arrow
Return

A fast all-packets-based DDoS attack detection approach based on network graph and graph kernel

delete2021-07-01
delete10
PRE
AI
X
Xinqian Liu
任家东 (Jiadong Ren) *
H
Haitao He
B
Bing Zhang
C
Chen Song
Y
Yunxue Wang
DOI:10.1016/j.jnca.2021.103079delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
DDoS attack detection methods play a very important role in protecting computer network security. However, the existing flow-based DDoS attack detection methods face the non-negligible time delay and are not general for different types of DDoS attacks at different rates. In order to fill this research gap, a fast all-packets-based DDoS attack detection approach (FAPDD) is proposed. The FAPDD firstly designs a new time series network graph model to effectively simplify the processing of network traffic handling compared with the flow-based detections. Furthermore, it is the first time that the directed Weisfeiler-Lehman graph kernel is built for measuring the divergence between the current network graph and the normalization network graphs. Due to the new graph model and kernel measurement method to judge network changes, the different types and rates of DDoS attacks can be especially detected. In addition, the dynamic threshold and freezing mechanism are constructed to display standard traffic changes and prevent the pollution of attack traffic to the standard network. Finally, a number of real DDoS attack datasets are applied to evaluate the effectiveness of the proposed method, as well as the overall time efficiency and detection effect. Compared with other methods, the FAPDD can better meet the real-time requirements and achieve good detection effects in different types of DDoS attacks with different attack rates.
Keywords:
Network security
Fast DDoS attack detection
Network graph based all packets
Directed weisfeiler-lehman graph kernel
Dynamic threshold mechanism
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Network and Computer Applications cover
Journal of Network and Computer Applications
IF:
8
Papers:
3.6K
Citations:
1.1W

Organization

Y
Yanshan University
Scholars:
1.7W
Papers: 1.1W
Citations: 1.3W