Abstract
DDoS is a predominant threat to the reliability of online services and is frequently experienced by service providers worldwide. An effective DDoS classification mechanism is essential to prevent resource outages caused by such attacks. However, relatively few studies utilize up-to-date datasets that reflect recent DDoS attack patterns. Furthermore, existing solutions often require high processing capacity for model training and prediction. The main objective of this study is to verify the generalizability of relevant and significant features extracted from large-scale network traffic to enhance DDoS attack detection. In this paper, we present a universal machine learning approach for DDoS attack detection based on a universal feature set. In this approach, we apply both an over-sampling method (SMOTE) and an under-sampling method (NearMiss) to produce balanced and variably sized samples. We then implement the following machine learning algorithms using minimal universal feature subsets: Complement Naïve Bayes (CNB), k-Nearest Neighbor (KNN), Random Forest (RF), and Logistic Regression (LR). Moreover, we analyze and evaluate a universal feature set and several minimal universal feature subsets. The models are trained and tested using modern, reliable datasets, namely the CIC-DDoS2019, SDN-DDoS Traffic, CIC-IoT 2023, and VeReMi datasets. The results demonstrate that the universal features set delivered suboptimal performance not only in a Software-Defined Networking (SDN) environment but also in a Vehicular Ad-hoc Network (VANET) context, thereby confirming its limited generalizability. Its efficacy was, in fact, confined to the Internet of Things (IoT) environment, where the Random Forest algorithm achieved superior results across all performance metrics. Although this study offers a constrained methodological contribution, it experimentally identifies a critical shortcoming affecting model performance stability: a strong linear correlation between two features within the universal features set.
Author supplied keywords
Cite
CITATION STYLE
Ebrahem, O., Dowaji, S., & Alhammoud, S. (2026). On the Limited Generalizability of a Universal Features Set for DDoS Detection Across Network Environments. IEEE Access, 14, 7932–7974. https://doi.org/10.1109/ACCESS.2026.3653648
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.