Spatiotemporal characterization and graph-based interpretation of distributed denial of service attacks using deep learning
Résumé fourni par la source
The proliferation of cyberattacks demands defensive mechanisms capable of adapting to massive traffic volumes and increasingly dynamic threat patterns. This work proposes a spatiotemporal characterization of distributed denial-of-service attacks that serves as a preprocessing stage for downstream tasks such as detection, prediction, or mitigation. The central idea is to define how to segment and group traffic over time to reproducibly describe the evolution of an attack and to prepare the data for any subsequent module. The methodology structures traffic into temporal states and ordered sequences, which are then transformed into sequence tensors used as input to a hybrid Transformer–3D-CNN model. Through a systematic search, the study identifies the best-performing configuration consisting of ten-second states, sixty-four flows per state, a one-second temporal overlap between consecutive states, and five states per sequence. Consequently, each sequence spans an effective temporal window of forty-six seconds. Consecutive sequences are generated using an additional overlap of one complete state. For the final selected model, graph metrics and visual graph representations are analyzed to support post hoc interpretability and to identify observable structural patterns associated with the model’s classifications. The robustness of the selected characterization is further assessed through a 2D-CNN-LSTM architectural baseline, external assessment on the available CIC subsets, and distribution-based tests with increasing benign traffic proportions. The results show that the Transformer–3D-CNN outperforms the 2D-CNN-LSTM baseline, and that its performance decreases as benign traffic becomes dominant.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Spatiotemporal characterization and graph-based interpretation of distributed denial of service attacks using deep learning
- Date Crossref
- 15/08/2026
- Éditeur
- Springer Science and Business Media LLC
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude et ne compte pas comme une seconde source scientifique indépendante.
Institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.