Adoption and realization of deep learning in network traffic anomaly detection device design

被引:0
|
作者
Guanglu Wei
Zhonghua Wang
机构
[1] PLA Strategic Support Force Information Engineering University,
[2] National Computer Network Emergency Response Technical Team Coordination Center of China,undefined
来源
Soft Computing | 2021年 / 25卷
关键词
Deep learning; CNN; Circulatory neural network; Network traffic; Anomaly detection;
D O I
暂无
中图分类号
学科分类号
摘要
In order to study the application of deep learning in the design of network traffic anomaly detection device, aiming at two common problems in the field of network anomaly detection: characteristic dependence and high false positive rate, the convolutional neural network (CNN) is combined with recurrent neural network (RNN) to propose the network anomaly detection method based on hierarchical spatiotemporal feature learning (HAST-NAD) based on deep learning. It automatically learns the traffic characteristics and improves the network traffic anomaly detection efficiency. First, the CNN is used to learn the spatial feature algorithm of data, and long-short term memory of RNN is used to learn the temporal feature algorithm of data. Then the two original data sets DARPA1998 and ISCX2012 are preprocessed. The accuracy, detection rate, and false positive rate of normal traffic and Dos, Probe, U2R, and R2L attack traffic are compared in DARPA1998 data set. The accuracy, detection rate, and false positive rate of normal traffic and Brute force SSH, DDoS, HttpDoS, and buffering attack traffic are compared in ISCX2012 data set. Finally, it is compared with other network traffic anomaly detection methods. The results show that when the network flow length is 800, the model shows good performance on the DARPA1998 data set (accuracy, detection rate and false positive rate are 98.68%, 97.78%, and 0.07%, respectively). When the network flow length is 600, the model performs better on the ISCX2012 dataset (accuracy, detection rate and false positive rate are 99.69%, 96.91%, and 0.22%, respectively). At the same time, when the packet length is 100 and the number of packets is 6, the model shows high precision, high detection rate, and low false positive rate on ISCX2012 data set. In the same data set, the temporal feature algorithm has better performance and lower false positive rate than the spatial feature algorithm. Compared with other network traffic anomaly detection methods, HAST-NAD has better comprehensive test results. In conclusion, the combination of CNN and RNN can better realize abnormal detection of network traffic, which has practical application and theoretical value.
引用
收藏
页码:1147 / 1158
页数:11
相关论文
共 50 条
  • [31] Anomaly detection in network traffic
    Duraj, Agnieszka
    Bucki, Pawel
    Drajling, Aleksander
    Makrocki, Robert
    Sipinski, Mateusz
    PRZEGLAD ELEKTROTECHNICZNY, 2022, 98 (12): : 205 - 208
  • [32] Deep Learning Driven QoS Anomaly Detection for Network Performance Optimization
    Ghuge, Madhuri
    Ranjan, Nidhi
    Mahajan, Rupali Atul
    Upadhye, Pawan Arunkumar
    Shirkande, Shrinivas T.
    Bhamare, Darshana
    JOURNAL OF ELECTRICAL SYSTEMS, 2023, 19 (02) : 97 - 104
  • [33] Sparse Representation and Dictionary Learning for Network Traffic Anomaly Detection
    Kierul, Tomasz
    Kierul, Michal
    Andrysiak, Tomasz
    Saganowski, Lukasz
    THEORY AND APPLICATIONS OF DEPENDABLE COMPUTER SYSTEMS, DEPCOS-RELCOMEX 2020, 2020, 1173 : 344 - 354
  • [34] Unsupervised Machine Learning for Anomaly Detection in Synchrophasor Network Traffic
    Donner, Phillip
    Leger, Aaron St.
    Blaine, Raymond
    2019 51ST NORTH AMERICAN POWER SYMPOSIUM (NAPS), 2019,
  • [35] Network Traffic Anomaly Detection using Machine Learning Approaches
    Limthong, Kriangkrai
    Tawsook, Thidarat
    2012 IEEE NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (NOMS), 2012, : 542 - 545
  • [36] A Deep Learning Ensemble for Network Anomaly and Cyber-Attack Detection
    Dutta, Vibekananda
    Choras, Michal
    Pawlicki, Marek
    Kozik, Rafal
    SENSORS, 2020, 20 (16) : 1 - 20
  • [37] Intelligent Anomaly Detection for Large Network Traffic With Optimized Deep Clustering (ODC) Algorithm
    Roselin, Annie Gilda
    Nanda, Priyadarsi
    Nepal, Surya
    He, Xiangjian
    IEEE ACCESS, 2021, 9 : 47243 - 47251
  • [38] Design of IoT Network using Deep Learning-based Model for Anomaly Detection
    Varalakshmi, Sudha
    Premnath, S. P.
    Yogalakshmi, V
    Vijayalakshmi, P.
    Kavitha, V. R.
    Vimalarani, G.
    PROCEEDINGS OF THE 2021 FIFTH INTERNATIONAL CONFERENCE ON I-SMAC (IOT IN SOCIAL, MOBILE, ANALYTICS AND CLOUD) (I-SMAC 2021), 2021, : 216 - 220
  • [39] Traffic Anomaly Detection Using Deep Semi-Supervised Learning at the Mobile Edge
    Pelati, Annalisa
    Meo, Michela
    Dini, Paolo
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2022, 71 (08) : 8919 - 8932
  • [40] Deep Active Learning for Anomaly Detection
    Pimentel, Tiago
    Monteiro, Marianne
    Veloso, Adriano
    Ziviani, Nivio
    2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,