Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (422)

Search Parameters:
Keywords = distributed denial of service attacks

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
29 pages, 4024 KB  
Article
Dynamic Evolutionary Game and Convergence Analysis of Mining Pool Strategies Under DDoS Attacks for IoT-Oriented Blockchain Systems
by Xiaozhen Cheng, Xiao Liu, Zhaozhan Li, Dong Ding, Yuning Zhao, Jinping Li and Zhixue Wang
Electronics 2026, 15(15), 3362; https://doi.org/10.3390/electronics15153362 - 30 Jul 2026
Abstract
Distributed Denial-of-Service (DDoS) attacks are a major security threat to blockchain systems, especially in Internet-of-Things (IoT)-oriented and edge-assisted deployments where mining services, gateway nodes, and communication resources are more vulnerable to disruption. In Proof-of-Work (PoW) blockchain networks, such attacks can degrade mining pool [...] Read more.
Distributed Denial-of-Service (DDoS) attacks are a major security threat to blockchain systems, especially in Internet-of-Things (IoT)-oriented and edge-assisted deployments where mining services, gateway nodes, and communication resources are more vulnerable to disruption. In Proof-of-Work (PoW) blockchain networks, such attacks can degrade mining pool connectivity, reduce effective revenue, and undermine both system security and resilient infrastructure design. Existing studies have mainly focused on DDoS detection or static mining games, while paying limited attention to dynamic strategy evolution and convergence under varying network conditions. To address this problem, this paper proposes a dynamic evolutionary game (DEG)-based revenue model for mining pools under DDoS attacks. Unlike static game methods that only identify equilibrium points, this work analyzes both the convergence dynamics and the sensitivity of equilibrium outcomes to key parameters, including attack scale, penalty, reward, and network quality. The proposed method characterizes the adaptive interaction between honest mining and attack behaviors through replicator dynamics, and analyzes strategy stability and convergence using equilibrium and Lyapunov-based methods. In addition, we investigate how key system parameters, including attack scale, reward, penalty, and network quality, affect the convergence speed of mining pool strategies in different environments. MATLAB results show that the proposed DEG model better captures the dynamic evolution of mining pool behaviors than conventional static-game formulations. The results further indicate that improved network conditions may unintentionally incentivize DDoS attacks, while proper parameter tuning can accelerate convergence toward security-favorable strategies. These findings provide useful insights for secure blockchain design and resilient mining infrastructure in IoT-oriented systems. Full article
(This article belongs to the Special Issue New Trends in Cybersecurity and Hardware Design for IoT)
Show Figures

Figure 1

26 pages, 2360 KB  
Article
Distributed Containment Control for Caputo Fractional-Order Multi-Agent Systems Under Stochastic Communication Uncertainties and Intermittent DoS Attacks
by Saleh ALYahya, Ammar Alsinai, Romana Ashfaq and Azmat Ullah Khan Niazi
Fractal Fract. 2026, 10(8), 508; https://doi.org/10.3390/fractalfract10080508 - 27 Jul 2026
Viewed by 204
Abstract
The current paper deals with the containment control issue of fractional-order complex networks (FCNs) under communication uncertainties occurring with both multiplicative and additive noises and denial-of-service attacks. The dynamics of the followers are incorporated through the use of Caputo fractional derivatives, which are [...] Read more.
The current paper deals with the containment control issue of fractional-order complex networks (FCNs) under communication uncertainties occurring with both multiplicative and additive noises and denial-of-service attacks. The dynamics of the followers are incorporated through the use of Caputo fractional derivatives, which are able to capture the nature of memory and hereditary dynamics of the complex systems. In order to reduce stochastic noise caused by the noisy communication medium, a new distributed containment protocol is proposed that takes both the multiplicative and additive noise effects in the interactions between the leader and the followers. Using the Mittag–Leffler stability theory, stochastic Lyapunov analysis, Itô calculus, the derivation of necessary conditions to ensure that the followers converge to the convex hull of the leaders was done. The explicit stability conditions are stipulated based on system parameters and control gains as well as intensities of noise. In addition, the robustness of the protocol suggested for use against intermittent DoS attacks is critically examined. The theoretical findings are substantiated by simulation experiments that demonstrate that the suggested methodology guarantees containment and resilience to the fluctuations in the fractional order and communication breakdowns. The findings offer an inclusive framework in the development of robust distributed controllers of fractional-order MASs operating under adversarial and uncertain networked frameworks. Full article
(This article belongs to the Special Issue Fractional Dynamics and Control in Multi-Agent Systems and Networks)
Show Figures

Figure 1

24 pages, 6438 KB  
Article
SMRE: A Lightweight Statistical Mean Rényi Entropy Approach for Early DDoS Detection in SDN
by Bavani Kannan, Deepalakshmi Perumalsamy, Ranjit Panigrahi, Paolo Barsocchi and Akash Kumar Bhoi
Future Internet 2026, 18(8), 388; https://doi.org/10.3390/fi18080388 - 25 Jul 2026
Viewed by 169
Abstract
Software-Defined Networking (SDN) centralizes control logic, improving programmability but exposing the controller to volumetric and low-rate Distributed Denial of Service (DDoS) attacks. Entropy-based detectors often raise late alarms or require significant traffic distribution changes, while machine-learning approaches impose high training and inference overhead. [...] Read more.
Software-Defined Networking (SDN) centralizes control logic, improving programmability but exposing the controller to volumetric and low-rate Distributed Denial of Service (DDoS) attacks. Entropy-based detectors often raise late alarms or require significant traffic distribution changes, while machine-learning approaches impose high training and inference overhead. To address these issues, this work proposes a Statistical Mean Renyi Entropy (SMRE)-based early-warning system that amplifies micro-level disturbances in flow randomness using a tunable sensitivity weight (μ). The formulation enhances responsiveness to entropy deviations without adding computational complexity, enabling O(n) single-pass execution per monitoring window. The method was implemented on a Mininet testbed (nine switches, 64 hosts, POX controller with the L3_learning module) with mixed benign traffic and hping3/Scapy-generated UDP and TCP flood attack traffic at intensities ranging from 10 to 75%. Experimental results demonstrate that SMRE detects early-stage attacks with 94.7–98.1% accuracy, 0.8–2.3% false positive rate, and 6.5–14 ms detection latency, outperforming Shannon and classical Renyi entropy detectors. ROC analysis (AUC ≈ 0.99) and paired t-tests (p < 0.01) confirm statistical significance. Resource profiling shows negligible CPU and memory overhead, supporting real-time deployment. By eliminating model training and ensuring robust early detection, SMRE offers a lightweight and practical detection mechanism for SDN environments, whose applicability to cloud, edge, and IoT deployments will be further substantiated through validation on real traffic traces and multi-controller architectures. Full article
Show Figures

Figure 1

20 pages, 4579 KB  
Article
Explainable AI for Securing Perception-Layer Sensor Data in IoT Environmental Danger Detection Systems
by Taha Al-Jadir, Iván García-Magariño and Raquel Lacuesta Gilaberte
Future Internet 2026, 18(8), 385; https://doi.org/10.3390/fi18080385 - 24 Jul 2026
Viewed by 142
Abstract
This paper presents an explainable defense framework against perception-layer and Man-in-the-Middle (MitM) attacks in Internet of Things (IoT)-based environmental hazard warning systems. These systems rely on heterogeneous sensors (gas, light, sound, temperature, and humidity) whose integrity is crucial for reliable environmental alerts. Perception-layer [...] Read more.
This paper presents an explainable defense framework against perception-layer and Man-in-the-Middle (MitM) attacks in Internet of Things (IoT)-based environmental hazard warning systems. These systems rely on heterogeneous sensors (gas, light, sound, temperature, and humidity) whose integrity is crucial for reliable environmental alerts. Perception-layer attacks such as spoofing, jamming, and data injection can compromise sensor readings, while MitM attacks threaten communication reliability. The proposed approach integrates incremental Dynamic Time Warping (DTW) for time-series anomaly detection with a tree- based ensemble classifier (XGBoost), in addition to Shapley Additive Explanations (SHAP) for interpretability. A comparative evaluation framework jointly considers detection performance and explanation quality through metrics including pre-registering a Casual Ground Truth based on network protocol localized Precision@ K feature overlap metrics (Q), instead of relying on subjective human-expert or global rank correlations to quantitively evaluate the explanation transparency. Experimental simulations using an authentic EdgeIIoT-2022 dataset under 3-fold forward–chaining cross-validation demonstrated high detection accuracy and moderated explainability scores. The results prove the framework’s ability to detect and explain adversarial behaviors in sensor networks, strengthening trust, transparency, and resilience in safety-critical IoT infrastructures. Full article
Show Figures

Figure 1

18 pages, 2692 KB  
Article
High-Throughput and Low-Latency DrDoS Detection Using Quantized ONNX Models
by Salih Eren, Alperen Gültekin, Ömer Özkan and İlker Özçelik
Symmetry 2026, 18(7), 1187; https://doi.org/10.3390/sym18071187 - 14 Jul 2026
Viewed by 295
Abstract
Distributed Reflection Denial-of-Service (DrDoS) attacks, such as DNS Amplification, exploit inherent asymmetries in standard network protocols to generate devastating traffic volumes. To restore defense-side balance against these asymmetric threats, we present a comprehensive, systematic comparison of ONNX compilation and quantization configurations across Multi-Layer [...] Read more.
Distributed Reflection Denial-of-Service (DrDoS) attacks, such as DNS Amplification, exploit inherent asymmetries in standard network protocols to generate devastating traffic volumes. To restore defense-side balance against these asymmetric threats, we present a comprehensive, systematic comparison of ONNX compilation and quantization configurations across Multi-Layer Perceptron (MLP), Convolutional Neural Network (CNN), and Gated Recurrent Unit (GRU) architectures evaluated on a unified reference platform. To achieve this, our evaluation analyzes training durations, throughput scalability, and sample latency across varying batch sizes to align with operational network environments. We demonstrate that while small batch sizes suffer from data transfer overhead, increasing batch configurations significantly accelerates GPU throughput, particularly for statically quantized ONNX models. Additionally, training durations exhibit an inverse scaling relationship with batch size, yielding massive temporal savings as workloads expand. Furthermore, larger batch sizes effectively amortize fixed execution costs across thousands of samples, reducing average per-sample latency. Ultimately, this systematic evaluation provides a deployment blueprint for highly efficient intrusion detection engines capable of neutralizing asymmetric network threats at line-rate. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

24 pages, 456 KB  
Article
From RISC to Risk: Exception Handling as a Gateway to Exploitation
by Mina Soltani Siapoush and Jim Alves-Foss
Computers 2026, 15(7), 440; https://doi.org/10.3390/computers15070440 - 10 Jul 2026
Viewed by 257
Abstract
RISC-V’s open and extensible design improves flexibility, but it also permits vendors to customize trap behavior and reserved opcode space in ways that can affect exception handling. This paper presents a scoping review of RISC-V exception-handling security, focusing on how traps, privilege transitions, [...] Read more.
RISC-V’s open and extensible design improves flexibility, but it also permits vendors to customize trap behavior and reserved opcode space in ways that can affect exception handling. This paper presents a scoping review of RISC-V exception-handling security, focusing on how traps, privilege transitions, control registers, and handler routines can become attack surfaces when they are not correctly protected. We organize the literature by a five-stage exception lifecycle and map documented attacks and defenses to the architectural state they affect. Our review shows that exception-handling vulnerabilities arise from exposed control registers, insufficiently protected trap entry and return paths, and flawed handler execution. Recent attacks, such as GhostWrite, halt-and-catch-fire conditions, and side-channel exploits, illustrate how weaknesses in exception management can lead to privilege escalation, denial of service, or data leakage. In contrast, defenses are unevenly distributed across the lifecycle: backward-edge return-time integrity is addressed by multiple dedicated mechanisms, while dispatch-time and privilege-transition protection remain largely indirect and are often embedded within broader trusted-execution designs. Because the primary studies report heterogeneous cost metrics, the overhead values we extract are presented as reported rather than normalized across a common benchmark. The literature suggests that lightweight mechanisms, such as Physical Memory Protection and software-based control-flow enforcement, generally incur modest overhead, whereas stronger approaches, such as CHERI-RISC-V and Trusted-Execution Environments, may impose substantially higher costs on exception-heavy workloads. Overall, our findings indicate that exception handling should be treated as a security-critical boundary and that future work should emphasize stage-specific defenses, formal verification, and tighter integration between hardware and software protections. Full article
Show Figures

Figure 1

14 pages, 2099 KB  
Article
Time-Series Modeling-Based Early Detection of DDoS Attacks in Drone Networks
by ChungMan Oh, JaePil Youn, WonHo Ryu and Jin Ho Park
Electronics 2026, 15(13), 2945; https://doi.org/10.3390/electronics15132945 - 6 Jul 2026
Viewed by 292
Abstract
Drone (UAV)-based ad hoc networks are highly vulnerable to Distributed Denial of Service (DDoS) attacks due to their resource constraints and dynamic connectivity. To ensure the survivability of UAVs, ultra-low latency early threat detection is essential. This study proposes three novel time-series network [...] Read more.
Drone (UAV)-based ad hoc networks are highly vulnerable to Distributed Denial of Service (DDoS) attacks due to their resource constraints and dynamic connectivity. To ensure the survivability of UAVs, ultra-low latency early threat detection is essential. This study proposes three novel time-series network metrics—Packet Flood Rate (PFR), Link Jitter Index (LJI), and Network Congestion Factor (NCF)—optimized for capturing the dynamic characteristics of DDoS attacks in drone networks. To evaluate the effectiveness of the proposed metrics, we applied lightweight deep learning architectures, including 1D-CNN, GRU, and LSTM. The experimental results demonstrate that the 1D-CNN model, guided by the proposed metrics, achieved the highest accuracy with an F1 Score of 0.9669 and an ROC-AUC of 0.9971. Notably, in terms of Average Detection Delay, a critical factor for early defense, the metric-driven 1D-CNN recorded 0.364 steps, reducing the detection time by approximately 30% compared to GRU (0.527) and LSTM (0.522) with statistical significance (p < 0.001, d = 0.6). Furthermore, despite requiring significantly fewer parameters (20,097), the 1D-CNN achieved a per-window inference latency of 0.611 ms on a standard CPU, demonstrating computational efficiency suitable for edge deployment in resource-constrained UAV environments. These results quantitatively demonstrate that the proposed feature-engineering approach combined with lightweight deep learning is highly viable for real-time threat mitigation in resource-constrained UAV networks. Full article
(This article belongs to the Special Issue AI for Cybersecurity and Emerging Technologies for Secure Systems)
Show Figures

Figure 1

18 pages, 3380 KB  
Article
Detection of UDP-Based Volumetric DDoS Attacks in IoT Environments Using LSTM with Temporal Attention Mechanism
by Bengisu Eda Aydin, Zafer Güney and Hakan Aydin
Sensors 2026, 26(13), 4237; https://doi.org/10.3390/s26134237 - 3 Jul 2026
Viewed by 353
Abstract
Internet of Things (IoT) environments, similarly to traditional network infrastructures, are highly vulnerable to volumetric Distributed Denial of Service (DDoS) attacks. Detecting such attacks remains challenging due to their bursty and short-lived nature, particularly in User Datagram Protocol (UDP) flood traffic, which often [...] Read more.
Internet of Things (IoT) environments, similarly to traditional network infrastructures, are highly vulnerable to volumetric Distributed Denial of Service (DDoS) attacks. Detecting such attacks remains challenging due to their bursty and short-lived nature, particularly in User Datagram Protocol (UDP) flood traffic, which often blends into normal traffic fluctuations. Conventional deep learning (DL) approaches, particularly Long Short-Term Memory (LSTM) networks, assign uniform importance to all time steps, limiting their ability to capture temporally localized burst patterns critical for identifying UDP-based volumetric attacks. To address this limitation, this study proposes LSTM-IoT, an attention-enhanced intrusion detection framework that integrates a temporal attention mechanism into an LSTM architecture. The model selectively emphasizes informative time intervals while suppressing irrelevant temporal segments, improving discrimination between benign and attack traffic. Evaluated on UDP traffic flows from the CICDDoS2019 dataset, LSTM-IoT achieves a detection accuracy of 99.93%, outperforming a baseline LSTM model. The results confirm that the proposed DL-based model effectively detects UDP-based volumetric DDoS attacks in IoT environments. Full article
Show Figures

Figure 1

56 pages, 6614 KB  
Review
Systematic Analysis on the Use of AI Techniques in Industrial IoT DDoS Attack Detection, Mitigation, and Prevention
by Mikiyas Alemayehu, Mohamed Chahine Ghanem, Hamza Kheddar, Dipo Dunsin and Marcio J. Lacerda
IoT 2026, 7(3), 51; https://doi.org/10.3390/iot7030051 - 30 Jun 2026
Viewed by 267
Abstract
Distributed Denial of Service (DDoS) attacks pose significant threats to Industrial Internet of Things (IIoT) environments, exacerbated by the resource constraints of IoT devices and the disruptive impact of such attacks. Conventional detection and prevention methods fall short of ensuring the availability and [...] Read more.
Distributed Denial of Service (DDoS) attacks pose significant threats to Industrial Internet of Things (IIoT) environments, exacerbated by the resource constraints of IoT devices and the disruptive impact of such attacks. Conventional detection and prevention methods fall short of ensuring the availability and operational continuity required in industrial deployments. This article systematically analyses artificial intelligence (AI) techniques for detecting, preventing, and mitigating DDoS attacks in IIoT systems. We examine diverse AI-driven solutions, including machine learning (ML) and deep learning (DL) models, alongside hybrid approaches that enhance real-time threat identification, adaptive defence mechanisms, and decentralised trust management, addressing the evolving sophistication of DDoS attacks. This study highlights AI’s potential to strengthen IIoT security and resilience, particularly in critical national infrastructure (CNI), where uninterrupted operations are paramount. However, challenges such as computational overhead, model interpretability, and dataset scarcity in industrial settings remain critical barriers. Additionally, the dynamic IIoT topology and heterogeneous device ecosystems necessitate context-aware AI solutions. This analysis underscores the need for lightweight, explainable AI frameworks and collaborative defence strategies tailored to the IIoT’s unique constraints. It emphasises the integration of AI with emerging technologies like edge computing and federated learning to advance proactive, scalable DDoS defence mechanisms in industrial ecosystems. Full article
(This article belongs to the Special Issue IoT and Distributed Computing)
Show Figures

Graphical abstract

19 pages, 2571 KB  
Article
Event-Triggered Resilient Cooperative Control Strategy for Urban Rail Transit Virtually Coupled Train Sets Against Cyber-Attacks
by Jianen Yang, Yuchen Dai, Junyi Li, Jiehao Chen, Lei Li and Shuangfei Ni
Symmetry 2026, 18(7), 1091; https://doi.org/10.3390/sym18071091 - 27 Jun 2026
Viewed by 235
Abstract
The virtually coupled train set (VCTS) system is a promising urban rail transit paradigm that replaces physical couplers with train-to-train (T2T) wireless communication, enabling dynamic marshaling to achieve the precise matching of transportation demand and resources. However, existing VCTS control strategies either assume [...] Read more.
The virtually coupled train set (VCTS) system is a promising urban rail transit paradigm that replaces physical couplers with train-to-train (T2T) wireless communication, enabling dynamic marshaling to achieve the precise matching of transportation demand and resources. However, existing VCTS control strategies either assume perfect leader state availability, rely on continuous communication, or lack guaranteed transient/steady-state performance under Denial-of-Service (DoS) attacks. To address these critical limitations, this paper proposes a unified finite-time resilient event-triggered cooperative control framework for VCTSs against malicious DoS attacks. The proposed framework integrates three synergistic components: a distributed finite-time leader state estimator to reconstruct leader information under intermittent communication interruptions, a prescribed performance finite-time controller to bound tracking error fluctuations and accelerate convergence, and an adaptive event-triggered communication protocol to reduce controller update frequency. The closed-loop system stability, finite-time convergence, and prescribed performance guarantees are rigorously proven via Lyapunov analysis, and Zeno behavior is strictly excluded. Extensive comparative simulations demonstrate that the proposed framework outperforms representative state-of-the-art methods in terms of tracking accuracy, attack resilience, and communication efficiency, achieving a significance reduction of approximately 70% in controller update frequency while maintaining system stability under the considered DoS attack scenarios. Full article
(This article belongs to the Section F: Engineering and Materials)
Show Figures

Figure 1

21 pages, 1071 KB  
Article
Resilient State and Attack Estimation in Discrete Markovian Cyber-Physical Systems via Generalized Dynamic Observers
by Angel R. Guadarrama-Estrada, Gloria L. Osorio-Gordillo, Olivier Sename, Rodolfo A. Vargas-Méndez, Carlos M. Astorga-Zaragoza, Juan Reyes-Reyes, Dulce A. Serrano-Cruz and Alejandro Pineda-Uribe
Electronics 2026, 15(13), 2824; https://doi.org/10.3390/electronics15132824 - 26 Jun 2026
Viewed by 248
Abstract
This article presents a generalized observer scheme for dynamic structures designed to estimate the dynamic behavior of various types of attacks, such as Denial of Service (DoS) attacks, False Data Injection (FDIA), and Random Data Injection (RDI). These attacks employ a Markovian distribution [...] Read more.
This article presents a generalized observer scheme for dynamic structures designed to estimate the dynamic behavior of various types of attacks, such as Denial of Service (DoS) attacks, False Data Injection (FDIA), and Random Data Injection (RDI). These attacks employ a Markovian distribution logic to alter the behavior of actuators and sensors in a cyber-physical system. A three-tank interconnected system is used to demonstrate the effectiveness in estimating these attacks, modeled under the Takagi–Sugeno representation. This approach allows for precise detection and diagnosis of the attacks, which is essential for the design of controllers that ensure the security and integrity of cyber-physical systems. Moreover, it lays the foundation for developing an attack-tolerant controller based on observers, offering a comprehensive and robust solution to address security challenges. Full article
(This article belongs to the Special Issue Cyber-Physical Systems: Recent Developments and Emerging Trends)
Show Figures

Figure 1

41 pages, 2880 KB  
Article
A Comparative Study of Large Language Models for Industrial Cyber-Physical Security
by J. de Curtò, I. de Zarzà, Juan Carlos Cano and Carlos T. Calafate
Electronics 2026, 15(13), 2779; https://doi.org/10.3390/electronics15132779 - 24 Jun 2026
Viewed by 301
Abstract
Intrusion detection in industrial cyber-physical systems is constrained by small labelled-attack corpora and by the subtler signal of physical-process attacks compared with classical IT-network intrusions, motivating renewed interest in foundation-model-based detectors; classical detectors are typically trained per dataset and degrade under the distribution [...] Read more.
Intrusion detection in industrial cyber-physical systems is constrained by small labelled-attack corpora and by the subtler signal of physical-process attacks compared with classical IT-network intrusions, motivating renewed interest in foundation-model-based detectors; classical detectors are typically trained per dataset and degrade under the distribution shift that is common in operational technology, where attack repertoires evolve faster than retraining cycles. Two foundation-model families are now plausible candidates: open-source Large Language Models (LLMs) and recent tabular foundation models (TabPFN, TabICL) pre-trained for in-context tabular inference. We compare the two families head-to-head, alongside Random Forest and XGBoost classical anchors, across three established industrial security benchmarks (SWaT, HAI, WUSTL-IIoT-2021) under a controlled multi-seed full-holdout protocol with paired McNemar and cross-seed Mann–Whitney tests. The empirical picture is dataset-dependent rather than universal: tabular foundation models establish a strong, previously unreported baseline that is competitive with or superior to classical anchors on every dataset evaluated, while LLMs are complementary detectors with a specific advantage on schemas that carry process-engineering semantics (such as SWaT’s named sensor channels). A per-class analysis on the WUSTL five-class attack taxonomy shows that the two families have structurally different strengths: tabular methods dominate traffic-rich attacks (Denial-of-Service, Reconnaissance), whereas LLMs are competitive on rare attack types (Backdoor, Command Injection). A confidence-gated cascade that escalates only low-confidence tabular decisions to an LLM exceeds either detector alone at a small query budget, and a leave-one-attack-type-out analysis shows that foundation-model detectors generalise to unseen attack families substantially better than the classical anchors. The appropriate detector choice in industrial cyber-physical security is therefore informed by the dataset’s feature schema, the attack-type mix, and the operational cost envelope, rather than by a specific performance metric. Full article
Show Figures

Figure 1

33 pages, 5099 KB  
Article
Persian Eagle: A Hybrid Machine Learning and Deep Learning Framework for High-Precision DDoS Detection in Urban Digital Infrastructures
by Hamid Yarali and Kaebeh Yaeghoobi
Information 2026, 17(7), 618; https://doi.org/10.3390/info17070618 - 23 Jun 2026
Viewed by 897
Abstract
Urban environments increasingly rely on interconnected digital infrastructures like IoT devices, SDN-enabled networks, and cloud platforms to support essential municipal services. Ensuring the resilience of these systems requires advanced, data-driven mechanisms capable of detecting and mitigating cyber disruptions. This study presents Persian Eagle, [...] Read more.
Urban environments increasingly rely on interconnected digital infrastructures like IoT devices, SDN-enabled networks, and cloud platforms to support essential municipal services. Ensuring the resilience of these systems requires advanced, data-driven mechanisms capable of detecting and mitigating cyber disruptions. This study presents Persian Eagle, a hybrid machine learning and deep learning framework designed to enhance the cyber-resilience of urban digital infrastructures by providing high-precision detection of Distributed Denial of Service (DDoS) attacks. DDoS attacks disrupt service availability by flooding targets with massive malicious traffic orchestrated through botnets, and in critical infrastructures, disruptions can be life-threatening. The proposed framework integrates multi-stage data preprocessing, SMOTE-based class balancing, and a four-phase feature-selection pipeline combining filtering, statistical ranking, PCA, and XGBoost. Seven complementary classifiers, including Random Forest, SVM, Gaussian Naive Bayes, XGBoost, MLP, LSTM, and Autoencoder, are bonded through a stacking cooperative with a Gradient Boosting meta-learner. The framework was evaluated on CICDDoS2019 and CICIDS2017 datasets, and achieved near-perfect performance up to 99.9998% accuracy, demonstrating strong generalization across diverse attack scenarios. By offering a scalable, transparent, and data-driven detection mechanism, Persian Eagle maintains urban digital-risk management and supports the continuity and resilience of critical smart-city services. Full article
Show Figures

Figure 1

25 pages, 882 KB  
Article
Impact of Network Topology on Machine Learning-Based DDoS and Anomaly Detection in Software-Defined Networks
by Łukasz Bakuła and Andrzej Jasinski
Appl. Sci. 2026, 16(12), 6204; https://doi.org/10.3390/app16126204 - 19 Jun 2026
Viewed by 386
Abstract
The development of Software-Defined Networks (SDNs) introduces new challenges in network security, particularly in detecting Distributed Denial of Service (DDoS) attacks and network anomalies. Due to the centralized architecture of SDN, traditional detection methods are often insufficient in dynamic environments. Therefore, machine learning [...] Read more.
The development of Software-Defined Networks (SDNs) introduces new challenges in network security, particularly in detecting Distributed Denial of Service (DDoS) attacks and network anomalies. Due to the centralized architecture of SDN, traditional detection methods are often insufficient in dynamic environments. Therefore, machine learning techniques are increasingly applied to improve detection effectiveness. This paper analyzes the impact of network topology on the performance of machine learning-based detection methods in SDN environments. A controlled experimental setup based on the RYU controller and OpenFlow 1.3 was implemented using Mininet. Two network topologies (linear and hierarchical) were evaluated under multiple attack scenarios, including TCP SYN flood and TCP/UDP port scanning. Two supervised learning models, Random Forest (RF) and K-Nearest Neighbors (KNN), were implemented and compared using standard evaluation metrics: accuracy, precision, recall, F1-score, and detection time. The results show that Random Forest significantly outperforms KNN, achieving up to 100% accuracy and detection times as low as 4.24 s, while KNN exhibits lower stability and reduced recall in anomaly detection scenarios. The study demonstrates that network topology has a measurable impact on both detection performance and latency. The observed effects varied across attack scenarios and machine learning models. Hierarchical topology generally improved detection sensitivity in DDoS scenarios, while linear topology often enabled lower detection latency during selected anomaly detection experiments. The results indicate that both machine learning model selection and network topology should be jointly considered when designing intrusion detection systems for SDN environments. These findings contribute to improving the effectiveness and responsiveness of security mechanisms in modern programmable networks. Full article
(This article belongs to the Special Issue Advances in Computer Networks and Software-Defined Networks)
Show Figures

Figure 1

15 pages, 212 KB  
Article
Trends in Non-Profit Cybersecurity: Analyzing Three Years of Incident Data from the NPCIR
by Stanley J. Mierzwa, Joanna Paliszkiewicz and Edyta Skarzyńska
Information 2026, 17(6), 601; https://doi.org/10.3390/info17060601 - 17 Jun 2026
Viewed by 1254
Abstract
This study analyzes cyberattack trends targeting non-profit organizations using longitudinal data collected over a three-year period within the Non-Profit Cybersecurity Incident Repository (NPCIR). Developed through a National Security Agency Center of Academic Excellence in Cyber Defense (NSA CAE-CD) designated center, the NPCIR applies [...] Read more.
This study analyzes cyberattack trends targeting non-profit organizations using longitudinal data collected over a three-year period within the Non-Profit Cybersecurity Incident Repository (NPCIR). Developed through a National Security Agency Center of Academic Excellence in Cyber Defense (NSA CAE-CD) designated center, the NPCIR applies an open-source intelligence (OSINT) methodology to systematically document cybersecurity incidents affecting the global non-profit sector. This study examines attack types, threat actor characteristics, sectoral distribution, and cybersecurity impacts using the Confidentiality–Integrity–Availability (CIA) triad framework. The results indicate that availability-related incidents, particularly ransomware and distributed denial-of-service (DDoS) attacks, constitute the most prevalent threats, while confidentiality breaches remain highly significant due to frequent data exposure incidents. Statistical analyses further demonstrate significant differences between non-profit organizations aligned with DHS CISA critical infrastructure sectors and those operating outside these sectors, especially regarding the prevalence of availability-focused attacks. In addition to its empirical contribution, the NPCIR initiative supports experiential learning opportunities for undergraduate and graduate students in cybersecurity and information technology. The resulting dataset provides actionable cyber threat intelligence for researchers, practitioners, and non-profit leaders seeking to strengthen organizational cybersecurity resilience and awareness. Full article
(This article belongs to the Special Issue Trustworthy AI and Knowledge Management for Sustainable Organizations)
Back to TopTop