信息网络安全 ›› 2025, Vol. 25 ›› Issue (2): 240-248.doi: 10.3969/j.issn.1671-1122.2025.02.005

• 理论研究 • 上一篇    下一篇

基于残差卷积神经网络的网络攻击检测技术研究

张双全, 殷中豪, 张环, 高鹏()   

  1. 南京理工大学网络空间安全学院,南京 210094
  • 收稿日期:2024-11-28 出版日期:2025-02-10 发布日期:2025-03-07
  • 通讯作者: 高鹏 E-mail:gao.itslab@gmail.com
  • 作者简介:张双全(1991—),男,河南,讲师,博士,CCF会员,主要研究方向为网络安全、深度学习|殷中豪(2002—),男,江苏,本科,主要研究方向为网络安全|张环(2004—),女,江苏,本科,主要研究方向为数据科学与数据安全|高鹏(1982—),男,江苏,副教授,博士,CCF会员,主要研究方向为网络安全
  • 基金资助:
    国家自然科学基金(62302218);江苏省科技厅重点研发计划(BE2022081);江苏省前沿技术研发计划(BF2024071)

Research on Cyber Attack Detection Technology Based on Residual Convolutional Neural Network

ZHANG Shuangquan, YIN Zhonghao, ZHANG Huan, GAO Peng()   

  1. School of Cyber Science and Engineering, Nanjing University of Science and Technology, Nanjing 210094, China
  • Received:2024-11-28 Online:2025-02-10 Published:2025-03-07

摘要:

随着我国网络安全能力逐渐提高,网络攻击的数量和复杂性也逐渐增长,网络攻击检测技术面临着巨大挑战。为了提高网络攻击检测的准确性,文章提出一种基于残差卷积神经网络的网络攻击检测模型HaoResNet,并在USTC-TFC2016数据集上对HaoResNet模型进行测试。首先,HaoResNet模型将pcap流量文件转化为灰度图像;然后,对正常流量和恶意流量进行二分类、十分类和二十分类实验。实验结果表明,HaoResNet模型在二分类任务上的精确率达到100%,正常流量十分类任务上的精确率为99%,恶意流量十分类任务上的精确率为98%,二十分类任务上的精确率为98%。与现有模型相比,HaoResNet模型在二分类任务上实现了更高的检测精度。

关键词: 网络攻击检测, 卷积神经网络, 恶意流量, 多分类

Abstract:

As our cyber security capabilities are gradually improving, the number and complexity of network attacks are also gradually increasing, and cyber attack detection technology are facing greater challenges. To improve the accuracy of cyber attack detection, this article proposed a cyber attack detection model HaoResNet based on residual convolutional neural network and tested the HaoResNet model on the USTC-TFC2016 dataset. First, HaoResNet model converted the pcap traffic file into a grayscale image, and then performed 2-classification, 10-classification, and 20-classification experiments on normal and malicious traffic. The experimental results demonstrate that HaoResNet achieves 100% accuracy on the 2-classification task, 99% accuracy on the normal traffic 10-classifier task, 98% accuracy on the malicious traffic 10- classification task, and 98% accuracy on the 20-classification task. Compared with existing models, HaoResNet achieves the higher detection precision on the 2- classification task.

Key words: cyber attack detection, convolutional neural network, malicious traffic, multi-classification

中图分类号: