返回
Semi-supervised machine learning approach for DDoS detection
DOI:10.1007/s10489-018-1141-2.png)
摘要
En 中文
Even though advanced Machine Learning (ML) techniques have been adopted for DDoS detection, the attack remains a major threat of the Internet. Most of the existing ML-based DDoS detection approaches are under two categories: supervised and unsupervised. Supervised ML approaches for DDoS detection rely on availability of labeled network traffic datasets. Whereas, unsupervised ML approaches detect attacks by analyzing the incoming network traffic. Both approaches are challenged by large amount of network traffic data, low detection accuracy and high false positive rates. In this paper we present an online sequential semi-supervised ML approach for DDoS detection based on network Entropy estimation, Co-clustering, Information Gain Ratio and Exra-Trees algorithm. The unsupervised part of the approach allows to reduce the irrelevant normal traffic data for DDoS detection which allows to reduce false positive rates and increase accuracy. Whereas, the supervised part allows to reduce the false positive rates of the unsupervised part and to accurately classify the DDoS traffic. Various experiments were performed to evaluate the proposed approach using three public datasets namely NSL-KDD, UNB ISCX 12 and UNSW-NB15. An accuracy of 98.23%, 99.88% and 93.71% is achieved for respectively NSL-KDD, UNB ISCX 12 and UNSW-NB15 datasets, with respectively the false positive rates 0.33%, 0.35% and 0.46%.
Keyword:
DDoS detection
Co-clustering
Entropy analysis
Information gain ratio
Feature selection
Extra-Trees
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.5
论文数:
7.6K
被引数:
1.7W
机构
引用论文
Bioreductive deposition of palladium (0) nanoparticles onShewanella oneidensiswith catalytic activity towards reductive dechlorination of polychlorinated biphenyls钯 (0) 纳米颗粒在 Shewanella oneidensis 上的生物还原沉积,对多氯联苯的还原脱氯具有催化活性
Toward developing a systematic approach to generate benchmark datasets for intrusion detection
COMPUTERS & SECURITY
IF5.4
Detection of known and unknown DDoS attacks using Artificial Neural Networks使用人工神经网络检测已知和未知DDoS攻击
NEUROCOMPUTING
IF6.5

