article
Distributed Denial-of-Service (DDoS) attacks pose a significant threat to network security. The need for Internet security has grown as a result of attackers having more opportunities to cause harm due to the rapid growth in Internet users over the past twenty years. In this study, we utilized Snort, a widely used network intrusion detection system, to capture and analyze network traffic, and Wazuh, a security information and event management system, to integrate the machine learning model and preventive mechanism script for active response. This study examined the effectiveness of integrating machine learning techniques and traditional signature-based approaches for real-world Network Intrusion Detection and Prevention Systems (NIDPS) applications in detecting and mitigating these attacks. The Random Forest model demonstrated exceptional performance on the prepared dataset, achieving an accuracy, recall, precision, and F1-score of around 99.99% with a training time of approximately 18.84 seconds. The system's integration with Snort and Wazuh allowed for consistent monitoring and analysis of network traffic, and the active response module enabled the system to make machine learning-based predictions and execute preventive measures in real-time. These results suggested the viability of utilizing machine learning, particularly Random Forest algorithms, for effective DDoS attack detection within Network Intrusion Detection and Prevention Systems (NIDPS) frameworks.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1109/nigercon62786.2024.10927195
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.