详细信息

A Multiple-Layer Representation Learning Model for Network-Based Attack Detection  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:A Multiple-Layer Representation Learning Model for Network-Based Attack Detection

作者:Zhang, Xueqin[1];Chen, Jiahao[1];Zhou, Yue[1];Han, Liangxiu[2];Lin, Jiajun[1]

机构:[1]East China Univ Sci & Technol, Coll Informat Sci & Engn, Shanghai 200237, Peoples R China;[2]Manchester Metropolitan Univ, Sch Comp Math & Digital Technol, Manchester M15 6BH, Lancs, England

年份:2019

卷号:7

起止页码:91992

外文期刊名:IEEE ACCESS

收录:;EI(收录号:20193207285784);WOS:【SCI-EXPANDED(收录号:WOS:000477864400099)】;

语种:英文

外文关键词:Network intrusion detection; convolutional neural networks; deep random forests; representation learning

摘要:Accurate detection of network-based attacks is crucial to prevent security breaches of information systems. The recent application of deep learning approaches for network intrusion detection has shown promising. However, the challenges remain on how to deal with imbalance data and small samples as well as reducing false alarm rate (FAR). To address these issues, this work has proposed a multiple-layer representation learning model for accurate end-to-end network intrusion detection by combining deep convolutional neural networks (CNN) with gcForest. The contributions of this work lie in 1) a new data encoding scheme based on P-Zigzag to encode network traffic data into two-dimensional gray-scale images for representation learning without loss of original information; 2) The combination of gcForest and CNN allows accurate detection on imbalanced data and small scale data with fewer hyperparamters comparing to most existing deep learning models, which increase computational efficiency. The proposed approach is based on a multiple-layer approach consisting of a coarse layer and a fine layer, in which the coarse layer with the improved CNN model (GoogLeNetNP) focuses on identification of N abnormal classes and a normal class. While in the fine layer, an improved model based on gcForest (caXGBoost) further classifies the abnormal classes into N-1 subclasses. This ensures fine-grained detection of various attacks. The proposed framework has been compared with the existing deep learning models using three real datasets (a new dataset NBC, a combination of UNSW-NB15 and CICIDS2017 consisting of 101 classes). The experimental results show that our proposed method outperforms other single deep learning methods (i.e., AlexNet, VGG19, GoogleNet, InceptionV3, ResNet18) in terms of accuracy, detection rate, and FAR, which demonstrates its effectiveness in detecting fine-grained attacks and handling imbalanced datasets with high-precision and low FAR.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心