Interpretable DDoS attack detection: Combining machine learning and SHAP
Loading...
Date
Publisher
Institute of Electrical and Electronics Engineers Inc.
Citation
T. Tahrim, M. A. Sharan, M. F. Ahmed and A. Shakil, "Interpretable DDoS Attack Detection: Combining Machine Learning and SHAP," 2024 27th International Conference on Computer and Information Technology (ICCIT), Cox's Bazar, Bangladesh, 2024, pp. 1392-1397, doi: 10.1109/ICCIT64611.2024.11022481.
Abstract
In today's world, technology has significantly advanced across all sectors of life. As computers are becoming smaller, faster and more accessible, it also presents a significant challenge in maintaining network security to protect private information and ensure the reliability of networks. It has become a priority for technology experts, particularly in defending against cyberattacks. Therefore, this study focuses on detecting Distributed Denial of Service (DDoS) attacks, specifically those that can target many servers and web applications. In this research, a new taxonomy was developed for classifying the attack into two categories, Reflection based attack and Exploitation based attack to enhance detection accuracy and better performance of the model. Several machine learning models, such as Random Forest, Naive Bayes, Decision Tree, and XGBoost have also been implemented on the CIC-DDoS2019 dataset. Besides, Explainable AI (SHAP) technique has been introduced for models performance interpretation. The results demonstrated a high level of accuracy, achieving 99.89% for exploitation-based attacks and 99.74% for reflection-based attacks, showing substantial improvement in detection rates while minimizing processing time.
LC Subject Headings
Description
Publisher Link
Type
Conference Proceeding