Detection of Unknown DDoS Attacks with Deep Learning and Gaussian Mixture Model

2021 
The development of the Internet has facilitated our daily communication. However, crises of security also rise at the same time. DDoS (Distributed Denial of Service) is one of the most destructive attacks among others. Nowadays, deep learning has been applied to intrusion detection and achieves a satisfactory detection rate. However, most of the related works suffer from the problem of Open-Set Recognition. No particular measure is taken for unknown attacks, which leads to the reduction of model generalization ability. The complexity of today's networks is continuously increasing. To maintain the generalization ability, it is necessary to find a method that can handle unknown traffic. This paper uses time series-based BI-LSTM (Bidirectional LSTM) for attack detection. It incorporates the concept of open-set recognition and the Gaussian mixture model for unknown attack detection. It then uses progressive learning to update the model to maintain the accuracy of the model. Experiment results reveal that the proposed scheme can detect unknown attacks with a detection probability close to 99%.
    • Correction
    • Source
    • Cite
    • Save
    • Machine Reading By IdeaReader
    8
    References
    0
    Citations
    NaN
    KQI
    []