{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T23:09:26Z","timestamp":1775603366220,"version":"3.50.1"},"reference-count":57,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2022,5,20]],"date-time":"2022-05-20T00:00:00Z","timestamp":1653004800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Deanship of Scientific Research (DSR) at King Abdulaziz University (KAU)","award":["RG-10-611-43"],"award-info":[{"award-number":["RG-10-611-43"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>In recent times, organisations in a variety of businesses, such as healthcare, education, and others, have been using the Internet of Things (IoT) to produce more competent and improved services. The widespread use of IoT devices makes our lives easier. On the other hand, the IoT devices that we use suffer vulnerabilities that may impact our lives. These unsafe devices accelerate and ease cybersecurity attacks, specifically when using a botnet. Moreover, restrictions on IoT device resources, such as limitations in power consumption and the central processing unit and memory, intensify this issue because they limit the security techniques that can be used to protect IoT devices. Fortunately, botnets go through different stages before they can start attacks, and they can be detected in the early stage. This research paper proposes a framework focusing on detecting an IoT botnet in the early stage. An empirical experiment was conducted to investigate the behaviour of the early stage of the botnet, and then a baseline machine learning model was implemented for early detection. Furthermore, the authors developed an effective detection method, namely, Cross CNN_LSTM, to detect the IoT botnet based on using fusion deep learning models of a convolutional neural network (CNN) and long short-term memory (LSTM). According to the conducted experiments, the results show that the suggested model is accurate and outperforms some of the state-of-the-art methods, and it achieves 99.7 accuracy. Finally, the authors developed a kill chain model to prevent IoT botnet attacks in the early stage.<\/jats:p>","DOI":"10.3390\/s22103895","type":"journal-article","created":{"date-parts":[[2022,5,21]],"date-time":"2022-05-21T09:18:08Z","timestamp":1653124688000},"page":"3895","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["Cross Deep Learning Method for Effectively Detecting the Propagation of IoT Botnet"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3333-0850","authenticated-orcid":false,"given":"Majda","family":"Wazzan","sequence":"first","affiliation":[{"name":"Computer Science Department, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5533-3203","authenticated-orcid":false,"given":"Daniyal","family":"Algazzawi","sequence":"additional","affiliation":[{"name":"Information Systems Department, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3796-0294","authenticated-orcid":false,"given":"Aiiad","family":"Albeshri","sequence":"additional","affiliation":[{"name":"Computer Science Department, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Syed","family":"Hasan","sequence":"additional","affiliation":[{"name":"Information Systems Department, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8680-7080","authenticated-orcid":false,"given":"Osama","family":"Rabie","sequence":"additional","affiliation":[{"name":"Information Systems Department, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3320-2074","authenticated-orcid":false,"given":"Muhammad Zubair","family":"Asghar","sequence":"additional","affiliation":[{"name":"Institute of Computing and Information Technology (ICIT), Gomal University, Dera Ismail Khan 29050, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,5,20]]},"reference":[{"key":"ref_1","unstructured":"(2022, April 07). Hampshire. IoT Connections to Reach 83 Billion by 2024, Driven by Maturing Industrial Use Cases. Available online: https:\/\/www.juniperresearch.com\/press\/iot-connections-to-reach-83-bn-by-2024."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Beltr\u00e1n-Garc\u00eda, P., Aguirre-Anaya, E., Escamilla-Ambrosio, P.J., and Acosta-Bermejo, R. (2019). IoT botnets. Communications in Computer and Information Science, Springer Science and Business Media LLC.","DOI":"10.1007\/978-3-030-33229-7_21"},{"key":"ref_3","first-page":"688","article-title":"A multi-class neural network model for rapid detection of IoT botnet attacks","volume":"11","author":"Alzahrani","year":"2020","journal-title":"Int. J. Adv. Comput. Sci. Appl."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MC.2017.62","article-title":"Botnets and internet of things security","volume":"50","author":"Bertino","year":"2017","journal-title":"Computer"},{"key":"ref_5","unstructured":"TrendMicro (2021, March 05). Into the Battlefield: A Security Guide to IoT Botnets. Available online: https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/internet-of-things\/into-the-battlefield-a-security-guide-to-iot-botnets."},{"key":"ref_6","unstructured":"Costin, A., and Zaddach, J. (2018, January 3\u20136). Iot malware: Comprehensive survey, analysis framework and case studies. Proceedings of the BlackHat, Las Vegas, NV, USA."},{"key":"ref_7","unstructured":"Holmes, D., and Shattuck, J. (2022, April 07). Reaper: The Professional Bot Herder\u2019s Thingbot. Available online: https:\/\/www.f5.com\/labs\/articles\/threat-intelligence\/reaper-the-professional-bot-herders-thingbo."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s11235-019-00599-z","article-title":"A survey of DDoS attacking techniques and defence mechanisms in the IoT network","volume":"73","author":"Vishwakarma","year":"2020","journal-title":"Telecommun. Syst."},{"key":"ref_9","unstructured":"CSDE (2022, April 07). International Botnet and Iot Security Guide 2020. Available online: https:\/\/securingdigitaleconomy.org\/wp-content\/uploads\/2019\/11\/CSDE_Botnet-Report_2020_FINAL.pdf."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Wazzan, M., Algazzawi, D., Bamasaq, O., Albeshri, A., and Cheng, L. (2021). Internet of Things botnet detection approaches: Analysis and recommendations for future research. Appl. Sci., 11.","DOI":"10.3390\/app11125713"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1007\/s42979-021-00535-6","article-title":"Deep cybersecurity: A comprehensive overview from neural network and deep learning perspective","volume":"2","author":"Sarker","year":"2021","journal-title":"SN Comput. Sci."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"107450","DOI":"10.1016\/j.measurement.2019.107450","article-title":"Robust detection for network intrusion of industrial IoT based on multi-CNN fusion","volume":"154","author":"Li","year":"2019","journal-title":"Measurement"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Rezende, E., Ruppert, G., Carvalho, T., Ramos, F., and de Geus, P. (2017, January 18\u201321). Malicious software classification using transfer learning of resnet-50 deep neural network. Proceedings of the 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA), Cancun, Mexico.","DOI":"10.1109\/ICMLA.2017.00-19"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"102662","DOI":"10.1016\/j.jnca.2020.102662","article-title":"Detecting Internet of Things attacks using distributed deep learning","volume":"163","author":"Parra","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"S48","DOI":"10.1016\/j.diin.2018.01.007","article-title":"MalDozer: Automatic framework for android malware detection using deep learning","volume":"24","author":"Karbab","year":"2018","journal-title":"Digit. Investig."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Sarker, I.H., Abushark, Y.B., Alsolami, F., and Khan, A.I. (2020). Intrudtree: A machine learning based cyber security intrusion detection model. Symmetry, 12.","DOI":"10.20944\/preprints202004.0481.v1"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"5008","DOI":"10.1109\/JIOT.2020.2975779","article-title":"AUToSen: Deep-learning-based implicit continuous authentication using smartphone sensors","volume":"7","author":"Abuhamad","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"198","DOI":"10.3390\/fi13080198","article-title":"A survey on botnets: Incentives, evolution, detection and current trends","volume":"13","author":"Vu","year":"2021","journal-title":"Future Internet"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"160391","DOI":"10.1109\/ACCESS.2021.3130714","article-title":"Detecting Internet of Things Bots: A Comparative Study","volume":"9","author":"Stephens","year":"2021","journal-title":"IEEE Access"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Alghazzawi, D., Bamasag, O., Ullah, H., and Asghar, M.Z. (2021). Efficient detection of DDoS attacks using a hybrid deep learning model with improved feature selection. Appl. Sci., 11.","DOI":"10.3390\/app112411634"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Raju, P.M., and Gupta, G.P. (2022). Intrusion Detection Framework Using an Improved Deep Reinforcement Learning Technique for IoT Network. Soft Computing for Security Applications, Springer.","DOI":"10.1007\/978-981-16-5301-8_54"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Guerra-Manzanares, A., Medina-Galindo, J., Bahsi, H., and N\u00f5mm, S. (2020). MedBIoT: Generation of an IoT Botnet Dataset in a Medium-sized IoT Network. ICISSP, ResearchGate.","DOI":"10.5220\/0009187802070218"},{"key":"ref_23","unstructured":"Aprianti, W., and Deris Stiawan, M.T. (2021). Implementasi Principal Component Analysis (PCA) Dan Algoritma Na\u00efve Bayes Classifier Pada Klasifikasi Botnet di Jaringan Internet of Things (IoT). [Ph.D. Dissertation, Sriwijaya University]."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Gandhi, R., and Li, Y. (2021, January 23\u201327). Comparing Machine Learning and Deep Learning for IoT Botnet Detection. Proceedings of the 2021 IEEE International Conference on Smart Computing (SMARTCOMP), Irvine, CA, USA.","DOI":"10.1109\/SMARTCOMP52413.2021.00053"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Giaretta, L., Lekssays, A., Carminati, B., Ferrari, E., and Girdzijauskas, \u0160. (2021). LiMNet: Early-Stage Detection of IoT Botnets with Lightweight Memory Networks. European Symposium on Research in Computer Security, Springer.","DOI":"10.1007\/978-3-030-88418-5_29"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"McDermott, C.D., Majdani, F., and Petrovski, A.V. (2018, January 8\u201313). Botnet detection in the internet of things using deep learning approaches. Proceedings of the 2018 International Joint Conference on Neural Networks (IJCNN), Rio de Janeiro, Brazil.","DOI":"10.1109\/IJCNN.2018.8489489"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kim, J., Shim, M., Hong, S., Shin, Y., and Choi, E. (2020). Intelligent detection of IoT botnets using machine learning and deep learning. Appl. Sci., 10.","DOI":"10.3390\/app10197009"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Vishwakarma, R., and Jain, A.K. (2019, January 23\u201325). A Honeypot with machine learning based detection framework for defending IoT based botnet DDoS attacks. Proceedings of the 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI.2019.8862720"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Nguyen, H.-T., Ngo, Q.-D., and Le, V.-H. (2018, January 28\u201330). IoT Botnet Detection Approach Based on PSI graph and DGCNN classifier. Proceedings of the 2018 IEEE International Conference on Information Communication and Signal Processing (ICICSP), Singapore.","DOI":"10.1109\/ICICSP.2018.8549713"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Liu, J., Liu, S., and Zhang, S. (2019, January 27\u201330). Detection of IoT botnet based on deep learning. Proceedings of the 2019 Chinese Control Conference (CCC), Guangzhou, China.","DOI":"10.23919\/ChiCC.2019.8866088"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Bahsi, H., Nomm, S., and La Torre, F.B. (2018, January 18\u201321). Dimensionality reduction for machine learning based iot botnet detection. Proceedings of the 2018 15th International Conference on Control, Automation, Robotics and Vision (ICARCV), Singapore.","DOI":"10.1109\/ICARCV.2018.8581205"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1373","DOI":"10.1109\/TII.2019.2940742","article-title":"ConnSpoiler: Disrupting C&C communication of IoT-based botnet through fast detection of anomalous domain queries","volume":"16","author":"Yin","year":"2019","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"100103","DOI":"10.1016\/j.smhl.2019.100103","article-title":"IoT botnet detection via power consumption modeling","volume":"15","author":"Jung","year":"2020","journal-title":"Smart Health"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Koroniotis, N., Moustafa, N., Sitnikova, E., and Slay, J. (2017, January 13\u201315). Towards developing network forensic mechanism for botnet activities in the IoT based on machine learning techniques. Proceedings of the International Conference on Mobile Networks and Management, Melbourne, Australia.","DOI":"10.1007\/978-3-319-90775-8_3"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"2809","DOI":"10.1007\/s12652-019-01387-y","article-title":"Unsupervised intelligent system based on one class support vector machine and Grey Wolf optimization for IoT botnet detection","volume":"11","author":"Faris","year":"2020","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_36","unstructured":"Virtualbox (2022, April 07). Welcome to VirtualBox.org! 2022. Available online: https:\/\/www.virtualbox.org\/."},{"key":"ref_37","unstructured":"(2022, April 07). Vagrant. Development Environments Made Easy. Available online: https:\/\/www.vagrantup.com\/."},{"key":"ref_38","unstructured":"(2022, April 07). Jgamblin. Mirai-Source-Code. Available online: https:\/\/github.com\/jgamblin\/Mirai-Source-Code."},{"key":"ref_39","unstructured":"(2022, April 07). Lestertang. Mirai-Botnet-Source-Code. Available online: https:\/\/github.com\/lestertang\/mirai-botnet-source-code."},{"key":"ref_40","unstructured":"(2022, April 07). Kulukami. Build-a-Mirai-Botnet. Available online: https:\/\/github.com\/kulukami\/Build-a-Mirai-botnet."},{"key":"ref_41","unstructured":"Virtualbox (2022, April 07). VBoxManage. Available online: https:\/\/www.virtualbox.org\/manual\/ch08.html."},{"key":"ref_42","unstructured":"(2022, April 07). Wireshark. Download. Available online: https:\/\/www.wireshark.org\/."},{"key":"ref_43","unstructured":"UNSW (2022, April 07). The UNSW-NB15 Dataset. Available online: https:\/\/research.unsw.edu.au\/projects\/unsw-nb15-dataset."},{"key":"ref_44","unstructured":"UNSW (2022, April 07). The Bot-IoT Dataset. Available online: https:\/\/research.unsw.edu.au\/projects\/bot-iot-dataset."},{"key":"ref_45","unstructured":"(2022, April 07). Splunk. Turn Data into Doing. Available online: https:\/\/www.splunk.com\/."},{"key":"ref_46","unstructured":"Scikit Learn (2022, April 07). Sklearn.Model_Selection.Train_Test_Split. Available online: https:\/\/scikit-learn.org\/stable\/modules\/generated\/sklearn.model_selection.train_test_split.html."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3459665","article-title":"k-Nearest neighbour classifiers\u2014A Tutorial","volume":"54","author":"Cunningham","year":"2022","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_48","first-page":"74","article-title":"Study and analysis of decision tree based classification algorithms","volume":"6","author":"Patel","year":"2018","journal-title":"Int. J. Comput. Sci. Eng."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3178582","article-title":"A survey of random forest based methods for intrusion detection systems","volume":"51","author":"Resende","year":"2019","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_50","unstructured":"Rao, A. (2022, April 07). Top 10 Python Libraries. Available online: https:\/\/www.edureka.co\/blog\/python-libraries\/."},{"key":"ref_51","unstructured":"Cass, S. (2022, April 07). The 2018 Top Programming Languages. Available online: https:\/\/spectrum.ieee.org\/the-2018-top-programming-languages."},{"key":"ref_52","unstructured":"Anaconda (2022, April 07). Data Science Technology for a Better World. Available online: https:\/\/www.anaconda.com\/."},{"key":"ref_53","unstructured":"TensorFlow (2022, April 07). TensorFlow 2 Quick Start for Beginners. Available online: https:\/\/www.tensorflow.org\/."},{"key":"ref_54","unstructured":"Fchollet, F. (2022, April 07). Introduction to Keras for Researchers. Available online: https:\/\/keras.io\/getting_started\/intro_to_keras_for_researchers\/."},{"key":"ref_55","unstructured":"Raschka, S. (2014). An overview of general performance metrics of binary classifier systems. arXiv, preprint."},{"key":"ref_56","unstructured":"MITRE Corporation (2022, April 07). ATT&CK Matrix for Enterprise. Available online: https:\/\/attack.mitre.org\/."},{"key":"ref_57","unstructured":"Lockheed Martin Corporation (2022, April 07). Seven Ways to Apply the Cyber Kill Chain with a Threat Intelligence Platform. Available online: https:\/\/www.lockheedmartin.com\/content\/dam\/lockheedmartin\/rms\/documents\/cyber\/Seven_Ways_to_Apply_the_Cyber_Kill_Chain_with_a_Threat_Intelligence_Platform.pdf."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/10\/3895\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:15:43Z","timestamp":1760138143000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/10\/3895"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,20]]},"references-count":57,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2022,5]]}},"alternative-id":["s22103895"],"URL":"https:\/\/doi.org\/10.3390\/s22103895","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,5,20]]}}}