International Journal of Computer
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 7 | Year 2026 | Article Id. IJCTT-V74I7P106 | DOI : https://doi.org/10.14445/22312803/IJCTT-V74I7P106

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques


Shubhendra Singh, Alok Kumar

Received Revised Accepted Published
29 May 2026 30 Jun 2026 18 Jul 2026 31 Jul 2026

Citation :

Shubhendra Singh, Alok Kumar, "Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques," International Journal of Computer Trends and Technology (IJCTT), vol. 74, no. 7, pp. 61-71, 2026. Crossref, https://doi.org/10.14445/22312803/IJCTT-V74I7P106

Abstract

Distributed Denial-of-Service (DDoS) attacks remain among the most disruptive threats to modern network infrastructure, with adversaries continually adapting their strategies to overwhelm cloud platforms, Internet-of-Things (IoT) deployments, and Software-Defined Network (SDN) environments. Traditional signature-based intrusion detection systems exhibit inherent inflexibility against novel attack vectors, motivating a shift toward intelligent, data-driven defense mechanisms. This paper presents an intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies. Evaluated on the CICDDoS2019, NSL-KDD, and UNSW-NB15 benchmark datasets, the proposed hybrid framework incorporating XGBoost and a Bidirectional LSTM model achieves a classification accuracy of 99.31%, a precision of 99.18%, a recall of 99.27%, and an F1-score of 99.22%, outperforming standalone classifiers while sustaining sub-millisecond detection latency under realistic traffic loads. SDN-assisted rule insertion further reduces the mean mitigation response time to 8.4 ms. The results affirm the viability of deploying intelligent, explainable ML-based defense pipelines in production-grade network environments.

Keywords

Distributed Denial-of-Service, Intrusion Detection System, Machine Learning, Deep Learning, Software-Defined Networking, Explainable AI, Network Security.

References

[1] Arbor Networks, “Worldwide Infrastructure Security Report,” 2015.
[
Google Scholar]

[2] DDoS Trend Report 2024, Nexus Guard, 2024. [Online]. Available: https://www.nexusguard.com/threat-report/ddos-trend-report-2024

[3] Alberto Dainotti et al., “Analysis of Country-Wide Internet Outages Caused by Censorship,” Proceedings of the 2011 ACM SIGCOMM Conference on Internet Measurement Conference, Association for Computing Machinery, New York, NY, United States, pp. 1-18, 2011.
[CrossRef] [Google Scholar] [Publisher Link]

[4] R. Vinayakumar et al., “Deep Learning Approach for Intelligent Intrusion Detection System,” IEEE Access, vol. 7, pp. 41525-41550, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[5] Chuanlong Yin et al., “A Deep Learning Approach for Intrusion Detection using Recurrent Neural Networks,” IEEE Access, vol. 5, pp. 21954-21961, 2017.
[CrossRef] [Google Scholar] [Publisher Link]

[6] Seungwon Shin et al., “Enhancing Network Security through Software Defined Networking (SDN),” 2016 25th International Conference on Computer Communication and Networks (ICCCN), Waikoloa, HI, USA, pp. 1-9, 2016.
[CrossRef] [Google Scholar] [Publisher Link]

[7] Paxson V. Bro, “A System for Detecting Network Intruders in Real-Time,” Proceedings 7th USENIX Security Symposium, 1998.
[Google Scholar]

[8] Peter Stavroulakis, and Mark Stamp, Handbook of Information and Communication Security, 1st ed., Springer Berlin, Heidelberg, 2010.
[CrossRef] [Google Scholar] [Publisher Link]

[9] Mahbod Tavallaee et al., “A Detailed Analysis of the KDD CUP 99 Data Set,” 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada, pp. 1-6, 2009.
[CrossRef] [Google Scholar] [Publisher Link]

[10] Nour Moustafa, and Jill Slay, “UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems (UNSW-NB15 Network Data Set),” 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia, pp. 1-6, 2015.
[CrossRef] [Google Scholar] [Publisher Link]

[11] Mohamed Amine Ferrag et al., “Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study,” Journal of Information Security and Applications, vol. 50, 2020.
[CrossRef] [Google Scholar] [Publisher Link]

[12] Q. Zhang, “Federated Learning-based Intrusion Detection for Distributed Networks,” IEEE Access, 2024.
[Google Scholar]

[13] Shi Dong, Khushnood Abbas, and Raj Jain, “A Survey on Distributed Denial of Service (DDoS) Attacks in SDN and Cloud Computing Environments,” IEEE Access, vol. 7, pp. 80813-80828, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[14] Somya Ranjan Sahoo, and B.B. Gupta, “Multiple Features-based Approach for Automatic Fake News Detection on Social Networks using Deep Learning,” Applied Soft Computing, vol. 100, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[15] Lyna Touileb et al., “A Hybrid LSTM-Autoencoder based Approach for Network Anomaly Detection System in IoT Environments,” 2024 IEEE International Mediterranean Conference on Communications and Networking (MeditCom), Spain, pp. 125-130, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[16] Tuan A. Tang et al., “Deep Recurrent Neural Network for Intrusion Detection in SDN-based Networks,” 2018 4th IEEE Conference on Network Softwarization and Workshops (NetSoft), Montreal, QC, Canada, pp. 202-206, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[17] Manuel Lopez-Martin et al., “Network Traffic Classifier with Convolutional and Recurrent Neural Networks for Internet of Things,” IEEE Access, vol. 5, pp. 18042-18050, 2017.
[CrossRef] [Google Scholar] [Publisher Link]

[18] Eirini Anthi et al., “A Supervised Intrusion Detection System for Smart Home IoT Devices,” IEEE Internet of Things Journal, vol. 6, no. 5, pp. 9042-9053, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[19] Thien Duc Nguyen et al., “DIoT: A Federated Self-Learning Anomaly Detection System for IoT,” 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS), Dallas, TX, USA, pp. 756-767, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[20] Lingjuan Lyu et al., “Privacy-Preserving Collaborative Deep Learning with Application to Human Activity Recognition,” Proceedings of the 2017 ACM on Conference on Information and Knowledge Management, Association for Computing Machinery, New York, NY, US, pp. 1219-1228, 2017.
[CrossRef] [Google Scholar] [Publisher Link]