[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120457-en":3,"doc-seo-120457-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120457,962075114101,"Seraphina","https://ap-avatar.wpscdn.com/avatar/e000253a75eb197efd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780044092746381165",8,"Research & Report","A Comparative Study of Machine Learning Models for HTTP Flood Attack Detection","Internet connectivity increasingly influences daily life, while cyberattacks and intrusions keep rising as breaking news. Among attack categories, denial-of-service (DoS) remains particularly severe, and HTTP flooding at the application layer is especially difficult to detect because it blends in with seemingly legitimate HTTP GET or POST traffic. This thesis presents a machine-learning-based approach for detecting HTTP flood attacks using five supervised models. It builds the dataset via Selenium for normal traffic and specific tools for generating HTTP flood traffic, captures traffic with Wireshark, converts PCAP to CSV, extracts 84 features, and selects 30 features for experiments. Across seven metrics, Random Forest delivers the strongest results while Naive Bayes performs the weakest.","Jimma University  \nSchool of Graduate studies  \nJimma Institute of Technology  \nFaculty of Electrical and computer engineering  \nA Comparative Study of Machine Learning Models for [HTTP Flood Attack Detection](HTTP Flood Attack Detection).  \nBy: Abdu Seid  \nA Thesis submitted to the School of Graduate Studies of Jimma University, Jimma Institute of Technology in partial fulfillment of the requirements for the Degree of Masters of Science in Electrical Engineering (Computer Engineering).  \nFebruary 2023 Jimma, Ethiopia  \nJimma University  \nSchool of Graduate studies  \nJimma Institute of Technology Faculty of electrical and computer engineering Masters of Science Program in Computer Engineering  \nA Comparative Study of Machine Learning Models for [HTTP Flood Attack Detection](HTTP Flood Attack Detection).  \nBy: Abdu Seid  \nA Thesis submitted to the School of Graduate Studies of Jimma University, Jimma Institute of Technology in partial fulfillment of the requirements for the Degree of Masters of Science in Electrical Engineering (Computer Engineering).  \nMain advisor: Dr. Srinivasan.T.R.  \nCo-advisor: Mr. Fetulhak  \nFebruary 2023 Jimma, Ethiopia  \nDECLARATION  \nI declare that this research entitled “A Comparative Study of Machine Learning Models for [HTTP](HTTP) Flood Attack Detection.” is my original work and has not been submitted as a requirement for the award of any degree in Jimma University or elsewhere.  \nAbdu Seid      \nCandidate Signature Date  \nAs research Adviser, I hereby certify that I have read and evaluated this thesis paper prepared under my guidance, by Abdu Seid “A Comparative Study of Machine Learning Models for [Http Flood Attack Detection](Http Flood Attack Detection)” and recommend and would be accepted as a fulfilling requirement for the Degree Master of Science in Computer Engineering  \nSigned by the Examining Committee:  \nMr. Kebebew Ababu  \n\n| Internal Examiner Dr. Henock Mulugeta |\n| --- |\n| External Examiner\u003Cbr>Fetulhak A. |\n| Co-advisor\u003Cbr>Dr. Srinivasan.T. R |\n\nMain-advisor  \nSignature  \nSignature  \n____________  \n____________  \nSignature  \n\n| Date |\n| --- |\n| Date\u003Cbr>04/22/2023 |\n| Date |\n\nDate  \nABSTRACT  \nNowadays, almost every aspect of human life is impacted by the Internet. Incidents of cyberattacks and intrusions are therefore becoming regular news. Among many attack types, denial-of-service (DoS) attacks remain the most devastating and severe due to their potential impact. As we movedown the tier, attacks at the application layer are particularly challenging to identify since they are stealthy by nature. [HTTP](HTTP) flooding is an application layer attack that is extremely dangerous and damaging since it is simple to bring a targeted site or server down by flooding it with a large number of [HTTP requests because the](HTTP requests because the) attacker uses seemingly-legitimate [HTTP GET or POST requests](HTTP GET or POST requests) to  \nattack a web server or application.  \nMachine learning and artificial intelligence research have exploded in recent years, offering new opportunities for intrusion detection solutions. However, data availability continues to greatly affect the success of such systems, as there is a scarcity of high-quality IDS datasets. This study introducesa solution that contributes to the detection of [HTTP](HTTP) flood attacks using five machine learning approaches. The dataset is an important part of building machine learning-based IDS models. The process starts with generating a dataset. To generate normal [http traffic](http traffic), Selenium, a web browser automation tool, was used; to generate [http flood attack traffic](http flood attack traffic), tools such as slow[httptest and hoic](httptest and hoic)[ ](httptest and hoic)[were used. Meanwhile](were used. Meanwhile), [Wireshark software is being](Wireshark software is being) used to capture network data and save it as apcap file. Consequently, utilize CICflowmeter to convert the Pcap file to CSV file format. 84","cbCaicHrb5nSwjVb","https://ap.wps.com/l/cbCaicHrb5nSwjVb","pdf",2058292,1,78,"English","en",105,"# Abstract\n# Methodology and Dataset Construction\n## Traffic Generation and Capture\n## Feature Extraction and Selection\n# Experimental Setup and Evaluation\n## Models Compared\n## Performance Metrics\n# Results and Discussion\n## Best and Worst Performing Models","[{\"question\":\"Why is HTTP flooding difficult to detect at the application layer?\",\"answer\":\"HTTP flooding can appear as normal web activity because attackers use seemingly legitimate HTTP GET or POST requests. This stealth nature makes application-layer identification challenging.\"},{\"question\":\"How is the dataset for the HTTP flood detection study created?\",\"answer\":\"Normal traffic is generated with Selenium, while HTTP flood traffic is produced using tools such as httptest and hoic. Traffic is captured using Wireshark as PCAP, converted to CSV with CICflowmeter, and then processed for modeling.\"},{\"question\":\"Which machine learning model achieved the best and worst detection performance?\",\"answer\":\"Random Forest produced the best overall results across key metrics (including high accuracy and recall). Naive Bayes was the weakest performer for detecting HTTP flood attacks in this study.\"}]","A Comparative Study of Machine Learning Models for HTTP Flood Attack Detection | PDF",1785730205,197,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"a-comparative-study-of-machine-learning-models-for-http-flood-attack-detection","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-comparative-study-of-machine-learning-models-for-http-flood-attack-detection/120457/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is HTTP flooding difficult to detect at the application layer?","Question",{"text":76,"@type":77},"HTTP flooding can appear as normal web activity because attackers use seemingly legitimate HTTP GET or POST requests. This stealth nature makes application-layer identification challenging.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How is the dataset for the HTTP flood detection study created?",{"text":81,"@type":77},"Normal traffic is generated with Selenium, while HTTP flood traffic is produced using tools such as httptest and hoic. Traffic is captured using Wireshark as PCAP, converted to CSV with CICflowmeter, and then processed for modeling.",{"name":83,"@type":74,"acceptedAnswer":84},"Which machine learning model achieved the best and worst detection performance?",{"text":85,"@type":77},"Random Forest produced the best overall results across key metrics (including high accuracy and recall). Naive Bayes was the weakest performer for detecting HTTP flood attacks in this study.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]