An intelligent DDoS attack detection tree-based model using Gini index feature selection method

被引:20
|
作者
Bouke, Mohamed Aly [1 ]
Abdullah, Azizol [1 ]
ALshatebi, Sameer Hamoud [1 ]
Abdullah, Mohd Taufik [1 ]
El Atigh, Hayate [2 ]
机构
[1] Univ Putra Malaysia, Fac Comp Sci & Informat Technol, Serdang 43400, Malaysia
[2] Bandirma Onyedi Eylul Univ, Fac Comp Engn, TR-10200 Balikesir, Turkiye
关键词
Feature importance; Decision trees; Gini index; DDoS; UNSW-NB15; DEEP LEARNING APPROACH; INTERNET; THINGS; PERFORMANCE; SYSTEMS;
D O I
10.1016/j.micpro.2023.104823
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber security has recently garnered enormous attention due to the popularity of the Internet of Things (IoT), intelligent devices' rapid growth, and a vast number of real-life applications. As a result, detecting threats and constructing an efficient Intrusion detection system (IDS) have become crucial in today's security requirements. Withal, the large amount of high dimensional data might influence detection effectiveness and raise the computation requirements. Artificial Intelligence (AI) has recently attracted much attention and is widely used to build intelligent IDSs to preserve data confidentiality, integrity, and availability. Distributed denial of service (DDoS) is a denial of service (DoS) variant mainly targeting asset availability. Preventing DoS at the network or infrastructure level typically depends on implementing an IDS. This paper proposes a novel intelligent DDoS attack detection model based on a Decision Tee (DT) algorithm and an enhanced Gini index feature selection method. Our approach is evaluated on the UNSW-NB15 dataset, which contains 1,140,045 samples and is more recent and comprehensive than those used in previous works. Our system achieved an overall accuracy of 98%, outperforming baseline models that used more advanced algorithms such as Random Forest and XGBoost. Our enhanced Gini index feature selection method allowed us to select only 13 out of 45 security features, signifi-cantly reducing the data dimensionality and avoiding overfitting issues. Our model also has a lower false alarm rate, misclassifying only 2% of the testing instances. Our approach is, therefore, highly effective and efficient, with the potential to be used in real-world network security applications.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] DDoS attack detection method using cluster analysis
    Lee, Keunsoo
    Kim, Juhyun
    Kwon, Ki Hoon
    Han, Younggoo
    Kim, Sehun
    EXPERT SYSTEMS WITH APPLICATIONS, 2008, 34 (03) : 1659 - 1665
  • [32] Generalizing Gain Penalization for Feature Selection in Tree-Based Models
    Wundervald, Bruna
    Parnell, Andrew C.
    Domijan, Katarina
    IEEE ACCESS, 2020, 8 : 190231 - 190239
  • [33] DDoS Attack Detection Model Parameter Update Method Based on EWC Algorithm
    Zhang Bin
    Zhou Yitao
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2021, 43 (10) : 2928 - 2935
  • [34] An Algorithm of Feature Selection in Text Categorization Based on Gini-index
    Zhu, Wei-Dong
    Wang, Bo
    Lin, Yong-Min
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND MANAGEMENT INNOVATION, 2015, 6 : 272 - 278
  • [35] DDoS Attack Detection Method Based on Machine Learning
    Liu, Cuilian
    Zhong, Sirong
    2024 IEEE 15TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE, ICSESS 2024, 2024, : 83 - 87
  • [36] A Framework For Intelligent DDoS Attack Detection and Response using SIEM and Ontology
    Cakmakci, Salva Daneshgadeh
    Hutschenreuter, Helmar
    Maeder, Christian
    Kemmerich, Thomas
    2021 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2021,
  • [37] Machine-Learning-Based DDoS Attack Detection Using Mutual Information and Random Forest Feature Importance Method
    Alduailij, Mona
    Khan, Qazi Waqas
    Tahir, Muhammad
    Sardaraz, Muhammad
    Alduailij, Mai
    Malik, Fazila
    SYMMETRY-BASEL, 2022, 14 (06):
  • [38] DDOS Attack Detection Using Lightweight Partial Decision Tree algorithm
    Kareem, Mohammed Ibrahim
    Jasim, Mahdi Nsaif
    PROCEEDING OF THE 2ND 2022 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (CSASE 2022), 2022, : 362 - 367
  • [39] A DDoS Attack Detection Method Using Conditional Entropy Based on SDN Traffic
    Tian, Qiwen
    Miyata, Sumiko
    IOT, 2023, 4 (02): : 95 - 111
  • [40] Improving DDoS Attack Detection Leveraging a Multi-aspect Ensemble Feature Selection
    Golchin, Pegah
    Kundel, Ralf
    Steuer, Tim
    Hark, Rhaban
    Steinmetz, Ralf
    PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,