用强化学习实现云端智能攻防,实时检测并自动拦截攻击
Machine Learning-Based Cyber Defense for Cloud Infrastructure: An Adaptive Deep Q-Network Architecture for Intelligent Intrusion Detection and Automated Threat Mitigation
- 基于深度Q网络构建自适应防御策略
- 准确率达99.72%,检测延迟仅15毫秒
- 适合需要实时安全响应的云平台部署
随着云环境中网络攻击日益复杂,亟需具备实时检测与自主响应能力的自适应安全方案。本文提出一种基于强化学习的动态网络安全防御框架,采用深度Q网络(DQN)训练有效的防御策略以应对不断演化的攻击。模型在CICIDS2017数据集上构建,并在UNSW-NB15数据集上进行外部验证,涵盖数据预处理、特征工程与自适应策略学习。与决策树、支持向量机、随机森林、XGBoost及多层感知机等模型相比,所提DQN在测试中达到99.72%准确率、99.68%精确率、99.65%召回率、99.66%F1分数、0.999ROC-AUC值,误报率0.31%,漏报率0.35%,检测延迟为15毫秒。该框架实现99.54%的攻击缓解率,展现出强大的自适应与实时防御能力。结果表明,强化学习在现代云环境中的自主网络安全中具有强大且可扩展的潜力。
原文摘要 · Abstract (English)
With the increasing complexity of cyber assaults in cloud environments, adaptable security solutions are needed that can support real-time detection and autonomous response. In this paper, we propose a reinforcement learning-based dynamic cyber defense framework. We deploy a Deep Q-Network (DQN) to train effective defensive strategies to counteract the evolving cyberattacks. We leverage the CICIDS2017 dataset for model creation and the UNSW-NB15 dataset for external validation, involving preprocessing of data, feature engineering, and adaptive policy learning. We compare the proposed DQN with decision tree, support vector machine, random forest, XGBoost, and multilayer perceptron models. The proposed DQN achieves an accuracy of 99.72%, a precision of 99.68%, a recall of 99.65%, an F1-score of 99.66%, and an ROC-AUC of 0.999, while the false positive rate is 0.31%, the false negative rate is 0.35%, and the detection latency is 15 ms. The framework achieved 99.54% attack mitigation rate, demonstrating strong adaptive and real-time defensive capabilities. These results demonstrate the potential of reinforcement learning as a powerful and scalable approach for autonomous cybersecurity in modern cloud environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。