Comparative Study of Learning Models for DDoS Traffic Detection Based on Network Flow Features
DOI: https://doi.org/10.62517/jbdc.202601308
Author(s)
Zuming Liang
Affiliation(s)
Communication Engineering, Nanjing University of Posts and Telecommunications, Nanjing, China
Abstract
The growing complexity of cyberattack behaviors has made network traffic classification a critical task in intelligent intrusion detection. This study investigates the adaptability of different learning architectures for Distributed Denial-of-Service (DDoS) traffic detection based on structured flow-level statistical features from the CIC-IDS2017 dataset. Three representative models, namely Multi-Layer Perceptron (MLP), Convolutional Neural Network-Long Short-Term Memory-Attention (CNN-LSTM-Attention), and Extreme Gradient Boosting (XGBoost), were implemented and evaluated under a consistent preprocessing and experimental protocol. Accuracy, Precision, Recall, F1-score, Receiver Operating Characteristic (ROC) curve, and Area Under the Curve (AUC) were used to compare overall detection performance and class-level behavior. Experimental results show that XGBoost achieved the best performance, with an accuracy of 0.9999 and an AUC of 1.0000. The MLP model also obtained highly competitive results, reaching an accuracy of 0.9997 and an AUC of 1.0000. In contrast, the CNN-LSTM-Attention model showed limited effectiveness, with an accuracy of 0.5752 and an AUC of 0.4956, because the structured statistical features did not provide meaningful temporal dependencies for sequence learning. These results indicate that model performance is strongly related to the compatibility between feature representation and learning mechanism. Under the current CIC-IDS2017 binary DDoS setting, tabular learning models such as XGBoost and MLP showed better suitability for structured flow-level features than the tested sequence-based architecture.
Keywords
Intrusion Detection System (IDS); Network Traffic Classification; Deep Learning; XGBoost; CNN-LSTM-Attention; Multi-Layer Perceptron (MLP); Structured Traffic Features; DDoS Traffic Detection
References
[1] J. Mirkovic and P. Reiher, “A taxonomy of DDoS attack and DDoS defense mechanisms,” ACM SIGCOMM Computer Communication Review, vol. 34, no. 2, pp. 39–53, 2004.
[2] A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: Techniques, datasets and challenges,” Cybersecurity, vol. 2, no. 1, pp. 1–22, 2019.
[3] N. Masri, Y. A. Sultan, A. N. Akkila, A. Almasri, A. Ahmed, A. Y. Mahmoud, I. Zaqout, and S. S. Abu-Naser, “Survey of Rule-Based Systems,” International Journal of Academic Information Systems Research (IJAISR), vol. 3, no. 7, pp. 1–22, 2019.
[4] H. Arif, A. K. S. Ali, and H. A. Nabi, “IoT Security through ML/DL: Software Engineering Challenges and Directions,” ICCK Journal of Software Engineering, vol. 1, no. 2, pp. 90–108, 2025.
[5] S. Rezaei and X. Liu, “Deep learning for encrypted traffic classification: An overview,” IEEE Communications Magazine, vol. 57, no. 5, pp. 76–81, 2019.
[6] A. Verma and V. Ranga, “Machine Learning based Intrusion Detection Systems for IoT Applications,” Wireless Personal Communications, vol. 111, no. 4, pp. 2287–2310, 2020.
[7] T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016, pp. 785–794.
[8] Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proceedings of the IEEE, vol. 86, no. 11, pp. 2278–2324, 1998.
[9] S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural Computation, vol. 9, no. 8, pp. 1735–1780, 1997.
[10] A. Vaswani et al., “Attention is all you need,” in Advances in Neural Information Processing Systems (NeurIPS), 2017, pp. 5998–6008.
[11] N. Wang and H. Kang, “An Enhanced Detection Method of Hardware Trojan Based on CNN-Attention-LSTM,” Computer Networks and Communications, vol. 2, no. 2, pp. 361–373, 2024.
[12] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. 4th Int. Conf. Information Systems Security and Privacy (ICISSP), 2018, pp. 108–116.