Flow-Based and Packet-Based Intrusion Detection Using BLSTM Flow-Based and Packet-Based Intrusion Detection Using BLSTM

Flow-Based and Packet-Based Intrusion Detection Using BLSTM Flow-Based and Packet-Based Intrusion Detection Using BLSTM
复制标题

使用 BLSTM 进行基于流和基于数据包的入侵检测 使用 BLSTM 进行基于流和基于数据包的入侵检测

DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Omar Youssef
Omar Youssef
中科院分区:
--
文献类型:
--
作者:
Brook Andreas;Jayaweera Dilruksha;Eric McCandless;Shaibal Chakrabarty;Omar Youssef

文献摘要

被引文献

相似文献

.网络总是受到恶意入侵的威胁。深度学习模型用于帮助识别和减轻入侵,防止损害发生。人们已经研究、构建和测试了各种类型的深度学习模型,目的是提高入侵检测和效率。本文提出了一种称为混合入侵检测系统(HIDS)的两阶段深度学习方法,该方法使用双向长短期记忆神经网络(BLSTM)来评估基于流的网络数据和基于数据包的数据。这种方法是独特的,因为使用BLSTM而不是传统的深度神经网络(DNN),并且使用两个模型来评估基于流和基于分组的数据,而通常只评估一种类型的数据。使用UNSW-NB 15数据集测试了这两个模型,并使用准确度,精确度,召回率和F1测量评估了性能。将模型的准确性与使用DNN模型生成的结果进行比较。BLSTM基于流的模型实现了96%的准确度,而DNN则为93%。然而,BLSTM基于数据包的模型达到了76%的准确率,略低于DNN的81%。结果表明,BLSTM在预测基于流的数据时更有效,但DNN在预测基于分组的数据时更有效。未来的工作将是改进BLSTM基于数据包的模型,使其优于或与DNN相当。一旦实现这一点,使用BLSTM以混合方式分析基于流和基于分组的数据可以提供额外的可靠保护层(如果内置在级联场景中)。
. Networks are always under the threat of malicious intrusions. Deep learning models are used to help identify and mitigate intrusions before damage can occur. Various types of deep learning models have been researched, built, and tested with the goal of improving intrusion detection and efficiencies. In this paper, a two-phase deep learning approach called a Hybrid Intrusion Detection System (HIDS) is proposed that uses Bi-Directional Long Short-Term Memory Neural Network (BLSTM) to assess both flow-based network data and packet-based data. This approach is unique because BLSTM is employed rather than a traditional Deep Neural Network (DNN) and two models are used to assess both flow-based and packet-based data, whereas typically only one type of data is assessed. The two models were tested using the UNSW-NB15 dataset and performance was evaluated using accuracy, precision, recall, and F1-measure. Accuracy of the models was compared to results generated using DNN models. The BLSTM flow-based model achieved an accuracy of 96% compared to 93% using DNN. However, the BLSTM packet-based model achieved 76% accuracy, which is slightly lower than 81% using DNN. The results suggest that BLSTM is more effective in predicting flow-based data, but DNN is more effective in predicting packet-based data. Future work will be to improve the BLSTM packet-based model so that it is better than or comparable to DNN. Once this is achieved, analyzing both flow-based and packet-based data in a hybrid fashion using BLSTM could provide an extra layer of reliable protection if built in a cascaded scenario.