发表机构
Islamic University of Lebanon; Lebanese University; Polytechnic Institute of Paris; Télécom Paris(黎巴嫩伊斯兰大学; 黎巴嫩大学; 巴黎综合理工学院; 巴黎电信学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出一种结合WGAN-GP生成对抗网络与多种机器学习模型的DDoS检测框架,通过生成对抗流量增强模型鲁棒性,实验证明能显著提升对未知对抗攻击的检测能力。
AI 中文摘要
在线服务的可用性和一致性仍然因分布式拒绝服务(DDoS)攻击而面临脆弱性。这些攻击正在通过采用更复杂的策略来规避传统的网络安全系统。尽管机器学习模型在检测DDoS流量方面具有有效性,但针对性的对抗性攻击会降低其分类准确性。本工作提出了一种鲁棒检测框架,该框架将生成对抗建模与先进的机器学习模型相结合。我们使用CICDDoS2019数据集训练了随机森林、深度神经集成和基于Transformer的模型,以建立框架的基线性能。为了增强模型的防御能力,我们使用带梯度惩罚的Wasserstein生成对抗网络(WGAN-GP)生成了模拟潜在规避尝试和对抗性流量的合成对抗流。然后,我们将生成的流量与良性流量和恶意流量相结合,构建混合数据集,以训练模型学习更具泛化性的决策边界。实验结果表明,所提出的方法显著提高了检测准确性和鲁棒性,尤其是在面对未见过的对抗性流量时。我们还使用真实世界生成的流量测试了所设计的框架,这证明了其在实际场景中的能力。本工作引入的针对对抗性DDoS攻击的可扩展且高效的解决方案,为构建更具鲁棒性和适应性的网络防御系统铺平了道路,该系统将生成对抗增强与学习模型的最新进展相结合。
英文摘要
The availability and consistency of online services remain vulnerable due to Distributed Denial of Service (DDoS) attacks. These attacks are evolving by adopting more complex strategies to evade traditional network security systems. Despite the effectiveness of machine learning models in detecting DDoS traffic, targeted adversarial attacks can degrade their classification accuracy. This work proposes a robust detection framework that integrates generative adversarial modelling with advanced machine learning models. We trained Random Forests, Deep Neural Ensembles, and Transformer-based models using the CICDDoS2019 dataset to establish the frameworks baseline performance. To enhance the models defensive capacity, we generated synthetic adversarial flows that simulate potential evasion attempts and adversarial traffic using a Wasserstein Generative Adversarial Network with Gradient Penalty (WGAN-GP). Then, we combined the generated traffic with benign and malicious traffic to construct hybrid datasets to train the models to learn more generalizable decision boundaries. The experimental results indicate that the proposed methodology significantly enhances detection accuracy and resilience, especially against unseen adversarial traffic. We also tested the designed framework using real-world generated traffic, which demonstrates its capability in practical settings. The scalable and efficient solution against adversarial DDoS attacks, introduced in this work, paves the way towards more resilient and adaptive network defense systems that combine generative adversarial augmentation with recent advances in learning models.