Improve IDS Detection Efficiency based on Sequence-to-Sequence Model

碩士 === 國立成功大學 === 電腦與通信工程研究所 === 107 === To prevent users from malware intrusion, many kinds of defense system are used, especially Intrusion Detection System (IDS), an important role in cybersecurity area. Most of network managements use network-based IDS(NIDS) to alert network attacks. However, NI...

Full description

Bibliographic Details
Main Authors: Cheng-HsuangLo, 羅政翔
Other Authors: Jung-Shian Li
Format: Others
Language:zh-TW
Published: 2019
Online Access:http://ndltd.ncl.edu.tw/handle/sw76qz
id ndltd-TW-107NCKU5652053
record_format oai_dc
spelling ndltd-TW-107NCKU56520532019-10-26T06:24:15Z http://ndltd.ncl.edu.tw/handle/sw76qz Improve IDS Detection Efficiency based on Sequence-to-Sequence Model 利用從序列到序列模型改善入侵偵測系統之惡意入侵偵測能力 Cheng-HsuangLo 羅政翔 碩士 國立成功大學 電腦與通信工程研究所 107 To prevent users from malware intrusion, many kinds of defense system are used, especially Intrusion Detection System (IDS), an important role in cybersecurity area. Most of network managements use network-based IDS(NIDS) to alert network attacks. However, NIDS suffers variety and quick-changing malwares and NIDS cannot identify the attacks fast and correctly. Many machine learning algorithms are used in NIDS to improve the detection rate of malware, but to our knowledge, the efficiency is not fast and correct enough. We can improve the IDS detection efficiency by two methods: Novel dataset and suited algorithms. We proposed a new method based on deep learning technology and shown good performance for intrusion detection. We use random forest (RF) to rank and choose features in CICIDS2017 datasets, and embed the high dimension features to low dimension, then input these data to the deep neural network model called Sequence to Sequence. By the intrusion detection experiment, we finally get 99.93% on accuracy and 0.3% on false alert rate. Jung-Shian Li 李忠憲 2019 學位論文 ; thesis 61 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立成功大學 === 電腦與通信工程研究所 === 107 === To prevent users from malware intrusion, many kinds of defense system are used, especially Intrusion Detection System (IDS), an important role in cybersecurity area. Most of network managements use network-based IDS(NIDS) to alert network attacks. However, NIDS suffers variety and quick-changing malwares and NIDS cannot identify the attacks fast and correctly. Many machine learning algorithms are used in NIDS to improve the detection rate of malware, but to our knowledge, the efficiency is not fast and correct enough. We can improve the IDS detection efficiency by two methods: Novel dataset and suited algorithms. We proposed a new method based on deep learning technology and shown good performance for intrusion detection. We use random forest (RF) to rank and choose features in CICIDS2017 datasets, and embed the high dimension features to low dimension, then input these data to the deep neural network model called Sequence to Sequence. By the intrusion detection experiment, we finally get 99.93% on accuracy and 0.3% on false alert rate.
author2 Jung-Shian Li
author_facet Jung-Shian Li
Cheng-HsuangLo
羅政翔
author Cheng-HsuangLo
羅政翔
spellingShingle Cheng-HsuangLo
羅政翔
Improve IDS Detection Efficiency based on Sequence-to-Sequence Model
author_sort Cheng-HsuangLo
title Improve IDS Detection Efficiency based on Sequence-to-Sequence Model
title_short Improve IDS Detection Efficiency based on Sequence-to-Sequence Model
title_full Improve IDS Detection Efficiency based on Sequence-to-Sequence Model
title_fullStr Improve IDS Detection Efficiency based on Sequence-to-Sequence Model
title_full_unstemmed Improve IDS Detection Efficiency based on Sequence-to-Sequence Model
title_sort improve ids detection efficiency based on sequence-to-sequence model
publishDate 2019
url http://ndltd.ncl.edu.tw/handle/sw76qz
work_keys_str_mv AT chenghsuanglo improveidsdetectionefficiencybasedonsequencetosequencemodel
AT luózhèngxiáng improveidsdetectionefficiencybasedonsequencetosequencemodel
AT chenghsuanglo lìyòngcóngxùlièdàoxùlièmóxínggǎishànrùqīnzhēncèxìtǒngzhīèyìrùqīnzhēncènénglì
AT luózhèngxiáng lìyòngcóngxùlièdàoxùlièmóxínggǎishànrùqīnzhēncèxìtǒngzhīèyìrùqīnzhēncènénglì
_version_ 1719279708313485312