计算机科学 ›› 2026, Vol. 53 ›› Issue (8): 455-468.doi: 10.11896/jsjkx.251000056

• 信息安全 • 上一篇    下一篇

基于多聚合异构图卷积模型的SDN饱和攻击检测方法

钱清1,2, 冉龙文1, 王欢1,2, 崔允贺3, 王凌云1   

  1. 1 贵州财经大学信息学院 贵阳 550025
    2 贵州省计算与网络融合重点实验室 贵阳 550025
    3 贵州大学计算机科学与技术学院文本计算与认知智能教育部工程研究中心 贵阳 550025
  • 收稿日期:2025-10-14 修回日期:2025-11-22 发布日期:2026-08-17
  • 通讯作者: 崔允贺(yhcui@gzu.edu.cn)
  • 作者简介:(qqian2018_p@163.com)
  • 基金资助:
    国家自然科学基金(62462010,61902085);贵州省重点实验室建设项目(QKHPTZSYS[2025]005);贵州省基础研究计划面上项目(黔科合基础MS(2026)056);贵州省教育厅自然科学科研项目(黔教合KY字[2023]065号,黔教合KY字[2023]014号)

Multi-aggregation Heterogeneous Graph Neural Network-based Saturation Attack DetectionMethod for SDN

QIAN Qing1,2, RAN Longwen1, WANG Huan1,2, CUI Yunhe3, WANG Lingyun1   

  1. 1 School of Information, Guizhou University of Finance and Economics, Guiyang 550025, China
    2 Guizhou Province Key Laboratory of Computing and Network Convergence, Guiyang 550025, China
    3 Engineering Research Center of Text Computing and Cognitive Intelligence, Ministry of Education, School of Computer Science and Technology, Guizhou University, Guiyang 550025, China
  • Received:2025-10-14 Revised:2025-11-22 Online:2026-08-17
  • About author:QIAN Qing,born in 1986,Ph.D,asso-ciate professor,is a member of CCF(No.K8203S).Her main research interests include natural language processing,digital media forensics and multimedia signal processing.
    CUl Yunhe,born in 1987,Ph.D,asso-ciate professor,is a member of CCF(No.F3600M).His main research interests include lightweight large mo-dels,network security,software-defined networks,data center networks and network telemetry.
  • Supported by:
    National Natural Science Foundation of China(62462010, 61902085),Construction Project for Guizhou Provincial Key Laboratory(QKHPTZSYS[2025] 005),Guizhou Provincial Basic Research Program General Projects(QKH-Basic-MS(2026)056) and Natural Science Researching Program of D.o.E. of Guizhou(Qian Edu.& Tech. [2023] 065,Qian Edu. & Tech. [2023] 014).

摘要: 饱和攻击是一种资源消耗型攻击,亦是软件定义网络面临的关键网络安全威胁之一。当前,基于图神经网络的饱和攻击检测方法主要将网络流建模为同构图结构,虽取得一定成效,但在检测过程中难以充分捕捉网络设备与流量之间的复杂交互特征。同时,现有方法在节点信息聚合机制方面存在局限,限制了其检测精度的进一步提升。针对上述问题,提出一种基于异构分层图神经网络的饱和攻击检测方法MARATHON。该方法构建了一种能够精确表征流量-主机-交换机间关联关系的异构流图结构,该结构充分考虑了流量、主机与交换机的差异化特征,从而有效刻画设备与流量之间的交互行为。在此基础上,设计了一种新型图神经网络检测模型。该模型融合了3类聚合机制,即主机/交换机同构聚合、主机-流量/交换机-流量异构聚合,以及流量-主机-流量/流量-交换机-流量元路径聚合,通过分层特征提取策略充分挖掘网络流中潜在的判别性信息,以提升攻击检测的精度。在公开数据集IMC10和4SICS上的实验结果表明,MARATHON方法在准确率、召回率与F1分数等多项指标上均优于现有主流方法。在IMC10数据集Fattree拓扑下,MARATHON的准确率与宏召回率分别达到97.5%与98.3%;在4SICS数据集Agis拓扑下,其准确率与宏召回率进一步提升至98.4%与98.5%。实验结果验证了所提方法的有效性与优越性。

关键词: 饱和攻击检测, 软件定义网络, 异构图卷积

Abstract: Saturation attack is a resource-consuming attack and one of the key cybersecurity threats facing software-defined networks.The current saturation attack detection methods based on graph neural networks mainly model network flows as isomorphic structures and achieve certain results,However,they fail to fully capture the complex interaction characteristics between network devices and traffic during the detection process.At the same time,the existing methods have limitations in the node information aggregation mechanism,which limits the further improvement of their detection accuracy.To solve the above problems,this paper proposes a saturation attack detection method based on a heterogeneous hierarchical graph neural network,MARATHON.This method constructs a heterogeneous flow graph structure that can accurately characterize the relationship between traffic,host and switch,which fully considers the differentiated characteristics of traffic,host and switch,so as to effectively describe the interaction behavior between devices and traffic.On this basis,a new graph neural network detection model is designed,which integrates three types of aggregation mechanisms:host/switch isomorphic aggregation,host-traffic/switch-traffic heterogeneous aggregation,and traffic-host-traffic/traffic-switch-traffic metapath aggregation,which fully mines the potential discriminant information in the network flow through hierarchical feature extraction strategy to improve the accuracy of attack detection.Experimental results on the public datasets IMC10 and 4SICS show that the MARATHON method is better than the existing mainstream methods in terms of accuracy,recall and F1 score.Specifically,under the Fattree topology of IMC10 dataset,the accuracy and macro recall of MARATHON reach 97.5% and 98.3%,respectively.Under the Agis topology of the 4SICS dataset,the accuracy and macro recall are further improved to 98.4% and 98.5%,which verifies the effectiveness and superiority of the proposed method.

Key words: Saturation attack detection, Software-defined network, Heterogeneous graph convolution

中图分类号: 

  • TP393
[1] YE M,WANG J,JIANG Q,et al.SDN-based Integrated Communication and Storage Edge In-network Storage Node Selection Method[J].Computer Science,2025,52(8):343-353.
[2] WU Z H,WEI Q,WANG Q X.Survey for Attack and Defense Approaches of OpenFlow-enabled Software Defined Network[J].Computer Science,2017,44(6):121-132.
[3] CUI Y,QIAN Q,GUO C,et al.Towards DDoS detection mecha-nisms in software-defined networking[J].Journal of Network and Computer Applications,2021,190:103156.
[4] TANG D,GAO C,LIANG W,et al.FTMaster:A detection and mitigation system of low-rate flow table overflow attacks via SDN[J].IEEE Transactions on Network and Service Management,2023,20(4):5073-5084.
[5] TANG D,ZHENG Z,YIN C,et al.FTODefender:An efficient flow table overflow attacksdefending system in SDN[J].Expert Systems with Applications,2024,237:121460.
[6] ZHENG J,LI D.GCN-TC:Combining trace graph with statistical features for network traffic classification[C]//ICC 2019-2019 IEEE International Conference on Communications(ICC).IEEE,2019:1-6.
[7] DENG X,ZHU J,PEI X,et al.Flow topology-based graph con-volutional network for intrusion detection in label-limited IoT networks[J].IEEE Transactions on Network and Service Ma-nagement,2022,20(1):684-696.
[8] WANG K,CUI Y,QIAN Q,et al.USAGE:Uncertain flowgraph and spatio-temporal graph convolutional network-based saturation attack detection method[J].Journal of Network and Computer Applications,2023,219:103722.
[9] RAN L,CUI Y,ZHAO J,et al.TITAN:Combining a bidirectional forwarding graph and GCN to detect saturation attack targeted at SDN[J].PLoS One,2024,19(4):e0299846.
[10] RAN L,CUI Y,SHEN G,et al.Towards Saturation Attack De-tection in SDN:A Device Hyperedge Graph and Flow-Device Hypergraph Neural Network-Based Method[C]//International Conference on Intelligent Computing.Singapore:Springer Nature Singapore,2025:50-62.
[11] JI Z,CUI Y,GUO Y,et al.Towards saturation attack detection in SDN:a multi-edge representation learning-based method[J].Journal of King Saud University Computer and Information Sciences,2025,37(6):138.
[12] KUBRA K,LEVENT A,GURKAN G,et al.JESS:Joint Entropy-Based DDoS Defense Scheme in SDN[J].IEEE Journal on Selected Areas in Communications,2018,36(10):2358-2372.
[13] LI Z,XING W,KHAMAISEH S,et al.Detecting saturation attacks based on self-similarity of OpenFlow traffic[J].IEEE Transactions on Network and Service Management,2019,17(1):607-621.
[14] NAJAR A A,NAIK S M.Cyber-secure SDN:A CNN-based approach for efficient detection andmitigation of DDoS attacks[J].Computers & Security,2024,139:103716.
[15] HNAMTE V,NAJAR A A,NHUNG-NGUYEN H,et al.DDoSattack detection and mitigation using deep neural network in SDN environment[J].Computers & Security,2024,138:103661.
[16] XU J,WANG L,XU Z.An enhanced saturation attack and its mitigation mechanism in software-defined networking[J].Computer Networks,2020,169:107092.
[17] YANG L,SONG Y,GAO S,et al.Griffin:Real-time network intrusion detection system via ensemble of autoencoder in SDN[J].IEEE Transactions on Network and Service Management,2022,19(3):2269-2281.
[18] NAGARAJ K,STARKE A,MCNAIR J.Glass:a graph learning approach for software defined network based smart grid ddos security[C]//ICC 2021-IEEE International Conference on Communications.2021.
[19] CAO Y,JIANG H,DENG Y,et al.Detecting and mitigatingDDoS attacks in SDN using spatial-temporal graph convolutio-nal network[J].IEEE Transactions on Dependable and Secure Computing,2021,19(6):3855-3872.
[20] DU R,HUANG M,LIU F.Multiple Classification Algorithm Based on Graph Convolutional Neural Network for Intrusion Detection[J].Signal,Image and Video Processing,2025,19(6):1-8.
[21] YE Y,HOU S,CHEN L,et al.Out-of-sample node representation learning for heterogeneous graph in real-time android malware detection[C]//28th International Joint Conference on Artificial Intelligence(IJCAI).2019.
[22] SUN X,YANG J,WANG Z,et al.Hgdom:Heterogeneousgraph convolutional networks for malicious domain detection[C]//NOMS 2020-2020 IEEE/IFIP Network Operations and Management Symposium.IEEE,2020:1-9.
[23] ZHANG T,XU R,ZHANG J,et al.DSHGT:Dual-Supervisors Heterogeneous GraphTransformer—A Pioneer Study of Using Heterogeneous Graph Learning for Detecting Software Vulnerabilities[J].ACM Transactions on Software Engineering and Methodology,2024,33(8):1-31.
[24] CHEN T,DONG C,LYU M,et al.Apt-kgl:An intelligent apt detection system based on threat knowledge and heterogeneous provenance graph learning[J].IEEE Transactions on Dependable and Secure Computing,2022,19(1):1-15.
[25] MUDGAL A,VERMA A,SINGH M,et al.FloRa:Flow table low-rate overflow reconnaissance and detection in SDN[J].IEEE Transactions on Network and Service Management,2024,21(6):6670-6683.
[26] HAMILTON W,YING Z,LESKOVEC J.Inductive representa-tion learning on large graphs[C]//Advances in Neural Information Processing Systems.2017.
[27] SCHLICHTKRULL M,KIPF T N,BLOEM P,et al.Modeling relational data with graph convolutional networks[C]//Euro-pean Semantic Web Conference.Cham:Springer,2018:593-607.
[28] WANG X,JI H,SHI C,et al.Heterogeneous graph attention network[C]//The World Wide Web Conference.2019:2022-2032.
[29] KIPF T N.Semi-supervised classification with graph convolu-tional networks[J].arXiv:1609.02907,2016.
[30] VELIČKOVIĆ P,CUCURULL G,CASANOVA A,et al.Graph attention networks[J].arXiv:1710.10903,2017.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!