Efficient DDoS Detection with Minimal Features: High Accuracy Using CIC-DDoS2019

MD Ahad Hasan, Amir Eaman, Esteve Hassan · Procedia Computer Science · 2025

Distributed Denial of Service (DDoS) attacks remain a critical threat to network security, stability, and service availability necessitating robust detection mechanisms. This research demonstrates that just five carefully selected features from the CIC-DDoS2019 dataset can achieve classification accuracy exceeding 98%, comparable to complex models using the full feature set. Our analysis identifies TCP fags (particularly ACK and URG), packet rate metrics, and specific TCP window characteristics as the most discriminative features for DDoS attack type classification. Both XGBoost and MLP models trained on this minimal feature set showed less than 1% performance degradation compared to full-feature models. Our findings highlight the potential for efficient, lightweight DDoS detection systems suitable for resource-constrained environments e.g. IoT devices and 5G networks.

Read the paper · More papers on PaperTik