The problem of detecting anomalies in network traffic caused by the distributed denial of service (DDoS) attack so far has mainly been investigated in terms of detection of illegitimate DDoS traffic generated by conventional terminal devices (PCs, laptops, mobile devices, tablets, servers). Technological development has resulted in the emergence of the Internet of Things (IoT) concept, whose implementation implies numerous terminal devices with a low level of implemented protection. The large growth and prediction of future growth is noticeable in the environment of a smart home and smart office. IoT devices in such environments are increasingly being used as a platform for generating DDoS traffic due to its numeracy and low level of protection. The aim of this research is to propose a novel approach for detection of DDoS traffic generated by IoT devices in a form of conceptual network anomaly detection model. Proposed conceptual model is based on device classes which are dependent on individual device traffic characteristics.