计算机科学 ›› 2026, Vol. 53 ›› Issue (6A): 250300060-9.doi: 10.11896/jsjkx.250300060

• 信息安全 • 上一篇    下一篇

基于多尺度时空融合注意力网络的DDoS攻击检测方法

李杰1, 王宝会1, 张静远2   

  1. 1 北京航空航天大学软件学院 北京 100191
    2 北京市公安局 北京 100029
  • 出版日期:2026-06-16 发布日期:2026-06-12
  • 通讯作者: 王宝会(wangbh@buaa.edu.cn)
  • 作者简介:(spankingsnail@163.com)

DDoS Attack Detection Based on Attention Mechanism TCN-BiLSTM

LI Jie1, WANG Baohui1, ZHANG Jingyuan2   

  1. 1 School of Software,Beihang University,Beijing 100191,China
    2 Public Security Bureau of Beijing,Beijing 100029,China
  • Published:2026-06-16 Online:2026-06-12
  • About author:LI Jie,born in 1996,postgraduate.His main research interests include network security and artificial intelligence,etc.
    WANG Baohui,born in 1973,senior engineer,master supervisor.His main research interests include network security,big data,

摘要: DDoS攻击对个人和国家数据安全造成巨大威胁,如何精准检测并识别DDoS攻击具有重要意义。文中针对传统DDoS攻击检测中存在的预测效率低、过拟合、泛化能力差等问题,提出一种基于多尺度时空融合注意力网络的DDoS攻击检测算法。首先,针对异质数据进行特征区分与增补,并注入白噪声增强模型对随机扰动的鲁棒性。其次,在算法层面提出多尺度TCN与BiLSTM并行的分层策略,覆盖由短时到长时的多重依赖,并将分层输出的特征矩阵通过深度可分离卷积进行压缩,以提炼核心时序模式并有效控制网络复杂度。最后,将压缩后的向量序列传到Transformer自注意力机制,实现对跨尺度与跨通道特征的全局关联建模,动态凸显具有高判别力的时序上下文切片,识别DDoS攻击的异常流量。基于CIC-IDS-2017数据集分别进行对比实验和消融实验,结果表明,基于多尺度时空融合注意力网络算法的预测精确率可达99.82%,召回率为99.35%,F1值为99.58%,较TCN与BiLSTM模型的精确率提升了4.28%,可有效识别DDoS攻击。

关键词: 分布式拒绝服务, 多尺度时空融合, 自注意力机制, 双向长短期记忆网络

Abstract: DDoS attacks pose a great threat to personal and national data security.How to accurately detect and identify DDoS attacks is of great significance.Aiming at the problems such as low prediction efficiency,overfitting and poor generalization ability in traditional DDoS attack detection,a new DDoS attack detection algorithm based on multi-scale spatiotemporal fusion attention network is proposed.Firstly,the features of heterogeneous data are distinguished and supplemented,and white noise is injected to enhance the robustness of the model to random disturbance.Secondly,at the algorithm level,a hierarchical strategy of multi-scale TCN and BiLSTM in parallel is proposed to cover multiple dependencies from short time to long time,and the layered output feature matrix is compressed by deep separable convolution to extract core timing patterns and effectively control network complexity.Finally,the compressed vector sequence is transferred to Transformer self-attention mechanism to realize global correlation modeling of cross-scale and cross-channel features,dynamically highlight timing context slices with high discriminating power,and identify abnormal traffic of DDoS attacks.Comparison experiments and ablation experiments are conducted based on the CIC-IDS-2017 dataset respectively.The results show that the prediction accuracy of the multi-scale spatial-temporal fusion attention network algorithm can reach 99.82%,the recall rate is 99.35%,and the F1 value is 99.58%,which is 4.28% higher than the accuracy of TCN and BiLSTM models and it can effectively identify DDoS attacks.

Key words: Distributed denial of service, Multi-scale space-time fusion, Self-attention mechanism, Bidirectional long short-term memory network

中图分类号: 

  • TN915.08
[1] JIA J,WANG Q S,CHEN Y L,et al.DDoS Attack DetectionMethod Based on Attention Mechanism[J].Computer Engineering and Design,2021,42(9):2439-2445.
[2] JIA B,LIANG Y.Anti-D chain:A lightweight DDoS attack detection scheme based on heterogeneous ensemble learning in blockchain[J].China Communications,2020,17(9):11-24.
[3] WANG Y.A Deep Learning-Based Detection Method for DDoS Attack Traffic[J].Network Security Technology and Application,2021(11):49-51.
[4] WANG Y X,HUANG H X.A Review of the Development and Defense of DDoS Attacks[J].Modern Computer,2021(2):51-56.
[5] CHEN F,BI X H,WANG J J,et al.A Survey on the Development of DDoS Attack Defense Technologies[J].Chinese Journal of Network and Information Security,2017,3(10):16-24.
[6] JIA M,SHU Y,GUO Q,et al.DDoS attack detection method for space-based network based on SDN architecture[J].ZTE communications,2020,18(4):18.
[7] LIU F Y,PRUNUS S K,SONG F,et al.DDoS Attack Malicious Behavior Knowledge Base Broussonetia papyrifera Construction [J].Telecommunications Science,2021,37(11):17-32.
[8] XIE X,LI J P,HU X Y,et al.High performance DDoS attack detection system based on distribution statistics[M]//Lecture Notes in Computer Science.Cham:Springer International Publishing,2019:132-142.
[9] JING X,YAN Z,JIANG X,et al.Network traffic fusion and analysis against DDoS flooding attacks with a novel reversible sketch[J].Information Fusion,2019,51:100-113.
[10] CHEN H S,CHEN J J.Statistical-based detection of distributed denial-of-service attacks in the Internet of Things[J].Journal of Jilin University(Engineering and Technology Edition),2020,50(5):1894-1904.
[11] ARSHI M,NASREEN M D,MADHAVIK.A survey of DDOS attacks using machine learning techniques[J].E3S Web of Conferences,2020(184):01052.
[12] JIA B,HUANG X,LIU R,et al.A DDoS attack detectionmethod based on hybrid heterogeneous multiclassifier ensemble learning[J].Journal of Electrical and Computer Engineering,2017,2017(1):4975343.
[13] MAO Y,GAO R.DDoS Attack Detection Based on Entropy and SVM Algorithm [J].Journal of Chongqing University of Science and Technology(Natural Sciences Edition),2024,26(2):50-55.
[14] XU J C,CHEN X B,DONG Y L.A Multi-Type DDoS Attack Detection Method Based on Deep Forest [J].Software Guide,2024,23(2):106-112.
[15] LI N N,WANG Y,ZHOU L,et al.DDoS Attack Random Forest Detection Method Based on Secondary Screening of Feature Importance [J].Computer Science,2021,48(S1):464-467,476.
[16] POLAT H,POLAT O,CETIN A.Detecting DDoS attacks insoftware-defined networks through feature selection methods and machine learning models[J].Sustainability,2020,12(3):1035.
[17] ALBAHAR M A.Recurrent Neural Network Model Based on a New RegularizationTechnique for Real-Time Intrusion Detection in SDN Environments[J].Security and Communication Networks,2019(11):1-9.
[18] YUNGAICELA-NAULA,NOE MARCELO,CESAR VAR-GAS-ROSALES,et al.SDN-based architecture for transport and application layer DDoS attack detection by using machine and deep learning[J].IEEE Access,2021(9):108495-108512.
[19] RADZI K,TOMAS Z,OVERIL L,et al.Detection of known and unknown DDoS attacks using artificial neural networks [J].Neurocomputing,2016,12(8):385-393.
[20] YUAN X,LI C,LI X.DeepDefense:Identifying DDoS attack via deep learning[C]//IEEEInternational Conference on Smart Computing.2017:1-8.
[21] YANG K X,MORUS A Y S.Research on DDoS Attack Detection Based on BP Neural Network[J].Journal of Sichuan University(Natural Science Edition),2017,54(1):71-75.
[22] YE C R,XU H,DENG Z H.Research on DDoS Attack Detection Based on Lightweight Convolutional Neural Network[J].Software Guide,2024,23(3):8-14.
[23] SHAN S.Decision tree learning [M].Berlin:Springer,2016:1-28.
[24] JIANG W M,GUO C,JIANG C H.A BiLSTM-Based Low-Rate DDoS Attack Detection Method[J].Computer and Modernization,2020(5):120-126.
[25] GE H W,YANG Q H,SHI L Y.A DDoS Attack Detection Method Based on Deep Learning and Ensemble Learning[J].Modern Electronics Technique,2024,47(3):63-67.
[26] LI M.Research on DDoS Attack Detection and Defense Based on Intelligent Evolutionary Algorithms[J].Computing Technology and Automation,2021,40(2):110-117.
[27] ALI M,SALEEM Y,HINA S,et al.DDoSViT:IoT DDoS attack detection for fortifying firmware Over-The-Air(OTA) updates using vision transformer[J].Internet of Things,2025,30:101527.
[28] FAN Q,LI X,WANG P,et al.IDAD:An improved tensor train based distributed DDoS attack detection framework and its application in complex networks[J].Future Generation Computer Systems,2025,162:107471.
[29] BAI S,KOLTER J Z,KOLTUN V.An empirical evaluation of generic convolutional and recurrent networks for sequence modeling[J].arXiv:1803.01271,2018.
[30] BAI W C,BAI S W,HAN X X,et al.An efficient query workload prediction algorithm based on the TCN-GA model[J].Computer Science,2024,51(7): 71-79.
[31] BAI W R,WEI F,ZHENG G Y,et al.Research on intrusion detection algorithm based on TCN-BiLSTM[J].Computer Science,2023,50(S2): 941-948.
[32] SUN J F,PRUNUS S C H,CAO B.Network security situation prediction based on TCN-BiLSTM[J].Systems Engineering and Electronics,2023,45(11): 3671-3679.
[33] CHEN H,WANG H W,JIN H B.An intrusion detection model integrating improved autoencoder and residual network[J].Computer Engineering,2024,50(2): 188-195.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!