arrow
Return

Proactive DoS and DDoS Attack Detection Through Behavior-Based Threat Intelligence

delete2026-06-10
delete0
delete
OA
AI
O
Orieb AbuAlghanam *
M
Malik AL-Essa
W
Wesam Almobaideen
M
Mohammad Qatawneh
A
Ahmad Sami Al‐Shamayleh
DOI:10.3390/electronics15122559delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
The rapid growth of cyberattacks necessitates the development of more sophisticated detection techniques. DoS and DDoS are well-known harmful attacks that affect organizations. This paper proposes a proactive, behavior-based DoS and DDoS detection framework that integrates threat intelligence and machine learning to analyze attack behavior and enhance early detection. XGBoost is used to train the proposed model and evaluate feature importance. The evaluation of the proposed model and the generated rules is conducted using three different datasets: CICIoT2023, BoT-IoT, and Edge-IIoT. Experimental results demonstrate high detection performance, achieving up to 99.98% accuracy and 99.89% F1-score, while maintaining low false positive rates across diverse datasets. Integrating threat intelligence into SIEM has been evaluated using two datasets, DDoS-AT-2022 and CIC-DDoS2019. The rule-based detection technique enhances detection rates and mitigates false positives. Moreover, the proposed framework enhances detection accuracy.
Keywords:
behavioral analysis
DDoS detection
threat intelligence
MITRE ATT&CK
XGBoost
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Electronics cover
Electronics
IF:
2.6
Papers:
9.3K
Citations:
4.7W

Organization

A
al-ahliyya amman university
Scholars:
677
Papers: 672
Citations: 0
T
The University of Jordan
Scholars:
555
Papers: 253
Citations: 0