arXiv:2410.18380cs.LGcs.CR2024-10被引 5

用少量标注数据提升云环境下的DDoS检测精度

Harnessing PU Learning for Enhanced Cloud-based DDoS Detection: A Comparative Analysis

  • 基于正例-未标记学习,仅用部分标注数据训练模型
  • XGBoost和随机森林F1超过98%,表现最佳
  • 适合标签稀缺的云安全场景,可推广至多云环境

本文研究了正例-未标记(PU)学习在云环境中增强分布式拒绝服务(DDoS)检测的应用。利用《BCCC-cPacket-Cloud-DDoS-2024》数据集,我们采用XGBoost、随机森林、支持向量机和朴素贝叶斯四种机器学习算法实现PU学习。实验结果表明,集成方法表现更优,其中XGBoost与随机森林的F₁分数均超过98%。通过F₁分数、ROC AUC、召回率和精确率等指标量化各方法效能。本研究弥合了PU学习与云环境异常检测之间的差距,为多云环境下上下文感知的DDoS检测提供了基础。研究结果凸显了在标注数据有限情况下,PU学习在构建更鲁棒、自适应的云安全机制中的潜力。

原文摘要 · Abstract (English)

This paper explores the application of Positive-Unlabeled (PU) learning for enhanced Distributed Denial-of-Service (DDoS) detection in cloud environments. Utilizing the $\texttt{BCCC-cPacket-Cloud-DDoS-2024}$ dataset, we implement PU learning with four machine learning algorithms: XGBoost, Random Forest, Support Vector Machine, and Naïve Bayes. Our results demonstrate the superior performance of ensemble methods, with XGBoost and Random Forest achieving $F_{1}$ scores exceeding 98%. We quantify the efficacy of each approach using metrics including $F_{1}$ score, ROC AUC, Recall, and Precision. This study bridges the gap between PU learning and cloud-based anomaly detection, providing a foundation for addressing Context-Aware DDoS Detection in multi-cloud environments. Our findings highlight the potential of PU learning in scenarios with limited labeled data, offering valuable insights for developing more robust and adaptive cloud security mechanisms.

DDoS检测PU学习云安全集成学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。