In recent years, Distributed Denial of Service (DDoS) attacks have become prevalent and highly destructive network threats, making reliable, high-quality attack traffic datasets essential for defense research. However, existing datasets are often inadequate, failing to comprehensively reflect real attack scenarios, thereby highlighting the need for traffic data augmentation. Through in-depth analysis of real traffic data, we found implicit relationships between the multidimensional attributes of attack traffic and attack types, as well as unique temporal correlations. Based on this, this paper proposes a Time-Aware DDoS Traffic Generation (TADG) model based on a probabilistic graphical model (PGM) for data augmentation. The TADG model is structured with a five-layer dependency architecture and leverages the time dependency of Dirichlet distributions to model the dynamic evolution of attack characteristics over time. Experimental results demonstrate that the TADG model outperforms existing methods in terms of data fidelity and latent feature extraction. The generated attack traffic data exhibit significant advantages in implicit relationship mining, temporal correlation, and overall performance, providing strong support for research and applications in the field of network security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

TADG: A Probabilistic Graph Model for DDoS Data Augmentation

  • Jiahui Hu,
  • Ye Tian,
  • Gongli Xi,
  • Zeming Gao,
  • Xirong Que,
  • Xiangyang Gong

摘要

In recent years, Distributed Denial of Service (DDoS) attacks have become prevalent and highly destructive network threats, making reliable, high-quality attack traffic datasets essential for defense research. However, existing datasets are often inadequate, failing to comprehensively reflect real attack scenarios, thereby highlighting the need for traffic data augmentation. Through in-depth analysis of real traffic data, we found implicit relationships between the multidimensional attributes of attack traffic and attack types, as well as unique temporal correlations. Based on this, this paper proposes a Time-Aware DDoS Traffic Generation (TADG) model based on a probabilistic graphical model (PGM) for data augmentation. The TADG model is structured with a five-layer dependency architecture and leverages the time dependency of Dirichlet distributions to model the dynamic evolution of attack characteristics over time. Experimental results demonstrate that the TADG model outperforms existing methods in terms of data fidelity and latent feature extraction. The generated attack traffic data exhibit significant advantages in implicit relationship mining, temporal correlation, and overall performance, providing strong support for research and applications in the field of network security.