Research Article | Open Access | Download PDF
Volume 74 | Issue 7 | Year 2026 | Article Id. IJETT-V74I7P115 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I7P115Analyzing Class-Level Performance Variability in Multi-Class DDoS Detection: A Diagnostic Framework Based on XGBoost and Per-Attack Difficulty Scoring
Keano Nikko L. Sy, Patrick D. Cerna
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 06 Jan 2026 | 10 Feb 2026 | 18 Jun 2026 | 28 Jul 2026 |
Citation :
Keano Nikko L. Sy, Patrick D. Cerna, "Analyzing Class-Level Performance Variability in Multi-Class DDoS Detection: A Diagnostic Framework Based on XGBoost and Per-Attack Difficulty Scoring," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 7, pp. 217-229, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I7P115
Abstract
The DDoS attacks continue to be one of the most widespread menace to the modern network infrastructure, since they flood systems with harmful traffic and disabling of the valid services. Considering the continuously changing nature of the attack pattern, detection through a machine-learning method has been a mandatory requirement to observe the slight differences that are present between the different kinds of DDoS attacks. The paper trains and tests a multi-class XGBoost detection model on a mixed dataset with eleven different categories of DDoS attacks. Precision, Recall, F1 -score, ROC -like interpretations, Precision -Recall curves, confusion matrices, and computational efficiency metrics were used to evaluate the model. The results indicate that there is a high level of detectability variation among classes. High-performance attacks, including DrDoS NTP, TFTP, and DrDoS MSSQL, had almost perfect F1 -scores, which means that they were very separable and displayed consistent patterns of features. NetBIOS, SNMP, and Syn were moderate in their performance, with some overlap in the distributions of features. Classes with the worst performance of LDAP, SSDP, DrDoS UDP, DrDoS DNS, and UDPLag had more misclassification rates and difficulty scores, indicating complex or noisy traffic characteristics that do not help with accurate classification. The model was also found to be very computationally efficient, and inference times were fast enough to allow the model to be used in a real or near-real-time setting. These findings highlight the importance of using hybrid datasets and diagnostics of class-level performance to reveal variability of attack detection. The study concludes that XGBoost has strong flexibility in the accuracy, stability, and working efficiency in multi-class DDoS detection. The next improvements can include the addition of deep-learning frameworks, adversarial training, and real-time threat feeds, which can be used to enhance detection and other network defense against the most difficult types of attacks.
Keywords
XGBoost Classification, Multi-Class Intrusion Analysis, Network Security, Machine Learning.
References
[1] Donghwoon Kwon et al., “A Survey of
Deep Learning-based Network Anomaly Detection,” Cluster Computing, vol.
22, no. S1, pp. 949-961, 2017.
[CrossRef] [Google Scholar] [Publisher Link]
[2] Nazrul Hoque, Dhruba K.
Bhattacharyya, and Jugal K. Kalita, “Botnet in DDoS Attacks: Trends and
Challenges,” IEEE Communications Surveys and Tutorials, vol. 17, no. 4,
pp. 2242–2270, 2015.
[CrossRef] [Google Scholar] [Publisher Link]
[3] Iman Sharafaldin, Arash Habibi Lashkari,
and Ali A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and
Intrusion Traffic Characterization,” Proceedings of the 4th
International Conference on Information Systems Security and Privacy (ICISSP
2018), SCITEPRESS – Science and
Technology Publications,
vol. 1, pp. 108-116, 2018.
[CrossRef] [Google Scholar] [Publisher Link]
[4] Nour Moustafa, and Jill Slay, “The
Evaluation of Network Anomaly Detection Systems: Statistical Analysis of the
UNSW-NB15 Dataset,” Information Security Journal: A Global Perspective,
vol. 25, no. 1-3, pp. 18-31, 2016.
[CrossRef] [Google Scholar] [Publisher Link]
[5] Nickolaos Koroniotis et al., “Towards
the Development of Realistic Botnet Dataset in The Internet of Things for
Network Forensic Analytics: Bot-IoT Dataset,” Future Generation Computer
Systems, vol. 100, pp. 779-796, 2019.
[CrossRef] [Google Scholar] [Publisher Link]
[6] Rodrigo Braga, Edjard Mota, and Alexandre Passito,
“Lightweight DDoS Flooding Attack Detection using NOX/OpenFlow,” IEEE Local
Computer Network Conference, Denver, CO, USA, pp. 408-415, 2010.
[CrossRef] [Google Scholar] [Publisher Link]
[7] Kun Wang et al., “Detection and
Mitigation of DDoS Attacks based on Multi-Dimensional Characteristics in SDN,” Scientific
Reports, vol. 14, no. 1, pp. 1-19, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[8] Yuyang Zhou et al., “Building an
Efficient Intrusion Detection System based on Feature Selection and Ensemble
Classifier,” Computer Networks, vol. 174, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[9] Hardik Arya et al., “Adaptive Sliding
Window and LightGBM-based DDoS Attack Detection Framework for IoT Networks,” Peer-to-Peer
Networking and Applications, vol. 19, no. 1, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[10] Amal
M. Al-Eryani, Fatma A. Omara, and Eman Hossny, “A Deep Learning GRU-BiLSTM for
DDoS Attack Detection,” SN Computer Science, vol. 6, no. 6, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[11] Ameur
Salem Zaidoun, and Zied Lachiri, “A Hybrid Deep Learning Model for Multi-Class
DDoS Detection in SDN Networks,” Annals of Telecommunications, vol. 80,
no. 5-6, pp. 459-472, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[12] S.
Pradeesh, M. Jeyakarthic, and A. Thirumalairaj, “Enhanced Hybrid Approach for
Multi-Class DDoS Attack Detection and Classification in Software-Defined
Networks using Remote Sensing and Data Analytics,” Remote Sensing in Earth
Systems Sciences, vol. 8, no. 2, pp. 530-544, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[13] Hakan
Aydin, and Muhammed Ali Aydin, “A Multi-Agent-based DdoS Detection and Defense
System Design with Federated Learning and Blockchain in Public Cloud Network
Environment,” Cluster Computing, vol. 28, no. 16, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[14] Qasem
Abu Al-Haija, and Ayat Droos, “Resilient Intrusion Detection System for
Adversarial Attacks on Low-Rate DDoS,” International Journal of Machine Learning
and Cybernetics, vol. 16, no. 10, pp. 8473-8502, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[15] Rohan
Doshi, Noah Apthorpe, and Nick Feamster, “Machine Learning DDoS Detection for
Consumer Internet of Things Devices,” 2018 IEEE Security and Privacy
Workshops (SPW), San Francisco, CA, USA, pp. 29-35, 2018.
[CrossRef] [Google Scholar] [Publisher Link]
[16] Mohamed
Amine Ferrag et al., “Deep Learning for Cyber Security Intrusion Detection:
Approaches, Datasets, and Comparative Study,” Journal of Information
Security and Applications, vol. 50, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[17] Markus
Ring et al., “A Survey of Network-based Intrusion Detection Data Sets,” Computers
and Security, vol. 86, pp. 147-167, 2019.
[CrossRef] [Google Scholar] [Publisher Link]
[18] Nour
Moustafa, and Jill Slay, “UNSW-NB15: A Comprehensive Data Set for Network
Intrusion Detection Systems (UNSW-NB15 Network Data Set),” 2015 Military
Communications and Information Systems Conference (MilCIS), Canberra, ACT,
Australia, pp. 1-6, 2015.
[CrossRef] [Google Scholar] [Publisher Link]
[19] Nathan
Shone et al., “A Deep Learning Approach to Network Intrusion Detection,” IEEE
Transactions on Emerging Topics in Computational Intelligence, vol. 2, no.
1, pp. 41-50, 2018.
[CrossRef] [Google Scholar] [Publisher Link]
[20] Preeti
Mishra et al., “A Detailed Investigation and Analysis of using Machine Learning
Techniques for Intrusion Detection,” IEEE Communications Surveys and
Tutorials, vol. 21, no. 1, pp. 68-728, 2019.
[CrossRef] [Google Scholar] [Publisher Link]
[21] Anna
L. Buczak, and Erhan Guven, “A Survey of Data Mining and Machine Learning
Methods for Cyber Security Intrusion Detection,” IEEE Communications Surveys
and Tutorials, vol. 18, no. 2, pp. 1153-1176, 2016.
[CrossRef] [Google Scholar] [Publisher Link]
[22] Amardeep
Kumar, Danish Ali Khan, and Ruhul Amin, “Detecting Application Layer DDoS
Attacks with RSPF: A Hybrid Ensemble Learning Approach,” Cluster Computing,
vol. 28, no. 15, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[23] Naziya
Aslam, Shashank Srivastava, and M.M. Gore, “ONOS DDoS Defender: A Comparative
Analysis of Existing DDoS Attack Datasets using Ensemble Approach,” Wireless
Personal Communications, vol. 133, no. 3, pp. 1805-1827, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[24] Min-Joo
Kang, and Je-Won Kang, “Intrusion Detection System using Deep Neural Network
for in-Vehicle Network Security,” PLOS ONE, vol. 11, no. 6, pp. 1-17,
2016.
[CrossRef] [Google Scholar] [Publisher Link]
[25] Razan Abdulhammed et al., “Features
Dimensionality Reduction Approaches for Machine Learning-based Network
Intrusion Detection,” Electronics, vol. 8, no. 3, pp. 1-27, 2019.
[CrossRef] [Google
Scholar] [Publisher
Link]