{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T15:02:40Z","timestamp":1771513360188,"version":"3.50.1"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T00:00:00Z","timestamp":1770163200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T00:00:00Z","timestamp":1771459200000},"content-version":"vor","delay-in-days":15,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cloud Comp"],"DOI":"10.1186\/s13677-026-00848-y","type":"journal-article","created":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T20:34:39Z","timestamp":1770237279000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Online machine learning for proactive threat intelligence and timely DDoS attack prediction"],"prefix":"10.1186","volume":"15","author":[{"given":"Rrezearta","family":"Thaqi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gabriele","family":"Lenzini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marcus","family":"V\u00f6lp","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Blerim","family":"Rexha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,2,4]]},"reference":[{"key":"848_CR1","unstructured":"Cloudflare DDoS threat report for 2025 Q2. https:\/\/blog.cloudflare.com\/ddos-threat-report-for-2025-q2\/. Accessed Aug 22 2025"},{"key":"848_CR2","doi-asserted-by":"publisher","DOI":"10.35940\/ijitee.B1032.14020125","author":"V N","year":"2025","unstructured":"N V, Sriram VSS (2025) Mitigating DDoS attacks in virtual machine migration: an in-depth security framework utilizing deep learning and advanced encryption techniques. Int J Innovative Technol Exploring Eng. https:\/\/doi.org\/10.35940\/ijitee.B1032.14020125","journal-title":"Int J Innovative Technol Exploring Eng"},{"key":"848_CR3","doi-asserted-by":"publisher","unstructured":"Thaqi R, Krasniqi B, Mazrekaj A, Rexha B (2025) Literature review of machine learning and threat intelligence in cloud security. IEEE Access 13. https:\/\/doi.org\/10.1109\/ACCESS.2025.3529636","DOI":"10.1109\/ACCESS.2025.3529636"},{"key":"848_CR4","doi-asserted-by":"publisher","unstructured":"Alshammari A, Aldribi A (2021) Apply machine learning techniques to detect malicious network traffic in cloud computing. J Big Data 8(90). https:\/\/doi.org\/10.1186\/s40537-021-00475-1","DOI":"10.1186\/s40537-021-00475-1"},{"key":"848_CR5","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1002\/9781394272464.ch25","volume":"25","author":"A Sharma","year":"2025","unstructured":"Sharma A, Singh UK (2025) Cloud computing security through detection & mitigation of zero-day attack using machine learning techniques. Chap. 25:357\u2013388. https:\/\/doi.org\/10.1002\/9781394272464.ch25","journal-title":"Chap."},{"key":"848_CR6","doi-asserted-by":"publisher","unstructured":"Rai HM, Yoo J, Agarwal S (2024) The improved network intrusion detection techniques using the feature engineering approach with boosting classifiers. Mathematics 12(24). https:\/\/doi.org\/10.3390\/math12243909","DOI":"10.3390\/math12243909"},{"key":"848_CR7","unstructured":"Joseph O, Ajax R (2025) Comparison of traditional vs. ai-based intrusion detection and prevention systems: efficiency and accuracy. J Cybersecur Adv"},{"key":"848_CR8","doi-asserted-by":"publisher","DOI":"10.3389\/fcomp.2025.1520741","author":"VZ Mohale","year":"2025","unstructured":"Mohale VZ (2025) Evaluating machine learning-based intrusion detection: improved accuracy, reduced false positives, and identification of unseen threats. Front Comput Sci. https:\/\/doi.org\/10.3389\/fcomp.2025.1520741. published online in 2025","journal-title":"Front Comput Sci"},{"key":"848_CR9","doi-asserted-by":"publisher","unstructured":"Rahman MR, Mahdavi-Hezaveh R, Williams L (2021) What are the attackers doing now? automating cyber threat intelligence extraction from text on pace with the changing threat landscape: a survey. arXiv preprint arXiv:2109.06808 https:\/\/doi.org\/10.48550\/arxiv.2109.06808","DOI":"10.48550\/arxiv.2109.06808"},{"key":"848_CR10","doi-asserted-by":"publisher","unstructured":"Sousa P, Neves NF, Verissimo P, Sanders WH (2006) Proactive resilience revisited: the delicate balance between resisting intrusions and remaining available. In 2006 25th IEEE Symposium on Reliable Distributed Systems (SRDS\u201906), pp 71\u201382. https:\/\/doi.org\/10.1109\/SRDS.2006.37","DOI":"10.1109\/SRDS.2006.37"},{"key":"848_CR11","doi-asserted-by":"publisher","unstructured":"Silva DS, Graczyk R, Decouchant J, V\u00f6lp M, Esteves-Verissimo P (2021) Threat adaptive byzantine fault tolerant state-machine replication. In 2021 40th International Symposium on Reliable Distributed Systems (SRDS), pp 78\u201387. https:\/\/doi.org\/10.1109\/SRDS53918.2021.00017","DOI":"10.1109\/SRDS53918.2021.00017"},{"issue":"18","key":"848_CR12","doi-asserted-by":"publisher","first-page":"3801","DOI":"10.3390\/electronics12183801","volume":"12","author":"W Zhong","year":"2023","unstructured":"Zhong W, Yang C, Liang W, Cai J, Chen L, Liao J, Xiong N (2023) Byzantine fault-tolerant consensus algorithms: a survey. Electronics 12(18):3801. https:\/\/doi.org\/10.3390\/electronics12183801","journal-title":"Electronics"},{"issue":"16","key":"848_CR13","doi-asserted-by":"publisher","first-page":"3319","DOI":"10.3390\/electronics14163319","volume":"14","author":"S-R Chen","year":"2025","unstructured":"Chen S-R et al. (2025) Enhancing machine learning-based ddos detection with adaptive hyperparameter tuning for robust generalization. Electronics 14(16):3319. https:\/\/doi.org\/10.3390\/electronics14163319","journal-title":"Electronics"},{"key":"848_CR14","doi-asserted-by":"publisher","unstructured":"Alrassan I, AlQahtani AM (2023) Detection of ddos attacks on clouds computing environments using machine learning techniques. In 2023 International Conference on Communication and Network Security (ICCNS). https:\/\/doi.org\/10.1109\/iccns58795.2023.10193141","DOI":"10.1109\/iccns58795.2023.10193141"},{"key":"848_CR15","doi-asserted-by":"publisher","DOI":"10.34117\/bjdv10n1-022","author":"S Polu","year":"2024","unstructured":"Polu S, Bapuji V, Supervisor R (2024) Mitigating ddos attacks in cloud computing using machine learning. Braz J Devel. https:\/\/doi.org\/10.34117\/bjdv10n1-022","journal-title":"Braz J Devel"},{"key":"848_CR16","doi-asserted-by":"publisher","DOI":"10.54216\/fpa.170207","author":"M Mohd","year":"2024","unstructured":"Mohd M, Ab MF, Azmi ZRBM, Firdaus A, Nuhu AH, Hussain SS (2024) Machine learning and deep learning approaches for detecting ddos attacks in cloud. Future Predictive Analytics. https:\/\/doi.org\/10.54216\/fpa.170207","journal-title":"Future Predictive Analytics"},{"key":"848_CR17","doi-asserted-by":"publisher","unstructured":"Sathvika C, Satwika V, Sruthi Y, Geethika M, Bulla S, Swathi K (2023) Ddos attack detection on cloud computing services using algorithms of machine learning: survey. In 2023 7th International Conference on Computing Methodologies and Communication (ICCMC), pp 1094\u20131100. https:\/\/doi.org\/10.1109\/ICCMC56507.2023.10083549","DOI":"10.1109\/ICCMC56507.2023.10083549"},{"key":"848_CR18","doi-asserted-by":"publisher","unstructured":"Arunkumar R, Navanitha S, Padmavathi B, Snekaa V (2024) Hybrid svm approach for enhanced ddos attack detection using machine learning in cloud environment. In 2024 2nd International Conference on Artificial Intelligence and Machine Learning Applications Theme: Healthcare and Internet of Things (AIMLA), pp 1\u20134. https:\/\/doi.org\/10.1109\/AIMLA59606.2024.10531330","DOI":"10.1109\/AIMLA59606.2024.10531330"},{"key":"848_CR19","doi-asserted-by":"publisher","unstructured":"Reddy SPK, Nagavelli U, Kiran YS, Kondoju CS, Bushmoni S, Yashaswi A (2024) Deep learning for zero-day threat detection and mitigation. In 2024 International Conference on IoT Based Control Networks and Intelligent Systems (ICICNIS), pp 1362\u20131368. https:\/\/doi.org\/10.1109\/ICICNIS64247.2024.10823270","DOI":"10.1109\/ICICNIS64247.2024.10823270"},{"key":"848_CR20","unstructured":"Benjamin M (2025) Real-time threat intelligence feeds and machine learning fusion: proactive security in dynamic network environments"},{"key":"848_CR21","doi-asserted-by":"publisher","first-page":"103200","DOI":"10.1016\/j.cose.2023.103200","volume":"129","author":"T Freitas","year":"2023","unstructured":"Freitas T, Soares J, Correia ME, Martins R (2023) Deterministic or probabilistic? \u2013 a survey on byzantine fault tolerant state machine replication. Comput Secur 129:103200. https:\/\/doi.org\/10.1016\/j.cose.2023.103200","journal-title":"Comput Secur"},{"key":"848_CR22","unstructured":"Castro M, Liskov B (1999) Practical byzantine fault tolerance. In Proceedings of the Third Symposium on Operating Systems Design and Implementation. OSDI\u201999, USENIX Association, USA, 173\u2013186"},{"key":"848_CR23","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3583633","author":"X Liu","year":"2025","unstructured":"Liu X, Zhang Z, Li Z, Lu X, Li M, Xu L, Ao M, Zhu L (2025) Group bft: two-round bft protocols via replica grouping. IEEE Trans Dependable Secure Comput. https:\/\/doi.org\/10.1109\/TDSC.2025.3583633","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"848_CR24","doi-asserted-by":"publisher","unstructured":"Sumukh S, Sandhya S (2024) Ddos detection using ml and deep learning approaches. In CSITSS 2024. https:\/\/doi.org\/10.1109\/csitss64042.2024.10817014","DOI":"10.1109\/csitss64042.2024.10817014"},{"key":"848_CR25","doi-asserted-by":"publisher","unstructured":"Subrmanian K, Thangarasu G, Yanyan Z, Kannan KN (2024) Enhancing detection and prediction of ddos attacks through regression modeling. In 2024 IEEE 6th Symposium on Computers & Informatics (ISCI), pp 253\u2013257. https:\/\/doi.org\/10.1109\/ISCI62787.2024.10668039","DOI":"10.1109\/ISCI62787.2024.10668039"},{"key":"848_CR26","doi-asserted-by":"publisher","unstructured":"Makkawi AM, Yousif A (2021) Machine learning for cloud ddos attack detection: a systematic review. In 2020 International Conference on Computer, Control, Electrical, and Electronics Engineering (ICCCEEE), pp 1\u20139. https:\/\/doi.org\/10.1109\/ICCCEEE49695.2021.9429678","DOI":"10.1109\/ICCCEEE49695.2021.9429678"},{"key":"848_CR27","doi-asserted-by":"publisher","unstructured":"Mishra A, Gupta BB, Perakovi\u0107 D, Pe\u00f1alvo FJG, Hsu C-H (2021) Classification based machine learning for detection of ddos attack in cloud computing. In 2021 IEEE International Conference on Consumer Electronics (ICCE), pp 1\u20134. https:\/\/doi.org\/10.1109\/ICCE50685.2021.9427665","DOI":"10.1109\/ICCE50685.2021.9427665"},{"issue":"7","key":"848_CR28","doi-asserted-by":"publisher","first-page":"1469","DOI":"10.1080\/01969722.2022.2157603","volume":"55","author":"AAS Aliar","year":"2023","unstructured":"Aliar AAS, Agoramoorthy M, Justindhas Y (2023) An automated detection of ddos attack in cloud using optimized weighted fused features and hybrid dbn-gru architecture. Cybern Syst 55(7):1469\u20131510. https:\/\/doi.org\/10.1080\/01969722.2022.2157603","journal-title":"Cybern Syst"},{"key":"848_CR29","doi-asserted-by":"publisher","unstructured":"Manimaran A, GnanaJeyaraman R, J Carmel Mary Belinda M, M S, Kannan E, Sivaram M (2024) An adaptive framework for low-rate ddos detection in cloud environments using decision tree machine learning algorithm. In 2024 IEEE International Conference on Blockchain and Distributed Systems Security (ICBDS), pp 1\u20135. https:\/\/doi.org\/10.1109\/ICBDS61829.2024.10837242","DOI":"10.1109\/ICBDS61829.2024.10837242"},{"key":"848_CR30","doi-asserted-by":"publisher","DOI":"10.3390\/s24051418","author":"I AlSaleh","year":"2024","unstructured":"AlSaleh I, Al-Samawi A, Nissirat L (2024) Novel machine learning approach for ddos cloud detection: Bayesian-based cnn and data fusion enhancements. Sensors. https:\/\/doi.org\/10.3390\/s24051418","journal-title":"Sensors"},{"key":"848_CR31","doi-asserted-by":"publisher","DOI":"10.36676\/urr.v8.i4.1400","author":"SB Green","year":"2021","unstructured":"Green SB (2021) Advancements in cloud security: leveraging machine learning for threat detection. Univers Res Rep. https:\/\/doi.org\/10.36676\/urr.v8.i4.1400","journal-title":"Univers Res Rep"},{"key":"848_CR32","doi-asserted-by":"publisher","DOI":"10.1007\/S10922-020-09578-1","author":"JHGM Corr\u00eaa","year":"2021","unstructured":"Corr\u00eaa JHGM, Ciarelli PM, Ribeiro MRN, Silva Villa\u00e7a R (2021) Ml-based ddos detection and identification using native cloud telemetry macroscopic monitoring. J Network Syst Manag. https:\/\/doi.org\/10.1007\/S10922-020-09578-1","journal-title":"J Network Syst Manag"},{"key":"848_CR33","doi-asserted-by":"publisher","DOI":"10.48175\/ijarsct-18812","author":"DV Krishna","year":"2024","unstructured":"Krishna DV, Sneha E, Latha, Yadav B, Aswini J, Harshini K (2024) Securing the cloud: a machine learning approach for threat detection and mitigation. Int J Adv Res Sci Commun Technol (IJARSCT). https:\/\/doi.org\/10.48175\/ijarsct-18812","journal-title":"Int J Adv Res Sci Commun Technol (IJARSCT)"},{"key":"848_CR34","doi-asserted-by":"publisher","unstructured":"Chauhan S, Byahatti P, Patel SK (2024) Securing networks: leveraging machine learning for enhanced ddos detection. In 2024 First International Conference on Software, Systems and Information Technology (SSITCON), pp 1\u20138. https:\/\/doi.org\/10.1109\/SSITCON62437.2024.10796323","DOI":"10.1109\/SSITCON62437.2024.10796323"},{"issue":"1","key":"848_CR35","doi-asserted-by":"publisher","first-page":"5678","DOI":"10.1038\/s41598-024-84879-y","volume":"15","author":"S Abiramasundari","year":"2025","unstructured":"Abiramasundari S, Ramaswamy V (2025) Distributed denial-of-service (ddos) attack detection using supervised machine learning algorithms. Sci Rep 15(1):5678. https:\/\/doi.org\/10.1038\/s41598-024-84879-y","journal-title":"Sci Rep"},{"key":"848_CR36","doi-asserted-by":"publisher","unstructured":"Feng H, Lu Z, Mai T, Tang Q (2025) Faster hash-based multi-valued validated asynchronous byzantine agreement. In Proceedings of the 55th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp 303\u2013316. https:\/\/doi.org\/10.1109\/DSN64029.2025.00040","DOI":"10.1109\/DSN64029.2025.00040"},{"key":"848_CR37","doi-asserted-by":"publisher","unstructured":"Wu C, Qin H, Amiri MJ, Loo BT, Malkhi D, Marcus R (2025) Bftbrain: adaptive BFT consensus with reinforcement learning. In Proceedings of the 22nd USENIX Symposium on Networked Systems Design and Implementation (NSDI). https:\/\/doi.org\/10.48550\/arXiv.2408.06432","DOI":"10.48550\/arXiv.2408.06432"},{"issue":"12","key":"848_CR38","doi-asserted-by":"publisher","first-page":"2664","DOI":"10.1109\/TIFS.2025.3544034","volume":"20","author":"X Fu","year":"2025","unstructured":"Fu X, Li M, Zeng Q, Li T, Yang S, Guan Y, Liu C (2025) Hamster: a fast synchronous byzantine fault tolerant protocol. IEEE Trans Inf Forensics Secur 20(12):2664\u20132676. https:\/\/doi.org\/10.1109\/TIFS.2025.3544034","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"848_CR39","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1186\/s13677-024-00625-9","volume":"13","author":"AV Songa","year":"2024","unstructured":"Songa AV, Karri GR (2024) An integrated sdn framework for early detection of ddos attacks in cloud computing. J Cloud Comput 13:64. https:\/\/doi.org\/10.1186\/s13677-024-00625-9","journal-title":"J Cloud Comput"},{"key":"848_CR40","doi-asserted-by":"publisher","first-page":"5456","DOI":"10.1109\/TIFS.2023.3345012","volume":"18","author":"Y Li","year":"2023","unstructured":"Li Y, Zhang H, Xu K (2023) Model poisoning attack against federated learning with adaptive aggregation. IEEE Trans Inf Forensics Secur 18:5456\u20135468. https:\/\/doi.org\/10.1109\/TIFS.2023.3345012","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"848_CR41","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2025.110021","author":"X Wang","year":"2025","unstructured":"Wang X, Zhao Y, Chen L, Li J (2025) Fedllmguard: a federated large language model for anomaly detection in 5g networks. Comput Networks. https:\/\/doi.org\/10.1016\/j.comnet.2025.110021","journal-title":"Comput Networks"}],"container-title":["Journal of Cloud Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13677-026-00848-y","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-026-00848-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-026-00848-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T14:03:06Z","timestamp":1771509786000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s13677-026-00848-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,4]]},"references-count":41,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["848"],"URL":"https:\/\/doi.org\/10.1186\/s13677-026-00848-y","relation":{},"ISSN":["2192-113X"],"issn-type":[{"value":"2192-113X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,4]]},"assertion":[{"value":"9 September 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 January 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 February 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"22"}}