Network Anomaly Early Warning through Generalized Network Temperature and Deep Learning

Yufan Feng,Changda Wang
DOI: https://doi.org/10.1007/s10922-023-09727-2
2023-02-16
Journal of Network and Systems Management
Abstract:A successful DDoS attack disables systems and causes huge economic losses, which is every company's worst fear. The goal of IT security is to avoid this worst-case situation. Anomaly detection is one of the most imperative currently. However, feature selection and accuracy detection limitations are still pertinent to traditional algorithms. Moreover, these methods cannot predict and respond to DDoS attacks in advance. Therefore, this paper proposes a network anomaly early warning method based on Generalized Network Temperature (GNT) and deep learning. The approach first classifies DDoS-induced network congestion. Then, it predicts network traffic characteristics using Bi-GRU and discovers the class of congestion states corresponding to each feature collection through the Stacking model. In what follows, this method connects the two models to achieve the early warning function. Furthermore, a combination of criteria is designed based on congestion states and attack probability to improve the early warning accuracy. The proposed model is validated using the intrusion detection dataset CICIDS2017 and UNSW-NB15. The Bi-GRU model achieves the best result of 77.95% and 81.96% for the R-Squared traffic prediction on the two datasets. The Stacking model achieves 94.37% accuracy and 95.82% for congestion states classification, respectively. After the model is connected, our proposed approach performs the best warning accuracy of 96.84% on the CICIDS2017 dataset and 95.68% on the UNSW-NB15 dataset.
computer science, information systems,telecommunications
What problem does this paper attempt to address?