基于RFE+SVM的卷积神经网络在入侵检测方面的应用
2021-07-19张峻豪王怀彬
张峻豪 王怀彬


摘要:神经网络在入侵检测方向的使用已经是入侵检测领域的热门发展方向。传统入侵检测方法如机器学习、数据挖掘、统计分析等都具有一定局限性。通过引入基于RFE+SVM降维的卷积神经网络算法,从Python的深度学习库(tensorflow)出发,搭建出一类基于卷积神经网络的入侵检测数据分类模型。通过数据集对比及实验证明,该模型有效且稳定的提高了对异常数据的判别率,并可发现未知的攻击类型。
关键词:入侵检测;RFE+SVM;tensorflow;卷积神经网络;未知攻击
中图分类号:TP393 文献标识码:A
文章编号:1009-3044(2021)13-0191-03
Abstract:The use of neural network in intrusion detection has been a hot development direction in the field of intrusion detection. Traditional intrusion detection methods such as machine learning, data mining, statistical analysis have some limitations. By introducing convolutional neural network algorithm based on RFE + SVM dimension reduction and starting from Python's tensorFlow, a data classification model of Intrusion Detection Based on convolutional neural network is built. Through the comparison of data sets and experiments, it is proved that the model can effectively and stably improve the discrimination rate of abnormal data, and can find unknown attack types.
Key words:intrusion detection; RFE+SVM; tensorFlow; convolutional neural network; unknown attack
入侵檢测的发展历史已经有几十年[1],传统方法的使用一般有以下几种:
①早期的入侵检测系统基于专家经验,通过专家的知识,对已知网络提取特征,建立数据库,通过数据库比对达到入侵检测的目的,这是一种早期比较有效的手段,但工程量大,时间长,且仅凭人为的知识填充,IDS应对攻击类型种类不全,不能应对未知攻击。
②基于统计分析的方法也是一种常见方法,使用高斯模型进行参数估计,从而达到降低假阴性率和假阳性率的目的,其缺点是阈值很难确定。
③基于模式匹配是第一种方法的升级,与现有多个庞大的数据库进行对比,降低误报率,缺点是容易忽略没有规则描述的攻击。
④基于数据挖掘的入侵检测是近年常用方法,通过聚类算法进行划分,以此解决由密度簇引起的边缘错误,但在参数选择上较为困难。
⑤人工智能的兴起带来了基于机器学习的思路,机器学习算法通过分类器进行分类,其优点是可发现未知攻击,但精确度不高。……
