DOI: https://doi.org/10.1038/s41598-025-89798-0
PMID: https://pubmed.ncbi.nlm.nih.gov/39939428
تاريخ النشر: 2025-02-11
المؤلف: Qihao Zhao وآخرون
الموضوع الرئيسي: أمن الشبكات وكشف التسلل
نظرة عامة
تستكشف هذه الورقة البحثية تحسين نماذج الشبكات العصبية متعددة الطبقات (MLP) لأنظمة كشف التسلل (IDS) من خلال دمج الشبكات العصبية التلافيفية (CNNs) وآليات الانتباه. تسلط الدراسة الضوء على التحديات التي تطرحها مجموعات البيانات غير المتوازنة في الكشف بدقة عن هجمات الفئة الأقل، مما قد يؤدي إلى حركة مرور خبيثة غير مكتشفة. يقترح المؤلفون نهجًا جديدًا يجمع بين قدرات استخراج الميزات لـ AlexNet مع إطار عمل MLP، مدعومًا بآلية الانتباه SKNet. يهدف هذا الدمج إلى تحسين قدرة النموذج على التعرف على أنواع الهجمات النادرة، لا سيما في البيئات ذات الموارد المحدودة.
تظهر النتائج التجريبية أن نموذج MLP المحسن يتفوق بشكل كبير على نموذج MLP القياسي وطرق أخرى شائعة، مثل الشبكات العصبية العميقة (DBNs)، عبر مهام التصنيف المختلفة. ومن الجدير بالذكر أن درجات F1 لهجمات BotnetARES و PortScan تحسنت بنسبة 18.93% و 26.57%، على التوالي. بينما يظهر النموذج المقترح نتائج واعدة من حيث الدقة والاسترجاع، فإنه يقدم أيضًا تحديات تتعلق باستهلاك الموارد الحاسوبية أثناء التدريب، لا سيما مع مجموعات البيانات الأكبر. قد تركز الأعمال المستقبلية على تحسين كفاءة النموذج لمعالجة هذه القيود مع الحفاظ على فعاليته في كشف التسللات.
الطرق
في هذه الدراسة، يعزز المؤلفون دقة تصنيف الفئة الأقل من خلال دمج وحدة استخراج الميزات لـ AlexNet في إطار عمل الشبكة العصبية متعددة الطبقات (MLP). يسمح استخدام نوى تلافيفية أصغر في AlexNet بالتقاط تفاصيل أدق، وهو أمر حاسم للكشف عن ميزات الفئة الأقل في مراحل المعالجة المبكرة. بالإضافة إلى ذلك، تقوم آلية الانتباه SKNet بضبط المجال الاستقبالي ديناميكيًا بناءً على خصائص الإدخال، مما يسهل التقاط المعلومات متعددة المقاييس بشكل فعال. تشمل بنية الخوارزمية المعدلة تقليل الطبقات التلافيفية الخمس الأولية لـ AlexNet إلى ثلاث، كل منها تستخدم نواة تلافيفية بحجم $3 \times 3$، مع الحفاظ على طبقات التجميع الأقصى مع أحجام نوافذ وخطوات معدلة.
تظهر النتائج التجريبية أن خوارزمية MLP-AS تحسن بشكل كبير من درجة F1 والاسترجاع للفئات الأقل، مع زيادات ملحوظة بنسبة 18.93% و 26.57% لفئات BotnetARES و PortScan، على التوالي. تحدث هذه التحسينات مع الحفاظ على أداء قابل للمقارنة لتسللات الفئة الأكثر. يتم استخدام مقاييس التقييم، بما في ذلك درجة F1، والدقة، والاسترجاع، لتوفير تقييم شامل لأداء النموذج، لا سيما في سياق عدم التوازن العالي بين الفئات. تشير النتائج إلى أن دمج قدرات استخراج الميزات لـ AlexNet يحسن بشكل فعال من التعرف على العينات الإيجابية في كشف التسلل للفئة الأقل، كما يتضح من النتائج المقدمة في أشكال وجداول مختلفة طوال الدراسة.
المناقشة
تستعرض قسم المناقشة في الورقة تطور أنظمة كشف التسلل (IDS) وتسلط الضوء على المساهمات المهمة من مختلف الباحثين على مر السنين. تبدأ بعمل جيمس أندرسون الرائد في عام 1980، الذي قدم مفهوم كشف التسلل، تليه نموذج دوروثي إي. دينينغ النظري في عام 1987 الذي أسس طرق الكشف القائمة على القواعد. شملت التقدمات اللاحقة تطوير أنظمة الكشف الموزعة وطرق الكشف القائمة على السلوك، culminating في تقديم أطر مثل EMERALD وأدوات مثل Snort. تؤكد الورقة على قيود IDS التقليدية، لا سيما اعتمادها على تقنيات قائمة على القواعد التي تكافح للتكيف مع أنماط الهجوم الجديدة. استكشفت الدراسات الحديثة أساليب التعلم الآلي والتعلم العميق، مما أظهر تحسينات في دقة الكشف وتقليل الإيجابيات الكاذبة، على الرغم من أن التحديات لا تزال قائمة في تصنيف أنواع الهجمات الأقل.
يقدم المؤلفون نموذجهم الخاص، الذي يدمج شبكة عصبية متعددة الطبقات (MLP) مع AlexNet لاستخراج الميزات وSKNet من أجل كفاءة حسابية محسنة. يستخدمون مجموعة بيانات CICIDS2017، مع معالجة قضايا عدم توازن البيانات والتكرار من خلال تقنيات المعالجة المسبقة مثل تحليل المكونات الرئيسية (PCA). تشير النتائج إلى أن نموذج MLP الخاص بهم، لا سيما عند تحسينه باستخدام AlexNet وSKNet، يحسن بشكل كبير من مقاييس الكشف، خاصة للفئات الأقل، متفوقًا على الطرق التقليدية مثل الشبكات العصبية العميقة (DBNs) ويظهر زيادات ملحوظة في درجات F1 لأنواع هجمات معينة. ومع ذلك، يعترف المؤلفون بأنه بينما يظهر نموذجهم أداءً متفوقًا، فإنه يتكبد أيضًا تكاليف حسابية أعلى، مما يشير إلى الحاجة إلى مزيد من التحسين لتعزيز الكفاءة في مجموعات البيانات الأكبر.
DOI: https://doi.org/10.1038/s41598-025-89798-0
PMID: https://pubmed.ncbi.nlm.nih.gov/39939428
Publication Date: 2025-02-11
Author(s): Qihao Zhao et al.
Primary Topic: Network Security and Intrusion Detection
Overview
This research paper investigates the enhancement of multilayer perceptron (MLP) models for intrusion detection systems (IDS) by integrating convolutional neural networks (CNNs) and attention mechanisms. The study highlights the challenges posed by imbalanced datasets in accurately detecting minority class attacks, which can lead to undetected malicious traffic. The authors propose a novel approach that combines the feature extraction capabilities of AlexNet with the MLP framework, augmented by the SKNet attention mechanism. This integration aims to improve the model’s ability to recognize rare attack types, particularly in resource-constrained environments.
Experimental results demonstrate that the enhanced MLP model significantly outperforms the standard MLP and other popular methods, such as Deep Belief Networks (DBNs), across various classification tasks. Notably, the F1 scores for BotnetARES and PortScan attacks improved by 18.93% and 26.57%, respectively. While the proposed model shows promising results in terms of accuracy and recall, it also presents challenges regarding computational resource consumption during training, particularly with larger datasets. Future work may focus on optimizing the model’s efficiency to address these limitations while maintaining its effectiveness in detecting intrusions.
Methods
In this study, the authors enhance minority class classification accuracy by integrating AlexNet’s feature extraction module into a multilayer perceptron (MLP) framework. The use of smaller convolutional kernels in AlexNet allows for the capture of finer details, which is crucial for detecting minority class features early in the processing stages. Additionally, the SKNet attention mechanism dynamically adjusts the receptive field based on input characteristics, facilitating effective multi-scale information capture. The modified algorithm structure includes a reduction of AlexNet’s initial five convolutional layers to three, each employing a $3 \times 3$ convolutional kernel, while maintaining maximum pooling layers with adjusted window sizes and strides.
The experimental results demonstrate that the MLP-AS algorithm significantly improves the F1-score and recall for minority classes, with notable increases of 18.93% and 26.57% for the BotnetARES and PortScan classes, respectively. These enhancements occur while maintaining comparable performance for majority class intrusions. The evaluation metrics, including F1-score, precision, and recall, are employed to provide a comprehensive assessment of model performance, particularly in the context of high class imbalance. The findings indicate that the integration of AlexNet’s feature extraction capabilities effectively improves the recognition of positive samples in minority class intrusion detection, as evidenced by the results presented in various figures and tables throughout the study.
Discussion
The discussion section of the paper reviews the evolution of intrusion detection systems (IDS) and highlights significant contributions from various researchers over the years. It begins with James Anderson’s pioneering work in 1980, which introduced the concept of intrusion detection, followed by Dorothy E. Denning’s theoretical model in 1987 that established rule-based detection methods. Subsequent advancements included the development of distributed detection systems and behavior-based detection methods, culminating in the introduction of frameworks like EMERALD and tools such as Snort. The paper emphasizes the limitations of traditional IDS, particularly their reliance on rule-based techniques that struggle to adapt to novel attack patterns. Recent studies have explored machine learning and deep learning approaches, demonstrating improved detection accuracy and reduced false positives, although challenges remain in classifying minority attack types.
The authors present their own model, which integrates a multilayer perceptron (MLP) with AlexNet for feature extraction and SKNet for enhanced computational efficiency. They utilize the CICIDS2017 dataset, addressing issues of data imbalance and redundancy through preprocessing techniques such as Principal Component Analysis (PCA). The results indicate that their MLP model, particularly when enhanced with AlexNet and SKNet, significantly improves detection metrics, especially for minority classes, outperforming traditional methods like Deep Belief Networks (DBNs) and demonstrating notable increases in F1 scores for specific attack types. However, the authors acknowledge that while their model shows superior performance, it also incurs higher computational costs, suggesting a need for further optimization to enhance efficiency in larger datasets.
