4.6 Article

Detection of Unknown DDoS Attacks with Deep Learning and Gaussian Mixture Model

期刊

APPLIED SCIENCES-BASEL
卷 11, 期 11, 页码 -

出版社

MDPI
DOI: 10.3390/app11115213

关键词

distributed denial of service (DDoS); machine learning; long short-term memory (LSTM); gaussian mixture model; incremental learning

资金

  1. Minister of Science and Technology, Taiwan [109-2637-E-992-006, MOST 109-2622-E-992-033, 109-2221-E-992-073-MY3]
  2. Ministry of Education, Taiwan under University-Industry Innovation RD (RSC)

向作者/读者索取更多资源

The study investigates the impact of the Open Set Recognition (OSR) problem on the detection of DDoS attacks in ML/DL systems, proposing a new detection framework that achieves high recall, precision, and accuracy.
DDoS (Distributed Denial of Service) attacks have become a pressing threat to the security and integrity of computer networks and information systems, which are indispensable infrastructures of modern times. The detection of DDoS attacks is a challenging issue before any mitigation measures can be taken. ML/DL (Machine Learning/Deep Learning) has been applied to the detection of DDoS attacks with satisfactory achievement. However, full-scale success is still beyond reach due to an inherent problem with ML/DL-based systems-the so-called Open Set Recognition (OSR) problem. This is a problem where an ML/DL-based system fails to deal with new instances not drawn from the distribution model of the training data. This problem is particularly profound in detecting DDoS attacks since DDoS attacks' technology keeps evolving and has changing traffic characteristics. This study investigates the impact of the OSR problem on the detection of DDoS attacks. In response to this problem, we propose a new DDoS detection framework featuring Bi-Directional Long Short-Term Memory (BI-LSTM), a Gaussian Mixture Model (GMM), and incremental learning. Unknown traffic captured by the GMM are subject to discrimination and labeling by traffic engineers, and then fed back to the framework as additional training samples. Using the data sets CIC-IDS2017 and CIC-DDoS2019 for training, testing, and evaluation, experiment results show that the proposed BI-LSTM-GMM can achieve recall, precision, and accuracy up to 94%. Experiments reveal that the proposed framework can be a promising solution to the detection of unknown DDoS attacks.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据