DDoS attack detection in SDN: Enhancing entropy‐based detection with machine learning

服务拒绝攻击 计算机科学 人工智能 机器学习 计算机安全 操作系统 互联网
作者
Marcos J. Santos‐Neto,Jacir L. Bordim,Eduardo Alchieri,Edison Ishikawa
出处
期刊:Concurrency and Computation: Practice and Experience [Wiley]
卷期号:36 (11) 被引量:5
标识
DOI:10.1002/cpe.8021
摘要

Summary Software defined network (SDN) has emerged as a new paradigm in terms of network architecture, providing flexibility, agility, and programmability to network management. These benefits boosted the SDN adoption, bringing new challenges mainly related to security, in particular, those related to Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks. The detection, prevention, and mitigation of these attacks are important since they can affect the entire network. Many current security measures use statistical techniques, as entropy, or machine learning (ML) algorithms to detect DoS and DDoS attacks. While the definition of a threshold to determine whether a traffic is an attack is not trivial in statistical techniques, ML solutions may provide better accuracy but require considerable computational resources and time to converge to a model able to detect these attacks. Trying to circumvent these limitations, current hybrid approaches either use the results from entropy as input in ML algorithms (EntropyML) or use entropy as a filter and ML algorithms to identify attacks. This work goes one step ahead and combines these techniques in a three‐step approach (EntropyMLEntropy), called ML‐Entropy, which inherits the intelligence of ML algorithms to adjust the threshold used by entropy. The proposed solution was implemented and evaluated in two datasets, the well‐known synthetic DARPA dataset and a dataset composed by traffic collected from a real‐corporate environment. Experimental results show that, in general, ML‐Entropy presents an accuracy above 99%, similar to support vector machine (SVC) and random forest (RF) algorithms, being able to converge to a detection model up to and faster than RF and SVC, respectively.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
bkagyin应助jilgy采纳,获得10
刚刚
1秒前
奇奇完成签到,获得积分10
2秒前
堪如南发布了新的文献求助10
3秒前
勤恳马里奥应助bad boy采纳,获得10
5秒前
zou发布了新的文献求助10
5秒前
6秒前
勤恳马里奥应助健壮听筠采纳,获得10
6秒前
向阳花小朵完成签到,获得积分10
6秒前
7秒前
bc应助堪如南采纳,获得20
10秒前
万能图书馆应助堪如南采纳,获得10
10秒前
桐桐应助纯真野狼采纳,获得10
11秒前
11秒前
栗栗栗知发布了新的文献求助10
11秒前
ZX801完成签到 ,获得积分10
12秒前
sincerely完成签到,获得积分20
14秒前
Singularity应助拼搏的人达采纳,获得10
15秒前
ape完成签到,获得积分20
15秒前
jilgy发布了新的文献求助10
16秒前
17秒前
17秒前
动听山蝶发布了新的文献求助10
18秒前
火星上的凝安完成签到,获得积分10
18秒前
wzyttxs完成签到,获得积分20
18秒前
19秒前
寒冷的凝旋完成签到,获得积分10
19秒前
YOYOYO应助上官从波采纳,获得30
20秒前
20秒前
LamChem发布了新的文献求助10
21秒前
21秒前
22秒前
22秒前
22秒前
脑洞疼应助小马sad采纳,获得10
23秒前
qwer发布了新的文献求助10
25秒前
JHM发布了新的文献求助10
26秒前
欢欢完成签到,获得积分10
26秒前
26秒前
Lizhenzhen123完成签到,获得积分10
26秒前
高分求助中
Les Mantodea de Guyane Insecta, Polyneoptera 2500
Nucleophilic substitution in azasydnone-modified dinitroanisoles 500
Technologies supporting mass customization of apparel: A pilot project 450
Brain and Heart The Triumphs and Struggles of a Pediatric Neurosurgeon 400
Cybersecurity Blueprint – Transitioning to Tech 400
Mixing the elements of mass customisation 400
Периодизация спортивной тренировки. Общая теория и её практическое применение 310
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3783709
求助须知:如何正确求助?哪些是违规求助? 3328883
关于积分的说明 10239058
捐赠科研通 3044346
什么是DOI,文献DOI怎么找? 1670946
邀请新用户注册赠送积分活动 799982
科研通“疑难数据库(出版商)”最低求助积分说明 759171