GADoT: GAN-based Adversarial Training for Robust DDoS Attack Detection

GADoT: GAN-based Adversarial Training for Robust DDoS Attack Detection
复制标题

DOI:
10.1109/cns53000.2021.9705040
复制
发表时间:
2021-10
期刊:
2021 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Maged AbdelAty;Sandra Scott-Hayward;R. D. Corin;D. Siracusa
Maged AbdelAty;Sandra Scott-Hayward;R. D. Corin;D. Siracusa
中科院分区:
其他
文献类型:
--
作者:
Maged AbdelAty;Sandra Scott-Hayward;R. D. Corin;D. Siracusa

文献摘要

相似文献

机器学习(ML)已被证明在许多应用领域是有效的。然而,ML方法很容易受到敌意攻击,在这种攻击中,攻击者试图通过精心编制输入数据来欺骗分类/预测机制。在基于ML的网络入侵检测系统(NIDS)的情况下,攻击者可能会利用他们对入侵检测逻辑的了解来生成仍然未被检测到的恶意流量。解决这一问题的一种方法是采用对抗性训练,即用对抗性流量样本来扩充训练集。提出了一种称为Gadot的对抗性训练方法,该方法利用产生式对抗性网络(GAN)来生成对抗性DDoS样本用于训练。我们的研究表明,在热门数据集上具有高准确率的最新网络入侵检测系统,在敌意攻击下可以经历60%以上的未被检测到的恶意流量。然后,我们演示了在使用Gadot进行对抗性训练后,这个分数如何下降到1.8%或更低。
Machine Learning (ML) has proven to be effective in many application domains. However, ML methods can be vulnerable to adversarial attacks, in which an attacker tries to fool the classification/prediction mechanism by crafting the input data. In the case of ML-based Network Intrusion Detection Systems (NIDSs), the attacker might use their knowledge of the intrusion detection logic to generate malicious traffic that remains undetected. One way to solve this issue is to adopt adversarial training, in which the training set is augmented with adversarial traffic samples. This paper presents an adversarial training approach called GADoT, which leverages a Generative Adversarial Network (GAN) to generate adversarial DDoS samples for training. We show that a state-of-the-art NIDS with high accuracy on popular datasets can experience more than 60% undetected malicious flows under adversarial attacks. We then demonstrate how this score drops to 1.8% or less after adversarial training using GADoT.