FTG-Net-E: A hierarchical ensemble graph neural network for DDoS attack detection

被引:4
作者
Bakar, Rana Abu [1 ]
Marinis, Lorenzo De [1 ]
Cugini, Filippo [2 ]
Paolucci, Francesco [2 ]
机构
[1] Scuola Super Sant Anna, I-56124 Pisa, Italy
[2] CNIT, I-56124 Pisa, Italy
关键词
DDoS; Network security; Cybersecurity; Deep learning; Ensemble learning; Attack detection; Graph neural networks;
D O I
10.1016/j.comnet.2024.110508
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial-of-Service (DDoS) attacks are a major threat to computer networks. These attacks can be carried out by flooding a network with malicious traffic, overwhelming its resources, and/or making it unavailable to legitimate users. Existing machine learning methods for DDoS attack detection typically use statistical features of network traffic, such as packet sizes and inter-arrival times. However, these methods often fail to capture the complex relationships between different traffic flows. This paper proposes a new DDoS attack detection approach that uses Graph Neural Networks (GNN) ensemble learning. GNN ensemble learning is a type of machine learning that combines multiple GNN models to improve the detection accuracy. We evaluated our approach on the Canadian Institute for Cybersecurity Intrusion Detection Evaluation Dataset (CICIDS2018) and CICIDS2017 datasets, a benchmark dataset for DDoS attack detection. Our work provides two main contributions. First, we extend our DDoS attack detection approach using GNN ensemble learning. Second, we explore the evaluation and fine-tuning of hyperparameter metrics through ensemble learning, significantly enhancing accuracy compared to a single GNN model and achieving an average 3.2% higher F1- score. Additionally, our approach effectively reduces overfitting by incorporating regularization techniques, such as dropout and early stopping. Specifically, we use a hierarchical ensemble of GNN, where each GNN learns the relationships between traffic flows at a different granularity level. We then use bagging and boosting to combine the predictions of the individual GNN, further improving detection accuracy. Results show that our system can achieve 99.67% accuracy, with a F1-score of 99.29%, which is better than state-of-the-art methods, even traffic architecture.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] A parameter-free graph reduction for spectral clustering and SpectralNet
    Alshammari, Mashaan
    Stavrakakis, John
    Takatsuka, Masahiro
    [J]. ARRAY, 2022, 15
  • [2] Ensemble modelling or selecting the best model: Many could be better than one
    Barai, SV
    Reich, Y
    [J]. AI EDAM-ARTIFICIAL INTELLIGENCE FOR ENGINEERING DESIGN ANALYSIS AND MANUFACTURING, 1999, 13 (05): : 377 - 386
  • [3] FTG-Net: Hierarchical Flow-to-Traffic Graph Neural Network for DDoS Attack Detection
    Barsellotti, Luca
    De Marinis, Lorenzo
    Cugini, Filippo
    Paolucci, Francesco
    [J]. 2023 IEEE 24TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING, HPSR, 2023,
  • [4] Introducing Data Processing Units (DPU) at the Edge [Invited]
    Barsellotti, Luca
    Alhamed, Faris
    Olmos, Juan Jose Vegas
    Paolucci, Francesco
    Castoldi, Piero
    Cugini, Filippo
    [J]. 2022 31ST INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2022), 2022,
  • [5] Detecting and Mitigating DDoS Attacks in SDN Using Spatial-Temporal Graph Convolutional Network
    Cao, Yongyi
    Jiang, Hao
    Deng, Yuchuan
    Wu, Jing
    Zhou, Pan
    Luo, Wei
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (06) : 3855 - 3872
  • [6] Anomal-E: A self-supervised network intrusion detection system based on graph neural networks
    Caville, Evan
    Lo, Wai Weng
    Layeghy, Siamak
    Portmann, Marius
    [J]. KNOWLEDGE-BASED SYSTEMS, 2022, 258
  • [7] Telemetry and AI-based security P4 applications for optical networks [Invited]
    Cugini, Filippo
    Scano, Davide
    Giorgetti, Alessio
    Sgambelluri, Andrea
    De Marinis, Lorenzo
    Castoldi, Piero
    Paolucci, Francesco
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2023, 15 (01) : A1 - A10
  • [8] Cascaded Look Up Table Distillation of P4 Deep Neural Network Switches
    De Marinis, Lorenzo
    Paolini, Emilio
    Abu Bakar, Rana
    Cugini, Filippo
    Paolucci, Francesco
    [J]. IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 2111 - 2116
  • [9] Lucid: A Practical, Lightweight Deep Learning Solution for DDoS Attack Detection
    Doriguzzi-Corin, R.
    Millar, S.
    Scott-Hayward, S.
    Martinez-del-Rincon, J.
    Siracusa, D.
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (02): : 876 - 889
  • [10] Esmaeili B., 2023, IEEE Internet Things J.