Academic Journal

Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach.

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach.
Συγγραφείς: Kumar, Amardeep, Khan, Danish Ali, Amin, Ruhul
Πηγή: Cluster Computing; Dec2025, Vol. 28 Issue 15, p1-19, 19p
Θεματικοί όροι: Denial of service attacks, Ensemble learning, Internet security, HTTP (Computer network protocol), Machine learning
Περίληψη: An ensemble learning paradigm is a widely adopted machine learning strategy that has demonstrated significant benefits across various applications. In this context, an ensemble refers to a system composed of multiple models that operate concurrently and integrate their outputs through decision fusion to yield a single predictive solution. Distributed Denial of Service (DDoS) attacks at the application layer have amplified the impact of traditional flooding-based attacks, posing an increasing threat to internet-based web services. These high-level attacks can cause comparable damage to their lower-layer counterparts while using fewer resources. HTTP, being the most widely used internet protocol, is frequently targeted in such flooding-based application-layer DDoS scenarios. To address these challenges, an alternative ensemble-based detection approach is presented and evaluated using several base classifiers, including K-Nearest Neighbours, Logistic Regression(LR), Support Vector Machine (SVM), Gaussian Naïve Bayes, and Self-Organizing Maps (SOM). In addition, ensemble learning techniques such as Bagging, Random Forest, Extra Trees, Voting, and Gradient Boosting are employed to assess their effectiveness in DDoS detection. Experimental findings indicate that ensemble approaches consistently yield superior performance compared to individual classifiers. A novel ensemble framework, termed Random Subspace and Parameter Fusion (RSPF), is introduced. This model achieves higher accuracy and efficiency than traditional ensemble methods, thereby enhancing detection capabilities and consistently delivering robust performance against application-layer DDoS attacks. Evaluation is conducted using the CICIDS2019 dataset, which offers comprehensive coverage of modern network intrusion scenarios and is suitable for benchmarking a wide range of cyberattack detection techniques. [ABSTRACT FROM AUTHOR]
Copyright of Cluster Computing is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Βάση Δεδομένων: Complementary Index
FullText Links:
  – Type: other
Text:
  Availability: 0
CustomLinks:
  – Url: https://dx.doi.org/doi:10.1007/s10586-025-05671-9
    Name: EDS - Springer Nature Journals (s7799221)
    Category: fullText
    Text: View record at Springer
Header DbId: edb
DbLabel: Complementary Index
An: 188547707
RelevancyScore: 1041
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 1040.81262207031
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Kumar%2C+Amardeep%22">Kumar, Amardeep</searchLink><br /><searchLink fieldCode="AR" term="%22Khan%2C+Danish+Ali%22">Khan, Danish Ali</searchLink><br /><searchLink fieldCode="AR" term="%22Amin%2C+Ruhul%22">Amin, Ruhul</searchLink>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: Cluster Computing; Dec2025, Vol. 28 Issue 15, p1-19, 19p
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Denial+of+service+attacks%22">Denial of service attacks</searchLink><br /><searchLink fieldCode="DE" term="%22Ensemble+learning%22">Ensemble learning</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22HTTP+%28Computer+network+protocol%29%22">HTTP (Computer network protocol)</searchLink><br /><searchLink fieldCode="DE" term="%22Machine+learning%22">Machine learning</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: An ensemble learning paradigm is a widely adopted machine learning strategy that has demonstrated significant benefits across various applications. In this context, an ensemble refers to a system composed of multiple models that operate concurrently and integrate their outputs through decision fusion to yield a single predictive solution. Distributed Denial of Service (DDoS) attacks at the application layer have amplified the impact of traditional flooding-based attacks, posing an increasing threat to internet-based web services. These high-level attacks can cause comparable damage to their lower-layer counterparts while using fewer resources. HTTP, being the most widely used internet protocol, is frequently targeted in such flooding-based application-layer DDoS scenarios. To address these challenges, an alternative ensemble-based detection approach is presented and evaluated using several base classifiers, including K-Nearest Neighbours, Logistic Regression(LR), Support Vector Machine (SVM), Gaussian Naïve Bayes, and Self-Organizing Maps (SOM). In addition, ensemble learning techniques such as Bagging, Random Forest, Extra Trees, Voting, and Gradient Boosting are employed to assess their effectiveness in DDoS detection. Experimental findings indicate that ensemble approaches consistently yield superior performance compared to individual classifiers. A novel ensemble framework, termed Random Subspace and Parameter Fusion (RSPF), is introduced. This model achieves higher accuracy and efficiency than traditional ensemble methods, thereby enhancing detection capabilities and consistently delivering robust performance against application-layer DDoS attacks. Evaluation is conducted using the CICIDS2019 dataset, which offers comprehensive coverage of modern network intrusion scenarios and is suitable for benchmarking a wide range of cyberattack detection techniques. [ABSTRACT FROM AUTHOR]
– Name: Abstract
  Label:
  Group: Ab
  Data: <i>Copyright of Cluster Computing is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edb&AN=188547707
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10586-025-05671-9
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 19
        StartPage: 1
    Subjects:
      – SubjectFull: Denial of service attacks
        Type: general
      – SubjectFull: Ensemble learning
        Type: general
      – SubjectFull: Internet security
        Type: general
      – SubjectFull: HTTP (Computer network protocol)
        Type: general
      – SubjectFull: Machine learning
        Type: general
    Titles:
      – TitleFull: Detecting application layer DDoS attacks with RSPF: A hybrid ensemble learning approach.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Kumar, Amardeep
      – PersonEntity:
          Name:
            NameFull: Khan, Danish Ali
      – PersonEntity:
          Name:
            NameFull: Amin, Ruhul
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: Dec2025
              Type: published
              Y: 2025
          Identifiers:
            – Type: issn-print
              Value: 13867857
          Numbering:
            – Type: volume
              Value: 28
            – Type: issue
              Value: 15
          Titles:
            – TitleFull: Cluster Computing
              Type: main
ResultId 1