{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T20:04:35Z","timestamp":1765051475845,"version":"3.46.0"},"reference-count":131,"publisher":"Springer Science and Business Media LLC","issue":"15","license":[{"start":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T00:00:00Z","timestamp":1759968000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T00:00:00Z","timestamp":1759968000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2025,12]]},"DOI":"10.1007\/s10586-025-05633-1","type":"journal-article","created":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:51:22Z","timestamp":1760032282000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["IoT botnets Unveiled: architectural analysis, threat vectors, and cutting-edge detection techniques"],"prefix":"10.1007","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1815-5794","authenticated-orcid":false,"given":"Umang","family":"Garg","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3809-0887","authenticated-orcid":false,"given":"Preeti","family":"Mishra","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Neha","family":"Gupta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emmanuel S.","family":"Pilli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,9]]},"reference":[{"key":"5633_CR1","doi-asserted-by":"crossref","unstructured":"Al-Shurbaji, T., Anbar, M., Manickam, S., Hasbullah, I.H., ALfriehate, N., Alabsi, B.A., Alzighaibi, A.R., Hashim, H.: Deep learning-based intrusion detection system for detecting iot botnet attacks: a review. IEEE Access, (2025)","DOI":"10.1109\/ACCESS.2025.3526711"},{"key":"5633_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.measen.2024.101406","volume":"37","author":"K Kaushik","year":"2025","unstructured":"Kaushik, K., Bhardwaj, A., Dahiya, S.: Framework to analyze and exploit the smart home iot firmware. Meas. Sens. 37, 101406 (2025)","journal-title":"Meas. Sens."},{"key":"5633_CR3","volume-title":"Nokia Threat Intelligence Report","author":"CS Providers","year":"2018","unstructured":"Providers, C.S., Intelligence, T.: Nokia Threat Intelligence Report. Tech. Rep, Network Security (2018)"},{"issue":"2","key":"5633_CR4","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MC.2017.62","volume":"50","author":"E Bertino","year":"2017","unstructured":"Bertino, E., Islam, N.: Botnets and internet of things security. Computer 50(2), 76\u201379 (2017)","journal-title":"Computer"},{"issue":"1","key":"5633_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2018\/7178164","volume":"2018","author":"M De Donno","year":"2018","unstructured":"De Donno, M., Dragoni, N., Giaretta, A., Spognardi, A.: Ddos-capable iot malwares: comparative analysis and mirai investigation. Secur. Commun. Netw. 2018(1), 1\u201330 (2018)","journal-title":"Secur. Commun. Netw."},{"key":"5633_CR6","doi-asserted-by":"crossref","unstructured":"Jonsdottir, G., Wood, D., Doshi, R.: Iot network monitor. In 2017 IEEE MIT Undergraduate Research Technology Conference (URTC), pages 1\u20135. IEEE, (2017)","DOI":"10.1109\/URTC.2017.8284179"},{"issue":"1","key":"5633_CR7","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1016\/j.knosys.2017.09.014","volume":"136","author":"H Wang","year":"2017","unstructured":"Wang, H., Jie, G., Wang, S.: An effective intrusion detection framework based on svm with feature augmentation. Knowl.-Based Syst. 136(1), 130\u2013139 (2017)","journal-title":"Knowl.-Based Syst."},{"issue":"1","key":"5633_CR8","first-page":"105","volume":"189","author":"A Aldweesh","year":"2020","unstructured":"Aldweesh, A., Derhab, A., Emam, A.Z.: Deep learning approaches for anomaly-based intrusion detection systems: a survey, taxonomy, and open issues. Knowl.-Based Syst. 189(1), 105\u2013124 (2020)","journal-title":"Knowl.-Based Syst."},{"key":"5633_CR9","doi-asserted-by":"crossref","unstructured":"Wohlin, C.: Guidelines for snowballing in systematic literature studies and a replication in software engineering. In Proceedings of the 18th international conference on evaluation and assessment in software engineering, pages 1\u201310, (2014)","DOI":"10.1145\/2601248.2601268"},{"key":"5633_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.infsof.2015.03.007","volume":"64","author":"K Petersen","year":"2015","unstructured":"Petersen, K., Vakkalanka, S., Kuzniarz, L.: Guidelines for conducting systematic mapping studies in software engineering: an update. Inf. Softw. Technol. 64, 1\u201318 (2015)","journal-title":"Inf. Softw. Technol."},{"key":"5633_CR11","unstructured":"Mazdadi, M.I., Riadi, I., Luthfi, A.: Live forensics on routeros using api services to investigate network attacks. Int. J. Comput. Sci. Inf. Secur. (IJCSIS), 15(2), (2017)"},{"key":"5633_CR12","doi-asserted-by":"crossref","unstructured":"\u010eurfina, L., K\u0159oustek, J., Zemek, P.: Psybot malware: a step-by-step decompilation case study. In 2013 20th Working Conference on Reverse Engineering (WCRE), pages 449\u2013456. IEEE, (2013)","DOI":"10.1109\/WCRE.2013.6671321"},{"issue":"1","key":"5633_CR13","first-page":"1","volume":"1","author":"A Costin","year":"2018","unstructured":"Costin, A., Zaddach, J.: Iot malware: comprehensive survey, analysis framework and case studies. BlackHat USA 1(1), 1\u20139 (2018)","journal-title":"BlackHat USA"},{"key":"5633_CR14","doi-asserted-by":"crossref","unstructured":"Marzano, A., Alexander, D., Fonseca, O., Fazzion, E., Hoepers, C., Steding-Jessen, K., Chaves, M.H.P.C., Cunha, \u00cd., Guedes, D., Meira, W.: The evolution of bashlite and mirai iot botnets. In 2018 IEEE Symposium on Computers and Communications (ISCC), pages 813\u2013818. IEEE, (2018)","DOI":"10.1109\/ISCC.2018.8538636"},{"key":"5633_CR15","doi-asserted-by":"crossref","unstructured":"Celeda, P., Krejc\u00ed, R., Vykopal, J., Drasar, M.: Embedded malware-an analysis of the chuck norris botnet. In 2010 European Conference on Computer Network Defense, pages 3\u201310. IEEE, (2010)","DOI":"10.1109\/EC2ND.2010.15"},{"issue":"5","key":"5633_CR16","doi-asserted-by":"publisher","first-page":"503","DOI":"10.1109\/JCN.2019.000043","volume":"21","author":"W Hsin-Te","year":"2019","unstructured":"Hsin-Te, W., Tsai, C.-W.: An intelligent agriculture network security system based on private blockchains. J. Commun. Netw. 21(5), 503\u2013508 (2019)","journal-title":"J. Commun. Netw."},{"issue":"3","key":"5633_CR17","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1145\/1842733.1842736","volume":"44","author":"E Nygren","year":"2010","unstructured":"Nygren, E., Sitaraman, R.K., Sun, J.: The akamai network: a platform for high-performance internet applications. ACM SIGOPS Operating Systems Review 44(3), 2\u201319 (2010)","journal-title":"ACM SIGOPS Operating Systems Review"},{"key":"5633_CR18","doi-asserted-by":"crossref","unstructured":"Margolis, J., Oh, T., Jadhav, S., Jeong, J., Kim, Y.H., Kim, J.N.: Analysis and impact of iot malware. In Proceedings of the 18th Annual Conference on Information Technology Education, pages 187\u2013187, (2017)","DOI":"10.1145\/3125659.3125710"},{"key":"5633_CR19","unstructured":"Angrishi, K.: Turning internet of things (iot) into internet of vulnerabilities (iov): Iot botnets. arXiv preprint arXiv:1702.03681, (2017)"},{"issue":"1","key":"5633_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1080\/17440572.2017.1411807","volume":"19","author":"M Paquet-Clouston","year":"2018","unstructured":"Paquet-Clouston, M., D\u00e9cary-H\u00e9tu, D., Bilodeau, O.: Cybercrime is whose responsibility? a case study of an online behaviour system in crime. Global crime 19(1), 1\u201321 (2018)","journal-title":"Global crime"},{"issue":"13","key":"5633_CR21","first-page":"27","volume":"9","author":"JCS Sicato","year":"2019","unstructured":"Sicato, J.C.S., Sharma, P.K., Loia, V., Park, J.H.: Vpnfilter malware analysis on cyber threat in smart home network. Appl. Sci. 9(13), 27\u201340 (2019)","journal-title":"Appl. Sci."},{"key":"5633_CR22","doi-asserted-by":"crossref","unstructured":"Mudgerikar, A., Bertino, E.: Iot attacks and malware. In Cyber Security Meets Machine Learning, pages 1\u201325. Springer, (2021)","DOI":"10.1007\/978-981-33-6726-5_1"},{"key":"5633_CR23","doi-asserted-by":"crossref","unstructured":"Herwig, S., Harvey, K., Hughey, G., Roberts, R., Levin, D.: Measurement and analysis of hajime, a peer-to-peer iot botnet. In Network and Distributed Systems Security (NDSS) Symposium, (2019)","DOI":"10.14722\/ndss.2019.23488"},{"key":"5633_CR24","doi-asserted-by":"crossref","unstructured":"Kambourakis, G., Kolias, C., Stavrou, A.: The mirai botnet and the iot zombie armies. In MILCOM 2017-2017 IEEE Military Communications Conference (MILCOM), pages 267\u2013272. IEEE, (2017)","DOI":"10.1109\/MILCOM.2017.8170867"},{"issue":"39","key":"5633_CR25","first-page":"3","volume":"182","author":"Z Shouran","year":"2019","unstructured":"Shouran, Z., Ashari, A., Priyambodo, T.: Internet of things (iot) of smart home: privacy and security. Int. J. Comput. Appl. 182(39), 3\u20138 (2019)","journal-title":"Int. J. Comput. Appl."},{"key":"5633_CR26","unstructured":"T. Yeh, D. Chiu, K. Lu. Persirai: new internet of things (iot) botnet targets ip cameras. blog, Trend-Labs 9 (2017)"},{"key":"5633_CR27","unstructured":"Liu,Y., Wang, H.: Vb2018 paper: Tracking mirai variants\u2019. Virus Bulletin. Available at: https:\/\/www. virusbulletin. com\/virusbulletin\/2018\/12\/vb2018-paper-tracking-mirai-variants\/(Accessed: 21 April 2020), (2018)"},{"key":"5633_CR28","doi-asserted-by":"crossref","unstructured":"Vervier, P.-A., Shen, Y.: Before toasters rise up: a view into the emerging iot threat landscape. In International Symposium on Research in Attacks, Intrusions, and Defenses, pages 556\u2013576. Springer, (2018)","DOI":"10.1007\/978-3-030-00470-5_26"},{"key":"5633_CR29","unstructured":"Anubhav, A.: Masuta: satori creators\u2019 second botnet weaponizes a new router exploit. NewSky Security. Jan 23, (2018)"},{"issue":"2","key":"5633_CR30","doi-asserted-by":"publisher","first-page":"285","DOI":"10.3390\/iot3020017","volume":"3","author":"R Alghamdi","year":"2022","unstructured":"Alghamdi, R., Bellaiche, M.: Evaluation and selection models for ensemble intrusion detection systems in iot. IoT 3(2), 285\u2013314 (2022)","journal-title":"IoT"},{"key":"5633_CR31","doi-asserted-by":"crossref","unstructured":"Kayas, G., Hossain, M., Payton, J., Islam, S.M.: An overview of upnp-based iot security: threats, vulnerabilities, and prospective solutions. arXiv preprint arXiv:2011.02587, (2020)","DOI":"10.1109\/IEMCON51383.2020.9284885"},{"issue":"3","key":"5633_CR32","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/S1353-4858(19)30037-6","volume":"2019","author":"S Haria","year":"2019","unstructured":"Haria, S.: The growth of the hide and seek botnet. Netw. Secur. 2019(3), 14\u201317 (2019)","journal-title":"Netw. Secur."},{"key":"5633_CR33","unstructured":"Zheng, C., Ji, Y., Davila, A.: Muhstik botnet attacks tomato routers to harvest new iot devices, (2020)"},{"key":"5633_CR34","doi-asserted-by":"crossref","unstructured":"Alhamad, R.N., Alserhani, F.M.: Prediction models to effectively detect malware patterns in the iot systems. Int. J. Adv. Comput. Sci. Appl. 13(7), (2022)","DOI":"10.14569\/IJACSA.2022.0130744"},{"key":"5633_CR35","doi-asserted-by":"crossref","unstructured":"Kompougias, O., Papadopoulos, D., Mantas, E., Litke, A., Papadakis, N., Paraschos, D., Kourtis, A., Xylouris, G.: Iot botnet detection on flow data using autoencoders. In 2021 IEEE International Mediterranean Conference on Communications and Networking (MeditCom), pages 506\u2013511. IEEE, (2021)","DOI":"10.1109\/MeditCom49071.2021.9647639"},{"issue":"1","key":"5633_CR36","doi-asserted-by":"publisher","first-page":"182459","DOI":"10.1109\/ACCESS.2019.2960412","volume":"7","author":"M Wazid","year":"2019","unstructured":"Wazid, M., Das, A.K., Rodrigues, J.J.P.C., Shetty, S., Park, Y.: Iomt malware detection approaches: analysis and research challenges. IEEE Access 7(1), 182459\u2013182476 (2019)","journal-title":"IEEE Access"},{"key":"5633_CR37","unstructured":"Lakshmanan, R.: Dark nexus: a new emerging iot botnet malware spotted in the wild. The Hacker News, https:\/\/thehackernews. com\/2020\/04\/darknexus-iot-ddos-botnet. html (accessed on April 25th 2020), (2020)"},{"key":"5633_CR38","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102677","volume":"117","author":"B Hammi","year":"2022","unstructured":"Hammi, B., Zeadally, S., Khatoun, R., Nebhen, J.: Survey on smart homes: vulnerabilities, risks, and countermeasures. Comput. Secur. 117, 102677 (2022)","journal-title":"Comput. Secur."},{"key":"5633_CR39","doi-asserted-by":"crossref","unstructured":"Srinivasa, S., Pedersen, J.M., Vasilomanolakis, E.: Open for hire: attack trends and misconfiguration pitfalls of iot devices. In Proceedings of the 21st ACM Internet Measurement Conference, pages 195\u2013215, (2021)","DOI":"10.1145\/3487552.3487833"},{"key":"5633_CR40","doi-asserted-by":"crossref","unstructured":"Sahota, J., Vlajic, N.: Mozi iot malware and its botnets: From theory to real-world observations. In 2021 International Conference on Computational Science and Computational Intelligence (CSCI), pages 698\u2013703. IEEE, (2021)","DOI":"10.1109\/CSCI54926.2021.00181"},{"issue":"8","key":"5633_CR41","doi-asserted-by":"publisher","first-page":"161","DOI":"10.9734\/jerr\/2024\/v26i81237","volume":"26","author":"OS Ogungbemi","year":"2024","unstructured":"Ogungbemi, O.S., Ezeugwa, F.A., Olaniyi, O.O., Akinola, O.I., Oladoyinbo, O.B.: Overcoming remote workforce cyber threats: a comprehensive ransomware and bot net defense strategy utilizing vpn networks. J. Eng. Res. Reports 26(8), 161\u2013184 (2024)","journal-title":"J. Eng. Res. Reports"},{"key":"5633_CR42","unstructured":"Konoth, R.K.,van Wegberg, R., Moonsamy, V., Bos, H.: Malicious cryptocurrency miners: status and outlook. arXiv preprint arXiv:1901.10794, (2019)"},{"issue":"1","key":"5633_CR43","first-page":"1","volume":"11","author":"\u0130 Kara","year":"2019","unstructured":"Kara, \u0130, Aydos, M.: The ghost in the system: technical analysis of remote access trojan. Int. J. Inf. Technol. Secur. 11(1), 1\u201312 (2019)","journal-title":"Int. J. Inf. Technol. Secur."},{"issue":"1","key":"5633_CR44","first-page":"100","volume":"11","author":"S Rizvi","year":"2020","unstructured":"Rizvi, S., Pipetti, R., McIntyre, N., Todd, J., Williams, I.: Threat model for securing internet of things (iot) network at device-level. Int. Things 11(1), 100\u2013240 (2020)","journal-title":"Int. Things"},{"key":"5633_CR45","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.jnca.2016.10.015","volume":"77","author":"P Mishra","year":"2017","unstructured":"Mishra, P., Pilli, E.S., Varadharajan, V., Tupakula, U.: Intrusion detection techniques in cloud environment: a survey. J. Netw. Comput. Appl. 77, 18\u201347 (2017)","journal-title":"J. Netw. Comput. Appl."},{"issue":"2","key":"5633_CR46","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1080\/23738871.2017.1366536","volume":"2","author":"C Maple","year":"2017","unstructured":"Maple, C.: Security and privacy in the internet of things. J. Cyber Policy 2(2), 155\u2013184 (2017)","journal-title":"J. Cyber Policy"},{"key":"5633_CR47","doi-asserted-by":"crossref","unstructured":"Moustafa, N., Slay, J.: Unsw-nb15: a comprehensive data set for network intrusion detection systems (unsw-nb15 network data set). In 2015 military communications and information systems conference (MilCIS), pages 1\u20136. IEEE, (2015)","DOI":"10.1109\/MilCIS.2015.7348942"},{"issue":"8","key":"5633_CR48","doi-asserted-by":"publisher","first-page":"1745","DOI":"10.1109\/TMC.2018.2866249","volume":"18","author":"A Sivanathan","year":"2018","unstructured":"Sivanathan, A., Gharakheili, H.H., Loi, F., Radford, A., Wijenayake, C., Vishwanath, A., Sivaraman, V.: Classifying iot devices in smart environments using network traffic characteristics. IEEE Trans. Mob. Comput. 18(8), 1745\u20131759 (2018)","journal-title":"IEEE Trans. Mob. Comput."},{"key":"5633_CR49","doi-asserted-by":"crossref","unstructured":"Bezerra, V.H., da Costa, V.G.T., Martins, R.A., Junior, S.B., Miani, R.S., Zarpelao, B.B.: Providing iot host-based datasets for intrusion detection research. In Anais Principais do XVIII Simp\u00f3sio Brasileiro em Seguran\u00e7a da Informa\u00e7\u00e3o e de Sistemas Computacionais, pages 15\u201328. SBC, (2018)","DOI":"10.5753\/sbseg.2018.4240"},{"key":"5633_CR50","doi-asserted-by":"crossref","unstructured":"McDermott, C.D., Majdani, F., Petrovski, A.V.: Botnet detection in the internet of things using deep learning approaches. In 2018 international joint conference on neural networks (IJCNN), pages 1\u20138. IEEE, (2018)","DOI":"10.1109\/IJCNN.2018.8489489"},{"issue":"3","key":"5633_CR51","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","volume":"17","author":"Y Meidan","year":"2018","unstructured":"Meidan, Y., Bohadana, M., Mathov, Y., Mirsky, Y., Shabtai, A., Breitenbacher, D., Elovici, Y.: N-baiot\u2013network-based detection of iot botnet attacks using deep autoencoders. IEEE Pervasive Comput. 17(3), 12\u201322 (2018)","journal-title":"IEEE Pervasive Comput."},{"key":"5633_CR52","unstructured":"Kang, H, Ahn, D.H., Lee, G.M., Yoo, J.D., Park, K.H., Kim, H.K.: Iot network intrusion dataset. IEEE Dataport, (2019)"},{"key":"5633_CR53","doi-asserted-by":"publisher","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","volume":"100","author":"N Koroniotis","year":"2019","unstructured":"Koroniotis, N., Moustafa, N., Sitnikova, E., Turnbull, B.: Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: bot-iot dataset. Futur. Gener. Comput. Syst. 100, 779\u2013796 (2019)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"5633_CR54","doi-asserted-by":"crossref","unstructured":"Guerra-Manzanares, A., Medina-Galindo, J., Bahsi, H., N\u00f5mm, S.: Medbiot: generation of an iot botnet dataset in a medium-sized iot network. In ICISSP, pages 207\u2013218, (2020)","DOI":"10.5220\/0009187802070218"},{"key":"5633_CR55","unstructured":"Trajanovski, T., Zhang, N.: Iot-bda botnet analysis dataset, (2021)"},{"issue":"13","key":"5633_CR56","doi-asserted-by":"publisher","first-page":"5941","DOI":"10.3390\/s23135941","volume":"23","author":"ECP Neto","year":"2023","unstructured":"Neto, E.C.P., Dadkhah, S., Ferreira, R., Zohourian, A., Rongxing, L., Ghorbani, A.A.: Ciciot 2023: a real-time dataset and benchmark for large-scale attacks in iot environment. Sensors 23(13), 5941 (2023)","journal-title":"Sensors"},{"key":"5633_CR57","doi-asserted-by":"crossref","unstructured":"Adjei, J., Heywood, N.Z., Nandy, B., Seddigh, N.: Identifying iot devices: a machine learning analysis using traffic flow metadata. In NOMS 2024-2024 IEEE Network Operations and Management Symposium, pages 1\u20137. IEEE, (2024)","DOI":"10.1109\/NOMS59830.2024.10575442"},{"key":"5633_CR58","doi-asserted-by":"crossref","unstructured":"Jun, C., Chi, C.: Design of complex event-processing ids in internet of things. In 2014 sixth international conference on measuring technology and mechatronics automation, pages 226\u2013229. IEEE, (2014)","DOI":"10.1109\/ICMTMA.2014.57"},{"key":"5633_CR59","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101707","volume":"91","author":"MS Pour","year":"2020","unstructured":"Pour, M.S., Mangino, A., Friday, K., Rathbun, M., Bou-Harb, E., Iqbal, F., Samtani, S., Crichigno, J., Ghani, N.: On data-driven curation, learning, and analysis for inferring evolving internet-of-things (iot) botnets in the wild. Comput. Secur. 91, 101707 (2020)","journal-title":"Comput. Secur."},{"key":"5633_CR60","first-page":"229","volume":"99","author":"M Roesch","year":"1999","unstructured":"Roesch, M., et al.: Snort: lightweight intrusion detection for networks. Lisa 99, 229\u2013238 (1999)","journal-title":"Lisa"},{"key":"5633_CR61","unstructured":"Behal, S., Brar, A.S., Kumar, K.: Signature-based botnet detection and prevention. In Proceedings of International Symposium on Computer Engineering and Technology, pages 127\u2013132, (2010)"},{"key":"5633_CR62","doi-asserted-by":"crossref","unstructured":"Liu, C., Yang, J., Chen, R., Zhang, Y., Zeng, J.: Research on immunity-based intrusion detection technology for the internet of things. In 2011 Seventh International Conference on Natural Computation, volume\u00a01, pages 212\u2013216. IEEE, (2011)","DOI":"10.1109\/ICNC.2011.6022060"},{"key":"5633_CR63","doi-asserted-by":"crossref","unstructured":"Kasinathan, P., Pastrone, C., Spirito, M.A., Vinkovits, M.: Denial-of-service detection in 6lowpan based internet of things. In 2013 IEEE 9th international conference on wireless and mobile computing, networking and communications (WiMob), pages 600\u2013607. IEEE, (2013)","DOI":"10.1109\/WiMOB.2013.6673419"},{"issue":"12","key":"5633_CR64","doi-asserted-by":"publisher","first-page":"24188","DOI":"10.3390\/s141224188","volume":"14","author":"O Doohwan","year":"2014","unstructured":"Doohwan, O., Kim, D., Ro, W.W.: A malicious pattern detection engine for embedded security systems in the internet of things. Sensors 14(12), 24188\u201324211 (2014)","journal-title":"Sensors"},{"key":"5633_CR65","doi-asserted-by":"crossref","unstructured":"Abbas, M.F.B., Srikanthan, T.: Low-complexity signature-based malware detection for iot devices. In International Conference on Applications and Techniques in Information Security, pages 181\u2013189. Springer, (2017)","DOI":"10.1007\/978-981-10-5421-1_15"},{"key":"5633_CR66","unstructured":"Ioulianou, P., Vasilakis, V., Moscholios, I., Logothetis, M.: A signature-based intrusion detection system for the internet of things. Information and Communication Technology Form, pages 1\u20137, (2018)"},{"issue":"14","key":"5633_CR67","doi-asserted-by":"publisher","first-page":"18355","DOI":"10.1007\/s11042-017-5560-6","volume":"77","author":"X Jia","year":"2018","unstructured":"Jia, X., He, D., Li, L., Choo, K.-K.R.: Signature-based three-factor authenticated key exchange for internet of things applications. Multimed. Tools Appl. 77(14), 18355\u201318382 (2018)","journal-title":"Multimed. Tools Appl."},{"issue":"3","key":"5633_CR68","doi-asserted-by":"publisher","first-page":"164","DOI":"10.3390\/info15030164","volume":"15","author":"M Schr\u00f6tter","year":"2024","unstructured":"Schr\u00f6tter, M., Niemann, A., Schnor, B.: A comparison of neural-network-based intrusion detection against signature-based detection in iot networks. Information 15(3), 164 (2024)","journal-title":"Information"},{"key":"5633_CR69","unstructured":"Carl, L., et al.: Using machine learning technliques to identify botnet traffic. In Local Computer Networks, Proceedings 2006 31st IEEE Conference on. IEEE, (2006)"},{"issue":"9","key":"5633_CR70","doi-asserted-by":"publisher","first-page":"1967","DOI":"10.3390\/s17091967","volume":"17","author":"M Lopez-Martin","year":"2017","unstructured":"Lopez-Martin, M., Carro, B., Sanchez-Esguevillas, A., Lloret, J.: Conditional variational autoencoder for prediction and feature recovery applied to intrusion detection in iot. Sensors 17(9), 1967 (2017)","journal-title":"Sensors"},{"issue":"1","key":"5633_CR71","first-page":"1750637","volume":"2017","author":"F Yulong","year":"2017","unstructured":"Yulong, F., Yan, Z., Cao, J., Kon\u00e9, O., Cao, X.: An automata based intrusion detection method for internet of things. Mob. Inf. Syst. 2017(1), 1750637 (2017)","journal-title":"Mob. Inf. Syst."},{"key":"5633_CR72","volume":"89","author":"SY Bobade","year":"2025","unstructured":"Bobade, S.Y., Apare, R.S., Borhade, R.H., Mahalle, P.N.: Intelligent detection framework for iot-botnet detection: dbn-rnn with improved feature set. J. Inf. Secur. Appl. 89, 103961 (2025)","journal-title":"J. Inf. Secur. Appl."},{"key":"5633_CR73","doi-asserted-by":"crossref","unstructured":"Midi, D., Rullo, A., Mudgerikar, A., Bertino, E.: Kalis\u2014a system for knowledge-driven adaptable intrusion detection for the internet of things. In 2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), pages 656\u2013666. IEEE, (2017)","DOI":"10.1109\/ICDCS.2017.104"},{"issue":"1","key":"5633_CR74","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1186\/s13638-018-1128-z","volume":"2018","author":"L Liu","year":"2018","unstructured":"Liu, L., Bing, X., Zhang, X., Xianjun, W.: An intrusion detection method for internet of things based on suppressed fuzzy clustering. EURASIP J. Wirel. Commun. Netw. 2018(1), 113 (2018)","journal-title":"EURASIP J. Wirel. Commun. Netw."},{"key":"5633_CR75","doi-asserted-by":"crossref","unstructured":"Le, A., Loo, J., Luo, Y., Lasebae, A.: Specification-based ids for securing rpl from topology attacks. In 2011 IFIP Wireless Days (WD), pages 1\u20133. IEEE, (2011)","DOI":"10.1109\/WD.2011.6098218"},{"issue":"2","key":"5633_CR76","doi-asserted-by":"publisher","first-page":"25","DOI":"10.3390\/info7020025","volume":"7","author":"A Le","year":"2016","unstructured":"Le, A., Loo, J., Chai, K.K., Aiash, M.: A specification-based ids for detecting attacks on rpl-based network topology. Information 7(2), 25 (2016)","journal-title":"Information"},{"key":"5633_CR77","doi-asserted-by":"crossref","unstructured":"Lee, S.-Y., Wi, S.-R., Seo, E., Jung, J.-K., Chung, T.-M.: Profiot: abnormal behavior profiling (abp) of iot devices based on a machine learning approach. In 2017 27th International Telecommunication Networks and Applications Conference (ITNAC), pages 1\u20136. IEEE, (2017)","DOI":"10.1109\/ATNAC.2017.8215434"},{"issue":"3","key":"5633_CR78","doi-asserted-by":"publisher","first-page":"415","DOI":"10.3390\/electronics9030415","volume":"9","author":"Zeeshan Ali Khan and Ubaid Abbasi","year":"2020","unstructured":"Zeeshan Ali Khan and Ubaid Abbasi: Reputation management using honeypots for intrusion detection in the internet of things. Electronics 9(3), 415 (2020)","journal-title":"Electronics"},{"key":"5633_CR79","doi-asserted-by":"publisher","DOI":"10.7717\/peerj-cs.2512","volume":"10","author":"Y Diao","year":"2024","unstructured":"Diao, Y., Chen, H., Liu, W., Rasool, A.: Sh-sds: a new static-dynamic strategy for substation host security detection. PeerJ Computer Science 10, e2512 (2024)","journal-title":"PeerJ Computer Science"},{"key":"5633_CR80","doi-asserted-by":"crossref","unstructured":"Nobakht, M., Sivaraman, V., Boreli, R.: A host-based intrusion detection and mitigation framework for smart home iot using openflow. In 2016 11th International conference on availability, reliability and security (ARES), pages 147\u2013156. IEEE, (2016)","DOI":"10.1109\/ARES.2016.64"},{"key":"5633_CR81","doi-asserted-by":"crossref","unstructured":"Breitenbacher, D., Homoliak, I., Aung, Y.L., Tippenhauer, N.O., Elovici, Y.: Hades-iot: a practical host-based anomaly detection system for iot devices. In Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, pages 479\u2013484, (2019)","DOI":"10.1145\/3321705.3329847"},{"issue":"11","key":"5633_CR82","first-page":"16912","volume":"12","author":"Z Wang","year":"2025","unstructured":"Wang, Z., Zhou, R., Yang, S., He, D., Chan, S.: A novel lightweight iot intrusion detection model based on self-knowledge distillation. IEEE Int. Things J. 12(11), 16912\u201316930 (2025)","journal-title":"IEEE Int. Things J."},{"issue":"1","key":"5633_CR83","doi-asserted-by":"publisher","first-page":"99508","DOI":"10.1109\/ACCESS.2019.2930200","volume":"7","author":"I Ghafir","year":"2019","unstructured":"Ghafir, I., Kyriakopoulos, K.G., Lambotharan, S., Aparicio-Navarro, F.J., AsSadhan, B., BinSalleeh, H., Diab, D.M.: Hidden markov models and alert correlations for the prediction of advanced persistent threats. IEEE Access 7(1), 99508\u201399520 (2019)","journal-title":"IEEE Access"},{"key":"5633_CR84","doi-asserted-by":"crossref","unstructured":"von Sperling, T.L., de Caldas Filho, F.L., de Sousa, R.T., e Martins. L.M.C., Rocha, R.L.: Tracking intruders in iot networks by means of dns traffic analysis. In 2017 Workshop on Communication Networks and Power Systems (WCNPS), pages 1\u20134. IEEE, (2017)","DOI":"10.1109\/WCNPS.2017.8252938"},{"key":"5633_CR85","doi-asserted-by":"crossref","unstructured":"Passerini, E., Paleari, R., Martignoni, L., Bruschi, D.: Fluxor: detecting and monitoring fast-flux service networks. In International conference on detection of intrusions and malware, and vulnerability assessment, pages 186\u2013206. Springer, (2008)","DOI":"10.1007\/978-3-540-70542-0_10"},{"issue":"4","key":"5633_CR86","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2584679","volume":"16","author":"L Bilge","year":"2014","unstructured":"Bilge, L., Sen, S., Balzarotti, D., Kirda, E., Kruegel, C.: Exposure: a passive dns analysis service to detect and report malicious domains. ACM Transactions on Information and System Security (TISSEC) 16(4), 1\u201328 (2014)","journal-title":"ACM Transactions on Information and System Security (TISSEC)"},{"key":"5633_CR87","unstructured":"Antonakakis, M., Perdisci, R., Nadji, Y., Vasiloglou, N., Abu-Nimeh, S., Lee, W., Dagon, D.: From throw-away traffic to bots: detecting the rise of dga-based malware. In Presented as part of the 21st $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 12), pages 491\u2013506, (2012)"},{"key":"5633_CR88","doi-asserted-by":"crossref","unstructured":"Sharifnya, R., Abadi, M.: A novel reputation system to detect dga-based botnets. In ICCKE 2013, pages 417\u2013423. IEEE, (2013)","DOI":"10.1109\/ICCKE.2013.6682860"},{"issue":"4","key":"5633_CR89","doi-asserted-by":"publisher","first-page":"4436","DOI":"10.1109\/TIA.2020.2971952","volume":"56","author":"R Vinayakumar","year":"2020","unstructured":"Vinayakumar, R., Alazab, M., Srinivasan, S., Pham, Q.-V., Padannayil, S.K., Simran, K.: A visualized botnet detection system based deep learning for the internet of things networks of smart cities. IEEE Trans. Ind. Appl. 56(4), 4436\u20134456 (2020)","journal-title":"IEEE Trans. Ind. Appl."},{"key":"5633_CR90","doi-asserted-by":"crossref","unstructured":"Moubayed, A., Aqeeli, E., Shami, A.: Ensemble-based feature selection and classification model for dns typo-squatting detection. In 2020 IEEE Canadian Conference on Electrical and Computer Engineering (CCECE), pages 1\u20136. IEEE, (2020)","DOI":"10.1109\/CCECE47787.2020.9255697"},{"key":"5633_CR91","doi-asserted-by":"crossref","unstructured":"Quinkert, F., Tatang, D., Holz, T.: Digging deeper: an analysis of domain impersonation in the lower dns hierarchy. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pages 68\u201387. Springer, (2021)","DOI":"10.1007\/978-3-030-80825-9_4"},{"issue":"5","key":"5633_CR92","doi-asserted-by":"publisher","first-page":"455","DOI":"10.1007\/s10207-015-0310-0","volume":"15","author":"M Anagnostopoulos","year":"2016","unstructured":"Anagnostopoulos, M., Kambourakis, G., Gritzalis, S.: New facets of mobile botnet: architecture and evaluation. Int. J. Inf. Secur. 15(5), 455\u2013473 (2016)","journal-title":"Int. J. Inf. Secur."},{"key":"5633_CR93","doi-asserted-by":"crossref","unstructured":"Hu, X., Knysz, M., Shin, K.G.: Measurement and analysis of global ip-usage patterns of fast-flux botnets. In 2011 Proceedings IEEE INFOCOM, pages 2633\u20132641. IEEE, (2011)","DOI":"10.1109\/INFCOM.2011.5935091"},{"key":"5633_CR94","doi-asserted-by":"crossref","unstructured":"Dwyer, O.P., Marnerides, A.K., Giotsas. V., Mursch, T.: Profiling iot-based botnet traffic using dns. In 2019 IEEE Global Communications Conference (GLOBECOM), pages 1\u20136. IEEE, (2019)","DOI":"10.1109\/GLOBECOM38437.2019.9014300"},{"issue":"1","key":"5633_CR95","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jnca.2019.01.006","volume":"130","author":"G Liu","year":"2019","unstructured":"Liu, G., Quan, W., Cheng, N., Zhang, H., Shui, Yu.: Efficient ddos attacks mitigation for stateful forwarding in internet of things. J. Netw. Comput. Appl. 130(1), 1\u201313 (2019)","journal-title":"J. Netw. Comput. Appl."},{"issue":"3","key":"5633_CR96","doi-asserted-by":"publisher","first-page":"816","DOI":"10.3390\/s20030816","volume":"20","author":"J Galeano-Brajones","year":"2020","unstructured":"Galeano-Brajones, J., Carmona-Murillo, J., Valenzuela-Vald\u00e9s, J.F., Luna-Valero, F.: Detection and mitigation of dos and ddos attacks in iot-based stateful sdn: an experimental approach. Sensors 20(3), 816\u2013830 (2020)","journal-title":"Sensors"},{"issue":"1","key":"5633_CR97","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1504\/IJSNET.2020.109720","volume":"34","author":"H Cheng","year":"2020","unstructured":"Cheng, H., Liu, J., Tongge, X., Ren, B., Mao, J., Zhang, W.: Machine learning based low-rate ddos attack detection for sdn enabled iot networks. Int. J. Sensor Netw. 34(1), 56\u201369 (2020)","journal-title":"Int. J. Sensor Netw."},{"issue":"8","key":"5633_CR98","first-page":"2279","volume":"40","author":"Z Yi","year":"2020","unstructured":"Yi, Z., Zhenhu, N., Yihua, Z.: Lightweight detection technology of typosquatting based on visual features. J. Comput. Appl. 40(8), 2279\u20132285 (2020)","journal-title":"J. Comput. Appl."},{"issue":"4","key":"5633_CR99","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3191329","volume":"51","author":"Y Zhauniarovich","year":"2018","unstructured":"Zhauniarovich, Y., Khalil, I., Ting, Yu., Dacier, M.: A survey on malicious domains detection through dns data analysis. ACM Computing Surveys (CSUR) 51(4), 1\u201336 (2018)","journal-title":"ACM Computing Surveys (CSUR)"},{"issue":"8","key":"5633_CR100","doi-asserted-by":"publisher","first-page":"2661","DOI":"10.1016\/j.adhoc.2013.04.014","volume":"11","author":"S Raza","year":"2013","unstructured":"Raza, S., Wallgren, L., Voigt, T.: Svelte: real-time intrusion detection in the internet of things. Ad Hoc Netw. 11(8), 2661\u20132674 (2013)","journal-title":"Ad Hoc Netw."},{"key":"5633_CR101","doi-asserted-by":"crossref","unstructured":"Krimmling, J., Peter, S.: Integration and evaluation of intrusion detection for coap in smart city applications. In 2014 IEEE Conference on Communications and Network Security, pages 73\u201378. IEEE, (2014)","DOI":"10.1109\/CNS.2014.6997468"},{"key":"5633_CR102","doi-asserted-by":"crossref","unstructured":"Cervantes, C., Poplade, D., Nogueira, M., Santos, A.: Detection of sinkhole attacks for supporting secure routing on 6lowpan for internet of things. In 2015 IFIP\/IEEE International Symposium on Integrated Network Management (IM), pages 606\u2013611. IEEE, (2015)","DOI":"10.1109\/INM.2015.7140344"},{"key":"5633_CR103","doi-asserted-by":"crossref","unstructured":"Hodo, E., Bellekens, X., Hamilton, A., Dubouilh, P.-L., Iorkyase, E., Tachtatzis, C., Atkinson, R.: Threat analysis of iot networks using artificial neural network intrusion detection system. In 2016 International Symposium on Networks, Computers and Communications (ISNCC), pages 1\u20136. IEEE, (2016)","DOI":"10.1109\/ISNCC.2016.7746067"},{"key":"5633_CR104","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1016\/j.comcom.2016.12.001","volume":"98","author":"H Bostani","year":"2017","unstructured":"Bostani, H., Sheikhan, M.: Hybrid of anomaly-based and specification-based ids for internet of things using unsupervised opf based on mapreduce approach. Comput. Commun. 98, 52\u201371 (2017)","journal-title":"Comput. Commun."},{"issue":"11","key":"5633_CR105","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3390\/electronics8111210","volume":"8","author":"A Khraisat","year":"2019","unstructured":"Khraisat, A., Gondal, I., Vamplew, P., Kamruzzaman, J., Alazab, A.: A novel ensemble of hybrid intrusion detection system for detecting internet of things attacks. Electronics 8(11), 1\u201318 (2019)","journal-title":"Electronics"},{"key":"5633_CR106","doi-asserted-by":"crossref","unstructured":"Chinnasamy, R., Subramanian, M., Sengupta, N.: Empowering intrusion detection systems: a synergistic hybrid approach with optimization and deep learning techniques for network security. International Arab Journal of Information Technology (IAJIT) 22(1), (2025)","DOI":"10.34028\/iajit\/22\/1\/6"},{"issue":"10","key":"5633_CR107","doi-asserted-by":"publisher","first-page":"18237","DOI":"10.1109\/JIOT.2024.3360626","volume":"11","author":"R Kalakoti","year":"2024","unstructured":"Kalakoti, R., Bahsi, H., N\u00f5mm, S.: Improving iot security with explainable ai: quantitative evaluation of explainability for iot botnet detection. IEEE Internet Things J. 11(10), 18237\u201318254 (2024)","journal-title":"IEEE Internet Things J."},{"key":"5633_CR108","doi-asserted-by":"publisher","first-page":"71024","DOI":"10.1109\/ACCESS.2024.3402446","volume":"12","author":"AN Gummadi","year":"2024","unstructured":"Gummadi, A.N., Napier, J.C., Abdallah, M.: Xai-iot: an explainable ai framework for enhancing anomaly detection in iot systems. IEEE Access 12, 71024\u201371054 (2024)","journal-title":"IEEE Access"},{"issue":"7","key":"5633_CR109","doi-asserted-by":"publisher","first-page":"2288","DOI":"10.3390\/s25072288","volume":"25","author":"Taiwo Blessing Ogunseyi and Gogulakrishan Thiyagarajan","year":"2025","unstructured":"Taiwo Blessing Ogunseyi and Gogulakrishan Thiyagarajan: An explainable lstm-based intrusion detection system optimized by firefly algorithm for iot networks. Sensors 25(7), 2288 (2025)","journal-title":"Sensors"},{"key":"5633_CR110","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104191","volume":"149","author":"S Shoukat","year":"2025","unstructured":"Shoukat, S., Gao, T., Javeed, D., Saeed, M.S., Adil, M.: Trust my ids: an explainable ai integrated deep learning-based transparent threat detection system for industrial networks. Com. Secur. 149, 104191 (2025)","journal-title":"Com. Secur."},{"key":"5633_CR111","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104318","volume":"151","author":"CS Kalutharage","year":"2025","unstructured":"Kalutharage, C.S., Liu, X., Chrysoulas, C.: Neurosymbolic learning and domain knowledge-driven explainable ai for enhanced iot network attack detection and response. Com. Secur. 151, 104318 (2025)","journal-title":"Com. Secur."},{"issue":"1","key":"5633_CR112","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/j.jnca.2017.02.009","volume":"84","author":"BB Zarpel\u00e3o","year":"2017","unstructured":"Zarpel\u00e3o, B.B., Miani, R.S., Kawakani, C.T., de Alvarenga, S.C.: A survey of intrusion detection in internet of things. J. Netw. Comput. Appl. 84(1), 25\u201337 (2017)","journal-title":"J. Netw. Comput. Appl."},{"issue":"4","key":"5633_CR113","doi-asserted-by":"publisher","first-page":"3496","DOI":"10.1109\/COMST.2018.2844742","volume":"20","author":"E Benkhelifa","year":"2018","unstructured":"Benkhelifa, E., Welsh, T., Hamouda, W.: A critical review of practices and challenges in intrusion detection systems for iot: toward universal and resilient systems. IEEE Communications Surveys & Tutorials 20(4), 3496\u20133509 (2018)","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"1","key":"5633_CR114","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13677-018-0123-6","volume":"7","author":"MF Elrawy","year":"2018","unstructured":"Elrawy, M.F., Awad, A.I., Hamed, H.F.A.: Intrusion detection systems for iot-based smart environments: a survey. J. Cloud Comput. 7(1), 1\u201321 (2018)","journal-title":"J. Cloud Comput."},{"issue":"3","key":"5633_CR115","doi-asserted-by":"publisher","first-page":"2671","DOI":"10.1109\/COMST.2019.2896380","volume":"21","author":"N Chaabouni","year":"2019","unstructured":"Chaabouni, N., Mosbah, M., Zemmari, A., Sauvignac, C., Faruki, P.: Network intrusion detection for iot security based on learning techniques. IEEE Commun. Surveys & Tutorials 21(3), 2671\u20132701 (2019)","journal-title":"IEEE Commun. Surveys & Tutorials"},{"issue":"3","key":"5633_CR116","doi-asserted-by":"publisher","first-page":"1646","DOI":"10.1109\/COMST.2020.2988293","volume":"22","author":"MA Al-Garadi","year":"2020","unstructured":"Al-Garadi, M.A., Mohamed, A., Al-Ali, A., Xiaojiang, D., Ali, I., Guizani, M.: A survey of machine and deep learning methods for internet of things (iot) security. IEEE Commun. Surveys & Tutorials 22(3), 1646\u20131685 (2020)","journal-title":"IEEE Commun. Surveys & Tutorials"},{"issue":"4","key":"5633_CR117","doi-asserted-by":"publisher","first-page":"629","DOI":"10.3390\/electronics9040629","volume":"9","author":"J Arshad","year":"2020","unstructured":"Arshad, J., Azad, M.A., Amad, R., Salah, K., Alazab, M., Iqbal, R.: A review of performance, energy and privacy of intrusion detection systems for iot. Electronics 9(4), 629\u2013653 (2020)","journal-title":"Electronics"},{"issue":"12","key":"5633_CR118","doi-asserted-by":"publisher","first-page":"13","DOI":"10.3390\/app11125713","volume":"11","author":"M Wazzan","year":"2021","unstructured":"Wazzan, M., Algazzawi, D., Bamasaq, O., Albeshri, A., Cheng, L.: Internet of things botnet detection approaches: analysis and recommendations for future research. Appl. Sci. 11(12), 13\u201357 (2021)","journal-title":"Appl. Sci."},{"key":"5633_CR119","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103096","volume":"127","author":"Pooja Kumari and Ankit Kumar Jain","year":"2023","unstructured":"Pooja Kumari and Ankit Kumar Jain: A comprehensive study of ddos attacks over iot network and their countermeasures. Comput. Secur. 127, 103096 (2023)","journal-title":"Comput. Secur."},{"issue":"3","key":"5633_CR120","doi-asserted-by":"publisher","first-page":"1027","DOI":"10.3390\/s24031027","volume":"24","author":"A Woodiss-Field","year":"2024","unstructured":"Woodiss-Field, A., Johnstone, M.N., Haskell-Dowland, P.: Examination of traditional botnet detection on iot-based bots. Sensors 24(3), 1027 (2024)","journal-title":"Sensors"},{"issue":"2","key":"5633_CR121","doi-asserted-by":"publisher","DOI":"10.1111\/exsy.13726","volume":"42","author":"Qasem Abu Al-Haija and Ayat Droos","year":"2025","unstructured":"Qasem Abu Al-Haija and Ayat Droos: A comprehensive survey on deep learning-based intrusion detection systems in internet of things (iot). Expert. Syst. 42(2), e13726 (2025)","journal-title":"Expert. Syst."},{"issue":"4","key":"5633_CR122","doi-asserted-by":"publisher","first-page":"2242","DOI":"10.1109\/COMST.2015.2457491","volume":"17","author":"N Hoque","year":"2015","unstructured":"Hoque, N., Bhattacharyya, D.K., Kalita, J.K.: Botnet in ddos attacks: trends and challenges. IEEE Communications Surveys & Tutorials 17(4), 2242\u20132270 (2015)","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"2","key":"5633_CR123","doi-asserted-by":"publisher","first-page":"1191","DOI":"10.1109\/COMST.2019.2962586","volume":"22","author":"M Stoyanova","year":"2020","unstructured":"Stoyanova, M., Nikoloudakis, Y., Panagiotakis, S., Pallis, E., Markakis, E.K.: A survey on the internet of things (iot) forensics: challenges, approaches, and open issues. IEEE Communications Surveys & Tutorials 22(2), 1191\u20131221 (2020)","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"5633_CR124","doi-asserted-by":"crossref","unstructured":"Indre, I., Lemnaru, C.: Detection and prevention system against cyber attacks and botnet malware for information systems and internet of things. In 2016 IEEE 12th International Conference on Intelligent Computer Communication and Processing (ICCP), pages 175\u2013182. IEEE, (2016)","DOI":"10.1109\/ICCP.2016.7737142"},{"key":"5633_CR125","doi-asserted-by":"publisher","first-page":"29763","DOI":"10.1109\/ACCESS.2018.2880838","volume":"7","author":"IU Din","year":"2018","unstructured":"Din, I.U., Guizani, M., Kim, B.-S., Hassan, S., Khan, M.K.: Trust management techniques for the internet of things: a survey. IEEE Access 7, 29763\u201329787 (2018)","journal-title":"IEEE Access"},{"issue":"2","key":"5633_CR126","doi-asserted-by":"publisher","first-page":"927","DOI":"10.1109\/JIOT.2020.3010023","volume":"8","author":"J Wang","year":"2020","unstructured":"Wang, J., Shirong Hao, R., Wen, B.Z., Zhang, L., Hongxin, H., Rongxing, L.: Iot-praetor: undesired behaviors detection for iot devices. IEEE Internet Things J. 8(2), 927\u2013940 (2020)","journal-title":"IEEE Internet Things J."},{"issue":"13","key":"5633_CR127","doi-asserted-by":"publisher","first-page":"3625","DOI":"10.3390\/s20133625","volume":"20","author":"H Mrabet","year":"2020","unstructured":"Mrabet, H., Belguith, S., Alhomoud, A., Jemai, A.: A survey of iot security based on a layered architecture of sensing and data analysis. Sensors 20(13), 3625\u20133644 (2020)","journal-title":"Sensors"},{"issue":"3","key":"5633_CR128","doi-asserted-by":"publisher","first-page":"727","DOI":"10.3390\/s19030727","volume":"19","author":"JM Ceron","year":"2019","unstructured":"Ceron, J.M., Steding-Jessen, K., Hoepers, C., Granville, L.Z., Margi, C.B.: Improving iot botnet investigation using an adaptive network layer. Sensors 19(3), 727\u2013740 (2019)","journal-title":"Sensors"},{"key":"5633_CR129","doi-asserted-by":"publisher","first-page":"145768","DOI":"10.1109\/ACCESS.2020.3014891","volume":"8","author":"H-V Le","year":"2020","unstructured":"Le, H.-V., Ngo, Q.-D.: V-sandbox for dynamic analysis iot botnet. IEEE Access 8, 145768\u2013145786 (2020)","journal-title":"IEEE Access"},{"key":"5633_CR130","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103820","volume":"141","author":"A Nitish","year":"2024","unstructured":"Nitish, A., Hanumanthappa, J., Shiva Prakash, S.P., et al.: Class imbalance and concept drift invariant online botnet threat detection framework for heterogeneous iot edge. Comput. Secur. 141, 103820 (2024)","journal-title":"Comput. Secur."},{"key":"5633_CR131","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103176","volume":"129","author":"I Debicha","year":"2023","unstructured":"Debicha, I., Cochez, B., Kenaza, T., Debatty, T., Dricot, J.-M., Mees, W.: Adv-bot: realistic adversarial botnet attacks against network intrusion detection systems. Comput. Secur. 129, 103176 (2023)","journal-title":"Comput. Secur."}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-025-05633-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10586-025-05633-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-025-05633-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T20:01:21Z","timestamp":1765051281000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10586-025-05633-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,9]]},"references-count":131,"journal-issue":{"issue":"15","published-print":{"date-parts":[[2025,12]]}},"alternative-id":["5633"],"URL":"https:\/\/doi.org\/10.1007\/s10586-025-05633-1","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"type":"print","value":"1386-7857"},{"type":"electronic","value":"1573-7543"}],"subject":[],"published":{"date-parts":[[2025,10,9]]},"assertion":[{"value":"1 October 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 June 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 July 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 October 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interest"}},{"value":"Not Applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval"}}],"article-number":"945"}}