详细信息

Dual Generative Adversarial Networks Based Unknown Encryption Ransomware Attack Detection  ( SCI-EXPANDED收录 EI收录)  

文献类型:期刊文献

英文题名:Dual Generative Adversarial Networks Based Unknown Encryption Ransomware Attack Detection

作者:Zhang, Xueqin[1];Wang, Jiyuan[1];Zhu, Shinan[1]

机构:[1]East China Univ Sci & Technol, Coll Informat Sci & Engn, Shanghai 200237, Peoples R China

年份:2022

卷号:10

起止页码:900

外文期刊名:IEEE ACCESS

收录:;EI(收录号:20214711211068);WOS:【SCI-EXPANDED(收录号:WOS:000739977900001)】;

语种:英文

外文关键词:Ransomware; encrypted trafic; anomaly detection; GAN; transfer learning

摘要:Aiming at unknown or variant ransomware attack encrypted with SSL (Secure Sockets Layer)/ TLS (Transport Layer Security) protocol, a detection framework named TGAN-IDS (Transferred Generating Adversarial Network-Intrusion Detection System) based on dual generative adversarial networks is presented in this paper. In this framework, DCGAN (Deep Convolutional Generative Adversarial Network) is adopted to train a generator which has good performance to generate adversarial sample, and is transferred to the generator of TGAN. A pre-training model named PreD is built based on CNN (Convolutional Neural Network), which has good performance to do binary classification, and is transferred to the discriminator of TGAN. The generator and discriminator of TGAN play games in training process until the discriminator has a strong ability to detection unknown attack, and then it is output as an anomaly detector. In order to suppress the deterioration of normal sample detection ability during adversarial training of TGAN, a reconstruction loss function is introduced into the target function of TGAN. Experiments on a mixed dataset which is constructed by CICIDS2017 and other ransomware datasets show comparing with other deep learning network, such as AlexNet, ResNet and DenseNet etc., TGAN-IDS performs well in the indicators of detection accuracy, recall or F1-score etc. Also experiments on KDD99, SWaT and WADI datasets show that TGAN-IDS is suitable for other unencrypted unknown network attack detection.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心