Skip to content
Conference

Development of an Intelligent DDoS Detection and Mitigation System using Router Log and Flow-based Traffic Analysis with Ensemble Machine Learning

Jul 2026 · 2026 International Conference on Intelligent and Sustainable AI Systems (ICOSAAS) · pp. 520-526 · 0 citations · 18 references

Abstract

The increasing frequency and advance of Distributed Denial of Service (DDoS) attacks have rendered traditional signature-based detection methods insufficient for protecting modern network infrastructures. This study presents the development of an intelligent DDoS detection and mitigation system that synergizes router log analysis with flow-based traffic monitoring using ensemble machine learning. The proposed system continuously captures and processes router Syslog data and network flow records in real time, extracts statistical features from both data sources, and applies a Hist Gradient Boosting Classifier model for attack classification. The model achieved 99.96% accuracy and 99.97% F1-score on the holdout test set, with only 14 false positives and 24 false negatives out of 86,274 test samples. The system architecture integrates a web-based dashboard providing real-time visualization of network traffic, attack alerts, and mitigation actions. Automated mitigation mechanisms including rate limiting, IP blacklisting, and Access Control List (ACL) updates are triggered upon attack confirmation. Evaluation using the CICDDoS2019 dataset demonstrates the system's effectiveness with high detection accuracy and low false-positive rates. The proposed system provides a scalable, cost-effective, and privacy-preserving solution suitable for deployment in ISP and enterprise networks without reliance on commercial DDoS mitigation appliances.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.