Key Laboratory of Information and Computing Science Guizhou Province, Guizhou Normal University, Guiyang 550001, Guizhou, China
Show less
文章历史+
Received
Published
2019-09-01
2020-04-24
Issue Date
2026-07-23
PDF (2887K)
摘要
针对传统入侵检测方法在高维海量数据且类别分布不均衡的环境下检测性能较差的问题,提出一种流量异常检测方法SSAE-IWELM-AdaBoost,该方法基于堆叠稀疏自编码网络(stacked spare auto encoder,SSAE)并融合改进加权极限学习机(weighted extreme learning machine,WELM)。该方法首先使用堆叠稀疏自编码网络直接从原始流量数据中自动学习并提取特征,获取原始数据的低维抽象表示,然后以WELM作为集成算法(AdaBoost)的基础分类器,利用修改的训练样本权值分配规则和基分类器权值更新公式迭代训练基分类器,通过加权投票表决的方法得到最优强分类器完成网络攻击流量的识别。在UNSW-NB15数据集上进行仿真实验,实验结果表明,SSAE-IWELM-AdaBoost算法可以提高整体的检测精度以及小样本攻击的检测率,缩短分类器的训练时间,能较好地满足大规模网络环境下原始流量数据实时检测,对不均衡流量数据识别也具有较好的表现。
Abstract
To solve the problem of high-dimensional massive data with unbalance distribution that the traditional intrusion detection method has poor performance in detection,we propose a method of traffic anomaly detection SSAE-IWELM-AdaBoost, which is based on the stacked spar auto encoder (SSAE) and integrates the weighted extreme learning machine (WELM). Firstly, the algorithm employs stacked spare auto encoder network to automatically learn and extract features from the original traffic data, obtaining the low-dimensional abstract representation of the original data. Then, WELM is used as the basic classifier of the integrated algorithm (AdaBoost), utilizing the revised training sample weight assignment rules and the base classifier weight update formula to iterative training base classifier, thus the optimal strong classifier is obtained by weighted voting method to identify the network attack traffic. Finally, the simulation experiment is carried out on the UNSW-NB15 dataset. The experimental results show that SSAE-IWELM-AdaBoost algorithm can improve the overall detection accuracy and the detection rate of small sample attacks, shorten the training time of classifier, and can be better for the real-time detection of original traffic data in large-scale network environment. It has a good performance for the identification of unbalanced traffic data.
MOUSTAFAN, SLAYJ. The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 dataset and the comparison with the KDD99 dataset[J]. Information Systems Security, 2016,25(1):18-31. DOI:10.1080/1929355.2015.1125974 .
[2]
KHAMMASSIC, KRICHENS. A GA-LR wrapper approach for feature selection in network intrusion detection[J]. Computers & Security,2017,70:255-277. DOI:10.1016/j.cose.2017.06.005 .
ZHANGY Q, DONGY, LIUC Y, et al. Situation, trends and prospects of deep learning applied to cyberspace security[J].Journal of Computer Research and Development,2018,55(6):1117-1142. DOI:10.7544/issn1000-1239.201 8.20170649(Ch).
[5]
YADAVS, SUBRMANIANS. Detection of Application Layer DDos Attack by Feature Learning Using Stacked AutoEncoder[DB/OL].[2019-03-04].
[6]
YINC L, ZHUY F, FEIJ L, et al. A deep learning approach for intrusion detection using recurrent neural networks[J]. IEEE Access,2017,5:21954-21961. DOI:10.1109/ACCESS.2017.2762418 .
[7]
YUANX Y, LIC H, LIX L. Deep Defense: Identifying DDos Attack via Deep Learning[DB/OL].[2019-03-04].
[8]
PEKTASA, ACARMANT. Botnet detection based on network flow summary and deep learning [J]. International Journal of Network Management,2018,28(6):2039-2054.DOI:10.1002/nem.2039 .
LIANGJ, CHENJ H, ZHANGX Q, et al. One-hot encoding and convolutional neural network based anomaly detcetion [J]. Journal of Tsinghua University(Science and Technology),2019,59(7):523-529. DOI:10.16511/j.cnki.qhdxxb.2018.25.061(Ch).
LIUX Q, SHANC, RENJ D, et al. An intrusion detection method based on multi-dimensonal optimization of traffic anomaly analysis[J].Journal of Cyber Security,2019,4(1):14-26. DOI:10.19363/J.cnki.cn10-1380/ tn.2019.01.02(Ch).
GALARM, FERNANDEZA, BARRENECHEAE, et al. A review on ensembles for the class imbalance problem bagging, boosting and hybrid based approaches[J]. IEEE Transactions on Systems and Cybernetics—Part C:Applications and Reviews, 2012,42(4):463-484. DOI:10.1109/TSMCC.2011.2161285 .
[16]
LIK, KONGX F, LUZ, et al. Boosting weighted ELM for imbalanced learning[J].Neurocomputing, 2014,128 (3):15-21. DOI:10.1016/j.neucom.2013.05.051 .
[17]
MOUSTAFAN, SLAYJ. UNSW-NB15:A Comprehensive Data Set for Network Intrusion Detection Systems(UNSW-NB15 network dataset)[DB/OL].[2019-03-04].