High-Speed Network DDoS Attack Detection: A Survey

被引:3
作者
Haseeb-ur-rehman, Rana M. Abdul [1 ]
Aman, Azana Hafizah Mohd [1 ]
Hasan, Mohammad Kamrul [1 ]
Ariffin, Khairul Akram Zainol [1 ]
Namoun, Abdallah [2 ]
Tufail, Ali [3 ]
Kim, Ki-Hyung [4 ]
机构
[1] Univ Kebangsaan Malaysia, Fac Informat Sci & Technol, Ctr Cyber Secur, Bangi 43600, Malaysia
[2] Islamic Univ Madinah, Fac Comp & Informat Syst, Madinah 42351, Saudi Arabia
[3] Univ Brunei Darussalam, Sch Digital Sci, BE-1410 Gadong, Brunei
[4] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
基金
新加坡国家研究基金会;
关键词
denial of service; distributed denial of service; cyber-physical system; machine learning; high-speed network; intrusion detection system; express data path; REAL-TIME; BIG DATA;
D O I
10.3390/s23156850
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Having a large number of device connections provides attackers with multiple ways to attack a network. This situation can lead to distributed denial-of-service (DDoS) attacks, which can cause fiscal harm and corrupt data. Thus, irregularity detection in traffic data is crucial in detecting malicious behavior in a network, which is essential for network security and the integrity of modern Cyber-Physical Systems (CPS). Nevertheless, studies have shown that current techniques are ineffective at detecting DDoS attacks on networks, especially in the case of high-speed networks (HSN), as detecting attacks on the latter is very complex due to their fast packet processing. This review aims to study and compare different approaches to detecting DDoS attacks, using machine learning (ML) techniques such as k-means, K-Nearest Neighbors (KNN), and Naive Bayes (NB) used in intrusion detection systems (IDSs) and flow-based IDSs, and expresses data paths for packet filtering for HSN performance. This review highlights the high-speed network accuracy evaluation factors, provides a detailed DDoS attack taxonomy, and classifies detection techniques. Moreover, the existing literature is inspected through a qualitative analysis, with respect to the factors extracted from the presented taxonomy of irregular traffic pattern detection. Different research directions are suggested to support researchers in identifying and designing the optimal solution by highlighting the issues and challenges of DDoS attacks on high-speed networks.
引用
收藏
页数:25
相关论文
共 120 条
  • [41] Florea R., 2022, P 2022 26 INT C SYST, P146
  • [42] Learning-Based Simultaneous Detection and Characterization of Time Delay Attack in Cyber-Physical Systems
    Ganesh, Prakhar
    Lou, Xin
    Chen, Yao
    Tan, Rui
    Yau, David K. Y.
    Chen, Deming
    Winslett, Marianne
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2021, 12 (04) : 3581 - 3593
  • [43] An m-health application for cerebral stroke detection and monitoring using cloud services
    Garcia, Laura
    Tomas, Jesus
    Parra, Lorena
    Lloret, Jaime
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2019, 45 (319-327) : 319 - 327
  • [44] Analysis of Machine Learning Classifiers for Early Detection of DDoS Attacks on IoT Devices
    Gaur, Vimal
    Kumar, Rajneesh
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2022, 47 (02) : 1353 - 1374
  • [45] A systematic literature review of machine learning applications in IoT
    Gherbi, Chirihane
    Senouci, Oussama
    Harbi, Yasmine
    Medani, Khedidja
    Aliouat, Zibouda
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2023, 36 (11)
  • [46] Ghorbani H., 2020, 2020 International Conference on Technology and Entrepreneurship-Virtual (ICTE-V), P1, DOI DOI 10.1109/ICTE-V50708.2020.9113779
  • [47] Smart defense against distributed Denial of service attack in IoT networks using supervised learning classifiers
    Gupta, B. B.
    Chaudhary, Pooja
    Chang, Xiaojun
    Nedjah, Nadia
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 98
  • [48] Real-time big data processing for anomaly detection: A Survey
    Habeeb, Riyaz Ahamed Ariyaluran
    Nasaruddin, Fariza
    Gani, Abdullah
    Hashem, Ibrahim Abaker Targio
    Ahmed, Ejaz
    Imran, Muhammad
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2019, 45 : 289 - 307
  • [49] A Multifunctional Full-Packet Capture and Network Measurement System Supporting Nanosecond Timestamp and Real-Time Analysis
    Han, Luchao
    Guo, Zhichuan
    Huang, Xiaoying
    Zeng, Xuewen
    [J]. IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2021, 70
  • [50] Sensor Cloud Frameworks: State-of-the-Art, Taxonomy, and Research Issues
    Haseeb-Ur-Rehman, Rana M. Abdul
    Liaqat, Misbah
    Aman, Azana Hafizah Mohd
    Ab Hamid, Siti Hafizah
    Ali, Rana Liaqat
    Shuja, Junaid
    Khan, Muhammad Khurram
    [J]. IEEE SENSORS JOURNAL, 2021, 21 (20) : 22347 - 22370