With the increasing severity of network security threats, Network Intrusion Detection (NID) has become a key technology to ensure network security. To address the problem of low detection rate of traditional intrusion detection models, this paper proposes a Dual-Attention model for NID, which combines Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) to design two modules: the FocusConV and the TempoNet module. The FocusConV module, which automatically adjusts and weights CNN extracted local features, focuses on local features that are more important for intrusion detection. The TempoNet module focuses on global information, identifies more important features in time steps or sequences, and filters and weights the information globally to further improve the accuracy and robustness of NID. Meanwhile, in order to solve the class imbalance problem in the dataset, the EQL v2 method is used to compute the class weights of each class and to use them in the loss computation, which optimizes the performance of the model on the class imbalance problem. Extensive experiments were conducted on the NSL-KDD, UNSW-NB15, and CIC-DDos2019 datasets, achieving average accuracy rates of 99.66%, 87.47%, and 99.39%, respectively, demonstrating excellent detection accuracy and robustness. The model also improves the detection performance of minority classes in the datasets. On the UNSW-NB15 dataset, the detection rates for Analysis, Exploits, and Shellcode attacks increased by 7%, 7%, and 10%, respectively, demonstrating the Dual-Attention CNN-BiLSTM model’s excellent performance in NID.
- Article type
- Year
Open Access
Article
Issue
Open Access
Article
Issue
With the rapid development of the Internet of Things (IoT), the widespread adoption of applications such as smart homes and industrial IoT has raised the demand for secure authentication and key agreement among resource-constrained devices over open communication channels. Traditional authentication protocols often rely on centralized servers for key distribution, which results in high communication overhead and exposes systems to single-point-of-failure risks. Moreover, IoT devices are typically constrained in computational resources and are vulnerable to hardware cloning. These limitations necessitate lightweight yet robust security mechanisms. To address these challenges, we propose a lightweight peer-to-peer authentication protocol based on Physically Unclonable Function (PUF) and Multiple Reference Fuzzy Extractor (MRFE). The proposed protocol enables direct mutual authentication and key agreement between IoT devices without the participation of a trusted third-party server. Formal security analysis, along with evaluations of computation and communication costs, demonstrates that the protocol achieves strong security guarantees while maintaining high efficiency. Therefore, the proposed protocol is well-suited for lightweight peer-to-peer authentication scenarios in IoT environments.
京公网安备11010802044758号