{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:08:09Z","timestamp":1783098489158,"version":"3.54.6"},"reference-count":31,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2023,5,25]],"date-time":"2023-05-25T00:00:00Z","timestamp":1684972800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Network traffic anomaly detection is a key step in identifying and preventing network security threats. This study aims to construct a new deep-learning-based traffic anomaly detection model through in-depth research on new feature-engineering methods, significantly improving the efficiency and accuracy of network traffic anomaly detection. The specific research work mainly includes the following two aspects: 1. In order to construct a more comprehensive dataset, this article first starts from the raw data of the classic traffic anomaly detection dataset UNSW-NB15 and combines the feature extraction standards and feature calculation methods of other classic detection datasets to re-extract and design a feature description set for the original traffic data in order to accurately and completely describe the network traffic status. We reconstructed the dataset DNTAD using the feature-processing method designed in this article and conducted evaluation experiments on it. Experiments have shown that by verifying classic machine learning algorithms, such as XGBoost, this method not only does not reduce the training performance of the algorithm but also improves its operational efficiency. 2. This article proposes a detection algorithm model based on LSTM and the recurrent neural network self-attention mechanism for important time-series information contained in the abnormal traffic datasets. With this model, through the memory mechanism of the LSTM, the time dependence of traffic features can be learned. On the basis of LSTM, a self-attention mechanism is introduced, which can weight the features at different positions in the sequence, enabling the model to better learn the direct relationship between traffic features. A series of ablation experiments were also used to demonstrate the effectiveness of each component of the model. The experimental results show that, compared to other comparative models, the model proposed in this article achieves better experimental results on the constructed dataset.<\/jats:p>","DOI":"10.3390\/s23115059","type":"journal-article","created":{"date-parts":[[2023,5,25]],"date-time":"2023-05-25T02:58:48Z","timestamp":1684983528000},"page":"5059","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["Research on Anomaly Network Detection Based on Self-Attention Mechanism"],"prefix":"10.3390","volume":"23","author":[{"given":"Wanting","family":"Hu","sequence":"first","affiliation":[{"name":"University of Xiamen, Xiamen 361005, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lu","family":"Cao","sequence":"additional","affiliation":[{"name":"University of Xiamen, Xiamen 361005, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6679-8655","authenticated-orcid":false,"given":"Qunsheng","family":"Ruan","sequence":"additional","affiliation":[{"name":"University of Xiamen, Xiamen 361005, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingfeng","family":"Wu","sequence":"additional","affiliation":[{"name":"University of Xiamen, Xiamen 361005, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,5,25]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Aboaoja, F.A., Zainal, A., Ghaleb, F.A., Al-rimy, B.A.S., Eisa, T.A.E., and Elnour, A.A.H. (2022). Malware Detection Issues, Challenges, and Future Directions: A Survey. Appl. Sci., 12.","DOI":"10.3390\/app12178482"},{"key":"ref_2","unstructured":"Liaropoulos, A. (2015). European Conference on Cyber Warfare and Security, Academic Conferences International Limited."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"86542","DOI":"10.1109\/ACCESS.2022.3198947","article-title":"On Apache Log4j2 Exploitation in Aeronautical, Maritime, and Aerospace Communication","volume":"10","author":"Juvonen","year":"2022","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"407","DOI":"10.1109\/JAS.2021.1004344","article-title":"Cyber Security Intrusion Detection for Agriculture 4.0: Machine Learning-Based Solutions, Datasets, and Future Directions","volume":"9","author":"Ferrag","year":"2022","journal-title":"IEEE Caa J. Autom. Sin."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Hussain, F., Abbas, S.G., Shah, G.A., Pires, I.M., Fayyaz, U.U., Shahzad, F., Garcia, N.M., and Zdravevski, E. (2021). A Framework for Malicious Traffic Detection in IoT Healthcare Environment. Sensors, 21.","DOI":"10.3390\/s21093025"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"107536","DOI":"10.1016\/j.compeleceng.2021.107536","article-title":"Three-layer hybrid intrusion detection model for smart home malicious attacks","volume":"96","author":"Shi","year":"2021","journal-title":"Comput. Electr. Eng."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"616","DOI":"10.1109\/JIOT.2021.3084796","article-title":"MTH-IDS: A Multitiered Hybrid Intrusion Detection System for Internet of Vehicles","volume":"9","author":"Yang","year":"2021","journal-title":"IEEE Int. Things J."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"810","DOI":"10.1109\/TC.2002.1017701","article-title":"Multivariate statistical analysis of audit trails for host-based intrusion detection","volume":"51","author":"Ye","year":"2002","journal-title":"IEEE Trans. Comput."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1016\/j.inffus.2009.01.003","article-title":"Processing intrusion detection alert aggregates with time series modeling","volume":"10","author":"Viinikka","year":"2009","journal-title":"Inf. Fusion"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection","volume":"18","author":"Buczak","year":"2016","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"19572","DOI":"10.1109\/ACCESS.2022.3151248","article-title":"Machine Learning and Deep Learning Approaches for CyberSecurity: A Review","volume":"10","author":"Halbouni","year":"2022","journal-title":"IEEE Access"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Bhattacharya, S., Maddikunta, P.K.R., Kaluri, R., Singh, S., Gadekallu, T.R., Alazab, M., and Tariq, U. (2020). A Novel PCA-Firefly Based XGBoost Classification Model for Intrusion Detection in Networks Using GPU. Electronics, 9.","DOI":"10.3390\/electronics9020219"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"240","DOI":"10.1016\/j.future.2022.01.026","article-title":"Imbalanced data classification: A KNN and generative adversarial networks-based hybrid approach for intrusion detection","volume":"131","author":"Ding","year":"2022","journal-title":"Future Gener. Comput.-Syst.-Int. J. Escience"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Balyan, A.K., Ahuja, S., Lilhore, U.K., Sharma, S.K., Manoharan, P., Algarni, A.D., Elmannai, H., and Raahemifar, K. (2022). A Hybrid Intrusion Detection Model Using EGA-PSO and Improved Random Forest Method. Sensors, 22.","DOI":"10.3390\/s22165986"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Ahmim, A., Maglaras, L., Ferrag, M.A., Derdour, M., and Janicke, H. (2019, January 29\u201331). A Novel Hierarchical Intrusion Detection System based on Decision Tree and Rules-based Models. Proceedings of the 15th Annual International Conference on Distributed Computing in Sensor Systems (DCOSS), Santorini, Greece.","DOI":"10.1109\/DCOSS.2019.00059"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"13624","DOI":"10.1109\/ACCESS.2018.2810198","article-title":"An Improved Intrusion Detection Algorithm Based on GA and SVM","volume":"6","author":"Tao","year":"2018","journal-title":"IEEE Access"},{"key":"ref_17","first-page":"170","article-title":"Improved Intrusion Detection Algorithm based on TLBO and GA Algorithms","volume":"18","author":"Aljanabi","year":"2021","journal-title":"Int. Arab. J. Inf. Technol."},{"key":"ref_18","unstructured":"Ioannou, C., Vassiliou, V., and Association for Computing Machinery (November, January 28). An Intrusion Detection System for Constrained WSN and IoT Nodes Based on Binary Logistic Regression. Proceedings of the 21st ACM International Conference on Modeling, Analysis and Simulation of Wireless and Mobile Systems (MSWiM), Alicante, Spain."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Cao, B., Li, C., Song, Y., Qin, Y., and Chen, C. (2022). Network Intrusion Detection Model Based on CNN and GRU. Appl. Sci., 12.","DOI":"10.3390\/app12094184"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"106458","DOI":"10.1016\/j.compeleceng.2019.106458","article-title":"Real-time anomaly detection based on long short-Term memory and Gaussian Mixture Model","volume":"79","author":"Ding","year":"2019","journal-title":"Comput. Electr. Eng."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Suda, H., Natsui, M., and Hanyu, T. (2018, January 16\u201318). Systematic Intrusion Detection Technique for an In-Vehicle Network Based on Time-Series Feature Extraction. Proceedings of the 48th IEEE International Symposium on Multiple-Valued Logic (ISMVL), Linz, Austria.","DOI":"10.1109\/ISMVL.2018.00018"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Roy, B., and Cheung, H. (2018, January 21\u201323). A Deep Learning Approach for Intrusion Detection in Internet of Things using Bi-Directional Long Short-Term Memory Recurrent Neural Network. Proceedings of the 28th International Telecommunication Networks and Applications Conference (ITNAC), Sydney, Australia.","DOI":"10.1109\/ATNAC.2018.8615294"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Li, D., Chen, D., Jin, B., Shi, L., Goh, J., and Ng, S.K. (2019, January 17\u201319). MAD-GAN: Multivariate Anomaly Detection for Time Series Data with Generative Adversarial Networks. Proceedings of the 28th International Conference on Artificial Neural Networks (ICANN), Munich, Germany.","DOI":"10.1007\/978-3-030-30490-4_56"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"104695","DOI":"10.1109\/ACCESS.2021.3100087","article-title":"Network Anomaly Detection Using Memory-Augmented Deep Autoencoder","volume":"9","author":"Min","year":"2021","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Xu, X., and Zheng, X. (2021, January 6\u201312). Hybrid Model for Network Anomaly Detection with Gradient Boosting Decision Trees and Tabtransformer. Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Virtual.","DOI":"10.1109\/ICASSP39728.2021.9414766"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1145\/380995.381030","article-title":"The UCI KDD archive of large data sets for data mining research and experimentation","volume":"2","author":"Bay","year":"2000","journal-title":"ACM SIGKDD Explor. Newletter"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_28","unstructured":"Beigi, E.B., Jazi, H.H., Stakhanova, N., and Ghorbani, A.A. (June, January 30). Towards effective feature selection in machine learning-based botnet detection approaches. Proceedings of the 2014 IEEE Conference on Communications and Network Security, Xi\u2019an, China."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2019, January 1\u20133). Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India.","DOI":"10.1109\/CCST.2019.8888419"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Atefi, K., Hashim, H., and Khodadadi, T. (2020, January 28\u201329). A Hybrid Anomaly Classification with Deep Learning (DL) and Binary Algorithms (BA) as Optimizer in the Intrusion Detection System (IDS). Proceedings of the 2020 16th IEEE International Colloquium on Signal Processing & Its Applications (CSPA), Langkawi, Malaysia.","DOI":"10.1109\/CSPA48992.2020.9068725"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/11\/5059\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:41:42Z","timestamp":1760125302000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/11\/5059"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,25]]},"references-count":31,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2023,6]]}},"alternative-id":["s23115059"],"URL":"https:\/\/doi.org\/10.3390\/s23115059","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,25]]}}}