返回
A multi-task based deep learning approach for intrusion detection
DOI:10.1016/j.knosys.2021.107852.png)
摘要
En 中文
With the frequent occurrence of cyber-security incidents, intrusion detection system (IDS) has been payed more and more attention recently. However, detecting attacks from traffic data stream ac-curately is rather challenging. The great diversity and variation of network intrusions make the intrusion feature extraction difficult, and the serious imbalanced class distribution makes common classifiers cannot work properly. Traditional methods for intrusion detection suffer from some obvious drawbacks. Classic machine learning-based methods seriously depend on the pre-defined features, automatic feature learning-based methods usually overfit the training data and neglect the problem of imbalanced data distribution, and the unsupervised learning-based methods are not suitable for dealing with multi-class classification of attacks. In this paper, to understand the characteristics of network traffic clearly, we analyze the class distribution of classic intrusion datasets through visualization. Based on the observed characteristics we innovatively propose exploiting distinctive features of each type of traffic from three perspectives, namely, anomaly identification, clustering and classification. We consider the feature learning in each perspective as a single task, then propose three models to fulfill three tasks, namely, an Autoencoder-based contrastive learning model, a supervised learning-based clustering model, and MLP-based classifier, and we also develop a unified framework to integrate three models for accomplishing intrusion detection comprehensively. Additionally, we propose a customized loss function to deal with imbalanced distribution of traffic data. Finally, we conduct extensive experiments on three classic intrusion detection datasets. The results demonstrate that the proposed method can outperform the state-of-art methods on both binary and multi-class classification. (c) 2021 Elsevier B.V. All rights reserved.
Keyword:
Intrusion detection
Deep learning
Multi-task learning
Contrastive learning
Autoencoder
期刊
K
IF:
7.6
论文数:
1.3W
被引数:
4.5W
机构
引用论文
Carbonylation of osmium and ruthenium oxo complexes. X-ray crystal structures of [Me4N]2[Os(O)2(COOMe)2(μ-OMe)]2 and [nPr4N][fac-Ru(O2CMe)3(CO)3]
Polyhedron
IF0
The manipulation of miRNA-gene regulatory networks by KSHV induces endothelial cell motility
Blood
IF0
Intrusion Detection in 802.11 Networks: Empirical Evaluation of Threats and a Public Dataset802.11网络中的入侵检测: 威胁和公共数据集的经验评估
Unsupervised feature selection and cluster center initialization based arbitrary shaped clusters for intrusion detection
COMPUTERS & SECURITY
IF5.4
Application of deep reinforcement learning to intrusion detection for supervised problems深度强化学习在监督问题入侵检测中的应用

