Network security situation assessment with network attack behavior classification

被引:6
|
作者
Yang, Hongyu [1 ,2 ]
Zhang, Zixin [2 ]
Xie, Lixia [2 ]
Zhang, Liang [3 ]
机构
[1] Civil Aviat Univ China, Sch Safety Sci & Engn, Tianjin 300300, Peoples R China
[2] Civil Aviat Univ China, Sch Comp Sci & Technol, Tianjin 300300, Peoples R China
[3] Univ Arizona, Sch Informat, Tucson, AZ USA
基金
中国国家自然科学基金;
关键词
attention mechanism; bidirectional gate recurrent unit; network attack behavior classification; network security situation assessment; parallel feature extraction;
D O I
10.1002/int.22867
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
To solve the problems that existing network security situation assessment (NSSA) methods are difficult to extract features and have poor timeliness, an NSSA method with network attack behavior classification (NABC) is proposed. First, an NABC model is designed. The model combines features and advantages of a parallel feature extraction network (PFEN), a bidirectional gate recurrent unit (BiGRU), and the attention mechanism (ATT). The PFEN module is composed of parallel sparse autoencoders which extract key data from different network attack behaviors. The BiGRU module gets the time-series relationship from the state of three different time periods, finds potential representation rules from network attack behaviors. The ATT module pays more attention to the network traffic key information and improves the NABC accuracy. Second, the NABC detects and classifies attacks from network behaviors, the occurrence number of each attack behavior, and the error probability matrix are counted. Finally, the occurrence number of each attack behavior is corrected according to the error probability matrix, and the network security situation value is calculated through combining the severity factor of each attack behavior. The experimental results show that the precision and recall of the NABC model are improved by 5.28% and 5.65%, respectively, compared with the conventional method. The comparison experiment with the classical situation assessment method also proves that the proposed method can assess the overall situation of network security more effectively and comprehensively.
引用
收藏
页码:6909 / 6927
页数:19
相关论文
共 50 条
  • [1] A Network Security Situation Assessment Method Based On Attack Intention Perception
    Kou Guang
    Tang Guangming
    Ding Xia
    Wang Shuo
    Wang Kun
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 1138 - 1142
  • [2] A Novel Approach to Network Security Situation Assessment Based on Attack Confidence
    Liu, Donghang
    Dong, Lihua
    Lv, Shaoqing
    Dong, Ying
    He, Fannv
    Wu, Chensi
    Zhang, Yuqing
    Ma, Hua
    [J]. NETWORK AND SYSTEM SECURITY, 2017, 10394 : 450 - 463
  • [3] Network Security Situation Analysis Aimed at Distributed Attack
    Fu Yanming
    Chen Wen
    Li Lin
    Pan Yanxian
    [J]. MATERIALS SCIENCE AND ENGINEERING, PTS 1-2, 2011, 179-180 : 1005 - +
  • [4] Research on attack graph generation for network security situation
    Wang, Yanbo
    Wang, Huiqiang
    Zhao, Chao
    Zhang, Yushu
    Yu, Ming
    [J]. Advances in Intelligent Systems and Computing, 2013, 212 : 1147 - 1154
  • [5] Network Information Security Situation Assessment Based on Bayesian Network
    Wang Xing-zhu
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (05): : 129 - 137
  • [6] An efficient method for network security situation assessment
    Tao, Xiaoling
    Kong, Kaichuan
    Zhao, Feng
    Cheng, Siyan
    Wang, Sufang
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2020, 16 (11)
  • [7] Research on Network Security Situation Assessment Method
    Gao, Yuan
    Wen, Jin
    Chen, Pu
    Wang, Zhiqiang
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND NETWORKS, VOL III, CENET 2023, 2024, 1127 : 140 - 152
  • [8] Network Security Situation Assessment Based on HMM
    Zhang, Boyun
    Chen, Zhigang
    Wang, Shulin
    Yan, Xiai
    Zhang, Dingxing
    Fan, Qiang
    [J]. ADVANCED INTELLIGENT COMPUTING THEORIES AND APPLICATIONS: WITH ASPECTS OF ARTIFICIAL INTELLIGENCE, 2012, 6839 : 387 - +
  • [9] Network Security Situation Assessment: A review and discussion
    Leau, Yu-Beng
    Manickam, Selvakumar
    Chong, Yung-Wey
    [J]. Lecture Notes in Electrical Engineering, 2015, 339 : 407 - 414
  • [10] Research on Network Security Situation Assessment Method
    Jing, Sen
    Li, Min
    Si, Guanlin
    Gao, Ranxin
    [J]. 2022 IEEE 6TH ADVANCED INFORMATION TECHNOLOGY, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (IAEAC), 2022, : 1912 - 1915