A Software-Defined IoT Analytics Platform forMulti-Method Anomaly Detection Using Docker and theELKStack

Authors

  • Khalid S. Al-Tahat Arab Open University, Amman, Jordan Author
  • Hamzeh J. Aljawawdeh Zarqa University, Zarqa, Jordan Author
  • Mohammad Azmi Al-madi Al-Zaytoonah University of Jordan Author
  • Shorouq Ata Elmanaseer Al-Zaytoonah University of Jordan, Amman, Jordan Author
  • Abdallah AL Sabbagh Beirut Arab University, Tripoli, Lebanon Author

DOI:

https://doi.org/10.66823/bsbqjj38

Keywords:

Internet of Things, Anomaly Detection, ELK Stack, Software-Defined IoT, Fuzzy Logic, Machine Learning

Abstract

The rapid growth of Internet of Things (IoT) deployments has resulted in massive streams of heterogeneous sensor data, making dependable anomaly detection indispensable for supporting the security, operational efficiency, and reliability of a system. Nonetheless, several current approaches depend on one detection technique, limiting robustness when handling nosisy and partially dealing labeled IoT data. This paper produces a software-defined IoT analytics platform to incorporate several anomaly detection techniques through a containerized ELK (Elasticsearch Logstash-Kibana) architecture deployed based on the use of Docker. The platform consolidates the use of supervised machine learning, fuzzy logic inference, unsupervised isolation Forest approach, and rule-based detection to assess real-world sensor data and improve the robustness of anomaly detection performance. Experiments were carried out on a dataset that contains 9,606 IoT sensor records, where the most effective performance was achieved by the supervised learning model with 98.14% precision, 96.66% accuracy, an F1-score of 93.54%, and 89.35% recall. On the other hand, 87.70% accuracy was achieved by the fuzzy logic model with a 75.71% F1-score. Additionally, 426 high-confidence anomalies were determined by the cross-method intersection analysis by revealing the effectiveness of integrating heterogeneous detection approaches. The experimental results demonstrate that the produced platform strengthens the robustness of anomaly detection while preserving cost efficiency, scalability, and low deployment complexity and ensuring its appropriateness for industrial and research IoT monitoring applications.

Downloads

Published

2026-09-04

Data Availability Statement

The experiments used the publicly available Intel Lab dataset. Access details were reported in the source as Intel Berkeley Research Lab (2004).

How to Cite

A Software-Defined IoT Analytics Platform forMulti-Method Anomaly Detection Using Docker and theELKStack. (2026). Journal of Sustainable Smart Systems in Education & Environment, 1(02), 1-23. https://doi.org/10.66823/bsbqjj38

Similar Articles

You may also start an advanced similarity search for this article.