English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 83776/83776 (100%)
造訪人次 : 58210803      線上人數 : 7156
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋


    請使用永久網址來引用或連結此文件: https://ir.lib.ncu.edu.tw/handle/987654321/98067


    題名: 基於輕量化特徵選擇與樹模型之網路惡意流量偵測設計與分析;Design and Analysis of Network Malicious Traffic Detection Based on Lightweight Feature Selection and Tree-Based Models
    作者: 林詠麒;Lin, Yong-Chi
    貢獻者: 通訊工程學系在職專班
    關鍵詞: 惡意流量偵測;輕量梯度提升;決策樹;隨機森林;極限梯度提升;Malicious Traffic Detection;LightGBM;Decision Tree;Random Forest;XGBoost
    日期: 2025-07-24
    上傳時間: 2025-10-17 12:19:03 (UTC+8)
    出版者: 國立中央大學
    摘要: 本研究即是探討機器學習方法於網路惡意流量偵測中的應用,目標為設計一套兼具辨識效能與測試效率的偵測模型。實驗中選用UNSW-NB15與CSE-CIC-IDS2018兩組公開數據集作為基礎,這兩個數據集涵蓋從基本偵查攻擊到複雜系統漏洞利用等多種真實世界的網路攻擊情境。在模型建構前,針對兩組數據集分別進行適當的預處理,包括數據清洗、重複值及缺失值處理與類型轉換。完成預處理後,採用輕量梯度提升的嵌入式特徵選擇法進行關鍵特徵篩選,並進一步建構雙層樹模型架構,分別結合決策樹、隨機森林、極限梯度提升與輕量梯度提升,強化模型對惡意流量的辨識能力與泛化效果。為評估模型效能,本研究採用多項指標進行量化分析。實驗結果顯示,在相同特徵選擇條件下,輕量梯度提升於兩個數據集中皆達成最高整體準確度與F1-score,同時還具備所有模型中最短的每筆測試時間,為本次實驗最佳;隨機森林在兩組數據集中各項指標略低於輕量梯度提升且測試時間稍長。極限梯度提升在惡意流量偵測上具備高召回率與中等測試時間;而單一決策樹雖測試速度最快,但分類準確度明顯低於前述集成模型。本研究驗證了將輕量梯度提升特徵篩選結合樹模型的方法,能有效提升惡意流量識別的效能與效率,並且模型對不同數據集有良好的適應能力,具備實務可行性與應用潛力。;This study investigates the application of machine learning in malicious traffic detection, aiming to design a model that achieves both high performance and efficiency. Experiments were conducted on the UNSW-NB15 and CSE-CIC-IDS2018 datasets, which include various real-world attack scenarios. After preprocessing, LightGBM’s embedded method was used for feature selection. Based on the selected features, four models—Decision Tree, Random Forest, XGBoost, and LightGBM—were individually trained and compared. Results show that LightGBM achieved the best performance in accuracy, F1-score, and testing speed, making it the best-performing model in this study. Random Forest performed consistently with high recall; XGBoost showed strong malicious flow detection with moderate test time; while Decision Tree was fastest but less accurate. Overall, the proposed method demonstrates high detection effectiveness, efficiency, and adaptability, indicating strong potential for real-world deployment.
    顯示於類別:[通訊工程學系碩士在職專班 ] 博碩士論文

    文件中的檔案:

    檔案 描述 大小格式瀏覽次數
    index.html0KbHTML16檢視/開啟


    在NCUIR中所有的資料項目都受到原著作權保護.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明