用变分自编码与代价敏感学习提升物联网僵尸网络检测能力
Enhancing IoT-Botnet Detection using Variational Auto-encoder and Cost-Sensitive Learning: A Deep Learning Approach for Imbalanced Datasets
- 用变分自编码器提取特征,结合代价敏感学习应对数据不平衡
- 在高度不平衡数据上,两种深度模型均实现高精度与召回率
- 适合安全研究人员及物联网系统防护开发者参考
物联网技术在各行业广泛应用,但其常成为恶意攻击的入口,尤其以僵尸网络攻击最为典型。本研究采用变分自编码器(VAE)与代价敏感学习,构建轻量高效模型,提升对少数类攻击流量的检测能力。在多分类任务中,针对高度不平衡的数据集进行评估,对比标准前馈深度神经网络(DNN)与双向LSTM(BLSTM)两种模型,均在各类流量识别中取得优异的准确率、精确率、召回率和F1分数。
原文摘要 · Abstract (English)
The Internet of Things (IoT) technology has rapidly gained popularity with applications widespread across a variety of industries. However, IoT devices have been recently serving as a porous layer for many malicious attacks to both personal and enterprise information systems with the most famous attacks being botnet-related attacks. The work in this study leveraged Variational Auto-encoder (VAE) and cost-sensitive learning to develop lightweight, yet effective, models for IoT-botnet detection. The aim is to enhance the detection of minority class attack traffic instances which are often missed by machine learning models. The proposed approach is evaluated on a multi-class problem setting for the detection of traffic categories on highly imbalanced datasets. The performance of two deep learning models including the standard feed forward deep neural network (DNN), and Bidirectional-LSTM (BLSTM) was evaluated and both recorded commendable results in terms of accuracy, precision, recall and F1-score for all traffic classes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。