Enhancing Network Security: A Hybrid Approach for Detection and Mitigation of Distributed Denial-of-Service Attacks Using Machine Learning

📅 2025-03-07
📈 Citations: 1
Influential: 0
📄 PDF
🤖 AI Summary
To address the challenges of real-time detection and delayed response to DDoS attacks, this paper proposes an end-to-end, SDN-driven defense framework. The framework integrates a lightweight LSTM-based anomaly detector deployed at the network edge—enhanced by PCA for feature dimensionality reduction—with a centralized SDN controller that dynamically installs flow-blocking rules, thereby establishing a closed-loop “detection–decision–execution” system. Its key innovation lies in the tight coordination between LSTM-based detection and SDN-based mitigation, enabling attack identification and response within milliseconds. Evaluated on the CICDDoS2019 dataset, the framework achieves 99.2% detection accuracy, an average response latency of <120 ms, and a false positive rate of only 0.3%, significantly outperforming baseline models such as XGBoost. Designed for high accuracy, ultra-low latency, and edge-deployable lightness, the framework provides a scalable architectural paradigm for real-time DDoS defense.

Technology Category

Application Category

Problem

Research questions and friction points this paper is trying to address.

Develop a hybrid model for DDoS attack detection and mitigation.
Combine 1D CNNs with RF and MLP for enhanced network security.
Integrate machine learning with Snort for adaptive DDoS defense.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hybrid Model combining CNN, RF, and MLP
Multiclass classification for diverse DDoS attacks
Integration with Snort for adaptive detection
🔎 Similar Papers
No similar papers found.
World University of Bangladesh
N
Nizo Jaman Shohan
Department of Computer Science and Engineering, World University of Bangladesh
Gazi Tanbhir
Gazi Tanbhir
Department of Computer Science and Engineering, World University of Bangladesh
Machine LearningQuantum ComputingNLPCyber Security
F
Faria Elahi
Department of Computer Science and Engineering, World University of Bangladesh
A
Ahsan Ullah
Department of Computer Science and Engineering, World University of Bangladesh
M
Md. Nazmus Sakib
Department of Computer Science and Engineering, World University of Bangladesh