DDOS attack detection with data imperfections using machine learning algorithms
| dc.contributor.author | Dremov, Artem | |
| dc.contributor.author | Volokyta, Artem | |
| dc.date.accessioned | 2026-02-06T13:31:17Z | |
| dc.date.available | 2026-02-06T13:31:17Z | |
| dc.date.issued | 2025 | |
| dc.description.abstract | The issue of DDoS attacks remains a prevalent one even in recent years. Modern environment is highlydynamic and is characterized by a large amount of traffic flow. Existing research covers several models,techniques and approaches to detecting DDoS traffic, which aim to optimize the detection in controlleddatasets. However, unintentional noise or data corruption may lower the efficacy of such methods. As such,determining most effective ways to detect DDoS traffic in conditions of data imperfections is necessary forreliable network performance.Therefore, the object of this research Is the usage of machine learning algorithms for detection ofincoming DDoS attacks. The purpose of this research is to determine the performance of ways to detectincoming DDoS attacks with machine learning algorithms based on detection accuracy, while simulatingimperfect data conditions. The study also examines the impact of class rebalancing on modified data.To achieve the aim of this research a variety of machine learning algorithms were implemented andtested on aCIC-DDoS2019dataset. The data is modified by removing values and introducing noise, tested,the classes are resampled and the dataset is tested again. The goal is to achieve over 90% accuracy in aclassification task of the type of DDoS attack and to determine how much the changes affect the performanceof the algorithms.The results of the testing indicated that several solutions reach the target mark and changes to thedataset in realistic conditions do not significantly affect the final result. However, all models tested showa decrease in accuracy compared to unmodified data with more complex models showing higher resilience(smaller decrease in accuracy). In addition, resampling of the data shows comparable decrease in accuracyof the models with more complex models being affected less.The results of this study may be used in development of an algorithm of repairing the corrupted dataor development of models more resistant to such data changes. Additionally, the results of this study maybe used when considering models for practical implementations of a DDoS traffic classification system. | |
| dc.description.abstractother | Проблема DDoS-атак (Distributed Denial of Service) залишається актуальною навіть в останні роки. Сучасне середовище є дуже динамічним і характеризується великим обсягом трафіку. Існуючі дослідження охоплюють кілька моделей, технік і підходів до виявлення DDoS-трафіку, які спрямовані на оптимізацію виявлення в контрольованих наборах даних. Однак ненавмисний шум або пошкодження даних можуть знизити ефективність таких методів. Таким чином, для надійної роботи мережі необхідно визначити найефективніші способи виявлення DDoS-трафіку в умовах недосконалості даних. Тому предметом цього дослідження є використання алгоритмів машинного навчання для виявлення вхідних DDoS-атак. Мета цього дослідження — визначити ефективність способів виявлення вхідних DDoS-атак за допомогою алгоритмів машинного навчання спираючись на точність виявлення, моделюючи умови недосконалості даних. У дослідженні також розглядається вплив перебалансування класів на модифіковані дані. Для досягнення мети цього дослідження було впроваджено та протестовано різноманітні алгоритми машинного навчання на наборі даних CIC-DDoS2019. Дані модифікуються шляхом видалення значень та введення шуму, тестуються, класи передискретизуються, а набір даних тестується знову. Мета полягає в досягненні точності понад 90% у завданні класифікації типу DDoS-атаки та визначенні, наскільки зміни впливають на продуктивність алгоритмів. Результати тестування показали, що кілька рішень досягають цільового показника, а зміни в наборі даних в реалістичних умовах суттєво не впливають на кінцевий результат. Однак усі протестовані моделі демонструють зниження точності порівняно з немодифікованими даними, причому більш складні моделі виявляють вищу стійкість (менше зниження точності). Крім того, передискретизація даних показує порівнянне зниження точності моделей, причому більш складні моделі зазнають меншого впливу. Результати цього дослідження можуть бути використані для розробки алгоритму відновлення пошкоджених даних або розробки моделей, більш стійких до таких змін даних. Крім того, результати цього дослідження можуть бути використані при розгляді моделей для практичного впровадження системи класифікації DDoS-трафіку. | |
| dc.format.pagerange | P. 71-82 | |
| dc.identifier.citation | Dremov, A. DDOS attack detection with data imperfections using machine learning algorithms / Artem Dremov, Artem Volokyta // Information, Computing and Intelligent systems. – 2025. – No. 7. – P. 71-82. – Bibliogr.: 27 ref. | |
| dc.identifier.doi | https://doi.org/0.20535/2786-8729.7.2025.334076 | |
| dc.identifier.orcid | 0009-0005-7214-9458 | |
| dc.identifier.orcid | 0000-0001-9069-5544 | |
| dc.identifier.uri | https://ela.kpi.ua/handle/123456789/78687 | |
| dc.language.iso | en | |
| dc.publisher | National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute" | |
| dc.publisher.place | Kyiv | |
| dc.relation.ispartof | Information, Computing and Intelligent systems, No. 7, 2025 | |
| dc.rights.uri | https://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | machine learning | |
| dc.subject | DDoS | |
| dc.subject | network security | |
| dc.subject | network traffic analysis | |
| dc.subject | data resampling | |
| dc.subject | Машинне навчання | |
| dc.subject | DDoS | |
| dc.subject | мережева безпека | |
| dc.subject | аналіз мережевого трафіку | |
| dc.subject | передискретизація даних | |
| dc.subject.udc | 004.8:004.94 | |
| dc.title | DDOS attack detection with data imperfections using machine learning algorithms | |
| dc.title.alternative | Виявлення DDOS атак при недосконалості даних за допомогою алгоритмів машинного навчання | |
| dc.type | Article |
Файли
Контейнер файлів
1 - 1 з 1
Ліцензійна угода
1 - 1 з 1
Ескіз недоступний
- Назва:
- license.txt
- Розмір:
- 8.98 KB
- Формат:
- Item-specific license agreed upon to submission
- Опис: