Mitigating IoT botnet attacks: An early-stage explainable network-based anomaly detection approach

Abdelaziz Amara Korba, Alaeddine Diaf, Mouhamed Amine Bouchiha, Yacine M. Ghamri-Doudane · Computer Communications · 2025

As the Internet of Things (IoT) continues to expand, botnet-driven threats pose a growing and severe risk to the security of IoT-enabled infrastructures. These threats exploit large numbers of compromised devices to establish covert control channels and, eventually, launch large-scale cyberattacks such as Distributed Denial of Service (DDoS), capable of severely disrupting critical services and causing substantial economic damage. This paper highlights the urgent need for detecting botnets at an early stage, particularly by identifying stealthy command and control (C&C) traffic that precedes the execution of such attacks. We propose an anomaly-based detection framework that combines semi-supervised learning with explainable Artificial Intelligence (XAI). Unlike most existing approaches, our method requires only benign traffic for training, thereby enabling the detection of previously unseen or evolving botnet threats without relying on labeled malicious data. The framework supports multiple traffic representations, including raw bytes, packet-level data, and unidirectional or bidirectional flows, enriched with diverse network features to enhance detection coverage and adaptability. Experimental evaluations using the IoT-23 dataset demonstrate a 99.51% detection rate and a 1.09% false positive rate for stealthy C&C communications, underscoring the method’s effectiveness and robustness. The integration of XAI enhances transparency and interpretability, enabling security professionals to better understand model decisions and refine detection strategies.

Read the paper · More papers on PaperTik