Optimized Hybrid IDS Using HBA, LightGBM, and LSTM for DDoS Attack Detection

PDF (1253KB), PP.1-16

Views: 0 Downloads: 0

Author(s)

Rudragouda G. Hiregoudar 1,* S. V. Saboji 1

1. Department of Computer Science and Engineering, Basaveshwar Engineering College, Bagalkot, affiliated to Visvesvaraya Technological University, Belagavi – 590018, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijcnis.2026.05.01

Received: 16 Jul. 2025 / Revised: 12 Oct. 2025 / Accepted: 22 Jan. 2026 / Published: 8 Oct. 2026

Index Terms

Hybrid Intrusion Detection System, Honey Badger Algorithm, Light Gradient Boosting Machine, Long Short-Term Memory, DDoS Attack Detection, Feature Selection, Network Security.

Abstract

The rapid growth of digital networks has made online platforms more vulnerable to Distributed Denial of Service (DDoS) attacks. These attacks can cause serious service interruptions and performance degradation. Traditional Intrusion Detection Systems (IDSs) often struggle with poor detection accuracy, frequent false alerts, and delays in recognizing ongoing attacks. This study proposes an improved hybrid IDS that uses the Honey Badger Algorithm (HBA) to choose essential traffic features, Light Gradient Boosting Machine (LightGBM) for accurate and fast classification, and Long Short-Term Memory (LSTM) networks to analyze time-based traffic patterns. The system was tested with the CICDDoS2019 dataset using 10-fold cross-validation. To ensure generalization and robustness, the proposed IDS was further validated on the NSL-KDD dataset. Comparative analysis demonstrates superior detection accuracy, faster convergence, and reduced false positive rates compared to traditional and recent hybrid IDS models. The study emphasizes novelty, includes multiple dataset evaluations, and presents ablation testing to demonstrate reliability. Results show that the model achieves more than 98% detection accuracy with a low false positive rate and quick processing time. Hence the proposed IDS provides a scalable and real-time-capable framework for modern DDoS detection across diverse network environments.

Cite This Paper

Rudragouda G. Hiregoudar, S. V. Saboji, "Optimized Hybrid IDS Using HBA, LightGBM, and LSTM for DDoS Attack Detection", International Journal of Computer Network and Information Security(IJCNIS), Vol.18, No.5, pp. 1-16, 2026. DOI:10.5815/ijcnis.2026.05.01 

Reference

[1]A. K. B. Arnob, M. F. Mridha, M. Safran, and others, “An Enhanced LSTM Approach for Detecting IoT-Based DDoS Attacks Using Honeypot Data,” International Journal of Computer Intelligence Systems, vol. 18, no. 1, pp. 19, 2025. doi:10.1007/s44196-025-00741-7
[2]A. Sharma, S. S. Suhas Vaddhiparthy, S. Usha Goparaju, D. Gangadharan, and H. Kandath, “Attention Meets UAVs: A Comprehensive Evaluation of DDoS Detection in Low-Cost UAVs,” in Proc. 2024 IEEE 20th Int. Conf. Automation Science and Engineering (CASE), Bari, Italy, 2024, pp. 3748–3753. doi:10.1109/CASE59546.2024.10711508
[3]D. Alghazzawi, O. Bamasag, H. Ullah, and M. Z. Asghar, “Efficient Detection of DDoS Attacks Using a Hybrid Deep Learning Model with Improved Feature Selection,” Applied Sciences, vol. 11, no. 24, 11634, Dec. 2021, doi:10.3390/app112411634 .
[4]Y. Wei, J. Jang-Jaccard, F. Sabrina, W. Xu, S. Camtepe, and A. Dunmore, “Reconstruction-based LSTMAutoencoder for Anomaly-based DDoS Attack Detection over Multivariate Time-Series Data,” arXiv preprint arXiv:2305.09475, Apr. 2023. doi:10.48550/arXiv.2305.09475 .
[5]Y.-M. Yang, K.-C. Chang, and J.-N. Luo, “Hybrid neural network-based IDS: Leveraging LightGBM and MobileNetV2 for IoT security,” Symmetry, vol. 17, no. 314, Feb. 2025. doi:10.3390/sym17030314
[6]R. Devendiran and A. V. Turukmane, “Dugat-LSTM: Deep learning based network intrusion detection system using chaotic optimization strategy,” Expert Syst. Appl., vol. 245, art. 123027, 2024. doi:10.1016/j.eswa.2023.123027
[7]O. Pandithurai, C. Venkataiah, S. Tiwari, and N. Ramanjaneyulu, “DDoS attack prediction using a honey badger optimization algorithm-based feature selection and Bi-LSTM in cloud environment,” Expert Syst. Appl., vol.241, art.122544, 2024. doi:10.1016/j.eswa.2023.122544 .
[8]S. Kanthimathi, S. Venkatraman, K. S. Jayasankar, T. Pranay Jiljith, and R. Jashwanth, “A novel self-attentionenabled weighted ensemble-based convolutional neural network framework for distributed denial of service attack classification,” arXiv preprint arXiv:2409.00810, Sept. 2024. doi:10.48550/arXiv.2409.00810
[9]J. Zhao, Y. Liu, Q. Zhang, and X. Zheng, “CNN-AttBiLSTM Mechanism: A DDoS Attack Detection Method Based on Attention Mechanism and CNN-BiLSTM,” IEEE Access, vol. 11, pp. 136308–136317, Nov. 2023. doi:10.1109/ACCESS.2023.3334916
[10]G. Ke, Q. Meng, T. Finley, T. Wang, W. Chen, W. Ma, Q. Ye, and T.-Y. Liu, “LightGBM: A Highly Efficient Gradient Boosting Decision Tree,” in Proc. 31st Conf. Neural Information Processing Systems (NeurIPS 2017), Long Beach, CA, USA, 2017, pp. 3146–3154.
[11]M. Hariharan, H. K. Abhishek, and B. G. Prasad, “DDoS Attack Detection Using C5.0 Machine Learning Algo-rithm,” International Journal of Wireless and Microwave Technologies,vol. 9, no. 1, pp. 52–59, 2019. DOI: 10.5815/ijwmt.2019.01.06.
[12]Canadian Institute for Cybersecurity, “CICDDoS2019 Dataset,” 2024. [Online]. Available: https://www.unb. ca/cic/datasets/ddos-2019.html [Accessed: Jul. 12, 2025]
[13]R. Preethi, “Detection of Threats in Wireless Sensor Network Based on OPTICS Clustering With DE-BiLSTM Clas-sifier,” International Journal of Wireless and Microwave Technologies, vol. 14, no. 3, pp. 14–30, Jun. 2024. DOI: 10.5815/ijwmt.2024.03.02.
[14]I. Sharafaldin, A. H. Lashkari, A. A. Ghorbani,"Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization", IEEE Access, vol. 6, pp. 804-816, 2018. doi: 10.1109/ACCESS.2017.2785320
[15]S. A. Elsaid, E. Shehab, A. M. Mattar, A. T. Azar, and I. A. Hameed, “Hybrid intrusion detection models based on GWO optimized deep learning,” Discover Applied Sciences, vol. 6, no. 10, 2024. doi: 10.1007/s42452-024-06209-1
[16]F. A. Hashim, E. H. Houssein, K. Hussain, M. S. Mabrouk, and W. Al-Atabany, “Honey Badger Algorithm: New metaheuristic algorithm for solving optimization problems,” Mathematics and Computers in Simulation, vol. 192, pp. 84–110, 2022. doi:10.1016/j.matcom.2021.08.013
[17]J. Jeba Praba and R. Sridaran, “LCDT-M: Log-Cluster DDoS Tree Mitigation Framework Using SDN in the Cloud Environment,” Int. J. Comput. Netw. Inf. Secur., vol. 15, no. 2, pp. 15–29, Apr. 2023.
[18]M. Sokolova and G. Lapalme, “A Systematic Analysis of Performance Measures for Classification Tasks,” Inf. Process. Manag., vol. 45, no. 4, pp. 427–437, Jul. 2009.