Distributed Denial-of-service(DDoS) attacks in the network have become more complex today. Large-scale attacks are unusually active, the frequency of attacks continues to grow, the complexity of attacks is increasing, and the threat of attacks has intensified. However, existing DDoS attacks detectors and Intrusion Detection System(IDS) are unable to efficiently detect these complex DDoS attacks within an effective detection time. Most of the detectors, despite being able to handle huge amount of DDoS attacks traffic, also have elevated detection latency and poor model timeliness. Since the normal traffic of the network in the training data is much more than the malicious traffic, these models fail to learn the data distribution characteristics of the malicious traffic well. This paper propose TDAT, a real-time two-stage DDoS detection and classification detector for DDoS attacks traffic, which performs data reconstruction of benign traffic by Anomaly Transformer and detects malicious traffic by series-association and prior-association in the first stage and then completes more detailed multiple classification of attacks traffic in the second stage. A series of experiments show that TDAT achieves state-of-the-art performance on all four public datasets, and excels in latency and memory usage.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

TDAT: A Real-Time Two-Stage DDoS Attacks Detector Based on Anomaly Transformer

  • Zhen Huang,
  • Shang Liu,
  • Ke Zhao,
  • Yong Xiang

摘要

Distributed Denial-of-service(DDoS) attacks in the network have become more complex today. Large-scale attacks are unusually active, the frequency of attacks continues to grow, the complexity of attacks is increasing, and the threat of attacks has intensified. However, existing DDoS attacks detectors and Intrusion Detection System(IDS) are unable to efficiently detect these complex DDoS attacks within an effective detection time. Most of the detectors, despite being able to handle huge amount of DDoS attacks traffic, also have elevated detection latency and poor model timeliness. Since the normal traffic of the network in the training data is much more than the malicious traffic, these models fail to learn the data distribution characteristics of the malicious traffic well. This paper propose TDAT, a real-time two-stage DDoS detection and classification detector for DDoS attacks traffic, which performs data reconstruction of benign traffic by Anomaly Transformer and detects malicious traffic by series-association and prior-association in the first stage and then completes more detailed multiple classification of attacks traffic in the second stage. A series of experiments show that TDAT achieves state-of-the-art performance on all four public datasets, and excels in latency and memory usage.