Abstract In practical scenarios, security events triggered by abnormal network traffic often result from the collective behavior of multiple data streams, embodying group security events with collective characteristics. Existing research methods, focusing on individual data streams, lack a macroscopic analysis and struggle with challenges of analyzing massive, imbalanced data sets. To address these challenges, this paper adopts a multi-instance learning approach, mapping multiple data streams into a bag with a coarse-grained approach, where each bag corresponds to a security event label and each data stream represents an instance. We propose a multi-instance network traffic conversion method, Bag2Image, which transforms temporal multi-instance network traffic data into image representations, preserving the spatio-temporal characteristics of instances within the bag through image channels and pixels. This strategy allows the network security event prediction task to be approached as an image classification problem, leveraging advanced image classification techniques for prediction. Our cross-experiments with six advanced multi-instance learning (MIL) algorithms and six dif
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً