Adoption and realization of deep learning in network traffic anomaly detection device design

被引:0
|
作者
Guanglu Wei
Zhonghua Wang
机构
[1] PLA Strategic Support Force Information Engineering University,
[2] National Computer Network Emergency Response Technical Team Coordination Center of China,undefined
来源
Soft Computing | 2021年 / 25卷
关键词
Deep learning; CNN; Circulatory neural network; Network traffic; Anomaly detection;
D O I
暂无
中图分类号
学科分类号
摘要
In order to study the application of deep learning in the design of network traffic anomaly detection device, aiming at two common problems in the field of network anomaly detection: characteristic dependence and high false positive rate, the convolutional neural network (CNN) is combined with recurrent neural network (RNN) to propose the network anomaly detection method based on hierarchical spatiotemporal feature learning (HAST-NAD) based on deep learning. It automatically learns the traffic characteristics and improves the network traffic anomaly detection efficiency. First, the CNN is used to learn the spatial feature algorithm of data, and long-short term memory of RNN is used to learn the temporal feature algorithm of data. Then the two original data sets DARPA1998 and ISCX2012 are preprocessed. The accuracy, detection rate, and false positive rate of normal traffic and Dos, Probe, U2R, and R2L attack traffic are compared in DARPA1998 data set. The accuracy, detection rate, and false positive rate of normal traffic and Brute force SSH, DDoS, HttpDoS, and buffering attack traffic are compared in ISCX2012 data set. Finally, it is compared with other network traffic anomaly detection methods. The results show that when the network flow length is 800, the model shows good performance on the DARPA1998 data set (accuracy, detection rate and false positive rate are 98.68%, 97.78%, and 0.07%, respectively). When the network flow length is 600, the model performs better on the ISCX2012 dataset (accuracy, detection rate and false positive rate are 99.69%, 96.91%, and 0.22%, respectively). At the same time, when the packet length is 100 and the number of packets is 6, the model shows high precision, high detection rate, and low false positive rate on ISCX2012 data set. In the same data set, the temporal feature algorithm has better performance and lower false positive rate than the spatial feature algorithm. Compared with other network traffic anomaly detection methods, HAST-NAD has better comprehensive test results. In conclusion, the combination of CNN and RNN can better realize abnormal detection of network traffic, which has practical application and theoretical value.
引用
收藏
页码:1147 / 1158
页数:11
相关论文
共 50 条
  • [1] Adoption and realization of deep learning in network traffic anomaly detection device design
    Wei, Guanglu
    Wang, Zhonghua
    SOFT COMPUTING, 2021, 25 (02) : 1147 - 1158
  • [2] Network traffic anomaly detection based on deep learning: a review
    Zhang, Wenjing
    Lei, Xuemei
    INTERNATIONAL JOURNAL OF COMPUTATIONAL SCIENCE AND ENGINEERING, 2024, 27 (03) : 249 - 257
  • [3] VANET Network Traffic Anomaly Detection Using GRU-Based Deep Learning Model
    Almahadin, Ghayth
    Aoudni, Yassine
    Shabaz, Mohammad
    Agrawal, Anurag Vijay
    Yasmin, Ghazaala
    Alomari, Esraa Saleh
    Al-Khafaji, Hamza Mohammed Ridha
    Dansana, Debabrata
    Maaliw III, Renato Racelis
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 4548 - 4555
  • [4] Anomaly Detection in Traffic Surveillance Videos Using Deep Learning
    Khan, Sardar Waqar
    Hafeez, Qasim
    Khalid, Muhammad Irfan
    Alroobaea, Roobaea
    Hussain, Saddam
    Iqbal, Jawaid
    Almotiri, Jasem
    Ullah, Syed Sajid
    SENSORS, 2022, 22 (17)
  • [5] An Unsupervised Deep Learning Model for Early Network Traffic Anomaly Detection
    Hwang, Ren-Hung
    Peng, Min-Chun
    Huang, Chien-Wei
    Lin, Po-Ching
    Van-Linh Nguyen
    IEEE ACCESS, 2020, 8 : 30387 - 30399
  • [6] Network Traffic Anomaly Detection Method Based on Deep Features Learning
    Dong Shuqin
    Zhang Bin
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (03) : 695 - 703
  • [7] Network Traffic Anomaly Detection Based on Information Gain and Deep Learning
    Lu, Xianglin
    Liu, Pengju
    Lin, Jiayi
    PROCEEDINGS OF 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND DATA MINING (ICISDM 2019), 2019, : 11 - 15
  • [8] RawPower: Deep Learning based Anomaly Detection from Raw Network Traffic Measurements
    Marin, Gonzalo
    Casas, Pedro
    Capdehourat, German
    SIGCOMM'18: PROCEEDINGS OF THE ACM SIGCOMM 2018 CONFERENCE: POSTERS AND DEMOS, 2018, : 75 - 77
  • [9] Leveraging Deep Learning for Network Anomaly Detection
    Kourtis, Michail-Alexandros
    Oikonomakis, Andreas
    Papadopoulos, Dimitris
    Xylouris, George
    Chochliouros, Ioannis P.
    2021 SIXTH INTERNATIONAL CONFERENCE ON FOG AND MOBILE EDGE COMPUTING (FMEC), 2021, : 91 - 96
  • [10] Network Traffic Anomaly Detection Method Based on Deep Features Learning
    Dong S.
    Zhang B.
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2020, 42 (03): : 695 - 703