用大模型提升云网络异常检测准确率与效率
Research on Cloud Platform Network Traffic Monitoring and Anomaly Detection System based on Large Language Models

- 融合Transformer注意力机制的混合模型处理网络流量序列
- 在真实数据上实现更高检测准确率和更低误报率
- 支持快速适应未知网络结构,适合安全运维人员使用
快速发展的云平台和日益复杂的网络流量对网络安全与性能监控提出更高要求。本文提出一种基于大语言模型(LLM)的网络流量监控与异常检测系统。除传统自编码器与决策树外,引入大语言模型处理网络流量序列数据,更有效捕捉深层复杂模式及细微波动。实验表明,将Transformer的注意力机制融入监督学习框架可显著提升检测精度。系统采用预训练大语言模型预测正常流量,并增加考虑时序与上下文的异常检测层。此外,提出一种新型迁移学习方法,在无需大量标注数据的情况下,快速适应未知网络结构与对抗环境。实际测试结果显示,该模型在检测准确率和计算效率上优于传统方法,能有效识别零日攻击、流量拥塞等异常,且显著降低误报率。
原文摘要 · Abstract (English)
The rapidly evolving cloud platforms and the escalating complexity of network traffic demand proper network traffic monitoring and anomaly detection to ensure network security and performance. This paper introduces a large language model (LLM)-based network traffic monitoring and anomaly detection system. In addition to existing models such as autoencoders and decision trees, we harness the power of large language models for processing sequence data from network traffic, which allows us a better capture of underlying complex patterns, as well as slight fluctuations in the dataset. We show for a given detection task, the need for a hybrid model that incorporates the attention mechanism of the transformer architecture into a supervised learning framework in order to achieve better accuracy. A pre-trained large language model analyzes and predicts the probable network traffic, and an anomaly detection layer that considers temporality and context is added. Moreover, we present a novel transfer learning-based methodology to enhance the model's effectiveness to quickly adapt to unknown network structures and adversarial conditions without requiring extensive labeled datasets. Actual results show that the designed model outperforms traditional methods in detection accuracy and computational efficiency, effectively identify various network anomalies such as zero-day attacks and traffic congestion pattern, and significantly reduce the false positive rate.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。