用自动化机器学习构建自主入侵检测系统,降低人工依赖。
Towards Autonomous Cybersecurity: An Intelligent AutoML Framework for Autonomous Intrusion Detection
- 全链路自动化:从数据处理到模型集成全程无需人工干预。
- 在CICIDS2017和5G-NIDD上优于现有主流方法。
- 适合需要低维护、高自动化的下一代网络安全部署。
从5G到6G的移动网络快速发展,推动了零接触网络(ZTN)等自治网络管理系统的兴起。然而,网络复杂度与自动化程度的提升也带来了更高的网络安全风险。现有基于传统机器学习(ML)的入侵检测系统(IDS)虽有效缓解风险,但普遍依赖大量人工操作与专家知识。为此,本文提出一种基于自动化机器学习(AutoML)的自主入侵检测框架,实现下一代网络的自主安全防护。该框架自动化完成数据预处理、特征工程、模型选择、超参数调优及模型集成等关键流程:采用表格变分自编码器(TVAE)实现数据平衡;基于树模型进行特征选择与基础模型训练;使用贝叶斯优化(BO)进行超参数调优;并提出一种新型置信度优化堆叠集成(OCSE)方法实现自动化模型融合。在两个公开基准数据集CICIDS2017和5G-NIDD上的实验表明,该方法性能优于当前先进安全技术。本研究为实现下一代网络的完全自主安全迈出关键一步,有望革新网络安全部署范式。
原文摘要 · Abstract (English)
The rapid evolution of mobile networks from 5G to 6G has necessitated the development of autonomous network management systems, such as Zero-Touch Networks (ZTNs). However, the increased complexity and automation of these networks have also escalated cybersecurity risks. Existing Intrusion Detection Systems (IDSs) leveraging traditional Machine Learning (ML) techniques have shown effectiveness in mitigating these risks, but they often require extensive manual effort and expert knowledge. To address these challenges, this paper proposes an Automated Machine Learning (AutoML)-based autonomous IDS framework towards achieving autonomous cybersecurity for next-generation networks. To achieve autonomous intrusion detection, the proposed AutoML framework automates all critical procedures of the data analytics pipeline, including data pre-processing, feature engineering, model selection, hyperparameter tuning, and model ensemble. Specifically, it utilizes a Tabular Variational Auto-Encoder (TVAE) method for automated data balancing, tree-based ML models for automated feature selection and base model learning, Bayesian Optimization (BO) for hyperparameter optimization, and a novel Optimized Confidence-based Stacking Ensemble (OCSE) method for automated model ensemble. The proposed AutoML-based IDS was evaluated on two public benchmark network security datasets, CICIDS2017 and 5G-NIDD, and demonstrated improved performance compared to state-of-the-art cybersecurity methods. This research marks a significant step towards fully autonomous cybersecurity in next-generation networks, potentially revolutionizing network security applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。