Flow based anomaly detection system for distributed denial of service DDoS anomalies

Abstract

This study develops a flow-based Anomaly Detection System to detect multiple DDoSattack types. A review of 77 research papers identifies research gaps, followed by a pilot study on the CICDDoS2019 dataset to compare algorithm classes and evaluate hyperparameters. To optimize the feature set, the ML-FEB framework is proposed, integrating filter and embedding-based selection with skewness analysis and data balancing. ML-FEB reduces feature dimensions by 79.76%, 88.46%, and 58.33% on the CICDDoS2019, CICIDS2017, and BOUN DDoS datasets, improving performance and efficiency. The study introduces a Multi-Stage Anomaly Detection Framework with Greedy Cosine Diversity and Autoencoder-Enhanced Hierarchical Multiclass Classification. The model achieves 100% binary accuracy, 99.98% group accuracy and 98.42% attack accuracy with high computational efficiency. newline

Description

Keywords

Citation

item.page.endorsement

item.page.review

item.page.supplemented

item.page.referenced