首页> 外文期刊>Journal of network and computer applications >Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence
【24h】

Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence

机译:分布式实时慢速通过人工智能攻击对加密流量的检测

获取原文
获取原文并翻译 | 示例

摘要

SlowDoS attacks exploit slow transmissions on application-level protocols like HTTP to carry out denial of service against web-servers. These attacks are difficult to be detected with traditional signature-based intrusion detection approaches, even more when the HTTP traffic is encrypted. To cope with this challenge, this paper describes and AI-based anomaly detection system for real-time detection of SlowDoS attacks over application-level encrypted traffic. Our system monitors in real-time the network traffic, analyzing, processing and aggregating packets into conversation flows, getting valuable features and statistics that are dynamically analyzed in streaming for AI-based anomaly detection. The distributed AI model running in Apache Spark-streaming, combines clustering analysis for anomaly detection, along with deep learning techniques to increase detection accuracy in those cases where clustering obtains ambiguous probabilities. The proposal has been implemented and validated in a real testbed, showing its feasibility, performance and accuracy for detecting in real-time different kinds of SlowDoS attacks over encrypted traffic. The achieved results are close to the optimal precision value with a success rate 98%, while the false negative rate takes a value below 0.5%.
机译:慢速攻击攻击在应用程序级协议上慢速传输,如HTTP以对Web服务器执行拒绝服务。通过基于传统的签名的入侵检测方法,难以检测这些攻击,甚至在HTTP流量加密时更多。为了应对这一挑战,本文介绍了基于AI的异常检测系统,用于对应用程序级加密流量的慢速攻击的实时检测。我们的系统在实时监视网络流量,分析,处理和聚合数据包到会话流程,获取在流动的基于异常检测中动态分析的有价值的特征和统计信息。在Apache Spark-Streaming中运行的分布式AI模型,组合了异常检测的聚类分析,以及深入学习技术,以提高聚类获得模糊概率的那些情况下的检测准确性。该提案已在实际测试平台实施和验证,显示其可行性,性能和准确性,用于检测实时不同类型的慢速攻击加密流量。实现的结果与成功率98%的最佳精度值接近,而假负速率达到0.5%的值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号