Detection and classification of DDoS flooding attacks by machine learning method

📅 2024-12-25
🏛️ BAIT
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
To address the challenge of detecting and fine-grained classifying multi-type DDoS flooding attacks (SYN, ACK, HTTP, UDP), this paper proposes an end-to-end neural network approach. We design a unified fully connected neural network with architecture 24–106–5, enabling joint detection and classification of all four attack types within a single model for the first time. The method integrates temporal statistical features of network traffic with protocol-specific feature engineering. A near-realistic virtualized testbed is constructed using Mininet and VMware to ensure evaluation validity and reproducibility. Experimental results demonstrate strong performance: online real-time detection achieves 95.05% accuracy with balanced F-score; offline evaluation yields 99.35% accuracy and 99.54% recall, with 100% identification rates for all four attack classes. The proposed method significantly enhances generalizability and practical applicability in dynamic network environments.

Technology Category

Machine Learning: Multi-class/Multi-label Learning & Extreme ClassificationComputer Vision: Multi-modal VisionApplication Domains: Internet of Things, Sensor Networks & Smart Cities

Application Category

Graph Algorithms and Modeling for the Web: Graph neural networks and deep learning approaches for Web-related graphsSystems and Infrastructure for Web, Mobile and WoT: Web performance, measurement, and characterizationWeb Mining and Content Analysis: Normalization, clustering, classification, and summarization of Web text
📝 Abstract
This study focuses on a method for detecting and classifying distributed denial of service (DDoS) attacks, such as SYN Flooding, ACK Flooding, HTTP Flooding, and UDP Flooding, using neural networks. Machine learning, particularly neural networks, is highly effective in detecting malicious traffic. A dataset containing normal traffic and various DDoS attacks was used to train a neural network model with a 24-106-5 architecture. The model achieved high Accuracy (99.35%), Precision (99.32%), Recall (99.54%), and F-score (0.99) in the classification task. All major attack types were correctly identified. The model was also further tested in the lab using virtual infrastructures to generate normal and DDoS traffic. The results showed that the model can accurately classify attacks under near-real-world conditions, demonstrating 95.05% accuracy and balanced F-score scores for all attack types. This confirms that neural networks are an effective tool for detecting DDoS attacks in modern information security systems.
Problem

Research questions and friction points this paper is trying to address.

DDoS Detection
Smart Learning Methods
Network Attack Classification
Innovation

Methods, ideas, or system contributions that make the work stand out.

Neural Network Model
DDoS Attack Detection
High Accuracy
🔎 Similar Papers
No similar papers found.
Ternopil Ivan Puluj National Technical University
Dmytro Tymoshchuk
Dmytro Tymoshchuk
Ternopil Ivan Puluj National Technical University, Тернопільський національний технічний університет
CybersecurityVirtualizationMachine LearningNetwork SecurityOperating Systems
O
Oleh Yasniy
Ternopil Ivan Puluj National Technical University, Ruska str. 56, Ternopil, 46001, Ukraine
M
Mykola Mytnyk
Ternopil Ivan Puluj National Technical University, Ruska str. 56, Ternopil, 46001, Ukraine
N
Nataliya Zagorodna
Ternopil Ivan Puluj National Technical University, Ruska str. 56, Ternopil, 46001, Ukraine
Vitaliy Tymoshchuk
Vitaliy Tymoshchuk
Ternopil Ivan Puluj National Technical University