通过统计分析与特征工程,提升机器学习对拒绝服务攻击的检测效果
Exploring Feature Importance and Explainability Towards Enhanced ML-Based DoS Detection in AI Systems
- 结合统计分析与特征工程,挖掘网络流量中关键特征
- 实验证明该方法能显著提高攻击检测准确率与训练效率
- 适合安全研究人员和机器学习防护系统开发者参考
拒绝服务(DoS)攻击对人工智能系统安全构成重大威胁,导致巨大经济损失与服务中断。然而,由于AI系统计算需求高、行为动态且数据变化大,监测和检测DoS攻击极具挑战。当前基于统计和机器学习(ML)的DoS分类与检测方法普遍采用多种特征选择机制,从网络流量数据集中选取特征子集。特征选择在提升模型性能、增强攻击检测精度的同时,可有效缩短训练时间。本文研究特征选择在提升基于机器学习的DoS检测能力中的作用,具体通过统计分析与特征工程方法,探究特征在DoS流量数据集中的贡献度。实验结果表明,深入的统计分析与特征工程有助于理解攻击行为,并识别出最优特征子集,从而显著提升基于机器学习的DoS分类与检测性能。
原文摘要 · Abstract (English)
Denial of Service (DoS) attacks pose a significant threat in the realm of AI systems security, causing substantial financial losses and downtime. However, AI systems' high computational demands, dynamic behavior, and data variability make monitoring and detecting DoS attacks challenging. Nowadays, statistical and machine learning (ML)-based DoS classification and detection approaches utilize a broad range of feature selection mechanisms to select a feature subset from networking traffic datasets. Feature selection is critical in enhancing the overall model performance and attack detection accuracy while reducing the training time. In this paper, we investigate the importance of feature selection in improving ML-based detection of DoS attacks. Specifically, we explore feature contribution to the overall components in DoS traffic datasets by utilizing statistical analysis and feature engineering approaches. Our experimental findings demonstrate the usefulness of the thorough statistical analysis of DoS traffic and feature engineering in understanding the behavior of the attack and identifying the best feature selection for ML-based DoS classification and detection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。