DR-LSTM Detection Scheme for B5G DoS Traffic

Tianbin Dang, Qian Sun, Lulu Dai, Lin Tian, Jie Zeng · 2024

Denial-of-Service (DoS) attacks on Beyond 5G (B5G) networks can render network services unavailable. Deep learning (DL)-based anomaly detection models have effectively identified and prevented B5G DoS traffic. However, current DL-based detection models face two primary challenges: (1) inaccurate evaluation of feature redundancy and classification ability during feature selection and (2) difficulty capturing attack patterns across different time durations during detection. This paper proposes a detection scheme for B5G DoS traffic, including feature selection and anomaly detection. A two-dimensional feature selection algorithm is developed by introducing the distinguishing and redundancy (DR) indices. In one dimension, redundant features are deleted based on redundancy indices, with the feature angle cosine calculated to address inaccuracies caused by feature value discrepancies. In the other dimension, features with high classification ability are retained using distinguishing indices, bridging the gap between correlation parameters and classification ability. Then, an anomaly detection model for B5G DoS traffic is provided by one modified LSTM (mLSTM) network with double LSTM layers setting different sequence lengths and corresponding LSTM units. Thus, the DoS patterns of short-term bursting and long-term lasting can be accurately captured. After that, two DoS cases of B5G networks are provided and carried on a simulation platform, where DoS traffic is collected. Finally, with the collected traffic data, the proposed detection scheme’s time efficiency and detection performance are discussed and proven.

Read the paper · More papers on PaperTik