<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Informacionnye Tehnologii</journal-id><journal-title-group><journal-title xml:lang="en">Informacionnye Tehnologii</journal-title><trans-title-group xml:lang="ru"><trans-title>Информационные технологии</trans-title></trans-title-group></journal-title-group><issn publication-format="print">1684-6400</issn><publisher><publisher-name xml:lang="en">New Technologies Publishing House</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">717425</article-id><article-id pub-id-type="doi">10.17587/it.32.428-436</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>Information security</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>Безопасность информации</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">An approach to protecting corporate networks from DDoS attacks based on machine learning and neural networks</article-title><trans-title-group xml:lang="ru"><trans-title>Подход к защите корпоративных сетей от DDoS-атак на основе методов машинного обучения и нейронных сетей</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Alekseeva</surname><given-names>A. A.</given-names></name><name xml:lang="ru"><surname>Алексеева</surname><given-names>А. А.</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Cand. of Tech. Sc., Assistant Professor</p></bio><bio xml:lang="ru"><p>канд. техн. наук, доц.</p></bio><email>annank90@mail.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Safiullina</surname><given-names>L. K.</given-names></name><name xml:lang="ru"><surname>Сафиуллина</surname><given-names>Л. Х.</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Cand. of Tech. Sc., Assistant Professor</p></bio><bio xml:lang="ru"><p>канд. техн. наук, доц.</p></bio><email>lina.kh.safiullina@mail.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Sadykov</surname><given-names>A. M.</given-names></name><name xml:lang="ru"><surname>Садыков</surname><given-names>А. М.</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Cand. of Tech. Sc., Assistant Professor</p></bio><bio xml:lang="ru"><p>канд. техн. наук, доц.</p></bio><email>alex.sadykov@mail.ru</email><xref ref-type="aff" rid="aff1"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">Kazan National Research Technological University</institution></aff><aff><institution xml:lang="ru">Казанский национальный исследовательский технологический университет</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2026-08-21" publication-format="electronic"><day>21</day><month>08</month><year>2026</year></pub-date><volume>32</volume><issue>8</issue><issue-title xml:lang="en"/><issue-title xml:lang="ru"/><fpage>428</fpage><lpage>436</lpage><history><date date-type="received" iso-8601-date="2026-08-21"><day>21</day><month>08</month><year>2026</year></date><date date-type="accepted" iso-8601-date="2026-08-21"><day>21</day><month>08</month><year>2026</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2026, Informacionnye Tehnologii</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2026, Информационные технологии</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="en">Informacionnye Tehnologii</copyright-holder><copyright-holder xml:lang="ru">Информационные технологии</copyright-holder></permissions><self-uri xlink:href="https://journals.eco-vector.com/1684-6400/article/view/717425">https://journals.eco-vector.com/1684-6400/article/view/717425</self-uri><abstract xml:lang="en"><p>The purpose of this study is to develop an approach for implementing DDoS protection mechanisms in corporate networks using a decision-making system based on machine learning methods. The proposed DDoS attack detection process comprises several stages, including data collection and analysis, model training, feature selection, validation, performance evaluation, and continuous monitoring with retraining. Data were collected using packet capture libraries and traffic analyzers. Neural network training involved dividing the dataset into training and test subsets through standard functions, which ensured accurate evaluation of the model on previously unseen data. Feature selection was performed in two stages: automated statistical analysis and expert validation. Cross-validation and early stopping techniques were applied to prevent overfitting and maintain optimal model performance.</p> <p>At the monitoring and retraining stage, the model was deployed in a real network environment, where selected metrics enabled tracking of algorithm performance, detection of traffic variations, and initiation of adaptive updates. To enhance network security, a hardware—software filtering module was implemented based on access control lists and programmable logic integrated circuits (PLCs). To verify the effectiveness of the proposed methods, a dedicated test bench was developed for simulating various types of DDoS attacks, including MAC flood, ICMP flood, SYN flood, UDP flood, and Layer 7 attacks.</p> <p>The resulting architecture, which integrates machine learning algorithms, access control mechanisms, and hardware-based filtering, provides comprehensive detection and mitigation of attacks at the L2—L4 and L7 layers of the OSI model. This approach enables timely threat identification, reduces incident response time, and can be integrated into corporate infrastructures as a component of a cybersecurity decision-support system.</p></abstract><trans-abstract xml:lang="ru"><p>Рассматривается подход к защите корпоративных сетей от DDoS-атак с использованием системы принятия решений на основе методов машинного обучения. Разработан алгоритм, включающий сбор и анализ данных, обучение модели, отбор информативных признаков, оценку качества, а также последующий мониторинг и дообучение. Проведено тестирование предложенных алгоритмов обнаружения DDoS-атак.</p></trans-abstract><kwd-group xml:lang="en"><kwd>DDoS attack</kwd><kwd>OSI model</kwd><kwd>filtering rules</kwd><kwd>machine learning</kwd><kwd>neural network</kwd><kwd>network traffic</kwd><kwd>access control lists</kwd><kwd>hardware filtering</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>DDoS-атака</kwd><kwd>модель OSI</kwd><kwd>правила фильтрации</kwd><kwd>машинное обучение</kwd><kwd>нейронная сеть</kwd><kwd>сетевой трафик</kwd><kwd>списки контроля доступа</kwd><kwd>аппаратная фильтрация</kwd></kwd-group><funding-group/></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><citation-alternatives><mixed-citation xml:lang="en">Razumov P. V., Safaryan O. А., Smirnov I. А., Porksheyan V. M., Boldyrikhin N. V., Korochentsev D. А., Cherckesova L. V., Osikov S. A. Developing of Algorithm of HTTP FLOOD DDoS Protection, 2020 3rd International Conference on Computer Applications &amp; Information Security (ICCAIS). IEEE, 2020, pp. 1—6, DOI: 10.1109/ICCAIS48893.2020.9096870.</mixed-citation><mixed-citation xml:lang="ru">Razumov P. V., Safaryan O. А., Smirnov I. А., Porksheyan V. M., Boldyrikhin N. V., Korochentsev D. А., Cherckesova L. V., Osikov S. A. Developing of Algorithm of HTTP FLOOD DDoS Protection // 2020 3rd International Conference on Computer Applications &amp; Information Security (ICCAIS). IEEE, 2020. P. 1—6. DOI: 10.1109/ICCAIS48893.2020.9096870.</mixed-citation></citation-alternatives></ref><ref id="B2"><label>2.</label><citation-alternatives><mixed-citation xml:lang="en">Peruhin M. Yu., Voronina L. T., Safiullina L. Kh., Alekseeva А. А. Designing a secure corporate network using VPN, Mezhdunarodnyj nauchno-issledovatel’skij zhurnal, 2025, vol. 3, no. 153, pp. 1—7, DOI: 10.60797/IRJ.2025.153.44 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Перухин М. Ю., Воронина Л. Т., Сафиуллина Л. Х., Алексеева А. А. Проектирование защищенной корпоративной сети с применением VPN // Международный научно-исследовательский журнал. 2025. Т. 3, № 153. С. 1—7. DOI: 10.60797/IRJ.2025.153.44.</mixed-citation></citation-alternatives></ref><ref id="B3"><label>3.</label><citation-alternatives><mixed-citation xml:lang="en">Zakalkin P. V. Dobryshin M. M., Brechko A. А., Gucyn R. V. А proposal to reduce the damage caused by network attacks to a VPN server, Voprosy oboronnoj tekhniki. Seriya 16: Tekhnicheskie sredstva protivodejstviya terrorizmu, 2020, vol. 3—4, no. 141—142, pp. 111—116 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Закалкин П. В., Добрышин М. М., Бречко А. А., Гуцын Р. В. Предложение по снижению ущерба, наносимого сетевыми атаками серверу VPN // Вопросы оборонной техники. Серия 16: Технические средства противодействия терроризму. 2020. Т. 3—4, № 141—142. С. 111—116.</mixed-citation></citation-alternatives></ref><ref id="B4"><label>4.</label><citation-alternatives><mixed-citation xml:lang="en">Palchevsky E. V., Khristodulo O. I. Developing a self-learning method for a spiking neural network to protect against DDoS attacks, Software &amp; Systems, 2019, vol. 32, no. 3, pp. 419—432, DOI: 10.15827/0236-235X.127.419-432 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Пальчевский Е. В., Христодуло О. И. Разработка метода самообучения импульсной нейронной сети для защиты от DDoS-атак // Программные продукты и системы. 2019. Т. 32, № 3. С. 419—432. DOI: 10.15827/0236-235X.127.419-432</mixed-citation></citation-alternatives></ref><ref id="B5"><label>5.</label><citation-alternatives><mixed-citation xml:lang="en">Sadykov A. M., Evdokimov A. A. DDoS attack and how to protect yourself from it, Innovacionny`e texnologii: teoriya, instrumenty`, praktika, 2024, vol. 1, pp. 506—512.</mixed-citation><mixed-citation xml:lang="ru">Садыков А. М., Евдокимов А. А. DDoS-атака и как от нее защититься // Инновационные технологии: теория, инструменты, практика. 2024. Т. 1. С. 506—512.</mixed-citation></citation-alternatives></ref><ref id="B6"><label>6.</label><citation-alternatives><mixed-citation xml:lang="en">Loshchilin A. V., YArikov V. G., Nikishova А. V. Machine learning methods in predicting and preventing cyberattacks, NBI-technologies, 2024, vol. 18, no. 2, pp. 33—39, DOI: 10.15688/NBIT.jvolsu.2024.2.5 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Лощилин А. В., Яриков В. Г., Никишова А. В. Методы машинного обучения в прогнозировании и предотвращении кибератак // НБИ Технологии. 2024. Т. 18, № 2. С. 33—39. DOI: 10.15688/NBIT.jvolsu.2024.2.5.</mixed-citation></citation-alternatives></ref><ref id="B7"><label>7.</label><citation-alternatives><mixed-citation xml:lang="en">Avdoshin S. M., Pesotskaya E.nY., Patrushev K. A. Technologies of trusted artificial intelligence, Informacionnye Tehnologii, 2024, vol. 30, no. 8, pp. 400—410, DOI: 10.17587/it.30.400-410</mixed-citation><mixed-citation xml:lang="ru">Авдошин С. М., Песоцкая Е. Ю.., Патрушев К. А. Технологии доверенного искусственного интеллекта // Информационные технологии. 2024. Т. 30, № 8. С. 400—410. DOI: 10.17587/it.30.400-410.</mixed-citation></citation-alternatives></ref><ref id="B8"><label>8.</label><citation-alternatives><mixed-citation xml:lang="en">Ivanov S. O. А technique for creating and training an artificial neural network to detect network traffic anomalies, Informacionnye Tehnologii, 2024, vol. 30, no. 1, pp. 32—41, DOI: 10.17587/it.30.32-41.</mixed-citation><mixed-citation xml:lang="ru">Иванов С. О. Методика создания и обучения искусственной нейронной сети для решения задачи распознавания аномалий сетевого трафика // Информационные технологии. 2024. Т. 30, № 1. C. 32—41. DOI: 10.17587/it.30.32-41.</mixed-citation></citation-alternatives></ref><ref id="B9"><label>9.</label><citation-alternatives><mixed-citation xml:lang="en">Gapsalamov A. R., Akhmetshin E. M., Sharipov R. R., Vasilev V. L., Bochkareva T. N. Approaches to Information Security in Educational Processes in the Context of Digitalization, TEM Journal, 2020, pp. 708—715, DOI: 10.18421/TEM92-38.</mixed-citation><mixed-citation xml:lang="ru">Gapsalamov A. R., Akhmetshin E. M., Sharipov R. R., Vasilev V. L., Bochkareva T. N. Approaches to Information Security in Educational Processes in the Context of Digitalization // TEM Journal. 2020. С. 708—715. DOI: 10.18421/TEM92-38.</mixed-citation></citation-alternatives></ref><ref id="B10"><label>10.</label><citation-alternatives><mixed-citation xml:lang="en">Mittal M., Kumar K., Behal S. Deep learning approaches for detecting DDoS attacks: a systematic review, Soft comput, 2023, vol. 27, no.18, pp. 13039—13075, DOI: 10.1007/s00500-021-06608-1.</mixed-citation><mixed-citation xml:lang="ru">Mittal M., Kumar K., Behal S. Deep learning approaches for detecting DDoS attacks: a systematic review // Soft comput. 2023. Т. 27, № 18. С. 13039—13075. DOI: 10.1007/s00500-021-06608-1.</mixed-citation></citation-alternatives></ref><ref id="B11"><label>11.</label><citation-alternatives><mixed-citation xml:lang="en">Klimenko T. M., Akzhigitov R. R. А Review of Machine Learning and Deep Learning-Based Detection Methods for Distributed Denial of Service Attacks, International Journal of Open Information Technologies, 2023, vol. 11, no. 6, pp. 46—66 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Клименко Т. М., Акжигитов Р. Р. Обзор методов обнаружения распределенных атак типа "отказ в обслуживании" на основе машинного обучения и глубокого обучения // International Journal of Open Information Technologies. 2023. Т. 11, № 6. С. 46—66.</mixed-citation></citation-alternatives></ref><ref id="B12"><label>12.</label><citation-alternatives><mixed-citation xml:lang="en">Kulinchenko V. N. PCAP and WinPCap libraries one packet sensing LAN channels, Izvestiya Gomel’skogo gosudarstvennogo universiteta im. F. Skoriny, 2011, vol. 6, no. 69, pp. 187—190 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Кулинченко В. Н. Особенности использования библиотек PCAP и WinPCAP для реализации метода однопакетного зондирования в каналах ЛВС // Известия Гомельского государственного университета им. Ф. Скорины. 2011. Т. 6, № 69. С. 187—190.</mixed-citation></citation-alternatives></ref><ref id="B13"><label>13.</label><citation-alternatives><mixed-citation xml:lang="en">Zuev V. N. Network anomalies detection by deep learning, Software &amp; Systems, 2021, vol. 34, no. 1, pp. 91—97, DOI: 10.15827/0236-235X.133.091-097 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Зуев В. Н. Обнаружение аномалий сетевого трафика методом глубокого обучения // Программные продукты и системы. 2021. Т. 34. № 1. С. 91—97. DOI: 10.15827/0236-235X.133.091-097.</mixed-citation></citation-alternatives></ref><ref id="B14"><label>14.</label><citation-alternatives><mixed-citation xml:lang="en">Murthy B. N., Siddappa M. An Efficient Intrusion Detection System in Cloud Network Based on Deep Learning and Improved Marine Predators-Particle Swarm Optimization, International Journal of Intelligent Engineering and Systems, 2023, vol. 16, no. 6, pp. 60—71, DOI: 10.22266/ijies2023.1231.06.</mixed-citation><mixed-citation xml:lang="ru">Murthy B. N., Madappa S. An Efficient Intrusion Detection System in Cloud Network Based on Deep Learning and Improved Marine Predators-Particle Swarm Optimization // International Journal of Intelligent Engineering and Systems. 2023. Т. 16, № 6. С. 60—71. DOI: 10.22266/ijies2023.1231.06.</mixed-citation></citation-alternatives></ref><ref id="B15"><label>15.</label><citation-alternatives><mixed-citation xml:lang="en">Sergadeeva A. I., Lavrova D. S. Application of a modular neural network to detect DDoS attacks, Problemy informacionnoj bezopasnosti. Komp’yuternye sistemy., 2023. vol. 1, no. 53, pp. 111—118, DOI: 10.48612/jisp/65d1-nu8m-8euv (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Сергадеева А. И., Лаврова Д. С. Применение модульной нейронной сети для обнаружения DDoS-атак // Проблемы информационной безопасности. Компьютерные системы. 2023. Т. 1, № 53. С. 111—118. DOI: 10.48612/jisp/65d1-nu8m-8euv.</mixed-citation></citation-alternatives></ref><ref id="B16"><label>16.</label><citation-alternatives><mixed-citation xml:lang="en">Namiot D. E., Il’yushin E. A. Monitoring data drift in machine learning models, International Journal of Open Information Technologies, 2022, vol. 10, no. 12, pp. 84—93 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Намиот Д. Е., Ильюшин Е. А. Мониторинг сдвига данных в моделях машинного обучения // International Journal of Open Information Technologies. 2022. Т. 10, № 12. С. 84—93.</mixed-citation></citation-alternatives></ref><ref id="B17"><label>17.</label><citation-alternatives><mixed-citation xml:lang="en">Denisenko V. V., Maslov A. A., Chesnikov L. S., Klimenko K. S. Hyperparameter optimization in machine learning models: a comparative study, Automation. Modern Technologies, 2023, vol. 77, no. 10, pp. 475—480, DOI: 10.36652/0869-4931-2023-77-10-475-480 (in Russian).</mixed-citation><mixed-citation xml:lang="ru">Денисенко В. В., Маслов А. А., Чесников Л. С., Клименко К. С. Оптимизация гиперпараметров в моделях машинного обучения: сравнительное исследование // Автоматизация. Современные технологии. 2023. Т. 77, № 10. С. 475—480. DOI: 10.36652/0869-4931-2023-77-10-475-480.</mixed-citation></citation-alternatives></ref><ref id="B18"><label>18.</label><citation-alternatives><mixed-citation xml:lang="en">Liu Y., Li Y., Xie D. Implications of imbalanced datasets for empirical ROC-AUC estimation in binary classification tasks, J Stat Comput Simul, 2024, vol. 94, no. 1, pp. 183—203, DOI: 10.1080/00949655.2023.2238235.</mixed-citation><mixed-citation xml:lang="ru">Liu Y., Li Y., Xie D. Implications of imbalanced datasets for empirical ROC-AUC estimation in binary classification tasks // J Stat Comput Simul. 2024. Vol. 94, N 1. P. 183—203. DOI:10.1080/00949655.2023.2238235.</mixed-citation></citation-alternatives></ref><ref id="B19"><label>19.</label><citation-alternatives><mixed-citation xml:lang="en">Soltani M., Khajavi K., Siavoshani M. J., Jahangir A. H. А Multi-Agent Adaptive Deep Learning Framework for Online Intrusion Detection, 2023, DOI:10.48550/arXiv.2303.02622.</mixed-citation><mixed-citation xml:lang="ru">Soltani M., Khajavi K., Siavoshani M. J., Jahangir A. H. А Multi-Agent Adaptive Deep Learning Framework for Online Intrusion Detection. 2023. DOI: 10.48550/arXiv.2303.02622.</mixed-citation></citation-alternatives></ref><ref id="B20"><label>20.</label><citation-alternatives><mixed-citation xml:lang="en">Theobald S., Vesth T. C., Andersen M. R. Genus level analysis of PKS-NRPS and NRPS-PKS hybrids reveals their origin in Aspergilli, BMC Genomics, 2019, vol. 20, no. 1, pp. 847, DOI: 10.1186/s12864-019-6114-2.</mixed-citation><mixed-citation xml:lang="ru">Theobald S., Vesth T. C., Andersen M. R. Genus level analysis of PKS-NRPS and NRPS-PKS hybrids reveals their origin in Aspergilli // BMC Genomics. 2019. Vol. 20, N. 1. P. 847. DOI: 10.1186/s12864-019-6114-2.</mixed-citation></citation-alternatives></ref></ref-list></back></article>
