首页|期刊导航|高师理科学刊|基于LKAN模型的恶意加密流量检测

基于LKAN模型的恶意加密流量检测OA

Malicious encrypted traffic detection based on LKAN model

中文摘要英文摘要

随着网络技术的飞速发展,恶意加密流量已成为网络安全领域的重要威胁.恶意加密流量通过加密技术对恶意数据进行封装,使其难以被传统检测方法识别和拦截.提出一种基于长短期记忆网络(LSTM)和Kolmogorov Arnold Networks(KAN)的恶意加密流量检测模型——LKAN模型.LSTM能有效捕捉流量数据的时序特征,KAN是一种基于函数分解理论的神经网络,能够高效地学习高维数据的复杂结构,LKAN模型结合LSTM和KAN的优势,进行特征提取和分类,实现了对恶意加密流量的准确识别.利用提出的LKAN模型在ISCX-VPN-NonVPN-2016 数据集进行多分类实验,准确率为 0.982 591,表明了模型的有效性,为恶意加密流量检测方法设计提供了一种新思路.

With the rapid development of network technology,malicious encrypted traffic has become an important threat in the field of network security.Malicious encrypted traffic encapsulates malicious data through encryption technology,making it difficult to be identified and intercepted by traditional detection methods.This paper proposes a malicious encrypted traffic detection model named LKAN based on Long Short-Term Memory network(LSTM)and Kolmogorov Arnold Networks(KAN).LSTM can effectively capture the temporal features of traffic data,and KAN is a neural network based on the function decomposition theory,which can efficiently learn the complex structure of high-dimensional data.By combining the advantages of LSTM and KAN,LKAN conducts feature extraction and classification to achieve accurate identification of malicious encrypted traffic.The proposed LKAN model was used to conduct multi-classification experiments on the ISCX-VPN-NonVPN-2016 dataset,achieving an accuracy of 0.982 591,which demonstrates the model's effectiveness and provides a novel approach for designing malicious encrypted traffic detection methods.

邢哲辉;王海珍

齐齐哈尔大学 计算机与控制工程学院,黑龙江 齐齐哈尔 161006||齐齐哈尔大学 黑龙江省重点实验室大数据网络安全检测分析,黑龙江 齐齐哈尔 161006齐齐哈尔大学 计算机与控制工程学院,黑龙江 齐齐哈尔 161006||齐齐哈尔大学 黑龙江省重点实验室大数据网络安全检测分析,黑龙江 齐齐哈尔 161006

信息技术与安全科学

LSTMKAN恶意加密流量检测神经网络

LSTMKANmalicious encrypted traffic detectionneural network

《高师理科学刊》 2026 (2)

29-35,7

黑龙江省教育厅基本科研业务专项(145409442)

10.3969/j.issn.1007-9831.2026.02.006

评论