Distributed Denial of Service Attack Detection Model with Random Forest
Yaddarabullah Yaddarabullah, Muhammad Wahyudin, Dewi Lestari, Gatot Tri Pranoto, Opitasari, Faik Bajsair · 2025
One of the most prevalent cyber-attacks today is Distributed Denial of Service (DDoS). Today, many network administrators still rely on manual analysis to detect suspicious activity with the help of IDS (Intrusion Detection System) and IPS (Intrusion Prevention System). This method involves a detailed review of transaction logs and network activity. Although effective in some cases, manual analysis requires a long time and high accuracy, which is not practical for large and complex network environments. This research aims to develop an accurate DDoS attack detection model on computer networks using Machine Learning method with Random Forest algorithm. Through data analysis of the CICDDoS2019 dataset, especially the UDP (User Datagram Protocol) flooding attack type. Based on the evaluation results, the Random Forest-based DDoS attack detection model shows very high effectiveness, especially in identifying DrDoS_UDP attacks. With an accuracy of 99.99%, precision of 98.86%, and recall of 97.36%, this model is able to correctly distinguish between benign data and attack data. The cross-validation results also show the consistency of the model's performance, with an average accuracy of 99.96% and a very small variance. The model successfully detects attacks with good precision and balance, evidenced by the high F1-Score value of 98.10%, as well as superior performance in detecting DrDoS_UDP and BENIGN classes.