Netinfo Security ›› 2026, Vol. 26 ›› Issue (8): 1264-1276.doi: 10.3969/j.issn.1671-1122.2026.08.008
Previous Articles Next Articles
Zhang Hongtao1,2, Wang Qingtao1,2, Zhang Liancheng3(
), Wang Jichang3
Received:2025-12-25
Online:2026-08-10
Published:2026-09-23
Contact:
Zhang Liancheng
E-mail:liancheng17@aliyun.com
CLC Number:
Zhang Hongtao, Wang Qingtao, Zhang Liancheng, Wang Jichang. Argus6: an IPv6 DDoS threat detection model[J]. Netinfo Security, 2026, 26(8): 1264-1276.
Add to citation manager EndNote|Ris|BibTeX
URL: http://netinfo-security.org/EN/10.3969/j.issn.1671-1122.2026.08.008
| 层名 | 输出形状 | 说明 |
|---|---|---|
| Input | [128,512,2048] | 2048位定长特征序列 |
| Linear | [128,512,64] | Transformer分支投影 2048→64 |
| TransformerEncoder | [128,512,64] | 全局建模(2×281,152) |
| Mean Pooling | [128,64] | 序列均值池化 |
| Linear | [128,512,64] | Mamba分支投影 2048→64 |
| Mamba | [128,512,64] | 状态空间序列建模 |
| Mean Pooling | [128,64] | 序列均值池化 |
| 特征拼接 | [128,128] | 拼接融合 |
| Fusion:Linear+LN+GeLU(128→64) | [128,64] | 融合降维 |
| Classifier:Linear+ GeLU+Linear(64→32→2) | [128,2] | 分类输出 |
| [1] | Cisco. 6lab IPv6 stats:world users[EB/OL]. (2025-11-30)[2025-12-10]. https://6lab.cisco.com/stats/cible.php?country=world&option=users.s. |
| [2] | IETF. Internet engineering task force[EB/OL]. (2025-09-20)[2025-12-10]. https://www.ietf.org/about/introduction/. |
| [3] | Hnamte V, Najar A A, Nhung-Nguyen H, et al. DDoS attack detection and mitigation using deep neural network in SDN environment[EB/OL]. (2023-12-18)[2025-12-10]. https://doi.org/10.1016/j.cose.2023.103661. |
| [4] | 张连成, 程兰馨, 杜雯雯, 等. IPv6网络安全[M]. 北京: 科学出版社, 2024. |
| [5] | Xia Wenhao, Zhang Liancheng, Guo Yi, et al. P4NSA: P4-based security protection technology for IPv6 neighbor solicitation and advertisement spoofing[EB/OL]. (2025-02-23)[2025-12-10]. https://doi.org/10.1016/j.cose.2025.104400. |
| [6] | Balarezo J F, Wang S, Chavez K G, et al. A survey on DoS/DDoS attacks mathematical modelling for traditional, SDN and virtual networks[EB/OL]. (2021-10-23)[2025-12-10]. https://doi.org/10.1016/j.jestch.2021.09.011. |
| [7] | Guerra J L, Catania C, Veas E. Datasets are not enough: challenges in labeling network traffic[EB/OL]. (2022-06-22)[2025-12-10]. https://doi.org/10.1016/j.cose.2022.102810. |
| [8] | Lee S W, Mohammed Sidqi H, Mohammadi M, et al. Towards secure intrusion detection systems using deep learning techniques: comprehensive analysis and review[EB/OL]. (2021-05-19).[2025-12-10]. https://doi.org/10.1016/j.jnca.2021.103111. |
| [9] | Xu Congyan, Zhang Fan, Yang Ziqi, et al. A few-shot network intrusion detection method based on mutual centralized learning[EB/OL]. (2025-03-21).[2025-12-10]. https://doi.org/10.1038/s41598-025-93185-0. |
| [10] | 蒋英肇, 陈雷, 闫巧. 基于双通道特征融合的分布式拒绝服务攻击检测算法[J]. 信息网络安全, 2023, 23(7): 86-97. |
| [11] | Gu A, Dao T. Mamba: linear-time sequence modeling with selective state spaces[EB/OL]. (2024-05-31).[2025-12-10]. https://arxiv.org/abs/2312.00752. |
| [12] | Wang Tongze, Xie Xiaohui, Wang Wenduo, et al. Netmamba: efficient network traffic classification via pre-training unidirectional mamba[C]// IEEE. 2024 IEEE 32nd International Conference on Network Protocols (ICNP). New York: IEEE, 2024: 1-11. |
| [13] | Fortunati S, Gini F, Greco M S, et al. An improvement of the state-of-the-art covariance-based methods for statistical anomaly detection algorithms[J]. Signal, Image and Video Processing, 2016, 10(4): 687-694. |
| [14] | Hoque N, Kashyap H, Bhattacharyya D K. Real-time DDoS attack detection using FPGA[J]. Computer Communications, 2017, 110: 48-58. |
| [15] | Naiem S, Khedr A E, Idrees A M, et al. Enhancing the efficiency of gaussian naïve bayes machine learning classifier in the detection of DDoS in cloud computing[J]. IEEE Access, 2023, 11: 124597-124608. |
| [16] | Maazalahi M, Hosseini S. K-means and meta-heuristic algorithms for intrusion detection systems[J]. Cluster Computing, 2024, 27(8): 10377-10419. |
| [17] | Sanmorino A, Gustriansyah R, Alie J. DDoS attacks detection method using feature importance and support vector machine[J]. JUITA: Journal Informatika, 2022, 10(2): 167-171. |
| [18] | Hai Tao, Zhou Jincheng, Adetiloye O A, et al. DDoS attack prediction using decision tree and random forest algorithms[C]//Springer. Proceedings of ICACTCE’23-The International Conference on Advances in Communication Technology and Computer Engineering. Heidelberg: Springer, 2023: 37-46. |
| [19] |
徐精诚, 陈学斌, 董燕灵, 等. 融合特征选择的随机森林DDoS攻击检测[J]. 计算机应用, 2023, 43 (11): 3497-3503.
doi: 10.11772/j.issn.1001-9081.2022111792 |
| [20] | 丑义凡, 易波, 王兴伟, 等. IPv6网络中基于MF-DL的DDoS攻击快速防御机制[J]. 计算机学报, 2021, 44(10): 2047-2060. |
| [21] | Alghazzawi D, Bamasag O, Ullah H, et al. Efficient detection of DDoS attacks using a hybrid deep learning model with improved feature selection[EB/OL]. (2021-12-01)[2025-12-10]. https://doi.org/10.3390/app112411634. |
| [22] | Elejla O E, Anbar M, Hamouda S, et al. Deep-learning-based approach to detect ICMPv6 flooding DDoS attacks on IPv6 networks[EB/OL]. (2022-06-16)[2025-12-10]. https://doi.org/10.3390/app12126150. |
| [23] | 王郁夫, 王兴伟, 易波, 等. IPv6中一种基于卷积的DDoS攻击两阶段防御机制[J]. 软件学报, 2024, 35 (5): 2522-2542. |
| [24] | 范明钰, 李珂. 一种基于RNN区分DDoS攻击类型的方法[J]. 信息网络安全, 2022, 22(7): 1-8. |
| [25] | Ouhssini M, Afdel K, Akouhar M, et al. Advancements in detecting, preventing, and mitigating DDoS sttacks in cloud environments: a comprehensive systematic review of state-of-the-art approaches[EB/OL]. (2024-08-26)[2025-12-10]. https://doi.org/10.1016/j.eij.2024.100517. |
| [26] | Li Siyuan, Zhang Liumei, Han Yu. LMIPv6ATK: a labeled dataset containing multiple ICMPv6-DDoS attacks[C]// 2023 International Conference on Networking and Network Applications (NaNA). Qingdao, China: IEEE, 2023: 52-57. |
| [27] | Abinayadevi C, Parvathy M, Manoj Kumar P. IDOS6-ICMPv6 based DDoS attack dataset[EB/OL]. (2024-12-26)[2025-12-10]. https://ieee-dataport.org/documents/idos6-icmpv6-based-ddos-attack-dataset. |
| [28] | Abiramasundari S, Ramaswamy V. Distributed denial-of-service (DDoS) attack detection using supervised machine learning algorithms[J]. Scientific Reports, 2025, 15(1): 13098. |
| [29] | Alduailij M, Khan Q W, Tahir M, et al. Machine-learning-based DDoS attack detection using mutual information and random forest feature importance method[EB/OL]. (2025-05-16).[2025-12-01]. https://doi.org/10.1038/s41598-024-84879-y. |
| [30] | Wang Yufu, Wang Xingwei, Ni Qiang, et al. BCDM: an early-stage DDoS incident monitoring mechanism based on binary-CNN in IPv6 network[J]. IEEE Transactions on Network and Service Management, 2024, 21(5): 5873-5887. |
| [31] | Zabeehullah, Arif F, Qazi M U H, et al. Hybrid CNN-LSTM model for DDoS attack detection in internet of things-based healthcare industry 5.0[J]. IEEE Internet of Things Journal, 2025, 12(22): 46075-46082. |
| [32] | Ding Zhaoxu, Zhong Guoqiang, Qin Xianping, et al. MF-Net: multi-frequency intrusion detection network for internet traffic data[EB/OL]. (2023-09-27).[2025-12-10]. https://doi.org/10.1016/j.patcog.2023.109999. |
| [1] | Zheng Tianming, Liu Shangdong, Li Haitian, Li Hua. Interactive convolution and Transformer based anomaly detection algorithm [J]. Netinfo Security, 2026, 26(7): 1077-1086. |
| [2] | CHEN Yuqi, QIAN Hanwei, XIA Lingling, WANG Qun. FEViT: A Frequency Domain Enhanced ViT for Deepfake Detection [J]. Netinfo Security, 2026, 26(3): 432-441. |
| [3] | ZHAO Wenyu, DANG Chenxi, DU Zhenhua, ZHANG Jian. Research and Implementation of Ransomware Detection Technology Based on Hardware Performance Counters [J]. Netinfo Security, 2025, 25(9): 1397-1406. |
| [4] | SUN Jianwen, ZHANG Bin, SI Nianwen, FAN Ying. Lightweight Malicious Traffic Detection Method Based on Knowledge Distillation [J]. Netinfo Security, 2025, 25(6): 859-871. |
| [5] | WEI Chaoren, XIA Wanxu, QU Gang, BAI Wanrong, YANG Liqun. Research on the Optimization Technology of Open Source Fuzzing Framework for Intelligent Systems [J]. Netinfo Security, 2025, 25(4): 587-597. |
| [6] | ZHANG Xinyou, GAO Zhichao, FENG Li, XING Huanlai. FFT-iTransformer-Based Cybersecurity Situation Awareness Feature Imputation and Prediction [J]. Netinfo Security, 2025, 25(2): 228-239. |
| [7] | LIU Qiang, WANG Jian, WANG Yanan, WANG Shan. A Dynamic Malware Detection Method Based on Ensemble Learning [J]. Netinfo Security, 2025, 25(1): 159-172. |
| [8] | ZHANG Bowen, LI Dong, ZHAO Yizhu, YU Junqing. Research on Endogenous Security Mechanism of Cloud Network Driven by IPv6 Address [J]. Netinfo Security, 2024, 24(1): 113-120. |
| [9] | LI Dong, YU Junqing, WEN Ruibin, XIE Yiding. Endogenous Security Methods for Container Cloud Based on IPv6 [J]. Netinfo Security, 2023, 23(12): 21-28. |
| [10] | YE Huanrong, LI Muyuan, JIANG Bo. Research on DGA Malicious Domain Name Detection Method Based on Transfer Learning and Threat Intelligence [J]. Netinfo Security, 2023, 23(10): 8-15. |
| [11] | DAI Xiang, SUN Haichun, NIU Shuo, ZHU Rongchen. Research on Chinese Question Answering Matching Based on Mutual Attention Mechanism and Bert [J]. Netinfo Security, 2021, 21(12): 102-108. |
| [12] | WANG Tengfei, CAI Manchun, LU Tianliang, YUE Ting. IPv6 Network Attack Source Tracing Method Based on iTrace_v6 [J]. Netinfo Security, 2020, 20(3): 83-89. |
| [13] | JIN Zhi-hu, GAN Yu-xi, JIN Yi, HU Long-bin. Discussion on Constructing Secure and Reliable IPv6 Customer Premise Network [J]. Netinfo Security, 2015, 15(8): 59-66. |
| [14] | . NULL [J]. , 2012, 12(Z): 0-0. |
| [15] | . NULL [J]. , 2012, 12(Z): 0-0. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||