An Enhanced Model of DDoS Attacks Detection Using One-Hot Encoding of Feature's Categories

Sawsan Alodibat, Mouhammd Sharari Alkasassbeh · 2025

Recently, network security has expanded and has become more important than ever because of the rise in data transmission. Researchers have used Machine Learning (ML) techniques to find and recognize network risks to improve Intrusion Detection Systems (IDS). However, a key drawback of these techniques is that, because they dismiss the particular sub-attacks that make up a larger attack family, they generate a large false positive rate. Therefore, this study introduces a novel technique to handle these problems by considering sub-attacks related to Distributed Denial of Service (DDoS). First, we apply a data preprocessing approach that uses one-hot encoding of feature categories. Using this technique, the model can successfully capture the patterns in categorical data by converting categorical variables into numerical features. This enables the model to generate accurate classifications based on the categorical variables. We applied three classification models: Random Forest (RF), K-Nearest Neighbor (KNN), and Support Vector Machine (SVM). Moreover, we performed extensive experiments on the CSE-CICIDS2018 dataset, which provides a comprehensive collection of real network traffic data, to verify the efficacy of the proposed methods. For evaluation, we found the Precision, Recall, Accuracy, and F-measure. The results show that the proposed approach outperforms the others in terms of f-measure and false positive rate, with 99.7% and 5.2%, respectively.

Read the paper · More papers on PaperTik