{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T06:46:54Z","timestamp":1777704414209,"version":"3.51.4"},"reference-count":22,"publisher":"SAGE Publications","issue":"5","license":[{"start":{"date-parts":[[2020,8,6]],"date-time":"2020-08-06T00:00:00Z","timestamp":1596672000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"published-print":{"date-parts":[[2020,11,19]]},"abstract":"<jats:p>While internet technologies have been evolving day by day, threats against them have been increasing with the same pace. One of the most serious and commonly executed attack type is Distributed Denial of Service (DDoS) attacks. Despite there are many security mechanisms against this type of attack, there is still need for new solutions due to the occurred DDoS attacks worldwide. In this work, a DDoS attack detection approach based on fuzzy logic and entropy is proposed. Network is modelled as a graph and graph-based features are used for discriminating attack traffic from attack-free traffic. Fuzzy-c-means clustering is applied based on these features in order to show the tendencies of IP addresses or port numbers to be in a same cluster or not. Based on this uncertainty, attack and attack-free traffic are modelled. In detection phase, fuzzy membership function is used. This algorithm is tested on the real data collected from Bogazi\u00e7i University network.<\/jats:p>","DOI":"10.3233\/jifs-189099","type":"journal-article","created":{"date-parts":[[2020,8,11]],"date-time":"2020-08-11T14:01:54Z","timestamp":1597154514000},"page":"6315-6324","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":1,"title":["Graph-based fuzzy approach against DDoS attacks"],"prefix":"10.1177","volume":"39","author":[{"given":"\u00c7agatay","family":"Ates","sequence":"first","affiliation":[{"name":"Department of Electrical &amp; Electronics Engineering, Bogazi\u00e7i University, Istanbul, Turkey"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S\u00fcleyman","family":"\u00d6zdel","sequence":"additional","affiliation":[{"name":"Department of Electrical &amp; Electronics Engineering, Bogazi\u00e7i University, Istanbul, Turkey"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emin","family":"Anarim","sequence":"additional","affiliation":[{"name":"Department of Electrical &amp; Electronics Engineering, Bogazi\u00e7i University, Istanbul, Turkey"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2020,8,6]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.031413.00127"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/1216370.1216373"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.06.002"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.2298\/CSIS160905039P"},{"issue":"5","key":"e_1_3_1_6_2","first-page":"1274","article-title":"An improved intrusion detection based on neural network and fuzzy algorithm","volume":"9","author":"Liang H.","year":"2014","unstructured":"LiangH., An improved intrusion detection based on neural network and fuzzy algorithm, Journal of Networks 9(5) (2014), 1274.","journal-title":"Journal of Networks"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2012.09.010"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.3233\/JIFS-169007"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-014-0365-y"},{"key":"e_1_3_1_10_2","first-page":"361","article-title":"Grids-a graph based intrusion detection system for large networks, in","volume":"1","author":"Staniford-Chen S.","year":"1996","unstructured":"Staniford-ChenS., CheungS., CrawfordR., DilgerM., FrankJ., HoaglandJ., LevittK., WeeC., YipR. and ZerkleD., Grids-a graph based intrusion detection system for large networks, in, Proceedings of the 19th national information systems security conference 1 (1996), 361\u2013370, Baltimore.","journal-title":"Proceedings of the 19th national information systems security conference"},{"key":"e_1_3_1_11_2","doi-asserted-by":"crossref","unstructured":"DingQ. KatenkaN. BarfordP. KolaczykE. and CrovellaM. Intrusion as (anti) social communication: characterization and detection in Proceedings of the 18th ACM SIGKDD international conference on Knowledge discovery and data mining pp. 886\u2013894 ACM 2012.","DOI":"10.1145\/2339530.2339670"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2007.01.040"},{"key":"e_1_3_1_13_2","doi-asserted-by":"crossref","unstructured":"MingqiangZ. HuiH. and QianW. A graph-based clustering algorithm for anomaly intrusion detection in 2012 7th International Conference on Computer Science & Education (ICCSE) pp. 1311\u20131314 IEEE 2012.","DOI":"10.1109\/ICCSE.2012.6295306"},{"key":"e_1_3_1_14_2","doi-asserted-by":"crossref","unstructured":"Ate\u015f\u00c7. \u00d6zdelS. and Anar\u0131mE. Graph\u2013based anomaly detection using fuzzy clustering in International Conference on Intelligent and Fuzzy Systems pp. 338\u2013345 Springer 2019.","DOI":"10.1007\/978-3-030-23756-1_42"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-017-0074-7"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF02621888"},{"key":"e_1_3_1_17_2","doi-asserted-by":"crossref","unstructured":"DunnJ.C. A fuzzy relative of the isodata process and its use in detecting compact well-separated clusters 1973.","DOI":"10.1080\/01969727308546046"},{"key":"e_1_3_1_18_2","unstructured":"BezdekJ.C. Pattern recognition with fuzzy objective function algorithms. Springer Science & Business Media 2013."},{"key":"e_1_3_1_19_2","article-title":"Detection of ddos attacks against wireless sdn controllers based on the fuzzy synthetic evaluation decision-making model","volume":"33","author":"Yan Q.","year":"2016","unstructured":"YanQ., GongQ. and DengF.-A., Detection of ddos attacks against wireless sdn controllers based on the fuzzy synthetic evaluation decision-making model, Adhoc & Sensor Wireless Networks, vol 33, 2016.","journal-title":"Adhoc & Sensor Wireless Networks"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","unstructured":"Bo\u0103azi\u00e7i university ddos dataset http:\/\/dx.doi.org\/10.21227\/45m9-9p82 2019.","DOI":"10.21227\/45m9-9p82"},{"key":"e_1_3_1_21_2","first-page":"226","article-title":"A densitybased algorithm for discovering clusters in large spatial databases with noise, in","volume":"96","author":"Ester M.","year":"1996","unstructured":"EsterM., KriegelH.-P., SanderJ., XuX., et al., A densitybased algorithm for discovering clusters in large spatial databases with noise, in, Kdd 96 (1996), 226\u2013231.","journal-title":"Kdd"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(02)00060-2"},{"key":"e_1_3_1_23_2","doi-asserted-by":"crossref","unstructured":"PramanaM.I.W. PurwantoY. and SuratmanF.Y. Ddos detection using modified k-means clustering with chain initialization over landmark window in 2015 International Conference on Control Electronics Renewable Energy and Communications (ICCEREC) pp. 7\u201311 IEEE 2015.","DOI":"10.1109\/ICCEREC.2015.7337056"}],"container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JIFS-189099","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JIFS-189099","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JIFS-189099","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:41:09Z","timestamp":1777455669000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JIFS-189099"}},"subtitle":[],"editor":[{"given":"Cengiz","family":"Kahraman","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2020,8,6]]},"references-count":22,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2020,11,19]]}},"alternative-id":["10.3233\/JIFS-189099"],"URL":"https:\/\/doi.org\/10.3233\/jifs-189099","relation":{},"ISSN":["1064-1246","1875-8967"],"issn-type":[{"value":"1064-1246","type":"print"},{"value":"1875-8967","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,6]]}}}