Multi-class DRDoS Attack Detection Method Based on Feature Selection

Tianqi Yang,Weilin Wang,Ying Liu,Huachun Zhou
DOI: https://doi.org/10.56801/rebicte.v7i.127
2021-01-01
Abstract:Distributed denial of service (DDoS) attack is one of the most serious threats to the Internet The emergenceof distributed reflection denial of service (DRDoS) attacks has increased the harm of DDoSattacks. Aiming at the common DRDoS attacks such as Memcached, TFTP, NTP, SSDP, SNMPand Chargen in the network, a multi-class DRDoS attack detection method based on feature selectionis proposed. Through the analysis of the behavior and characteristics of attack, combined withprobability distribution of features and feature importance to obtain a feature subset of 24 features.When constructing XGBoost model, the input features are the feature subset obtained by the abovefeature selection, and the model outputs multi classification results. The selected features can betterreflect the characteristics of DRDoS attack and improve the detection performance of the model. Experimentalresults show that the feature subset obtained by this method has high precision in multiclassification against DRDoS attacks, and is better than the traditional methods such as support vectormachine and multi-layer perceptron. Feature selection not only reduces the processing time, butalso reduces the malicious traffic by 99.93%.
What problem does this paper attempt to address?