Deception and cloud integration: A multi-layered approach for DDoS detection, mitigation, and attack surface minimization in SD-IoT networks

Faculty Computer Science Year: 2025
Type of Publication: ZU Hosted Pages:
Authors:
Journal: Computers and Electrical Engineering .Elsevier Ltd Volume: 126
Keywords : Deception , cloud integration: , multi-layered approach , DDoS    
Abstract:
Detecting Distributed Denial of Service (DDoS) attacks in Software-Defined Internet of Things (SD-IoT) networks is challenging due to vulnerabilities in single-controller architectures, the limitations of the OpenFlow protocol, evolving DDoS strategies, and resource constraints. This research proposes a multi-layered security framework that integrates deception-based security, cloud-integrated machine learning (ML), a new hierarchically distributed multi-controller (HDMC) architecture, P4-enabled real-time traffic monitoring, and adaptive mitigation. The framework includes dynamic time-based windowing for enhanced detection, a decoy network to divert attackers, and a cloud-based multi-task ML model (MT-EDD) for attack classification. It also features a synchronized multi-control design for secure communication and coordinated actions among multiple controllers and a dynamic monitoring algorithm for real-time traffic analysis. P4 switches extract features from network traffic and send them to a cloud-based server for preprocessing and analysis by a pre-trained ensemble learning model (MT-EDD), which predicts attack states and communicates results to the central controller for mitigation. The controller then enforces appropriate mitigation actions on P4 switches. This approach offloads computationally intensive tasks to the cloud, improving scalability and detection accuracy. Evaluations show the framework achieves an average accuracy of 98.42%, precision of 96.17%, recall of 94.72%, F1-score of 95.39%, and specificity of 98.22%. The proposed P4-enabled solution consumes 30% less bandwidth and 25% less CPU, reduces detection times by 54.3%, and improves detection accuracy by 5.2% compared to the OpenFlow-enabled method. The HDMC architecture, evaluated against a single-controller setup, demonstrated 40% higher throughput and 32% lower latency, confirming its superior performance across multiple metrics.
   
     
 
       

Author Related Publications

  • Wael Said AbdelMageed Mohamed, "A big data approach to sentiment analysis using greedy feature selection with cat swarm optimization-based long short-term memory neural networks", Springer Nature, 2018 More
  • Wael Said AbdelMageed Mohamed, "High-Precision Brain Tumor Diagnosis Using SECNN-MNet Framework and Explainable AI", Springer Nature Link, 2025 More
  • Wael Said AbdelMageed Mohamed, "Reinforcement Learning for Industrial Automation: A Comprehensive Review of Adaptive Control and Decision-Making in Smart Factories", MDPI, 2025 More
  • Wael Said AbdelMageed Mohamed, "RAUM-GANs: A Multi-Layer GAN-Enhanced Framework for Accurate Multiple Sclerosis Lesion Segmentation in MRI", Nature Portfolio, 2025 More
  • Wael Said AbdelMageed Mohamed, "MC-LBTO: secure and resilient state-aware multi-controller framework with adaptive load balancing for SD-IoT performance optimization", Nature Portfolio, 2025 More

Department Related Publications

  • Ahmed Salah Mohamed Mostafa, "Cluster-Distribute-Align-Merge: A General Algorithm to Speed Up Multiple Sequence Alignment on Multi-Core Computers", Journal of Computational and Theoretical Nanoscience, 2014 More
  • Zaher Awad Aboelenieen Elhendy, "NEW APPROACH TO IMAGE EDGE DETECTION BASED ON QUANTUM ENTROPY", JOURNAL OF RUSSIAN LASER RESEARCH, 2016 More
  • Sarah AbdelRazek Ahmed AbdulHameid, "Cloud Storage Forensics: Survey", International Journal of Engineering Trends and Technology (IJETT), 2017 More
  • Doaa El-Shahat Barakat Mohammed, "A modified hybrid whale optimization algorithm for the scheduling problem in multimedia data objects", Wiley online library, 2019 More
  • Abdallah Gamal abdallah mahmoud, "A novel model for evaluation Hospital medical care systems based on plithogenic sets", Elsevier B.V., 2019 More
Tweet