DDoS attack matching detection method based on dynamic threshold for power monitoring local area networks
PEI Jun
WAN Bo
PENG Weiwei
YAN Hanqiu
WANG Sijie
Abstract:[Objective]DDoS attacks,as a highly destructive network threat,seriously threaten the stable operation of the power system.Due to the complexity and variability of data traffic in the power monitoring local area network(LAN),DDoS attack traffic and normal traffic have many similarities in their manifestations,making it difficult to effectively distinguish between the two.Although traditional static threshold methods can achieve traffic monitoring to a certain extent,misjudgments often occur due to their inability to adapt to the dynamic changes of traffic.The detection effect of DDoS attacks is thus weakened and reliable security guarantee cannot be provided for power monitoring LANs.Therefore,a DDoS attack matching detection method for power monitoring local area networks was proposed based on dynamic thresholds.[Methods]Real time network traffic data in the power monitoring local area network were collected through network traffic collection devices.The entropy value of these flows was calculated using information entropy theory.The chaos degree in data could be reflected by information entropy.Normal traffic usually had a certain regularity with relatively stable entropy values.Due to the influx of a large number of abnormal packets,however,DDoS attack traffic had significant fluctuations in entropy values.Based on this characteristic,a dynamic threshold was set,and the entropy value of the traffic was determined as abnormal when exceeding this dynamic threshold.The six-tuple feature set of the abnormal traffic was then extracted,including average flow packet count,average byte count,source IP address growth,flow table survival time variation,port growth,and convection ratio,and input into a pre-trained least squares support vector machine(LSSVM)classifier.The LSSVM classifier learned from the existing samples to establish the mapping relationship between features and classes.The abnormal traffic was then classified and judged to determine whether it was DDoS attack traffic.[Results]According to the test result,the proposed method shows significant improvements on both the ROC and PR curves,with higher receiver operating characteristic curve(ROC-AUC)and accuracy recall curve(PR-AUC)values than the traditional method.This fully demonstrates that the method,with higher accuracy and recall rate in detecting DDoS attacks,can effectively identify DDoS attack traffic hidden in normal traffic and reduce the misjudgment rate.[Conclusions]The detection method based on dynamic thresholds and LSSVM classifier can effectively overcome the difficulty in distinguishing DDoS attack traffic from normal traffic in power monitoring local area networks.By improving the accuracy and reliability of DDoS attack detection,it provides a more effective DDoS attack detection method for power monitoring local area networks,helps improve the security and stability of power systems,ensures the reliable operation of the power supply,and has important practical application value for network security protection in the power industry.
Keywords:power monitoring local area networkDDoS attackmatching detectiondynamic thresholdleast squares support vector machineabnormal trafficoptimal classifiersix-tuple feature
Publication Date:2025-11-25
Online Publishing Date:2025-12-29(First online date of this platform, not the publication date of the document)
Pages:8( 800-807 )
Journal of Shenyang University of Technology

Journal of Shenyang University of Technology

ISTICPKU
ISSN:1000-1646
Year, Vol.(Issue):2025,47(6)