针对网络入侵检测的不平衡数据,提出基于良性流量偏差的特征选择方法。
nCMD: Benign-Anchored Feature Selection for Imbalanced Network Intrusion Detection

- 以良性流量均值为锚点,衡量攻击特征偏离程度
- 在四个数据集上均优于传统方法,尤其在特征少时提升明显
- 轻量且可解释,适合资源受限的实时检测系统
在高维、严重不平衡的网络流量下,特征选择对网络入侵检测系统(NIDS)至关重要。传统过滤方法基于跨类对称统计量排名,无法捕捉入侵检测中攻击作为良性流量偏离的本质特性。本文提出轻量级、可解释的良性锚定类内均值偏差(nCMD)方法,通过计算攻击类分布相对于良性类均值的偏离度来评分特征相关性,而非依赖全局偏倚参考。该方法与NIDS实际运行语义一致,且无需额外计算开销。在CICIDS2017、CICDDoS2019、NSL-KDD和UNSW-NB15四个基准数据集上,多种特征预算和三种下游分类器下,nCMD在宏平均F1分数上达到或超过经典过滤基线,三个数据集表现最佳,且在严苛特征预算和严重类别不平衡条件下改进最显著。结果支持良性锚定排序作为资源受限NIDS的可扩展、可解释预处理组件。
原文摘要 · Abstract (English)
Feature selection is critical for network intrusion detection systems (NIDS) operating under high-dimensional, highly imbalanced traffic, as found in operational and defense networks. Traditional filter methods rank features using global statistics computed symmetrically across classes and thus fail to capture the asymmetry of intrusion detection, where attacks are best characterized as deviations from dominant benign traffic. We propose benign-anchored Classwise Mean Deviation (nCMD), a lightweight and interpretable method that scores feature relevance based on the deviation of attack-class distributions from the benign-class mean, rather than a globally biased reference. This approach aligns feature selection with the operational semantics of NIDS at no additional computational cost. Across four benchmark datasets (CICIDS2017, CICDDoS2019, NSL-KDD, and UNSW-NB15), multiple feature budgets, and three downstream classifiers, nCMD matches or exceeds classical filter baselines in macro-averaged F1-score. It achieves the best result on three of the four datasets and under every classifier, with the strongest improvements observed under tight feature budgets and severe class imbalance. These results support benign-anchored ranking as a scalable and interpretable preprocessing component for resource-constrained NIDS.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。