پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

ارائه سیستم تشخیص حملات DDoS مبتنی بر یادگیری عمیق و مکانیزم توجهㅤ

نوع مقاله : مقاله پژوهشی

نویسندگان
1 دانشجوی کارشناسی ارشد، دانشگاه گلستان، گرگان، ایران
2 استادیار، دانشگاه گلستان، گرگان، ایران
چکیده
با گسترش سریع اینترنت و افزایش تعداد دستگاه‌های متصل به شبکه، سطح حملات سایبری به‌طور چشمگیری افزایش یافته است. یکی از تهدیدات جدی در این حوزه، حملات منع سرویس توزیع‌شده (DDoS) هستند که با بهره‌گیری از تعداد زیادی سیستم آلوده، حجم عظیمی از ترافیک را به سمت اهداف مشخص هدایت می‌کنند. ویژگی توزیع‌یافته و مقیاس‌پذیر این حملات، تشخیص و مقابله با آن‌ها را به‌مراتب دشوارتر از سایر تهدیدات امنیتی کرده است. در سال‌های اخیر، مدل‌های مختلفی برای شناسایی این نوع حملات توسعه یافته‌اند، اما بسیاری از آن‌ها در تشخیص دقیق یا کاهش نرخ خطا با چالش مواجه هستند. برای مقابله با این مسئله، در این مقاله یک سیستم تشخیص نفوذ مبتنی بر شبکه‌های عصبی عمیق و مکانیزم توجه پیشنهاد شده است. روش پیشنهادی با استفاده از زبان برنامه‌نویسی Python و کتابخانه PyTorch پیاده‌سازی و بر روی مجموعه داده‌های CICIDS2017، CICIDS2018 و CICDDoS2019 آزمایش شده است. نتایج نشان داد که مدل پیشنهادی در مقایسه با روش‌های پیشین، عملکرد بهتری در شناسایی حملات DDoS ارائه می‌دهد و نرخ خطای کاذب را به‌طور قابل توجهی کاهش می‌دهد. این نتایج بیانگر پتانسیل روش پیشنهادی در بهبود امنیت شبکه و ارائه یک راهکار مؤثر در برابر تهدیدات سایبری است.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Deep Learning-Based DDoS Attack Detection System with Attention Mechanism

نویسندگان English

Mehran Nosrati 1
Fatemeh Bagheri 2
1 Master's Student, Golestan University, Gorgan, Iran
2 Assistant Professor, Golestan University, Gorgan, Iran.
چکیده English

With the rapid expansion of the internet and the increasing number of devices connected to the network, the level of cyberattacks has increased significantly. One of the serious threats in this field is Distributed Denial of Service (DDoS) attacks, which use a large number of infected systems to direct a massive volume of traffic towards specific targets. The distributed and scalable nature of these attacks makes detecting and defending against them considerably more difficult than other security threats. In recent years, various models have been developed to detect these types of attacks, but many of them face challenges in accurate detection or reducing the error rate. To address this issue, this paper proposes an intrusion detection system based on deep neural networks and an attention mechanism. The proposed method was implemented using the Python programming language and the PyTorch library and tested on the CICIDS2017, CICIDS2018, and CICDDoS2019 datasets. The results showed that the proposed model outperforms previous methods in detecting DDoS attacks and significantly reduces the false positive rate. These results indicate the potential of the proposed method in enhancing network security and providing an effective solution against cyber threats.

کلیدواژه‌ها English

Intrusion Detection System
Neural Network
Attention Mechanism
Distributed Denial of Service Attack

Smiley face

 

[1]     K. Nikolskaia and A. Minbaleev, “Legal regulation of incidents related to DDoS attacks,” in 2020 International Conference Quality Management, Transport and Information Security, Information Technologies (IT&QM&IS), pp. 53-55, 2020. doi:10.1109/ITQMIS51053.2020.9322874.
[2]     M. Sachdeva, G. Singh, K. Kumar, and K. Singh, “DDoS Incidents and their Impact: A Review,” Int. Arab J. Inf. Technol., vol. 7, no. 1, pp. 14-20, 2010.
[3]     J.A. Malik and M. Saleem, “Blockchain and cyber-physical system for security engineering in the smart industry,” in Security Engineering for Embedded and Cyber-Physical Systems, CRC Press, pp. 51-70, 2022. doi:10.1201/9781003278207-6.
[4]     Z.A. Chughtai, S. Chugtai, R. Malik, H. Raza, and M. Saleem, “Towards a blockchain enabled integrated library managment system using Hyperledger Fabric,” Int. J. Comput. Innov. Sci., vol. 1, no. 3, pp. 17-24, 2022.
[5]     J. Wei, C. Long, J. Li, and J. Zhao, “An intrusion detection algorithm based on bag representation with ensemble support vector machine in cloud computing,” Concurrency and Computation, vol. 32, no. 24, p. e5922, 2020. doi:10.1002/cpe.5922.
[6]     P. Mishra, E.S. Pilli, V. Varadharajan, and U. Tupakula, “Intrusion detection techniques in cloud environment: a survey,” Journal of Network and Computer Applications, vol. 77, pp. 18-47, 2017. doi:10.1016/j.jnca.2016.10.015.
[7]     K. Peng, V.C.M. Leung, L. Zheng, S. Wang, C. Huang, and T. Lin, “Intrusion detection system based on decision tree over big data in fog environment,” Wireless Communications and Mobile Computing, vol. 2018, no. 1, p. 4680867, 2018. doi:10.1155/2018/4680867.
[8]     Q. Schueller, K. Basu, M. Younas, M. Patel, and F. Ball, “A hierarchical intrusion detection system using support vector machine for SDN network in cloud data center,” in 2018 International Telecommunication Networks and Applications Conference (ITNAC), pp. 1-6, 2018. doi:10.1109/ATNAC.2018.8615255.
[9]     C. Modi, D. Patel, B. Borisanya, A. Patel, and M. Rajarajan, “A novel framework for intrusion detection in cloud,” in Proceedings of the Fifth International Conference on Security of Information and Networks, pp. 67-74, 2012. doi:10.1145/2388576.2388585.
[10]     V.R. Pathmudi, N. Khatri, S. Kumar, A.S.H. Abdul-Qawy, and A.K. Vyas, “A systematic review of IoT technologies and their constituents for smart and sustainable agriculture applications,” Scientific African, vol. 19, p. e01577, 2023. doi:10.1016/j.sciaf.2023.e01577.
[11]     O. Alkadi, N. Moustafa, B. Turnbull, and K.-K. R. Choo, “A deep blockchain framework-enabled collaborative intrusion detection for protecting IoT and cloud networks,” IEEE Internet Things J., vol. 8, no. 12, pp. 9463–9472, 2021. doi:10.1109/JIOT.2020.2996590.
[12]     R. Zhao, Y. Yin, Y. Shi, and Z. Xue, “Intelligent intrusion detection based on federated learning aided long short-term memory,” Physical Communication, vol. 42, p. 101157, 2020. doi:10.1016/j.phycom.2020.101157.
[13]     A. Dawoud, S. Shahristani, and C. Raun, “Deep learning and software-defined networks: towards secure IoT architecture,” Internet of Things, vol. 3-4, pp. 82-89, 2018. doi:10.1016/j.iot.2018.09.003.
[14]     M. Almiani, A. AbuGhazleh, A. Al-Rahayfeh, S. Atiewi, and A. Razaque, “Deep recurrent neural network for IoT intrusion detection system,” Simulation Modelling Practice and Theory, vol. 101, p. 102031, 2020. doi:10.1016/j.simpat.2019.102031.
[15]     P. Ghosh, A. Karmakar, J. Sharma, and S. Phadikar, “CS-PSO based intrusion detection system in cloud environment,” Emerging Technologies in Data Mining and Information Security, vol. 755, pp. 261-269, 2019. doi:10.1007/978-981-13-1951-8_24.
[16]     R. SaiSindhuTheja and G.K. Shyam, “An efficient metaheuristic algorithm based feature selection and recurrent neural network for DoS attack detection in cloud computing environment,” Applied Soft Computing, vol. 100, p. 106997, 2021. doi:10.1016/j.asoc.2020.106997.
[17]     M.R. Gauthama Raman, N. Somu, K. Kirthivasan, R. Liscano, and V.S. Shankar Sriram, “An efficient intrusion detection system based on hypergraph - genetic algorithm for parameter optimization and feature selection in support vector machine,” Knowledge-Based Systems, vol. 134, pp. 1-12, 2017. doi:10.1016/j.knosys.2017.07.005.
[18]     S.P. RM et al., “An effective feature engineering for DNN using hybrid PCA-GWO for intrusion detection in IoMT architecture,” Computer Communications, vol. 160, pp. 139-149, 2020. doi:10.1016/j.comcom.2020.05.048.
[19]     D. Ciregan, U. Meier, and J. Schmidhuber, “Multi-column deep neural networks for image classification,” in 2012 IEEE Conference on Computer Vision and Pattern Recognition, pp. 3642-3649, 2012. doi:10.1109/CVPR.2012.6248110.
[20]     A. Krizhevsky, I. Sutskever, and G.E. Hinton, “ImageNet classification with deep convolutional neural networks,” Commun. ACM, vol. 60, no. 6, pp. 84-90, 2017. doi:10.1145/3065386.
[21]     Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature, vol. 521, no. 7553, pp. 436-444, 2015. doi:10.1038/nature14539.
[22]     M. Eskandari, Z.H. Janjua, M. Vecchio, and F. Antonelli, “Passban IDS: An intelligent anomaly-based intrusion detection system for IoT edge devices,” IEEE Internet Things J., vol. 7, no. 8, pp. 6882-6897, 2020. doi:10.1109/JIOT.2020.2970501.
[23]     Y. Mirsky, T. Doitshman, Y. Elovici, and A. Shabtai, “Kitsune: An ensemble of autoencoders for online network intrusion detection,” arXiv preprint arXiv:1802.09089, 2018.
[24]     H. Gharaee and H. Hosseinvand, “A new feature selection IDS based on genetic algorithm and SVM,” in 2016 8th International Symposium on Telecommunications (IST), pp. 139-144, 2016. doi:10.1109/ISTEL.2016.7881798.
[25]     M. Belouch, S.E. Hadaj, and M. Idhammad, “A two-stage classifier approach using RepTree algorithm for network intrusion detection,” International Journal of Advanced Computer Science and Applications (IJACSA), vol. 8, no. 6, pp. 30-44, 2017. doi:10.14569/IJACSA.2017.080651.
[26]     M.M. Baig, M.M. Awais, and E.-S.M. El-Alfy, “A multiclass cascade of artificial neural network for network intrusion detection,” Journal of Intelligent & Fuzzy Systems, vol. 32, no. 4, pp. 2875-2883, 2017. doi:10.3233/JIFS-169230.
[27]     B.A. Tama and K.-H. Rhee, “An in-depth experimental study of anomaly detection using gradient boosted machine,” Neural Comput & Applic, vol. 31, no. 4, pp. 955–965, 2019. doi:10.1007/s00521-017-3128-z.
[28]     R. Primartha and B.A. Tama, “Anomaly detection using random forest: A performance revisited,” in 2017 International Conference on Data and Software Engineering (ICoDSE), pp. 1-6, 2017. doi:10.1109/ICODSE.2017.8285847.
[29]     J.B. Awotunde, C. Chakraborty, and A.E. Adeniyi, “Intrusion detection in industrial Internet of Things network-based on deep learning model with rule-based feature selection,” Wireless Communications and Mobile Computing, vol. 2021, no. 1, p. 7154587, 2021. doi:10.1155/2021/7154587.
[30]     S. Naseer et al., “Enhanced network anomaly detection based on deep neural networks,” IEEE Access, vol. 6, pp. 48231-48246, 2018. doi:10.1109/ACCESS.2018.2863036.
[31]     S. Alzughaibi and S. El Khediri, “A cloud intrusion detection systems based on DNN using backpropagation and PSO on the CSE-CIC-IDS2018 dataset,” Applied Sciences, vol. 13, no. 4, p. 2276, 2023. doi:10.3390/app13042276.
[34]     M. Aamir and S.M. Ali Zaidi, “Clustering based semi-supervised machine learning for DDoS attack classification,” Journal of King Saud University - Computer and Information Sciences, vol. 33, no. 4, pp. 436-446, 2021. doi:10.1016/j.jksuci.2019.02.003.
[35]     Y. Otoum, D. Liu, and A. Nayak, “DL-IDS: a deep learning–based intrusion detection framework for securing IoT,” Trans Emerging Tel Tech, vol. 33, no. 3, p. e3803, 2022. doi:10.1002/ett.3803.
[36]     H.A. Ahmed, A. Hameed, and N.Z. Bawany, “Network intrusion detection using oversampling technique and machine learning algorithms,” PeerJ Computer Science, vol. 8, p. e820, 2022. doi:10.7717/peerj-cs.820.
[37]     A. Singh, J. Amutha, J. Nagar, S. Sharma, and C.-C. Lee, “LT-FS-ID: log-transformed feature learning and feature-scaling-based machine learning algorithms to predict the k-barriers for intrusion detection using wireless sensor network,” Sensors, vol. 22, no. 3, p. 1070, 2022. doi:10.3390/s22031070.
[38]     A. Raghuvanshi et al., “Intrusion detection using machine learning for risk mitigation in IoT-enabled smart irrigation in smart farming,” Journal of Food Quality, vol. 2022, pp. 1-8, 2022. doi:10.1155/2022/3955514.
[39]     A. Jaszcz and D. Połap, “AIMM: artificial intelligence merged methods for flood DDoS attacks detection,” Journal of King Saud University - Computer and Information Sciences, vol. 34, no. 10, pp. 8090-8101, 2022. doi:10.1016/j.jksuci.2022.07.021.
[41]     R. Chaganti, W. Suliman, V. Ravi, and A. Dua, “Deep learning approach for SDN-enabled intrusion detection system in IoT networks,” Information, vol. 14, no. 1, p. 41, 2023. doi:10.3390/info14010041.
[42]     J. Figueiredo, C. Serrão, and A.M. De Almeida, “Deep learning model transposition for network intrusion detection systems,” Electronics, vol. 12, no. 2, p. 293, 2023. doi:10.3390/electronics12020293.
[43]     S.V.J. Rani et al., “Detection of DDoS attacks in D2D communications using machine learning approach,” Computer Communications, vol. 198, pp. 32-51, 2023. doi:10.1016/j.comcom.2022.11.013.
[45]     A. Alfatemi et al., “Identifying distributed denial of service attacks through multi-model deep learning fusion and combinatorial analysis,” J Netw Syst Manage, vol. 33, no. 1, p. 8, 2025. doi:10.1007/s10922-024-09882-0.
[46]     H. Lu, J. Liu, J. Peng, and J. Lu, “Adversarial attacks based on time-series features for traffic detection,” Computers & Security, vol. 148, p. 104175, 2025. doi:10.1016/j.cose.2024.104175.
[47]     Y. Gorishniy, A. Kotelnikov, and A. Babenko, “TabM: Advancing tabular deep learning with parameter-efficient ensembling,” arXiv preprint arXiv:2410.24210, 2024.
[48]     I. Sharafaldin, A. Habibi Lashkari, and A.A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Madeira, Portugal: SCITEPRESS - Science and Technology Publications, pp. 108-116, 2018. doi:10.5220/0006639801080116.
[49]     I. Sharafaldin, A. Gharib, A.H. Lashkari, A.A. Ghorbani, “Towards a reliable intrusion detection benchmark dataset,” JSN, vol. 2017, no. 1, pp. 177-200, 2017. doi:10.13052/jsn2445-9739.2017.009.
[50]     R. Abdulhammed, H. Musafer, A. Alessa, M. Faezipour, and A. Abuzneid, “Features dimensionality reduction approaches for machine learning based network intrusion detection,” Electronics, vol. 8, no. 3, p. 322, 2019. doi:10.3390/electronics8030322.
[51]     A. Gharib, I. Sharafaldin, A.H. Lashkari, and A.A. Ghorbani, “An evaluation framework for intrusion detection dataset,” in 2016 International Conference on Information Science and Security (ICISS), pp. 1-6, 2016. doi:10.1109/ICISSEC.2016.7885840.
[52]     I. Sharafaldin, A.H. Lashkari, S. Hakak, and A.A. Ghorbani, “Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy,” in 2019 International Carnahan Conference on Security Technology (ICCST), pp. 1-8, 2019. doi:10.1109/CCST.2019.8888419.
[53]     S. Abiramasundari and V. Ramaswamy, “Distributed Denial-of-Service (DDoS) Attack Detection Using Supervised Machine Learning Algorithms,” Sci Rep, vol. 15, no. 1, p. 13098, 2025, doi:10.1038/s41598-024-84879-y.

  • تاریخ دریافت 29 دی 1404
  • تاریخ بازنگری 16 اسفند 1404
  • تاریخ پذیرش 24 فروردین 1405
  • تاریخ انتشار 01 خرداد 1405