Deep learning for malicious flow detection

Deep learning for malicious flow detection
复制标题

DOI:
10.1109/pimrc.2017.8292316
复制
发表时间:
2017-10
期刊:
2017 IEEE 28th Annual International Symposium on Personal, Indoor, and Mobile Radio Communications (PIMRC)
影响因子:
--
通讯作者:
Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin
Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin
中科院分区:
其他
文献类型:
--
作者:
Yun-Chun Chen;Yu-Jhe Li;Aragorn Tseng;Tsungnan Lin

文献摘要

被引文献

相似文献

网络安全是近年来的一个热点问题。如何识别潜在的恶意软件成为一项具有挑战性的任务。为了应对这一挑战,我们采用深度学习方法并对真实的数据进行流检测。然而,真实的数据经常遇到数据分布不平衡的问题,这将导致梯度稀释问题。在训练神经网络时,这个问题不仅会导致偏向多数类,而且会显示无法从少数类学习。在本文中,我们提出了一种树形深度神经网络(Tree-Shaped Deep Neural Network,TSDNN),它以分层的方式对数据进行分类。为了更好地从少数类中学习,我们提出了一种数量相关反向传播(QDBP)算法,该算法结合了类之间差异的知识。我们评估我们的方法在一个不平衡的数据集。实验结果表明,我们的方法优于国家的最先进的方法,并证明所提出的方法是能够克服不平衡学习的困难。我们还进行了一个部分流实验,展示了实时检测的可行性,以及一个零射击学习实验,证明了深度学习在网络安全中的泛化能力。
Cyber security has grown up to be a hot issue in recent years. How to identify potential malware becomes a challenging task. To tackle this challenge, we adopt deep learning approaches and perform flow detection on real data. However, real data often encounters an issue of imbalanced data distribution which will lead to a gradient dilution issue. When training a neural network, this problem will not only result in a bias toward the majority class but show the inability to learn from the minority classes. In this paper, we propose a Tree-Shaped Deep Neural Network (TSDNN) which classifies the data in a layer-wise manner. To better learn from the minority classes, we propose a Quantity Dependent Backpropagation (QDBP) algorithm which incorporates the knowledge of the disparity between classes. We evaluate our method on an imbalanced data set. Experimental result demonstrates that our approach outperforms the state-of-the-art methods and justifies that the proposed method is able to overcome the difficulty of imbalanced learning. We also conduct a partial flow experiment which shows the feasibility of realtime detection and a zero-shot learning experiment which justifies the generalization capability of deep learning in cyber security.