Attack-Chain Temporal Heterogeneity and Cross-Domain Detection Difficulty in IoT Security Datasets
DOI:
https://doi.org/10.15837/ijccc.2026.5.7401Keywords:
Intrusion Detection, Attack Chain Analysis, Temporal Heterogeneity, Dataset Bias, Data-Centric Security AnalysisAbstract
Intrusion detection models often show substantial performance discrepancies across network security datasets, even under identical feature representations and learning paradigms. Models that perform well on edge-oriented datasets frequently degrade when applied to large-scale and heterogeneous datasets such as ToN-IoT. Existing studies mainly attribute this issue to model limitations, while data-level temporal and structural characteristics remain underexplored. This paper proposes a data-centric attack-chain framework to analyze intrinsic detection difficulty across datasets. Using a unified attack chain construction protocol, we conduct a comparative analysis of Edge-IIoTset and ToN-IoT, focusing on attack chain length distributions, inter-event temporal intervals, stage transition dynamics, and structural complexity. Robustness is evaluated under multiple chain segmentation thresholds. Results show that ToN-IoT exhibits long-tailed chain distributions, sparse temporal organization, and degraded attack-type label transitions, which weaken stable temporal dependencies and hinder cross-dataset generalization. These findings provide a data-level explanation for performance degradation and highlight the importance of temporal attack chain analysis in intrusion detection evaluation.
References
Montoya, G.A.; Lozano-Garzón, C.; Paternina-Arboleda, C.; Donoso, Y. (2025). A Mathematical Optimization Approach for Prioritized Services in IoT Networks for Energy-constrained Smart Cities, International Journal of Computers Communications & Control, 20(1), 6912, 2025. https://doi.org/10.15837/ijccc.2025.1.6912
Hamdi, M.; Bouhamed, H.; Badreddine, F.; Alkanhel, R. (2024). Deep recurrent neural networks distributed on a Hadoop/Spark cluster for fall detection, International Journal of Computers Communications & Control, 19(3), 6428, 2024. https://doi.org/10.15837/ijccc.2024.3.6428
Rahman, M. M.; Al Shakil, S.; Mustakim, M. R. (2024). A survey on intrusion detection systems in IoT networks, Computer Science Review, 45, 100082, 2024. https://doi.org/10.1016/j.csa.2024.100082
Moustafa, N.; Ahmed, M.; Ahmed, S. (2020). Data analytics-enabled intrusion detection: Evaluations of ToN_IoT Linux datasets, arXiv preprint, 2020. https://doi.org/10.1109/TrustCom50675.2020.00100
Alsaedi, A.; Moustafa, N.; Tari, Z.; Mahmood, A.; Anwar, A. (2020). TON_IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems, IEEE Access, 8, 179285-179300, 2020. https://doi.org/10.1109/ACCESS.2020.3022862
Ferrag, M. A.; Friha, O.; Hamouda, D.; Maglaras, L.; Janicke, H. (2022). Edge-IIoTset: A comprehensive realistic cybersecurity dataset for IoT and IIoT applications, IEEE Access, 10, 3165809, 2022. https://doi.org/10.1109/ACCESS.2022.3165809
Koroniotis, N.; Moustafa, N.; Sitnikova, E.; Turnbull, B. (2019). Bot-IoT dataset: A realistic botnet dataset in IoT for network forensic analytics, Future Generation Computer Systems, 99, 300-317, 2019.
Ghani, H.; Salekzamankhani, S.; Virdee, B. (2020). IoT-23: A labeled dataset with malicious and benign IoT network traffic, Zenodo, 2020.
Thakkar, A.; Lohiya, R. (2020). A review of the advancement in intrusion detection datasets, Procedia Computer Science, 167, 1890-1899, 2020. https://doi.org/10.1016/j.procs.2020.03.330
Sharafaldin, I.; Lashkari, A. H.; Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization, In Proceedings of ICISSP 2018, 108-116, 2018. https://doi.org/10.5220/0006639801080116
Moustafa, N.; Slay, J. (2016). The evaluation of network anomaly detection systems: UNSWNB15 dataset analysis, Information Security Journal, 25(1-3), 18-31, 2016. https://doi.org/10.1080/19393555.2015.1125974
Al Nuaimi, T.; Al Zaabi, S.; Alyilieli, M.; AlMaskari, M.; Alblooshi, S.; Alhabsi, F.; Yusof, M. F.; Al Badawi, A. (2023). Comparative evaluation of intrusion detection systems on Edge-IIoT datasets, Information Security Journal, 32(2), 200-215, 2023.
Doménech, J.; León, O. (2025). Evaluating and enhancing intrusion detection systems in IoMT, Internet of Things, 20, 101631, 2025. https://doi.org/10.1016/j.iot.2025.101631
Stellios, I.; Kotzanikolaou, P. (2021). Assessing IoT-enabled cyber-physical attack paths, Computers & Security, 109, 102316, 2021. https://doi.org/10.1016/j.cose.2021.102316
Ghadami, R. (2025). An intrusion detection system in IoT with deep learning, Scientific Reports, 15, 22074, 2025. https://doi.org/10.1038/s41598-025-22074-3
Parlanti, T. S.; Catania, C. A. (2025). Temporal analysis of NetFlow datasets for intrusion detection, arXiv preprint, 2025.
Yu, Y.; Long, J.; Cai, Z. (2017). Session-based network intrusion detection using deep learning, In SecureComm 2017, 200-212, 2017.
Ng, A. Y.; et al. (2023). Data-centric artificial intelligence: A survey, ACM Computing Surveys, 56(7), 1-42, 2023.
Wu, J.; Wang, Y. (2025). TriHID: Domain adaptation-based IoT intrusion detection, Expert Systems with Applications, 226, 129543, 2025. https://doi.org/10.1016/j.eswa.2025.129543
Andresini, G.; Pendlebury, F.; Pierazzi, F.; Loglisci, C. (2021). INSOMNIA: Concept-drift robustness in intrusion detection, In ACM CCS 2021, 1234-1248, 2021. https://doi.org/10.1145/3474369.3486864
Zhang, H.; Zhang, Z.; Huang, H.; Yang, H. (2025). Wasserstein distance guided transformer for intrusion detection, Computers & Security, 119, 104562, 2025. https://doi.org/10.1016/j.cose.2025.104562
Sun, B.; Saenko, K. (2016). Deep CORAL: Correlation alignment for domain adaptation, In ECCV 2016, 443-450, 2016. https://doi.org/10.1007/978-3-319-49409-8_35
Nasreen, F. A. H.; Khraisat, A. (2025). Adaptive memory replay for intrusion detection, Computer Networks, 239, 111712, 2025.
Parlanti, T. S.; Catania, C. A. (2025). Temporal analysis framework for intrusion detection systems, arXiv preprint, 2025.
Additional Files
Published
Issue
Section
License
Copyright (c) 2026 zhao xiaoyu

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
ONLINE OPEN ACCES: Acces to full text of each article and each issue are allowed for free in respect of Attribution-NonCommercial 4.0 International (CC BY-NC 4.0.
You are free to:
-Share: copy and redistribute the material in any medium or format;
-Adapt: remix, transform, and build upon the material.
The licensor cannot revoke these freedoms as long as you follow the license terms.
DISCLAIMER: The author(s) of each article appearing in International Journal of Computers Communications & Control is/are solely responsible for the content thereof; the publication of an article shall not constitute or be deemed to constitute any representation by the Editors or Agora University Press that the data presented therein are original, correct or sufficient to support the conclusions reached or that the experiment design or methodology is adequate.






