<p>The cybersecurity challenge posed by botnet-driven Distributed Denial of Service (DDoS) attacks targeting IoT monitoring systems involves the manipulation of sensor data to disrupt firewall reasoning mechanisms. To counteract these unknown attacks, this paper focuses on botnet device streaming data-directed DDoS attacks, captures cross-window attacks using time slices with a fixed overlap rate, and employs the Expectation-Maximization (EM) algorithm to incrementally update Gaussian Mixture Model (GMM) parameters in order to adapt to new attack variants. The corresponding parameters of the sample data are inferred to eliminate False Data Injection Attack components, thereby achieving the objective of attack detection and identification. In the proposed Expectation-Maximization Transformer hybrid model, parallel processing is utilized to enhance computational speed. Additionally, the detection batch size is adjusted to optimize performance and reduce the number of training cycles. We adapt the learning rate within the Software-Defined Networking (SDN) framework to ensure generalization capability across the Internet of Things. Experimental analysis demonstrates that the lightweight reasoning model presented in this paper achieves parallel computation of the attention matrix. Compared to other mainstream methods, the model attains a computational accuracy of 96.2%. Its robustness is 10.24% higher than that of alternative schemes, and simulations for DDoS attack detection yield the best performance. These results confirm that the cybersecurity detection approach based on the EM-Transformer model proposed in this paper offers high detection accuracy and strong capability for detecting and preventing potential future network threats, making it highly suitable for widespread application in IoT security.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Application of EM-transformer hybrid model in real-time detection of directed DDoS attacks on botnet devices

  • Liping Hao,
  • Xuesong Wang

摘要

The cybersecurity challenge posed by botnet-driven Distributed Denial of Service (DDoS) attacks targeting IoT monitoring systems involves the manipulation of sensor data to disrupt firewall reasoning mechanisms. To counteract these unknown attacks, this paper focuses on botnet device streaming data-directed DDoS attacks, captures cross-window attacks using time slices with a fixed overlap rate, and employs the Expectation-Maximization (EM) algorithm to incrementally update Gaussian Mixture Model (GMM) parameters in order to adapt to new attack variants. The corresponding parameters of the sample data are inferred to eliminate False Data Injection Attack components, thereby achieving the objective of attack detection and identification. In the proposed Expectation-Maximization Transformer hybrid model, parallel processing is utilized to enhance computational speed. Additionally, the detection batch size is adjusted to optimize performance and reduce the number of training cycles. We adapt the learning rate within the Software-Defined Networking (SDN) framework to ensure generalization capability across the Internet of Things. Experimental analysis demonstrates that the lightweight reasoning model presented in this paper achieves parallel computation of the attention matrix. Compared to other mainstream methods, the model attains a computational accuracy of 96.2%. Its robustness is 10.24% higher than that of alternative schemes, and simulations for DDoS attack detection yield the best performance. These results confirm that the cybersecurity detection approach based on the EM-Transformer model proposed in this paper offers high detection accuracy and strong capability for detecting and preventing potential future network threats, making it highly suitable for widespread application in IoT security.