Deep learning model for distributed denial of service (DDoS) detection

被引:0
|
作者
Tennakoon, Chaminda [1 ]
Fernando, Subha [2 ]
机构
[1] Informat Inst Technol, Dept Comp, Colombo, Sri Lanka
[2] Univ Moratuwa, Dept Computat Math, Moratuwa, Sri Lanka
关键词
Application-layer; DDoS detection autoencoder; Deep learning models; Cybersecurity; ATTACKS;
D O I
10.21833/ijaas.2022.02.012
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Distributed denial of service (DDoS) attacks is one of the serious threats in the domain of cybersecurity where it affects the availability of online services by disrupting access to its legitimate users. The consequences of such attacks could be millions of dollars in worth since all of the online services are relying on high availability. The magnitude of DDoS attacks is ever increasing as attackers are smart enough to innovate their attacking strategies to expose vulnerabilities in the intrusion detection models or mitigation mechanisms. The history of DDoS attacks reflects that network and transport layers of the OSI model were the initial target of the attackers, but the recent history from the cybersecurity domain proves that the attacking momentum has shifted toward the application layer of the OSI model which presents a high degree of difficulty distinguishing the attack and benign traffics that make the combat against application-layer DDoS attack a sophisticated task. Striding for high accuracy with high DDoS classification recall is key for any DDoS detection mechanism to keep the reliability and trustworthiness of such a system. In this paper, a deep learning approach for application-layer DDoS detection is proposed by using an autoencoder to perform the feature selection and Deep neural networks to perform the attack classification. A popular benchmark dataset CIC DoS 2017 is selected by extracting the most appealing features from the packet flows. The proposed model has achieved an accuracy of 99.83% with a detection rate of 99.84% while maintaining the false-negative rate of 0.17%, which has the heights accuracy rate among the literature reviewed so far. (C) 2022 The Authors. Published by IASE.
引用
收藏
页码:109 / 118
页数:10
相关论文
共 50 条
  • [41] Intrusion Prevention Against Distributed Denial-of-Service(DDoS) on the cloud
    Vanitha, R.
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2016, 16 (04): : 90 - 96
  • [42] The Distributed Denial of Service Attacks (DDoS) Prevention Mechanisms on Application Layer
    Bhosale, Karuna S.
    Nenova, Maria
    Iliev, Georgi
    [J]. 2017 13TH INTERNATIONAL CONFERENCE ON ADVANCED TECHNOLOGIES, SYSTEMS AND SERVICES IN TELECOMMUNICATIONS (TELSIKS), 2017, : 136 - 139
  • [43] Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy
    Sharafaldin, Iman
    Lashkari, Arash Habibi
    Hakak, Saqib
    Ghorbani, Ali A.
    [J]. 2019 IEEE 53RD INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST 2019), 2019,
  • [44] Mitigation strategies for distributed denial of service (DDoS) in SDN: A survey and taxonomy
    Karnani, Suruchi
    Shakya, Harish Kumar
    [J]. INFORMATION SECURITY JOURNAL, 2023, 32 (06): : 444 - 468
  • [45] Impact of Distributed Denial of Service (DDoS) attack due to ARP storm'
    Kumar, S
    [J]. NETWORKING - ICN 2005, PT 2, 2005, 3421 : 997 - 1002
  • [46] Review on Mitigation of Distributed Denial of Service (DDoS) Attacks in Cloud Computing
    Khadke, Ashwini
    Madankar, Mangala
    Motghare, Manish
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND CONTROL (ISCO'16), 2016,
  • [47] The compliance implications of a cyberattack: a distributed denial of service (DDoS) attack explored
    Fabian Maximilian Johannes Teichmann
    Bruno S. Sergi
    Chiara Wittmann
    [J]. International Cybersecurity Law Review, 2023, 4 (3): : 291 - 298
  • [48] Factors Effecting Businesses due to Distributed Denial of Service (DDoS) Attack
    Mateen, Hafsa
    Shahzad, Malik
    Awan, Kaleem
    [J]. 4TH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING (IC)2, 2021, : 404 - 410
  • [49] Distributed denial of service (DDoS) resilience in cloud: Review and conceptual cloud DDoS mitigation framework
    Osanaiye, Opeyemi
    Choo, Kim-Kwang Raymond
    Dlodlo, Mqhele
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 67 : 147 - 165
  • [50] Distributed denial of service attack detection using machine learning classifiers
    Gautam, R.
    Padmavathy, R.
    [J]. INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2024, 46 (03)