Feature-Driven Supervised Learning for Detecting DDoS Attack
Md Boktiar Hossain, Rashedur Rahman, Khandoker Hoque · International Journal of Science and Research Archive · 2021
Distributed Denial-of-Service (DDoS) attacks are intentional efforts to disrupt the normal traffic of a targeted server, network, or organization by overwhelming the victim or its neighboring systems with excessive network traffic. Detecting such attacks using machine-learning models is challenging due to significant variations in traffic patterns and rates. So, an automated detection approach is proposed, which reduces the feature space to minimize model overfitting and computational cost. The CICDDoS2019 dataset, including a wide range of DDoS attack scenarios, is used to train and evaluate the proposed method in a cloud-based environment. Relevant features are extracted using the Extra Trees classifier and then passed to Decision Tree, XGBoost, and Random Forest classifiers. XGBoost achieved the highest validation accuracy of 98.87% with feature selection, while Decision Tree maintained a strong baseline accuracy of 98.49% even without feature selection.