Comparative Analysis Of Support Vector Machine Kernels For DDOS Attack Detection: A Study Of Classification Performance And Computational Efficiency In Network Traffic
DOI:
https://doi.org/10.54082/jiki.368Keywords:
CICIDS2017, DDoS Detection, Intrusion Detection System, Machine Learning, Support Vector MachineAbstract
Distributed Denial of Service (DDoS) attacks remain one of the most significant cybersecurity threats because they disrupt network services, degrade performance, and cause financial losses. Machine-learning-based intrusion detection systems have become a promising solution for automatically identifying malicious traffic. This study aims to compare the classification performance and computational efficiency of three Support Vector Machine (SVM) kernels: Linear, Polynomial, and Radial Basis Function (RBF). The experiment used 225,745 network traffic records consisting of 97,718 BENIGN flows and 128,027 DDoS flows extracted from the CICIDS2017 Friday-WorkingHours-Afternoon-DDoS subset. Data preprocessing included data cleaning, label encoding, feature selection, feature scaling using StandardScaler, and an 80:20 train-test split. The models were evaluated using Accuracy, Precision, Recall, F1-Score, Area Under the Curve (AUC), training time, and testing latency. Experimental results show that the RBF kernel achieved the best classification performance with 98.89% accuracy, 98.90% precision, 98.90% recall, 98.80% F1-score, and an AUC of 0.99. In contrast, the Linear kernel achieved the fastest computational performance with the lowest training and testing time. The novelty of this study lies in providing a kernel-level optimization analysis that simultaneously evaluates detection accuracy and computational efficiency, demonstrating that optimized traditional SVM models remain relevant for lightweight and real-time intrusion detection despite the increasing adoption of deep learning approaches.
References
A. Sanmorino, R. Gustriansyah, and J. Alie, “DDoS Attacks Detection Method Using Feature Importance and Support Vector Machine,” JUITA: Jurnal Informatika, vol. 10, no. 2, pp. 167–171, 2022, doi: 10.30595/juita.v10i2.14023.
R. I. Perwira and H. Prapcoyo, “Software Defined Network: The Comparison of SVM kernel on DDoS Detection,” RSF Conference Series: Engineering and Technology, vol. 1, no. 1, pp. 281–290, 2021, doi: 10.31098/cset.v1i1.413.
S. Berríos, S. Garcia, P. Hermosilla, and H. Allende-Cid, “A machine-learning-based approach for the detection and mitigation of distributed denial-of-service attacks in Internet of Things environments,” Applied Sciences, vol. 15, no. 11, p. 6012, 2025, doi: 10.3390/app15116012.
A. Hirsi, “Comprehensive analysis of DDoS anomaly detection in software-defined networks,” IEEE Access, vol. 13, no. 1, pp. 23013–23071, 2025, doi: 10.1109/ACCESS.2025.3535943.
W. Zhang, “A Survey on Network Security Traffic Analysis and Anomaly Detection Techniques,” International Journal of Emerging Technologies and Advanced Applications, vol. 1, no. 4, pp. 8–16, 2024, doi: 10.62677/IJETAA.2404117.
J. Zhao, Y. Liu, Q. Zhang, and X. Zheng, “CNN-AttBiLSTM mechanism: A DDoS attack detection method based on attention mechanism and CNN-BiLSTM,” IEEE Access, vol. 11, no. 1, pp. 136308–136317, 2023, doi: 10.1109/ACCESS.2023.3334916.
A. S. Zaidoun and Z. Lachiri, “A hybrid deep learning model for multi-class DDoS detection in SDN networks,” Annals of Telecommunications, vol. 80, pp. 459–472, 2025, doi: 10.1007/s12243-025-01085-1.
M. S. Sawah, “Distributed denial of service (DDoS) classification based on random forest model with backward elimination algorithm and grid search algorithm,” Sci. Rep., vol. 15, no. 1, p. 19063, 2025, doi: 10.1038/s41598-025-03868-x.
U. B. Clinton, N. Hoque, and K. R. Singh, “Classification of DDoS attack traffic on SDN network environment using deep learning,” Cybersecurity, vol. 7, no. 1, p. 23, 2024, doi: 10.1186/s42400-024-00219-7.
N. Albanbay, “Federated Learning-Based Intrusion Detection in IoT Networks: Performance Evaluation and Data Scaling Study,” Journal of Sensor and Actuator Networks (JSAN), vol. 14, no. 4, p. 78, 2025, doi: 10.3390/jsan14040078.
A. A. Bahashwan, M. Anbar, S. Manickam, T. A. Al-Amiedy, M. A. Aladaileh, and I. H. Hasbullah, “A Systematic Literature Review on Machine Learning and Deep Learning Approaches for Detecting DDoS Attacks in Software-Defined Networking,” Sensors, vol. 23, no. 9, p. 4441, 2023, doi: 10.3390/s23094441.
S. Ganeshan and R. K. Ramasamy, “A Systematic Review of Machine-Learning-Based Detection of DDoS Attacks in Software-Defined Networks,” Future Internet, vol. 16, no. 2, p. 109, 2026, doi: 10.3390/fi18020109.
Tasmi et al., “Pengenalan Pola Serangan pada Internet of Thing (IoT) Menggunakan Support Vector Machine (SVM) dengan Tiga Kernel,” Jurnal PROCESSOR, vol. 18, no. 2, pp. 241–251, 2023, doi: 10.33998/processor.2023.18.2.1457.
S. Abiramasundari and V. Ramaswamy, “Distributed Denial-of-Service (DDoS) attack detection using supervised machine learning algorithms,” Sci. Rep., vol. 15, no. 1, p. 13098, 2025, doi: 10.1038/s41598-024-84879-y.
A. Alabdulatif, N. N. Thilakarathne, and M. Aashiq, “Machine Learning Enabled Novel Real-Time IoT Targeted DoS/DDoS Cyber Attack Detection System,” Computers, Materials & Continua, vol. 79, no. 2, pp. 312–330, 2024, doi: 10.32604/cmc.2024.054610.
A. Dembele, E. Mwangi, K. K. Ronoh, and E. O. Ataro, “A Novel Approach for Detection of DDoS Attacks in Software-Defined Networks Based on Grey Wolf Optimizer and Support Vector Machine,” SSRG International Journal of Electrical and Electronics Engineering, vol. 11, no. 3, pp. 86–96, 2024, doi: 10.14445/23488379/IJEEE-V11I3P107.
S. Ginta, P. Hia, N. Hayati, D. Hindarto, and A. Sani, “Blockchain and SVM Integration for Distributed DDoS Attack Detection,” Sinkron : Jurnal dan Penelitian Teknik Informatika, vol. 10, no. 1, pp. 75–84, 2026, doi: 10.33395/sinkron.v10i1.15483.
F. Musumeci, “Machine-Learning-Enabled DDoS Attacks Detection in P4 Programmable Networks,” Journal of Network and Systems Management, vol. 30, no. 1, pp. 1–27, 2022, doi: 10.1007/s10922-021-09633-5.
A. A. Alhussain and B. S. Alsulami, “DDoS Detection by Using Machine Learning,” Journal of Information Systems Engineering and Management, vol. 10, no. 54s, 2025, doi: 10.52783/jisem.v10i54s.11045.
S. Rasheed and M. S. Rathore, “Support Vector Machine Based DDoS Detection and Mitigation in Software Defined Networks,” Journal of Innovative Computing and Emerging Technologies, vol. 4, no. 2, pp. 54–68, 2024, doi: https://doi.org/10.56536/jicet.v4i2.161.
A. A. Alsadhan, “Kernel-based machine learning intrusion detection for IPv6 ICMPv6 DDoS attacks,” Array, vol. 26, p. 100389, 2025, doi: 10.1016/j.array.2025.100389.
F. Ferdiansyah, D. Antoni, M. Valdo, C. Mukmin, and U. Ependi, “Machine Learning Models for DDoS Detection in Software-Defined Networking: A Comparative Analysis,” Journal of Informatics Engineering, vol. 6, no. 3, pp. 1790–1803, 2024, doi: 10.51519/journalisi.v6i3.864.
Y. Irawan, R. Pramitasari, W. M. Ashari, A. Nur, and H. Yansyah, “Support Vector Machine Classification Algorithm for Detecting DDoS Attacks on Network Traffic,” Journal of Applied Informatics and Computing (JAIC), vol. 9, no. 4, pp. 1945–1954, 2025, doi: 10.30871/jaic.v9i4.10003.
M. S. Sawah, H. Elmannai, A. A. El-Bary, and K. Lotfy, “Traffic Feature Selection and Distributed Denial of Service Attack Detection Using Machine Learning Techniques,” Sci. Rep., vol. 14, no. 1, p. 16021, 2024, doi: 10.1038/s41598-024-66634-6.
A. L. Hadiyani and B. Handaga, “Implementasi Sistem Deteksi Anomali Berbasis Jaringan Menggunakan CNN dan SVM untuk Klasifikasi Data Secara Real-Time,” Jurnal Informatika Universitas Pamulang, vol. 10, no. 2, pp. 75–85, 2025, doi: 10.32493/jiup.v10i2.52163.
Haeruddin, Erick, and H. W. Aripradono, “Perbandingan Support Vector Machine, Random Forest Classifier, dan K-Nearest Neighbour dalam Pendeteksian Anomali pada Jaringan DDoS,” JTIM: Jurnal Teknologi Informasi dan Multimedia, vol. 7, no. 1, pp. 23–33, 2025, doi: 10.35746/jtim.v7i1.628.
R. Abbas, “Machine learning-based hybrid technique to enhance cyber-attack perspective,” Journal of Cloud Computing, vol. 11, no. 1, pp. 45–56, 2025, doi: 10.1186/s13677-025-00782-5.
G. O. Anyanwu, C. I. Nwakanma, J. M. Lee, and D.-S. Kim, “RBF-SVM kernel-based model for detecting DDoS attacks in SDN integrated vehicular network,” Ad Hoc Networks, vol. 140, p. 103026, 2023, doi: 10.1016/j.adhoc.2022.103026.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Libertino Felani Xavier Sarmento, Ivana Lucia Kharisma

This work is licensed under a Creative Commons Attribution 4.0 International License.



