节点文献
基于极端随机树的入侵检测模型研究
Research on Intrusion Detection Model Based on Extreme Random Tree
【摘要】 传统机器学习算法训练网络入侵数据集时,容易出现特征维数多、过拟合与数据集不平衡等问题,导致入侵检测算法的准确率降低以及时间效率低下。为解决上述问题,文章提出基于极端随机树的入侵检测模型,使用线性判别式分析进行数据降维,然后利用过采样减少网络入侵数据集样本类别不平衡带来的影响,最后使用极端随机树进行模型训练。实验结果表明,经过LDA降维和过采样后,使用极端随机树分类模型能够提高多分类下不平衡数据集的整体识别性能并能满足网络入侵检测实际应用的时间效率要求。
【Abstract】 When traditional machine learning algorithms train network intrusion data sets, they are prone to problems such as too many feature dimensions, over fitting and imbalance of data sets, which lead to the reduction of accuracy and time efficiency of intrusion detection algorithms. In order to solve the above problems, this paper proposes an intrusion detection model based on Extreme Random Tree, uses linear discriminant analysis(LDA) to reduce the dimension of data, then uses oversampling to reduce the impact of sample category imbalance in network intrusion data set, and finally uses Extreme Random Tree for model training. The experimental results show that after LDA dimensionality reduction and oversampling, the use of Extreme Random Tree classification model can improve the overall recognition performance of unbalanced data sets under multi classification, and can meet the time efficiency requirements of practical application of network intrusion detection.
【Key words】 intrusion detection; principal component analysis; sampling technology; unbalanced data set;
- 【文献出处】 信息化研究 ,Informatization Research , 编辑部邮箱 ,2022年02期
- 【分类号】TP393.08
- 【下载频次】52