arXiv:2412.14021cs.CRcs.LG2024-12被引 4

用HERA重制网络数据集,提升入侵检测模型性能。

Flow Exporter Impact on Intelligent Intrusion Detection Systems

  • 用HERA工具重生成流量和特征,改进数据质量。
  • 新数据集上模型准确率更高,泛化能力更强。
  • 适合关注数据质量对检测效果影响的研究者。

高质量数据集对机器学习模型训练至关重要,特征生成不一致会降低威胁检测的准确性和可靠性。为此,确保网络入侵检测数据集中数据质量尤为关键,其中流量和特征的生成工具可靠性是核心。本文研究了流量导出器对入侵检测机器学习模型性能与可靠性的影。使用专门设计用于导出流量并提取特征的HERA工具,将两个广泛使用的数据集UNSW-NB15和CIC-IDS2017的原始PCAP包处理,生成新版本数据集。将这些新版本与原数据集对比,评估其对多种模型(包括Random Forest、XGBoost、LightGBM和Explainable Boosting Machine)性能的影响。结果显著:在HERA生成的数据集上训练的模型始终优于在原始数据集上训练的模型,准确率提升明显,表明模型具备更好泛化能力。这凸显了流量生成过程对区分良性与恶意流量的关键作用。

原文摘要 · Abstract (English)

High-quality datasets are critical for training machine learning models, as inconsistencies in feature generation can hinder the accuracy and reliability of threat detection. For this reason, ensuring the quality of the data in network intrusion detection datasets is important. A key component of this is using reliable tools to generate the flows and features present in the datasets. This paper investigates the impact of flow exporters on the performance and reliability of machine learning models for intrusion detection. Using HERA, a tool designed to export flows and extract features, the raw network packets of two widely used datasets, UNSW-NB15 and CIC-IDS2017, were processed from PCAP files to generate new versions of these datasets. These were compared to the original ones in terms of their influence on the performance of several models, including Random Forest, XGBoost, LightGBM, and Explainable Boosting Machine. The results obtained were significant. Models trained on the HERA version of the datasets consistently outperformed those trained on the original dataset, showing improvements in accuracy and indicating a better generalisation. This highlighted the importance of flow generation in the model's ability to differentiate between benign and malicious traffic.

入侵检测数据质量流量生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。