Computer Science ›› 2022, Vol. 49 ›› Issue (6A): 581-587.doi: 10.11896/jsjkx.210400044

Study on Key Technologies of Unknown Network Attack Identification

CAO Yang-chen, ZHU Guo-sheng, SUN Wen-he, WU Shan-chao   

  1. School of Computer and Information Engineering,Hubei University,Wuhan 430062,China
  • Online:2022-06-10 Published:2022-06-08
  • About author:CAO Yang-chen,born in 1996,postgraduate.Her main research interests include machine learning and network traffic analysis.
    ZHU Guo-sheng,born in 1972,Ph.D,professor.His main research interests include next-generation Internet and software-defined networks.
  • Supported by:
    CERNET Innovation Project and Campus Regional Public Opinion Mining and Monitoring System Based on Network Traffic Reconstruction(NGII20170210).

Abstract: Intrusion detection is a technology that proactively defends against attacks in the network and plays a vital role in network management.Traditional intrusion detection technology cannot identify unknown attacks,which is also a problem that has plagued this field for a long time.Aiming at unknown types of intrusion attacks,an unknown attack recognition model combining K-Means and FP-Growth algorithms is proposed to extract the rules of unknown attacks.First,for the data of a mixture of multiple unknown attacks,cluster analysis is performed with K-Means based on the similarity between samples,and the silhouette coefficient is introduced to evaluate the effect of clustering.After the clustering is completed,the same unknown attacks are classified into the same cluster,the feature of unknown attack is manually extracted,the feature data is preprocessed,the continuous feature is discretized,and then the frequent item sets and association rules of the unknown attack data are mined by the FP-Growth algorithm,and finally the rule unknown attack is obtained by analyzing it.The rules of attack are used to detect this type of unknown attack.The results show that the accuracy rate can reach 98.74%,which is higher than that of the related algorithms.

Key words: K-Means, Association rules, FP-Growth, Intrusion detection, Unknown attack

  • TP181
