>
Fa   |   Ar   |   En
   تحلیل ترافیک شبکه با یادگیری ماشین برای تشخیص سریع‌تر حمله قطع سرویس توزیع‌یافته  
   
نویسنده ظهیری محمد ,شیرینی کیمیا ,صمدی قره ورن سینا
منبع علوم و فناوري هاي پدافند نوين - 1402 - دوره : 14 - شماره : 4 - صفحه:273 -282
چکیده    در این تحقیق، به بررسی و تحلیل چهار الگوریتم یادگیری ماشین برای شناسایی حملات ddos پرداخته شده است. برای این منظور، از پایگاه‌داده intrusion detection evaluation dataset (cic-ids2017) استفاده شده است که شامل نمونه‌های ترافیک بات‌ نت است. الگوریتم‌های knn، rf، naive bayes و j48 با استفاده از ویژگی‌های انتخاب‌شده با تابع selectkbest و کتابخانه scikit-learn آموزش داده شدند. نتایج نشان می‌دهند که الگوریتم‌های rf، knn و j48 از نظر دقت بسیار به هم نزدیک بوده و عملکرد خوبی در شناسایی ترافیک بات ‌نت و ترافیک معمولی داشته‌اند. الگوریتم rf با f1-score بالاتر نسبت به knn، دقت بیشتری در شناسایی ترافیک بات ‌نت ارائه داده است. از سوی دیگر، الگوریتم naive bayes، باوجود دقت کلی بالا، در شناسایی ترافیک بات ‌نت عملکرد ضعیفی داشته و precision و recall آن برای دسته‌بندی بات‌ نت بسیار پایین است. الگوریتم j48 نیز عملکرد نسبتاً خوبی داشته، ولی به دلیل مقدار پایین recall، بخش قابل‌توجهی از ترافیک حمله به‌اشتباه به‌عنوان ترافیک معمولی شناسایی شده است. این تحقیق تاکید دارد که برای مقابله با حملات ddos، استفاده از الگوریتم‌های مدرن یادگیری ماشین می‌تواند دقت و سرعت شناسایی را بهبود بخشد. در آینده، آزمایش مدل‌ها در شرایط واقعی و با داده‌های متنوع‌تر، به‌منظور افزایش دقت و قابلیت‌های مدل‌های شناسایی حملات اینترنتی، ضروری است.
کلیدواژه یادگیری ماشین، ترافیک شبکه، حمله ddos، درخت تصمیم، نزدیک‌ترین همسایه
آدرس دانشگاه شهید مدنی آذربایجان, ایران, دانشگاه تبریز, ایران, دانشگاه تبریز, ایران
پست الکترونیکی s.samadi@tabrizu.ac.ir
 
   network traffic analysis with machine learning for faster detection of distributed denial of service attack  
   
Authors zahiri mohammad ,shirini kimia ,samadi gharehveran sina
Abstract    in this research, four machine learning algorithms for detecting ddos attacks have been investigated and analyzed. for this purpose, the intrusion detection evaluation dataset (cic-ids2017) database, which includes botnet traffic samples, has been used. knn, rf, naive bayes, and j48 algorithms were trained using the selected features with the selectkbest function and the scikit-learn library. the results show that the rf, knn, and j48 algorithms are very close in terms of accuracy and have performed well in identifying botnet traffic and normal traffic. the rf algorithm with a higher f1-score compared to knn has provided more accuracy in identifying botnet traffic. on the other hand, the naive bayes algorithm, despite its high overall accuracy, has performed poorly in identifying botnet traffic, and its precision and recall are very low for botnet classification. the j48 algorithm has also performed relatively well, but due to the low recall value, a significant part of the attack traffic has been mistakenly identified as normal traffic. this research emphasizes that to deal with ddos attacks, the use of modern machine learning algorithms can improve the accuracy and speed of identification. in the future, it will be necessary to test the models in real-world conditions with more diverse data in order to increase the accuracy and capabilities of internet attack detection models.
Keywords ddos attack ,decision tree ,machine learning ,nearest neighbor ,network traffic
 
 

Copyright 2023
Islamic World Science Citation Center
All Rights Reserved