Anomaly detection method

Zak_1221
Zak_1221 New Altair Community Member
edited November 5 in Altair RapidMiner
Hi I’m currently in my final year for computer science for cyber security. My FYP module is in regards to anomaly detection for DDoS attacks, I am using MATLAB to create this anomaly detection system. 
Where my issue falls is the fact that I am having a hard time finalising a method I have currently selected isolation forest but I am not sure if that’s the best method to run on the dataset I have for DDoS attacks.
The dataset consist of labelled frames with 0 meaning it’s not an attack and 1 meaning it’s an attack. Any form of help will be highly appreciated, thank you.