論文名稱(外文):Design and Implementation of Intrusion Detection Classification Based on Neural Network
外文關鍵詞:Intrusion DetectionDeep LearningRecurrent Neural Network
本論文以KDD’99及NSL-KDD做為資料集,並建構LSTM、RNN、CNN+LSTM及CNN+RNN四種模型,將訓練集進行資料預處理後,輸入模型進行訓練,判斷該連線是否為惡意攻擊的二元分類。另外也進行多元分類實驗,除正常連線外,將惡意攻擊分為四大類:DoS、Probe、R2L(Remote to Local)、U2R(User to Root)。其中CNN+LSTM在各項實驗都有最高的準確率,針對KDD’99資料集,其二元分類準確率95.37%,多元分類準確率為93.56%,而NSL-KDD資料集其二元分類準確率為81.43%,多元分類準確率為76.98%。

With the development of Internet, life is inseparable from Internet. No matter it is any system, mobile device, or network device, there are always weaknesses that can easily become the target of intrusion. Therefore, how to construct a security mechanism on the network has become an important topic, and intrusion detection is one of the important functions. In recent years, the advancement of hardware has led to further development in the field of AI, and more and more intrusion detection methods based on machine learning have been developed. It is hoped that machine learning can reveal rules that are difficult to find in malicious attacks to achieve more accurate classification.
This paper takes KDD'99 and NSL-KDD as the data set, and constructs four models: LSTM, RNN, CNN+LSTM and CNN+RNN. After preprocessing the training set, input the model for training and determine the connection whether it is a malicious attacks The malicious attacks are categorized into four major groups: DoS, Probe, R2L(Remote to Local), and U2R(User to Root). Among all the models, CNN+LSTM has the highest accuracy rate in all experiments. In the KDD'99 classification experiment, the accuracy rate of binary classification is 95.37% and the accuracy rate of multi-class classification is 93.56%, while the accuracy rate of NSL-KDD's binary classification is 81.43% and the accuracy rate of multi-class classification is 76.98%.

