A Hybrid Deterministic–Machine Learning Framework for Bandwidth-Efficient Ddos Detection in Iot Networks
DOI:
Keywords:
Deterministic Filtering, Distributed Denial-ofService (DDoS), Hybrid Detection, IoT Security, Lightweight Defense., Machine learningAbstract
The spread of Internet of Things (IoT) devices has significantly expanded the attack surface for Distributed Denial-of-Service (DDoS) threats, exposing resource-constrained gateways to bandwidth exhaustion and service disruption. While machine learning (ML)–based detection systems achieve strong accuracy, their computational cost renders them impractical for IoT environments. Conversely, lightweight deterministic filters provide efficiency but lack adaptability to evolving attack strategies. This study presents a Hybrid Deterministic–Machine Learning (HD-ML) framework that integrates deterministic packet verification with lightweight supervised classifiers to achieve both scalability and adaptability. The framework filters trivially malicious traffic at the gateway and forwards only residual ambiguous flows for ML-based classification. Using NS-3 simulations, we generated a dataset of over 100,000 packets, extracted flow-level features, and evaluated multiple classifiers including Decision Tree, Naïve Bayes, Logistic Regression, Random Forest, and Support Vector Machine (SVM). Results demonstrate that the HD-ML framework achieves an overall detection accuracy of 98.8% with a false positive rate as low as 0.8%, significantly outperforming standalone deterministic or ML-based approaches. Among the classifiers, SVM exhibited the highest performance with a perfect ROC-AUC score of 1.0 and an F1-Score of 0.926, confirming its suitability for residual traffic analysis. The proposed framework therefore offers a bandwidth-efficient, computationally lightweight, and adaptive defense mechanism for real-time DDoS mitigation in IoT networks.
References
(2023) Number of IoT connected devices worldwide 2019-2030.
N. Hassan, S. S. Gill, L. Xu (2020) Security and privacy in edge-enabled IoT: State-of-the-art and future directions. 7(10), 10345-10372. https://doi.org/10.1109/JIOT.2020.2985611
C. Kolas, G. Kambourakis, A. Stavrou, S. Gritzalis (2017) DDoS in the IoT: Mirai and other botnets. 50(7), 80-84. https://doi.org/10.1109/MC.2017.201
S. Yu, J. Liu, W. Zhou (2020) A survey on DDoS attacks and defense mechanisms. 53(6), 1-36. https://doi.org/10.1145/3417980
M. A. Islam, M. M. Hossain, M. R. Karim (2020) A lightweight DDoS attack detection scheme using statistical analysis and information gain. 8, 198847-198856. https://doi.org/10.1109/ACCESS.2020.3034961
R. Tian, J. Wang, J. Liu, W. Zhang (2022) A deep learning-based method for DDoS detection using LSTM and GRU. 78, 10157-10177. https://doi.org/10.1007/s11227-021-04032-4
M. Antonakakis (2017) Understanding the Mirai botnet. 1093-1110.
L. Bazzi, G. Marchetto, R. Sisto (2022) Advanced mitigation techniques for DDoS attacks: A review. 127, 14-29. https://doi.org/10.1016/j_future.2021.09.031
Q. Chen, J. Wang, X. He (2020) Adaptive detection of low-rate DDoS attacks based on self-similarity in network traffic. 8, 153748-153757. https://doi.org/10.1109/ACCESS.2020.3018941
R. Hou, Y. Zhao, X. Liu (2020) Slow DDoS attack detection using graph entropy. 94, 101824. https://doi.org/10.1016/j.cose.2020.101824
M. Ghazizadeh, M. Hashemi, A. Taherkordi (2021) Software-defined DDoS detection and mitigation: Approaches, challenges and future directions. 180, 103009. https://doi.org/10.1016/j.jnca.2021.103009
B. Alzahrani, N. Alomar, F. Alhaidari (2021) DDoS attack detection and mitigation in IoT-based cloud using ensemble learning. 69(2), 2043-2059. https://doi.org/10.32604/cmc.2021.014308
J. Mugerwa, C. Ajaegbu, E. Oyerinde, S. O. Awodele (2025) An efficient MAC-based ICMP verification algorithm for early detection of bandwidth-depleting DDoS attacks. 8(2), 130-140. https://doi.org/10.52589/BJCNIT-BQJKBU5P
A. K. Sood, R. J. Enbody (2021) Targeted DDoS attacks in IoT ecosystems. 19(1), 36-45. https://doi.org/10.1109/MSEC.2020.3029350
A. Alrawais, A. Alhonthaily, C. Hu, X. Cheng (2017) Fog computing for the Internet of Things: Security and privacy issues. 21(2), 34-42. https://doi.org/10.1109/MIC.2017.36
D. S. Berman, A. L. Buczak, J. S. Chavis, C. L. Corbett (2019) A survey of deep learning methods for cyber security. 10(4), 122. https://doi.org/10.3390/info10040122
M. Shahid, H. Abbas, R. A. Shaikh (2020) IoT protocols: A comprehensive review. 12(9), 149. https://doi.org/10.3390/fi12090149
S. Kumar, S. Shukla, R. Tripathi (2019) Entropy-based DDoS detection in cloud computing. 152, 99-106. https://doi.org/10.1016/j.procs.2019.05.013
M. Idhammad, K. Afdel, M. Belouch (2018) Semi-supervised machine learning approach for DDoS detection. 41, 1-11. https://doi.org/10.1016/j.jisa.2018.05.001
R. Doshi, N. Apthorpe, N. Teamster (2018) Machine learning DDoS detection for consumer IoT devices. 29-35. https://doi.org/10.1109/SPW.2018.00013
R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, S. Venkatraman (2019) Deep learning approach for intelligent intrusion detection system. 7, 41525-41550. https://doi.org/10.1109/ACCESS.2019.2895334
J. Zhang, Y. Li, Y. Wang (2021) Deep learning for network anomaly detection: A survey. 191, 108077. https://doi.org/10.1016/j.comnet.2021.108077
A. Shukla, A. K. Tyagi (2021) PCA-based anomaly detection in IoT networks. 118, 3441-3462. https://doi.org/10.1007/s11277-021-08250-y
R. Doriguzzi-Corin, D. Siracusa, A. Capone, A. Campi (2020) LSTM-based anomaly detection in network traffic. 17(3), 1328-1341. https://doi.org/10.1109/TNSM.2020.2993175
J. Zheng, F. Jiang, L. Wang, J. Liu (2020) A hybrid CNN-LSTM model for DDoS detection. 8, 172032-172045. https://doi.org/10.1109/ACCESS.2020.3024507
F. Hussain, R. Hussain, S. A. Hassan, E. Hossain (2020) Machine learning in IoT security: Current solutions and future challenges. 22(3), 1686-1721. https://doi.org/10.1109/COMST.2020.2986444
A. Singh, T. De (2020) Hybrid entropy-SVM model for DDoS detection in IoT. 158, 1-12. https://doi.org/10.1016/j.comcom.2020.04.029
M. Ahmed, A. N. Mahmood, J. Hu (2021) A hybrid statistical-machine learning approach for anomaly detection in IoT networks. 190, 103160. https://doi.org/10.1016/j.jnca.2021.103160
K. S. Sahoo, S. N. Mohanty, S. K. Udgata (2020) A hybrid anomaly detection model for IoT traffic using statistical and machine learning techniques. 19(4), 425-439. https://doi.org/10.1007/s10207-019-00478-3
R. Kumar, Y. Lim (2022) SDN-based DDoS detection and mitigation in IoT networks: A hybrid approach. 205, 108736. https://doi.org/10.1016/j.comnet.2021.108736
D. Kreutz, F. M. Ramos, P. E. Verissimo, C. E. Rothenberg, S. Azodolmolky, S. Uhlig (2015) Software-defined networking: A comprehensive survey. 103(1), 14-76. https://doi.org/10.1109/JPROC.2014.2371999
Y. Fang, J. Zhang, L. Zhou (2021) Blockchain for IoT: A survey on recent advances. 117, 721-739. https://doi.org/10.1016/j_future.2020.12.016
M. S. Ali, M. Vecchio, M. Pincheira, K. Dolui, F. Antonelli, M. H. Rehmani (2018) Applications of blockchains in the Internet of Things: A comprehensive survey. 21(2), 1676-1717. https://doi.org/10.1109/COMST.2018.2886932
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Authors and Global Journals Private Limited

This work is licensed under a Creative Commons Attribution 4.0 International License.
