返回
A fast all-packets-based DDoS attack detection approach based on network graph and graph kernel
DOI:10.1016/j.jnca.2021.103079.png)
摘要
En 中文
DDoS attack detection methods play a very important role in protecting computer network security. However, the existing flow-based DDoS attack detection methods face the non-negligible time delay and are not general for different types of DDoS attacks at different rates. In order to fill this research gap, a fast all-packets-based DDoS attack detection approach (FAPDD) is proposed. The FAPDD firstly designs a new time series network graph model to effectively simplify the processing of network traffic handling compared with the flow-based detections. Furthermore, it is the first time that the directed Weisfeiler-Lehman graph kernel is built for measuring the divergence between the current network graph and the normalization network graphs. Due to the new graph model and kernel measurement method to judge network changes, the different types and rates of DDoS attacks can be especially detected. In addition, the dynamic threshold and freezing mechanism are constructed to display standard traffic changes and prevent the pollution of attack traffic to the standard network. Finally, a number of real DDoS attack datasets are applied to evaluate the effectiveness of the proposed method, as well as the overall time efficiency and detection effect. Compared with other methods, the FAPDD can better meet the real-time requirements and achieve good detection effects in different types of DDoS attacks with different attack rates.
Keyword:
Network security
Fast DDoS attack detection
Network graph based all packets
Directed weisfeiler-lehman graph kernel
Dynamic threshold mechanism
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
8
论文数:
3.6K
被引数:
1.1W
机构
引用论文
Efficient DDoS flood attack detection using dynamic thresholding on flow-based network traffic基于流的网络流量动态阈值的高效DDoS洪水攻击检测
COMPUTERS & SECURITY
IF5.4

