Enhancing DDoS Attack Detection: A Hybrid SVM-Decision Tree Ensemble Approach

Debendra Muduli, Sandesh Bhatta, Shantanu Shookdeb, Aayush Adhikari, Amir Sapkota, Prabhat Chaturvedi · 2024

A DDoS attack overwhelms a network or server with an excessive amount of traffic, disrupting its normal operation and rendering it inaccessible to legitimate users. DDoS attacks involve coordinated efforts from multiple compromised devices, known as botnets, flooding the target with traffic simultaneously. This flood of data exhausts the target’s resources, causing service disruptions. Machine learning aids in DDoS attack detection by analyzing network traffic patterns. It learns to differentiate between normal and malicious activity by studying features such as packet rates, traffic volume, and protocol anomalies. By training on labeled datasets containing both benign and attack traffic, machine learning algorithms can identify deviations indicative of DDoS attacks, thereby enhancing network security. The hybrid machine learning model combines the precision of Support Vector Machines with the decision-making clarity of Decision Trees to effectively combat DDoS attacks. This innovative model achieves an impressive accuracy rate of $\mathbf{9 9. 9 8 \%}$ against the CICDDoS2019 dataset, demonstrating its exceptional performance in detecting various DDoS attack vectors.

Read the paper · More papers on PaperTik