返回
Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence
DOI:10.1016/j.jnca.2020.102871.png)
摘要
En 中文
SlowDoS attacks exploit slow transmissions on application-level protocols like HTTP to carry out denial of service against web-servers. These attacks are difficult to be detected with traditional signature-based intrusion detection approaches, even more when the HTTP traffic is encrypted. To cope with this challenge, this paper describes and AI-based anomaly detection system for real-time detection of SlowDoS attacks over application-level encrypted traffic. Our system monitors in real-time the network traffic, analyzing, processing and aggregating packets into conversation flows, getting valuable features and statistics that are dynamically analyzed in streaming for AI-based anomaly detection. The distributed AI model running in Apache Spark-streaming, combines clustering analysis for anomaly detection, along with deep learning techniques to increase detection accuracy in those cases where clustering obtains ambiguous probabilities. The proposal has been implemented and validated in a real testbed, showing its feasibility, performance and accuracy for detecting in real-time different kinds of SlowDoS attacks over encrypted traffic. The achieved results are close to the optimal precision value with a success rate 98%, while the false negative rate takes a value below 0.5%.
Keyword:
Cybersecurity
Artificial intelligence
Cyberattacks
Machine learning
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
8
论文数:
3.7K
被引数:
1.1W
机构
引用论文
SeArch: A Collaborative and Intelligent NIDS Architecture for SDN-Based Cloud IoT Networks
IEEE ACCESS
IF3.6
Comprehensive Review of Artificial Intelligence and Statistical Approaches in Distributed Denial of Service Attack and Defense Methods人工智能和统计方法在分布式拒绝服务攻击和防御方法中的综合评述
IEEE ACCESS
IF3.6

