A Novel Self-supervised Few-shot Network Intrusion Detection Method

被引:2
作者
Zhang, Jing [1 ,2 ]
Shi, Zhixin [1 ]
Wu, Hao [1 ,2 ]
Xing, Mengyan [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
来源
WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2022), PT I | 2022年 / 13471卷
关键词
Self-supervised learning; Network intrusion detection; Generating labels; Few-shot learning; ATTACK DETECTION; DEEP;
D O I
10.1007/978-3-031-19208-1_42
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Supervised models for network intrusion detection usually rely on many training samples, but the annotation costs are very high. Unlabeled network traffic data is relatively easy to obtain. However, there are only a few methods to utilize these unlabeled data adequately. We propose a novel self-supervised few-shot network intrusion detection method to address the above problems. The method consists of two models: a) network traffic representation model and b) network intrusion detection model. First, the network traffic representation model uses unlabeled network traffic data through self-supervised learning to obtain network traffic representations, which will benefit the training of network intrusion detection model. Then, the shared layers of the network traffic representation model are transferred to the network intrusion detection model and frozen. Finally, a few training samples are used to fine-tune the network intrusion detection model, and we can obtain a model with good generalization. However, self-supervised learning of the network traffic representation model requires a method for generating labels from network traffic. Therefore, we propose a novel method to generate labels based on discrete features of network traffic. Experiments show that our proposed method has better performance than other network intrusion detection models with few-shot. On NSL-KDD, only 200 labeled samples are needed to achieve 95.2% accuracy.
引用
收藏
页码:513 / 525
页数:13
相关论文
共 21 条
[1]   Autoencoder-based deep metric learning for network intrusion detection [J].
Andresini, Giuseppina ;
Appice, Annalisa ;
Malerba, Donato .
INFORMATION SCIENCES, 2021, 569 (569) :706-727
[2]   An efficient XGBoost-DNN-based classification model for network intrusion detection system [J].
Devan, Preethi ;
Khare, Neelu .
NEURAL COMPUTING & APPLICATIONS, 2020, 32 (16) :12499-12514
[3]   Incorporating evolutionary computation for securing wireless network against cyberthreats [J].
Dwivedi, Shubhra ;
Vardhan, Manu ;
Tripathi, Sarsij .
JOURNAL OF SUPERCOMPUTING, 2020, 76 (11) :8691-8728
[4]   An effective intrusion detection approach using SVM with naive Bayes feature embedding [J].
Gu, Jie ;
Lu, Shan .
COMPUTERS & SECURITY, 2021, 103
[5]   A survey: Deep learning for hyperspectral image classification with few labeled samples [J].
Jia, Sen ;
Jiang, Shuguo ;
Lin, Zhijie ;
Li, Nanying ;
Xu, Meng ;
Yu, Shiqi .
NEUROCOMPUTING, 2021, 448 :179-204
[6]   Self-Supervised Visual Feature Learning With Deep Neural Networks: A Survey [J].
Jing, Longlong ;
Tian, Yingli .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2021, 43 (11) :4037-4058
[7]  
Khan Riaz Ullah, 2019, 2019 Cybersecurity and Cyberforensics Conference (CCC). Proceedings, P74, DOI 10.1109/CCC.2019.000-6
[8]  
Liu X, 2021, T KNOWL DATA ENG
[9]  
Sarkar P., 2020, T AFFECT COMPUT
[10]   DL-IDS: Extracting Features Using CNN-LSTM Hybrid Network for Intrusion Detection System [J].
Sun, Pengfei ;
Liu, Pengju ;
Li, Qi ;
Liu, Chenxi ;
Lu, Xiangling ;
Hao, Ruochen ;
Chen, Jinpeng .
SECURITY AND COMMUNICATION NETWORKS, 2020, 2020