Detection and classification of DDoS flooding attacks by machine learning method

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Tymoshchuk, Dmytro, Yasniy, Oleh, Mytnyk, Mykola, Zagorodna, Nataliya, Tymoshchuk, Vitaliy
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866916546570354688
author Tymoshchuk, Dmytro
Yasniy, Oleh
Mytnyk, Mykola
Zagorodna, Nataliya
Tymoshchuk, Vitaliy
author_facet Tymoshchuk, Dmytro
Yasniy, Oleh
Mytnyk, Mykola
Zagorodna, Nataliya
Tymoshchuk, Vitaliy
contents This study focuses on a method for detecting and classifying distributed denial of service (DDoS) attacks, such as SYN Flooding, ACK Flooding, HTTP Flooding, and UDP Flooding, using neural networks. Machine learning, particularly neural networks, is highly effective in detecting malicious traffic. A dataset containing normal traffic and various DDoS attacks was used to train a neural network model with a 24-106-5 architecture. The model achieved high Accuracy (99.35%), Precision (99.32%), Recall (99.54%), and F-score (0.99) in the classification task. All major attack types were correctly identified. The model was also further tested in the lab using virtual infrastructures to generate normal and DDoS traffic. The results showed that the model can accurately classify attacks under near-real-world conditions, demonstrating 95.05% accuracy and balanced F-score scores for all attack types. This confirms that neural networks are an effective tool for detecting DDoS attacks in modern information security systems.
format Preprint
id arxiv_https___arxiv_org_abs_2412_18990
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Detection and classification of DDoS flooding attacks by machine learning method
Tymoshchuk, Dmytro
Yasniy, Oleh
Mytnyk, Mykola
Zagorodna, Nataliya
Tymoshchuk, Vitaliy
Cryptography and Security
Machine Learning
Networking and Internet Architecture
This study focuses on a method for detecting and classifying distributed denial of service (DDoS) attacks, such as SYN Flooding, ACK Flooding, HTTP Flooding, and UDP Flooding, using neural networks. Machine learning, particularly neural networks, is highly effective in detecting malicious traffic. A dataset containing normal traffic and various DDoS attacks was used to train a neural network model with a 24-106-5 architecture. The model achieved high Accuracy (99.35%), Precision (99.32%), Recall (99.54%), and F-score (0.99) in the classification task. All major attack types were correctly identified. The model was also further tested in the lab using virtual infrastructures to generate normal and DDoS traffic. The results showed that the model can accurately classify attacks under near-real-world conditions, demonstrating 95.05% accuracy and balanced F-score scores for all attack types. This confirms that neural networks are an effective tool for detecting DDoS attacks in modern information security systems.
title Detection and classification of DDoS flooding attacks by machine learning method
topic Cryptography and Security
Machine Learning
Networking and Internet Architecture
url https://arxiv.org/abs/2412.18990