首页 | 官方网站   微博 | 高级检索  
     

基于内外卷积网络的网络入侵检测
引用本文:王艺霏,莫爽,吴文睿,范少华,肖丁. 基于内外卷积网络的网络入侵检测[J]. 北京邮电大学学报, 2021, 44(5): 94-100. DOI: 10.13190/j.jbupt.2021-007
作者姓名:王艺霏  莫爽  吴文睿  范少华  肖丁
作者单位:1. 国网冀北电力有限公司信息通信分公司, 北京 100054;2. 北京邮电大学 计算机学院(国家示范性软件学院), 北京 100876
基金项目:基于全业务统一数据中心的数据融合及可视化关键技术研究项目(52018E18006N)
摘    要:网络入侵检测通过分析流量特征来区分正常和异常的网络行为以实现入侵流量的检测,是网络安全领域的重要研究课题.针对已有入侵检测模型特征提取过程复杂、信息提取不足等问题,提出了一种基于内外卷积网络的入侵检测模型.首先使用一维卷积神经网络提取流量数据的内部特征,然后通过对内部特征计算相似度建模得到无向同质图,此外将流量在外部网络侧的通信行为建模为有向异质图,并对两图使用图卷积网络学习包含网络流量多种交互行为的嵌入向量,最后将学习到的流量嵌入向量输入到分类器中用于最终的分类.实验结果表明,所提模型的检测准确率和误报率均优于对比模型.

关 键 词:入侵检测  深度学习  图卷积网络  卷积神经网络  
收稿时间:2021-07-07

Internal-External Convolutional Networks for Network Intrusion Detection
WANG Yi-fei,MO Shuang,WU Wen-rui,FAN Shao-hua,XIAO Ding. Internal-External Convolutional Networks for Network Intrusion Detection[J]. Journal of Beijing University of Posts and Telecommunications, 2021, 44(5): 94-100. DOI: 10.13190/j.jbupt.2021-007
Authors:WANG Yi-fei  MO Shuang  WU Wen-rui  FAN Shao-hua  XIAO Ding
Affiliation:1. State Grid Jibei Information and Telecommunication Company, Beijing 100054, China;2. School of Computer Science (National Pilot Software Engineering School), Beijing University of Posts and Telecommunications, Beijing 100876, China
Abstract:Network intrusion detection is an important research topic in the field of network security which is used to distinguish normal and abnormal network behaviors by analyzing traffic characteristics to realize intrusion traffic detection. To solve the problems of the complex feature extraction process,and insufficient information extraction in existing intrusion detection models,an intrusion detection model based on internal and external convolutional networks is proposed. Firstly,an one-dimensional convolutional neural network is used to extract the internal features of the traffic data. Then, an undirected homogeneous graph is obtained by calculating the similarity of the internal features. In addition the communication behavior of the traffic on the external network side is modeled as a directed heterogeneous graph,and graph convolutional network is used to learn embedding containing multiple interactive behaviors of network traffic from two graghs. Finally, the learned flow embedding is input into the classifier for final classification. Experimental results show that compared with existing methods,the detection accuracy and false alarm rate of the proposed model are better than those of the compared models.
Keywords:intrusion detection  deep learning  graph convolutional network  convolutional neural network  
本文献已被 万方数据 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号