信息网络安全 ›› 2024, Vol. 24 ›› Issue (11): 1615-1623.doi: 10.3969/j.issn.1671-1122.2024.11.001

• 入选论文 • 上一篇    下一篇

基于人工智能的物联网DDoS攻击检测

印杰1(), 陈浦1, 杨桂年2, 谢文伟3, 梁广俊1   

  1. 1.江苏警官学院计算机信息与网络安全系,南京 210031
    2.南京市公安局网络安全保卫支队,南京 210005
    3.趋势科技(中国)南京分公司,南京 210012
  • 收稿日期:2024-08-10 出版日期:2024-11-10 发布日期:2024-11-21
  • 通讯作者: 印杰 yinjiejspi@163.com
  • 作者简介:印杰(1977—),男,江苏,高级工程师,硕士,CCF会员,主要研究方向为网络空间安全、人工智能|陈浦(2000—),男,江苏,本科,主要研究方向为网络空间安全、人工智能|杨桂年(1986—),男,江苏,本科,主要研究方向为网络黑灰产犯罪侦查|谢文伟(1978—),男,江苏,工程师,硕士,主要研究方向为网络空间安全、人工智能、计算机视觉|梁广俊(1982—),男,安徽,副教授,博士,CCF会员,主要研究方向为网络空间安全、数据建模
  • 基金资助:
    国家自然科学基金(62272203)

Detection of DDoS Attacks in the Internet of Things Based on Artificial Intelligence

YIN Jie1(), CHEN Pu1, YANG Guinian2, XIE Wenwei3, LIANG Guangjun1   

  1. 1. Department of Computer Information and Cybersecurity, Jiangsu Police Institute, Nanjing 210031, China
    2. Network Security Support Team of Nanjing Public Security Bureau, Nanjing 210005, China
    3. Trend Micro(China) Nanjing Branch, Nanjing 210012, China
  • Received:2024-08-10 Online:2024-11-10 Published:2024-11-21

摘要:

针对物联网DDoS攻击检测最优解问题,文章采用多种算法对物联网DDoS攻击进行检测和建模分类,运用核密度估计筛选出有影响的流量特征字段,建立基于机器学习和深度学习算法的DDoS攻击检测模型,分析了通过可逆残差神经网络和大语言模型处理数据集并进行攻击检测的可行性。实验结果表明,ResNet50算法在综合指标上表现最好;在区分DDoS攻击流量和其他流量问题上,梯度提升类算法表现更优秀;在细分DDoS攻击类型方面,经过优化的ResNet50-GRU算法表现更好。

关键词: 物联网, DDoS攻击, 机器学习, 深度学习算法, 残差神经网络

Abstract:

Aiming at the optimal solution for detecting IoT DDoS attacks, this paper used multiple algorithms to detect and model IoT DDoS attacks. This paper used kernel density estimation to screen out influential traffic feature fields. A DDoS attack detection model based on machine learning and deep learning algorithms was established. The feasibility of processing data sets and performing attack detection through reversible residual neural networks and large language models was analyzed. Experimental results show that the ResNet50 algorithm performs best in comprehensive indicators. In distinguishing DDoS attack traffic from other traffic issues, the gradient boosting algorithm performs better. In terms of segmenting DDoS attack types, the optimized ResNet50-GRU algorithm performs better.

Key words: IoT, DDoS attacks, machine learning, deep learning algorithms, residual neural network

中图分类号: