A Novel Multimodal-Sequential Approach Based on Multi-View Features for Network Intrusion Detection

被引:50
作者
He, Haitao [1 ,3 ]
Sun, Xiaobing [1 ,3 ]
He, Hongdou [1 ,3 ]
Zhao, Guyu [1 ,3 ]
He, Ligang [2 ]
Ren, Jiadong [1 ,3 ]
机构
[1] Yanshan Univ, Coll Informat Sci & Engn, Qinhuangdao 066004, Hebei, Peoples R China
[2] Univ Warwick, Dept Comp Sci, Coventry CV4 7AL, W Midlands, England
[3] Yanshan Univ, Key Comp Virtual Technol & Syst Integrat Lab, Qinhuangdao 066004, Hebei, Peoples R China
基金
中国国家自然科学基金;
关键词
Network anomaly detection; hierarchical progressive network; multimodal deep learning; DEEP LEARNING APPROACH; ANOMALY DETECTION;
D O I
10.1109/ACCESS.2019.2959131
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network intrusion detection systems (NIDS) are essential tools in ensuring network information security, and neural networks have become an increasingly popular solution for NIDS. However, with the gradual complexity of the network environment, the existing solutions using the conventional neural network cannot make full use of the rich information in the network traffic data due to its single structure. More importantly, this will lead to the existing NIDS have incomplete knowledge of the intrusion detection domain, and making it unable to achieve a high detection rate and good stability in the new environment. In this paper, we take a step forward and extract the different level features from the network connection, rather than a long feature vector used in the traditional approach, which can process feature information separately more efficiently. And further, we propose multimodal-sequential intrusion detection approach with special structure of hierarchical progressive network, which is supported by multimodal deep auto encoder (MDAE) and LSTM technologies. By design the special structure of hierarchical progressive network, our approach can efficiently integrate the different level features information within a network connection and automatically learn temporal information between adjacent network connections at the same time. Based on the three benchmark datasets from 1999 to 2017, including NSL-KDD, UNSW-NB15, and CICIDS 2017, we investigated the performance of our proposed approach on the task of detecting attacks within modern network. The experimental results show that the average accuracy of this method is 94% in binary classification and 88% in multi-class classification, which is at least 2% and 4% super than other methods respectively, and demonstrated that our model has excellent stability. Moreover, we further explore the multimodality and complementarity in traffic data, the experimental results show that the performance of detection model can be further improved in the range 2% to 5% when using our MDAE model to process the features of traffic data.
引用
收藏
页码:183207 / 183221
页数:15
相关论文
共 30 条
[1]   A New Intrusion Detection System Based on Fast Learning Network and Particle Swarm Optimization [J].
Ali, Mohammed Hasan ;
Al Mohammed, Bahaa Abbas Dawood ;
Ismail, Alyani ;
Zolkipli, Mohamad Fadli .
IEEE ACCESS, 2018, 6 :20255-20261
[2]  
[Anonymous], IEEE T SUSTAIN COMPU
[3]  
[Anonymous], 2010, IEEE INT C COMM ICC
[4]  
Aung YY, 2017, 2017 18TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNDP 2017), P127, DOI 10.1109/SNPD.2017.8022711
[5]  
Brownlee N., 1999, Traffic flow measurement: architecture (rfc 2722)
[6]   DAD-MCNN: DDoS Attack Detection via Multi-channel CNN [J].
Chen, Jinyin ;
Yang, Yi-tao ;
Hu, Ke-ke ;
Zheng, Hai-bin ;
Wang, Zhen .
ICMLC 2019: 2019 11TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND COMPUTING, 2019, :484-488
[7]  
Gogoi P, 2012, COMM COM INF SC, V306, P322
[8]   Multimodal semi-supervised learning for image classification [J].
Guillaumin, Matthieu ;
Verbeek, Jakob ;
Schmid, Cordelia .
2010 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2010, :902-909
[9]  
Hochreiter S, 1997, Neural Computation, V9, P1735
[10]  
Javaid A., 2016, P 9 EAI INT C BIOINS, V3, P2, DOI [DOI 10.4108/EAI.3-12-2015.2262516, 10.4108/eai.3-12-2015.2262516]