Class-imbalanced traffic abnormal detection based on 1D-CNN and BiGRU

Hong CHEN, Bing QI(), Haibo JIN, Cong WU, Li’ang ZHANG   

  1. College of Software,Liaoning Technical University,Huludao Liaoning 125105,China
  • Received:2023-08-18 Revised:2023-10-24 Accepted:2023-11-14 Online:2023-12-18 Published:2024-08-10
  • Contact: Bing QI
  • About author:bio graphy:CHEN Hong, born in 1967, M. S., associate professor. Her research interests include information security, network security.
    bio graphy:JIN Haibo, born in 1983, Ph. D., associate professor. His research interests include stochastical process, decision theory, complex system optimal maintenance, system reliability.
    bio graphy:WU Cong, born in 1979, Ph. D. candidate, lecturer. His research interests include e-commerce, data analysis, intelligent decision-making.
    bio graphy:ZHANG Li’ang, born in 1998, M. S. candidate. His research interests include network and information security, internet of vehicles security.
  • Supported by:
    National Natural Science Foundation of China(62173171);Scientific Research Project of Liaoning Provincial Department of Education(LJKFZ20220198)


Network traffic anomaly detection is a network security defense method that involves analyzing and determining network traffic to identify potential attacks. A new approach was proposed to address the issue of low detection accuracy and high false positive rate caused by imbalanced high-dimensional network traffic data and different attack categories. One Dimensional Convolutional Neural Network(1D-CNN) and Bidirectional Gated Recurrent Unit (BiGRU) were combined to construct a model for traffic anomaly detection. For class-imbalanced data, balanced processing was performed by using an improved Synthetic Minority Oversampling TEchnique (SMOTE), namely Borderline-SMOTE, and an undersampling clustering technique based on Gaussian Mixture Model (GMM). Subsequently, a one-dimensional CNN was utilized to extract local features in the data, and BiGRU was used to better extract the time series features in the data. Finally, the proposed model was evaluated on the UNSW-NB15 dataset, achieving an accuracy of 98.12% and a false positive rate of 1.28%. The experimental results demonstrate that the proposed model outperforms other classic machine learning and deep learning models, it improves the recognition rate for minority attacks and achieves higher detection accuracy.

Key words: traffic anomaly detection, imbalance processing, feature selection, Convolutional Neural Network (CNN), Bidirectional Gated Recurrent Unit (BiGRU)



关键词: 流量异常检测, 不平衡处理, 特征选择, 卷积神经网络, 双向门控循环单元

CLC Number: