| 講演抄録/キーワード |
| 講演名 |
2023-03-13 14:40
単語埋め込みとLSTMを用いたパケット単位異常通信分類モデルに関する考察 ○柏原芳克・宮本耕平・飯田昌澄・川中翔太(九大)・韓 燦洙・班 涛・高橋健志(NICT)・竹内純一(九大) ICSS2022-53 |
| 抄録 |
(和) |
近年,ネットワーク上の不正アクセスを検知するシステムであるネットワーク型侵入検知システム(NIDS;network-based intrusion detection system)には,高度なニューラルネットワークの技術を応用したものが登場している. 本研究では,LSTMが時系列情報の学習に強み置いていることをモチベーションに,通信パケット中の文字列の特徴をうまく学習することで,既存のNIDSモデルよりも高精度で通信を分類することを目標としている.先行研究に基づいた単語埋め込みとLSTMを用いたモデルによって,ヘッダーから情報を一部隠した上で分類した結果,パケットの分類精度が著しく低下することが新たに分かった.それに加えて,ヘッダーにペイロードの情報を付与してパケットを分類した場合,ヘッダーのみの場合と比較して,分類の精度が高くなることも確認できた. |
| (英) |
In recent years, network-based intrusion detection systems (NIDS), which are systems for detecting unauthorized access on a network, have appeared that apply advanced neural network techniques. Motivated by LSTM's strength in learning time-series information, this study aims to classify communications with higher accuracy than existing NIDS models by successfully learning the characteristics of strings in communication packets. Based on previous research, we have newly found that the accuracy of packet classification is significantly degraded by a model that uses word embedding and LSTM to hide some of the information from the header. In addition, we also confirmed that classification of packets with payload information in the header is more accurate than the header-only case. |
| キーワード |
(和) |
機械学習 / 深層学習 / 情報セキュリティ / ネットワーク侵入検知システム / LSTM / / / |
| (英) |
machine learning / deep learning / Information Security / NIDS / LSTM / / / |
| 文献情報 |
信学技報, vol. 122, no. 422, ICSS2022-53, pp. 31-36, 2023年3月. |
| 資料番号 |
ICSS2022-53 |
| 発行日 |
2023-03-06 (ICSS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2022-53 |