Journal of System Simulation ›› 2021, Vol. 33 ›› Issue (3): 679-689.doi: 10.16182/j.issn1004731x.joss.19-0573

Previous Articles     Next Articles

Network Traffic Anomaly Detection Method for Imbalanced Data

Dong Shuqin1,2, Zhang Bin1,2   

  1. 1. SSF Information Engineering University, Zhengzhou 450001, China;
    2. Henan Key Laboratory of Information Security, Zhengzhou 450001, China
  • Received:2019-11-01 Revised:2020-01-17 Online:2021-03-18 Published:2021-03-18

Abstract: Aiming at the poor detection performances caused by the low feature extraction accuracy of rare traffic attacks from scarce samples, a network traffic anomaly detection method for imbalanced data is proposed. A traffic anomaly detection model is designed, in which the traffic features in different feature spaces are learned by alternating activation functions, architectures, corrupted rates and dropout rates of stacked denoising autoencoder (SDA), and the low accuracy in extracting features of rare traffic attacks in a single space is solved. A batch normalization algorithm is designed, and the Adam algorithm is adopted to train parameters of SDAs to extract multifarious traffic features. The Softmax classifier is trained by combining the extracted features, so that the rare traffic attacks can be detected with a high detection precision. The experimental results show that, compared with the methods based on random forest, single SDA and feature fusion, the proposed method has higher classification accuracy, higher detection rate of rare traffic attacks and the detection performances are stable.

Key words: anomaly detection, imbalanced traffic classification, deep learning, stacked denoising autoencoder

CLC Number: