发表机构
Symbiosis Institute of Technology; Symbiosis Center for Applied Artificial Intelligence; Peoples’ Friendship University of Russia(共生技术学院; 共生应用人工智能中心; 俄罗斯人民友谊大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出结合GAN合成数据与随机森林,并应用对抗性去偏的DDoS检测方法,在基准数据上达到99.98%准确率,对未见合成流量性能提升22.60%,具有良好泛化性。
AI 中文摘要
分布式拒绝服务(DDoS)攻击对网络基础设施构成日益严重的威胁,而包括生成式人工智能在内的新技术使得这些攻击更难被检测。传统的检测系统,如基于规则的防火墙,往往无法识别这些不断演变的攻击模式。在本研究中,我们提出了一种新的DDoS攻击检测方法,该方法将使用生成对抗网络(GAN)的合成数据生成与随机森林分类器相结合。GAN生成的数据与真实流量的余弦相似度达到80.3%,这有助于模型更有效地学习底层流量模式。为了解决数据中的不平衡问题,特别是在与数据包相关的特征方面,我们应用了对抗性去偏。这降低了模型对诸如前向和后向数据包计数以及总字节长度等变量中偏斜分布的敏感性。我们的结果表明,在合成数据和真实数据混合训练出的模型取得了显著更好的性能:在基准数据上准确率达到99.98%,在测试先前未见过的合成流量时性能提升了22.60%。这表明该方法能够很好地泛化到不同的流量场景,并快速适应新型攻击。所提出的方法不仅提高了DDoS检测能力,还为考虑偏差并受益于数据增强的安全模型提供了可扩展的基础。我们的研究结果表明,将GAN与对抗性去偏相结合可以带来更稳健、更有效的DDoS缓解,支持基于机器学习的网络安全的进一步发展。
英文摘要
Distributed Denial of Service attacks are a growing threat to network infrastructure, and new techniques, including the use of generative AI, make them harder to detect. Traditional detection systems, such as rule based firewalls, often fail to identify these evolving attack patterns. In this study, we propose a new method for detecting DDoS attacks by combining synthetic data generation using Generative Adversarial Networks with a Random Forest classifier. The GAN generated data showed 80.3 percent cosine similarity to real traffic, which helped the model learn underlying traffic patterns more effectively. To address imbalances in the data, especially in packet related features, we applied adversarial debiasing. This reduced the model's sensitivity to skewed distributions in variables such as forward and backward packet counts and total byte lengths. Our results show that models trained on a mix of synthetic and real data achieved significantly better performance: 99.98 percent accuracy on benchmark data and a 22.60 percent improvement when tested on previously unseen synthetic traffic. This suggests that the method can generalize well across different traffic scenarios and adapt quickly to new types of attacks. The proposed approach not only improves DDoS detection but also provides a scalable foundation for security models that account for bias and benefit from data augmentation. Our findings show that combining GANs with adversarial debiasing can lead to more robust and effective DDoS mitigation, supporting the further development of machine learning based cyber security.
Comments20 pages, 2 tables, 5 figures