Network Flow Analytics: Multi-Class Classification of DDoS Attacks Based on OKNN
Irénée Mungwarakarama, Xinhong Hei, Yichuan Wang, Wenjiang Ji, Xinyu Jiang · 2020
in the past decade DDoS attacks detection solutions have been one hot area in the research of cyberspace. Different techniques including machine learning and recent complex deep learning models were used and improved. However, only a few have used real network data and multiclass classification. In this paper, we challenged an Optimized K-Nearest Neighbor (OKNN) on a recent public dataset of the real network containing labeled classes of normal network flow and DDoS attacks. While performing minimum preprocessing to keep data original, OKNN with a tune of hyper-parameters such as; n_neighbors, metric, weights, n_jobs, has identified a normal traffic flow and DDoS attacks with high accuracy. The results of the experiment show that our model would perform better than its counterparts if only they are trained in the same conditions.