Research on SYN Flood Malicious Traffic Detection Method Based on FPGA-SOC HarmonyOS
Guoqing Wang, Pingfei Cui, Zhe Yu, Mengxiao Wang · 2024
SYN Flood malicious traffic attack is a typical representative of distributed denial of service (DDo$S$) attacks and one of the primary factors threatening IoT security. In response to the architecture pattern of FPGA-SOC HarmonyOS, a lightweight detection method combining Renyi entropy and CUSUM algorithm suitable for this architecture is proposed. Firstly, the calculated Renyi entropy of the quadruple tuple is used to perform initial inspection on the traffic based on extracted packet features, determining whether it is suspicious traffic. Then, the CUSUM value of SYN packet quantity is utilized for secondary inspection to determine if it constitutes a SYN Flood malicious traffic attack. Finally, through experimental simulations generating both attack and normal traffic, results show that the SYN Flood malicious traffic detection method based on FPGA-SOC HarmonyOS achieves an accuracy rate of 87.7%, which surpasses adaptive threshold algorithms and CUSUM algorithm in terms of accuracy and effectively enhances IoT security protection.