Detecting DDoS Attacks in IoT Healthcare
DOI:
https://doi.org/10.34190/eccws.25.1.4779Keywords:
DDoS detection, IoT healthcare, MQTT, Long short-term memory (LSTM), Intrusion detectionAbstract
The increased adoption of IoT devices in healthcare domains has significantly increased the attack surface, leaving critical infrastructure vulnerable to attacks such as Distributed Denial of Service (DDoS). Our work investigates the role of feature selection and temporal dependency modelling in detecting MQTT (Message Queuing Telemetry Transport) DDoS attacks using the CICIoMT 2024 dataset. We compare two approaches; using the Naïve Bayes model which assumes flow independence and Long Short-Term Memory (LSTM) model, which captures sequential dependencies in the raw network flows. Feature selection was also performed to reduce 84 raw features to 31 informative features. Our preliminary results show that the LSTM model outperformed naïve bayes by leveraging the temporal patterns that are characteristic of DDoS traffic. This study evaluates the importance of guided feature selection and temporal dependency modelling in DDoS detection in IoT healthcare networks.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.