用多任务时序模型生成真实网络流量,提升安全训练环境质量
TempoNet: Learning Realistic Communication and Timing Patterns for Network Traffic Simulation
- 结合多任务学习与多标记点过程,同步建模包间隔和头部字段
- 生成的流量在时间一致性与高保真度上优于传统方法,验证通过真实数据集
- 适合用于网络安全训练和入侵检测模型测试,可替代真实数据
真实网络流量模拟对评估入侵检测系统、压力测试网络协议及构建高保真网络安全训练环境至关重要。尽管攻击流量可通过红队演练或回放方法注入,但生成真实的良性背景流量仍是核心挑战,尤其在模拟现实网络中复杂的时空动态方面。本文提出TempoNet,一种新型生成模型,结合多任务学习与多标记时序点过程,联合建模包间到达时间及所有包级和流头字段。TempoNet能够捕捉细粒度的时间模式与高阶相关性,如主机对行为和季节性趋势,克服了基于GAN、LLM和贝叶斯方法在再现结构化时间变化方面的局限。其生成的流量在时间上一致且保真度高,在真实数据集上得到验证。此外,基于TempoNet生成背景流量训练的入侵检测模型,性能可媲美使用真实数据训练的模型,证实其在实际安全应用中的有效性。
原文摘要 · Abstract (English)
Realistic network traffic simulation is critical for evaluating intrusion detection systems, stress-testing network protocols, and constructing high-fidelity environments for cybersecurity training. While attack traffic can often be layered into training environments using red-teaming or replay methods, generating authentic benign background traffic remains a core challenge -- particularly in simulating the complex temporal and communication dynamics of real-world networks. This paper introduces TempoNet, a novel generative model that combines multi-task learning with multi-mark temporal point processes to jointly model inter-arrival times and all packet- and flow-header fields. TempoNet captures fine-grained timing patterns and higher-order correlations such as host-pair behavior and seasonal trends, addressing key limitations of GAN-, LLM-, and Bayesian-based methods that fail to reproduce structured temporal variation. TempoNet produces temporally consistent, high-fidelity traces, validated on real-world datasets. Furthermore, we show that intrusion detection models trained on TempoNet-generated background traffic perform comparably to those trained on real data, validating its utility for real-world security applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。