<?xml version='1.0' encoding='UTF-8'?>
<ArticleSet>
  <Article>
    <Journal>
      <PublisherName>Dr. Mohammad Doostizadeh</PublisherName>
      <PublisherNameVernacular>دکتر محمد دوستی زاده</PublisherNameVernacular>
      <JournalTitle>Journal of New Achievements in Electrical,Computer and Technology</JournalTitle>
      <JournalTitleVernacular>نشریه علمی-تخصصی دستاوردهای نوین در برق،کامپیوتر و فناوری</JournalTitleVernacular>
      <Issn></Issn>
      <Volume></Volume>
      <Issue></Issue>
      <PubDate PubStatus="epublish">
        <Year></Year>
        <Month></Month>
        <Day></Day>
      </PubDate>
    </Journal>

    <ArticleTitle>Enhancing DDoS attack detection with hybrid feature selection and
ensemble-based classifier: A promising solution for robust cybersecurity</ArticleTitle>
    <VernacularTitle>ارتقای تشخیص حملات DDoS با استفاده از انتخاب ویژگی ترکیبی و طبقه بندهای گروهی: رویکردی نویدبخش برای امنیت سایبری مقاوم</VernacularTitle>

    <FirstPage></FirstPage>
    <LastPage></LastPage>
    <ELocationID EIdType="doi"></ELocationID>
    <Language>FA</Language>

    <AuthorList>
      <Author>
        <FirstName>Armin</FirstName>
        <LastName>bagherifard</LastName>
        <Affiliation>Armin bagherifard</Affiliation>
        <VernacularFirstName>آرمین</VernacularFirstName>
        <VernacularLastName>باقری فرد</VernacularLastName>
        <VernacularAffiliation>کارشناس امنیت شبکه</VernacularAffiliation>
      </Author>
    </AuthorList>

    <PublicationType></PublicationType>

    <History>
      <PubDate PubStatus="received">
        <Year></Year>
        <Month></Month>
        <Day></Day>
      </PubDate>
    </History>

    <Abstract>Distributed denial-of-service (DDoS) attacks pose a significant threat to computer networks and systems by
disrupting services through the saturation of targeted systems with traffic from multiple sources. Real-time
detection of these attacks has become a critical cybersecurity task. However, current DDoS attack detection
methods suffer from high false positive rates and limited ability to capture the complex patterns of attack traffic.
This research proposes an enhanced approach for detecting DDoS attacks using a hybrid feature selection
technique in combination with an ensemble-based classifiers. The ensemble-based approach aggregates many
decision trees to increase classification accuracy and reduce overfitting and model robustness. The feature se­
lection technique uses correlation analysis, mutual information, and principal component analysis to identify the
most useful characteristics for attack detection. The ensemble-based Random Forest classifier from the various
ensemble-based approaches with the specified relevant features produces the best detection rates. Many datasets
related to identifying DDoS attacks are used to evaluate the proposed model, and experimental findings
demonstrate that it surpasses existing techniques in terms of accuracy, recall, precision, f1-score, and false
positive rate, with other evaluation metrics. The proposed approach achieves almost 100 % accuracy, 100 % true
positive rate, and 0 % error rate making it a promising solution for DDoS attack detection.</Abstract>
    <OtherAbstract Language="FA">حملات محروم سازی از خدمات توزیع شده (DDoS) با ایجاد حجم عظیمی از ترافیک از منابع متعدد و اشباع سیستم های هدف، یکی از تهدیدهای جدی علیه شبکه ها و سامانه های رایانه ای به شمار می روند. ازاین رو، تشخیص بلادرنگ این حملات به یکی از وظایف مهم در حوزه امنیت سایبری تبدیل شده است. بااین حال، بسیاری از روش های موجود برای تشخیص حملات DDoS با چالش هایی همچون نرخ بالای مثبت کاذب و توانایی محدود در شناسایی الگوهای پیچیده ترافیک حمله مواجه هستند.
در این پژوهش، یک رویکرد بهبودیافته برای تشخیص حملات DDoS ارائه شده است که در آن، یک روش انتخاب ویژگی ترکیبی با طبقه بندهای گروهی (Ensemble-based) تلفیق می شود. در رویکرد گروهی، با ترکیب تعداد زیادی درخت تصمیم، دقت طبقه بندی افزایش یافته و احتمال بیش برازش کاهش می یابد؛ در نتیجه، استحکام مدل نیز بهبود پیدا می کند. روش انتخاب ویژگی پیشنهادی با ترکیب تحلیل همبستگی (Correlation Analysis)، اطلاعات متقابل (Mutual Information) و تحلیل مؤلفه های اصلی (Principal Component Analysis)، ویژگی های مؤثرتر برای تشخیص حملات را شناسایی می کند.
در میان روش های مختلف یادگیری ماشین گروهی، طبقه بند جنگل تصادفی گروهی (Ensemble Random Forest) با استفاده از ویژگی های منتخب، بهترین عملکرد تشخیصی را ارائه می دهد. مدل پیشنهادی با استفاده از چندین مجموعه داده عمومی مرتبط با تشخیص حملات DDoS ارزیابی شده است. نتایج تجربی نشان می دهند که این مدل از نظر معیارهایی همچون دقت (Accuracy)، بازخوانی (Recall)، صحت (Precision)، امتیاز F1 و نرخ مثبت کاذب (False Positive Rate)، عملکرد بهتری نسبت به روش های موجود دارد.
نتایج نشان می دهد که رویکرد پیشنهادی به دقتی نزدیک به ۱۰۰ درصد، نرخ مثبت واقعی (TPR) برابر با ۱۰۰ درصد و نرخ خطای ۰ درصد دست یافته است. این نتایج، روش پیشنهادی را به راهکاری نویدبخش برای تشخیص مؤثر حملات DDoS تبدیل می کند.</OtherAbstract>

    <ObjectList>
      <Object Type="keyword"><Param Name="value">DDoS attack detection</Param></Object>
      <Object Type="keyword"><Param Name="value">Hybrid feature selection to identify DDoS attacks</Param></Object>
      <Object Type="keyword"><Param Name="value">Ensemble</Param></Object>
      <Object Type="keyword"><Param Name="value">based approach to detect DDoS attacks</Param></Object>
      <Object Type="keyword"><Param Name="value">Ensemble random forest in cybersecurity</Param></Object>
      <Object Type="keyword"><Param Name="value_vernacular">حملات DDoS؛ تشخیص حملات DDoS؛ انتخاب ویژگی ترکیبی؛ یادگیری ماشین گروهی؛ تشخیص حملات DDoS مبتنی بر روش های گروهی؛ جنگل تصادفی گروهی؛ امنیت سایبری</Param></Object>
    </ObjectList>

    <ArchiveCopySource DocType="pdf">https://jnaect.ir/downloadfilepdf/2457156</ArchiveCopySource>
  </Article>
</ArticleSet>