支持向量机
计算机科学
异常检测
人工智能
分类器(UML)
机器学习
交通分类
模式识别(心理学)
数据挖掘
核方法
核(代数)
网络数据包
数学
计算机网络
组合数学
作者
Qian Ma,Cong Sun,Baojiang Cui,Xiaohui Jin
标识
DOI:10.1016/j.cose.2021.102215
摘要
Machine learning models are widely used for anomaly detection in network traffic. Effective transformation of the raw traffic data into mathematical expressions and hyper-parameter adjustment are two important steps before training the machine learning classifier, which is used to predict whether the unknown traffic is normal or abnormal. In this paper, a novel model SVM-L is proposed for anomaly detection in network traffic. In particular, raw URLs are treated as natural language, and then transformed into mathematical vectors via statistical laws and natural language processing technique. They are used as the training data for the traffic classifier, the kernel Support Vector Machine (SVM). Based on the idea of the dual formulation of kernel SVM and Linear Discriminant Analysis (LDA), we propose an optimization model to adjust the hyper-parameter of the classifier. The corresponding problem is simply one-dimensional, and is easily solved by the golden section method. Numerical tests indicate that the proposed model achieves more than 99% accuracy on all tested datasets, and outperforms the state of the arts in terms of standard evaluation measurements.
科研通智能强力驱动
Strongly Powered by AbleSci AI