Adoption and realization of deep learning in network traffic anomaly detection device design

被引:0
|
作者
Guanglu Wei
Zhonghua Wang
机构
[1] PLA Strategic Support Force Information Engineering University,
[2] National Computer Network Emergency Response Technical Team Coordination Center of China,undefined
来源
Soft Computing | 2021年 / 25卷
关键词
Deep learning; CNN; Circulatory neural network; Network traffic; Anomaly detection;
D O I
暂无
中图分类号
学科分类号
摘要
In order to study the application of deep learning in the design of network traffic anomaly detection device, aiming at two common problems in the field of network anomaly detection: characteristic dependence and high false positive rate, the convolutional neural network (CNN) is combined with recurrent neural network (RNN) to propose the network anomaly detection method based on hierarchical spatiotemporal feature learning (HAST-NAD) based on deep learning. It automatically learns the traffic characteristics and improves the network traffic anomaly detection efficiency. First, the CNN is used to learn the spatial feature algorithm of data, and long-short term memory of RNN is used to learn the temporal feature algorithm of data. Then the two original data sets DARPA1998 and ISCX2012 are preprocessed. The accuracy, detection rate, and false positive rate of normal traffic and Dos, Probe, U2R, and R2L attack traffic are compared in DARPA1998 data set. The accuracy, detection rate, and false positive rate of normal traffic and Brute force SSH, DDoS, HttpDoS, and buffering attack traffic are compared in ISCX2012 data set. Finally, it is compared with other network traffic anomaly detection methods. The results show that when the network flow length is 800, the model shows good performance on the DARPA1998 data set (accuracy, detection rate and false positive rate are 98.68%, 97.78%, and 0.07%, respectively). When the network flow length is 600, the model performs better on the ISCX2012 dataset (accuracy, detection rate and false positive rate are 99.69%, 96.91%, and 0.22%, respectively). At the same time, when the packet length is 100 and the number of packets is 6, the model shows high precision, high detection rate, and low false positive rate on ISCX2012 data set. In the same data set, the temporal feature algorithm has better performance and lower false positive rate than the spatial feature algorithm. Compared with other network traffic anomaly detection methods, HAST-NAD has better comprehensive test results. In conclusion, the combination of CNN and RNN can better realize abnormal detection of network traffic, which has practical application and theoretical value.
引用
收藏
页码:1147 / 1158
页数:11
相关论文
共 50 条
  • [41] Deep Learning for Anomaly Detection: A Review
    Pang, Guansong
    Shen, Chunhua
    Cao, Longbing
    Van den Hengel, Anton
    ACM COMPUTING SURVEYS, 2021, 54 (02)
  • [42] Deep Learning-based DDoS Detection in Network Traffic Data
    Hadi, Teeb Hussein
    INTERNATIONAL JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING SYSTEMS, 2024, 15 (05) : 407 - 414
  • [43] Anomaly Detection of actual IoT traffic flows through Deep Learning
    Aversano, Lerina
    Bernardi, Mario Luca
    Cimitile, Marta
    Pecori, Riccardo
    20TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA 2021), 2021, : 1736 - 1741
  • [44] IEEE 802.11 Network Anomaly Detection and Attack Classification: A Deep Learning Approach
    Thing, Vrizlynn L. L.
    2017 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2017,
  • [45] Sequential Deep Learning Architectures for Anomaly Detection in Virtual Network Function Chains
    Lee, Chungjun
    Hong, Jibum
    Heo, DongNyeong
    Choi, Heeyoul
    12TH INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC 2021): BEYOND THE PANDEMIC ERA WITH ICT CONVERGENCE INNOVATION, 2021, : 1163 - 1168
  • [46] Network Encryption Traffic Anomaly Detection Based on Integrated Machine Learning
    Yang, Xiaoqing
    Angkawisittpan, Niwat
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2025, 32 (02): : 713 - 722
  • [47] Network Traffic Anomaly Detection in CAN Bus Based on Ensemble Learning
    Wu, Yuxi
    Tao, Xiaodong
    2024 4TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND INTELLIGENT SYSTEMS ENGINEERING, MLISE 2024, 2024, : 240 - 245
  • [48] A survey of deep learning-based network anomaly detection
    Kwon, Donghwoon
    Kim, Hyunjoo
    Kim, Jinoh
    Suh, Sang C.
    Kim, Ikkyun
    Kim, Kuinam J.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2019, 22 (Suppl 1): : 949 - 961
  • [49] A survey of deep learning-based network anomaly detection
    Donghwoon Kwon
    Hyunjoo Kim
    Jinoh Kim
    Sang C. Suh
    Ikkyun Kim
    Kuinam J. Kim
    Cluster Computing, 2019, 22 : 949 - 961
  • [50] Network Anomaly Intrusion Detection Based on Deep Learning Approach
    Wang, Yung-Chung
    Houng, Yi-Chun
    Chen, Han-Xuan
    Tseng, Shu-Ming
    SENSORS, 2023, 23 (04)