Performance Evaluation of Feature-Selection-Based Support Vector Machine Kernels for Real-Time DDoS Attack Detection via Orange3 Platform
DOI:
https://doi.org/10.65417/ljcas.v4i2.401Keywords:
Cybersecurity, DDoS attacks, Support Vector Machine (SVM), Feature selection, Information Gain Ratio (IGR), Orange3 platformAbstract
Distributed Denial-of-Service (DDoS) attacks severely threaten network stability. Early detection remains challenging due to massive traffic volumes that slow down algorithms and induce bias. This study evaluates Support Vector Machine (SVM) performance by comparing four kernels (Linear, RBF, Polynomial, and Sigmoid) and investigating feature filtering techniques to enhance classification efficiency. Employing a comparative experimental approach via the Orange3 visual programming environment, the methodology utilizes two standard datasets: CICDDoS2019 and CICDoS2017. These datasets were processed using balanced random sampling alongside two feature selection techniques: Information Gain (IG) and Information Gain Ratio (IGR). The results revealed sharp behavioral discrepancies between the datasets. For the CICDDoS2019 cohort, the IGR Sigmoid SVM model emerged as the top performer, achieving a Classification Accuracy (CA) of 90.1%, an F1-score of 89.2%, and excellent AUC stability at 90.8%. Conversely, hidden bias caused the RBF kernel's AUC curve to plunge to 1.8%. For the CICDoS2017 cohort, accuracy sharply declined, capping at 42.2% due to the algorithm's susceptibility to competitive noise from outdated data and crosstalk attacks. The study recommends integrating IGR as a mandatory preprocessing step for dimensionality reduction and cautions against relying solely on CA without AUC correlation. It advises avoiding traditional kernels like RBF in imbalanced environments and explores hybrid models for complex datasets like CICDoS2017.
