232
Y. Zhou et al.
FTP session, is all 0 in KDDCUP’99 data set. Therefore, the features mentioned
above can be eliminated.
In addition, the original intrusion data is usually one-dimensional vector data,
but CNN is generally used to process two-dimensional image data. It is necessary
to convert the original one-dimensional data into two-dimensional data. After
eliminating features 1, 7, 9, 20, and 21 during dimensionality reduction, the
remaining 36 features are reshaped into a 6 × 6 form in this paper.
One-Hot Encoding In the numerical processing mentioned above, the values
of the label are represented by [0, 22]. To make the data sparse, this paper uses
one-hot encoding to convert the integers from [0, 22] into a 23-bit binary vector,
in which all the digits are 0 except that the index bit corresponding to the integer
is 1.
2.2 CNN Modeling
The basic structure of CNN consists of an input layer, a convolutional layer,
a pooling layer, a fully connected layer, and an output layer. Usually, in CNN
structure, the deeper the network depth is, the larger the number of feature maps
is, the greater the feature space that the network can represent and the stronger
the network learning ability will be, while which will also make the calculation
of the network more complex and lead to overfitting problems. Therefore, in
practical applications, the network depth, the number of feature faces, the size
of the convolution kernel, and the sliding step of convolution should be selected
appropriately, so that a good model can be obtained during training, and the
training time can be reduced.
This paper uses a simplified CNN model, as shown in Fig. 3, which mainly
consists of a convolutional layer, a max pooling layer, two fully connected layers,
and a Softmax classifier.
S
o
f
t
m
a
x
Output
Predictions
Original
Output
Input
Normal(0.01)
Dos(0.03)
R2L(0.91)
U2R(0.02)
Fully
connected
1@6×6
32@6×6
32@3×3
1×1024
Convolution
3×3
Max-Pooling
2×2
Fully
connected
S
o
f
t
m
a
x
Output
Predictions
Original
Output
Input
Normal(0.01)
Dos(0.03)
R2L(0.91)
U2R(0.02)
Fully
connected
1@6×6
32@6×6
32@3×3
1×1024
Convolution
3×3
Max-Pooling
2×2
Fully
connected
Fig. 3. Basic structure of the convolutional network
Dropout Learning Dropout is used to prevent parameters from over-reliance
on training data effectively and improve the ability of parameters to generalize
Précédent

- 244/679

Suivant