Deep-Learning-Based Approach to Detect ICMPv6 Flooding DDoS Attacks on IPv6 Networks
نویسندگان
چکیده
Internet Protocol version six (IPv6) is more secure than its forerunner, four (IPv4). IPv6 introduces several new protocols, such as the Control Message (ICMPv6), an essential protocol to networks. However, it exposes networks some security threats since ICMPv6 messages are not verified or authenticated, and they mandatory that cannot be blocked disabled. One of currently facing exploitation by malicious actors execute distributed denial service (DDoS) attacks. Therefore, this paper proposes a deep-learning-based approach detect flooding DDoS attacks on introducing ensemble feature selection technique utilizes chi-square information gain ratio methods select significant features for attack detection with high accuracy. In addition, long short-term memory (LSTM) employed train model selected features. The proposed was evaluated using synthetic dataset false-positive rate (FPR), accuracy, F-measure, recall, precision, achieving 0.55%, 98.41%, 98.39%, 97.3%, 99.4%, respectively. Additionally, results reveal outperforms existing approaches.
منابع مشابه
Analysis of Entropy Based DDoS Attack Detection to Detect UDP Based DDoS Attacks in IPv6 Networks
Distributed Denial of Service (DDoS) attacks is an important thread in internet. In IPv6 internet worms are difficult to identify, because of the total amount of traffic which does not allow the instant investigation of fine points. In Internet Protocol Version 6 (IPv6) networks one of the common traffic flows occurs is UDP data flows. It is an unreliable data flow. This characteristic can be u...
متن کاملAn Entropy Based Approach to Detect and Distinguish DDoS Attacks from Flash Crowds in VoIP Networks
Voice over IP (VoIP) is a facility of providing voice services in accordance with IP (Internet Protocol) which provides better QoS (Quality of Service) than Public Switched Telephone Network (PSTN) at comparatively less cost.. Since Internet suffers from various threats, VoIP, which uses IP for servicing the Clients also results in stepping down QoS. One of the major QoS threats is Server Avail...
متن کاملFlooding Based DDoS Attacks and Their Influence on Web Services
In present era, the world is highly dependent on the Internet and it is considered as main infrastructure of the global information society. Therefore, the Availability of information and services is very critical for the socio-economic growth of the society. However, the inherent vulnerabilities of the Internet architecture provide opportunities for a lot of attacks on its infrastructure and s...
متن کاملMitigating Flooding-Based DDoS Attacks by Stochastic Fairness Queueing
Flooding-based DDoS attacks is a very common way to attack a victim machine by directly or indirectly sending a large amount of malicious traffic to it. Stochastic Fairness Queueing (SFQ) is a typical implementation of Fair Queueing. This paper focuses on exploring the feasibility of mitigating flooding-based DDoS attacks by queueing disciplines. A comparative study is made between SFQ and FCFS...
متن کاملA Defense Framework for Flooding-based DDoS Attacks
Distributed denial of service (DDoS) attacks are widely regarded as a major threat to the Internet. A flooding-based DDoS attack is a very common way to attack a victim machine by sending a large amount of malicious traffic. Existing networklevel congestion control mechanisms are inadequate in preventing service quality from deteriorating because of these attacks. Although a number of technique...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Applied sciences
سال: 2022
ISSN: ['2076-3417']
DOI: https://doi.org/10.3390/app12126150