-item>
<p><bold>Stage One:</bold> Data Acquisition<list list-type="simple"><list-item><label>&#x25CB;</label>
<p>Data gathering from IoT/IIoT sensors in a smart environment like the smart city.</p>
</list-item><list-item><label>&#x25CB;</label>
<p>After collecting all data, it is used to create an IoT/IIoT dataset.</p></list-item></list></p></list-item><list-item>
<p><bold>Stage Two:</bold> Data Handling and Management<list list-type="simple"><list-item><label>&#x25CB;</label>
<p>Pre-processing involves data handling, like selecting specific features to be suitable for the analytical engines.</p></list-item><list-item><label>&#x25CB;</label>
<p>The data has been split into two sets; one set has 80&#x0025; for training, and another set has 20&#x0025; for testing.</p></list-item></list></p></list-item><list-item>
<p><bold>Stage Three:</bold> IoT Data Classification for Intrusion Detection<list list-type="simple"><list-item><label>&#x25CB;</label>
<p>Classifying the gathered data and grouping them into normal or intrusion classes.</p></list-item><list-item><label>&#x25CB;</label>
<p>Evaluate classification models using assessment metrics with the comparative analysis of several ML approaches for detecting intrusion actions in an IoT environment.</p></list-item><list-item><label>&#x25CB;</label>
<p>Visualizing the results on the management console to make an alarm if any intrusion appeared in the gathered data. Then, finally, the security professional can decide and take the appropriate action.</p></list-item></list></p></list-item></list></p>
<fig id="fig-4">
<label>Figure 4</label>
<caption><title>Comprehensive intrusion detection framework in smart IoT/IIoT infrastructure</title></caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_34095-fig-4.tif"/>
</fig>
</sec>
<sec id="s5_3">
<label>5.3</label><title>Results Analysis</title>
<p>This part discusses the performance of the candidate machine learning methods for intrusion detection objectives using IoT datasets. To evaluate the performance of several machine learning approaches on the TON_IoT dataset for thirteen different datasets, the next several test cases were studied:<list list-type="bullet"><list-item>
<p>Classifying the seven IoT sensors linking records as either normal or attack.</p></list-item><list-item>
<p>Classifying the network connection record as either normal or malicious activity (i.e., attack).</p></list-item><list-item>
<p>Classifying the Linux Operating system data from three different scenarios Linux OS disk, Memory, and process records as either normal or malicious activity (i.e., attack).</p></list-item><list-item>
<p>Classifying the Windows operating system data from three different scenarios, Windows7 OS, and Windows10 OS records as either normal or malicious activity (i.e., attack).</p></list-item></list></p>
<p>Publicly accessible TON_IoT datasets are used to assess the performance of candidate machine-learning algorithms to identify a baseline system. These datasets include the IoT/IIoT services-based Telemetry data that involves logs of Operating Systems and IoT-based traffic networks collected from a realistic medium-scale IoT network. The total number of datasets is thirteen that are separated into train and test datasets, with applying the necessary pre-processing mechanism as normalization to be ready to use by the machine learning models such as LR, LDA, KNN, NB, CART, RF, and AB for classification and detection of intrusion activities in an efficient way. First, train and test datasets are used to train and test the models. Then, metrics such as accuracy, precision, recall, F1-score, and ROC curve are used to assess the proposed framework.</p>
<p>To understand more interpretation for the obtained results, a comparative analysis among the models on the used datasets using each metric individually is presented in <xref ref-type="table" rid="table-3">Tables 3</xref>&#x2013;<xref ref-type="table" rid="table-6">6</xref>. These tables show the machine learning models&#x2019; results on the thirteen examined datasets. The results represent the comparison among the used models based on accuracy, precision, recall, and F1-score, respectively. For dataset 1, the KNN outperforms the other models, while the NB gives fewer results based on all metrics. For dataset 2, all models give the same results, which are 100&#x0025; for all metrics. For dataset 3, the RF outperforms the other models, while the NB gives fewer results based on all metrics. For dataset 4, the CART outperforms the other models, while the LR, LDA, and NB give fewer results based on all metrics. For dataset 5, all models give the same results, except the KNN gives fewer results based on all metrics. For dataset 6, all models give the same results except KNN and CART, where the KNN gives fewer results based on all metrics. For dataset 7, the CART outperforms the other models, while the LR and LDA give fewer results based on all metrics. For dataset 8, the CART outperforms the other models, while the LR gives fewer results based on all metrics. For dataset 9, KNN, CART, AB, and RF models give the same results, which are the highest, while the LR gives fewer results based on all metrics. Like dataset 9, KNN, CART, AB, and RF models give the same results, which are the highest, while the LR gives fewer results based on all metrics for dataset 10. The NB outperforms the other models, while the RF gives fewer results based on all metrics for dataset 11. For dataset 12, The RF outperforms the other models while the NB gives fewer results based on all metrics. Finally, for dataset 13, the AB outperforms the other models, while the KNN gives low results based on all tested metrics.</p>
<table-wrap id="table-3"><label>Table 3</label>
<caption><title>Accuracy results of dataset 1(D1) to dataset 13 (D13)</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th align="left" rowspan="2">Algorithm</th>
<th align="center" colspan="13">Accuracy</th>
</tr>
<tr>
<th align="left">D1</th>
<th align="left">D2</th>
<th align="left">D3</th>
<th align="left">D4</th>
<th align="left">D5</th>
<th align="left">D6</th>
<th align="left">D7</th>
<th align="left">D8</th>
<th align="left">D9</th>
<th align="left">D10</th>
<th align="left">D11</th>
<th align="left">D12</th>
<th align="left">D13</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">LR</td>
<td align="left">0.81</td>
<td align="left">1.00</td>
<td align="left">0.86</td>
<td align="left">0.68</td>
<td align="left">0.58</td>
<td align="left">0.66</td>
<td align="left">0.61</td>
<td align="left">1.00</td>
<td align="left">0.94</td>
<td align="left">0.61</td>
<td align="left">0.63</td>
<td align="left">0.73</td>
<td align="left">0.62</td>
</tr>
<tr>
<td align="left">LDA</td>
<td align="left">0.80</td>
<td align="left">1.00</td>
<td align="left">0.87</td>
<td align="left">0.68</td>
<td align="left">0.58</td>
<td align="left">0.66</td>
<td align="left">0.61</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.78</td>
<td align="left">0.64</td>
<td align="left">0.73</td>
<td align="left">0.83</td>
</tr>
<tr>
<td align="left">NB</td>
<td align="left">0.50</td>
<td align="left">1.00</td>
<td align="left">0.85</td>
<td align="left">0.68</td>
<td align="left">0.58</td>
<td align="left">0.66</td>
<td align="left">0.69</td>
<td align="left">0.69</td>
<td align="left">0.96</td>
<td align="left">0.96</td>
<td align="left">0.65</td>
<td align="left">0.67</td>
<td align="left">0.73</td>
</tr>
<tr>
<td align="left">KNN</td>
<td align="left">0.99</td>
<td align="left">1.00</td>
<td align="left">0.91</td>
<td align="left">0.78</td>
<td align="left">0.42</td>
<td align="left">0.56</td>
<td align="left">0.80</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.38</td>
<td align="left">0.97</td>
<td align="left">0.43</td>
</tr>
<tr>
<td align="left">CART</td>
<td align="left">0.97</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.99</td>
<td align="left">0.58</td>
<td align="left">0.59</td>
<td align="left">0.88</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.37</td>
<td align="left">0.88</td>
<td align="left">0.88</td>
</tr>
<tr>
<td align="left">AB</td>
<td align="left">0.94</td>
<td align="left">1.00</td>
<td align="left">0.90</td>
<td align="left">0.68</td>
<td align="left">0.58</td>
<td align="left">0.66</td>
<td align="left">0.72</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.57</td>
<td align="left">0.88</td>
<td align="left">0.90</td>
</tr>
<tr>
<td align="left">RF</td>
<td align="left">0.97</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.98</td>
<td align="left">0.58</td>
<td align="left">0.66</td>
<td align="left">0.86</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.36</td>
<td align="left">0.97</td>
<td align="left">0.66</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-4"><label>Table 4</label>
<caption><title>Precision results of dataset 1(D1) to dataset 13 (D13)</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th align="left" rowspan="2">Algorithm</th>
<th align="center" colspan="13">Precision</th>
</tr>
<tr>
<th align="left">D1</th>
<th align="left">D2</th>
<th align="left">D3</th>
<th align="left">D4</th>
<th align="left">D5</th>
<th align="left">D6</th>
<th align="left">D7</th>
<th align="left">D8</th>
<th align="left">D9</th>
<th align="left">D10</th>
<th align="left">D11</th>
<th align="left">D12</th>
<th align="left">D13</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">LR</td>
<td align="left">0.87</td>
<td align="left">1.00</td>
<td align="left">0.86</td>
<td align="left">0.34</td>
<td align="left">0.29</td>
<td align="left">0.33</td>
<td align="left">0.59</td>
<td align="left">0.50</td>
<td align="left">0.96</td>
<td align="left">0.64</td>
<td align="left">0.78</td>
<td align="left">0.66</td>
<td align="left">0.31</td>
</tr>
<tr>
<td align="left">LDA</td>
<td align="left">0.84</td>
<td align="left">1.00</td>
<td align="left">0.86</td>
<td align="left">0.34</td>
<td align="left">0.29</td>
<td align="left">0.33</td>
<td align="left">0.59</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.85</td>
<td align="left">0.81</td>
<td align="left">0.67</td>
<td align="left">0.86</td>
</tr>
<tr>
<td align="left">NB</td>
<td align="left">0.51</td>
<td align="left">1.00</td>
<td align="left">0.84</td>
<td align="left">0.34</td>
<td align="left">0.29</td>
<td align="left">0.33</td>
<td align="left">0.70</td>
<td align="left">0.50</td>
<td align="left">0.95</td>
<td align="left">0.96</td>
<td align="left">0.80</td>
<td align="left">0.60</td>
<td align="left">0.72</td>
</tr>
<tr>
<td align="left">KNN</td>
<td align="left">0.99</td>
<td align="left">1.00</td>
<td align="left">0.91</td>
<td align="left">0.75</td>
<td align="left">0.29</td>
<td align="left">0.50</td>
<td align="left">0.80</td>
<td align="left">0.68</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.42</td>
<td align="left">0.95</td>
<td align="left">0.51</td>
</tr>
<tr>
<td align="left">CART</td>
<td align="left">0.98</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.29</td>
<td align="left">0.51</td>
<td align="left">0.87</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.41</td>
<td align="left">0.85</td>
<td align="left">0.87</td>
</tr>
<tr>
<td align="left">AB</td>
<td align="left">0.95</td>
<td align="left">1.00</td>
<td align="left">0.89</td>
<td align="left">0.75</td>
<td align="left">0.29</td>
<td align="left">0.54</td>
<td align="left">0.71</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.51</td>
<td align="left">0.86</td>
<td align="left">0.89</td>
</tr>
<tr>
<td align="left">RF</td>
<td align="left">0.98</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.99</td>
<td align="left">0.29</td>
<td align="left">0.51</td>
<td align="left">0.86</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.40</td>
<td align="left">0.96</td>
<td align="left">0.75</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-5"><label>Table 5</label>
<caption><title>Recall results of dataset 1(D1) to dataset 13 (D13)</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th align="left" rowspan="2">Algorithm</th>
<th align="center" colspan="13">Recall</th>
</tr>
<tr>
<th align="left">D1</th>
<th align="left">D2</th>
<th align="left">D3</th>
<th align="left">D4</th>
<th align="left">D5</th>
<th align="left">D6</th>
<th align="left">D7</th>
<th align="left">D8</th>
<th align="left">D9</th>
<th align="left">D10</th>
<th align="left">D11</th>
<th align="left">D12</th>
<th align="left">D13</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">LR</td>
<td align="left">0.78</td>
<td align="left">1.00</td>
<td align="left">0.87</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.54</td>
<td align="left">0.50</td>
<td align="left">0.92</td>
<td align="left">0.60</td>
<td align="left">0.50</td>
<td align="left">0.55</td>
<td align="left">0.50</td>
</tr>
<tr>
<td align="left">LDA</td>
<td align="left">0.77</td>
<td align="left">1.00</td>
<td align="left">0.88</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.54</td>
<td align="left">0.88</td>
<td align="left">0.99</td>
<td align="left">0.78</td>
<td align="left">0.51</td>
<td align="left">0.55</td>
<td align="left">0.79</td>
</tr>
<tr>
<td align="left">NB</td>
<td align="left">0.51</td>
<td align="left">1.00</td>
<td align="left">0.85</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.65</td>
<td align="left">0.84</td>
<td align="left">0.95</td>
<td align="left">0.96</td>
<td align="left">0.52</td>
<td align="left">0.59</td>
<td align="left">0.70</td>
</tr>
<tr>
<td align="left">KNN</td>
<td align="left">0.99</td>
<td align="left">1.00</td>
<td align="left">0.91</td>
<td align="left">0.73</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.79</td>
<td align="left">0.55</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.43</td>
<td align="left">0.97</td>
<td align="left">0.51</td>
</tr>
<tr>
<td align="left">CART</td>
<td align="left">0.97</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.98</td>
<td align="left">0.50</td>
<td align="left">0.51</td>
<td align="left">0.87</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.43</td>
<td align="left">0.87</td>
<td align="left">0.87</td>
</tr>
<tr>
<td align="left">AB</td>
<td align="left">0.93</td>
<td align="left">1.00</td>
<td align="left">0.90</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.69</td>
<td align="left">0.99</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.51</td>
<td align="left">0.84</td>
<td align="left">0.89</td>
</tr>
<tr>
<td align="left">RF</td>
<td align="left">0.97</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.97</td>
<td align="left">0.50</td>
<td align="left">0.50</td>
<td align="left">0.84</td>
<td align="left">0.99</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.42</td>
<td align="left">0.97</td>
<td align="left">0.72</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-6"><label>Table 6</label>
<caption><title>F1-Score results of dataset 1(D1) to dataset 13 (D13)</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th align="left" rowspan="2">Algorithm</th>
<th align="center" colspan="13">F1-score</th>
</tr>
<tr>
<th align="left">D1</th>
<th align="left">D2</th>
<th align="left">D3</th>
<th align="left">D4</th>
<th align="left">D5</th>
<th align="left">D6</th>
<th align="left">D7</th>
<th align="left">D8</th>
<th align="left">D9</th>
<th align="left">D10</th>
<th align="left">D11</th>
<th align="left">D12</th>
<th align="left">D13</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">LR</td>
<td align="left">0.79</td>
<td align="left">1.00</td>
<td align="left">0.86</td>
<td align="left">0.41</td>
<td align="left">0.37</td>
<td align="left">0.40</td>
<td align="left">0.49</td>
<td align="left">0.50</td>
<td align="left">0.93</td>
<td align="left">0.58</td>
<td align="left">0.40</td>
<td align="left">0.53</td>
<td align="left">0.38</td>
</tr>
<tr>
<td align="left">LDA</td>
<td align="left">0.77</td>
<td align="left">1.00</td>
<td align="left">0.86</td>
<td align="left">0.41</td>
<td align="left">0.37</td>
<td align="left">0.40</td>
<td align="left">0.50</td>
<td align="left">0.93</td>
<td align="left">0.99</td>
<td align="left">0.77</td>
<td align="left">0.42</td>
<td align="left">0.52</td>
<td align="left">0.80</td>
</tr>
<tr>
<td align="left">NB</td>
<td align="left">0.50</td>
<td align="left">1.00</td>
<td align="left">0.85</td>
<td align="left">0.41</td>
<td align="left">0.37</td>
<td align="left">0.40</td>
<td align="left">0.65</td>
<td align="left">0.42</td>
<td align="left">0.95</td>
<td align="left">0.96</td>
<td align="left">0.43</td>
<td align="left">0.59</td>
<td align="left">0.71</td>
</tr>
<tr>
<td align="left">KNN</td>
<td align="left">0.99</td>
<td align="left">1.00</td>
<td align="left">0.91</td>
<td align="left">0.74</td>
<td align="left">0.37</td>
<td align="left">0.50</td>
<td align="left">0.79</td>
<td align="left">0.58</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.38</td>
<td align="left">0.96</td>
<td align="left">0.41</td>
</tr>
<tr>
<td align="left">CART</td>
<td align="left">0.97</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.99</td>
<td align="left">0.37</td>
<td align="left">0.50</td>
<td align="left">0.87</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.37</td>
<td align="left">0.86</td>
<td align="left">0.88</td>
</tr>
<tr>
<td align="left">AB</td>
<td align="left">0.94</td>
<td align="left">1.00</td>
<td align="left">0.89</td>
<td align="left">0.42</td>
<td align="left">0.37</td>
<td align="left">0.40</td>
<td align="left">0.70</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.50</td>
<td align="left">0.85</td>
<td align="left">0.89</td>
</tr>
<tr>
<td align="left">RF</td>
<td align="left">0.97</td>
<td align="left">1.00</td>
<td align="left">0.99</td>
<td align="left">0.98</td>
<td align="left">0.37</td>
<td align="left">0.40</td>
<td align="left">0.85</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">1.00</td>
<td align="left">0.35</td>
<td align="left">0.96</td>
<td align="left">0.66</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The ROC curve is a standard metric used to evaluate the system performance where the machine learning model is better if the AUC is higher. For example, <xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows the ROC results for all models on the used dataset1. In addition, the confusion matrix shows the correct and incorrect classification percentages for all examined ML models. For the simple presentation of results, the obtained confusion matrices of all employed ML models for the tested dataset 12, as shown in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>. It is clear for the attained results that the utilized ML models introduce high classification ratios and low misclassification ratios.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption><title>ROC curves of all examined ML models for dataset 1</title></caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_34095-fig-5.tif"/>
</fig><fig id="fig-6">
<label>Figure 6</label>
<caption><title>Confusion matrices of all examined ML models for dataset 12</title></caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_34095-fig-6.tif"/>
</fig>
<p>To further clarify the security and detection efficacy of the proposed IDS compared to the other related IDSs, a comparative analysis is performed on the same TON_IoT dataset as given in <xref ref-type="table" rid="table-7">Table 7</xref>. The average values of accuracy, precision, recall, and F1 score are estimated. As a result, it is declared that the suggested IDS framework accomplished high detection and accuracy performance compared to the recent related IDS frameworks in terms of all examined assessment parameters.</p>
<table-wrap id="table-7"><label>Table 7</label>
<caption><title>Comparative analysis between the proposed IDS and related IDS frameworks</title></caption>
<table><colgroup><col align="left"/><col align="left"/><col align="left"/><col align="left"/><col align="left"/>
</colgroup>
<thead valign="top">
<tr>
<th align="left">IDS framework</th>
<th align="left">Accuacy (&#x0025;)</th>
<th align="left">Precision (&#x0025;)</th>
<th align="left">Recall (&#x0025;)</th>
<th align="left">F1 score (&#x0025;)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Proposed</td>
<td align="left">98.4</td>
<td align="left">97.8</td>
<td align="left">95.6</td>
<td align="left">98.2</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-16">16</xref>]</td>
<td align="left">79.8</td>
<td align="left">86.4</td>
<td align="left">91.7</td>
<td align="left">93.5</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-23">23</xref>]</td>
<td align="left">96.5</td>
<td align="left">96.7</td>
<td align="left">93.5</td>
<td align="left">96.4</td>
</tr>
<tr>
<td align="left">[<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
<td align="left">97.7</td>
<td align="left">97.68</td>
<td align="left">95.4</td>
<td align="left">98.14</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s6">
<label>6</label><title>Conclusion and Future Scope</title>
<p>This work aims to present an efficient framework to analyze and classify intrusion and malicious activities in IoT Infrastructure using machine learning methods. This system was comprehensively evaluated based on extensive experiments on thirteen datasets collected from IoT/IIoT testbed. Several machine learning-based approaches, such as LR, NB, CART, LDA, KNN, RF, and AB, are used. The obtained results in this paper urge that the CART algorithm gives the highest scores for classification and detection based on the evaluation metrics such as accuracy, precision, recall, and F1-score. Also, the ROC curve results confirmed the same conclusion for the proposed framework. The performed comparisons clarified that the suggested IDS framework accomplished high detection and accuracy performance compared to the recent related IDS frameworks in terms of all examined assessment parameters. In future work, we plan to apply different deep learning algorithms within the proposed scheme to the same datasets. In addition, we plan to investigate the multiclass classification problem for industrial IoT.</p>
</sec>
</body>
<back>
<ack>
<p>Princess Nourah bint Abdulrahman University Researchers Supporting Project Number (PNURSP2022R197), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia.</p>
</ack>
<sec><title>Funding Statement</title>
<p><funding-source>Princess Nourah bint Abdulrahman University Researchers</funding-source> Supporting Project Number (<award-id>PNURSP2022R197</award-id>), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear"><title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I.</given-names> <surname>Akyildiz</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Jornet</surname></string-name></person-group>, &#x201C;<article-title>The internet of nano-things</article-title>,&#x201D; <source>IEEE Wireless Communications</source>, vol. <volume>17</volume>, no. <issue>6</issue>, pp. <fpage>58</fpage>&#x2013;<lpage>63</lpage>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Alarifi</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Sankar</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Altameem</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Jithin</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Amoon</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Novel hybrid cryptosystem for secure streaming of high efficiency H. 265 compressed videos in IoT multimedia applications</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>128548</fpage>&#x2013;<lpage>128573</lpage>, <year>2020</year>&#x200F;.&#x200f;</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Essa</surname></string-name>, <string-name><given-names>A.</given-names> <surname>El-Mahalawy</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Attiya</surname></string-name> and <string-name><given-names>A.</given-names> <surname>El-Sayed</surname></string-name></person-group>, &#x201C;<article-title>IFHDS: Intelligent framework for securing healthcare big data</article-title>,&#x201D; <source>Journal of Medical Systems</source>, vol. <volume>43</volume>, no. <issue>5</issue>, pp. <fpage>124</fpage>&#x2013;<lpage>135</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Akyildiz</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Pierobon</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Balasubramaniam</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Koucheryavy</surname></string-name></person-group>, &#x201C;<article-title>The internet of bio-nano things</article-title>,&#x201D; <source>IEEE Communications Magazine</source>, vol. <volume>53</volume>, no. <issue>3</issue>, pp. <fpage>32</fpage>&#x2013;<lpage>40</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Dressler</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Fischer</surname></string-name></person-group>, &#x201C;<article-title>Connecting in-body nano communication with body area networks: Challenges and opportunities of the internet of nano things</article-title>,&#x201D; <source>Nano Communication Networks</source>, vol. <volume>6</volume>, no. <issue>2</issue>, pp. <fpage>29</fpage>&#x2013;<lpage>38</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Alsaedi</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Moustafa</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Tari</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Mahmood</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Anwar</surname></string-name></person-group>, &#x201C;<article-title>TON_IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>165130</fpage>&#x2013;<lpage>165150</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Hindy</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Brosset</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Bayne</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Seeam</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Bellekens</surname></string-name></person-group>, &#x201C;<article-title>Improving SIEM for critical SCADA water infrastructures using machine learning</article-title>,&#x201D; <source>Journal of Bioinformatics</source>, vol. <volume>11</volume>, no. <issue>3</issue>, pp. <fpage>3</fpage>&#x2013;<lpage>19</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Mitchell</surname></string-name> and <string-name><given-names>I.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>A survey of intrusion detection techniques for cyber-physical systems</article-title>,&#x201D; <source>ACM Computational Survey</source>, vol. <volume>46</volume>, no. <issue>4</issue>, pp. <fpage>55</fpage>&#x2013;<lpage>71</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Amin</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Litrico</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Sastry</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Bayen</surname></string-name></person-group>, &#x201C;<article-title>Cyber security of water SCADA systems part II: Attack detection using enhanced hydrodynamic models</article-title>,&#x201D; <source>IEEE Transactions Control Systems Technolgy</source>, vol. <volume>21</volume>, no. <issue>5</issue>, pp. <fpage>1679</fpage>&#x2013;<lpage>1693</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Amin</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Litrico</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Sastry</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Bayen</surname></string-name></person-group>, &#x201C;<article-title>Cyber security of water SCADA systems part I: Analysis and experimentation of stealthy deception attacks</article-title>,&#x201D; <source>IEEE Transactions Control Systems Technolgy</source>, vol. <volume>21</volume>, no. <issue>5</issue>, pp. <fpage>1963</fpage>&#x2013;<lpage>1970</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>El-Shafai</surname></string-name>, <string-name><given-names>S.</given-names> <surname>El-Rabaie</surname></string-name>, <string-name><given-names>M.</given-names> <surname>El-Halawany</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Abd El-Samie</surname></string-name></person-group>, &#x201C;<article-title>Security of 3D-HEVC transmission based on fusion and watermarking techniques</article-title>,&#x201D; <source>Multimedia Tools and Applications</source>, vol. <volume>78</volume>, no. <issue>19</issue>, pp. <fpage>27211</fpage>&#x2013;<lpage>27244</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>El-Shafai</surname></string-name>, <string-name><given-names>S.</given-names> <surname>El-Rabaie</surname></string-name>, <string-name><given-names>M.</given-names> <surname>El-Halawany</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Abd El-Samie</surname></string-name></person-group>, &#x201C;<article-title>Efficient hybrid watermarking schemes for robust and secure 3D-MVC communication</article-title>,&#x201D; <source>International Journal of Communication Systems</source>, vol. <volume>31</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>23</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>El-Shafai</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Mohamed</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Elkamchouchi</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Abd-Elnaby</surname></string-name> and <string-name><given-names>A.</given-names> <surname>ElShafee</surname></string-name></person-group>, &#x201C;<article-title>Efficient and secure cancelable biometric authentication framework based on genetic encryption algorithm</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>9</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>25</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>El-Shafai</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Almomani</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Alkhayer</surname></string-name></person-group>, &#x201C;<article-title>Optical bit-plane-based 3D-JST cryptography algorithm with cascaded 2D-FrFT encryption for efficient and secure HEVC communication</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>9</volume>, pp. <fpage>35004</fpage>&#x2013;<lpage>35026</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>El-Hag</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Sedik</surname></string-name>, <string-name><given-names>F.</given-names> <surname>El-Samie</surname></string-name>, <string-name><given-names>H.</given-names> <surname>El-Hoseny</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Khalaf</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Classification of retinal images based on convolutional neural network</article-title>,&#x201D; <source>Microscopy Research and Technique</source>, vol. <volume>84</volume>, no. <issue>3</issue>, pp. <fpage>394</fpage>&#x2013;<lpage>414</lpage>, <year>2021</year>&#x200F;.&#x200f;</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Panda</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abraham</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Patra</surname></string-name></person-group>, &#x201C;<article-title>A hybrid intelligent approach for network intrusion detection</article-title>,&#x201D; <source>Procedia Engineering</source>, vol. <volume>30</volume>, no. <issue>5</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>9</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Kang</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>A feature selection approach to find optimal feature subsets for the network intrusion detection system</article-title>,&#x201D; <source>Cluster Computing</source>, vol. <volume>19</volume>, no. <issue>1</issue>, pp. <fpage>325</fpage>&#x2013;<lpage>333</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Soliman</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abd-Alhalem</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abdulrahman</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Abd El-Samie</surname></string-name></person-group>, &#x201C;<article-title>An improved convolutional neural network model for DNA classification</article-title>,&#x201D; <source>Computers, Materials and Continua</source>, vol. <volume>70</volume>, no. <issue>3</issue>, pp. <fpage>5907</fpage>&#x2013;<lpage>5927</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Siddiqui</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Naahid</surname></string-name></person-group>, &#x201C;<article-title>Analysis of KDD CUP 99 dataset using clustering-based data mining</article-title>,&#x201D; <source>International Journal of Database Theory and Application</source>, vol. <volume>6</volume>, no. <issue>5</issue>, pp. <fpage>23</fpage>&#x2013;<lpage>34</lpage>, <year>2013</year>.&#x200F;</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>O.</given-names> <surname>Faragallah</surname></string-name>, <string-name><given-names>M.</given-names> <surname>AlZain</surname></string-name>, <string-name><given-names>H.</given-names> <surname>El-Sayed</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Al-Amri</surname></string-name>, <string-name><given-names>F.</given-names> <surname>El-Samie</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Secure color image cryptosystem based on chaotic logistic in the FrFT domain</article-title>,&#x201D; <source>Multimedia Tools and Applications</source>, vol. <volume>79</volume>, no. <issue>3</issue>, pp. <fpage>2495</fpage>&#x2013;<lpage>2519</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Nasir</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Mehmood</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Zubair</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Network meddling detection using machine learning empowered with blockchain technology</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>22</volume>, no. <issue>18</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>El-Hoseny</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Abd El-Rahman</surname></string-name>, <string-name><given-names>F.</given-names> <surname>El-Samie</surname></string-name>, <string-name><given-names>G.</given-names> <surname>El-Banby</surname></string-name>, <string-name><given-names>E.</given-names> <surname>El-Rabaie</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Efficient multi-scale non-sub-sampled shearlet fusion system based on modified central force optimization and contrast enhancement</article-title>,&#x201D; <source>Infrared Physics &#x0026; Technology</source>, vol. <volume>10</volume>, no. <issue>2</issue>, pp. <fpage>102</fpage>&#x2013;<lpage>123</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Le</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Oktian</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Kim</surname></string-name></person-group>, &#x201C;<article-title>XGBoost for imbalanced multiclass classification-based industrial internet of things intrusion detection systems</article-title>,&#x201D; <source>Sustainability</source>, vol. <volume>14</volume>, no. <issue>14</issue>, pp. <fpage>87</fpage>&#x2013;<lpage>105</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Alshammri</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Samha</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Hemdan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Amoon</surname></string-name> and <string-name><given-names>W.</given-names> <surname>El-Shafai</surname></string-name></person-group>, &#x201C;<article-title>An efficient intrusion detection framework in software-defined networking for cybersecurity applications</article-title>,&#x201D; <source>CMC-Computers Materials &#x0026; Continua</source>, vol. <volume>72</volume>, no. <issue>2</issue>, pp. <fpage>3529</fpage>&#x2013;<lpage>3548</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>AbuKhurma</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Almomani</surname></string-name> and <string-name><given-names>I.</given-names> <surname>Aljarah</surname></string-name></person-group>, &#x201C;<article-title>IoT botnet detection using salp swarm and ant lion hybrid optimization model</article-title>,&#x201D; <source>Symmetry</source>, vol. <volume>13</volume>, no. <issue>8</issue>, pp. <fpage>13</fpage>&#x2013;<lpage>77</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Dahou</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Abd Elaziz</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Chelloug</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Awadallah</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Al-Betar</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Intrusion detection system for IoT based on deep learning and modified reptile search algorithm</article-title>,&#x201D; <source>Computational Intelligence and Neuroscience</source>, vol. <volume>2</volume>, no. <issue>3</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>17</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Moustafa</surname></string-name></person-group>, &#x201C;<article-title>A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets</article-title>,&#x201D; <source>Sustainable Cities and Society</source>, vol. <volume>7</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>13</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Qaddoura</surname></string-name>, <string-name><given-names>A. M.</given-names> <surname>Al-Zoubi</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Faris</surname></string-name> and <string-name><given-names>I.</given-names> <surname>Almomani</surname></string-name></person-group>, &#x201C;<article-title>A multi-layer classification approach for intrusion detection in IoT networks based on deep learning</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>21</volume>, no. <issue>9</issue>, pp. <fpage>29</fpage>&#x2013;<lpage>87</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Dina</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Manivannan</surname></string-name></person-group>, &#x201C;<article-title>Intrusion detection based on machine learning techniques in computer networks</article-title>,&#x201D; <source>Internet of Things</source>, vol. <volume>1</volume>, no. <issue>6</issue>, pp. <fpage>100</fpage>&#x2013;<lpage>117</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>El-Hoseny</surname></string-name>, <string-name><given-names>W.</given-names> <surname>El-Rahman</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Abd El-Samie</surname></string-name>, <string-name><given-names>S. M.</given-names> <surname>El-Rabaie</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Mahmoud</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Optimal multi-scale geometric fusion based on non-subsampled contourlet transform and modified central force optimization</article-title>,&#x201D; <source>International Journal of Imaging Systems and Technology</source>, vol. <volume>29</volume>, no. <issue>1</issue>, pp. <fpage>4</fpage>&#x2013;<lpage>18</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Randhawa</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Loo</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Nandi</surname></string-name></person-group>, &#x201C;<article-title>Credit card fraud detection using AdaBoost and majority voting</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>6</volume>, pp. <fpage>14277</fpage>&#x2013;<lpage>14284</lpage>, <year>2018</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>












