Deep Defender: An Adaptive Edge Cloud Framework for Intelligent DDoS Detection, Deception, and Tracking
DOI:
https://doi.org/10.17010/ijcs/2026/v11/i4/176099Keywords:
Cloud security, CNN-LSTM, cyberattack detection, deep learning, distributed denial-of-service (DDoS), intrusion detection systems
Publishing Chronology Paper Submission Date : June 6, 2026 ; Paper sent back for Revision : June 12, 2026 ; Paper Acceptance Date : June 15, 2026 ; Paper Published Online : August 5, 2026.
Abstract
Cloud computing environments are increasingly vulnerable to Distributed Denial-of-Service (DDoS) attacks and sophisticated cyber intrusions that compromise service availability, scalability, and operational security. In this research, we have developed a resilient cloud-based intrusion detection framework using a hybrid Convolutional Neural Network–Long Short-Term Memory (CNN-LSTM) deep-learning architecture for intelligent DDoS detection and cyberattack tracking. The proposed framework integrates spatial feature extraction and temporal traffic-learning mechanisms to effectively capture complex network-behavior patterns within heterogeneous cloud environments. We used the NSL-KDD dataset for experimental validation, which included preprocessing, feature normalization, correlation analysis, feature-importance evaluation, PCA visualization, and t-SNE-based nonlinear traffic analysis. The results reflected high detection performance (accuracy-99.14%, precision-99.06%, recall-99.14%, and F1 score-99.04%) besides low false-positive behavior and strong attack-prediction. The developed framework exhibited robust adaptive intrusion-learning capability, reliable multi-class attack classification, and scalable operational suitability for intelligent cloud-security monitoring and resilient cyber-threat management applications.
Downloads
References
[1] G. Loukas, T. Vuong, R. Heartfield, G. Sakellari, Y. Yoon, and D. Gan, “Cloud-based cyber-physical intrusion detection for vehicles using deep learning,” IEEE Access, vol. 6, pp. 3491–3508, 2018, doi: 10.1109/ACCESS.2017.2782159. DOI: https://doi.org/10.1109/ACCESS.2017.2782159
[2] G. Somani, M. S. Gaur, D. Sanghi, M. Conti, and M. Rajarajan, “Scale inside-out: Rapid mitigation of cloud DDoS attacks,” IEEE Trans. Dependable Secure Comput., vol. 15, no. 6, pp. 959–973, Nov.–Dec. 2018, doi: 10.1109/TDSC.2017.2763160. DOI: https://doi.org/10.1109/TDSC.2017.2763160
[3] N. Keegan, S.-Y. Ji, A. Chaudhary, C. Concolato, B. Yu, and D. H. Jeong, “A survey of cloud-based network intrusion detection analysis,” Human-Centric Comput. Inf. Sci., vol. 6, no. 19, pp. 1–16, Dec. 2016, doi: 10.1186/s13673-016-0076-z. DOI: https://doi.org/10.1186/s13673-016-0076-z
[4] H. Attou, A. Guezzaz, S. Benkirane, M. Azrour, and Y. Farhaoui, “Cloud-based intrusion detection approach using machine learning techniques,” Big Data Mining Anal., vol. 6, no. 3, pp. 311–320, Apr. 2023, doi: 10.26599/BDMA.2022.9020038. DOI: https://doi.org/10.26599/BDMA.2022.9020038
[5] A. Bakshi and Y. B. Dujodwala, “Securing cloud from DDoS attacks using intrusion detection system in virtual machine,” in 2010 2nd Int. Conf. Communication Softw. Networks, Singapore, 2010, pp. 260–264, doi: 10.1109/ICCSN.2010.56. DOI: https://doi.org/10.1109/ICCSN.2010.56
[6] O. Alkadi, N. Moustafa, B. Turnbull, and K.-K. R. Choo, “A deep blockchain framework-enabled collaborative intrusion detection for protecting IoT and cloud networks,” IEEE Internet Things J., vol. 8, no. 12, pp. 9463–9472, Jun. 2021, doi: 10.1109/JIOT.2020.2996590. DOI: https://doi.org/10.1109/JIOT.2020.2996590
[7] R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525–41550, 2019, doi: 10.1109/ACCESS.2019.2895334. DOI: https://doi.org/10.1109/ACCESS.2019.2895334
[8] A. Halbouni, T. S. Gunawan, M. H. Habaebi, M. Halbouni, M. Kartiwi, and R. Ahmad, “Machine learning and deep learning approaches for cybersecurity: A review,” IEEE Access, vol. 10, pp. 19572-19585, 2022, doi: 10.1109/ACCESS.2022.3151248. DOI: https://doi.org/10.1109/ACCESS.2022.3151248
[9] J. Zhang, L. Pan, Q.-L. Han, C. Chen, S. Wen, and Y. Xiang, “Deep learning based attack detection for cyber-physical system cybersecurity: A survey,” IEEE/CAA J. Autom. Sinica, vol. 9, no. 3, pp. 377–391, Mar. 2022, doi: 10.1109/JAS.2021.1004261. DOI: https://doi.org/10.1109/JAS.2021.1004261
[10] H. Karimipour, A. Dehghantanha, R. M. Parizi, K.-K. R. Choo, and H. Leung, “A deep and scalable unsupervised machine learning system for cyber-attack detection in large-scale smart grids,” IEEE Access, vol. 7, pp. 80778–80788, 2019, doi: 10.1109/ACCESS.2019.2920326. DOI: https://doi.org/10.1109/ACCESS.2019.2920326
[11] A. A. Diro and N. Chilamkurti, “Distributed attack detection scheme using deep learning approach for Internet of Things,” Future Gener. Comput. Syst., vol. 82, pp. 761–768, May 2018, doi: 10.1016/j.future.2017.08.043. DOI: https://doi.org/10.1016/j.future.2017.08.043
[12] Y. Xin, L. Kong, Z. Liu, Y. Chen, Y. Li, H. Zhu, M. Gao, H. Hou, and C. Wang, “Machine learning and deep learning methods for cybersecurity,” IEEE Access, vol. 6, pp. 35365–35381, 2018, doi: 10.1109/ACCESS.2018.2836950. DOI: https://doi.org/10.1109/ACCESS.2018.2836950
[13] P. Sinha, D. Sahu, S. Prakash, T. Yang, R. S. Rathore, and V. K. Pandey, “A high performance hybrid LSTM CNN secure architecture for IoT environments using deep learning,” Sci. Rep., vol. 15, Art. no. 9684, 2025, doi: 10.1038/s41598-025-94500-5. DOI: https://doi.org/10.1038/s41598-025-94500-5
[14] A. Halbouni, T. S. Gunawan, M. H. Habaebi, M. Halbouni, M. Kartiwi, and R. Ahmad, “CNN-LSTM: Hybrid deep neural network for network intrusion detection system,” IEEE Access, vol. 10, pp. 99837–99849, 2022, doi: 10.1109/ACCESS.2022.3206425. DOI: https://doi.org/10.1109/ACCESS.2022.3206425
[15] M. Alhussein, K. Aurangzeb, and S. I. Haider, “Hybrid CNN-LSTM model for short-term individual household load forecasting,” IEEE Access, vol. 8, pp. 180544–180557, 2020, doi: 10.1109/ACCESS.2020.3028281. DOI: https://doi.org/10.1109/ACCESS.2020.3028281
[16] H. Alkahtani and T. H. Aldhyani, “Botnet attack detection by using CNN-LSTM model for Internet of Things applications,” Security Commun. Netw., vol. 2021, Art. no. 3806459, pp. 1–9, Sep. 2021, doi: 10.1155/2021/3806459. DOI: https://doi.org/10.1155/2021/3806459
[17] A. Alferaidi, K. Yadav, Y. Alharbi, N. Razmjooy, W. Viriyasitavat, K. Gulati, and S. Kautish, “Distributed Deep CNN-LSTM model for intrusion detection method in IoT-based vehicles,” Math. Probl. Eng., vol. 2022, Art. no. 3424819, pp. 1–15, Mar. 2022, doi: 10.1155/2022/3424819. DOI: https://doi.org/10.1155/2022/3424819
[18] M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in Proc. 2009 IEEE Symp. Comput. Intell. Security Defense Appl., Ottawa, ON, Canada, Jul. 2009, pp. 1–6, doi: 10.1109/CISDA.2009.5356528. DOI: https://doi.org/10.1109/CISDA.2009.5356528
[19] J. Wong, “NSL-KDD Dataset Repository,” GitHub Repository. Accessed: May 11, 2026. [Online]. Available: https://github.com/jmnwong/NSL-KDD-Dataset