Network Traffic Anomaly Detection Based on Information Gain and Deep Learning

被引:19
作者
Lu, Xianglin [1 ]
Liu, Pengju [1 ]
Lin, Jiayi [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Xitucheng Rd 10, Beijing, Peoples R China
来源
PROCEEDINGS OF 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND DATA MINING (ICISDM 2019) | 2019年
关键词
Network traffic anomaly detection; Information Gain; Deep learning; Convolutional neural network; Long Short-Term Memory; KDDCUP99;
D O I
10.1145/3325917.3325946
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the rapid development of the Internet, the network traffic shows an explosive growth trend. Although the Internet facilitates people's lives, it also brings a lot of security threats. Thus, the analysis of abnormal behavior of network traffic becomes a crucial factor for ensuring the quality of Internet services and preventing network intrusion. This paper proposes a deep learning method that combines CNN and LSTM to detect abnormal network traffic, especially unknown intrusions. In the field of machine learning, the choice of features is the key ingredient to the effect and accuracy of the model. Therefore, this paper also proposes a feature selection method based on Information Gain (IG), extracting more valuable features, which are fed into the model. We use CNN to extract the higher dimensional features of the input data, and then use LSTM to learn the timing characteristics of the network traffic. We applied our model on the KDD99 dataset and assessed its accuracy. When the epoch greater than 4, the training accuracy reaches 0.99 and testing accuracy reaches 0.925, which showed a certain improvement compared with the traditional model. In the era when information volume is becoming more and more dense, the analysis of network traffic will become more and more necessary, which also proves broader application prospects.
引用
收藏
页码:11 / 15
页数:5
相关论文
共 16 条
[1]  
Anderson James P., 1980, Tech. Rep
[2]  
[Anonymous], 1997, 3 INT C KNOWL DISC D, P14
[3]   ImageNet Classification with Deep Convolutional Neural Networks [J].
Krizhevsky, Alex ;
Sutskever, Ilya ;
Hinton, Geoffrey E. .
COMMUNICATIONS OF THE ACM, 2017, 60 (06) :84-90
[4]  
KwonKathiravan Donghwoon, 2018 IEEE 38 INT C D
[5]  
Li S, 2017, 2017 12TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND KNOWLEDGE ENGINEERING (IEEE ISKE)
[6]  
Liu Jiaomin, 2009, 2009 2 INT C INT NET
[7]  
Song Ruoning, 2014, 2014 IEEE 3 INT C CL
[8]  
Vinayakumar R, 2017, 2017 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), P1677, DOI 10.1109/ICACCI.2017.8126084
[9]  
Wang Fei, 2018, 2018 13 APCA INT C C
[10]  
Wu Qingtao, 2011, J COMPUTERS