DDoS attack detection method based on deep learning

Through deep learning-based methods, using SDAE and CNN-self-Attention models to extract and analyze attack characteristics in network traffic data, the existing DDoS attack detection methods solve the false alarms and underreport problems in identifying complex DDoS attacks, achieving higher detection accuracy and flexibility.

CN119945791AActive Publication Date: 2025-05-06XIDIAN UNIV HANGZHOU RES INST +1
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510168768.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-06
Estimated Expiration
2045-02-17

AI Technical Summary

Technical Problem

Existing DDoS attack detection methods have high false alarm rates and missed alarm rates when identifying complex large-scale, distributed DDoS attacks, and it is difficult to deal with diversified attack methods and camouflage traffic.

Method used

A deep learning-based approach is adopted to extract potential attack features in network traffic data through selective deep self-encoder (SDAE), and capture attack features from spatial and temporal dimensions using the CNN-self-Attention model to realize the detection and classification of DDoS attacks.

Benefits of technology

It improves the accuracy and flexibility of DDoS attack detection, reduces the false alarm rate and missed alarm rate, can more effectively identify complex DDoS attack modes, and takes into account computing performance and real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945791A_ABST
    Figure CN119945791A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and discloses a DDoS attack detection method based on deep learning, which comprises the following steps: S1, data preprocessing: carrying out preprocessing operations such as data cleaning, denoising and format standardization on an obtained network flow data stream to ensure that the data is suitable for subsequent processing; s2, feature selection: transmitting the preprocessed network data traffic to a feature selection module, and extracting potential attack features in the network traffic data by using a selective depth auto encoder (Selective Depth Autoencoder); and S3, attack detection: transmitting the extracted network traffic data features to a DDoS attack detection module, detecting whether the network traffic data is DDoS attack traffic by using a CNN-Self-Attention model, and identifying the attack type of the DDoS attack traffic. According to the method, the important representation can be extracted from the complex network flow data, the detection accuracy is improved, the accuracy of the detection result is high, and the method is suitable for a current DDoS attack detection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and in particular relates to a DDoS attack detection method based on deep learning. Background Art

[0002] With the widespread application and rapid development of the Internet of Things, the scale and complexity of the global network have increased significantly. The surge in network traffic and the doubling of the number of connected devices have made network security issues increasingly serious and have become the focus of attention from all walks of life. Distributed Denial of Service (DDoS) attacks, as a serious means of network attack, are increasingly being used to interfere with the normal operation of the network due to their distributed, coordinated and large-scale characteristics, posing a great threat to various network systems and services.

[0003] DDoS (Distributed Denial of Service) attack is a distributed denial of service attack, usually launched by a botnet consisting of a large number of malicious computers or devices distributed in different geographical locations. The target of the attack is usually a network, service, or website. The attacker uses a large amount of false traffic or requests to make the target system unable to respond to normal user requests, causing the target service to be unable to respond to requests normally or even completely crash. Due to its hidden attack method, huge traffic and scattered sources, DDoS attacks are difficult to defend against, causing immeasurable losses to areas such as network service security.

[0004] DDoS attacks are essentially a sudden, many-to-one communication method, and the attack traffic has obvious temporal and spatial characteristics. Therefore, traditional DDoS detection methods usually only focus on the statistical characteristics based on the time dimension of traffic, and do not fully consider the changes in the overall state of the network and the potential correlation of interactive communication patterns in attack traffic. Due to ignoring the characteristic changes of network traffic in the spatial and temporal dimensions, existing methods often perform poorly in identifying certain complex DDoS attacks, especially in the face of large-scale, distributed attacks, with high false positive and false negative rates.

[0005] In addition, traditional DDoS attack classification methods usually classify attacks based on single-dimensional traffic features. However, with the diversification of DDoS attack methods, especially the disguise of traffic features and the change of attack modes, many attacks have high similarities in the traffic dimension, making it difficult for existing classification methods to cope with complex fine-grained attack classification tasks. With the increase in network data volume and feature dimensions, the demand for classification calculations in existing models is also increasing, which requires classification methods to ensure high accuracy while also taking into account computing performance and real-time performance. Summary of the invention

[0006] The purpose of the present invention is to provide a DDoS attack detection method based on deep learning to solve the above-mentioned technical problems.

[0007] The technical solution adopted by the present invention to achieve the above-mentioned purpose is:

[0008] A DDoS attack detection method based on deep learning includes the following steps:

[0009] 1) Preprocess the acquired network traffic data stream;

[0010] 2) Use the selective deep autoencoder SDAE to extract potential attack features from the preprocessed network traffic data;

[0011] 3) Based on the extracted attack features, a deep learning model is used to detect whether the network traffic data is DDoS attack traffic and identify its attack type.

[0012] The step 1) comprises the following steps:

[0013] 1.1) Clean the acquired network traffic data stream;

[0014] 1.2) Perform SMOTE oversampling on the cleaned data stream;

[0015] 1.3) Normalize the oversampled data.

[0016] The step 1.1) is specifically as follows:

[0017] Remove irrelevant features that cannot distinguish attacks from normal traffic, as well as samples containing NaN values, infinite values, and null values. The irrelevant features include "Unnamed", "Flow ID", "Destination Port", "Source Port", "Destination IP", "Source IP", and "SimilarHTTP".

[0018] The step 1.2) is specifically as follows:

[0019] Select a class of samples whose number is less than the threshold from the data set as minority class samples. For each minority class sample X, use SMOTE oversampling to calculate its nearest k neighbor samples in the feature space, and randomly select a neighbor sample X from the selected k neighbor samples. n , according to the current sample and the neighbor sample X n Generate a new sample X new , that is, between the original sample X and the neighbor sample X n Randomly interpolate between to generate a new minority class sample X new ,Right now:

[0020] X new =X+θ(X n -X)

[0021] Here, θ is a random number between 0 and 1.

[0022] The step 2) comprises the following steps:

[0023] 2.1) Pre-training stage: The pre-processed raw data is input into the encoder part of the autoencoder model to obtain the low-dimensional potential representation of the input data. The decoder of the autoencoder model reconstructs the low-dimensional potential representation to obtain reconstructed data, and compares the reconstructed data with the original data, calculates the loss and feeds back to adjust the model parameters, and then conducts the next round of training until the training converges;

[0024] 2.2) Feature selection stage: A selective layer is added before the encoder obtained after the pre-training stage, and the decoder part is removed to obtain a new deep network model. The selective layer assigns a weight vector to each input feature. The encoder learns a new low-dimensional potential representation of the data based on the selected features, optimizes its similarity with the low-dimensional potential representation in the pre-training stage and the selection layer weights. Finally, only the features corresponding to non-zero weights are retained as a subset representing the entire feature space.

[0025] By minimizing the objective function, the similarity between the new low-dimensional potential representation and the low-dimensional potential representation in the pre-training stage and the weight of the selected layer are optimized, where the objective function is:

[0026]

[0027] Among them, W ≥ 0 represents the non-negativity constraint of weight, θ enc represents the parameters of the depth encoder, γ1>0 represents the coefficient parameter of the L1 regularization term of the encoder layer, γ2>0 represents the coefficient parameter of the L1 regularization term of the selection layer, represents the reconstructed code in the encoder network during the pre-training phase, f(XW,θ enc ) represents the reconstruction code of the depth encoder.

[0028] The step 3) comprises the following steps:

[0029] 3.1) Use batch normalization to normalize the input data;

[0030] 3.2) The normalized output is processed using the first convolution layer containing 8 1*3 convolution kernels, and linearly transformed using the ReLU activation function to obtain F0;

[0031] 3.3) Input F0 into two parallel convolutional layers to obtain F1 and F2, respectively, to extract deeper features from F0 in the horizontal and vertical directions, and then process it through the maximum pooling layer to obtain F pool1 and F pool2 ;

[0032] 3.4) Use the depth level layer to connect the output results of the two parallel convolutional layers and process them using the maximum pooling layer to obtain F concat ;

[0033] 3.5) After passing F0 through the maximum pooling layer, add it to F concat After being connected through a deep cascade layer and processed using an average pooling layer, we get F t ;

[0034] 3.6) Use the self-attention mechanism module that combines the convolution operation and the self-attention mechanism idea to t to process;

[0035] 3.6) The output of the self-attention mechanism module is processed through the dense layer, softmax layer and fully connected layer in turn to obtain the detection result.

[0036] The step 3.3) is specifically as follows:

[0037] After one layer of convolution operation, the first convolutional stream is processed again with an asymmetric convolution kernel and passed through a maximum pooling layer to obtain a deeper feature F. pool1 ;

[0038]

[0039] F pool1 =P max (F1)

[0040] in, It represents the output result after a layer of convolution operation. They represent the output results of processing using two asymmetric convolution blocks, F1 represents the processing result of the first convolution flow, D represents the depth cascade layer function, and P max represents the maximum pooling layer, F pool1 Represents the result of the first convolutional stream being processed by the maximum pooling layer;

[0041] The second convolutional stream is processed through two convolutional layers to obtain a deeper feature F pool2 :

[0042]

[0043] F pool2 =P max (F2)

[0044] in, represents the output result of the first convolutional layer, represents the output result of the second convolutional layer, F2 represents the processing result of the second convolutional stream, D represents the depth cascade layer function, P max represents the maximum pooling layer, F pool2 Represents the result of the second convolutional stream after the maximum pooling layer.

[0045] A DDoS attack detection system based on deep learning, comprising:

[0046] A data stream preprocessing module, used for preprocessing the acquired network traffic data stream;

[0047] A feature extraction module is used to extract potential attack features from the preprocessed network traffic data using a selective deep autoencoder SDAE;

[0048] The DDoS attack identification module is used to detect whether the network traffic data is DDoS attack traffic and identify its attack type based on the extracted attack features using a deep learning model.

[0049] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the DDoS attack detection method based on deep learning is implemented.

[0050] The present invention has the following beneficial effects and advantages:

[0051] 1. In view of the imbalance problem of data sets in existing DDoS detection technologies, the present invention adopts SMOTE oversampling technology to oversample the sample types with a smaller number, and increases the number of samples to solve the problem of imbalanced data sets.

[0052] 2. In order to solve the problem of excessive model overhead in existing DDoS detection technology, the present invention adopts SDAE for feature selection, autonomously trains to obtain the optimal number of feature selections, removes redundant features to reduce data dimensions, reduces the time complexity of the model, and reduces overhead.

[0053] 3. In order to solve the problem of information loss or difficulty in capturing global information when dealing with long-distance dependencies, the present invention adopts a self-attention model to capture the global dependencies in the sequence, and more comprehensively considers the complex global correlation information of each part of the network traffic data.

[0054] 4. In order to solve the problem of difficulty in identifying specific attack patterns, the present invention adopts the CNN-self-Attention model to capture more comprehensive attack features from the spatial dimension and the temporal dimension, so as to identify different attack patterns more accurately and flexibly. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 A flowchart of a DDoS attack detection method based on deep learning disclosed in an embodiment of the present invention.

[0056] Figure 2 This is a diagram of an implementation framework of a deep learning-based DDoS attack detection method disclosed in an embodiment of the present invention.

[0057] Figure 3 SDAE model structure diagram used in the embodiment of the present invention.

[0058] Figure 4 CNN model structure diagram used in the embodiment of the present invention.

[0059] Figure 5 This is a structural diagram of the self-attention mechanism model used in an embodiment of the present invention.

[0060] Figure 6 This is a structural diagram of the CNN-self-Attention model used in an embodiment of the present invention.

[0061] Figure 7 This is a schematic diagram of the confusion matrix of the CIC-DDoS-2019 dataset according to an embodiment of the present invention. DETAILED DESCRIPTION

[0062] The present invention is further described in detail below in conjunction with the accompanying drawings and embodiments.

[0063] like Figure 1 As shown and Figure 2As shown, the DDoS attack detection method based on deep learning of the present invention, first, the network traffic data is removed from redundant features and samples containing outliers through a data preprocessing module, then the SMOTE oversampling technology is used to increase the number of samples of attack types with fewer samples, and then the data is normalized so that the data can be processed by the deep learning model; the data set after data preprocessing is divided into a labeled training set and an unlabeled test set, which are respectively sent to the model training stage and the detection stage; in the training stage, the training data after data preprocessing is used as input and sent to the CNN-Self-Attention deep learning model for training, and the prediction results are obtained, compared with the real labels, the loss is calculated and the parameters of the model are adjusted by feedback, and then the next round of training is carried out until the training converges. The trained model parameters are sent to the model framework in the detection stage, and the test data is also preprocessed and entered into the model for classification to obtain the predicted label results, and finally various evaluation indicators are calculated to judge the effect of the intrusion detection system.

[0064] like Figure 3 As shown, the feature selection method based on SDAE of the present invention, first, in the pre-training stage, the pre-processed data is input into the encoder part of the model to obtain a low-dimensional potential representation of the input data, and then the decoder reconstructs the low-dimensional potential representation to obtain reconstructed data, compares the reconstructed data with the original data, calculates the loss and feeds back to adjust the parameters of the model, and then performs the next round of training until the training converges. Then, in the feature selection stage, a selective layer is added before the encoder obtained after the pre-training stage training is completed, and the decoder part is removed to obtain a new deep network model, the selective layer assigns a weight vector to each input feature, the encoder learns the low-dimensional potential representation of the data according to the selected features, optimizes its similarity with the low-dimensional potential representation in the pre-training stage and the weight of the selection layer, and finally, only the features corresponding to the non-zero weights are retained as a subset representing the entire feature space.

[0065] like Figure 4 As shown, the CNN model used in the present invention adopts a convolution decomposition method to decompose the large convolution kernel into two asymmetric small convolution kernels to extract deep features of the data from the horizontal and vertical directions respectively, reducing the amount of matrix multiplication operations, and adopts a residual network structure to alleviate the gradient vanishing problem.

[0066] like Figure 5 As shown in the figure, the Self-Attention model used in the present invention combines the idea of ​​convolution operation and self-attention mechanism. First, the local features are extracted by convolution operation, and then the feature map is divided into three parts: query (q), key (k) and value (v), and the feature output is obtained according to the calculation. Then, the residual edge is used to fuse the v feature with the self-attention feature to improve the model's back-propagation capability.

[0067] like Figure 6 As shown, the DDoS attack detection method based on deep learning of the present invention, the features selected by SDAE are first input into the CNN model to extract deep spatial features, and then input into the Self-Attention model to extract deep temporal features. Finally, they are processed in turn through the dense layer, softmax layer and fully connected layer to obtain the detection result.

[0068] The method of preprocessing network traffic data by the method of the present invention and the CNN-Self-Attention deep learning model will be specifically described below.

[0069] The DDoS attack detection method based on deep learning of the present invention comprises three steps: Step S1, a data preprocessing module, which performs preprocessing operations such as oversampling, data cleaning, denoising and format standardization on the acquired network traffic data stream to ensure that the data is suitable for subsequent processing;

[0070] Step S2, feature selection, transmits the preprocessed network data traffic to the feature selection module, and uses the selective deep autoencoder SDAE (Selective Deep Autoencoder) to extract potential attack features in the network traffic data;

[0071] Step S3, the attack detection module transmits the extracted network traffic data features to the DDoS attack detection module, and uses the deep learning model to detect whether the network traffic data is DDoS attack traffic and identify its attack type.

[0072] The DDoS attack detection method based on deep learning of the present invention, the specific implementation method of step S1 is as follows:

[0073] First, we remove seven irrelevant features, namely “Unnamed”, “Flow ID”, “Destination Port”, “Source Port”, “Destination IP”, “Source IP” and “SimilarHTTP”, which cannot distinguish attacks from normal traffic. Then, we clean the samples containing NaN values, infinite values ​​and null values ​​in the dataset.

[0074] Furthermore, the specific method of SMOTE oversampling in step S1 is as follows:

[0075] First, minority class samples are selected from the dataset. Then, for each minority class sample, SMOTE calculates its k nearest neighbors in the feature space. Then, a neighbor is randomly selected from the selected k neighbors and a new sample is generated based on the distance between the current sample and the neighbor. Then, random interpolation is performed between the original sample and the neighbor sample to generate a new minority class sample.

[0076] Furthermore, the specific calculation method of the SMOTE oversampling in step S1 is as follows:

[0077] X new =X+θ(X n -X)

[0078] Among them, θ is a random number between 0 and 1, X n is the neighboring sample.

[0079] Furthermore, the data normalization calculation method of step S1 is as follows:

[0080]

[0081] Among them, X sca represents the result of data normalization, X min Indicates the minimum value of the data, X max Indicates the maximum value of the data.

[0082] The DDoS attack detection method based on deep learning of the present invention, the specific implementation method of step S2 is as follows:

[0083] The feature selection module includes a pre-training stage and a feature selection stage.

[0084] Pre-training phase: In this phase, SDAE first trains a deep autoencoder to learn the low-dimensional potential representation of the input data by minimizing the reconstruction error. The encoder part of the autoencoder maps the input data to the latent space, and the decoder is responsible for reconstructing the latent representation back to the original data. The reconstructed data is compared with the original data, the loss is calculated and the parameters of the model are adjusted, and then the next round of training is carried out until the training converges. By optimizing this process, SDAE can obtain low-dimensional encodings that are globally representative.

[0085] Feature selection stage: During the feature selection process, SDAE introduces a customized selective layer, which is used to select the most relevant features by weighting the input features (through a feature-dependent weight vector). The weights of the selective layer are sparse through L1 regularization, thereby pushing the weights of redundant features to zero. The encoder learns a low-dimensional potential representation of the data based on the selected features, optimizing its similarity with the low-dimensional potential representation in the pre-training stage and the selection layer weights, that is, minimizing the following objective function:

[0086]

[0087] Ultimately, only features corresponding to non-zero weights are retained as a subset representing the entire feature space.

[0088] The DDoS attack detection method based on deep learning of the present invention, the specific implementation method of step S3 is as follows:

[0089] The attack detection module inputs the network traffic features extracted by the feature selection module into the CNN detection model, and firstly uses batch normalization to normalize the input data; the normalized output result is processed by a convolution layer containing 8 (1*3) convolution kernels, and linearly transformed by a ReLU activation function to obtain F0;

[0090]

[0091] F0 is input into two parallel convolutional layers to extract richer features from the horizontal and vertical directions respectively;

[0092] After one convolution operation, the first convolution stream is processed again with an asymmetric convolution kernel to extract deeper features.

[0093]

[0094] F pool1 =P max (F1)

[0095] The second convolutional stream is processed through two convolutional layers to extract deeper features:

[0096]

[0097] F pool2 =P max (F2)

[0098] After that, the outputs of the two parallel convolutional layers are connected through the depth level layer and processed through the maximum pooling layer;

[0099] F concat =D(Fpool1 ,F pool2 )

[0100] Afterwards, in order to prevent the gradient from disappearing, the output of the first convolutional layer is connected to the maximum pooling layer through the depth cascade layer and then through the average pooling layer P. avg deal with;

[0101] F t =P avg (z)+(X 1×1 (F concat ))

[0102] The processing result of the average pooling layer is input into the self-attention mechanism module, which combines the convolution operation and the self-attention mechanism. First, the local features are extracted using the convolution operation, and then the feature map is divided into three parts: query (q), key (k) and value (v), and the feature output is calculated;

[0103]

[0104] Where Q represents the query vector, K represents the key vector, V represents the value vector, and d k Represents the dimension of the key vector.

[0105] Finally, the output of the self-attention mechanism module is sent to the dense layer. After the dense layer, the output data is processed by the softmax layer and the fully connected layer to obtain the detection result.

[0106] After training the deep network with the network traffic training set data, the detection model is obtained. The network traffic test set data is preprocessed, and the trained detection model is used for detection, and the classification results are output to determine whether the current data is a DDoS attack and identify its specific attack type.

[0107] When training the detection model, the cross entropy loss function is used, and the detection accuracy of the detection model is calculated until the requirements are met to obtain a trained detection model.

[0108] The present invention uses the CIC-DDoS-2019 dataset compiled by the Canadian Institute for Cyber ​​Security to verify the effect of the DDoS attack detection method based on deep learning of the present invention. The dataset information is shown in Table 1. The model parameter settings are shown in Table 2. The evaluation indicators include confusion matrix, accuracy, precision, recall and F1 score to measure the performance of the algorithm.

[0109] Table 1 Dataset information:

[0110]

[0111]

[0112] Table 2 Model parameter settings:

[0113] parameter value Total number of features 88 Optimizer Adam Loss Function Binary Cross-Entropy Bath size 128 Epochs 30 Activation Function ReLU Learning Rate 0.001

[0114] The confusion matrix, also known as the error matrix, is a statistical count of the number of observations that the classification model classifies as incorrect or correct, and is used to judge the quality of the classifier. The confusion matrix results of the four types of attacks in the in-vehicle network attack dataset obtained in the experiment are as follows: Figure 7 As shown, it can be seen that the model detects various types of attacks very well.

[0115] As shown in Table 3, the performance of the method of the present invention on the CIC-DDoS-2019 dataset is shown.

[0116] Table 3 CIC-DDoS-2019 performance:

[0117] Model Accuracy Accuracy Recall F1-score CNN-Self-Attention 99.00% 99.08% 92.22% 95.52%

[0118] The above results show that the DDoS attack detection method based on deep learning proposed in the present invention has high accuracy, precision, recall rate and F1-score from the perspective of multi-dimensional and temporal characteristics of traffic characteristics, and can show good performance for different types of attacks on the CIC-DDoS-2019 dataset.

[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A DDoS attack detection method based on deep learning, characterized in that: The following steps are involved: 1) Preprocess the acquired network traffic data stream; 2) Use the selective deep autoencoder SDAE to extract potential attack features from the preprocessed network traffic data; 3) Based on the extracted attack features, a deep learning model is used to detect whether the network traffic data is DDoS attack traffic and identify its attack type.

2. According to a deep learning-based DDoS attack detection method according to claim 1, it is characterized in that: The step 1) comprises the following steps: 1.1) Clean the acquired network traffic data stream; 1.2) Perform SMOTE oversampling on the cleaned data stream; 1.3) Normalize the oversampled data.

3. According to a deep learning-based DDoS attack detection method according to claim 2, it is characterized in that: The step 1.1) is specifically as follows: Remove irrelevant features that cannot distinguish attacks from normal traffic, as well as samples containing NaN values, infinite values, and null values. The irrelevant features include "Unnamed", "FlowID", "Destination Port", "Source Port", "Destination IP", "Source IP", and "SimilarHTTP".

4. According to a deep learning-based DDoS attack detection method according to claim 2, it is characterized in that: The step 1.2) is specifically as follows: Select a class of samples whose number is less than the threshold from the data set as minority class samples. For each minority class sample X, use SMOTE oversampling to calculate its nearest k neighbor samples in the feature space, and randomly select a neighbor sample X from the selected k neighbor samples. n , according to the current sample and the neighbor sample X n Generate a new sample X new , that is, between the original sample X and the neighbor sample X n Randomly interpolate between to generate a new minority class sample X new ,Right now: X new =X+θ(X n -X) Here, θ is a random number between 0 and 1.

5. The DDoS attack detection method based on deep learning according to claim 1, characterized in that: The step 2) comprises the following steps: 2.1) Pre-training stage: The pre-processed raw data is input into the encoder part of the autoencoder model to obtain the low-dimensional potential representation of the input data. The decoder of the autoencoder model reconstructs the low-dimensional potential representation to obtain reconstructed data, and compares the reconstructed data with the original data, calculates the loss and feeds back to adjust the model parameters, and then conducts the next round of training until the training converges; 2.2) Feature selection stage: A selective layer is added before the encoder obtained after the pre-training stage, and the decoder part is removed to obtain a new deep network model. The selective layer assigns a weight vector to each input feature. The encoder learns a new low-dimensional potential representation of the data based on the selected features, optimizes its similarity with the low-dimensional potential representation in the pre-training stage and the selection layer weights. Finally, only the features corresponding to non-zero weights are retained as a subset representing the entire feature space.

6. A DDoS attack detection method based on deep learning according to claim 5, characterized in that: By minimizing the objective function, the similarity between the new low-dimensional potential representation and the low-dimensional potential representation in the pre-training stage and the weight of the selected layer are optimized, where the objective function is: Among them, W ≥ 0 represents the non-negativity constraint of weight, θ enc represents the parameters of the depth encoder, γ1>0 represents the coefficient parameter of the L1 regularization term of the encoder layer, γ2>0 represents the coefficient parameter of the L1 regularization term of the selection layer, represents the reconstructed code in the encoder network during the pre-training phase, f(XW,θ enc ) represents the reconstruction code of the depth encoder.

7. The DDoS attack detection method based on deep learning according to claim 1, characterized in that: The step 3) comprises the following steps: 3.1) Use batch normalization to normalize the input data; 3.2) The normalized output is processed using the first convolution layer containing 8 1*3 convolution kernels, and linearly transformed using the ReLU activation function to obtain F0; 3.3) Input F0 into two parallel convolutional layers to obtain F1 and F2, respectively, to extract deeper features from F0 in the horizontal and vertical directions, and then process it through the maximum pooling layer to obtain F pool1 and F pool2 ; 3.4) Use the depth level layer to connect the output results of the two parallel convolutional layers and process them using the maximum pooling layer to obtain F concat ; 3.5) After passing F0 through the maximum pooling layer, add it to F concat After being connected through a deep cascade layer and processed using an average pooling layer, we get F t ; 3.6) Use the self-attention mechanism module that combines the convolution operation and the self-attention mechanism idea to t to process; 3.6) The output of the self-attention mechanism module is processed through the dense layer, softmax layer and fully connected layer in turn to obtain the detection result.

8. The DDoS attack detection method based on deep learning according to claim 7, characterized in that: The step 3.3) is specifically as follows: After one layer of convolution operation, the first convolutional stream is processed again with an asymmetric convolution kernel and passed through a maximum pooling layer to obtain a deeper feature F. pool1 ; F pool1 =P max (F1) in, It represents the output result after a layer of convolution operation. They represent the output results of processing using two asymmetric convolution blocks, F1 represents the processing result of the first convolution flow, D represents the depth cascade layer function, and P max represents the maximum pooling layer, F pool1 Represents the result of the first convolutional stream being processed by the maximum pooling layer; The second convolutional stream is processed through two convolutional layers to obtain a deeper feature F pool2 : F pool2 =P max (F2) in, represents the output result of the first convolutional layer, represents the output result of the second convolutional layer, F2 represents the processing result of the second convolutional stream, D represents the depth cascade layer function, P max represents the maximum pooling layer, F pool2 Represents the result of the second convolutional stream after the maximum pooling layer.

9. A DDoS attack detection system based on deep learning, characterized in that: include: A data stream preprocessing module, used for preprocessing the acquired network traffic data stream; A feature extraction module is used to extract potential attack features from the preprocessed network traffic data using a selective deep autoencoder SDAE; The DDoS attack identification module is used to detect whether the network traffic data is DDoS attack traffic and identify its attack type based on the extracted attack features using a deep learning model.

10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by the processor, a DDoS attack detection method based on deep learning as described in any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • An unknown attack identification method based on a depth auto-encoder

    CN109829299A

  • Detection method and device for detecting DDoS attack and storage medium

    CN116566724A

  • Decentralized network DDoS attack identification method based on large language model

    CN116781341A

  • College teacher evaluation method based on auto-encoder clustering algorithm

    CN117035502A

  • DDoS attack detection method

    CN117278314A