Adaptive IoT Botnet Defense: Combining Hybrid Deep Learning and Real-Time SDN Mitigation
Preeti Kailas Suryawanshi, Sahil Jagtap · International Journal of Computer Science and Engineering · 2025
The rapid expansion of the Internet of Things (IoT) has led to botnet attacks, which use compromised devices for malicious activities such as Distributed Denial-of-Service (DDoS) attacks and data breaches. Traditional rule-based intrusion detection systems struggle to detect these new threats, which demand advanced machine learning (ML) and deep learning (DL) models. In this paper, a hybrid CNN-RNN model employing both spatial and temporal analysis of traffic is proposed for better IoT botnet detection. Federated learning also maintains privacy during model training, and Graph Neural Networks (GNNs) improve botnet behavior modeling. A Software-Defined Networking (SDN)-based mitigation method is employed for providing real-time response with rapid isolation of malicious traffic. To counter IoT resource constraints, model optimization techniques such as pruning and quantization are employed. Experimental evaluations using the UNSW-NB15 dataset demonstrate superior detection accuracy (99.1), with minimal false positives over traditional approaches. These findings recognize the potential of hybrid deep learning and SDN-based solutions for effective, real-time IoT botnet protection.