Decision Tree-Based IoT Botnet Attack Detection

Hazem Mohammad Al-Najjar, Nadia Al‐Rousan · 2024

This paper investigated the predictive capabilities of three decision tree models for IoT botnet attack prediction using packet information while minimizing the number of predictors. The study employed three decision tree models (C5, CHAID, and Random Forest) and two additional models (Logistic Regression and Bayesian Network) for comparison purposes. The IoT botnet attack dataset comprised various devices, mainly two types of attacks (Gafgyt and Mirai) and 23 feature engineering variables. Simulation results from all models showed that Accuracy, Precision, Recall, and False Omission Rate (FOR) values are approximately one, with an F1 score of around 0.5. CHAID and C5 models outperform other models in predicting IoT botnet attacks, as they are developed using only four and two variables, respectively. These results demonstrated that decision tree models with fewer variables can perform better than models that utilize all predictors.

Read the paper · More papers on PaperTik