arXiv:2412.18990cs.CRcs.LG2024-12被引 25

用神经网络精准识别多种DDoS攻击,准确率达99.35%

Detection and classification of DDoS flooding attacks by machine learning method

  • 采用24-106-5结构神经网络,从流量特征中学习攻击模式
  • 分类任务中准确率99.35%,各类攻击识别率均超99%
  • 在近真实环境测试中仍保持95.05%准确率,适合安全系统部署

本研究提出一种基于神经网络的分布式拒绝服务(DDoS)攻击检测与分类方法,涵盖SYN Flood、ACK Flood、HTTP Flood和UDP Flood等典型攻击类型。使用包含正常流量及多种DDoS攻击的数据集,训练了一个24-106-5结构的神经网络模型。在分类任务中,模型达到99.35%的准确率(Accuracy)、99.32%的精确率(Precision)、99.54%的召回率(Recall)和0.99的F-score。所有主要攻击类型均被正确识别。进一步在实验室虚拟环境中生成真实流量进行测试,模型在近现实条件下实现95.05%的准确率,且各类攻击的F-score表现均衡。结果表明,神经网络是现代信息安全系统中检测DDoS攻击的有效工具。

原文摘要 · Abstract (English)

This study focuses on a method for detecting and classifying distributed denial of service (DDoS) attacks, such as SYN Flooding, ACK Flooding, HTTP Flooding, and UDP Flooding, using neural networks. Machine learning, particularly neural networks, is highly effective in detecting malicious traffic. A dataset containing normal traffic and various DDoS attacks was used to train a neural network model with a 24-106-5 architecture. The model achieved high Accuracy (99.35%), Precision (99.32%), Recall (99.54%), and F-score (0.99) in the classification task. All major attack types were correctly identified. The model was also further tested in the lab using virtual infrastructures to generate normal and DDoS traffic. The results showed that the model can accurately classify attacks under near-real-world conditions, demonstrating 95.05% accuracy and balanced F-score scores for all attack types. This confirms that neural networks are an effective tool for detecting DDoS attacks in modern information security systems.

DDoS检测神经网络网络安全流量分类

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。