Supervised learning-based DDoS attacks detection: Tuning hyperparameters
- Authors
- Kim, Meejoung
- Issue Date
- 10월-2019
- Publisher
- WILEY
- Keywords
- accuracy of detection; DDoS attack; long short-term memory; machine learning; tensorflow
- Citation
- ETRI JOURNAL, v.41, no.5, pp.560 - 573
- Indexed
- SCIE
SCOPUS
KCI
- Journal Title
- ETRI JOURNAL
- Volume
- 41
- Number
- 5
- Start Page
- 560
- End Page
- 573
- URI
- https://scholar.korea.ac.kr/handle/2021.sw.korea/62628
- DOI
- 10.4218/etrij.2019-0156
- ISSN
- 1225-6463
- Abstract
- Two supervised learning algorithms, a basic neural network and a long short-term memory recurrent neural network, are applied to traffic including DDoS attacks. The joint effects of preprocessing methods and hyperparameters for machine learning on performance are investigated. Values representing attack characteristics are extracted from datasets and preprocessed by two methods. Binary classification and two optimizers are used. Some hyperparameters are obtained exhaustively for fast and accurate detection, while others are fixed with constants to account for performance and data characteristics. An experiment is performed via TensorFlow on three traffic datasets. Three scenarios are considered to investigate the effects of learning former traffic on sequential traffic analysis and the effects of learning one dataset on application to another dataset, and determine whether the algorithms can be used for recent attack traffic. Experimental results show that the used preprocessing methods, neural network architectures and hyperparameters, and the optimizers are appropriate for DDoS attack detection. The obtained results provide a criterion for the detection accuracy of attacks.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - ETC > 1. Journal Articles
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.