Aug 2026· Cluster Computing· Vol 29· 0 citations· 43 references
TL;DR
A hybrid model combining Machine Learning and Deep Learning algorithms is introduced to enhance the detection of DDoS attacks, showing promising results in DDoS attack detection scenarios.
Abstract
Over the past decades, distributed denial of service attacks have been one of the most devastating security threats, disrupting many services that rely heavily on the Internet and leading to significant economic losses for various sectors. Identifying DDoS attacks poses a significant challenge that must be addressed through detection methods before effective mitigation strategies can be deployed. Detection of these attacks requires sophisticated technical solutions to discern malicious traffic from legitimate network activity in real-time. According to the work in this paper, a hybrid model combining Machine Learning and Deep Learning algorithms is introduced to enhance the detection of DDoS attacks. This hybrid model employs two main stages. The Gradient Boosting (GB) Machine Learning algorithm has been utilized in the first stage for efficient feature selection and computational complexity reduction. In the second stage, the Gated Recurrent Units (GRU) Deep learning algorithm has been employed to improve attack detection by capturing temporal dependencies and complex patterns. The hybrid model (GB-GRU) capitalizes on the strengths of both traditional machine learning and deep learning algorithms. The proposed hybrid model’s effectiveness is validated using the CICDoS2019 dataset, showing promising results in DDoS attack detection scenarios. Experimental results indicate that the proposed hybrid model achieves high detection performance with an accuracy rate of 99.96%, a False Positive Rate (FPR) of 0.2, less computational complexity compared to existing algorithms, and a test time of 5.729s.
A deep learning-based approach for reliable DDoS attack detection and classification into distinct classes goes beyond the state-of-the-art binary classification approach by incorporating the multi-class classification at various levels that help to distinguish particular DDoS attack categories.
Haythem Hayouni, Wala Ben Rhouma· Journal of Communications So...· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
As a technology that connects even more systems and services to the Internet with each passing day, cybercrime has grown out of control globally. Significant problems with traditional IDSs have been uncovered when they are exposed to new attack vectors and advanced evasion strategies not contained in their rule sets and/or signature databases. This paper contains comprehensive research and empirical analysis of 9 machine learning and deep learning algorithms for binary classification of network traffics into normal or malicious network traffic. The benchmark dataset used in this study is the KDD Cup 1999 dataset, which consists of around 494,021 network connection records derived from a relatively large network, characterized with 41 different features of continuous, discrete and categorical attribute types. Its performance was compared with five classical machine learning algorithms, namely decision tree, random forest, support vector machine with a linear kernel, K-nearest neighbours and gaussian naive bayes. Furthermore, four deep learning architectures were studied, a fully connected Artificial Neural Network, a one dimensional Convolutional Neural Network (CNN), a Long Short-Term Memory (LSTM) recurrent network, and an Autoencoder based model for anomaly detection (AD). These models were thoroughly validated with accuracy, precision, recall, F1 score and ROC-AUC on an 80-20 stratified train test partition. Experimental results showed that the ensemble of Random Forest classifiers has the best overall performance with an overall accuracy of 99.98% and a near-perfect value of ROC-AUC (99.99%). Decision Tree obtained a value of 99.97% in terms of accuracy and a near-perfect value of 99.98% for the ROC-AUC measure. The best deep learning models were the ANN (accuracy of 99.95%) and the LSTM (accuracy of 99.95%) with their nearest architectures, followed by the unsupervised model of Autoencoder (accuracy of 98.94%) with the reconstruction error thresholding. The results highlight that the ensemble tree based methods are still highly effective for the structured network traffic classification cases, and a Deep learning-based approach presents an even more competitive solution with the task of feature selection through raw data, which opens doors of opportunity to extract features by various means from raw data for these cases. In addition, the model was deployed practically with a RESTful API built using FastAPI, allowing for the real-time analysis of live traffic with the trained models.
Dhilleswari Palli, Jyothi Musireddy, V. P· International Journal of Res...· 0 citations
The rapid growth of digital communication, cloud computing, Internet of Things (IoT), software-defined networking, and edge computing has significantly increased the complexity and volume of network traffic, creating new opportunities for sophisticated cyberattacks. Traditional signature-based intrusion detection systems are highly effective against previously identified threats but often fail to recognize emerging zero-day attacks whose behavioral characteristics have not been previously observed. Consequently, anomaly-based deep learning approaches have gained considerable attention because of their capability to automatically learn complex traffic patterns and identify deviations from legitimate network behavior. This study proposes an anomaly-based deep learning model for detecting both known and zero-day attacks in heterogeneous network environments. The proposed framework integrates advanced traffic preprocessing, automated feature extraction, deep neural representation learning, adaptive anomaly scoring, and intelligent attack classification to enhance detection accuracy while minimizing false alarms. The model is designed to capture nonlinear relationships among network traffic attributes, enabling effective identification of sophisticated intrusion attempts that evade conventional security mechanisms. Furthermore, the proposed architecture emphasizes scalability, robustness, and real-time applicability for modern enterprise networks. The anticipated outcomes demonstrate improved detection performance, reduced false positive rates, enhanced generalization capability for unseen attacks, and strengthened network resilience, thereby providing an effective intelligent cybersecurity solution for next-generation network intrusion detection systems.
Aswathy N. Rajan· Journal of Intelligent Decis...· 0 citations
LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.
Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al.· Italian National Conference...· 0 citations
A transformer-based classifier for DDoS detection on the CIC-DDoS2019 dataset demonstrates stable convergence and generalization across folds, highlighting the strength of attention mechanisms in capturing feature dependencies, while also pointing to future directions such as real-time deployment, explainability, and resilience to zero-day attacks.
Lokeshwaran Kanagaraj, Raguraman Purushothaman, Sathya Subramanian et al.· IAES International Journal o...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.