MAD-SE: ADAPTIVE THRESHOLD-BASED STACK ENSEMBLE APPROACH FOR THE DETECTION OF DDOS ATTACK IN CLOUD

Authors

  • Rajesh Kumar Pateriya Department of Computer Science and Engineering, Maulana Azad National Institute of Technology (MANIT), M.P., India.
  • Priyanka Verma Department of Computer Science and Engineering, Maulana Azad National Institute of Technology (MANIT), M.P., India.
  • Dharam Singh Department of Computer Science and Engineering, Maulana Azad National Institute of Technology (MANIT), M.P., India.

Keywords:

Cloud computing, Dynamic threshold, DDoS attack, Ensemble learning, Machine learning

Abstract

At present, cyber-attacks are steadily increasing in the cloud network. TCP, ICMP, UDP protocol-based Distributed Denial of Service (DDoS) attacks are the major contributors for making the cloud-based system unsafe. The rate of growth of DDoS cyber-attack is a severe and challenging problem in the network. In the literature, to handle such attacks, various feature selection, and classification techniques are used. In these methods, for the collection of optimal attributes, static thresholding methods are applied. However, when the various variant of DDoS causes a DDoS attack, the size of packets and attribute’s value is significantly changed. Thus, the methods utilizing static statistics are not suitable for a dynamic network. Therefore, an adaptive threshold-based Mean Absolute Deviation technique (MAD) is used to overcome these drawbacks. Moreover, in this work, the Stacked Ensemble (SE) approach is utilized instead of the single classification algorithm for the classification purpose. The proposed approach comprises of three components; (1) data pre-processing, (2) optimal attribute selection, and (3) detection and prevention system from DDoS attacks. In this work, to evaluate the proposed approach, a standard NSL-KDD dataset is used. It is observed that MAD with SE beats all other combinations. In conventional methods, selecting a single classifier may not perform well because it works well on training data, but it poorly classifies the non-viewed new data. The stack ensemble approach removes this issue. Moreover TCP, UDP, and ICMP-based DDoS flooding attacks can also be easily noticed and classified by MAD-SE.

References

Aldossary, S., and Allen, W. (2016). Data security, privacy, availability and integrity in cloud computing: issues and current solutions.Int. J. of Advanced Computer Sci and App., 7(4):485-498.

Chaudhary, D., Bhushan, K., and Gupta, B.B. (2018). Survey on DDoS attacks and defense mechanisms in cloud and fog computing. Int. J. of E-Services and Mobile Applications (IJESMA)., 10(3):61-83.

Hoz De la., E., Hoz De La., E., Ortiz, A., Ortega, J., and Prieto, B. (2015). PCA filtering and probabilistic SOM for network intrusion detection. Neurocomputing., 164:71-81.

Hajimirzaei, B. and Navimipour, N.J. (2019). Intrusion detection for cloud computing using neural networks and artificial bee colony optimization algorithm. ICT Express., 5(1):56-59.

Hamza, R., Yan, Z., Muhammad, K., Bellavista, P., and Titouna, F. (2020). A privacy-preserving cryptosystem for IoT E-healthcare. Information Sci., 527:493-510.

Han, J., Pei, J., and Kamber, M. (2011). Data mining: concepts and techniques. Elsevier.

Inayat, Z., Gani, A., Anuar, N.B., Anwar, S., and Khan, M.K. (2017). Cloud-based intrusion detection and response system: open research issues, and solutions. Arabian J. for Sci. and Eng., 42(2):399-423.

Jia, Y., Zhong, F., Alrawais, A., Gong, B., and Cheng, X. (2020). Flowguard: An intelligent edge defense mechanism against IoT DDoS attacks. IEEE Internet of Things Journal., 7(10):9,552-9,562.

Koc, L., Mazzuchi, T.A., and Sarkani, S. (2012). A network intrusion detection system based on a Hidden Naïve Bayes multiclass classifier. Expert Systems with Applications., 39(18):13,492-13,500.

Mazini, M., Shirazi, B., and Mahdavi, I. (2019). Anomaly network-based intrusion detection system using a reliable hybrid artificial bee colony and AdaBoost algorithms. Journal of King Saud University-Computer and Information Sci., 31(4):541-553.

Osanaiye, O., Cai, H., Choo, K.K.R., Dehghantanha, A., Xu, Z., and Dlodlo, M. (2016). Ensemble-based multi-filter feature selection method for DDoS detection in cloud computing. EURASIP J. on Wireless Communications and Networking., 2016(1):1-10.

Özçelik, İ. and Brooks, R.R. (2015). Deceiving entropy based DoS detection. Computers and Security., 48:234-245.

Peng, T., Leckie, C., and Ramamohanarao, K. (2007). Survey of network-based defense mechanisms countering the DoS and DDoS problems. ACM Computing Surveys (CSUR)., 39(1):3-es.

Riad, K., Hamza, R., and Yan, H. (2019). Sensitive and energetic IoT access control for managing cloud electronic health records. IEEE Access., 7:86,384-86,393.

Shannon, C.E. (2001). A mathematical theory of communication. ACM SIGMOBILE mobile computing and communications review., 5(1):3-55.

Somani, G., Gaur, M.S., Sanghi, D., Conti, M., Rajarajan, M., and Buyya, R. (2017a). Combating DDoS attacks in the cloud: requirements, trends, and future directions. IEEE Cloud Computing., 4(1):22-32.

Somani, G., Gaur, M.S., Sanghi, D., Conti, M., and Buyya, R. (2017b). DDoS attacks in cloud computing: Issues, taxonomy, and future directions. Computer Communications., 107:30-48.

Sree, T.R., and Bhanu, S.M.S. (2018). Detection of http flooding attacks in cloud using dynamic entropy method. Arabian J. for Sci. and Eng., 43(12):6,995-7,014.

Thaseen, I.S., and Kumar, C.A. (2017). Intrusion detection model using fusion of chi-square feature selection and multi class SVM. J. of King Saud University-Computer and Information Sci., 29(4):462-472.

Verma, P., Tapaswi, S., and Godfrey, W.W. (2020). An adaptive threshold-based attribute selection to classify requests under DDoS attack in cloud-based systems. Arabian J. for Sci. and Eng., 45(4):2,813-2,834.

Wang, W., and Gombault, S. (2008). Efficient detection of DDoS attacks with important attributes. In: 2008 Third International Conference on Risks and Security of Internet and Systems, pp. 61-67.

Yang, C. (2019a). Anomaly network traffic detection algorithm based on information entropy measurement under the cloud computing environment. Cluster Computing., 22(4):8,309-8,317.

Yang, J., Rahardja, S., and Fränti, P. (2019). Outlier detection: how to threshold outlier scores?. In Proceedings of the international conference on artificial intelligence, information processing and cloud computing, pp. 1-6.

Zissis, D. and Lekkas, D. (2012). Addressing cloud computing security issues. Future Generation computer systems, 28(3):583-592.

Downloads

Published

2026-08-28

How to Cite

Kumar Pateriya, R., Verma, P., & Singh, D. (2026). MAD-SE: ADAPTIVE THRESHOLD-BASED STACK ENSEMBLE APPROACH FOR THE DETECTION OF DDOS ATTACK IN CLOUD. Suranaree Journal of Science and Technology, 29(5), 010168(1–7). retrieved from https://ph04.tci-thaijo.org/index.php/SUJST/article/view/15227

Issue

Section

Research Article