Detection Syn Flood and UDP Lag Attacks Based on Machine Learning Using AdaBoost
Nova Hanafi Syafiuddin, Satria Mandala, Niken Dwi Wahyu Cahyani · 2023
Syn flood is a commonly used Distributed Denial-of-Service (DDoS) attack that aims to overwhelm a server by sending a large number of Transmission Control Protocol (TCP) SYN requests without completing the handshake process and rejecting user packets. On the other hand, UDP flood attacks target the network infrastructure rather than the server, making it difficult to identify the source of the attack. In recent years, research related using machine learning to detect Distributed Denial-of-Service (DDoS) attacks with different methods. Steps taken to detect SYN Flood and UDP Lag attacks are system design, data collection, search, and data analysis. Test metrics such as precision, recall, accuracy, and F1-score are closely related to machine learning algorithms used for detecting Distributed Denial-of-Service (DDoS) attacks, including SYN Flood and UDP Lag attacks. Some literatures on SYN Flood attack detection have a low accuracy value with algorithm has been used. With the research conducted by author in detecting attacks by designing and building a system using machine learning algorithm which include ensemble Learning using AdaBoost and CICDDoS2019 dataset. For AdaBoost is an ensemble algorithm boosting type classifier that each individual model has its own way self to build sequentially by repeating the previous and CICDDoS2019 dataset was created by the Canadian Institute for Cybersecurity (CIC) at the University of New Brunswick.