通信学报2024,Vol.45Issue(2) :54-67.DOI:10.11959/j.issn.1000-436x.2024013

基于VAE-CWGAN和特征统计重要性融合的网络入侵检测方法

Network intrusion detection method based on VAE-CWGAN and fusion of statistical importance of feature

刘涛涛 付钰 王坤 段雪源
通信学报2024,Vol.45Issue(2) :54-67.DOI:10.11959/j.issn.1000-436x.2024013

基于VAE-CWGAN和特征统计重要性融合的网络入侵检测方法

Network intrusion detection method based on VAE-CWGAN and fusion of statistical importance of feature

刘涛涛 1付钰 1王坤 2段雪源3
扫码查看

作者信息

  • 1. 海军工程大学信息安全系,湖北 武汉 430033
  • 2. 海军工程大学信息安全系,湖北 武汉 430033;信阳职业技术学院数学与信息工程学院,河南 信阳 464000
  • 3. 海军工程大学信息安全系,湖北 武汉 430033;信阳师范大学计算机与信息技术学院,河南 信阳 464000
  • 折叠

摘要

针对传统入侵检测方法受限于数据集类不平衡以及所选特征代表性不强等问题,提出一种基于VAE-CWGAN 和特征统计重要性融合的检测方法.首先,为提升数据质量对数据集进行预处理;其次,搭建VAE-CWGAN模型生成新样本以解决数据集类不平衡问题,使分类模型不再偏向于多数类;再次,使用标准差、中值均值差对特征进行排序,并融合其统计重要性来进行特征选择旨在获得代表性更强的特征,从而使模型更好地学习数据信息;最后,通过一维卷积神经网络对特征选择后的混合数据集进行分类.实验结果表明,所提方法在NSL-KDD、UNSW-NB15 和CIC-IDS-2017数据集上都表现出较好的性能优势,准确率分别为98.95%、96.24%和99.92%,有效提升了入侵检测性能.

Abstract

Considering the problems of traditional intrusion detection methods limited by the class imbalance of datasets and the poor representation of selected features,a detection method based on VAE-CWGAN and fusion of statistical im-portance of features was proposed.Firstly,data preprocessing was conducted to enhance data quality.Secondly,a VAE-CWGAN model was constructed to generate new samples,addressing the problem of imbalanced datasets,ensuring that the classification model no longer biased towards the majority class.Next,standard deviation,difference of median and mean were used to rank the features and fusion their statistical importance for feature selection,aiming to obtain more representative features,which made the model can better learn data information.Finally,the mixed data set after feature selection was classified through a one-dimensional convolutional neural network.Experimental results show that the proposed method demonstrates good performance advantages on three datasets,namely NSL-KDD,UNSW-NB15,and CIC-IDS-2017.The accuracy rates are 98.95%,96.24%,and 99.92%,respectively,effectively improving the perfor-mance of intrusion detection.

关键词

入侵检测/网络流量/类不平衡/特征选择/统计重要性融合

Key words

intrusion detection/network traffic/class imbalance/feature selection/fusion of statistical importance

引用本文复制引用

基金项目

国家重点研发计划基金资助项目(2018YFB0804104)

出版年

2024
通信学报
中国通信学会

通信学报

CSTPCDCSCD北大核心
影响因子:1.265
ISSN:1000-436X
参考文献量45
段落导航相关论文