Passer à la navigation principale Passer à la recherche Passer au contenu principal

Distributed Denial-of-Service Attack Vector Identification in IoT Networks Using Wavelet Transform and Hybrid Deep Learning

  • KU Leuven
  • EnergyVille

Résultats de recherche: Contribution à un journalArticleRevue par des pairs

Résumé

Robust defense mechanisms against distributed denial-of-service (DDoS) attacks often require not only precise detection of anomalous flows, but also real-time identification and quantification of the implicated attack vector. This has become highly challenging with the increasing scale and complexity of Internet of Things (IoT) networks, especially under widespread traffic encryption. Most prior works in this area are either limited to binary classification or rely on packet-level signatures that become inaccessible or highly altered by encryption protocols such as transport layer security (TLS), datagram TLS (DTLS), or virtual private network (VPN). This article presents a novel methodology and multiclass classification framework for DDoS attack-vector identification and quantification across different open systems interconnection (OSI) layers, using an approach that is agnostic to payload content and packet-level signatures and instead focuses exclusively on traffic timing characteristics. The proposed framework utilizes packet interarrival times (PIATs) as its sole observable, enabling not only the detection of attack traffic but also the identification of attack vectors and quantification of attack intensity, even in the presence of cryptographic overheads and the resulting increase in temporal uncertainty. Discrete wavelet transforms (DWTs) are applied to PIAT sequences to capture both transient and persistent timing patterns across multiple scales. These patterns are then processed by a hybrid deep learning (DL) architecture that integrates convolutional layers, BiLSTM units, and an attention mechanism. Comprehensive experiments are conducted on the IEEE P2668-MLIDD and Bot-IoT datasets, augmented by incorporating cryptographic processing overhead to imitate encrypted network conditions. The results demonstrate that the framework achieves high accuracy in both attack vector and intensity classification, and consistently sustains robust performance across different network and communication settings.

langue originaleAnglais
Pages (de - à)32272-32291
Nombre de pages20
journalIEEE Internet of Things Journal
Volume13
Numéro de publication14
Les DOIs
étatPublié - 15 juil. 2026

Empreinte digitale

Examiner les sujets de recherche de « Distributed Denial-of-Service Attack Vector Identification in IoT Networks Using Wavelet Transform and Hybrid Deep Learning ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation