提出实时连续学习框架,应对多环境网络恶意流量检测难题。
MULTI-LF: A Continuous Learning Framework for Real-Time Malicious Traffic Detection in Multi-Environment Networks
- 用轻量模型快速检测,深度模型精准修正,协同提升效率与准确率。
- 在真实动态环境中实现99.9%准确率,仅0.0026%包需人工干预。
- 适合需要持续更新的网络安全系统,尤其适用于物联网混合网络。
多环境(M-En)网络融合了物联网(IoT)与传统计算系统的多样化流量,为恶意流量检测带来复杂且动态的挑战。现有基于机器学习的方法通常在静态单一域数据集上训练,难以在异构网络环境中泛化。为此,我们构建了一个基于Docker-NS3的真实测试平台,模拟物联网与传统流量条件,生成并捕获实时标注的网络流。由此产生的M-En数据集结合了公开的PCAP痕迹,全面覆盖良性与恶意行为。在此基础上,我们提出Multi-LF框架:采用轻量级模型(M1)实现快速检测,深层模型(M2)进行高置信度精炼与适应。通过置信度协调机制提升效率,权重插值缓解持续更新中的灾难性遗忘。每秒提取特征以捕捉细微时间模式,实现对演化攻击行为的早期识别。在Docker-NS3测试平台上的实时流量评估中,Multi-LF达到0.999的准确率,仅0.0026%的包需人工干预,验证了其在异构网络中实时恶意流量检测的有效性与实用性。
原文摘要 · Abstract (English)
Multi-environment (M-En) networks integrate diverse traffic sources, including Internet of Things (IoT) and traditional computing systems, creating complex and evolving conditions for malicious traffic detection. Existing machine learning (ML)-based approaches, typically trained on static single-domain datasets, often fail to generalize across heterogeneous network environments. To address this gap, we develop a realistic Docker-NS3-based testbed that emulates both IoT and traditional traffic conditions, enabling the generation and capture of live, labeled network flows. The resulting M-En Dataset combines this traffic with curated public PCAP traces to provide comprehensive coverage of benign and malicious behaviors. Building on this foundation, we propose Multi-LF, a real-time continuous learning framework that combines a lightweight model (M1) for rapid detection with a deeper model (M2) for high-confidence refinement and adaptation. A confidence-based coordination mechanism enhances efficiency without compromising accuracy, while weight interpolation mitigates catastrophic forgetting during continuous updates. Features extracted at 1-second intervals capture fine-grained temporal patterns, enabling early recognition of evolving attack behaviors. Implemented and evaluated within the Docker-NS3 testbed on live traffic, Multi-LF achieves an accuracy of 0.999 while requiring human intervention for only 0.0026 percent of packets, demonstrating its effectiveness and practicality for real-time malicious traffic detection in heterogeneous network environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。