通过多视角融合提升复杂网络异常流量检测能力
Network Anomaly Traffic Detection via Multi-view Feature Fusion
- 从时间与交互两个视角建模流量特征
- 在六大数据集上均实现优异检测性能
- 适合需要高精度异常检测的网络安全场景
传统异常流量检测方法依赖单一视角分析,在应对复杂攻击和加密通信时存在明显局限。为此,本文提出多视角特征融合(MuFF)方法,分别基于时间视角和交互视角建模网络流量中数据包的时序与交互关系,学习相应的时序与交互特征,并从不同视角进行融合以实现异常流量检测。在六个真实流量数据集上的大量实验表明,MuFF在异常流量检测任务中表现优异,弥补了单一视角检测的不足。
原文摘要 · Abstract (English)
Traditional anomalous traffic detection methods are based on single-view analysis, which has obvious limitations in dealing with complex attacks and encrypted communications. In this regard, we propose a Multi-view Feature Fusion (MuFF) method for network anomaly traffic detection. MuFF models the temporal and interactive relationships of packets in network traffic based on the temporal and interactive viewpoints respectively. It learns temporal and interactive features. These features are then fused from different perspectives for anomaly traffic detection. Extensive experiments on six real traffic datasets show that MuFF has excellent performance in network anomalous traffic detection, which makes up for the shortcomings of detection under a single perspective.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。