Network security threats are increasingly becoming the focus of information system security, and an efficient and intelligent detection mechanism is urgently needed to deal with the evolving attack methods in time. This paper is devoted to exploring and evaluating network security threat detection algorithms based on machine learning. Through the empirical analysis of typical data sets such as KDD99, the performance of different algorithms in real network environment is compared. We have focused on algorithms such as Support Vector Machine (SVM) and Long Short-Term Memory (LSTM) in deep learning and attempted to explore their hybrid applications. Through comparative experiments, it was found that the LSTM+SVM hybrid model can effectively control the false alarm rate while improving accuracy. The experimental results on KDD99 data set show that our model has significantly improved the accuracy of many attack types, especially in the scene where the "U2R" attack type is "normal", the false alarm rate is about 9%. Through this study, I hope to provide valuable reference for the research and practical application in the field of network security threat detection and contribute to building a smarter and more robust network security defense system.
Paper
Full text
Network security threat detection algorithm based on machine learning
Semantic Scholar · Computer Science · 2024
Abstract
Network security threats are increasingly becoming the focus of information system security, and an efficient and intelligent detection mechanism is urgently needed to deal with the evolving attack methods in time. This paper is devoted to exploring and evaluating network security threat detection algorithms based on machine learning. Through the empirical analysis of typical data sets such as KDD99, the performance of different algorithms in real network environment is compared. We have focused on algorithms such as Support Vector Machine (SVM) and Long Short-Term Memory (LSTM) in deep learning and attempted to explore their hybrid applications. Through comparative experiments, it was found that the LSTM+SVM hybrid model can effectively control the false alarm rate while improving accuracy. The experimental results on KDD99 data set show that our model has significantly improved the accuracy of many attack types, especially in the scene where the "U2R" attack type is "normal", the false alarm rate is about 9%. Through this study, I hope to provide valuable reference for the research and practical application in the field of network security threat detection and contribute to building a smarter and more robust network security defense system.