Cargando…

Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network

Distributed Denial of Service (DDoS) attack is one of the top cyber threats. As a kind of application layer DDoS attack, Challenge Collapsar (CC) attack has become a real headache for defenders. However, there are many researches on DDoS attack, but few on CC attack. The related works on CC attack e...

Descripción completa

Detalles Bibliográficos
Autores principales: Liu, Xiaolin, Li, Shuhao, Zhang, Yongzheng, Yun, Xiaochun, Li, Jia
Formato: Online Artículo Texto
Lenguaje:English
Publicado: 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7304042/
http://dx.doi.org/10.1007/978-3-030-50420-5_21
_version_ 1783548186679312384
author Liu, Xiaolin
Li, Shuhao
Zhang, Yongzheng
Yun, Xiaochun
Li, Jia
author_facet Liu, Xiaolin
Li, Shuhao
Zhang, Yongzheng
Yun, Xiaochun
Li, Jia
author_sort Liu, Xiaolin
collection PubMed
description Distributed Denial of Service (DDoS) attack is one of the top cyber threats. As a kind of application layer DDoS attack, Challenge Collapsar (CC) attack has become a real headache for defenders. However, there are many researches on DDoS attack, but few on CC attack. The related works on CC attack employ rule-based and machine learning-based models, and just validate their models on the outdated public datasets. These works appear to lag behind once the attack pattern changes. In this paper, we present a model based on packet Field Differentiated Preprocessing and Deep neural network (FDPD) to address this problem. Besides, we collected a fresh dataset which contains 7.92 million packets from real network traffic to train and validate FDPD model. The experimental results show that the accuracy of this model reaches 98.55%, the [Formula: see text] value reaches 98.59%, which is 3% higher than the previous models (SVM and Random Forest-based detection model), and the training speed is increased by 17 times in the same environment. It proved that the proposed model can help defenders improve the efficiency of detecting CC attack.
format Online
Article
Text
id pubmed-7304042
institution National Center for Biotechnology Information
language English
publishDate 2020
record_format MEDLINE/PubMed
spelling pubmed-73040422020-06-19 Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network Liu, Xiaolin Li, Shuhao Zhang, Yongzheng Yun, Xiaochun Li, Jia Computational Science – ICCS 2020 Article Distributed Denial of Service (DDoS) attack is one of the top cyber threats. As a kind of application layer DDoS attack, Challenge Collapsar (CC) attack has become a real headache for defenders. However, there are many researches on DDoS attack, but few on CC attack. The related works on CC attack employ rule-based and machine learning-based models, and just validate their models on the outdated public datasets. These works appear to lag behind once the attack pattern changes. In this paper, we present a model based on packet Field Differentiated Preprocessing and Deep neural network (FDPD) to address this problem. Besides, we collected a fresh dataset which contains 7.92 million packets from real network traffic to train and validate FDPD model. The experimental results show that the accuracy of this model reaches 98.55%, the [Formula: see text] value reaches 98.59%, which is 3% higher than the previous models (SVM and Random Forest-based detection model), and the training speed is increased by 17 times in the same environment. It proved that the proposed model can help defenders improve the efficiency of detecting CC attack. 2020-05-22 /pmc/articles/PMC7304042/ http://dx.doi.org/10.1007/978-3-030-50420-5_21 Text en © Springer Nature Switzerland AG 2020 This article is made available via the PMC Open Access Subset for unrestricted research re-use and secondary analysis in any form or by any means with acknowledgement of the original source. These permissions are granted for the duration of the World Health Organization (WHO) declaration of COVID-19 as a global pandemic.
spellingShingle Article
Liu, Xiaolin
Li, Shuhao
Zhang, Yongzheng
Yun, Xiaochun
Li, Jia
Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network
title Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network
title_full Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network
title_fullStr Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network
title_full_unstemmed Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network
title_short Challenge Collapsar (CC) Attack Traffic Detection Based on Packet Field Differentiated Preprocessing and Deep Neural Network
title_sort challenge collapsar (cc) attack traffic detection based on packet field differentiated preprocessing and deep neural network
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7304042/
http://dx.doi.org/10.1007/978-3-030-50420-5_21
work_keys_str_mv AT liuxiaolin challengecollapsarccattacktrafficdetectionbasedonpacketfielddifferentiatedpreprocessinganddeepneuralnetwork
AT lishuhao challengecollapsarccattacktrafficdetectionbasedonpacketfielddifferentiatedpreprocessinganddeepneuralnetwork
AT zhangyongzheng challengecollapsarccattacktrafficdetectionbasedonpacketfielddifferentiatedpreprocessinganddeepneuralnetwork
AT yunxiaochun challengecollapsarccattacktrafficdetectionbasedonpacketfielddifferentiatedpreprocessinganddeepneuralnetwork
AT lijia challengecollapsarccattacktrafficdetectionbasedonpacketfielddifferentiatedpreprocessinganddeepneuralnetwork