Detecting DDoS Attacks Through Decision Tree Analysis: An EDA Approach with the CIC DDoS 2019 Dataset

Ahmad Turmudi Zy, Amali Amali, Anggi Muhammad Rifa’i, Antika Zahrotul Kamalia, Asep Arwan Sulaeman · 2024

Distributed Denial of Service (DDoS) attacks pose a significant threat to network security, often causing severe service disruptions. This study explores the CIC DDoS 2019 dataset through Exploratory Data Analysis (EDA) to identify patterns and features critical for DDoS attack detection. The focus is on enhancing detection mechanisms using the Decision Tree algorithm, known for its simplicity, interpretability, and ability to manage both numerical and categorical data. The algorithm's transparency allows for clear insight into the decision-making process, making it easier to understand and explain classifications. Moreover, Decision Trees are robust against outliers, ensuring reliable performance in diverse network conditions. Key features and trends identified through EDA help differentiate between normal and malicious traffic. The Decision Tree algorithm effectively classifies and predicts DDoS attacks, achieving a ROC-AUC score of 99.13% and an accuracy of 98.55%. These findings underscore the algorithm's potential for real-time DDoS detection and mitigation. This research highlights the value of Decision Trees in cybersecurity, offering insights that can lead to more effective and adaptive network security strategies.

Read the paper · More papers on PaperTik