DDOS attack detection method based on CNN-RNN hybrid model
By using the CNN-RNN hybrid model in DDoS attack detection, the spatial and timing characteristics in traffic data are extracted and modeled, the problem of insufficient accuracy and real-time in the prior art is solved, and more efficient DDoS attack detection is achieved.
Patent Information
- Application Number
- CN202510238869.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art lacks accuracy and real-time performance when processing high-dimensional complex traffic data of DDoS attacks, especially when dealing with new attacks and large-scale traffic.
Using the DDoS attack detection method based on the CNN-RNN hybrid model, local spatial features in traffic are extracted through CNN, and the dynamic process of traffic changes is captured using the timing features of RNN modeling to realize automatic feature learning.
It improves the accuracy of DDoS attack detection, enhances the adaptability and generalization capabilities of the model, and can more effectively deal with irregular attack patterns and large-scale traffic.
Smart Images

Figure CN120074934A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and in particular relates to a DDOS attack detection method based on a CNN-RNN hybrid model. Background Art
[0002] With the rapid development of Internet technology, network attacks are becoming increasingly complex and large-scale. Distributed Denial of Service (DDoS) attacks have become one of the core threats in the field of network security due to their strong destructiveness and high difficulty in defense. Traffic detection research on DDoS attacks usually relies on traditional feature engineering and machine learning methods, such as decision trees and support vector machines (SVMs). However, these methods have certain limitations when processing high-dimensional complex traffic data, especially when dealing with new attacks and large-scale traffic, and often cannot provide sufficient accuracy and real-time performance. Summary of the invention
[0003] 1. Technical issues to be resolved
[0004] The technical problem to be solved by the present invention is to propose a DDOS attack detection method for DDOS attack scenarios to improve detection accuracy.
[0005] (II) Technical solution
[0006] In order to solve the above technical problems, the present invention provides a DDOS attack detection method based on a CNN-RNN hybrid model, comprising the following steps:
[0007] Step 1: Data processing
[0008] Select a traffic data set for DDoS attacks. This traffic data set provides annotations of normal traffic and attack traffic, simulates the network environment in the real world, selects appropriate data from the traffic data set for preprocessing, removes unnecessary features, selects features and labels that need to be retained, and then processes them. Then, the processed data is divided into training sets and test sets.
[0009] Step 2: Build a CNN-RNN hybrid model
[0010] The CNN-RNN hybrid model is used to process sequence data with spatial and temporal structures. The CNN model extracts local features from the input data, while the RNN processes the dependencies in the sequence. The two are combined to extract local spatial features from the traffic data. At the same time, the temporal features are used to capture the dynamic process of traffic changes and realize automatic feature learning. The CNN-RNN hybrid model adopts a parallel structure, that is, the CNN model and the RNN model each process the original input data, extract features independently, and then merge these features.
[0011] Step 3: Model Training
[0012] Train the CNN-RNN hybrid model constructed in Step 2. During the training process, save the information of each iteration, including the loss value, accuracy rate during the training process, and the loss and accuracy rate on the test set. By plotting the loss curves of training and testing, determine whether there is overfitting or underfitting.
[0013] Step 4: Model Prediction: Use the trained CNN-RNN hybrid model to predict new traffic data; make a judgment based on the output result. If it is 0, it is judged as normal traffic, and if it is 1, it is judged as DDOS attack traffic.
[0014] Preferably, in Step 1, select the CIC-DDoS2019 dataset as the training data.
[0015] Preferably, in Step 1, the useful features to be retained include: flow duration, Total Fwd Packets, Total Backward Packets features, and the Label label.
[0016] Preferably, when processing the retained features and labels in Step 1, to make different features have the same scale, uniformly perform standardization processing on the numerical features, and then reshape the feature data into a three-dimensional format suitable for CNN input through reshape(). Separate the Label from the dataset and convert it into an integer label using LabelEncoder. Finally, divide the processed data into a certain proportion of training set and a certain proportion of test set.
[0017] Preferably, in the CNN-RNN hybrid model constructed in Step 2, the CNN model uses Conv1D() to create a one-dimensional convolutional layer, uses the ReLU activation function, and performs convolutional operations on the time series data to extract preset important features in the data; then perform one-dimensional pooling operations on the output data of the one-dimensional convolution to reduce the dimension of the features; the RNN model uses LSTM to capture the time series features; after the data extraction of the features of the CNN model and the RNN model is completed, use the concatenate() method in TensorFlow to splice the outputs of the CNN branch and the LSTM branch along the feature dimension to fuse the feature representations of the two; finally, perform binary classification on the fused features through a fully connected layer.
[0018] Preferably, the output shape of the CNN is (None, 64 layers), and the output shape of the CNN is also (None, 64 layers). After merging through concatenate(), the output is (None, 128 layers).
[0019] The present invention also provides a system for implementing the above method.
[0020] (III) Beneficial effects
[0021] Compared with the prior art, the method of the present invention has the following advantages: on the one hand, traditional methods may be limited by the limitations of feature selection and algorithms. When the attack type changes, the model may need to be retrained or the feature extraction method adjusted. While the CNN-RNN hybrid model not only focuses on local information during feature extraction, but can also perform deeper abstraction of data through multiple layers of networks. Further, through time series modeling, the model can cope with irregular attack patterns and has stronger generalization ability. On the other hand, in DDoS attacks, the attack traffic may be concentrated in terms of time and may also show aggregation in space (for example, the attack sources are concentrated in certain IP addresses). The CNN-RNN hybrid model can capture both spatial and temporal features simultaneously, improving the detection accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] To make the objectives, content and advantages of the present invention clearer, the following further describes in detail the specific embodiments of the present invention with reference to the drawings and embodiments.
[0024] The present invention proposes a DDoS attack detection method based on a CNN-RNN hybrid model for DDoS attack scenarios. The present invention uses a hybrid model based on Convolutional Neural Networks (CNN) and Recurrent Neural Network (RNN) for DDoS attack detection. By using CNN to extract local spatial features in the traffic and RNN to model the temporal features to capture the dynamic process of traffic changes, through automatic feature learning, it not only has higher detection accuracy, but also avoids the dependence on manual feature extraction of traditional methods, and has stronger adaptability and generalization ability.
[0025] The general design process of the method is as follows: first, perform preprocessing operations on the training data to facilitate subsequent model training; secondly, construct a CNN-RNN hybrid model; then train the model, and save the log information of each epoch during the training process to facilitate timely adjustment and optimization of parameters; finally, use the trained model to predict new traffic data. Refer to Figure 1 , the specific content of the present invention includes the following four parts:
[0026] Step 1. Data Processing: The method of the present invention selects the CIC-DDoS2019 dataset as the training data. This dataset is a traffic dataset for DDoS attacks released by the Canadian Institute for Cybersecurity (CIC), which provides annotations for normal traffic and attack traffic, simulates the network environment in the real world, and is specifically used for researching and evaluating DDoS attack detection and defense methods. According to the actual scenario requirements, appropriate data is selected from the above dataset for preprocessing, unnecessary features are removed, and the features and labels to be retained are selected (the useful features to be retained include features such as flow duration, Total Fwd Packets, Total Backward Packets, etc. and the Label label), then format conversion, normalization processing, etc. are carried out, and then it is converted into a format suitable for CNN input.
[0027] Among them, when processing the above features and labels, in order to make different features have the same scale, the numerical features need to be uniformly normalized, and then the feature data is reshaped into a three-dimensional format suitable for CNN input through reshape(). Since there is already a Label label in this dataset, the Label can be separately extracted from the dataset and converted into an integer label using LabelEncoder for subsequent operations.
[0028] Finally, the processed data is divided into an 80% training set and a 20% test set for subsequent model training.
[0029] Step 2. Construct a CNN-RNN Hybrid Model: The CNN-RNN hybrid model is used to process sequence data with spatial and temporal structures. CNN is good at extracting local features from input data, while RNN (such as LSTM or GRU) is good at dealing with long-term dependencies in sequences. The combination of the two can not only extract local spatial features in the traffic but also use temporal features to capture the dynamic process of traffic changes, and improve the detection accuracy through automatic feature learning.
[0030] In addition, the CNN-RNN hybrid model adopts a parallel structure, that is, in this hybrid model, CNN and RNN each process the original input data, independently extract features, and then these features are merged. The parallel structure can enhance the diversity of features and avoid the situation that the RNN receives "filtered" features rather than the original time series due to being in series, thus missing key temporal information.
[0031] Among them, the CNN model uses Conv1D() to create a one-dimensional convolutional layer, and uses the ReLU activation function. By performing convolutional operations on time series data, it is used to extract important features in the data. Then, a one-dimensional pooling operation is performed on the output data of the one-dimensional convolution to reduce the dimension of the features and reduce the computational complexity. The RNN model uses LSTM to capture temporal features. This is mainly because LSTM can effectively retain long-term dependencies when processing sequences and solve the problem of gradient disappearance that ordinary RNNs are prone to. After the CNN and RNN feature data are extracted, the concatenate() method in TensorFlow is used to concatenate the outputs of the CNN branch and the LSTM branch along the feature dimension to fuse the feature representations of both. Finally, binary classification is performed on the fused features through a fully connected layer. The schematic code is as follows:
[0032]
[0033] Where input_layer represents the input layer. Both CNN and RNN process the data of the input layer. The output shape of CNN is (None, 64 layers), and the output shape of RNN is also (None, 64 layers). After merging through concatenate(), the output is (None, 128 layers).
[0034] Step 3: Model training: Train the hybrid model constructed in Step 2. During the training process, save the information of each iteration, including the loss value, accuracy, and the loss and accuracy on the test set during the training process. By plotting the loss curves of training and testing, determine whether there is overfitting or underfitting, so as to adjust and optimize in a timely manner.
[0035] Step 4: Model prediction: Use the trained CNN-RNN hybrid model to predict new traffic data. Make a judgment based on the output result. If it is 0, it is judged as normal traffic; if it is 1, it is judged as DDOS attack traffic.
[0036] It can be seen that a DDOS attack detection method based on a CNN-RNN hybrid model proposed by the present invention extracts local spatial features in the traffic through CNN, uses the temporal features modeled by RNN to capture the dynamic process of traffic changes, and through automatic feature learning, not only has higher detection accuracy, but also avoids the dependence on artificial feature extraction of traditional methods, and has stronger adaptability and generalization ability.
[0037] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can still be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.
Claims
1. A DDOS attack detection method based on a CNN-RNN hybrid model, characterized in that: The following steps are involved: Step 1: Data processing Select a traffic data set for DDoS attacks. This traffic data set provides annotations of normal traffic and attack traffic, simulates the network environment in the real world, selects appropriate data from the traffic data set for preprocessing, removes unnecessary features, selects features and labels that need to be retained, and then processes them. Then, the processed data is divided into training sets and test sets. Step 2: Build a CNN-RNN hybrid model The CNN-RNN hybrid model is used to process sequence data with spatial and temporal structures. The CNN model extracts local features from the input data, while the RNN processes the dependencies in the sequence. The two are combined to extract local spatial features from the traffic data. At the same time, the temporal features are used to capture the dynamic process of traffic changes and realize automatic feature learning. The CNN-RNN hybrid model adopts a parallel structure, that is, the CNN model and the RNN model each process the original input data, extract features independently, and then merge these features. Step 3: Model training Train the CNN-RNN hybrid model built in step 2. During the training process, save the information of each iteration number, including the loss value and accuracy during the training process, as well as the loss and accuracy on the test set. By drawing the loss curves of training and testing, determine whether it is overfitting or underfitting. Step 4: Model prediction: Use the trained CNN-RNN hybrid model to predict new traffic data; make a judgment based on the output result. If it is 0, it is considered normal traffic; if it is 1, it is considered DDOS attack traffic.
2. The method according to claim 1, characterized in that In step 1, the CIC-DDoS2019 dataset is selected as training data.
3. The method according to claim 1, characterized in that In step 1, the useful features retained include: flowduration, Total Fwd Packets, Total Backward Packets features, and Label tags.
4. The method according to claim 1, characterized in that In step 1, when processing the retained features and labels, in order to make different features have the same scale, the numerical features are uniformly standardized, and then the feature data is reshaped into a three-dimensional format suitable for CNN input through reshape(). The Label is extracted from the dataset and converted into an integer label using LabelEncoder. Finally, the processed data is divided into a certain proportion of training sets and a certain proportion of test sets.
5. The method according to claim 4, characterized in that In step 1, the processed data is divided into 80% training set and 20% test set.
6. The method according to claim 1, characterized in that In the CNN-RNN hybrid model constructed in step 2, the CNN model uses Conv1D() to create a one-dimensional convolution layer and uses the ReLU activation function to perform convolution operations on time series data to extract preset important features in the data; The output data of the one-dimensional convolution is then subjected to a one-dimensional pooling operation to reduce the dimension of the features. The RNN model uses LSTM to capture time series features. After the CNN model and RNN model features have completed data extraction, the concatenate() method in TensorFlow is used to concatenate the outputs of the CNN branch and the LSTM branch along the feature dimension to fuse the feature representations of the two. Finally, the fused features are classified into two categories through a fully connected layer.
7. The method according to claim 6, characterized in that The CNN output shape is (None, 64 layers), and the CNN output shape is also (None, 64 layers). After concatenate(), the output is (None, 128 layers).
8. The method according to claim 1, characterized in that This method is applied in the field of network security.
9. A system for implementing the method according to any one of claims 1 to 8.
10. The system according to claim 9, characterized in that The system is applied in the field of network security.
Citation Information
Patent Citations
Internet-of-Things network attack traffic monitoring system based on spatial-temporal feature learning
CN112491894A
Novel Internet of Things wireless network attack detection method based on artificial intelligence
CN113543137A
DDoS attack detection method
CN117278314A
Network intrusion detection method, device and system based on deep learning neural network, and storage medium
CN117294476A
Method for building network intrusion detection system model based on DCNN-LSTM technology
CN117768225A