Per-Host DDoS Mitigation by Direct-Control Reinforcement Learning

Per-Host DDoS Mitigation by Direct-Control Reinforcement Learning
复制标题

DOI:
10.1109/tnsm.2019.2960202
复制
发表时间:
2020-03
影响因子:
5.3
通讯作者:
Kyle A. Simpson;S. Rogers;D. Pezaros
Kyle A. Simpson;S. Rogers;D. Pezaros
中科院分区:
计算机科学2区
文献类型:
--
作者:
Kyle A. Simpson;S. Rogers;D. Pezaros

文献摘要

被引文献

相似文献

如今,DDoS攻击困扰着在线服务的可用性,但就像许多网络安全问题一样,它们也在不断发展和变化。随着新协议和应用程序的引入,正常模式和攻击模式也会发生变化,并且由于突发性和季节性变化而进一步复杂化。因此,在实践中很难应用基于机器学习的技术和防御。强化学习(RL)可以通过管理和监控后果来克服DDoS攻击的检测问题;代理的作用是以在线的方式学习优化性能标准(这些标准总是可用的)。我们通过引入两个代理类,以协议无关的方式对任何网络拓扑以每个流为基础进行操作,从而提高了基于rl的DDoS缓解技术的水平。这是由特征适用性和实证评估的深入调查支持。我们的研究结果表明,当用作类反馈控制的基础时,存在对不同流量类别具有高预测能力的流特征。我们表明,新的RL代理模型可以为许多选择的主机密度提供合法TCP流量的显著增加。
DDoS attacks plague the availability of online services today, yet like many cybersecurity problems are evolving and non-stationary. Normal and attack patterns shift as new protocols and applications are introduced, further compounded by burstiness and seasonal variation. Accordingly, it is difficult to apply machine learning-based techniques and defences in practice. Reinforcement learning (RL) may overcome this detection problem for DDoS attacks by managing and monitoring consequences; an agent’s role is to learn to optimise performance criteria (which are always available) in an online manner. We advance the state-of-the-art in RL-based DDoS mitigation by introducing two agent classes designed to act on a per-flow basis, in a protocol-agnostic manner for any network topology. This is supported by an in-depth investigation of feature suitability and empirical evaluation. Our results show the existence of flow features with high predictive power for different traffic classes, when used as a basis for feedback-loop-like control. We show that the new RL agent models can offer a significant increase in goodput of legitimate TCP traffic for many choices of host density.