基于改进GraphSAGE的网络攻击检测OA
Network Attack Detection Based on Improved GraphSAGE
基于深度学习的网络攻击检测是对欧几里得数据进行建模,无法学习攻击数据中的结构特征.为此,提出一种基于改进图采样与聚合(graph sample and aggregate,GraphSAGE)的网络攻击检测算法.首先,将攻击数据从平面结构转换为图结构数据.其次,对 GraphSAGE算法进行了改进,包括在消息传递阶段融合节点和边的特征,同时在消息聚合过程中考虑不同源节点对目标节点的影响程度,并在边嵌入生成时引入残差学习机制.在两个公开网络攻击数据集上的实验结果表明,在二分类情况下,所提算法的总体性能优于 E-GraphSAGE、LSTM、RNN、CNN 算法;在多分类情况下,所提算法在大多数攻击类型上的 F1 值高于对比算法.
Network attack detection based on deep learning was modeled on Euclidean data and couldn′t capture the structural features within attack data.To address this issue,a network attack detection algo-rithm based on improved graph sample and aggregate(GraphSAGE)was proposed.Firstly,the attack data was initially transformed from a flat structure into a graph structure.Secondly,the GraphSAGE algo-rithm was enhanced in several ways,including the fusion of node and edge features during the message passing phase,consideration of the impact of different source nodes on the target node during the message aggregation phase,and the introduction of residual learning mechanism during the edge embedding gener-ation.The experimental results on two public network attack datasets showed that the overall performance of the proposed algorithm was superior to that of the E-GraphSAGE,LSTM,RNN,and CNN algorithms in binary classification scenarios.And the F1 values of the proposed algorithm were higher than compari-son algorithms on most attack categories in multi classification scenarios.
闫彦彤;于文涛;李丽红;方伟
华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210
信息技术与安全科学
网络攻击检测深度学习图神经网络图采样与聚合注意力机制
network attack detectiondeep learninggraph neural networkgraph sample and aggre-gateattention mechanism
《郑州大学学报(理学版)》 2026 (1)
27-34,8
河北省数据科学与应用重点实验室项目(10120201)唐山市数据科学重点实验室项目(10120301)
评论