Early‐Stage
DDoS
Detection in
IPv6
Using Curriculum Training and Attention Mechanism‐Based
CNN
Ar
Enes Açıkgözoğlu ABSTRACT
With the widespread adoption of IPv6 network infrastructures, the early detection of Distributed Denial of Service (DDoS) attacks has become increasingly critical for network security. Particularly in low‐intensity attack scenarios, the fact that attack traffic is largely embedded within normal network traffic limits the effectiveness of traditional detection methods. This study proposes a deep learning‐based approach for early‐stage DDoS attack detection in IPv6 environments. In the proposed method, 100 × 256 traffic matrices obtained from raw IPv6 packets and created over sequential 100‐packet windows are used. These matrices are modeled using a Convolutional Neural Network (CNN) architecture enhanced with an attention mechanism (Convolutional Block Attention Module—CBAM). The training process was carried out using a curriculum learning strategy, in which the attack intensity was gradually reduced from 15% to 1%. The ablation analyses performed reveal that the effectiveness of the attention mechanism increases significantly when used in conjunction with the gradual learning strategy. Experimental results demonstrate that the proposed approach can detect low‐intensity IPv6 DDoS attacks with high accuracy and ROC‐AUC values. Furthermore, protocol‐based multi‐class analyses reveal that the model can meaningfully distinguish between TCP, UDP, and ICMP‐based attacks. Practically, the proposed approach offers a viable solution for early warning systems, network monitoring platforms, and automatic attack prevention mechanisms in IPv6‐based networks.