Abnormal Network Traffic Detection Based on Transfer Component Analysis

Jie Niu,Yong Zhang,Dan Liu,Da Guo,Yinglei Teng
DOI: https://doi.org/10.1109/ICCW.2019.8756996
2019-01-01
Abstract:Machine learning based abnormal traffic detection schemes require related training and test datasets to have the same feature distribution. Due to differences of the dataset types and feature distributions, when the trained classification model is applied to the new network traffic datasets, the valid identification cannot be achieved, resulting in the failure of the model. In order to enhance detection accuracy and generalization performance of the classification model, this paper investigates how the transfer learning theory is applied to abnormal network traffic detection system and proposes a network intrusion detection method based on transfer component analysis. With datasets of different distributions mapped to the same subspace by domain adaptation, the model is trained with the base classifiers in the shared subspace and detects the new traffic data generated from different domains. Experiments involving different traffic datasets show that, compared with the traditional machine learning method, the accuracy of our method can be increased by up to 75%. It can also extend the application range of the abnormal network traffic detection schemes based on machine learning.
What problem does this paper attempt to address?