Minimal Feature Ensemble Learning
Open Access DepositedA Multi-Agent Consensus Approach to Efficient Binary DDoS Detection
secondly to identify if the production environment can maintain low false positive rates, while minimizing the number of false alarms that disrupt legitimate traffic and add cost to operations. The CIC-DDoS2019 dataset presents several challenges offering opportunity to evaluate the robustness of consensus approaches in challenging conditions, including the extreme class imbalance (110
Distributed Denial-of-Service (DDoS) attacks continue to cause significant network performance issues. Although machine learning detection Systems achieve very high accuracy in detecting these attacks, they face a fundamental trade-off
high accuracy requires processing large numbers of features, which limits response time and network protection capabilities. This praxis examines if multiple agents, utilizing different algorithms and processing smaller independent subsets of features, will provide comparable performance to single classifier approaches while reducing the computational overhead. This research employs the CIC-DDoS2019 dataset to train three agents
CatBoost (Categorical Boosting), XGBoost (Extreme Gradient Boosting), and Gradient Boosting. Each agent works on about 25 features that were chosen using different importance metrics. A majority consensus vote decides the predictions. The Random Forest baseline trained on the full feature set was used as a basis for comparison. There are two primary objectives of this investigation
first to determine if the multi-agent system can provide baseline equivalent accuracy, utilizing fewer than 40% of the original number of features
1 attack to benign ratio), and the possibility of distribution vi shifts between the training and testing data. A key gap in the current body of literature is that most DDoS detection studies focus solely on optimizing the Benchmark Accuracy for DDoS detection systems, without addressing the ability to deploy such systems in resource constrained environments at the network edge. Using minimal feature sets, distributed agent architectures, and algorithmic diversity, this praxis will examine if it is possible to achieve both efficiency and reliability in DDoS Detection Systems without sacrificing one objective for the other.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.