<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">20938</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2022.020938</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>DNNBoT: Deep Neural Network-Based Botnet Detection and Classification</article-title>
<alt-title alt-title-type="left-running-head">DNNBoT: Deep Neural Network-Based Botnet Detection and Classification</alt-title>
<alt-title alt-title-type="right-running-head">DNNBoT: Deep Neural Network-Based Botnet Detection and Classification</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author"><name name-style="western"><surname>Haq</surname><given-names>Mohd Anul</given-names></name>
</contrib>
<contrib id="author-2" contrib-type="author" corresp="yes"><name name-style="western"><surname>Khan</surname><given-names>Mohd Abdul Rahim</given-names></name><email>m.khan@mu.edu.sa</email>
</contrib>
<aff>
<institution>Department of Computer Science, College of Computer and Information Sciences, Majmaah University</institution>, <addr-line>Al-Majmaah 11952</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Mohd Abdul Rahim Khan. Email: <email>m.khan@mu.edu.sa</email></corresp>
</author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2021-10-18">
<day>18</day>
<month>10</month>
<year>2021</year>
</pub-date>
<volume>71</volume>
<issue>1</issue>
<fpage>1729</fpage>
<lpage>1750</lpage>
<history>
<date date-type="received">
<day>15</day>
<month>6</month>
<year>2021</year>
</date>
<date date-type="accepted">
<day>30</day>
<month>8</month>
<year>2021</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2022 Haq and Khan</copyright-statement>
<copyright-year>2022</copyright-year>
<copyright-holder>Haq and Khan</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_20938.pdf"></self-uri>
<abstract>
<p>The evolution and expansion of IoT devices reduced human efforts, increased resource utilization, and saved time; however, IoT devices create significant challenges such as lack of security and privacy, making them more vulnerable to IoT-based botnet attacks. There is a need to develop efficient and faster models which can work in real-time with efficiency and stability. The present investigation developed two novels, Deep Neural Network (DNN) models, DNNBoT1 and DNNBoT2, to detect and classify well-known IoT botnet attacks such as Mirai and BASHLITE from nine compromised industrial-grade IoT devices. The utilization of PCA was made to feature extraction and improve effectual and accurate Botnet classification in IoT environments. The models were designed based on rigorous hyperparameters tuning with GridsearchCV. Early stopping was utilized to avoid the effects of overfitting and underfitting for both DNN models. The in-depth assessment and evaluation of the developed models demonstrated that accuracy and efficiency are some of the best-performed models. The novelty of the present investigation, with developed models, bridge the gaps by using a real dataset with high accuracy and a significantly lower false alarm rate. The results were evaluated based on earlier studies and deemed efficient at detecting botnet attacks using the real dataset.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Botnet</kwd>
<kwd>network monitoring</kwd>
<kwd>machine learning</kwd>
<kwd>deep neural network</kwd>
<kwd>IoT threat</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The expansion of the Internet of Things (IoT) network and its applications have risen enormously due to upgrading communication efficiency, low cost, and ever-increasing demand. The IoT devices have been developed and utilized for numerous sectors, including smart cities, smart grid, smart manufacturing and maintenance, intelligent transport, security and surveillance, precision agriculture, utilities such as power, electricity and water, supply chain, and inventory optimization, more. Over the past few years, the number of sensor-based smart devices that can communicate over the internet without human involvement is growing exponentially. It will be reaching around 30 billion by 2050 [<xref ref-type="bibr" rid="ref-1">1</xref>]. However, the massively increasing numbers and global presence of IoT have become an opportunity for hackers to exploit the security and privacy of the IoT network by using anomalous entities such as botnets, as IoT infrastructure still lacks robust security [<xref ref-type="bibr" rid="ref-2">2</xref>]. The primary security challenge in infrastructure is botnet-based attacks where illegitimate users inject malicious scripts into the IoT devices to infect them.</p>
<sec id="s1_1">
<label>1.1</label>
<title>Botnet</title>
<p>The compromised IoT devices do not show any indications of being hacked and act like zombies for the botmaster to launch the attacks. The size of the botnets might be smaller with hundreds of bots, to a larger botnet contains thousands of bots. Some bots are available on the dark web as cheap as 0.5$ per bot to a massive collection of botnets with a high price. Botnets are of two types, (1) botnets taking commands and in continuous communication with botmaster in a client-server architecture (2) peer to peer bots, which communicated autonomously with each other and launch the attacks after receiving commands from the botmaster. Botmaster used to communicate with bots using the help command-and-control (CnC) server; the bots used to hide until commands from botmaster; this hidden behavior of bots make identification of infected bots and botnet attack a complex task.</p>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Type of Botnet Attacks</title>
<p>The attacks class are: (1) the scan commands used to find out the vulnerable IoT devices; (2) ACK, SYN, UDP, and TCP flooding; and (3) combo or combination attacks used to open a connection and to transmit the spam to it [<xref ref-type="bibr" rid="ref-3">3</xref>].</p>
<sec id="s1_2_1">
<label>1.2.1</label>
<title>Scan Attack</title>
<p>Botmaster scan IoT device in the network to collect information, including IP scanning, port scanning, etc.</p>
</sec>
<sec id="s1_2_2">
<label>1.2.2</label>
<title>DDoS Attack</title>
<p>The DDoS attack is one of the major cyberattacks where a hacker sends massive traffic or flooding to the target server from different locations, which results in disruption of the service and no service to legitimate users [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-5">5</xref>]. Botmaster launches the DDoS attack with the botnet, which exhausted the victim server or platform in memory, computing, and resource disruption.</p>
</sec>
<sec id="s1_2_3">
<label>1.2.3</label>
<title>TCP Flooding</title>
<p>TCP SYN flood is a DDoS attack where the botmaster sends faster TCP syn traffic to exhaust the target&#x2019;s resources and make it unavailable for legitimate requests.</p>
</sec>
<sec id="s1_2_4">
<label>1.2.4</label>
<title>ACK Flooding</title>
<p>The botmaster sends massive fake acknowledgments in ack flooding to the target server that fake IoT devices received the transmitted data successfully.</p>
</sec>
<sec id="s1_2_5">
<label>1.2.5</label>
<title>UDP Flooding</title>
<p>In a UDP flood attack, the botmaster sends UDP packets in a massive amount to exhaust the target server or device to lose processing and respond. In addition, the protecting firewall is also exhausted due to the UDP flood, which rejects legitimate requests.</p>
</sec>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Previous Studies</title>
<p>Botnet refers to a robot network, which means a network of various bots; aimed to perform unlawful activities against any type of IT infrastructure, including websites or networks. Botnets are controlled by botmaster or herder or cybercriminals using command and control protocol [<xref ref-type="bibr" rid="ref-6">6</xref>]. Therefore, a botnet is one of the significant issues for the security and privacy of IoT networks.</p>
<p>Several studies addressed botnet detection and classification (<?A3B2 "tbl1",5,"anchor"?><xref ref-type="table" rid="table-1">Tab. 1</xref>). Reference [<xref ref-type="bibr" rid="ref-7">7</xref>] proposed an ANN-based botnet detection model with a data resampling in detecting DDoS attacks. Author [<xref ref-type="bibr" rid="ref-8">8</xref>] used machine learning (ML) models with dimensionality reduction for detecting DDoS attacks in IoT systems and observed that k-nearest neighbors (KNN) shown best performance and feature reduction reduced system overhead with has less impact on accuracy. Author [<xref ref-type="bibr" rid="ref-9">9</xref>] used dimensionality reduction and decision tree model to detect botnet attack and stated that dimensionality reduction improved the time efficiency and scalability. Author [<xref ref-type="bibr" rid="ref-10">10</xref>] utilized ML model to detect botnet based on honeypot approach to study the hacker behavior by tempting an attacker to detect new malware attacks in the botnet. Author [<xref ref-type="bibr" rid="ref-11">11</xref>] used novel PCA-firefly based XGBoost classification model for intrusion detection.</p>
<p>Like BClus, CAMNEP, and BotHunter, different methods were compared on the dataset containing normal, background, and Botnet traffic [<xref ref-type="bibr" rid="ref-12">12</xref>]. Also, there is an analysis of different machine learning algorithm for Botnet detection, which has two results Botnet or normal [<xref ref-type="bibr" rid="ref-13">13</xref>]. In [<xref ref-type="bibr" rid="ref-14">14</xref>] a decision tree based framework is used for effective detection of P2P Botnet. The researchers also used decision tree algorithm for the feature extraction. Some of them used a method for detecting IOT Botnet, which uses MQTT protocol [<xref ref-type="bibr" rid="ref-15">15</xref>]. A deep learning neural net has been made to detect the Android malware detection which also uses the recurrent neural network [<xref ref-type="bibr" rid="ref-16">16</xref>]. Some researchers use Deep Learning methods for the detection of Botnet. Binary classification has been done using the Feed Forward backpropagation ANN method [<xref ref-type="bibr" rid="ref-17">17</xref>]. BotShark named framework is used for the detection of Botnet. It is based on the deep learning techniques for the inspection of network transactions which also uses the Convolutional Neural Network (CNNs) [<xref ref-type="bibr" rid="ref-18">18</xref>]. In [<xref ref-type="bibr" rid="ref-19">19</xref>] researchers uses convolutional neural network(CNN) for the feature extraction which will be useful in predictive analysis.</p>
<p>Reinforcement Learning is also used for the classification of a packet into Botnet or Normal. The researchers also tested the model on real world dataset and found a good accuracy [<xref ref-type="bibr" rid="ref-20">20</xref>]. Different feature selection methods are also applied on a Botnet dataset and then finding the best possible combination of features for the binary classification [<xref ref-type="bibr" rid="ref-21">21</xref>].</p>
<p>In the medical field also deep learning is being used widely. Many researchers also used deep learning methods in the combination of autoencoders to detect the premature birth of a child [<xref ref-type="bibr" rid="ref-22">22</xref>]. LSTM is also used for the detection of IoT datasets. IoT devices are also vulnerable to different types of threats and especially Botnet. Researchers show that the bidirectional approach is a better model over time [<xref ref-type="bibr" rid="ref-23">23</xref>]. There is also an approach for detecting Botnet using nodes of a graph. It uses a self-organizing map clustering method on the features [<xref ref-type="bibr" rid="ref-24">24</xref>]. Some researchers also use transfer learning on a dataset obtained by combining the different Botnet datasets [<xref ref-type="bibr" rid="ref-25">25</xref>].</p>
<p>A method has been used by some researchers which uses some multiclass classification techniques. They have used a LSTM based framework for managing multiclass imbalance [<xref ref-type="bibr" rid="ref-26">26</xref>]. In [<xref ref-type="bibr" rid="ref-27">27</xref>] used a method to detect Botnet with network flow. They did a multi class classification on the dataset. Authors [<xref ref-type="bibr" rid="ref-28">28</xref>] used two theorems to show that the method can effectively reduce the compute resources consumption, identify DDoS attacks at their primary stage with higher detection rates, and lower false alarm rates.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>State of the art research focused on botnet detection</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Models</th>
<th>Merit</th>
<th>Demerit</th>
<th>Ref.</th>
</tr>
</thead>
<tbody>
<tr>
<td>XGBoost classification</td>
<td>Used the XGBoost approach to decreased the dataset for classification.<break/>This technique gave the better result in presented machine learning techniques.</td>
<td>There is probability to loss of Information due to suppression.</td>
<td>[<xref ref-type="bibr" rid="ref-11">11</xref>]</td>
</tr>
<tr>
<td>BClus and CAMNEP</td>
<td>Applied the three different methods to botnet detection on real and massive botnet dataset. Applied the error metric designed for botnet detections techniques</td>
<td>Complex to deal dynamically the networks flows and clustering the feature at run time.</td>
<td>[<xref ref-type="bibr" rid="ref-12">12</xref>]</td>
</tr>
<tr>
<td>Multi-layer botnet detection technique</td>
<td>Extracted the most relevant feature by using decision tree algorithm.<break/>In third layer of models, tried to reduce the features, which may enhance the efficiency of classification.</td>
<td>There is probability to loss of Information due to suppression.</td>
<td>[<xref ref-type="bibr" rid="ref-13">13</xref>&#x2013;<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
</tr>
<tr>
<td>Deep neural network</td>
<td>Extracted the new feature and original feature by using convolutional neural networks (CNNs) on each layer of autoencoder. On the layer of softmax, classified the predicted malicious traffics.</td>
<td>Distinguish between new original and malware detection is very typical to detect.</td>
<td>[<xref ref-type="bibr" rid="ref-16">16</xref>&#x2013;<xref ref-type="bibr" rid="ref-18">18</xref>]</td>
</tr>
<tr>
<td>Reinforcement learning-detection</td>
<td>The reduction of network traffic and applied reinforcement learning technique to improve the efficiency and accuracy of models.</td>
<td>There is probability to loss of Information due to suppression.</td>
<td>[<xref ref-type="bibr" rid="ref-20">20</xref>]</td>
</tr>
<tr>
<td>P2P botnet detection</td>
<td>Observed the important features which will be more useful in building a botnet detection model.</td>
<td>Specific feature base detection can create problem in future.</td>
<td>[<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
</tr>
<tr>
<td>DNN with semi-classification</td>
<td>In deep neural network, used the three layers such as stacked sparse autoencoder (SSAE) network with two hidden softmax layers to detect the botnet. Contraction intervals and non-contraction intervals were manually segmented.</td>
<td>Human interaction is required. Not detected good accuracy rate that other machine learning approaches. Just considered only 26 features only.</td>
<td>[<xref ref-type="bibr" rid="ref-22">22</xref>]</td>
</tr>
<tr>
<td>BLSTM-RNN detection</td>
<td>Used the bidirectional long short term memory recurrent neural network (BLSTM-RNN), in conjunction with Word Embedding for botnet detection</td>
<td>Ten attack vectors used by the mirai botnet malware is not enough to deal all malware families of botnet.</td>
<td>[<xref ref-type="bibr" rid="ref-23">23</xref>]</td>
</tr>
<tr>
<td>Graph-based botnet detection</td>
<td>Authors captured the abnormal behaviors of bots in terms of their graph-based behaviors.<break/>On the captured behaviors to applied clustering-based detection algorithm.</td>
<td>This static approach is not suitable for the real datasets. Not existing the capability to deal network flows.</td>
<td>[<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
</tr>
<tr>
<td>Transfer-learning</td>
<td>The hypothesis is &#x201C;Predictive Performance can be improved by using transfer learning techniques across datasets containing network traffic from different Botnet</td>
<td>Not achieved the adequate level of accuracy for detection botnet datasets compare to machine learning</td>
<td>[<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
</tr>
<tr>
<td>Domain generation algorithms (DGA)</td>
<td>In the approached used the LSTM.MI algorithm to combine both binary and multiclass classification models. Experiments are carried out on a real-world collected dataset.</td>
<td>Not considering all existing malware families to test botnet datasets</td>
<td>[<xref ref-type="bibr" rid="ref-26">26</xref>]</td>
</tr>
<tr>
<td>ANN</td>
<td>The applied a fuzzy logic based feature engineering method.<break/>In this models used the different learning models can perform differently on different datasets</td>
<td>There is not used the real datasets of botnet to test the models</td>
<td>[<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3">
<label>3</label>
<title>Significance of the Problem</title>
<p>Numerous studies performed botnet detection. However, a lack of studies addressed the issues related to feature extraction, dimensionality reduction to suppress duplicate information, overfitting, and rigorous parameters tuning. Most studies used real botnet attack datasets in a real environment. Additionally, studies evaluated ML models for synthetic botnet data without much contribution for feature engineering and in-depth assessment of overfitting. Most research used high imbalanced real-time datasets to study botnet detection. Studies majorly focus on the higher accuracies without addressing limitations of highly imbalanced datasets and obtained illusory accuracy. The data splitting was also a significant issue with proper validation of the model without using unforeseen data from training.</p>
</sec>
<sec id="s4">
<label>4</label>
<title>Our Novel Contribution</title>
<p>The present investigation aimed to resolve the gaps from previous studies with a combined PCA method with DNN. PCA reduced the high dimensionality of the data, and DNN models developed with rigorous hyperparameters tuning using GridSearchCV. Early stopping was also implemented to prevent overfitting. The present investigation does not use entire data during training; some data kept separate from the training process was used to evaluate the model&#x2019;s performance for proper validation. This complete exercise prevents overfitting or underfitting, a notable instance of the ML and DL model&#x2019;s output.</p>
<p>Our proposed approach base hybrid met has the multiclass classification including different types of attacks and non-attacks with high precision. The first stage has a high accuracy rate, which indicates the most extensive amount of botnet attacks possible is classified as a threat. The proposed PCA and DNN-based approach demonstrated promising results. Although earlier studies used ML and AI-based techniques for the botnet, as per our knowledge, a combination of PCA and DNN was not applied so far for multiclass classification of actual botnet attacks to defend an IoT environment, reaching a level of high accuracy. The main contribution of current research are as follows:
<list list-type="roman-lower">
<list-item>
<p>We proposed a novel approach that utilizes the benefits of PCA for feature collection and the deep neural classifiers to improve effectual and accurate Botnet detection in IoT environments,</p></list-item>
<list-item>
<p>Two novel developed hybrid methods, DNNBoT1 and DNNBoT2, utilized PCA and demonstrated high accuracy in both training and validation phases with less variance for multiclass classification to detect botnet attacks</p></list-item>
<list-item>
<p>The main contribution of this paper is to detect and classify the application-specific threat, <italic>e.g</italic>., scan attacks, DDoS, TCP flooding, UDP flooding, and sync flooding, which are some of the most common attacks.</p></list-item>
<list-item>
<p>The proposed approach yields stable, reliable, advanced, accurate, safe, and feasible performance into IoT applications-based approach.</p></list-item>
</list></p>
<sec id="s4_1">
<label>4.1</label>
<title>Principal Component Analysis</title>
<p>PCA is an unsupervised learning technique to find informative, new, and uncorrelated features. It was evident from the correlation heatmap (see <xref ref-type="fig" rid="fig-2">Fig. 2</xref>) that a large number of features for different devices were correlated well, which can be reduced to new candidate features in less number utilizing PCA without losing any vital information. The PCA process involves finding the mean, covariance matrix with eigenvectors and eigenvalues, selecting PC&#x2019;s with the highest Eigenvalues, and the product of the original data matrix. The steps for the PCA process were given in <xref ref-type="disp-formula" rid="eqn-1">Eqs. (1)</xref>&#x2013;<xref ref-type="disp-formula" rid="eqn-8">(8)</xref>. With a sample of &#x2018;<italic>n&#x2019;</italic> observations on a vector of <italic>d&#x2019;</italic> variables</p>
<p><disp-formula id="eqn-1">
<label>(1)</label>
<mml:math id="mml-eqn-1" display="block"><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="fraktur">R</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msup></mml:math>
</disp-formula></p>
<p>Define the first PC using the linear transformation</p>
<p><disp-formula id="eqn-2">
<label>(2)</label>
<mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:munderover><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>;</mml:mo><mml:mspace width="1em" /><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo>.</mml:mo></mml:math>
</disp-formula></p>
<p>where a<sub>1</sub> is selected based on v[z<sub>1</sub>] is maximum.</p>
<p>where the vector</p>
<p><disp-formula id="eqn-3">
<label>(3)</label>
<mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>11</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>21</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>d</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>;</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>1</mml:mn><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>d</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math>
</disp-formula></p>
<p>The variance was calculated from <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>.</p>
<p><disp-formula id="eqn-4">
<label>(4)</label>
<mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:mi mathvariant="italic">v</mml:mi><mml:mi mathvariant="italic">a</mml:mi><mml:mi mathvariant="italic">r</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mover><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>n</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:munderover><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>n</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:munderover><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msup><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mi>S</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math>
</disp-formula></p>
<p>The covariance matrix is given in <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>.</p>
<p><disp-formula id="eqn-5">
<label>(5)</label>
<mml:math id="mml-eqn-5" display="block"><mml:mi>S</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>n</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:munderover><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msup></mml:math>
</disp-formula></p>
<p>where <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:math></inline-formula> is the mean given as <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>.</p>
<p><disp-formula id="eqn-6">
<label>(6)</label>
<mml:math id="mml-eqn-6" display="block"><mml:mover><mml:mi>x</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>n</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:munderover><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math>
</disp-formula></p>
<p>To find a1 which maximize the variance subject to a1T a1; Let &#x03BB; is Lagrange multiplier</p>
<p><disp-formula id="eqn-7">
<label>(7)</label>
<mml:math id="mml-eqn-7" display="block"><mml:mi>L</mml:mi><mml:mo>=</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mi>S</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mfrac><mml:mi mathvariant="normal">&#x2202;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2202;</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:mfrac><mml:mi>L</mml:mi><mml:mo>=</mml:mo><mml:mi>S</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">&#x21D2;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>S</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mi>I</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math>
</disp-formula></p>
<p>The a1 and a2 are eigenvectors of S, which corresponds to the highest and second-highest eigenvalues, respectively.</p>
<p><disp-formula id="eqn-8">
<label>(8)</label>
<mml:math id="mml-eqn-8" display="block"><mml:mrow><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">r</mml:mi></mml:mrow><mml:mo stretchy="false">[</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo>=</mml:mo><mml:msubsup><mml:mi>a</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mi>S</mml:mi><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math>
</disp-formula></p>
<p>The <italic>k</italic><sup>th</sup> highest eigenvalue of S is the variance of the <italic>k</italic><sup>th</sup> PC, and the <italic>k</italic><sup>th</sup> PC holds the <italic>k</italic><sup>th</sup> highest fraction of the variation.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Deep Neural Network</title>
<p>Neural Network (NN) belongs to a feedforward artificial neural network (ANN). It mainly consists of three layers: an input layer, a hidden layer, and an output layer; however, the number of layers can be more, where it becomes DNN. Each node uses a nonlinear activation function except for the input nodes. The advantage of automatic feature extraction in DL-based models such as DNN makes it popular for classification [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-5">5</xref>]. The feature extraction is otherwise difficult to define manually. DL is a variation of ML-based algorithms which consisting of a more significant number of sequential layers. DL&#x2019;s primary advantage is that it automatically selects the features, unlike ML methods where feature extraction needs to be done manually. The DNN is a type of DL model that extracts the feasible features from the input data. DNN, which leads to the identification and classification of elements with less requirement of preprocessing. DNN model generally used three main layers: an input layer, activation function layer, and finally, a classification layer (FCN) used for classification purposes. In the present investigation, DNN models were developed to detect and classify botnet attacks for IoT frameworks.</p>
<sec id="s4_2_1">
<label>4.2.1</label>
<title>Activation Layer</title>
<p>A neural network needs an activation function to make the prediction. The rectifier activation function (ReLU) is one of the default activation functions for deep learning applications; it adds nonlinearity to the network. ReLU output 0 for negative value and output the same value for non-negative values. Another activation function is the Sigmoid or logistic function, which is suitable for binary classification and output between 0 and 1. However, the sigmoid function is not suitable for multiclass classification environments, and it needs the multinomial probability distribution for a mutually exclusive class. Instead, Softmax is a function used to activate the function in the output layer of a neural network to deal with a multiclass classification problem. This activation function predicts a multinomial probability distribution with more than two classes.</p>
<p>If we input {1,2,3}, the max function will output the largest number, 3, in the present example. The argmax will output the index of the largest number, which is 2, the softmax function, which is the probabilistic or &#x201C;softer&#x201D; version of the argmax function in which the unit with the largest input has output &#x002B;1. In contrast, all other units have output 0 {0,0,1} in the current example.</p>
</sec>
<sec id="s4_2_2">
<label>4.2.2</label>
<title>Dense Layer</title>
<p>The dense layer is a NN layer, which is deeply connected. Each neuron in the dense layer receives input from all neurons of its preceding layer. It uses a linear operation function to map every input with every output. It can be implemented using Kears as <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>.</p>
<p><disp-formula id="eqn-11">
<label>(9)</label>
<mml:math id="mml-eqn-11" display="block"><mml:mi mathvariant="normal">m</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mo>.</mml:mo><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="normal">D</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mn>10</mml:mn><mml:mo>,</mml:mo><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">p</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">m</mml:mi><mml:mo>=</mml:mo><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi mathvariant="normal">d</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">&#x005F;</mml:mi><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">h</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">p</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mtext>&#xA0;</mml:mtext><mml:mo stretchy="false">[</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">c</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">v</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">t</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mo>=</mml:mo><mml:mo>&#x2018;</mml:mo><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:msup><mml:mi mathvariant="normal">u</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p>where relu is the activation function, the shape of training data is the input dimension, with ten units. The units are used to define the shape of output, and its output becomes the input for the successive layer.</p>
</sec>
<sec id="s4_2_3">
<label>4.2.3</label>
<title>Training</title>
<p>Models such as NN use learning algorithms to minimize the differences between target and output values. One of the main learning algorithms is backpropagation that computes the gradient of a function to fine-tune the network parameters for error minimization.</p>
</sec>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Dataset</title>
<p>The N-BaIoT Dataset contains traffic data from 9 Industrial IoT devices, in which seven devices collected instances for 11 classes and the remaining two devices collected data for six classes (Ennio_doorbell and Samsung_SNH_1011_N_Webcam) [<xref ref-type="bibr" rid="ref-29">29</xref>]. The data comprise benign traffic and a variety of malicious attacks such as scan, TCP, UDP, and SYN (<xref ref-type="fig" rid="fig-1">Fig. 1</xref>). There is a total of 89 csv files in the current version of the dataset with a total size of 7.58 GB and 1486418 instances of normal and attack occurrences. The two botnet attacks MIRAI and BASHLITE were categorized into ten attack and non-attack classes (see <xref ref-type="fig" rid="fig-1">Fig. 1</xref>). The attacks class are: (1) the scan commands used to find out the vulnerable IoT devices; (2) ACK, SYN, UDP, and TCP flooding; and (3) combo or combination attacks used to open a connection and to transmit the spam to it [<xref ref-type="bibr" rid="ref-3">3</xref>].</p>
</sec>
<sec id="s6">
<label>6</label>
<title>Methodology</title>
<p>Two DNN based models DNNBoT1 and DNNBoT2, were developed in the present investigation to detect botnet attacks based on data from nine industry-grade IoT devices. The primary step to understand the data so that it can be fed for DNN models.</p>
<sec id="s6_1">
<label>6.1</label>
<title>Exploratory Data Analysis (EDA)</title>
<p>The sklearn, mpl_toolkits, matplotlib, NumPy, pandas, and seaborn libraries were used based on Keras, TensorFlow, and Python language to perform the EDA. The primary objective of EDA is to data cleaning, understand the variables, and analyzing relationships between variables. The columns with NaN were dropped, and the columns were kept, which contains more than one unique value. The statistical correlation of the variables for each device was visualized through a correlation matrix, which is the fastest way to develop an understanding of all variables.<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Number of classes/instances in each device</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-1.png"/>
</fig></p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Principal Component Analysis (PCA)</title>
<p>There were 1486418 instances for ten types of attacks and one non-attack data collected from nine industrial IoT devices. It was observed that some feature vectors have no value close to zero. Therefore, the utility of the PCA was a reasonable idea to synthesize with the DNN models developed in the present investigation to suppress the dimensionality of the feature vectors (see <xref ref-type="fig" rid="fig-3">Fig. 3</xref>). It was evident from the correlation heatmap (see <xref ref-type="fig" rid="fig-2">Fig. 2</xref>) that a large number of features for different devices were correlated well, which can be reduced to new candidate features in less number utilizing PCA without losing any vital information. The first step before applying PCA is data standardization. The botnet data have different files and instances; it was required to apply feature scaling to make data of the same scale. The data in the present investigation followed the normal distribution. Therefore standardization was applied. If the data values were skewed, then a normalization function such as min-max scalar could be helpful; to convert data scale-free and ranging between 0 to 1. The PCA process involves finding the mean, covariance matrix with eigenvectors and eigenvalues, selecting PC&#x2019;s with the highest Eigenvalues, and the product of the original data matrix. The number of PCs was selected based on the CEVR (Cumulative Explained Variance Ratio). The steps for the PCA process were given in <xref ref-type="disp-formula" rid="eqn-1">Eqs. (1)</xref>&#x2013;<xref ref-type="disp-formula" rid="eqn-8">(8)</xref>. The standard scalar libraries from sklearn were utilized to obtain the PCA of all nine devices (<xref ref-type="fig" rid="fig-3">Fig. 3</xref>).</p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Deep Neural Network Based Models</title>
<p>Two novel DNN based models DNNBoT1 and DNNBot2 were developed with six layers each in the present study to detect botnet attacks based on data from 9 industrial IoT. Python 3.8, and Keras 2.3.0 API, Tensorflow 2.0 backend, NumPy, pandas, os, sklearn, matplotlib, and DateTime libraries were used in this research. Data preprocessing and PCA were already applied to the raw dataset; so that the output of both steps can be utilized with developed DNN models. We have used six neural network layers that operate on all ten classes of attacks and one class of non-attack. The rectifier activation function (ReLU) was utilized in starting four neural network layers. The ReLU activation function can be defined as <xref ref-type="disp-formula" rid="eqn-9">Eq. (10)</xref>. ReLU acts as a linear function for all positive values and provides zero for all negative values.</p>
<p><disp-formula id="eqn-12">
<label>(10)</label>
<mml:math id="mml-eqn-12" display="block"><mml:mrow><mml:mi mathvariant="normal">y</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mrow><mml:mi mathvariant="normal">x</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math>
</disp-formula></p>
<p>The fifth layer used the kernel initializer followed by the dense layer with softmax function for classification in the sixth layer. The softmax function can be given as <xref ref-type="disp-formula" rid="eqn-10">Eq. (11)</xref>.</p>
<p><disp-formula id="eqn-13">
<label>(11)</label>
<mml:math id="mml-eqn-13" display="block"><mml:mi>&#x03C3;</mml:mi><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:munder><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mi mathvariant="normal">Z</mml:mi></mml:mrow></mml:munder><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:msup><mml:mrow><mml:mi mathvariant="normal">e</mml:mi></mml:mrow><mml:mrow><mml:mtext>zi&#xA0;</mml:mtext></mml:mrow></mml:msup><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="normal">j</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi></mml:mrow></mml:mrow></mml:munderover><mml:msup><mml:mrow><mml:mi mathvariant="normal">e</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">z</mml:mi><mml:mi mathvariant="normal">j</mml:mi></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:mfrac></mml:math>
</disp-formula></p>
<p>where K&#x003D;no of classes, <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msup><mml:mrow><mml:mi mathvariant="normal">e</mml:mi></mml:mrow><mml:mrow><mml:mtext>zi&#xA0;</mml:mtext></mml:mrow></mml:msup></mml:math></inline-formula> is input vector function, and <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msup><mml:mrow><mml:mi mathvariant="normal">e</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">z</mml:mi><mml:mi mathvariant="normal">j</mml:mi></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula> is output vector function.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>The correlation matrix between non-attack and attack instances for provision_PT_737E_security_camera device</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-2.png"/>
</fig>
<p>Early stopping was used to reduce the learning rate through Keras callbacks function to prevent overfitting. The number of epochs was automatically chosen using the early stopping of Keras callback functions based on validation loss, minimum delta value, and patience. In DNN model training, the number of parameters such as iterations, learning rate, batch size, and the activation function was obtained using GridSearchCV. Deep learning models such as DNN might be complex, and data splitting is also a significant issue; while tuning the parameters.<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>3-D PCA for all 9 IoT devices, cyan data shown normal traffic instances and pink color data shown attack instances</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-3.png"/>
</fig></p>
<p>Using GridsearchCV, testing different parameter branches was performed to select the best combination of data splitting ratios for the training and testing. Other important hyperparameters such as batch size, number of neurons, and activation functions such as relu and sigmoid were also assessed utilizing the GridsearchCV. Based on the GridsearchCV utility, the best parameters for both DNNBoT1 and DNNBoT2 models were obtained (<xref ref-type="fig" rid="fig-4">Fig. 4</xref>). There was a total 2653 number of parameters, and all parameters were trainable using DNNBoT1. For DNNBoT2, there were 8981 parameters, and all parameters were trainable.</p>
<p>Both models were compiled after defining the model. The Adam optimizer was used with a decay of 1e&#x2013;3; the learning rate was automatically selected dynamically using a callback monitor. The present problem was multiclass classification; therefore, the loss was measured based on categorical cross-entropy; it used to compute the rate of error between the actual and the m values for classification, such as <xref ref-type="disp-formula" rid="eqn-11">Eq. (12)</xref>.</p>
<p><disp-formula id="eqn-9">
<label>(12)</label>
<mml:math id="mml-eqn-9" display="block"><mml:mtext>Loss</mml:mtext><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mrow><mml:mi mathvariant="normal">O</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="normal">O</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:munderover><mml:msub><mml:mrow><mml:mi mathvariant="normal">a</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi mathvariant="normal">t</mml:mi></mml:mrow><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">a</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi mathvariant="normal">t</mml:mi></mml:mrow><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math>
</disp-formula></p>
<p>where <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msub><mml:mrow><mml:mi mathvariant="normal">O</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>; <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msub><mml:mrow><mml:mi mathvariant="normal">a</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi mathvariant="normal">t</mml:mi></mml:mrow><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">i</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> are the output size, target, and output values, respectively.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>(a) Developed DNN models DNNBoT1 and (b) DNNBoT2 to detect botnet attacks for ten attack classes and one non-attack class</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-4.png"/>
</fig>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Results and Discussions</title>
<p>In this section, the results were discussed based on the training accuracy, validation accuracy, training loss, and validation loss. The performance of both developed models was assessed with the unforeseen data kept separate from during the training process for proper assessment and evaluation of the developed models. The computation time and accuracies compared to the results of other studies.</p>
<sec id="s7_1">
<label>7.1</label>
<title>Accuracy Assessment</title>
<p>We evaluated the performance of both DNNBoT1 and DNNBoT2 models based on loss and accuracy (<xref ref-type="table" rid="table-2">Tab. 2</xref>). These metrics are defined as follows: Accuracy of a method on a test dataset is the percentage used to correctly identifies the test occurrences, and it is computed as <xref ref-type="disp-formula" rid="eqn-10">Eq. (13)</xref>.
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Performance of developed models based on training and validation accuracies for all 9 IoT devices</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Performance</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Dev-</th>
<th>Avg.</th>
</tr>
<tr>
<th></th>
<th>ice 1</th>
<th>ice 2</th>
<th>ice 3</th>
<th>ice 4</th>
<th>ice 5</th>
<th>ice 6</th>
<th>ice 7</th>
<th>ice 8</th>
<th>ice 9</th>
<th>Accu</th>
</tr>
</thead>
<tbody>
<tr>
<td>T_Accu_</td>
<td>0.8940</td>
<td>0.9115</td>
<td>0.8017</td>
<td>0.9188</td>
<td>0.9012</td>
<td>0.9064</td>
<td>0.7815</td>
<td>0.9240</td>
<td>0.8940</td>
<td>0.9071</td>
</tr>
<tr>
<td>T_Accu_</td>
<td>0.9270</td>
<td>0.9004</td>
<td>0.8112</td>
<td>0.9368</td>
<td>0.9045</td>
<td>0.9185</td>
<td>0.8277</td>
<td>0.9111</td>
<td>0.9023</td>
<td>0.9144</td>
</tr>
<tr>
<td>V_Accu_</td>
<td>0.8925</td>
<td>0.9095</td>
<td>0.7913</td>
<td>0.9157</td>
<td>0.9010</td>
<td>0.9055</td>
<td>0.7810</td>
<td>0.9216</td>
<td>0.8921</td>
<td>0.9054</td>
</tr>
<tr>
<td>V_Accu_</td>
<td>0.9197</td>
<td>0.9001</td>
<td>0.8109</td>
<td>0.9360</td>
<td>0.9016</td>
<td>0.9176</td>
<td>0.8198</td>
<td>0.9102</td>
<td>0.9015</td>
<td>0.9124</td>
</tr>
</tbody>
</table>
</table-wrap>
</p>
<p><disp-formula id="eqn-10">
<label>(12)</label>
<mml:math id="mml-eqn-10" display="block"><mml:mtext>Accuracy</mml:mtext><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">P</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">T</mml:mi><mml:mi mathvariant="normal">N</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mtext>TP&#xA0;</mml:mtext><mml:mo>+</mml:mo><mml:mtext>&#xA0;FP&#xA0;</mml:mtext><mml:mo>+</mml:mo><mml:mtext>&#xA0;TN&#xA0;</mml:mtext><mml:mo>+</mml:mo><mml:mtext>&#xA0;FN</mml:mtext><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:math>
</disp-formula></p>
<p>An attempt was made to see if both the model was overfitted. Overfitting can be detected if training loss is comparatively less than validation loss or a significant variance between the validation and training loss. It was observed that the variance between validation loss and training loss was significantly lower; therefore, it indicated that the overfitting did not exist. It was observed that the training loss was higher since it was more challenging for the network to provide the correct representation. However, all of the units were available during validation so that the network can utilize its full computational power, and therefore, it may perform better than in training. The high accuracy was obtained on the training sets and validation sets with significantly low variance for both models applied on nine devices. Therefore, there was no overfitting.
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Comparison of proposed DNNBoT1 and DNNBoT2 with other studies</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Model</th>
<th>Classification/</th>
<th>Accuracy</th>
<th>Limitation</th>
<th>Source</th>
</tr>
<tr>
<th></th>
<th>Detection</th>
<th></th>
<th></th>
<th></th>
</tr>
</thead>
<tbody>
<tr>
<td>Deep autoencoder</td>
<td>Detection</td>
<td>Detection accuracy 100%</td>
<td>Data splitting is done manually<break/>no classification performed</td>
<td>[<xref ref-type="bibr" rid="ref-1">1</xref>]</td>
</tr>
<tr>
<td>Semi-supervised</td>
<td>Detection</td>
<td>Detection accuracy<break/>80%</td>
<td>Low accuracy and high speed</td>
<td>[<xref ref-type="bibr" rid="ref-3">3</xref>]</td>
</tr>
<tr>
<td>SMOTE-Recurrent neural network (DRNN)</td>
<td></td>
<td>Detection<break/>accuracy 99.98%</td>
<td>Data pre processing is required, and no classification </td>
<td>[<xref ref-type="bibr" rid="ref-4">4</xref>]</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>Deep learning ANN technique</td>
<td>Detection</td>
<td>Detection accurcy <break/>99.6%,</td>
<td>This method is not suitable for real-time analysis, no classification</td>
<td>[<xref ref-type="bibr" rid="ref-17">17</xref>]</td>
</tr>
<tr>
<td>Deep autoencoders</td>
<td>Detection</td>
<td>Detection accuracy 84%</td>
<td>Cannot detect unknown<break/>botnets</td>
<td>[<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
</tr>
<tr>
<td>ZeroR, OneR classifier</td>
<td>Classification</td>
<td>Classification accuracy 85%</td>
<td>10 to 60 attributes only</td>
<td>[<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
</tr>
<tr>
<td>Domain generation algorithm(DGA) based on deep learning</td>
<td>Classification</td>
<td>Classification accuracy 90%</td>
<td>Not suitable for real-time</td>
<td>[<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
</tr>
<tr>
<td>DNNBoT (Proposed)</td>
<td>Detection, classification</td>
<td>Accuracy 90.71%, 91.44%</td>
<td>     -</td>
<td>(Proposed)</td>
</tr>
</tbody>
</table>
</table-wrap></p>
<p>As mentioned earlier, both models were hyperparameters tuned using GridsearchCV, and callbacks were utilized to automatically select the optimal number of epochs to prevent overfitting for all nine devices. The automatically selected number of epochs for both DNNBoT1 and DNNBoT2 were given in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>. DNNBoT1 was efficient in several epochs, which were 233 and 196 for DNNBoT1 and DNNBoT2, respectively, <xref ref-type="fig" rid="fig-6">Figs. 6</xref>, <xref ref-type="fig" rid="fig-7">7</xref>. The utilization of callbacks to select an optimal number of epochs was computation and time efficient instead of fixing the number of epochs for different models or datasets, consuming more computing resources and time.</p><fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Number of epochs for both models for each device</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-5.png"/>
</fig>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Performance evaluation of DNNBoT1 model for all 9 IoT devices (D1&#x2013;D9) based on accuracy and loss of training and validation</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-6a.png"/>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-6b.png"/>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-6c.png"/>
</fig>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Performance evaluation of DNNBoT2 model for all 9 IoT devices (D1&#x2013;D9) based on accuracy and loss of training and validation models&#x2019; performance based on computation</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-7a.png"/>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-7b.png"/>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_20938-fig-7c.png"/>
</fig>
<p>The developed models, <italic>i.e</italic>., DNNBoT1 and DNNBoT2, demonstrated good training and validation accuracy; however, devices 3 and 9 showed average training and validation accuracy of 80%. The significantly lower performances of both models for device 3 (Ennio doorbell) and device 7 (Samsung_SNH_1011_N_Webcam) can be correlated with fewer data, <italic>i.e</italic>., data of only six classes out of a total of eleven classes. The average training accuracy of DNNBoT1 and DNNBoT2 was 90.71% and 91.44%, respectively; the average validation accuracy of DNNBoT1 and DNNBoT2 was 90.54% and 91.24%, respectively. Thus, DNNBoT2 performed slightly better than DNNBoT1 based on the training and validation accuracies. Interestingly, the variance between training and validation accuracy was significantly lower in both models; and there was no sign of overfitting or underfitting. Therefore, the accuracies of both models for multiclass botnet classification are higher than in previous studies [<xref ref-type="bibr" rid="ref-3">3</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>&#x2013;<xref ref-type="bibr" rid="ref-31">31</xref>] based on DNNBoT1 and DNNBoT2 datasets.</p>
</sec>
<sec id="s7_2">
<label>7.2</label>
<title>Computational Complexity of the Present Study</title>
<p>The developed models, <italic>i.e</italic>., DNNBoT1 and DNNBoT2converge quicker with an automated and optimized number of epochs using callback functions. The number of parameters for both models was 2663 and 8991, respectively; all the parameters were trainable. It was evident that DNN models were having a smaller number of parameters. The present investigation utilized Tensor Processing Units (TPUs) v2&#x2013;8. These TPU&#x2019;s are Google&#x2019;s application-specific circuits, which accelerate the AI models training workflows. There were eight cores and 64 GiB memory in the TPU v2&#x2013;8 used in the present investigation. DNNBoT1 took 64 s and 37 ms with 26 epochs on average, whereas MLP used only 58 seconds and 16 ms to train the model with 22 epochs.</p>
</sec>
<sec id="s7_3">
<label>7.3</label>
<title>Comparison from Other Studies</title>
<p>The present study used the N-BaIoT dataset, one of the available real industrial IoT datasets compromised with two well-known botnet attacks, <italic>i.e</italic>., MIRAI and BASHLTE. The accuracy of developed novel models DNNBoT1 and DNNBoT2 was compared with other established studies using presented in <xref ref-type="table" rid="table-3">Tab. 3</xref>.</p>
</sec>
</sec>
<sec id="s8">
<label>8</label>
<title>Conclusion</title>
<p>We aimed to develop two novel deep neural network-based botnet detection and classification models for IoT devices. The main contribution of this research is to detect and classify the application-specific threat, <italic>e.g</italic>., scan attack, DDoS, TCP flooding, UDP flooding, and sync flooding; which are one the most common attack. Models developed in the present investigation used complete attack datasets, unlike previous approaches, which assumed that attacks constitute only a small subset of the whole dataset. Presented models utilized the PCA process to reduce the dimensionality; deep neural network-based models run with optimized parameters obtained from rigorous GridsearchCV based hyperparameters tuning. The callback function was utilized for early stopping to optimize the number of epochs and avoid overfitting. Both models keep learning with time to detect and classify botnet attacks. The results based on unforeseen data kept separate from the training process were used to evaluate the performance of the two developed models. Both models showed good training and validation accuracy with minimal loss and time efficiency. The future scope of the present investigation is to integrate more datasets, apply novel model such as firefly with deep neural networks to understand the internal learning process so that efficiency can be further enhanced in the future [<xref ref-type="bibr" rid="ref-32">32</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>].</p>
</sec>
</body>
<back>
<fn-group>
<fn fn-type="other">
<p><bold>Funding Statement:</bold> Authors would like to thank the Deanship of Scientific Research at Majmaah University for supporting this work under Project No. R-2021-220.</p>
</fn>
<fn fn-type="conflict">
<p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Evans</surname></string-name></person-group>, &#x201C;<article-title>The internet of things: How the next evolution of the internet is changing everything</article-title>,&#x201D; <source>CISCO white paper</source>, vol. <volume>1</volume>, no. <issue>2011</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>11</lpage>, <year>2011</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Markowsky</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Markowsky</surname></string-name></person-group>, &#x201C;<article-title>Scanning for vulnerable devices in the internet of things</article-title>,&#x201D; in <conf-name>Proc. IDAACS</conf-name>, <conf-loc>Warsaw, Poland</conf-loc>, pp. <fpage>463</fpage>&#x2013;<lpage>467</lpage>, <year>2015</year>. </mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Naveed</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Wu</surname></string-name></person-group>, &#x201C;<article-title>A semi-supervised framework to detect botnets in IoT devices</article-title>,&#x201D; in <conf-name>Proc. IFIP</conf-name>, <conf-loc>Paris, France</conf-loc>, pp. <fpage>649</fpage>&#x2013;<lpage>651</lpage>, <year>2020</year>. </mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. I.</given-names> <surname>Popoola</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Adebisi</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Ande</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Hammoudeh</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Anoh</surname></string-name></person-group>, &#x201C;<article-title>SMOTE-DRNN: A deep learning algorithm for botnet detection in the internet-of-things networks</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>21</volume>, no. <issue>9</issue>, pp. <fpage>2985</fpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Kansal</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Dave</surname></string-name></person-group>, &#x201C;<article-title>DDoS attack isolation using moving target defense</article-title>,&#x201D; in <conf-name>Proc. ICCCA</conf-name>, <conf-loc>Greater Noida, India</conf-loc>, pp. <fpage>511</fpage>&#x2013;<lpage>514</lpage>, <year>2017</year>. </mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Almutairi</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Mahfoudh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Almutairi</surname></string-name> and <string-name><given-names>J. S.</given-names> <surname>Alowibdi</surname></string-name></person-group>, &#x201C;<article-title>Hybrid botnet detection based on host and network analysis</article-title>,&#x201D; <source>Journal of Computer Networks and Communications</source>, vol. <volume>2020</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>16</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Y. N.</given-names> <surname>Soe</surname></string-name>, <string-name><given-names>P. I.</given-names> <surname>Santosa</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Hartanto</surname></string-name></person-group>, &#x201C;<article-title>DDoS attack detection based on simple ANN with smote for IoT environment</article-title>,&#x201D; in <conf-name>Proc. ICIC</conf-name>, <conf-loc>Semarang, Indonesia</conf-loc>, pp. <fpage>4</fpage>, <year>2019</year>. </mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Aamir</surname></string-name> and <string-name><given-names>S. M. A.</given-names> <surname>Zaidi</surname></string-name></person-group>, &#x201C;<article-title>DDoS attack detection with feature engineering and machine learning: The framework and performance evaluation</article-title>,&#x201D; <source>International Journal of Information Security</source>, vol. <volume>18</volume>, no. <issue>6</issue>, pp. <fpage>761</fpage>&#x2013;<lpage>785</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Bahsi</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Nomm</surname></string-name> and <string-name><given-names>F. B.</given-names> <surname>La Torre</surname></string-name></person-group>, &#x201C;<article-title>Dimensionality reduction for machine learning-based IoT botnet detection</article-title>,&#x201D; in <conf-name>Proc. ICARCV</conf-name>, <conf-loc>Singapore</conf-loc>, pp. <fpage>1857</fpage>&#x2013;<lpage>1862</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Dietz</surname></string-name>, <string-name><given-names>R. L.</given-names> <surname>Castro</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Steinberger</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Wilczak</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Antzek</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>IoT-botnet detection and isolation by access router</article-title>,&#x201D; in <conf-name>Proc. NOF</conf-name>, <conf-loc>Poznan, Poland</conf-loc>, pp. <fpage>88</fpage>&#x2013;<lpage>95</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Bhattacharya</surname></string-name>, <string-name><given-names>P. K. R.</given-names> <surname>Maddikunta</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Kaluri</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Singh</surname></string-name>, <string-name><given-names>T. R.</given-names> <surname>Gadekallu</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>"A novel PCA-firefly based XGBoost classification model for intrusion detection in networks using GPU</article-title>,&#x201D; <source>Electronics</source>, vol. <volume>9</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>16</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Garc&#x00ED;a</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Grill</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Stiborek</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Zunino</surname></string-name></person-group>, &#x201C;<article-title>An empirical comparison of botnet detection methods</article-title>,&#x201D; <source>Computers and Security</source>, vol. <volume>45</volume>, pp. <fpage>100</fpage>&#x2013;<lpage>123</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Joshi</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Bharti</surname></string-name> and <string-name><given-names>R. K.</given-names> <surname>Ranjan</surname></string-name></person-group>, &#x201C;<article-title>Botnet detection using machine learning algorithms</article-title>,&#x201D; in <conf-name>Proc. PCCDS</conf-name>, <publisher-loc>Singapore</publisher-loc>, pp. <fpage>717</fpage>&#x2013;<lpage>727</lpage>, <year>2020</year>. </mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R. U.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Kumar</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Sharif</surname></string-name>, <string-name><given-names>N. A.</given-names> <surname>Golilarz</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>An adaptive multi-layer. An adaptive multi-layer botnet detection technique using machine learning classifiers</article-title>,&#x201D; <source>Applied Sciences</source>, vol. <volume>9</volume>, no. <issue>11</issue>, pp. <fpage>2375</fpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Alaiz-Moreton</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Aveleira-Mata</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Ondicol-Garcia</surname></string-name>, <string-name><given-names>A. L.</given-names> <surname>Munoz-Casta&#x00F1;eda</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Garcia</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Multiclass classification procedure for detecting attacks on MQTTIoT protocol</article-title>,&#x201D; <source>Complexity</source>, vol. <volume>2019</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>11</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Pei</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Yu</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Tian</surname></string-name></person-group>, &#x201C;<article-title>AMalNet: A deep learning framework based on graph convolutional networks for malware detection</article-title>,&#x201D; <source>Computers and Security</source>, vol. <volume>93</volume>, no. <issue>6</issue>, pp. <fpage>101792</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Ahmed</surname></string-name>, <string-name><given-names>W. A.</given-names> <surname>Jabbar</surname></string-name>, <string-name><given-names>A. S.</given-names> <surname>Sadiq</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Patel</surname></string-name></person-group>, &#x201C;<article-title>Deep learning-based classification model for botnet attack detection</article-title>,&#x201D; <source>Journal of Ambient Intelligence and Humanized Computing</source>, vol. <volume>2020</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>10</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Homayoun</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ahmadzadeh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Hashemi</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Dehghantanha</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Khayami</surname></string-name></person-group>, &#x201C;<article-title>BoTShark: A deep learning approach for botnet traffic detection</article-title>,&#x201D; <source>Advances in Information Security</source>, vol. <volume>70</volume>, pp. <fpage>137</fpage>&#x2013;<lpage>153</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Financial quantitative investment using convolutional neural network and deep learning technology</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>390</volume>, pp. <fpage>5</fpage>&#x2013;<lpage>11</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Alauthman</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Aslam</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Al-kasassbeh</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Al-Qerem</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>An efficient reinforcement learning-based botnet detection approach</article-title>,&#x201D; <source>Journal of Network and Computer Applications</source>, vol. <volume>150</volume>, no. <issue>11</issue>, pp. <fpage>102479</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Joshi</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Bharti</surname></string-name> and <string-name><given-names>R. K.</given-names> <surname>Ranjan</surname></string-name></person-group>, &#x201C;<article-title>Analysis of feature selection methods for p2p botnet detection</article-title>,&#x201D; in <conf-name>Proc. ICACDS-2020</conf-name>, <publisher-loc>Singapore</publisher-loc>, pp. <fpage>272</fpage>&#x2013;<lpage>282</lpage>, <year>2020</year>. </mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Xu</surname></string-name></person-group>, &#x201C;<article-title>Deep neural network for semi-automatic classification of term and preterm uterine recordings</article-title>,&#x201D; <source>Artificial Intelligence in Medicine</source>, vol. <volume>105</volume>, pp. <fpage>101861</fpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C. D.</given-names> <surname>McDermott</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Majdani</surname></string-name> and <string-name><given-names>A. V.</given-names> <surname>Petrovski</surname></string-name></person-group>, &#x201C;<article-title>Botnet detection in the internet of things using deep learning approaches</article-title>,&#x201D; in <conf-name>Proc. IJCNN</conf-name>, <publisher-loc>Brazil</publisher-loc>, <publisher-name>Rio de Janeiro</publisher-name>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Chowdhury</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Khanzadeh</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Akula</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zhang</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Botnet detection using graph-based feature clustering</article-title>,&#x201D; <source>Journal of Big Data</source>, vol. <volume>4</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>23</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Alothman</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Rattadilok</surname></string-name></person-group>, &#x201C;<article-title>Towards using transfer learning for botnet detection</article-title>,&#x201D; in <conf-name>Proc. ICITST</conf-name>, <publisher-loc>Cambridge, UK</publisher-loc>, pp. <fpage>281</fpage>&#x2013;<lpage>282</lpage>, <year>2017</year>. </mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Tran</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Mac</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Tong</surname></string-name>, <string-name><given-names>H. A.</given-names> <surname>Tran</surname></string-name> and <string-name><given-names>L. G.</given-names> <surname>Nguyen</surname></string-name></person-group>, &#x201C;<article-title>An LSTM based framework for handling multiclass imbalance in DGA botnet detection</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>275</volume>, no. <issue>8</issue>, pp. <fpage>2401</fpage>&#x2013;<lpage>2413</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Mathur</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Raheja</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Ahlawat</surname></string-name></person-group>, &#x201C;<article-title>Botnet detection via mining of network traffic flow</article-title>,&#x201D; <source>Procedia Computer Science</source>, vol. <volume>132</volume>, pp. <fpage>1668</fpage>&#x2013;<lpage>1677</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>R. M.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>X. Y.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>V. S.</given-names> <surname>Sheng</surname></string-name> and <string-name><given-names>C. T.</given-names> <surname>Cai</surname></string-name></person-group>, &#x201C;<article-title>An abnormal network flow feature sequence prediction approach for DDoS attacks detection in big data environment</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>55</volume>, no. <issue>1</issue>, pp. <fpage>95</fpage>&#x2013;<lpage>119</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Meidan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Bohadana</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Mathov</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Mirsky</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Shabtai</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>N-BaIoT&#x2014;network-based detection of IoT botnet attacks using deep autoencoders</article-title>,&#x201D; <source>IEEE Pervasive Computing</source>, vol. <volume>17</volume>, no. <issue>3</issue>, pp. <fpage>12</fpage>&#x2013;<lpage>22</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S. S.</given-names> <surname>Chawathe</surname></string-name></person-group>, &#x201C;<article-title>Monitoring IoT networks for botnet activity</article-title>,&#x201D; in <conf-name>Proc. NCA</conf-name>, <conf-loc>Cambridge, MA, USA</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Vinayakumar</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Alazab</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Srinivasan</surname></string-name>, <string-name><given-names>Q. V.</given-names> <surname>Pham</surname></string-name>, <string-name><given-names>S. K.</given-names> <surname>Padannayil</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>A visualized botnet detection system based deep learning for the internet of things networks of smart cities</article-title>,&#x201D; <source>IEEE Transactions on Industry Applications</source>, vol. <volume>56</volume>, no. <issue>4</issue>, pp. <fpage>4436</fpage>&#x2013;<lpage>4456</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T. R.</given-names> <surname>Gadekallu</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Khare</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Bhattacharya</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Singh</surname></string-name>, <string-name><given-names>P. K. R.</given-names> <surname>Maddikunta</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Early detection of diabetic retinopathy using PCA-firefly based deep learning model</article-title>,&#x201D; <source>Electronics</source>, vol. <volume>9</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>16</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R. M. S.</given-names> <surname>Priya</surname></string-name>, <string-name><given-names>P. K. R.</given-names> <surname>Maddikunta</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Parimala</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Koppu</surname></string-name>, <string-name><given-names>T. R.</given-names> <surname>Gadekallu</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>An effective feature engineering for DNN using hybrid PCA-GWO for intrusion detection in IoMT architecture</article-title>,&#x201D; <source>Computer Communications</source>, vol. <volume>160</volume>, no. <issue>2020</issue>, pp. <fpage>139</fpage>&#x2013;<lpage>149</lpage>, <year>2020</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>
