无需标注数据,实时学习网络正常行为并检测异常。
Anomaly detection in network flows using unsupervised online machine learning
- 基于在线学习的无监督模型,持续更新网络正常模式。
- 在NF-UNSW-NB15-v2上达98%准确率、100%召回率、<3.1%误报率。
- 每流处理时间低于0.033毫秒,适合实时系统部署。
当前网络流量持续增长,攻击频率和复杂度不断提升,亟需能够持续自适应的解决方案,因为网络行为具有动态性且随时间变化。本文提出一种基于无监督机器学习的在线学习异常检测模型,用于网络流分析。该方法无需标签数据,可动态学习网络正常行为并识别偏离,适用于流量频繁变化且标注数据稀缺的真实环境。模型基于River库实现,采用One-Class SVM,在NF-UNSW-NB15数据集及其v2版本上进行评估,后者包含多种攻击类别的标注流量。结果显示,在最先进版本数据集上,准确率超过98%,误报率低于3.1%,召回率达到100%。此外,单个流处理时间低于0.033毫秒,证明了该方法在实时应用中的可行性。
原文摘要 · Abstract (English)
Nowadays, the volume of network traffic continues to grow, along with the frequency and sophistication of attacks. This scenario highlights the need for solutions capable of continuously adapting, since network behavior is dynamic and changes over time. This work presents an anomaly detection model for network flows using unsupervised machine learning with online learning capabilities. This approach allows the system to dynamically learn the normal behavior of the network and detect deviations without requiring labeled data, which is particularly useful in real-world environments where traffic is constantly changing and labeled data is scarce. The model was implemented using the River library with a One-Class SVM and evaluated on the NF-UNSW-NB15 dataset and its extended version v2, which contain network flows labeled with different attack categories. The results show an accuracy above 98%, a false positive rate below 3.1%, and a recall of 100% in the most advanced version of the dataset. In addition, the low processing time per flow (<0.033 ms) demonstrates the feasibility of the approach for real-time applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。