Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Edge-Fog-Cloud Distributed Architecture for Intelligent DDoS Detection and Mitigation

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

Abstract Cloud and distributed infrastructures face significant challenges from increasingly sophisticated Distributed Denial-of-Service (DDoS) attacks. Real-time efficiency is limited by the latency and scalability issues that affect traditional centralized detection systems. This paper presents a multi-layered DDoS detection and mitigation framework built on the Edge-Fog-Cloud paradigm. Hierarchical intelligence is integrated into the architecture to strike a balance between adaptive defense, resource efficiency, and responsiveness. A threshold-guided lightweight classifier quickly distinguishes malicious, suspicious, and benign traffic at the edge. A compact Deep Neural Network (DNN) verifies anomalies in suspicious flows that are escalated to the fog. For context-aware mitigation, a deep classifier at the cloud layer categorizes confirmed attacks into two main families: reflection/amplification and exploitation. Evaluation on the CICDDoS2019 dataset demonstrates high accuracy, a low false-positive rate, and efficient traffic handling. The modular design ensures scalability and adaptability for modern distributed computing infrastructures.

Similar Papers
  • Book Chapter
  • Cite Count Icon 7
  • 10.1007/978-3-319-52015-5_35
A DDoS Detection and Mitigation System Framework Based on Spark and SDN
  • Jan 1, 2017
  • Qiao Yan + 1 more

Distributed Denial of Service (DDoS) attack is a serious threat to commercial service network. DDoS attack has been studied for years. However, detecting and relieving DDoS attacks are still a problem. Especially, nowadays more and more DDoS attacks produce heavy network traffic, it is hard to response rapidly because that needs high processing performance to process massive traffic data. With big data technology, volumes of network traffic data can be processed much faster. Apache Spark can process a great amount of data in a reasonable time so that DDoS attack can be detected in time. Besides, it is difficult to modify the network configuration in traditional network. With Software-Defined Networking (SDN), a new paradigm in networking, networking can be controlled by programs, which makes modifying the network configuration easier. In this paper, a DDoS detection and mitigation system framework in SDN is introduced, a framework that can control network based on analyzing the network traffic data. Comparing to the traditional defense methods of DDoS attack, the framework can response to DDoS attack by rules automatically.

  • Book Chapter
  • Cite Count Icon 5
  • 10.1007/978-981-15-5243-4_53
DDoS Prevention: Review and Issues
  • Jul 26, 2020
  • Shail Saharan + 1 more

Networks connected to the Internet are always susceptible to distributed denial-of-service (DDoS) attacks. In spite of a lot of different DDoS defense mechanisms in place, DDoS attacks still happen. These mechanisms fall under the category of DDoS detection, DDoS mitigation, and DDoS prevention. Although DDoS detection and mitigation are well defined and understood terms, DDoS prevention is used with different meanings in the literature. Concerning reflection-based DDoS amplification attacks, in this paper, we define ideal prevention and true prevention. Former is an ideal situation in which primarily the security of all the Internet hosts is well up to the mark and does not allow them to become participating members of DDoS attacks, whereas later is a practically feasible situation in which the network itself can prevent and mitigate DDoS attack within some fixed time interval. We also provide the literature review of DDoS prevention techniques and argue that the ones which conform to the definition of ideal prevention or true prevention are either not dynamic, are computationally expensive, or not scalable; thus, practically not feasible.

  • Research Article
  • Cite Count Icon 3
  • 10.1109/ojcoms.2025.3586199
A Survey on Distributed Denial-of-Service Attack Mitigation for 5G and Beyond
  • Jan 1, 2025
  • IEEE Open Journal of the Communications Society
  • Sanzida Hoque + 3 more

The introduction of 6G networks is expected to significantly change the threat landscape related to Distributed Denial of Service (DDoS) attacks, requiring robust detection and mitigation measures. This paper methodologically classifies and evaluates the growing collection of research efforts focusing on detection and protection mechanisms against DDoS attacks in 5G and beyond networks. The survey covers various methods used in the scientific literature and categorizes DDoS mitigation efforts into two main areas: DDoS detection and DDoS defense. It thoroughly analyzes each approach, highlighting its benefits, limitations, and effectiveness in mitigating DDoS attacks against B5G. This survey also discusses the experimental environments and data sets being used for each work by comparing them. Finally, we provide insights and directions for future research and development efforts to protect B5G networks against DDoS threats. Our results highlight gaps in current methods, including problems such as the lack of real-time testbed implementations and the inability to reproduce the results of experiments. In addition, we suggest future research directions that emphasize quantum-resistant solutions and scalable architectures for next-generation networks. This work aims to guide researchers and practitioners in developing robust and adaptive DDoS mitigation frameworks for evolving communication systems.

  • Conference Article
  • 10.1109/globecom59602.2025.11431920
Collaborative P4-SDN DDoS Detection and Mitigation with Early-Exit Neural Networks
  • Dec 8, 2025
  • Ouassim Karrakchou + 3 more

Distributed Denial of Service (DDoS) attacks pose a persistent threat to network security, requiring timely and scalable mitigation strategies. In this paper, we propose a novel collaborative architecture that integrates a P4-programmable data plane with an SDN control plane to enable real-time DDoS detection and response. At the core of our approach is a split early-exit neural network that performs partial inference in the data plane using a quantized Convolutional Neural Network (CNN), while deferring uncertain cases to a Gated Recurrent Unit (GRU) module in the control plane. This design enables high-speed classification at line rate with the ability to escalate more complex flows for deeper analysis. Experimental evaluation using real-world DDoS datasets demonstrates that our approach achieves high detection accuracy with significantly reduced inference latency and control plane overhead. These results highlight the potential of tightly coupled ML-P4-SDN systems for efficient, adaptive, and low-latency DDoS defense.

  • Research Article
  • Cite Count Icon 7
  • 10.1080/23335777.2021.1992798
ProSD-EdgeIoT: Protected Cluster assisted SDWSN for Tetrad Edge-IoT by Collaborative DDoS Detection and Mitigation
  • Nov 3, 2021
  • Cyber-Physical Systems
  • Vishnu V.M + 1 more

Software-Defined Networking (SDN) and Edge computing are the major elements due to its scalability, flexibility and efficiency. Still, security is one of the significant issues. Distributed Denial of Service (DDoS) is the harmful attack that exhausts many resources. The existing solutions consume large time for detection and present poor mitigation schemes. To address these issues, this paper presents a Protected Cluster-assisted SDWSN for Edge-IoT (ProSD-EdgeIoT) architecture. The ProSD-EdgeIoT follows tetrad architecture that performs clustering in the device layer, first-level DDoS detection in the edge layer,second-level DDoS detection in the control layer and multi-level DDoS mitigation in data forwarding layer.

  • Research Article
  • Cite Count Icon 124
  • 10.1016/j.cose.2023.103661
DDoS attack detection and mitigation using deep neural network in SDN environment
  • Dec 18, 2023
  • Computers & Security
  • Vanlalruata Hnamte + 4 more

DDoS attack detection and mitigation using deep neural network in SDN environment

  • Book Chapter
  • Cite Count Icon 1
  • 10.1007/978-3-031-35507-3_54
Machine Learning Method for DDoS Detection and Mitigation in a Multi-controller SDN Environment Using Cloud Computing
  • Jan 1, 2023
  • Ameni Chetouane + 2 more

Software Defined Networking (SDN) is widely used in many practical contexts and provides a method for managing networks by separating the data plane from the control plane. However, because of its centralized control logic, SDN is particularly susceptible to Distributed Denial of Service (DDoS) attacks. In numerous studies, methods based on Machine Learning (ML) have been proposed to identify DDoS attacks in the context of SDN. However, the proposed methods are resource intensive and unreliable in a large-scale SDN where a huge amount of traffic data is produced from control and data planes. This may exhaust computational resources, deteriorate the performance of the network, or even result in the shutdown of network systems as a result of resource exhaustion. To deal with the above issues, this paper presents a real-time DDoS detection and mitigation method in a multi-controller SDN environment using cloud computing. We propose to run the Machine Learning development cycle on a secured server in a virtual machine. Then we deploy back the trained model into the SDN controllers. All the exchanges between the virtual machine and the controllers are secured. In this way, we configure these controllers to detect and mitigate DDoS in SDN in real-time. Through useful experiments, we demonstrate that our method is secure, reliable, and efficient.

  • Research Article
  • Cite Count Icon 2
  • 10.3390/computers14110472
Feature-Optimized Machine Learning Approaches for Enhanced DDoS Attack Detection and Mitigation
  • Nov 1, 2025
  • Computers
  • Ahmed Jamal Ibrahim + 2 more

Distributed denial of service (DDoS) attacks pose a serious risk to the operational stability of a network for companies, often leading to service disruptions and financial damage and a loss of trust and credibility. The increasing sophistication and scale of these threats highlight the pressing need for advanced mitigation strategies. Despite the numerous existing studies on DDoS detection, many rely on large, redundant feature sets and lack validation for real-time applicability, leading to high computational complexity and limited generalization across diverse network conditions. This study addresses this gap by proposing a feature-optimized and computationally efficient ML framework for DDoS detection and mitigation using benchmark dataset. The proposed approach serves as a foundational step toward developing a low complexity model suitable for future real-time and hardware-based implementation. The dataset was systematically preprocessed to identify critical parameters, such as packet length Min, Total Backward Packets, Avg Fwd Segment Size, and others. Several ML algorithms, involving Logistic Regression, Decision Tree, Random Forest, Gradient Boosting, and Cat-Boost, are applied to develop models for detecting and mitigating abnormal network traffic. The developed ML model demonstrates high performance, achieving 99.78% accuracy with Decision Tree and 99.85% with Random Forest, representing improvements of 1.53% and 0.74% compared to previous work, respectively. In addition, the Decision Tree algorithm achieved 99.85% accuracy for mitigation. with an inference time as low as 0.004 s, proving its suitability for identifying DDoS attacks in real time. Overall, this research presents an effective approach for DDoS detection, emphasizing the integration of ML models into existing security systems to enhance real-time threat mitigation.

  • Research Article
  • Cite Count Icon 7
  • 10.1016/j.rineng.2025.104839
Detection and mitigation of distributed denial of service attacks in vehicular ad hoc network using a spatiotemporal deep learning and reinforcement learning approach
  • Jun 1, 2025
  • Results in Engineering
  • Naramalli Jayakrishna + 1 more

Detection and mitigation of distributed denial of service attacks in vehicular ad hoc network using a spatiotemporal deep learning and reinforcement learning approach

  • Conference Article
  • Cite Count Icon 11
  • 10.1109/iss1.2017.8389464
DDoS attack detection and mitigation techniques in cloud computing environment
  • Dec 1, 2017
  • B S Kiruthika Devi + 1 more

Cloud computing is the emerging technology and most of the IT enabled services are operating in this platform. In the recent era, the internet infrastructure relies on the cloud for their business and the cloud deployment model is inevitable. The important aspects of the cloud infrastructure are confidentiality, integrity, availability and accessibility. Availability is one of the major concern in providing services to the cloud users without disruption. There exists security and privacy issues in the cloud that affects the cloud utilities. Distributed Denial of Service (DDoS) attack is one of the major cloud security attack that needs utmost consideration. The cloud resources are degraded and the access to critical services are denied to genuine users leading to severe financial loss, data theft and non-repudiation. The article provides an overview of the DDoS attacks in cloud, recent trends and the existing methodologies that are adopted for ensuring cloud security. The threats alarming the security in cloud and the DDoS detection and mitigation methods are discussed and compared to comprehend the significance of the current deployed solutions. Further, the need for devising effective DDoS countermeasures are emphasized and the recent era in cloud computing requires strong security standards and solutions for real time deployment.

  • Research Article
  • Cite Count Icon 1
  • 10.37933/nipes/7.3.2025.11
Machine Learning-Driven Cybersecurity Solutions for Enhanced Smart Grids and Critical Infrastructure: A Review
  • Jul 8, 2025
  • NIPES - Journal of Science and Technology Research
  • Afe Idowu + 2 more

Distributed Denial of Service (DDoS) attacks have emerged as one of the most pervasive and damaging threats to network security, disrupting services and incurring substantial financial costs. Machine learning (ML) has been widely explored as a potential solution to enhance DDoS detection and mitigation. This systematic review evaluates the effectiveness of ML techniques in detecting DDoS attacks, synthesizing findings from studies published between 2004 and 2024. The review analyzes models such as Random Forest, Support Vector Machines (SVM), and K-Nearest Neighbors (K-NN) based on key performance metrics like accuracy, precision, recall, and F1-score. A comprehensive search of multiple databases, including Web of Science, IEEE, Scopus, ScienceDirect, and Google Scholar, resulted in 19 studies that met inclusion criteria. The findings show that ensemble methods, particularly Random Forest, consistently outperformed other models in terms of detection rates, mainly due to their ability to handle large feature sets and reduce overfitting. Support Vector Machines also performed well in specific scenarios. However, their effectiveness was sometimes limited by computational complexity and the dataset size. K-Nearest Neighbors showed mixed results, depending on the nature of the attack patterns. This review emphasizes the potential of ensemble learning approaches for DDoS detection, demonstrating their robustness in dynamic environments. The review identifies key gaps in the existing research, including the need for better feature selection and exploring deep learning techniques to enhance DDoS detection accuracy and adaptability further. This study contributes valuable insights into the strengths and limitations of ML-based DDoS detection models, offering a foundation for future advancements in the field. It underscores the importance of continued research into hybrid and deep learning models to address the evolving and increasingly sophisticated nature of DDoS attacks in real-world applications.

  • Conference Article
  • Cite Count Icon 13
  • 10.1145/3148055.3148077
An Unsupervised Approach for Online Detection and Mitigation of High-Rate DDoS Attacks Based on an In-Memory Distributed Graph Using Streaming Data and Analytics
  • Dec 5, 2017
  • J J Villalobos + 2 more

A Distributed Denial of Service (DDoS) attack is an attempt to make an online service, a network, or even an entire organization, unavailable by saturating it with traffic from multiple sources. DDoS attacks are among the most common and most devastating threats that network defenders have to watch out for. DDoS attacks are becoming bigger, more frequent, and more sophisticated. Volumetric attacks are the most common types of DDoS attacks. A DDoS attack is considered volumetric, or high-rate, when within a short period of time it generates a large amount of packets or a high volume of traffic. High-rate attacks are well-known and have received much attention in the past decade; however, despite several detection and mitigation strategies have been designed and implemented, high-rate attacks are still halting the normal operation of information technology infrastructures across the Internet when the protection mechanisms are not able to cope with the aggregated capacity that the perpetrators have put together. With this in mind, the present paper aims to propose and test a distributed and collaborative architecture for online high-rate DDoS attack detection and mitigation based on an in-memory distributed graph data structure and unsupervised machine learning algorithms that leverage real-time streaming data and analytics. We have successfully tested our proposed mechanism using a real-world DDoS attack dataset at its original rate in pursuance of reproducing the conditions of an actual large scale attack.

  • Research Article
  • Cite Count Icon 56
  • 10.3390/su13031522
Entropy Based Features Distribution for Anti-DDoS Model in SDN
  • Feb 1, 2021
  • Sustainability
  • Raja Majid Ali Ujjan + 5 more

In modern network infrastructure, Distributed Denial of Service (DDoS) attacks are considered as severe network security threats. For conventional network security tools it is extremely difficult to distinguish between the higher traffic volume of a DDoS attack and large number of legitimate users accessing a targeted network service or a resource. Although these attacks have been widely studied, there are few works which collect and analyse truly representative characteristics of DDoS traffic. The current research mostly focuses on DDoS detection and mitigation with predefined DDoS data-sets which are often hard to generalise for various network services and legitimate users’ traffic patterns. In order to deal with considerably large DDoS traffic flow in a Software Defined Networking (SDN), in this work we proposed a fast and an effective entropy-based DDoS detection. We deployed generalised entropy calculation by combining Shannon and Renyi entropy to identify distributed features of DDoS traffic—it also helped SDN controller to effectively deal with heavy malicious traffic. To lower down the network traffic overhead, we collected data-plane traffic with signature-based Snort detection. We then analysed the collected traffic for entropy-based features to improve the detection accuracy of deep learning models: Stacked Auto Encoder (SAE) and Convolutional Neural Network (CNN). This work also investigated the trade-off between SAE and CNN classifiers by using accuracy and false-positive results. Quantitative results demonstrated SAE achieved relatively higher detection accuracy of 94% with only 6% of false-positive alerts, whereas the CNN classifier achieved an average accuracy of 93%.

  • Research Article
  • Cite Count Icon 100
  • 10.1016/j.jnca.2021.103093
Emerging DDoS attack detection and mitigation strategies in software-defined networks: Taxonomy, challenges and future directions
  • May 11, 2021
  • Journal of Network and Computer Applications
  • Ismael Amezcua Valdovinos + 3 more

Emerging DDoS attack detection and mitigation strategies in software-defined networks: Taxonomy, challenges and future directions

  • Research Article
  • Cite Count Icon 11
  • 10.2139/ssrn.3852902
Distributed Denial of Service Attacks Prevention, Detection and Mitigation – A Review
  • Jan 1, 2021
  • SSRN Electronic Journal
  • Rahamathullah U + 1 more

Distributed Denial of Service Attacks Prevention, Detection and Mitigation – A Review

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant