Feature Selection to Enhance DDoS Detection Using Hybrid N-Gram Heuristic Techniques

Q3 Decision Sciences
Andi Maslan, Kamaruddin Malik Bin Mohamad, Abdul Hamid, Hotma Pangaribuan, Sunarsan Sitohang
{"title":"Feature Selection to Enhance DDoS Detection Using Hybrid N-Gram Heuristic Techniques","authors":"Andi Maslan, Kamaruddin Malik Bin Mohamad, Abdul Hamid, Hotma Pangaribuan, Sunarsan Sitohang","doi":"10.30630/joiv.7.3.1533","DOIUrl":null,"url":null,"abstract":"Various forms of distributed denial of service (DDoS) assault systems and servers, including traffic overload, request overload, and website breakdowns. Heuristic-based DDoS attack detection is a combination of anomaly-based and pattern-based methods, and it is one of three DDoS attack detection techniques available. The pattern-based method compares a sequence of data packets sent across a computer network using a set of criteria. However, it cannot identify modern assault types, and anomaly-based methods take advantage of the habits that occur in a system. However, this method is difficult to apply because the accuracy is still low, and the false positives are relatively high. Therefore, this study proposes feature selection based on Hybrid N-Gram Heuristic Techniques. The research starts with the conversion process, package extract, and hex payload analysis, focusing on the HTTP protocol. The results show the Hybrid N-Gram Heuristic-based feature selection for the CIC-2017 dataset with the SVM algorithm on the CSDPayload+N-Gram feature with a 4-Gram accuracy rate of 99.86%, MIB- Dataset 2016 with the 2016 algorithm. SVM and CSPayload feature +N-Gram with 100% accuracy for 4-Gram, H2N-Payload Dataset with SVM Algorithm, and CSDPayload+N-Gram feature with 100% accuracy for 4-Gram. As a comparison, the KNN algorithm for 4-Gram has an accuracy rate of 99.44%, and the Neural Network Algorithm has an accuracy rate of 100% for 4-Gram. Thus, the best algorithm for DDoS detection is SVM with Hybrid N-Gram (4-Gram).","PeriodicalId":32468,"journal":{"name":"JOIV International Journal on Informatics Visualization","volume":"26 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-09-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"JOIV International Journal on Informatics Visualization","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.30630/joiv.7.3.1533","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"Decision Sciences","Score":null,"Total":0}
引用次数: 0

Abstract

Various forms of distributed denial of service (DDoS) assault systems and servers, including traffic overload, request overload, and website breakdowns. Heuristic-based DDoS attack detection is a combination of anomaly-based and pattern-based methods, and it is one of three DDoS attack detection techniques available. The pattern-based method compares a sequence of data packets sent across a computer network using a set of criteria. However, it cannot identify modern assault types, and anomaly-based methods take advantage of the habits that occur in a system. However, this method is difficult to apply because the accuracy is still low, and the false positives are relatively high. Therefore, this study proposes feature selection based on Hybrid N-Gram Heuristic Techniques. The research starts with the conversion process, package extract, and hex payload analysis, focusing on the HTTP protocol. The results show the Hybrid N-Gram Heuristic-based feature selection for the CIC-2017 dataset with the SVM algorithm on the CSDPayload+N-Gram feature with a 4-Gram accuracy rate of 99.86%, MIB- Dataset 2016 with the 2016 algorithm. SVM and CSPayload feature +N-Gram with 100% accuracy for 4-Gram, H2N-Payload Dataset with SVM Algorithm, and CSDPayload+N-Gram feature with 100% accuracy for 4-Gram. As a comparison, the KNN algorithm for 4-Gram has an accuracy rate of 99.44%, and the Neural Network Algorithm has an accuracy rate of 100% for 4-Gram. Thus, the best algorithm for DDoS detection is SVM with Hybrid N-Gram (4-Gram).
基于混合N-Gram启发式技术的特征选择增强DDoS检测
各种形式的分布式拒绝服务(DDoS)攻击系统和服务器,包括流量过载、请求过载和网站崩溃。基于启发式的DDoS攻击检测是基于异常和基于模式的方法的结合,是三种可用的DDoS攻击检测技术之一。基于模式的方法使用一组标准比较通过计算机网络发送的数据包序列。然而,它不能识别现代攻击类型,并且基于异常的方法利用了系统中出现的习惯。然而,由于准确率仍然较低,并且假阳性较高,因此该方法难以应用。因此,本研究提出了基于混合N-Gram启发式技术的特征选择。研究从转换过程、包提取和十六进制有效负载分析开始,重点关注HTTP协议。结果表明,SVM算法在CSDPayload+N-Gram特征上对CIC-2017数据集进行了基于Hybrid N-Gram启发式的特征选择,4-Gram准确率达到99.86%,MIB- dataset 2016使用2016算法。SVM和CSPayload feature +N-Gram对4-Gram准确率100%,H2N-Payload Dataset with SVM算法,CSDPayload+N-Gram feature对4-Gram准确率100%。作为对比,KNN算法对4-Gram的准确率为99.44%,而神经网络算法对4-Gram的准确率为100%。因此,DDoS检测的最佳算法是混合N-Gram (4-Gram) SVM。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
JOIV International Journal on Informatics Visualization
JOIV International Journal on Informatics Visualization Decision Sciences-Information Systems and Management
CiteScore
1.40
自引率
0.00%
发文量
100
审稿时长
16 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信