DDoS Attack Detection Combining Time Series-based Multi-dimensional Sketch and Machine Learning

Yanchao Sun, Yuanfeng Han, Yue Zhang*, Mingsong Chen, Shui Yu, Yimin Xu

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Machine learning-based DDoS attack detection methods are mostly implemented at the packet level with expensive computational time costs, and the space cost of those sketch-based detection methods is uncertain. This paper proposes a two-stage DDoS attack detection algorithm combining time series-based multi-dimensional sketch and machine learning technologies. Besides packet numbers, total lengths, and protocols, we construct the time series-based multi-dimensional sketch with limited space cost by storing elephant flow information with the Boyer-Moore voting algorithm and hash index. For the first stage of detection, we adopt CNN to generate sketch-level DDoS attack detection results from the time series-based multi-dimensional sketch. For the sketch with potential DDoS attacks, we use RNN with flow information extracted from the sketch to implement flow-level DDoS attack detection in the second stage. Experimental results show that not only is the detection accuracy of our proposed method much close to that of packet-level DDoS attack detection methods based on machine learning, but also the computational time cost of our method is much smaller with regard to the number of machine learning operations.

Original languageEnglish
Title of host publicationAPNOMS 2022 - 23rd Asia-Pacific Network Operations and Management Symposium
Subtitle of host publicationData-Driven Intelligent Management in the Era of beyond 5G
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9784885523397
DOIs
StatePublished - 2022
Event23rd Asia-Pacific Network Operations and Management Symposium, APNOMS 2022 - Takamatsu, Japan
Duration: 28 Sep 202230 Sep 2022

Publication series

NameAPNOMS 2022 - 23rd Asia-Pacific Network Operations and Management Symposium: Data-Driven Intelligent Management in the Era of beyond 5G

Conference

Conference23rd Asia-Pacific Network Operations and Management Symposium, APNOMS 2022
Country/TerritoryJapan
CityTakamatsu
Period28/09/2230/09/22

Keywords

  • DDos Attack Detection
  • Machine Learning
  • The Boyer-Moore Voting Algorithm
  • Time Series-based Multi-dimensional Sketch

Fingerprint

Dive into the research topics of 'DDoS Attack Detection Combining Time Series-based Multi-dimensional Sketch and Machine Learning'. Together they form a unique fingerprint.

Cite this