Federated Incremental Learning Based DDoS Attack Detection Model in SDN Environment

被引:0
|
作者
Liu, Yan-Hua [1 ,2 ,4 ,5 ]
Fang, Wen-Yu [1 ,4 ,5 ]
Guo, Wen-Zhong [1 ,2 ,4 ,5 ]
Zhao, Bao-Kang [3 ]
Huang, Wei [1 ,4 ,5 ]
机构
[1] College of Computer and Data Science, Fuzhou University, Fuzhou,350108, China
[2] Zhicheng College, Fuzhou University, Fuzhou,350002, China
[3] College of Computer, National University of Defense Technology, Changsha,410073, China
[4] Engineering Research Center of Big Data Intelligence, Ministry of Education, Fuzhou,350108, China
[5] Fujian Key Laboratory of Network Computing and Intelligent Information Processing(Fuzhou University), Fuzhou,350108, China
来源
基金
中国国家自然科学基金;
关键词
Cybersecurity - Denial-of-service attack - Program debugging - Risk management - Solvent extraction - Time division multiple access;
D O I
10.11897/SP.J.1016.2024.02852
中图分类号
学科分类号
摘要
Software-Defined Networking (SDN) is a widely adopted network paradigm characterized by the separation of the control plane from the data plane. In light of network security threats, particularly Distributed Denial of Service (DDoS) attacks, the integration of effective DDoS attack detection methods within SDN is of paramount importance. The centralized control characteristic of SDN presents significant security risks when employing centralized DDoS attack detection methods, thereby posing considerable challenges to the security of the control plane in SDN environments. Furthermore, the growing volume of traffic data in SDN environments results in challenges related to more intricate traffic characterization and a pronounced Non-Independent and Identically Distributed (Non-IID) distribution among various entities. These issues present significant barriers to enhancing the accuracy and robustness of current federated learning-based detection models. The separation of management and control in SDN facilitates the creation of new flow rules by users, which enhances the efficiency of message routing control. However, current methodologies for flow detection face difficulties in preserving the knowledge of original features while simultaneously adapting to the distribution of newly generated features within the SDN environment. This challenge contributes to a phenomenon known as data forgetting. Furthermore,the imposition of flow rules restricts the forwarding targets of messages, resulting in variability in the data messages that can be collected by different host entities. The Non-IID distribution problem significantly undermines the performance and robustness of DDoS attack detection models that utilize artificial intelligence. To address these challenges, we propose a federated incremental learning-based model for DDoS attack detection within an SDN environment. This model integrates incremental learning and federated learning to accommodate new data inputs through incremental model updates, thereby eliminating the need for global re-training of the entire model. To mitigate the security risks associated with centralized DDoS attack detection methods and to address the Non-IID distribution issues arising from data increments, we introduce a weighted aggregation algorithm grounded in federated incremental learning. This algorithm personalizes adaptation to different subdataset increments by dynamically adjusting aggregation weights, thereby enhancing the efficiency of incremental aggregation. Additionally, in response to the complex traffic features inherent in SDN networks, we propose a DDoS attack detection methodology that employs Long Short-Term Memory (LSTM) networks. This approach enables real-time detection of traffic features by extracting and learning the temporal correlations present in the data, utilizing statistical analysis of the temporal characteristics of traffic data within SDN networks. Finally, by integrating the unique characteristics of SDN networks, we facilitate real-time decision-making for DDoS defense. This integration combines the results of DDoS attack detection with information pertaining to network entities, enabling the real-time deployment of flow rules. Concurrently, this approach effectively mitigates malicious DDoS attack traffic, safeguards critical entities, and ensures the stability of network topology. In this study, we evaluate the performance of the proposed method against existing techniques, including FedAvg, FA-FedAvg, and FIL-IIoT, in the context of an incremental DDoS attack detection task. The experimental results indicate that the proposed method enhances the accuracy of DDoS attack detection by an improvement range of 5. 06% to 12. 62% and increases the F1-Score by 0. 0565 to 0. 1410 when compared to alternative methods. © 2024 Science Press. All rights reserved.
引用
收藏
页码:2852 / 2866
相关论文
共 50 条
  • [21] Detection and defense of DDoS attack-based on deep learning in OpenFlow-based SDN
    Li, Chuanhuang
    Wu, Yan
    Yuan, Xiaoyong
    Sun, Zhengjun
    Wang, Weiming
    Li, Xiaolin
    Gong, Liang
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (05)
  • [22] Deep Learning-based Slow DDoS Attack Detection in SDN-based Networks
    Nugraha, Beny
    Murthy, Rathan Narasimha
    2020 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2020, : 51 - 56
  • [23] Cooperative defense of DDoS attack based on machine learning in SDN
    Shang L.
    Chen M.
    Zhang L.
    Liu X.
    Shi T.
    Li B.
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2021, 49 (16): : 170 - 176
  • [24] A Research Review on SDN-Based DDOS Attack Detection
    Zhu, Weidong
    Yi, Xiujuan
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND MANAGEMENT INNOVATION (MSMI 2017), 2017, 31 : 145 - 149
  • [25] A CGAN-based DDoS Attack Detection Method in SDN
    Liu
    Luo
    Jiang
    Wang
    Li
    Jia
    IWCMC 2021: 2021 17TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2021, : 1030 - 1034
  • [26] A DDoS attack detection method based on SVM and K-nearest neighbour in SDN environment
    Ma, Zhaohui
    Li, Bohong
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2020, 23 (03) : 224 - 234
  • [27] Enhancing DDoS Attack Detection and Mitigation in SDN Using an Ensemble Online Machine Learning Model
    Alashhab, Abdussalam Ahmed
    Zahid, Mohd Soperi
    Isyaku, Babangida
    Elnour, Asma Abbas
    Nagmeldin, Wamda
    Abdelmaboud, Abdelzahir
    Abdullah, Talal Ali Ahmed
    Maiwada, Umar Danjuma
    IEEE ACCESS, 2024, 12 : 51630 - 51649
  • [28] Classification of DDoS attack traffic on SDN network environment using deep learning
    Clinton, Urikhimbam Boby
    Hoque, Nazrul
    Singh, Khumukcham Robindro
    CYBERSECURITY, 2024, 7 (01):
  • [29] DDoS attack identification based on SDN
    Dobrin, Dobrev
    Dimiter, Avresky
    2021 IEEE 20TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2021,
  • [30] FedDB: A Federated Learning Approach Using DBSCAN for DDoS Attack Detection
    Lee, Yi-Chen
    Chien, Wei-Che
    Chang, Yao-Chung
    APPLIED SCIENCES-BASEL, 2024, 14 (22):