Cyber Attack Classification using a Multilayer Perceptron

Inna T. Kalakmabin, Irwan Sembiring

Abstract


The continued evolution of Distributed Denial-of-Service (DDoS) attacks poses a serious threat to network security. Numerous studies have employed machine learning and deep learning techniques for DDoS detection; however, most have focused on improving overall accuracy without adequately addressing the class imbalance characteristic of the CICDDoS2019 dataset. Moreover, the exploration of the Focal Loss function within a Multilayer Perceptron (MLP) architecture for multiclass classification remains limited. This study aims to develop an MLP-based cyberattack classification model using Focal Loss to address class imbalance. The research process includes data preprocessing, feature normalization, class weighting, and model training using two hidden layers with ReLU activation and a Softmax output layer. The model was evaluated using accuracy, precision, recall, F1-score, and confusion matrix analysis. The experimental results show that the MLP model achieved an accuracy of 98.80%, with a weighted F1-score of 0.99 and a macro F1-score of 0.87. Although Random Forest achieved a higher overall accuracy of 99.18%, the MLP model demonstrated competitive and stable performance in handling imbalanced data. This study provides preliminary evidence of the potential of an MLP model with Focal Loss for the development of a deep learning-based Intrusion Detection System (IDS), although further isolated testing is required.

Keywords


Cyber Attack Classification; Distributed Denial of Service; Focal Loss; Multilayer Perceptron; Network Intrusion Detection

Full Text:

PDF

References


A. Affinio et al., "The Evolution of Mirai Botnet Scans Over a Six-Year Period," Journal of Network and Computer Applications, Vol. 225, p. 103756, 2024.

S. Ahmed, Z. A. Khan, S. M. Mohsin, S. Latif, S. Aslam, H. Mujlid, and Z. Najam, "Effective and Efficient DDoS Attack Detection using Deep Learning Algorithm, Multi-Layer Perceptron," Future Internet, Vol. 15, No. 2, p. 76, 2023.

D. Akgun, S. Hizal, and U. Cavusoglu, "A New DDoS Attacks Intrusion Detection Model based on Deep Learning for Cybersecurity," Computers & Security, Vol. 118, p. 102746, 2022.

E. O. Nasution and A. Basuki, "Implementasi Algoritme C5.0 untuk Klasifikasi Serangan DDoS," Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer, Vol. 5, No. 1, pp. 389–395, 2021.

S. Mehmood et al., "Distributed Denial of Service (DDoS) Attack Detection in SDN using Optimizer-Equipped CNN-MLP," PLOS ONE, Vol. 20, No. 1, p. e0312425, 2025.

D. Kumar, R. K. Pateriya, R. K. Gupta, V. Dehalwar, and A. Sharma, "DDoS Detection using Deep Learning," Procedia Computer Science, Vol. 218, pp. 2420–2429, 2023.

W. Chimphlee and S. Chimphlee, "Network Intrusion Detector using Multilayer Perceptron (MLP) Approach," Turkish Journal of Computer and Mathematics Education, Vol. 13, No. 03, pp. 488–499, 2022.

Z. S. Arrak and R. J. S. Al-Janabi, "Detecting DDoS Attacks using Machine Learning: Survey," Journal of Al-Qadisiyah for Computer Science and Mathematics, Vol. 16, No. 2, pp. 118–134, 2024.

W. Priatna, H. D. Purnomo, A. Iriani, I. Sembiring, and T. Wellem, "Optimizing Multilayer Perceptron with Cost-Sensitive Learning for Addressing Class Imbalance in Credit Card Fraud Detection," Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi), Vol. 8, No. 4, pp. 563–570, 2024.

I. Maulana and A. Alamsyah, "Optimalisasi Deteksi Serangan DDoS menggunakan Algoritma Random Forest, SVM, KNN dan MLP pada Jaringan Komputer," Indonesian Journal of Mathematics and Natural Sciences, Vol. 46, No. 2, 2023.

P. Chang, "Multi-Layer Perceptron Neural Network for Improving Detection Performance of Malicious Phishing URLs without Affecting Other Attack Types Classification," arXiv preprint arXiv:2203.00774, 2022.

K.Saluja et al., "Exploring Robust DDoS Detection: A Machine Learning Analysis with the CICDDoS2019 Dataset," in Proc. IEEE INDISCON, 2024, pp. 1–6.

C. Singh et al., "A Comprehensive Survey on DDoS Attacks Detection & Mitigation," Computer Networks, Vol. 242, p. 110137, 2024.

F. A. Setiawan, A. S. Ahmad, and R. A. Asmara, "Handling Class Imbalance in Network Intrusion Detection Systems Using Focal Loss," Journal of Computer Science and Information Technology, Vol. 10, No. 1, pp. 45–54, 2023.

M. A. Setitra, M. Fan, B. L. Y. Agbley, and Z. E. A. Bensalem, "Optimized MLP-CNN Model to Enhance Detecting DDoS Attacks in SDN Environment," Network, Vol. 3, No. 4, pp. 538–562, 2023.




DOI: https://doi.org/10.32520/stmsi.v15i8.6529

Article Metrics

Abstract view : 0 times
PDF - 0 times

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.