Detection of A Novel Dual Attack in Named Data Networking
Liang Liu, Silin Peng · 2022
Distributed Denial of Service (DDoS) attacks in Named Data Networking (NDN), such as Cache Pollution Attacks (CPA) and Improved Collusive Interest Flooding Attacks (I-CIFA), can significantly threaten the NDN network. However, most of the previous research has focused on the detection of a single attack by using Machine Learning algorithms and threshold-based methods, so the previous methods are not efficient enough for detecting dual attacks. This paper first proposes a dual attack by combining I-CIFA and CPA, and extracts the network traffic features, including the number of CacheMisses and the number of PIT entries. After analyzing the severe impact of the dual attack, a detection scheme BO-CatBoost is proposed based on Bayesian optimization and CatBoost. Finally, the experiment results show that the proposed detection scheme is robust in detecting the dual attack.