<p>The hidden network environment of multi-agent systems is complex and intricate. The data characteristics generated by SIP flood attacks may overlap and confuse with normal traffic characteristics, and the network traffic characteristics will dynamically change over time, thereby affecting the accuracy of SIP flood attack detection. Therefore, an SIP flood detection technique based on BiGRU algorithm is proposed for covert networks in multi-agent systems. This technology is divided into two levels of detection. The primary detection collects and analyzes the hidden network data of multi-agent systems, and determines whether the traffic is abnormal by calculating the Renyi entropy value; abnormal traffic enters the second-level attack detection stage, extracting abnormal traffic from multi-agent covert networks and using the BiGRU model to learn features bidirectionally to determine whether it is an SIP flooding attack. If it is, the result of the SIP flooding attack on the multi-agent covert network is output. The experimental results show that this technology can accurately determine abnormal traffic and accurately detect the time, attacker IP, and attack frequency of SIP flooding attacks in the hidden network of multi-agent systems. The application effect is good.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SIP Flooding Attack Detection Technology of Multi-agent System Covert Network Based on BiGRU Algorithm

  • Tong Wu,
  • Hengyu Liu,
  • Tong Li,
  • Wei Fan,
  • Dawei Hu,
  • Jianshi Bai

摘要

The hidden network environment of multi-agent systems is complex and intricate. The data characteristics generated by SIP flood attacks may overlap and confuse with normal traffic characteristics, and the network traffic characteristics will dynamically change over time, thereby affecting the accuracy of SIP flood attack detection. Therefore, an SIP flood detection technique based on BiGRU algorithm is proposed for covert networks in multi-agent systems. This technology is divided into two levels of detection. The primary detection collects and analyzes the hidden network data of multi-agent systems, and determines whether the traffic is abnormal by calculating the Renyi entropy value; abnormal traffic enters the second-level attack detection stage, extracting abnormal traffic from multi-agent covert networks and using the BiGRU model to learn features bidirectionally to determine whether it is an SIP flooding attack. If it is, the result of the SIP flooding attack on the multi-agent covert network is output. The experimental results show that this technology can accurately determine abnormal traffic and accurately detect the time, attacker IP, and attack frequency of SIP flooding attacks in the hidden network of multi-agent systems. The application effect is good.