首页 | 本学科首页   官方微博 | 高级检索  
     

面向软件定义网络架构的入侵检测模型设计与实现
引用本文:池亚平,莫崇维,杨垠坦,陈纯霞. 面向软件定义网络架构的入侵检测模型设计与实现[J]. 计算机应用, 2020, 40(1): 116-122. DOI: 10.11772/j.issn.1001-9081.2019061125
作者姓名:池亚平  莫崇维  杨垠坦  陈纯霞
作者单位:1. 北京电子科技学院 网络空间安全系, 北京 100070;2. 西安电子科技大学 通信工程学院, 西安 710071
基金项目:国家重点研发计划项目(2018YFB1004101)。
摘    要:针对传统入侵检测方法无法检测软件定义网络(SDN)架构的特有攻击行为的问题,设计一种基于卷积神经网络(CNN)的入侵检测模型。首先,基于SDN流表项设计了特征提取方法,通过采集SDN特有攻击样本形成攻击流表数据集;然后,采用CNN进行训练和检测,并针对SDN攻击样本量较小而导致的识别率低的问题,设计了一种基于概率的加强训练方法。实验结果表明,所提的入侵检测模型可以有效检测面向SDN架构的特有攻击,具有较高的准确率,所提的基于概率的加强学习方法能有效提升小概率攻击的识别率。

关 键 词:入侵检测  卷积神经网络  软件定义网络  网络安全  加强学习  
收稿时间:2019-06-28
修稿时间:2019-09-24

Design and implementation of intrusion detection model for software defined network architecture
CHI Yaping,MO Chongwei,YANG Yintan,CHEN Chunxia. Design and implementation of intrusion detection model for software defined network architecture[J]. Journal of Computer Applications, 2020, 40(1): 116-122. DOI: 10.11772/j.issn.1001-9081.2019061125
Authors:CHI Yaping  MO Chongwei  YANG Yintan  CHEN Chunxia
Affiliation:1. Department of Cyberspace Security, Beijing Electronic Science and Technology Institute, Beijing 100070, China;2. College of Communication Engineering, Xidian University, Xi'an Shaanxi 710071, China
Abstract:Concerning the problem that traditional intrusion detection method cannot detect the specific attacks aiming at Software Defined Network (SDN) architecture, an intrusion detection model based on Convolutional Neural Network (CNN) was proposed. Firstly, an feature extraction method was designed based on SDN flow table entry. The SDN specific attack samples were collected to form the attack flow table dataset. Then, the CNN was used for training and detection. And focusing on the low recognition rate caused by small sample size of SDN attacks, a reinforcement learning method based on probability was proposed. The experimental results show that the proposed intrusion detection model can effectively detect the specific attacks aiming at SDN architecture with high accuracy, and the proposed reinforcement learning method can effectively improve the recognition rate of small probability attacks.
Keywords:intrusion detection  Convolutional Neural Network (CNN)  Software Defined Network (SDN)  network security  reinforcement learning
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《计算机应用》浏览原始摘要信息
点击此处可从《计算机应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号