YUSRIDA JELIANTI SIHITE SIHITE
Universitas Negeri Medan

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

PERBANDINGAN ALGORITMA RANDOM FOREST DAN KNN UNTUK DETEKSI SERANGAN DDOS SECARA REAL-TIME PADA JARINGAN LOKAL YUSRIDA JELIANTI SIHITE SIHITE; Dedy Kiswanto; Muhammad Rois Lukman Damanik
Jusikom : Jurnal Sistem Komputer Musirawas Vol. 11 No. 1 (2026): Jurnal Sistem Komputer Musirawas JUNI
Publisher : LPPM UNIVERSITAS BINA INSAN

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.32767/jusikom.v11i1.3207

Abstract

Distributed Denial of Service (DDoS) attacks are a cyber security threat capable of massively disrupting network services within a short period of time. Static rule-based detection methods have proven inadequate in the face of constantly evolving attack patterns, making machine learning approaches a more adaptive alternative. This study compares the performance of the Random Forest (RF) and K-Nearest Neighbour (KNN) algorithms in detecting DDoS attacks in real-time on a local network. The local network topology was physically constructed using a Router 1941, a Switch, an Attacker PC, and a Normal PC, whilst model training utilised the CICIDS2017 dataset comprising 225,711 samples with 78 features via Google Colab. The system was built entirely using Python, with Scapy as the packet sniffing engine and Streamlit as the interactive web dashboard framework, allowing detection results to be monitored simultaneously via both the command-line interface (CLI) and a browser-based visual display. Experimental results show that RF achieved an accuracy of 99.99% with a prediction time of 0.74 seconds and only 2 misclassifications, whilst KNN achieved an accuracy of 99.96% with a prediction time of 87.33 seconds and 14 misclassifications. In real-time latency testing, RF recorded 40.027 ms and KNN 34.678 ms. RF is recommended as the primary algorithm for DDoS detection systems on local networks.