用新型神经网络提升网络入侵检测与分类准确率
SCGNet-Stacked Convolution with Gated Recurrent Unit Network for Cyber Network Intrusion Detection and Intrusion Type Classification
- 融合堆叠卷积与门控循环单元的深度学习架构
- 在NSL-KDD数据集上检测准确率达99.76%,分类达98.92%
- 适合网络安全研究者和工业级入侵检测系统开发者
入侵检测系统(IDS)用于识别网络中的恶意活动或策略违规行为,通过检测已知攻击或异常行为来保护主机或网络。随着网络数据量激增,传统IDS难以高效应对复杂多变的攻击,尤其是低频攻击。本文提出一种新型深度学习架构SCGNet(Stacked Convolution with Gated Recurrent Unit Network),在NSL-KDD数据集上实现了99.76%的攻击检测准确率和98.92%的攻击类型分类准确率。同时,我们设计了一个通用的数据预处理流程,可适配其他类似数据集,并通过传统机器学习方法验证了该流程的有效性。
原文摘要 · Abstract (English)
Intrusion detection system (IDS) is a piece of hardware or software that looks for malicious activity or policy violations in a network. It looks for malicious activity or security flaws on a network or system. IDS protects hosts or networks by looking for indications of known attacks or deviations from normal behavior (Network-based intrusion detection system, or NIDS for short). Due to the rapidly increasing amount of network data, traditional intrusion detection systems (IDSs) are far from being able to quickly and efficiently identify complex and varied network attacks, especially those linked to low-frequency attacks. The SCGNet (Stacked Convolution with Gated Recurrent Unit Network) is a novel deep learning architecture that we propose in this study. It exhibits promising results on the NSL-KDD dataset in both task, network attack detection, and attack type classification with 99.76% and 98.92% accuracy, respectively. We have also introduced a general data preprocessing pipeline that is easily applicable to other similar datasets. We have also experimented with conventional machine-learning techniques to evaluate the performance of the data processing pipeline.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。