Interpretable DDoS attack detection: Combining machine learning and SHAP

bracu.type.groupResearch Publications
datacite.rightsMetadata Only
dc.contributor.authorTahrim, Tasmiah
dc.contributor.authorSharan, Md. Asif
dc.contributor.authorAhmed, Md Faisal
dc.contributor.authorShakil, Arif
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-10-01T05:14:48Z
dc.date.available2026-10-01T05:14:48Z
dc.date.issued2024-01-01
dc.description.abstractIn today's world, technology has significantly advanced across all sectors of life. As computers are becoming smaller, faster and more accessible, it also presents a significant challenge in maintaining network security to protect private information and ensure the reliability of networks. It has become a priority for technology experts, particularly in defending against cyberattacks. Therefore, this study focuses on detecting Distributed Denial of Service (DDoS) attacks, specifically those that can target many servers and web applications. In this research, a new taxonomy was developed for classifying the attack into two categories, Reflection based attack and Exploitation based attack to enhance detection accuracy and better performance of the model. Several machine learning models, such as Random Forest, Naive Bayes, Decision Tree, and XGBoost have also been implemented on the CIC-DDoS2019 dataset. Besides, Explainable AI (SHAP) technique has been introduced for models performance interpretation. The results demonstrated a high level of accuracy, achieving 99.89% for exploitation-based attacks and 99.74% for reflection-based attacks, showing substantial improvement in detection rates while minimizing processing time.
dc.description.versionPublished
dc.format.extent1392-1397
dc.identifier.citationT. Tahrim, M. A. Sharan, M. F. Ahmed and A. Shakil, "Interpretable DDoS Attack Detection: Combining Machine Learning and SHAP," 2024 27th International Conference on Computer and Information Technology (ICCIT), Cox's Bazar, Bangladesh, 2024, pp. 1392-1397, doi: 10.1109/ICCIT64611.2024.11022481.
dc.identifier.doi10.1109/ICCIT64611.2024.11022481
dc.identifier.issn9798331519094
dc.identifier.other2-s2.0-105009055898
dc.identifier.urihttps://hdl.handle.net/10361/30333
dc.language.isoen_US
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.hasversion10.1109/ICCIT64611.2024.11022481
dc.relation.ispartof2024 27th International Conference on Computer and Information Technology Iccit 2024 Proceedings
dc.relation.ispartofseries2024 27th International Conference on Computer and Information Technology Iccit 2024 Proceedings
dc.relation.urihttps://ieeexplore.ieee.org/document/11022481
dc.subjectComputers
dc.subjectAccuracy
dc.subjectExplainable AI
dc.subjectTaxonomy
dc.subjectDenial-of-service attack
dc.subjectFeature extraction
dc.subjectTurning
dc.subjectServers
dc.subjectComputer crime
dc.subjectRandom forests
dc.subjectDDoS attack
dc.subjectCyber security
dc.subjectMachine learning
dc.subjectExplainable AI
dc.subject.lcshDenial of service attacks.
dc.subject.lcshComputer security.
dc.titleInterpretable DDoS attack detection: Combining machine learning and SHAP
dc.typeConference Proceeding
person.affiliation.nameBRAC University
person.affiliation.nameBRAC University
person.affiliation.nameBRAC University
person.affiliation.nameBRAC University
person.identifier.scopus-author-id59222287500
person.identifier.scopus-author-id59964209800
person.identifier.scopus-author-id57222253716
person.identifier.scopus-author-id57219988560

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
IMG_8345.jpg
Size:
27.35 KB
Format:
Joint Photographic Experts Group/JPEG File Interchange Format (JFIF)

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: