UPM Institutional Repository

Shannon entropy based DDoS attacks detection using combination of machine learning based feature importance techniques


Citation

Ali, Basheer Husham and Sulaiman, Nasri and Al-Haddad, S. A.R. and Atan, Rodziah and Mohd Hassan, Siti Lailatul and Askar Al-Khafaji, Ali J. and Nur Amir Sjarif, Nilam and Al-Hashimi, Abdullah Saad (2025) Shannon entropy based DDoS attacks detection using combination of machine learning based feature importance techniques. In: International Research Conference on Engineering and Applied Sciences 2023, IRCEAS 2023, 16 - 17 Oct. 2023, Baghdad, Iraq. (pp. 1-9).

Abstract

A Distributed Denial of Service (DDoS) attack is one of the most dangerous cyber-attacks, capable of potentially bringing down servers. The main attacker in a DDoS attack assembles a very large number of infected machines and induces them to target a specific server. This attack overwhelms the targeted system with an extensive volume of useless requests, aiming to render legal users unable to access the available services on that system. Several pre-processing techniques were applied to the dataset to enhance the accuracy of detection, such as data cleaning, balancing, and encoding. CICFlowMeter was used to generate flows and extract features from each flow. Feature selection was utilized to choose relevant and important features and reduce the execution time of the detection process. A novel combination of four machine learning-based techniques-Random Forest, ANOVA, Extra Tree, and Pearson technique-was implemented for feature selection. Shannon entropy and Sequential Probability Ratio Test (SE-SPRT) techniques were combined to detect various types of DDoS threats. The CICDDoS2019 dataset and confusion matrix were used to test the effectiveness of the detection. Finally, the detection techniques exhibited higher f-score values and lower values of the probability of false alarms for most different attack types when compared with other state-of-the-art techniques.


Download File

[img] Text
127802.pdf - Published Version
Restricted to Repository staff only

Download (520kB)

Additional Metadata

Item Type: Conference or Workshop Item (Oral/Paper)
Subject: Physics and Astronomy (all)
Divisions: Faculty of Computer Science and Information Technology
Faculty of Engineering
DOI Number: https://doi.org/10.1063/5.0257765
Publisher: American Institute of Physics
Keywords: DDoS attacks; Cybersecurity; Network security; Machine learning; Feature selection; Shannon entropy; Random Forest; Extra Tree; CICDDoS2019 dataset; Anomaly detection
Sustainable Development Goals (SDGs): SDG 9: Industry, Innovation and Infrastructure, SDG 16: Peace, Justice and Strong Institutions, SDG 11: Sustainable Cities and Communities
Depositing User: Mr. Mohamad Syahrul Nizam Md Ishak
Date Deposited: 20 Aug 2026 07:41
Last Modified: 20 Aug 2026 07:41
Altmetrics: https://www.altmetric.com/details.php?domain=psasir.upm.edu.my&doi=10.1063/5.0257765
URI: http://psasir.upm.edu.my/id/eprint/127802
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item