Skip to content

An approach to protecting corporate networks from DDoS attacks based on machine learning and neural networks

Aug 2026 · INFORMACIONNYE TEHNOLOGII · 0 citations · 7 references

Abstract

The purpose of this study is to develop an approach for implementing DDoS protection mechanisms in corporate networks using a decision-making system based on machine learning methods. The proposed DDoS attack detection process comprises several stages, including data collection and analysis, model training, feature selection, validation, performance evaluation, and continuous monitoring with retraining. Data were collected using packet capture libraries and traffic analyzers. Neural network training involved dividing the dataset into training and test subsets through standard functions, which ensured accurate evaluation of the model on previously unseen data. Feature selection was performed in two stages: automated statistical analysis and expert validation. Cross-validation and early stopping techniques were applied to prevent overfitting and maintain optimal model performance. At the monitoring and retraining stage, the model was deployed in a real network environment, where selected metrics enabled tracking of algorithm performance, detection of traffic variations, and initiation of adaptive updates. To enhance network security, a hardware—software filtering module was implemented based on access control lists and programmable logic integrated circuits (PLCs). To verify the effectiveness of the proposed methods, a dedicated test bench was developed for simulating various types of DDoS attacks, including MAC flood, ICMP flood, SYN flood, UDP flood, and Layer 7 attacks. The resulting architecture, which integrates machine learning algorithms, access control mechanisms, and hardware-based filtering, provides comprehensive detection and mitigation of attacks at the L2—L4 and L7 layers of the OSI model. This approach enables timely threat identification, reduces incident response time, and can be integrated into corporate infrastructures as a component of a cybersecurity decision-support system.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.