服务拒绝攻击
计算机科学
利用
僵尸网络
图形
有状态防火墙
分布式计算
数据挖掘
代表(政治)
计算机网络
人工智能
机器学习
计算机安全
理论计算机科学
交通工程
互联网
政治
万维网
政治学
法学
作者
Luca Barsellotti,Lorenzo De Marinis,F. Cugini,F. Paolucci
标识
DOI:10.1109/hpsr57248.2023.10147929
摘要
Distributed Denial of Service (DDoS) is one of the most common cyber-attacks and caused several damages in recent years. Such attacks can be executed either through the orchestration of multiple devices that synchronously send requests or through specific patterns followed by a single device to force the victim to keep resources overrun. It becomes crucial to develop robust techniques to promptly detect those two kinds of DDoS attacks and mitigate their consequences. Most of the existing Machine Learning (ML) methods are based on flow and traffic information aggregations expressed in the form of independent vectors of statistical data, ignoring topological connections. Few recent solutions try to exploit the structural information of the network to improve the classification results. In particular, Graph Neural Network (GNN) based models can process traffic-level or flow-level relationships, represented as graphs, to detect malicious patterns.The objective of this paper is to combine the relationships at both the traffic-level and the flow-level by developing a two-level hierarchical graph representation and a GNN model able to process it, maximizing the information brought by the traffic structure and removing the necessity of stateful features. Experiments on the CIC-IDS2017 dataset show that the performances are comparable to the state-of-the-art solutions even using only the traffic structure.
科研通智能强力驱动
Strongly Powered by AbleSci AI