A two-stage detection system of DDoS attacks in SDN using a trigger with multiple features and self-adaptive thresholds

研究成果: 書籍/レポート タイプへの寄稿会議への寄与

4 被引用数 (Scopus)

抄録

Software-defined networking (SDN) has received a lot of attention in academia and industry in recent years, and DDoS attacks are still one of the most dangerous threats. As cyberattacks become more sophisticated, detection systems also become more complex and computationally intensive, for example, Deep Learning-based detection. Against this background, two-stage detection is proposed, in which a trigger is introduced before the complex detection being invoked. That is, the heavy detection module is called only when the requirements in the trigger are satisfied. Clearly, the triggering mechanism plays an important role in such detection systems as it determines when the second stage is invoked. Most of the existing relevant studies utilize one feature and a fixed threshold. However, it is not easy to predefine suitable thresholds in practice, and one feature is often not sufficient for effective trigger conditions that have a significant impact on detection performance of the whole detection system. The latest related work uses dynamic thresholding, but still only one feature, and the threshold adaptation mechanism is too simplistic, which make it too difficult to be used in real applications. Moreover, the performance of the approach in the most of related works are verified only using simulated data. In this study, we increase the number of features and optimized the threshold adjustment method in the trigger. In addition, in the detection module of the second stage, six features carefully determined from traffic bytes, packets, and IP addresses are used. The performance of the proposal is demonstrated in a simulated SDN environment using a public dataset. The experimental results indicate that the times of calling the computationally intensive detection module is significantly reduced, while at the same time the detection performance of the overall system is not degraded.

本文言語英語
ホスト出版物のタイトルProceedings of the 2023 17th International Conference on Ubiquitous Information Management and Communication, IMCOM 2023
編集者Sukhan Lee, Hyunseung Choo, Roslan Ismail
出版社Institute of Electrical and Electronics Engineers Inc.
ISBN(電子版)9781665453486
DOI
出版ステータス出版済み - 2023
イベント17th International Conference on Ubiquitous Information Management and Communication, IMCOM 2023 - Seoul, 韓国
継続期間: 1月 3 20231月 5 2023

出版物シリーズ

名前Proceedings of the 2023 17th International Conference on Ubiquitous Information Management and Communication, IMCOM 2023

会議

会議17th International Conference on Ubiquitous Information Management and Communication, IMCOM 2023
国/地域韓国
CitySeoul
Period1/3/231/5/23

!!!All Science Journal Classification (ASJC) codes

  • 安全性、リスク、信頼性、品質管理
  • 数値解析
  • 健康情報学
  • 人工知能
  • コンピュータ ネットワークおよび通信
  • コンピュータ サイエンスの応用
  • 情報システム
  • 情報システムおよび情報管理

フィンガープリント

「A two-stage detection system of DDoS attacks in SDN using a trigger with multiple features and self-adaptive thresholds」の研究トピックを掘り下げます。これらがまとまってユニークなフィンガープリントを構成します。

引用スタイル