Journals
  Publication Years
  Keywords
Search within results Open Search
Please wait a minute...
For Selected: Toggle Thumbnails
Multi‑type application‑layer DDoS attack detection method based on integrated learning
Yingzhi LI, Man LI, Ping DONG, Huachun ZHOU
Journal of Computer Applications    2022, 42 (12): 3775-3784.   DOI: 10.11772/j.issn.1001-9081.2021091653
Abstract300)   HTML13)    PDF (3299KB)(130)       Save

Aiming at the problem of multiple types of application?layer Distributed Denial of Service (DDoS) attacks, which are difficult to detect simultaneously, an application?layer DDoS attack detection method based on integrated learning was proposed to detect multiple types of application?layer DDoS attacks. Firstly, by using the dataset generation module, the normal and attack traffic was simulated, the corresponding feature information was filtered and extracted, and 47?dimensional feature information characterized Challenge Collapsar (CC), HTTP Flood, HTTP Post and HTTP Get attacks were generated. Secondly, by using the offline training module, the effective features were processed and input into the integrated Stacking detection model for training, thereby obtaining a detection model that can detect multiple types of application?layer DDoS attacks. Finally, by using the online detection module, the specific traffic type of the traffic to be detected was judged through deploying the detection model online. Experimental results show that compared with the classification models constructed by Bagging,Adaboost and XGBoost,the Stacking integretion model improves the accuracy by 0. 18 percentage points,0. 21 percentage points and 0. 19 percentage points respectively,and has the malicious traffic detection rate reached 98% under the optimal time window. It can be seen that the proposed method has good performance in detecting multi-type application-layer DDoS attacks.

Table and Figures | Reference | Related Articles | Metrics