首页> 外文期刊>Journal of network and computer applications >A fast all-packets-based DDoS attack detection approach based on network graph and graph kernel
【24h】

A fast all-packets-based DDoS attack detection approach based on network graph and graph kernel

机译:基于网络图和图形内核的基于快速全数据包的DDOS攻击检测方法

获取原文
获取原文并翻译 | 示例

摘要

DDoS attack detection methods play a very important role in protecting computer network security. However, the existing flow-based DDoS attack detection methods face the non-negligible time delay and are not general for different types of DDoS attacks at different rates. In order to fill this research gap, a fast all-packets-based DDoS attack detection approach (FAPDD) is proposed. The FAPDD firstly designs a new time series network graph model to effectively simplify the processing of network traffic handling compared with the flow-based detections. Furthermore, it is the first time that the directed Weisfeiler-Lehman graph kernel is built for measuring the divergence between the current network graph and the normalization network graphs. Due to the new graph model and kernel measurement method to judge network changes, the different types and rates of DDoS attacks can be especially detected. In addition, the dynamic threshold and freezing mechanism are constructed to display standard traffic changes and prevent the pollution of attack traffic to the standard network. Finally, a number of real DDoS attack datasets are applied to evaluate the effectiveness of the proposed method, as well as the overall time efficiency and detection effect. Compared with other methods, the FAPDD can better meet the real-time requirements and achieve good detection effects in different types of DDoS attacks with different attack rates.
机译:DDOS攻击检测方法在保护计算机网络安全方面发挥着非常重要的作用。然而,现有的基于流动的DDOS攻击检测方法面临不可忽略的时间延迟,并且对于不同速率的不同类型的DDOS攻击是不可忽略的时间延迟。为了填补这一研究差距,提出了一种基于快速的全数据包的DDOS攻击检测方法(FAPDD)。 FAPDD首先设计了新的时序序列网络图模型,以有效简化网络流量处理的处理与基于流动的检测。此外,它是第一次采用指示的Weisfeiler-Lehman图内核,用于测量当前网络图和标准化网络图之间的分歧。由于新的图形模型和内核测量方法来判断网络变化,可以特别检测到不同类型和DDOS攻击的速率。此外,构造动态阈值和冷冻机制以显示标准流量变化,并防止攻击流量污染到标准网络。最后,应用了许多真实DDOS攻击数据集来评估所提出的方法的有效性,以及整个时间效率和检测效果。与其他方法相比,FAPDD可以更好地满足实时要求,并在不同类型的DDOS攻击中实现良好的检测效果,不同的攻击率。

著录项

  • 来源
    《Journal of network and computer applications》 |2021年第7期|103079.1-103079.18|共18页
  • 作者单位

    Yanshan Univ Dept Informat Sci & Engn 438W Hebei Ave Qinhuangdao 066001 Hebei Peoples R China|Hebei Key Lab Software Engn Qinhuangdao 066001 Hebei Peoples R China;

    Yanshan Univ Dept Informat Sci & Engn 438W Hebei Ave Qinhuangdao 066001 Hebei Peoples R China|Hebei Key Lab Software Engn Qinhuangdao 066001 Hebei Peoples R China;

    Yanshan Univ Dept Informat Sci & Engn 438W Hebei Ave Qinhuangdao 066001 Hebei Peoples R China|Hebei Key Lab Software Engn Qinhuangdao 066001 Hebei Peoples R China;

    Yanshan Univ Dept Informat Sci & Engn 438W Hebei Ave Qinhuangdao 066001 Hebei Peoples R China|Hebei Key Lab Software Engn Qinhuangdao 066001 Hebei Peoples R China;

    Tianjin Univ Sci & Technol Coll Artificial Intelligence Tianjin 300457 Peoples R China;

    First Middle Sch Qinhuangdao City Dept Informat Qinhuangdao 066001 Hebei Peoples R China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Network security; Fast DDoS attack detection; Network graph based all packets; Directed weisfeiler-lehman graph kernel; Dynamic threshold mechanism;

    机译:网络安全;快速DDOS攻击检测;基于网络图的所有数据包;定向Weisfeiler-Lehman图内核;动态阈值机制;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号