Mitigating Cyber Threats from the Edge
摘要
In this paper we propose a light-weight disperse approach to detection of cyber threats at the network edge. With each edge node acting in isolation and independent of other transit nodes, with a limited perspective of the entire traffic targetting a destination host. Using a combination of three feature selection algorithms (hence reducing models computational overhead) as well as nine machine learning and deep learning classifiers, this research investigates suitable combinations that meet the following criteria: 1. suitably light-weight (requiring minimal compute resources), 2. having suitably high DDoS detection performance, 3. suitable for isolated source-end detection, and 4. able to detect DDoS attacks that utilise traffic flows which are indistinguishable from user traffic. Detailed performance comparisons of centralised detection is carried out against edge-detection by using a fraction of the training dataset available to the centralised model, hence simulating the view of edge nodes. To investigate detection performance of classifiers when DDoS attacks uses traffic similar to regular network data, a virtual network was implemented and utilised to generate two unique datasets. This paper also details the impact of using stateless benign flows for DDoS attacks compared to using stateful flows. The results clearly indicate the feasibility of our framework using light-weight disperse models to detect DDoS traffic in cases where known malicious and stateless benign network packets are used in the DDoS attack.