<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">47387</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2024.047387</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Unknown DDoS Attack Detection with Fuzzy C-Means Clustering and Spatial Location Constraint Prototype Loss</article-title>
<alt-title alt-title-type="left-running-head">Unknown DDoS Attack Detection with Fuzzy C-Means Clustering and Spatial Location Constraint Prototype Loss</alt-title>
<alt-title alt-title-type="right-running-head">Unknown DDoS Attack Detection with Fuzzy C-Means Clustering and Spatial Location Constraint Prototype Loss</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Nguyen</surname><given-names>Thanh-Lam</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Kao</surname><given-names>Hao</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Nguyen</surname><given-names>Thanh-Tuan</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Horng</surname><given-names>Mong-Fong</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>mfhorng@nkust.edu.tw</email></contrib>
<contrib id="author-5" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Shieh</surname><given-names>Chin-Shiuh</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>csshieh@nkust.edu.tw</email></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Electronic Engineering, National Kaohsiung University of Science and Technology</institution>, <addr-line>Kaohsiung, 807618</addr-line>, <country>Taiwan</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Electronic and Automation Engineering, Nha Trang University</institution>, <addr-line>Nha Trang, 650000</addr-line>, <country>Vietnam</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Authors: Mong-Fong Horng. Email: <email>mfhorng@nkust.edu.tw</email>; Chin-Shiuh Shieh. Email: <email>csshieh@nkust.edu.tw</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic"><year>2024</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>27</day><month>2</month><year>2024</year></pub-date>
<volume>78</volume>
<issue>2</issue>
<fpage>2181</fpage>
<lpage>2205</lpage>
<history>
<date date-type="received"><day>04</day><month>11</month><year>2023</year>
</date>
<date date-type="accepted"><day>25</day><month>12</month><year>2023</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2024 Nguyen et al.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Nguyen et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_47387.pdf"></self-uri>
<abstract>
<p>Since its inception, the Internet has been rapidly evolving. With the advancement of science and technology and the explosive growth of the population, the demand for the Internet has been on the rise. Many applications in education, healthcare, entertainment, science, and more are being increasingly deployed based on the internet. Concurrently, malicious threats on the internet are on the rise as well. Distributed Denial of Service (DDoS) attacks are among the most common and dangerous threats on the internet today. The scale and complexity of DDoS attacks are constantly growing. Intrusion Detection Systems (IDS) have been deployed and have demonstrated their effectiveness in defense against those threats. In addition, the research of Machine Learning (ML) and Deep Learning (DL) in IDS has gained effective results and significant attention. However, one of the challenges when applying ML and DL techniques in intrusion detection is the identification of unknown attacks. These attacks, which are not encountered during the system&#x2019;s training, can lead to misclassification with significant errors. In this research, we focused on addressing the issue of Unknown Attack Detection, combining two methods: Spatial Location Constraint Prototype Loss (SLCPL) and Fuzzy C-Means (FCM). With the proposed method, we achieved promising results compared to traditional methods. The proposed method demonstrates a very high accuracy of up to 99.8% with a low false positive rate for known attacks on the Intrusion Detection Evaluation Dataset (CICIDS2017) dataset. Particularly, the accuracy is also very high, reaching 99.7%, and the precision goes up to 99.9% for unknown DDoS attacks on the DDoS Evaluation Dataset (CICDDoS2019) dataset. The success of the proposed method is due to the combination of SLCPL, an advanced Open-Set Recognition (OSR) technique, and FCM, a traditional yet highly applicable clustering technique. This has yielded a novel method in the field of unknown attack detection. This further expands the trend of applying DL and ML techniques in the development of intrusion detection systems and cybersecurity. Finally, implementing the proposed method in real-world systems can enhance the security capabilities against increasingly complex threats on computer networks.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Cybersecurity</kwd>
<kwd>DDoS</kwd>
<kwd>unknown attack detection</kwd>
<kwd>machine learning</kwd>
<kwd>deep learning</kwd>
<kwd>incremental learning</kwd>
<kwd>convolutional neural networks (CNN)</kwd>
<kwd>open-set recognition (OSR)</kwd>
<kwd>spatial location constraint prototype loss</kwd>
<kwd>fuzzy c-means</kwd>
<kwd>CICIDS2017</kwd>
<kwd>CICDDoS2019</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Science and Technology Council, Taiwan</funding-source>
<award-id>112-2221-E-992-045</award-id>
<award-id>112-2221-E-992-057-MY3</award-id>
<award-id>112-2622-8-992-009-TD1</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>After the outbreak of the new Coronavirus pneumonia in 2020, people have become more reliant on the internet. Entertainment, shopping, education, and other remote activities on the Internet have become increasingly diverse and rapidly growing. Naturally, the number of DDoS attacks has been significantly increasing. CloudFlare, a content delivery network (CDN) and attack mitigation service provider, published a quarterly investigation on DDoS attacks [<xref ref-type="bibr" rid="ref-1">1</xref>] showing thousands of attacks occurring every month. While most attack traffic remains below 500 Mbps, this volume is sufficient to cause short disruptions for some enterprise services. However, the stability of networks and services is of utmost importance for a business service provider. The service disruption caused by an attack can lead to business losses, and more importantly damage to their image and reputation.</p>
<p>Defending enterprise network systems against DDoS attacks is an essential demand. Nevertheless, DDoS attack methods are continually evolving and becoming more diverse. In contemporary times, the IDS system plays a pivotal role in securing computer networks by identifying and responding to malicious activities in general, and DDoS attacks in particular. Researching and integrating cutting-edge technologies, such as ML and DL technologies into IDS systems to enhance their capabilities is an inevitable trend. Many related experiments have demonstrated that ML and DL methods achieve very high accuracy, up to 98%, on conventional data [<xref ref-type="bibr" rid="ref-2">2</xref>&#x2013;<xref ref-type="bibr" rid="ref-4">4</xref>]. However, existing ML and DL methods primarily focus on modeling and normalizing known attack patterns. Consequently, these methods often struggle to effectively identify unknown attacks with new characteristics, leading to a reduction in the defensive efficacy of IDS systems. Therefore, the identification of unknown DDoS attacks continues to pose a significant challenge for IDS systems.</p>
<p>The main objective of our research is to propose multiple IDS methods capable of concurrently detecting both known and unknown DDoS attacks and evaluating their detection performance. To address this challenge, we emphasize the necessity of the Open-Set Recognition (OSR) technique. The OSR technique deals with the challenge of identifying and classifying objects or instances not encountered during the training phase. Recently, there have been several outstanding achievements in OSR techniques [<xref ref-type="bibr" rid="ref-5">5</xref>]. Notably, the Spatial Location Constraint Prototype Loss (SLCPL) [<xref ref-type="bibr" rid="ref-6">6</xref>] method is a novel OSR technique designed for deep neural networks. It has demonstrated superior effectiveness compared to many previous OSR techniques when testing on many different datasets, with a majority achieving accuracy above 88% [<xref ref-type="bibr" rid="ref-6">6</xref>]. However, when applied alone in the context of detecting unknown DDoS attacks, the effectiveness of SLCPL is not excellent enough. Therefore, we have considered a supporting method, the Fuzzy C-Means (FCM) [<xref ref-type="bibr" rid="ref-7">7</xref>] clustering technique, with a prominent soft clustering feature. The combination of SLCPL and FCM enhances the ability to recognize changes in data patterns, increasing the accuracy of identifying unknown attacks.</p>
<p>Through the utilization of the FCM and the SLCPL, our proposed method achieves an impressive accuracy of up to 99.7% and a precision of up to 99.9% for unknown DDoS attack detection on the open CICDDoS2019 dataset. Simultaneously, it maintains a high accuracy of 99.8% for known attack detection on the well-known CICIDS2017 dataset. With this achievement, we aim to enhance tech organizations&#x2019; detection capabilities, safeguarding network infrastructure and ensuring service continuity amid evolving network threats.</p>
<p>The key contributions of this research are focused on the following aspects:</p>
<p>&#x2022; We have selected AlexNet [<xref ref-type="bibr" rid="ref-8">8</xref>] as the neural network architecture for our training process, and we have enhanced the AlexNet architecture for more effective classification of conventional data.</p>
<p>&#x2022; Through the SLCPL and FCM methods, we have adjusted the positions of unknown attack samples in the feature space, bringing them closer to specific categories and thus enabling the recognition of unknown DDoS attacks.</p>
<p>The structure of this article is as follows: <xref ref-type="sec" rid="s2">Section 2</xref> presents a concise summary of pertinent literature. <xref ref-type="sec" rid="s3">Section 3</xref> encompasses the system&#x2019;s architecture, the methodologies, and the algorithms utilized. <xref ref-type="sec" rid="s4">Section 4</xref> provides a detailed account of the experimental procedure and presents the findings obtained. The research is concluded in <xref ref-type="sec" rid="s5">Section 5</xref>, which also explores potential directions for future research.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>Detecting and mitigating DDoS attacks is a top concern in modern cybersecurity. Several methods have been proposed to handle this problem, varying from traditional signature-based methods to more advanced anomaly detection techniques.</p>
<sec id="s2_1">
<label>2.1</label>
<title>DDoS Attack Detection Technique</title>
<p>Traditional signature-based methods have undeniable advantages such as effectiveness against known DDoS attacks, low false positive rate, and ability to respond quickly to attacks. However, the signature-based method clearly shows its disadvantages against unknown DDoS attacks, zero-day attacks as well and high dependence on databases. Researchers have recognized the limitations of signature-based systems and have explored other approaches. In recent years, ML and DL technologies have been a research trend in developing IDS systems [<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<p>Recent research by Maseer et al. [<xref ref-type="bibr" rid="ref-2">2</xref>] synthesized and compared current popular ML algorithms on the CICIDS2017 dataset. In their research, multiple algorithms have demonstrated highly favorable outcomes, including Support Vector Machine (SVM), Random Forest (RF), Naive Bayes (NB), Artificial Neural Networks (ANN), and Convolutional Neural Network (CNN).</p>
<p>Ho et al. [<xref ref-type="bibr" rid="ref-3">3</xref>] introduced a novel CNN approach that surpasses conventional single-class classification methods, delivering exceptional performance in the realm of multi-class classification, particularly in the identification of both known and unknown attacks. Furthermore, many studies have applied CNN-based models, producing highly effective results [<xref ref-type="bibr" rid="ref-10">10</xref>,<xref ref-type="bibr" rid="ref-11">11</xref>].</p>
<p>Kim et al. [<xref ref-type="bibr" rid="ref-4">4</xref>] introduced a DL model that combines CNN and Recurrent Neural Networks (RNN) to detect Denial of Service (DoS) attacks. They optimized the CNN design through numerous experiments and achieved impressive results, particularly in terms of accuracy on two datasets KDD and CSE-CIC-IDS2018.</p>
<p>Kiranyaz et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] surveyed 1D Convolutional Neural Networks (1D-CNN) and their main applications. The 1D-CNN model [<xref ref-type="bibr" rid="ref-12">12</xref>,<xref ref-type="bibr" rid="ref-13">13</xref>] has demonstrated its advantages in a scarce training data environment as well as in some specific fields such as anomaly detection, personalized biomedical data classification, early diagnosis, etc.</p>
<p>Beitollahi et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] proposed an ML approach for detecting DDoS traffic. Their approach employs a Radial Basis Function (RBF) network in conjunction with the cuckoo search algorithm (CSA) to identify Application-layer DDoS attacks. This approach stands out for its effective performance in identifying DDoS traffic compared to several other methods, with notably low error rates and high precision.</p>
<p>Laghrissi et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] presented an IDS that utilizes Long Short-Term Memory (LSTM) networks, in combination with Principal Component Analysis (PCA) and Mutual Information (MI) techniques. This method achieves outstanding accuracy compared to other methods in both binary and multiclass classification.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Open Set Recognition Technique</title>
<p>The Open Set Recognition (OSR) technique aims to classify data into known classes and detect instances that do not belong to any known class, unknown class, or new instances [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>Recent advancements in OSR techniques include the work of Bendale et al. [<xref ref-type="bibr" rid="ref-16">16</xref>], who introduced the OpenMax technique. This technique has become a crucial method in the field of open-set recognition, where systems need the capability to recognize objects that do not belong to any of the classes learned during training. The fundamental theory behind the OpenMax algorithm involves calculating the &#x201C;openness&#x201D; level of a data sample based on the distance between that sample and the nearest samples in the nearest known class. OpenMax allows for the determination of whether a data sample belongs to a known class, an open-set class (a class corresponding to openness), or is unknown (not belonging to any known class). This enhances recognition capabilities in real-world situations where objects that do not belong to any known class may appear.</p>
<p>Ge et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] have published their research results as a development method of OpenMax. Unlike previous methods where unknown classes were inferred based on characteristics or distance decisions with known classes, the authors&#x2019; novel approach offers a clear framework and decisive criterion for unknown classes. The proposed technique, known as Generative OpenMax, enhances OpenMax by incorporating Generative Adversarial Networks (GANs) to create images for new classes artificially. Additionally, Yoshihashi et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] have proposed the Classification-Reconstruction learning for the OSR method (CROSR) to enhance the reliable detection of unknown classes without affecting the accuracy of known classes. Research results have shown the superiority of this method over traditional approaches.</p>
<p>Generally, Open-Set Recognition has been receiving the attention and research efforts of many scientists and scholars worldwide. The mentioned papers provided earlier represent only a fraction of the noteworthy contributions within this field.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Unknown DDoS Attack Detection Technique</title>
<p>The task of identifying unknown DDoS attacks is difficult, requiring inventive methods to improve the protection of network infrastructures. In recent years, researchers have made significant progress in the field of unknown DDoS attack detection, employing various techniques and methodologies to identify and mitigate these threats [<xref ref-type="bibr" rid="ref-19">19</xref>]. This section provides an overview of recent advances in unknown DDoS attack detection, highlighting key contributions in this domain.</p>
<p>Extreme Value Theory (EVT) has been utilized to enhance the identification of DDoS attacks [<xref ref-type="bibr" rid="ref-20">20</xref>]. This statistical methodology has proven effective in capturing the extreme behaviors of network traffic, aiding in the recognition of anomalous patterns associated with DDoS attacks.</p>
<p>Gaussian Mixture Models (GMMs) and related methods have been widely used for determining the distribution of network traffic data [<xref ref-type="bibr" rid="ref-21">21</xref>,<xref ref-type="bibr" rid="ref-22">22</xref>]. Chapaneri et al. have explored the use of several GMMs for modeling individual input features in the context of DDoS detection [<xref ref-type="bibr" rid="ref-21">21</xref>]. By modeling the underlying data distribution, this technique can help distinguish between benign and malicious traffic patterns, contributing to more accurate detection. Shieh et al. have adopted DL techniques, including Bidirectional Long Short-Term Memory (BI-LSTM) networks and GMMs, for the identification of unknown DDoS attacks [<xref ref-type="bibr" rid="ref-22">22</xref>]. Their research demonstrates the efficacy of combining deep learning and statistical modeling for robust attack identification.</p>
<p>Yang et al. have introduced the AutoEncoder-based DDoS attacks Detection Framework (AE-D3F), a novel technique for threat detection, which has shown promise in identifying anomalous network behavior [<xref ref-type="bibr" rid="ref-23">23</xref>]. By leveraging autoencoders, they contribute to the arsenal of tools for enhancing DDoS attack detection.</p>
<p>Generative Adversarial Networks (GANs) have demonstrated efficacy in DDoS attack detection [<xref ref-type="bibr" rid="ref-24">24</xref>,<xref ref-type="bibr" rid="ref-25">25</xref>]. GANs are proficient in generating synthetic data that can be used to compare and contrast with real network traffic, aiding in the identification of malicious activity. Lin et al. have presented the IDSGAN framework, which incorporates GAN networks as part of a defense system to protect against DDoS attacks [<xref ref-type="bibr" rid="ref-24">24</xref>]. This approach focuses on the proactive use of GANs to safeguard network resources. Chauhan et al. have harnessed Wasserstein GAN (WGAN) to address training issues in DDoS detection models [<xref ref-type="bibr" rid="ref-25">25</xref>]. By incorporating WGAN, they aim to improve the robustness and reliability of DDoS detection techniques.</p>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Fuzzy C-Means Clustering and Comparison between Recent Algorithms</title>
<p>Fuzzy C-Means (FCM) clustering is a common unsupervised learning technique used for data clustering and classification. In the context of DDoS attack detection, FCM has been applied to group network traffic data into clusters, allowing the identification of abnormal traffic patterns related to attacks. The work by Wu et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] used FCM clustering to partition network traffic data into distinct clusters and then employed anomaly detection techniques to identify DDoS attacks within these clusters. This approach has shown promising results in the identification of both known and unknown attacks.</p>
<p>In this section, we have discussed various approaches related to DDoS attack detection, OSR techniques, and Fuzzy C-Means clustering. For convenience, we have established a comparison table among recent research studies in machine learning and deep learning. <xref ref-type="table" rid="table-1">Table 1</xref> summarizes the techniques used, the scope of the problems, and some limitations of the studies.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison between recent machine learning techniques</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Author</th>
<th>Dataset</th>
<th>Problem scope</th>
<th>Technical</th>
<th>Limitation</th>
</tr>
</thead>
<tbody>
<tr>
<td>Ho et al. (2021) [<xref ref-type="bibr" rid="ref-3">3</xref>]</td>
<td>CICIDS2017</td>
<td>CSR, OSR</td>
<td>An IDS based on CNN and its comparison against nine well-known classifiers.</td>
<td>The model may struggle with classes having insufficient samples in the CICIDS2017 dataset, indicating potential issues in detecting open set data.</td>
</tr>
<tr>
<td>Laghrissi et al. (2021) [<xref ref-type="bibr" rid="ref-15">15</xref>]</td>
<td>KDD99</td>
<td>CSR</td>
<td>An LSTM network, combined with PCA and ML techniques for intrusion detection.</td>
<td>The primary limitation is the reliance on the KDD99 dataset, which, despite its widespread use, is outdated and not fully representative of current network traffic and attack patterns.</td>
</tr>
<tr>
<td>Chapaneri et al. (2021) [<xref ref-type="bibr" rid="ref-21">21</xref>]</td>
<td>CICIDS2017</td>
<td>CSR, OSR</td>
<td>A robust GMM with multiple levels has been proven effective in multi-class classification.</td>
<td>The model&#x2019;s effectiveness is tied to the quality and comprehensiveness of the CICIDS2017 dataset.</td>
</tr>
<tr>
<td>Beitollahi et al. (2022) [<xref ref-type="bibr" rid="ref-14">14</xref>]</td>
<td>NSL-KDD</td>
<td>CSR</td>
<td>An RBF network model with CSA technique.</td>
<td>The study primarily relies on the NSL-KDD dataset could limit the model&#x2019;s broader applicability, especially in open-set attacks.</td>
</tr>
<tr>
<td>Najafimehr et al. (2022) [<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
<td>CICIDS2017, CICDDoS2019</td>
<td>CSR, OSR</td>
<td>The Density-Based Spatial Clustering of Applications with Noise (DBSCAN) algorithm is utilized for traffic labeling, while statistical measures are employed to define the ML framework for DDoS detection.</td>
<td>The computational complexity and resources required for the proposed method might be challenging for real-world deployment.</td>
</tr>
<tr>
<td>Zhao et al. (2023) [<xref ref-type="bibr" rid="ref-28">28</xref>]</td>
<td>CICDDoS2019, CICIDS2017,<break/>CICIDS2018, KDD_CUP99,<break/>NSL-KDD, UNSW</td>
<td>CSR</td>
<td>An automatic method for generating Deep Neural Network (DNN) networks by using a genetic algorithm.</td>
<td>This study primarily focuses on model generation for close-set recognition (CSR).</td>
</tr>
<tr>
<td>Sharif et al. (2023) [<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
<td>CICIDS2017</td>
<td>CSR</td>
<td>The study explores the use of Multi-layer Perceptron (MLP) to detect DDoS attacks produced by different tools.</td>
<td>The study primarily relies on the CICIDS2017 dataset could limit the model&#x2019;s broader applicability, especially in open-set attacks.</td>
</tr>
<tr>
<td>Shieh et al. (2023) [<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>CICIDS2017, CICDDoS2019</td>
<td>CSR, OSR</td>
<td>DDoS defense model employs Reconstruct Error and One-Class SVN (OC-SVM) featuring Stochastic Gradient Descent (SGD).</td>
<td>The complexity of the proposed method might also pose challenges in terms of computational resources and real-time applicability.</td>
</tr>
<tr>
<td>Our</td>
<td>CICIDS2017, CICDDoS2019</td>
<td>CSR, OSR</td>
<td>CNN-based model, combined with OSR and FCM techniques for unknown attack detection.</td>
<td>N/A</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Recent notable studies have primarily focused on addressing the challenge of Closed Set Recognition (CSR). Some performance evaluations are conducted on outdated datasets (KDD99) or specific datasets such as NSL-KDD or CICIDS2017. Regarding methods for tackling the OSR problem, some approaches exhibit drawbacks, such as complexity and difficulty in real-world deployment. Our proposed method successfully addresses both CSR and OSR problems, with performance validated on both the CICIDS2017 and CICDDoS2019 datasets. This approach achieves exceptionally high performance and flexibility for real-world deployment. Of course, our method still has some limitations, which will be discussed in the section &#x201C;Discussion&#x201D; of this article.</p>
<p>In the following sections, we will explain our method in detail, a solution involving a deep neural network combined with the SLCPL and FCM techniques to detect unknown DDoS attacks. This combination is relatively new and remains unexplored.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Proposed IDS</title>
<p><xref ref-type="fig" rid="fig-1a">Figs. 1a</xref> and <xref ref-type="fig" rid="fig-1b">1b</xref> show the architecture of our proposed IDS developed in this research. The architecture consists of three main modules: Data Preprocessing Module, OSR Module, and Unknown Detecting Module. The primary machine learning technologies include AlexNet, SLCPL, and FCM. AlexNet is a deep CNN architecture that takes on an essential role in the development and popularization of deep learning. The SLCPL is a novel OSR technique with outstanding advantages. Additionally, we utilized the FCM clustering technique to distinguish between known and unknown attacks. By including the clustering method, the classification performance is enhanced compared to using SPCLP alone.</p>
<fig id="fig-1a">
<label>Figure 1a</label>
<caption>
<title>Training phase</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-1a.tif"/>
</fig>
<fig id="fig-1b">
<label>Figure 1b</label>
<caption>
<title>Evaluating phase</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-1b.tif"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>AlexNet</title>
<p>AlexNet, a Convolutional Neural Network, was developed by Krizhevsky and his team in 2012. It garnered significant acclaim for its exceptional performance in the ImageNet Large Scale Visual Recognition Challenge (ILSVRC) competition [<xref ref-type="bibr" rid="ref-8">8</xref>]. This network architecture marked an important milestone at the time, having a major influence on the advancement of deep learning and the development of the task of image classification.</p>
<p>The main characteristics of AlexNet lie in its combination of depth, convolution, and pooling layers, along with a large number of trainable parameters. Its architecture is as follows:
<list list-type="bullet">
<list-item>
<p>Convolutional and Pooling Layers: AlexNet utilizes convolutional and pooling layers to extract features. The layers efficiently capture specific characteristics within images and employ pooling layers to decrease the complexity of feature maps while preserving important features.</p></list-item>
<list-item>
<p>Activation Function: The (Rectified Linear Unit) ReLU activation function is applied by AlexNet after each convolutional layer to mitigate the issue of vanishing gradients and accelerate the training process.</p></list-item>
<list-item>
<p>Dropout: The dropout technique is introduced in the fully connected layers of AlexNet, mitigating overfitting and enhancing the model&#x2019;s generalization capability.</p></list-item>
<list-item>
<p>Multi-GPU Training: AlexNet pioneered the use of multiple GPUs for training in deep learning models, significantly accelerating the training process.</p></list-item>
</list></p>
<p>The success of AlexNet underscores the formidable capabilities of deep learning in tasks like image classification. While more profound neural network architectures emerged in the subsequent years, AlexNet&#x2019;s role as a starting point in deep learning has cast a lasting influence on the design and development of subsequent models. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> describes the architecture of the AlexNet network.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>AlexNet architecture</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-2.tif"/>
</fig>
<sec id="s3_1_1">
<label>3.1.1</label>
<title>1D AlexNet</title>
<p>In our model, we adapted the architecture of AlexNet using one-dimensional convolution. The structure of 1D AlexNet is similar to 2D AlexNet, and the main difference is that 1D AlexNet processes one-dimensional input data. In this research, we have modified the model of 1D AlexNet as shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>The architecture of improved 1D AlexNet</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-3.tif"/>
</fig>
<p>The model includes some important components as follows. First, convolutional layers use convolution to capture features from one-dimensional data. Next, activation function classes introduce nonlinearity, using the ReLU function. Subsequently, pooling layers are incorporated to diminish the dimensions of the feature map and the computational load, while preserving crucial features. Here, we utilized two kinds of pooling layers, Max Pooling and Average Pooling.</p>
<p>Additionally, 1D AlexNet includes fully connected layers to map features to the end goal of the classification. Normally, the output layer utilizes the SoftMax function to produce the final classification result. However, in this research, we used the SLCPL technique for classification during the training process as well as the evaluation process. Preceding a fully connected layer, a dropout layer is employed to alleviate overfitting. Finally, the proposed modified model is the best result of our multiple testing iterations.</p>
</sec>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Spatial Location Constraint Prototype Loss</title>
<p>Spatial Location Constraint Prototype Loss (SLCPL) [<xref ref-type="bibr" rid="ref-6">6</xref>] is an OSR technique, a loss function designed for the Convolutional Neural Network model. The SLCPL extends from the Generalized Convolutional Prototype Learning (GCPL) [<xref ref-type="bibr" rid="ref-31">31</xref>] by introducing spatial location constraints to solve a common issue faced by most current training methods, such as SoftMax and GCPL. The problem lies in the concentration of known features towards the center of the feature space, resulting in the overlapping of known and unknown feature distributions. To prevent this phenomenon, a spatial location restriction is incorporated into the loss function while undergoing the prototype learning procedure. This allows SLCPL to manipulate the spatial positioning of the prototypes. Consequently, the known features tend to be located in the periphery of the feature space, while the center of the feature space is typically reserved for unknown features.</p>
<p>We will describe the SLCPL function as follows:</p>
<p>Given a training set S &#x003D; {(<inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>), (<inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>), (<inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>), &#x2026;.} with N known classes, and the label <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. A CNN is a classifier with the parameters <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula> and the embedding function F. The prototypes O &#x003D; {<inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi></mml:math></inline-formula>} are initialized randomly or with a distribution.</p>
<p>With a training sample (x, y), the SLCPL loss function can be represented by:</p>
<p><disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>G</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>s</mml:mi><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>O</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>Here <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>G</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is a GCPL loss function and <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>s</mml:mi><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is a spatial location constraint introduced by SLCPL.</p>
<p><inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>G</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> can be represented as follows:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>G</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>&#x03BB;</mml:mi><mml:mo>.</mml:mo><mml:mi>p</mml:mi><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>The function <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> will be optimized to cluster different known classes. And <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> can be represented as follows:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>p</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mi>k</mml:mi><mml:mo>|</mml:mo></mml:mrow><mml:mi>x</mml:mi><mml:mo>,</mml:mo><mml:mi>F</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mfrac><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>F</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:munderover><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>F</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>,</mml:mo><mml:mrow><mml:mtext>with  K = 1,....N</mml:mtext></mml:mrow></mml:math></disp-formula></p>
<p>where <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>d</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>F</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the Euclidean distance between <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>F</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>.</p>
<p>The param &#x03BB; and the constraint <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>p</mml:mi><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>is used to enhance the compactness of the cluster.
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mi>p</mml:mi><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>x</mml:mi><mml:mo>;</mml:mo><mml:mi>&#x03B8;</mml:mi><mml:mo>,</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>F</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mrow><mml:mtext>with   K=1,2,....N</mml:mtext></mml:mrow></mml:math></disp-formula></p>
<p>where <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> is the training sample of class k.</p>
<p>The spatial location constraint <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>s</mml:mi><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>O</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> can be represented as follows:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mi>s</mml:mi><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>O</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mi>N</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:mfrac><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>N</mml:mi></mml:mfrac><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>where <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:mi>N</mml:mi></mml:mfrac></mml:mstyle><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msup><mml:mi>O</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>.</p>
<p>To clarify, <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>s</mml:mi><mml:mi>l</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>O</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> represents the variability of the distances <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> between the prototype of the cluster and the center <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msub><mml:mi>O</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p>As presented, the time complexity to compute the SLCPL loss function for each data sample is <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mrow><mml:mtext>O</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo>.</mml:mo><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where N is the number of known classes and D is the dimensionality of the feature space.</p>
<p>Finally, SLCPL is a new OSR technique with the ability to enhance the accuracy for classifying known and unknown classes. And SLCPL and 1D AlexNet are a promising combination for our OSR module.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Fuzzy C-Means</title>
<p>Fuzzy C-Means (FCM) [<xref ref-type="bibr" rid="ref-7">7</xref>] is a clustering analysis method to partition samples into multiple fuzzy categories. The algorithm considers the degree of membership of each sample to every category rather than just employing traditional hard clustering methods. In this research, we integrated FCM with OSR modules including SLCPL and 1D AlexNet. The 2-feature output from the OSR module will be clustered by FCM for Unknown DDoS attack detection.</p>
<p>We will describe the FCM algorithm as follows:</p>
<p>Given N samples and C cluster centers, each sample is denoted as <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, and each cluster center as <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo></mml:math></inline-formula> Define the fuzzy membership matrix U, where <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the degree of membership of the sample <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to cluster center <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. The objective function of FCM is to minimize the following cost function:
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mi>J</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>U</mml:mi><mml:mo>,</mml:mo><mml:mi>V</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:msubsup><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>Here, m is the fuzziness param that controls the degree of fuzziness in clustering. This objective function combines the weighted total of Euclidean distances between the samples and the cluster centres. The algorithm operates in the following manner:</p>
<list list-type="simple">
<list-item><label>i.</label><p>Initialize the fuzzy assignment matrix U and cluster centers V.</p></list-item>
<list-item><label>ii.</label><p>Perform iterative updates until a stopping condition is met (the maximum number of iterations or convergence of the objective function):</p>
<list list-type="simple">
<list-item><label>a.</label><p>Update U: Compute the degree of membership of each sample to each cluster center using the membership update formula:</p>
<p><disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>C</mml:mi></mml:mrow></mml:msubsup><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mfrac><mml:mn>2</mml:mn><mml:mrow><mml:mi>m</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:mfrac></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula></p></list-item>
<list-item><label>b.</label><p>Update V:</p>
<p><disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:munderover><mml:msubsup><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msubsup><mml:mo>.</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:munderover><mml:msubsup><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msubsup></mml:mrow></mml:mfrac></mml:math></disp-formula></p></list-item></list></list-item>
<list-item><label>iii.</label><p>Returns the final fuzzy assignment matrix U and the cluster centers V.</p></list-item></list>
<p>As presented, the time complexity of FCM typically is <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mrow><mml:mtext>O</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>I</mml:mtext></mml:mrow><mml:mo>.</mml:mo><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo>.</mml:mo><mml:mrow><mml:mtext>C</mml:mtext></mml:mrow><mml:mo>.</mml:mo><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where I represents the number of iterations, N represents the number of data samples, C represents the number of clusters, and D represents the dimension of each data sampling.</p>
<p>The core principle of this algorithm lies in iteratively updating the fuzzy assignment matrix and cluster centers, continuously adjusting the membership degrees of samples and the positions of cluster centers to minimize the objective function. Through the fuzzy assignment matrix, one can obtain the fuzzy membership degrees of each sample concerning each cluster center rather than solely obtaining rigid classification outcomes.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experiments and Results</title>
<sec id="s4_1">
<label>4.1</label>
<title>Dataset</title>
<p>In this research, we utilized the CICIDS2017 [<xref ref-type="bibr" rid="ref-32">32</xref>] and CICDDoS2019 [<xref ref-type="bibr" rid="ref-33">33</xref>] datasets to evaluate the proposed IDS. The CICIDS2017 and CICDDoS2019 are widely used datasets for IDS research and development. Developed by the Canadian Institute of Cyber Security (CIC), they aim to simulate various cyber attacks and common traffic in real-world networks. The simulation environment is set up with complete network topology, actual network traffic, and attack behaviors. They are used for various purposes, such as training, validating, and testing IDS performance. Both are valuable for many tasks like feature selection, model optimization, algorithm comparison, and other intrusion IDS-related research.</p>
<p>The CICIDS2017 dataset was collected from 9 AM on Monday, July 03, 2017, to 5 PM on Friday, July 07, 2017, spanning a duration of 5 days. The CICIDS2017 dataset encompasses a diverse range of attacks, such as Brute Force, DoS, Web Attack, Infiltration, Botnet, Heartbleed, and DDoS. In addition, the CICDDoS2019 dataset includes both benign traffic and the latest prevalent DDoS attacks such as DNS, LDAP, NETBIOS, and SNMP.</p>
<p>We utilized the CICIDS2017 Wednesday dataset to train the model in the context of known attack detection. In addition, we utilized CICIDS2017 Friday and CICDDoS2019 datasets in the context of unknown attack detection. <xref ref-type="table" rid="table-2">Table 2</xref> describes the structure of the datasets we used in this research.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Statistics of experimental datasets</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Attack type</th>
<th>Quantity</th>
<th>Ratio</th>
<th>Total</th>
</tr>
</thead>
<tbody>
<tr valign="top">
<td rowspan="6">CICIDS2017 Wednesday<break/> &#x003C;&#x003C;train dataset&#x003C;&#x003C;</td>
<td>BENIGN</td>
<td>319,186</td>
<td>64.260%</td>
<td rowspan="6">496,709</td>
</tr>
<tr>
<td>DoS Hulk</td>
<td>159,049</td>
<td>32.021%</td>
</tr>
<tr>
<td>DoS GoldenEye</td>
<td>7647</td>
<td>1.540%</td>
</tr>
<tr>
<td>DoS Slowloris</td>
<td>5707</td>
<td>1.149%</td>
</tr>
<tr>
<td>DoS Slowhttptest</td>
<td>5109</td>
<td>1.029%</td>
</tr>
<tr>
<td>HeartBleed</td>
<td>11</td>
<td>0.002%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICIDS2017 Friday</td>
<td>BENIGN</td>
<td>128027</td>
<td>56.713%</td>
<td rowspan="2">225745</td>
</tr>
<tr>
<td>DDoS</td>
<td>97718</td>
<td>43.287%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 LDAP</td>
<td>BENIGN</td>
<td>1602</td>
<td>0.073%</td>
<td rowspan="2">2,181,530</td>
</tr>
<tr>
<td>LDAP</td>
<td>2,179,928</td>
<td>2,179,928</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 MSSQL</td>
<td>BENIGN</td>
<td>1995</td>
<td>0.044%</td>
<td rowspan="2">4,524,484</td>
</tr>
<tr>
<td>MSSQL</td>
<td>4,522,489</td>
<td>99.956%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 DNS</td>
<td>BENIGN</td>
<td>3380</td>
<td>0.067%</td>
<td rowspan="2">5,074,382</td>
</tr>
<tr>
<td>DNS</td>
<td>5,071,002</td>
<td>99.933%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 NetBIOS</td>
<td>BENIGN</td>
<td>1705</td>
<td>0.042%</td>
<td rowspan="2">4,094,978</td>
</tr>
<tr>
<td>NetBIOS</td>
<td>4,093,273</td>
<td>99.958%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 NTP</td>
<td>BENIGN</td>
<td>14,337</td>
<td>1.178%</td>
<td rowspan="2">1,216,976</td>
</tr>
<tr>
<td>NTP</td>
<td>1,202,639</td>
<td>98.822%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 UDP</td>
<td>BENIGN</td>
<td>2151</td>
<td>0.069%</td>
<td rowspan="2">3,136,794</td>
</tr>
<tr>
<td>UDP</td>
<td>3,134,643</td>
<td>99.931%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 SNMP</td>
<td>BENIGN</td>
<td>1502</td>
<td>0.029%</td>
<td rowspan="2">5,161,365</td>
</tr>
<tr>
<td>SNMP</td>
<td>5,159,863</td>
<td>99.971%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 SSDP</td>
<td>BENIGN</td>
<td>762</td>
<td>0.029%</td>
<td rowspan="2">2,611,372</td>
</tr>
<tr>
<td>SSDP</td>
<td>2,610,610</td>
<td>99.971%</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 SYN</td>
<td>BENIGN</td>
<td>389</td>
<td>0.028%</td>
<td rowspan="2">1,380,404</td>
</tr>
<tr>
<td>Syn</td>
<td>1,380,015</td>
<td>99.972%</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Data Pre-Processing</title>
<p>Data pre-processing is a very important phase in conducting machine learning experiments. Pre-processing ensures the accuracy and reliability of the output. In this research, this phase includes Data cleaning and Feature transformation.</p>
<sec id="s4_2_1">
<label>4.2.1</label>
<title>Data Cleaning</title>
<p>Data cleaning is a necessary process during preprocessing. Error data will be corrected to ensure the experiment produces the best and most reliable results. In this research, we clean the data by using the following methods:</p>
<p>&#x2022; For data samples whose value of any feature is NAN, we proceed with elimination.</p>
<p>&#x2022; For features whose value is INF, we replaced the value with 10E10.</p>
<p>&#x2022; For features with negative values, we replaced the negative value with 0.</p>
</sec>
<sec id="s4_2_2">
<label>4.2.2</label>
<title>Feature Transformation</title>
<p>In this research, we have referred to the processing methods of Chapaneri et al. in the article [<xref ref-type="bibr" rid="ref-21">21</xref>] during the data transformation process. The feature value is transformed according to the following formula:
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mi>X</mml:mi><mml:mo stretchy="false">&#x2190;</mml:mo><mml:mfrac><mml:mrow><mml:mi>l</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:mn>10</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>X</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mn>10</mml:mn></mml:mfrac></mml:math></disp-formula></p>
<p>After data are transformed, the values of all features will be in the range [0, 1].</p>
</sec>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Experimental Environment</title>
<p>In this research, we utilized a workstation with the Ubuntu 20.04 OS. Our workstation is equipped with an AMD Ryzen 5700X 8C16T processor, 96 GB DDR4 memory, and Nvidia RTX3070 and Nvidia RTX2060 as computational accelerators. Regarding the model framework, we undertake development using PyTorch 1.11.0, Sklearn, and Python 3.9.12.</p>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Model Training</title>
<p>In this research, we have built the 1D AlexNet model using the Pytorch framework and calculated the evaluation metrics using Sklearn. To evaluate the model&#x2019;s effectiveness, we trained the model ten times using a different random number each time. We chose Adam as the optimizer. The detailed settings of the parameters are described in <xref ref-type="table" rid="table-3">Table 3</xref>. And <xref ref-type="fig" rid="fig-4">Fig. 4</xref> shows the network model of 1D AlexNet.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Training parameters</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Parameters</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>Learning rate</td>
<td>3.00E-03</td>
</tr>
<tr>
<td>Weight decay</td>
<td>3.00E-05</td>
</tr>
<tr>
<td>Optimizer</td>
<td>Adam</td>
</tr>
<tr>
<td>Batch size</td>
<td>1024</td>
</tr>
<tr>
<td>Training split ratio</td>
<td>0.8 training, 0.2 testing</td>
</tr>
<tr>
<td>Random seeds</td>
<td>0, 22, 42, 123, 222, 367, 419, 579, 623, 746, 844, 918, 1023, 1344, 65536, 815149</td>
</tr>
</tbody>
</table>
</table-wrap><fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>1D AlexNet model architecture</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-4.tif"/>
</fig>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Evaluation Metrics</title>
<p>In machine learning and pattern recognition, evaluation metrics serve as quantifiable measures to gauge model performance and effectiveness. These metrics assess and compare a model&#x2019;s performance on a specific task or problem. In the context of this research, we used the following metrics:
<list list-type="bullet">
<list-item>
<p>Accuracy: Evaluates the accuracy of model predictions.</p></list-item>
<list-item>
<p>Precision: Assess the ratio of true positive predictions to the total predicted positive samples.</p></list-item>
<list-item>
<p>Recall: Assess the ratio of true positive predictions to the total true positive samples.</p></list-item>
<list-item>
<p>F1 score: A comprehensive evaluation metric by considering both precision and recall.</p></list-item>
</list></p>
<p>These metrics will measure the model&#x2019;s performance in distinguishing between different classes. <xref ref-type="table" rid="table-4">Table 4</xref> is the definition of the confusion matrix in machine learning.<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mrow><mml:mtext>Accuracy</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>T</mml:mi><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mrow><mml:mtext>Precision</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>P</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:mrow><mml:mtext>Recall</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>N</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mrow><mml:mtext>F1 score</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mn>2</mml:mn><mml:mo>&#x2217;</mml:mo><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow><mml:mrow><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo>+</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>l</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Confusion matrix</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th></th>
<th>Attack</th>
<th>Normal</th>
</tr>
</thead>
<tbody>
<tr>
<td>Attack</td>
<td>TP (True Positive)</td>
<td>FP (False Positive)</td>
</tr>
<tr>
<td>Normal</td>
<td>FN (False Negative)</td>
<td>TN (True Negative)</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_6">
<label>4.6</label>
<title>Known DDoS Detection</title>
<p>For known DDoS detection, we utilized CICIDS2017 Wednesday dataset for the training model. Initially, we trained the 1D AlexNet model and visualized the 2-feature output from the 1D AlexNet module in feature space, as shown in <xref ref-type="fig" rid="fig-5">Fig. 5</xref>. We observed that the training process made the distribution of the known classes more dispersed. In some cases, the distribution areas of known classes have overlapped with one another.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Unmodified 1D AlexNet</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-5.tif"/>
</fig>
<p>Therefore, we continued to modify 1D AlexNet several times to improve the result. We have tried to increase the number of convolutional layers of the 1D AlexNet. After numerous improvements, we achieved the desired outcomes. <xref ref-type="fig" rid="fig-6">Fig. 6</xref> shows that the result of our final model (<xref ref-type="fig" rid="fig-3">Fig. 3</xref>) improves significantly compared to the initial model in terms of the distribution of known datasets.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Final 1D AlexNet model with fully connected layer</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-6.tif"/>
</fig>
<p>Furthermore, we obtained excellent results as shown in <xref ref-type="fig" rid="fig-7">Fig. 7</xref>, when evaluating known attacks by using the same CICIDS2017 Wednesday dataset. All evaluation metrics exceed 0.98.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Known attack evaluation matrix</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_47387-fig-7.tif"/>
</fig>
</sec>
<sec id="s4_7">
<label>4.7</label>
<title>Unknown DDoS Detection</title>
<sec id="s4_7_1">
<label>4.7.1</label>
<title>Unknown Attack Detection with 1D AlexNet</title>
<p>The 1D AlexNet model has shown good performance against known attacks. Next, we continued to evaluate the ability to defend against unknown attacks. Firstly, we used the CICIDS2017 Friday dataset to evaluate the trained model. <xref ref-type="table" rid="table-5">Table 5</xref> shows the results and correlation comparisons.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Unknown DDoS detection performance for the CICIDS2017 dataset</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Accuracy</th>
<th>Precision</th>
<th>Recall</th>
<th>F1 score</th>
</tr>
</thead>
<tbody>
<tr>
<td>CICIDS2017 Wednesday</td>
<td>0.9972</td>
<td>0.9942</td>
<td>0.9983</td>
<td>0.9962</td>
</tr>
<tr>
<td>CICIDS2017 Friday</td>
<td>0.7910</td>
<td>0.9925</td>
<td>0.6363</td>
<td>0.7755</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>When evaluating by CICIDS2017 Friday dataset, the accuracy is 0.7910 and other metrics are mostly at an average level. Because the CICIDS2017 Friday and CICIDS2017 Wednesday datasets are collected in the same environment. They have a certain similarity, especially in the BEGIGN traffic. However, the results show that the standalone model is not good enough to identify novel attacks.</p>
<p>Next, we used the CICDDoS2019 dataset to further evaluate the model. <xref ref-type="table" rid="table-6">Table 6</xref> shows the results and correlation comparison for the CICDDoS2019 dataset.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Unknown DDoS detection performance for the CICDDoS2019 dataset</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Accuracy</th>
<th>Precision</th>
<th>Recall</th>
<th>F1 score</th>
</tr>
</thead>
<tbody>
<tr>
<td>CICIDS2017 Wednesday</td>
<td>0.9972</td>
<td>0.9942</td>
<td>0.9983</td>
<td>0.9962</td>
</tr>
<tr>
<td>CICIDS2017 Friday</td>
<td>0.7910</td>
<td>0.9925</td>
<td>0.6363</td>
<td>0.7755</td>
</tr>
<tr>
<td>CICDDoS2019 DNS</td>
<td>0.0006</td>
<td>0.3795</td>
<td>4.75E-05</td>
<td>9.50E-05</td>
</tr>
<tr>
<td>CICDDoS2019 LDAP</td>
<td>0.0022</td>
<td>0.0462</td>
<td>9.49E-06</td>
<td>1.90E-05</td>
</tr>
<tr>
<td>CICDDoS2019 MSSQL</td>
<td>0.0004</td>
<td>0.3951</td>
<td>2.84E-05</td>
<td>5.68E-05</td>
</tr>
<tr>
<td>CICDDoS2019 NTP</td>
<td>0.0123</td>
<td>0.6402</td>
<td>0.0012</td>
<td>0.0025</td>
</tr>
<tr>
<td>CICDDoS2019 NetBIOS</td>
<td>0.0003</td>
<td>0.625</td>
<td>3.33E-05</td>
<td>6.66E-05</td>
</tr>
<tr>
<td>CICDDoS2019 Portmap</td>
<td>0.0236</td>
<td>0.1192</td>
<td>0.0001</td>
<td>0.0003</td>
</tr>
<tr>
<td>CICDDoS2019 SNMP</td>
<td>0.0002</td>
<td>0.5089</td>
<td>4.98E-05</td>
<td>9.96E-05</td>
</tr>
<tr>
<td>CICDDoS2019 SSDP</td>
<td>0.0004</td>
<td>0.775</td>
<td>0.0017</td>
<td>0.0035</td>
</tr>
<tr>
<td>CICDDoS2019 Syn</td>
<td>0.0095</td>
<td>0.775</td>
<td>0.0017</td>
<td>0.0035</td>
</tr>
<tr>
<td>CICDDoS2019 UDP</td>
<td>0.0009</td>
<td>0.7687</td>
<td>0.0002</td>
<td>0.0004</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The results are really bad when evaluating the model by CICDDoS2019. Because the CICDDoS2019 and CICIDS2017 datasets are different. Even though they are collected by the same organization Canadian Institute of Cyber Security (CIC). They have different simulation environments and the collected features are not the same. The attack pattern of CICDDoS2019 is strange to the trained model. That fooled the model into thinking the novel attacks were regular accesses. Therefore, we need to combine the model with an Unknown DDoS Detecting module to enhance the system&#x2019;s capabilities.</p>
</sec>
<sec id="s4_7_2">
<label>4.7.2</label>
<title>Unknown Attack Detection Module</title>
<p>In this research, we calculated the Outlier Detection Rate (ODR) to determine the efficiency of the Unknown DDoS Detecting module. The formula of ODR is as follows:</p>
<p><disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:mi>O</mml:mi><mml:mi>D</mml:mi><mml:mi>R</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>O</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub><mml:mi>N</mml:mi></mml:mfrac></mml:math></disp-formula></p>
<p>where <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>O</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the number of unknown samples that our system believes should be reviewed by network experts, and N is the total number of samples in the procedure.</p>
<p>The CICIDS2017 Friday and CICIDS2017 Wednesday are collected in the same environment and are quite similar. Therefore, the ODR of CICIDS2017 Friday is only 0.082. However, other CICDDoD2019 datasets have very high ODR of over 0.99. <xref ref-type="table" rid="table-7">Table 7</xref> shows that our Unknown DDoS Detecting module has very high performance when identifying outlier samples.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>The outcome of the Unknown DDoS detecting module</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>ODR</th>
</tr>
</thead>
<tbody>
<tr>
<td>CICIDS2017 Friday</td>
<td>0.0842</td>
</tr>
<tr>
<td>CICDDoS2019 DNS</td>
<td>0.9999</td>
</tr>
<tr>
<td>CICDDoS2019 LDAP</td>
<td>0.9998</td>
</tr>
<tr>
<td>CICDDoS2019 MSSQL</td>
<td>0.9999</td>
</tr>
<tr>
<td>CICDDoS2019 NTP</td>
<td>0.9987</td>
</tr>
<tr>
<td>CICDDoS2019 NetBIOS</td>
<td>0.9996</td>
</tr>
<tr>
<td>CICDDoS2019 Portmap</td>
<td>0.9983</td>
</tr>
<tr>
<td>CICDDoS2019 SNMP</td>
<td>0.9999</td>
</tr>
<tr>
<td>CICDDoS2019 SSDP</td>
<td>0.9999</td>
</tr>
<tr>
<td>CICDDoS2019 Syn</td>
<td>0.9990</td>
</tr>
<tr>
<td>CICDDoS2019 UDP</td>
<td>0.9999</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_7_3">
<label>4.7.3</label>
<title>Incremental Learning</title>
<p>After being processed by the Unknown DDoS Detecting module, suspicious samples will be analyzed and labeled by network experts. Next, new labeled data will be used for the incremental learning process. This process improves the machine learning model without the need to retrain it from scratch. The incremental learning ensures continuous operation of the system as well as full updates on new real-life cyber attack patterns. <xref ref-type="table" rid="table-8">Table 8</xref> shows the outcomes of the model after incremental learning.</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Our model outcomes post incremental learning</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Dataset</th>
<th>Incremental learning</th>
<th>Accuracy</th>
<th>Precision</th>
<th>Recall</th>
<th>F1 score</th>
</tr>
</thead>
<tbody>
<tr valign="top">
<td rowspan="2">CICIDS2017 Wednesday</td>
<td><italic>Before</italic></td>
<td>0.9972</td>
<td>0.9942</td>
<td>0.9983</td>
<td>0.9962</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9976</td>
<td>0.9944</td>
<td>0.9991</td>
<td>0.9968</td>
</tr>
<tr valign="top">
<td rowspan="2">CICIDS2017 Friday</td>
<td><italic>Before</italic></td>
<td>0.7910</td>
<td>0.9925</td>
<td>0.6363</td>
<td>0.7755</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9926</td>
<td>0.9985</td>
<td>0.9885</td>
<td>0.9934</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 DNS</td>
<td><italic>Before</italic></td>
<td>0.0006</td>
<td>0.3795</td>
<td>4.75E-05</td>
<td>9.50E-05</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 LDAP</td>
<td><italic>Before</italic></td>
<td>0.0022</td>
<td>0.0462</td>
<td>9.49E-06</td>
<td>1.90E-05</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9998</td>
<td>0.9999</td>
<td>0.9998</td>
<td>0.9999</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 MSSQL</td>
<td><italic>Before</italic></td>
<td>0.0004</td>
<td>0.3951</td>
<td>2.84E-05</td>
<td>5.68E-05</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 NTP</td>
<td><italic>Before</italic></td>
<td>0.0123</td>
<td>0.6402</td>
<td>0.0012</td>
<td>0.0025</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9991</td>
<td>0.9996</td>
<td>0.9994</td>
<td>0.9995</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 NetBIOS</td>
<td><italic>Before</italic></td>
<td>0.0003</td>
<td>0.625</td>
<td>3.33E-05</td>
<td>6.66E-05</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 Portmap</td>
<td><italic>Before</italic></td>
<td>0.0236</td>
<td>0.1192</td>
<td>0.0001</td>
<td>0.0003</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9965</td>
<td>0.9993</td>
<td>0.997</td>
<td>0.9982</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 SNMP</td>
<td><italic>Before</italic></td>
<td>0.0002</td>
<td>0.5089</td>
<td>4.98E-05</td>
<td>9.96E-05</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 SSDP</td>
<td><italic>Before</italic></td>
<td>0.0004</td>
<td>0.775</td>
<td>0.0017</td>
<td>0.0035</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9998</td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 Syn</td>
<td><italic>Before</italic></td>
<td>0.0095</td>
<td>0.775</td>
<td>0.0017</td>
<td>0.0035</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9995</td>
<td>0.9997</td>
<td>0.9997</td>
<td>0.9997</td>
</tr>
<tr valign="top">
<td rowspan="2">CICDDoS2019 UDP</td>
<td><italic>Before</italic></td>
<td>0.0009</td>
<td>0.7687</td>
<td>0.0002</td>
<td>0.0004</td>
</tr>
<tr>
<td><italic>After</italic></td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
<td>0.9999</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>After incremental learning, the model&#x2019;s performance has significantly improved. For the CICIDS2017 Friday dataset, despite the ODR rate being only 0.0842, it has led to an increase in accuracy of approximately 0.2. For the CICDDoS2019 dataset, the measured metrics exceeded expectations when all surpassed 0.98. This proves the module combined FCM and SLCPL is effective in distinguishing known and unknown traffic. Most of the samples determined as unknown traffic are strange to the system and can enhance the system&#x2019;s performance. Therefore, the system&#x2019;s capability to detect unknown attacks is guaranteed at the highest level.</p>
</sec>
</sec>
<sec id="s4_8">
<label>4.8</label>
<title>Comparison of the Proposed Method with the Existing Works</title>
<p>We used a lot of recent research in detecting DDoS attacks for the comparison. Chosen algorithms include Deep Neural Network with Genetic Algorithms (2023) [<xref ref-type="bibr" rid="ref-28">28</xref>], Multilayer Perceptron (2023) [<xref ref-type="bibr" rid="ref-29">29</xref>], and Convolutional Neural Network featuring Geometrical Metric (2023) [<xref ref-type="bibr" rid="ref-34">34</xref>]. All algorithms were evaluated on the CICIDS2017 dataset for known attack detection. <xref ref-type="table" rid="table-9">Table 9</xref> shows the comparisions of our method with recent ML algorithms.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Our method in the comparison with recent ML algorithms on CICIDS2017</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Method</th>
<th>Accuracy</th>
<th>Precision</th>
<th>Recall</th>
</tr>
</thead>
<tbody>
<tr>
<td>DNN-GA (2023)</td>
<td>0.9906</td>
<td>0.9896</td>
<td>0.9915</td>
</tr>
<tr>
<td>MLP (2023)</td>
<td>0.992</td>
<td>0.971</td>
<td>0.966</td>
</tr>
<tr>
<td>CNN-Geo (2023)</td>
<td><bold>0.9979</bold></td>
<td><bold>0.9962</bold></td>
<td>0.9944</td>
</tr>
<tr>
<td>Proposed method</td>
<td>0.9976</td>
<td>0.9944</td>
<td><bold>0.9991</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The performance metrics of our proposed method are slightly larger than DNN-GA and MLP. They have accuracy, precision, and recall of approximately 0.99. Compared with the CNN-Geo algorithm, the proposed method has similar performance with negligible differences.</p>
<p>Next, we continued to compare with other algorithms in detecting unknown attacks. The algorithms we chose to compare include GMM (2021) [<xref ref-type="bibr" rid="ref-21">21</xref>], DBSCAN with Random Forest (DBSCAN-RF) (2022) [<xref ref-type="bibr" rid="ref-27">27</xref>], DBSCAN with SVM (DBSCAN-SVM) (2022) [<xref ref-type="bibr" rid="ref-27">27</xref>], One-Dimensional Deep High-Resolution Network with One-Class SVM (1D-DHRNet-OCSVM) (2022) [<xref ref-type="bibr" rid="ref-30">30</xref>], and CNN featuring Geometrical Metric (CNN-Geo) (2023) [<xref ref-type="bibr" rid="ref-34">34</xref>]. All algorithms are trained on the CICIDS2017 dataset and evaluated on other datasets. The performance metrics of the overall system are listed in the <xref ref-type="table" rid="table-10">Table 10</xref>.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Our method in comparison with recent ML algorithms in unknown DDoS attack detection</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Method</th>
<th>Accuracy</th>
<th>Precision</th>
<th>Recall</th>
</tr>
</thead>
<tbody>
<tr>
<td>GMM (2021)</td>
<td>&#x2013;</td>
<td>0.9700</td>
<td>0.95</td>
</tr>
<tr>
<td>DBSCAN-RF (2022)</td>
<td>0.148</td>
<td>0.998</td>
<td>0.145</td>
</tr>
<tr>
<td>DBSCAN-SVM (2022)</td>
<td>0.314</td>
<td>0.998</td>
<td>0.312</td>
</tr>
<tr>
<td>1D-DHRNet-OCSVM (2022)</td>
<td>0.992</td>
<td>0.999</td>
<td>0.991</td>
</tr>
<tr>
<td>CNN-Geo (2023)</td>
<td>0.996</td>
<td>0.997</td>
<td>0.996</td>
</tr>
<tr>
<td>Proposed method</td>
<td><bold>0.996</bold></td>
<td><bold>0.999</bold></td>
<td><bold>0.997</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Compared with DBSCAN-SVM and DBSCAN-RF methods, our method has much more outstanding performance metrics. Compared with GMM (2021), 1D-DHRNet-OCSVM (2022), and CNN-Geo (2023), our method has slightly larger metrics. Combining the two cases of known and unknown attack detection, our performance is equal to or more outstanding than other methods. This proves that our research has caught up and surpassed recent outstanding research.</p>
</sec>
<sec id="s4_9">
<label>4.9</label>
<title>Discussion</title>
<p>The validity of a study is a concern that we prioritize throughout our research. For internal validity, we are meticulous in applying methods, algorithms, and experimental procedures in the fields of machine learning and deep learning. We have used multiple random seeds, as well as dropout techniques to avoid overfitting, during both model training and evaluation. Regarding external validity, in this research, we utilized two main datasets, CICIDS2017 and CICDDoS2019. The validity of these datasets will significantly impact the applicability of our model in real-world scenarios. These are two well-known and standard datasets in the broader field of network attack detection, including specific DDoS attacks. All of these efforts are aimed at ensuring the reliability of our research.</p>
<p>However, new attack methods and their variants are continually evolving. Deploying an unknown attack detection module along with ongoing support from network experts and machine learning incremental learning techniques forms a robust combination that enhances the system&#x2019;s capabilities over time. While the defense of our system has demonstrated effectiveness against a variety of DDoS attacks, it is essential to recognize certain limitations. This is particularly evident when confronting Layer 7 (L7) DDoS attacks and the intricate strategies employed in adversarial scenarios.</p>
<p>As mentioned, our proposed model heavily relies on two primary datasets, CICIDS2017 and CICDDoS2019, focused predominantly on DDoS attacks at Layer 3 and Layer 4. This specialization in lower network layers may result in inadequacies in addressing the distinct characteristics of DDoS attacks at the L7 layer, the Application layer. Notably, L7 DDoS attacks pose a unique challenge as they exploit vulnerabilities within applications, services, or protocols, diverging from conventional approaches that target network infrastructure. Detection mechanisms may encounter challenges in discerning benign from harmful activities at this granular level. Techniques such as encryption-based intrusion and complex application-layer exploitation, while effective, may incur significant processing costs on lightweight systems, impacting overall performance and response times during high-intensity attacks.</p>
<p>Furthermore, our system has not been studied to face adversarial DDoS attacks, a major evolving threat. These attacks dynamically adjust in attack types, IP address manipulation, and various attack vectors, deliberately employed to complicate defense mechanisms.</p>
<p>In summary, minimizing L7 DDoS attacks and adversarial DDoS attacks requires a sophisticated and adaptive approach, while acknowledging the limitations mentioned above. Traditional mitigation strategies may not be sufficient, and research on advanced techniques needs to be conducted and implemented.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion and Future Work</title>
<p>Today, business service providers are striving to achieve stable service quality, which has become their important goal. However, some individuals view DDoS attacks as a way to generate revenue. DDoS attacks are becoming increasingly diverse and complex. Meanwhile, intrusion detection systems trained on limited datasets find it difficult to identify novel, unknown attacks. To solve this challenge, our research proposes a hybrid approach that combines the characteristics of supervised and unsupervised techniques. We have adopted the 1D AlexNet network as our main technique. We improved the 1D AlexNet network several times to achieve the desired model. Additionally, the combination of FCM and SCLPL was successful in identifying unknown attacks with very high efficiency. Then, we ask the help of network experts to label suspicious traffic and use reinforcement learning methods to enhance the model. As a result, the improved 1D AlexNet model achieved very high performance, with an accuracy of up to 99.8% for known attacks and 99.7% for unknown attacks. The proposed system has demonstrated strong defense capabilities against both known and unknown attacks.</p>
<p>Currently, the unknown detection method by using SCLPL and FCM is not only compatible with the 1D AlexNet model but can also be extended to other CNN-based models. This opens up research opportunities for the future. We plan to do more research with more complex CNN models as the core of the system to replace 1D AlexNet. Alongside that, we will try the integration of other unknown detection methods. The diversity of unknown detection methods ensures that our system is sensitive enough to detect novel attacks. All these methods aim to ensure the strong defense capabilities of the IDS system against the complex developments on the internet.</p>
</sec>
</body>
<back>
<ack><p>We would like to thank the National Science and Technology Council, Taiwan for funding this research. Additionally, we appreciate the financial support from the Institute of IoT Cybersecurity granted with ICP DAS Co., Ltd.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This research was partly supported by the National Science and Technology Council, Taiwan with Grant Numbers 112-2221-E-992-045, 112-2221-E-992-057-MY3 and 112-2622-8-992-009-TD1.</p>
</sec>
<sec><title>Author Contributions</title>
<p>Conceptualization, C.-S. Shieh; methodology, T.-L. Nguyen and H. Kao; software, T.-L. Nguyen; validation, T.-T. Nguyen; visualization, H. Kao; writing&#x2014;draft manuscript preparation, T.-L. Nguyen; writing&#x2014;review and editing, T.-T. Nguyen and C.-S. Shieh; project funding, C.-S. Shieh and M.-F. Horng; project supervision, M.-F. Horng; project administration, M.-F. Horng. All authors have reviewed and approved the published version of the manuscript.</p>
</sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>Data supporting the reported results are available upon request.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>&#x201C;DDoS threat report for 2023 Q1,&#x201D;</collab></person-group> <article-title>The Cloudflare Blog, Apr. 2023</article-title>. <comment>Accessed: Nov. 02</comment>, <year>2023</year>. [<comment>Online</comment>]. Available: <ext-link ext-link-type="uri" xlink:href="http://blog.cloudflare.com/ddos-threat-report-2023-q1/">http://blog.cloudflare.com/ddos-threat-report-2023-q1/</ext-link></mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z. K.</given-names> <surname>Maseer</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Yusof</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Bahaman</surname></string-name>, <string-name><given-names>S. A.</given-names> <surname>Mostafa</surname></string-name>, and <string-name><given-names>C. F. M.</given-names> <surname>Foozy</surname></string-name></person-group>, &#x201C;<article-title>Benchmarking of machine learning for anomaly based intrusion detection systems in the CICIDS2017 dataset</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>9</volume>, pp. <fpage>22351</fpage>&#x2013;<lpage>22370</lpage>, <year>2021</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2021.3056614</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Ho</surname></string-name>, <string-name><given-names>S. A.</given-names> <surname>Jufout</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Dajani</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Mozumdar</surname></string-name></person-group>, &#x201C;<article-title>A novel intrusion detection model for detecting known and innovative cyberattacks using convolutional neural network</article-title>,&#x201D; <source>IEEE Open J. Comput. Soc.</source>, vol. <volume>2</volume>, pp. <fpage>14</fpage>&#x2013;<lpage>25</lpage>, <year>2021</year>. doi: <pub-id pub-id-type="doi">10.1109/OJCS.2021.3050917</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Shim</surname></string-name>, and <string-name><given-names>E.</given-names> <surname>Choi</surname></string-name></person-group>, &#x201C;<article-title>CNN-based network intrusion detection against denial-of-service attacks</article-title>,&#x201D; <source>Electronics</source>, vol. <volume>9</volume>, no. <issue>6</issue>, pp. <fpage>916</fpage>&#x2013;<lpage>937</lpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.3390/electronics9060916</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Geng</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Huang</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>Recent advances in open set recognition: A survey</article-title>,&#x201D; <source>IEEE Trans. Pattern Anal. Mach. Intell.</source>, vol. <volume>43</volume>, no. <issue>10</issue>, pp. <fpage>3614</fpage>&#x2013;<lpage>3631</lpage>, <year>Oct. 2021</year>. doi: <pub-id pub-id-type="doi">10.1109/TPAMI.2020.2981604</pub-id>; <pub-id pub-id-type="pmid">32191881</pub-id></mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Xia</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Dong</surname></string-name>, and <string-name><given-names>H.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Spatial location constraint prototype loss for open set recognition</article-title>,&#x201D; <source>Comput. Vis. Image Underst.</source>, vol. <volume>229</volume>, pp. <fpage>103651</fpage>, <year>Mar. 2023</year>. doi: <pub-id pub-id-type="doi">10.1016/j.cviu.2023.103651</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J. C.</given-names> <surname>Bezdek</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Ehrlich</surname></string-name>, and <string-name><given-names>W.</given-names> <surname>Full</surname></string-name></person-group>, &#x201C;<article-title>FCM: The fuzzy c-means clustering algorithm</article-title>,&#x201D; <source>Comput. Geosci.</source>, vol. <volume>10</volume>, no. <issue>2</issue>, pp. <fpage>2</fpage>, <year>Jan. 1984</year>. doi: <pub-id pub-id-type="doi">10.1016/0098-3004(84)90020-7</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Krizhevsky</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Sutskever</surname></string-name>, and <string-name><given-names>G. E.</given-names> <surname>Hinton</surname></string-name></person-group>, &#x201C;<article-title>ImageNet classification with deep convolutional neural networks</article-title>,&#x201D; <source>Commun. ACM</source>, vol. <volume>60</volume>, no. <issue>6</issue>, pp. <fpage>6</fpage>, <year>May 2017</year>. doi: <pub-id pub-id-type="doi">10.1145/3065386</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Nishant</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Kennedy</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Corbett</surname></string-name></person-group>, &#x201C;<article-title>Artificial intelligence for sustainability: Challenges, opportunities, and a research agenda</article-title>,&#x201D; <source>Int. J. Inf. Manag.</source>, vol. <volume>53</volume>, pp. <fpage>102104</fpage>, <year>Aug. 2020</year>. doi: <pub-id pub-id-type="doi">10.1016/j.ijinfomgt.2020.102104</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Cheng</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Tang</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Sheng</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>DDoS attack detection via multi-scale convolutional neural network</article-title>,&#x201D; <source>Comput. Mater. Contin.</source>, vol. <volume>62</volume>, no. <issue>3</issue>, pp. <fpage>3</fpage>, <year>2020</year>. doi: <pub-id pub-id-type="doi">10.32604/cmc.2020.06177</pub-id></mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Hu</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Zheng</surname></string-name>, and <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>DAD-MCNN: DDoS attack detection via multi-channel CNN</article-title>,&#x201D; in <conf-name>Proc. of the 2019 11th Int. Conf. Mach. Learn. Comput.</conf-name>, <publisher-loc>New York, USA</publisher-loc>, <publisher-name>Association for Computing Machinery</publisher-name>, <year>Feb. 2019</year>, pp. <fpage>484</fpage>&#x2013;<lpage>488</lpage>. doi: <pub-id pub-id-type="doi">10.1145/3318299.3318329</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Kiranyaz</surname></string-name>, <string-name><given-names>O.</given-names> <surname>Avci</surname></string-name>, <string-name><given-names>O.</given-names> <surname>Abdeljaber</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Ince</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Gabbouj</surname></string-name> and <string-name><given-names>D. J.</given-names> <surname>Inman</surname></string-name></person-group>, &#x201C;<article-title>1D convolutional neural networks and applications: A survey</article-title>,&#x201D; <source>Mech. Syst. Signal Process.</source>, vol. <volume>151</volume>, pp. <fpage>107398</fpage>, <year>Apr. 2021</year>. doi: <pub-id pub-id-type="doi">10.1016/j.ymssp.2020.107398</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>E. U. H.</given-names> <surname>Qazi</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Almorjan</surname></string-name>, and <string-name><given-names>T.</given-names> <surname>Zia</surname></string-name></person-group>, &#x201C;<article-title>A one-dimensional convolutional neural network (1D-CNN) based deep learning system for network intrusion detection</article-title>,&#x201D; <source>Appl. Sci.</source>, vol. <volume>12</volume>, no. <issue>16</issue>, pp. <fpage>16</fpage>, <year>Jan. 2022</year>. doi: <pub-id pub-id-type="doi">10.3390/app12167986</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Beitollahi</surname></string-name>, <string-name><given-names>D. M.</given-names> <surname>Sharif</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Fazeli</surname></string-name></person-group>, &#x201C;<article-title>Application layer DDoS attack detection using cuckoo search algorithm-trained radial basis function</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>10</volume>, pp. <fpage>63844</fpage>&#x2013;<lpage>63854</lpage>, <year>2022</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2022.3182818</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Laghrissi</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Douzi</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Douzi</surname></string-name>, and <string-name><given-names>B.</given-names> <surname>Hssina</surname></string-name></person-group>, &#x201C;<article-title>Intrusion detection systems using long short-term memory (LSTM)</article-title>,&#x201D; <source>J. Big Data</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>, <year>May 2021</year>. doi: <pub-id pub-id-type="doi">10.1186/s40537-021-00448-4</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Bendale</surname></string-name> and <string-name><given-names>T. E.</given-names> <surname>Boult</surname></string-name></person-group>, &#x201C;<article-title>Towards open set deep networks</article-title>,&#x201D; in <conf-name>2016 IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR)</conf-name>, <year>Jun. 2016</year>, pp. <fpage>1563</fpage>&#x2013;<lpage>1572</lpage>. doi: <pub-id pub-id-type="doi">10.1109/CVPR.2016.173</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Ge</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Demyanov</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Chen</surname></string-name>, and <string-name><given-names>R.</given-names> <surname>Garnavi</surname></string-name></person-group>, &#x201C;<article-title>Generative openmax for multi-class open set classification</article-title>,&#x201D; <source>arXiv:1707.07418.</source>, <year>Jul. 24, 2017</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Yoshihashi</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Shao</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Kawakami</surname></string-name>, <string-name><given-names>S.</given-names> <surname>You</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Iida</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Naemura</surname></string-name></person-group>, &#x201C;<article-title>Classification-reconstruction learning for open-set recognition</article-title>,&#x201D; <source>2019 IEEE/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)</source>, <year>Jun. 2019</year>, pp. <fpage>4011</fpage>&#x2013;<lpage>4020</lpage>. doi: <pub-id pub-id-type="doi">10.1109/CVPR.2019.00414</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Ahmed</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Naser Mahmood</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Hu</surname></string-name></person-group>, &#x201C;<article-title>A survey of network anomaly detection techniques</article-title>,&#x201D; <source>J. Netw. Comput. Appl.</source>, vol. <volume>60</volume>, pp. <fpage>19</fpage>&#x2013;<lpage>31</lpage>, <year>Jan. 2016</year>. doi: <pub-id pub-id-type="doi">10.1016/j.jnca.2015.11.016</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Henrydoss</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Cruz</surname></string-name>, <string-name><given-names>E. M.</given-names> <surname>Rudd</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Gunther</surname></string-name>, and <string-name><given-names>T. E.</given-names> <surname>Boult</surname></string-name></person-group>, &#x201C;<article-title>Incremental open set intrusion recognition using extreme value machine</article-title>,&#x201D; in <conf-name>2017 16th IEEE Int. Conf. Mach. Learn. Appl. (ICMLA)</conf-name>, <publisher-loc>Cancun, Mexico</publisher-loc>, <year>Dec. 2017</year>, pp. <fpage>1089</fpage>&#x2013;<lpage>1093</lpage>. doi: <pub-id pub-id-type="doi">10.1109/ICMLA.2017.000-3</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Chapaneri</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Shah</surname></string-name></person-group>, &#x201C;<article-title>Multi-level Gaussian mixture modeling for detection of malicious network traffic</article-title>,&#x201D; <source>J. Supercomput</source>, vol. <volume>77</volume>, no. <issue>5</issue>, pp. <fpage>5</fpage>, <year>May 2021</year>. doi: <pub-id pub-id-type="doi">10.1007/s11227-020-03447-z</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. S.</given-names> <surname>Shieh</surname></string-name>, <string-name><given-names>W. W.</given-names> <surname>Lin</surname></string-name>, <string-name><given-names>T. T.</given-names> <surname>Nguyen</surname></string-name>, <string-name><given-names>C. H.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>M. F.</given-names> <surname>Horng</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Miu</surname></string-name></person-group>, &#x201C;<article-title>Detection of unknown DDoS attacks with deep learning and gaussian mixture model</article-title>,&#x201D; <source>Appl. Sci.</source>, vol. <volume>11</volume>, no. <issue>11</issue>, pp. <fpage>11</fpage>, <year>Jan. 2021</year>. doi: <pub-id pub-id-type="doi">10.3390/app11115213</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Xu</surname></string-name>, and <string-name><given-names>J.</given-names> <surname>Chao</surname></string-name></person-group>, &#x201C;<article-title>DDoS attacks detection with autoEncoder</article-title>,&#x201D; in <conf-name>2020 IEEE/IFIP Netw. Oper. Manag. Symp.</conf-name>, <year>Apr. 2020</year>, pp. <fpage>1</fpage>&#x2013;<lpage>9</lpage>. doi: <pub-id pub-id-type="doi">10.1109/NOMS47738.2020.9110372</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Lin</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Shi</surname></string-name>, and <string-name><given-names>Z.</given-names> <surname>Xue</surname></string-name></person-group>, &#x201C;<article-title>IDSGAN: Generative adversarial networks for attack generation against intrusion detection</article-title>,&#x201D; in <conf-name>Advances in Knowledge Discovery and Data Mining:</conf-name> <publisher-loc>Berlin, Heidelberg</publisher-loc>, <publisher-name>Springer-Verlag</publisher-name>, <year>May 2022</year>, pp. <fpage>79</fpage>&#x2013;<lpage>91</lpage>. doi: <pub-id pub-id-type="doi">10.1007/978-3-031-05981-0_7</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Chauhan</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Heydari</surname></string-name></person-group>, &#x201C;<article-title>Polymorphic adversarial DDoS attack on IDS using GAN</article-title>,&#x201D; in <italic>2020 Int. Symp. Net., Comput. Commun. (ISNCC)</italic>, <publisher-loc>Montreal, QC, Canada</publisher-loc>, <comment>Oct. 2020, pp</comment>. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>Oct. 2020</year>. doi: <pub-id pub-id-type="doi">10.1109/ISNCC49221.2020.9297264</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B. S.</given-names> <surname>Harish</surname></string-name> and <string-name><given-names>S. V.</given-names> <surname>Aruna kumar</surname></string-name></person-group>, &#x201C;<article-title>Anomaly based intrusion detection using modified fuzzy clustering</article-title>,&#x201D; <source>Int. J. Interact. Multimed. Artif. Intell.</source>, <month>Jan</month>. <year>2017</year>. doi: <pub-id pub-id-type="doi">10.9781/ijimai.2017.05.002</pub-id></mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Najafimehr</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Zarifzadeh</surname></string-name>, and <string-name><given-names>S.</given-names> <surname>Mostafavi</surname></string-name></person-group>, &#x201C;<article-title>A hybrid machine learning approach for detecting unprecedented DDoS attacks</article-title>,&#x201D; <source>J. Supercomput</source>, vol. <volume>78</volume>, no. <issue>6</issue>, pp. <fpage>6</fpage>, <year>Apr. 2022</year>. doi: <pub-id pub-id-type="doi">10.1007/s11227-021-04253-x</pub-id>; <pub-id pub-id-type="pmid">35017789</pub-id></mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Zhao</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Chen</surname></string-name>, and <string-name><given-names>G.</given-names> <surname>Xu</surname></string-name></person-group>, &#x201C;<article-title>A DNN architecture generation method for DDoS detection via genetic alogrithm</article-title>,&#x201D; <source>Future Internet</source>, vol. <volume>15</volume>, no. <issue>4</issue>, pp. <fpage>4</fpage>, <year>Apr. 2023</year>. doi: <pub-id pub-id-type="doi">10.3390/fi15040122</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Mohammed Sharif</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Beitollahi</surname></string-name>, and <string-name><given-names>M.</given-names> <surname>Fazeli</surname></string-name></person-group>, &#x201C;<article-title>Detection of application-Layer DDoS attacks produced by various freely accessible toolkits using machine learning</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>11</volume>, pp. <fpage>51810</fpage>&#x2013;<lpage>51819</lpage>, <year>2023</year>. doi: <pub-id pub-id-type="doi">10.1109/ACCESS.2023.3280122</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. S.</given-names> <surname>Shieh</surname></string-name>, <string-name><given-names>T. T.</given-names> <surname>Nguyen</surname></string-name>, <string-name><given-names>C. Y.</given-names> <surname>Chen</surname></string-name>, and <string-name><given-names>M. F.</given-names> <surname>Horng</surname></string-name></person-group>, &#x201C;<article-title>Detection of unknown DDoS attack using reconstruct error and one-class SVM featuring stochastic gradient descent</article-title>,&#x201D; <source>Mathematics</source>, vol. <volume>11</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>, <year>Jan. 2023</year>. doi: <pub-id pub-id-type="doi">10.3390/math11010108</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H. M.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>X. Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Yin</surname></string-name>, and <string-name><given-names>C. L.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Robust classification with convolutional prototype learning</article-title>,&#x201D; in <conf-name>2018 IEEE/CVF Conf. Comput. Vis. Pattern Recognit.</conf-name>, <year>Jun. 2018</year>, pp. <fpage>3474</fpage>&#x2013;<lpage>3482</lpage>. doi: <pub-id pub-id-type="doi">10.1109/CVPR.2018.00366</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>U. O. N.</given-names> <surname>Brunswick</surname></string-name></person-group>, &#x201C;<article-title>Intrusion Detection Evaluation Dataset (CIC-IDS2017)</article-title>,&#x201D; <comment>Accessed: Nov. 02, 2023</comment>. [<comment>Online</comment>]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/ids-2017.html">https://www.unb.ca/cic/datasets/ids-2017.html</ext-link></mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>U. O. N.</given-names> <surname>Brunswick</surname></string-name></person-group>, &#x201C;<article-title>DDoS Evaluation Dataset (CIC-DDoS2019)</article-title>,&#x201D; <comment>Accessed: Nov. 02, 2023. [Online</comment>]. Available: <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/ddos-2019.html">https://www.unb.ca/cic/datasets/ddos-2019.html</ext-link></mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. S.</given-names> <surname>Shieh</surname></string-name>, <string-name><given-names>T. T.</given-names> <surname>Nguyen</surname></string-name>, and <string-name><given-names>M. F.</given-names> <surname>Horng</surname></string-name></person-group>, &#x201C;<article-title>Detection of unknown DDoS attack using convolutional neural networks featuring geometrical metric</article-title>,&#x201D; <source>Mathematics</source>, vol. <volume>11</volume>, no. <issue>9</issue>, pp. <fpage>9</fpage>, <year>Jan. 2023</year>. doi: <pub-id pub-id-type="doi">10.3390/math11092145</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>