arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

自主网络防御:基于机器学习的软件定义网络实时攻击检测与缓解

Autonomous Cyber Defense: Real-Time Attack Detection and Mitigation in Software-Defined Networks Using Machine Learning

Alexandre Amaral, Fernando Moro, Ana Malheiro

arXiv 2608.22075首次发表:更新:

发表机构

Instituto Federal Catarinense(圣卡塔琳娜联邦学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对当前网络攻击速度远超人工响应能力的问题,提出基于机器学习的SDN自主防御系统,通过NDC和IPS模块实现实时攻击检测与自动阻断,SYN洪水攻击响应时间达21秒。

AI 中文摘要

当前攻击者的行动速度远超人工响应流程的处理能力。2025年,电子犯罪的平均突破时间(即从初始访问到首次横向移动至另一主机的间隔)降至29分钟,较上年提速65%;观测到的最快突破仅耗时27秒,且在一起入侵事件中,数据外泄在初始访问后的4分钟内便已启动。本研究提出一种基于机器学习的系统,可实时监控软件定义网络(SDN)中的网络流量、诊断攻击并自动应用对策,使检测与响应不再依赖人工干预。该系统包含两个模块:网络数据集创建(NDC)模块,负责收集IP流、对其进行预处理与聚合以构建训练数据集;入侵防御系统(IPS)模块,可自动完成不同算法的建模、训练与评估,并向SDN控制器触发阻断操作。针对SYN洪水拒绝服务攻击的案例研究显示,该系统可在21秒内检测并阻断攻击,无需人工干预,其响应时间与当前突破时间所设定的时间窗口相匹配。

英文摘要

Autonomous response has evolved into a timing-critical challenge rather than solely a matter of detection accuracy. In recent intrusions, the interval between initial access and the first lateral movement has been observed to be as short as 27 seconds, a window that precludes any human-in-the-loop workflow. This paper presents a closed-loop framework that detects and blocks attacks in software-defined networks without operator involvement, evaluating its performance against this stringent temporal constraint rather than relying exclusively on detection accuracy. An automated data pipeline collects IP flows and aggregates them into labeled training data, while a prevention module selects and trains candidate classifiers and issues blocking rules directly to the SDN controller. In a SYN flooding denial of service case study, the deployed K-Nearest Neighbors classifier achieved an F1 score of 96.7% and the cycle from flow availability to enforced block completed in 21 seconds, below the fastest breakout time reported to date.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑