A High-Precision Machine Learning Algorithm for Detecting DDoS Attacks in a Cloud Computing Environment

محتوى المقالة الرئيسي

Noor Takla
Mohamed Mohamed

الملخص

A Distributed Denial of Service (DDoS) attack is an evil attempt to flood a website or a network with malicious traffic to force it to slow down or stop working and it is now extending to other technologies like cloud computing, IoT, and edge computing. This attack has different types, the attacker can exploit the UDP protocol to flood the victim's devices with a huge amount of data, or exploit vulnerabilities in network protocols, or may target the application layer. All of the above attempts to overwhelm all available resources including memory, CPU, and potentially the entire network aiming to incapacitate the victim's machine or server. Despite numerous proposed defensive mechanisms, these mechanisms often fall short as attackers continuously adapt using new automated tools. This is why we propose a machine learning-based approach for DDoS attack detection in cloud computing environments. Using machine learning classifiers, Random Forest (RF) and K-Nearest Neighbors (KNN) and compared based on classification performance and computational efficiency. Experimental results showed that the Random Forest classifier achieved the best performance by reaching an accuracy of 99.97% with minimal false positives. Finally, integrate the best selected model into a Flask-based real-time detection system able to classify generated traffic as either Normal or DDoS Attack.

##plugins.themes.bootstrap3.displayStats.downloads##

##plugins.themes.bootstrap3.displayStats.noStats##

تفاصيل المقالة

القسم

Articles

كيفية الاقتباس

"A High-Precision Machine Learning Algorithm for Detecting DDoS Attacks in a Cloud Computing Environment" (2026) مجلة الهندسة, 32(8), ص 1–15. doi:10.31026/j.eng.2026.08.01.

المراجع

Afraji, D. M., Lloret, J., and Penalver, L., 2025. Deep learning-driven defense strategies for mitigating DDoS attacks in cloud computing environments. KeAi publishing, Cyber Security and Applications (3), https://doi.org/10.1016/j.csa.2025.100085

Ahmad, A., Mohamed, M., and Mohamed, I., 2020. Mitigate distributed denial of service attack using dynamic threshold. Tartous University journal for research and Scientific Studies – engineering Sciences Series, 4(7), pp. 1-20. https://doi.org/10.5281/zenodo.21227496

Aktar, S. and Nur, A.Y., 2023. Towards DDoS attack detection using deep learning approach. Computers & Security, 129(9), P. 103251.

https://doi.org/10.1016/j.cose.2023.103251

Al-Qerem, A., Alauthman, M., Almomani, A., and Gupta, B.B., 2020. IoT transaction processing through cooperative concurrency control on fog–cloud computing environment. Soft Computing, 24(2-C), pp. 5695-5711. http://doi.org/10.1007/s00500-019-04220-y

Alarqan, M., Belaton, B., Almomani, A., Alauthman, M., Al-Betar, M.A., and Arya, V., 2025. Information theory-based DDoS attack detection in cloud computing. International Journal of Cloud Applications and Computing, 15(1), pp. 1-38. http://doi.org/10.4018/IJCAC.369817

Alduailij, M., Khan, Q. W., Taher, M., Sardaraz, M., Alduailij, M., and Malik, F.,2022. Machine-learning-based DDoS attack detection using mutual information and Random Forest feature importance method. Symmetry, 14(6). http://doi.org/10.3390/sym14061095

Alouffi, B., Hasnain, M., Alharbi, A., Alosaimi, W., Alyami, H., and Ayaz, M., 2021. A systematic literature review on cloud computing security: threats and mitigation strategies. IEEE Access, 9, pp. 57792-57807. http://doi.org/10.1109/ACCESS.2021.3073203

Amrish, R., Bavapriyan, K., Gopinaath, V., Jawahar, A., and Kumar, C. V., 2022. DDoS detection using machine learning techniques. Journal of IoT in Social, Mobile, Analytics, and Cloud, 4(1), pp. 24-32.‏‏‏ http://doi.org/10.36548/jismac.2022.1.003

Awan, M. J., Farooq, U., Babar, H. A., Yasin, A., Nobanee, H., Hussain, M., Hakeem, O., and Zain, A. M., 2021. Real-Time DDoS attack detection system using big data approach. Sustainability, 13(19). http://doi.org/10.3390/su131910743

Ayele, W.Y., 2022. Improving the utilization of digital services: Evaluating contest-driven open data development and the adoption of cloud services. arXiv preprint arXiv:2212.04491. http://doi.org/10.48550/arXiv.2212.04491

Bahashwan, A. A., Anbar, M., Manickam, S., Issa, G., Aladaileh, M. A., Alabsi, B. A., Rihan, S. D. A., 2024. HLD-DDoSDN: High and low-rates dataset-based DDoS attacks against SDN. PLoS ONE, 19(2). https://doi.org/10.1371/journal.pone.0297548

Bawany, N.Z., Shamsi, J.A. and Salah, K.,2017. DDoS attack detection and mitigation using SDN: Methods, practices, and solutions. Arab J Sci Eng., 42, pp. 425–441. http://doi.org/10.1007/s13369-017-2414-5

Berríos, S., Garcia, S., Hermosilla, P., and Allende-Cid, H., 2025. A machine-learning-based approach for the detection and mitigation of distributed denial-of-service attacks in internet of things environments. Applied Sciences, 15(11), P. 6012. https://doi.org/10.3390/app15116012

Bhushan, K., and Gupta, B. B.,2019. Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment. Journal of Ambient Intelligence and Humanized Computing, 10(4), pp. 1985-1997.‏ http://doi.org/10.1007/s12652-018-0800-9

Bonguet,A., and Bellaich, M., 2017. A Survey of denial-of-service and distributed denial of service attacks and defenses in cloud computing. Future Internet,9(3), P. 43. http://doi.org/10.3390/fi9030043

Dahiya, A., and Gupta, B,2020. A reputation score policy and Bayesian game theory based incentivized mechanism for DDoS attacks mitigation and cyber defense. Future Generation Computer Systems, 117(12), pp. 193-204. http://doi.org/10.1016/j.future.2020.11.027

Das, S., Mahfouz, A. M., Venugopal, D., and Shiva, S., 2019. DDoS intrusion detection through machine learning ensemble. A Review. in Proceedings IEEE 19th International Conference on Software Quality, Reliability and Security Companion, QRS-C. 22-26 July 2019, Sofia, Bulgaria. pp. 471-477. http://doi.org/10.1109/QRS-C.2019.00090

Deniz, E., and Serttas, S., 2023. Deep learning-based distributed denial of service detection system in the cloud network. Journal of Scientific Reports-A, 48, pp. 16–33. http://doi.org/10.59313/jsr-a.1333839

Dincalp, U., Guzel, M. S., Sevine, O., Bostanci, E., and Askerzade, I., 2018. Anomaly based distributed denial of service attack detection and prevention with machine learning. A Review. in Proceedings 2nd International Symposium on Multidisciplinary Studies and Innovative Technologies, ISMSIT. October 2018, Ankara. pp. 1-4.‏ http://doi.org/10.1109/ISMSIT.2018.8567252

Dong, S., Abbas, k., and Jain, R., 2019. A survey on distributed denial of service (DDoS) attacks in SDN and cloud computing environments. IEEE Access, 7, pp. 80813–80828. http://doi.org/10.1109/ACCESS.2019.2922196

Doshi, R., Apthorpe, N., and Feamster, N., 2018. Machine learning DDoS detection for consumer internet of things devices. in Proceedings International Conference on IEEE Security and Privacy Workshops, SPW. IEEE Xplore, 24-24

May 2018, San Francisco, CA. pp. 29-35.‏ http://doi.org/10.1109/SPW.2018.00013

Hassan, A.I., Abd El Reheem, E., and Guirguis, S.K., 2024. An entropy and machine learning based approach for DDoS attacks detection in software defined networks. Scientific Reports, 14(1), P. 18159. http://doi.org/10.1038/s41598-024-67984-w

Herath, B.M.T.I.T, 2024. The economic impact of cyberattacks research paper the economic impact of cyberattacks: A comprehensive analysis. SSRN Electronic Journal. http://doi.org/10.2139/ssrn.4885666

Khordadpour, P., and Ahamdi, S., 2023. FIDS: Fuzzy intrusion detection system for simultaneous detection of DoS/DDoS attacks in ؤloud computing. arXiv preprint arXiv:2305.16389. http://doi.org/10.48550/arXiv.2305.16389

Khuphiran, P., Leelaprute, P., Uthayopas, P., Ichikawa, K., and Watanakeesuntorn, W., 2018. Performance comparison of machine learning models for DDoS attacks detection. A Review. in Proceedings 22nd International Computer Science and Engineering Conference, ICSEC. IEEE Xplore, 21-24 November 2018, Chiang Mai, Thailand. pp. 1-4. http://doi.org/10.1109/ICSEC.2018.8712757

Kumar, D., Pateriya, R. K., Gupta, R. K., Dehalwar, V., and Sharma, A., 2023. DDoS detection using deep learning. Procedia Computer Science, 218, pp. 2420–2429. https://doi.org/10.1016/j.procs.2023.01.217

Mehboob, T., Sumra, I. A., and Shahzadi, I.,2024. Detection of DDoS/DoS attack methodologies in cloud computing network: A survey. Journal of Cybersecurity and Information Management, 8(1), pp. 1–11.

Mishra, A., Gupta, B. B., Peraković, D., Peñalvo, F. J. G., and Hsu, C. H. 2021. Classification based machine learning for detection of DDoS attack in cloud computing. in Proceedings International Conference on consumer electronics, ICCE. IEEE Xplore, 10-12 January 2021, Las Vegas, NV, USA. pp. 1-4. http://doi.org/10.1109/ICCE50685.2021.9427665

Mittal, M., Kumar, K., and Behal, S., 2023. Deep learning approaches for detecting DDoS attacks: A systematic review. Soft computing, 27(18), pp. 13039-13075.‏ http://doi.org/10.1007/s00500-021-06608-1

Nazario, J., 2008. DDoS attack evolution, Network Security, 2008(7), pp. 7-10. http://doi.org/10.1016/S1353-4858(08)70086-2

Nur, A. Y., 2021. Combating DDoS attacks with fair rate throttling. A Review. in Proceedings IEEE International Systems Conference, SysCon. 15 April - 15 May 2021, Vancouver, BC, Canada. P. 3. http://doi.org/10.1109/SysCon48628.2021.9447054

Osanaiye, O., Choo, K. R., Dehghantanha, A., Xu, Z., and Dlodlo, M., 2018. Ensemble-based multi-filter feature selection method for DDoS detection in cloud computing. arXiv preprint arXiv:1807.10443. http://doi.org/10.48550/arXiv.1807.10443

Ouhssini, M., Afdel, K., Agherrabi, E., Akouhar, M., and Abarda, A., 2024. Deep defend: A comprehensive framework for DDoS attack detection and prevention in cloud computing. Journal of King Saud University - Computer and Information Sciences, 36, Article 101938. https://doi.org/10.1016/j.jksuci.2024.101938

Pandey, N., and Mishra, P.K., 2025. Conditional entropy-based hybrid DDoS detection model for IoT networks. Computers & Security, 150, P. 104199. http://doi.org/10.1016/j.cose.2024.104199

Peng, T., Leckie, C. and Ramamohanarao, K., 2004. Proactively detecting distributed denial of service attacks using source IP address monitoring. A Review. in Proceedings International Conference on Research in Networking, 9-14 may, 2004, Springer, Berlin, Heidelberg. pp. 771–782. http://doi.org/10.1007/978-3-540-24693-0_63

Pise, N., and Kulkarni, P., 2016. Algorithm selection for classification problems. A Review. in Proceedings SAI Computing Conference, SAI. 13-15 July 2016, London, UK. pp. 203-211. http://doi.org/10.1109/SAI.2016.7555983

Rahman, O., Quraishi, M. A. G., and Lung, C.,2019. DDoS attacks detection and mitigation in SDN using machine learning. A Review. in Proceedings IEEE World Congress on Services, SERVICES. 08-13 July 2019, Milan, Italy. pp. 184-189. http://doi.org/10.1109/SERVICES.2019.00051

Singh, P., Rehman, S., and Manickam, S., 2019. Comparative analysis of state-of-the-art EDoS mitigation techniques in cloud computing environment. arXiv preprint arXiv:1905.13447. http://doi.org/10.48550/arXiv.1905.13447

Somani, G., Gaur, M. S., Sanghi, D., Conti, M., and Buyya, R., 2017. DDoS attacks in cloud computing: Issues, taxonomy, and future directions. Computer Communications, 107, pp. 30-48. http://doi.org/10.1016/j.comcom.2017.03.010

المؤلفات المشابهة

يمكنك أيضاً إبدأ بحثاً متقدماً عن المشابهات لهذا المؤلَّف.