APP下载

基于增量集成学习的动态自适应SDN入侵检测

2021-10-01陈昌娜李昭桦

计算技术与自动化 2021年3期

陈昌娜 李昭桦

摘 要:随着SDN网络应用的推广,SDN网络的安全也越来越受到重视,基于模式识别的网络入侵检测由于无法一次性收集完备的训练数据集,使得对未知的入侵行为识别率不高。为提高入侵检测系统的自适应性,提出了增量集成学习算法,并用该算法解决SDN入侵检测问题。该算法利用滑动窗口法获得数据块,对新的数据块进行训练获得子分类器,然后依据在历史数据块和当前数据块的分类结果筛选子分类器进行集成,使得分类模型不断完善从而能够自适应的识别未知攻击行为。通过在NSL-KDD数据集上的实验结果可以看到,该算法可以提高未知攻击的识别率。

关键词:增量学习;集成学习;入侵检测;软件定义网络

Abstract:With the popularization of SDN network application, the security of SDN network has been paid more and more attention. Because the network intrusion detection method based on pattern recognition cannot collect complete training dataset at one time, the recognition rate of intrusion detection model for unknown intrusion behavior is not high. In order to improve the adaptability of intrusion detection system, this paper proposes an incremental ensemble learning algorithm and uses it to solve the problem of SDN intrusion detection. The proposed algorithm uses sliding window method to obtain data blocks and trains data blocks to obtain sub classifiers. Then it selects sub-classifiers according to the classification results of historical data blocks and current data blocks for integration, so that the classification model is constantly improved and can identify unknown attack behavior adaptively. The experimental results on the NSL-KDD dataset show that the algorithm can improve the recognition rate of unknown attacks.

Key words:incremental learning; ensemble learning; intrusion detection; software defined network

软件定义网络( Software Defined Network,SDN)是一种新兴的网络架构,已逐渐成为云计算环境所依赖的重要技术之一[1],但SDN 架构自身的安全问题也受到国内外专家学者的关注。入侵检测作为网络安全的重要技术之一,也是网络安全领域的研究热点[1-6],把机器学习、模式识别用于网络入侵检测是该领域的研究热点之一,也就是把网络入侵检测问题转化为分类问题。

常见的机器学习算法均有学者尝试用于解决网络入侵检测问题,例如支持向量机[2-3]、深度学习[4-6]、决策树[7]、集成学习[8-10]等分类算法,这些方法都是对已知的训练数据集进行训练,获得分类模型,然后对未知的数据进行预测,因此训练数据集对算法的影响较大,决定了最终构建模型……

登录APP查看全文