信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1264-1276.doi: 10.3969/j.issn.1671-1122.2026.08.008
收稿日期:2025-12-25
出版日期:2026-08-10
发布日期:2026-09-23
通讯作者:
张连成
E-mail:liancheng17@aliyun.com
作者简介:张宏涛(1977—),男,陕西,高级实验师,博士,主要研究方向为网络与系统安全、数据安全、下一代互联网安全|王清涛(2000—),男,河南,硕士研究生,主要研究方向为下一代互联网安全、IPv6网络安全|张连成(1982—),男,河南,副教授,博士,主要研究方向为下一代互联网安全、IPv6网络安全、SDN网络安全|王吉昌(1999—),男,河南,助教,硕士,主要研究方向为下一代互联网安全、IPv6网络安全
基金资助:
Zhang Hongtao1,2, Wang Qingtao1,2, Zhang Liancheng3(
), Wang Jichang3
Received:2025-12-25
Online:2026-08-10
Published:2026-09-23
Contact:
Zhang Liancheng
E-mail:liancheng17@aliyun.com
摘要:
IPv6网络的快速扩展加剧了分布式拒绝服务(DDoS)威胁的多样性和复杂性,而实际运行环境中标注流量数据的匮乏又严重削弱了传统监督式检测器的性能。为应对这些挑战,文章提出Argus6混合深度学习模型,该模型并行融合了基于Transformer的分支与Mamba状态空间分支,Transformer分支用于建模全局时序依赖关系,Mamba分支用于高效捕捉长序列动态特征。在两个基准数据集上的消融实验表明,完整的Argus6架构显著优于单一结构变体:在数据集1上,F1-Score为0.9874、AUC为0.9986;在数据集2上,F1-Score为0.9926、AUC为0.9995,且误报率及漏报率分别降至1.19%和0.84%。在K-shot小样本实验中,Argus6仅需少量标签即可快速收敛:每类仅使用10个样本时,F1-Score约为0.78、AUC约为0.81;当每类样本超过100个时,F1-Score约为0.91、AUC约为0.96。最后,在完整的IPv6 DDoS威胁数据集上,Argus6在准确率、F1-Score、AUC和错误率等指标上均超越了1D-CNN、CNN-LSTM、MF-Net及多种经典方法,充分验证了其在大规模DDoS威胁防御中的鲁棒性与数据效率。
中图分类号:
张宏涛, 王清涛, 张连成, 王吉昌. Argus6:一种IPv6 DDoS威胁检测模型[J]. 信息网络安全, 2026, 26(8): 1264-1276.
Zhang Hongtao, Wang Qingtao, Zhang Liancheng, Wang Jichang. Argus6: an IPv6 DDoS threat detection model[J]. Netinfo Security, 2026, 26(8): 1264-1276.
表1
Argus6模型结构
| 层名 | 输出形状 | 说明 |
|---|---|---|
| Input | [128,512,2048] | 2048位定长特征序列 |
| Linear | [128,512,64] | Transformer分支投影 2048→64 |
| TransformerEncoder | [128,512,64] | 全局建模(2×281,152) |
| Mean Pooling | [128,64] | 序列均值池化 |
| Linear | [128,512,64] | Mamba分支投影 2048→64 |
| Mamba | [128,512,64] | 状态空间序列建模 |
| Mean Pooling | [128,64] | 序列均值池化 |
| 特征拼接 | [128,128] | 拼接融合 |
| Fusion:Linear+LN+GeLU(128→64) | [128,64] | 融合降维 |
| Classifier:Linear+ GeLU+Linear(64→32→2) | [128,2] | 分类输出 |
| [1] | Cisco. 6lab IPv6 stats:world users[EB/OL]. (2025-11-30)[2025-12-10]. https://6lab.cisco.com/stats/cible.php?country=world&option=users.s. |
| [2] | IETF. Internet engineering task force[EB/OL]. (2025-09-20)[2025-12-10]. https://www.ietf.org/about/introduction/. |
| [3] | Hnamte V, Najar A A, Nhung-Nguyen H, et al. DDoS attack detection and mitigation using deep neural network in SDN environment[EB/OL]. (2023-12-18)[2025-12-10]. https://doi.org/10.1016/j.cose.2023.103661. |
| [4] | 张连成, 程兰馨, 杜雯雯, 等. IPv6网络安全[M]. 北京: 科学出版社, 2024. |
| [5] | Xia Wenhao, Zhang Liancheng, Guo Yi, et al. P4NSA: P4-based security protection technology for IPv6 neighbor solicitation and advertisement spoofing[EB/OL]. (2025-02-23)[2025-12-10]. https://doi.org/10.1016/j.cose.2025.104400. |
| [6] | Balarezo J F, Wang S, Chavez K G, et al. A survey on DoS/DDoS attacks mathematical modelling for traditional, SDN and virtual networks[EB/OL]. (2021-10-23)[2025-12-10]. https://doi.org/10.1016/j.jestch.2021.09.011. |
| [7] | Guerra J L, Catania C, Veas E. Datasets are not enough: challenges in labeling network traffic[EB/OL]. (2022-06-22)[2025-12-10]. https://doi.org/10.1016/j.cose.2022.102810. |
| [8] | Lee S W, Mohammed Sidqi H, Mohammadi M, et al. Towards secure intrusion detection systems using deep learning techniques: comprehensive analysis and review[EB/OL]. (2021-05-19).[2025-12-10]. https://doi.org/10.1016/j.jnca.2021.103111. |
| [9] | Xu Congyan, Zhang Fan, Yang Ziqi, et al. A few-shot network intrusion detection method based on mutual centralized learning[EB/OL]. (2025-03-21).[2025-12-10]. https://doi.org/10.1038/s41598-025-93185-0. |
| [10] | 蒋英肇, 陈雷, 闫巧. 基于双通道特征融合的分布式拒绝服务攻击检测算法[J]. 信息网络安全, 2023, 23(7): 86-97. |
| [11] | Gu A, Dao T. Mamba: linear-time sequence modeling with selective state spaces[EB/OL]. (2024-05-31).[2025-12-10]. https://arxiv.org/abs/2312.00752. |
| [12] | Wang Tongze, Xie Xiaohui, Wang Wenduo, et al. Netmamba: efficient network traffic classification via pre-training unidirectional mamba[C]// IEEE. 2024 IEEE 32nd International Conference on Network Protocols (ICNP). New York: IEEE, 2024: 1-11. |
| [13] | Fortunati S, Gini F, Greco M S, et al. An improvement of the state-of-the-art covariance-based methods for statistical anomaly detection algorithms[J]. Signal, Image and Video Processing, 2016, 10(4): 687-694. |
| [14] | Hoque N, Kashyap H, Bhattacharyya D K. Real-time DDoS attack detection using FPGA[J]. Computer Communications, 2017, 110: 48-58. |
| [15] | Naiem S, Khedr A E, Idrees A M, et al. Enhancing the efficiency of gaussian naïve bayes machine learning classifier in the detection of DDoS in cloud computing[J]. IEEE Access, 2023, 11: 124597-124608. |
| [16] | Maazalahi M, Hosseini S. K-means and meta-heuristic algorithms for intrusion detection systems[J]. Cluster Computing, 2024, 27(8): 10377-10419. |
| [17] | Sanmorino A, Gustriansyah R, Alie J. DDoS attacks detection method using feature importance and support vector machine[J]. JUITA: Journal Informatika, 2022, 10(2): 167-171. |
| [18] | Hai Tao, Zhou Jincheng, Adetiloye O A, et al. DDoS attack prediction using decision tree and random forest algorithms[C]//Springer. Proceedings of ICACTCE’23-The International Conference on Advances in Communication Technology and Computer Engineering. Heidelberg: Springer, 2023: 37-46. |
| [19] | 徐精诚, 陈学斌, 董燕灵, 等. 融合特征选择的随机森林DDoS攻击检测[J]. 计算机应用, 2023, 43 (11): 3497-3503. |
| [20] | 丑义凡, 易波, 王兴伟, 等. IPv6网络中基于MF-DL的DDoS攻击快速防御机制[J]. 计算机学报, 2021, 44(10): 2047-2060. |
| [21] | Alghazzawi D, Bamasag O, Ullah H, et al. Efficient detection of DDoS attacks using a hybrid deep learning model with improved feature selection[EB/OL]. (2021-12-01)[2025-12-10]. https://doi.org/10.3390/app112411634. |
| [22] | Elejla O E, Anbar M, Hamouda S, et al. Deep-learning-based approach to detect ICMPv6 flooding DDoS attacks on IPv6 networks[EB/OL]. (2022-06-16)[2025-12-10]. https://doi.org/10.3390/app12126150. |
| [23] | 王郁夫, 王兴伟, 易波, 等. IPv6中一种基于卷积的DDoS攻击两阶段防御机制[J]. 软件学报, 2024, 35 (5): 2522-2542. |
| [24] | 范明钰, 李珂. 一种基于RNN区分DDoS攻击类型的方法[J]. 信息网络安全, 2022, 22(7): 1-8. |
| [25] | Ouhssini M, Afdel K, Akouhar M, et al. Advancements in detecting, preventing, and mitigating DDoS sttacks in cloud environments: a comprehensive systematic review of state-of-the-art approaches[EB/OL]. (2024-08-26)[2025-12-10]. https://doi.org/10.1016/j.eij.2024.100517. |
| [26] | Li Siyuan, Zhang Liumei, Han Yu. LMIPv6ATK: a labeled dataset containing multiple ICMPv6-DDoS attacks[C]// 2023 International Conference on Networking and Network Applications (NaNA). Qingdao, China: IEEE, 2023: 52-57. |
| [27] | Abinayadevi C, Parvathy M, Manoj Kumar P. IDOS6-ICMPv6 based DDoS attack dataset[EB/OL]. (2024-12-26)[2025-12-10]. https://ieee-dataport.org/documents/idos6-icmpv6-based-ddos-attack-dataset. |
| [28] | Abiramasundari S, Ramaswamy V. Distributed denial-of-service (DDoS) attack detection using supervised machine learning algorithms[J]. Scientific Reports, 2025, 15(1): 13098. |
| [29] | Alduailij M, Khan Q W, Tahir M, et al. Machine-learning-based DDoS attack detection using mutual information and random forest feature importance method[EB/OL]. (2025-05-16).[2025-12-01]. https://doi.org/10.1038/s41598-024-84879-y. |
| [30] | Wang Yufu, Wang Xingwei, Ni Qiang, et al. BCDM: an early-stage DDoS incident monitoring mechanism based on binary-CNN in IPv6 network[J]. IEEE Transactions on Network and Service Management, 2024, 21(5): 5873-5887. |
| [31] | Zabeehullah, Arif F, Qazi M U H, et al. Hybrid CNN-LSTM model for DDoS attack detection in internet of things-based healthcare industry 5.0[J]. IEEE Internet of Things Journal, 2025, 12(22): 46075-46082. |
| [32] | Ding Zhaoxu, Zhong Guoqiang, Qin Xianping, et al. MF-Net: multi-frequency intrusion detection network for internet traffic data[EB/OL]. (2023-09-27).[2025-12-10]. https://doi.org/10.1016/j.patcog.2023.109999. |
| [1] | 郑天明, 刘尚东, 李海天, 李华. 一种基于交互式卷积和Transformer的异常检测算法[J]. 信息网络安全, 2026, 26(7): 1077-1086. |
| [2] | 陈宇琪, 钱汉伟, 夏玲玲, 王群. FEViT:一种基于频域增强ViT的深度伪造检测模型[J]. 信息网络安全, 2026, 26(3): 432-441. |
| [3] | 赵文宇, 党晨曦, 杜振华, 张健. 基于硬件性能计数器的勒索软件检测技术研究与实现[J]. 信息网络安全, 2025, 25(9): 1397-1406. |
| [4] | 孙剑文, 张斌, 司念文, 樊莹. 基于知识蒸馏的轻量化恶意流量检测方法[J]. 信息网络安全, 2025, 25(6): 859-871. |
| [5] | 韦超仁, 夏万煦, 屈刚, 白万荣, 杨立群. 面向智能系统开源模糊测试框架优化技术研究[J]. 信息网络安全, 2025, 25(4): 587-597. |
| [6] | 张新有, 高志超, 冯力, 邢焕来. 基于FFT-iTransformer的网络安全态势特征插补与预测[J]. 信息网络安全, 2025, 25(2): 228-239. |
| [7] | 刘强, 王坚, 王亚男, 王珊. 基于集成学习的恶意代码动态检测方法[J]. 信息网络安全, 2025, 25(1): 159-172. |
| [8] | 张博文, 李冬, 赵贻竹, 于俊清. IPv6地址驱动的云网络内生安全机制研究[J]. 信息网络安全, 2024, 24(1): 113-120. |
| [9] | 李冬, 于俊清, 文瑞彬, 谢一丁. 基于IPv6的容器云内生安全机制[J]. 信息网络安全, 2023, 23(12): 21-28. |
| [10] | 叶桓荣, 李牧远, 姜波. 基于迁移学习和威胁情报的DGA恶意域名检测方法研究[J]. 信息网络安全, 2023, 23(10): 8-15. |
| [11] | 王腾飞, 蔡满春, 芦天亮, 岳婷. 基于iTrace_v6的IPv6网络攻击溯源研究[J]. 信息网络安全, 2020, 20(3): 83-89. |
| [12] | 金志虎, 甘玉玺, 金毅, 胡龙斌. 构建安全可靠的IPv6驻地网络的探讨[J]. 信息网络安全, 2015, 15(8): 59-66. |
| [13] | 钱福民;张海港. 浅谈下一代基于IPv6互联网的安全保护[J]. , 2012, 12(Z): 0-0. |
| [14] | 温昱晖;任卫红;于毅;申永波. IPv6环境下信息安全等级保护面临的挑战与应对[J]. , 2012, 12(Z): 0-0. |
| [15] | 沈亮;张艳;顾健. 物联网网络层中基于IPv6的信息安全产品发展趋势研究[J]. , 2012, 12(8): 0-0. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||