{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T04:05:29Z","timestamp":1781064329128,"version":"3.54.1"},"reference-count":41,"publisher":"Oxford University Press (OUP)","issue":"8","license":[{"start":{"date-parts":[[2025,3,11]],"date-time":"2025-03-11T00:00:00Z","timestamp":1741651200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"funder":[{"name":"Fundamental Research Funds Special Project for Research Innovation Platform of Higher Education Institutions of Heilongjiang Province","award":["145409442"],"award-info":[{"award-number":["145409442"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,8,14]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>With the widespread adoption of Software Defined Networking (SDN), detecting Distributed Denial of Service (DDoS) attacks has become an urgent challenge in SDN maintenance and Security. Given the diversity of DDoS attack types, we face significant challenges. This paper proposes a model called ARSAE-QGRU, which is based on integrating attention mechanisms and residual connections within a stacked autoencoder for DDoS attack detection. By introducing attention mechanisms and residual connections into the stacked autoencoder (SAE), the model effectively conveys more valuable information and facilitates gradient propagation, allowing it to learn low-dimensional representations better. It also combines the learned low-dimensional representations with traffic features to generate data for DDoS attack training. Furthermore, incorporating Gated Recurrent Unit aids in a more in-depth understanding of the temporal characteristics of traffic data, resulting in improved detection accuracy. This model demonstrates outstanding performance on the CICDDoS2019 and CICIDS2017 datasets, achieving accuracy rates of 97.2% and 97.9%, respectively. Moreover, when applied to datasets in SDN environments, it reaches an even higher accuracy rate of 99.8%. This research provides a reliable solution for high-dimensional data processing and DDoS attack detection within SDN, addressing the urgent challenges in these domains.<\/jats:p>","DOI":"10.1093\/comjnl\/bxaf021","type":"journal-article","created":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T15:20:40Z","timestamp":1740151240000},"page":"1028-1049","source":"Crossref","is-referenced-by-count":7,"title":["A new DDoS attack detection model based on improved stacked autoencoder and gated recurrent unit for software defined network"],"prefix":"10.1093","volume":"68","author":[{"given":"Haizhen","family":"Wang","sequence":"first","affiliation":[{"name":"Department of Computer Science and Technology, College of Computer and Control Engineering, Qiqihar University , No. 42 Wenhua Street, Jianhua District, Heilongjiang, Qiqihar 161006 ,","place":["China"]},{"name":"Heilongjiang Key Laboratory of Big Data Network Security Detection and Analysis, Qiqihar University , No. 42 Wenhua Street, Jianhua District, Heilongjiang, Qiqihar 161006,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8137-3637","authenticated-orcid":false,"given":"Na","family":"Jia","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, College of Computer and Control Engineering, Qiqihar University , No. 42 Wenhua Street, Jianhua District, Heilongjiang, Qiqihar 161006 ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-6878-4736","authenticated-orcid":false,"given":"Yang","family":"He","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, College of Computer and Control Engineering, Qiqihar University , No. 42 Wenhua Street, Jianhua District, Heilongjiang, Qiqihar 161006 ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3861-0405","authenticated-orcid":false,"given":"Zuozheng","family":"Lian","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, College of Computer and Control Engineering, Qiqihar University , No. 42 Wenhua Street, Jianhua District, Heilongjiang, Qiqihar 161006 ,","place":["China"]},{"name":"Heilongjiang Key Laboratory of Big Data Network Security Detection and Analysis, Qiqihar University , No. 42 Wenhua Street, Jianhua District, Heilongjiang, Qiqihar 161006,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2025,3,11]]},"reference":[{"key":"2025081702470730000_ref1","article-title":"Distributed denial of service attacks and its defenses in IoT: a survey","volume":"76","author":"Salim","year":"2019","journal-title":"J Supercomput"},{"key":"2025081702470730000_ref2","doi-asserted-by":"publisher","first-page":"1078","DOI":"10.3724\/SP.J.1001.2013.04390","article-title":"Research on SDN technology based on OpenFlow","volume":"24","author":"Zuo","year":"2013","journal-title":"J Softw"},{"key":"2025081702470730000_ref3","volume-title":"Global DDoS Threat Report for the First Half of 2021 [R\/OL]","author":"Tencent Security and Green Alliance Technology","year":"2021"},{"key":"2025081702470730000_ref4","volume-title":"DDoS Year-in-Review Report by StormWall [R\/OL]","author":"StormWall","year":"2022"},{"key":"2025081702470730000_ref5","doi-asserted-by":"publisher","first-page":"100279","DOI":"10.1016\/j.cosrev.2020.100279","article-title":"Detection and mitigation of DDoS attacks in SDN: a comprehensive review, research challenges and future directions","volume":"37","author":"Singh","year":"2020","journal-title":"Comput Sci Rev"},{"key":"2025081702470730000_ref6","doi-asserted-by":"publisher","first-page":"102595","DOI":"10.1016\/j.jnca.2020.102595","article-title":"Security in SDN: a comprehensive survey","volume":"159","author":"Chica","year":"2020","journal-title":"J Netw Comput Appl"},{"key":"2025081702470730000_ref7","doi-asserted-by":"publisher","first-page":"102587","DOI":"10.1016\/j.jisa.2020.102587","article-title":"A DDoS attack detection and defense scheme using time-series analysis for SDN","volume":"54","author":"Fouladi","year":"2020","journal-title":"J Inf Secur Appl"},{"key":"2025081702470730000_ref8","doi-asserted-by":"publisher","first-page":"609","DOI":"10.1109\/PICST51311.2020.946796","volume-title":"2020 IEEE International Conference on Problems of Info Communications. Science and Technology (PIC S&T)","author":"Klymash","year":"2020"},{"key":"2025081702470730000_ref9","doi-asserted-by":"publisher","first-page":"731","DOI":"10.1109\/ITNEC48623.2020.9084885","volume-title":"2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC)","author":"Li","year":"2020"},{"key":"2025081702470730000_ref10","doi-asserted-by":"publisher","first-page":"1679","DOI":"10.1109\/TNSM.2022.3142254","article-title":"An online entropy-based DDoS flooding attack detection system with dynamic threshold","volume":"19","author":"Tsobdjou","year":"2022","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"2025081702470730000_ref11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ViTECoN.2019.8899682","volume-title":"2019 International Conference on Vision Towards Emerging Trends in Communication and Networking (ViTECoN)","author":"Deepa","year":"2019"},{"key":"2025081702470730000_ref12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/NTMS.2011.572058","volume-title":"2011 4th IFIP International Conference on New Technologies, Mobility and Security","author":"Winter","year":"2011"},{"key":"2025081702470730000_ref13","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1007\/s10922-023-09749-w","article-title":"Secure SDN-IoT framework for DDoS attack detection using deep learning and counter based approach","volume":"31","author":"Cherian","year":"2023","journal-title":"J Netw Syst Manage"},{"key":"2025081702470730000_ref14","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/SEAISAP49340.2020.234999","volume-title":"Proceedings of the 2020 Third ISEA Conference on Security and Privacy (ISEA-ISAP)","author":"Nandi","year":": , 2020"},{"key":"2025081702470730000_ref15","doi-asserted-by":"publisher","first-page":"103462","DOI":"10.1016\/j.cose.2023.103462","article-title":"Detecting and mitigating DDoS attacks with moving target defence approach based on automated flow classification in SDN networks","volume":"134","author":"Ribeiro","year":"2023","journal-title":"Comput Secur"},{"key":"2025081702470730000_ref16","doi-asserted-by":"crossref","first-page":"100042","DOI":"10.1016\/j.csa.2024.100042","article-title":"A novel dual optimised IDS to detect DDoS attack in SDN using hyper tuned RFE and deep grid network","volume":"2","author":"Nalayini","year":"2024","journal-title":"Cyber Security and Applications"},{"key":"2025081702470730000_ref17","first-page":"1","article-title":"DDoS attack detection based on joint entropy and multiple clustering in SDN networks","volume":"23","author":"Wang","year":"2023","journal-title":"Information Network Security"},{"key":"2025081702470730000_ref18","doi-asserted-by":"publisher","first-page":"1030","DOI":"10.1109\/IWCMC51323.2021.9498840","volume-title":"2021 International Wireless Communications and Mobile Computing (IWCMC)","author":"Gang","year":"2021"},{"key":"2025081702470730000_ref19","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1016\/j.future.2021.06.047","article-title":"Adversarial deep learning approach detection and defence against DDoS attacks in SDN environments","volume":"125","author":"Novaes","year":"2021","journal-title":"Future Gener Comput Syst"},{"key":"2025081702470730000_ref20","doi-asserted-by":"publisher","first-page":"1084","DOI":"10.1109\/ITNEC48623.2020.9085007","volume-title":"2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC)","author":"Wang","year":"2020"},{"key":"2025081702470730000_ref21","doi-asserted-by":"publisher","first-page":"876","DOI":"10.1109\/TNSM.2020.2971776","article-title":"Lucid: a practical, lightweight deep learning solution for DDoS attack detection","volume":"17","author":"Doriguzzi-Corin","year":"2020","journal-title":"IEEE Transactions on Network and Service Management"},{"key":"2025081702470730000_ref22","doi-asserted-by":"publisher","first-page":"407","DOI":"10.59670\/ml.v20iS13.6472","article-title":"Detection and mitigation of DDoS attack in SDN environment using hybrid CNN-LSTM","volume":"20","author":"Rajan","year":"2023","journal-title":"Migration Letters"},{"key":"2025081702470730000_ref23","doi-asserted-by":"publisher","first-page":"538","DOI":"10.3390\/network3040024","article-title":"Optimized MLP-CNN model to enhance detecting DDoS attacks in SDN environment","volume":"3","author":"Setitra","year":"2023","journal-title":"Networks"},{"key":"2025081702470730000_ref24","doi-asserted-by":"publisher","first-page":"1040","DOI":"10.3390\/s24031040","article-title":"Multi-stage learning framework using convolutional neural network and decision tree-based classification for detection of DDoS pandemic attacks in SDN-based SCADA systems","volume":"24","author":"Polat","year":"2024","journal-title":"Sensors"},{"key":"2025081702470730000_ref25","first-page":"2440","article-title":"Attention mechanism based attack DDoS detection method","volume":"42","author":"Jing","year":"2021","journal-title":"Computer Engineering and Design"},{"key":"2025081702470730000_ref26","first-page":"277","article-title":"Bi-LSTM-based DDoS attack detection scheme in SDN environment","volume":"45","author":"Bai","year":"2023","journal-title":"Computer Engineering and Science"},{"key":"2025081702470730000_ref27","doi-asserted-by":"publisher","first-page":"116748","DOI":"10.1016\/j.eswa.2022.116748","article-title":"A novel approach for accurate detection of the DDoS attacks in SDN-based SCADA systems based on deep recurrent neural networks","volume":"197","author":"Polat","year":"2022","journal-title":"Expert Systems with Applications"},{"key":"2025081702470730000_ref28","first-page":"73","article-title":"DDoS traffic detection for 5G SDN environment based on self-attention mechanism","volume":"01","author":"Chen","year":"2022","journal-title":"Network Security Technology and Application"},{"key":"2025081702470730000_ref29","first-page":"419","article-title":"Research on DDoS attack detection method with DWT and AKD autoencoder","volume":"15","author":"Wang","year":"2023","journal-title":"Journal of Nanjing University of Information Engineering: Natural Science Edition"},{"key":"2025081702470730000_ref30","doi-asserted-by":"publisher","first-page":"53015","DOI":"10.1109\/ACCESS.2022.3172304","article-title":"Cyber threats detection in smart environments using SDN-enabled DNN-LSTM hybrid framework","volume":"10","author":"Razib","year":"2022","journal-title":"IEEE Access"},{"key":"2025081702470730000_ref31","doi-asserted-by":"publisher","first-page":"197","DOI":"10.3390\/a16040197","article-title":"An adversarial DBN-LSTM method for detecting and defending against DDoS attacks in SDN environments","volume":"16","author":"Chen","year":"2023","journal-title":"Algorithms"},{"key":"2025081702470730000_ref32","doi-asserted-by":"publisher","first-page":"417","DOI":"10.1007\/s00779-023-01785-2","article-title":"DDoS attack traffic classification in SDN using deep learning","volume":"28","author":"Ahuja","year":"2024","journal-title":"Personal and Ubiquitous Computing"},{"key":"2025081702470730000_ref33","doi-asserted-by":"publisher","first-page":"103661","DOI":"10.1016\/j.cose.2023.103661","article-title":"DDoS attack detection and mitigation using deep neural network in SDN environment","volume":"138","author":"Hnamte","year":"2024","journal-title":"Comput Secur"},{"key":"2025081702470730000_ref34","doi-asserted-by":"publisher","first-page":"2340008","DOI":"10.1142\/S0219519423400080","article-title":"DDoS attack detection methods based on deep learning in healthcare","volume":"23","author":"Wang","year":"2023","journal-title":"Journal of Mechanics in Medicine and Biology"},{"key":"2025081702470730000_ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CCST.2019.8888419","volume-title":"IEEE 53rd International Carnahan Conference on Security Technology","author":"Sharafaldin","year":"2019"},{"key":"2025081702470730000_ref36","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/j.comnet.2017.03.018","article-title":"Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling","volume":"121","author":"Jazi","year":"2017","journal-title":"Comput Netw"},{"key":"2025081702470730000_ref37","article-title":"SDN-TCP-SYN attack-DDOS dataset","volume":"V2","author":"Kumar","year":"2022","journal-title":"Mendeley Data"},{"key":"2025081702470730000_ref38","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2022\/8530312","article-title":"Recurrent and deep learning neural network models for DDoS attack detection","volume":"2022","author":"Sumathi","year":"2022","journal-title":"J Sens"},{"key":"2025081702470730000_ref39","article-title":"A cooperative detection of DDoS attacks based on CNN-BiLSTM in SDN","volume":"2589","author":"Zhou","year":"2023","journal-title":"Journal of Physics: Conference Series"},{"key":"2025081702470730000_ref40","doi-asserted-by":"publisher","first-page":"26","DOI":"10.13140\/RG.2.2.14667.59684","volume-title":"Proceedings of the 2018 10th International Conference on Machine Learning and Computing (ICMLC'18)","author":"Agarap","year":"2018"},{"key":"2025081702470730000_ref41","volume-title":"Research on Network Intrusion Detection System Based on Improved Transformer [D]","author":"Gao","year":"2023"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/68\/8\/1028\/62370374\/bxaf021.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/68\/8\/1028\/62370374\/bxaf021.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,17]],"date-time":"2025-08-17T06:47:15Z","timestamp":1755413235000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/68\/8\/1028\/8069014"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,11]]},"references-count":41,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2025,3,11]]},"published-print":{"date-parts":[[2025,8,14]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxaf021","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2025,8]]},"published":{"date-parts":[[2025,3,11]]}}}