DeepDDoS: Online DDoS Attack Detection

DeepDDoS: Online DDoS Attack Detection
复制标题

DeepDDoS:在线DDoS攻击检测

DOI:
10.1109/globecom38437.2019.9013186
复制
发表时间:
2019
期刊:
Proc. of IEEE GlobeCom 2019
影响因子:
--
通讯作者:
Chentao Wu
Chentao Wu
中科院分区:
--
文献类型:
--
作者:
Zhenping Shi;Jie Li;Chentao Wu

文献摘要

相似文献

高效、可靠的大规模DDoS攻击检测方案对于网络异常检测至关重要。典型的机器学习算法(例如决策树和 Adaboost)在流级别分析方面效果很好,但无法执行数据包级别的细粒度检测。由于这些算法需要更多的数据包信息进行检测,导致检测时延较高,准确率相对较低。为了解决这个问题,我们提出了 DeepDDoS,这是一种专注于周期攻击和数据包攻击检测的深度学习方法。首先,对网络数据包进行时间维度建模,发现潜在的异常时间段。其次,网络数据包按5个元组(流)分组,组内的数据包根据到达时间排序。然后对各组进行数据包级序列建模。综合性能评估表明,DeepDDoS检测准确率达到99%。此外,只需要5个连续的数据包即可进行逐包检测,大大减少了检测延迟和计算开销。对比实验表明,DeepDDoS 优于现有的典型攻击检测方法。
Highly efficient and dependable large-scale DDoS attack detection scheme is critical for network anomaly detection. Typical machine learning algorithms such as Decision Tree and Adaboost work well on flow level analysis but cannot perform fine- grained detection of packet levels. Since these algorithms require more packets information for detection, resulting in higher detection delay and relatively lower accuracy. To address the problem, we propose DeepDDoS which is a deep learning method focusing on both period- wise and packetwise attack detection. First, the network packets are modeled in time dimension to discover the potential abnormal time period. Second, the network packets are grouped by 5 tuples (flow), the packets inside the group are sorted according to their arrival time. Then the data packet level sequence modeling is performed in each group. Comprehensive performance evaluation shows that the detection accuracy of DeepDDoS reach 99%. Furthermore, only 5 consecutive packets are needed for packet-wise detection, greatly reducing detection delay and computational overhead. Comparative experiments show that DeepDDoS outperforms existing typical attack detection methods.