Fang Jun, Xie Cunxiang
Naval Aviation University, Yantai, 264001, China.
Sci Rep. 2025 May 16;15(1):17001. doi: 10.1038/s41598-025-01084-1.
Intrusion traffic detection technology is an important network protection technology to ensure network communication security and protect users' information privacy. To address problems relating to the low classification accuracy of current intrusion traffic detection algorithms and that most of the current research focus on closed set detection, this paper proposes a detection and classification model for open set traffic based on information maximization generative adversarial network and OpenMax algorithm. Firstly, the intrusion traffic classification model under the closed set condition is trained, and the sample activation vector is recalculated in the penultimate layer of the model by using the OpenMax algorithm. According to the activation vector of the known category, the estimated probability of the unknown category is then calculated to identify unknown traffic. Results show that the model's classification accuracy for CICIDS2017 open set traffic in the misuse and anomaly detection experiments is above 88.5 and 88.2%, respectively. The model can effectively detect various types of unknown traffic with high detection accuracy and robustness.
入侵流量检测技术是确保网络通信安全、保护用户信息隐私的一项重要网络保护技术。针对当前入侵流量检测算法分类准确率低以及当前大多数研究集中于闭集检测的问题,本文提出一种基于信息最大化生成对抗网络和OpenMax算法的开放集流量检测与分类模型。首先,训练闭集条件下的入侵流量分类模型,并使用OpenMax算法在模型的倒数第二层重新计算样本激活向量。根据已知类别的激活向量,计算未知类别的估计概率以识别未知流量。结果表明,该模型在误用检测和异常检测实验中对CICIDS2017开放集流量的分类准确率分别高于88.5%和88.2%。该模型能够以高检测准确率和鲁棒性有效检测各类未知流量。