Oraib AbuAlganam, Malik AL-Essa, Wesam Almobaideen, Mohammad Qatawneh, Ahmad Sami Al‐Shamayleh
The rapid growth of cyberattacks necessitates the development of more sophisticated detection techniques. DoS and DDoS are well-known harmful attacks that affect organizations. This paper proposes a proactive, behavior-based DoS and DDoS detection framework that integrates threat intelligence and machine learning to analyze attack behavior and enhance early detection. XGBoost is used to train the proposed model and evaluate feature importance. The evaluation of the proposed model and the generated rules is conducted using three different datasets: CICIoT2023, BoT-IoT, and Edge-IIoT. Experimental results demonstrate high detection performance, achieving up to 99.98% accuracy and 99.89% F1-score, while maintaining low false positive rates across diverse datasets. Integrating threat intelligence into SIEM has been evaluated using two datasets, DDoS-AT-2022 and CIC-DDoS2019. The rule-based detection technique enhances detection rates and mitigates false positives. Moreover, the proposed framework enhances detection accuracy.