%A Wei Feng and Yuqin Wu %T DDoS Attack Real-Time Defense Mechanism using Deep Q-Learning Network %0 Journal Article %D 2020 %J Int J Performability Eng %R 10.23940/ijpe.20.09.p5.13621373 %P 1362-1373 %V 16 %N 9 %U {https://www.ijpe-online.com/CN/abstract/article_4467.shtml} %8 2020-09-30 %X The system distributed denial of service (DDoS) contains high covert attack characteristics and requires real-time defense. In order to solve such two problems for system DDoS, this paper proposes a novel DDoS attack real-time defense mechanism based on deep Q-learning network (DQN). This mechanism regards the terminal adaptive control system as the protection object, periodically extracts the network attack characteristic parameters, and takes such parameters as the input parameters of the deep Q-learning network. Our defense measures are based on dynamic service resource allocation, which dynamically adjusts the service resource according to the current operating state of the system. The current operating state will ensure the response rate of normal service requests. Finally, the attack and defense processes are modeled and simulated using colored Petri network (CPN) combined with DQN. Experimental results show that the proposed mechanism has real-time and high sensitivity defense for the response to DDoS attacks. The proposed mechanism significantly improves the automation degree of system defense. By using such a mechanism in the real-time defense of DDoS attacks, the system will be safer than the state-of-the-art mechanisms.