Claim Missing Document
Check
Articles

Found 1 Documents
Search

An Empirical Benchmarking Framework for IoT Traffic Anomaly Detection Using Elastic Stack SIEM Ferdiansyah Ferdiansyah; Reynaldi Rizki Billanivo; M Ardiansyah; Tegar Putra; M. Habibullah Amin
Intechno Journal : Information Technology Journal Vol. 8 No. 1 (2026): July
Publisher : Universitas Amikom Yogyakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24076/intechnojournal.2026v8i1.2808

Abstract

Purpose: This study aims to construct a realistic IoT-MQTT benchmark dataset and evaluate supervised machine learning classifiers for detecting network traffic anomalies, specifically Distributed Denial of Service (DDoS) and spoofing attacks, within a live Security Information and Event Management (SIEM) environment. Methods: An empirical benchmarking framework based on a live Elastic (ELK) Stack SIEM environment was developed, and supervised machine learning classifiers were evaluated for IoT network traffic anomaly detection. Result: KNN and SVM achieved the highest accuracy (0.99), whereas Naive Bayes achieved 0.96. Further analysis revealed that the superior performance of KNN and SVM was largely influenced by data leakage caused by the _attacker_ip feature, while Naive Bayes demonstrated better generalization without relying on identity-based features. Conclusion: The findings highlight the importance of rigorous feature engineering and data leakage analysis when developing machine learning models for IoT traffic anomaly detection, particularly in live SIEM environments. Moreover, the proposed framework contributes to the achievement of Sustainable Development Goals (SDGs) 9 by supporting resilient digital infrastructure and secure IoT-based innovation.