Intelligent Detection of DDoS Attacks in Internet of Things Devices Using a Hybrid Approach of CNN, LSTM, and FFNN Neural Networks
Mandana Rostami
1
(
)
Pouya Derakhshan Barjouei
2
(
- Artificial Intelligence and Data Analysis Research Center, Department of Electrical Engineering, SR.C., Islamic Azad University, Tehran, Iran.
)
Elahe Moradi
3
(
Department of Electrical Engineering, YI.C., Islamic Azad University, Tehran, Iran.
)
Keywords: Feedforward Neural Network, Long Short-Term Memory, Internet of Things, Deep Learning, Convolutional Neural Network,
Abstract :
As the use of Internet of Things (IoT) devices expands, cyber-attacks, especially DDoS, have become more sophisticated, making their detection a fundamental challenge. Research shows that deep neural networks perform well due to their compatibility with large volumes of data. This study investigates and compares the performance of deep learning models for detecting cyber-attacks in distributed networks.Four deep learning models, including the CNN, LSTM, and FFNN neural networks, as well as their combination (CNN-FFNN and CNN-LSTM), were evaluated for analyzing network traffic data. The models were trained on the Bot-IoT dataset, and their performance was measured based on accuracy. The results show that the combination of CNN and LSTM, by leveraging both spatial features and temporal dependencies, achieves the highest accuracy in detecting complex attacks like DDoS.This model can extract hidden features from raw data and simulate the temporal relationships of attacks, which is crucial for identifying gradual and complex threats in IoT and Fog computing environments. The combination of CNN and FFNN also demonstrated a notable performance in detecting faster threats with less complexity. Ultimately, this research emphasizes the importance of combining deep learning models to improve the accuracy of cyber-attack detection systems and proposes solutions based on distributed architectures for the security of IoT and Fog networks.
[1] Alieyan, K., Kadhum, M. M., Anbar, M., Rehman, S. U., & Alajmi, N. K. (2016). An overview of DDoS attacks based on DNS. In Proceedings of the International Conference on Information and Communication Technology Convergence (ICTC) (pp. 276–280). IEEE. https://doi.org/10.1109/ICTC.2016.7763313
[2] Tyagi, H., & Kumar, R. (2021). Attack and anomaly detection in IoT networks using supervised machine learning approaches. Revue d’Intelligence Artificielle, 35(1), 11–21.
[3] Li, J., Xue, Z., Li, C., & Liu, M. (2021). RTED SD: A real time edge detection scheme for Sybil DDoS on the Internet of Vehicles. IEEE Access, 9, 11296–11305.
[4] Gupta, R. K., Mishra, A., & Gupta, B. (2021). Enhanced identity-based encryption for secure key generation in large-scale cloud computing. IEEE Access, 9, 165259–165272. https://doi.org/10.1109/ACCESS.2021.3138503
[5] Inuwa, M. M., & Das, R. (2024). A comparative analysis of various machine learning methods for anomaly detection in cyber attacks on IoT networks. Internet of Things, 26, 101162. https://doi.org/10.1016/j.iot.2023.101162
[6] Cherdantseva, Y., & Hilton, J. (2013). A reference model of information assurance security. In Proceedings of the International Conference on Availability, Reliability and Security (ARES) (pp. 546–555). IEEE. https://doi.org/10.1109/ARES.2013.72
[7] Kwon, D., Kim, H., Kim, J., Suh, S., Kim, I., & Kim, J. (2019). A survey of deep learning based network anomaly detection. Cluster Computing, 22(5), 949–961.
[8] Anderson, J., Carbonell, J., Mitchell, T., Michalski, R., Amarel, S., Tecuci, T., & Kodratoff, Y. (1983). Machine learning: An artificial intelligence approach. Morgan Kaufmann.
[9] Kilincer, I., Ertam, F., & Sengur, A. (2021). Machine learning methods for cyber security intrusion detection: Datasets and comparative study. Computer Networks, 188, 107840.
[10] Fadlullah, Z. M., Tang, F., Mao, B., Kato, N., Akashi, O., Inoue, T., & Mizutani, K. (2017). State of the art deep learning: Evolving machine intelligence toward tomorrow’s intelligent network traffic control systems. IEEE Communications Surveys & Tutorials, 19(4), 2432–2455.
[11] Tsimenidis, S., Lagkas, T., & Rantos, K. (2022). Deep learning in IoT intrusion detection. Journal of Network and Systems Management, 30(3), 58. https://doi.org/10.1007/s10922-022-09666-x
[12] Diro, A. A., & Chilamkurti, N. (2018). Distributed attack detection scheme using deep learning approach for Internet of Things. Future Generation Computer Systems, 82, 761–768. https://doi.org/10.1016/j.future.2017.10.045
[13] Roopak, M., Tian, G. Y., & Chambers, J. (2019). Deep learning models for cyber security in IoT networks. In Proceedings of the IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 452–457). IEEE. https://doi.org/10.1109/CCWC.2019.8666590
[14] Shalaka, M., Pawar, P. M., & Muthalagu, R. (2023). Efficient intelligent intrusion detection system for heterogeneous Internet of Things (HetIoT). Journal of Network and Systems Management, 31(4), 87. https://doi.org/10.1007/s10922-023-09748-7
[15] Mahjabin, T., Xiao, Y., Sun, G., & Jiang, W. (2017). A survey of distributed denial-of-service attack, prevention, and mitigation techniques. International Journal of Distributed Sensor Networks, 13(12), 1–20.
[16] University of California, Irvine. (1999). KDD Cup 1999 data [Data set]. UCI Machine Learning Repository. https://archive.ics.uci.edu/ml/datasets/kdd+cup+1999+data
[17] Canadian Institute for Cybersecurity. (n.d.). NSL-KDD dataset [Data set]. University of New Brunswick. https://www.unb.ca/cic/datasets/nsl.html
[18] Ramchoun, H., Idrissi, M. J., Ghanou, Y., & Ettaouil, M. (2016). Multilayer perceptron: Architecture optimization and training. International Journal of Interactive Multimedia and Artificial Intelligence, 4(1), 26–30.
[19] Hochreiter, S., & Schmidhuber, J. (1997). Long short term memory. Neural Computation, 9(8), 1735–1780. https://doi.org/10.1162/neco.1997.9.8.1735
[20] Alom, M. Z., Bontupalli, V., & Taha, T. M. (2015). Intrusion detection using deep belief networks. In Proceedings of the IEEE National Aerospace and Electronics Conference (NAECON) (pp. 339–344). IEEE. https://doi.org/10.1109/NAECON.2015.7443094
[21] Kim, J., Kim, J., Thi Thu, H. L., & Kim, H. (2016). Long short-term memory recurrent neural network classifier for intrusion detection. In Proceedings of the International Conference on Platform Technology and Service (PlatCon) (pp. 1–5). IEEE.
[22] Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41–50.
[23] Rahman, M. M., Al Faraj, A., & Alshamrani, A. (2023). Transformer CNN hybrid architecture for real time DDoS attack detection in IoT networks. Computer Networks, 228, 109280. https://doi.org/10.1016/j.comnet.2023.109280
[24] Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, 102419. https://doi.org/10.1016/j.jisa.2019.102419
[25] Yadav, S., & Subramanian, S. (2016). Detection of application layer DDoS attack by feature learning using stacked autoencoder. In Proceedings of the International Conference on Computational Techniques in Information and Communication Technologies (ICCTICT) (pp. 361–366). IEEE.
[26] Lopez-Martin, M., Carro, B., Sanchez-Esguevillas, A., & Lloret, J. (2017). Conditional variational autoencoder for prediction and feature recovery applied to intrusion detection in IoT.Sensors (Basel, Switzerland), 17(9), 1967. https://doi.org/10.3390/s17091967
[27] Luo, T., & Nagarajan, S. G. (2018). Distributed anomaly detection using autoencoder neural networks in WSN for IoT. In Proceedings of the IEEE International Conference on Communications (ICC) (pp. 1–6). IEEE.
[28] Chen, C., Zhao, L., Wang, J., & Li, Y. (2024). Graph neural network based intrusion detection in software defined networking environments. Scientific Reports, 14, 65321. https://doi.org/10.1038/s41598-024-65321-7
[29] Yaseen, Z. M., Hameed, A., & Karim, A. F. (2024). Hybrid autoencoder and convolutional neural network for intrusion detection in fog enabled IoT systems. IEEE Access, 12, 87102–87118. https://doi.org/10.1109/ACCESS.2024.3456712
[30] Abbas, S., Alsubai, S., Ojo, S., Sampedro, G. A., Almadhor, A., Al Hejaili, A., & Bouazzi, I. (2024). An efficient deep recurrent neural network for detection of cyberattacks in realistic IoT environment. The Journal of Supercomputing, 80(10), 13557–13575.
[31] Patel, D., Pillai, S., & Kumar, V. (2023). Deep reinforcement learning based anomaly detection for securing IoT edge networks. Neural Computing and Applications, 35(23), 17159–17175. https://doi.org/10.1007/s00521-023-08672-x
[32] Rajabzadeh,M., Derakhshan-Barjoei,P. (2022). An Efficient Proxy-Based Message Authentication Framework in Vehicular Ad-hoc Networks. Journal of Communication Engineering, 11(1), 111-136. doi: 10.22070/jce.2024.18230.1255
[33] Rajabzadeh Asaar, M., Derakhshan Barjoei, P. (2023). A New Protocol for Lightweight Anonymous Authentication with Leading Security in Wireless Sensor Networks Based on IoT. Intelligent Multimedia Processing and Communication Systems (IMPCS), vol. 4, no. 3, 2023, pp. 1-13. 10.71856/impcs.2023.903612
[34] Kumar, P., Gupta, G. P. (2024). Hybrid deep learning based threat intelligence framework for securing Internet of Things. IEEE Transactions on Information Forensics and Security, 19, 882–895. https://doi.org/10.1109/TIFS.2023.3321500
[35] Shahpar, Z., Badragheh, M. (2026). Presenting a Hybrid Model on Machine Learning and Principal Component Analysis for Action Detection in the Internet of Things. Journal of Information and Communication Technology, vol. 17, no. 66.
[36] davami, F. , Derakhshan-Barjoei, P. and Shaviklou, N. (2026). Detecting abnormal nodes in IoT security using neural networks and graph theory. Tabriz Journal of Electrical Engineering, doi: 10.22034/tjee.2026.69361.5088
[37] zeraatkarmoghaddam, m., ghayori, m. (2023). Improvement of intrusion detection system on Industrial Internet of Things based on deep learning using metaheuristic algorithms. Journal of Information and Communication Technology, vol. 15, no. 57, pp. 165-190.
[38] Abdi, A., Salimi-Badr, A., Souzani, A.(2026). A Self-supervised Sensors’ Anomaly Detection Scheme in Industrial Control Systems based on Ensemble Deep Learning . Journal of Information and Communication Technology, vol. 17, no. 66.