Examining the Robustness of Learning-Based DDoS Detection in Software Defined Networks

Examining the Robustness of Learning-Based DDoS Detection in Software Defined Networks
复制标题

DOI:
10.1109/dsc47296.2019.8937669
复制
发表时间:
2019-11
期刊:
2019 IEEE Conference on Dependable and Secure Computing (DSC)
影响因子:
--
通讯作者:
Ahmed A. Abusnaina;Aminollah Khormali;Daehun Nyang;M. Yuksel;Aziz Mohaisen
Ahmed A. Abusnaina;Aminollah Khormali;Daehun Nyang;M. Yuksel;Aziz Mohaisen
中科院分区:
其他
文献类型:
--
作者:
Ahmed A. Abusnaina;Aminollah Khormali;Daehun Nyang;M. Yuksel;Aziz Mohaisen

文献摘要

被引文献

相似文献

随着软件定义网络(SDN)的快速发展,提倡集中的网络视图,需要高效可靠的分布式拒绝服务防御来保护集中式SDN控制器。最近,一些研究利用基于深度学习(DL)的算法实现了这种防御。虽然基于dl的算法通常容易受到对抗性学习攻击,但这些攻击在多大程度上适用于SDN中的DDoS防御还没有得到检验。在这项工作中,我们探讨了SDN中基于dl的DDoS防御对对抗性学习攻击的鲁棒性。首先,我们研究了通用的现成对抗性攻击,以测试SDN中DDoS防御的稳健性,并证明虽然它们会导致错误分类,但这些攻击不会保留流的特征。因此,我们提出了针对现实对抗流的流合并,同时实现了高逃避率,包括目标和非目标错误分类攻击。所提出的Flow-Merge能够强制基于dl的DDoS防御将100%的良性流错误分类为恶意流,同时保留流的原始特征。使用最先进的防御手段,我们发现使用Flow-Merge生成的对抗流很难被检测到,当使用对抗训练时,检测率只有49.31%。
With the rapid development of Software-Defined Networking (SDN) advocating a centralized view of networks, efficient and reliable Distributed Denial of Service (DDoS) defenses are necessary to protect the centralized SDN controller. Recently, an amalgamation of work has realized such defenses using Deep Learning (DL) based algorithms. Although DL-based algorithms are generally prone to adversarial learning attacks, the extent to which those attacks are applicable to DDoS defenses in SDN is unexamined. In this work, we explore the robustness of DL-based DDoS defenses in SDN against adversarial learning attacks. First, we investigate generic off-the-shelf adversarial attacks to test the robustness of DDoS defenses in SDN, and demonstrate that while they lead to misclassification, these attacks do not preserve the characteristics of flows. As a result, we propose Flow-Merge for realistic adversarial flows while achieving a high evasion rate, with both targeted and untargeted misclassification attacks. The proposed Flow-Merge is able to force the DL-based DDoS defenses to misclassify 100% of benign flows as malicious, while preserving original characteristics of flows. Using state-of-the-art defenses, we show that the adversarial flows generated using Flow-Merge are difficult to detect, with only 49.31% detection rate when using adversarial training.