Supervised learning to detect DDoS attacks

Eray Balkanli, Jander Alves, Nur Zincir-Heywood · 2014

In this research, we explore the performances of two supervised learning techniques and two open-source network intrusion detection systems (NIDS) on backscatter darknet traffic. We employ Bro and Corsaro open-source systems as well as the CART Decision Tree and Naive Bayes machine learning classifiers. While designing our machine learning classifiers, we used different sizes of training/test sets and different feature sets to understand the importance of data pre-processing. Our results show that a machine learning base approach can achieve very high performance on such backscatter darknet traffic without using IP addresses and port numbers.

Read the paper · More papers on PaperTik