期刊文献+

基于深度循环神经网络和改进SMOTE算法的组合式入侵检测模型 被引量:10

Combinatorial intrusion detection model based on deep recurrent neural network and improved SMOTE algorithm
下载PDF
导出
摘要 已有入侵检测模型普遍只针对网络入侵行为的静态特征进行分析检测,造成检测率低及误报率高等缺陷,且无法有效应用低频攻击。为此提出一种新的基于深度循环神经网络(DRNN)和区域自适应合成过采样算法(RA-SMOTE)的组合式入侵检测模型(DRRS)。首先,RA-SMOTE对数据集中低频攻击样本进行自适应区域划分,实现差别样本增量,从数据层面提升低频攻击样本数量;其次,利用DRNN特有的层间反馈单元,完成多阶段分类特征的时序积累学习,同时多隐层网络结构实现对原始数据分布的最优非线性拟合;最后,使用训练好的DRRS模型完成入侵检测。实验结果表明,相比已有入侵检测模型,DRRS在改善整体检测效果的同时显著提高了低频攻击检测率,且对未知新型攻击具有一定检出率,适用于实际网络环境。 Existing intrusion detection models generally only analyze the static characteristics of network intrusion actions, resulting in low detection rate and high false positive rate, and cannot effectively detect low-frequency attacks. Therefore, a novel combinatorial intrusion detection model(DRRS) based on deep recurrent neural network(DRNN) and region adaptive synthetic minority oversampling technique algorithm(RA-SMOTE) was proposed. Firstly, RA-SMOTE divided the low frequency attack samples into different regions adaptively and improved the number of low-frequency attack samples with different methods from the data level. Secondly, the multi-stage classification features were learned by using the level feedback units in DRNN, at the same time, the multi-layer network structure achieved the optimal non-linear fitting of the original data distribution. Finally, the intrusion detection was completed by trained DRRS. The empirical results show that compared with the traditional intrusion detection models, DRRS significantly improves the detection rate of low-frequency attacks and overall detection efficiency. Besides, DRRS has a certain detection rate for unknown new attacks. So DRRS model is effective and suitable for the actual network environment.
作者 燕昺昊 韩国栋 YAN Binghao;HAN Guodong(National Digital Switching System Engineering and Technological Research Center,Zhengzhou 450002,China)
出处 《网络与信息安全学报》 2018年第7期48-59,共12页 Chinese Journal of Network and Information Security
基金 国家科技重大专项基金资助项目(No.2016ZX01012101) 国家自然科学基金资助项目(No.61572520) 国家自然科学基金创新群体资助项目(No.61521003)~~
关键词 网络安全 深度学习 入侵检测 循环神经网络 过采样算法 network security deep learning intrusion detection DRNN oversampling algorithm
  • 相关文献

参考文献2

二级参考文献5

共引文献80

同被引文献66

引证文献10

二级引证文献103

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部