Comparative Analysis of AI-Driven and Rule-Based Approaches in Detecting DDoS Attacks in IoT Network
Sebastian Hansel, Jason Benedict Wijaya, Aditya Kurniawan, Chrisando Ryan Pardomuan Siahaan · 2025
IoT is considered as one of the fastest growing objects, with an estimation of having 29.42 billion connected devices by 2030. Considering the constrained resources available to devices in IoTs, these resources make devices very susceptible to cyber threats, specifically DDoS. Classic IDS, based on a set of predefined rules, may fall in handling the continuous evolution of characteristics found in the patterns of different attacks. AI-driven models such as CNNs and LSTMs demonstrate better detection performance. This paper evaluates the performance of four deep learning models: CNN, LSTM, BiLSTM, and DCNNBiLSTM to identify DDoS attack in IoT Network using Edge IIoT dataset in terms of accuracy, loss, F1 score, ROC-AUC, and inference. The result shows that DCNNBiLSTM performs better with accuracy of 99.999% than the rest although with a prolonged inference time relative to CNN. BiLSTM outperforms compared to LSTM for efficient classification on a wide range of DDoS attacks. We also assess Snort, an open-source rule-based IDS, which shows poor accuracy (49%) and F1-score (24.5%), resulting from the absence of dynamic rule updates. The high inference time of Snort(3156s) can be explained by the large number of static rules used. These findings show the trade off between precision and inference duration, indicating that although AI models are more precise, they pose difficulties for real-time applications. Future research must be devoted to model optimization and integration of AI with rule based systems.