用AI识别和缓解分布式拒绝服务攻击,系统梳理最新方法与数据挑战
Detecting and Mitigating DDoS Attacks with AI: A Survey
- 基于人工分类与AI生成树状图的双重分类体系,解决攻击类型混淆问题
- 分析多种数据集格式及对抗训练、数据增强对模型性能的关键影响
- 覆盖检测到缓解的全链条技术,适合安全研究者和防御系统开发者参考
分布式拒绝服务攻击是当前网络安全的重要研究课题。近年来,研究重心从静态规则防御转向基于人工智能的检测与缓解方法。本文全面综述多个关键方向:首先深入讨论最先进的AI检测方法,提出基于人工专家层级与AI生成树状图的双重分类体系,有效解决了DDoS攻击分类中的模糊性问题;其次系统分析现有数据集,涵盖数据格式选择及其在训练AI检测模型中的作用,强调对抗训练与数据增强的重要性;此外,还对基于AI的缓解技术进行了综述;最后,提出多个未解的开放研究方向。
原文摘要 · Abstract (English)
Distributed Denial of Service attacks represent an active cybersecurity research problem. Recent research shifted from static rule-based defenses towards AI-based detection and mitigation. This comprehensive survey covers several key topics. Preeminently, state-of-the-art AI detection methods are discussed. An in-depth taxonomy based on manual expert hierarchies and an AI-generated dendrogram are provided, thus settling DDoS categorization ambiguities. An important discussion on available datasets follows, covering data format options and their role in training AI detection methods together with adversarial training and examples augmentation. Beyond detection, AI based mitigation techniques are surveyed as well. Finally, multiple open research directions are proposed.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。