信息网络安全 ›› 2024, Vol. 24 ›› Issue (9): 1458-1469.doi: 10.3969/j.issn.1671-1122.2024.09.013

• 技术研究 • 上一篇    下一篇

基于多门控混合专家模型的网络异常流量识别与防御模型

郭永进1,2, 黄河俊1,2()   

  1. 1.上海开放大学,上海 200433
    2.上海教育软件发展有限公司,上海 200082
  • 收稿日期:2024-06-02 出版日期:2024-09-10 发布日期:2024-09-27
  • 通讯作者: 黄河俊 aachouchou@163.com
  • 作者简介:郭永进(1969—),男,河南,硕士,主要研究方向为大数据分析、网络安全|黄河俊(1978—),男,浙江,硕士,主要研究方向为机器学习、网络安全

Anomaly Traffic Identification and Defense Model in Networks Based on the Multi-Gate Mixture of Experts

GUO Yongjin1,2, HUANG Hejun1,2()   

  1. 1. Shanghai Open University, Shanghai 200433, China
    2. Shanghai Education Software Development Company, Shanghai 200082, China
  • Received:2024-06-02 Online:2024-09-10 Published:2024-09-27

摘要:

文章提出一种基于多门控混合专家模型的网络异常流量识别与防御模型,该模型适用于业务高峰期间混杂攻击流量的场景。首先,多门控混合专家模型对网络流量进行实时监测和异常识别,区分由业务需求导致的正常流量峰值和异常流量,减少误报,系统将检测到的异常流量作为输入,生成针对性的防御策略。然后,多门控混合专家模型对异常流量识别和防御策略生成专家模型进行协调,提高系统的识别精准度和策略生成的有效性。在实际业务场景中获取的数据集上的实验结果表明,该模型识别准确率和防御效果优于主流的机器学习模型,能够准确识别出混杂在业务高峰期间的异常攻击流量,并生成合适的防御策略。

关键词: 异常流量识别, 防御策略生成, 混合专家模型, 隐蔽攻击

Abstract:

This paper proposed a big data network anomaly traffic identification and defense strategy generation model based on the multi-gate mixture of experts(MMoE) model. This model is particularly suitable for scenarios involving mixed attack traffic during peak business periods. First, the MMoE model conducted real-time monitoring and anomaly identification of network traffic, distinguishing between normal traffic peaks caused by business demands and genuine anomalous traffic, effectively reducing false alarms. When anomalous traffic was detected, the system used it as input to generate targeted defense strategies. Secondly, the MMoE model coordinated the expert models for anomaly detection and defense strategy generation, enhancing the precision of identification and the effectiveness of strategy generation. Experimental results on datasets obtained from real business scenarios show that the identification accuracy and defense effect of the model proposed in this study are better than mainstream machine learning models and can accurately identify abnormal attack traffic mixed during business peaks and generate appropriate defense strategies.

Key words: anomaly traffic identification, defense strategy generation, mixture of experts model, stealth attack

中图分类号: