当时间与空间相遇:面向SDN中自适应DDoS检测的熵整合与动态阈值
When Time Meets Space: Entropy Integration and Dynamic Threshold for Adaptive DDoS Detection in SDN
AI总结:
针对SDN中基于熵的DDoS检测易受IoT合法流量波动影响的问题,提出轻量级时空熵检测器,结合动态阈值实现高检测性能,支持资源受限场景部署。
AI中文摘要:
软件定义网络(SDN)中基于熵的分布式拒绝服务(DDoS)检测通常依赖于空间流量分布以及静态或松散自适应的阈值,这使其在物联网(IoT)环境中容易受到合法流量波动的影响。本文提出一种轻量级时空熵DDoS检测器:空间熵由动态选择的流量属性对计算得到,时间熵则捕获数据包到达间隔的随机性;将两个归一化的熵度量融合为统一指标,采用受约束的二阶指数加权移动平均(Exponentially Weighted Moving Average)阈值进行评估,该阈值可同时跟踪熵的趋势与波动性;为防止受攻击污染的观测值偏置阈值自适应,仅对被分类为正常的窗口执行阈值更新。测试平台结果显示,该方法的召回率为99.26%,F1分数为0.9737,误报率为3.2%,比仅使用空间熵的方法降低了41.74%;在CICDDoS2019数据集上,该方法的误报率为0,且与基于机器学习的方法相比具有竞争力;每个窗口的核心处理耗时为3.95毫秒,系统范围内CPU利用率为11.65%,支持资源受限的边缘与物联网部署。
英文摘要:
Entropy-based Distributed Denial of Service (DDoS) detection in Software-Defined Networking (SDN) commonly relies on spatial traffic distributions and static or loosely adaptive thresholds, making it vulnerable to legitimate traffic fluctuations in Internet of Things (IoT) environments. This paper proposes a lightweight spatiotemporal entropy-based detector for DDoS attacks. Spatial entropy is computed from dynamically selected traffic attribute pairs, while temporal entropy captures the randomness of packet inter-arrival times. The two normalized entropy measures are fused into a unified indicator and evaluated using a constrained second-order Exponentially Weighted Moving Average threshold that jointly tracks entropy trend and volatility. To prevent attack-contaminated observations from biasing threshold adaptation, threshold updates are performed only for windows classified as normal. Testbed results show 99.26% recall, a 0.9737 F1-score, and a 3.2% false positive rate (41.74% below that of spatial entropy alone). On CICDDoS2019, the method achieves an FPR of 0 and remains competitive with machine-learning-based methods. It requires 3.95 ms of core processing per window and 11.65% system-wide CPU utilization, supporting resource-constrained edge and IoT deployment.