首页> 外文期刊>Network and Service Management, IEEE Transactions on >DDoS Detection System: Using a Set of Classification Algorithms Controlled by Fuzzy Logic System in Apache Spark
【24h】

DDoS Detection System: Using a Set of Classification Algorithms Controlled by Fuzzy Logic System in Apache Spark

机译:DDOS检测系统:使用Apache Spark中的模糊逻辑系统控制的一组分类算法

获取原文
获取原文并翻译 | 示例

摘要

Distributed denial of service (DDoS) attacks are a major security threat against the availability of conventional or cloud computing resources. Numerous DDoS attacks, which have been launched against various organizations in the last decade, have had a direct impact on both vendors and users. Many researchers have attempted to tackle the security threat of DDoS attacks by combining classification algorithms with distributed computing. However, their solutions are static in terms of the classification algorithms used. In fact, current DDoS attacks have become so dynamic and sophisticated that they are able to pass the detection system thereby making it difficult for static solutions to detect. In this paper, we propose a dynamic DDoS attack detection system based on three main components: 1) classification algorithms; 2) a distributed system; and 3) a fuzzy logic system. Our framework uses fuzzy logic to dynamically select an algorithm from a set of prepared classification algorithms that detect different DDoS patterns. Out of the many candidate classification algorithms, we use Naive Bayes, Decision Tree (Entropy), Decision Tree (Gini), and Random Forest as candidate algorithms. We have evaluated the performance of classification algorithms and their delays and validated the fuzzy logic system. We have also evaluated the effectiveness of the distributed system and its impact on the classification algorithms delay. The results show that there is a trade-off between the utilized classification algorithms' accuracies and their delays. We observe that the fuzzy logic system can effectively select the right classification algorithm based on the traffic status.
机译:分布式拒绝服务(DDOS)攻击是针对传统或云计算资源的可用性的主要安全威胁。众多DDOS攻击已在过去十年中对各种组织启动,对供应商和用户进行了直接影响。许多研究人员试图通过将分类算法与分布式计算组合来解决DDOS攻击的安全威胁。但是,它们的解决方案是在所使用的分类算法方面的静态。事实上,当前的DDOS攻击已经变得如此动态和复杂,以至于它们能够通过检测系统,从而使静态解决方案难以检测。在本文中,我们提出了一种基于三个主要组成部分的动态DDOS攻击检测系统:1)分类算法; 2)分布式系统; 3)模糊逻辑系统。我们的框架使用模糊逻辑从检测不同DDOS模式的一组准备的分类算法动态选择算法。除了众多候选分类算法中,我们使用天真的贝父,决策树(熵),决策树(GINI)和随机森林作为候选算法。我们评估了分类算法及其延迟的性能,并验证了模糊逻辑系统。我们还评估了分布式系统的有效性及其对分类算法延迟的影响。结果表明,利用分类算法的准确性和延误之间存在权衡。我们观察到模糊逻辑系统可以基于交通状态有效选择正确的分类算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号