Attack-Chain Temporal Heterogeneity and Cross-Domain Detection Difficulty in IoT Security Datasets

Authors

  • Xiaoyu Zhao Geely University of China, Chengdu, Sichuan, China
  • Lei Bu Zhejiang Dahua Technology Co., Ltd. Chengdu, Sichuan, China
  • Xing Yang Geely University of China, Chengdu, Sichuan, China
  • Shufang He Geely University of China, Chengdu, Sichuan, China

DOI:

https://doi.org/10.15837/ijccc.2026.5.7401

Keywords:

Intrusion Detection, Attack Chain Analysis, Temporal Heterogeneity, Dataset Bias, Data-Centric Security Analysis

Abstract

Intrusion detection models often show substantial performance discrepancies across network security datasets, even under identical feature representations and learning paradigms. Models that perform well on edge-oriented datasets frequently degrade when applied to large-scale and heterogeneous datasets such as ToN-IoT. Existing studies mainly attribute this issue to model limitations, while data-level temporal and structural characteristics remain underexplored. This paper proposes a data-centric attack-chain framework to analyze intrinsic detection difficulty across datasets. Using a unified attack chain construction protocol, we conduct a comparative analysis of Edge-IIoTset and ToN-IoT, focusing on attack chain length distributions, inter-event temporal intervals, stage transition dynamics, and structural complexity. Robustness is evaluated under multiple chain segmentation thresholds. Results show that ToN-IoT exhibits long-tailed chain distributions, sparse temporal organization, and degraded attack-type label transitions, which weaken stable temporal dependencies and hinder cross-dataset generalization. These findings provide a data-level explanation for performance degradation and highlight the importance of temporal attack chain analysis in intrusion detection evaluation.

References

Montoya, G.A.; Lozano-Garzón, C.; Paternina-Arboleda, C.; Donoso, Y. (2025). A Mathematical Optimization Approach for Prioritized Services in IoT Networks for Energy-constrained Smart Cities, International Journal of Computers Communications & Control, 20(1), 6912, 2025. https://doi.org/10.15837/ijccc.2025.1.6912

Hamdi, M.; Bouhamed, H.; Badreddine, F.; Alkanhel, R. (2024). Deep recurrent neural networks distributed on a Hadoop/Spark cluster for fall detection, International Journal of Computers Communications & Control, 19(3), 6428, 2024. https://doi.org/10.15837/ijccc.2024.3.6428

Rahman, M. M.; Al Shakil, S.; Mustakim, M. R. (2024). A survey on intrusion detection systems in IoT networks, Computer Science Review, 45, 100082, 2024. https://doi.org/10.1016/j.csa.2024.100082

Moustafa, N.; Ahmed, M.; Ahmed, S. (2020). Data analytics-enabled intrusion detection: Evaluations of ToN_IoT Linux datasets, arXiv preprint, 2020. https://doi.org/10.1109/TrustCom50675.2020.00100

Alsaedi, A.; Moustafa, N.; Tari, Z.; Mahmood, A.; Anwar, A. (2020). TON_IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems, IEEE Access, 8, 179285-179300, 2020. https://doi.org/10.1109/ACCESS.2020.3022862

Ferrag, M. A.; Friha, O.; Hamouda, D.; Maglaras, L.; Janicke, H. (2022). Edge-IIoTset: A comprehensive realistic cybersecurity dataset for IoT and IIoT applications, IEEE Access, 10, 3165809, 2022. https://doi.org/10.1109/ACCESS.2022.3165809

Koroniotis, N.; Moustafa, N.; Sitnikova, E.; Turnbull, B. (2019). Bot-IoT dataset: A realistic botnet dataset in IoT for network forensic analytics, Future Generation Computer Systems, 99, 300-317, 2019.

Ghani, H.; Salekzamankhani, S.; Virdee, B. (2020). IoT-23: A labeled dataset with malicious and benign IoT network traffic, Zenodo, 2020.

Thakkar, A.; Lohiya, R. (2020). A review of the advancement in intrusion detection datasets, Procedia Computer Science, 167, 1890-1899, 2020. https://doi.org/10.1016/j.procs.2020.03.330

Sharafaldin, I.; Lashkari, A. H.; Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization, In Proceedings of ICISSP 2018, 108-116, 2018. https://doi.org/10.5220/0006639801080116

Moustafa, N.; Slay, J. (2016). The evaluation of network anomaly detection systems: UNSWNB15 dataset analysis, Information Security Journal, 25(1-3), 18-31, 2016. https://doi.org/10.1080/19393555.2015.1125974

Al Nuaimi, T.; Al Zaabi, S.; Alyilieli, M.; AlMaskari, M.; Alblooshi, S.; Alhabsi, F.; Yusof, M. F.; Al Badawi, A. (2023). Comparative evaluation of intrusion detection systems on Edge-IIoT datasets, Information Security Journal, 32(2), 200-215, 2023.

Doménech, J.; León, O. (2025). Evaluating and enhancing intrusion detection systems in IoMT, Internet of Things, 20, 101631, 2025. https://doi.org/10.1016/j.iot.2025.101631

Stellios, I.; Kotzanikolaou, P. (2021). Assessing IoT-enabled cyber-physical attack paths, Computers & Security, 109, 102316, 2021. https://doi.org/10.1016/j.cose.2021.102316

Ghadami, R. (2025). An intrusion detection system in IoT with deep learning, Scientific Reports, 15, 22074, 2025. https://doi.org/10.1038/s41598-025-22074-3

Parlanti, T. S.; Catania, C. A. (2025). Temporal analysis of NetFlow datasets for intrusion detection, arXiv preprint, 2025.

Yu, Y.; Long, J.; Cai, Z. (2017). Session-based network intrusion detection using deep learning, In SecureComm 2017, 200-212, 2017.

Ng, A. Y.; et al. (2023). Data-centric artificial intelligence: A survey, ACM Computing Surveys, 56(7), 1-42, 2023.

Wu, J.; Wang, Y. (2025). TriHID: Domain adaptation-based IoT intrusion detection, Expert Systems with Applications, 226, 129543, 2025. https://doi.org/10.1016/j.eswa.2025.129543

Andresini, G.; Pendlebury, F.; Pierazzi, F.; Loglisci, C. (2021). INSOMNIA: Concept-drift robustness in intrusion detection, In ACM CCS 2021, 1234-1248, 2021. https://doi.org/10.1145/3474369.3486864

Zhang, H.; Zhang, Z.; Huang, H.; Yang, H. (2025). Wasserstein distance guided transformer for intrusion detection, Computers & Security, 119, 104562, 2025. https://doi.org/10.1016/j.cose.2025.104562

Sun, B.; Saenko, K. (2016). Deep CORAL: Correlation alignment for domain adaptation, In ECCV 2016, 443-450, 2016. https://doi.org/10.1007/978-3-319-49409-8_35

Nasreen, F. A. H.; Khraisat, A. (2025). Adaptive memory replay for intrusion detection, Computer Networks, 239, 111712, 2025.

Parlanti, T. S.; Catania, C. A. (2025). Temporal analysis framework for intrusion detection systems, arXiv preprint, 2025.

Additional Files

Published

2026-09-01

Most read articles by the same author(s)

Obs.: This plugin requires at least one statistics/report plugin to be enabled. If your statistics plugins provide more than one metric then please also select a main metric on the admin's site settings page and/or on the journal manager's settings pages.