DoLLM: How Large Language Models Understanding Network Flow Data to Detect Carpet Bombing DDoS

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Qingyang, Zhang, Yihang, Jia, Zhidong, Hu, Yannan, Zhang, Lei, Zhang, Jianrong, Xu, Yongming, Cui, Yong, Guo, Zongming, Zhang, Xinggong
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917664295747584
author Li, Qingyang
Zhang, Yihang
Jia, Zhidong
Hu, Yannan
Zhang, Lei
Zhang, Jianrong
Xu, Yongming
Cui, Yong
Guo, Zongming
Zhang, Xinggong
author_facet Li, Qingyang
Zhang, Yihang
Jia, Zhidong
Hu, Yannan
Zhang, Lei
Zhang, Jianrong
Xu, Yongming
Cui, Yong
Guo, Zongming
Zhang, Xinggong
contents It is an interesting question Can and How Large Language Models (LLMs) understand non-language network data, and help us detect unknown malicious flows. This paper takes Carpet Bombing as a case study and shows how to exploit LLMs' powerful capability in the networking area. Carpet Bombing is a new DDoS attack that has dramatically increased in recent years, significantly threatening network infrastructures. It targets multiple victim IPs within subnets, causing congestion on access links and disrupting network services for a vast number of users. Characterized by low-rates, multi-vectors, these attacks challenge traditional DDoS defenses. We propose DoLLM, a DDoS detection model utilizes open-source LLMs as backbone. By reorganizing non-contextual network flows into Flow-Sequences and projecting them into LLMs semantic space as token embeddings, DoLLM leverages LLMs' contextual understanding to extract flow representations in overall network context. The representations are used to improve the DDoS detection performance. We evaluate DoLLM with public datasets CIC-DDoS2019 and real NetFlow trace from Top-3 countrywide ISP. The tests have proven that DoLLM possesses strong detection capabilities. Its F1 score increased by up to 33.3% in zero-shot scenarios and by at least 20.6% in real ISP traces.
format Preprint
id arxiv_https___arxiv_org_abs_2405_07638
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DoLLM: How Large Language Models Understanding Network Flow Data to Detect Carpet Bombing DDoS
Li, Qingyang
Zhang, Yihang
Jia, Zhidong
Hu, Yannan
Zhang, Lei
Zhang, Jianrong
Xu, Yongming
Cui, Yong
Guo, Zongming
Zhang, Xinggong
Networking and Internet Architecture
Artificial Intelligence
Cryptography and Security
It is an interesting question Can and How Large Language Models (LLMs) understand non-language network data, and help us detect unknown malicious flows. This paper takes Carpet Bombing as a case study and shows how to exploit LLMs' powerful capability in the networking area. Carpet Bombing is a new DDoS attack that has dramatically increased in recent years, significantly threatening network infrastructures. It targets multiple victim IPs within subnets, causing congestion on access links and disrupting network services for a vast number of users. Characterized by low-rates, multi-vectors, these attacks challenge traditional DDoS defenses. We propose DoLLM, a DDoS detection model utilizes open-source LLMs as backbone. By reorganizing non-contextual network flows into Flow-Sequences and projecting them into LLMs semantic space as token embeddings, DoLLM leverages LLMs' contextual understanding to extract flow representations in overall network context. The representations are used to improve the DDoS detection performance. We evaluate DoLLM with public datasets CIC-DDoS2019 and real NetFlow trace from Top-3 countrywide ISP. The tests have proven that DoLLM possesses strong detection capabilities. Its F1 score increased by up to 33.3% in zero-shot scenarios and by at least 20.6% in real ISP traces.
title DoLLM: How Large Language Models Understanding Network Flow Data to Detect Carpet Bombing DDoS
topic Networking and Internet Architecture
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2405.07638