信息网络安全 ›› 2026, Vol. 26 ›› Issue (6): 913-924.doi: 10.3969/j.issn.1671-1122.2026.06.006
张三1,2(
), 马宇航1, 周世良1, 丁倩文1, 周曼丽1
收稿日期:2026-01-10
出版日期:2026-06-10
发布日期:2026-07-27
作者简介:张三(1983—),男,河南,副教授,博士,主要研究方向为网络安全、图像分析与处理|马宇航(2000—),男,陕西,硕士研究生,主要研究方向为网络安全态势感知|周世良(2001—),男,宁夏,硕士研究生,主要研究方向为网络安全态势感知|丁倩文(2000—),女,河南,硕士研究生,主要研究方向为网络安全态势感知、水下图像增强|周曼丽(2001—),女,陕西,硕士研究生,主要研究方向为网络安全态势感知、水下图像增强
基金资助:
ZHANG San1,2(
), MA Yuhang1, ZHOU Shiliang1, DING Qianwen1, ZHOU Manli1
Received:2026-01-10
Online:2026-06-10
Published:2026-07-27
摘要:
网络流量分类是网络安全管理不可或缺的基础支撑技术之一,具有至关重要的理论价值与现实意义。针对现有分类方法在动态网络安全环境中特征依赖性高、分类精度低和准确率不足等问题,文章提出一种基于双路径门控混合专家系统(MoE)的网络流量分类方法,通过动态门控网络自适应激活不同专家网络,实现了对网络异构流量的准确高效分类。该方法在CIC-IDS2017数据集上的实验结果表明,相较于现有网络流量分类方法,模型效果在各个方面都有巨大提升,达到了99%的准确率,误报率也极低,验证了模型的鲁棒性和准确性,该方法为复杂动态网络环境中的流量分类提供了一种轻量化、自适应的解决方法。
中图分类号:
张三, 马宇航, 周世良, 丁倩文, 周曼丽. 基于迁移学习与改进OpenMax算法的开集射频指纹识别研究[J]. 信息网络安全, 2026, 26(6): 913-924.
ZHANG San, MA Yuhang, ZHOU Shiliang, DING Qianwen, ZHOU Manli. The Network Traffic Classification Method Based on the MoE[J]. Netinfo Security, 2026, 26(6): 913-924.
| [1] | LU Guoli, WANG Guangqing. Research Review on Network Traffic Classification Technology Based on Four-Layer Classification Model[J]. China Sciencepaper, 2025(20): 406-417. |
| 陆国丽, 王光庆. 基于四层分类模型的网络流量分类技术研究综述[J]. 中国科技论文, 2025(20):406-417. | |
| [2] | ZHAO Changqing, LIAO Lingxia, CHEN Guomin, et al. Condensation of Data and Knowledge for Network Traffic Classification: Techniques, Applications, and Open Issues[J]. Sensors, 2025 (25) :2368-2376. |
| [3] | YANG Hongyu, ZHANG Haohao, CHENG Xiang. Anomaly Traffic Detection Method Based on Multi-scale Attention Feature Enhancement[J]. Journal on Communications, 2024 (45): 88-105. |
| 杨宏宇, 张豪豪, 成翔. 基于多尺度注意力特征增强的异常流量检测方法[J]. 通信学报, 2024(45):88-105. | |
| [4] | LIANG Yulong, WANG Fei, CHEN Shuhui, et al. STI: A Self-Evolutive Traffic Identification System for Unknown Applications Based on Improved Random Forest[J]. Computer Communications, 2024 (219): 64-75. |
| [5] | LU Zikui, CHANG Zixi, HE Mingshu, et al. Zero-Shot Traffic Identification with Attribute and Graph-Based Representations for Edge Computing[EB/OL]. (2024-11-24)[2025-12-05]. https://doi.org/10.3390/s25020545. |
| [6] | DONG Wenqi, YU Jing, LIN Xinjie, et al. Deep Learning and Pre-Training Technology for Encrypted Traffic Classification: A Comprehensive Review[J]. Neurocomputing, 2025 (617): 326-339. |
| [7] | CAI Weilin, JIANG Juyong, WANG Fan, et al. A Survey on Mixture of Experts in Large Language Models[J]. IEEE Transactions on Knowledge and Data Engineering, 2025 (37): 3896-3915. |
| [8] | WANG Ziyi. Anomaly Detection and Analysis of Network Traffic for Autonomous and Controllable Server Software Based on Machine Learning[J]. Electronic Technology, 2025(54): 320-321. |
| 王子宜. 基于机器学习的自主可控服务器软件网络流量异常检测分析[J]. 电子技术, 2025(54):320-321. | |
| [9] | GU Jie, LU Shan. An Effective Intrusion Detection Approach Using SVM with Naïve Bayes Feature Embedding[J]. Computers & Security, 2021(103): 102-158. |
| [10] | XU Binhan, CHEN Shuyu, ZHANG Hancui, et al. Incremental K-NN SVM Method in Intrusion Detection[C]// IEEE. 2017 8th IEEE International Conference on Software Engineering and Service Science (ICSESS). New York: IEEE, 2017: 712-717. |
| [11] | ACI C I, MUTLU G, OZEN M, et al. Enhanced Multi-Class Driver Injury Severity Prediction Using a Hybrid Deep Learning and Random Forest Approach[J]. Applied Sciences-Basel, 2025, 15(3):1569-1586. |
| [12] | WU Chen. Massive Logs Security Analysis System Based on Storm and Hadoop Technology[J]. Xi'an University of Posts and Telecommunications, 2016(2): 119-126. |
| 吴晨. 一种基于Storm及Hadoop的海量日志安全分析系统[J]. 西安邮电大学学报, 2016(2):119-126. | |
| [13] | SUN Yuhao, PENG Hao, CHEN Yingjun, et al. A Transformer Based Malicious Traffic Detection Method in Android Mobile Networks[C]//Springer. Advanced Data Mining and Applications, Part III. Heidelberg: Springer, 2025: 370-385. |
| [14] | WU Zhijun, LIANG Cheng, LI Yuqi. Intrusion Detection Method Based on Deep Learning[C]//IEEE. 2021 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA/BD Cloud/Social Com/Sustain Com). New York: IEEE, 2021: 445-452. |
| [15] | HALBOUNI A, GUNAWAN T S, HABAEBEI M H, et al. CNN-LSTM: Hybrid Deep Neural Network for Network Intrusion Detection System[J]. IEEE Access, 2022 (10) :99837-99849. |
| [16] | Qi Zijian, LIU Yi. A Malicious Network Traffic Detection Method Based on Bidirectional GRU and CNN[J]. Computer Applications and Software, 2024 (41) :334-340. |
| 戚子健, 柳毅. 基于双向GRU和CNN的恶意网络流量检测方法[J]. 计算机应用与软件Computer Applications and Software, 2024(41):334-340. | |
| [17] | LONG Hancheng, LI Huanzhou, TANG Zhangguo, et al. BOA-ACRF: An Intrusion Detection Method for Data Imbalance Problems[J]. Computers & Electrical Engineering, 2025 (124):110309-110320. |
| [18] | JACOBS R A, JORDAN M I, NOWLAN S J, et al. Adaptive Mixtures of Local Experts[J]. Neural Computation, 1991 (3): 79-87. |
| [19] | SHAZEER N, MIRHOSEINI A, MAZIARZ K, et al. Outrageously Large Neural Networks: The Sparsely-Gated Mixture-of-Experts Layer[EB/OL]. (2017-01-23)[2025-12-05]. https://arxiv.org/abs/1701.06538 |
| [20] | FEDUS W, ZOPH B, SHAZEER N, et al. Switch Transformers: Scaling to Trillion Parameter Models with Simple and Efficient Sparsity[EB/OL]. (2021-01-11)[2025-12-05]. https://arxiv.org/abs/2101.03961 |
| [21] | PEI Jiahuan, YAN Guojun, DE RIJKE M, et al. Mixture-of-Languages Routing for Multilingual Dialogues[J]. ACM Transactions on Information Systems, 2024, 42(6):1-33. |
| [22] | DRIESS D, XIA Fei, SAJJADI M S M, et al. PaLM-E: An Embodied Multimodal Language Model, International Conference on Machine Learning[EB/OL]. (2023-03-06)[2025-12-05]. https://arxiv.org/abs/2303.03378 |
| [23] | DU Nan, HUANG Yanping, DAI A M, et al. GLaM: Efficient Scaling of Language Models with Mixture-of-Experts[EB/OL]. (2021-12-13) [2025-12-05]. https://arxiv.org/abs/2112.06905 |
| [24] | CHEN Bowen, CHEN Keyan, YANG Mohan, et al. Heterogeneous Mixture of Experts for Remote Sensing Image Super-Resolution[J]. IEEE Geoscience and Remote Sensing Letters, 2025, 22: 1-5. |
| [25] | XU Zhi, FU Zhengyong. Using Mixture of Experts to Accelerate Dataset Distillation[J]. Journal Of Visual Communication And Image Representation, 2024, 100:104-137. |
| [26] | PANDEY S, CHOPRA R, BHAT S M, et al. Hecto: Modular Sparse Experts for Adaptive and Interpretable Reasoning[EB/OL]. (2025-06-28)[2025-12-05]. https://arxiv.org/abs/2506.22919 |
| [27] | WANG Yimeng, YANG Zhiyao, CHE Xiangjiu. A Hierarchical Mixture-of-Experts Framework for Few Labeled Node Classification[J]. Neural Networks, 2025, 188: 267-285. |
| [28] | GAO Yifei, XU Ning, TIAN Hongshuo, et al. Mixture of Causal Experts: A Causal Perspective to Build Dual-Level Mixture-of-Experts Models[J]. Expert Systems with Applications, 2025, 280: 408-422. |
| [29] | MANOCCHIO L D, LAYEGHY S, GALLAGHER M, et al. An Empirical Evaluation of Preprocessing Methods for Machine Learning Based Network Intrusion Detection Systems[J]. Engineering Applications of Artificial Intelligence, 2025, 158: 269-289. |
| [30] | ROOKARD C, KHOJANDI A. Unsupervised Machine Learning for Cybersecurity Anomaly Detection in Traditional and Software-Defined Networking Environments[J]. IEEE Transactions on Network and Service Management, 2025 (22) :1129-1144. |
| [31] | USTEBAY S, TURGUT Z, AYDIN M A. Cyber Attack Detection by Using Neural Network Approaches: Shallow Neural Network, Deep Neural Network and Autoencoder[C]//Springer. The 26th International Conference on Computer Networks. Heidelberg: Springer, 2019: 144-155. |
| [32] | DONG Changyu, RUSSELLO G, DULAY N. Shared and Searchable Encrypted Data for Untrusted Servers[C]//Springer. Data and Applications Security XXII. Heidelberg: Springer, 2008: 127-143. |
| [33] | CUI Wenchao, LU Qiong, QURESHI A M, et al. An Adaptive LeNet-5 Model for Anomaly Detection[J]. Information Security Journal: A Global Perspective, 2021 (30):19-29. |
| [34] | YANG Yahua, ZHAO Junfeng, DU Huanfu, et al. Shear-Wave Velocity Prediction by CNN-GRU Fusion Network Based on the Self-Attention Mechanism[J]. IEEE Geoscience and Remote Sensing Letters, 2025, 22: 1-5. |
| [35] | LI Yulian, SU Yang. A Network Traffic Anomaly Classification Model Based on Self-Attention Mechanism and Convolutional Gated Recurrent Unit[J]. IEEE Access, 2025, 13: 134804-134821. |
| [36] | KAMAL H, MASHALY M. Advanced Hybrid Transformer-CNN Deep Learning Model for Effective Intrusion Detection Systems with Class Imbalance Mitigation Using Resampling Techniques[J]. Future Internet, 2024, 16(12): 481-495. |
| [37] | RAJATHI C, RUKMANI P. Hybrid Learning Model for Intrusion Detection System: A Combination of Parametric and Non-Parametric Classifiers[J]. Alexandria Engineering Journal, 2025, 112: 384-396. |
| [1] | 顾兆军, 郝锦涛, 周景贤. 基于改进双线性卷积神经网络的恶意网络流量分类算法[J]. 信息网络安全, 2020, 20(10): 67-74. |
| [2] | 魏书宁, 陈幸如, 唐勇, 刘慧. AR-HELM算法在网络流量分类中的应用研究[J]. 信息网络安全, 2018, 18(1): 9-14. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||