An intelligent DDoS attack detection tree-based model using Gini index feature selection method

被引:20
|
作者
Bouke, Mohamed Aly [1 ]
Abdullah, Azizol [1 ]
ALshatebi, Sameer Hamoud [1 ]
Abdullah, Mohd Taufik [1 ]
El Atigh, Hayate [2 ]
机构
[1] Univ Putra Malaysia, Fac Comp Sci & Informat Technol, Serdang 43400, Malaysia
[2] Bandirma Onyedi Eylul Univ, Fac Comp Engn, TR-10200 Balikesir, Turkiye
关键词
Feature importance; Decision trees; Gini index; DDoS; UNSW-NB15; DEEP LEARNING APPROACH; INTERNET; THINGS; PERFORMANCE; SYSTEMS;
D O I
10.1016/j.micpro.2023.104823
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber security has recently garnered enormous attention due to the popularity of the Internet of Things (IoT), intelligent devices' rapid growth, and a vast number of real-life applications. As a result, detecting threats and constructing an efficient Intrusion detection system (IDS) have become crucial in today's security requirements. Withal, the large amount of high dimensional data might influence detection effectiveness and raise the computation requirements. Artificial Intelligence (AI) has recently attracted much attention and is widely used to build intelligent IDSs to preserve data confidentiality, integrity, and availability. Distributed denial of service (DDoS) is a denial of service (DoS) variant mainly targeting asset availability. Preventing DoS at the network or infrastructure level typically depends on implementing an IDS. This paper proposes a novel intelligent DDoS attack detection model based on a Decision Tee (DT) algorithm and an enhanced Gini index feature selection method. Our approach is evaluated on the UNSW-NB15 dataset, which contains 1,140,045 samples and is more recent and comprehensive than those used in previous works. Our system achieved an overall accuracy of 98%, outperforming baseline models that used more advanced algorithms such as Random Forest and XGBoost. Our enhanced Gini index feature selection method allowed us to select only 13 out of 45 security features, signifi-cantly reducing the data dimensionality and avoiding overfitting issues. Our model also has a lower false alarm rate, misclassifying only 2% of the testing instances. Our approach is, therefore, highly effective and efficient, with the potential to be used in real-world network security applications.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Detection of Application Layer DDoS Attack by Feature Learning Using Stacked Autoencoder
    Yadav, Satyajit
    Subramanian, Selvakumar
    2016 INTERNATIONAL CONFERENCE ON COMPUTATIONAL TECHNIQUES IN INFORMATION AND COMMUNICATION TECHNOLOGIES (ICCTICT), 2016,
  • [22] A Flow-Based Anomaly Detection Approach With Feature Selection Method Against DDoS Attacks in SDNs
    El Sayed, Mahmoud Said
    Le-Khac, Nhien-An
    Azer, Marianne A.
    Jurcut, Anca D.
    IEEE TRANSACTIONS ON COGNITIVE COMMUNICATIONS AND NETWORKING, 2022, 8 (04) : 1862 - 1880
  • [23] Implementing attack detection system using filter-based feature selection methods for fog-enabled IoT networks
    Chaudhary, Pooja
    Gupta, Brij
    Singh, A. K.
    TELECOMMUNICATION SYSTEMS, 2022, 81 (01) : 23 - 39
  • [24] A Lightweight Model for DDoS Attack Detection Using Machine Learning Techniques
    Sadhwani, Sapna
    Manibalan, Baranidharan
    Muthalagu, Raja
    Pawar, Pranav
    APPLIED SCIENCES-BASEL, 2023, 13 (17):
  • [25] BukaGini: A Stability-Aware Gini Index Feature Selection Algorithm for Robust Model Performance
    Bouke, Mohamed Aly
    Abdullah, Azizol
    Frnda, Jaroslav
    Cengiz, Korhan
    Salah, Bashir
    IEEE ACCESS, 2023, 11 : 59386 - 59396
  • [26] Defensive mechanism against DDoS attack based on feature selection and multi-classifier algorithms
    Anupama Mishra
    Neena Gupta
    Brij B. Gupta
    Telecommunication Systems, 2023, 82 : 229 - 244
  • [27] Defensive mechanism against DDoS attack based on feature selection and multi-classifier algorithms
    Mishra, Anupama
    Gupta, Neena
    Gupta, Brij. B. B.
    TELECOMMUNICATION SYSTEMS, 2023, 82 (02) : 229 - 244
  • [28] A Spark-Based DDoS Attack Detection Model in Cloud Services
    Zhang, Jian
    Zhang, Yawei
    Liu, Pin
    He, Jianbiao
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, ISPEC 2016, 2016, 10060 : 48 - 64
  • [29] Curse of Feature Selection: a Comparison Experiment of DDoS Detection Using Classification Techniques
    Wang, Wenjia
    Sadjadi, Seyed Masoud
    Rishe, Naphtali
    2022 IEEE INTL CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, BIG DATA & CLOUD COMPUTING, SUSTAINABLE COMPUTING & COMMUNICATIONS, SOCIAL COMPUTING & NETWORKING, ISPA/BDCLOUD/SOCIALCOM/SUSTAINCOM, 2022, : 262 - 269
  • [30] Aspect term extraction for sentiment analysis in large movie reviews using Gini Index feature selection method and SVM classifier
    Asha S Manek
    P Deepa Shenoy
    M Chandra Mohan
    Venugopal K R
    World Wide Web, 2017, 20 : 135 - 154