Effective Visualization Approaches for Distributed Denial of Service Threat Prediction in Large-Scale Networks Using Interpretable Machine Learning
摘要
In recent years, Distributed Denial of Service (DDoS) attacks have become a significant threat to cybersecurity, capable of crippling critical networks and online services. This study is aimed at developing a data driven approach to distinguish between normal network traffic and DDoS attacks. The dataset consists of four types of DDoS attacks, namely UDP-Flood, Smurf, SIDDOS and HTTP-FLOOD attacks that are combined into a single malicious traffic class. The approach entails detailed data preprocessing such as handling of missing values and balancing of the dataset using SMOTE. Three machine learning models, namely Logistic Regression, Decision Tree and Random Forest were compared, and Random Forest provides superior performance. After hyperparameter tuning using Random Search Cross Validation, the model achieved a precision of 96.3%, recall of 87.3% and F1-score of 91.6%. XAI techniques like SHAP and LIME were employed to make the model more interpretable and offer features that are most relevant to the detection of DDoS attacks and thus improve the development of network security solutions.