Early Detection of Campus Network DDoS Attacks using Predictive Models.

GLOBECOM(2022)

引用 0|浏览8
暂无评分
摘要
DDoS attacks are one of the most threatening types of cyberattacks in the growing number of Internet-based services. In late 2016, a DDoS attack by IoT botnets of up to 1.5 Tbps caused many U.S. websites, including Twitter and Facebook, to become inaccessible. In addition, DDoS attacks are increasing every year, and the volume of attacks is expected to double in 2023, as compared to 2018. To protect services from DDoS attacks, much research has been done on IDS and has discussed methods with higher and more accurate detection. However, many studies use public benchmark datasets rather than real network traffic data, and as a result, their practicality is unknown. Threshold detection is already in place on our campus firewalls, but threshold detection cannot detect attacks until they actually come. In order to detect attacks before they actually come, we propose a system that uses machine learning to detect signs of attacks. In this study, we examined machine learning models for early detection of DDoS attacks using actual logs generated by servers at our campus, which contains about 400 million daily session logs. To ensure the feasibility and applicability of our proposed approach, we tested seven different machine learning methods, including GBDT, which has received much attention recently. A sliding window was also used for feature creation to improve the accuracy of predictive detection.
更多
查看译文
关键词
IDS, DDoS, Sequential analysis, Machine learning, Campus network, GBDT
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要