A neural network-based DDoS attack detection method for drone IoT

Through the neural network-based drone IoT DDoS attack detection method, drones are used as filtering nodes and filtering strategies are dynamically adjusted, which solves the problems of flexibility and limited resources in DDoS attack detection in IoT systems and achieves efficient attack identification and defense.

CN119995974BActive Publication Date: 2025-09-30JINAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510129541.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-09-30
Estimated Expiration
2045-02-05

AI Technical Summary

Technical Problem

When detecting and filtering DDoS attacks, existing IoT systems have problems such as inflexible filtering node deployment, fixed filtering policies, and limited computing resources. These problems make it difficult to cope with diverse attacks, resulting in insufficient system security.

Method used

A neural network-based drone IoT DDoS attack detection method is adopted. Drones are used as filtering nodes, and a DDoS attack detection model is obtained through neural network model training. The linear programming model is combined to optimize drone deployment and resource utilization, and the filtering strategy is dynamically adjusted to deal with different types of DDoS attacks.

Benefits of technology

It improves detection accuracy and reduces false alarm rate, ensuring that the system can adaptively identify diverse attacks under limited resource conditions and provide lasting security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995974B_ABST
    Figure CN119995974B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication protection technology and discloses a neural network-based method for detecting DDoS attacks in drone-based Internet of Things (IoT) networks. The method comprises receiving a data stream containing DDoS attacks uploaded by a rechargeable IoT device and detecting and filtering DDoS attacks in the data stream based on a preset DDoS attack detection model trained using a neural network model. The present invention uses drones as filtering nodes and detects and filters DDoS attacks in the data stream based on the DDoS attack detection model. Because the DDoS attack detection model is trained using a neural network model, the neural network model, through continuous optimization and adjustment, not only improves detection accuracy but also effectively reduces the false alarm rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication protection technology, and in particular to a method for detecting DDoS attacks on unmanned aerial vehicle (UAV) Internet of Things (IoT) based on a neural network. Background Art

[0002] With the rapid development of IoT technology, IoT devices have been widely used in fields such as agriculture and healthcare, playing a vital role as data transmitters. However, due to the small size and limited internal battery capacity of these devices, they are unable to meet the high-speed, multimodal, multi-connectivity, and high-energy demands of future communications. Therefore, providing a continuous power supply for IoT devices has become a key issue. Based on existing energy harvesting technologies, using solar energy to charge IoT devices has become a widely adopted solution.

[0003] However, with the increasing number of IoT devices and the expansion of their applications, wireless data transmission has exposed issues such as weak security, limited computing power, and insufficient standardization. These issues make IoT devices vulnerable to exploitation by malicious attackers, allowing them to become part of botnets and launch DDoS (Distributed Denial of Service) attacks against other IoT devices. Such attacks not only disrupt the normal functionality of the targeted devices but can also severely damage the stable operation of the entire IoT system. Therefore, how to effectively detect and filter DDoS attacks in IoT systems and protect the security and reliability of the system has become a critical issue that needs to be addressed.

[0004] While various methods exist for detecting and filtering DDoS attacks in IoT systems, they still suffer from significant shortcomings. First, current approaches often overlook the scalability of IoT systems when deploying filtering nodes. In most cases, filtering nodes are fixed and deployed in specific locations, lacking flexibility and making it difficult to adapt to the challenges of system expansion or contraction. Second, regarding the configuration of filtering programs, existing methods often use fixed filtering programs that are pre-installed in filtering nodes. This approach fails to dynamically adjust filtering strategies based on different types of DDoS attacks, significantly reducing the filtering effectiveness of filtering nodes facing diverse attacks. Finally, existing methods often implement independent filtering nodes. However, filtering nodes in IoT systems typically have limited computing resources. When faced with large-scale DDoS attack traffic, independent filtering nodes struggle to cope, failing to ensure the security of the entire system.

[0005] Therefore, there is an urgent need for a neural network-based UAV IoT DDoS attack detection method. Summary of the Invention

[0006] The purpose of the present invention is to overcome the above-mentioned deficiencies of the prior art and provide a neural network-based drone Internet of Things DDoS attack detection method to protect the Internet of Things system from DDoS attacks.

[0007] To achieve the above object, the technical solution of the present invention is:

[0008] A neural network-based method for detecting DDoS attacks on drones in the Internet of Things (UAV) is provided, the method comprising:

[0009] Receive a data stream containing DDoS attacks uploaded by a rechargeable IoT device, detect and filter DDoS attacks in the data stream based on a preset DDoS attack detection model; the DDoS attack detection model is trained by a neural network model.

[0010] Preferably, the DDoS attack detection model is trained by a neural network model and includes:

[0011] Generate several different sets of IoT system environment parameters;

[0012] The generated IoT system environmental parameters are used to solve a linear programming model to obtain a DDoS attack detection strategy; the optimization goal of the linear programming model is to minimize the number of drones deployed;

[0013] Constructing a data set based on the generated IoT system environment parameters and according to the DDoS attack detection strategy;

[0014] The data set is used to train a neural network model to obtain a DDoS attack detection model.

[0015] Preferably, the linear programming model includes the following constraints:

[0016] Energy consumption upper limit constraint: The energy consumed by each IoT device in each time slot must not exceed the sum of the energy collected in the time slot and the available energy at the beginning of the time slot;

[0017] Unique upload constraint: Each rechargeable IoT device can only upload data stream to one drone in each time slot;

[0018] Unique deployment constraint: Each drone can only be deployed at one location, and only one drone can be deployed at each location;

[0019] Computing resource constraints: The computing resources consumed by each drone in each time slot must not exceed the maximum value of its available computing resources;

[0020] Traffic balancing constraint: For each type of DDoS attack traffic, the DDoS attack traffic input of each drone in each time slot must be equal to the DDoS attack traffic output.

[0021] Preferably, the DDoS attack detection model takes the IoT system environment parameters uploaded by the rechargeable IoT device as input and outputs a prediction detection strategy, which includes a drone deployment strategy, a rechargeable IoT device upload strategy, a VNF configuration strategy, and a VNF execution strategy.

[0022] Preferably, the neural network-based drone IoT DDoS attack detection method further includes:

[0023] The DDoS attack detection model is adjusted, where the adjustment includes one adjustment, and the one adjustment includes:

[0024] Adjust the rechargeable IoT device upload strategy based on the drone deployment strategy:

[0025] If a rechargeable IoT device uploads a DDoS attack to one or more drone deployment locations, the following formula is used to adjust the location uploaded by the rechargeable IoT device:

[0026]

[0027] in, is the channel attenuation value between the rechargeable IoT device i and location l; is a set of locations where drones are deployed; the rechargeable IoT device i selects the location l that maximizes the formula to upload the data stream.

[0028] Preferably, adjusting the rechargeable IoT device upload strategy according to the drone deployment strategy further includes:

[0029] If a rechargeable IoT device uploads a DDoS attack to multiple locations, and drones are deployed in some locations, the following formula is used to adjust the location where the rechargeable IoT device uploads:

[0030]

[0031] in, Select the upload location for the device in the predicted value; the rechargeable IoT device i selects the location l with the minimum channel attenuation to upload the data stream.

[0032] Preferably, the one-time adjustment further includes:

[0033] Adjusting the VNF execution policy according to the VNF configuration policy:

[0034] If the VNF to be executed in the VNF execution policy is not pre-deployed on the drone, adjusting the VNF execution policy so that the drone cannot execute the VNF;

[0035] If filtering DDoS attacks according to the VNF execution strategy will cause the upper limit of the drone's computing power resources to be exceeded, the VNF execution strategy is adjusted using an annealing algorithm.

[0036] Preferably, the adjustment further includes:

[0037] Check the adjusted drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy, and VNF execution strategy. If the adjusted drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy, and VNF execution strategy cannot meet the traffic balance constraint, deploy a new drone and readjust the drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy, and VNF execution strategy.

[0038] Preferably, the drone includes a data receiving antenna, a data storage unit, a data antenna, and a processor; the data receiving antenna is responsible for receiving data streams from rechargeable IoT devices; the data storage unit is used to temporarily store DDoS attacks that cannot be immediately filtered locally and route them to other drones through the data antenna; the processor is responsible for deploying and executing VNFs to effectively detect and filter DDoS attacks.

[0039] Preferably, the rechargeable IoT device includes a solar panel, a rechargeable battery, a data acquisition gateway, a data storage unit, a data antenna, and a processor; the solar panel is connected to the rechargeable battery and is responsible for providing continuous energy support for the device; the data acquisition gateway is responsible for collecting and generating data streams from the surrounding environment, and the generated data streams are temporarily stored in the data storage unit and sent out through the data antenna after processing; the processor is responsible for managing and allocating the computing resources of the device, and calculating and adjusting the traffic of each DDoS attack in real time according to the wireless channel status.

[0040] Compared with the prior art, the present invention has the following beneficial effects:

[0041] The present invention uses drones to inspect device data streams and minimizes the number of deployed UAVs over multiple time periods to ensure that all DDoS attacks in the system are filtered out. It also optimizes the rechargeable IoT device upload strategy, drone deployment strategy, VNF deployment strategy, VNF execution strategy, and drone routing strategy, enabling the network to always be in an active defense state and provide lasting security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1The structure diagram of the UAV auxiliary rechargeable IoT system;

[0043] Figure 2 Schematic diagram of the grid structure for drone deployment;

[0044] Figure 3 This is the training flow chart of the DDoS attack detection model;

[0045] Figure 4 Flowchart for adjusting the DDoS attack detection model. DETAILED DESCRIPTION

[0046] Example:

[0047] The technical solution of the present invention is further described below with reference to the accompanying drawings and embodiments.

[0048] See Figure 1 The diagram below shows the structure of the drone-assisted rechargeable IoT system, which mainly includes two parts: IoT devices and drones. The rechargeable IoT devices are responsible for collecting solar energy and sending data streams with DDoS attacks. Figure 2 In the grid shown, the neural network-based drone IoT DDoS attack detection method provided in this embodiment is primarily applied to drone networks. The drones are responsible for receiving data streams containing DDoS attacks uploaded by rechargeable IoT devices and detecting and filtering DDoS attacks in the data streams based on a preset DDoS attack detection model trained by a neural network model.

[0049] As can be seen, this method uses drones as filtering nodes and detects and filters DDoS attacks in data streams based on a DDoS attack detection model. Because the DDoS attack detection model is trained using a neural network model, continuous optimization and adjustment of the neural network model not only improves detection accuracy but also effectively reduces the false alarm rate. This efficient detection capability enables reliable DDoS attack defense even on resource-limited edge devices, ensuring full resource utilization. Furthermore, neural networks possess powerful learning capabilities and can adaptively identify various types of DDoS attacks. Over time, by continuously learning and updating new attack patterns, neural networks can maintain the effectiveness and accuracy of the detection mechanism. This is particularly important for combating complex and ever-changing attack methods, enabling the network to maintain a proactive defense state and provide long-term security.

[0050] In a specific embodiment, if Figure 3 As shown, the DDoS attack detection model is trained by a neural network model and includes the following steps:

[0051] 310. Generate 10,000 sets of different IoT system environmental parameters;

[0052] 320. Solve a linear programming model using the IoT system environmental parameters generated in step 310 to obtain a DDoS attack detection strategy; the optimization goal of the linear programming model is to minimize the number of deployed drones;

[0053] Specifically, the optimization objective of the linear programming model is to minimize the number of drones deployed. The linear programming model contains the following main constraints: an energy consumption upper limit constraint, that is, the energy consumed by each IoT device in each time slot must not exceed the sum of the energy collected in that time slot and the available energy at the beginning of the time slot; a unique upload constraint, that is, each rechargeable IoT device can only upload data streams to one drone in each time slot; a unique deployment constraint, that is, each drone can only be deployed in one location, and only one drone can be deployed at each location; a computing power resource constraint, that is, the computing resources consumed by each drone in each time slot must not exceed the maximum value of its available computing power resources; and a traffic balance constraint, that is, for each type of DDoS attack traffic, the DDoS attack traffic input of each drone in each time slot must be equal to the DDoS attack traffic output to ensure traffic balance.

[0054] 330. Construct a data set based on the generated IoT system environment parameters and according to the DDoS attack detection strategy;

[0055] 340. Use the data set to train a neural network model to obtain a DDoS attack detection model.

[0056] In other words, the DDoS attack detection model is constructed based on existing environmental parameters and the detection strategy determined by the linear programming model. A data set is then used to train the neural network model, so that the resulting DDoS attack detection model can accurately reflect the detection strategies in various environments.

[0057] After the DDoS attack detection model is trained, the IoT system environment parameters uploaded by the rechargeable IoT device are used as input to the DDoS attack detection model. In this embodiment, the IoT system environment parameters uploaded by the rechargeable IoT device are as follows:

[0058] (1) The network operating time is 5 time slots. The channel state in each time slot remains unchanged, but changes between time slots. The path loss parameter is 2, and the attenuation coefficients of the LoS channel and the NLoS channel are 1 and 20 respectively.

[0059] (2) The carrier frequency is 2.4 GHz, the channel bandwidth is 20 MHz, and the noise power is -90 dBm;

[0060] (3) Solar energy modeling based on Hidden Markov Model;

[0061] (4) The solar panel area of ​​the rechargeable IoT device is 30 × 30 square centimeters;

[0062] (5) The rechargeable battery capacity of the rechargeable IoT device is 20J;

[0063] (6) The transmit power of rechargeable IoT devices is 43dBm;

[0064] (7) The UAV’s transmission power is 30dBm;

[0065] (8) It takes 120 clock cycles for the drone to process 1 bit of data stream.

[0066] The DDoS attack detection model outputs a predictive detection strategy based on the IoT system environment parameters uploaded by the input rechargeable IoT device. The predictive detection strategy includes a drone deployment strategy, an IoT device upload strategy, a VNF (Virtual Network Function) configuration strategy, and a VNF execution strategy.

[0067] Since the prediction detection strategy output by the DDoS attack detection model may not meet the constraints of the linear programming model, it needs to be adjusted, such as Figure 4 As shown, the adjustment includes one adjustment:

[0068] Adjust the rechargeable IoT device upload strategy based on the drone deployment strategy:

[0069] If a rechargeable IoT device uploads a DDoS attack to one or more drone deployment locations, the following formula is used to adjust the location l uploaded by the rechargeable IoT device: * :

[0070]

[0071] in, is the channel attenuation value between the rechargeable IoT device i and location l; is a set of locations where drones are deployed; the rechargeable IoT device i selects the location l that maximizes the formula to upload the data stream.

[0072] In an optional embodiment, adjusting the rechargeable IoT device upload strategy according to the drone deployment strategy further includes:

[0073] If a rechargeable IoT device uploads a DDoS attack to multiple locations, and some locations have drones deployed, the following formula is used to adjust the location of the rechargeable IoT device uploading l *:

[0074]

[0075] in, Select the upload location for the device in the predicted value; the rechargeable IoT device i selects the location l with the minimum channel attenuation to upload the data stream.

[0076] In this way, by adjusting the upload strategy of rechargeable IoT devices, the number of deployed UAVs can be minimized in multiple time periods to ensure that all DDoS attacks in the system are filtered.

[0077] In an optional embodiment, the one-time adjustment further includes:

[0078] Adjust the VNF execution policy according to the VNF configuration policy:

[0079] If the VNF of type k to be executed in the VNF execution policy is not pre-deployed on the drone, adjust the VNF execution policy so that the drone cannot execute the VNF of type k;

[0080] If filtering DDoS attacks according to the VNF execution policy will cause the drone's computing resource limit to be exceeded, the annealing algorithm is used to adjust the VNF execution policy.

[0081] In an optional embodiment, the adjustment further includes: checking the adjusted drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy and VNF execution strategy; if the adjusted drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy and VNF execution strategy cannot meet the traffic balance constraint, deploying a new drone and readjusting the drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy and VNF execution strategy.

[0082] In one specific embodiment, the rechargeable IoT device includes the following key modules: a solar panel, a rechargeable battery, a data acquisition gateway, a data storage unit, a data antenna, and a processor. The solar panel, connected to the rechargeable battery, provides continuous energy to the device. The data acquisition gateway collects and generates data streams from the surrounding environment. These data streams may contain packets from DDoS attacks. These streams are temporarily stored in the data storage unit and then transmitted via the data antenna after processing. The processor, as the core module, connects and coordinates the work of all other modules. It not only manages and allocates the device's computing resources but also calculates and adjusts the traffic flow of each DDoS attack in real time based on the wireless channel status to optimize the transmission strategy.

[0083] In one specific embodiment, the drone's key modules include a data receiving antenna, a data storage unit, a data antenna, and a processor. The data receiving antenna receives data streams from rechargeable IoT devices, which may contain data related to DDoS attacks. The data storage unit temporarily stores DDoS attacks that can't be immediately filtered locally for further processing. For DDoS attacks that can't be immediately filtered, the drone routes this data via the data antenna to other drones, leveraging their computing resources for collaborative filtering. The processor, the drone's core module, connects all other modules and is responsible for deploying and executing VNFs to effectively detect and filter DDoS attacks, ensuring system security and stability.

[0084] In summary, the present invention, based on network virtualization technology, deploys multiple IoT devices with solar charging capabilities in the wild for wireless data transmission. Some IoT devices launch DDoS attacks, and drones are used as filtering nodes. The number of deployed UAVs is minimized over multiple time periods to ensure that all DDoS attacks in the system are filtered. In a time-varying environment, a DDoS attack detection and filtering method is proposed by comprehensively considering factors such as the data and energy status of IoT devices, the status of wireless channels, the upload strategy of IoT devices, the location deployment strategy of drones, the VNF (Virtual Network Function) deployment strategy, and the routing strategy between drones, thereby protecting the IoT system from DDoS attacks.

[0085] The above embodiments are intended only to illustrate the technical concepts and features of the present invention. Their purpose is to enable those skilled in the art to understand the contents of the present invention and implement them accordingly. They are not intended to limit the scope of protection of the present invention. Any equivalent changes or modifications made based on the essence of the present invention are intended to be covered by the scope of protection of the present invention.

Claims

1. A neural network-based drone IoT DDoS attack detection method for drone networks, characterized by: The method comprises: Receive a data stream containing DDoS attacks uploaded by a rechargeable IoT device, and detect and filter DDoS attacks in the data stream based on a preset DDoS attack detection model trained by a neural network model. The DDoS attack detection model uses IoT system environmental parameters uploaded by the rechargeable IoT device as input and outputs a predictive detection strategy, which includes a drone deployment strategy, a rechargeable IoT device upload strategy, a VNF configuration strategy, and a VNF execution strategy. The method further comprises: The DDoS attack detection model is adjusted, where the adjustment includes one adjustment, and the one adjustment includes: Adjusting the rechargeable IoT device upload strategy according to the drone deployment strategy includes: If a rechargeable IoT device uploads a DDoS attack to one or more drone deployment locations, the following formula is used to adjust the location l uploaded by the rechargeable IoT device: * : in, is the channel attenuation value between the rechargeable IoT device i and location l; is a set of locations where drones are deployed; the rechargeable IoT device i selects the location l that maximizes the formula to upload data stream; The adjusting the rechargeable IoT device upload strategy according to the drone deployment strategy further includes: If a rechargeable IoT device uploads a DDoS attack to multiple locations, and some locations have drones deployed, the following formula is used to adjust the location of the rechargeable IoT device uploading l * : in, Select the upload location for the device in the predicted value; the rechargeable IoT device i selects the location l with the minimum channel attenuation to upload the data stream.

2. The neural network-based drone IoT DDoS attack detection method according to claim 1, wherein: The DDoS attack detection model is trained by a neural network model and includes: Generate several different sets of IoT system environment parameters; The generated IoT system environmental parameters are used to solve a linear programming model to obtain a DDoS attack detection strategy; the optimization goal of the linear programming model is to minimize the number of drones deployed; Constructing a data set based on the generated IoT system environment parameters and according to the DDoS attack detection strategy; The data set is used to train a neural network model to obtain a DDoS attack detection model.

3. The neural network-based drone IoT DDoS attack detection method according to claim 2, wherein: The linear programming model includes the following constraints: Energy consumption upper limit constraint: The energy consumed by each IoT device in each time slot must not exceed the sum of the energy collected in the time slot and the available energy at the beginning of the time slot; Unique upload constraint: Each rechargeable IoT device can only upload data stream to one drone in each time slot; Unique deployment constraint: Each drone can only be deployed at one location, and only one drone can be deployed at each location; Computing resource constraints: The computing resources consumed by each drone in each time slot must not exceed the maximum value of its available computing resources; Traffic balancing constraint: For each type of DDoS attack traffic, the DDoS attack traffic input of each drone in each time slot must be equal to the DDoS attack traffic output.

4. The neural network-based drone IoT DDoS attack detection method according to claim 1, wherein: The one-time adjustment also includes: Adjusting the VNF execution policy according to the VNF configuration policy includes: If the VNF to be executed in the VNF execution policy is not pre-deployed on the drone, adjusting the VNF execution policy so that the drone cannot execute the VNF; If filtering the DDoS attack according to the VNF execution policy will cause the upper limit of the drone computing resources to be exceeded, the VNF execution policy is adjusted using an annealing algorithm.

5. The neural network-based drone IoT DDoS attack detection method according to claim 4, wherein: The adjustments also include: Check the adjusted drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy, and VNF execution strategy. If the adjusted drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy, and VNF execution strategy cannot meet the traffic balance constraint, deploy a new drone and readjust the drone deployment strategy, rechargeable IoT device upload strategy, VNF deployment strategy, and VNF execution strategy.

6. The neural network-based drone IoT DDoS attack detection method according to claim 1, wherein: The drone includes a data receiving antenna, a data storage unit, a data antenna, and a processor; the data receiving antenna is responsible for receiving data streams carrying DDoS attacks from rechargeable IoT devices; The data storage unit is used to temporarily store DDoS attacks that cannot be immediately filtered locally and route them to other drones via the data antenna; The processor is responsible for deploying and executing VNF.

7. The neural network-based drone IoT DDoS attack detection method according to claim 1, wherein: The rechargeable IoT device includes a solar panel, a rechargeable battery, a data acquisition gateway, a data storage unit, a data antenna, and a processor. The solar panel is connected to the rechargeable battery and is responsible for providing continuous energy support for the device. The data acquisition gateway is responsible for collecting and generating data streams containing DDoS attacks from the surrounding environment. The generated data streams are temporarily stored in the data storage unit and transmitted through the data antenna after processing. The processor is responsible for managing and allocating computing resources of the device, and calculating and adjusting the traffic of each DDoS attack in real time according to the wireless channel status.