摘要
针对网络入侵检测在数据不均衡下检测性能较差的问题,提出了一种对比主成分分析(c PCA)结合可改变网络结构的自组织映射(AMSOM)的入侵检测模型。通过把少数类设置为背景数据,c PCA在降维的同时提高模型对少数类攻击的识别能力。AMSOM在输出层构建一个更加灵活的动态神经元网络,保持两个空间的对应关系,解决了SOM在训练过程中产生畸形的问题,提高输出神经元的聚类结果识别率。使用NSL-KDD数据集,实验结果表明提出的模型对少数的网络攻击表现出良好的性能,具有更高的准确率、召回率和F1值。
To solve the problem of poor performance of network intrusion detection under unbalanced data,a new intrusion detection model based on c PCA and AMSOM is proposed.By setting a small number of classes as background data,c PCA can reduce the dimension and improve the classifier’s ability to recognize attacks on a small number of classes.AMSOM constructs a more flexible dynamic neuron network in the output layer and maintains the corresponding relationship between the two spaces,which solves the problem of misshapen in the training process of SOM and improves the recognition rate of the clustering results of output neurons.Using NSL-KDD dataset,the experimental results show that the proposed model has good performance against a few network attacks,with higher accuracy,recall rate and F1 value.
作者
吴德鹏
柳毅
WU Depeng;LIU Yi(School of Computer,Guangdong University of Technology,Guangzhou 510006,China)
出处
《计算机工程与应用》
CSCD
北大核心
2020年第12期81-86,共6页
Computer Engineering and Applications
基金
国家自然科学基金(No.61572144)。