计算机科学
入侵检测系统
数据挖掘
公制(单位)
特征(语言学)
编码(内存)
机器学习
依赖关系(UML)
发电机(电路理论)
模式识别(心理学)
欧几里德距离
任务(项目管理)
人工智能
经济
功率(物理)
管理
语言学
量子力学
物理
哲学
运营管理
作者
Jingcheng Yang,Hongwei Li,Shuo Shao,Futai Zou,Yue Wu
标识
DOI:10.1016/j.cose.2022.102899
摘要
Due to the high dependency of traditional intrusion detection method on a fully-labeled large dataset, existing works can hardly be applied in real-world scenarios, especially facing zero-day attacks. In this paper we present a novel intrusion detection framework called “FS-IDS”, including flow data encoding method, feature fusion mechanism and architecture of intrusion detection system based on few-shot learning. We utilize task generator to split the dataset into separate tasks and train model in an episodic way, hoping model to learn general knowledge rather than those specific to a single class. The extraction module and distance metric module are responsible for learning and determining whether the traffic data are benign or not. We conduct three sets of experiments on “FS-IDS”, i.e., comparison study, ablation study and multiclass study. Comparison study firstly determines that the best measure metric for discrimination is Euclidean distance. Based on the optimal implementation, “FS-IDS” achieves comparable performance with existing works by using much fewer malicious samples. Ablation study sets two base models to explore how proposed encoding method and feature fusion mechanism improve detection capacity. Both the image representation and feature fusion achieve more than 2% improvement in accuracy and recall. Finally, to test whether “FS-IDS” can perform well under real-world scenario or not, we design network traffic containing various attacks to simulate complex malicious network environment. Experimental results show that “FS-IDS” maintains more than 90% detection accuracy and recall under the worst circumstances, which composes of various seen or unseen attacks with only a few malicious samples available.
科研通智能强力驱动
Strongly Powered by AbleSci AI