SNMP Watcher: A Model to Detect DoS and DDoS Attacks Using SNMP Management Information Base Analysis
摘要
Internet has become daily routine of the world in the present generation, there is no individual who has no internet access. The increase in usage of internet has also increased varieties of vulnerabilities which empowered the attackers to make use of these vulnerabilities. Denial of Service (DoS) and Distributed Denial of Service (DDoS) are attacks which make large impact on many reputed organizations which results in monetary loss and defamation. Addressing these, we propose a model that makes use of Simple Network Management Protocol Management Information Base (SNMP-MIB) data to effectively detect DoS and DDoS attacks and provide accurate results using Machine Learning Algorithms. SNMP-MIB data is used to monitor flow of network and also identify abnormal behaviour in the traffic. This data makes it less difficult to detect malicious behaviour, if occurred in the network. Machine Learning algorithms such as Extreme Gradient Boosting, CatBoost (Categorical Boosting) and LightGBM generated results with astonishing accuracies of 99.67%, 99.78% and 99.78% respectively. Usage of broad dataset and strict evaluation metrics, including accuracy, recall and F1-score increased the robustness and dependability of our models. As a whole the primary goal of our research is to provide innovative and cost-effective solution to build robust defence system that helps Enterprises in protecting their assets and resume their operations in the phase of evolving cyberthreats.