High-Speed Network DDoS Attack Detection: A Survey

被引:3
作者
Haseeb-ur-rehman, Rana M. Abdul [1 ]
Aman, Azana Hafizah Mohd [1 ]
Hasan, Mohammad Kamrul [1 ]
Ariffin, Khairul Akram Zainol [1 ]
Namoun, Abdallah [2 ]
Tufail, Ali [3 ]
Kim, Ki-Hyung [4 ]
机构
[1] Univ Kebangsaan Malaysia, Fac Informat Sci & Technol, Ctr Cyber Secur, Bangi 43600, Malaysia
[2] Islamic Univ Madinah, Fac Comp & Informat Syst, Madinah 42351, Saudi Arabia
[3] Univ Brunei Darussalam, Sch Digital Sci, BE-1410 Gadong, Brunei
[4] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
基金
新加坡国家研究基金会;
关键词
denial of service; distributed denial of service; cyber-physical system; machine learning; high-speed network; intrusion detection system; express data path; REAL-TIME; BIG DATA;
D O I
10.3390/s23156850
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Having a large number of device connections provides attackers with multiple ways to attack a network. This situation can lead to distributed denial-of-service (DDoS) attacks, which can cause fiscal harm and corrupt data. Thus, irregularity detection in traffic data is crucial in detecting malicious behavior in a network, which is essential for network security and the integrity of modern Cyber-Physical Systems (CPS). Nevertheless, studies have shown that current techniques are ineffective at detecting DDoS attacks on networks, especially in the case of high-speed networks (HSN), as detecting attacks on the latter is very complex due to their fast packet processing. This review aims to study and compare different approaches to detecting DDoS attacks, using machine learning (ML) techniques such as k-means, K-Nearest Neighbors (KNN), and Naive Bayes (NB) used in intrusion detection systems (IDSs) and flow-based IDSs, and expresses data paths for packet filtering for HSN performance. This review highlights the high-speed network accuracy evaluation factors, provides a detailed DDoS attack taxonomy, and classifies detection techniques. Moreover, the existing literature is inspected through a qualitative analysis, with respect to the factors extracted from the presented taxonomy of irregular traffic pattern detection. Different research directions are suggested to support researchers in identifying and designing the optimal solution by highlighting the issues and challenges of DDoS attacks on high-speed networks.
引用
收藏
页数:25
相关论文
共 120 条
  • [51] Analysing performance issues of open-source intrusion detection systems in high-speed networks
    Hu, Qinwen
    Yu, Se-Young
    Asghar, Muhammad Rizwan
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 51
  • [52] Imthiyas M., 2020, International Journal of Pervasive Computing and Communications, V6, P67
  • [53] A review of amplification-based distributed denial of service attacks and their mitigation
    Ismail, Salih
    Hassen, Hani Ragab
    Just, Mike
    Zantout, Hind
    [J]. COMPUTERS & SECURITY, 2021, 109
  • [54] Review of Recent Detection Methods for HTTP DDoS Attack
    Jaafar, Ghafar A.
    Abdullah, Shahidan M.
    Ismail, Saifuladli
    [J]. JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS, 2019, 2019
  • [55] SELWAK: A Secure and Efficient Lightweight and Anonymous Authentication and Key Establishment Scheme for IoT Based Vehicular Ad hoc Networks
    Jan, Sagheer Ahmed
    Ul Amin, Noor
    Shuja, Junaid
    Abbas, Assad
    Maray, Mohammed
    Ali, Mazhar
    [J]. SENSORS, 2022, 22 (11)
  • [56] Kalra Vaibhav, 2022, Emerging Technologies for Computing, Communication and Smart Cities: Proceedings of ETCCS 2021. Lecture Notes in Electrical Engineering (875), P577, DOI 10.1007/978-981-19-0284-0_42
  • [57] Karlsson M., 2018, P LIN PLUMB C VANC B
  • [58] Adaptive tuning of network traffic policing mechanisms for DDoS attack mitigation systems
    Karpowicz, Michal P.
    [J]. EUROPEAN JOURNAL OF CONTROL, 2021, 61 : 101 - 118
  • [59] Katal A., 2022, MATH MODELING INTELL, P17
  • [60] SETA plus plus : Real-Time Scalable Encrypted Traffic Analytics in Multi-Gbps Networks
    Kattadige, Chamara
    Choi, Kwon Nung
    Wijesinghe, Achintha
    Nama, Arpit
    Thilakarathna, Kanchana
    Seneviratne, Suranga
    Jourjon, Guillaume
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3244 - 3259