Detection of DDoS Attack: A Comparative Evaluation of Machine Learning Techniques

Afsana Mimi, Iffath Tanjim Moon, Md. Musfiqur Rahman Mridha, Md. Shakiul Jafor · 2024

Distributed denial-of-service (DDoS) attacks are a common and increasing threat to online services, targeting multiple layers of the OSI model. As communication technology advances, these attacks are getting more frequent and complicated, making detection and protection more challenging. Therefore, the need to study DDoS attack detection is growing. This paper evaluated multiple machine learning models for detecting DDoS attacks using binary classifications. We have used nine machine learning models for binary classification namely Support Vector Machine, Random Forest, Gaussian Naïve Bayes, Extra Trees, AdaBoost, XGBoost, Gradient Boosting, Logistic Regression, and Multilayer Perceptron. Besides, we have selected the KDDCup99 dataset for this research. The dimensions of data determine a detection system's usefulness, consequently, feature selection and preprocessing are used to reduce the dataset's dimensionality, which minimizes the mathematical complexity. The evaluation of models is based on the accuracy, recall, precision, f1-score, false alarm rate, false positive ratio, false negative ratio, and error rate of datasets. Finally, using these evaluation criteria, we have compared the performance of the machine learning models and achieved the best results in binary classification using the XGBoost model with the highest accuracy (99.98%), precision (99.97%), recall (99.96%), f1-score (99.97%), and lowest false alarm rate (0.01 %), error rate (0.02%), false positive ratio (0.03 %), and false negative ratio (0.03 %).

Read the paper · More papers on PaperTik