A Machine Learning Approach for Detecting Distributed Denial of Service Attacks
Tanaphon Roempluk, Olarik Surinta · 2019
This research aims to present the method for identifying distributed denial of service (DDoS) attacks. Two benchmark dataset, including KDD CUP 1999 and NSL-KDD, were used. The dataset were checked and deleted duplicate data. After the process, the amount of records of KDD Cup 1999 dataset were decreased from 4,898,431 records to 529,655 records, and the amount of records of NSL-KDD dataset were decreased from 125,373 to only 12,354 records. The reduction of the records always happened because of the characteristics of DDoS attacks which send repeated data to the victims' server. The researchers converted alphabet data to numeric data, then training by K-nearest neighbor (KNN), multi-layer perceptron and support vector machine. The result showed that KNN was the best method to identify the DDoS attacks.