{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T15:43:20Z","timestamp":1781883800605,"version":"3.54.5"},"reference-count":15,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T00:00:00Z","timestamp":1765843200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The rapid expansion of Internet of Things (IoT) technologies has introduced significant challenges in understanding the complexity and structure of network traffic data, which is essential for developing effective cybersecurity solutions. This research presents a comprehensive statistical and multivariate analysis of the IoT-23 dataset to identify meaningful network traffic patterns and assess the effectiveness of various analytical methods for IoT security research. The study applies descriptive statistics, inferential analysis, and multivariate techniques, including Principal Component Analysis (PCA), DBSCAN clustering, and factor analysis (FA), to the publicly available IoT-23 dataset. Descriptive analysis reveals clear evidence of non-normal distributions: for example, the features src_bytes, dst_bytes, and src_pkts have skewness values of \u22124.21, \u22123.87, and \u22122.98, and kurtosis values of 38.45, 29.67, and 18.23, respectively. These values indicate highly skewed, heavy-tailed distributions with frequent outliers. Correlation analysis revealed a strong positive correlation (0.97) between orig_bytes and resp_bytes, and a strong negative correlation (\u22120.76) between duration and resp_bytes, while inferential statistics indicate that linear regression provides optimal modeling of data relationships. Key findings show that PCA is highly effective, capturing 99% of the dataset\u2019s variance and enabling significant dimensionality reduction. DBSCAN clustering identifies six distinct clusters, highlighting diverse network traffic behaviors within IoT environments. In contrast, FA explains only 11.63% of the variance, indicating limited suitability for this dataset. These results establish important benchmarks for future IoT cybersecurity research and demonstrate the superior effectiveness of PCA and DBSCAN for analyzing complex IoT network traffic data. The findings offer practical guidance for researchers in selecting appropriate statistical methods for IoT dataset analysis, ultimately supporting the development of more robust cybersecurity solutions.<\/jats:p>","DOI":"10.3390\/jcp5040112","type":"journal-article","created":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T11:00:26Z","timestamp":1765882826000},"page":"112","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Statistical and Multivariate Analysis of the IoT-23 Dataset: A Comprehensive Approach to Network Traffic Pattern Discovery"],"prefix":"10.3390","volume":"5","author":[{"given":"Humera","family":"Ghani","sequence":"first","affiliation":[{"name":"School of Computing and Digital Media, London Metropolitan University, London N7 8DB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shahram","family":"Salekzamankhani","sequence":"additional","affiliation":[{"name":"School of Computing and Digital Media, London Metropolitan University, London N7 8DB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7203-0039","authenticated-orcid":false,"given":"Bal","family":"Virdee","sequence":"additional","affiliation":[{"name":"School of Computing and Digital Media, London Metropolitan University, London N7 8DB, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,16]]},"reference":[{"key":"ref_1","unstructured":"Statista (2025, May 02). Internet of Things Market Outlook Report. Statista. Available online: https:\/\/www.statista.com\/study\/109197\/internet-of-things-market-outlook-report\/."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1007\/s43926-025-00167-9","article-title":"IoT technology in maritime logistics management: Exploration of data analysis methods","volume":"5","author":"Wang","year":"2025","journal-title":"Discov. Internet Things"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1186\/s40537-025-01146-1","article-title":"Towards a minimum universal features set for IoT DDoS attack detection","volume":"12","author":"Ebrahem","year":"2025","journal-title":"J. Big Data"},{"key":"ref_4","first-page":"995","article-title":"Enhancing IoT Security: A Comparative Analysis of Preprocessing Techniques and Classifier Performance on IoT23 and CIC IoT 2023 Datasets","volume":"52","author":"Elkhadir","year":"2025","journal-title":"IAENG Int. J. Comput. Sci."},{"key":"ref_5","first-page":"1","article-title":"Multi-Stage Enhanced Zero Trust Intrusion Detection System for Unknown Attack Detection in Internet of Things and Traditional Networks","volume":"28","author":"Almajali","year":"2025","journal-title":"ACM Trans. Priv. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"e2145","DOI":"10.7717\/peerj-cs.2145","article-title":"Improved temporal IoT device identification using robust statistical features","volume":"10","author":"Aqil","year":"2024","journal-title":"PeerJ Comput. Sci."},{"key":"ref_7","first-page":"864","article-title":"Performance evaluation of parametric and non-parametric machine learning models using statistical analysis for RT-IoT2022 dataset: Parametric and non-parametric machine learning models","volume":"83","author":"Sharmila","year":"2024","journal-title":"J. Sci. Ind. Res. (JSIR)"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Li, J., Othman, M.S., Chen, H., and Yusuf, L.M. (2024, January 21\u201322). Cybersecurity Insights: Analyzing IoT Data Through Statistical and Visualization Techniques. Proceedings of the 2024 International Symposium on Parallel Computing and Distributed Systems (PCDS), Singapore.","DOI":"10.1109\/PCDS61776.2024.10743769"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Smiesko, J., Segec, P., and Kontsek, M. (2023). Machine recognition of DDoS attacks using statistical parameters. Mathematics, 12.","DOI":"10.3390\/math12010142"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Kim, Y.G., Ahmed, K.J., Lee, M.J., and Tsukamoto, K. (2022, January 7\u20139). A Comprehensive Analysis of Machine Learning-Based Intrusion Detection System for IoT-23 Dataset. Proceedings of the International Conference on Intelligent Networking and Collaborative Systems, Sanda-Shi, Japan.","DOI":"10.1007\/978-3-031-14627-5_48"},{"key":"ref_11","unstructured":"Chakraborty, S., Khayer, N., and Ahmed, T. (2020, January 19\u201321). Assessing critical factors affecting the mass adoption of IoT in Bangladesh. Proceedings of the International Conference on Mechanical Industrial & Energy Engineering, Khulna, Bangladesh."},{"key":"ref_12","unstructured":"Garcia, S., Parmisano, A., and Erquiaga, M.J. (2020). IoT-23: A labeled dataset with malicious and benign IoT network traffic (Version 1.0.0) [Data set]. Zenodo, Available online: https:\/\/www.stratosphereips.org\/datasets-iot23."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1080\/19393555.2015.1125974","article-title":"The evaluation of Network Anomaly Detection Systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set","volume":"25","author":"Moustafa","year":"2016","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Damasevicius, R., Venckauskas, A., Grigaliunas, S., Toldinas, J., Morkevicius, N., Aleliunas, T., and Smuikys, P. (2020). LITNET-2020: An annotated real-world network flow dataset for network intrusion detection. Electronics, 9.","DOI":"10.3390\/electronics9050800"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"485","DOI":"10.1109\/JIOT.2021.3085194","article-title":"ToN_IoT: The role of heterogeneity and the need for standardization of features and attack types in IoT network intrusion data sets","volume":"9","author":"Booij","year":"2021","journal-title":"IEEE Internet Things J."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/112\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,16]],"date-time":"2025-12-16T11:20:36Z","timestamp":1765884036000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/112"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,16]]},"references-count":15,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040112"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040112","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,16]]}}}