Deep Learning-Based DDoS Attack Detection Using Adversarial Optimization
Dahai Yu, Jianming Cui, Yungang Jia, Peiguo Fu, Ming Liu · 2024
In the field of cybersecurity, increasingly emerging network threats seriously affect the security of network and users. Notably, DDoS attacks represent a critical concern due to their capacity to inundate and debilitate targeted systems via distributed networks. This study introduces a DDoS attack detection framework employing a dual-detection model designed to identify both conventional and adversarial DDoS attacks. Adversarial DDoS attacks are characterized by their enhanced capability to circumvent standard DDoS detection mechanisms. The proposed framework incorporates an optimized CNN architecture for the detection of traditional DDoS attacks. This optimization involves substituting fully connected layers with global average pooling layers, an approach validated through comparative experimentation to yield the most effective base CNN model. For the detection of adversarial DDoS attacks, we propose a new detection algorithm, in which methodology initially employs the WGAN-GP data generation process to create synthetic DDoS attack data, followed by the strategic alteration of certain feature values within the generated attack data using normal traffic data. The resultant perturbed data are then utilized to train the adversarial DDoS attack detection model. Empirical assessments performed on the CIC-IDS2017 and CIC-DDoS2019 datasets confirm the efficacy of the dual-detection model in accurately identifying both traditional and adversarial DDoS attacks, achieving an accuracy exceeding 95%.