Utilizing Poisson modeling and advanced machine learning techniques for enhanced detection of slowloris attacks
International Journal of Artificial Intelligence
Abstract
This paper presents a secure framework for detecting and mitigating slowloris attacks in software defined networks (SDN) using Poisson arrival modeling to generate attack traffic. Slowloris attacks imitate legitimate traffic patterns, making them difficult to identify. The framework includes three modules: a data generation module, a feature selection module based on the blended statistical and information gain (BSIG) approach, and a traffic classification module using machine learning and deep learning algorithms. Poisson arrival modeling captures the stochastic nature of attack traffic by introducing variability in packet inter-arrival times, thereby simulating realistic network conditions. Monte Carlo simulations establish anomaly thresholds, while the BSIG method identifies key features, such as inter-arrival variability and CPU utilization. Support vector machine (SVM), k-nearest neighbors (KNN), and random forest (RF) classifiers achieve high precision in distinguishing legitimate traffic from attack traffic. The integration of Poisson modeling with advanced analytical methods improves detection capability while maintaining scalability for similar stealth attacks. The proposed methodology provides high detection accuracy and adapts to dynamic network environments, enhancing web server defenses against slowloris attacks in real-world scenarios. The framework also reduces false positives, supports efficient resource utilization, and strengthens proactive security management in modern SDN infrastructures under varying conditions.
Discover Our Library
Embark on a journey through our expansive collection of articles and let curiosity lead your path to innovation.





