Skip to main navigation Skip to search Skip to main content

An Improved Attention-Enhanced LSTM Model for Early Detection of Distributed Denial of Service Attacks

  • Istanbul Technical University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

In this extended study, we aim to enhance the performance of the Long Short-Term Memory (LSTM) model for detecting Distributed Denial of Service (DDoS) attacks by incorporating an Attention layer. Our previous work demonstrates the effectiveness of rule-based, Gaussian Naive Bayes (GNB), and LSTM models in DDoS detection but reveals limitations in terms of model stability and false negative rates, particularly with datasets containing a high proportion of benign data [19]. To address these issues, we introduce the Attention layer to the LSTM model, aiming to improve detection accuracy and reduce false negatives. Experiments use the UNSW-NB15 and CIC-DDoS2019 datasets with various configurations of mini-batch sizes and detection windows. The results show that the Attention-enhanced LSTM model generally outperforms the standard LSTM model across different configurations and datasets. The Enhanced LSTM model demonstrates higher accuracy, precision, recall, and F1 scores, and the inclusion of the Attention layer leads to more consistent and reliable performance. These findings highlight the potential of attention-enhanced LSTM models for improving DDoS attack detection, making them valuable tools for cybersecurity applications. The improved model effectively distinguishes between benign and malicious packets, providing more accurate and timely alerts for incident response teams.

Original languageEnglish
Title of host publicationInformation Systems Security and Privacy - 9th International Conference, ICISSP 2023, and 10th International Conference, ICISSP 2024, Revised Selected Papers
EditorsGabriele Lenzini, Paolo Mori, Steven Furnell
PublisherSpringer Science and Business Media Deutschland GmbH
Pages115-126
Number of pages12
ISBN (Print)9783031895173
DOIs
Publication statusPublished - 2026
Event9th and 10th International Conferences on Information Systems Security and Privacy, ICISSP 2023 and 2024 - Rome, Italy
Duration: 26 Feb 202428 Feb 2024

Publication series

NameCommunications in Computer and Information Science
Volume2459 CCIS
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference9th and 10th International Conferences on Information Systems Security and Privacy, ICISSP 2023 and 2024
Country/TerritoryItaly
CityRome
Period26/02/2428/02/24

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.

Keywords

  • Attention layer
  • DDoS
  • LSTM

Fingerprint

Dive into the research topics of 'An Improved Attention-Enhanced LSTM Model for Early Detection of Distributed Denial of Service Attacks'. Together they form a unique fingerprint.

Cite this