arXiv:2503.08293cs.CRcs.LG2025-03中稿 · publication in Log…综述被引 9

系统梳理无监督学习在流量异常检测中的应用,助力发现未知攻击。

A systematic literature review of unsupervised learning algorithms for anomalous traffic detection based on flows

  • 基于流数据与无监督算法,避免依赖标注样本
  • 自编码器最常用,多类模型验证有效性
  • 覆盖物联网与真实蜜罐数据集,适合安全研究者

互联网设备持续增加导致网络攻击频发,传统基于报文的分析方法因流量过大难以适用。采用流(flows)作为分析单位更适配大规模网络,尤其在未来的5G网络中更具优势。结合无监督学习模型,可识别未训练过的新型威胁。本文遵循PRISMA指南,对63篇相关文献进行系统性回顾,其中13篇深度分析。结果表明,自编码器是最常使用的算法,其次为SVM、ALAD和SOM。所有实验所用数据集均被收集整理,涵盖面向物联网的专用数据集及从蜜罐获取的真实数据。

原文摘要 · Abstract (English)

The constant increase of devices connected to the Internet, and therefore of cyber-attacks, makes it necessary to analyze network traffic in order to recognize malicious activity. Traditional packet-based analysis methods are insufficient because in large networks the amount of traffic is so high that it is unfeasible to review all communications. For this reason, flows is a suitable approach for this situation, which in future 5G networks will have to be used, as the number of packets will increase dramatically. If this is also combined with unsupervised learning models, it can detect new threats for which it has not been trained. This paper presents a systematic review of the literature on unsupervised learning algorithms for detecting anomalies in network flows, following the PRISMA guideline. A total of 63 scientific articles have been reviewed, analyzing 13 of them in depth. The results obtained show that autoencoder is the most used option, followed by SVM, ALAD, or SOM. On the other hand, all the datasets used for anomaly detection have been collected, including some specialised in IoT or with real data collected from honeypots.

异常检测无监督学习网络流量系统综述

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。