Academic Journal
Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach.
| Τίτλος: | Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach. |
|---|---|
| Συγγραφείς: | Kumar, Amardeep, Khan, Danish Ali, Amin, Ruhul |
| Πηγή: | Cluster Computing; Dec2025, Vol. 28 Issue 15, p1-19, 19p |
| Θεματικοί όροι: | Denial of service attacks, Ensemble learning, Internet security, HTTP (Computer network protocol), Machine learning |
| Περίληψη: | An ensemble learning paradigm is a widely adopted machine learning strategy that has demonstrated significant benefits across various applications. In this context, an ensemble refers to a system composed of multiple models that operate concurrently and integrate their outputs through decision fusion to yield a single predictive solution. Distributed Denial of Service (DDoS) attacks at the application layer have amplified the impact of traditional flooding-based attacks, posing an increasing threat to internet-based web services. These high-level attacks can cause comparable damage to their lower-layer counterparts while using fewer resources. HTTP, being the most widely used internet protocol, is frequently targeted in such flooding-based application-layer DDoS scenarios. To address these challenges, an alternative ensemble-based detection approach is presented and evaluated using several base classifiers, including K-Nearest Neighbours, Logistic Regression(LR), Support Vector Machine (SVM), Gaussian Naïve Bayes, and Self-Organizing Maps (SOM). In addition, ensemble learning techniques such as Bagging, Random Forest, Extra Trees, Voting, and Gradient Boosting are employed to assess their effectiveness in DDoS detection. Experimental findings indicate that ensemble approaches consistently yield superior performance compared to individual classifiers. A novel ensemble framework, termed Random Subspace and Parameter Fusion (RSPF), is introduced. This model achieves higher accuracy and efficiency than traditional ensemble methods, thereby enhancing detection capabilities and consistently delivering robust performance against application-layer DDoS attacks. Evaluation is conducted using the CICIDS2019 dataset, which offers comprehensive coverage of modern network intrusion scenarios and is suitable for benchmarking a wide range of cyberattack detection techniques. [ABSTRACT FROM AUTHOR] |
| Copyright of Cluster Computing is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Βάση Δεδομένων: | Complementary Index |
| FullText | Links: – Type: other Text: Availability: 0 CustomLinks: – Url: https://dx.doi.org/doi:10.1007/s10586-025-05671-9 Name: EDS - Springer Nature Journals (s7799221) Category: fullText Text: View record at Springer |
|---|---|
| Header | DbId: edb DbLabel: Complementary Index An: 188547707 RelevancyScore: 1041 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 1040.81262207031 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Kumar%2C+Amardeep%22">Kumar, Amardeep</searchLink><br /><searchLink fieldCode="AR" term="%22Khan%2C+Danish+Ali%22">Khan, Danish Ali</searchLink><br /><searchLink fieldCode="AR" term="%22Amin%2C+Ruhul%22">Amin, Ruhul</searchLink> – Name: TitleSource Label: Source Group: Src Data: Cluster Computing; Dec2025, Vol. 28 Issue 15, p1-19, 19p – Name: Subject Label: Subject Terms Group: Su Data: <searchLink fieldCode="DE" term="%22Denial+of+service+attacks%22">Denial of service attacks</searchLink><br /><searchLink fieldCode="DE" term="%22Ensemble+learning%22">Ensemble learning</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22HTTP+%28Computer+network+protocol%29%22">HTTP (Computer network protocol)</searchLink><br /><searchLink fieldCode="DE" term="%22Machine+learning%22">Machine learning</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: An ensemble learning paradigm is a widely adopted machine learning strategy that has demonstrated significant benefits across various applications. In this context, an ensemble refers to a system composed of multiple models that operate concurrently and integrate their outputs through decision fusion to yield a single predictive solution. Distributed Denial of Service (DDoS) attacks at the application layer have amplified the impact of traditional flooding-based attacks, posing an increasing threat to internet-based web services. These high-level attacks can cause comparable damage to their lower-layer counterparts while using fewer resources. HTTP, being the most widely used internet protocol, is frequently targeted in such flooding-based application-layer DDoS scenarios. To address these challenges, an alternative ensemble-based detection approach is presented and evaluated using several base classifiers, including K-Nearest Neighbours, Logistic Regression(LR), Support Vector Machine (SVM), Gaussian Naïve Bayes, and Self-Organizing Maps (SOM). In addition, ensemble learning techniques such as Bagging, Random Forest, Extra Trees, Voting, and Gradient Boosting are employed to assess their effectiveness in DDoS detection. Experimental findings indicate that ensemble approaches consistently yield superior performance compared to individual classifiers. A novel ensemble framework, termed Random Subspace and Parameter Fusion (RSPF), is introduced. This model achieves higher accuracy and efficiency than traditional ensemble methods, thereby enhancing detection capabilities and consistently delivering robust performance against application-layer DDoS attacks. Evaluation is conducted using the CICIDS2019 dataset, which offers comprehensive coverage of modern network intrusion scenarios and is suitable for benchmarking a wide range of cyberattack detection techniques. [ABSTRACT FROM AUTHOR] – Name: Abstract Label: Group: Ab Data: <i>Copyright of Cluster Computing is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=188547707 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1007/s10586-025-05671-9 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 19 StartPage: 1 Subjects: – SubjectFull: Denial of service attacks Type: general – SubjectFull: Ensemble learning Type: general – SubjectFull: Internet security Type: general – SubjectFull: HTTP (Computer network protocol) Type: general – SubjectFull: Machine learning Type: general Titles: – TitleFull: Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Kumar, Amardeep – PersonEntity: Name: NameFull: Khan, Danish Ali – PersonEntity: Name: NameFull: Amin, Ruhul IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 12 Text: Dec2025 Type: published Y: 2025 Identifiers: – Type: issn-print Value: 13867857 Numbering: – Type: volume Value: 28 – Type: issue Value: 15 Titles: – TitleFull: Cluster Computing Type: main |
| ResultId | 1 |