计算机工程与应用 ›› 2020, Vol. 56 ›› Issue (22): 109-116.DOI: 10.3778/j.issn.1002-8331.2003-0353

• 网络、通信与安全 • 上一篇    下一篇

网络未知攻击检测的深度学习方法

狄冲,李桐   

  1. 1.上海交通大学 网络空间安全学院,上海 200240
    2.国网辽宁省电力有限公司 电力科学研究院,沈阳 110000
  • 出版日期:2020-11-15 发布日期:2020-11-13

Network Unknown Attack Detection with Deep Learning

DI Chong, LI Tong   

  1. 1.School of Cyber Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China
    2.Electric Power Research Institute of State Grid Liaoning Electric Power Co., Ltd., Shenyang 110000, China
  • Online:2020-11-15 Published:2020-11-13

摘要:

为了实现入侵检测系统对未知攻击类型的检测,提出基于深度学习的网络异常检测方法。利用置信度神经网络,对已知类型流量和未知攻击流量进行自适应判别。基于深度神经网络,制定置信度估计方法评估模型分类结果,训练模型面向已知类型流量时输出高置信度值,识别到未知攻击流量时输出低置信度值,从而实现对未知攻击网络流量的检测,并设计自适应损失平衡策略和基于学习自动机的动态正则化策略优化异常检测模型。在网络异常检测UNSW-NB15和CICIDS 2017数据集上进行仿真实验,评估模型效果。结果表明,该方法实现了未知攻击流量的有效检测,并提高了已知类型流量的分类效果,从而增强了入侵检测系统的综合性能。

关键词: 网络安全, 入侵检测, 深度学习

Abstract:

A deep learning-based method for network anomaly detection is proposed to discriminate unknown attacks for an intrusion detection system. A confidence-based neural network is adopted to adaptively distinguish the traffic?information of given behaviors and?that of unknown attacks.?The proposed model?is trained to?assign a higher?confidence value to a piece of?traffic?information?from a known behavior and?a lower?confidence value to that?from an?unknown attack. Moreover, an adaptive loss balance strategy and a learning automata-based dynamic regularization strategy are designed?to improve the performance of the model. The proposed model is evaluated in benchmark datasets UNSW-NB15 and CICIDS 2017. Compared with traditional models, the simulation results indicate that the proposed model can detect the unknown attack effectively while preserving an advantageous classification effect for traffic from known attacks.

Key words: cyber security, intrusion detection, deep learning