International Journal of Networking and Computing
Online ISSN : 2185-2847
Print ISSN : 2185-2839
ISSN-L : 2185-2839
Special issue on the Thirteenth International Symposium on Networking and Computing
Consideration of Network Anomaly Detection Models for DoS/DDoS Attacks in GNS3 Environments using Machine Learning
Souma KaiChikatoshi YamadaSoichiro Hanashiro
著者情報
ジャーナル オープンアクセス

2026 年 16 巻 2 号 p. 224-241

詳細
抄録
In recent years, the rapid advancement of network technologies has led to increasingly sophisticated cyberattacks, posing significant challenges to traditional rule-based anomaly detection systems. This research proposes and verifies a dual-stage network anomaly detection pipeline that integrates machine learning models to identify both known and unknown threats effectively. The proposed system utilizes a Random Forest (RF) model for the classification of established attack patterns and an Autoencoder (AE) for the detection of unknown anomalies through a reconstruction-based approach. To ensure a highly reproducible and realistic experimental environment, the virtual network simulator GNS3 was employed to construct a complex topology including attacker, client, and victim nodes. Network traffic data, comprising normal communications and DDoS attacks (SYN Flood and Slowloris), were collected and processed using the NFStream library to extract key statistical features. The experimental results demonstrate the high performance of the proposed model, with the Random Forest achieving an accuracy of 1.00 in classifying known attacks even within complex traffic scenarios. Furthermore, the Autoencoder successfully identified anomalies with high precision (0.96 accuracy in GNS3-based experiments) by learning normal traffic baselines and detecting deviations through Mean Squared Error (MSE) analysis.
著者関連情報
© 2026 International Journal of Networking and Computing
前の記事 次の記事
feedback
Top