A method, apparatus, and computer device for detecting anomalies in a border gateway protocol.
By using a BGP temporal convolutional network to process long-term sequences and long-term dependencies in BGP data, the limitations of existing technologies in detection are addressed, resulting in higher detection accuracy.
Patent Information
- Application Number
- CN202411765235.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-03
AI Technical Summary
Existing neural network architectures cannot effectively handle long-term sequences of Border Gateway Protocol (BGP) data and capture long-term dependencies, resulting in limitations in BGP data anomaly detection.
We employ a BGP temporal convolutional network, which captures temporal patterns in time-series data through multiple temporal convolutional layers and self-attention layers. We also utilize residual structures to pass on data dependencies and combine global average pooling or fully connected layers for anomaly detection.
It improves the accuracy of BGP data anomaly detection, can handle long-term sequence features and capture long-term dependencies, and improves detection precision.
Smart Images

Figure CN119788578B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of border gateway protocol anomaly detection technology, specifically to a border gateway protocol anomaly detection method, apparatus, and computer equipment. Background Technology
[0002] Cybersecurity is a crucial pillar for ensuring cyberspace security, while the security of network infrastructure is fundamental to ensuring reliable network operation. To guarantee the secure conduct of various activities within the network, diverse cybersecurity detection measures provide secure communication safeguards. In cyberspace, routing systems and domain name systems, as vital network infrastructure, are the foundation and prerequisite for ensuring the safe operation of all network activities.
[0003] Border Gateway Protocol (BGP) is a distance-vector routing protocol that enables route reachability between Autonomous Systems (AS) and selects the best route. Based on the consequences, BGP anomalies can be categorized into flow hijacking anomalies and update message surge anomalies. Flow hijacking anomalies can cause data flow redirection in the victim network, creating traffic black holes and compromising the reachability of the victim network. Update message surge anomalies can cause a large number of BGP update messages to be generated in a very short period of time, disrupting the stability of the global Internet. Therefore, anomaly detection for BGP is crucial.
[0004] In related technologies, the traditional neural network structure used for anomaly detection in BGP data, such as recurrent neural networks, long short-term memory networks, and naive Bayes networks, has certain limitations in anomaly detection because these networks cannot handle long-term sequence data and capture long-term dependencies in the data. Summary of the Invention
[0005] In view of this, the present invention provides a method, apparatus and computer device for detecting anomalies in border gateway protocols, in order to solve the problem that there are certain limitations in the detection of anomalies in BGP data.
[0006] According to the first aspect, embodiments of this disclosure provide a border gateway protocol anomaly detection method, the method comprising:
[0007] Obtain the BGP data to be tested, which is each type of data from various BGP data types, and the BGP data to be tested has been pre-processed;
[0008] Extract the BGP data to be tested from the BGP data to be tested, and fuse the BGP data to be tested from multiple BGP data sources;
[0009] The fused BGP data to be tested is input into a BGP temporal convolutional network for detection, yielding anomaly detection results for the BGP data. The BGP temporal convolutional network is pre-trained. After transmitting the BGP data to the input layer, it performs convolution operations in the temporal dimension through multiple temporal convolutional layers to capture temporal patterns in the time-series data and the BGP data to be tested. A self-attention layer is added after each temporal convolutional layer to perform a weighted summation of its output. Multiple temporal convolutional layers and a skip connection form a residual structure, which includes multiple residual blocks. The skip connection directly adds the input to the output of the residual structure to pass on the dependencies of the BGP data to be tested. The output of the residual structure is then processed through global average pooling or a fully connected layer to obtain the anomaly detection results for the BGP data to be tested.
[0010] By implementing the above-described embodiments, this disclosure ultimately enables the processing of long-term sequence features of BGP data and the capture of long-term dependencies in BGP data, thereby improving the accuracy of BGP data anomaly detection.
[0011] In some alternative implementations, various types of BGP data include: network traffic data, log data, and system call data.
[0012] In some optional implementations, extracting the BGP data to be tested from the BGP data to be tested includes:
[0013] If the BGP data to be tested is network traffic data, extract at least one of the following features from the network traffic data: average traffic and peak traffic.
[0014] In some optional implementations, extracting the BGP data to be tested from the BGP data to be tested includes:
[0015] If the BGP data to be tested is log data, extract at least one of the following features from the log data: keywords and event frequency.
[0016] In some optional implementations, extracting the BGP data to be tested from the BGP data to be tested includes:
[0017] If the BGP data to be tested is system call data, extract at least one of the following features from the system call data: call frequency and common call sequence.
[0018] In some alternative implementations, the method includes, before acquiring the BGP data to be tested:
[0019] Obtain the historical training dataset, historical validation dataset, and historical test dataset used to train the BGP temporal convolutional network.
[0020] According to a second aspect, embodiments of this disclosure provide a border gateway protocol anomaly detection device, the device comprising:
[0021] The acquisition module is used to acquire the BGP data to be tested, which is each type of data in a variety of BGP data, and the BGP data to be tested has been pre-processed.
[0022] The extraction module is used to extract the BGP data to be tested from the BGP data to be tested, and to fuse the BGP data to be tested from multiple BGP data.
[0023] The detection module is used to input the fused BGP data to be tested into a BGP temporal convolutional network for detection, and obtain the anomaly detection results of the BGP data to be tested. The BGP temporal convolutional network is pre-trained. After the BGP data to be tested is transmitted to the input layer, it performs convolution operations in the time dimension through multiple temporal convolutional layers to capture the temporal patterns in the time series data and the BGP data to be tested. A self-attention layer is added after each temporal convolutional layer to perform weighted summation of the output of the temporal convolutional layer. Multiple temporal convolutional layers and a skip connection form a residual structure. The residual structure includes multiple residual blocks. The skip connection directly adds the input to the output of the residual structure to pass the dependencies of the BGP data to be tested. The output of the residual structure is passed through a global average pooling or fully connected layer to obtain the anomaly detection results of the BGP data to be tested.
[0024] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the first aspect described above or any of its corresponding embodiments in some optional embodiments.
[0025] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the border gateway protocol anomaly detection method of the first aspect or any corresponding embodiment described above.
[0026] Fifthly, the present invention provides a computer program product, including computer instructions for causing a computer to execute the border gateway protocol anomaly detection method described in the first aspect or any corresponding embodiment thereof. Attached Figure Description
[0027] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0028] Figure 1 This is a flowchart illustrating a border gateway protocol anomaly detection method according to an embodiment of the present invention;
[0029] Figure 2 This is a structural block diagram of a BGP temporal convolutional network according to an embodiment of the present invention;
[0030] Figure 3 This is a schematic diagram of the structure of online detection and offline training of a BGP temporal convolutional network according to an embodiment of the present invention;
[0031] Figure 4 This is a structural block diagram of a border gateway protocol anomaly detection device according to an embodiment of the present invention;
[0032] Figure 5 This is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Detailed Implementation
[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0034] According to an embodiment of the present invention, a method for detecting anomalies in a border gateway protocol is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0035] Border Gateway Protocol (BGP) is a distance-vector routing protocol that enables route reachability between Autonomous Systems (AS) and selects the best route. BGP uses TCP as its transport layer protocol (port 179). BGP works by establishing and maintaining routing tables through the exchange of routing information. Each AS is equipped with one or more BGP routers, which exchange routing information via TCP connections. A BGP router shares its known routing information with neighboring BGP routers and receives routing information from them. By comparing the attributes and policies of each routing message, the BGP router selects the best route and adds it to its own routing table. The global internet consists of interconnected networks of different regions and sizes. For a long time, networks have established interconnectivity by advertising route reachability information through BGP. However, with the increasing interconnectivity of networks, the lack of a trusted route authentication mechanism in BGP has become increasingly apparent. Therefore, routers face various network attacks, leading to abnormal events in BGP data, which in turn affects network connectivity and security.
[0036] In related technologies, the traditional neural network structure used for anomaly detection in BGP data, such as recurrent neural networks, long short-term memory networks, and naive Bayes networks, has certain limitations in anomaly detection because these networks cannot handle long-term sequence data and capture long-term dependencies in the data.
[0037] In view of this, this embodiment provides a method for detecting anomalies in a border gateway protocol, which can be used in computer devices such as mobile phones, tablets, desktop computers, laptops, and servers. Figure 1 As shown, the process includes the following steps:
[0038] Step S101: Obtain the BGP data to be tested, wherein the BGP data to be tested is each type of data among various BGP data, and the BGP data to be tested has been pre-processed.
[0039] In a specific example, various types of BGP data include: network traffic data, log data, and system call data.
[0040] Specifically, network traffic data includes: network traffic packet data, average route path length, longest route path length, number of gateway protocol packets, source IP address, and destination IP address. Log data includes: system events, error messages, and user login information. System call data includes: application requests to the operating system, file operation data, and process management data.
[0041] This is equivalent to collecting multimodal data from the border gateway at the network layer. Specifically, network traffic data refers to traffic-related data collected from the network layer, log data refers to data recording event states, and system call data refers to data on applications making calls.
[0042] Step S102: Extract the BGP data to be tested from the BGP data to be tested, and fuse the BGP data to be tested from multiple BGP data.
[0043] In some optional implementations, extracting the BGP data to be tested from the BGP data to be tested includes:
[0044] Extracting BGP data from the BGP data to be tested includes: if the BGP data to be tested is network traffic data, extracting at least one of the following features from the network traffic data: average traffic, peak traffic. Extracting BGP data from the BGP data to be tested also includes: if the BGP data to be tested is log data, extracting at least one of the following features from the log data: keywords, event frequency.
[0045] In some optional implementations, the BGP data to be tested is extracted from the BGP data to be tested, including: if the BGP data to be tested is system call data, extracting at least one of the following features from the system call data: call frequency and common call sequence.
[0046] Step S103: The fused BGP data to be tested is input into the BGP temporal convolutional network for detection to obtain the anomaly detection result of the BGP data to be tested. The BGP temporal convolutional network is pre-trained. After the BGP data to be tested is transmitted to the input layer, it performs convolution operations in the time dimension through multiple temporal convolutional layers to capture the temporal patterns in the time series data and the BGP data to be tested. A self-attention layer is added after each temporal convolutional layer to perform weighted summation of the output of the temporal convolutional layer. Multiple temporal convolutional layers and a skip connection form a residual structure. The residual structure includes multiple residual blocks. The skip connection directly adds the input to the output of the residual structure to pass the dependency relationship of the BGP data to be tested. The output of the residual structure is processed by global average pooling or a fully connected layer to obtain the anomaly detection result of the BGP data to be tested.
[0047] like Figure 2The diagram shows the structure of the BGP temporal convolutional network in this embodiment. In Figure 2, the input layer receives time-series data as input. The temporal convolutional layer is the core of the BGP temporal convolutional network, consisting of multiple temporal convolutional layers. Each temporal convolutional layer contains a one-dimensional convolutional layer and a non-linear activation function. The function of the temporal convolutional layer is to perform convolution operations in the time dimension, capturing temporal patterns and features in the time-series data. A self-attention layer is added after each convolutional layer in the BGP temporal convolutional network. The self-attention layer performs a weighted summation of the outputs of the convolutional layers based on the importance of the input sequence, highlighting important BGP messages. Residual blocks are introduced to enhance the depth and feature representation capability of the BGP temporal convolutional network. Each residual block consists of multiple temporal convolutional layers and a skip connection. The skip connection directly adds the input to the output of the residual block, enabling the BGP temporal convolutional network to better propagate gradients and learn long-term dependencies. In the output layer, the output of the last residual block is processed by global average pooling or a fully connected layer to obtain the final prediction result.
[0048] This disclosure primarily utilizes various software (such as Wireshark, Netflow, and log collection tools) to collect BGP data under test from the network layer. This network layer data refers to data closely related to specific network activities. Currently, commonly used BGP data under test includes network traffic data, log data, and system call data. Further feature extraction is performed on the BGP data under test. For example, multiple features such as source IP, destination IP, average route path length, longest route path length, and the number of gateway protocol packets (IGP packets) are extracted from the network traffic data packets of the BGP data under test. Furthermore, the time-series characteristics of the BGP data under test and the randomness of network traffic are considered, and these features are transformed into time-series data for subsequent anomaly detection. This disclosure constructs a BGP time-series convolutional network containing multiple BGP time-series convolutional networks and a self-attention layer. The self-attention layer performs a weighted summation of the outputs of multiple time-series convolutional layers based on the importance of the input sequence, thereby highlighting important BGP messages and capturing long-term dependencies and abnormal patterns in the time series. Furthermore, the BGP temporal convolutional network undergoes multiple iterative learning processes on a large amount of data, continuously optimizing the network parameters by minimizing the loss function value, thereby improving the accuracy of the BGP temporal convolutional network in detecting the BGP data under test. Using the trained BGP temporal convolutional network, anomaly detection is performed on the BGP data under test to determine if any abnormalities exist. Finally, based on the anomaly detection results, corresponding alerts are generated or appropriate measures are taken to address the issue.
[0049] Therefore, the border gateway protocol anomaly detection method in this embodiment of the present disclosure acquires BGP data to be tested, wherein the BGP data to be tested is each type of data from multiple BGP data types, and the BGP data to be tested is pre-processed; extracts BGP data to be tested from the BGP data to be tested, and fuses the BGP data to be tested from multiple BGP data types; inputs the fused BGP data to be tested into a BGP temporal convolutional network for detection, and obtains the anomaly detection result of the BGP data to be tested; finally, this embodiment of the present disclosure can process the long-term sequence features of BGP data and capture the long-term dependencies of BGP data, thereby improving the accuracy of BGP data anomaly detection.
[0050] In some alternative implementations, the BGP data to be tested undergoes a preprocessing process including: removal of outliers or missing values, compression, or filtering.
[0051] For example, during peak network traffic periods, data compression and fragmentation techniques can be introduced to compress and fragment traffic data, reducing the amount of data transmitted and latency, and improving data processing speed and efficiency. Simultaneously, the compressed data can be decompressed and reassembled to restore the original data stream, ensuring data integrity and accuracy. Furthermore, in the face of large-scale DDoS attacks, traffic rate limiting and filtering techniques can be implemented to limit and filter abnormal traffic, ensuring the transmission and processing of normal traffic. At the same time, abnormal traffic can be analyzed and processed in depth to prevent further attacks by attackers.
[0052] In some optional implementations, the method further includes, before acquiring the BGP data to be tested, the following steps:
[0053] Obtain the historical training dataset, historical validation dataset, and historical test dataset used to train the BGP temporal convolutional network.
[0054] The BGP temporal convolutional network is trained using the following process:
[0055] The first step is to collect data;
[0056] Collect multimodal data from the border gateway, including network traffic data, log data, and system call data. Log data may include system events, error messages, and user login information; system call data may include application requests to the operating system, file operations, and process management. Preprocess different types of data, such as removing outliers, handling missing values, and feature extraction. For network traffic data, extract statistical features such as average traffic and peak traffic; for log data, extract keywords and event frequency; and for system call data, extract call frequency and common call sequences.
[0057] The second step is to perform multimodal data fusion;
[0058] Fusing different types of data can be achieved in several ways. For example, features from different types of data can be concatenated to form a unified multimodal feature vector. Alternatively, a concatenation method can be used, where features from different types of data are extracted separately through a neural network and then concatenated. Another approach is to use an attention mechanism for weighted fusion, which dynamically adjusts the weights of different modal data based on their importance to obtain a more comprehensive multimodal data representation.
[0059] The third step is to partition the data;
[0060] The fused multimodal dataset is divided into training, validation, and test sets. Cross-validation or hold-out methods are typically used for this purpose. Cross-validation makes more efficient use of the data and reduces fluctuations caused by different sample partitions; the hold-out method is simple and direct and suitable for large datasets.
[0061] The fourth step is to build the model;
[0062] This is a temporal convolutional network model based on a multimodal fusion attention mechanism. The model structure should include multiple branches to process different types of data; for example, one branch might handle network traffic data, another log data, and a third system call data. These branches can employ different neural network architectures, such as convolutional neural networks (CNNs) and recurrent neural networks (RNNs). The attention mechanism dynamically adjusts the weights of different modalities, enabling the model to adaptively focus on information from different modalities. The temporal convolutional network is used to capture time-series features; for time-series data such as network traffic and system call data, it can effectively extract time-related features.
[0063] Step 5: Loss Function Selection
[0064] Choosing an appropriate loss function is crucial for anomaly detection problems. Suitable loss functions can be selected, such as mean squared error or cross-entropy loss.
[0065] The sixth step is to validate and tune the model.
[0066] Use a validation set to validate the trained model and adjust the model's hyperparameters, such as the learning rate and regularization parameters, to improve the model's generalization ability. Parameter tuning can be performed using methods such as cross-validation.
[0067] Step 7: Evaluate the model
[0068] The trained model is evaluated using a test set, and performance metrics such as accuracy, recall, precision, and F1 score are calculated to assess the model's detection performance.
[0069] Step 8: Deploy the model
[0070] The trained model is deployed to a real-world environment to detect border gateway protocol anomalies, monitor network traffic, and promptly identify and handle abnormal situations.
[0071] Step 9: Continuous Model Optimization
[0072] Based on real-world application scenarios, continuously optimize the model, including updating the dataset and adjusting the model structure, to improve its detection performance and stability. Online learning and other methods can be used for continuous model optimization.
[0073] To enhance the computational efficiency of anomaly detection using BGP temporal convolutional networks, the networks can be distributed across multiple computing nodes for parallel computation, thereby improving computational efficiency and processing speed. Simultaneously, technologies such as GPU acceleration can be introduced to leverage hardware acceleration and further speed up computation.
[0074] Traditional BGP temporal convolutional networks cannot effectively adapt to different types of protocol traffic. Therefore, embodiments of this disclosure improve the adaptability and accuracy to different protocols by fusing features from different modalities for anomaly detection.
[0075] Traditional temporal convolutional networks may be interfered with by attackers when facing adversarial attacks, leading to a decrease in the accuracy of anomaly detection.
[0076] Therefore, embodiments of this disclosure utilize historical training datasets and historical test datasets to train the BGP temporal convolutional network to improve the robustness and reliability of anomaly detection.
[0077] like Figure 3 The diagram shown is a schematic of the structure of the BGP temporal convolutional network in this embodiment of the present disclosure. The BGP temporal convolutional network includes an offline network and an online network. In the offline network, the labeled routing dataset is first acquired, then BGP data is extracted, and finally the model is trained. In the online model, the BGP data to be tested is first acquired, then BGP features are extracted, and finally BGP data is classified to obtain normal detection results and abnormal detection results.
[0078] According to embodiments of this disclosure, a border gateway protocol anomaly detection device is provided, such as... Figure 4 As shown, the device includes:
[0079] The acquisition module 41 is used to acquire the BGP data to be tested, wherein the BGP data to be tested is each type of data among various BGP data, and the BGP data to be tested is pre-processed.
[0080] Extraction module 42 is used to extract the BGP data to be tested from the BGP data to be tested, and to fuse the BGP data to be tested from multiple BGP data.
[0081] The detection module 43 is used to input the fused BGP data to be tested into the BGP temporal convolutional network for detection, and obtain the anomaly detection result of the BGP data to be tested. The BGP temporal convolutional network is pre-trained. After the BGP data to be tested is transmitted to the input layer, it performs convolution operations in the time dimension through multiple temporal convolutional layers to capture the temporal patterns in the time series data and the BGP data to be tested. A self-attention layer is added after each temporal convolutional layer to perform weighted summation of the output of the temporal convolutional layer. Multiple temporal convolutional layers and a skip connection form a residual structure. The residual structure includes multiple residual blocks. The skip connection directly adds the input to the output of the residual structure to pass the dependency relationship of the BGP data to be tested. The output of the residual structure is passed through a global average pooling or fully connected layer to obtain the anomaly detection result of the BGP data to be tested.
[0082] In some alternative implementations, various types of BGP data include: network traffic data, log data, and system call data.
[0083] In some optional implementations, extracting the BGP data to be tested from the BGP data to be tested includes:
[0084] In some alternative implementations, the extraction module 42 includes:
[0085] The first extraction submodule is used to extract at least one of the following features from the network traffic data if the BGP data to be tested is network traffic data: average traffic and peak traffic.
[0086] In some alternative implementations, the extraction module 42 includes:
[0087] The second extraction submodule is used to extract at least one of the following features from the log data if the BGP data to be tested is log data: keywords and event frequency.
[0088] In some alternative implementations, the extraction module 42 includes:
[0089] The third extraction submodule is used to extract at least one of the following features from the system call data if the BGP data to be tested is system call data: call frequency and common call sequence.
[0090] In some alternative implementations, the acquisition module 41 includes:
[0091] The sample training data acquisition module is used to acquire historical training datasets, historical validation datasets, and historical test datasets for training BGP temporal convolutional networks.
[0092] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.
[0093] In this embodiment, the border gateway protocol anomaly detection device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0094] This invention also provides a computer device having the border gateway protocol anomaly detection device described above.
[0095] Please see Figure 5 , Figure 5 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 5 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 5 Take a processor 10 as an example.
[0096] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.
[0097] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.
[0098] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0099] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0100] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.
[0101] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.
[0102] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0103] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A method for detecting anomalies in a border gateway protocol, characterized in that, The method includes: Acquire the BGP data to be tested, wherein the BGP data to be tested is each type of data among various BGP data, and the BGP data to be tested has been pre-processed; Extract the BGP data to be tested from the BGP data to be tested, and fuse the BGP data to be tested from multiple BGP data; The fused BGP data to be tested is input into a BGP temporal convolutional network for detection, yielding anomaly detection results for the BGP data. This BGP temporal convolutional network is pre-trained. After transmitting the BGP data to be tested to the input layer, it performs convolution operations in the temporal dimension through multiple temporal convolutional layers to capture temporal patterns in the time-series data and the BGP data to be tested. A self-attention layer is added after each temporal convolutional layer to perform a weighted summation of its output. These multiple temporal convolutional layers and a skip connection form a residual structure, which includes multiple residual blocks. The skip connection directly adds the input to the output of the residual structure to convey the dependencies of the BGP data to be tested. The output of the residual structure is then processed through global average pooling or a fully connected layer to obtain the anomaly detection results for the BGP data to be tested.
2. The method according to claim 1, characterized in that, The various types of BGP data include: network traffic data, log data, and system call data.
3. The method according to claim 2, characterized in that, Extracting the BGP data to be tested from the BGP data to be tested includes: If the BGP data to be tested is the network traffic data, extract at least one of the following features from the network traffic data: average traffic and peak traffic.
4. The method according to claim 2, characterized in that, Extracting the BGP data to be tested from the BGP data to be tested includes: If the BGP data to be tested is the log data, extract at least one of the following features from the log data: keywords and event frequency.
5. The method according to claim 2, characterized in that, Extracting the BGP data to be tested from the BGP data to be tested includes: If the BGP data to be tested is system call data, extract at least one of the following features from the system call data: call frequency and common call sequence.
6. The method according to claim 1, characterized in that, The method includes the following steps before acquiring the BGP data to be tested: Obtain the historical training dataset, historical validation dataset, and historical test dataset used to train the BGP temporal convolutional network.
7. A border gateway protocol anomaly detection device, characterized in that, The device includes: The acquisition module is used to acquire the BGP data to be tested, wherein the BGP data to be tested is each type of data among a variety of BGP data, and the BGP data to be tested is pre-processed. The extraction module is used to extract the BGP data to be tested from the BGP data to be tested, and to fuse the BGP data to be tested from multiple BGP data. The detection module is used to input the fused BGP data to be tested into a BGP temporal convolutional network for detection, and obtain anomaly detection results for the BGP data to be tested. The BGP temporal convolutional network is pre-trained. After transmitting the BGP data to be tested to the input layer, it performs convolution operations in the time dimension through multiple temporal convolutional layers to capture temporal patterns in the time series data and the BGP data to be tested. A self-attention layer is added after each temporal convolutional layer to perform a weighted summation of the output of that temporal convolutional layer. The multiple temporal convolutional layers and a skip connection form a residual structure. The residual structure includes multiple residual blocks. The skip connection directly adds the input to the output of the residual structure to pass the dependencies of the BGP data to be tested. The output of the residual structure is then processed by global average pooling or a fully connected layer to obtain the anomaly detection results for the BGP data to be tested.
8. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the border gateway protocol anomaly detection method according to any one of claims 1 to 6 by executing the computer instructions.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to execute the border gateway protocol anomaly detection method according to any one of claims 1 to 6.
10. A computer program product, characterized in that, Includes computer instructions for causing a computer to execute the border gateway protocol anomaly detection method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Routing anomaly identification method and device, electronic equipment and storage medium
CN117319251A
Multi-period time sequence anomaly detection method based on space-time diagram neural network
CN118939699A