Um Método para Detecção Online Não Supervisionada de Ataques DDoS em Fluxos de Dados
Resumo
A infraestrutura digital enfrenta desafios crescentes com ataques de Negação de Serviço Distribuído (DDoS), cuja detecção em fluxos de dados exige alta precisão sob restrições de passagem única e memória limitada. Este artigo apresenta o MODUS (Method for Online Detection Unsupervised Streams), um método online e não supervisionado para detecção de ataques DDoS volumétricos sob as restrições de Processamento de Fluxo de Dados (DSP), que monitora mudanças estatísticas no tráfego para incorporar informações de mudança de conceito à detecção de anomalias. A avaliação com os conjuntos CTU-13, Edge-IIoT e ASEADOS-SDN-IoT demonstra que o MODUS mantém reduzido custo computacional, aderindo estritamente às restrições de memória e processamento inerentes ao paradigma de aprendizado em fluxos de dados.
Referências
Bifet, A., Gavaldà, R., Holmes, G., and Pfahringer, B. (2018). Machine Learning for Data Streams with Practical Examples in MOA. MIT Press. [link].
Bifet, A. and Gavaldà, R. (2007). Learning from time-changing data with adaptive windowing. In Proceedings of the 7th SIAM International Conference on Data Mining, pages 1–7.
Cardellini, V., Lo Presti, F., Nardelli, M., and Russo, G. R. (2022). Runtime adaptation of data stream processing systems: The state of the art. ACM Comput. Surv., 54(11s):1–36.
Cloudflare (2026). DDoS threat report for 2025 Q4. Online. Acessado em: 3 maio 2026.
Ferrag, M. A., Friha, O., Hamouda, D., Maglaras, L., and Janicke, H. (2022). Edge-iiotset: A new comprehensive realistic cyber security dataset of iot and iiot applications for centralized and federated learning. IEEE Access, 10.
García, S., Ramírez-Gallego, S., Luengo, J., Benítez, J. M., and Herrera, F. (2016). Big data preprocessing: methods and prospects. Big Data Analytics, 1(1):9.
García, S., Grill, M., Stiborek, J., and Zunino, A. (2014). An empirical comparison of botnet detection methods. Computers & Security, 45:100–123.
Garg, U., Kaur, M., Kaushik, M., and Gupta, N. (2021). Detection of DDoS attacks using semi-supervised based machine learning approaches. In International Conference on Computational Methods in Science & Technology, pages 112–117.
Hindy, H., Brosset, D., Bayne, E., Seeam, A., Tachtatzis, C., and Bellekens, X. (2020). A taxonomy of network threats and the effect of current datasets on intrusion detection systems. IEEE Access, PP:1–28.
Iglewicz, B. and Hoaglin, D. (1993). How to Detect and Handle Outliers. ASQC basic references in quality control. ASQC Quality Press.
Khraisat, A., Gondal, I., Vamplew, P., and Kamruzzaman, J. (2019). Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity, 2:1–22.
Lakshan Yasarathna, T. and Le-Khac, N.-A. (2026). Aseados-sdn-iot: A novel sdn-iot network intrusion detection dataset and framework. Internet of Things, 36:1–30.
NETSCOUT Systems, Inc. (2026). Brazil - latest cyber threat intelligence report. Online. Acessado em: 3 maio 2026.
Ring, M., Wunderlich, S., Scheuring, D., Landes, D., and Hotho, A. (2019). A survey of network-based intrusion detection data sets. Comput. Secur., 86(C):147—-167.
Romo-Chavero, M. A., Cantoral-Ceballos, J. A., Pérez-Díaz, J. A., and Martinez-Cagnazzo, C. (2024). Median absolute deviation for bgp anomaly detection. Future Internet, 16(5):5–18.
Rossow, C. (2014). Amplification hell: Revisiting network protocols for ddos abuse. In 2014 Network and Distributed System Security Symposium, pages 1–15.
Scaranti, G. F., Carvalho, L. F., Barbon, S., Lloret, J., and Proença, M. L. (2022). Unsupervised online anomaly detection in software defined network environments. Expert Systems with Applications, 191:1–13.
Selvam, S. and Maheswari Balasubramanian, U. (2024). UASDAC: An unsupervised adaptive scalable DDoS attack classification in large-scale IoT network under concept drift. IEEE Access, 12:64701–64716.
Shi, Z., Li, J., and Wu, C. (2019). Deepddos: Online DDoS attack detection. In IEEE Global Communications Conference (GLOBECOM), pages 1–6.
Sommer, R. and Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010 IEEE Symposium on Security and Privacy, pages 305–316, USA. IEEE Computer Society.
Tan, S. C., Ting, K. M., and Liu, T. F. (2017). Fast anomaly detection for streaming data. In Proceedings of the International Joint Conference on Artificial Intelligence (IJCAI), volume 106, pages 1469–1495.
Yang, S., Zheng, X., Li, J., Xu, J., Zhang, X., and Ngai, E. C. H. (2025). Self-supervised adaptation method to concept drift for network intrusion detection. IEEE Transactions on Dependable and Secure Computing, 22(6):7632–7646.
Zhou, P. (2025). A survey of streaming data anomaly detection in network security. PeerJ Computer Science, pages 21–22. DOI: 10.7717/peerj-cs.3066.
