Network intrusion detection method, device and equipment

By constructing heterogeneous graph data and graph convolution models, the shortcomings of traditional network intrusion detection methods in new attacks and modal fusion are solved, and high-precision and adaptive intrusion detection are achieved.

CN120455116AActive Publication Date: 2025-08-08ZHENGZHOU UNIVERSITY OF AERONAUTICS +1

Patent Information

Application Number
CN202510699624.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-08
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

Traditional network intrusion detection methods are powerless when facing new attacks, and are difficult to make full use of complementary information between different modes, and lack the ability to integrate structural perception and adaptive features, resulting in low intrusion detection accuracy.

Method used

By acquiring network traffic data, preprocessing it, extracting multimodal feature sets, constructing heterogeneous graph data, and using detection models to perform graph-level feature vector analysis, combining graph convolution and attention mechanism for intrusion type determination.

Benefits of technology

It improves the detection accuracy of diverse network attacks, enhances the structural perception ability of complex attacks, and improves robustness and generalization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455116A_ABST
    Figure CN120455116A_ABST
Patent Text Reader

Abstract

The invention provides a network intrusion detection method, device and equipment, belongs to the technical field of network security, and solves the problems that a traditional network intrusion detection method is insufficient in cross-modal feature fusion, weak in complex attack modeling capability and poor in adaptive capability. The method comprises the following steps: acquiring network flow data; preprocessing the network traffic data to obtain a traffic data packet; performing feature extraction on the traffic data packet to obtain a multi-modal feature set; performing point-line analysis processing on the multi-modal feature set to obtain heterogeneous graph data; inputting the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector; and determining intrusion type data according to the graph-level feature vector. According to the scheme, the detection accuracy of diversified attacks is improved, the structure perception capability of complex attacks is enhanced, and the robustness and generalization are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network intrusion detection method, device and equipment. Background Art

[0002] In modern network security, intrusion detection is a critical component that impacts system protection capabilities, resource allocation efficiency, and security response timeliness. Traditional network intrusion detection systems (NIDS) are typically based on signature-based intrusion detection systems (SIDS) and anomaly-based intrustion detection systems (AIDS). These approaches each have their own advantages and disadvantages. SIDS, due to its heavy reliance on predefined signature libraries, is largely ineffective against new or mutated attack patterns. AIDS, due to its analysis of network communication behavioral patterns, may miss more subtle attacks embedded in individual packet payloads. Furthermore, existing network intrusion detection methods based on traditional machine learning-based NIDS technology often focus on extracting static features from a single modality, failing to fully leverage the complementary information across different modalities. Furthermore, most methods lack the ability to model complex attack behaviors through structured perception and adaptive feature fusion, making it difficult to accurately identify diverse intrusion patterns and resulting in low intrusion detection accuracy. Summary of the Invention

[0003] The present invention provides a network intrusion detection method, device and equipment, which improve the accuracy and generalization capability of intrusion detection.

[0004] In order to solve the above technical problems, the technical solutions of the present invention are as follows:

[0005] An embodiment of the present invention provides a network intrusion detection method, comprising:

[0006] Get network traffic data;

[0007] Preprocessing the network traffic data to obtain traffic data packets;

[0008] Extracting features from the traffic data packets to obtain a multimodal feature set;

[0009] Performing point and line analysis on the multimodal feature set to obtain heterogeneous graph data;

[0010] Inputting the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector;

[0011] Intrusion type data is determined according to the graph-level feature vector.

[0012] Optionally, obtain network traffic data, including:

[0013] Capture and process data on the preset network interface to obtain a traffic data file;

[0014] The traffic data file is parsed to obtain network traffic data.

[0015] Optionally, preprocessing the network traffic data to obtain a traffic data packet includes:

[0016] Performing address filtering on the network traffic data to obtain effective attack data;

[0017] Normalizing the effective attack data to obtain a normalized data set;

[0018] Perform sample balancing processing on the normalized data set to obtain a traffic data packet.

[0019] Optionally, feature extraction is performed on the traffic data packet to obtain a multimodal feature set, including:

[0020] Classifying and processing the traffic data packets according to flow types to obtain flow data;

[0021] Performing feature statistical processing on the flow data to obtain flow-level feature data;

[0022] Performing time series feature extraction processing on the flow-level feature data to obtain time series feature data;

[0023] Performing protocol identification processing on the traffic data packet to obtain protocol header metadata;

[0024] Encoding the traffic data packet to obtain payload encoded data;

[0025] Integrate the flow-level feature data and the time series feature data to obtain a plurality of first flow node feature vectors;

[0026] Integrate the protocol header metadata and the payload encoding data to obtain a plurality of first packet node feature vectors;

[0027] The multiple first flow node feature vectors and the multiple first packet node feature vectors are integrated to obtain a multimodal feature set.

[0028] Optionally, performing point and line analysis on the multimodal feature set to obtain heterogeneous graph data includes:

[0029] Determining a plurality of flow nodes according to the plurality of first flow node feature vectors of the multimodal feature set, wherein each flow node corresponds to a first flow node feature vector in the multimodal feature set;

[0030] Determining a plurality of packet nodes according to the plurality of first packet node feature vectors of the multimodal feature set, each packet node corresponding to a first packet node feature vector in the multimodal feature set;

[0031] Determine the first edge data based on the subordinate relationship between the flow node and the packet node;

[0032] Determining second edge data according to a temporal adjacent relationship between the plurality of packet nodes;

[0033] Integrating the first edge data and the second edge data to obtain edge set data;

[0034] updating the first flow node feature vector according to the first edge data to obtain a second flow node feature vector;

[0035] updating the first packet node feature vector according to the second edge data to obtain a second packet node feature vector;

[0036] Integrate the second flow node feature vector and the second packet node feature vector to obtain node set data;

[0037] The edge set data and the node set data are integrated to obtain heterogeneous graph data.

[0038] Optionally, the detection model processes the heterogeneous graph data including:

[0039] Performing graph convolution processing on the heterogeneous graph data to obtain node feature data;

[0040] Performing batch normalization on the node feature data to obtain normalized feature data;

[0041] Global pooling is performed on the normalized feature data to obtain a graph-level feature vector.

[0042] Optionally, determining intrusion type data according to the graph-level feature vector includes:

[0043] Performing a linear transformation on the graph-level feature vector to obtain a representation tensor;

[0044] Performing weight calculation on the representation tensor to obtain attention weight data;

[0045] Performing weighted fusion processing on the graph-level feature vector according to the attention weight data to obtain a fused graph-level representation vector;

[0046] An intrusion detection result is determined according to the fused graph-level representation vector.

[0047] An embodiment of the present invention further provides a network intrusion detection device, comprising:

[0048] Acquisition module, used to obtain network traffic data;

[0049] a processing module configured to pre-process the network traffic data to obtain traffic data packets; perform feature extraction on the traffic data packets to obtain a multimodal feature set; perform point-line analysis on the multimodal feature set to obtain heterogeneous graph data; and input the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector;

[0050] A determination module is used to determine intrusion type data according to the graph-level feature vector.

[0051] An embodiment of the present invention further provides a computing device, comprising: a processor and a memory storing a computer program, wherein the computer program executes the above method when executed by the processor.

[0052] An embodiment of the present invention further provides a computer-readable storage medium storing instructions, which, when executed on a computer, enable the computer to execute the above method.

[0053] The technical solution of the present invention includes at least the following effects:

[0054] The above-mentioned solution of the present invention obtains network traffic data; preprocesses the network traffic data to obtain traffic data packets; performs feature extraction on the traffic data packets to obtain a multimodal feature set; performs point and line analysis on the multimodal feature set to obtain heterogeneous graph data; inputs the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector; and determines the intrusion type data based on the graph-level feature vector, thereby improving the detection accuracy of diversified network attacks, enhancing the structural perception capability of complex attacks, and improving robustness and generalization. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 is a flow chart of a network intrusion detection method provided by an embodiment of the present invention;

[0056] Figure 2 This is a schematic diagram of the data processing process of the network intrusion detection method provided by an embodiment of the present invention;

[0057] Figure 3 Schematic diagram of the heterogeneous graph data construction process of the network intrusion detection method provided by an embodiment of the present invention;

[0058] Figure 4Schematic diagram of information aggregation between nodes in a detection model of a network intrusion detection method provided by an embodiment of the present invention;

[0059] Figure 5 is a structural diagram of a network intrusion detection device provided by an embodiment of the present invention;

[0060] Figure 6 It is a structural diagram of a computing device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0061] Exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.

[0062] like Figure 1 and Figure 2 As shown, an embodiment of the present invention provides a network intrusion detection method, comprising:

[0063] Step 11, obtaining network traffic data;

[0064] Step 12, pre-processing the network traffic data to obtain traffic data packets;

[0065] Step 13: extracting features from the traffic data packets to obtain a multimodal feature set;

[0066] Step 14: performing point and line analysis on the multimodal feature set to obtain heterogeneous graph data;

[0067] Step 15: Input the heterogeneous graph data into the detection model for processing to obtain a graph-level feature vector;

[0068] Step 16: Determine intrusion type data based on the graph-level feature vector.

[0069] In this example, network traffic data is first acquired using network traffic collection software, such as Wireshark or Snort. Wireshark is a network protocol analysis tool that can capture network packets in real time and provide detailed protocol parsing and filtering capabilities. Snort is an open-source network intrusion detection system that also has traffic collection capabilities and can capture and analyze traffic according to preset rules.

[0070] The collected raw network traffic data contains a lot of noise, redundant information, and data formats that do not meet the analysis requirements, and needs to be preprocessed; the purpose of preprocessing is to clean, convert, and format this data to make it more suitable for subsequent feature extraction and analysis.

[0071] The pre-processing process may include: data cleaning, removing duplicate data packets, erroneous data packets, and data packets not related to intrusion detection;

[0072] Data segmentation divides continuous network traffic data into individual data packets according to certain rules; data format conversion converts the collected network traffic data into a unified format to facilitate subsequent feature extraction algorithm processing.

[0073] After obtaining the traffic data packets, key information that can reflect network behavior and intrusion characteristics is extracted from the traffic data packets to form a multimodal feature set;

[0074] The feature extraction process may include: Statistical feature extraction, which calculates statistical features of traffic packets, such as packet size, number of packets, and packet arrival time interval. For example, counting the number of packets sent from a specific IP address over a period of time. An abnormal increase in this number may indicate network scanning or attack activity. Protocol feature extraction, which analyzes the protocol type and related features used in traffic packets. Different network protocols have different characteristics and behavior patterns. Extracting protocol features can identify abnormal protocol usage. For example, detecting protocol packets that should not normally appear on a port may indicate an intrusion. Content feature extraction, which analyzes the payload content of packets to extract content features. For example, deep packet inspection techniques can be used to check for content features such as malicious code or attack instructions. Multimodal fusion, which combines the extracted statistical, protocol, and content features to form a multimodal feature set. Multimodal feature sets can comprehensively reflect multiple aspects of network traffic, improving the accuracy and robustness of intrusion detection. For example, features such as packet size, protocol type, and specific keywords in the payload content can be combined to form a comprehensive feature vector.

[0075] After determining the multimodal feature set, it is converted into a heterogeneous graph data structure that is easier for machine learning models to process through point-line analysis.

[0076] The point-line analysis processing process may include: node construction, which treats different entities in the multimodal feature set, such as IP addresses, port numbers, protocol types, etc., as nodes in the graph. For example, each unique IP address is treated as a node, and each port number is also treated as a node. Edge construction, which constructs edges in the graph based on the relationships between entities, such as communication connections, protocol associations, etc. For example, if there is a communication connection between two IP addresses, an edge is constructed between their corresponding nodes; if a data packet uses a specific protocol, an edge is constructed between the protocol node and the relevant IP address node. Heterogeneous graph generation, which generates heterogeneous graph data through the above-mentioned node and edge construction. Heterogeneous graphs can contain different types of nodes and edges, and can more comprehensively represent the complex relationships and patterns in network traffic. For example, in a heterogeneous graph, there can be nodes representing IP addresses, nodes representing protocols, and nodes representing ports. Different types of nodes are connected by different types of edges, forming a complex network structure.

[0077] After obtaining heterogeneous graph data, it is input into a detection model for processing. The detection model processes and analyzes the heterogeneous graph data, determines whether network traffic contains intrusions, and outputs a graph-level feature vector. The specific process may include: Model selection: selecting a deep learning model suitable for processing graph data, such as a graph neural network (GNN) model. GNN models can effectively capture node relationships and patterns in graph-structured data and are highly applicable to network intrusion detection. Model training: Using a large amount of labeled data, the detection model is trained to learn the characteristic patterns of normal and intrusion network traffic. During the training process, the model parameters are continuously adjusted through an optimization algorithm to improve the model's accuracy and generalization capabilities. Output: After inputting the heterogeneous graph data into the trained detection model, the model outputs a graph-level feature vector. Each element in this vector represents the probability or confidence level of the network traffic belonging to different categories (e.g., normal or different intrusion types).

[0078] Finally, the type of network intrusion is determined based on the graph-level feature vector. The specific process may include: threshold judgment, setting an appropriate threshold, and comparing the probability value in the graph-level feature vector with the threshold. If the probability value of a certain category exceeds the threshold, the network traffic is determined to belong to that category. Category mapping, determining the intrusion type data based on the category corresponding to the maximum probability value in the graph-level feature vector. For example, if the probability of "DDoS attack" in the graph-level feature vector is the highest, the network traffic is determined to be a DDoS attack type. Result feedback, feeding back the determined intrusion type data to the network administrator or security system so that appropriate measures can be taken in a timely manner, such as blocking the attack source and repairing vulnerabilities.

[0079] The solution described in this embodiment simulates adversarial interactions between attackers and target devices, constructing highly realistic network threat scenarios such as distributed denial of service (DDoS), denial of service (DoS), network reconnaissance, web-based application layer attacks, and brute-force attacks. Secondly, multimodal feature extraction and fusion are performed, accurately filtering based on the attacker's MAC address, retaining only traffic samples whose source or destination MAC addresses match a known attacker address database as valid attack data. Finally, a heterogeneous graph neural network (HGNN) is used to model graph-level data, leveraging a modal attention mechanism to dynamically fuse traffic-level and packet-level information. This dynamic fusion mechanism empowers the model with autonomous "judgment," ensuring a more comprehensive analysis of network behavior in complex network environments. This improves the detection accuracy of diverse attacks, enhances the structural perception of complex attacks, and enhances robustness and generalization.

[0080] In an optional embodiment of the present invention, step 11 may include:

[0081] Step 111, performing data capture processing on a preset network interface to obtain a traffic data file;

[0082] Step 112: parse the traffic data file to obtain network traffic data.

[0083] In this embodiment, an underlying library, such as libpcap / WinPcap, is first used to monitor a specified interface and capture the raw data packets passing through. The raw data packets include the link layer header, IP / TCP header, payload, etc. The captured raw data packets are saved as a standard format file, such as a .pcap file, preserving metadata such as timestamp and protocol type.

[0084] After obtaining the traffic data file, it is parsed and processed, including link layer parsing to strip the Ethernet header; network layer parsing to extract the IP header; and transport layer parsing to analyze TCP / UDP ports, flags (such as SYN / ACK), sequence numbers, etc. After parsing is complete, packets are aggregated according to the five-tuple (source IP, destination IP, source port, destination port, protocol), generating a network flow. Flow-level statistical features such as flow duration, total bytes, average packet size, and packet rate are calculated. Finally, each flow or packet is labeled for supervised learning.

[0085] In an optional embodiment of the present invention, step 12 may include:

[0086] Step 121, performing address filtering on the network traffic data to obtain effective attack data;

[0087] Step 122: normalize the valid attack data to obtain a normalized data set;

[0088] Step 123: Perform sample balancing processing on the normalized data set to obtain a traffic data packet.

[0089] In this embodiment, the extracted original network traffic data is in the format of .pcap data.

[0090] In step 121, the source MAC address or destination MAC address and the traffic samples that match the known attacker address library are retained as valid attack data, while any traffic associated with the attacker address is strictly excluded from being misclassified as a benign sample, thereby achieving address filtering processing on the network traffic data and obtaining valid attack data.

[0091] In step 122, further is the core function that normalizes numerical features; μ represents the feature mean and σ represents the standard deviation. This transformation makes all features follow a standard normal distribution with a mean of 0 and a standard deviation of 1, eliminating differences in dimension and numerical range between different features.

[0092] In step 122, the majority class samples are further randomly undersampled, and the minority class samples are subjected to synthetic minority oversampling technique (SMOTE). The oversampling technique uses the core sample generation function of formula (1) to perform sample balancing on the normalized data set:

[0093] NewSample=OriginalSample+λ×(SelectedNeighbor-OriginalSample) (1)

[0094] Where: OriginalSample is an original sample point selected from the minority class, and a sample of the minority class is determined as the "center point"; SelectedNeighbor is a neighbor sample randomly selected from the K nearest neighbors of OriginalSample; NewSample is the new sample; λ is a random number between 0 and 1, used for linear interpolation between OriginalSample and SelectedNeighbor.

[0095] Integrate the new sample with the original data to obtain the traffic data packet.

[0096] In an optional embodiment of the present invention, step 13 may include:

[0097] Step 131, classifying the traffic data packets according to flow types to obtain flow data;

[0098] Step 132: performing feature statistical processing on the flow data to obtain flow-level feature data;

[0099] Step 133, performing time series feature extraction processing on the flow-level feature data to obtain time series feature data;

[0100] Step 134: performing protocol identification processing on the traffic data packet to obtain protocol header metadata;

[0101] Step 135: Encode the traffic data packet to obtain payload encoded data;

[0102] Step 136: Integrate the flow-level feature data and the time series feature data to obtain a plurality of first flow node feature vectors;

[0103] Step 137: Integrate the protocol header metadata and the payload encoding data to obtain multiple first packet node feature vectors;

[0104] Step 138 : Integrate the multiple first flow node feature vectors and the multiple first packet node feature vectors to obtain a multimodal feature set.

[0105] In this embodiment, first, in step 131, the traffic data packets are classified into independent flows according to the five-tuple (source IP, destination IP, source port, destination port, protocol) to obtain flow data.

[0106] In step 132, the following statistical features are extracted for each flow: (1) basic statistics, including connection duration, total number of transmitted bytes, protocol type (such as TCP / UDP), and communication frequency; (2) packet-level derived features, including average packet size, TCPSYN packet ratio, and unidirectional packet ratio (for detecting DDoS attacks); a 76-dimensional flow-level feature vector containing the above statistics is formed to obtain flow-level feature data.

[0107] In step 133, the 76-dimensional flow-level feature vector is segmented by sliding windows at different time granularities (10s, 30s, 60s, and 300s). The following dynamic indicators are calculated in each window, and the features of different time windows are concatenated by dimension to form a time series feature vector, i.e., time series feature data. This process can be expressed as:

[0108] FlowFeature=[F 10s ,F 30s ,F 60s ,F 300s ]∈R 52 (2)

[0109] Among them, FlowFeature is a 52-dimensional time series feature vector, F 10s 、F 30s 、F 60s 、F 300s These are the feature subsets under the time windows of 10s, 30s, 60s, and 300s respectively.

[0110] In step 134, the application layer protocol information of the traffic data packet is parsed using the nDPI library to extract the host name and URL path for HTTP traffic; the server name indication (SNI) for TLS traffic; and a packet-level semantic feature with 14-dimensional protocol header metadata is formed.

[0111] In step 135, the original payload of the traffic data packet is obtained, the payload length is uniformly truncated or padded to 1500 bytes, and then each byte is converted into an integer value from 0 to 255 to form a 1500-dimensional packet-level payload feature vector to obtain payload encoding data.

[0112] In step 136, the plurality of 76-dimensional flow-level feature data are merged with the 52-dimensional time series feature data to form a plurality of 128-dimensional first flow node feature vectors;

[0113] In step 137, the plurality of 14-dimensional packet-level semantic features are combined with the 1500-dimensional payload encoding to form a plurality of 1514-dimensional first packet node feature vectors;

[0114] In step 138, a multimodal feature set is obtained based on the multiple 128-dimensional flow-level features and 1514-dimensional packet-level features.

[0115] like Figure 3 As shown, in an optional embodiment of the present invention, step 14 may include:

[0116] Step 141: determining a plurality of flow nodes according to the plurality of first flow node feature vectors of the multimodal feature set, wherein each flow node corresponds to a first flow node feature vector in the multimodal feature set;

[0117] Step 142: determining a plurality of packet nodes based on the plurality of first packet node feature vectors of the multimodal feature set, wherein each packet node corresponds to a first packet node feature vector in the multimodal feature set;

[0118] Step 143, determining the first edge data according to the subordinate relationship between the flow node and the packet node;

[0119] Step 144: determining second edge data based on the temporal adjacent relationship between the plurality of packet nodes;

[0120] Step 145: Integrate the first edge data and the second edge data to obtain edge set data;

[0121] Step 146: updating the first flow node feature vector according to the first edge data to obtain a second flow node feature vector;

[0122] Step 147: Update the first packet node feature vector according to the second edge data to obtain a second packet node feature vector.

[0123] Step 148: Integrate the second flow node feature vector and the second packet node feature vector to obtain node set data.

[0124] Step 149 : Integrate the edge set data and the node set data to obtain heterogeneous graph data.

[0125] In this embodiment, in order to effectively utilize the extracted flow-level and packet-level information, it is necessary to convert the extracted two modal features into a heterogeneous graph structure so as to be input into the network model. The specific process includes:

[0126] In step 141 and step 142, a plurality of first flow node feature vectors and a plurality of first packet node feature vectors are determined based on the multimodal feature set; wherein the flow node v represented by each first flow node feature vector is f Corresponding to a network flow F; each packet node v represented by the first packet node feature vector p Corresponding to a data packet P i ;

[0127] In steps 143 and 144, for each flow node v f and package node v p Traverse the subordinate relationship of p Belongs to flow node v f , then add edge e c (v f , v p )∈ε c , indicating that the flow contains the data packet, ε c is the first edge data; if the i-th packet node v pi and the i+1th v pi+ If they appear in the same flow and in chronological order, then add edge e c (v pi , v pi+ )∈ε l , represents the temporal adjacent relationship, ε l is the second side data;

[0128] In step 145, εc With ε l Integrate to obtain edge set data, that is: ε=ε c ∪ε l , ε is the edge set data.

[0129] In steps 146 and 147, after determining the edge set data, the edge features are integrated into the flow node and the packet node. The corresponding information is transmitted by aggregating the node features. The node features and the first edge data ε are combined by the function ψ. c And the second side data ε l The specific process of aggregation operation can be expressed as:

[0130] v′ f =ψ(v f ,{ε c (v f ,v pi )|1≤i≤n}) (3)

[0131] v′ p =ψ(v p ,{ε l (v pi ,v po+1 )∣1≤i <n}) (4)

[0132] Among them, ε c (v f ,v pi ) is the flow node v f with package node v pi Edge features, v′ f For flow node v f Updated node features; ε l (v pi ,v pi+1 ) is the packet node v pi+ with package node v pi Edge features, v′ p For packet node v p Updated node features; ψ is an aggregation function (such as mean pooling) used to aggregate packet node features to flow nodes.

[0133] In step 148, the updated flow node v′ f Merge and determine the flow node set V f ; At the same time, the updated packet node v′ p Merge and determine the flow node set V p ;and: Updated node set for:

[0134] Where V is the node set; ε f,p is the edge set representing the connection relationship between nodes;

[0135] In step 149, the heterogeneous graph data G can be expressed as:

[0136] G=(V,ε) (6)

[0137] In an optional embodiment of the present invention, the detection model processes the heterogeneous graph data including:

[0138] Step 151: performing graph convolution processing on the heterogeneous graph data to obtain node feature data;

[0139] Step 152: performing batch normalization processing on the node feature data to obtain normalized feature data;

[0140] Step 153: Perform global pooling processing on the normalized feature data to obtain a graph-level feature vector.

[0141] In this embodiment, the basic structure of the detection model adopts a neural network model with a hypergraph structure, which can enable the packet-level micro features and flow-level macro features in the network traffic data to interact at a deeper level through the graph structure.

[0142] In step 151, the detection model uses a two-layer convolution operator, such as Figure 4 As shown in the figure, through graph convolution operations, efficient information aggregation between heterogeneous nodes can be effectively achieved. At the same time, its neighbor sampling and feature propagation mechanism can be used to dynamically integrate local features of different types of nodes to capture the intricate relationships between different types of nodes and edges in the network traffic graph.

[0143] Taking a flow node as an example, we sample its packet neighbors to obtain information about them. We then use the mean aggregation function to aggregate these packet features to update the node's embedding vector. Furthermore, we apply batch normalization (BN) to each node type to mitigate gradient explosion or vanishing issues. The following describes the model in layers:

[0144]

[0145] in, Output features of the first layer nodes; For each node type v iThe initial node features are: A is the adjacency matrix; E is the adjacent edge; SAGEConv() is the SAGEConv convolution operator; σ() is the nonlinear activation function. This model uses the LeakyReLU activation function, given by Equation (8). Compared with the ReLU activation function, which is more "tolerant" to negative values, the LeakyReLU activation function improves the model's expressive power and enhances feature sparsity and nonlinearity by introducing nonlinearity.

[0146]

[0147] Where x is the input variable; usually α = 0.01.

[0148] The SAGEConv layer aggregates and updates the information of each node in the graph structure, so that the model can capture the deeper connections between each node. The detection model uses two layers of graph convolution. The first layer node The update rules are:

[0149]

[0150] in, is the feature data of the l-th layer node; Represents any node; is the set of neighbor nodes connected by edge E; W α and W β They are the self-loop weight and neighbor aggregation weight, which are used to ensure that the model can retain the node's own information while absorbing the neighbor context and information aggregation.

[0151] In this way, the flow node is α The original statistical characteristics are retained under the action of information aggregation, and the relationship pattern with the package node is learned. The package node maintains its own effective information expression and perceives the interaction frequency with the flow node.

[0152] In step 152, after determining the node feature data, to alleviate the gradient explosion or vanishing problem, Batch Normalization (BN) is applied to each node type separately, as shown in Equation (10). This standardizes the node embedding matrix and also uses different BN layers to normalize different types of nodes.

[0153]

[0154] Where μ and σ are the mean and standard deviation of the features of the same node in the current batch; γ and β are the learnable scaling and offset parameters; ∈ is a very small constant used to prevent the denominator from being zero, usually ∈=1×10 -5 .

[0155] In step 153, global pooling is a key operation in graph neural networks that upgrades the representation from node level to graph level. It is often used in graph classification tasks and can aggregate all node information in the graph, that is, embedding all nodes in each graph into a vector and performing dimensionality reduction at the same time. It is an important operation before implementing the dynamic weight fusion mechanism. The specific process includes: is the Kth picture, then and It represents the set of flow nodes and packet nodes in the Kth graph. The feature representation of the node after the second layer of convolution is The graph-level embeddings of the two types of nodes are:

[0156]

[0157] in, is the graph-level representation of the flow node, which means the average of all flow node features in the K-th graph; It is the graph-level representation of the package node, which means the average of all package node features in the K-th graph.

[0158] Concatenate the graph-level representations of the flow nodes and the package nodes to form the final graph-level feature vector:

[0159] h graph (k) =[h f (k) ;h p (k) ]∈R 256 (13)

[0160] Among them, h graph (k) is the graph-level feature vector.

[0161] In an optional embodiment of the present invention, the detection model processes the heterogeneous graph data including:

[0162] Step 161, performing a linear transformation on the graph-level feature vector to obtain a representation tensor;

[0163] Step 162: performing weight calculation on the representation tensor to obtain attention weight data;

[0164] Step 163: performing weighted fusion processing on the graph-level feature vector according to the attention weight data to obtain a fused graph-level representation vector;

[0165] Step 164 : Determine an intrusion detection result based on the fused graph-level representation vector.

[0166] In this embodiment, after multiple rounds of information propagation and aggregation of nodes using a heterogeneous graph neural network, the detection model obtains graph-level representations of flow nodes and packet nodes. These two types of embeddings contain statistical behavioral characteristics and semantic content characteristics, respectively. Different types of attacks have different modal dependencies. For brute force attacks, attackers often attempt to submit login requests repeatedly within a short period of time. These login requests are typically included in the payload of the packet modality because the payload contains username and password fields, as shown in Table 1. Therefore, it is necessary to learn an adaptive attention mechanism to assign appropriate weights to each modality and generate a unified fusion graph representation for use by downstream classifiers.

[0167] Table 1 Different modal preferences for various attack types

[0168]

[0169] Mapping the embeddings of the two modalities to the Hidden space of the same dimension is the premise of the attention mechanism. f and h p Since the data come from different modalities, their original representations are different and cannot be directly compared semantically. Therefore, it is necessary to project the two different modalities into a common semantic space through linear transformation to provide a "comparable" space for subsequent attention allocation.

[0170] Using the trainable projection weight matrix W via step 161 f and W p and the bias term b f and b p , map the modal embeddings to the same dimension and distribution, and stack the projection results and concatenate them into a tensor. Each batch will get a 2×d′ modal representation combination Z, which is calculated as follows:

[0171]

[0172] Among them, z f is the result of linear transformation of flow mode; z p is the result of the linear transformation of the bag modality; Z is a tensor containing the semantic alignment representation of the two modalities for subsequent attention calculation.

[0173] In step 162, a shared attention mechanism is used, that is, the same parameter W is used. a Score the two modal representations. The reason for choosing shared attention rather than independent attention is to avoid artificial bias and ensure that attention is a relative measure of which modality is more important. The attention weight formula is:

[0174]

[0175] Among them, α is the attention weight; α f is the flow mode weight; α p is the packet modality weight; softmax() is the normalization function. To enhance the model’s discriminability, the tanh function is added for nonlinear mapping, and the softmax normalization function is added to obtain the attention weight.

[0176] In step 163, based on the attention weights, the detection model performs weighted fusion processing between the two modalities to obtain the final fused graph-level representation h ζ , the specific formula is:

[0177] h ζ =α f ·h f +α p ·h p (16)

[0178] Graph-level representation h ζ The information of both modalities is retained, while the more important modal features are automatically highlighted through learnable weights.

[0179] In step 164, the graph level representation h ζ The final classification output will be generated through a series of fully connected layers to determine the intrusion detection result. The specific formula is:

[0180] Out=LogSoftmax(W2·ReLU(W1·ReLU(W0·h ζ ))) (17)

[0181] Among them, W0, W1 and W2 are the weight matrices of the fully connected layer, and LogSoftmax() converts the final output into category probability.

[0182] This heterogeneous graph framework effectively integrates packet-level and flow-level information, and performs information aggregation and representation learning within the heterogeneous graph structure, capturing interactive features in deeper networks. Furthermore, through the dynamic weighted fusion of the attention mechanism, it achieves adaptive modeling of modality preferences across different attack types, improving overall classification accuracy. The detection model's final accuracy, recall, and F1 score for eight different classification results are shown in Table 2.

[0183] Table 2 Classification results of detection model

[0184] Attack Type Accuracy Recall F1 value Benign 0.98 0.99 0.98 Web Based 0.93 0.99 0.96 Spoofing 0.98 0.98 0.98 Recon 0.99 0.93 0.96 Mirai 1.00 1.00 1.00 Dos 1.00 1.00 1.00 DDos 1.00 1.00 1.00 Brute Force 1.00 1.00 1.00

[0185] The network intrusion detection method proposed in this paper is based on an attention-driven dynamic fusion mechanism, which can adaptively weigh the weights of Flow and Packet modes, thereby improving the detection accuracy of diversified attacks (such as DDoS and SQL injection). It also uses a heterogeneous graph neural network (HGNN) to model the interaction between traffic and packet nodes, thereby enhancing the structural perception capability of complex attacks such as APT. At the same time, a multi-scale sliding window is used to extract time series features, and SMOTE and undersampling are combined to solve the data imbalance problem and reduce noise interference. The end-to-end processing flow from raw traffic to graph structure supports large-scale deployment and improves the practicality of the model in real network environments.

[0186] like Figure 5 As shown, the embodiment of the present invention further provides a network intrusion detection device 50, comprising:

[0187] An acquisition module 51 is used to acquire network traffic data;

[0188] The processing module 52 is configured to pre-process the network traffic data to obtain traffic data packets; perform feature extraction on the traffic data packets to obtain a multimodal feature set; perform point and line analysis on the multimodal feature set to obtain heterogeneous graph data; and input the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector.

[0189] The determination module 53 is configured to determine intrusion type data according to the graph-level feature vector.

[0190] Optionally, the acquisition module 51 is specifically configured to:

[0191] Capture and process data on the preset network interface to obtain a traffic data file;

[0192] The traffic data file is parsed to obtain network traffic data.

[0193] Optionally, the processing module 52 is specifically configured to:

[0194] Performing address filtering on the network traffic data to obtain effective attack data;

[0195] Normalizing the effective attack data to obtain a normalized data set;

[0196] Perform sample balancing processing on the normalized data set to obtain a traffic data packet.

[0197] Optionally, the processing module 52 is further specifically configured to:

[0198] Classifying and processing the traffic data packets according to flow types to obtain flow data;

[0199] Performing feature statistical processing on the flow data to obtain flow-level feature data;

[0200] Performing time series feature extraction processing on the flow-level feature data to obtain time series feature data;

[0201] Performing protocol identification processing on the traffic data packet to obtain protocol header metadata;

[0202] Encoding the traffic data packet to obtain payload encoded data;

[0203] Integrate the flow-level feature data and the time series feature data to obtain a plurality of first flow node feature vectors;

[0204] Integrate the protocol header metadata and the payload encoding data to obtain a plurality of first packet node feature vectors;

[0205] The multiple first flow node feature vectors and the multiple first packet node feature vectors are integrated to obtain a multimodal feature set.

[0206] Optionally, the processing module 52 is further specifically configured to:

[0207] Determining a plurality of flow nodes according to the plurality of first flow node feature vectors of the multimodal feature set, wherein each flow node corresponds to a first flow node feature vector in the multimodal feature set;

[0208] Determining a plurality of packet nodes according to the plurality of first packet node feature vectors of the multimodal feature set, each packet node corresponding to a first packet node feature vector in the multimodal feature set;

[0209] Determine the first edge data based on the subordinate relationship between the flow node and the packet node;

[0210] Determining second edge data according to a temporal adjacent relationship between the plurality of packet nodes;

[0211] Integrating the first edge data and the second edge data to obtain edge set data;

[0212] updating the first flow node feature vector according to the first edge data to obtain a second flow node feature vector;

[0213] updating the first packet node feature vector according to the second edge data to obtain a second packet node feature vector;

[0214] Integrate the second flow node feature vector and the second packet node feature vector to obtain node set data;

[0215] The edge set data and the node set data are integrated to obtain heterogeneous graph data.

[0216] Optionally, the detection model processes the heterogeneous graph data including:

[0217] Performing graph convolution processing on the heterogeneous graph data to obtain node feature data;

[0218] Performing batch normalization on the node feature data to obtain normalized feature data;

[0219] Global pooling is performed on the normalized feature data to obtain a graph-level feature vector.

[0220] Optionally, the determining module 53 is further specifically configured to:

[0221] Performing a linear transformation on the graph-level feature vector to obtain a representation tensor;

[0222] Performing weight calculation on the representation tensor to obtain attention weight data;

[0223] Performing weighted fusion processing on the graph-level feature vector according to the attention weight data to obtain a fused graph-level representation vector;

[0224] An intrusion detection result is determined according to the fused graph-level representation vector.

[0225] It should be noted that this device is a device corresponding to the above method, and all implementation methods in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.

[0226] like Figure 6 As shown, an embodiment of the present invention further provides a computing device 60, including a processor 61, a memory 62, and a program or instruction stored in the memory 62 and executable on the processor 61. When the program or instruction is executed by the processor 61, each process of the above-mentioned network intrusion detection method embodiment is implemented and can achieve the same technical effect. To avoid repetition, it is not described here. It should be noted that the computing device in the embodiment of the present invention includes the above-mentioned mobile electronic device and non-mobile electronic device.

[0227] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0228] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0229] In the embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0230] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0231] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0232] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, ROM, RAM, a magnetic disk, or an optical disk.

[0233] In addition, it should be noted that, in the apparatus and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. Moreover, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but it is not necessary to perform them in chronological order, and some steps can be performed in parallel or independently of each other. For those of ordinary skill in the art, it will be understood that all or any steps or components of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or a network of computing devices in hardware, firmware, software or a combination thereof, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0234] Therefore, the purpose of the present invention can also be achieved by running a program or a group of programs on any computing device. The computing device can be a well-known general-purpose device. Therefore, the purpose of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or device. That is to say, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the device and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. In addition, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but do not necessarily need to be performed in chronological order. Certain steps can be performed in parallel or independently of each other.

[0235] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A network intrusion detection method, characterized in that: include: Get network traffic data; Preprocessing the network traffic data to obtain traffic data packets; Extracting features from the traffic data packets to obtain a multimodal feature set; Performing point and line analysis on the multimodal feature set to obtain heterogeneous graph data; Inputting the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector; Intrusion type data is determined according to the graph-level feature vector.

2. The network intrusion detection method according to claim 1, characterized in that: Obtain network traffic data, including: Capture and process data on the preset network interface to obtain a traffic data file; The traffic data file is parsed to obtain network traffic data.

3. The network intrusion detection method according to claim 1, wherein: Preprocessing the network traffic data to obtain traffic data packets includes: Performing address filtering on the network traffic data to obtain effective attack data; Normalizing the effective attack data to obtain a normalized data set; Perform sample balancing processing on the normalized data set to obtain a traffic data packet.

4. The network intrusion detection method according to claim 3, characterized in that: Feature extraction is performed on the traffic data packet to obtain a multimodal feature set, including: Classifying and processing the traffic data packets according to flow types to obtain flow data; Performing feature statistical processing on the flow data to obtain flow-level feature data; Performing time series feature extraction processing on the flow-level feature data to obtain time series feature data; Performing protocol identification processing on the traffic data packet to obtain protocol header metadata; Encoding the traffic data packet to obtain payload encoded data; Integrate the flow-level feature data and the time series feature data to obtain a plurality of first flow node feature vectors; Integrate the protocol header metadata and the payload encoding data to obtain a plurality of first packet node feature vectors; The multiple first flow node feature vectors and the multiple first packet node feature vectors are integrated to obtain a multimodal feature set.

5. The network intrusion detection method according to claim 4, characterized in that: Performing point and line analysis on the multimodal feature set to obtain heterogeneous graph data, including: Determining a plurality of flow nodes according to the plurality of first flow node feature vectors of the multimodal feature set, wherein each flow node corresponds to a first flow node feature vector in the multimodal feature set; Determining a plurality of packet nodes according to the plurality of first packet node feature vectors of the multimodal feature set, each packet node corresponding to a first packet node feature vector in the multimodal feature set; Determine the first edge data based on the subordinate relationship between the flow node and the packet node; Determining second edge data according to a temporal adjacent relationship between the plurality of packet nodes; Integrating the first edge data and the second edge data to obtain edge set data; updating the first flow node feature vector according to the first edge data to obtain a second flow node feature vector; updating the first packet node feature vector according to the second edge data to obtain a second packet node feature vector; Integrate the second flow node feature vector and the second packet node feature vector to obtain node set data; The edge set data and the node set data are integrated to obtain heterogeneous graph data.

6. The network intrusion detection method according to claim 1, wherein: The detection model processes the heterogeneous graph data including: Performing graph convolution processing on the heterogeneous graph data to obtain node feature data; Performing batch normalization on the node feature data to obtain normalized feature data; Global pooling is performed on the normalized feature data to obtain a graph-level feature vector.

7. The network intrusion detection method according to claim 1, wherein: Determining intrusion type data based on the graph-level feature vector includes: Performing a linear transformation on the graph-level feature vector to obtain a representation tensor; Performing weight calculation on the representation tensor to obtain attention weight data; Performing weighted fusion processing on the graph-level feature vector according to the attention weight data to obtain a fused graph-level representation vector; An intrusion detection result is determined according to the fused graph-level representation vector.

8. A network intrusion detection device, characterized in that: include: Acquisition module, used to obtain network traffic data; A processing module, configured to pre-process the network traffic data to obtain traffic data packets; Extracting features from the traffic data packets to obtain a multimodal feature set; performing point and line analysis on the multimodal feature set to obtain heterogeneous graph data; inputting the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector; A determination module is used to determine intrusion type data according to the graph-level feature vector.

9. A computing device, characterized in that include: A processor and a memory storing a computer program, wherein when the computer program is executed by the processor, the method according to any one of claims 1 to 7 is performed.

10. A computer-readable storage medium, characterized in that The device stores instructions, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network intrusion detection method for modeling by combining graph embedding knowledge

    CN115118451A

  • Intrusion detection method based on gating time convolutional network and graph

    CN117579324A

  • Host intrusion detection method and system based on attribute heterogeneous graph

    CN118862075A

  • Intrusion detection method and device based on network flow data, terminal equipment and storage medium

    CN119520109A

  • Method and system for detecting intrusions in a computer network by machine learning

    WO2024126521A1

Cited By

  • Computer network intrusion detection system and method based on abnormal behavior analysis

    CN120896779A