Improving the Classification Effectiveness of Intrusion Detection by Using Improved Conditional Variational AutoEncoder and Deep Neural Network

被引:169
作者
Yang, Yanqing [1 ,2 ]
Zheng, Kangfeng [1 ]
Wu, Chunhua [1 ]
Yang, Yixian [1 ,3 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing 100876, Peoples R China
[2] Xinjiang Univ, Coll Informat Sci & Engn, Urumqi 830046, Peoples R China
[3] Guizhou Univ, Guizhou Prov Key Lab Publ Big Data, Guiyang 550025, Guizhou, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
intrusion detection; variational inference; improved conditional variational autoencoder; generator network; deep neural network; RESTRICTED BOLTZMANN MACHINES; SUPPORT VECTOR MACHINE; DETECTION SYSTEM; LEARNING APPROACH; MODEL;
D O I
10.3390/s19112528
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Intrusion detection systems play an important role in preventing security threats and protecting networks from attacks. However, with the emergence of unknown attacks and imbalanced samples, traditional machine learning methods suffer from lower detection rates and higher false positive rates. We propose a novel intrusion detection model that combines an improved conditional variational AutoEncoder (ICVAE) with a deep neural network (DNN), namely ICVAE-DNN. ICVAE is used to learn and explore potential sparse representations between network data features and classes. The trained ICVAE decoder generates new attack samples according to the specified intrusion categories to balance the training data and increase the diversity of training samples, thereby improving the detection rate of the imbalanced attacks. The trained ICVAE encoder is not only used to automatically reduce data dimension, but also to initialize the weight of DNN hidden layers, so that DNN can easily achieve global optimization through back propagation and fine tuning. The NSL-KDD and UNSW-NB15 datasets are used to evaluate the performance of the ICVAE-DNN. The ICVAE-DNN is superior to the three well-known oversampling methods in data augmentation. Moreover, the ICVAE-DNN outperforms six well-known models in detection performance, and is more effective in detecting minority attacks and unknown attacks. In addition, the ICVAE-DNN also shows better overall accuracy, detection rate and false positive rate than the nine state-of-the-art intrusion detection methods.
引用
收藏
页数:20
相关论文
共 55 条
[1]   A survey of intrusion detection systems based on ensemble and hybrid classifiers [J].
Aburomman, Abdulla Amin ;
Reaz, Mamun Bin Ibne .
COMPUTERS & SECURITY, 2017, 65 :135-152
[2]   Identification of malicious activities in industrial internet of things based on deep learning models [J].
AL-Hawawreh, Muna ;
Moustafa, Nour ;
Sitnikova, Elena .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2018, 41 :1-11
[3]   An evaluation of the performance of Restricted Boltzmann Machines as a model for anomaly network intrusion detection [J].
Aldwairi, Tamer ;
Perera, Dilina ;
Novotny, Mark A. .
COMPUTER NETWORKS, 2018, 144 :111-119
[4]   A New Intrusion Detection System Based on Fast Learning Network and Particle Swarm Optimization [J].
Ali, Mohammed Hasan ;
Al Mohammed, Bahaa Abbas Dawood ;
Ismail, Alyani ;
Zolkipli, Mohamad Fadli .
IEEE ACCESS, 2018, 6 :20255-20261
[5]   Anomaly-based intrusion detection system through feature selection analysis and building hybrid efficient model [J].
Aljawarneh, Shadi ;
Aldwairi, Monther ;
Yassein, Muneer Bani .
JOURNAL OF COMPUTATIONAL SCIENCE, 2018, 25 :152-160
[6]   A Survey of Random Forest Based Methods for Intrusion Detection Systems [J].
Alves Resende, Paulo Angelo ;
Drummond, Andre Costa .
ACM COMPUTING SURVEYS, 2018, 51 (03)
[7]   Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm [J].
Ambusaidi, Mohammed A. ;
He, Xiangjian ;
Nanda, Priyadarsi ;
Tan, Zhiyuan .
IEEE TRANSACTIONS ON COMPUTERS, 2016, 65 (10) :2986-2998
[8]  
[Anonymous], UNSW NB15 DAT
[9]  
[Anonymous], P 2014 IEEE INT S SI
[10]  
[Anonymous], P 2018 4 IEEE C NETW