Learning to Detect: A Data-driven Approach for Network Intrusion Detection

Learning to Detect: A Data-driven Approach for Network Intrusion Detection
复制标题

DOI:
10.1109/ipccc51483.2021.9679415
复制
发表时间:
2021-08
期刊:
2021 IEEE International Performance, Computing, and Communications Conference (IPCCC)
影响因子:
--
通讯作者:
Z. Tauscher;Yushan Jiang;Kai Zhang;Jian Wang;H. Song
Z. Tauscher;Yushan Jiang;Kai Zhang;Jian Wang;H. Song
中科院分区:
其他
文献类型:
--
作者:
Z. Tauscher;Yushan Jiang;Kai Zhang;Jian Wang;H. Song

文献摘要

相似文献

随着每天产生的海量数据和世界互联网基础设施的日益互联,基于机器学习的入侵检测系统已经成为保护我们的经济和国家安全的重要组成部分。在本文中,我们对网络流量数据集NSL-KDD进行了全面的研究,通过可视化模式和使用不同的基于学习的模型来检测网络攻击。不同于以往的浅层学习和深度学习模型使用单一学习模型的方法进行入侵检测,本文采用了分层策略,首先对入侵行为和正常行为进行分类,然后对特定类型的攻击进行分类。我们展示了无监督表示学习模型在二进制入侵检测任务中的优势。此外,我们还利用支持向量机-SMOTE过采样技术缓解了四类分类中的数据不平衡问题,并进一步论证了以深度神经网络为基本模型的过采样机制的有效性和不足。
With massive data being generated daily and the ever-increasing interconnectivity of the world’s Internet infrastructures, a machine learning based intrusion detection system (IDS) has become a vital component to protect our economic and national security. In this paper, we perform a comprehensive study on NSL-KDD, a network traffic dataset, by visualizing patterns and employing different learning-based models to detect cyber attacks. Unlike previous shallow learning and deep learning models that use the single learning model approach for intrusion detection, we adopt a hierarchy strategy, in which the intrusion and normal behavior are classified firstly, and then the specific types of attacks are classified. We demonstrate the advantage of the unsupervised representation learning model in binary intrusion detection tasks. Besides, we alleviate the data imbalance problem with SVM-SMOTE oversampling technique in 4-class classification and further demonstrate the effectiveness and the drawback of the oversampling mechanism with a deep neural network as a base model.