Evaluation of Machine Learning Techniques for Denial-of-Service Attack Detection in Digital Information Exchange

dc.contributor.authorSuwimol, Piyapol
dc.contributor.authorChimmanee, Krishna
dc.contributor.authorPomsathit, Auttapon
dc.date.accessioned2026-08-06T10:53:47Z
dc.date.available2026-08-06T10:53:47Z
dc.date.issued2026-01-01
dc.description.abstractAnomaly detection plays a critical role in mitigating cybersecurity threats, particularly Distributed Denial of Service (DDoS) attacks. This study evaluates the performance of tree-based and ensemble learning models, including Decision Tree, Random Forest, and XGBoost, for classifying Snort log data, alongside the application of Isolation Forest for time-series anomaly detection. The experiments were conducted using ICMP-based Ping Flood attacks in a controlled network environment, with data collected from Snort intrusion detection system logs. The classification results indicate that XGBoost achieved the highest performance, with 99.81% accuracy, 99.93% precision, 99.65% recall, and 99.79% F1-score under a 70–30 train-test split. Random Forest and Decision Tree also demonstrated strong performance, while Logistic Regression showed lower effectiveness due to its limitations in modeling nonlinear patterns. For anomaly detection, Isolation Forest was applied to time-series data collected over a 19-day period. The model detected 93 anomaly points, of which 41 overlapped with Wireshark-confirmed events. However, a false positive rate of 41.67% was observed, indicating the need for parameter tuning to balance detection sensitivity and operational efficiency. Overall, the findings demonstrate that ensemble-based learning approaches, particularly XGBoost, are effective for detecting DDoS-related patterns within the experimental setting. However, the results are limited to ICMP-based attack scenarios in a controlled environment. Further validation, including cross-validation, multi-attack evaluation, and deployment-level performance analysis, is required to assess generalizability and practical applicability.
dc.identifier.citationJournal of Computer Networks and Communications, 2026(1), 2026
dc.identifier.doi10.1155/jcnc/3114551
dc.identifier.issn20907141
dc.identifier.other2-s2.0-105038116541
dc.identifier.urihttps://dspace.kmitl.ac.th/handle/123456789/17653
dc.sourceJournal of Computer Networks and Communications
dc.subjectanomaly detection
dc.subjectDDoS
dc.subjectDistributed Denial of Service
dc.subjectIsolation Forest
dc.subjectmachine learning
dc.subjectSnort
dc.subjectXGBoost
dc.titleEvaluation of Machine Learning Techniques for Denial-of-Service Attack Detection in Digital Information Exchange
dc.typeArticle

Files

Collections