With the increasing complexity and volume of network traffic, accurate detection of malicious network attacks by machine learning-based network intrusion detection systems (NIDSs) remains a challenging task due to imbalanced network traffic. Conventional machine learning algorithms prioritize high overall accuracy without considering class imbalances. To address this issue, we propose ConFlow, a contrastive learning method for network intrusion detection. ConFlow leverages the Dropout layer to obtain two different vector representations of the same traffic, applying supervised contrast loss and cross-entropy loss during training. Experimental results on the ISCX-IDS2012 and CSE-CIC-IDS2017 datasets show that ConFlow outperforms other methods, especially in few-shot learning scenarios, and exhibits high generalization and robustness in real network environments. Our proposed method has significant practical implications for building an intrusion detection system with high accuracy and low false positive rates.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ConFlow: Contrast Network Flow Improving Class-Imbalanced Learning in Network Intrusion Detection

  • Lan Liu,
  • Pengcheng Wang,
  • Jianliang Ruan,
  • Jun Lin,
  • Junhan Hu

摘要

With the increasing complexity and volume of network traffic, accurate detection of malicious network attacks by machine learning-based network intrusion detection systems (NIDSs) remains a challenging task due to imbalanced network traffic. Conventional machine learning algorithms prioritize high overall accuracy without considering class imbalances. To address this issue, we propose ConFlow, a contrastive learning method for network intrusion detection. ConFlow leverages the Dropout layer to obtain two different vector representations of the same traffic, applying supervised contrast loss and cross-entropy loss during training. Experimental results on the ISCX-IDS2012 and CSE-CIC-IDS2017 datasets show that ConFlow outperforms other methods, especially in few-shot learning scenarios, and exhibits high generalization and robustness in real network environments. Our proposed method has significant practical implications for building an intrusion detection system with high accuracy and low false positive rates.