节点文献
基于耦合学习的网络流量异常检测方法研究
Research on Network Traffic Anomaly Detection Method Based on Coupled Learning
【作者】 孙俊;
【作者基本信息】 江南大学 , 软件工程(专业学位), 2023, 硕士
【摘要】 随着5G通信、大数据和深度学习等技术的广泛应用和快速发展,其推动社会飞速发展的同时也使得网络流量数据呈指数级增长,并带来了一系列网络安全问题。目前,互联网技术朝着万物互联的方向急速发展,使得传统的网络安全方法在新技术框架下的网络空间内几乎失去效果,难以适应未来人们对网络信息安全的要求。因此网络流量异常检测对保证网络的安全运行有重要意义。本文围绕网络流量异常检测任务,以可解释性为切入点,提出了基于耦合学习的网络流量异常检测方法和基于公司真实网络流量的特征选取方法,并进一步对网络流量异常检测具体应用进行研究。论文主要内容如下:1.针对目前网络流量异常检测模型缺乏可解释性的问题,论文提出了耦合演化采样和深度解码的可解释网络流量异常检测模型(CESDDM)。首先,引入演化采样学习抽取代表特征样本,依此实现了强可解释性的样本编码过程;其次,构建了可解释的演化采样样本编码过程和不可解释的深度神经网络解码过程的耦合学习模型;最后,使用样本编码结果和重构误差进行异常检测。在公共数据集上的实验结果表明,该方法可显著提升模型可解释性和模型规模效率,并取得与现有最优方法同等水平的检测性能。此外,上述新方法也可为可解释机器学习方法研究提供一种极具特色的技术参考。2.为了验证本文提出的CESDDM在公司真实网络流量中的有效性和解决原始网络流量无法直接应用于CESDDM的问题,论文设计了公司真实网络流量特征选取及检测分析方法。首先,基于公司真实原始网络流量数据,从网络流量的基本特征、时间特征和连接特征这三个维度出发,提取带有统计信息的网络流量特征;其次,基于真实网络环境和模拟攻击构建网络流量异常检测数据集;最后,利用构建的数据集验证CESDDM的有效性。3.基于上述工作,论文进一步设计并实现了网络流量异常检测原型系统。为帮助用户处理原始网络流量数据、进行网络流量异常检测,论文集成网络流量异常检测任务,构建完整的网络流量异常检测流程,提供包括网络流量预处理、网络流量黑白名单、网络流量异常检测和数据分析等多种功能。网络流量预处理功能对原始的网络流量进行处理,并生成一组适用于机器学习的网络流量统计特征;网络流量黑白名单能够录入流量黑白名单,通过将黑白名单IP分别识别为异常和正常以完成网络流量预检;网络流量异常检测功能调用CESDDM模型完成流量异常检测;数据分析模块能够绘制数据可视化图表,包括柱状图和饼图等。此外,针对网络流量异常检测原型系统的主要功能模块进行功能测试和性能测试,验证网络流量异常检测集成系统能够达到预期效果。综上,基于耦合学习策略的网络流量异常检测能够有效提升异常检测能力,并增强模型的可解释性;而公司真实网络流量特征选取方法可以有效表征原始网络流量并验证了CESDDM的有效性,而进一步的应用研究发现,论文网络流量异常检测原型系统能够有效集成特征预处理和异常检测功能,具有明确的实用价值。
【Abstract】 With the widespread application and rapid development of technologies such as 5G communication,big data,and deep learning,society is experiencing rapid development while also facing exponential growth in network traffic data and a series of cybersecurity issues.Currently,internet technology is rapidly moving towards the direction of the Internet of Things,rendering traditional network security methods almost ineffective in the new technological framework and unable to meet the future demands for network information security.Therefore,anomaly detection in network traffic is of great significance for ensuring the secure operation of networks.This paper focuses on the task of network traffic anomaly detection,taking explainability as a starting point.It proposes a network traffic anomaly detection method based on coupled learning and a feature selection method based on real network traffic from a company.Furthermore,the specific application of network traffic anomaly detection is further studied.The main contents of the paper are as follows:1.In response to the lack of explainability in current network traffic anomaly detection models,the paper proposes an explainable network traffic anomaly detection model based on coupling evolutionary sampling and deep decoding(CESDDM).Firstly,evolutionary sampling learning is introduced to extract representative feature samples,achieving a highly explainable sample encoding process.Secondly,a coupled learning model is constructed,combining the interpretable evolutionary sampling sample encoding process with the unexplainable deep neural network decoding process.Lastly,the sample encoding results and reconstruction errors are utilized for anomaly detection.Experimental results on public datasets demonstrate that this method significantly improves model interpretability and model scalability while achieving detection performance comparable to existing state-of-the-art methods.Furthermore,this novel approach can provide a distinctive technical reference for the study of explainable machine learning methods.2.In order to verify the effectiveness of the proposed CESDDM in real network traffic from a company and address the issue of the inability to directly apply raw network traffic to CESDDM,the paper designs a method for feature selection and detection analysis of real network traffic from a company.Firstly,based on the company’s real raw network traffic data,network traffic features with statistical information are extracted from three dimensions: basic features,time features,and connection features.Secondly,a network traffic anomaly detection dataset is constructed based on the real network environment and simulated attacks.Finally,the effectiveness of CESDDM is validated using the constructed dataset.3.Based on the aforementioned work,the paper further designs and implements a prototype system for network traffic anomaly detection.To assist users in processing raw network traffic data and conducting network traffic anomaly detection,the paper integrates the network traffic anomaly detection task,constructs a complete network traffic anomaly detection workflow,and provides various functionalities,including network traffic preprocessing,network traffic blacklisting/whitelisting,network traffic anomaly detection,and data analysis.The network traffic preprocessing functionality processes the raw network traffic and generates a set of statistical features suitable for machine learning.The network traffic blacklisting/whitelisting allows users to input traffic blacklists and whitelists,enabling the identification of blacklisted and whitelisted IP addresses as anomalies and normal traffic,respectively,for pre-screening network traffic.The network traffic anomaly detection functionality utilizes the CESDDM model to perform traffic anomaly detection.The data analysis module can generate visualizations such as bar charts and pie charts.Additionally,functional testing and performance testing are conducted on the main functional modules of the network traffic anomaly detection prototype system to validate its ability to achieve the desired results.In conclusion,the network traffic anomaly detection based on the coupled learning strategy can effectively enhance anomaly detection capabilities and improve model explainability.The method of selecting features from real network traffic of a company can accurately represent the original network traffic and validate the effectiveness of CESDDM.Furthermore,through further application research,the network traffic anomaly detection prototype system described in the paper proves to be effective in integrating feature preprocessing and anomaly detection functionalities,demonstrating clear practical value.
【Key words】 Network traffic anomaly detection; evolutionary sampling; coupled learning strategy; deep learning; system development;
- 【网络出版投稿人】 江南大学 【网络出版年期】2024年 05期
- 【分类号】TP393.08