Network security detection method based on artificial intelligence
Through online incremental learning of multimodal fusion model and federated learning framework, traditional AI technology is solved inadequate adaptability in feature engineering, efficient network threat detection and rapid response are achieved, and detection effect and resource utilization efficiency are improved.
Patent Information
- Application Number
- CN202510476315.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-08-01
AI Technical Summary
Traditional AI technology relies on manual experience in feature engineering and is difficult to dynamically adapt to complex and changing network environments. It may miss key features or extract redundant features, affecting model performance and detection effects.
A multimodal fusion model is used to extract features of network traffic, system logs and user behavior data, combined with a hybrid detection engine of unsupervised learning, supervised learning and reinforcement learning, online incremental learning is performed through the federated learning framework, dynamically optimize detection thresholds, and data privacy is protected using traffic entropy mutation detection and differential privacy technology.
It improves the detection rate of zero-day attacks, reduces the false alarm rate, can handle high-bandwidth network traffic in real time, quickly respond to network threats, adapt to changes in the network environment, reduce computing resource consumption, and ensure network security.
Smart Images

Figure CN120415784A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and specifically relates to a network security detection method based on artificial intelligence. Background Art
[0002] With the rapid development of information technology, the network has been deeply integrated into all aspects of society. Whether it is an individual's daily life or an enterprise's operation and management, it depends on the network. In such a large environment, network security issues have become increasingly prominent, and various network attack means emerge in an endless stream, such as malicious software intrusion, phishing, DDoS attacks, etc., which pose threats to personal privacy and enterprise economic interests.
[0003] A patent with the Chinese invention patent publication number CN115037519A discloses a network security vulnerability detection method based on artificial intelligence, including the following steps: Step S1: Hardware security vulnerability detection; Step S2: System security vulnerability detection; Step S3: Detection and testing of system security vulnerabilities; Step S4: Construction of an artificial intelligence platform; Step S5: Intelligent daily detection; This network security vulnerability detection method based on artificial intelligence can detect hardware security vulnerabilities and system security vulnerabilities by detecting hardware security vulnerabilities and system security vulnerabilities. At the same time, by collecting and processing different features and training a classification model, an artificial intelligence platform is constructed. Through the artificial intelligence platform for daily vulnerability detection of network security, it can have a finer inspection granularity and better vulnerability detection effect; at the same time, through the interface indication sign, the security status of the plugged and unplugged devices can be effectively indicated, improving the convenience of use.
[0004] However, the above technologies often have the following defects: Traditional AI technologies also have defects in feature engineering. At present, feature engineering often relies on artificial experience, and professionals select and extract features according to their own experience. However, the network environment is complex and dynamically changing, and the features set manually are difficult to dynamically adapt to this complex network environment, which may miss some key features or extract some redundant and useless features, thus affecting the performance and detection effect of the model.
[0005] Therefore, the present invention provides a network security detection method based on artificial intelligence. Summary of the Invention
[0006] In order to make up for the deficiencies of the prior art and solve at least one technical problem proposed in the background art.
[0007] The technical solution adopted by the present invention to solve its technical problems is: A network security detection method based on artificial intelligence according to the present invention includes the following steps:
[0008] A1. Collect network traffic data, system log data, user behavior data, and external threat intelligence data to generate a multi-source heterogeneous dataset;
[0009] A2. Preprocess the multi-source heterogeneous dataset, including data normalization, missing value filling, and noise filtering;
[0010] A3. Extract features from the preprocessed data through a multi-modal fusion model, where:
[0011] (1) Use a temporal convolutional network (TCN) to extract traffic temporal features from network traffic data;
[0012] (2) Use a natural language processing model (NLP) to extract semantic features from system log data;
[0013] (3) Use a graph neural network (GNN) to model the interaction relationship between users, devices, and services for user behavior data;
[0014] A4. Input the extracted multi-modal features into a hybrid detection engine, and the hybrid detection engine includes:
[0015] (1) An anomaly detection module based on unsupervised learning, used to identify behaviors that deviate from a preset baseline;
[0016] (2) A classification module based on supervised learning, used to determine the attack type;
[0017] (3) A policy adjustment module based on reinforcement learning, used to dynamically optimize the detection threshold;
[0018] A5. Trigger response actions according to the detection results, including generating alarms, blocking connections, or isolating devices;
[0019] A6. Update the multi-modal fusion model and the hybrid detection engine through an online incremental learning mechanism, including multi-node collaborative training under a federated learning framework.
[0020] The collection of the network traffic data includes:
[0021] Extract metadata of encrypted traffic (such as HTTPS, SSH), including server name indication (SNI) in the TLS handshake phase, certificate issuer information, and key exchange protocol type;
[0022] Perform deep packet inspection (DPI) on non-encrypted traffic to extract application layer protocol headers and payload features.
[0023] The feature extraction of the multi-modal fusion model further includes:
[0024] Dynamically weight the contribution degrees of network traffic, system logs, and user behavior characteristics using the Attention Mechanism;
[0025] Generate joint feature vectors through Feature Concatenation or Tensor Fusion.
[0026] Calculate the reconstruction error based on the Variational Autoencoder (VAE), and identify anomalies by comparing the differences between the reconstructed data and the original data.
[0027] Evaluate the anomaly score based on the Isolation Forest, and determine whether it is an anomaly according to the degree of isolation of the data points.
[0028] Based on the time series analysis of traffic entropy value mutation detection, detect abnormal traffic by using the sudden change of traffic entropy value.
[0029] The time series analysis of the traffic entropy value mutation detection divides the network traffic data into time windows according to the time series, calculates the entropy value for the traffic data within each time window, and the calculation formula for the entropy value is:
[0030]
[0031] where H(X) is the entropy value of feature X, p(x i ) is the probability of the feature value x i appearing, and n is the total number of feature values.
[0032] The online incremental learning mechanism includes:
[0033] Actively learn and screen false positive samples and missed detection samples, and add them to the training data set;
[0034] Adopt the Elastic Weight Consolidation (EWC) algorithm to prevent catastrophic forgetting;
[0035] Under the federated learning framework, protect local data privacy through Differential Privacy technology.
[0036] The federated learning adds noise to the model gradient for local nodes using Differential Privacy:
[0037] g~=g+N(0,σ 2 Δg 2 I)
[0038] Among them, g is the original gradient, Δg is the gradient sensitivity, and σ is the noise intensity.
[0039] The adaptation processing of the flow rate of the industrial control system:
[0040] Extract the function code (FunctionCode) of the TCP protocol and the register read / write mode;
[0041] Construct a device state transition diagram, and detect abnormal control instructions through a temporal graph convolutional network (TGCN).
[0042] The beneficial effects of the present invention are as follows:
[0043] 1. Through multi-modal data fusion, the detection rate of zero-day attacks can be increased to a high level. In contrast, the detection rate of traditional methods has obvious advantages in dealing with new threats. At the same time, in terms of false alarm rate control, the false alarm rate can be reduced below the normal value, which greatly reduces the burden on security personnel to handle invalid alarms. Avoiding a large number of false alarms not only causes waste of manpower and material resources, but may also lead to the neglect of real security threats.
[0044] 2. Through the federated learning framework, it is able to perform real-time processing on network traffic up to 100 Gbps, meeting the stringent requirements for security detection in today's high-speed network environment, ensuring a rapid response to network security threats, being able to detect and block potential attack behaviors in a timely manner, and providing a strong guarantee for network security.
[0045] 3. Through the time series analysis of traffic entropy value mutation detection using a weekly incremental update mechanism, there is no need for full-scale retraining. It can not only enable the model to adapt to the changing network security situation in a timely manner, quickly learn newly emerging attack patterns and features, but also significantly reduce the consumption of computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The present invention will be further described below with reference to the accompanying drawings.
[0047] Figure 1 is a step flow chart of a network security detection method based on artificial intelligence provided by the present invention;
[0048] Figure 2 is a data comparison reference diagram of a network security detection method based on artificial intelligence provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0049] In order to make the technical means, creative features, achieved purposes and effects of the present invention easy to understand, the present invention will be further described below in conjunction with specific embodiments.
[0050] As Figure 1 shown, it includes the following steps:
[0051] A1. Collect network traffic data, system log data, user behavior data, and external threat intelligence data to generate a multi-source heterogeneous dataset;
[0052] A2. Preprocess the multi-source heterogeneous dataset, including data normalization, missing value filling, and noise filtering;
[0053] A3. Extract features from the preprocessed data through a multi-modal fusion model, where:
[0054] (1) Use a temporal convolutional network (TCN) to extract traffic temporal features from network traffic data;
[0055] (2) Use a natural language processing model (NLP) to extract semantic features from system log data;
[0056] (3) Use a graph neural network (GNN) to model the interaction relationship between users, devices, and services for user behavior data;
[0057] A4. Input the extracted multi-modal features into a hybrid detection engine, and the hybrid detection engine includes:
[0058] (1) An anomaly detection module based on unsupervised learning, used to identify behaviors that deviate from a preset baseline;
[0059] (2) A classification module based on supervised learning, used to determine the attack type;
[0060] (3) A policy adjustment module based on reinforcement learning, used to dynamically optimize the detection threshold;
[0061] A5. Trigger response actions according to the detection results, including generating alarms, blocking connections, or isolating devices;
[0062] A6. Update the multi-modal fusion model and the hybrid detection engine through an online incremental learning mechanism, including multi-node collaborative training under a federated learning framework.
[0063] We collect a wide range of network traffic data, system log data, user behavior data, and external threat intelligence data to build a multi-source heterogeneous data set. Network traffic data, as an intuitive reflection of network activities, can reflect the network operation status. System log data records key system operations, which is of great significance for troubleshooting security risks. User behavior data can provide insights into user operating habits and identify abnormal behaviors. External threat intelligence data provides security threat information from the outside, broadens the detection field of view, and carries out preprocessing work for the constructed multi-source heterogeneous data set, including data normalization to make different data dimensions comparable, fill in missing values, and ensure the accuracy of data. Integrity implements noise filtering, removes interfering data, improves data quality, and lays a solid foundation for subsequent analysis. With the help of multimodal fusion models, feature extraction is performed on the pre-processed data. For network traffic data, the temporal convolutional network (TCN) is used to mine the characteristics of traffic in time series and accurately capture the changes in traffic over time. For system log data, the natural language processing model (NLP) is used to extract the semantic features and understand the deep meaning conveyed by the log records. For user behavior data, the graph neural network (GNN) is used to model the interaction between users, devices, and services to fully display user behavior patterns.
[0064] The extracted multimodal features are input into the hybrid detection engine. The unsupervised learning anomaly detection module keenly identifies behaviors that deviate from the normal range and discovers potential security threats by comparing them with the preset baseline. The supervised learning classification module accurately determines the type of attack detected based on known attack type characteristics. The reinforcement learning strategy adjustment module dynamically optimizes the detection threshold according to the detection results to improve the accuracy and adaptability of detection.
[0065] Response actions are quickly triggered based on the detection results, including generating alarm information, notifying security personnel in a timely manner, blocking connections, preventing the spread of threats, isolating equipment, and avoiding further deterioration of security incidents. The multimodal fusion model and hybrid detection engine are continuously updated through the online incremental learning mechanism to achieve multi-node collaborative training under the federated learning framework. This mechanism enables the model to continuously learn new data and adapt to the ever-changing network security environment, while ensuring data privacy and model performance.
[0066] like Figures 1 to 2 As shown in the figure, the attention mechanism is used to dynamically adjust the weights of network traffic, system logs and user behavior features, highlighting the contribution of key features to the detection results. The joint feature vector is generated through feature splicing or tensor fusion technology, effectively integrating multimodal features and improving the detection effect.
[0067] For encrypted traffic, extract its metadata, including the Server Name Indication (SNI), certificate issuer information, and key exchange protocol type during the TLS handshake phase. Although these metadata do not involve the encrypted content itself, they can provide key clues for detecting abnormal behaviors in encrypted traffic. For non-encrypted traffic, use Deep Packet Inspection (DPI) technology to deeply extract application layer protocol headers and payload features, thereby accurately identifying network activities at the application layer. And utilize time series analysis of traffic entropy value mutation detection to detect abnormal traffic by the sudden change of traffic entropy value. Under the federated learning framework, with the help of differential privacy technology, ensure that local data privacy is fully protected during the multi-node collaborative training process.
[0068] The time series analysis of the traffic entropy value mutation detection divides the network traffic data into time windows according to the time series. Calculate the entropy value for the traffic data within each time window. The calculation formula for the entropy value is:
[0069]
[0070] where H(X) is the entropy value of feature X, p(x i ) is the probability of the feature value x i appearing, and n is the total number of feature values.
[0071] Monitor and record the network traffic over a period of time, count the number of occurrences of each feature value, and calculate the frequency of each feature value, that is, the number of occurrences of the feature value divided by the total number of data packets.
[0072] By calculating the traffic entropy value in real time and comparing it with the entropy value baseline under normal conditions, if the entropy value suddenly increases or decreases significantly, it may mean that there is abnormal traffic in the network, such as DDoS attacks and malicious scans. The traffic entropy value can reflect the stability and uniformity of network traffic. A higher entropy value may indicate that the network traffic distribution is relatively dispersed, and the utilization of network resources may not be efficient enough. A lower entropy value may indicate that the traffic is too concentrated on certain nodes or paths, and there may be a congestion risk.
[0073] In network traffic analysis, the change of the traffic entropy value over time constitutes a time series. By analyzing this time series, we can discover features such as the change trend, periodicity, seasonality of the traffic entropy value, as well as abnormal situations such as mutations. By analyzing the change trend and periodicity of the traffic entropy value time series, we can timely discover the mutation of the entropy value, which may indicate that the network has been attacked. For example, a DDoS attack will cause a sudden change in the traffic pattern, resulting in a mutation of the traffic entropy value. Analyze the change trend and periodicity of the traffic entropy value to predict future network traffic demands, reasonably allocate network resources, and avoid network congestion.
[0074] Such as Figures 1 to 2 shown.
[0075] The active learning method is used to screen false positive samples and false negative samples, and add them to the training data set to continuously improve the model training data. The elastic weight consolidation algorithm is adopted to effectively prevent the model from forgetting the important knowledge learned before when learning new data. Under the federated learning framework, with the help of differential privacy technology, it is ensured that local data privacy is fully protected during the multi-node collaborative training process. By using federated learning to add noise to the model gradient using differential privacy for local nodes:
[0076] g~=g+N(0,σ 2 Δg 2 I)
[0077] Where g is the original gradient, Δg is the gradient sensitivity, and σ is the noise intensity. In federated learning, if no privacy protection measures are taken, attackers may try to reverse-engineer the original data of local nodes through information such as model gradients. After adding noise, the gradient information is perturbed, making it difficult for attackers to accurately restore the original data from the gradients, effectively protecting the privacy of local node data. Differential privacy is achieved by adding noise to the model gradient. On the premise of ensuring the privacy of local node data, federated learning can proceed normally. Local nodes can safely participate in federated learning and share model update information without worrying about excessive leakage of data privacy, thus promoting the application of federated learning in more scenarios with high requirements for data privacy.
[0078] The above front, back, left, right, up, and down are all based on the Figure 1 in the accompanying drawings of the specification. According to the standard of the observer's perspective, the side of the device facing the observer is defined as the front, and the left side of the observer is defined as the left, and so on.
[0079] In the description of the present invention, it should be understood that the orientation or positional relationships indicated by the terms "center", "longitudinal", "transverse", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as limiting the protection scope of the present invention.
[0080] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A network security detection method based on artificial intelligence, characterized in that, The method includes the following steps: A1. Collect network traffic data, system log data, user behavior data, and external threat intelligence data to generate a multi-source heterogeneous dataset; A2. Preprocess the multi-source heterogeneous dataset, including data normalization, missing value filling, and noise filtering; A3. Extract features from the preprocessed data through a multi-modal fusion model, where: (1) Use a temporal convolutional network to extract traffic temporal features from network traffic data; (2) Use a natural language processing model to extract semantic features from system log data; (3) Use a graph neural network to model the interaction relationship between users, devices, and services for user behavior data; A4. Input the extracted multi-modal features into a hybrid detection engine, and the hybrid detection engine includes: (1) An anomaly detection module based on unsupervised learning, which is used to identify behaviors that deviate from a preset baseline; (2) A classification module based on supervised learning, which is used to determine the type of attack; (3) A policy adjustment module based on reinforcement learning, which is used to dynamically optimize the detection threshold; A5. Trigger response actions according to the detection results, including generating an alarm, blocking a connection, or isolating a device; A6. Update the multi-modal fusion model and the hybrid detection engine through an online incremental learning mechanism, including multi-node collaborative training under a federated learning framework.
2. A network security detection method based on artificial intelligence according to claim 1, According to the method described in claim 1, wherein the collection of network traffic data in step A1 includes: extracting metadata of encrypted traffic, including server name indication, certificate issuer information, and key exchange protocol type in the TLS handshake stage; performing deep packet inspection on non-encrypted traffic to extract application layer protocol headers and payload features.
3. A network security detection method based on artificial intelligence according to claim 1, According to the method described in claim 1, wherein the feature extraction of the multi-modal fusion model in step A3 further includes: using an attention mechanism to dynamically weight the contribution degrees of network traffic, system log, and user behavior features; generating a joint feature vector through feature concatenation or tensor fusion.
4. A network security detection method based on artificial intelligence according to claim 1, According to the method described in claim 1, wherein the anomaly detection module of the hybrid detection engine in step A4 can adopt any one of the following technologies: Calculating the reconstruction error based on a variational autoencoder, and identifying anomalies by comparing the differences between the reconstructed data and the original data; Evaluating the anomaly score based on an isolation forest, and determining whether it is an anomaly according to the degree to which a data point is isolated; Time series analysis based on traffic entropy value mutation detection, and detecting abnormal traffic by using sudden changes in traffic entropy values.
5. The network security detection method based on artificial intelligence according to claim 4, characterized in that: The time series analysis of traffic entropy value mutation detection divides network traffic data into time windows according to time series, calculates the entropy value for the traffic data within each time window, and the calculation formula for the entropy value is: where H(X) is the entropy value of feature X, and p(x i ) is the probability of the feature value x i occurring, and n is the total number of feature values.
6. A network security detection method based on artificial intelligence according to claim 1, According to the method described in claim 1, wherein the online incremental learning mechanism in step A6 includes: Actively learning and screening false positive samples and missed detection samples, and adding them to the training dataset; Adopting an elastic weight consolidation algorithm to prevent catastrophic forgetting; Under the federated learning framework, protecting local data privacy through differential privacy technology.
7. An artificial intelligence-based network security detection method according to claim 6, characterized in that: The federated learning adds noise to the model gradient using differential privacy for local nodes: g~=g+N(0,σ 2 Δg 2 I) Among them, g is the original gradient, Δg is the gradient sensitivity, and σ is the noise intensity.
8. A network security detection method based on artificial intelligence according to claim 1, The method according to claim 1, wherein The method further includes an adaptation process for the traffic of the industrial control system: Extract the function code of the TCP protocol and the register read / write mode; Construct a device state transition diagram and detect abnormal control instructions through a temporal graph convolutional network.
Citation Information
Patent Citations
Network security vulnerability detection method based on artificial intelligence
CN115037519A
Cited By
Flow collection system, threat analysis method and strategy generation method
CN120785652A
Safety monitoring intelligent management system based on big data Internet of Things
CN120856463A
Network security sensing method and device based on artificial intelligence and network information entropy
CN121077743A
Network security perception method and device based on artificial intelligence and network information entropy
CN121077743B
Methods, systems, and media for bi-modal understanding of natural languages and neural architectures
US20240037336A1