PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 2, 2026Security and Privacy2 citationsOpen Access

Edge‐Oriented DoS/DDoS Intrusion Detection and Supervision Platform

View Full Paper
GJGeraldo Eufrazio Martins JúniorTMThales Guimaraes MarquesWSWendley Souza da Silva

Key Points

  • The goal is to develop a novel intrusion detection platform that can effectively identify DoS and DDoS attacks on resource-constrained edge servers.
  • Developed an anomaly detection system using ML and DL algorithms.
  • Integrated four temporal analysis techniques including Shannon entropy and ARIMA.
  • Validated the approach using datasets from CIC-IDS for application-layer attacks.
  • Implemented statistical rigor through cross-validation and confidence intervals.
  • Achieved 99.9% accuracy in temporal cross-validation with Configuration 5.
  • Confirmed the approach's performance on a Raspberry Pi 3B+, ensuring effective real-time detection.
  • Demonstrated the models' adaptability to different time periods of missing data.

Abstract

ABSTRACT This work presents an Edge Node‐Oriented DoS/DDoS Intrusion Detection and Monitoring Platform, a novel anomaly detection system based on temporal analysis with machine learning (ML) and deep learning (DL) algorithms, specifically designed to operate on edge servers with limited resources. The proposed approach systematically integrates four complementary temporal analysis techniques: Shannon entropy, autoregressive integrated moving average (ARIMA), Hölder local exponent, and moving averages, used for smoothing and trend identification. This multidimensional combination enables robust modeling of normal network traffic behavior and effective detection of statistical deviations that characterize malicious activity. Experimental validation was performed using datasets (CIC‐IDS‐2017, CSE‐CIC‐IDS2018, CIC‐IDS‐2023) with a specific focus on application‐layer attacks, notably denial‐of‐service (DoS) and distributed denial‐of‐service (DDoS) attacks, such as Slowloris and SlowHTTPTest, which pose threats due to their ability to mimic their own traffic. The experimental methodology included 99% confidence intervals, ensuring statistical rigor. A significant methodological contribution was the implementation of cross‐validation between datasets to assess temporal transferability, demonstrating the models' ability to maintain adequate performance when applied to missing data from different time periods. The experimental results demonstrate the high performance of the proposed approach, with Configuration 5 (combination of mobile media and Shannon entropy) achieving 99.9% accuracy in temporal cross‐validation. Validation on a real device (Raspberry Pi 3B+) confirmed the computational prediction of the solution, demonstrating the ability to detect data in real time without significantly compromising the device's computational resources.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Júnior et al. (2026) studied this question.

synapsesocial.com/papers/6980fecbc1c9540dea8113cdhttps://doi.org/10.1002/spy2.70193
Ask AI
Helpful
Bookmark
Share
View Full Paper