SDN网络中基于联合熵与多重聚类的DDoS攻击检测  被引量:7

A Hybrid Method of Joint Entropy and Multiple Clustering Based DDoS Detection in SDN

在线阅读下载全文

作  者:王智 张浩[1,2] 顾建军 WANG Zhi;ZHANG Hao;Jason GU(Colleage of Computer and Date Science,Fuzhou University,Fuzhou 350116,China;Fujian Key Laboratory of Network Computing and Intelligent Information Processing,Fuzhou 350116,China;Department of Electrical and Computer Engineering,Dalhousie University,Halifax B3J1Z1,Canada)

机构地区:[1]福州大学计算机与大数据学院,福州350116 [2]福建省网络计算与智能信息处理重点实验室,福州350116 [3]达尔豪斯大学电气与计算机工程学院,哈利法克斯B3J1Z1

出  处:《信息网络安全》2023年第10期1-7,共7页Netinfo Security

基  金:国家自然科学基金[U1804263,U21A20472];国家留学基金[202006655011];福建省自然科学基金[2020J01130167,2021J01616,2021J01625]。

摘  要:软件定义网络(Software Defined Networking,SDN)作为一种新兴的网络范式,在带来便利性的同时也引入了更为严峻的分布式拒绝服务攻击(Distributed Denial of Service Attacks,DDoS)风险。现有的模型通常是使用机器学习模型来检测DDoS攻击,忽略了模型给SDN控制器带来的额外开销。为了更加高效且精确地检测DDoS攻击,文章采取了多级检测模块的方式,即一级模块通过计算当前流量窗口的联合熵快速检测异常,二级模块采用半监督模型,并使用特征选择、multi-training算法、多重聚类等技术,通过训练多个局部模型提高检测性能。与现有的其他模型相比,该模型在多个数据集上均表现更好,拥有更好的检测精度和泛化能力。Software Defined Networking(SDN),an emerging networking paradigm,has introduced more severe Distributed Denial of Service attacks(DDoS)along with convenience.Existing works typically use machine learning models to detect DDoS attacks,but ignore the additional overhead that models impose on SDN controllers.In order to detect DDoS attacks more efficiently and accurately,this paper adoptd a strategy of multi-level detection modules:the first-level module detectd suspicious traffic by calculating the joint entropy of the traffic in the current window;the second-level module used a semi-supervised model that used techniques such as feature selection,multi-training algorithms,and multiple clustering to improve detection performance by training multiple local models.Compared with other existing models,this model performs best on multiple data sets and has better detection accuracy and generalization ability.

关 键 词:软件定义网络 分布式拒绝服务攻击 半监督学习 统计学习 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象