Machine Learning Approach For Classification of DHCP DoS Attacks in NIDS
Shameel Syed, Faheem Yar Khuhawar, Shahnawaz Talpur · 2021
Network Intrusion Detection System (NIDS) is used to detect anomalous activities that occur in the network, whether the activity arises from outside or from inside. An extensive amount of studies have been done in the domain of NIDS using Machine Learning, Deep Learning, and Reinforcement Learning based techniques on publicly available datasets. The main problem lies in publicly available datasets as the datasets are un-realistic and too general for real-life events and attacks and thus the models trained may produce better results during the training and testing phase but once it is deployed in the real network, most of the attacks may go undetected. This research focuses on a specific protocol “Dynamic Host Control Protocol” which is enabled in most of networks whether the network is small, medium or large. In this research, DHCP specific dataset was generated and trained with different classifiers to analyze their performance. Random Forest classifier presented better results among other classifiers.