Deep learning model for distributed denial of service (DDoS) detection

被引:0
|
作者
Tennakoon, Chaminda [1 ]
Fernando, Subha [2 ]
机构
[1] Informat Inst Technol, Dept Comp, Colombo, Sri Lanka
[2] Univ Moratuwa, Dept Computat Math, Moratuwa, Sri Lanka
关键词
Application-layer; DDoS detection autoencoder; Deep learning models; Cybersecurity; ATTACKS;
D O I
10.21833/ijaas.2022.02.012
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Distributed denial of service (DDoS) attacks is one of the serious threats in the domain of cybersecurity where it affects the availability of online services by disrupting access to its legitimate users. The consequences of such attacks could be millions of dollars in worth since all of the online services are relying on high availability. The magnitude of DDoS attacks is ever increasing as attackers are smart enough to innovate their attacking strategies to expose vulnerabilities in the intrusion detection models or mitigation mechanisms. The history of DDoS attacks reflects that network and transport layers of the OSI model were the initial target of the attackers, but the recent history from the cybersecurity domain proves that the attacking momentum has shifted toward the application layer of the OSI model which presents a high degree of difficulty distinguishing the attack and benign traffics that make the combat against application-layer DDoS attack a sophisticated task. Striding for high accuracy with high DDoS classification recall is key for any DDoS detection mechanism to keep the reliability and trustworthiness of such a system. In this paper, a deep learning approach for application-layer DDoS detection is proposed by using an autoencoder to perform the feature selection and Deep neural networks to perform the attack classification. A popular benchmark dataset CIC DoS 2017 is selected by extracting the most appealing features from the packet flows. The proposed model has achieved an accuracy of 99.83% with a detection rate of 99.84% while maintaining the false-negative rate of 0.17%, which has the heights accuracy rate among the literature reviewed so far. (C) 2022 The Authors. Published by IASE.
引用
收藏
页码:109 / 118
页数:10
相关论文
共 50 条
  • [1] Distributed Denial of Service (DDoS) Attacks Detection: A Machine Learning Approach
    Samom, Premson Singh
    Taggu, Amar
    [J]. APPLIED SOFT COMPUTING AND COMMUNICATION NETWORKS, 2021, 187 : 75 - 87
  • [2] Distributed Denial of Service (DDoS) Attacks Detection Using Machine Learning Prototype
    Hoyos Ll, Manuel S.
    Isaza E, Gustavo A.
    Velez, Jairo I.
    Castillo O, Luis
    [J]. DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE, (DCAI 2016), 2016, 474 : 33 - 41
  • [3] Distributed Denial of Service (DDoS) detection by traffic pattern analysis
    Theerasak Thapngam
    Shui Yu
    Wanlei Zhou
    S. Kami Makki
    [J]. Peer-to-Peer Networking and Applications, 2014, 7 : 346 - 358
  • [4] Distributed Denial of Service (DDoS) detection by traffic pattern analysis
    Thapngam, Theerasak
    Yu, Shui
    Zhou, Wanlei
    Makki, S. Kami
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2014, 7 (04) : 346 - 358
  • [5] Distributed Denial of Service (DDoS): A History
    Brooks, Richard R.
    Yu, Lu
    Ozcelik, Ilker
    Oakley, Jon
    Tusing, Nathan
    [J]. IEEE ANNALS OF THE HISTORY OF COMPUTING, 2022, 44 (02) : 44 - 54
  • [6] DeepDetect: Detection of Distributed Denial of Service Attacks Using Deep Learning
    Asad, Muhammad
    Asim, Muhammad
    Javed, Talha
    Beg, Mirza O.
    Mujtaba, Hasan
    Abbas, Sohail
    [J]. COMPUTER JOURNAL, 2020, 63 (07): : 983 - 994
  • [7] DeepDetect: Detection of distributed denial of service attacks using deep learning
    Asad, Muhammad
    Asim, Muhammad
    Javed, Talha
    Beg, Mirza O.
    Mujtaba, Hasan
    Abbas, Sohail
    [J]. Computer Journal, 2021, 63 (07): : 983 - 994
  • [8] Distributed Denial of Service Attack Detection for the Internet of Things Using Hybrid Deep Learning Model
    Ahmim, Ahmed
    Maazouzi, Faiz
    Ahmim, Marwa
    Namane, Sarra
    Dhaou, Imed Ben
    [J]. IEEE ACCESS, 2023, 11 : 119862 - 119875
  • [9] Detecting Distributed Denial of Service (DDoS) attacks through inductive learning
    Noh, S
    Lee, C
    Choi, K
    Jung, GH
    [J]. INTELLIGENT DATA ENGINEERING AND AUTOMATED LEARNING, 2003, 2690 : 286 - 295
  • [10] The Design of SDN based Detection for Distributed Denial of Service (DDoS) attack
    Oo, Myo Myint
    Kamolphiwong, Sinchai
    Kamolphiwong, Thossaporn
    [J]. 2017 21ST INTERNATIONAL COMPUTER SCIENCE AND ENGINEERING CONFERENCE (ICSEC 2017), 2017, : 258 - 263