A Statistical Method and Deep Learning Models for Detecting Denial of Service Attacks in the Internet of Things (IoT) Environment
Ruuhwan, Rendy Munadi, Hilal Hudan Nuha, Erwin Budi Setiawan, Niken Dwi Wahyu Cahyani · Applied System Innovation · 2025
The flourishing of the Internet of Things (IoT) has not only improved our lives in smart homes and healthcare but also made us more susceptible to cyberattacks. Legacy intrusion detection systems are simply overwhelmed by the scale and diversity of IoT traffic, which is why there is a need for more intelligent forensic solutions. In this paper, we present a statistical technique, the Averaging Detection Method (ADM), for detecting attack traffic. Furthermore, the five deep learning models SimpleRNN, LSTM, GRU, BLSTM, and BGRU are compared for malicious traffic detection in IoT network forensics. A smart home dataset with a simulated DoS attack was used for performance analysis of accuracy, precision, recall, F1-score, and training time. The results indicate that all models achieve high accuracy, above 97%. BiGRU achieves the best performance, 99% accuracy, precision, recall, and F1-score, at the cost of high training time. GRU achieves perfect precision and recall (100%) with faster training, which can be considered for resource-constrained scenarios. SimpleRNN trains faster with comparable accuracy, while LSTMs and their bidirectional counterparts are better at capturing long-term dependencies but are computationally more expensive. In summary, deep learning, especially BiGRU and GRU, holds great promise for boosting IoT forensic investigation by enabling real-time DoS detection and reliable evidence collection. Meanwhile, the proposed ADM is simpler and more efficient at classifying DoS traffic than deep learning models.