A Lightweight Flow-based DDoS Detection Approach using Dual Convolutional Kernels

Qingrong Liang, Chun Liu, Yuxuan Zhong, Xiaoqiang Ren · 2022

The damage caused by Distributed Denial of Service (DDoS) attacks is becoming more and more serious with the development of the Internet, especially as we enter the era of the Internet of Things (IoT). Being able to efficiently analyze real-time traffic and detect anomalous flows is one of the current challenges. In this paper, we propose a lightweight detection framework based on Convolutional Neural Network (CNN), including a preprocessing mechanism for live traffic to extract data features, which are then fed into a network with dual convolutional kernels for training. Through different sizes of convolution kernels, we can learn the feature relationships between packets at different distances, while introducing Dilated Convolution to further improve the detection performance. Experimental results show that our method can effectively detect both benign and malicious flows, and has the advantage of high performance and low overhead compared with other state-of-the-art methods, which is suitable for effective DDoS detection in resource-constrained environments.

Read the paper · More papers on PaperTik