UPM Institutional Repository

Detection of different types of distributed denial of service attacks using multiple features of entropy and sequential probability ratio test


Citation

Al Mafrachi, Basheer Husham Ali (2024) Detection of different types of distributed denial of service attacks using multiple features of entropy and sequential probability ratio test. Doctoral thesis, Universiti Putra Malaysia.

Abstract

Distributed Denial of Service (DDoS) attacks are among the most dangerous types of attacks. These kinds of attacks bring targeted servers down and make their services unavailable to legal users. The main problem of current entropy-based detection techniques is how can these techniques identify up-to-date DDoS attacks accurately using dynamic threshold and effective features that can be selected to decrease time complexity or cost by using effective flows or features generation tool to improve confusion metrics. The first objective of this study is to identify infected ethernet and detect various kinds of up-to-date DDoS attacks using dynamic threshold by implementing multiple features of entropy and Sequential Probabilities Ratio Test approach (E-SPRT). The second is to select relevant features to reduce time complexity or cost and improve performance of detection by implementing a new combination of machine learning techniques which are ANOVA, Extra Trees Classifier, Random Forest, and Correlation Matrix with Pearson Correlation approaches. The third is to analyse problems of original CICFlowMeter and validate the effectiveness of revised version of CICFlowMeter tool on detection approach as well. Furthermore, the Defense Advanced Research Projects Agency (DARPA) 1998, DARPA2000, and Canadian Institute for Cybersecurity (CIC-DDoS2019) databases were utilizing to evaluate the implementation. In addition, ESPRT using feature selection approach with five features achieved an accuracy over 97% with a time cost 0.189ms based on using CICDDoS2019 dataset. The accuracy of ESPRT with best single features also exceeded or equalled to 99% for different kinds of DDoS attacks such as NTP, DNS, LDAP, MSSQL, NETBIOS, SSDP, and UDP. The average detection rates for identifying NTP, DNS, LDAP, MSSQL, NETBIOS, SSDP, and UDP using best single features were consistently above 99%. However, the average detection rates for identifying UDP-lag, SYN, and TFTP were 97%, 89%, and 98%, respectively. Most of these attacks exhibited an average False Positive Rate (FPR) close to 0. The execution times of ESPRT approach were approximately 189ms, 625ms, 831ms, and 1,276ms when feature sets were 5, 10, 15, and 20, respectively. Finally, the accuracy and f-score for ESPRT using the revised version exceeded 99% when DARPA 1998 dataset used. However, when using the original version, the accuracy ranged between 33% and 38% for various features.


Download File

[img] Text
FK 2024 12 - Declaration Form.pdf
Restricted to Repository staff only
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (735kB)
[img] Text
FK 2024 12 - Full Text.pdf
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (8MB)
[img] Text
FK 2024 12.pdf
Restricted to Repository staff only
Available under License Creative Commons Attribution Non-commercial No Derivatives.

Download (8MB)
Official URL or Download Paper: http://ethesis.upm.edu.my/id/eprint/18976

Additional Metadata

Item Type: Thesis (Doctoral)
Subject: Computer networks - Security measures
Subject: Anomaly detection (Computer security)
Subject: Entropy (Information theory)
Call Number: FK 2024 12
Chairman Supervisor: Associate Professor Nasri bin Sulaiman
Divisions: Faculty of Engineering
Keywords: DDoS Attacks; SPRT; Entropy; ANOVA; Extra Trees Classifier; Random Forest; And Correlation Matrix
Sustainable Development Goals (SDGs): GOAL 9: Industry, Innovation and Infrastructure, GOAL 11: Sustainable Cities and Communities
Depositing User: Pelajar Latihan Industri
Date Deposited: 06 Aug 2026 06:53
Last Modified: 06 Aug 2026 06:53
URI: http://psasir.upm.edu.my/id/eprint/125788
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item