{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T18:55:45Z","timestamp":1784055345330,"version":"3.55.0"},"reference-count":39,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2024,8,12]],"date-time":"2024-08-12T00:00:00Z","timestamp":1723420800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JSAN"],"abstract":"<jats:p>Distributed Denial of Service (DDoS) attacks disrupt service availability, leading to significant financial setbacks for individuals and businesses. This paper introduces Eye-Net, a deep learning-based system optimized for DDoS attack detection that combines feature selection, balancing methods, Multilayer Perceptron (MLP), and quantization-aware training (QAT) techniques. An Analysis of Variance (ANOVA) algorithm is initially applied to the dataset to identify the most distinctive features. Subsequently, the Synthetic Minority Oversampling Technique (SMOTE) balances the dataset by augmenting samples for under-represented classes. Two distinct MLP models are developed: one for the binary classification of flow packets as regular or DDoS traffic and another for identifying six specific DDoS attack types. We store MLP model weights at 8-bit precision by incorporating the quantization-aware training technique. This adjustment slashes memory use by a factor of four and reduces computational cost similarly, making Eye-Net suitable for Internet of Things (IoT) devices. Both models are rigorously trained and assessed using the CICDDoS2019 dataset. Test results reveal that Eye-Net excels, surpassing contemporary DDoS detection techniques in accuracy, recall, precision, and F1 Score. The multiclass model achieves an impressive accuracy of 96.47% with an error rate of 8.78%, while the binary model showcases an outstanding 99.99% accuracy, maintaining a negligible error rate of 0.02%.<\/jats:p>","DOI":"10.3390\/jsan13040045","type":"journal-article","created":{"date-parts":[[2024,8,12]],"date-time":"2024-08-12T11:23:46Z","timestamp":1723461826000},"page":"45","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Eye-Net: A Low-Complexity Distributed Denial of Service Attack-Detection System Based on Multilayer Perceptron"],"prefix":"10.3390","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-5391-9022","authenticated-orcid":false,"given":"Ramzi","family":"Khantouchi","sequence":"first","affiliation":[{"name":"Computer Science and Applied Mathematics Laboratory, Chadli Bendjdid El Tarf University, El Tarf 36000, Algeria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8939-1727","authenticated-orcid":false,"given":"Ibtissem","family":"Gasmi","sequence":"additional","affiliation":[{"name":"Computer Science and Applied Mathematics Laboratory, Chadli Bendjdid El Tarf University, El Tarf 36000, Algeria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0632-3172","authenticated-orcid":false,"given":"Mohamed Amine","family":"Ferrag","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Guelma University, Guelma 24000, Algeria"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,8,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"116748","DOI":"10.1016\/j.eswa.2022.116748","article-title":"A novel approach for accurate detection of the DDoS attacks in SDN-based SCADA systems based on deep recurrent neural networks","volume":"197","author":"Polat","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"49794","DOI":"10.1109\/ACCESS.2022.3173319","article-title":"Detection and Characterization of DDoS Attacks Using Time-Based Features","volume":"10","author":"Halladay","year":"2022","journal-title":"IEEE Access"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1697","DOI":"10.1007\/s00500-014-1250-8","article-title":"A method of DDoS attack detection using HTTP packet pattern and rule engine in cloud computing environment","volume":"18","author":"Choi","year":"2014","journal-title":"Soft Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"109725","DOI":"10.1016\/j.comnet.2023.109725","article-title":"Real-time bot infection detection system using DNS fingerprinting and machine-learning","volume":"228","author":"Quezada","year":"2023","journal-title":"Comput. Netw."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"13039","DOI":"10.1007\/s00500-021-06608-1","article-title":"Deep learning approaches for detecting DDoS attacks: A systematic review","volume":"27","author":"Mittal","year":"2023","journal-title":"Soft Comput."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"5156","DOI":"10.1007\/s11227-018-2413-7","article-title":"NBC-MAIDS: Na\u00efve Bayesian classification technique in multi-agent system-enriched IDS for securing IoT against DDoS attacks","volume":"74","author":"Mehmood","year":"2018","journal-title":"J. Supercomput."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Khare, M., and Oak, R. (2020). Real-Time distributed denial-of-service (DDoS) attack detection using decision trees for server performance maintenance. Performance Management of Integrated Systems and Its Applications in Software Engineering, Springer. Available online: https:\/\/link.springer.com\/chapter\/10.1007\/978-981-13-8253-6_1.","DOI":"10.1007\/978-981-13-8253-6_1"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"310","DOI":"10.1016\/j.procs.2018.07.177","article-title":"Detection of DNS DDoS Attacks with Random Forest Algorithm on Spark","volume":"134","author":"Chen","year":"2018","journal-title":"Procedia Comput. Sci."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"103026","DOI":"10.1016\/j.adhoc.2022.103026","article-title":"RBF-SVM kernel-based model for detecting DDoS attacks in SDN integrated vehicular network","volume":"140","author":"Anyanwu","year":"2023","journal-title":"Ad Hoc Netw."},{"key":"ref_10","unstructured":"Zhang, L., Jiang, S.P., Shen, X., Gupta, B.B., and Tian, Z. (2021). PWG-IDS: An Intrusion Detection Model for Solving Class Imbalance in IIoT Networks Using Generative Adversarial Networks. arXiv."},{"key":"ref_11","first-page":"102419","article-title":"Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study","volume":"50","author":"Ferrag","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Chalapathy, R., and Chawla, S. (2019). Deep learning for anomaly detection: A survey. arXiv.","DOI":"10.1145\/3394486.3406704"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Elsayed, M.S., Le-Khac, N.A., Dev, S., and Jurcut, A.D. (September, January 31). Ddosnet: A deep-learning model for detecting network attacks. Proceedings of the 2020 IEEE 21st International Symposium on \u201cA World of Wireless, Mobile and Multimedia Networks\u201d (WoWMoM), Cork, Ireland.","DOI":"10.1109\/WoWMoM49955.2020.00072"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"102177","DOI":"10.1016\/j.adhoc.2020.102177","article-title":"IGAN-IDS: An imbalanced generative adversarial network towards intrusion detection system in ad-hoc networks","volume":"105","author":"Huang","year":"2020","journal-title":"Ad Hoc Netw."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"134","DOI":"10.1109\/TCSS.2021.3063538","article-title":"Intrusion Detection for Secure Social Internet of Things Based on Collaborative Edge Computing: A Generative Adversarial Network-Based Approach","volume":"9","author":"Nie","year":"2022","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"108495","DOI":"10.1109\/ACCESS.2021.3101650","article-title":"SDN-Based Architecture for Transport and Application Layer DDoS Attack Detection by Using Machine and Deep Learning","volume":"9","year":"2021","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"625","DOI":"10.19026\/rjaset.7.299","article-title":"A novel feature selection based on one-way anova f-test for e-mail spam classification","volume":"7","author":"Elssied","year":"2014","journal-title":"Res. J. Appl. Sci. Eng. Technol."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: Synthetic minority over-sampling technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"117500","DOI":"10.1016\/j.eswa.2022.117500","article-title":"Recognition of DDoS attacks on SD-VANET based on combination of hyperparameter optimization and feature selection","volume":"203","author":"Polat","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"103251","DOI":"10.1016\/j.cose.2023.103251","article-title":"Towards DDoS attack detection using deep learning approach","volume":"129","author":"Aktar","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"108655","DOI":"10.1016\/j.compeleceng.2023.108655","article-title":"Attack detection analysis in software-defined networks using various machine learning method","volume":"108","author":"Wang","year":"2023","journal-title":"Comput. Electr. Eng."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"175","DOI":"10.1016\/j.neunet.2022.12.011","article-title":"Proposed algorithm for smart grid DDoS detection based on deep learning","volume":"159","author":"Diaba","year":"2023","journal-title":"Neural Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"100825","DOI":"10.1016\/j.iot.2023.100825","article-title":"A big data analytics for DDOS attack detection using optimized ensemble framework in Internet of Things","volume":"23","author":"Ahmad","year":"2023","journal-title":"Internet Things"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"101645","DOI":"10.1016\/j.cose.2019.101645","article-title":"A dynamic MLP-based DDoS attack detection method using feature selection and feedback","volume":"88","author":"Wang","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"103160","DOI":"10.1016\/j.jnca.2021.103160","article-title":"A novel hybrid model for intrusion detection systems in SDNs based on CNN and a new regularization technique","volume":"191","author":"ElSayed","year":"2021","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Tonkal, \u00d6., Polat, H., Ba\u015faran, E., C\u00f6mert, Z., and Kocao\u011flu, R. (2021). Machine learning approach equipped with neighbourhood component analysis for DDoS attack detection in software-defined networking. Electronics, 10.","DOI":"10.3390\/electronics10111227"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kim, J., Kim, J., Kim, H., Shim, M., and Choi, E. (2020). CNN-based network intrusion detection against denial-of-service attacks. Electronics, 9.","DOI":"10.3390\/electronics9060916"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"104823","DOI":"10.1016\/j.micpro.2023.104823","article-title":"An intelligent DDoS attack detection tree-based model using Gini index feature selection method","volume":"98","author":"Bouke","year":"2023","journal-title":"Microprocess. Microsyst."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Patro, S., and Sahu, K.K. (2015). Normalization: A preprocessing stage. arXiv.","DOI":"10.17148\/IARJSET.2015.2305"},{"key":"ref_30","unstructured":"Loshchilov, I., and Hutter, F. (2017). Decoupled weight decay regularization. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Horowitz, M. (2014, January 9\u201313). 1.1 computing\u2019s energy problem (and what we can do about it). Proceedings of the 2014 IEEE International Solid-State Circuits Conference Digest of Technical Papers (ISSCC), San Francisco, CA, USA.","DOI":"10.1109\/ISSCC.2014.6757323"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2019, January 1\u20133). Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India.","DOI":"10.1109\/CCST.2019.8888419"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"114520","DOI":"10.1016\/j.eswa.2020.114520","article-title":"Detection of DDoS attacks with feed forward based deep neural network model","volume":"169","author":"Cil","year":"2021","journal-title":"Expert Syst. Appl."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"716","DOI":"10.37394\/23203.2020.15.72","article-title":"An enhanced deep autoencoder-based approach for DDoS attack detection","volume":"15","author":"Sindian","year":"2020","journal-title":"Wseas Trans. Syst. Control"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Shieh, C.S., Lin, W.W., Nguyen, T.T., Chen, C.H., Horng, M.F., and Miu, D. (2021). Detection of unknown ddos attacks with deep learning and gaussian mixture model. Appl. Sci., 11.","DOI":"10.3390\/app11115213"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"146810","DOI":"10.1109\/ACCESS.2021.3123791","article-title":"Ae-mlp: A hybrid deep learning approach for ddos detection and classification","volume":"9","author":"Wei","year":"2021","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"538","DOI":"10.3390\/network3040024","article-title":"Optimized MLP-CNN Model to Enhance Detecting DDoS Attacks in SDN Environment","volume":"3","author":"Setitra","year":"2023","journal-title":"Network"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Chartuni, A., and M\u00e1rquez, J. (2021). Multi-Classifier of DDoS Attacks in Computer Networks Built on Neural Networks. Appl. Sci., 11.","DOI":"10.3390\/app112210609"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Ferrag, M.A., Shu, L., Djallel, H., and Choo, K.K.R. (2021). Deep learning-based intrusion detection for distributed denial of service attack in Agriculture 4.0. Electronics, 10.","DOI":"10.3390\/electronics10111257"}],"container-title":["Journal of Sensor and Actuator Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2224-2708\/13\/4\/45\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:35:03Z","timestamp":1760110503000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2224-2708\/13\/4\/45"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,12]]},"references-count":39,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,8]]}},"alternative-id":["jsan13040045"],"URL":"https:\/\/doi.org\/10.3390\/jsan13040045","relation":{},"ISSN":["2224-2708"],"issn-type":[{"value":"2224-2708","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,12]]}}}