Aug 2026· Journal of Computer Science Application and Engineering (JOSAPEN)· 0 citations· 26 references
TL;DR
This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation, indicating that offline benchmarks alone are insufficient for validating IDS readiness.
Abstract
Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation. The study combines offline benchmarking on the CIC-DDoS2019 dataset (293,485 flows) with physical-network validation using a working Intrusion Detection System (IDS) prototype under a controlled SYN-flood attack. Session-disjoint stratified sampling prevented flow-level leakage across attack sessions, while SHapley Additive exPlanations (SHAP) interpreted global and local feature importance. Offline, both classifiers achieved near-perfect performance (accuracy 99.99% for XGBoost, 99.98% for Random Forest; F1 = 0.9999; ROC-AUC up to 1.0000), with no statistically significant difference between them (McNemar's exact test, p = 0.2188), though XGBoost achieved approximately 3.69 times higher inference throughput (1,819,816 flows/s). SHAP identified Min Packet Length, Fwd Packet Length Min, Inbound, Protocol, and Init_Win_bytes_forward as the most influential features. In physical deployment, however, the IDS prototype flagged 6.26% of captured flows (6,935 of 110,762) as ATTACK during the SYN-flood test, and a separate 397-flow ambient-benign subset yielded a 6.80% false positive rate (95% Wilson CI: 4.72–9.71%), with short-duration SSDP/UPnP-style UDP control traffic accounting for 70% of observed false positives. This gap shows that near-perfect offline accuracy does not guarantee low false positives in real deployment, indicating that offline benchmarks alone are insufficient for validating IDS readiness.
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.
J. Malik, N. Naz, Muhammad Saleem et al.· Italian National Conference...· 0 citations
Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...
Kamal Singh, Brijesh Kumar· international journal of eng...· 0 citations
An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.
Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al.· Journal of Computer Virology...· 0 citations
Machine learning-based Network Intrusion Detection Systems often report near-perfect performance on IoT benchmarks. However, whether these models learn generalizable attack behavior or exploit spurious dataset shortcuts- such as static testbed IP/MAC addresses and chronological recording artifacts-remains an important...
This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space.