arXiv:2412.16791cs.CRcs.AI2024-12被引 2

用集成学习提升网站流量攻击识别准确率,效果比传统方法高20%。

Enhancing web traffic attacks identification through ensemble methods and feature selection

  • 结合特征选择与随机森林、梯度提升等集成模型
  • 在CSIC2010 v2数据集上达到0.989的AUC,准确率提升约20%
  • 适合网络安全从业者部署于真实场景的攻击检测系统

网站作为重要数字资产,因高流量和泄露影响大而易受网络攻击。本研究通过机器学习提升网页流量攻击识别能力,基于CSIC2010 v2数据集提取HTTP日志特征。采用随机森林、极端梯度提升等集成方法,对比k近邻、LASSO、支持向量机等基线模型。结果表明,集成方法预测准确率高出约20%,在ROC曲线下面积(AUC)达0.989。信息增益、LASSO、随机森林等特征选择方法进一步增强了模型鲁棒性。研究表明,集成模型可有效提升攻击检测性能并降低波动,为多种应用场景提供实用的网页流量安全防护框架。

原文摘要 · Abstract (English)

Websites, as essential digital assets, are highly vulnerable to cyberattacks because of their high traffic volume and the significant impact of breaches. This study aims to enhance the identification of web traffic attacks by leveraging machine learning techniques. A methodology was proposed to extract relevant features from HTTP traces using the CSIC2010 v2 dataset, which simulates e-commerce web traffic. Ensemble methods, such as Random Forest and Extreme Gradient Boosting, were employed and compared against baseline classifiers, including k-nearest Neighbor, LASSO, and Support Vector Machines. The results demonstrate that the ensemble methods outperform baseline classifiers by approximately 20% in predictive accuracy, achieving an Area Under the ROC Curve (AUC) of 0.989. Feature selection methods such as Information Gain, LASSO, and Random Forest further enhance the robustness of these models. This study highlights the efficacy of ensemble models in improving attack detection while minimizing performance variability, offering a practical framework for securing web traffic in diverse application contexts.

攻击检测集成学习网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。