MARATTO

article · Egyptian Informatics Journal

Machine learning-based detection of DDoS attacks on IoT devices in multi-energy systems

In plain language

The growing reliance on connected Internet of Things devices within critical infrastructure creates major cybersecurity risks, particularly Distributed Denial of Service attacks directed at energy hubs. To counter these threats, multiple supervised machine learning algorithms were assessed for their ability to predict incoming attacks. Testing was carried out using the benchmark CICDDOS2019 and KDD-CUP datasets across several classifiers, including Decision Tree, Gradient Boosting, Support Vector Machine, K-Nearest Neighbors, and Random Forest, alongside hybrid combinations. Gradient Boosting emerged as the most effective algorithm, achieving superior accuracy and predictive capabilities, especially on the CICDDOS2019 dataset. Hybrid pairings of Gradient Boosting with either Support Vector Machine or Decision Tree also demonstrated strong detection capabilities, although their precision and recall varied. The findings offer guidance on choosing and tailoring machine learning models to strengthen the resilience of energy infrastructure against evolving digital threats.

Key takeaways

  • Gradient Boosting achieved the highest accuracy and predictive performance among evaluated models in detecting attacks on the CICDDOS2019 dataset.
  • Hybrid models combining Gradient Boosting with Decision Trees or Support Vector Machines showed strong overall performance, though precision and recall varied.
  • The tested classifiers, including Random Forest, K-Nearest Neighbors, and Decision Trees, provide comparative insights for tailoring security models to energy hub environments.

Why it matters

Energy hubs rely heavily on connected devices to coordinate power systems, leaving essential infrastructure vulnerable to disruptive cyberattacks. Identifying reliable algorithmic tools to detect digital assaults allows network operators to recognise threats early, protecting vital services from shutdowns caused by malicious network traffic.

Commercialisation angle

This research could support developers of cybersecurity software and operators of energy hub infrastructure seeking automated intrusion detection tools. Because the evaluation relied strictly on benchmark datasets such as CICDDOS2019 and KDD-CUP rather than active physical deployments, the technology sits at an applied testing stage and requires live operational trials before direct commercial implementation.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

With the growing integration of IoT devices in critical infrastructure, cybersecurity threats such as Distributed Denial of Service (DDoS) attacks on Energy Hubs (EH) have become a significant concern. This study aims to address these challenges by evaluating the effectiveness of various supervised machine learning (ML) algorithms in predicting DDoS attacks targeting EH systems through IoT devices. Using the CICDDOS2019 and KDD-CUP datasets, a comprehensive analysis was conducted on several classifiers, including Decision Tree (DT), Gradient Boosting, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), and Random Forest. The results highlight Gradient Boosting as the most effective model, particularly for the CICDDOS2019 dataset, demonstrating superior accuracy and predictive capability. Additionally, hybrid models combining Gradient Boosting with SVM or DT showed strong performance, though with varying precision and recall. This study provides valuable insights into the selection and tailoring of ML models for specific security challenges, emphasizing the need for ongoing research to enhance the resilience of EH systems and IoT devices against evolving DDoS threats.

Research topics

  • Smart Grid Security and Resilience
  • Advanced Data Processing Techniques
  • Integrated Energy Systems Optimization

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1016/j.eij.2024.100540

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.