APP下载

基于深度学习和三支决策的DDoS攻击检测算法

2021-01-06陶应亮

计算技术与自动化 2021年4期

陶应亮

摘 要:针对软件定义网络(Software Defined Ntwork,SDN)中的分布式拒绝服务(Distribute Denial of Service, DDoS)攻击检测的方法少、现存方法入侵检测率低的问题,提出了一种基于深度学习和三支决策的入侵检测算法。首先使用深度信念网络对SDN的流表项进行特征提取,然后利用基于三支决策理论的入侵检测模型进行DDoS攻击的入侵检测,对于正域和负域的数据直接进行分类,对于边界域中的数据使用K近邻算法重新进行分类。仿真实验结果表明,与其他入侵检测模型相比,所提算法的入侵检测效率更高。

关键词:软件定义网络;深度信念网络;三支决策;DDoS攻击

中图分类号:TN915.08     文献标识码:A

Abstract:Aiming at the problem of few DDoS attack detection methods and low intrusion detection rate of existing methods in software defined network (SDN), an intrusion detection algorithm based on deep learning and three decision making is proposed.First, use deep belief network to extract features of SDN flow entries, then use three-way decisions intrusion detection model forintrusion detection of DDoS attacks, directly classify data in the positive and negative domains, and the data in the boundary domain is reclassified using the K-nearest neighbor algorithm. Simulation results show that compared with other intrusion detection models, the detection rate of this methodis higher, and the false alarm rate is lower.

Key words:software defined network; deep belief network; three-way decisions; DDoS attack

軟件定义网络(Software Defined Network,SDN)作为新兴的网络架构,解耦了网络的控制层与数据层,被认为是未来网络发展的方向。但由于其及网络架构的特殊性,控制器作为网络架构的核心,容易面临单点失效的风险。分布式拒绝服务(Distribute Denial of Service, DDoS)攻击一直以来都是软件定义网络的的主要威胁之一[1]。为防御SDN下的DDoS攻击,国内外许多网络安全专家在常规方法的基础上,将机器学习应用于DDoS攻击的入侵检测。深度信念网络(Deep Belief Network,DBN)作为深度学习的一个分支,与传统的机器学习相比,可以学习到更加复杂的表达函数[2]。但由于SDN环境下的DDoS攻击的特征数量有限,通常会由于特征的不充足和信息的不确定性导致流量分类的错误。

因此,为解决软件定义网络中的分类正确率不足、入侵检测效率低的问题,提出一种在SDN下的基于深度信念网络和三支决策的入侵检测模型。……

登录APP查看全文