Abdelkader Dairi, Belkacem Khaldi, F. Harrou, Ying Sun
{"title":"DDOS attacks detection based on attention-deep learning and local outlier factor","authors":"Abdelkader Dairi, Belkacem Khaldi, F. Harrou, Ying Sun","doi":"10.1109/FMEC57183.2022.10062705","DOIUrl":null,"url":null,"abstract":"One of the most significant security concerns confronting network technology is the detection of distributed denial of service (DDOS). This paper introduces a semi-supervised data-driven approach to the detection of DDOS attacks. The proposed method employs normal events data without labeling to train the detection model. Specifically, this approach introduces an improved autoencoder (AE) model by incorporating a Gated Recurrent Unit (GRU) based on the attention mechanism (AM) at the encoder and decoder sides of the AE model. GRU enhances the AE's ability to learn temporal dependencies, and the AM enables the selection of relevant features. For DDOS attacks detection, the local outlier factor (LOF) anomaly detection algorithm is applied to extracted features from the improved AE model. The performance of the proposed approach has been verified using DDOS publically available datasets.","PeriodicalId":129184,"journal":{"name":"2022 Seventh International Conference on Fog and Mobile Edge Computing (FMEC)","volume":"136 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-12-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 Seventh International Conference on Fog and Mobile Edge Computing (FMEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FMEC57183.2022.10062705","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
One of the most significant security concerns confronting network technology is the detection of distributed denial of service (DDOS). This paper introduces a semi-supervised data-driven approach to the detection of DDOS attacks. The proposed method employs normal events data without labeling to train the detection model. Specifically, this approach introduces an improved autoencoder (AE) model by incorporating a Gated Recurrent Unit (GRU) based on the attention mechanism (AM) at the encoder and decoder sides of the AE model. GRU enhances the AE's ability to learn temporal dependencies, and the AM enables the selection of relevant features. For DDOS attacks detection, the local outlier factor (LOF) anomaly detection algorithm is applied to extracted features from the improved AE model. The performance of the proposed approach has been verified using DDOS publically available datasets.