发表机构
Middle Tennessee State University; C2C Tech; New Jersey Institute of Technology(中田纳西州立大学; C2C科技公司; 新泽西理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出GraphGAN模型,通过构建流量的k近邻图、对抗生成少数类样本及GCN分类,在四个基准数据集上实现了更优的DDoS攻击检测性能,尤其适用于数据稀缺场景。
AI 中文摘要
分布式拒绝服务(DDoS)攻击威胁网络可用性,需要一种认知检测过程,该过程在严重的类别不平衡和非平稳条件下感知流量、推断意图并支持自适应响应。本文提出一种基于图的生成对抗网络(GraphGAN)作为该任务的认知检测引擎。GraphGAN捕获流量流之间的关系结构,同时通过生成合成样本解决类别不平衡问题。使用滑动窗口将顺序流量转换为k近邻图,以保留流量间的特征相似性和时间依赖关系。生成器学习DDoS攻击的分布以合成真实的少数类样本,而基于图卷积网络(GCN)的判别器区分真实和合成图数据。在平衡数据集上训练的单独GCN分类器执行最终检测决策。对四个基准数据集的评估显示,与最先进方法相比,GraphGAN在准确率、精确率和召回率上表现更优,尤其在数据稀缺场景中。通过整合时间图构建、对抗增强和GCN分类,GraphGAN有效建模协同攻击行为并缓解类别不平衡,为数据受限环境中的入侵检测提供了鲁棒且感知拓扑的解决方案。
英文摘要
Distributed Denial-of-Service (DDoS) attacks threaten network availability, requiring a cognitive detection process that senses traffic, infers intent, and supports an adaptive response under severe class imbalance and non-stationary conditions. This paper proposes a Graph-based Generative Adversarial Network (GraphGAN) that serves as the cognitive detection engine for this task. GraphGAN captures the relational structure among traffic flows while addressing imbalance through adversarial generation of synthetic samples. Sequential flows are converted into $k$-nearest neighbor graphs using sliding windows to preserve feature-similarity and temporal dependencies among flows. The generator learns the distribution of DDoS attacks to synthesize realistic minority samples, while a Graph Convolutional Network (GCN)-based discriminator distinguishes real from synthetic graph data. A separate GCN classifier, trained on the balanced dataset, performs the final detection decision. Evaluations on four benchmark datasets show that GraphGAN achieves superior accuracy, precision, and recall compared to state-of-the-art approaches, particularly in data-scarce scenarios. By integrating temporal graph construction, adversarial augmentation, and GCN classification, GraphGAN effectively models coordinated attack behaviors and mitigates class imbalance, providing a robust and topology-aware solution for intrusion detection in data-constrained environments.