Electronic Thesis/Dissertation
 

Using Machine Learning to Detect and Mitigate IoT-based DDoS Attacks in Home Networks

Open Access Deposited

The field of Internet of Things (IoT) devices is expanding rapidly. Similarly, the exploitation of IoT devices is growing exponentially. Armies of infected IoT devices are being weaponized daily to launch Distributed Denial of Service (DDoS) cyberattacks against various organizations and online resources costing companies billions of dollars annually. This praxis presents a novel approach to mitigate IoT-based DDoS attacks using machine learning by detecting and blocking attacks at the source, thereby preventing network propagation and dispersing the attack before it starts to shape.This praxis utilizes three datasets (ACI-IoT-2023, CIC-Bot-IoT, and CIC-IDS-2017) that contain traffic from physical IoT devices and consist of millions of packets of benign and malicious traffic covering various attack vectors for model training. The praxis utilizes two additional datasets (Unicauca-Version2 and ITC-Net-Audio-5) to test the accuracy of the model against unseen real-user traffic. The features selected from the datasets directly align with the record structure of NetFlow, a widely popular network-monitoring protocol utilized by major Internet Service Providers (ISPs). This alignment facilitates easy deployment and streamlines applications in the field. The praxis evaluates various machine-learning models to identify the best performance, with eXtreme Gradient Boosting achieving an accuracy of 99.99%, total training time of 0.26 seconds, and average classification time of 288 nanoseconds. The research revealed that the selected features (Flow Duration, Source Port, Destination Port, Protocol, Average Packet Size, Bytes/s, Packets/s, Transmission Control Protocol (TCP) Flags) are superior to those of various other datasets and machine-learning algorithms. When the trained models were tested on unseen datasets with real-user traffic, they achieved 100% precision across all dataset combinations with 0% false DDoS detections. The differentiated positioning of the proposed approach, high level of accuracy of the generated machine-learning model, extremely short model-training and classification time, and ease of implementation in the field owing to compatibility with existing network-monitoring protocols produce an unparalleled solution to effectively detect and mitigate DDoS attacks.

Author Language Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Mheish_gwu_0075A_17117.pdf Mheish_gwu_0075A_17117.pdf 2025-04-09 Open Access