MODELING AN EVALUATION SYSTEM FOR DDoS ATTACK DETECTION TOOLS IN HEI’S WEB RESOURCES

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.026315

Abstract

This study addressed the need for a comprehensive approach to the assessment and selection of cybersecurity tools
for protecting web resources in higher education institutions (HEIs) against modern cyber threats, particularly distributed
denial-of-service (DDoS) attacks. This study examined contemporary threats to the information security of web resources
and justified the need for their timely identification, analysis and neutralisation in order to ensure the continuity of
information systems, particularly in HEIs. The academic literature review showed that traditional approaches to
monitoring and protecting information systems are inefficient in spite of modern multi-vector attacks, requiring a shift
towards integrated, adaptive and intelligent cybersecurity systems. Short-term but intense cyberattacks (e.g. DDoS
incidents), can significantly disrupt service availability in the absence of proper protection measures. Additionally, we
found that effective protection of web resources requires a thorough approach that ensures the confidentiality, integrity,
and availability of information, along with the ability to adapt to the changing conditions in cyber environment. A multilayered cybersecurity architecture and a hybrid DDoS detection framework were proposed. The proposed framework
combined signature-based, behavioural, and statistical methods to facilitate effective and modifiable threat detection
system. In order to support objective decision-making, a multi-criteria hierarchical evaluation model was designed. The
proposed evaluation model included nine criteria groups that were aimed at assessing technical performance, scalability,
adaptability, integration capability, automation, and cost-effectiveness. The proposed method enables an organised and
transparent comparison of DDoS detection tools on specific conditions of higher research institutions.
Keywords: cyber threats, SIEM systems, higher education institution web resources, DDoS attacks, cyber
resilience, attack detection, provision of educational services.

References
1. Kryvoruchko, О., Shestak, Y., Kulіnich, О., & Zavhorodnya, E. (2026). Intellectualization of information flow
management as a means of ensuring the cyber resilience of a higher education institution’s infrastructure. Management
of Development of Complex Systems, (65), 194–203. https://doi.org/10.32347/2412-9933.2026.65.194-203.
2. Kryvoruchko, О., Kulіnich, О., Shestak, Y., & Zavhorodnya, E. (2026). Conceptual approaches to creating a
sustainable information infrastructure for higher education institutions. In Science, Technology and Global Challenges
(p. 166–173). CPN Publishing Group. https://sci-conf.com.ua/wp-content/uploads/2026/01/SCIENCE-TECHNOLOGYAND-GLOBAL-CHALLENGES-11-13.01.26.pdf.
3. Kryvoruchko, O., Shestak, Y., Zavhorodnya, E., & Fesenko, A. (2025). Higher education cyber resilience:
Intelligent protection of educational, administrative and resource systems. Cyber Security and Data Protection 2025 (p.
117–131). https://ceur-ws.org/Vol-4042/paper9.pdf.
4. Sevastieiev, Y., Dovgan, М., & Limar, І. (2026). Analysis of the effectiveness of detecting attacks using Wazuh
SIEM. Informatics and Mathematical Methods in Simulation, 16(1), 85–95. https://doi.org/10.15276/imms.v16.no1.85.
5. Dudkin, V. (2024). Analiz zasobiv vyiavlennia ta poperedzhennia DDoS atak u kiberprostori [Analysis of
methods for detecting and preventing DDoS attacks in cyberspace]. In Free and Open-Source Software (с. 17–18). Simon
Kuznets Kharkiv National University of Economics. https://foss.kn-it.info/uploads/foss-2024-theses.pdf.
6. Kavetskyi, M., Sievierinov, O., Gvozdov, R., & Smirnov, A. (2024). Using machine learning to classify
DOS/DDoS attacks. Radiotekhnika, (217), 55–63. https://doi.org/10.30837/rt.2024.2.217.04.
7. Ryzhakov, M., & Ponochovnyi, P. (2025). Model of network function transformation with elements of DDoS
protection. Scientific Journal «Applied Problems of Computer Science, Security and Mathematics», (4), 14–32.
https://apcssm.vnu.edu.ua/index.php/Journalone/article/view/128.
8. Cherniashchuk, N., & Dudko, A. (2025). Phishing, DDoS attacks and other cyberattacks – how to protect
yourself. International Scientific-Practical Conference "Problems of Computer Sciences, Software Modeling and Security
of Digital Systems", 145–147. Retrieved from https://apcssm.vnu.edu.ua/index.php/conf/article/view/229.
9. Havrylov, M. (2024). Zakhyst informatsiinykh system pidpryiemstva vid kiberzahroz: pidkhody ta instrumenty
v umovakh tsyfrovoi transformatsii biznesu [Protection of enterprise information systems against cyber threats:
approaches and tools in the context of business digital transformation]. Transformatsiia biznesu dlia staloho maibutnoho:
doslidzhennia, tsyfrovizatsiia ta innovatsii: monograph, 287-305. PE Palianytsia V.A. [in Ukrainian].
https://elartu.tntu.edu.ua/bitstream/lib/46653/2/ColMon_2024_Havrylov_M-Protection_of_enterprise_287-305.pdf.
10. Shcherbyna, Y. V., Kazakova, N. F., Lohinova, N. I., & Bazarov, D. A. (2024). Modern approaches to
protection against distributed denial-of-service attacks. Modern Information Security, 58(2), 77–83. https://doi.org/10.
31673/2409-7292.2024.020009.
11. Derkach, M. V., Khomyshyn, V. G., & Hudzenko, V. O. (2023). Testing the security of a web resource using
tools for scanning and identifying vulnerabilities. Scientific news of Dahl university. https://doi.org/10.33216/2222-3428-
2023-25-1.
12. Savchenko, V., Haidur, H., & Lehominova, S. (2025). Prohnozuvannia povilnykh DDoS atak na osnovi
koreliatsiinoho analizu indyvidualnykh traiektorii trafiku [Predicting slow DDoS attacks based on correlation analysis of
individual traffic trajectories]. In Security of Modern Information & Communication Systems (SMI&CS-2025). Ivan
Franko National University of Lviv. https://smics.lnu.edu.ua/uk/prognozuvannya-povilnyh-ddos-atak-na-osnovikorelyaczijnogo-analizu-indyvidualnyh-trayektorij-trafiku/.

Downloads

Published

2026-06-25

Issue

Section

Articles