基于流量异常分析多维优化的入侵检测方法

Xinqian Liu, Chun Shan*, Jiadong Ren, Qian Wang, Jiawei Guo

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

6 引用 (Scopus)

摘要

In the process of detecting and preventing various network anomaly behaviors, intrusion detection system is facing the problem of low accuracy and high false alarm rate due to the massive and high-dimensional traffic data. An intrusion detection method based on multi-dimensional optimization of traffic anomaly analysis is proposed, in which both horizontal and vertical dimensions of intrusion detection dataset are optimized. In horizontal dimensions optimization, those categories with a large number are sampled and the optimal sampling proportion parameters of each category are obtained by genetic algorithm. Data equalization is accomplished. In vertical dimensions optimization, combining with the correlation analysis of features with label, recursive features addition algorithm is adopted to select features, and the average recall is proposed to evaluate the effect of features selection. The low-dimensional and high-efficient training data set is achieved. Based on optimized intrusion detection dataset, the random forest classifier is obtained by training dataset, and the real data set UNSW_NB15 is used to evaluate and validate the proposed method. Compared with other algorithms, the proposed algorithm has high accuracy and low false alarm rate, and effective recall rate on attack category is obtained.

投稿的翻译标题An intrusion detection method based on multi-dimensional optimization of traffic anomaly analysis
源语言繁体中文
页(从-至)14-26
页数13
期刊Journal of Cyber Security
4
1
DOI
出版状态已出版 - 2019

关键词

  • data sampling
  • genetic algorithm parameter optimization
  • intrusion detection framework
  • multi-dimensional optimization
  • random forest
  • recursive features addition

指纹

探究 '基于流量异常分析多维优化的入侵检测方法' 的科研主题。它们共同构成独一无二的指纹。

引用此