构建含时间特征的NetFlow数据集,助力入侵检测模型识别攻击模式。
Temporal Analysis of NetFlow Datasets for Network Intrusion Detection Systems
- 构建包含时序特征的公开NetFlow数据集,填补现有数据空白。
- 发现多种攻击具有独特的时间频率模式,利于机器学习识别。
- 适用于网络安全研究者及入侵检测系统开发者参考使用。
本文研究基于机器学习的网络入侵检测系统(NIDS)中NetFlow数据集的时间特性。尽管以往研究强调了包间到达时间、流长度/持续时间等时间特征的重要性,但现有NetFlow数据集普遍缺乏这些特征。为此,本文创建并公开了一组包含时间特征的NetFlow数据集[1]。基于这些特征,我们对NetFlow数据进行了全面的时间分析,考察各类特征随时间的分布,并展示其时间序列表示,这是此前文献未提供的。此外,借鉴信号处理中的时频分析思想,测试了不同攻击对应的时间频率信号表示(TFSPs)的差异。结果表明,多种攻击呈现独特模式,有助于机器学习模型更准确地识别它们。
原文摘要 · Abstract (English)
This paper investigates the temporal analysis of NetFlow datasets for machine learning (ML)-based network intrusion detection systems (NIDS). Although many previous studies have highlighted the critical role of temporal features, such as inter-packet arrival time and flow length/duration, in NIDS, the currently available NetFlow datasets for NIDS lack these temporal features. This study addresses this gap by creating and making publicly available a set of NetFlow datasets that incorporate these temporal features [1]. With these temporal features, we provide a comprehensive temporal analysis of NetFlow datasets by examining the distribution of various features over time and presenting time-series representations of NetFlow features. This temporal analysis has not been previously provided in the existing literature. We also borrowed an idea from signal processing, time frequency analysis, and tested it to see how different the time frequency signal presentations (TFSPs) are for various attacks. The results indicate that many attacks have unique patterns, which could help ML models to identify them more easily.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。