Unknown DDoS Attack Detection with Sliced Iterative Normalizing Flows Technique

被引:0
作者
Shieh, Chin-Shiuh [1 ]
Nguyen, Thanh-Lam [1 ]
Nguyen, Thanh-Tuan [2 ]
Horng, Mong-Fong [1 ]
机构
[1] Natl Kaohsiung Univ Sci & Technol, Dept Elect Engn, Kaohsiung 807618, Taiwan
[2] Nha Trang Univ, Dept Elect & Automat Engn, Nha Trang 650000, Vietnam
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2025年 / 82卷 / 03期
关键词
Distributed denial of service; sliced iterative normalizing flows; open-set recognition; cybersecurity; deep learning;
D O I
10.32604/cmc.2025.061001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
DDoS attacks represent one of the most pervasive and evolving threats in cybersecurity, capable of crippling critical infrastructures and disrupting services globally. As networks continue to expand and threats become more sophisticated, there is an urgent need for Intrusion Detection Systems (IDS) capable of handling these challenges effectively. Traditional IDS models frequently have difficulties in detecting new or changing attack patterns since they heavily depend on existing characteristics. This paper presents a novel approach for detecting unknown Distributed the Sliced Wasserstein distance to repeatedly modify probability distributions, enabling better management of highdimensional data when there are only a few samples available. The unique architecture of SINF ensures efficient density estimation and robust sample generation, enabling IDS to adapt dynamically to emerging threats without relying heavily on predefined signatures or extensive retraining. By incorporating Open-Set Recognition (OSR) techniques, this method improves the system's ability to detect both known and unknown attacks while maintaining high detection performance. The experimental evaluation on CICIDS2017 and CICDDoS2019 datasets demonstrates that the proposed system achieves an accuracy of 99.85% for known attacks and an F1 score of 99.99% after incremental learning for unknown attacks. The results clearly demonstrate the system's strong generalization capability across unseen attacks while maintaining the computational efficiency required for real-world deployment.
引用
收藏
页码:4881 / 4912
页数:32
相关论文
共 48 条
[31]   Unknown DDoS Attack Detection with Fuzzy C-Means Clustering and Spatial Location Constraint Prototype Loss [J].
Nguyen, Thanh-Lam ;
Kao, Hao ;
Nguyen, Thanh-Tuan ;
Horng, Mong-Fong ;
Shieh, Chin-Shiuh .
CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 78 (02) :2181-2205
[32]  
Phulre Ajay Kumar, 2024, Machine Intelligence for Research and Innovations: Proceedings of MAiTRI 2023. Lecture Notes in Networks and Systems (831), P59, DOI 10.1007/978-981-99-8135-9_6
[33]   A novel IoT intrusion detection framework using Decisive Red Fox optimization and descriptive back propagated radial basis function models [J].
Rabie, Osama Bassam J. ;
Selvarajan, Shitharth ;
Hasanin, Tawfiq ;
Alshareef, Abdulrhman M. ;
Yogesh, C. K. ;
Uddin, Mueen .
SCIENTIFIC REPORTS, 2024, 14 (01)
[34]   Machine Learning for DDoS Attack Detection in Industry 4.0 CPPSs [J].
Saghezchi, Firooz B. ;
Mantas, Georgios ;
Violas, Manuel A. ;
de Oliveira Duarte, A. Manuel ;
Rodriguez, Jonathan .
ELECTRONICS, 2022, 11 (04)
[35]   DDoS attack detection in SDN: Enhancing entropy-based detection with machine learning [J].
Santos-Neto, Marcos J. ;
Bordim, Jacir L. ;
Alchieri, Eduardo A. P. ;
Ishikawa, Edison .
CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (11)
[36]   Detection of Application-Layer DDoS Attacks Produced by Various Freely Accessible Toolkits Using Machine Learning [J].
Sharif, Dyari Mohammed ;
Beitollahi, Hakem ;
Fazeli, Mahdi .
IEEE ACCESS, 2023, 11 :51810-51819
[37]   Open-Set Recognition in Unknown DDoS Attacks Detection With Reciprocal Points Learning [J].
Shieh, Chin-Shiuh ;
Ho, Fu-An ;
Horng, Mong-Fong ;
Nguyen, Thanh-Tuan ;
Chakrabarti, Prasun .
IEEE ACCESS, 2024, 12 :56461-56476
[38]   Detection of Unknown DDoS Attack Using Convolutional Neural Networks Featuring Geometrical Metric [J].
Shieh, Chin-Shiuh ;
Nguyen, Thanh-Tuan ;
Horng, Mong-Fong .
MATHEMATICS, 2023, 11 (09)
[39]   Detection of Unknown DDoS Attack Using Reconstruct Error and One-Class SVM Featuring Stochastic Gradient Descent [J].
Shieh, Chin-Shiuh ;
Nguyen, Thanh-Tuan ;
Chen, Chun-Yueh ;
Horng, Mong-Fong .
MATHEMATICS, 2023, 11 (01)
[40]   Detection of Unknown DDoS Attacks with Deep Learning and Gaussian Mixture Model [J].
Shieh, Chin-Shiuh ;
Lin, Wan-Wei ;
Nguyen, Thanh-Tuan ;
Chen, Chi-Hong ;
Horng, Mong-Fong ;
Miu, Denis .
APPLIED SCIENCES-BASEL, 2021, 11 (11)