{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,6]],"date-time":"2026-04-06T12:06:23Z","timestamp":1775477183609,"version":"3.50.1"},"reference-count":32,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2024,6,17]],"date-time":"2024-06-17T00:00:00Z","timestamp":1718582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The tremendous growth of the Internet of Things (IoT) has gained a lot of attention in the global market. The massive deployment of IoT is also inherent in various security vulnerabilities, which become easy targets for hackers. IoT botnets are one type of critical malware that degrades the performance of the IoT network and is difficult to detect by end-users. Although there are several traditional IoT botnet mitigation techniques such as access control, data encryption, and secured device configuration, these traditional mitigation techniques are difficult to apply due to normal traffic behavior, similar packet transmission, and the repetitive nature of IoT network traffic. Motivated by botnet obfuscation, this article proposes an intelligent mitigation technique for IoT botnets, named IMTIBoT. Using this technique, we harnessed the stacking of ensemble classifiers to build an intelligent system. This stacking classifier technique was tested using an experimental testbed of IoT nodes and sensors. This system achieved an accuracy of 0.984, with low latency.<\/jats:p>","DOI":"10.3390\/fi16060212","type":"journal-article","created":{"date-parts":[[2024,6,17]],"date-time":"2024-06-17T06:29:43Z","timestamp":1718605783000},"page":"212","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["IMTIBOT: An Intelligent Mitigation Technique for IoT Botnets"],"prefix":"10.3390","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1815-5794","authenticated-orcid":false,"given":"Umang","family":"Garg","sequence":"first","affiliation":[{"name":"Computer Science and Engineering, Amity University, Gwalior 201301, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1008-0804","authenticated-orcid":false,"given":"Santosh","family":"Kumar","sequence":"additional","affiliation":[{"name":"Computer Science and Engineering, Graphic Era (Deemed to be University), Dehradun 248002, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aniket","family":"Mahanti","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Auckland, Auckland 1010, New Zealand"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,6,17]]},"reference":[{"key":"ref_1","first-page":"85","article-title":"Internet Of Things: Architecture, Issues, and Applications","volume":"7","author":"Kalmeshwar","year":"2017","journal-title":"Int. J. Eng. Res. Appl."},{"key":"ref_2","first-page":"7178164","article-title":"DDoS-Capable IoT Malwares: Comparative Analysis and Mirai Investigation","volume":"2018","author":"Dragoni","year":"2018","journal-title":"Secur. Commun. Netw."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1016\/S1353-4858(18)30122-3","article-title":"Nokia Threat Intelligence Report\u20142019","volume":"2018","author":"Providers","year":"2018","journal-title":"Netw. Secur."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Sasi, T., Lashkari, A.H., Lu, R., Xiong, P., and Iqbal, S. (J. Inf. Intell., 2023). A comprehensive survey on IoT attacks: Taxonomy, detection mechanisms and challenges, J. Inf. Intell., in press.","DOI":"10.1016\/j.jiixd.2023.12.001"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Baz, M. (2022). SEHIDS: Self Evolving Host-Based Intrusion Detection System for IoT Networks. Sensors, 22.","DOI":"10.3390\/s22176505"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"109365","DOI":"10.1016\/j.comnet.2022.109365","article-title":"A real-time IoT-based botnet detection method using a novel two-step feature selection technique and the support vector machine classifier","volume":"217","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2671","DOI":"10.1109\/COMST.2019.2896380","article-title":"Network Intrusion Detection for IoT Security Based on Learning Techniques","volume":"21","author":"NChaabouni","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Zhao, H., Shu, H., and Xing, Y. (2021, January 28\u201330). A Review on IoT Botnet. Proceedings of the the 2nd International Conference on Computing and Data Science, Stanford, CA, USA.","DOI":"10.1145\/3448734.3450911"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"100030","DOI":"10.1016\/j.teler.2022.100030","article-title":"Hybrid intelligent intrusion detection system for internet of things","volume":"8","author":"Jain","year":"2022","journal-title":"Telemat. Inform. Rep."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"212220","DOI":"10.1109\/ACCESS.2020.3039985","article-title":"Systematic Literature Review on IoT-Based Botnet Attack","volume":"8","author":"Ali","year":"2020","journal-title":"IEEE Access"},{"key":"ref_11","first-page":"1060","article-title":"Stability of feature selection algorithm: A review","volume":"34","author":"Khaire","year":"2022","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Tzagkarakis, C., Petroulakis, N., and Ioannidis, S. (2019, January 17\u201321). Botnet Attack Detection at the IoT Edge Based on Sparse Representation. Proceedings of the 2019 Global IoT Summit (GIoTS), Aarhus, Denmark.","DOI":"10.1109\/GIOTS.2019.8766388"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"4944","DOI":"10.1109\/JIOT.2020.3034156","article-title":"Hybrid Deep Learning for Botnet Attack Detection in the Internet-of-Things Networks","volume":"8","author":"Popoola","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"2412","DOI":"10.1109\/TIFS.2019.2898817","article-title":"Modeling, Analysis, and Mitigation of Dynamic Botnet Formation in Wireless IoT Networks","volume":"14","author":"Farooq","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_15","first-page":"2","article-title":"P2P botnet detection based on traffic behavior analysis and classification","volume":"6","author":"Beiknejad","year":"2018","journal-title":"Int. J. Comput. Inf. Technol."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"222302","DOI":"10.1007\/s11432-020-3228-8","article-title":"Differential game-based analysis of multi-attacker multi-defender interaction","volume":"64","author":"Gao","year":"2021","journal-title":"Sci. China Inf. Sci."},{"key":"ref_17","first-page":"468","article-title":"IDS feature reduction using two algorithms","volume":"8","author":"Abbas","year":"2017","journal-title":"Int. J. Civ. Eng. Technol."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"3010","DOI":"10.1007\/s11227-017-2216-2","article-title":"The individual identification method of wireless device based on dimensionality reduction and machine learning","volume":"75","author":"Lin","year":"2017","journal-title":"J. Supercomput."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1016\/j.comnet.2018.11.010","article-title":"Dimensionality reduction with IG-PCA and ensemble classifier for network intrusion detection","volume":"148","author":"Salo","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_20","first-page":"693","article-title":"Addressing big data analytics for classification intrusion detection system","volume":"8","author":"Mutlaq","year":"2020","journal-title":"Period. Eng. Nat. Sci."},{"key":"ref_21","first-page":"665","article-title":"Dimensional Reduction with Fast ICA for IoT Botnet Detection","volume":"18","author":"Susanto","year":"2022","journal-title":"J. Appl. Secur. Res."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1016\/j.comcom.2022.10.026","article-title":"A survey on Blockchain solutions in DDoS attacks mitigation: Techniques, open challenges and future directions","volume":"197","author":"Chaganti","year":"2023","journal-title":"Comput. Commun."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Djenna, A., Bouridane, A., Rubab, S., and Marou, I.M. (2023). Artificial Intelligence-Based Malware Detection, Analysis, and Mitigation. Symmetry, 15.","DOI":"10.3390\/sym15030677"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Lawal, M.A., Shaikh, R.A., and Hassan, S.R. (2020). An anomaly mitigation framework for iot using fog computing. Electronics, 9.","DOI":"10.3390\/electronics9101565"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Khazane, H., Ridouani, M., Salahdine, F., and Kaabouch, N. (2024). A Holistic Review of Machine Learning Adversarial Attacks in IoT Networks. Future Internet, 16.","DOI":"10.3390\/fi16010032"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Pozzebon, A. (2024). Edge and Fog Computing for the Internet of Things. Future Internet, 16.","DOI":"10.3390\/fi16030101"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Alrubayyi, H., Alshareef, M.S., Nadeem, Z., Abdelmoniem, A.M., and Jaber, M. (2024). Security Threats and Promising Solutions Arising from the Intersection of AI and IoT: A Study of IoMT and IoET Applications. Future Internet, 16.","DOI":"10.3390\/fi16030085"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Ullah, I., and Mahmoud, Q.H. (2020, January 11\u201314). A Technique for Generating a Botnet Dataset for Anomalous Activity Detection in IoT Networks. Proceedings of the 2020 IEEE International Conference on Systems, Man, and Cybernetics (SMC), Toronto, ON, Canada.","DOI":"10.1109\/SMC42975.2020.9283220"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"104753","DOI":"10.1016\/j.micpro.2022.104753","article-title":"Discover botnets in IoT sensor networks: A lightweight deep learning framework with hybrid self-organizing maps","volume":"97","author":"Khan","year":"2023","journal-title":"Microprocess. Microsyst."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B.S. (2024, April 29). Malware Images, Visualization and Automatic. Available online: https:\/\/vision.ece.ucsb.edu\/sites\/vision.ece.ucsb.edu\/files\/publications\/nataraj_vizsec_2011_paper.pdf.","DOI":"10.1145\/2016904.2016908"},{"key":"ref_31","first-page":"664","article-title":"Lightweight Classification of IoT Malware Based on Image Recognition","volume":"2","author":"Su","year":"2018","journal-title":"Proc. Int. Comput. Softw. Appl. Conf."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"101873","DOI":"10.1016\/j.cose.2020.101873","article-title":"HYDRA: A multimodal deep learning framework for malware classification","volume":"95","author":"Gibert","year":"2020","journal-title":"Comput. Secur."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/16\/6\/212\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T14:59:52Z","timestamp":1760108392000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/16\/6\/212"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,17]]},"references-count":32,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2024,6]]}},"alternative-id":["fi16060212"],"URL":"https:\/\/doi.org\/10.3390\/fi16060212","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,17]]}}}