🤖 AI Summary
To address the challenge of detecting and fine-grained classifying multi-type DDoS flooding attacks (SYN, ACK, HTTP, UDP), this paper proposes an end-to-end neural network approach. We design a unified fully connected neural network with architecture 24–106–5, enabling joint detection and classification of all four attack types within a single model for the first time. The method integrates temporal statistical features of network traffic with protocol-specific feature engineering. A near-realistic virtualized testbed is constructed using Mininet and VMware to ensure evaluation validity and reproducibility. Experimental results demonstrate strong performance: online real-time detection achieves 95.05% accuracy with balanced F-score; offline evaluation yields 99.35% accuracy and 99.54% recall, with 100% identification rates for all four attack classes. The proposed method significantly enhances generalizability and practical applicability in dynamic network environments.
📝 Abstract
This study focuses on a method for detecting and classifying distributed denial of service (DDoS) attacks, such as SYN Flooding, ACK Flooding, HTTP Flooding, and UDP Flooding, using neural networks. Machine learning, particularly neural networks, is highly effective in detecting malicious traffic. A dataset containing normal traffic and various DDoS attacks was used to train a neural network model with a 24-106-5 architecture. The model achieved high Accuracy (99.35%), Precision (99.32%), Recall (99.54%), and F-score (0.99) in the classification task. All major attack types were correctly identified. The model was also further tested in the lab using virtual infrastructures to generate normal and DDoS traffic. The results showed that the model can accurately classify attacks under near-real-world conditions, demonstrating 95.05% accuracy and balanced F-score scores for all attack types. This confirms that neural networks are an effective tool for detecting DDoS attacks in modern information security systems.