Exploration of Various Machine Learning Techniques for Identifying and Mitigating DDoS Attacks

Olufunsho I. Falowo, Izunna Okpala, Emmanuel Kojo Gyamfi, Sylvia Worlali Azumah, Chengcheng Li · 2023

This study is conducted as a result of some of the key observations documented in a recent study published by IEEE, titled "Threat Actors’ Tenacity to Disrupt: Examination of Major Cybersecurity incidents" where some of the key findings therein that study describes how DDoS attack together with other attack techniques were used by threat actors to disrupt public and private enterprises on multiple occasions. In this study, there is a focus on DDoS attacks and exploration of how various machine learning techniques may be leveraged to identify and mitigate them. Real world examples of major DDoS attacks that happened and reported or announced to the public were examined and it was found that in the last seven years, there has been an increase in the use of DDoS attacks to cause major disruptions to organizations. In a total of over 700 major cybersecurity incidents that we analyzed from 2015 to 2022, evidence of DDoS attacks were found every year. Hence, in that subset of dataset we examined, there was an increase from 8 to 31 major DDoS attacks from 2021 to 2022 which is an estimate of 288 percent increase. Due to the volume of network traffic analysis involved in the detection of DDoS events which more often may be very difficult for humans to manually or efficiently analyze, the validation of the importance of utilizing AI technologies such machine learning algorithms as effective capabilities for the detection of DDoS attacks and DDoS mitigation are assessed in this study. Identification of specific machine learning algorithms that may be used for the detection and mitigation of DDoS attacks were looked into. Given that there is no one-size-fits-all solution to the mitigation of DDoS attacks, this study echoes the leveraging of the CIS Benchmarks and also encourages organizations to adopt referencing one of the NIST frameworks that was released to the public on January 26, 2023 titled "AI Risk Management Framework" as guidelines in ensuring multiple layers of controls in handling DDoS attacks.

Read the paper · More papers on PaperTik