• 中国精品科技期刊
  • CCF推荐A类中文期刊
  • 计算领域高质量科技期刊T1类
高级检索

SDN中基于信息熵与DNN的DDoS攻击检测模型

张龙, 王劲松

张龙, 王劲松. SDN中基于信息熵与DNN的DDoS攻击检测模型[J]. 计算机研究与发展, 2019, 56(5): 909-918. DOI: 10.7544/issn1000-1239.2019.20190017
引用本文: 张龙, 王劲松. SDN中基于信息熵与DNN的DDoS攻击检测模型[J]. 计算机研究与发展, 2019, 56(5): 909-918. DOI: 10.7544/issn1000-1239.2019.20190017
Zhang Long, Wang Jinsong. DDoS Attack Detection Model Based on Information Entropy and DNN in SDN[J]. Journal of Computer Research and Development, 2019, 56(5): 909-918. DOI: 10.7544/issn1000-1239.2019.20190017
Citation: Zhang Long, Wang Jinsong. DDoS Attack Detection Model Based on Information Entropy and DNN in SDN[J]. Journal of Computer Research and Development, 2019, 56(5): 909-918. DOI: 10.7544/issn1000-1239.2019.20190017
张龙, 王劲松. SDN中基于信息熵与DNN的DDoS攻击检测模型[J]. 计算机研究与发展, 2019, 56(5): 909-918. CSTR: 32373.14.issn1000-1239.2019.20190017
引用本文: 张龙, 王劲松. SDN中基于信息熵与DNN的DDoS攻击检测模型[J]. 计算机研究与发展, 2019, 56(5): 909-918. CSTR: 32373.14.issn1000-1239.2019.20190017
Zhang Long, Wang Jinsong. DDoS Attack Detection Model Based on Information Entropy and DNN in SDN[J]. Journal of Computer Research and Development, 2019, 56(5): 909-918. CSTR: 32373.14.issn1000-1239.2019.20190017
Citation: Zhang Long, Wang Jinsong. DDoS Attack Detection Model Based on Information Entropy and DNN in SDN[J]. Journal of Computer Research and Development, 2019, 56(5): 909-918. CSTR: 32373.14.issn1000-1239.2019.20190017

SDN中基于信息熵与DNN的DDoS攻击检测模型

基金项目: 国家重点研发计划项目(2018YFC0831405);天津市自然科学基金项目(18JCZDJC30700);赛尔网络下一代互联网创新项目(NGII20160121)
详细信息
  • 中图分类号: TP393

DDoS Attack Detection Model Based on Information Entropy and DNN in SDN

  • 摘要: 软件定义网络(software defined networking, SDN)解耦了网络的数据层与控制层,同时控制器也面临“单点失效”的危险.攻击者可以发起分布式拒绝服务攻击(distributed denial of service, DDoS)使控制器失效,影响网络安全.为解决SDN中的DDoS流量检测问题,创新性地提出了基于信息熵与深度神经网络(deep neural network, DNN)的DDoS检测模型.该模型包括基于信息熵的初检模块和基于深度神经网络DNN的DDoS流量检测模块.初检模块通过计算数据包源、目的IP地址的信息熵值初步发现网络中的可疑流量,并利用基于DNN的DDoS检测模块对疑似异常流量进行进一步确认,从而发现DDoS攻击.实验表明:该模型对DDoS流量的识别率达到99%以上,准确率也有显著提高,误报率明显优于基于信息熵的检测方法.同时,该模型还能缩短检测时间,提高资源使用效率.
    Abstract: The software defined networking (SDN) decouples the data layer and the control layer of the network, but the controller is in danger of “single node invalidation ”. Attackers launch DDoS attacks to disable the controller and threaten the safety of networks. This paper presents a DDoS detection model based on entropy and deep neural network (DNN), which includes the initial detection module based on entropy-based detection method and the further detection module based on DNN. The initial detection module finds out the suspicious traffic in the network preliminarily by calculating the entropy of source and destination IP address, and then the suspected abnormal traffic with DNN-based DDoS detection module confirms the anomaly traffic. Experiments show that this model has higher recognition rate and accuracy rate than the traditional detection algorithm based on entropy or machine learning. At the same time, the model can shorten the detection time and improve the efficiency of resource utilization.
  • 期刊类型引用(2)

    1. 李学成,王力. 新型水果切片机结构的发展研究. 南方农机. 2020(02): 3+5 . 百度学术
    2. 方旭东,吴俊杰. 基于忆阻器的计算存储融合体系结构研究进展. 计算机工程与科学. 2020(11): 1929-1940 . 百度学术

    其他类型引用(6)

计量
  • 文章访问数:  1892
  • HTML全文浏览量:  16
  • PDF下载量:  985
  • 被引次数: 8
出版历程
  • 发布日期:  2019-04-30

目录

    /

    返回文章
    返回