{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T20:57:44Z","timestamp":1773521864979,"version":"3.50.1"},"reference-count":37,"publisher":"MDPI AG","issue":"8","license":[{"start":{"date-parts":[[2021,7,28]],"date-time":"2021-07-28T00:00:00Z","timestamp":1627430400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>In the last decade, the devices and appliances utilizing the Internet of Things (IoT) have expanded tremendously, which has led to revolutionary developments in the network industry. Smart homes and cities, wearable devices, traffic monitoring, health systems, and energy savings are typical IoT applications. The diversity in IoT standards, protocols, and computational resources makes them vulnerable to security attackers. Botnets are challenging security threats in IoT devices that cause severe Distributed Denial of Service (DDoS) attacks. Intrusion detection systems (IDS) are necessary for safeguarding Internet-connected frameworks and enhancing insufficient traditional security countermeasures, including authentication and encryption techniques. This paper proposes a wrapper feature selection model (SSA\u2013ALO) by hybridizing the salp swarm algorithm (SSA) and ant lion optimization (ALO). The new model can be integrated with IDS components to handle the high-dimensional space problem and detect IoT attacks with superior efficiency. The experiments were performed using the N-BaIoT benchmark dataset, which was downloaded from the UCI repository. This dataset consists of nine datasets that represent real IoT traffic. The experimental results reveal the outperformance of SSA\u2013ALO compared to existing related approaches using the following evaluation measures: TPR (true positive rate), FPR (false positive rate), G-mean, processing time, and convergence curves. Therefore, the proposed SSA\u2013ALO model can serve IoT applications by detecting intrusions with high true positive rates that reach 99.9% and with a minimal delay even in imbalanced intrusion families.<\/jats:p>","DOI":"10.3390\/sym13081377","type":"journal-article","created":{"date-parts":[[2021,7,28]],"date-time":"2021-07-28T21:21:04Z","timestamp":1627507264000},"page":"1377","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":42,"title":["IoT Botnet Detection Using Salp Swarm and Ant Lion Hybrid Optimization Model"],"prefix":"10.3390","volume":"13","author":[{"given":"Ruba","family":"Abu Khurma","sequence":"first","affiliation":[{"name":"King Abdullah II School of Information Technology, The University of Jordan, Amman 11942, Jordan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4639-516X","authenticated-orcid":false,"given":"Iman","family":"Almomani","sequence":"additional","affiliation":[{"name":"King Abdullah II School of Information Technology, The University of Jordan, Amman 11942, Jordan"},{"name":"Security Engineering Lab, Computer Science Department, Prince Sultan University, Riyadh 11586, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9265-9819","authenticated-orcid":false,"given":"Ibrahim","family":"Aljarah","sequence":"additional","affiliation":[{"name":"King Abdullah II School of Information Technology, The University of Jordan, Amman 11942, Jordan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,7,28]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Alieyan, K., Almomani, A., Abdullah, R., Almutairi, B., and Alauthman, M. (2021). Botnet and Internet of Things (IoTs): A Definition, Taxonomy, Challenges, and Future Directions. Research Anthology on Combating Denial-of-Service Attacks, IGI Global.","DOI":"10.4018\/978-1-7998-5348-0.ch007"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"2759","DOI":"10.1007\/s11192-020-03819-5","article-title":"IoT-based botnet attacks systematic mapping study of literature","volume":"126","author":"Hamid","year":"2021","journal-title":"Scientometrics"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Dange, S., and Chatterjee, M. (2020). IoT Botnet: The Largest Threat to the IoT Network. Data Communication and Networks, Springer.","DOI":"10.1007\/978-981-15-0132-6_10"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"8155","DOI":"10.1109\/JIOT.2019.2925825","article-title":"Blockchain technology for applications in internet of things\u2014Mapping from system design perspective","volume":"6","author":"Viriyasitavat","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"567","DOI":"10.1007\/s10207-019-00475-6","article-title":"A novel graph-based approach for IoT botnet detection","volume":"19","author":"Nguyen","year":"2020","journal-title":"Int. J. Inf. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Qaddoura, R., Al-Zoubi, A., Almomani, I., and Faris, H. (2021). A Multi-Stage Classification Approach for IoT Intrusion Detection Based on Clustering with Oversampling. Appl. Sci., 11.","DOI":"10.3390\/app11073022"},{"key":"ref_7","first-page":"110","article-title":"Toward a deep learning-based intrusion detection system for IoT against botnet attacks","volume":"10","author":"Idrissi","year":"2021","journal-title":"IAES Int. J. Artif. Intell."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Qaddoura, R., Al-Zoubi, A.M., Faris, H., and Almomani, I. (2021). A Multi-Layer Classification Approach for Intrusion Detection in IoT Networks Based on Deep Learning. Sensors, 21.","DOI":"10.3390\/s21092987"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Aljarah, I., Mafarja, M., Heidari, A.A., Faris, H., and Mirjalili, S. (2020). Multi-Verse Optimizer: Theory, Literature Review, and Application in Data Clustering, Nature-Inspired Optimizers.","DOI":"10.1007\/978-3-030-12127-3_8"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1650033","DOI":"10.1142\/S0218213016500330","article-title":"Optimizing the learning process of feedforward neural networks using lightning search algorithm","volume":"25","author":"Faris","year":"2016","journal-title":"Int. J. Artif. Intell. Tools"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Mafarja, M., Heidari, A.A., Faris, H., Mirjalili, S., and Aljarah, I. (2020). Dragonfly Algorithm: Theory, Literature Review, and Application in Feature Selection, Nature-Inspired Optimizers.","DOI":"10.1007\/978-3-030-12127-3_4"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2809","DOI":"10.1007\/s12652-019-01387-y","article-title":"Unsupervised intelligent system based on one class support vector machine and Grey Wolf optimization for IoT botnet detection","volume":"11","author":"Faris","year":"2020","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Khurma, R.A., Aljarah, I., Sharieh, A., and Mirjalili, S. (2020). Evolopy-fs: An open-source nature-inspired optimization framework in python for feature selection. Evolutionary Machine Learning Techniques, Springer.","DOI":"10.1007\/978-981-32-9990-0_8"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Pamukov, M.E., Poulkov, V.K., and Shterev, V.A. (2018, January 4\u20136). Negative selection and neural network based algorithm for intrusion detection in iot. Proceedings of the 2018 41st International Conference on Telecommunications and Signal Processing (TSP), Athens, Greece.","DOI":"10.1109\/TSP.2018.8441338"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"5156","DOI":"10.1007\/s11227-018-2413-7","article-title":"NBC-MAIDS: Na\u00efve Bayesian classification technique in multi-agent system-enriched IDS for securing IoT against DDoS attacks","volume":"74","author":"Mehmood","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/MSP.2018.2825478","article-title":"IoT security techniques based on machine learning: How do IoT devices use AI to enhance security?","volume":"35","author":"Xiao","year":"2018","journal-title":"IEEE Signal Process. Mag."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Shaikh, F., Bou-Harb, E., Crichigno, J., and Ghani, N. (2018, January 25\u201329). A machine learning model for classifying unsolicited iot devices by observing network telescopes. Proceedings of the 2018 14th International Wireless Communications & Mobile Computing Conference (IWCMC), Limassol, Cyprus.","DOI":"10.1109\/IWCMC.2018.8450404"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s13638-018-1128-z","article-title":"An intrusion detection method for internet of things based on suppressed fuzzy clustering","volume":"2018","author":"Liu","year":"2018","journal-title":"EURASIP J. Wirel. Commun. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1016\/j.asoc.2018.05.049","article-title":"Semi-supervised learning based distributed attack detection framework for IoT","volume":"72","author":"Rathore","year":"2018","journal-title":"Appl. Soft Comput."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"4815","DOI":"10.1109\/JIOT.2018.2871719","article-title":"An ensemble intrusion detection technique based on proposed statistical flow features for protecting network traffic of internet of things","volume":"6","author":"Moustafa","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"390","DOI":"10.1016\/j.eswa.2017.09.013","article-title":"Network anomaly detection system using genetic algorithm and fuzzy logic","volume":"92","author":"Hamamoto","year":"2018","journal-title":"Expert Syst. Appl."},{"key":"ref_22","first-page":"179109","article-title":"Using genetic algorithm to minimize false alarms in insider threats detection of information misuse in windows environment","volume":"2014","author":"Akram","year":"2014","journal-title":"Math. Probl. Eng."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1016\/j.icte.2018.01.014","article-title":"Intrusion detection for cloud computing using neural networks and artificial bee colony optimization algorithm","volume":"5","author":"Hajimirzaei","year":"2019","journal-title":"ICT Express"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"20255","DOI":"10.1109\/ACCESS.2018.2820092","article-title":"A new intrusion detection system based on fast learning network and particle swarm optimization","volume":"6","author":"Ali","year":"2018","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1016\/j.cose.2018.11.005","article-title":"Firefly algorithm based feature selection for network intrusion detection","volume":"81","author":"Selvakumar","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Panigrahi, A., and Patra, M.R. (2018). A Layered Approach to Network Intrusion Detection Using Rule Learning Classifiers with Nature-Inspired Feature Selection. Progress in Computing, Analytics and Networking, Springer.","DOI":"10.1007\/978-981-10-7871-2_21"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"2661","DOI":"10.1016\/j.adhoc.2013.04.014","article-title":"SVELTE: Real-time intrusion detection in the Internet of Things","volume":"11","author":"Raza","year":"2013","journal-title":"Ad Hoc Netw."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"2093","DOI":"10.1109\/JIOT.2018.2883344","article-title":"Ai-based two-stage intrusion detection for software defined iot networks","volume":"6","author":"Li","year":"2018","journal-title":"IEEE Internet Things J."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2492956","DOI":"10.1155\/2018\/2492956","article-title":"An evolutionary computation based feature selection method for intrusion detection","volume":"2018","author":"Xue","year":"2018","journal-title":"Secur. Commun. Netw."},{"key":"ref_30","first-page":"660","article-title":"Efficient Feature Selection Technique for Network Intrusion Detection System Using Discrete Differential Evolution and Decision","volume":"19","author":"Popoola","year":"2017","journal-title":"IJ Netw. Secur."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"914","DOI":"10.2991\/ijcis.2017.10.1.61","article-title":"GAB-BBO: Adaptive Biogeography Based Feature Selection Approach for Intrusion Detection","volume":"10","author":"Guendouzi","year":"2017","journal-title":"Int. J. Comput. Intell. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Gharaee, H., and Hosseinvand, H. (2016, January 27\u201328). A new feature selection IDS based on genetic algorithm and SVM. Proceedings of the 2016 8th International Symposium on Telecommunications (IST), Tehran, Iran.","DOI":"10.1109\/ISTEL.2016.7881798"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1016\/j.advengsoft.2017.07.002","article-title":"Salp Swarm Algorithm: A bio-inspired optimizer for engineering design problems","volume":"114","author":"Mirjalili","year":"2017","journal-title":"Adv. Eng. Softw."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1016\/j.advengsoft.2015.01.010","article-title":"The ant lion optimizer","volume":"83","author":"Mirjalili","year":"2015","journal-title":"Adv. Eng. Softw."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","article-title":"N-baiot\u2014Network-based detection of iot botnet attacks using deep autoencoders","volume":"17","author":"Meidan","year":"2018","journal-title":"IEEE Pervasive Comput."},{"key":"ref_36","unstructured":"Asuncion, A., and Newman, D. (2007). UCI Machine Learning Repository, University of California."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"406","DOI":"10.1016\/j.patcog.2017.09.037","article-title":"A comparative evaluation of outlier detection algorithms: Experiments and analyses","volume":"74","author":"Domingues","year":"2018","journal-title":"Pattern Recognit."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/8\/1377\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:36:17Z","timestamp":1760164577000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/8\/1377"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,28]]},"references-count":37,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2021,8]]}},"alternative-id":["sym13081377"],"URL":"https:\/\/doi.org\/10.3390\/sym13081377","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,28]]}}}