$$A Blocking and Rate-Limiting Mitigation Framework for Distributed Denial of Service (DDoS) Attacks Using a Heterogeneous Ensemble Deep Learning Model (HEDDS-Net)$$
Chinyere Chioma Isiekwene
Abstract
$Existing hybrid ensemble deep learning detectors are often assembled without theoretical justification for architectural diversity, rely on heuristic mitigation thresholds (Najar and Naik, 2024), separate detection from enforcement, and remain static after deployment (Hnamte and Hussain, 2022). This study presents HEDDS-Net, a Heterogeneous Ensemble Deep-Learning Detection System integrating five architecturally diverse models: Deep Belief Network (DBN), Transformer, Long Short-Term Memory (LSTM), Recurrent Neural Network (RNN), and Autoencoder. The models are aggregated via weighted soft voting and coupled with a two-tier confidence-based mitigation policy that blocks attacks at confidence ≥ 0.7 and rate-limits at ≥ 0.5, derived from the Chow–Elkan cost-parametric decision framework (Chow, 1970). HEDDS-Net was evaluated on CIC-DDoS2019 (225,745 records) and CIC-IDS2017 (692,703 records), representing datasets with contrasting attack complexity. On CIC-DDoS2019, both the three-model ensemble comprising Transformer, LSTM, and Autoencoder and a reduced two-model ensemble achieved 99.92% accuracy, 100% precision, zero false positives, and 36 false negatives. In contrast, CIC-IDS2017 required the full five-model ensemble to achieve 97.36% accuracy and 94.57% recall, while ensemble reduction resulted in 1,715 additional missed attacks. The Autoencoder demonstrated the strongest cross-dataset robustness, whereas the RNN performed poorly and proved unsuitable for operational deployment. Mitigation achieved 100% blocking and rate-limiting accuracy with zero benign-traffic impact on CIC-DDoS2019, while CIC-IDS2017 retained minimal false-mitigation rates due to feature-space overlap. These findings demonstrate that ensemble architecture should be selected based on attack-pattern complexity rather than being fixed a priori, while theoretically grounded thresholds and careful model curation can support effective DDoS detection and mitigation. [1] Chow, C. K. 1970. On optimum recognition error and reject trade-off. IEEE Transactions on Information Theory 16, 1, 41–46. [2] Elkan, C. 2001. The foundations of cost-sensitive learning. IJCAI 2001, 973–978. [3] Hnamte, V. and Hussain, J. 2022. 1D-CNN/LSTM/GRU ensemble for DDoS detection. Intelligent Automation & Soft Computing 33, 2. [4] Diaba, S. Y. and Elmusrati, M. 2023. Proposed algorithm for smart grid DDoS detection based on deep learning. Engineering Applications of Artificial Intelligence (Elsevier), 175–184. [5] Najar, A. A. and Naik, S. M. 2024. APSO-optimised ensemble for multi-class DDoS detection. Computers & Security 139, 103716. $
Chat is not available.
Successful Page Load