Towards Effective Detection of Recent DDoS Attacks: A Deep Learning Approach

被引:12
作者
Lopes, Ivandro Ortet [1 ,2 ,3 ,4 ]
Zou, Deqing [2 ,4 ,5 ,6 ]
Ruambo, Francis A. [1 ,2 ,3 ,4 ]
Akbar, Saeed [1 ]
Yuan, Bin [2 ,4 ,5 ,6 ,7 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Comp Sci & Technol, Wuhan 430074, Peoples R China
[2] Huazhong Univ Sci & Technol, Natl Engn Res Ctr Big Data Technol & Syst, Wuhan 430074, Peoples R China
[3] Huazhong Univ Sci & Technol, Cluster & Grid Comp Lab, Wuhan 430074, Peoples R China
[4] Huazhong Univ Sci & Technol, Serv Comp Technol & Syst Lab, Wuhan 430074, Peoples R China
[5] Huazhong Univ Sci & Technol, Big Data Secur Engn Res Ctr, Wuhan 430074, Peoples R China
[6] Huazhong Univ Sci & Technol, Sch Cyber Sci & Engn, Wuhan 430074, Peoples R China
[7] Shenzhen Huazhong Univ Sci & Technol, Res Inst, Shenzhen 518057, Peoples R China
基金
中国国家自然科学基金;
关键词
NETWORK INTRUSION DETECTION;
D O I
10.1155/2021/5710028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) is a predominant threat to the availability of online services due to their size and frequency. However, developing an effective security mechanism to protect a network from this threat is a big challenge because DDoS uses various attack approaches coupled with several possible combinations. Furthermore, most of the existing deep learning- (DL-) based models pose a high processing overhead or may not perform well to detect the recently reported DDoS attacks as these models use outdated datasets for training and evaluation. To address the issues mentioned earlier, we propose CyDDoS, an integrated intrusion detection system (IDS) framework, which combines an ensemble of feature engineering algorithms with the deep neural network. The ensemble feature selection is based on five machine learning classifiers used to identify and extract the most relevant features used by the predictive model. This approach improves the model performance by processing only a subset of relevant features while reducing the computation requirement. We evaluate the model performance based on CICDDoS2019, a modern and realistic dataset consisting of normal and DDoS attack traffic. The evaluation considers different validation metrics such as accuracy, precision, F1-Score, and recall to argue the effectiveness of the proposed framework against state-of-the-art IDSs.
引用
收藏
页数:14
相关论文
共 37 条
[1]   Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues [J].
Aldweesh, Arwa ;
Derhab, Abdelouahid ;
Emam, Ahmed Z. .
KNOWLEDGE-BASED SYSTEMS, 2020, 189
[2]   DDoS detection in 5G-enabled IoT networks using deep Kalman backpropagation neural network [J].
Almiani, Muder ;
AbuGhazleh, Alia ;
Jararweh, Yaser ;
Razaque, Abdul .
INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2021, 12 (11) :3337-3349
[3]  
[Anonymous], CISCO ANN INT REP CI
[4]  
Antonakakis M, 2017, PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), P1093
[5]   SEAL: SDN based secure and agile framework for protecting smart city applications from DDoS attacks [J].
Bawany, Narmeen Zakaria ;
Shamsi, Jawwad A. .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 145
[6]   A Hierarchical Hybrid Intrusion Detection Approach in IoT Scenarios [J].
Bovenzi, Giampaolo ;
Aceto, Giuseppe ;
Ciuonzo, Domenico ;
Persico, Valerio ;
Pescape, Antonio .
2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
[7]  
Criscuolo P. J, DISTRIBUTED DENIAL S, P18
[8]   Near real-time security system applied to SDN environments in IoT networks using convolutional neural network [J].
de Assis, Marcos V. O. ;
Carvalho, Luiz F. ;
Rodrigues, Joel J. P. C. ;
Lloret, Jaime ;
Proenca Jr, Mario L. .
COMPUTERS & ELECTRICAL ENGINEERING, 2020, 86
[9]   Deep Learning: Methods and Applications [J].
Deng, Li ;
Yu, Dong .
FOUNDATIONS AND TRENDS IN SIGNAL PROCESSING, 2013, 7 (3-4) :I-387
[10]   Lucid: A Practical, Lightweight Deep Learning Solution for DDoS Attack Detection [J].
Doriguzzi-Corin, R. ;
Millar, S. ;
Scott-Hayward, S. ;
Martinez-del-Rincon, J. ;
Siracusa, D. .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (02) :876-889