发表机构
Karabuk University(卡拉比克大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究利用CSE-CIC-IDS2018数据集,将网络流量特征转换为自然可见图并提取拓扑描述符,通过CNN分类和统计检验,证明不同攻击类别具有独特拓扑特征,实现96.20%准确率。
AI 中文摘要
基于自然可见图(NVG)的表示方法为捕获序列网络流量中的结构模式提供了一种有前景的途径。然而,不同的网络攻击类别在此类表示中是否表现出独特的拓扑特征,仍未被充分理解。本研究使用CSE-CIC-IDS2018数据集,探讨基于NVG的网络流量表示的判别性和结构特征。76个数值流量特征在40个观测值的重叠窗口内被独立转换为NVG,并从每个图中提取十个图论度量,得到每帧760个拓扑描述符。使用多分支卷积神经网络(CNN)结合分层五折交叉验证评估了这些表示的判别能力。模型实现了96.20%的平均准确率和0.9566的马修斯相关系数(MCC)。为了表征类别特定的拓扑差异,将Kruskal-Wallis和Mann-Whitney U检验与Benjamini-Hochberg错误发现率校正及效应量度量相结合。在10,640次攻击与良性比较中,7,777次(73.1%)在FDR校正后仍具有统计显著性,其中4,844次表现出较大的Cliff's delta效应。最强的全局差异主要与反向流量和分组长度相关特征以及连通性、聚类和中心性度量相关。这些发现表明,NVG衍生的表示可以提供强大的判别能力,同时揭示与不同网络攻击类别相关的类别依赖性拓扑模式。
英文摘要
Natural Visibility Graph (NVG)-based representations provide a promising approach for capturing structural patterns in sequential network traffic. However, whether different cyber-attack classes exhibit distinctive topological signatures in such representations remains insufficiently understood. This study investigates the discriminative and structural characteristics of NVG-based network traffic representations using the CSE-CIC-IDS2018 dataset. Seventy-six numerical traffic features were independently transformed into NVGs within overlapping frames of 40 observations, and ten graph-theoretic metrics were extracted from each graph, resulting in 760 topological descriptors per frame. The discriminative capability of these representations was evaluated using a multi-branch convolutional neural network (CNN) with stratified five-fold cross-validation. The model achieved an average accuracy of 96.20% and a Matthews correlation coefficient (MCC) of 0.9566. To characterize class-specific topological differences, Kruskal-Wallis and Mann-Whitney U tests were combined with Benjamini-Hochberg false discovery rate correction and effect-size measures. Of the 10,640 attack-versus-benign comparisons, 7,777 (73.1%) remained statistically significant after FDR correction, with 4,844 exhibiting large Cliff's delta effects. The strongest global differences were predominantly associated with backward-traffic and packet-length-related features combined with connectivity, clustering, and centrality measures. These findings indicate that NVG-derived representations can provide strong discriminative capability while revealing class-dependent topological patterns associated with different cyber-attack classes.