基于 eBPF 与 LSTM 的 DDoS 攻击检测系统
DOI:
作者:
作者单位:

作者简介:

通讯作者:

基金项目:


DDoS Attack Detection System Based on eBPF and LSTM
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    针对网络异常流量检测中的 DDoS 攻击检测,以往的基于深度学习的解决方案都是在脱离系统实体的数据集上构建模型和优化参数,提出并实现一种使用 Linux 内核观测技术 eBPF(extended Berkeley Packet Filter)与深度学习技术结合的基于网络流量特征分析的网络异常流量检测系统。 系统采用 eBPF 直接从 Linux 内核网络栈最底层高效地采集网络流量特征数据,然后使用基于长短记忆网络 LSTM(Long Short Term Memory)构建的深度学习系统检测网络异常流量。 在具体实现中,系统首先通过 Linux 内核网络栈最底层 XDP(eXpress Data Path)中的 eBPF程序挂载点采集网络流量特征数据。 之后,使用 LSTM 构建神经网络模型和预测分类。 将系统应用于一个仿真实验网络环境得出的实验结果表明,系统的识别精确度达到 97. 9%,同时,在使用该系统的情况下,网络中的 TCP 与 UDP 通信的吞吐率仅平均下降 8. 53%。 结果表明:系统对网络通信影响较低,同时也实现了较好的检测效果,具有可用性,为网络异常流量检测提供了一种新的解决方法。

    Abstract:

    For DDoS attack detection in abnormal network traffic detection, previous deep learning-based solutions construct models and optimize parameters on datasets separated from system entities. This paper proposed and implemented a network anomaly traffic detection system based on network traffic characteristic analysis that combined Linux kernel observation technology eBPF (extended Berkeley Packet Filter) with deep learning technology. The system used eBPF to efficiently collect network traffic feature data directly from the bottom layer of the Linux kernel network stack, and then used a deep learning system based on the Long Short Term Memory (LSTM) to detect abnormal network traffic. In the specific implementation, the system first collected network traffic characteristic data through the eBPF program mount point in the bottom XDP (eXpress Data Path) of the Linux kernel network stack. LSTM was used to build neural network model and predict classification. The experimental results obtained by applying the system to a simulated experimental network environment showed that the recognition accuracy of the system reached 97. 9%. At the same time, in the case of using this system, the throughput rate of TCP and UDP communication in the network dropped by only 8. 53% on average. The results show that the system has a low impact on network communication, achieves better detection results, has the availability, and provides a new solution for abnormal network traffic detection.

    参考文献
    相似文献
    引证文献
引用本文

昌武洋, 付 雄, 王俊昌.基于 eBPF 与 LSTM 的 DDoS 攻击检测系统[J].重庆工商大学学报(自然科学版),2023,40(2):36-43
CHANG Wuyang, FU Xiong, WANG Junchang. DDoS Attack Detection System Based on eBPF and LSTM[J]. Journal of Chongqing Technology and Business University(Natural Science Edition),2023,40(2):36-43

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
历史
  • 收稿日期:
  • 最后修改日期:
  • 录用日期:
  • 在线发布日期: 2023-04-06
×
2023年《重庆工商大学学报(自然科学版)》影响因子稳步提升