A Method for DDoS Attack Detection Based on Machine Learning Approach

سال انتشار: 1405
نوع سند: مقاله کنفرانسی
زبان: انگلیسی
مشاهده: 63

فایل این مقاله در 15 صفحه با فرمت PDF قابل دریافت می باشد

استخراج به نرم افزارهای پژوهشی:

لینک ثابت به این مقاله:

شناسه ملی سند علمی:

SMARTCITYC04_190

تاریخ نمایه سازی: 24 مرداد 1405

چکیده مقاله:

Distributed Denial of Service (DDoS) attacks are among the most serious threats to network security, as they can disrupt the availability of online services by overwhelming network resources with massive malicious traffic. Traditional detection mechanisms are often insufficient for identifying complex and high-volume DDoS attacks, especially in dynamic network environments. Therefore, machine learning-based intrusion detection methods have received significant attention due to their ability to learn traffic patterns and distinguish between normal and attack behaviors. This paper proposes a hybrid machine learning approach for DDoS attack detection based on the integration of K-Means clustering, Particle Swarm Optimization (PSO), and Support Vector Machine (SVM) classification. In the proposed method, network traffic data are first preprocessed to remove noise and prepare the dataset for analysis. Then, K-Means clustering is applied to group similar traffic patterns. To improve the clustering process, PSO is used to optimize the cluster centroids and enhance the quality of traffic grouping. Finally, SVM is employed as the classification model to distinguish normal traffic from DDoS attack traffic. The proposed model was evaluated using standard performance metrics, including accuracy, precision, recall, F۱-score, detection rate, and false positive rate. The experimental results show that the proposed K-Means–PSO–SVM model achieved an accuracy of ۹۷.۴۲%, precision of ۹۶.۸۵%, recall of ۹۷.۱۰%, F۱-score of ۹۶.۹۷%, and a detection rate of ۹۹.۷۸%, with a false positive rate of ۱.۸۴%. Moreover, the proposed method improved the detection rate by ۰.۴۳% compared with the baseline SVM-K-Means approach. These results indicate that combining clustering, optimization, and classification techniques can improve the effectiveness of machine learning-based DDoS attack detection systems.

نویسندگان

Masoumeh Ebrahimi

Department of Computer Engineering, Faculty of Engineering Technology, Apadana Institute of Higher Education

Mostafa Fakhr Ahmad

Department of Engineering and Computer Science, Faculty of Engineering, Shiraz University

Kimia Bazargan Lari

Department of Computer Engineering, Faculty of Engineering Technology, Apadana Institute of Higher Education