首页|雾环境中基于深自编码器和扩展孤立森林的入侵检测方法

雾环境中基于深自编码器和扩展孤立森林的入侵检测方法

扫码查看
针对物联网中多变性的入侵行为,在雾计算模式下提出一种基于深自编码器和扩展孤立森林相混合的入侵检测方法。使用一维卷积神经网络(1 D-CNN)实现的自编码器对雾节点采集的网络流量数据进行入侵检测,并将攻击和正常流量数据分为两组;采用扩展孤立森林算法分别对深自编码器区分的攻击流量和正常流量进行异常检测,尝试识别攻击组和正常组中不匹配的数据点,从而提高所提方法的整体检测准确度和降低误报率。与其他入侵检测方法相比,所提方法在多个指标中取得最佳的结果,能够有效识别快速演化的网络攻击。
INTRUSION DETECTION METHOD BASED ON DEEP AUTOENCODER AND EXTENDED ISOLATED FOREST IN FOG ENVIRONMENT
Aimed at the variability of intrusion behavior in the Internet of things,a hybrid intrusion detection method based on deep autoencoder and extended isolated forest is proposed for fog computing mode.The autoencoder based on one-dimensional convolutional neural network(1 D-CNN)was used to detect the network traffic data collected by fog nodes,and the attack and normal traffic data were divided into two groups.The extended isolated forest algorithm was used to detect the anomaly of attack traffic and normal traffic,and try to identify the mismatched data points in attack group and normal group,so as to improve the overall detection accuracy and reduce the false alarm rate of the proposed method.Compared with other intrusion detection methods,the proposed method achieves the best results among multiple indicators,and can effectively identify rapidly evolving network attacks.

Fog computingDeep autoencoderExtended isolated forestIntrusion detection method

蔡黎亚、田英杰

展开 >

苏州工业园区服务外包职业学院 江苏 苏州 215123

中国科学院大数据挖掘与知识管理重点实验室中国科学院虚拟经济与数据科学研究中心 北京 100190

雾计算 深自编码器 扩展孤立森林 入侵检测方法

国家自然科学基金重点项目

71731009

2024

计算机应用与软件
上海市计算技术研究所 上海计算机软件技术开发中心

计算机应用与软件

CSTPCD北大核心
影响因子:0.615
ISSN:1000-386X
年,卷(期):2024.41(2)
  • 2