用随机森林+分层交叉验证,0.24秒精准识别车载网络的SYN洪水攻击
Random Forest Stratified K-Fold Cross Validation on SYN DoS Attack SD-IoV
- 采用分层K折交叉验证优化随机森林模型
- 各项指标平均达0.999998,检测仅需0.24秒
- 适合车联网安全防护与实时攻击检测场景
针对软件定义车联网(SD-IoV)中普遍存在的TCP SYN洪水攻击问题,本研究致力于提升车辆通信系统中的网络安全性能。通过预处理包含SYN攻击实例的数据集,结合特征缩放与标签编码技术,并应用分层K折交叉验证,优化随机森林分类器在准确率、精确率、召回率和F1分数等关键指标上的表现。实验结果表明,经过调优的随机森林模型(配置为20个估计器,深度为10)在所有评估指标上均达到平均0.999998的精度,且对SYN DoS攻击的检测时间仅为0.24秒。该方法显著提升了检测准确性与响应速度,为应对车载网络中的此类攻击提供了高效可靠的解决方案,兼顾了网络效率与系统可靠性。
原文摘要 · Abstract (English)
In response to the prevalent concern of TCP SYN flood attacks within the context of Software-Defined Internet of Vehicles (SD-IoV), this study addresses the significant challenge of network security in rapidly evolving vehicular communication systems. This research focuses on optimizing a Random Forest Classifier model to achieve maximum accuracy and minimal detection time, thereby enhancing vehicular network security. The methodology involves preprocessing a dataset containing SYN attack instances, employing feature scaling and label encoding techniques, and applying Stratified K-Fold cross-validation to target key metrics such as accuracy, precision, recall, and F1-score. This research achieved an average value of 0.999998 for all metrics with a SYN DoS attack detection time of 0.24 seconds. Results show that the fine-tuned Random Forest model, configured with 20 estimators and a depth of 10, effectively differentiates between normal and malicious traffic with high accuracy and minimal detection time, which is crucial for SD-IoV networks. This approach marks a significant advancement and introduces a state-of-the-art algorithm in detecting SYN flood attacks, combining high accuracy with minimal detection time. It contributes to vehicular network security by providing a robust solution against TCP SYN flood attacks while maintaining network efficiency and reliability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。