In network security, Distributed Denial of Service (DDoS) attacks disrupt critical online services and are becoming increasingly sophisticated. Machine learning is essential for detecting and classifying these attacks, using novel datasets featuring modern attack types. As DDoS attacks target crucial platforms like banking and social networks, intrusion detection systems (IDS) integrated with machine learning are vital. Achieving 100% accuracy in attack detection remains challenging due to the lack of comprehensive datasets including newer attack types such as UDP-flood, SIDDoS, HTTP-flood, and Smurf. Machine learning classifies network traffic based on various features, distinguishing normal from DDoS traffic. Explainable AI (XAI) methods, including LIME and SHAP, enhance model interpretability and transparency, offering insights into feature contributions for attack detection. Related works highlight the importance of new datasets and information theory-based techniques, such as information entropy and correlation methods, for DDoS detection. Hybrid approaches and SDN implementations also show promise in improving accuracy. As DDoS attacks evolve and IoT devices increase, this paper aims to enhance network security and protect critical online servies.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DDoS Attack Detection Using Explainable AI in Machine Learning

  • Sudhansu Kumar Jena,
  • Ashish Ranjan,
  • Vibhav Prakash Singh

摘要

In network security, Distributed Denial of Service (DDoS) attacks disrupt critical online services and are becoming increasingly sophisticated. Machine learning is essential for detecting and classifying these attacks, using novel datasets featuring modern attack types. As DDoS attacks target crucial platforms like banking and social networks, intrusion detection systems (IDS) integrated with machine learning are vital. Achieving 100% accuracy in attack detection remains challenging due to the lack of comprehensive datasets including newer attack types such as UDP-flood, SIDDoS, HTTP-flood, and Smurf. Machine learning classifies network traffic based on various features, distinguishing normal from DDoS traffic. Explainable AI (XAI) methods, including LIME and SHAP, enhance model interpretability and transparency, offering insights into feature contributions for attack detection. Related works highlight the importance of new datasets and information theory-based techniques, such as information entropy and correlation methods, for DDoS detection. Hybrid approaches and SDN implementations also show promise in improving accuracy. As DDoS attacks evolve and IoT devices increase, this paper aims to enhance network security and protect critical online servies.