DoS Attack Detection Using Machine Learning
Mohammad Kosasih, Stanley Figo Gunawan, Surya Immanuel, Franz Adeta, Ayu Maulina · 2024
This research explores the detection of Denial of Service (DoS) attacks using a machine learning approach. DoS attacks aim to make internet services unavailable, which negatively impacts individuals and organizations. Intrusion Detection System (IDS) has long been used as a method of preventing DoS attacks. In previous studies, real-time implementation of ML IDS has not been conducted. Therefore, in this research, the Decision Tree algorithm is combined with the ensemble bagging method, and the data is processed using the NearMiss undersampling technique. The CICIDS2017 dataset is used as the DoS attack database. The test results show that the machine learning-based IDS achieves an accuracy of 97.5% and a recall of 99.5%, which shows higher performance compared to the traditional IDS, which achieves an accuracy of 17.5% and a recall of 19.5%. Furthermore, the research concludes that the Bagging Decision Tree with the NearMiss balancing method is the most effective approach, achieving an accuracy of 0.99 and a recall of 0.89. While Snort is more precise in identifying attacks, it may fail to detect them entirely. On the other hand, the machine learning-based IDS proves to be more sensitive to attacks, leading to better detection, though it carries a higher risk of false positives. The results demonstrate that the machine learning-based IDS significantly outperforms traditional methods in terms of accuracy and recall, making it a more reliable tool for detecting DoS attacks and reducing the risk of undetected threats.