STRAD - Network Intrusion Detection Algorithm Based on Zero-Positive Learning in Real Complex Network Environment.

Ying Zhong,Ziqi Gao,Rui Li,Citong Que,Xinjie Yang,Zhiliang Wang,Jiahai Yang,Xia Yin,Xingang Shi,Keqin Li
DOI: https://doi.org/10.1109/iscc53001.2021.9631496
2021-01-01
Abstract:With the increasing network security risks, network intrusion detection technology has become more important. At present, machine learning is applied in most advanced traffic anomaly detection algorithms, but these algorithms have three main shortcomings. First, algorithms using deep neural network are highly complex and not suitable for real-time online processing. Second, algorithms based on supervised learning require training on huge labeled data sets, which are limited and insufficient. Third, most algorithms have such poor generalization ability and portability that they are less suitable for real-world environments. Therefore, we propose a novel network anomaly detection model, STRAD. We use Word2vec and Damped Incremental Statistics algorithm for spatiotemporal features extraction, latent space compression (LSC) for feature vectors compression and an unsupervised one-class classifier for anomaly detection. Our evaluations show that STRAD has a better performance than other state of the art algorithms.
What problem does this paper attempt to address?