Detecting application layer DDoS attack using an advanced signature detection algorithm

A Abdul Ghafar Jaafar M Md Asri Ngadi N Nazri Kama N Nazhatul Hafizah Kamarudin K Khairol Shapawi

Abstract

Abstract Application-layer Distributed Denial of Service (App-DDoS) attacks are an ongoing issue in the cyber security world. The attack constructs request headers and uses a large number of channels to disrupt targeted services, such as an automated attack tool. A variety of approaches have been attempted, but the detection of attacks through the identification of forged request headers is a significant gap in the research. Signature detection, which shows a strong ability to accurately identify attacks with low false positive and false negative rates, can be used to address this challenge. The paper introduces a new detection method to categorize traffic as malicious or legitimate by analyzing the request headers of the traffic. To address the concerns of various researchers regarding outdated attack patterns and the lack of datasets available for public research, the dataset used in this research is recent and representative of real-world App DDoS attack patterns. The signature detection demonstrates promising performance in detecting the attack with the latest data set, which has strong implications for adaptation to real-world applications. The key contributions of this study are the proposed detection algorithms that can detect forged request headers at the initial stage, prior to their processing by the web server, and the practical analysis, which showed that the attack strategy approach relies on the manipulation of request headers. The hybrid feature selection method employed in this research was proven to be workable and successfully identified the features which contribute significantly to the detection performance with an accuracy of 96.93%, a precision of 99.11%, a recall of 97.55%, and an F1-score of 98.32%. These results demonstrate that the signature-based detection is effective and appropriate for detecting the attack. Although Machine Learning (ML) is gaining traction, signature-based detection can still be effective for checking signatories generated by the attack in the request headers.

Article Details

Volume / Issue Vol. 1, Issue 1
Published June 11, 2026
ISSN 2045-2322
Publisher Nature Portfolio

Journal Info

Scientific Reports

Nature Portfolio

ISSN: 2045-2322 Open Access Life Sciences

Authors (5)

A

Abdul Ghafar Jaafar

M

Md Asri Ngadi

N

Nazri Kama

N

Nazhatul Hafizah Kamarudin

K

Khairol Shapawi