DDoS Attack Traffic Identification Using Recurrent Neural Network

Yu Li, Hao Shi, Mingyu Fan · 2021

Cyber security plays a very important role in all walks of our life, especially in information industries. We all know, there are a lot of cyber attacks in network. Among all, DDoS attacks are more common and harmful than other types. Nowadays, with the rapid development of distributed computing technologies, cloud technologies and Internet, the scope of DDoS attacks is increased. These DDoS attacks are of different types like denial of service, distributed denial of service, Slowloris, and so on. We know that there are a number of technologies to detect the attacks, and the most popular way is machine learning. In this paper, we propose a recurrent neural network-based solution for DDoS attack traffic flow detection. This solution can be used for online intrusion detection systems and intrusion prevention systems. Firstly, we need to collect dataset. Due to the lack of reliable test and validation datasets, the existing datasets illustrate that most of them are out of date and useless, we use DDoS 2019 dataset for our experiment. Secondly, we extract features by CICFlowMeter tool. Thirdly, the extracted features are converted into grayscale images by a certain algorithm. Finally, the grayscale images are used as input to the RNN classifier. Regardless of a feature appears in the image, through RNN classifier, we will get the same output, this is a fundamental and most important benefit of RNN classifiers. With this implementation, we can achieve an accuracy of 99.95%.

Read the paper · More papers on PaperTik