A Hybrid Machine Learning and Large Language Model Framework for Real-Time DDos Detection and Mitigation With Explainability

Distributed Denial of Service (DDoS) attacks remain a persistent threat to network infrastructure, particularly in cloud-native, IoT, and SDN environments. While traditional machine learning (ML) models offer fast and lightweight classification of anomalous traffic, they often lack transparency and actionable guidance for mitigation. In this research, we propose a novel hybrid architecture that combines the efficiency of traditional ML models (e.g., Random Forest) for real-time DDoS detection with the interpretability of Large Language Models (LLMs) for attack summarization and automated rule generation. The ML part identifies traffic using flow-level characteristics derived from the NetFlow and NSL-KDD data sets, whereas LLMs provide natural language explanations of detected risks and provide mitigation rules suited for fire-wall or SDN-Controllers. We test our approach on the NSL-KDD and CIC-DDoS2019 data-sets(Standard data-set for training and testing DDoS attacks), attaining 96.2% detection accuracy with Random Forest and showing that LLMs can generate consistent, humanaligned interpretations with over 91 % accuracy in rule development. This design strikes a compromise between detection speed and explanation, making it ideal for use in operational security situations. Our findings show that integrating conceptual ML detection and LLM-driven insights can considerably improve the reliability, interpretability, and reactivity of contemporary DDoS defensive solution.

Paper

Full text

PDF

A Hybrid Machine Learning and Large Language Model Framework for Real-Time DDos Detection and Mitigation With Explainability

Semantic Scholar · 2025

Abstract

Distributed Denial of Service (DDoS) attacks remain a persistent threat to network infrastructure, particularly in cloud-native, IoT, and SDN environments. While traditional machine learning (ML) models offer fast and lightweight classification of anomalous traffic, they often lack transparency and actionable guidance for mitigation. In this research, we propose a novel hybrid architecture that combines the efficiency of traditional ML models (e.g., Random Forest) for real-time DDoS detection with the interpretability of Large Language Models (LLMs) for attack summarization and automated rule generation. The ML part identifies traffic using flow-level characteristics derived from the NetFlow and NSL-KDD data sets, whereas LLMs provide natural language explanations of detected risks and provide mitigation rules suited for fire-wall or SDN-Controllers. We test our approach on the NSL-KDD and CIC-DDoS2019 data-sets(Standard data-set for training and testing DDoS attacks), attaining 96.2% detection accuracy with Random Forest and showing that LLMs can generate consistent, humanaligned interpretations with over 91 % accuracy in rule development. This design strikes a compromise between detection speed and explanation, making it ideal for use in operational security situations. Our findings show that integrating conceptual ML detection and LLM-driven insights can considerably improve the reliability, interpretability, and reactivity of contemporary DDoS defensive solution.

Similar papers

© 2026 NYSGPT2525 LLC