首页 | 本学科首页   官方微博 | 高级检索  
     

基于在线特征选择的网络流异常检测
引用本文:莫小勇,潘志松,邱俊洋,余亚军,蒋铭初.基于在线特征选择的网络流异常检测[J].山东大学学报(工学版),2016,46(4):21-27.
作者姓名:莫小勇  潘志松  邱俊洋  余亚军  蒋铭初
作者单位:解放军理工大学指挥信息系统学院, 江苏 南京 210007
基金项目:国家自然科学基金资助项目(61473149)
摘    要:针对传统批处理特征选择方法处理大规模骨干网数据流存在时间和空间的限制,提出基于在线特征选择(online feature selection, OFS)的网络流异常检测方法,该方法将在线思想融入线性分类模型,在特征选择过程中,首先使用在线梯度下降法更新分类器,并将其限制在L1球内,然后用截断函数控制特征选择的数量。研究结果表明,提出的方法能充分利用网络流的时序性特点,同时减少检测时间且准确率和批处理方法相近,能满足网络流异常检测的实时性要求,为网络流分类和异常检测提供一种全新的思路。

关 键 词:网络流  异常检测  时序性  在线特征选择  批处理  
收稿时间:2016-03-01

Anomaly detection in network traffic based on online feature selection
MO Xiaoyong;PAN Zhisong;QIU Junyang;YU Yajun;JIANG Mingchu.Anomaly detection in network traffic based on online feature selection[J].Journal of Shandong University of Technology,2016,46(4):21-27.
Authors:MO Xiaoyong;PAN Zhisong;QIU Junyang;YU Yajun;JIANG Mingchu
Affiliation:College of Command Information System, PLA University of Science and Technology, Nanjing 210007, Jiangsu, China
Abstract:Traditional batch feature selection methods had the limitations in time and space when dealing large-scale backbone network traffic. A method based on online feature selection detection was proposed to address the limitations, which integrated the idea of online learning into the linear classification model. When selecting the features, the classifier was first updated by online gradient descent and projected to a L1 ball to ensure that the norm of the classifier is bounded, and then the truncate function was used to control the quantity of features. The analysis results showed that the proposed method could make a good use of the time-sequence property of traffic, reduce the time of anomaly detection and hold the similar accuracy when comparing with the batch methods, and meet the real-time demand of network traffic anomaly detection. The proposed method provided a new idea for the network traffic anomaly detection.
Keywords:network traffic  anomaly detection  time-sequence  online feature selection  batch learning  
本文献已被 CNKI 等数据库收录!
点击此处可从《山东大学学报(工学版)》浏览原始摘要信息
点击此处可从《山东大学学报(工学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号