Home > Published Issues > 2026 > Volume 17, No. 7, 2026 >
JAIT 2026 Vol.17(7): 1383-1396
doi: 10.12720/jait.17.7.1383-1396

Data-Driven Detection of Multi-vector IoT DDoS Attacks across Network Layers

Rania A. Al-Ali 1, Mohammad Alnabhan 1, and Qasem Abu Al-Haija 2,*
1. Department of Cybersecurity, Princess Sumaya University for Technology, Amman, Jordan
2. Department of Cybersecurity, Jordan University of Science and Technology, Irbid, Jordan
Email: ran20238134@std.psut.edu.jo (R.A.A.-A); m.alnabhan@psut.edu.jo (M.A.); qsabuhaija@just.edu.jo (Q.A.A.-H)
*Corresponding author

Manuscript received January 23, 2026; revised March 18, 2026; accepted April 21, 2026; published July 28, 2026.

Abstract—As cyberattacks targeting Internet of Things (IoT) networks grow more sophisticated, the demand for models capable of accurately detecting and mitigating these threats becomes increasingly urgent existing detection systems often concentrate on a single attack surface which leads to critical blind spots in IoT network monitoring. This research introduces an intensive IoT attack-detection framework that addresses internal and external attack sources, leveraging multi-layer attack vectors across the application, transport, network, and data link layers. The proposed framework was evaluated in two phases. In the first phase, three datasets that simulate a distinct attack source were created: outbound, including Dynamic Host Configuration Protocol (DHCP) amplification and DHCP starvation; inbound attacks, including application-layer attacks, Synchronize (SYN) flood, User Datagram Protocol (UDP) flood, Internet Control Message Protocol (ICMP) Smurf, and ICMP direct; and internal Address Resolution Protocol (ARP) spoofing. Three machine learning models; Random Forest, Light Gradient-Boosting Machine (LightGBM), and Categorical Boosting (CatBoost) were evaluated using accuracy, precision, recall, F1-Score, and Receiver Operating Characteristic (ROC) curve. In the second phase, a new dataset was generated by combining all datasets from the first phase. On the combined dataset, LightGBM achieved the highest performance, with accuracy: 94.08%, precision: 93.94%, recall: 94.08%, and F1-Score: 93.90%. Random Forest and CatBoost showed comparable performance, with all metrics ranging from approximately 93.2% to 93.9%. LightGBM demonstrates a slight edge in overall detection performance compared to other models, which highlights its effectiveness in detecting diverse and complex attack patterns across multiple traffic directions.
 
Keywords—Internet of Things (IoT) security, Distributed Denial of Service (DDoS) attack detection, inbound traffic attacks, outbound traffic attacks, internal traffic attacks, machine learning, network layer attacks, Light Gradient-Boosting Machine (LightGBM)

Cite: Rania A. Al-Ali, Mohammad Alnabhan, and Qasem Abu Al-Haija, "Data-Driven Detection of Multi-vector IoT DDoS Attacks across Network Layers," Journal of Advances in Information Technology, Vol. 17, No. 7, pp. 1383-1396, 2026. doi: 10.12720/jait.17.7.1383-1396

Copyright © 2026 by the authors. This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited (CC BY 4.0).

Article Metrics in Dimensions