Software-Defined Networking (SDN) provides flexible and programmable network management; however, its centralized control architecture remains highly vulnerable to Distributed Denial-of-Service (DDoS) attacks, particularly Carpet-Bombing DDoS attacks that distribute malicious traffic across multiple targets to evade conventional detection mechanisms. In this paper, a Retrieval-Augmented Generation (RAG)-based framework is proposed for real-time detection and mitigation of Carpet-Bombing DDoS attacks in SDN environments. The proposed framework combines interface-level traffic features representation, semantic embedding generation, FAISS-based similarity retrieval, and Large Language Model (LLM)-driven contextual inference to classify traffic behavior without requiring conventional supervised model training or retraining. To evaluate the effectiveness of the proposed framework, extensive experiments were conducted under multiple Carpet-Bombing DDoS attack scenarios with different attack intensities. In addition, two traffic representation strategies, namely structured JSON-based representation and natural language-based representation (NLR), were investigated using multiple state-of-the-art LLMs. The experimental results demonstrate that the proposed framework achieved highly accurate and stable attack detection performance, while the framework configuration utilizing the Gemma-4-31B-IT model achieved the strongest overall detection results. Furthermore, real-time experiments confirmed the capability of the proposed framework to rapidly detect and mitigate Carpet-Bombing DDoS attacks while maintaining stable SDN network operation. The obtained results highlight the effectiveness of integrating RAG mechanisms with LLM for intelligent and adaptive SDN security analysis.


翻译:软件定义网络(SDN)提供了灵活可编程的网络管理能力,但其集中式控制架构仍极易遭受分布式拒绝服务(DDoS)攻击,尤其是针对多目标分布恶意流量以规避传统检测机制的地毯式轰炸DDoS攻击。本文提出了一种基于检索增强生成(RAG)的框架,用于在SDN环境中实时检测和缓解地毯式轰炸DDoS攻击。该框架融合了接口级流量特征表示、语义嵌入生成、基于FAISS的相似性检索以及大语言模型(LLM)驱动的上下文推理,在无需传统监督模型训练或重训练的情况下实现流量行为分类。为评估所提框架的有效性,我们在多种攻击强度的地毯式轰炸DDoS攻击场景下开展了大量实验。此外,我们采用多种最先进的LLM,研究了两种流量表示策略,即结构化JSON表示和基于自然语言的表示(NLR)。实验结果表明,该框架实现了高精度且稳定的攻击检测性能,其中采用Gemma-4-31B-IT模型的框架配置取得了最佳综合检测效果。进一步的实时实验验证了所提框架能够快速检测并缓解地毯式轰炸DDoS攻击,同时维持SDN网络的稳定运行。研究结果凸显了将RAG机制与LLM相结合用于智能自适应SDN安全分析的有效性。

0
下载
关闭预览

相关内容

专知会员服务
34+阅读 · 2021年9月16日
专知会员服务
57+阅读 · 2020年12月28日
【综述】生成式对抗网络GAN最新进展综述
专知
61+阅读 · 2019年6月5日
最新《生成式对抗网络GAN进展》论文
专知
95+阅读 · 2019年4月5日
必读!TOP10生成对抗网络GAN论文(附链接)
数据派THU
17+阅读 · 2019年3月24日
必读!生成对抗网络GAN论文TOP 10
GAN生成式对抗网络
58+阅读 · 2019年3月20日
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
1+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
VIP会员
最新内容
俄乌无人机战争的六大启示
专知会员服务
9+阅读 · 8月3日
《无人机空中监控:通信实验洞察》
专知会员服务
7+阅读 · 8月3日
从采集到决策:美军视角下的战术情报范式重构
《履带式无人地面战车技术发展现状》
专知会员服务
7+阅读 · 8月2日
《无人机脆弱性利用:网络空间力量的新域》
专知会员服务
10+阅读 · 8月1日
相关基金
国家自然科学基金
2+阅读 · 2017年12月31日
国家自然科学基金
1+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
Top
微信扫码咨询专知VIP会员