• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

FAFS: A Fuzzy Association Feature Selection Method for Network Malicious Traffic Detection


Abstract

Analyzing network traffic is the basis of dealing with network security issues. Most of the network security systems depend on the feature selection of network traffic data and the de-tection ability of malicious traffic in network can be improved by the correct method of feature selection. An FAFS method, which is short for Fuzzy Association Feature Selection method, is proposed in this paper for network malicious traffic detection. Association rules, which can reflect the relationship among different characteristic attributes of network traffic data, are mined by association analysis. The membership value of association rules are obtained by the calculation of fuzzy reasoning. The data features with the highest correlation intensity in network data sets are calculated by comparing the membership values in association rules. The dimension of data features are reduced and the detection ability of malicious traffic detection algorithm in network is improved by FAFS method. To verify the effect of malicious traffic feature selection by FAFS method, FAFS method is used to select data features of different dataset in this paper. Then, K-Nearest Neighbor algorithm, C4.5 Decision Tree algorithm and Naïve Bayes algorithm are used to test on the dataset above. Moreover, FAFS method is also compared with classical feature selection methods. The analysis of experimental results show that the precision and recall rate of malicious traffic detection in the network can be signifi-cantly improved by FAFS method, which provides a valuable reference for the establishment of network security system.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
Y. Feng, Y. Kang, H. Zhang, W. Zhang, "FAFS: A Fuzzy Association Feature Selection Method for Network Malicious Traffic Detection," KSII Transactions on Internet and Information Systems, vol. 14, no. 1, pp. 240-259, 2020. DOI: 10.3837/tiis.2020.01.014.

[ACM Style]
Yongxin Feng, Yingyun Kang, Hao Zhang, and Wenbo Zhang. 2020. FAFS: A Fuzzy Association Feature Selection Method for Network Malicious Traffic Detection. KSII Transactions on Internet and Information Systems, 14, 1, (2020), 240-259. DOI: 10.3837/tiis.2020.01.014.

[BibTeX Style]
@article{tiis:23231, title="FAFS: A Fuzzy Association Feature Selection Method for Network Malicious Traffic Detection", author="Yongxin Feng and Yingyun Kang and Hao Zhang and Wenbo Zhang and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2020.01.014}, volume={14}, number={1}, year="2020", month={January}, pages={240-259}}