IMPLEMENTASI GRAPHSAGE UNTUK DETEKSI INTRUSI JARINGAN INTERNET OF THINGS (IOT) | ELECTRONIC THESES AND DISSERTATION

Electronic Theses and Dissertation

Universitas Syiah Kuala

    SKRIPSI

IMPLEMENTASI GRAPHSAGE UNTUK DETEKSI INTRUSI JARINGAN INTERNET OF THINGS (IOT)


Pengarang
Dosen Pembimbing

Sayed Muchallil - 198006162005011002 - Dosen Pembimbing I
Yudha Nurdin - 197910012010121002 - Dosen Pembimbing II



Nomor Pokok Mahasiswa

1904111010060

Fakultas & Prodi

Fakultas Teknik / Teknik Komputer (S1) / PDDIKTI : 56202

Subject
-
Kata Kunci
-
Penerbit

Banda Aceh : Fakultas Teknik., 2026

Bahasa

No Classification

-

Literature Searching Service

Hard copy atau foto copy dari buku ini dapat diberikan dengan syarat ketentuan berlaku, jika berminat, silahkan hubungi via telegram (Chat Services LSS)

Perkembangan Internet of Things (IoT) meningkatkan jumlah perangkat yang terhubung ke jaringan, namun turut meningkatkan risiko serangan siber seperti Distributed Denial of Service (DDoS) dan botnet. Sebagian besar metode deteksi intrusi berbasis machine learning konvensional memperlakukan setiap data lalu lintas jaringan (flow) secara independen, sehingga kurang mampu memanfaatkan hubungan atau kemiripan antar flow dalam jaringan. Penelitian ini bertujuan mengimplementasikan dan mengevaluasi GraphSAGE, salah satu metode Graph Neural Network (GNN), untuk mendeteksi intrusi pada jaringan IoT menggunakan dataset CICIoT2023, dengan fokus pada tiga kategori, yaitu aktivitas normal, DDoS, dan botnet (Mirai). Data tabular yang telah melalui tahap seleksi kelas, sampling, dan preprocessing (239.999 flow, 39 fitur numerik) ditransformasikan menjadi graf melalui pendekatan K-Nearest Neighbor (KNN) berdasarkan kemiripan fitur antar flow. Model GraphSAGE dua lapis kemudian dilatih dan diuji pada beberapa skema validasi, yaitu transductive, semi-inductive, dan inductive penuh, serta dibandingkan dengan model non-graf (Random Forest dan Multilayer Perceptron). Hasil pengujian menunjukkan model baseline (K=10, dua lapis) mencapai accuracy dan F1-score sebesar 99,85% pada skema transductive, dengan performa yang tetap tinggi pada berbagai variasi nilai K dan jumlah layer. Perbandingan dengan model non-graf menunjukkan bahwa GraphSAGE belum memberikan keunggulan yang meyakinkan ketika seluruh data pelatihan berlabel lengkap, karena Random Forest dan MLP justru mencapai accuracy yang setara atau sedikit lebih tinggi. Namun, pada kondisi label pelatihan terbatas (10%), manfaat representasi graf terlihat bersifat kondisional: konfigurasi dengan konektivitas graf yang cukup (K=10, K=20, atau tiga layer) tahan terhadap keterbatasan label, sedangkan konfigurasi dengan konektivitas rendah (K=5) justru mengalami penurunan performa paling besar di antara seluruh model yang diuji. Penelitian ini menyimpulkan bahwa representasi graf melalui GraphSAGE mampu melakukan klasifikasi dan generalisasi dengan baik, tetapi keunggulannya atas metode non-graf konvensional bergantung pada ketersediaan label dan konektivitas graf, bukan bersifat mutlak, sehingga menjadi pertimbangan penting bagi penerapan pendekatan berbasis graf pada deteksi intrusi jaringan IoT di masa mendatang.
Kata Kunci: Internet of Things, Intrusion Detection System, Graph Neural Network, GraphSAGE, CICIoT2023, DDoS, Botnet.

The rapid growth of the Internet of Things (IoT) has increased the number of devices connected to computer networks, while also raising the risk of cyberattacks such as Distributed Denial of Service (DDoS) and botnet activity. Most conventional machine learning based intrusion detection methods treat each network flow independently, limiting their ability to exploit relationships or similarities among flows within a network. This study aims to implement and evaluate GraphSAGE, a Graph Neural Network (GNN) approach, for intrusion detection in IoT networks using the CICIoT2023 dataset, focusing on three categories: normal activity, DDoS, and botnet (Mirai). Tabular data that had undergone class selection, sampling, and preprocessing (239,999 flows, 39 numerical features) was transformed into a graph representation using K-Nearest Neighbor (KNN) based on feature similarity between flows. A two layer GraphSAGE model was then trained and evaluated under transductive, semi-inductive, and fully inductive validation schemes, and compared against non-graph baseline models (Random Forest and Multilayer Perceptron). The baseline model (K=10, two layers) achieved an accuracy and F1-score of 99.85% under the transductive scheme, with consistently high performance across variations in K and the number of layers. Comparison with non-graph models showed that GraphSAGE did not provide a convincing advantage when the full training data was labeled, as Random Forest and MLP achieved equal or slightly higher accuracy. However, under a limited labeling condition (10 percent labeled training data), the benefit of the graph representation proved conditional: configurations with sufficient graph connectivity (K=10, K=20, or three layers) remained robust to label scarcity, whereas the configuration with the lowest connectivity (K=5) experienced the largest performance drop among all models tested. This study concludes that graph representation through GraphSAGE is capable of accurate classification and generalization, but its advantage over conventional non-graph methods depends on label availability and graph connectivity rather than being absolute, an important consideration for future applications of graph based approaches to IoT intrusion detection. Keywords: Internet of Things, Intrusion Detection System, Graph Neural Network, GraphSAGE, CICIoT2023, DDoS, Botnet.

Citation



    SERVICES DESK