Discrete mathematical modeling–driven machine learning framework for secure encrypted DDoS attack detection in cloud and edge computing
Manmohan Sharmamanmohan.sharma@jaipur.manipal.eduDepartment of Computer Science & EngineeringFaculty of Science, Technology and Architecture (FoSTA)Manipal University JaipurJaipur, Rajasthan, 303007, IndiaView full profile → , Anudeep Aroraarora.anudeep85@gmail.comDepartment of ManagementNew Delhi Institute of Management (NDIM)Guru Gobind Singh Indraprastha UniversityTughlakabad, New Delhi, 110062, IndiaView full profile → , Priya Mathurpriya.mathur@poornima.orgDepartment of MathematicsPoornima Institute of Engineering & TechnologyJaipur, Rajasthan, 302022, IndiaView full profile → , Saloni Bhushandrsaloni.bhushan@gmail.comDepartment of Computer ApplicationSchool of Humanities & SciencesD Y Patil Deemed to be UniversityNerul, Navi Mumbai, Maharashtra, 400706, IndiaView full profile → , *Amit Kumar GuptaCorresponding authoramit.gupta@jaipur.manipal.eduDepartment of Computer Science & EngineeringFaculty of Science, Technology and Architecture (FoSTA)Manipal University JaipurJaipur, Rajasthan, 303007, IndiaView full profile →
* Corresponding author · click or hover a name for details
- Received:
- 01 Dec 2025
- Published Online:
- 14 Aug 2026
- Article type:
- Research Article
- Language:
- EN
- Article no.:
- JDMSC-2693
- Pages:
- 3085–3093
Abstract
Distributed denial-of-service (DDoS) attacks causes significant threats in modern cloud and edge computing because of complex traffic patterns that intricate attack detection. Traditional methods have limitations in distinguishing attack strategies and extracting relevant information. This study retains machine learning and deep learning techniques to find DDoS attacks using the CICDDoS-2019 dataset, which has pre-processed to include 431,371 records and 78 features. The preprocessing intricate handling duplicates, missing values, and class imbalances using SMOTE. Various classifiers, including Logistic Regression, Decision Tree, Random Forest, XGBoost, and LightGBM, alongside One-Class SVM and Autoencoder-Bidirectional LSTM (AE–BiLSTM) models, were utilized. Assessments of metrics such as accuracy, precision, recall, F1-score, and ROC–AUC were employed to assess the models. Results indicated that ensemble methods like XGBoost and LightGBM achieved perfect ROC–AUC scores of 1.00, while AE–BiLSTM shows strong anomaly detection with a ROC–AUC of 0.9979. This framework gives a practical solution for improving network security within cloud and edge computing environments.
Keywords
Subject Classifications
References
[1] A. L. Buczak and E. Guven, “A survey of data mining and machine learning methods for cyber security intrusion detection,” IEEE Commun. Surveys Tuts., vol. 18, no. 2, pp. 1153–1176 (2016).
[2] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. Int. Conf. Information Systems Security and Privacy (ICISSP), pp. 108–116 (2018).
[3] W. Lee and S. J. Stolfo, “A framework for constructing features and models for intrusion detection systems,” ACM Trans. Inf. Syst. Secur., vol. 3, no. 4, pp. 227–261 (Nov 2000).
[4] L. Breiman, “Random forests,” Mach. Learn., vol. 45, no. 1, pp. 5–32 (2001).
[5] T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD), San Francisco, CA, USA, pp. 785–794 (2016), doi: 10.1145/2939672.2939785.
[6] G. Ke, Q. Meng, T. Finley, T. Wang, W. Chen, W. Ma, Q. Ye, and T.-Y. Liu, “LightGBM: A highly efficient gradient boosting decision tree,” in Advances in Neural Information Processing Systems (NeurIPS), vol. 30, pp. 3146–3154 (2017).
[7] M. Hasan, M. M. Islam, M. A. Razzaque, and M. M. Hassan, “DDoS attack detection using ensemble machine learning,” Comput. Secur., vol. 113, Art. no. 102549 (2022).
[8] N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, “SMOTE: Synthetic minority over-sampling technique,” J. Artif. Intell. Res., vol. 16, pp. 321–357 (2002).
[9] B. Schölkopf, J. C. Platt, J. Shawe-Taylor, A. J. Smola, and R. C. Williamson, “Estimating the support of a high-dimensional distribution,” Neural Comput., vol. 13, no. 7, pp. 1443–1471 (2001).
[10] G. E. Hinton and R. R. Salakhutdinov, “Reducing the dimensionality of data with neural networks,” Science, vol. 313, no. 5786, pp. 504–507 (2006).
[11] S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural Comput., vol. 9, no. 8, pp. 1735–1780 (1997).
[12] T. Fawcett, “An introduction to ROC analysis,” Pattern Recognit. Lett., vol. 27, no. 8, pp. 861–874 (2006).
[13] A. Noonia, D. Thakral, P. Mathur, F. Sheth, H. Shaikh, and A. K. Gupta, “A discrete mathematical model and cryptography for secure medical image analysis: Encrypted chest X-ray classification,” J. Discrete Math. Sci. Cryptogr., vol. 28, no. 5-A, pp. 1473–1486 (2025).
[14] D. Goyal, A. Kumar, P. Mathur, F. Sheth, and A. K. Gupta, “Robust cybersecurity through discrete and large language models for effective phishing attack detection,” J. Discrete Math. Sci. Cryptogr., vol. 28, no. 5-A, pp. 1621–1638 (2025).
[15] D. Goyal, F. Sheth, P. Mathur, and A. K. Gupta, “Discrete mathematical models for enhancing cybersecurity: A mathematical and statistical analysis of machine learning approaches in phishing attack detection,” J. Discrete Math. Sci. Cryptogr., vol. 27, no. 2-B, pp. 569–599 (2024).




