节点文献
一种面向未知攻击检测的深度神经网络预处理方法
Unknown-Attack-Detection-Oriented DNN Preprocessing Methodology
【摘要】 现有的基于深度神经网络(Deep Neural Network,DNN)的检测方法对于未知攻击检测性能不佳。原因之一是现有的预处理方法并未考虑网络环境的内在特征。为解决该问题,首先提出一种新型的预处理方法,将训练集的统计特征作为网络环境的内在特征,用于测试集和检测集的预处理,以提高检测算法的性能;然后利用DNN模型进行入侵检测。对KDDCup’99、NSL-KDD和UNSW-NB15数据集的实验结果表明,与传统预处理方法相比,所提预处理方法在准确率方面表现更好,召回率也有一定程度提升。
【Abstract】 The existing detection methods based on deep neural network( DNN) have poor performance in detecting unknown attacks. One of the reasons is that the existing preprocessing methods do not consider the inherent characteristics of the network environment. In order to solve this problem,a novel method of preprocessing is proposed to improve the performance of the detection algorithms.First,statistical characteristics of the training set are treated as the inherent characteristics of the network environment,and they are utilized for the preprocessing of the test set and the detection set to improve the performance of the detection algorithm. Then a DNN model is utilized for intrusion detection. Experimental results on the KDDCup ’99,NSL-KDD and UNSW-NB15 datasets show that,compared with the traditional preprocessing method,the proposed preprocessing method performs better in terms of accuracy,and the recall is also increased to a certain extent.
【Key words】 intrusion detection; deep neural network; preprocess; normalization; feature generation;
- 【文献出处】 信息工程大学学报 ,Journal of Information Engineering University , 编辑部邮箱 ,2021年02期
- 【分类号】TP183;TP393.08
- 【被引频次】1
- 【下载频次】174