Network traffic aggregation analysis method based on deep learning
Through the network traffic aggregation analysis method based on deep learning, the LSTM model is used to perform timing modeling and incremental learning of network traffic, which solves the problem of difficulty in balancing adaptability and stability in complex dynamic network environments in the existing technology, and realizes dynamic updates and accurate portrayal of network traffic behavior, improving the timeliness and accuracy of abnormal traffic detection.
Patent Information
- Application Number
- CN202510672394.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-08-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing network traffic analysis methods are difficult to effectively capture the timing dependencies and deep behavior patterns of traffic data in complex and dynamic network environments, resulting in difficulty in balancing adaptability and stability, and the inability to accurately identify abnormal traffic and illegal access.
The network traffic aggregation analysis method based on deep learning is adopted to capture the original data packets from the network interface, extract the subset of traffic data packets with the specified source IP address, and use the LSTM model to perform timing modeling, dynamically filter relevant historical behavior patterns and timing fragments, and dynamic updates and accurate portrayal of network traffic behavior through traffic mode incremental aggregation learning.
Effectively capture the timing evolution laws of network traffic behavior, improve the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis, and be able to timely identify abnormal events and illegal activities in the network.
Smart Images

Figure CN120434008A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network traffic analysis, and more specifically, to a network traffic aggregation analysis method based on deep learning. Background Art
[0002] With the rapid development of internet technology and the increasing popularity of network applications, network traffic has exploded, and its complexity and dynamism have increased significantly. This trend is particularly pronounced in the context of the construction of new power systems. These new power systems have introduced a large number of distributed energy resources, smart loads, and low-voltage control services such as new power load management, distributed photovoltaics, and connected vehicle charging stations. The widespread deployment of these services has led to a surge in the number of edge computing devices and peripheral terminals. In power systems, power equipment often has numerous access points, small individual units, and uncontrollable physical security. They frequently interact with the main station, and some even directly connect to the open internet environment, significantly increasing the risk and attack surface of cyberattacks on the power grid. Therefore, effectively analyzing massive amounts of network traffic data and accurately characterizing its behavior patterns is crucial for identifying potential unauthorized access and abnormal operations, and ensuring the safe and stable operation of the power system.
[0003] In the field of network traffic analysis, as application scenarios become increasingly complex, traffic data exhibits significant dynamic and non-stationary characteristics. The real-time evolution of network environments, the sudden response to security incidents, and the rapid iteration of business needs result in not only long-term fluctuations in traffic patterns, but also sudden shifts due to localized anomalies. This dynamic nature requires that network traffic aggregation and analysis must be adaptable to multi-scale time windows, capturing long-term behavioral trends to support operational strategy formulation while promptly identifying short-term pattern shifts to prevent misjudgments. However, traditional network traffic analysis methods, such as port- and protocol-based statistics or simple flow aggregation, often struggle to capture the complex temporal dependencies and underlying behavioral patterns in traffic data. Aggregation techniques based on static rules or fixed time windows, with their inherent rigid analysis frameworks, often lead to two extreme outcomes when dealing with dynamic traffic changes: either excessive sensitivity leads to frequent and meaningless group reorganizations, undermining the stability required for operational decision-making; or delayed response leads to overlooking critical pattern shifts, creating blind spots in security threat detection. That is to say, in the network traffic aggregation analysis method, how to effectively establish and update the network traffic behavior pattern baseline of the source IP address and strike a balance between adaptability (sensitivity to changes in the real network traffic behavior pattern) and stability (robustness to noise and short-term fluctuations) is the core challenge faced by existing technologies.
[0004] Therefore, an optimized deep learning-based network traffic aggregation analysis method is expected. Summary of the Invention
[0005] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides a network traffic aggregation analysis method based on deep learning, which extracts a subset of traffic data packets of a specified source IP address from the original data packets captured by the network interface, and uses a deep learning algorithm to perform time series modeling on the subset of historical traffic data packets to capture the baseline behavior pattern of the network traffic of the source IP address. Furthermore, based on the latest network traffic time series characteristics currently obtained for the source IP address, multiple historical network traffic behavior pattern time series fragments that are most relevant to the current behavior pattern are dynamically screened to form a candidate attribution group, and by performing incremental traffic pattern aggregation learning on the latest network traffic time series pattern characteristics and candidate group characteristics, the behavioral migration of the latest traffic pattern relative to the historical group characteristics is mined to achieve dynamic update and accurate characterization of the network traffic behavior of the source IP address. This method can effectively capture the time series evolution law of network traffic behavior and improve the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis.
[0006] According to one aspect of the present application, a network traffic aggregation analysis method based on deep learning is provided, which includes:
[0007] Obtain candidate belonging groups of raw data packets captured through a network interface;
[0008] Extracting a subset of original data packets corresponding to the first source IP address from the candidate belonging groups of the original data packets;
[0009] Performing network traffic time series pattern feature extraction on a subset of original data packets corresponding to the first source IP address to obtain a sequence of local time series feature vectors of the network traffic of the first source IP address as a network traffic benchmark behavior encoding vector of the first source IP address;
[0010] Obtaining the latest network traffic time series feature vector of the first source IP address as a behavior embedding vector of the first source IP address;
[0011] Based on the latest network traffic time series feature vector, a state update based on traffic pattern incremental learning is performed on the sequence of the local time series feature vectors of the first source IP address network traffic to obtain a network traffic behavior state update encoding vector of the first source IP address.
[0012] Compared with the existing technology, the network traffic aggregation analysis method based on deep learning provided by this application extracts a subset of traffic packets of a specified source IP address from the original data packets captured by the network interface, and uses a deep learning algorithm to perform time series modeling on the subset of historical traffic packets to capture the baseline behavior pattern of the network traffic of the source IP address. Furthermore, based on the latest network traffic time series characteristics currently obtained by the source IP address, multiple historical network traffic behavior pattern time series fragments that are most relevant to the current behavior pattern are dynamically screened to form a candidate belonging group, and by performing incremental traffic pattern aggregation learning on the latest network traffic time series pattern characteristics and candidate group characteristics, the behavioral migration of the latest traffic pattern relative to the historical group characteristics is mined to achieve dynamic update and accurate characterization of the network traffic behavior of the source IP address. This method can effectively capture the time series evolution law of network traffic behavior and improve the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0014] Figure 1 Flowchart of a network traffic aggregation analysis method based on deep learning according to an embodiment of the present application.
[0015] Figure 2 Schematic diagram of data flow of a network traffic aggregation analysis method based on deep learning according to an embodiment of the present application.
[0016] Figure 3 This is a flowchart of sub-step S5 of the deep learning-based network traffic aggregation analysis method according to an embodiment of the present application.
[0017] Figure 4 This is a flowchart of sub-step S52 of the deep learning-based network traffic aggregation analysis method according to an embodiment of the present application. DETAILED DESCRIPTION
[0018] As used in this application and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not intended to refer to the singular but may include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.
[0019] Although the present application makes various references to certain modules in the system according to embodiments of the present application, any number of different modules can be used and run on the user terminal and / or server. The modules are illustrative only, and different aspects of the system and method can use different modules.
[0020] Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, the various steps may be processed in reverse order or simultaneously, as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0021] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0022] It is worth noting that in this application, all actions to obtain data are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.
[0023] In response to the technical problems described in the above background technology, this application proposes a network traffic aggregation analysis method based on deep learning, which extracts a subset of traffic packets of a specified source IP address from the original data packets captured by the network interface, and uses a deep learning algorithm to perform time series modeling on the subset of historical traffic packets to capture the baseline behavior pattern of the network traffic of the source IP address. Furthermore, based on the latest network traffic time series characteristics currently obtained by the source IP address, multiple historical network traffic behavior pattern time series fragments that are most relevant to the current behavior pattern are dynamically screened to form a candidate attribution group, and by performing incremental traffic pattern aggregation learning on the latest network traffic time series pattern characteristics and candidate group characteristics, the behavioral migration of the latest traffic pattern relative to the historical group characteristics is mined to achieve dynamic update and accurate characterization of the network traffic behavior of the source IP address. This method can effectively capture the time series evolution law of network traffic behavior and improve the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis.
[0024] Figure 1 Flowchart of a network traffic aggregation analysis method based on deep learning according to an embodiment of the present application. Figure 2 Schematic diagram of data flow of the network traffic aggregation analysis method based on deep learning according to the embodiment of the present application. Figure 1 and Figure 2As shown, the network traffic aggregation analysis method based on deep learning includes the following steps: S1, obtaining candidate belonging groups of original data packets captured through a network interface; S2, extracting a subset of original data packets corresponding to a first source IP address from the candidate belonging groups of the original data packets; S3, performing network traffic timing pattern feature extraction on the subset of original data packets corresponding to the first source IP address to obtain a sequence of local timing feature vectors of network traffic of the first source IP address as a network traffic baseline behavior encoding vector of the first source IP address; S4, obtaining the latest network traffic timing feature vector of the first source IP address as a behavior embedding vector of the first source IP address; S5, based on the latest network traffic timing feature vector, performing a state update based on traffic pattern incremental learning on the sequence of local timing feature vectors of network traffic of the first source IP address to obtain a network traffic behavior state update encoding vector of the first source IP address.
[0025] In the above-mentioned network traffic aggregation analysis method based on deep learning, the step S1 obtains the candidate belonging group of the original data packet captured through the network interface. It should be understood that due to the complex and changeable network environment, and the existing statistical or rule-based network traffic analysis method is difficult to capture the deep timing dependence and subtle behavior pattern changes in the source IP (for example, a low-voltage control terminal in the power system, or a server in the enterprise intranet), it is impossible to perform deep, dynamic and context-aware aggregation analysis. Therefore, in order to accurately characterize and track the evolution of the traffic behavior pattern of the source IP, this application is based on the principle of full traffic capture and data-driven analysis, and collects the original data packet set transmitted by the network interface in real time to achieve lossless recording of traffic behavior and underlying feature retention. Specifically, all the original data packets (including header information, load content and timestamp) passing through the network link can be captured by bypass mirroring or probe deployment, and temporarily cached using a ring buffer or distributed storage technology to ensure the integrity and timing consistency of the traffic data. In this way, high-fidelity original input can be provided for subsequent analysis.
[0026] During the specific implementation process, it is first necessary to deploy a data collection mechanism at the network level to ensure that all original data packets passing through the network interface can be completely and continuously captured. Specifically, bypass mirroring or probe deployment can be used to copy all data streams transmitted on the link to a dedicated data collection node in real time without interfering with normal business communications. The collected data packets should include but are not limited to the Ethernet frame header, IP header, transport layer protocol header (such as TCP / UDP), application layer payload content, and accurate timestamp information. This fine-grained information provides rich underlying semantic support for subsequent traffic behavior analysis based on the source IP address.
[0027] After completing the capture of the original data packets, the next key task is to perform preliminary classification processing on these massive data, that is, to extract the potential "candidate belonging group" to which each data packet belongs based on the source IP address field. This process is not a simple static grouping, but requires a multi-dimensional analysis combined with the dynamic characteristics of the network environment. For example, for a specific source IP address, the traffic generated in the network may be distributed in multiple different time periods, carried on different protocol types, and interact with multiple destination IP addresses. Therefore, in the process of constructing candidate belonging groups, it is necessary to comprehensively consider factors such as the time attributes, protocol characteristics, five-tuple information (source IP, source port, destination IP, destination port, protocol type) and session duration of the data packet to form a preliminary traffic behavior profile.
[0028] It's worth noting that because network traffic itself has significant bursty and non-steady-state characteristics, the behavior of certain source IP addresses may show drastic changes in a short period of time. Such changes may be caused by normal business fluctuations or may be a precursor to abnormal events (such as illegal access, malicious scanning, etc.). Therefore, during the construction of candidate attribution groups, it is necessary to introduce a certain dynamic adjustment mechanism to avoid information omissions or misjudgments caused by one-time static division. For example, a sliding window mechanism can be used to perform rolling updates on traffic data over a period of time to ensure that the candidate groups always contain the latest behavior samples, thereby improving the timeliness and accuracy of subsequent analysis.
[0029] Furthermore, given that a large number of terminal devices in power systems possess low power consumption and weak computing capabilities, their activity cycles within the network are often intermittent, and the same device may exhibit distinct communication patterns at different times. Therefore, the construction of candidate affiliation groups requires the introduction of an activity-based screening strategy to identify source IP addresses that have consistently communicated within a specified time window and include them in the candidate set as key targets. For IP addresses that have been inactive for a long time, their priority can be appropriately lowered or temporarily excluded to reduce inefficient computational overhead.
[0030] To further improve the accuracy and representativeness of candidate attribution groups, the identity attributes of source IP addresses can be annotated by combining network topology information and static configuration data in the asset management system. For example, if a source IP address is labeled as a "distributed photovoltaic controller" in the asset management database, its traffic behavior should reflect characteristics that match typical business scenarios such as energy scheduling and status reporting. By clustering the historical traffic of such known IP addresses, several representative behavioral baselines can be extracted, which can then be used to guide candidate attribution judgments for unknown IP addresses and enhance the contextual awareness of the overall analysis system.
[0031] At the same time, considering that in a high traffic density environment, the process of constructing candidate attribution groups may face problems such as large data volumes and high processing delays, it is also necessary to introduce efficient caching and indexing mechanisms to ensure the efficiency of data retrieval and matching. At the same time, in the actual deployment process, it is also possible that multiple source IP addresses share the same physical interface or virtual machine instance, especially in cloud computing or containerized environments. In such cases, the construction of candidate attribution groups also needs to introduce more fine-grained isolation strategies to ensure that the traffic behavior of each source IP address can be independently captured and classified to avoid behavioral confusion caused by resource reuse. To this end, additional metadata such as VLAN tags, tenant IDs, and container identifiers can be added during the data collection phase, and these additional dimensions can be used as one of the screening criteria during the group division process, thereby improving the purity and parsing capabilities of the candidate attribution groups.
[0032] In the above-mentioned network traffic aggregation analysis method based on deep learning, the step S2 extracts a subset of the original data packets corresponding to the first source IP address from the candidate belonging group of the original data packet. It should be understood that due to the presence of a large number of mixed source IP addresses in the network traffic, direct global analysis will lead to a waste of computing resources and it is difficult to focus on individual behavior characteristics. Therefore, in order to achieve targeted behavior modeling of a specific source IP address, this application is based on the principle of IP address filtering and traffic slicing, by filtering out a subset of data packets corresponding to the target source IP address (i.e., the first source IP address) from the original data packet set to construct an exclusive behavior analysis context for the IP. Specifically, this application is based on an exact match of the source IP field in the quintuple (source IP, destination IP, source port, destination port, protocol type), extracts all traffic packets belonging to the first source IP address, and arranges them in timestamp order to form a time series data stream. In this way, it is possible to isolate irrelevant traffic interference, focus on the behavior pattern of the target IP, and provide structured input data for subsequent time series modeling.
[0033] In the above-mentioned network traffic aggregation analysis method based on deep learning, the step S3 performs network traffic time series pattern feature extraction on a subset of the original data packets corresponding to the first source IP address to obtain a sequence of local time series feature vectors of the network traffic of the first source IP address as the network traffic baseline behavior encoding vector of the first source IP address. In a specific example of the present application, the step S3 includes: using a network traffic time series pattern feature extractor based on an LSTM model to perform feature extraction on a subset of the original data packets corresponding to the first source IP address to obtain a sequence of local time series feature vectors of the network traffic of the first source IP address. It should be understood that since network traffic behavior has long-term and short-term dependency characteristics (such as periodic access, burst transmission and protocol interaction), traditional statistical methods cannot model such complex time series associations. Therefore, in order to capture the baseline behavior pattern of the source IP address, the present application is based on the time series modeling principle of the long short-term memory network (LSTM), and features a subset of historical traffic data packets by training the LSTM model to generate a sequence of local time series feature vectors of the network traffic of the first source IP address that characterizes the traffic behavior baseline of the first source IP address. Specifically, first, the subset of the original data packets corresponding to the first source IP address is divided into sliding windows of fixed length (such as each window contains 100 consecutive data packets), and the data packet attributes in each window (such as packet size, transmission interval, protocol type) are normalized into multi-dimensional time series signals. After input into the LSTM network, the time dependency of the multi-dimensional features of each time step in the window is learned through its gating mechanism (input gate, forget gate, output gate), and finally the local time series feature vector of the network traffic of the first source IP address is extracted from the hidden state of the last time step. The local time series feature vectors of the network traffic of the first source IP address of each local window are arranged in chronological order to form a sequence of local time series feature vectors of the network traffic of the first source IP address. In this way, the original traffic data can be converted into high-dimensional semantic features, encoding the core laws of historical behavior patterns (such as normal access rhythm, legal protocol interaction), and providing a comparison benchmark for the subsequent dynamic update of network traffic behavior patterns.
[0034] In the above-mentioned network traffic aggregation analysis method based on deep learning, the step S4 obtains the latest network traffic time series feature vector of the first source IP address as the behavior embedding vector of the first source IP address. It should be understood that since the network traffic behavior has the characteristics of real-time evolution, in order to capture the current behavior state of the source IP address, the present application obtains the latest network traffic time series data packet of the first source IP address in real time, and based on the same time series encoding method as above, uses the LSTM model to process the latest traffic data packet of the source IP address, and finally outputs the latest network traffic time series feature vector as the current behavior pattern representation of the first source IP address. Specifically, this process ensures the consistency of the feature space by sharing LSTM model parameters (homogeneous to the historical model), avoids semantic deviation due to model differences, and can map the latest traffic behavior to the same feature space as the historical benchmark, providing a comparable real-time behavior representation for subsequent correlation analysis.
[0035] In the above-mentioned network traffic aggregation analysis method based on deep learning, the step S5, based on the latest network traffic time series feature vector, performs a state update based on traffic pattern incremental learning on the sequence of local time series feature vectors of the first source IP address network traffic to obtain the network traffic behavior state update encoding vector of the first source IP address. Figure 3 Flowchart of sub-step S5 of the network traffic aggregation analysis method based on deep learning according to an embodiment of the present application. Figure 3 As shown, the step S5 includes the steps of: S51, extracting the candidate belonging group of the first source IP address network traffic local timing feature vector from the network traffic benchmark behavior coding vector of the first source IP address based on the semantic correlation between the latest network traffic timing feature vector and each first source IP address network traffic local timing feature vector in the sequence of the first source IP address network traffic local timing feature vector; S52, inputting the latest network traffic timing feature vector of the first source IP address and the candidate belonging group of the first source IP address network traffic local timing feature vector into the network traffic aggregation state update network to obtain the network traffic behavior state update coding vector of the first source IP address.
[0036] Specifically, in a specific example of the present application, the step S51 includes: calculating the cosine similarity between the latest network traffic timing feature vector and each first source IP address network traffic local timing feature vector in the sequence of the first source IP address network traffic local timing feature vector as the semantic correlation, and sorting the semantic correlation from high to low, selecting the first source IP address network traffic local timing feature vectors corresponding to the first N semantic correlations as the candidate belonging group of the first source IP address network traffic local timing feature vector, where N is a preset positive integer. Specifically, since the network traffic behavior pattern has both gradual evolution and sudden offset. Therefore, in order to balance stability and adaptability in the dynamic update of network traffic behavior patterns, this application is based on the principle of semantic similarity measurement. By calculating the cosine similarity between the latest behavior embedding vector of the first source IP address and the local time series feature vectors of the network traffic of each first source IP address in the historical benchmark feature, the top N local time series feature vectors of the network traffic of the first source IP address with the highest semantic correlation are screened out to construct a candidate belonging group. In essence, it searches for the benchmark pattern cluster closest to the current behavior in the feature manifold as a reference set for the possible evolution of the current behavior pattern. In this way, the stability of historical behavior is taken into account, and it can flexibly respond to sudden behavioral deviations, which helps to identify whether the current behavior belongs to the continuation of the historical pattern, a gradual branch, or a completely new category, thereby avoiding the computational redundancy and misjudgment risk caused by full pattern matching, and providing a basis for the dynamic aggregation update of the subsequent network traffic behavior pattern status.
[0037] Figure 4 FIG is a flowchart of sub-step S52 of the network traffic aggregation analysis method based on deep learning according to an embodiment of the present application. Figure 4 As shown, the step S52 includes the steps of: S521, constructing a first source IP address network traffic local time series feature node association topology matrix based on the internal association topology structure of the candidate belonging group of the first source IP address network traffic local time series feature vector; S522, performing a graph structure analysis on the candidate belonging group of the first source IP address network traffic local time series feature vector based on the first source IP address network traffic local time series feature node association topology matrix to obtain a first source IP address network traffic local time series feature graph spectrum coding matrix; S523, performing feature query response coding on the latest network traffic time series feature vector of the first source IP address and the first source IP address network traffic local time series feature graph spectrum coding matrix to obtain a network traffic behavior state update coding vector of the first source IP address.
[0038] More specifically, step S521 includes: first, performing information condensation on each first source IP address network traffic local time series feature vector in the candidate belonging group of the first source IP address network traffic local time series feature vector to obtain a candidate belonging group of the first source IP address network traffic local time series feature condensation encoding vector, which is expressed as follows:
[0039] S={s1,s2,...,s i ,...,s n}
[0040]
[0041] H={h1,h2,...,h i ,...,h n}
[0042] Among them, S represents the candidate belonging group of the local time series feature vector of the network traffic of the first source IP address, s1, s2, s i and s n denote the first, second, i-th, and n-th local time series feature vectors of the network traffic of the first source IP address in the candidate belonging group of the local time series feature vector of the network traffic of the first source IP address, respectively. ‖·‖ denotes the calculation norm, ReLu(·) denotes the ReLu activation function, and W c and b c denote the weight matrix and bias term respectively, H denotes the candidate belonging group of the local temporal feature condensed coding vector of the network traffic of the first source IP address, h1, h2, h i and h n They respectively represent the 1st, 2nd, i-th and n-th first source IP address network traffic local time series feature condensed coding vectors in the candidate belonging group of the first source IP address network traffic local time series feature condensed coding vector.
[0043] That is, the irrelevant information in the local time series feature vector of the network traffic of the first source IP address is removed, and its most representative core semantics are extracted to achieve projection and refinement of the semantic space, rather than simple dimensionality reduction, thereby obtaining a more representative and measurable candidate belonging group of the concentrated coding vector of the local time series feature of the network traffic of the first source IP address, so as to more accurately characterize the network traffic behavior pattern. This enables subsequent network traffic analysis based on the concentrated coding vector of the local time series feature of the network traffic of the first source IP address to more efficiently and accurately identify the migration of behavioral patterns in network traffic, avoiding misjudgments and detection blind spots caused by the complexity of the local time series features of the network traffic of the first source IP address.
[0044] Then, the feature correlation between any two first source IP address network traffic local time series feature condensed coding vectors in the candidate belonging group of the first source IP address network traffic local time series feature condensed coding vector is calculated to obtain the first source IP address network traffic local time series feature node correlation topology matrix, which is expressed as follows:
[0045]
[0046] Among them, h j The jth first source IP address network traffic local time series feature condensed coding vector in the candidate belonging group of the first source IP address network traffic local time series feature condensed coding vector, W r and b r Represent the local feature association weight matrix and the local feature association bias term, r i,j Indicates h i and h j The feature correlation between them, L represents the length of the local temporal feature condensed encoding vector of the first source IP address network traffic, A i,j Represents r i,j The element value at the (i, j)th position in the inter-node association topology matrix corresponding to the local timing feature of the network traffic of the first source IP address.
[0047] Specifically, a topological matrix of inter-node correlations of local temporal features of network traffic from the first source IP address is constructed. This explicitly displays the relationships between the condensed encoding vectors of local temporal features of network traffic from each first source IP address, allowing for a clear understanding of the structure and characteristics of network traffic behavior patterns. This allows for in-depth analysis of the temporal evolution of network traffic behavior, more accurately capturing dynamic changes in network traffic behavior and promptly identifying migrations in traffic patterns. This provides a more precise basis for abnormal traffic detection and behavioral pattern analysis, while achieving a balance between adaptability and stability.
[0048] More specifically, step S522 includes: first, inputting the first source IP address network traffic local time series feature node correlation topology matrix into the gated mask network to obtain the first source IP address network traffic local time series feature node sparse correlation topology matrix, which is expressed as:
[0049]
[0050] A i,j '=M i,j ·A i,j
[0051] Among them, Sigmoid(·) represents the sigmoid activation function, (·) T represents the transpose of a vector, Indicates division by position, W g and b g Represent the mask weight vector and mask bias weight parameters respectively, M i,j Indicates h i and h j The first source IP address network traffic local time series feature associated mask weight, A i,j ' indicates A i,j The element value at the (i, j)th position in the sparse correlation topology matrix between nodes corresponding to the local timing feature of the network traffic of the first source IP address.
[0052] That is, the correlation topology matrix between the nodes of the local temporal feature of the network traffic of the first source IP address is sparsely processed through the gated mask network, the most critical semantic connections are extracted, and the graph structure is optimized to make its topological structure clearer and more stable. The sparse correlation topology matrix between the nodes of the local temporal feature of the network traffic of the first source IP address is obtained, so that the model focuses on more important semantic relationships, significantly reduces the computational complexity of subsequent graph convolution, improves the robustness of the model to noise, and effectively avoids the over-smoothing problem caused by excessive information propagation.
[0053] Then, the candidate belonging group of the concentrated coding vector of the local time series feature of the first source IP address network traffic and the sparse correlation topology matrix between nodes of the local time series feature of the first source IP address network traffic are input into the graph-like construction engine based on the graph convolutional network model to obtain the graph-like coding matrix of the local time series feature of the first source IP address network traffic, which is expressed as follows:
[0054]
[0055] Where A' represents the sparse correlation topology matrix between nodes of the local time series feature of the network traffic of the first source IP address, GCN(·) represents the graph convolutional network, n represents the number of concentrated encoding vectors of the local time series feature of the network traffic of the first source IP address, M g Represents the graph-like encoding matrix of the local temporal characteristics of the network traffic of the first source IP address.
[0056] That is, using a graph convolutional network, the candidate attribution groups of the concentrated encoding vector of the local temporal features of the network traffic from the first source IP address and the sparse correlation topology matrix between the nodes of the local temporal features of the network traffic from the first source IP address are processed to achieve a holistic, structured, deeply embedded representation of network traffic behavior and capture a wider range of contextual information. Based on this, each row vector in the resulting graph-like encoding matrix of the local temporal features of the network traffic from the first source IP address contains the context-aware position and semantic role of the corresponding feature in its feature manifold, which can capture high-order relationships and global structural information beyond similarity, making the analysis of network traffic behavior patterns more accurate and comprehensive.
[0057] More specifically, step S523 includes: performing feature interaction attention aggregation based on feature query response strength on the latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address to obtain the network traffic behavior state update encoding vector of the first source IP address. In a specific example of the present application, step S523 further includes: first, calculating the feature interaction response strength between the latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address to obtain a sequence of latest network traffic behavior query response attention weights, which is expressed as follows:
[0058] α i =softmax(u T g i )
[0059] Among them, u represents the latest network traffic time series feature vector, g i Represents the i-th row vector in the graph-like encoding matrix of the local temporal characteristics of the network traffic of the first source IP address, α i Represents the i-th latest network traffic behavior query response attention weight in the sequence of latest network traffic behavior query response attention weights.
[0060] That is, by quantifying the degree of correlation between the latest network traffic time series feature vector and each row vector in the graph encoding matrix of the local time series feature of the first source IP address network traffic, the historical time series fragments most relevant to the current behavior pattern are screened out, providing a weight basis for subsequent dynamic aggregation, allowing the model to focus on historical features that have a greater impact on the current traffic behavior pattern. In this way, the sequence of attention weights generated for the latest network traffic behavior query response can achieve adaptive selection of historical features, highlighting the effective interaction between key historical patterns and current features, while suppressing interference from irrelevant or minor features. It filters noise while adapting to real behavior changes, and enhances the pertinence and robustness of behavioral pattern baseline updates.
[0061] Then, based on the sequence of attention weights of the latest network traffic behavior query response, the correlation interaction features between the latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series feature of the first source IP address network traffic are weightedly aggregated by position to obtain the network traffic behavior state update encoding vector of the first source IP address, which is expressed as follows:
[0062] v r =∑ i α i (u⊙g i )
[0063] Among them, ⊙ represents the point product by position, v r A network traffic behavior state update encoding vector representing the first source IP address.
[0064] Specifically, by combining the sequence of attention weights for the latest network traffic behavior query responses, the correlation and interaction features between the latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series features of the first source IP address's network traffic are weighted and aggregated, effectively integrating current traffic features with historical behavior pattern information to accurately characterize the current network traffic behavior state of the first source IP address. In this way, the resulting updated encoding vector for network traffic behavior state can accurately reflect the location and relationship of the current traffic pattern in the semantic space of historical behavior patterns in complex and changing network environments, making the model's characterization of network traffic behavior more accurate and dynamic, and improving the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis.
[0065] In particular, although the graph neural network model has captured the high-order relationship and global structural information under the graph structure relative to the concentrated encoding vector of the local temporal feature of the network traffic of each first source IP address, due to the low-density topology introduced by the gated mask network to the topological structure of the graph, the row vectors g in the graph spectrum encoding matrix of the local temporal feature of the network traffic of the first source IP address are not well-defined. i , we still hope that it can show the same statistical laws as much as possible in the multi-order global distribution dimension outside the graph structure, that is, we hope to achieve each row vector g i Full-band statistical correlation. Based on this, in a preferred example of the present application, the step S523 includes: performing global distribution consistency regularization on each row vector in the graph-like coding matrix of the local time series feature of the network traffic of the first source IP address to obtain the optimized graph-like coding matrix of the local time series feature of the network traffic of the first source IP address; and then performing feature interactive attention aggregation based on feature query response intensity on each row vector in the latest network traffic time series feature vector and the optimized graph-like coding matrix of the local time series feature of the network traffic of the first source IP address to obtain the network traffic behavior state update coding vector of the first source IP address.
[0066] Specifically, first, the semi-ring cosine topology is used to calculate each row vector g i Rigid projection of the neighborhood structure:
[0067]
[0068] Among them, |·| means calculating the absolute value, g uThe mean vector g is obtained by averaging the row vectors in the spectral encoding matrix according to their positions, representing the local temporal characteristics of the network traffic of the first source IP address. i Indicates g i The corresponding neighborhood structure rigid projection vector.
[0069] Then, calculate the neighborhood structure rigid projection vector g i′ Time-varying aggregation measure of :
[0070]
[0071] Among them, g ij′ Indicates g ′i The eigenvalue of the jth position, ln(·) represents the logarithmic function with e as the base, r i represents a time-varying aggregate measure.
[0072] Finally, the time-varying aggregation measure r i For the row vector g i Perform weighted optimization:
[0073] g i′ =r i g i
[0074] Among them, g i′ Represents the i-th row vector in the graph encoding matrix for optimizing the local temporal characteristics of network traffic of the first source IP address.
[0075] That is, considering that the global multi-order statistical characteristics are mainly dominated by multi-order moment statistics, in order to make the global distribution correlation topology in different row vectors g i The time-varying aggregation measure under the structural constraint neighborhood is used to constrain the global time-varying symmetry, thereby ensuring the uniform propagation of global distribution features under the graph structure, avoiding the statistical decoupling effect under the graph structure, and thus improving the subsequent feature interaction effect with the latest traffic pattern features.
[0076] In summary, a network traffic aggregation analysis method based on deep learning according to an embodiment of the present application is illustrated, which extracts a subset of traffic packets of a specified source IP address from the original data packets captured by the network interface, and uses a deep learning algorithm to perform time series modeling on the subset of historical traffic packets to capture the baseline behavior pattern of the network traffic of the source IP address. Furthermore, based on the latest network traffic time series features currently obtained for the source IP address, multiple historical network traffic behavior pattern time series segments that are most relevant to the current behavior pattern are dynamically screened to form a candidate attribution group, and by performing incremental traffic pattern aggregation learning on the latest network traffic time series pattern features and the candidate group features, the behavioral migration of the latest traffic pattern relative to the historical group features is mined to achieve dynamic updating and accurate characterization of the network traffic behavior of the source IP address. This method can effectively capture the time series evolution law of network traffic behavior and improve the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis.
[0077] The basic principles of the present invention have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in the present invention are merely illustrative and non-limiting, and should not be construed as necessarily possessed by each embodiment of the present invention. Furthermore, the specific details of the above embodiments are provided for illustrative purposes and to facilitate understanding, and are not intended to be limiting. These details do not necessarily limit the present invention to being implemented using these specific details.
[0078] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, please refer to the relevant description of other embodiments. In the several embodiments provided by the present invention, it should be understood that the disclosed system and method can be implemented in other ways. For example, the system embodiment described above is only schematic. For example, the unit division is only a logical function division, and there may be other division methods in actual implementation. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.
[0079] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be encompassed therein. Any reference to a figure in a claim should not be construed as limiting the claim to which it relates.
[0080] In addition, it is obvious that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units stated in the system claims can also be implemented by one unit through software or hardware.
[0081] Finally, it should be noted that the above description has been provided for purposes of illustration and description. Furthermore, the above embodiments are intended only to illustrate the technical solutions of the present invention and are not intended to be limiting. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art will appreciate that the technical solutions of the present invention may be modified or replaced with equivalents without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A network traffic aggregation analysis method based on deep learning, characterized in that: include: Obtain candidate belonging groups of raw data packets captured through a network interface; Extracting a subset of original data packets corresponding to the first source IP address from the candidate belonging groups of the original data packets; Performing network traffic time series pattern feature extraction on a subset of original data packets corresponding to the first source IP address to obtain a sequence of local time series feature vectors of the network traffic of the first source IP address as a network traffic benchmark behavior encoding vector of the first source IP address; Obtaining the latest network traffic time series feature vector of the first source IP address as a behavior embedding vector of the first source IP address; Based on the latest network traffic time series feature vector, a state update based on traffic pattern incremental learning is performed on the sequence of the local time series feature vectors of the first source IP address network traffic to obtain a network traffic behavior state update encoding vector of the first source IP address.
2. The network traffic aggregation analysis method based on deep learning according to claim 1 is characterized in that: Performing network traffic time series pattern feature extraction on a subset of original data packets corresponding to the first source IP address to obtain a sequence of local time series feature vectors of the network traffic of the first source IP address as a network traffic baseline behavior encoding vector of the first source IP address, including: A network traffic timing pattern feature extractor based on an LSTM model is used to perform feature extraction on a subset of original data packets corresponding to the first source IP address to obtain a sequence of local timing feature vectors of the network traffic of the first source IP address.
3. The network traffic aggregation analysis method based on deep learning according to claim 2 is characterized in that: Based on the latest network traffic time series feature vector, performing a state update based on traffic pattern incremental learning on a sequence of local time series feature vectors of network traffic of the first source IP address to obtain a network traffic behavior state update encoding vector of the first source IP address, including: Extracting a candidate belonging group of the first source IP address network traffic local time series feature vector from the first source IP address network traffic benchmark behavior encoding vector based on the semantic association between the latest network traffic time series feature vector and each first source IP address network traffic local time series feature vector in the sequence of the first source IP address network traffic local time series feature vector; The latest network traffic timing feature vector of the first source IP address and the candidate belonging group of the local timing feature vector of the network traffic of the first source IP address are input into the network traffic aggregation state update network to obtain the network traffic behavior state update coding vector of the first source IP address.
4. The network traffic aggregation analysis method based on deep learning according to claim 3 is characterized in that: Extracting a candidate belonging group of the first source IP address network traffic local time series feature vector from the network traffic benchmark behavior encoding vector of the first source IP address based on the semantic association between the latest network traffic time series feature vector and each first source IP address network traffic local time series feature vector in the sequence of the first source IP address network traffic local time series feature vector includes: Calculate the cosine similarity between the latest network traffic timing feature vector and each first source IP address network traffic local timing feature vector in the sequence of the first source IP address network traffic local timing feature vector as the semantic association, and sort the semantic associations from high to low, and select the first source IP address network traffic local timing feature vectors corresponding to the top N semantic associations as the candidate belonging group of the first source IP address network traffic local timing feature vector, where N is a preset positive integer.
5. The network traffic aggregation analysis method based on deep learning according to claim 4 is characterized in that: Inputting the latest network traffic time series feature vector of the first source IP address and the candidate belonging group of the local network traffic time series feature vector of the first source IP address into a network traffic aggregation state update network to obtain a network traffic behavior state update coding vector of the first source IP address, including: Constructing a first source IP address network traffic local time series feature node correlation topology matrix based on the correlation topology structure within the candidate belonging group of the first source IP address network traffic local time series feature vector; Based on the inter-node correlation topology matrix of the local time series feature of the network traffic of the first source IP address, a graph structure analysis is performed on the candidate belonging groups of the local time series feature vector of the network traffic of the first source IP address to obtain a graph spectrum encoding matrix of the local time series feature of the network traffic of the first source IP address; The latest network traffic time series feature vector of the first source IP address and the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address are subjected to feature query response encoding to obtain the network traffic behavior state update encoding vector of the first source IP address.
6. The network traffic aggregation analysis method based on deep learning according to claim 5 is characterized in that: Based on the correlation topology structure within the candidate belonging group of the local time series feature vector of the network traffic of the first source IP address, a correlation topology matrix between nodes of the local time series feature of the network traffic of the first source IP address is constructed, including: Performing information condensation on each first source IP address network traffic local time series feature vector in the candidate belonging group of the first source IP address network traffic local time series feature vector to obtain a candidate belonging group of the first source IP address network traffic local time series feature condensation encoding vector; Calculate the feature correlation between any two first source IP address network traffic local time series feature condensed coding vectors in the candidate belonging group of the first source IP address network traffic local time series feature condensed coding vector to obtain the first source IP address network traffic local time series feature node correlation topology matrix.
7. The network traffic aggregation analysis method based on deep learning according to claim 6 is characterized in that: Based on the inter-node association topology matrix of the local time series feature of the network traffic of the first source IP address, a graph structure analysis is performed on the candidate belonging groups of the local time series feature vector of the network traffic of the first source IP address to obtain a graph spectrum encoding matrix of the local time series feature of the network traffic of the first source IP address, including: Inputting the first source IP address network traffic local time series feature node correlation topology matrix into the gated mask network to obtain the first source IP address network traffic local time series feature node sparse correlation topology matrix; The candidate belonging group of the concentrated coding vector of the local time series feature of the network traffic of the first source IP address and the sparse correlation topology matrix between the nodes of the local time series feature of the network traffic of the first source IP address are input into the graph-like construction engine based on the graph convolutional network model to obtain the graph-like coding matrix of the local time series feature of the network traffic of the first source IP address.
8. The network traffic aggregation analysis method based on deep learning according to claim 7 is characterized in that: Performing feature query response encoding on the latest network traffic time series feature vector of the first source IP address and the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address to obtain a network traffic behavior state update encoding vector of the first source IP address, including: The latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address are subjected to feature interactive attention aggregation based on the feature query response strength to obtain the network traffic behavior state update encoding vector of the first source IP address.
9. The network traffic aggregation analysis method based on deep learning according to claim 8 is characterized in that: Performing feature interactive attention aggregation based on feature query response strength on the latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address to obtain a network traffic behavior state update encoding vector of the first source IP address, including: Calculating the feature interaction response strength between the latest network traffic time series feature vector and each row vector in the graph-like encoding matrix of the local time series feature of the first source IP address network traffic to obtain a sequence of latest network traffic behavior query response attention weights; Based on the sequence of attention weights of the latest network traffic behavior query response, the associated interaction features between the latest network traffic time series feature vector and each row vector in the graph encoding matrix of the local time series feature of the network traffic of the first source IP address are weightedly aggregated by position to obtain the network traffic behavior state update encoding vector of the first source IP address.
10. The network traffic aggregation analysis method based on deep learning according to claim 7 is characterized in that: Performing feature query response encoding on the latest network traffic time series feature vector of the first source IP address and the graph-like encoding matrix of the local time series feature of the network traffic of the first source IP address to obtain a network traffic behavior state update encoding vector of the first source IP address, including: Performing global distribution consistency regularization on each row vector in the graph-like coding matrix of the local time series feature of the network traffic of the first source IP address to obtain an optimized graph-like coding matrix of the local time series feature of the network traffic of the first source IP address; The latest network traffic time series feature vector and each row vector in the optimized first source IP address network traffic local time series feature imitation graph encoding matrix are subjected to feature interactive attention aggregation based on feature query response strength to obtain the network traffic behavior state update encoding vector of the first source IP address.
Citation Information
Cited By
Intelligent image comparison method and system based on machine learning
CN120599295A
Network security policy optimization method and system based on network topology data flow analysis
CN121486019A