A Method of Few-Shot Network Intrusion Detection Based on Meta-Learning Framework

计算机科学 入侵检测系统 人工智能 数据挖掘 特征(语言学) 特征提取 任务(项目管理) 元学习(计算机科学) 机器学习 构造(python库) 网络安全 人工神经网络 模式识别(心理学) 假阳性率 样品(材料) 计算机安全 计算机网络 管理 经济 哲学 语言学 化学 色谱法
作者
Congyuan Xu,Jizhong Shen,Xin Du
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:15: 3540-3552 被引量:235
标识
DOI:10.1109/tifs.2020.2991876
摘要

Conventional intrusion detection systems based on supervised learning techniques require a large number of samples for training, while in some scenarios, such as zero-day attacks, security agencies can only intercept a limited number of shots of malicious samples. Therefore, there is a need for few-shot detection. In this paper, a detection method based on a meta-learning framework is proposed for this purpose. The proposed method can be used to distinguish and compare a pair of network traffic samples as a basic task of learning, including a normal unaffected sample and a malicious one. To accomplish this task, we design a deep neural network (DNN) named FC-Net, which mainly comprises two parts: feature extraction network and comparison network. FC-Net learns a pair of feature maps for classification from a pair of network traffic samples, then compares the obtained feature maps, and finally determines whether the pair of samples belongs to the same type. To evaluate the proposed detection method, we construct two datasets for few-shot network intrusion detection based on real network traffic data sources, using a specifically developed approach. The experimental results indicate that the proposed detection method is universal and is not limited to specific datasets or attack types. Training and testing on the same datasets demonstrate that the proposed method can achieve the average detection rate up to 98.88%. The outcome of training on one dataset and testing on the other one confirms that the proposed method can achieve better performance. In a few-shot scenario, malicious samples in an untrained dataset can be detected successfully, and the average detection rate is up to 99.62%.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
认真芷容完成签到,获得积分10
1秒前
1秒前
1秒前
2秒前
搜集达人应助坚定晓兰采纳,获得10
2秒前
AxiE完成签到,获得积分10
2秒前
wulala发布了新的文献求助10
3秒前
专注鼠标发布了新的文献求助10
4秒前
神明说困了完成签到,获得积分10
5秒前
丘比特应助眉间一把刀采纳,获得10
5秒前
nightmare发布了新的文献求助10
5秒前
5秒前
6秒前
coke完成签到,获得积分10
6秒前
6秒前
DHMO发布了新的文献求助10
6秒前
6秒前
7秒前
戊烷完成签到,获得积分10
8秒前
哦呵发布了新的文献求助10
8秒前
8秒前
莹莹啊发布了新的文献求助10
9秒前
9秒前
10秒前
丘比特应助朱研究采纳,获得10
10秒前
JCSY发布了新的文献求助10
10秒前
亦玉发布了新的文献求助30
10秒前
阳光果粒陈完成签到,获得积分10
11秒前
自觉士萧发布了新的文献求助10
11秒前
等待的音响完成签到,获得积分10
11秒前
wbw完成签到,获得积分10
11秒前
NexusExplorer应助直率不平采纳,获得10
11秒前
齐珏发布了新的文献求助10
12秒前
12秒前
MMM关闭了MMM文献求助
12秒前
12秒前
菜菜mm发布了新的文献求助10
12秒前
13秒前
123发布了新的文献求助10
13秒前
13秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Les Mantodea de Guyane Insecta, Polyneoptera 2000
Quality by Design - An Indispensable Approach to Accelerate Biopharmaceutical Product Development 800
Pulse width control of a 3-phase inverter with non sinusoidal phase voltages 777
Signals, Systems, and Signal Processing 610
Research Methods for Applied Linguistics: A Practical Guide 600
Research Methods for Applied Linguistics 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6405885
求助须知:如何正确求助?哪些是违规求助? 8225124
关于积分的说明 17439412
捐赠科研通 5458344
什么是DOI,文献DOI怎么找? 2884222
邀请新用户注册赠送积分活动 1860608
关于科研通互助平台的介绍 1701663