Distributed Denial of Service Attack Detection by Machine Learning Techniques

Varkha Jewani, Prafulla E. Ajmire, Mohd. Atique, Bhisham Sharma, Imed Ben Dhaou, Suhashini Awadhesh Chaurasia · 2025

The exponential expansion of computer networks and the internet makes it clear that there is a chance of being attacked and harmed. In the meantime, one of the most crucial defensive measures against the more complex and frequent network attacks is the intrusion detection and prevention systems (IDSs and IPSs). Due to insufficient datasets, anomaly-based research in intrusion detection systems is plagued by imprecise deployment, analysis, and evaluation. The researchers analyzed a variety of datasets, including DARPA98, KDD99, ISC2012, and ADFA13, to assess how well their suggested intrusion detection and intrusion prevention techniques performed. There are several issues: lack of adequate attack coverage, unrepresentative payloads, and anonymised packet information, insufficient traffic volume and diversity, or a deficiency in feature set and metadata. This study is focused on CICIDS-2017 which is the recently updated IDS dataset that meets real-world requirements and is accessible publicly. In addition to benign network flows and distributed denial of service (DDoS) attacks, it contains seven common attack network flows as well. To provide the optimal combination of features for the identification of the attack category, it also assesses the efficacy of several machine learning (ML) algorithms and network traffic feature sets. Even though various ML techniques like Linear Regression, Random Forests, and Decision Tree can be used, and performed very well, Hybrid Algorithm is designed to get better analysis on dataset.

Read the paper · More papers on PaperTik