Improved Bidirectional GAN-Based Approach for Network Intrusion Detection Using One-Class Classifier

Improved Bidirectional GAN-Based Approach for Network Intrusion Detection Using One-Class Classifier
复制标题

使用一类分类器改进基于双向 GAN 的网络入侵检测方法

DOI:
10.3390/computers11060085
复制
发表时间:
2022
期刊:
Comput.
影响因子:
--
通讯作者:
Jin Kwak
Jin Kwak
中科院分区:
--
文献类型:
--
作者:
Wen Xu;Ju;Tong Liu;Fariza Sabrina;Jin Kwak

文献摘要

被引文献

相似文献

现有的生成对抗网络(GAN)主要用于从自然图像创建假图像样本,需要很强的依赖性(即,生成器和鉴别器的训练策略需要同步),以便生成器产生能够“欺骗”鉴别器的真实假样本。我们认为,GAN训练对图像的这种强烈依赖性不一定适用于网络入侵检测任务的GAN模型。这是因为与现有的基于GAN的图像异常检测任务相比,网络入侵输入具有更简单的特征结构,例如相对低维,离散特征值和更小的输入大小。为了解决这个问题,我们提出了一个新的双向GAN(Bi-GAN)模型,该模型更适合于网络入侵检测,减少了过度训练的开销。在我们提出的方法中,生成器(以及相应的编码器)的训练迭代与训练的迭代分开增加,直到它满足与交叉熵损失相关的条件。我们的实证结果表明,这种建议的训练策略大大提高了性能的发电机和发电机,即使在存在不平衡的类。此外,我们的模型使用经过训练的编码器-鉴别器提供了一类分类器的新构造。单类分类器基于二进制分类结果来检测异常网络流量,而不是计算昂贵且复杂的异常分数(或阈值)。我们的实验结果表明,我们提出的方法是非常有效的用于网络入侵检测任务,并优于其他类似的生成方法在两个数据集:NSL-KDD和CIC-DDoS 2019数据集。
Existing generative adversarial networks (GANs), primarily used for creating fake image samples from natural images, demand a strong dependence (i.e., the training strategy of the generators and the discriminators require to be in sync) for the generators to produce as realistic fake samples that can “fool” the discriminators. We argue that this strong dependency required for GAN training on images does not necessarily work for GAN models for network intrusion detection tasks. This is because the network intrusion inputs have a simpler feature structure such as relatively low-dimension, discrete feature values, and smaller input size compared to the existing GAN-based anomaly detection tasks proposed on images. To address this issue, we propose a new Bidirectional GAN (Bi-GAN) model that is better equipped for network intrusion detection with reduced overheads involved in excessive training. In our proposed method, the training iteration of the generator (and accordingly the encoder) is increased separate from the training of the discriminator until it satisfies the condition associated with the cross-entropy loss. Our empirical results show that this proposed training strategy greatly improves the performance of both the generator and the discriminator even in the presence of imbalanced classes. In addition, our model offers a new construct of a one-class classifier using the trained encoder–discriminator. The one-class classifier detects anomalous network traffic based on binary classification results instead of calculating expensive and complex anomaly scores (or thresholds). Our experimental result illustrates that our proposed method is highly effective to be used in network intrusion detection tasks and outperforms other similar generative methods on two datasets: NSL-KDD and CIC-DDoS2019 datasets.