Distributed denial of service attack detection using Naive Bayes Classifier through Info Gain Feature Selection
Ningombam Anandshree Singh, Khundrakpam Johnson Singh, Tanmay De · 2016
Distributed Denial of Service (DDoS) attack brings revenue loss, productivity loss, reputation damage, theft, etc. to huge banking and business firms. This leads to the necessity of a good DDoS prevention and detection techniques. The paper aims to provide a better solution to these problems using features analysis. The statistical characteristics or parameters of the incoming packets viz. MTI (mean time intervals), POIP (probability of occurrence of IP), TTL (time to live), ACK value, SYN value, time stamp field, differentiated service field and sequence number are analyzed. The incoming packets are classified into normal and attack packets by deploying Naïve Bayes classifier algorithm using the attack and normal profile from previously available datasets. Information gain algorithm is used to decrease the computation time, memory usage and increase efficiency of detection by reducing the number of parameters. The performance increases with more consistency after the application of information gain. The efficiencies of detection before and after the application of information gain are 98% and 99.5% respectively. The computation time is also reduced by 46.6%. In the paper, we use CAIDA 2008 and CAIDA anonymous trace 2015 datasets for feature selection and classification.