Slow DoS attacks are stealthy threats that operate at a much lower packet rate than flooding-based DoS attacks, allowing them to blend seamlessly with normal traffic and evade detection. While several solutions have been proposed in the literature, most rely on labeled attack data, which is often unavailable, or depend on flow-level features, which are resource-intensive and may not enable timely detection. To overcome these limitations, we define a machine learning-based intrusion detection system that requires no prior knowledge of malicious traffic and operates at the packet level, enabling real-time detection. Unlike flow-level approaches, packet-based analysis does not require maintaining long-lived per-flow state or reconstructing high-volume traffic aggregates, which can be computationally expensive in high-throughput environments. Our solution is based on a three-phase approach: First, the preprocessing phase normalizes incoming network traffic using a risk-aware strategy designed to highlight deviations that may indicate malicious behavior. Next, the anomaly-detection phase employs an unsupervised neural model to distinguish normal traffic from anomalous patterns. Finally, the postprocessing phase refines the model's output and, whenever an attack is detected, identifies the attacker's IP address. We evaluate the proposed IDS against three real-world datasets under various slow DoS attacks. Experimental results demonstrate detection performance comparable to that of supervised methods.

Detecting the invisible without knowledge: Unsupervised packet-based real-time detection of slow DoS attacks

Rullo A.
;
Cambiaso E.;Guarascio M.
2026

Abstract

Slow DoS attacks are stealthy threats that operate at a much lower packet rate than flooding-based DoS attacks, allowing them to blend seamlessly with normal traffic and evade detection. While several solutions have been proposed in the literature, most rely on labeled attack data, which is often unavailable, or depend on flow-level features, which are resource-intensive and may not enable timely detection. To overcome these limitations, we define a machine learning-based intrusion detection system that requires no prior knowledge of malicious traffic and operates at the packet level, enabling real-time detection. Unlike flow-level approaches, packet-based analysis does not require maintaining long-lived per-flow state or reconstructing high-volume traffic aggregates, which can be computationally expensive in high-throughput environments. Our solution is based on a three-phase approach: First, the preprocessing phase normalizes incoming network traffic using a risk-aware strategy designed to highlight deviations that may indicate malicious behavior. Next, the anomaly-detection phase employs an unsupervised neural model to distinguish normal traffic from anomalous patterns. Finally, the postprocessing phase refines the model's output and, whenever an attack is detected, identifies the attacker's IP address. We evaluate the proposed IDS against three real-world datasets under various slow DoS attacks. Experimental results demonstrate detection performance comparable to that of supervised methods.
2026
Istituto di Calcolo e Reti ad Alte Prestazioni - ICAR
Deep learning
Denial of service
Intrusion detection system
Slow DoS
Unsupervised learning
File in questo prodotto:
File Dimensione Formato  
2026_ASOC.pdf

accesso aperto

Descrizione: published version
Tipologia: Versione Editoriale (PDF)
Licenza: Creative commons
Dimensione 3.5 MB
Formato Adobe PDF
3.5 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/599282
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact