An approach to protecting corporate networks from DDoS attacks based on machine learning and neural networks

Cover Page

Cite item

Full Text

Open Access Open Access
Restricted Access Access granted
Restricted Access Subscription or Fee Access

Abstract

The purpose of this study is to develop an approach for implementing DDoS protection mechanisms in corporate networks using a decision-making system based on machine learning methods. The proposed DDoS attack detection process comprises several stages, including data collection and analysis, model training, feature selection, validation, performance evaluation, and continuous monitoring with retraining. Data were collected using packet capture libraries and traffic analyzers. Neural network training involved dividing the dataset into training and test subsets through standard functions, which ensured accurate evaluation of the model on previously unseen data. Feature selection was performed in two stages: automated statistical analysis and expert validation. Cross-validation and early stopping techniques were applied to prevent overfitting and maintain optimal model performance.

At the monitoring and retraining stage, the model was deployed in a real network environment, where selected metrics enabled tracking of algorithm performance, detection of traffic variations, and initiation of adaptive updates. To enhance network security, a hardware—software filtering module was implemented based on access control lists and programmable logic integrated circuits (PLCs). To verify the effectiveness of the proposed methods, a dedicated test bench was developed for simulating various types of DDoS attacks, including MAC flood, ICMP flood, SYN flood, UDP flood, and Layer 7 attacks.

The resulting architecture, which integrates machine learning algorithms, access control mechanisms, and hardware-based filtering, provides comprehensive detection and mitigation of attacks at the L2—L4 and L7 layers of the OSI model. This approach enables timely threat identification, reduces incident response time, and can be integrated into corporate infrastructures as a component of a cybersecurity decision-support system.

Full Text

Restricted Access

About the authors

A. A. Alekseeva

Kazan National Research Technological University

Author for correspondence.
Email: annank90@mail.ru

Cand. of Tech. Sc., Assistant Professor

Russian Federation, Kazan

L. K. Safiullina

Kazan National Research Technological University

Email: lina.kh.safiullina@mail.ru

Cand. of Tech. Sc., Assistant Professor

Russian Federation, Kazan

A. M. Sadykov

Kazan National Research Technological University

Email: alex.sadykov@mail.ru

Cand. of Tech. Sc., Assistant Professor

Russian Federation, Kazan

References

  1. Razumov P. V., Safaryan O. А., Smirnov I. А., Porksheyan V. M., Boldyrikhin N. V., Korochentsev D. А., Cherckesova L. V., Osikov S. A. Developing of Algorithm of HTTP FLOOD DDoS Protection, 2020 3rd International Conference on Computer Applications & Information Security (ICCAIS). IEEE, 2020, pp. 1—6, doi: 10.1109/ICCAIS48893.2020.9096870.
  2. Peruhin M. Yu., Voronina L. T., Safiullina L. Kh., Alekseeva А. А. Designing a secure corporate network using VPN, Mezhdunarodnyj nauchno-issledovatel’skij zhurnal, 2025, vol. 3, no. 153, pp. 1—7, doi: 10.60797/IRJ.2025.153.44 (in Russian).
  3. Zakalkin P. V. Dobryshin M. M., Brechko A. А., Gucyn R. V. А proposal to reduce the damage caused by network attacks to a VPN server, Voprosy oboronnoj tekhniki. Seriya 16: Tekhnicheskie sredstva protivodejstviya terrorizmu, 2020, vol. 3—4, no. 141—142, pp. 111—116 (in Russian).
  4. Palchevsky E. V., Khristodulo O. I. Developing a self-learning method for a spiking neural network to protect against DDoS attacks, Software & Systems, 2019, vol. 32, no. 3, pp. 419—432, doi: 10.15827/0236-235X.127.419-432 (in Russian).
  5. Sadykov A. M., Evdokimov A. A. DDoS attack and how to protect yourself from it, Innovacionny`e texnologii: teoriya, instrumenty`, praktika, 2024, vol. 1, pp. 506—512.
  6. Loshchilin A. V., YArikov V. G., Nikishova А. V. Machine learning methods in predicting and preventing cyberattacks, NBI-technologies, 2024, vol. 18, no. 2, pp. 33—39, doi: 10.15688/NBIT.jvolsu.2024.2.5 (in Russian).
  7. Avdoshin S. M., Pesotskaya E.nY., Patrushev K. A. Technologies of trusted artificial intelligence, Informacionnye Tehnologii, 2024, vol. 30, no. 8, pp. 400—410, doi: 10.17587/it.30.400-410
  8. Ivanov S. O. А technique for creating and training an artificial neural network to detect network traffic anomalies, Informacionnye Tehnologii, 2024, vol. 30, no. 1, pp. 32—41, doi: 10.17587/it.30.32-41.
  9. Gapsalamov A. R., Akhmetshin E. M., Sharipov R. R., Vasilev V. L., Bochkareva T. N. Approaches to Information Security in Educational Processes in the Context of Digitalization, TEM Journal, 2020, pp. 708—715, doi: 10.18421/TEM92-38.
  10. Mittal M., Kumar K., Behal S. Deep learning approaches for detecting DDoS attacks: a systematic review, Soft comput, 2023, vol. 27, no.18, pp. 13039—13075, doi: 10.1007/s00500-021-06608-1.
  11. Klimenko T. M., Akzhigitov R. R. А Review of Machine Learning and Deep Learning-Based Detection Methods for Distributed Denial of Service Attacks, International Journal of Open Information Technologies, 2023, vol. 11, no. 6, pp. 46—66 (in Russian).
  12. Kulinchenko V. N. PCAP and WinPCap libraries one packet sensing LAN channels, Izvestiya Gomel’skogo gosudarstvennogo universiteta im. F. Skoriny, 2011, vol. 6, no. 69, pp. 187—190 (in Russian).
  13. Zuev V. N. Network anomalies detection by deep learning, Software & Systems, 2021, vol. 34, no. 1, pp. 91—97, doi: 10.15827/0236-235X.133.091-097 (in Russian).
  14. Murthy B. N., Siddappa M. An Efficient Intrusion Detection System in Cloud Network Based on Deep Learning and Improved Marine Predators-Particle Swarm Optimization, International Journal of Intelligent Engineering and Systems, 2023, vol. 16, no. 6, pp. 60—71, doi: 10.22266/ijies2023.1231.06.
  15. Sergadeeva A. I., Lavrova D. S. Application of a modular neural network to detect DDoS attacks, Problemy informacionnoj bezopasnosti. Komp’yuternye sistemy., 2023. vol. 1, no. 53, pp. 111—118, doi: 10.48612/jisp/65d1-nu8m-8euv (in Russian).
  16. Namiot D. E., Il’yushin E. A. Monitoring data drift in machine learning models, International Journal of Open Information Technologies, 2022, vol. 10, no. 12, pp. 84—93 (in Russian).
  17. Denisenko V. V., Maslov A. A., Chesnikov L. S., Klimenko K. S. Hyperparameter optimization in machine learning models: a comparative study, Automation. Modern Technologies, 2023, vol. 77, no. 10, pp. 475—480, doi: 10.36652/0869-4931-2023-77-10-475-480 (in Russian).
  18. Liu Y., Li Y., Xie D. Implications of imbalanced datasets for empirical ROC-AUC estimation in binary classification tasks, J Stat Comput Simul, 2024, vol. 94, no. 1, pp. 183—203, doi: 10.1080/00949655.2023.2238235.
  19. Soltani M., Khajavi K., Siavoshani M. J., Jahangir A. H. А Multi-Agent Adaptive Deep Learning Framework for Online Intrusion Detection, 2023, doi: 10.48550/arXiv.2303.02622.
  20. Theobald S., Vesth T. C., Andersen M. R. Genus level analysis of PKS-NRPS and NRPS-PKS hybrids reveals their origin in Aspergilli, BMC Genomics, 2019, vol. 20, no. 1, pp. 847, doi: 10.1186/s12864-019-6114-2.

Supplementary files

Supplementary Files
Action
1. JATS XML
2. Fig. 1. Software and hardware system for network traffic analysis

Download (39KB)
3. Fig. 2. Test stand

Download (44KB)
4. Fig. 3. Accuracy assessment of classification using different machine learning algorithms

Download (28KB)
5. Fig. 4. AUC Accuracy Assessment

Download (41KB)
6. Fig. 5. Adapted architecture for detecting and responding to DDoS attacks

Download (50KB)
7. Fig. 6. Comparison of the response time of the receiving node

Download (41KB)
8. Fig. 7. Analysis of L3-L4 stability against DDoS attacks

Download (80KB)

Copyright (c) 2026 Informacionnye Tehnologii



СМИ зарегистрировано Федеральной службой по надзору в сфере связи, информационных технологий и массовых коммуникаций (Роскомнадзор).
Регистрационный номер и дата принятия решения о регистрации СМИ: серия ПИ № 77 - 15565 от 02 июня 2003 г.