Adaptive sliding window and LightGBM-based DDoS attack detection framework for IoT networks
摘要
Cyberattacks are rapidly increasing, with Distributed Denial of Service (DDoS) attacks posing a significant threat by overwhelming the network resources. The dynamic and evolving nature of these attacks makes it challenging for traditional detection methods to identify and mitigate them effectively. This paper proposes a novel framework, the Adaptive Sliding Window framework, for DDoS attack detection and classification in Internet of Things (IoT) networks using machine learning. The approach incorporates an adaptive sliding window technique to divide the data into batches, Principal Component Analysis (PCA) for dimensionality reduction, embedded feature selection for identifying the most important features, and LightGBM for classifying different categories of DDoS attacks. Additionally, the Synthetic Minority Over-sampling Technique (SMOTE) is utilized to handle class imbalance problems. The primary objective is to design a classification system that is both accurate and computationally efficient, and is able to differentiate between different types of DDoS attacks and benign traffic in real-time applications. The proposed framework was evaluated on the Bot-IoT dataset, comprising diverse network traffic, yielding an overall accuracy of 99.90%, recall of 99.90%, precision of 99.92% and an F1-score of 99.87%.