To search, Click below search items.

 

All Published Papers Search Service

Title

An Explainable AI-Based Hybrid Framework for Botnet-Driven DDoS Attack Detection Using SHAP and Ensemble Learning

Author

Prof. Ruksar Fatima

Citation

Vol. 26  No. 7  pp. 1-17

Abstract

DDoS attacks performed through botnets constitute a significant threat to modern-day network systems. Such attacks aim at making the services available by sending huge volumes of malicious traffic which consumes bandwidth and resources and renders the services unavailable to individuals, businesses, or governments. While machine learning and deep learning have proven to be effective in identifying such types of cyber-attacks, most approaches are usually black-box techniques that hinder the work of cybersecurity experts. To remedy the situation, a new technique called SHAP-EnsembleIDS is proposed. It uses Explainable AI as a method of detecting botnet DDOS activities. In doing so, the method relies on multiple ensemble classifiers which include Random Forest, XGBoost, and Gradient Boosting. Preprocessing the data, normalizing features, and determining feature importance enhance representation of network traffic. Moreover, SHapley Additive exPlanations are included in the process to enable the provision of interpretable results showing the influence of traffic features on detection results. The methodology is applied to a publicly available benchmark dataset that includes legitimate and botnet-based DDoS traffic. The experiments carried out using the hybrid ensemble show that it has capabilities of distinguishing malicious traffic from normal ones. The comparative evaluation carried out using Accuracy, Precision, Recall, and F1 Score confirms the effectiveness of the framework. Therefore, it can be suggested that the proposed technique combining Ensemble Learning and SHAP is a viable approach for future intrusion detection systems.

Keywords

Botnet; Distributed Denial-of-Service Attack; Explainable Artificial Intelligence; SHAP; Ensemble Learning; Intrusion Detection System; Network Security; XGBoost; Random Forest.

URL

http://paper.ijcsns.org/07_book/202607/20260701.pdf