综述深度学习在入侵检测中的应用与挑战
Deep Learning-based Intrusion Detection Systems: A Survey
- 系统梳理深度学习入侵检测全流程技术
- 汇总公开可用的基准数据集资源
- 适合想入门该领域的研究者阅读
入侵检测系统(IDS)长期是网络安全领域的热点。近年来,随着深度学习(DL)技术的引入,基于深度学习的入侵检测系统(DL-IDS)因具备更强的泛化能力而取得显著进展。其核心思想是通过学习已知系统行为模式,将检测能力推广至零日漏洞攻击。本综述从深度学习视角,系统回顾了DL-IDS的全链条技术环节,包括数据收集、日志存储、日志解析、图摘要、攻击检测与攻击溯源。为便于研究,本文还整理了当前可用的公开基准数据集。此外,文章讨论了现有挑战与未来可能的研究方向,旨在帮助研究者理解DL-IDS的基本理念与愿景,激发研究兴趣。
原文摘要 · Abstract (English)
Intrusion Detection Systems (IDS) have long been a hot topic in the cybersecurity community. In recent years, with the introduction of deep learning (DL) techniques, IDS have made great progress due to their increasing generalizability. The rationale behind this is that by learning the underlying patterns of known system behaviors, IDS detection can be generalized to intrusions that exploit zero-day vulnerabilities. In this survey, we refer to this type of IDS as DL-based IDS (DL-IDS). From the perspective of DL, this survey systematically reviews all the stages of DL-IDS, including data collection, log storage, log parsing, graph summarization, attack detection, and attack investigation. To accommodate current researchers, a section describing the publicly available benchmark datasets is included. This survey further discusses current challenges and potential future research directions, aiming to help researchers understand the basic ideas and visions of DL-IDS research, as well as to motivate their research interests.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。