Deteksi Malware IoT Menggunakan K-Nearest Neighbor pada Dataset IoT-23

Authors

  • Muhammad Arif Perdiansyah
  • Adi Wibowo Universitas Muhammadiyah Kotabumi

DOI:

https://doi.org/10.32524/jusitik.v9i2.1975

Keywords:

intrusion detection; iot security; KNN; malware detection; network flow

Abstract

 The development of the Internet of Things (IoT) has increased the number of interconnected devices across various
sectors; however, it also introduces security challenges due to limited resources and weak protection mechanisms.
These conditions make IoT devices vulnerable to cyberattacks such as malware, botnets, and Distributed Denial
of Service (DDoS). Therefore, an effective and efficient intrusion detection system is required. This study aims to
analyze the characteristics of malware traffic and evaluate the performance of the K-Nearest Neighbor (KNN)
algorithm in detecting malicious traffic using the IoT-23 dataset based on network flow. The method employed is
supervised machine learning with preprocessing stages including data cleaning, label transformation, feature
encoding, and normalization using MinMaxScaler. The dataset is classified into two classes, namely benign and
malicious. The experimental results show that KNN is able to achieve an accuracy of up to 97%, with optimal
performance at K = 5, which provides the best balance between precision, recall, and F1-score. The ROC-AUC
value of 0.97 indicates that the model has a very good capability in distinguishing between normal and malicious
traffic. These results indicate that KNN based on network flow is effective and has the potential to be implemented
in intrusion detection systems in IoT environments.

Published

2026-07-16 — Updated on 2026-07-16

Versions