CyberGuard: Detecting Adversarial DDoS Attacks in SDN using WGAN-CNN-GRU
Konda Srikar Goud, Srinivasa Rao Giduturi · 2024
Detecting Distributed Denial of Service (DDoS) attacks in Software-Defined Networks (SDN) has become a critical challenge in ensuring network security and availability. Adversarial attacks, which aim to evade traditional detection methods, have emerged as a formidable threat. In this study, we present a novel approach for detecting adversarial DDoS attacks within an SDN environment by leveraging the combined power of Wasserstein Generative Adversarial Networks (WGAN) and Convolutional Neural Networks with Gated Recurrent Units (CNN-GRU). Our proposed methodology capitalizes on the strengths of both WGAN and CNN-GRU to effectively identify subtle adversarial attack patterns. Firstly, we utilize WGAN to synthesize adversarial DDoS attack traffic, exploiting its capability to generate data that mimics legitimate network traffic distribution. Subsequently, we employ a hybrid model of CNN-GRU to process the generated traffic. CNN extracts spatial features from traffic data, while GRU captures temporal dependencies in the network flows. The experimental results demonstrate the effectiveness of our approach in differentiating adversarial DDoS traffic from legitimate traffic. Our model achieves a high detection accuracy by training on synthesized adversarial traffic and real-world network data, even against sophisticated adversarial attack strategies. Furthermore, our approach showcases robustness against unseen adversarial patterns, highlighting its potential for real-world deployment.