• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

文档 ID:一种基于深度学习的网络流量特征提取和异常检测方法。

DOC-IDS: A Deep Learning-Based Method for Feature Extraction and Anomaly Detection in Network Traffic.

机构信息

Graduate School of Engineering, Kobe University, Kobe 657-8501, Japan.

出版信息

Sensors (Basel). 2022 Jun 10;22(12):4405. doi: 10.3390/s22124405.

DOI:10.3390/s22124405
PMID:35746191
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC9227447/
Abstract

With the growing diversity of cyberattacks in recent years, anomaly-based intrusion detection systems that can detect unknown attacks have attracted significant attention. Furthermore, a wide range of studies on anomaly detection using machine learning and deep learning methods have been conducted. However, many machine learning and deep learning-based methods require significant effort to design the detection feature values, extract the feature values from network packets, and acquire the labeled data used for model training. To solve the aforementioned problems, this paper proposes a new model called DOC-IDS, which is an intrusion detection system based on Perera's deep one-class classification. The DOC-IDS, which comprises a pair of one-dimensional convolutional neural networks and an autoencoder, uses three different loss functions for training. Although, in general, only regular traffic from the computer network subject to detection is used for anomaly detection training, the DOC-IDS also uses multi-class labeled traffic from open datasets for feature extraction. Therefore, by streamlining the classification task on multi-class labeled traffic, we can obtain a feature representation with highly enhanced data discrimination abilities. Simultaneously, we perform variance minimization in the feature space, even on regular traffic, to further improve the model's ability to discriminate between normal and abnormal traffic. The DOC-IDS is a single deep learning model that can automatically perform feature extraction and anomaly detection. This paper also reports experiments for evaluating the anomaly detection performance of the DOC-IDS. The results suggest that the DOC-IDS offers higher anomaly detection performance while reducing the load resulting from the design and extraction of feature values.

摘要

近年来,随着网络攻击的日益多样化,能够检测未知攻击的基于异常的入侵检测系统引起了广泛关注。此外,已经进行了广泛的使用机器学习和深度学习方法进行异常检测的研究。然而,许多基于机器学习和深度学习的方法需要大量的工作来设计检测特征值,从网络数据包中提取特征值,并获取用于模型训练的标记数据。为了解决上述问题,本文提出了一种新的模型,称为 DOC-IDS,这是一种基于 Perera 的深度单类分类的入侵检测系统。DOC-IDS 由一对一维卷积神经网络和自动编码器组成,使用三种不同的损失函数进行训练。虽然通常仅使用要检测的计算机网络的常规流量进行异常检测训练,但 DOC-IDS 还使用来自开放数据集的多类标记流量进行特征提取。因此,通过简化多类标记流量的分类任务,我们可以获得具有高度增强的数据区分能力的特征表示。同时,我们在特征空间中进行方差最小化,即使在常规流量上,也可以进一步提高模型区分正常和异常流量的能力。DOC-IDS 是一个单一的深度学习模型,可以自动执行特征提取和异常检测。本文还报告了评估 DOC-IDS 的异常检测性能的实验结果。结果表明,DOC-IDS 提供了更高的异常检测性能,同时减少了设计和提取特征值的负载。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/c8e073b178ec/sensors-22-04405-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/b5ce01330de4/sensors-22-04405-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/062331d78568/sensors-22-04405-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/135660813650/sensors-22-04405-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/1a66545c9cef/sensors-22-04405-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/f7415c46b24d/sensors-22-04405-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/32db092c6789/sensors-22-04405-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/c8e073b178ec/sensors-22-04405-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/b5ce01330de4/sensors-22-04405-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/062331d78568/sensors-22-04405-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/135660813650/sensors-22-04405-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/1a66545c9cef/sensors-22-04405-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/f7415c46b24d/sensors-22-04405-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/32db092c6789/sensors-22-04405-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/917d/9227447/c8e073b178ec/sensors-22-04405-g007.jpg

相似文献

1
DOC-IDS: A Deep Learning-Based Method for Feature Extraction and Anomaly Detection in Network Traffic.文档 ID:一种基于深度学习的网络流量特征提取和异常检测方法。
Sensors (Basel). 2022 Jun 10;22(12):4405. doi: 10.3390/s22124405.
2
A hybrid feature weighted attention based deep learning approach for an intrusion detection system using the random forest algorithm.基于混合特征加权注意力的深度学习方法与随机森林算法在入侵检测系统中的应用。
PLoS One. 2024 May 23;19(5):e0302294. doi: 10.1371/journal.pone.0302294. eCollection 2024.
3
Deep Encrypted Traffic Detection: An Anomaly Detection Framework for Encryption Traffic Based on Parallel Automatic Feature Extraction.深度加密流量检测:一种基于并行自动特征提取的加密流量异常检测框架。
Comput Intell Neurosci. 2023 Mar 10;2023:3316642. doi: 10.1155/2023/3316642. eCollection 2023.
4
A multi-information fusion anomaly detection model based on convolutional neural networks and AutoEncoder.一种基于卷积神经网络和自动编码器的多信息融合异常检测模型。
Sci Rep. 2024 Jul 12;14(1):16147. doi: 10.1038/s41598-024-66760-0.
5
A Novel Anomaly-Based Intrusion Detection Model Using PSOGWO-Optimized BP Neural Network and GA-Based Feature Selection.基于 PSOGWO-优化 BP 神经网络和基于 GA 的特征选择的新型异常入侵检测模型。
Sensors (Basel). 2022 Nov 30;22(23):9318. doi: 10.3390/s22239318.
6
Research on Anomaly Network Detection Based on Self-Attention Mechanism.基于自注意力机制的异常网络检测研究。
Sensors (Basel). 2023 May 25;23(11):5059. doi: 10.3390/s23115059.
7
Deep Complex Gated Recurrent Networks-Based IoT Network Intrusion Detection Systems.基于深度复杂门控循环网络的物联网网络入侵检测系统
Sensors (Basel). 2024 Sep 13;24(18):5933. doi: 10.3390/s24185933.
8
Evaluation of Machine Learning Techniques for Traffic Flow-Based Intrusion Detection.基于流量的入侵检测的机器学习技术评估。
Sensors (Basel). 2022 Nov 30;22(23):9326. doi: 10.3390/s22239326.
9
Transfer-Learning-Based Intrusion Detection Framework in IoT Networks.基于迁移学习的物联网网络入侵检测框架。
Sensors (Basel). 2022 Jul 27;22(15):5621. doi: 10.3390/s22155621.
10
Using Embedded Feature Selection and CNN for Classification on CCD-INID-V1-A New IoT Dataset.利用嵌入式特征选择和卷积神经网络对 CCD-INID-V1-新物联网数据集进行分类。
Sensors (Basel). 2021 Jul 15;21(14):4834. doi: 10.3390/s21144834.

引用本文的文献

1
A multi-information fusion anomaly detection model based on convolutional neural networks and AutoEncoder.一种基于卷积神经网络和自动编码器的多信息融合异常检测模型。
Sci Rep. 2024 Jul 12;14(1):16147. doi: 10.1038/s41598-024-66760-0.

本文引用的文献

1
Learning Deep Features for One-Class Classification.学习用于单类分类的深度特征。
IEEE Trans Image Process. 2019 Nov;28(11):5450-5463. doi: 10.1109/TIP.2019.2917862. Epub 2019 May 24.
2
Reducing the dimensionality of data with neural networks.使用神经网络降低数据维度。
Science. 2006 Jul 28;313(5786):504-7. doi: 10.1126/science.1127647.
3
Estimating the support of a high-dimensional distribution.估计高维分布的支撑集。
Neural Comput. 2001 Jul;13(7):1443-71. doi: 10.1162/089976601750264965.