使用元学习集成增强多类DDoS攻击识别
Enhanced Multi-Class DDoS Attack Identification using a Meta-Learning Ensemble
AI总结:
研究针对DDoS攻击类型识别问题,提出集成LSTM、KNN、RF模型并由逻辑回归元学习器合成输出的方法,所提模型在多类识别任务中准确率达96%,在SDN环境中也有良好表现,凸显元学习集成对DDoS威胁识别的价值。
AI中文摘要:
分布式拒绝服务(DDoS)攻击持续对网络可用性和安全构成重大威胁。许多检测系统专注于二元分类,而有效缓解通常需要识别DDoS攻击的具体类型。本文引入了一个强大的入侵检测框架,围绕高精度多类分类模型构建,旨在精确识别各种DDoS攻击类型。我们提出了一种集成架构,整合长短期记忆(LSTM)、K近邻(KNN)和随机森林(RF)模型,其输出由逻辑回归元学习器合成。在CIC-DDoS2019数据集上评估,我们提出的集成元学习模型在多类识别任务中达到96%的准确率,显著优于基线链模型。在软件定义网络(SDN)环境中使用Mininet和Ryu控制器进行集成和测试,证明了模型的实际适用性。我们的工作突出了元学习集成在细微DDoS威胁识别中的价值,为更具适应性和有效性的防御机制铺平了道路。
英文摘要:
Distributed Denial of Service (DDoS) attacks continue to pose significant threats to network availability and security. While many detection systems focus on binary classification (attack vs. benign), effective mitigation often requires identifying the specific type of DDoS attack. This paper introduces a robust intrusion detection framework centered around a high-accuracy, multi-class classification model designed to precisely identify various DDoS attack types. We propose an ensemble architecture integrating Long Short-Term Memory (LSTM), K-Nearest Neighbors (KNN), and Random Forest (RF) models, whose outputs are synthesized by a Logistic Regression meta-learner. This approach explicitly addresses the ambiguity often encountered when combining predictions from multiple independent classifiers. Evaluated on the CIC-DDoS2019 dataset, our proposed ensemble meta-learning model achieves 96% accuracy in the multi-class identification task, significantly outperforming a baseline chain model (combining individual binary classifiers), which reached 92% accuracy and suffered from high ambiguity. Furthermore, integration and testing within a Software-Defined Networking (SDN) environment using Mininet and the Ryu controller demonstrated the practical applicability of our model, achieving 93% accuracy in identifying DDoS types in the emulated network traffic. Our work highlights the value of meta-learning ensembles for nuanced DDoS threat identification, paving the way for more adaptive and effective defense mechanisms.