Classification of Distributed Denial of Service Attacks Using Traditional Machine Learning Models

Paulo Victor, Álvaro Sobrinho, Leandro Dias da Silva, Iris Viana, Danilo F. S. Santos, Lenardo Chaves e Silva, Ângelo Perkusich · 2025

Distributed Denial of Service (DDoS) attacks can cause substantial financial losses for businesses and industries due to service downtime, often amounting to thousands of dollars per minute. This study implemented and evaluated traditional Machine Learning (ML) models for classifying DDoS attacks. The algorithms evaluated include K-nearest neighbors, decision trees, support vector machines, random forests, extreme gradient boosting, gradient boosting machines, and multilayer perception. We used more than 5,000,000 attack samples from the CICDDoS2019 dataset, covering 11 attack classes and 79 features. We validated the models using both hold-out and 10-fold cross-validation, feature selection, and conducted class ablation analysis to assess the impact of specific attack classes on performance.

Read the paper · More papers on PaperTik