Enabling Real-Time, Explainable DDoS Mitigation via On-Premise Large Language Models and Flow Analysis

Henok Wondimu, Ali Alfatemi, Mohamed Rahouti, Abdellah Chehri, Paweł Weichbroth, Nasir Ghani · Procedia Computer Science · 2025

Distributed Denial of Service (DDoS) attacks continue to escalate in both frequency and sophistication, often overwhelming critical network infrastructures. While deep learning methods excel at recognizing malicious patterns, their lack of transparency undermines trust and hampers effective mitigation. This paper introduces a unified, on-premise pipeline that integrates an advanced flow based attack classifier with a local large language model (LLM) to deliver explainable, real-time DDoS defense. The proposed approach detects threats at the flow level, rapidly fags suspicious traffic, and then generates human-readable analyses and device specific countermeasures ranging from firewall rules to intrusion prevention system signatures all without transmitting data of-site. Through comprehensive testing on diverse, large scale network traces, we demonstrate that this framework not only achieves near-perfect detection accuracy but also considerably reduces operational costs and privacy risks associated with external cloud services. Furthermore, evaluators confirm the clarity and correctness of the automatically generated mitigation strategies, highlighting the system’s practicality in enterprise environments. Overall, our results validate on-premise, LLM-enhanced DDoS defense as a robust, transparent, and economical solution for safeguarding modern network ecosystems.

Read the paper · More papers on PaperTik