{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T14:28:52Z","timestamp":1785421732669,"version":"3.56.0"},"reference-count":61,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2023,1,6]],"date-time":"2023-01-06T00:00:00Z","timestamp":1672963200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"a joint United Arab Emirates University and Zayed University (UAEU-ZU)","award":["12R141"],"award-info":[{"award-number":["12R141"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The Internet of Things (IoT) has shown rapid growth and wide adoption in recent years. However, IoT devices are not designed to address modern security challenges. The weak security of these devices has been exploited by malicious actors and has led to several serious cyber-attacks. In this context, anomaly detection approaches are considered very effective owing to their ability to detect existing and novel attacks while requiring data only from normal execution. Because of the limited resources of IoT devices, conventional security solutions are not feasible. This emphasizes the need to develop new approaches that are specifically tailored to IoT devices. In this study, we propose a host-based anomaly detection approach that uses system call data and a Markov chain to represent normal behavior. This approach addresses the challenges that existing approaches face in this area, mainly the segmentation of the syscall trace into suitable smaller units and the use of a fixed threshold to differentiate between normal and malicious syscall sequences. Our proposed approach provides a mechanism for segmenting syscall traces into the program\u2019s execution paths and dynamically determines the threshold for anomaly detection. The proposed approach was evaluated against various attacks using two well-known public datasets provided by the University of New South Mexico (UNM) and one custom dataset (PiData) developed in the laboratory. We also compared the performance and characteristics of our proposed approach with those of recently published related work. The proposed approach has a very low false positive rate (0.86%), high accuracy (100%), and a high F1 score (100%) that is, a combined performance measure of precision and recall.<\/jats:p>","DOI":"10.3390\/s23020652","type":"journal-article","created":{"date-parts":[[2023,1,6]],"date-time":"2023-01-06T03:31:28Z","timestamp":1672975888000},"page":"652","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Efficient Approach for Anomaly Detection in IoT Using System Calls"],"prefix":"10.3390","volume":"23","author":[{"given":"Nouman","family":"Shamim","sequence":"first","affiliation":[{"name":"Department of Computer Science, National University of Computer and Emerging Sciences, Islamabad 44000, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2894-7891","authenticated-orcid":false,"given":"Muhammad","family":"Asim","sequence":"additional","affiliation":[{"name":"Department of Computer Science, National University of Computer and Emerging Sciences, Islamabad 44000, Pakistan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5166-4873","authenticated-orcid":false,"given":"Thar","family":"Baker","sequence":"additional","affiliation":[{"name":"School of Architecture, Technology and Engineering, The University of Brighton, Brighton BN2 4GJ, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3800-0757","authenticated-orcid":false,"given":"Ali Ismail","family":"Awad","sequence":"additional","affiliation":[{"name":"College of Information Technology, United Arab Emirates University, Al Ain P.O. Box 17551, United Arab Emirates"},{"name":"Centre for Security, Communications and Network Research, University of Plymouth, Plymouth PL4 8AA, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,1,6]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"100610","DOI":"10.1016\/j.iot.2022.100610","article-title":"Intelligent authentication of 5G healthcare devices: A survey","volume":"20","author":"Sodhro","year":"2022","journal-title":"Internet Things"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"119869","DOI":"10.1016\/j.jclepro.2019.119869","article-title":"Industry 4.0, digitization, and opportunities for sustainability","volume":"252","author":"Ghobakhloo","year":"2020","journal-title":"J. Clean. Prod."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1016\/j.comcom.2019.12.030","article-title":"Intelligence in the Internet of Medical Things era: A systematic review of current and future trends","volume":"150","author":"Nawaz","year":"2020","journal-title":"Comput. Commun."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"102491","DOI":"10.1016\/j.cose.2021.102491","article-title":"Authentication and Identity Management of IoHT Devices: Achievements, Challenges, and Future Directions","volume":"111","author":"Mamdouh","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Arasteh, H., Hosseinnezhad, V., Loia, V., Tommasetti, A., Troisi, O., Shafie-khah, M., and Siano, P. (2016, January 7\u201310). Iot-based smart cities: A survey. Proceedings of the 2016 IEEE 16th International Conference on Environment and Electrical Engineering (EEEIC), Florence, Italy.","DOI":"10.1109\/EEEIC.2016.7555867"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Muthuramalingam, S., Bharathi, A., Gayathri, N., Sathiyaraj, R., and Balamurugan, B. (2019). IoT based intelligent transportation system (IoT-ITS) for global perspective: A case study. Internet of Things and Big Data Analytics for Smart Generation, Springer.","DOI":"10.1007\/978-3-030-04203-5_13"},{"key":"ref_7","first-page":"4","article-title":"Industrial Internet of Things monitoring solution for advanced predictive maintenance applications","volume":"7","author":"Civerchia","year":"2017","journal-title":"J. Ind. Inf. Integr."},{"key":"ref_8","unstructured":"Collela, P. (2022, May 23). Ushering in a Better Connected Future. Available online: https:\/\/www.ericsson.com\/en\/about-us\/company-facts\/ericsson-worldwide\/india\/authored-articles\/ushering-in-a-better-connected-future."},{"key":"ref_9","unstructured":"Hassan, M. (2022, May 23). State of IoT 2022: Number of Connected IoT Devices Growing 18% to 14.4 Billion Globally. Available online: https:\/\/iot-analytics.com\/number-connected-iot-devices\/."},{"key":"ref_10","unstructured":"Marr, B. (2022, May 23). The 5 Biggest Internet of Things (IoT) Trends in 2022. Available online: https:\/\/www.forbes.com\/sites\/bernardmarr\/2021\/12\/13\/the-5-biggest-internet-of-things-iot-trends-in-2022\/?sh=568730785aba."},{"key":"ref_11","unstructured":"Vailshery, L.S. (2022, June 02). Internet of Things (IoT)-Statistics and Facts. Available online: https:\/\/www.statista.com\/topics\/2637\/internet-of-things."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Awad, A.I., and Abawajy, J. (2021). Security and Privacy in the Internet of Things: Architectures, Techniques, and Applications, John Wiley & Sons. [1st ed.].","DOI":"10.1002\/9781119607755"},{"key":"ref_13","unstructured":"(2022, May 26). Las Vegas Casino Hacked via Fish Tank. Available online: https:\/\/www.casinous.com\/las-vegas-casino-hacked-via-fish-tank\/."},{"key":"ref_14","unstructured":"Chiu, A. (2022, May 26). Ring Camera Hacker Harasses Mississippi 8-Year-Old in Her Bedroom\u2014The Washington Post. Available online: https:\/\/www.washingtonpost.com\/nation\/2019\/12\/12\/she-installed-ring-camera-her-childrens-room-peace-mind-hacker-accessed-it-harassed-her-year-old-daughter\/."},{"key":"ref_15","unstructured":"Point, C. (2022, May 26). Faxploit: Breaking the Unthinkable. Available online: https:\/\/blog.checkpoint.com\/2018\/08\/12\/faxploit-hp-printer-fax-exploit\/."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"100467","DOI":"10.1016\/j.cosrev.2022.100467","article-title":"Landscape of IoT security","volume":"44","author":"Schiller","year":"2022","journal-title":"Comput. Sci. Rev."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MC.2017.201","article-title":"DDoS in the IoT: Mirai and other botnets","volume":"50","author":"Kolias","year":"2017","journal-title":"Computer"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"76","DOI":"10.1109\/MC.2017.62","article-title":"Botnets and internet of things security","volume":"50","author":"Bertino","year":"2017","journal-title":"Computer"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ali, B., and Awad, A.I. (2018). Cyber and Physical Security Vulnerability Assessment for IoT-Based Smart Homes. Sensors, 18.","DOI":"10.3390\/s18030817"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"7743","DOI":"10.1109\/TII.2021.3053595","article-title":"A Novel Image Steganography Method for Industrial Internet of Things Security","volume":"17","author":"Hassaballah","year":"2021","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"6481","DOI":"10.1109\/JIOT.2019.2958185","article-title":"Anomaly detection for IoT time-series data: A survey","volume":"7","author":"Cook","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"3448","DOI":"10.1016\/j.comnet.2007.02.001","article-title":"An overview of anomaly detection techniques: Existing solutions and latest technological trends","volume":"51","author":"Patcha","year":"2007","journal-title":"Comput. Netw."},{"key":"ref_23","first-page":"79","article-title":"A survey of anomaly detection approaches in internet of things","volume":"10","author":"Behniafar","year":"2018","journal-title":"ISeCure"},{"key":"ref_24","unstructured":"Keniston, J., Mavinakayanahalli, A., Panchamukhi, P., and Prasad, V. (2007, January 27\u201330). Ptrace, utrace, uprobes: Lightweight, dynamic tracing of user apps. Proceedings of the 2007 Linux Symposium, Ottawa, ON, Canada."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Hubballi, N., Biswas, S., and Nandi, S. (2011, January 4\u20138). Sequencegram: N-gram modeling of system calls for program based anomaly detection. Proceedings of the 2011 Third International Conference on Communication Systems and Networks (COMSNETS 2011), Bangalore, India.","DOI":"10.1109\/COMSNETS.2011.5716416"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Sivanathan, A., Sherratt, D., Gharakheili, H.H., Sivaraman, V., and Vishwanath, A. (2016, January 6\u20139). Low-cost flow-based security solutions for smart-home IoT devices. Proceedings of the 2016 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), Bangalore, India.","DOI":"10.1109\/ANTS.2016.7947781"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"7295","DOI":"10.1109\/JIOT.2020.2984030","article-title":"Detecting behavioral change of IoT devices using clustering-based network traffic modeling","volume":"7","author":"Sivanathan","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"6882","DOI":"10.1109\/JIOT.2020.2970501","article-title":"Passban IDS: An intelligent anomaly-based intrusion detection system for IoT edge devices","volume":"7","author":"Eskandari","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Maniriho, P., Niyigaba, E., Bizimana, Z., Twiringiyimana, V., Mahoro, L.J., and Ahmad, T. (2020, January 17\u201318). Anomaly-based intrusion detection approach for IoT networks using machine learning. Proceedings of the 2020 International Conference on Computer Engineering, Network, and Intelligent Multimedia (CENIM), Surabaya, Indonesia.","DOI":"10.1109\/CENIM51130.2020.9297958"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1016\/j.jpdc.2020.06.008","article-title":"Lightweight collaborative anomaly detection for the IoT using blockchain","volume":"145","author":"Mirsky","year":"2020","journal-title":"J. Parallel Distrib. Comput."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Nguyen, T.D., Marchal, S., Miettinen, M., Fereidooni, H., Asokan, N., and Sadeghi, A.R. (2019, January 7\u201310). D\u00cfoT: A federated self-learning anomaly detection system for IoT. Proceedings of the 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS), Dallas, TX, USA.","DOI":"10.1109\/ICDCS.2019.00080"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"927","DOI":"10.1109\/JIOT.2020.3010023","article-title":"IoT-praetor: Undesired behaviors detection for IoT devices","volume":"8","author":"Wang","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Lear, E., Droms, R., and Romascanu, D. (2019). RFC 8520: Manufacturer Usage Description Specification, Internet Engineering Task Force (IETF).","DOI":"10.17487\/RFC8520"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"98","DOI":"10.1080\/02763869.2015.986796","article-title":"If this then that: An introduction to automated task services","volume":"34","author":"Hoy","year":"2015","journal-title":"Med. Ref. Serv. Q."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Proctor, M. (2011, January 4\u20137). Drools: A rule engine for complex event processing. Proceedings of the International Symposium on Applications of Graph Transformations with Industrial Relevance, Budapest, Hungary.","DOI":"10.1007\/978-3-642-34176-2_2"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"118556","DOI":"10.1109\/ACCESS.2019.2917135","article-title":"BRIoT: Behavior rule specification-based misbehavior detection for IoT-embedded cyber-physical systems","volume":"7","author":"Sharma","year":"2019","journal-title":"IEEE Access"},{"key":"ref_37","unstructured":"Forrest, S., Hofmeyr, S.A., Somayaji, A., and Longstaff, T.A. (1996, January 6\u20138). A sense of self for Unix processes. Proceedings of the 1996 IEEE Symposium on Security and Privacy, Oakland, CA, USA."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"151","DOI":"10.3233\/JCS-980109","article-title":"Intrusion detection using sequences of system calls","volume":"6","author":"Hofmeyr","year":"1998","journal-title":"J. Comput. Secur."},{"key":"ref_39","unstructured":"Eskin, E., Lee, W., and Stolfo, S.J. (2001, January 12\u201314). Modeling system calls for intrusion detection with dynamic window sizes. Proceedings of the DARPA Information Survivability Conference and Exposition II. DISCEX\u201901, Anaheim, CA, USA."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Hoang, D.K., and Vu, D.L. (2020, January 14\u201315). IoT Malware Classification Based on System Calls. Proceedings of the 2020 RIVF International Conference on Computing and Communication Technologies (RIVF), Ho Chi Minh, Vietnam.","DOI":"10.1109\/RIVF48685.2020.9140763"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"6401316","DOI":"10.1155\/2022\/6401316","article-title":"Anomaly Detection of System Call Sequence Based on Dynamic Features and Relaxed-SVM","volume":"2022","author":"Liao","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Shobana, M., and Poonkuzhali, S. (2020, January 13\u201314). A novel approach to detect IoT malware by system calls using Deep learning techniques. Proceedings of the 2020 International Conference on Innovative Trends in Information Technology (ICITIIT), Kottayam, India.","DOI":"10.1109\/ICITIIT49094.2020.9071531"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"106348","DOI":"10.1016\/j.infsof.2020.106348","article-title":"A statistical pattern based feature extraction method on system call traces for anomaly detection","volume":"126","author":"Liu","year":"2020","journal-title":"Inf. Softw. Technol."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"112","DOI":"10.1016\/j.future.2021.06.030","article-title":"Syscall-BSEM: Behavioral semantics enhancement method of system call sequence for high accurate and robust host intrusion detection","volume":"125","author":"Zhang","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Breitenbacher, D., Homoliak, I., Aung, Y.L., Tippenhauer, N.O., and Elovici, Y. (2019, January 9\u201312). HADES-IoT: A practical host-based anomaly detection system for IoT devices. Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, Auckland, New Zealand.","DOI":"10.1145\/3321705.3329847"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Carter, J., Mancoridis, S., and Galinkin, E. (2022, January 25\u201329). Fast, lightweight IoT anomaly detection using feature pruning and PCA. Proceedings of the 37th ACM\/SIGAPP Symposium on Applied Computing, Virtual Event.","DOI":"10.1145\/3477314.3508377"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Sivanathan, A., Sherratt, D., Gharakheili, H.H., Radford, A., Wijenayake, C., Vishwanath, A., and Sivaraman, V. (2017, January 1\u20134). Characterizing and classifying IoT traffic in smart cities and campuses. Proceedings of the 2017 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Atlanta, GA, USA.","DOI":"10.1109\/INFCOMW.2017.8116438"},{"key":"ref_48","first-page":"469","article-title":"A Novel Approach to Detect IoT Malware by System Calls and Long Short-Term Memory Model","volume":"99","author":"Ngoc","year":"2021","journal-title":"J. Theor. Appl. Inf. Technol."},{"key":"ref_49","unstructured":"Grimmer, M., R\u00f6hling, M.M., Kricke, M., Franczyk, B., and Rahm, E. (2018, January 27\u201328). Intrusion detection on system call graphs. Proceedings of the 25th DFN-Konferenz, Sicherheit in vernetzten Systemen, Hamburg, Germany."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Khan, M.T., Serpanos, D., and Shrobe, H. (2016, January 12\u201314). A rigorous and efficient run-time security monitor for real-time critical embedded system applications. Proceedings of the 2016 IEEE 3rd World Forum on Internet of Things (WF-IoT), Reston, VA, USA.","DOI":"10.1109\/WF-IoT.2016.7845510"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"116","DOI":"10.1109\/TR.2004.823851","article-title":"Robustness of the Markov-chain model for cyber-attack detection","volume":"53","author":"Ye","year":"2004","journal-title":"IEEE Trans. Reliab."},{"key":"ref_52","unstructured":"Ye, N. (2000, January 6). A markov chain model of temporal behavior for anomaly detection. Proceedings of the 2000 IEEE Systems, Man, and Cybernetics Information Assurance and Security Workshop, West Point, NY, USA."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1109\/MSP.2011.941097","article-title":"What is a Savitzky-Golay filter? [lecture notes]","volume":"28","author":"Schafer","year":"2011","journal-title":"IEEE Signal Process. Mag."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Ozcan, G., and Alpkocak, A. (2008, January 9\u201311). Online Suffix Tree Construction for Streaming Sequences. Proceedings of the Computer Society of Iran Computer Conference, 2008, Kish Island, Iran.","DOI":"10.1007\/978-3-540-89985-3_9"},{"key":"ref_55","unstructured":"(2022, December 10). HIDS\/Datasets\/UNM. Available online: https:\/\/github.com\/anandsagarthumati9848\/HIDS\/tree\/main\/Datasets\/UNM."},{"key":"ref_56","unstructured":"Warrender, C., Forrest, S., and Pearlmutter, B. (1999, January 9\u201312). Detecting intrusions using system calls: Alternative data models. Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No. 99CB36344), Oakland, CA, USA."},{"key":"ref_57","unstructured":"Soni, D., and Makwana, A. (2017, January 6\u20138). A survey on MQTT: A protocol of internet of things (IoT). Proceedings of the International Conference on Telecommunication, Power Analysis and Computing Techniques (ICTPACT-2017), Chennai, India."},{"key":"ref_58","unstructured":"(2022, September 22). Eclipse Mosquitto. Available online: https:\/\/mosquitto.org\/."},{"key":"ref_59","unstructured":"Zhang, X., Wu, S.F., Fu, Z., and Wu, T.L. (2000, January 14\u201317). Malicious packet dropping: How it might impact the TCP performance and how we can detect it. Proceedings of the 2000 International Conference on Network Protocols, Osaka, Japan."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Jurgelionis, A., Laulajainen, J.P., Hirvonen, M., and Wang, A.I. (August, January 31). An empirical study of netem network emulation functionalities. Proceedings of the 2011 Proceedings of 20th International Conference on Computer Communications and Networks (ICCCN), Maui, HI, USA.","DOI":"10.1109\/ICCCN.2011.6005933"},{"key":"ref_61","unstructured":"Robitaille, T. (2022, December 09). GitHub\u2014Astrofrog\/Psrecord: Record the CPU and Memory Activity of a Process. Available online: https:\/\/github.com\/astrofrog\/psrecord."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/2\/652\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T18:01:09Z","timestamp":1760119269000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/2\/652"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,6]]},"references-count":61,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2023,1]]}},"alternative-id":["s23020652"],"URL":"https:\/\/doi.org\/10.3390\/s23020652","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,6]]}}}