Related Experiment Video
Updated: Dec 26, 2025

03:31
Author Spotlight: Enhancement of Salient Object Detection for Smart Grid Applications
Published on: December 15, 2023
938
Malicious Network Traffic Detection Based on Deep Neural Networks and Association Analysis
Minghui Gao1,2, Li Ma1,2, Heng Liu3
1China NARI Group Corporation (State Grid Electronic Power Research Institute), Nanjing 211106, China.
Sensors (Basel, Switzerland)
|March 12, 2020
Summary
This study introduces a two-level system combining deep neural networks (DNNs) and association analysis for advanced network security. The system effectively detects malicious network traffic while significantly reducing false alarms, enhancing intrusion detection capabilities.
Area of Science:
- Computer Science
- Cybersecurity
- Artificial Intelligence
Background:
- Traditional anomaly detection struggles with complex, sophisticated network attacks.
- Deep Neural Networks (DNNs) show promise for automatic anomaly detection but can produce false positives.
- Misclassified traffic leads to redundant alarm information, impacting network security efficiency.
Purpose of the Study:
- To design a robust, two-level anomaly detection system for enhanced network security.
- To improve the accuracy of malicious traffic identification and reduce false alarm rates.
- To integrate deep learning with association rule mining for a more effective intrusion detection system.
Main Methods:
- Developed a two-level anomaly detection system utilizing Deep Neural Network (DNN-4) and association analysis.
- Employed the Apriori algorithm for mining association rules between network traffic features and normal traffic labels.
- Conducted comprehensive experiments using DNNs and other neural networks on publicly available datasets, including NSL-KDD.
Main Results:
- DNN-4 demonstrated high precision and accuracy in identifying malicious network traffic.
- The Apriori algorithm effectively filtered classified traffic, significantly reducing the false positive rate.
- The integrated system achieved a high precision in malicious traffic detection and reduced the number of false alarms.
Conclusions:
- The proposed two-level system, combining DNN-4 and association rules, offers a superior approach to intrusion detection.
- This hybrid method effectively addresses the limitations of traditional systems and standalone DNNs in handling complex network attacks.
- The system provides a practical solution for improving network security by accurately identifying threats and minimizing false alarms.

