An Explanatory Machine Learning Method for the Identification of DDoS Attacks in SDN Architectures

Himmat Rathore, Renu Ratnawat · 2024

Online services are the backbone of the digital world. A distributed denial of service (DDoS) attack is a persistent risk to the accessibility of internet facilities. Detecting DDoS attacks as they occur is only one of the problems; tracking down attack streams is another major obstacle to mitigation. However, DDoS attacks are difficult, if not impossible, to detect using current attack detection systems. In this paper, an innovative methodology is proposed to classify the traffic flow as DDoS attacks in software-defined networking. The proposed system is comprised of three steps. The initial stage involves pre-AI modeling explanations, where the data is presented visually to extract valuable insights. In addition, the data undergoes pre-processing to detect and eliminate any null values. One hot encoding approach is utilized to transform String features into numerical ones. The next step involves using machine learning modeling techniques, where a range of ML algorithms are applied to the pre-processed data. Out of all the ML models available, the decision tree and random forest models stand out as the top performers with an accuracy of 100%. The last step involves explaining the predictions made by the ML models. In order to clarify the predictions, Explainable Artificial Intelligence is utilized. Implementing the proposed approach in real-time will enhance the ability to precisely distinguish DDoS attacks and provide clear explanations for the predictions made.

Read the paper · More papers on PaperTik