Optimized Hybrid IDS Using HBA, LightGBM, and LSTM for DDoS Attack Detection

Rudragouda G. Hiregoudar S.V. Saboji

Журнал: International Journal of Computer Network and Information Security @ijcnis

Статья в выпуске: 5 vol.18, 2026 года.

Бесплатный доступ

The rapid growth of digital networks has made online platforms more vulnerable to Distributed Denial of Service (DDoS) attacks. These attacks can cause serious service interruptions and performance degradation. Traditional Intrusion Detection Systems (IDSs) often struggle with poor detection accuracy, frequent false alerts, and delays in recognizing ongoing attacks. This study proposes an improved hybrid IDS that uses the Honey Badger Algorithm (HBA) to choose essential traffic features, Light Gradient Boosting Machine (LightGBM) for accurate and fast classification, and Long Short-Term Memory (LSTM) networks to analyze time-based traffic patterns. The system was tested with the CICDDoS2019 dataset using 10-fold cross-validation. To ensure generalization and robustness, the proposed IDS was further validated on the NSL-KDD dataset. Comparative analysis demonstrates superior detection accuracy, faster convergence, and reduced false positive rates compared to traditional and recent hybrid IDS models. The study emphasizes novelty, includes multiple dataset evaluations, and presents ablation testing to demonstrate reliability. Results show that the model achieves more than 98% detection accuracy with a low false positive rate and quick processing time. Hence the proposed IDS provides a scalable and real-time-capable framework for modern DDoS detection across diverse network environments.

Hybrid Intrusion Detection System \ Honey Badger Algorithm \ Light Gradient Boosting Machine \ Long Short-Term Memory \ DDoS Attack Detection \ Feature Selection \ Network Security

Короткий адрес: https://sciup.org/15020697

IDS: 15020697   |   DOI: 10.5815/ijcnis.2026.05.01