Optimizing Distributed Denial of Service (DDoS) Detection with Time Series Transformers

Chibuike Henry Ejikeme · 2024

Distributed Denial of Service (DDoS) attacks pose a serious threat to large networks, especially with the rapid expansion of Internet of Things (IoT) and cloud services.Hackers are adopting more sophisticated techniques to disrupt services, which can lead to significant financial consequences for organizations.Therefore, the need for efficient detection and response methods is paramount.Achieving this goal requires high precision and recall in attack detection.False positives may trigger incorrect responses, making services inaccessible to legitimate users, while false negatives allow attacks to persist undetected within the network.This research proposes that traffic generated by modern DDoS tools can be distinguished by its unique packet creation patterns, which differ from regular network traffic.Although current DDoS tools have improved their packet crafting techniques, we assert that they still struggle to mimic authentic traffic closely enough to prevent alterations in the statistical profiles of traffic flows.In this work, we explore the application of the Time Series Transformer (TST) to enhance the detection of DDoS attacks, enabling network systems to initiate more accurate responses.While basic statistical analyses can detect DDoS traffic, more complex algorithms, such as transformers, offer enhanced flexibility and performance.We analyze several DDoS attack types based on protocol and utilize datasets such as CICDDOS2019 and CICIOT2023, which encompass a variety of network devices, to evaluate the effectiveness of the proposed model.Through this analysis, we aim to demonstrate the robustness and adaptability of transformer-based models in identifying and mitigating DDoS attacks, making them a powerful tool for modern network security.

Read the paper · More papers on PaperTik