Experiments with Reduction of Network Datasets for DDoS Analysis
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F63839172%3A_____%2F25%3A10133837" target="_blank" >RIV/63839172:_____/25:10133837 - isvavai.cz</a>
Výsledek na webu
<a href="https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11297489" target="_blank" >https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=11297489</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.23919/CNSM67658.2025.11297489" target="_blank" >10.23919/CNSM67658.2025.11297489</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Experiments with Reduction of Network Datasets for DDoS Analysis
Popis výsledku v původním jazyce
DDoS analysis and precise mitigation are still challenges due to more sophisticated DDoS attacks, their growing volume, and the diversity of network traffic itself. The machine learning methods enable automated analysis and subsequent mitigation by learning the legitimate traffic to be able to infer the boundary between the current DDoS and legitimate traffic during an attack. Since processing large packet samples is costly, especially if the sample is used during the DDoS analysis online, this paper assembles and evaluates several pipelines to reduce a large legitimate capture into a compact but representative packet sample for the timely analysis. The quality of the reduction is evaluated statistically and based on the resulting effectiveness of the ML method. The results show that the reduction pipelines produce samples with higher variability and contribute to the creation of boundaries that include a smaller proportion of legitimate traffic during mitigation than when using an unreduced sample of the same size.
Název v anglickém jazyce
Experiments with Reduction of Network Datasets for DDoS Analysis
Popis výsledku anglicky
DDoS analysis and precise mitigation are still challenges due to more sophisticated DDoS attacks, their growing volume, and the diversity of network traffic itself. The machine learning methods enable automated analysis and subsequent mitigation by learning the legitimate traffic to be able to infer the boundary between the current DDoS and legitimate traffic during an attack. Since processing large packet samples is costly, especially if the sample is used during the DDoS analysis online, this paper assembles and evaluates several pipelines to reduce a large legitimate capture into a compact but representative packet sample for the timely analysis. The quality of the reduction is evaluated statistically and based on the resulting effectiveness of the ML method. The results show that the reduction pipelines produce samples with higher variability and contribute to the creation of boundaries that include a smaller proportion of legitimate traffic during mitigation than when using an unreduced sample of the same size.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
<a href="/cs/project/LM2023054" target="_blank" >LM2023054: e-Infrastruktura CZ</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
Proceedings of the 2025 21st International Conference on Network and Service Management (CNSM)
ISBN
978-3-903176-75-1
ISSN
2165-963X
e-ISSN
—
Počet stran výsledku
6
Strana od-do
1-6
Název nakladatele
IEEE
Místo vydání
Bologna, Italy
Místo konání akce
Bologna, Italy
Datum konání akce
27. 10. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
—