Optimized Feature Reduction and SIEM Log Analysis for IoT Attack Classification
作者:Ravi Kiran Varma Penmatsa, Kaligithi Geethika, Gedela Sneha, G. Sirisha, A. Akshara · 发表于:International Conference Intelligent Data Communication Technologies and Internet Things · 年份:2026 · DOI:10.1109/ICICI68773.2026.11580522
Security Information and Event Management (SIEM) systems are integrated alerting and log analysis systems designed for threat detection. However, due to the large number of parameters, along with the exponential growth of Internet of Things (IoT) and Industrial IoT (IIoT) traffic, frequent zero-day security incidents, and imbalanced streams of activities, SIEM systems face performance limitations. To improve the threat detection capability and include IoT and IIoT along with day-to-day network traffic, a benchmark dataset, TON_IoT, is converted into SIEM style, and feature reduction methods are applied. Converting TON_IoT data into a SIEM-compatible format makes it easier to integrate with real-world security monitoring systems. It also helps standardize features across different data sources and makes machine learning-based intrusion detection models more practical for deployment. Mutual Information and Particle Swarm Optimization (PSO), forming a two-stage feature reduction approach, are used. Further, to evaluate efficiency, various machine learning (ML) models, including CatBoost, XGBoost, Random Forest and LightGBM, are employed for multi-class classification. Thus, a SIEM-style intrusion detection model for IoT and IIoT frameworks, which is feature-reduced and operationally efficient, is developed and tested. A 65% reduction in features and a 32% reduction in model training time are achieved, with a post-reduction macro F1-score of 97%.