Deteksi Malware IoT Menggunakan K-Nearest Neighbor pada Dataset IoT-23
DOI:
https://doi.org/10.32524/jusitik.v9i2.1975Keywords:
intrusion detection; iot security; KNN; malware detection; network flowAbstract
The development of the Internet of Things (IoT) has increased the number of interconnected devices across various
sectors; however, it also introduces security challenges due to limited resources and weak protection mechanisms.
These conditions make IoT devices vulnerable to cyberattacks such as malware, botnets, and Distributed Denial
of Service (DDoS). Therefore, an effective and efficient intrusion detection system is required. This study aims to
analyze the characteristics of malware traffic and evaluate the performance of the K-Nearest Neighbor (KNN)
algorithm in detecting malicious traffic using the IoT-23 dataset based on network flow. The method employed is
supervised machine learning with preprocessing stages including data cleaning, label transformation, feature
encoding, and normalization using MinMaxScaler. The dataset is classified into two classes, namely benign and
malicious. The experimental results show that KNN is able to achieve an accuracy of up to 97%, with optimal
performance at K = 5, which provides the best balance between precision, recall, and F1-score. The ROC-AUC
value of 0.97 indicates that the model has a very good capability in distinguishing between normal and malicious
traffic. These results indicate that KNN based on network flow is effective and has the potential to be implemented
in intrusion detection systems in IoT environments.
Downloads
Published
Versions
- 2026-07-16 (2)
- 2026-07-16 (1)
Issue
Section
License
Copyright (c) 2026 Muhammad Arif Perdiansyah, Adi Wibowo

This work is licensed under a Creative Commons Attribution 4.0 International License.




