基于BiGCN的入侵检测方法
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国家242信息安全计划 (2021–037); 四川省自然科学基金 (2024NSFSC0515)


Intrusion Detection Method Based on BiGCN
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    针对现有入侵检测方法对边特征蕴含的流量交互模式重视不足、难以通过节点捕捉双向通信关联性, 导致入侵行为表征不全面、检测准确率受影响的问题, 提出一种基于双向图卷积网络的入侵检测模型, 旨在通过边特征增强与双向融合机制提升检测性能. 首先, 采用自适应时间窗口划分网络流量, 并以主机为节点、通信会话为有向边构建动态图; 其次, 设计基于决策树的边特征增强机制, 利用基尼指数筛选强判别力特征并构造高阶交叉特征, 丰富边特征的语义信息; 最后, 引入BiGCN分别捕获正向与反向图结构信息, 并结合动态注意力融合机制, 根据节点表示与增强边特征自适应计算融合权重, 实现节点与边特征的深度融合, 再经多层图卷积完成分类预测. 在CIC-IDS2017和UNSW-NB15上的实验结果表明, 该模型在精确率、召回率和F1-score等指标上均优于其他对比方法, 证明了其在网络环境中进行入侵检测的有效性.

    Abstract:

    Existing intrusion detection methods place insufficient emphasis on the traffic interaction patterns contained in edge features and struggle to capture bidirectional communication relationships through nodes, resulting in an incomplete representation of intrusion behavior and compromised detection accuracy. To this end, this study proposes a bidirectional graph convolutional network (BiGCN)-based intrusion detection model that aims to enhance detection performance through edge feature enhancement and a bidirectional fusion mechanism. First, network traffic is segmented by adopting an adaptive time window, and a dynamic graph is constructed with hosts as nodes and communication sessions as directed edges. Second, a decision tree-based edge feature enhancement mechanism is designed, which leverages the Gini index to select highly discriminative features and construct high-order cross features to enrich the semantic information of edge features. Finally, BiGCN is introduced to separately capture forward and backward graph structural information. A dynamic attention fusion mechanism is combined to adaptively compute fusion weights according to node representations and enhanced edge features, enabling deep integration of the node and edge features. Finally, the multi-layer graph convolution is applied to complete the classification prediction. Experimental results on the CIC-IDS2017 and UNSW-NB15 datasets demonstrate that the built model outperforms other comparative methods in terms of precision, recall, and F1-score, thus validating its effectiveness for intrusion detection in network environments.

    参考文献
    相似文献
    引证文献
引用本文

刘传真,林宏刚,李鹏亮,段光明.基于BiGCN的入侵检测方法.计算机系统应用,2026,35(8):140-150

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-12-05
  • 最后修改日期:2025-12-30
  • 录用日期:
  • 在线发布日期: 2026-05-22
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62661041 传真: Email:csa@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号