Research Article | Open Access | Download PDF
Volume 74 | Issue 7 | Year 2026 | Article Id. IJCTT-V74I7P106 | DOI : https://doi.org/10.14445/22312803/IJCTT-V74I7P106Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques
Shubhendra Singh, Alok Kumar
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 29 May 2026 | 30 Jun 2026 | 18 Jul 2026 | 31 Jul 2026 |
Citation :
Shubhendra Singh, Alok Kumar, "Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques," International Journal of Computer Trends and Technology (IJCTT), vol. 74, no. 7, pp. 61-71, 2026. Crossref, https://doi.org/10.14445/22312803/IJCTT-V74I7P106
Abstract
Distributed Denial-of-Service (DDoS) attacks remain among the most disruptive threats to modern network infrastructure, with adversaries continually adapting their strategies to overwhelm cloud platforms, Internet-of-Things (IoT) deployments, and Software-Defined Network (SDN) environments. Traditional signature-based intrusion detection systems exhibit inherent inflexibility against novel attack vectors, motivating a shift toward intelligent, data-driven defense mechanisms. This paper presents an intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies. Evaluated on the CICDDoS2019, NSL-KDD, and UNSW-NB15 benchmark datasets, the proposed hybrid framework incorporating XGBoost and a Bidirectional LSTM model achieves a classification accuracy of 99.31%, a precision of 99.18%, a recall of 99.27%, and an F1-score of 99.22%, outperforming standalone classifiers while sustaining sub-millisecond detection latency under realistic traffic loads. SDN-assisted rule insertion further reduces the mean mitigation response time to 8.4 ms. The results affirm the viability of deploying intelligent, explainable ML-based defense pipelines in production-grade network environments.
Keywords
Distributed Denial-of-Service, Intrusion Detection System, Machine Learning, Deep Learning, Software-Defined Networking, Explainable AI, Network Security.
References
[1] Arbor Networks, “Worldwide
Infrastructure Security Report,” 2015.
[Google Scholar]
[2] DDoS Trend Report 2024, Nexus Guard, 2024. [Online].
Available: https://www.nexusguard.com/threat-report/ddos-trend-report-2024
[3] Alberto Dainotti et al., “Analysis of Country-Wide Internet
Outages Caused by Censorship,” Proceedings of the 2011 ACM SIGCOMM
Conference on Internet Measurement Conference, Association for Computing Machinery, New York, NY, United States, pp. 1-18, 2011.
[CrossRef] [Google Scholar] [Publisher
Link]
[4] R. Vinayakumar et al.,
“Deep Learning Approach for Intelligent Intrusion Detection System,” IEEE
Access, vol. 7, pp. 41525-41550, 2019.
[CrossRef] [Google Scholar] [Publisher
Link]
[5] Chuanlong Yin et al., “A
Deep Learning Approach for Intrusion Detection using Recurrent Neural
Networks,” IEEE Access, vol. 5, pp. 21954-21961, 2017.
[CrossRef] [Google Scholar] [Publisher
Link]
[6] Seungwon Shin et al.,
“Enhancing Network Security through Software Defined Networking (SDN),” 2016
25th International Conference on Computer Communication and Networks
(ICCCN), Waikoloa, HI, USA, pp. 1-9, 2016.
[CrossRef] [Google Scholar] [Publisher
Link]
[7] Paxson V. Bro, “A System
for Detecting Network Intruders in Real-Time,” Proceedings 7th
USENIX Security Symposium, 1998.
[Google Scholar]
[8] Peter Stavroulakis, and
Mark Stamp, Handbook of Information and Communication Security, 1st
ed., Springer Berlin, Heidelberg, 2010.
[CrossRef] [Google Scholar] [Publisher Link]
[9] Mahbod Tavallaee et al., “A
Detailed Analysis of the KDD CUP 99 Data Set,” 2009 IEEE Symposium on
Computational Intelligence for Security and Defense Applications, Ottawa,
ON, Canada, pp. 1-6, 2009.
[CrossRef] [Google Scholar] [Publisher
Link]
[10] Nour Moustafa, and Jill
Slay, “UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection
Systems (UNSW-NB15 Network Data Set),” 2015 Military Communications and
Information Systems Conference (MilCIS), Canberra, ACT, Australia, pp. 1-6,
2015.
[CrossRef] [Google Scholar] [Publisher
Link]
[11] Mohamed Amine Ferrag et
al., “Deep Learning for Cyber Security Intrusion Detection: Approaches,
Datasets, and Comparative Study,” Journal of Information Security and
Applications, vol. 50, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[12] Q. Zhang, “Federated
Learning-based Intrusion Detection for Distributed Networks,” IEEE Access,
2024.
[Google Scholar]
[13] Shi Dong, Khushnood Abbas,
and Raj Jain, “A Survey on Distributed Denial of Service (DDoS) Attacks in SDN
and Cloud Computing Environments,” IEEE Access, vol. 7, pp. 80813-80828,
2019.
[CrossRef] [Google Scholar] [Publisher
Link]
[14] Somya Ranjan Sahoo, and
B.B. Gupta, “Multiple Features-based Approach for Automatic Fake News Detection
on Social Networks using Deep Learning,” Applied Soft Computing, vol.
100, 2021.
[CrossRef] [Google Scholar] [Publisher Link]
[15] Lyna Touileb et al., “A
Hybrid LSTM-Autoencoder based Approach for Network Anomaly Detection System in
IoT Environments,” 2024 IEEE
International Mediterranean Conference on Communications and Networking
(MeditCom), Spain, pp. 125-130, 2024.
[CrossRef] [Google Scholar] [Publisher
Link]
[16] Tuan A. Tang et al., “Deep
Recurrent Neural Network for Intrusion Detection in SDN-based Networks,” 2018
4th IEEE Conference on Network Softwarization and Workshops
(NetSoft), Montreal, QC, Canada, pp. 202-206, 2018.
[CrossRef] [Google Scholar] [Publisher
Link]
[17] Manuel Lopez-Martin et al.,
“Network Traffic Classifier with Convolutional and Recurrent Neural Networks
for Internet of Things,” IEEE Access, vol. 5, pp. 18042-18050, 2017.
[CrossRef] [Google Scholar] [Publisher
Link]
[18] Eirini Anthi et al., “A
Supervised Intrusion Detection System for Smart Home IoT Devices,” IEEE
Internet of Things Journal, vol. 6, no. 5, pp. 9042-9053, 2019.
[CrossRef] [Google Scholar] [Publisher
Link]
[19] Thien Duc Nguyen et al.,
“DIoT: A Federated Self-Learning Anomaly Detection System for IoT,” 2019
IEEE 39th International Conference on Distributed Computing Systems
(ICDCS), Dallas, TX, USA, pp. 756-767, 2019.
[CrossRef] [Google Scholar] [Publisher
Link]
[20] Lingjuan Lyu et al., “Privacy-Preserving Collaborative Deep
Learning with Application to Human Activity Recognition,” Proceedings of the
2017 ACM on Conference on Information and Knowledge Management, Association for Computing Machinery, New York, NY, US, pp. 1219-1228, 2017.
[CrossRef] [Google Scholar] [Publisher
Link]