arXiv:2604.16575cs.LGcs.AI2026-04中稿 · publication at Exp…

对比时序与结构特征,发现结构特征更适配DDoS检测

Evaluating Temporal and Structural Anomaly Detection Paradigms for DDoS Traffic

论文配图:Evaluating Temporal and Structural Anomaly Detection Paradigms for DDoS Traffic
图 1 · 摘自论文原文
  • 用自相关和主成分方差判断该用时序还是结构特征
  • 结构特征在两种数据集上表现均优于时序特征
  • 适合云原生5G中无监督异常检测的研究者

无监督异常检测广泛用于云原生5G网络中的分布式拒绝服务(DDoS)攻击检测,但多数研究假设固定流量表示形式,或仅使用时序特征,或仅使用结构特征,未验证哪种特征空间最匹配数据。本文提出一种轻量级决策框架,在训练前优先选择时序或结构特征,基于两个诊断指标:聚合流信号的滞后1阶自相关性和主成分分析的累积解释方差。当诊断结果不明确时,框架保留混合选项作为未来备用方案,而非直接采用。在两个统计特性不同的数据集上,使用Isolation Forest、One-Class SVM和KMeans进行实验,结果显示结构特征始终匹配或优于时序特征,且随着时序依赖性减弱,性能差距扩大。

原文摘要 · Abstract (English)

Unsupervised anomaly detection is widely used to detect Distributed Denial-of-Service (DDoS) attacks in cloud-native 5G networks, yet most studies assume a fixed traffic representation, either temporal or structural, without validating which feature space best matches the data. We propose a lightweight decision framework that prioritizes temporal or structural features before training, using two diagnostics: lag-1 autocorrelation of an aggregated flow signal and PCA cumulative explained variance. When the probes are inconclusive, the framework reserves a hybrid option as a future fallback rather than an empirically validated branch. Experiments on two statistically distinct datasets with Isolation Forest, One-Class SVM, and KMeans show that structural features consistently match or outperform temporal ones, with the performance gap widening as temporal dependence weakens.

DDoS检测异常检测特征选择

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。