Federated Incremental Learning Based DDoS Attack Detection Model in SDN Environment

被引:0
|
作者
Liu, Yan-Hua [1 ,2 ,4 ,5 ]
Fang, Wen-Yu [1 ,4 ,5 ]
Guo, Wen-Zhong [1 ,2 ,4 ,5 ]
Zhao, Bao-Kang [3 ]
Huang, Wei [1 ,4 ,5 ]
机构
[1] College of Computer and Data Science, Fuzhou University, Fuzhou,350108, China
[2] Zhicheng College, Fuzhou University, Fuzhou,350002, China
[3] College of Computer, National University of Defense Technology, Changsha,410073, China
[4] Engineering Research Center of Big Data Intelligence, Ministry of Education, Fuzhou,350108, China
[5] Fujian Key Laboratory of Network Computing and Intelligent Information Processing(Fuzhou University), Fuzhou,350108, China
来源
基金
中国国家自然科学基金;
关键词
Cybersecurity - Denial-of-service attack - Program debugging - Risk management - Solvent extraction - Time division multiple access;
D O I
10.11897/SP.J.1016.2024.02852
中图分类号
学科分类号
摘要
Software-Defined Networking (SDN) is a widely adopted network paradigm characterized by the separation of the control plane from the data plane. In light of network security threats, particularly Distributed Denial of Service (DDoS) attacks, the integration of effective DDoS attack detection methods within SDN is of paramount importance. The centralized control characteristic of SDN presents significant security risks when employing centralized DDoS attack detection methods, thereby posing considerable challenges to the security of the control plane in SDN environments. Furthermore, the growing volume of traffic data in SDN environments results in challenges related to more intricate traffic characterization and a pronounced Non-Independent and Identically Distributed (Non-IID) distribution among various entities. These issues present significant barriers to enhancing the accuracy and robustness of current federated learning-based detection models. The separation of management and control in SDN facilitates the creation of new flow rules by users, which enhances the efficiency of message routing control. However, current methodologies for flow detection face difficulties in preserving the knowledge of original features while simultaneously adapting to the distribution of newly generated features within the SDN environment. This challenge contributes to a phenomenon known as data forgetting. Furthermore,the imposition of flow rules restricts the forwarding targets of messages, resulting in variability in the data messages that can be collected by different host entities. The Non-IID distribution problem significantly undermines the performance and robustness of DDoS attack detection models that utilize artificial intelligence. To address these challenges, we propose a federated incremental learning-based model for DDoS attack detection within an SDN environment. This model integrates incremental learning and federated learning to accommodate new data inputs through incremental model updates, thereby eliminating the need for global re-training of the entire model. To mitigate the security risks associated with centralized DDoS attack detection methods and to address the Non-IID distribution issues arising from data increments, we introduce a weighted aggregation algorithm grounded in federated incremental learning. This algorithm personalizes adaptation to different subdataset increments by dynamically adjusting aggregation weights, thereby enhancing the efficiency of incremental aggregation. Additionally, in response to the complex traffic features inherent in SDN networks, we propose a DDoS attack detection methodology that employs Long Short-Term Memory (LSTM) networks. This approach enables real-time detection of traffic features by extracting and learning the temporal correlations present in the data, utilizing statistical analysis of the temporal characteristics of traffic data within SDN networks. Finally, by integrating the unique characteristics of SDN networks, we facilitate real-time decision-making for DDoS defense. This integration combines the results of DDoS attack detection with information pertaining to network entities, enabling the real-time deployment of flow rules. Concurrently, this approach effectively mitigates malicious DDoS attack traffic, safeguards critical entities, and ensures the stability of network topology. In this study, we evaluate the performance of the proposed method against existing techniques, including FedAvg, FA-FedAvg, and FIL-IIoT, in the context of an incremental DDoS attack detection task. The experimental results indicate that the proposed method enhances the accuracy of DDoS attack detection by an improvement range of 5. 06% to 12. 62% and increases the F1-Score by 0. 0565 to 0. 1410 when compared to alternative methods. © 2024 Science Press. All rights reserved.
引用
收藏
页码:2852 / 2866
相关论文
共 50 条
  • [1] FLDDoS: DDoS Attack Detection Model based on Federated Learning
    Zhang, Jiachao
    Yu, Peiran
    Qi, Le
    Liu, Song
    Zhang, Haiyu
    Zhang, Jianzhong
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 635 - 642
  • [2] Federated Learning-Based Solution for DDoS Detection in SDN
    Mateus, Jovita
    Zodi, Guy-Alain Lusilao
    Bagula, Antoine
    2024 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2024, : 875 - 880
  • [3] DDoS attack detection and defense based on hybrid deep learning model in SDN
    Li C.
    Wu Y.
    Qian Z.
    Sun Z.
    Wang W.
    2018, Editorial Board of Journal on Communications (39): : 176 - 187
  • [4] An efficient DDoS attack detection mechanism in SDN environment
    Hnamte V.
    Hussain J.
    International Journal of Information Technology, 2023, 15 (5) : 2623 - 2636
  • [5] An optimized weighted voting based ensemble model for DDoS attack detection and mitigation in SDN environment
    Maheshwari, Aastha
    Mehraj, Burhan
    Khan, Mohd Shaad
    Idrisi, Mohd Shaheem
    MICROPROCESSORS AND MICROSYSTEMS, 2022, 89
  • [6] Efficient DDoS attack detection and prevention scheme based on SDN in cloud environment
    He H.
    Hu Y.
    Zheng L.
    Xue Z.
    He, Heng (heheng@wust.edu.cn), 2018, Editorial Board of Journal on Communications (39): : 139 - 151
  • [7] DDoS Attack Detection Model Based on Information Entropy and DNN in SDN
    Zhang L.
    Wang J.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2019, 56 (05): : 909 - 918
  • [8] FLAD: Adaptive Federated Learning for DDoS attack detection
    Doriguzzi-Corin, Roberto
    Siracusa, Domenico
    COMPUTERS & SECURITY, 2024, 137
  • [9] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [10] DDoS Attack Detection in a Real Urban IoT Environment using Federated Deep Learning
    Ahmadi, Khatereh
    Javidan, Reza
    2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 117 - 122