Accelerating convolutional neural network-based malware traffic detection through ant-colony clustering.

JOURNAL OF INTELLIGENT & FUZZY SYSTEMS(2019)

引用 7|浏览25
暂无评分
摘要
Deep learning methods have been widely used in today's network security systems for their outperforming in detecting rates of the patterns of anomalous network actions. Particularly, in the field of malware traffic classification, time reduction for a detecting process is of great importance and can stop network damage at an early stage. To achieve a balance between the detection rate and time consumption, practical structures of relative systems are usually simple, complicating the application of appropriate accelerating methods. In this study, we propose a novel ant-colony -based clustering algorithm, which can efficiently select the most valuable data points for the next step of learning. In addition, to take advantage of the widely-used convolutional neural network architecture, we defined the mapping-image of each raw traffic data, and then transformed the intrusion detection problem into an image recognition problem. Before each training iteration, we applied the clustering algorithm to locate the most-featured part of each specific type of network traffic. Next, we utilized this featured part in the training, by considering its depth and shallow information, so that its precision and robustness can be improved. Preliminary experiments demonstrate that our method not only achieves high-detection-rate results but also manages to utilize much less processing time with proper parameter tuning of the neural networks.
更多
查看译文
关键词
Deep learning,convolutional neural network,intrusion detection system,network anomaly detection,heuristic clustering
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要