用深度神经网络提升入侵检测准确率,识别各类网络攻击。
Investigating Application of Deep Neural Networks in Intrusion Detection System Design
- 采用多层感知机模型结合前向特征选择优化特征集
- 在ASNM-TUN数据集上实现对正常、直接及混淆攻击的分类
- 方法可加速检测流程,适合网络安全研究者参考
尽管经过多年发展,现有入侵检测系统(IDS)仍面临检测准确率低、易被规避以及难以发现未知攻击等问题。为此,众多研究转向利用深度神经网络(DNN)设计新型入侵检测系统,以提供更先进的威胁分析与检测能力。本研究旨在探索DNN在精准检测和识别恶意网络入侵中的有效性,并推动其在网络安全检测中的最优应用。基于ASNM-TUN数据集,采用多层感知机(MLP)模型对网络入侵进行建模,区分合法流量、直接攻击与混淆攻击。为提升效率,引入前向特征选择(FFS)技术,显著缩减特征子集。测试结果表明,该DNN模型在分类任务中未能有效准确区分各类网络入侵。
原文摘要 · Abstract (English)
Despite decades of development, existing IDSs still face challenges in improving detection accuracy, evasion, and detection of unknown attacks. To solve these problems, many researchers have focused on designing and developing IDSs that use Deep Neural Networks (DNN) which provides advanced methods of threat investigation and detection. Given this reason, the motivation of this research then, is to learn how effective applications of Deep Neural Networks (DNN) can accurately detect and identify malicious network intrusion, while advancing the frontiers of their optimal potential use in network intrusion detection. Using the ASNM-TUN dataset, the study used a Multilayer Perceptron modeling approach in Deep Neural Network to identify network intrusions, in addition to distinguishing them in terms of legitimate network traffic, direct network attacks, and obfuscated network attacks. To further enhance the speed and efficiency of this DNN solution, a thorough feature selection technique called Forward Feature Selection (FFS), which resulted in a significant reduction in the feature subset, was implemented. Using the Multilayer Perceptron model, test results demonstrate no support for the model to accurately and correctly distinguish the classification of network intrusion.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。