International Journal of Engineering
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 7 | Year 2026 | Article Id. IJETT-V74I7P115 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I7P115

Analyzing Class-Level Performance Variability in Multi-Class DDoS Detection: A Diagnostic Framework Based on XGBoost and Per-Attack Difficulty Scoring


Keano Nikko L. Sy, Patrick D. Cerna

Received Revised Accepted Published
06 Jan 2026 10 Feb 2026 18 Jun 2026 28 Jul 2026

Citation :

Keano Nikko L. Sy, Patrick D. Cerna, "Analyzing Class-Level Performance Variability in Multi-Class DDoS Detection: A Diagnostic Framework Based on XGBoost and Per-Attack Difficulty Scoring," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 7, pp. 217-229, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I7P115

Abstract

The DDoS attacks continue to be one of the most widespread menace to the modern network infrastructure, since they flood systems with harmful traffic and disabling of the valid services. Considering the continuously changing nature of the attack pattern, detection through a machine-learning method has been a mandatory requirement to observe the slight differences that are present between the different kinds of DDoS attacks. The paper trains and tests a multi-class XGBoost detection model on a mixed dataset with eleven different categories of DDoS attacks. Precision, Recall, F1 -score, ROC -like interpretations, Precision -Recall curves, confusion matrices, and computational efficiency metrics were used to evaluate the model. The results indicate that there is a high level of detectability variation among classes. High-performance attacks, including DrDoS NTP, TFTP, and DrDoS MSSQL, had almost perfect F1 -scores, which means that they were very separable and displayed consistent patterns of features. NetBIOS, SNMP, and Syn were moderate in their performance, with some overlap in the distributions of features. Classes with the worst performance of LDAP, SSDP, DrDoS UDP, DrDoS DNS, and UDPLag had more misclassification rates and difficulty scores, indicating complex or noisy traffic characteristics that do not help with accurate classification. The model was also found to be very computationally efficient, and inference times were fast enough to allow the model to be used in a real or near-real-time setting. These findings highlight the importance of using hybrid datasets and diagnostics of class-level performance to reveal variability of attack detection. The study concludes that XGBoost has strong flexibility in the accuracy, stability, and working efficiency in multi-class DDoS detection. The next improvements can include the addition of deep-learning frameworks, adversarial training, and real-time threat feeds, which can be used to enhance detection and other network defense against the most difficult types of attacks.

Keywords

XGBoost Classification, Multi-Class Intrusion Analysis, Network Security, Machine Learning.

References

[1] Donghwoon Kwon et al., “A Survey of Deep Learning-based Network Anomaly Detection,” Cluster Computing, vol. 22, no. S1, pp. 949-961, 2017.
[CrossRef] [Google Scholar] [Publisher Link]   

[2] Nazrul Hoque, Dhruba K. Bhattacharyya, and Jugal K. Kalita, “Botnet in DDoS Attacks: Trends and Challenges,” IEEE Communications Surveys and Tutorials, vol. 17, no. 4, pp. 2242–2270, 2015.
[CrossRef] [Google Scholar] [Publisher Link]   

[3] Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization,” Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), SCITEPRESS – Science and Technology Publications, vol. 1, pp. 108-116, 2018.
[CrossRef] [Google Scholar] [Publisher Link]   

[4] Nour Moustafa, and Jill Slay, “The Evaluation of Network Anomaly Detection Systems: Statistical Analysis of the UNSW-NB15 Dataset,” Information Security Journal: A Global Perspective, vol. 25, no. 1-3, pp. 18-31, 2016.
[CrossRef] [Google Scholar] [Publisher Link]

[5] Nickolaos Koroniotis et al., “Towards the Development of Realistic Botnet Dataset in The Internet of Things for Network Forensic Analytics: Bot-IoT Dataset,” Future Generation Computer Systems, vol. 100, pp. 779-796, 2019.
[CrossRef] [Google Scholar] [Publisher Link]   

[6] Rodrigo Braga, Edjard Mota, and Alexandre Passito, “Lightweight DDoS Flooding Attack Detection using NOX/OpenFlow,” IEEE Local Computer Network Conference, Denver, CO, USA, pp. 408-415, 2010.
[
CrossRef] [Google Scholar] [Publisher Link]   

[7] Kun Wang et al., “Detection and Mitigation of DDoS Attacks based on Multi-Dimensional Characteristics in SDN,” Scientific Reports, vol. 14, no. 1, pp. 1-19, 2024.
[CrossRef] [Google Scholar] [Publisher Link]   

[8] Yuyang Zhou et al., “Building an Efficient Intrusion Detection System based on Feature Selection and Ensemble Classifier,” Computer Networks, vol. 174, 2020.
[CrossRef] [Google Scholar] [Publisher Link]   

[9] Hardik Arya et al., “Adaptive Sliding Window and LightGBM-based DDoS Attack Detection Framework for IoT Networks,” Peer-to-Peer Networking and Applications, vol. 19, no. 1, 2025.
[CrossRef] [Google Scholar] [Publisher Link]   

[10] Amal M. Al-Eryani, Fatma A. Omara, and Eman Hossny, “A Deep Learning GRU-BiLSTM for DDoS Attack Detection,” SN Computer Science, vol. 6, no. 6, 2025.
[CrossRef] [Google Scholar] [Publisher Link]   

[11] Ameur Salem Zaidoun, and Zied Lachiri, “A Hybrid Deep Learning Model for Multi-Class DDoS Detection in SDN Networks,” Annals of Telecommunications, vol. 80, no. 5-6, pp. 459-472, 2025.
[CrossRef] [Google Scholar] [Publisher Link]   

[12] S. Pradeesh, M. Jeyakarthic, and A. Thirumalairaj, “Enhanced Hybrid Approach for Multi-Class DDoS Attack Detection and Classification in Software-Defined Networks using Remote Sensing and Data Analytics,” Remote Sensing in Earth Systems Sciences, vol. 8, no. 2, pp. 530-544, 2025.
[CrossRef] [Google Scholar] [Publisher Link]   

[13] Hakan Aydin, and Muhammed Ali Aydin, “A Multi-Agent-based DdoS Detection and Defense System Design with Federated Learning and Blockchain in Public Cloud Network Environment,” Cluster Computing, vol. 28, no. 16, 2025.
[CrossRef] [Google Scholar] [Publisher Link]   

[14] Qasem Abu Al-Haija, and Ayat Droos, “Resilient Intrusion Detection System for Adversarial Attacks on Low-Rate DDoS,” International Journal of Machine Learning and Cybernetics, vol. 16, no. 10, pp. 8473-8502, 2025.
[CrossRef] [Google Scholar] [Publisher Link]   

[15] Rohan Doshi, Noah Apthorpe, and Nick Feamster, “Machine Learning DDoS Detection for Consumer Internet of Things Devices,” 2018 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, pp. 29-35, 2018.
[CrossRef] [Google Scholar] [Publisher Link]   

[16] Mohamed Amine Ferrag et al., “Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study,” Journal of Information Security and Applications, vol. 50, 2020.
[CrossRef] [Google Scholar] [Publisher Link]

[17] Markus Ring et al., “A Survey of Network-based Intrusion Detection Data Sets,” Computers and Security, vol. 86, pp. 147-167, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[18] Nour Moustafa, and Jill Slay, “UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems (UNSW-NB15 Network Data Set),” 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia, pp. 1-6, 2015.
[CrossRef] [Google Scholar] [Publisher Link]

[19] Nathan Shone et al., “A Deep Learning Approach to Network Intrusion Detection,” IEEE Transactions on Emerging Topics in Computational Intelligence, vol. 2, no. 1, pp. 41-50, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[20] Preeti Mishra et al., “A Detailed Investigation and Analysis of using Machine Learning Techniques for Intrusion Detection,” IEEE Communications Surveys and Tutorials, vol. 21, no. 1, pp. 68-728, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[21] Anna L. Buczak, and Erhan Guven, “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection,” IEEE Communications Surveys and Tutorials, vol. 18, no. 2, pp. 1153-1176, 2016.
[CrossRef] [Google Scholar] [Publisher Link]

[22] Amardeep Kumar, Danish Ali Khan, and Ruhul Amin, “Detecting Application Layer DDoS Attacks with RSPF: A Hybrid Ensemble Learning Approach,” Cluster Computing, vol. 28, no. 15, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[23] Naziya Aslam, Shashank Srivastava, and M.M. Gore, “ONOS DDoS Defender: A Comparative Analysis of Existing DDoS Attack Datasets using Ensemble Approach,” Wireless Personal Communications, vol. 133, no. 3, pp. 1805-1827, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[24] Min-Joo Kang, and Je-Won Kang, “Intrusion Detection System using Deep Neural Network for in-Vehicle Network Security,” PLOS ONE, vol. 11, no. 6, pp. 1-17, 2016.
[CrossRef] [Google Scholar] [Publisher Link]

[25] Razan Abdulhammed et al., “Features Dimensionality Reduction Approaches for Machine Learning-based Network Intrusion Detection,” Electronics, vol. 8, no. 3, pp. 1-27, 2019.
[CrossRef] [Google Scholar] [Publisher Link]