DDOS attack detection with data imperfections using machine learning algorithms
Дата
2025
Автори
Науковий керівник
Назва журналу
Номер ISSN
Назва тому
Видавець
National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute"
Анотація
The issue of DDoS attacks remains a prevalent one even in recent years. Modern environment is highlydynamic and is characterized by a large amount of traffic flow. Existing research covers several models,techniques and approaches to detecting DDoS traffic, which aim to optimize the detection in controlleddatasets. However, unintentional noise or data corruption may lower the efficacy of such methods. As such,determining most effective ways to detect DDoS traffic in conditions of data imperfections is necessary forreliable network performance.Therefore, the object of this research Is the usage of machine learning algorithms for detection ofincoming DDoS attacks. The purpose of this research is to determine the performance of ways to detectincoming DDoS attacks with machine learning algorithms based on detection accuracy, while simulatingimperfect data conditions. The study also examines the impact of class rebalancing on modified data.To achieve the aim of this research a variety of machine learning algorithms were implemented andtested on aCIC-DDoS2019dataset. The data is modified by removing values and introducing noise, tested,the classes are resampled and the dataset is tested again. The goal is to achieve over 90% accuracy in aclassification task of the type of DDoS attack and to determine how much the changes affect the performanceof the algorithms.The results of the testing indicated that several solutions reach the target mark and changes to thedataset in realistic conditions do not significantly affect the final result. However, all models tested showa decrease in accuracy compared to unmodified data with more complex models showing higher resilience(smaller decrease in accuracy). In addition, resampling of the data shows comparable decrease in accuracyof the models with more complex models being affected less.The results of this study may be used in development of an algorithm of repairing the corrupted dataor development of models more resistant to such data changes. Additionally, the results of this study maybe used when considering models for practical implementations of a DDoS traffic classification system.
Опис
Ключові слова
machine learning, DDoS, network security, network traffic analysis, data resampling, Машинне навчання, DDoS, мережева безпека, аналіз мережевого трафіку, передискретизація даних
Бібліографічний опис
Dremov, A. DDOS attack detection with data imperfections using machine learning algorithms / Artem Dremov, Artem Volokyta // Information, Computing and Intelligent systems. – 2025. – No. 7. – P. 71-82. – Bibliogr.: 27 ref.