Toward Effective Intrusion Detection Using Log-Cosh Conditional Variational Autoencoder

Toward Effective Intrusion Detection Using Log-Cosh Conditional Variational Autoencoder
复制标题

DOI:
10.1109/jiot.2020.3034621
复制
发表时间:
2021-04-15
影响因子:
10.6
通讯作者:
Shen, Fumin
Shen, Fumin
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xu, Xing;Li, Jie;Shen, Fumin

文献摘要

被引文献

相似文献

入侵检测是一项重要技术,可以为网络设备抵御安全攻击提供坚实的保障。但攻击类型往往不均衡,随着互联网建设的发展,未知类别的攻击也可能出现。在这种情况下,传统的基于机器学习的入侵检测方法通常检测精度较差,误报率较高。为了解决这个问题,在本文中,我们提出了一种新颖的基于深度学习的入侵检测方法,称为 log-cosh 条件变分自动编码器(LCVAE)。它继承了条件变分自动编码器(CVAE)的功能,可以捕获观察数据的复杂分布并生成具有预先指定类别的新数据。与传统的CVAE不同,为了更好地模拟入侵数据中的离散属性,我们在所提出的LCVAE方法中使用对数双曲余弦(log-cosh)函数设计了有效的损失项。它可以很好地平衡生成和重建过程,并且更有效地为不平衡类生成多样化的入侵数据。为了提高检测精度,我们利用基于卷积神经网络的分类,根据观察到的和生成的入侵数据进行特征提取和分类。我们对具有挑战性的数据集 NSL-KDD 和大规模入侵数据进行了广泛的实验。结果表明,与几种最先进的入侵检测方法相比,所提出的 LCVAE 方法具有优越的检测性能,并且还证明了生成具有良好多样性的新入侵数据的潜力。
Intrusion detection is an important technique that can provide solid protection for the network equipment against the security attacks. However, the attacks are usually unbalanced in different types and the attacks of unknown classes may also occur with the growth of Internet construction. In this case, the traditional machine learning-based intrusion detection methods usually have inferior detection accuracy and high false-positive rates. To tackle this problem, in this article, we propose a novel deep learning-based intrusion detection method named log-cosh conditional variational autoencoder (LCVAE). It inherits the capability of the conditional variational autoencoder (CVAE) that can capture the complex distribution of observed data and generate new data with prespecified classes. Different from the traditional CVAE, to better model the discrete property in the intrusion data, we design an effective loss term using the log hyperbolic cosine (log-cosh) function in the proposed LCVAE method. It can well balance the generation and reconstruction procedures and is more effective to generate diverse intrusion data for the imbalanced classes. To improve the detection accuracy, we utilize the classification based on convolutional neural network to perform feature extraction and classification based on the observed and generated intrusion data. We conduct extensive experiments on the challenging data set NSL-KDD with large-scale intrusion data. The results show that the superior detection performance of the proposed LCVAE method comparing with several state-of-the-art intrusion detection methods, and also demonstrate the potentiality of generating new intrusion data with promising diversity.