详细信息
A Multiple-Layer Representation Learning Model for Network-Based Attack Detection ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:A Multiple-Layer Representation Learning Model for Network-Based Attack Detection
作者:Zhang, Xueqin[1];Chen, Jiahao[1];Zhou, Yue[1];Han, Liangxiu[2];Lin, Jiajun[1]
机构:[1]East China Univ Sci & Technol, Coll Informat Sci & Engn, Shanghai 200237, Peoples R China;[2]Manchester Metropolitan Univ, Sch Comp Math & Digital Technol, Manchester M15 6BH, Lancs, England
年份:2019
卷号:7
起止页码:91992
外文期刊名:IEEE ACCESS
收录:;EI(收录号:20193207285784);WOS:【SCI-EXPANDED(收录号:WOS:000477864400099)】;
语种:英文
外文关键词:Network intrusion detection; convolutional neural networks; deep random forests; representation learning
摘要:Accurate detection of network-based attacks is crucial to prevent security breaches of information systems. The recent application of deep learning approaches for network intrusion detection has shown promising. However, the challenges remain on how to deal with imbalance data and small samples as well as reducing false alarm rate (FAR). To address these issues, this work has proposed a multiple-layer representation learning model for accurate end-to-end network intrusion detection by combining deep convolutional neural networks (CNN) with gcForest. The contributions of this work lie in 1) a new data encoding scheme based on P-Zigzag to encode network traffic data into two-dimensional gray-scale images for representation learning without loss of original information; 2) The combination of gcForest and CNN allows accurate detection on imbalanced data and small scale data with fewer hyperparamters comparing to most existing deep learning models, which increase computational efficiency. The proposed approach is based on a multiple-layer approach consisting of a coarse layer and a fine layer, in which the coarse layer with the improved CNN model (GoogLeNetNP) focuses on identification of N abnormal classes and a normal class. While in the fine layer, an improved model based on gcForest (caXGBoost) further classifies the abnormal classes into N-1 subclasses. This ensures fine-grained detection of various attacks. The proposed framework has been compared with the existing deep learning models using three real datasets (a new dataset NBC, a combination of UNSW-NB15 and CICIDS2017 consisting of 101 classes). The experimental results show that our proposed method outperforms other single deep learning methods (i.e., AlexNet, VGG19, GoogleNet, InceptionV3, ResNet18) in terms of accuracy, detection rate, and FAR, which demonstrates its effectiveness in detecting fine-grained attacks and handling imbalanced datasets with high-precision and low FAR.
参考文献:
正在载入数据...
