Integrated RNN-SVM Model for Improved Detection of Imbalanced DNS Heavy Attacks
Ankita Kumari, Ishu Sharma · 2024
This study aims to make it simpler to detect uneven DNS heavy attack. Detecting DNS-heavy attack might be problematic when there is a lack of balanced datasets. Using both Recurrent Neural Network (RNN) and Support Vector Machine (SVM) designs together might help find things more accurately. The Recurrent Neural Network and a Support Vector Machine work well together in this model to handle the complexity that comes from unevenly distributed data. The model does a great job of recognizing the order of events in DNS query packets by utilizing the time-based understanding of Recurrent Neural Networks and its Long Short-Term Memory cells. These changes help us understand trends that are connected to bigger threats. To change how features are shown, SVM is also used. This is because it is good at navigating feature spaces with lots of factors. This makes the process of sorting better. The fact that the model may be applied to samples that are not evenly distributed while yet producing comparable learning results is an intriguing aspect of the approach. In general, it is underlined that the approach has the potential to make it far simpler to identify Attacks that are heavy on DNS. In the results analysis, found the numbers of Loss, Accuracy, Val_loss, and Val_accuracy at various epoch times. This helped us better understand how effective our method was at different stages of teaching. Analyzing these signs taught about how well the methods work at finding skewed DNS attacks.