Machine Learning-Enhanced DDoS Attack Detection: A Random Forest Approach Using High-Fidelity Simulated Network Traffic Logs

Máximo Nájera Medina, Antonio Miguel Martínez Martínez, Huber Girón Nieto · 2025

Distributed Denial-of-Service (DDoS) attacks constitute a principal threat to networked services by saturating targets with illegitimate HTTP requests. This paper presents an adaptive detection framework based on high-fidelity synthetic traffic generated over seven continuous days at ≤ 10μs timestamp precision. Baseline traffic follows a Poisson process (λn≈ 50reqs−1) and is augmented by four attack events—including volumetric bursts peaking at 2×104reqs−1—yielding ≈ 3.57×107request logs (≈ 4.8GB) on a single 8-core x86 workstation (32 GB RAM, NVMe SSD). A hyper-parameter-tuned Random Forest classifier achieves AUROC = 0.994 (95% CI ±0.003), true-positive rate ≥ 0.941, false-positive rate ≤ 0.004, precision ≈ 0.970, and recall ≈ 0.941; statistical significance is confirmed with McNemar’s test and Wilson confidence intervals. The study delivers a rigorously specified synthetic baseline and lays the groundwork for future validation on live traffic.

Read the paper · More papers on PaperTik