Assessment and mitigation of DDOS attacks in large scale networks

محتوى المقالة الرئيسي

Mohammed Wael Rasheed ALLQASAM

الملخص

Distributed Denial-of-Service (DDoS) attacks are a serious problem in today's networked world, especially with the rise of Internet of Things (IoT), Software-Defined Networking (SDN), cloud computing and 5G deployment that are driving the proliferation of network traffic in scale and complexity. This study suggests an integrated machine-learning framework for detecting multiclass DDoS attacks and mitigating the attacks by simulation; especially significant issues addressed in this study are severe class imbalance, redundant features, and reliable recognition of minority classes. The proposed framework is tested with the CIC-IDS2017 benchmark dataset using two stages experimental design. In Phase 1, a conventional baseline is created with three algorithms: Random Forest (RF), XGBoost (XGB) and LightGBM (LGB) with adaptive SMOTE. Rare-class filtering, training-only feature selection, SMOTE, class-weighted learning, and soft-voting ensemble classification are introduced in phase 2. A reproducible 20% sample of CIC-IDS2017 is used followed by an 80:20 stratified train-test split, and all the learned preprocessing processes are applied to the training data only to avoid information leakage. This feature selection further shrinks the input space from 77 to 30 features that are the most informative. Results show that the most accurate model is Random Forest with an accuracy of 99.83% and a Macro F1-Score of only 0.7353 indicating the shortcomings of accuracy while working with severe class imbalance. By contrast, the proposed Phase 2 ensemble achieves 99.51% accuracy, 0.8108 Macro Precision, 0.9409 Macro Recall, 0.8509 Macro F1-Score and 0.9956 Weighted F1-Score. Therefore, Macro F1 is enhanced by 0.1156 compared to the baseline and the Macro Recall is significantly enhanced. The integrated framework also consists of an integrated confidence-based mitigation simulation that blocks 72.23% of the prespecified synthetic attack scenario. The results indicate that this preprocessing method along with supervised feature reduction, weighted learning and probabilistic ensemble classification yields better balanced multiclass DDoS detection than the conventional methods that focus on accuracy.

تفاصيل المقالة

كيفية الاقتباس
ALLQASAM, M. W. R. . (2026). Assessment and mitigation of DDOS attacks in large scale networks. مجلة الشرق الأوسط للعلوم الإنسانية والثقافية, 6(3), 738–716. https://doi.org/10.56961/mejhss.v6i3.1724
القسم
المقالات