Protocol-Aware and Adaptive DDoS Defense Framework

Jihye Kim, Gabi Dreo Rodosek · 2025

DDoS attacks continue to grow in both volume and complexity, increasingly exploiting protocol-layer vulnerabilities in core Internet protocols such as NTP, DNS, and HTTP/S. Traditional defense mechanisms, primarily based on static rules and signature-based filtering, have limited adaptability and struggle to handle rapidly evolving attack strategies. This research proposes a protocol-aware and adaptive DDoS defense framework where XDP/eBPF and LLMs serve as modular, complementary components that can be deployed individually or in combination, depending on the attack scenario and the specific characteristics of the target protocol. XDP/eBPF enables high-performance, lowlevel packet filtering directly at the NIC level, offering efficient, line-rate mitigation capabilities. Meanwhile, LLMs are fine-tuned on structured protocol interaction logs (e.g., query sequences, entropy shifts, and temporal patterns) to detect semantic-level anomalies beyond traditional detection thresholds. The proposed framework improves detection accuracy and supports dynamic, context-sensitive mitigation strategies, such as real-time traffic throttling and adaptive rule generation. This modular design allows the system to dynamically adapt to evolving threats in heterogeneous networks.

Read the paper · More papers on PaperTik