通过时频谱分析提升攻击流量识别准确率与抗噪能力
An Attack Traffic Identification Method Based on Temporal Spectrum
- 用滑动窗口分割流量,生成时序特征与频谱标签
- 新方法使识别准确率提升10%,在噪声环境下更稳定
- 适合需要高鲁棒性网络检测的工程场景
针对现有网络攻击检测模型鲁棒性不足、特征不稳定及数据噪声干扰等问题,本文提出一种基于时频谱的攻击流量检测与识别方法。首先,通过滑动窗口对流量数据进行分段,构建对应的特征序列与标签序列;随后,采用提出的谱标签生成方法SSPE和COAP,将标签序列转换为谱标签,特征序列转换为时序特征,以捕捉并表征攻击行为模式;最后,利用构建的时序特征与谱标签训练模型,实现攻击行为的检测与识别。实验结果表明,相较于传统方法,使用SSPE或COAP方法训练的模型识别准确率提升10%,且在噪声环境中表现出更强的鲁棒性。
原文摘要 · Abstract (English)
To address the issues of insufficient robustness, unstable features, and data noise interference in existing network attack detection and identification models, this paper proposes an attack traffic detection and identification method based on temporal spectrum. First, traffic data is segmented by a sliding window to construct a feature sequence and a corresponding label sequence for network traffic. Next, the proposed spectral label generation methods, SSPE and COAP, are applied to transform the label sequence into spectral labels and the feature sequence into temporal features. Spectral labels and temporal features are used to capture and represent behavioral patterns of attacks. Finally, the constructed temporal features and spectral labels are used to train models, which subsequently detects and identifies network attack behaviors. Experimental results demonstrate that compared to traditional methods, models trained with the SSPE or COAP method improve identification accuracy by 10%, and exhibit strong robustness, particularly in noisy environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。