Network Anomaly Detection Mitigation of DDoS Attack Using Machine Learning
摘要
In order to improve network security and strengthen resistance against DDoS attacks, the suggested system attempts to dynamically adjust to changing network conditions and efficiently distinguish between regular and irregular traffic patterns. Its core functionalities encompass traffic flow initialization, feature extraction, dataset creation, intrusion detection, and mitigation strategies. During the initialization phase, the system collects traffic flow data from SDN switches, configures monitoring parameters, and establishes baseline profiles. Feature extraction entails the selection of pertinent characteristics from the data, followed by transformation and encoding for subsequent analysis. The dataset is then formed, with each flow entry categorized as normal or abnormal based on observed behavior. The detection module utilizes classification methodologies such as KNN and Random Forest to pinpoint intrusions, leveraging flow-based detection for its scalability and operational efficiency. In response to identified threats, the mitigation module implements proactive security measures and dynamic response strategies. Non-functional requirements stipulate detection and analysis timeframes, ensuring prompt responses to security incidents. In a comparative analysis, Random Forest exhibits superior accuracy compared to KNN, showcasing its efficacy in handling intricate datasets and delivering precise predictions. Overall, the proposed system integrates diverse components and methodologies to enhance network security and effectively mitigate DDoS attacks. The technological and operational issues got resolved to achieve high performance, including improved DDoS attack detection and mitigation using network anomaly detection. The suggested work makes it clear that the systems’ efficacy and dependability have improved.