Skip to content
Open access

An Efficient Framework for DDoS-Attack Classification and Mitigation with Pre-Attack Propagation Behavior Analysis using TL-CEReSP-BiLSTM

Jul 2026 · Journal of Intelligent Decision Making and Information Science · 0 citations · 29 references

Abstract

Currently, Distributed Denial of Service (DDoS) attacks have become a major threat to network security, causing serious issues by disrupting the availability of online services. Yet, none of the existing systems concentrated on analyzing the pre-attack propagation behavior of botnets before mitigating the DDoS attacks. Henceforth, this paper proposes an efficient framework for botnets pre-attack propagation behavior analysis-based DDoS attack classification along with mitigation by employing Transfer Learning based Contrastive Entropy Rectified SoftPlus Bidirectional Long Short-Term Memory (TL-CEReSP-BiLSTM). Firstly, the network nodes are initialized and provided to the pre-attack propagation model. To train this model, the Czech Technical University (CTU-13) is collected and pre-processed, followed by beeswarm plot construction. Then, the features are extracted from the pre-processed data as well as the constructed plot. Next, the features are selected as of the extracted features using the Greedy-Marine Predators Algorithm (G-MPA). Afterward, from selected features, the classification is carried out by employing TL-CEReSP-BiLSTM, followed by explainability using G-SHAP. The corresponding nodes are blocked if the classified outcome is attack traffic. If traffic is normal, the nodes are clustered using Density Peaks Cosine Angular K-Means (DPCAK-Means), followed by Cluster Head (CH) selection using G-MPA. Also, the optimal path selection is carried out from the selected CH via a communication protocol using G-MPA. Now, through the network, the data is sensed for transmission. Then, by using Elliptical Curve Cryptography (ECC), the sensed data are secured, followed by traffic filtering using DPCAK-Means. Now, to train the Network Intrusion Detection (NID) model, the filtered sensed packets are forwarded by decrypting the secured data. For training the NID model, the CIC-DDoS2019 dataset is collected and pre-processed, followed by beeswarm plot construction. Then, the features are extracted from the pre-processed data as well as the constructed plot. Next, from the extracted features, the features are selected by employing G-MPA, followed by attack type classification and explainability. Further, the severity level of the classified DDoS attacks is determined using Heavy-Tailed Distribution-based Fuzzy Interference System (HTD-FIS). The packets are dropped if the severity is high. If the severity is medium and low, then the mitigation is carried out using Quick UDP Internet Connections-Csendes Entropy-based-Hash-centric Message Authentication Code-HyperText Transfer Protocol Secure (QUIC-CEHMAC-HTTPS). Lastly, after mitigating the DDoS attacks, the optimal paths are reselected and the data are transmitted securely through the network. Thus, the proposed model attained 99.16% accuracy in attack type classification.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.