Performance Comparison of Machine Learning Methods in DDoS Attack Detection in Smart Grids
Edwin Meriaux, David Koehler, Md. Zahidul Islam, Vinod M. Vokkarane, Yuzhang Lin · 2022
The integration of the cyber-network with the physical power grid makes it prone to cyber-attacks disrupting the normal operation of the grid and therefore critical to detect. This paper compares how the detection of Distributed Denial of Service (DDOS) attacks, one of the most common types of cyber-attack, on smart grids varies depending on the Machine Learning (ML) method used for detection, the different datasets used for the training, and the features of the dataset incorporated in the training. The most commonly used datasets namely KDDCup’99 and CICIDS’17 datasets are adapted for the sake of testing. The different ML methods used for these experiments are Decision Tree, Random Forest, Quadratic Discriminant Analysis, Support Vector Machine, Naïve Bayes, and Extreme Gradient Boosting. With extensive comparison analyses among the ML models based on accuracy, computation time, and storage usage, the paper demonstrates the applicability of the models in smart grids