信息网络安全 ›› 2024, Vol. 24 ›› Issue (11): 1675-1684.doi: 10.3969/j.issn.1671-1122.2024.11.007

• 入选论文 • 上一篇    下一篇

基于溯因学习的无监督网络流量异常检测

胡文涛, 徐靖凯, 丁伟杰()   

  1. 浙江警察学院计算机与信息安全系,杭州 310053
  • 收稿日期:2024-06-20 出版日期:2024-11-10 发布日期:2024-11-21
  • 通讯作者: 丁伟杰 dingweijie@zjjcxy.cn
  • 作者简介:胡文涛(1995—),男,浙江,讲师,博士,主要研究方向为人工智能安全和数据治理|徐靖凯(2002—),男,浙江,本科,主要研究方向为人工智能安全|丁伟杰(1980—),男,河南,教授,博士,主要研究方向为人工智能安全和智慧警务
  • 基金资助:
    2024年度浙江省教育科学规划课题(2024SCG316)

Unsupervised Network Traffic Anomaly Detection Based on Abductive Learning

HU Wentao, XU Jingkai, DING Weijie()   

  1. Department of Computer and Information Security, Zhejiang Police College, Hangzhou 310053, China
  • Received:2024-06-20 Online:2024-11-10 Published:2024-11-21

摘要:

当前计算机网络流量异常检测面临缺乏标注信息的挑战,同时用户需要自行选择合适的技术并调整参数,但没有标签可用于交叉验证。为此,文章提出一种基于溯因学习的无监督网络流量异常检测(ABL-ATD)模型。该模型通过自动生成伪标签,并利用演绎与一致性验证生成高质量标签,避免人工干预。ABL-ATD从多种无监督异常检测模型中提取有效信号,并通过验证与修正,可靠区分异常流量和正常流量。实验结果表明,该模型在多个数据集上展现出与使用真实标签训练的监督学习模型相当的准确性。

关键词: 异常流量检测, 无监督学习, 溯因学习

Abstract:

The current challenge in computer network traffic anomaly detection is the lack of labeled information, while users must select appropriate technologies and adjust parameters without any labels for cross-validation. To address this issue, this paper proposed an abductive learning-based anomaly traffic detection (ABL-ATD) model, which operated in an unsupervised manner. This model automatically generated pseudo-labels and utilized deductive reasoning and consistency verification to produce high-quality labels, thereby avoiding manual intervention. The innovation of ABL-ATD lied in its ability to extract effective signals from multiple unsupervised anomaly detection models and reliably distinguish between anomalous and normal traffic through validation and correction. Experimental results demonstrate that this model exhibits accuracy comparable to that of supervised learning models trained with real labels across multiple datasets.

Key words: traffic anomaly detection, unsupervised learning, abductive learning

中图分类号: