{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T02:13:50Z","timestamp":1778120030985,"version":"3.51.4"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T00:00:00Z","timestamp":1778112000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T00:00:00Z","timestamp":1778112000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Distributed Denial of Service attacks (DDoS) are a common and influential network malicious behavior. The timely and accurate detection of Distributed Denial-of-Service (DDoS) attacks constitutes a critically significant research imperative in cyber security. Most current research focuses on classification based on statistical characteristics of network traffic, but less considers the significance of packet payload feature for DDoS attack identification. This paper proposes an adaptive DDoS detection framework integrating machine learning with payload feature engineering. The methodology comprises three phases: 1) constructing a heterogeneous task classification system based on packet metadata analysis, 2) establishing a hierarchical keyword lexicon through payload decomposition and feature pattern mining, followed by feature vector transformation via numerical encoding, and 3) implementing supervised learning algorithms for discriminative model training and feature validity verification. This multilevel feature engineering approach demonstrates enhanced adaptability in DDoS attack pattern recognition compared to conventional detection paradigms. Test results on the public datasets CIC-DDoS-2019, ISCX-SlowDoS-2016 and DoS\/DDoS-MQTT-IoT show that the average detection rate of the method in this paper reaches 98.9% for attack behaviors, and the false alarm rate is only 0.1%.<\/jats:p>","DOI":"10.1186\/s42400-025-00495-x","type":"journal-article","created":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T02:02:08Z","timestamp":1778119328000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Adaptive DDoS attack detection via packet payload feature selection"],"prefix":"10.1186","volume":"9","author":[{"given":"Fengjun","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yong","family":"Cui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9631-5363","authenticated-orcid":false,"given":"Guangcan","family":"Cui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lisheng","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qinghua","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kai","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yunhai","family":"Lan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,7]]},"reference":[{"key":"495_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103108","volume":"187","author":"N Ahuja","year":"2021","unstructured":"Ahuja N, Singal G, Mukhopadhyay D et al (2021) Automated DDoS attack detection in software defined networking. J Netw Comput Appl 187:103108","journal-title":"J Netw Comput Appl"},{"key":"495_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109809","volume":"231","author":"A Alatram","year":"2023","unstructured":"Alatram A, Sikos LF, Johnstone M et al (2023) DoS\/DDoS-MQTT-IoT: a dataset for evaluating intrusions in IoT networks using the MQTT protocol. Comput Netw 231:109809. https:\/\/doi.org\/10.1016\/j.comnet.2023.109809","journal-title":"Comput Netw"},{"key":"495_CR3","volume":"66","author":"M Anagnostopoulos","year":"2022","unstructured":"Anagnostopoulos M, Lagos S, Kambourakis G (2022) Large-scale empirical evaluation of DNS and SSDP amplification attacks. J Inf Secur Appl 66:103168","journal-title":"J Inf Secur Appl"},{"key":"495_CR4","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2023.106432","volume":"123","author":"J Bhayo","year":"2023","unstructured":"Bhayo J, Shah SA, Hameed S et al (2023) Towards a machine learning-based framework for DDoS attack detection in software-defined IoT (SD-IoT) networks. Eng Appl Artif Intell 123:106432","journal-title":"Eng Appl Artif Intell"},{"key":"495_CR5","doi-asserted-by":"publisher","first-page":"5039","DOI":"10.1109\/ACCESS.2019.2963077","volume":"8","author":"S Dong","year":"2020","unstructured":"Dong S, Sarem M (2020) DDoS attack detection method based on improved KNN with the degree of DDoS attack in software-defined networks. IEEE Access 8:5039\u20135048. https:\/\/doi.org\/10.1109\/ACCESS.2019.2963077","journal-title":"IEEE Access"},{"issue":"12","key":"495_CR6","doi-asserted-by":"publisher","first-page":"2556","DOI":"10.3390\/sym14122556","volume":"14","author":"OE Elejla","year":"2022","unstructured":"Elejla OE, Anbar M, Hamouda S et al (2022) Flow-based IDS features enrichment for ICMPv6-DDoS attacks detection. Symmetry 14(12):2556. https:\/\/doi.org\/10.3390\/sym14122556","journal-title":"Symmetry"},{"issue":"1","key":"495_CR7","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1109\/TNET.2021.3115517","volume":"30","author":"X Feng","year":"2022","unstructured":"Feng X, Li Q, Sun K et al (2022) Off-path TCP hijacking attacks via the side channel of downgraded IPID. IEEE\/ACM Trans Netw 30(1):409\u2013422. https:\/\/doi.org\/10.1109\/TNET.2021.3115517","journal-title":"IEEE\/ACM Trans Netw"},{"issue":"12","key":"495_CR8","doi-asserted-by":"publisher","first-page":"11407","DOI":"10.1002\/int.23048","volume":"37","author":"A Gaurav","year":"2022","unstructured":"Gaurav A, Gupta BB, Alhalabi W et al (2022) A comprehensive survey on DDoS attacks on various intelligent systems and it\u2019s defense techniques. Int J Intell Syst 37(12):11407\u201311431. https:\/\/doi.org\/10.1002\/int.23048","journal-title":"Int J Intell Syst"},{"issue":"1","key":"495_CR9","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/s10922-022-09704-1","volume":"31","author":"DSM Gon\u00e7alves","year":"2022","unstructured":"Gon\u00e7alves DSM, Couto RS, Rubinstein MG (2022) A protection system against HTTP flood attacks using software defined networking. J Netw Syst Manage 31(1):16. https:\/\/doi.org\/10.1007\/s10922-022-09704-1","journal-title":"J Netw Syst Manage"},{"key":"495_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107168","volume":"173","author":"S Hosseini","year":"2020","unstructured":"Hosseini S, Zade BMH (2020) New hybrid method for attack detection using combination of evolutionary algorithms, SVM, and ANN. Comput Netw 173:107168","journal-title":"Comput Netw"},{"key":"495_CR11","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103778","volume":"140","author":"S Javanmardi","year":"2024","unstructured":"Javanmardi S, Ghahramani M, Shojafar M et al (2024) M-RL: a mobility and impersonation-aware IDS for DDoS UDP flooding attacks in IoT-Fog networks. Comput Secur 140:103778","journal-title":"Comput Secur"},{"key":"495_CR12","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/j.comnet.2017.03.018","volume":"121","author":"HH Jazi","year":"2017","unstructured":"Jazi HH, Gonzalez H, Stakhanova N et al (2017) Detecting HTTP-based application layer DoS attacks on web servers in the presence of sampling. Comput Netw 121:25\u201336. https:\/\/doi.org\/10.1016\/j.comnet.2017.03.018","journal-title":"Comput Netw"},{"key":"495_CR13","doi-asserted-by":"publisher","unstructured":"Kang MS, Lee SB, Gligor VD (2013) The crossfire attack. In: 2013 IEEE Symposium on Security and Privacy, pp 127\u2013141, https:\/\/doi.org\/10.1109\/SP.2013.19","DOI":"10.1109\/SP.2013.19"},{"issue":"1","key":"495_CR14","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1007\/s12652-021-02907-5","volume":"13","author":"D Kshirsagar","year":"2022","unstructured":"Kshirsagar D, Kumar S (2022) A feature reduction based reflected and exploited DDoS attacks detection system. J Ambient Intell Humaniz Comput 13(1):393\u2013405. https:\/\/doi.org\/10.1007\/s12652-021-02907-5","journal-title":"J Ambient Intell Humaniz Comput"},{"issue":"10","key":"495_CR15","doi-asserted-by":"publisher","first-page":"2400084","DOI":"10.1002\/qute.202400084","volume":"7","author":"MY K\u00fc\u00e7\u00fckkara","year":"2024","unstructured":"K\u00fc\u00e7\u00fckkara MY, Atban F, Bay\u0131lm\u0131\u015f C (2024) Quantum-neural network model for platform independent ddos attack classification in cyber security. Adv Quantum Technol 7(10):2400084. https:\/\/doi.org\/10.1002\/qute.202400084","journal-title":"Adv Quantum Technol"},{"issue":"8","key":"495_CR16","doi-asserted-by":"publisher","first-page":"9180","DOI":"10.1007\/s11227-022-05025-x","volume":"79","author":"J Li","year":"2023","unstructured":"Li J, Zhang H, Liu Z et al (2023) Network intrusion detection via tri-broad learning system based on spatial-temporal granularity. J Supercomput 79(8):9180\u20139205. https:\/\/doi.org\/10.1007\/s11227-022-05025-x","journal-title":"J Supercomput"},{"issue":"4","key":"495_CR17","doi-asserted-by":"publisher","first-page":"5317","DOI":"10.1109\/TVT.2022.3233880","volume":"72","author":"Z Li","year":"2023","unstructured":"Li Z, Kong Y, Jiang C (2023) A transfer double deep Q network based DDoS detection method for internet of vehicles. IEEE Trans Veh Technol 72(4):5317\u20135331. https:\/\/doi.org\/10.1109\/TVT.2022.3233880","journal-title":"IEEE Trans Veh Technol"},{"key":"495_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102315","volume":"107","author":"D Nashat","year":"2021","unstructured":"Nashat D, Hussain FA (2021) Multifractal detrended fluctuation analysis based detection for SYN flooding attack. Comput Secur 107:102315","journal-title":"Comput Secur"},{"issue":"5","key":"495_CR19","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MCOM.2019.1800819","volume":"57","author":"S Rezaei","year":"2019","unstructured":"Rezaei S, Liu X (2019) Deep learning for encrypted traffic classification: an overview. IEEE Commun Mag 57(5):76\u201381. https:\/\/doi.org\/10.1109\/MCOM.2019.1800819","journal-title":"IEEE Commun Mag"},{"key":"495_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2023.100976","volume":"24","author":"MF Saiyed","year":"2023","unstructured":"Saiyed MF, Al-Anbagi I (2023) Flow and unified information-based DDOS attack detection system for multi-topology IoT networks. Internet Things 24:100976. https:\/\/doi.org\/10.1016\/j.iot.2023.100976","journal-title":"Internet Things"},{"key":"495_CR21","doi-asserted-by":"publisher","unstructured":"Sharafaldin I, Lashkari AH, Hakak S, et\u00a0al (2019) Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy. In: 2019 International Carnahan Conference on Security Technology (ICCST), pp 1\u20138, https:\/\/doi.org\/10.1109\/CCST.2019.8888419","DOI":"10.1109\/CCST.2019.8888419"},{"key":"495_CR22","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1007\/978-3-642-04444-1_3","volume-title":"Computer security - ESORICS 2009","author":"A Studer","year":"2009","unstructured":"Studer A, Perrig A (2009) The coremelt attack. In: Backes M, Ning P (eds) Computer security - ESORICS 2009. Springer Berlin Heidelberg, Berlin, Heidelberg, pp 37\u201352"},{"key":"495_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104526","volume":"157","author":"M Swain","year":"2025","unstructured":"Swain M, Tripathi N, Sethi K (2025) Identifying communication sequence anomalies to detect dos attacks against MQTT. Comput Secur 157:104526. https:\/\/doi.org\/10.1016\/j.cose.2025.104526","journal-title":"Comput Secur"},{"key":"495_CR24","doi-asserted-by":"publisher","first-page":"1581054","DOI":"10.1155\/2022\/1581054","volume":"1","author":"X Wang","year":"2022","unstructured":"Wang X, Xie X (2022) Research on NTP nonlinear reflection attack identification based on AHP multidimensional matrix in global COVID-19 endvironment. Wirel Commun Mob Comput 1:1581054. https:\/\/doi.org\/10.1155\/2022\/1581054","journal-title":"Wirel Commun Mob Comput"},{"key":"495_CR25","doi-asserted-by":"publisher","unstructured":"Yang G, Hosseini H, Sahabandu D, et\u00a0al (2018) Modeling and mitigating the coremelt attack. In: 2018 Annual American Control Conference (ACC), pp 3410\u20133416, https:\/\/doi.org\/10.23919\/ACC.2018.8431752","DOI":"10.23919\/ACC.2018.8431752"},{"issue":"1","key":"495_CR26","doi-asserted-by":"publisher","first-page":"5111","DOI":"10.1038\/s41598-024-55814-y","volume":"14","author":"X Yin","year":"2024","unstructured":"Yin X, Fang W, Liu Z et al (2024) A novel multi-scale cnn and bi-lstm arbitration dense network model for low-rate DDOS attack detection. Sci Rep 14(1):5111. https:\/\/doi.org\/10.1038\/s41598-024-55814-y","journal-title":"Sci Rep"},{"key":"495_CR27","doi-asserted-by":"publisher","unstructured":"Zheng Z, Wang H, Yu C (2020) Two algorithms to solve longest circular common subsequence problems. Appl Res Comput. https:\/\/doi.org\/10.19734\/j.issn.1001-3695.2019.06.0258","DOI":"10.19734\/j.issn.1001-3695.2019.06.0258"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00495-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00495-x","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00495-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T02:02:11Z","timestamp":1778119331000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00495-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,7]]},"references-count":27,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["495"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00495-x","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,7]]},"assertion":[{"value":"27 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"65"}}