A Novel FBD Detection Metric

Shaveta Gupta, Nimit Sachdeva, Jimmy Singla · Advances in information security, privacy, and ethics book series · 2025

Web and network services have been increasingly targeted by Distributed Denial of Service (DDoS) attacks, which pose a significant threat. To minimize collateral damage and computational requirements, it is crucial to identify DDoS attacks. A new metric called Forward-Backward distance (FBD) is proposed to achieve this objective. FBD can accurately distinguish attacks and normal traffic using just one data point without requiring a minimum data point collection requirement. To achieve FBD, the Random Forest machine learning algorithm is first applied to the training data to detect DDoS attacks. Then, SHAP values are calculated for each data point to understand how the model made predictions. The best feature, which explains the model outcome with the best predictive power, is used to design a metric which can be used as a standalone to identify DDoS attacks. This new metric (FBD) shows a much higher precision (97%), while the recall is lower (39%). This means that it detects ~40% of the DDoS attacks, but out of the detected ones, 97% are the attacks.

Read the paper · More papers on PaperTik