Online DDoS attack detection using Mahalanobis distance and Kernel-based learning algorithm

被引:46
|
作者
Cakmakci, Salva Daneshgadeh [1 ,4 ]
Kemmerich, Thomas [2 ]
Ahmed, Tarem [3 ]
Baykal, Nazife [1 ]
机构
[1] Middle East Tech Univ METU, Grad Sch Informat, Ankara, Turkey
[2] Norwegian Univ Sci & Technol NTNU, Dept Informat Secur & Commun Technol, Gjovik, Norway
[3] Independent Univ, Bangladesh IUB, Dept Comp Sci & Engn, Dhaka, Bangladesh
[4] Univ Bremen, Dept Comp Sci, Grp Comp Architecture, Bremen, Germany
关键词
Online learning algorithm; DDoS; KOAD; E-KOAD; Mahalanobis distance; Chi-square test; SELECTION; ENTROPY; SYSTEM; DOS;
D O I
10.1016/j.jnca.2020.102756
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial-of-service (DDoS) attacks are constantly evolving as the computer and networking technologies and attackers' motivations are changing. In recent years, several supervised DDoS detection algorithms have been proposed. However, these algorithms require a priori knowledge of the classes and cannot automatically adapt to frequently changing network traffic trends. This emphasizes the need for the development of new DDoS detection mechanisms that target zero-day and sophisticated DDoS attacks. In this paper, we propose an online, sequential, DDoS detection scheme that is suitable for use with multivariate data. The proposed algorithm utilizes a kernel-based learning algorithm, the Mahalanobis distance, and a chi-square test. Initially, we extract four entropy-based and four statistical features from network flows per minute as detection metrics. Then, we employ the kernel-based learning algorithm using the entropy features to detect input vectors that were suspected to be DDoS. This algorithm assumes no model for network traffic or DDoS. It constructs and adapts a dictionary of features that approximately span the subspace of normal behavior. Every T minutes, the Mahalanobis distance between suspicious vectors and the distribution of dictionary members is measured. Subsequently, the chi-square test is used to evaluate the Mahalanobis distance. The proposed DDoS detection scheme was applied to the CICIDS2017 dataset, and we compared the results with those given by existing algorithms. It was demonstrated that the proposed online detection scheme outperforms almost all available DDoS classification algorithms with an offline learning process.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Online learning algorithm of kernel-based ternary classifiers using support vectors
    Kovalchuk A.V.
    Bellyustin N.S.
    [J]. Optical Memory and Neural Networks, 2013, 22 (3) : 193 - 205
  • [2] Bounded kernel-based online learning
    Orabona, Francesco
    Keshet, Joseph
    Caputo, Barbara
    [J]. Journal of Machine Learning Research, 2009, 10 : 2643 - 2666
  • [3] Bounded Kernel-Based Online Learning
    Orabona, Francesco
    Keshet, Joseph
    Caputo, Barbara
    [J]. JOURNAL OF MACHINE LEARNING RESEARCH, 2009, 10 : 2643 - 2666
  • [4] Adaptive DDoS Attack Detection Method Based on Multiple-Kernel Learning
    Cheng, Jieren
    Zhang, Chen
    Tang, Xiangyan
    Sheng, Victor S.
    Dong, Zhe
    Li, Junqi
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [5] A new kernel-based algorithm for online clustering
    Boubacar, HA
    Lecoeuche, S
    [J]. ARTIFICIAL NEURAL NETWORKS: FORMAL MODELS AND THEIR APPLICATIONS - ICANN 2005, PT 2, PROCEEDINGS, 2005, 3697 : 583 - 588
  • [6] Smart Detection: An Online Approach for DoS/DDoS Attack Detection Using Machine Learning
    de Lima Filho, Francisco Sales
    Silveira, Frederico A. F.
    Brito Junior, Agostinho de Medeiros
    Vargas-Solar, Genoveva
    Silveira, Luiz F.
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [7] A Novel DDoS Attack Detection Method Using Optimized Generalized Multiple Kernel Learning
    Cheng, Jieren
    Li, Junqi
    Tang, Xiangyan
    Sheng, Victor S.
    Zhang, Chen
    Li, Mengyang
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 62 (03): : 1423 - 1443
  • [8] KERNEL-BASED EFFICIENT LIFELONG LEARNING ALGORITHM
    Kim, Seung-Jun
    Mowakeaa, Rami
    [J]. 2019 IEEE DATA SCIENCE WORKSHOP (DSW), 2019, : 175 - 179
  • [9] Machine Learning Based DDoS Attack Detection
    Ajeetha, G.
    Priya, Madhu G.
    [J]. 2019 INNOVATIONS IN POWER AND ADVANCED COMPUTING TECHNOLOGIES (I-PACT), 2019,
  • [10] DDoS Attack Detection Using Ensemble Machine Learning Models with RFE Algorithm
    Visetbunditkun, Tanut
    Srichavengsup, Warakorn
    [J]. 2022 7TH INTERNATIONAL CONFERENCE ON BUSINESS AND INDUSTRIAL RESEARCH (ICBIR2022), 2022, : 269 - 273