MARATTO

article · Journal of King Saud University - Computer and Information Sciences

DeepDefend: A comprehensive framework for DDoS attack detection and prevention in cloud computing

202429 citationsOpen accessIbn Tofail University

In plain language

Distributed denial-of-service (DDoS) attacks pose a persistent threat to cloud computing environments. DeepDefend is a framework developed to provide real-time detection and prevention against these security threats. The system integrates deep learning architectures, specifically combining convolutional neural networks, long short-term memory networks, and transformer models to predict network traffic entropy and recognise potential attack patterns. To improve classification performance, the framework uses a genetic algorithm to select the most relevant features, supporting an AutoCNN-DT model that distinguishes legitimate network traffic from malicious activity. When evaluated against the CIDDS-001 benchmark traffic dataset, the framework demonstrated high accuracy in forecasting entropy alongside rapid and precise detection of incoming attacks. By combining time series analysis, evolutionary algorithms, and deep learning, the framework provides a multi-layered approach to safeguarding cloud infrastructure.

Key takeaways

  • DeepDefend provides real-time detection and prevention of DDoS attacks targeting cloud infrastructure.
  • The framework predicts network traffic entropy using an integrated CNN-LSTM-Transformer deep learning model.
  • A genetic algorithm selects optimal traffic features to enhance classification by an AutoCNN-DT model.
  • Testing on the CIDDS-001 dataset confirmed high accuracy in entropy prediction and rapid identification of attacks.

Why it matters

Cloud services host critical digital operations, making them prime targets for disruptive cyberattacks that overwhelm servers with traffic. Developing fast and accurate automated detection methods helps maintain online services without disruption. By anticipating abnormal traffic surges before severe damage occurs, such systems strengthen the reliability and resilience of shared digital infrastructure.

Commercialisation angle

The framework could enable automated cybersecurity tools for cloud service providers and network operators seeking to block denial-of-service traffic. Because the system has been tested on a standard benchmark dataset, the CIDDS-001 traffic dataset, rather than deployed in an active production environment, it appears to be at an applied research stage. Further validation in live, commercial cloud networks would be required before integration into enterprise security platforms.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

DeepDefend is an advanced framework for real-time detection and prevention of DDoS attacks in cloud environments. It employs deep learning techniques, notably CNN-LSTM-Transformer networks, to predict network traffic entropy and detect potential attacks. The framework uses a genetic algorithm for optimal feature selection, enhancing the efficacy of the AutoCNN-DT model in distinguishing between normal and attack traffic. Tested on the CIDDS-001 traffic dataset, DeepDefend demonstrates high accuracy in entropy forecasting and rapid, precise detection of DDoS attacks. This integrated approach combines time series analysis, genetic algorithms, and deep learning, offering a robust solution to protect cloud computing infrastructure against DDoS threats.

Research topics

  • Network Security and Intrusion Detection
  • Internet Traffic Analysis and Secure E-voting
  • Anomaly Detection Techniques and Applications

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1016/j.jksuci.2024.101938

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.