Intrusion detection method, system and device for roadside heterogeneous device network

By constructing network behavior vectors in a highway road-side heterogeneous device network and using the K-Shape clustering algorithm to detect abnormalities, the problems of insufficient computing power and high false alarm rate for detecting zero-day attacks are solved, and efficient and low false alarm intrusion detection is achieved.

CN120474824APending Publication Date: 2025-08-12SHANDONG HI SPEED GRP CO LTD +1

Patent Information

Application Number
CN202510859001.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect zero-day attacks in highway road-side heterogeneous equipment networks, especially due to insufficient computing power, high false alarm rate, and lack of adaptive defense capabilities.

Method used

By calculating the function code changes and time intervals of the Modbus/TCP Internet of Things protocol, a network behavior vector is constructed, and anomaly detection is used using the K-Shape clustering algorithm to determine whether the data point is outlier to achieve intrusion detection.

Benefits of technology

It realizes efficient detection of zero-day attacks under low computing power requirements, with a recall rate of more than 84%, reducing false positives and no need for training on a large number of marked attack data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474824A_ABST
    Figure CN120474824A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of intrusion detection, and relates to an intrusion detection method, system and device for a roadside heterogeneous device network, and the method comprises the steps: calculating an action feature value for describing the change condition of a function code in front and back frames of data according to the function code in each frame of data, and obtaining an action feature vector; calculating each function code in each frame of data to read a time interval of a previous register with the same serial number to obtain a time interval vector; constructing a network behavior vector through the action feature vector and the time interval vector; clustering network behavior vectors constructed by normal network data through an anomaly detection model based on a clustering algorithm to obtain a central point and a threshold distance of each cluster; and judging whether the data points are abnormal data or not according to whether the network behavior vectors of the data points in the network data meet the characteristics of the outliers or not. The zero-day attack detection method is small in computing power requirement and can effectively detect zero-day attack at a low false alarm rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of intrusion detection technology, and relates to an intrusion detection method, system and equipment, and in particular to an intrusion detection method, system and equipment for a roadside heterogeneous device network. Background Art

[0002] With the development of information technology, intelligentization, and networking in highways, an increasing number of heterogeneous terminals are connected to their control networks. These heterogeneous terminals, due to their inconsistent computing power, inconsistent permissions, and inconsistent functions, as well as their large number, pose significant challenges to network management and protection. Hackers can exploit management flaws in these terminals to launch the same attack in different forms, making these heterogeneous terminals more vulnerable to zero-day attacks. Typically, zero-day attacks involve anomalous data of unknown types, and existing intrusion detection algorithms can only detect zero-day attacks through anomaly detection. A common approach to anomaly detection is deep learning-based anomaly detection methods, such as autoencoders and support vector machines. These methods can be deployed locally in real time on the device or online in real time through cloud management.

[0003] Due to the limited computing power of the large-scale heterogeneous terminals on highways, complex intrusion detection algorithms are difficult to deploy locally to these terminals to protect nodes. Cloud-based detection solutions, on the other hand, involve excessive data volumes and impose high detection speed requirements on the models. Furthermore, intrusion detection methods based on abnormal behavior data typically suffer from low detection accuracy and high false positive rates. Existing attack detection algorithms, particularly those based on deep learning, rely on large amounts of labeled attack and normal operation data, resulting in insufficient processing capabilities for unknown attacks and a lack of adaptive defense capabilities against them.

[0004] Therefore, in view of the defects in the above-mentioned prior art, it is necessary to develop a new intrusion detection method for roadside heterogeneous equipment networks. Summary of the Invention

[0005] In order to overcome the shortcomings of the existing technology, the present invention proposes an intrusion detection method, system and device for roadside heterogeneous equipment networks, which has low computing power requirements and can effectively detect zero-day attacks with a low false alarm rate.

[0006] In order to achieve the above object, the present invention provides the following technical solutions: A method for detecting intrusion in a roadside heterogeneous device network, comprising the following steps: Step 1: Based on the function code in each frame of Modbus / TCP IoT protocol data of the roadside heterogeneous device network, calculate the action feature value that describes the change of the function code between the previous and next two frames of data to obtain the action feature vector; Step 2: Calculate the time interval between each function code in each frame of Modbus / TCP IoT protocol of the roadside heterogeneous device network and the reading of the previous register with the same number, and obtain a time interval vector; Step 3: constructing a network behavior vector for describing the network behavior in the roadside heterogeneous device network using the action feature vector and the time interval vector; Step 4: Cluster the network behavior vectors constructed from the normal network data of the roadside heterogeneous equipment network using an anomaly detection model based on a clustering algorithm to obtain the center point and threshold distance of each cluster; Step 5: Determine whether the data point is abnormal data based on whether the network behavior vector of the data point in the network data of the roadside heterogeneous equipment network meets the characteristics of an outlier, so as to perform intrusion detection.

[0007] Preferably, the step 1 includes: By calculating the Hamming distance between each function code of the two frames of data, the action value used to describe the process of reading all registers in the Modbus / TCP Internet of Things is generated:

[0008] Where, Indicates the current frame data The action value corresponding to the i-th function code, Indicates the current frame data The i-th function code, Indicates the previous frame data of the current frame data The i-th function code, Indicates calculation of Hamming distance.

[0009] Preferably, the step one further comprises: According to the action value corresponding to each function code, the data describing the current frame is obtained. The action feature vector of the function code change :

[0010] Where, Respectively represent the current frame data The action value corresponding to the first function code and the current frame data The action value corresponding to the second function code and the current frame data The action value corresponding to the nth function code.

[0011] Preferably, the step 2 is specifically as follows: calculating the current frame data The time interval between the last read of the same register for each function code , forming a time interval vector describing the time interval :

[0012] Where, Respectively represent the current frame data The first function code of the last read time interval of the same register, the current frame data The second function code of the last read time interval of the same register, the current frame data The time interval since the last reading of the same register for the nth function code.

[0013] Preferably, the network behavior vector constructed in step 3 for: .

[0014] Preferably, the clustering algorithm used in step 4 is the Shape clustering algorithm.

[0015] Preferably, in step five, whether the network behavior vector of the data point in the network data of the roadside heterogeneous equipment network meets the characteristics of the outlier is determined in the following manner: the Euclidean distance between the network behavior vector of the data point and the center point of the nearest cluster in the hyperplane is calculated, and compared with the threshold distance of the cluster family obtained based on the normal network data of the roadside heterogeneous equipment network. If the Euclidean distance of the data point exceeds the threshold distance, it is determined to meet the characteristics of the outlier.

[0016] In addition, the present invention also provides an intrusion detection system for a roadside heterogeneous device network, which is characterized by comprising: An action feature vector calculation module is used to calculate the action feature value describing the change in the function code between the previous and next frames of data based on the function code in each frame of the Modbus / TCP Internet of Things protocol of the roadside heterogeneous device network, thereby obtaining an action feature vector; A time interval vector calculation module is used to calculate the time interval between each function code in each frame of Modbus / TCP IoT protocol data of the roadside heterogeneous device network and the previous register with the same number, thereby obtaining a time interval vector; A network behavior vector construction module, configured to construct a network behavior vector for describing the network behavior in the roadside heterogeneous device network using the action feature vector and the time interval vector; A network behavior vector clustering module is used to cluster network behavior vectors constructed from normal network data of the roadside heterogeneous equipment network using an anomaly detection model based on a clustering algorithm to obtain the center point and threshold distance of each cluster; The intrusion detection module is used to determine whether a data point in the network data of the roadside heterogeneous equipment network is abnormal data based on whether the network behavior vector of the data point meets the characteristics of an outlier, thereby realizing intrusion detection.

[0017] Furthermore, the present invention also provides an intrusion detection device for a roadside heterogeneous device network, characterized in that it includes: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the intrusion detection method for a roadside heterogeneous device network as described above.

[0018] Finally, the present invention also provides a computer-readable storage medium having a computer program stored thereon, characterized in that when the program is executed by a processor, the steps of the intrusion detection method for a roadside heterogeneous device network as described above are implemented.

[0019] Compared with the prior art, the intrusion detection method, system, and device for a roadside heterogeneous equipment network of the present invention have one or more of the following beneficial technical effects: 1. Whether it is cloud-based monitoring of heterogeneous roadside equipment networks or local active intrusion detection systems deployed on heterogeneous equipment, the present invention can achieve detection of large data volumes with relatively low computing power requirements and has a detection recall rate of over 84% for zero-day attacks with unknown attack forms.

[0020] 2. The anomaly detection model of the present invention does not need to rely on a large amount of labeled attack data for training, which is often difficult to obtain in large quantities in actual situations. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a flow chart of an intrusion detection method for a roadside heterogeneous device network according to the present invention; Figure 2 This is a data flow diagram of the intrusion detection method for a roadside heterogeneous equipment network according to the present invention; Figure 3 This is a flowchart of the specific application steps of the K-Shape algorithm in the present invention; Figure 4 is a k-value elbow diagram drawn by an embodiment of the present invention; Figure 5 A schematic diagram showing the determination of outliers in the present invention is shown; Figure 6 It is a schematic diagram of the composition of the intrusion detection system for roadside heterogeneous equipment networks of the present invention. DETAILED DESCRIPTION

[0022] Before describing in detail any embodiment of the present invention, it should be understood that the present invention is not limited in its application to the construction and arrangement details of the components set forth in the following description or illustrated in the following figures. The present invention is capable of other embodiments and can be practiced or carried out in various ways. In addition, it should be understood that the words and terms used herein are for descriptive purposes and should not be considered restrictive. The use of "including" or "having" and their variations herein is intended to cover the items and their equivalents set forth below and additional items. Unless otherwise specified or limited, the terms "mounted", "connected", "supported" and "coupled" and their variations are used broadly and cover direct mounting and indirect mounting, connection, support and coupling. In addition, "connected" and "coupled" are not limited to physical or mechanical connections or couplings.

[0023] To address the shortcomings of existing technologies, this invention provides an intrusion detection method for heterogeneous roadside equipment networks. First, to extract key information and facilitate intrusion detection, data mining is performed to construct network behavior vectors, which not only reduces the complexity of network traffic data but also increases its significance. Second, for clustering anomaly detection of time series data, the principles of anomaly detection based on the K-Means algorithm are transferred to the K-Shape algorithm, achieving zero-day attack detection in large-scale heterogeneous equipment networks with lower computing power.

[0024] Figure 1 The flowchart of the intrusion detection method for the roadside heterogeneous equipment network of the present invention is shown. Figure 1 and Figure 2 As shown, the intrusion detection method for a roadside heterogeneous device network of the present invention includes the following steps: 1. Calculation of motion feature vector.

[0025] The roadside heterogeneous device network uses the Modbus / TCP IoT protocol. To extract the information-rich Modbus / TCP IoT protocol data frames into concise intrusion detection data, the original network data needs to be abstracted and simplified to facilitate clustering by the subsequent anomaly detection model based on the clustering algorithm. To this end, the present invention first calculates the action feature vector. That is, based on the function code in each frame of the Modbus / TCP IoT protocol data in the roadside heterogeneous device network, the action feature value describing the change in the function code between the previous and next frames of data is calculated to obtain the action feature vector. This specifically includes: 1. By calculating the Hamming distance between each function code of the two frames of data before and after the Modbus / TCP Internet of Things protocol, the action value generated by the process of reading all registers in the Modbus / TCP Internet of Things is generated: .

[0026] Where, Indicates the current frame data The action value corresponding to the i-th function code, Indicates the current frame data The i-th function code, Indicates the previous frame data of the current frame data The i-th function code, Indicates calculation of Hamming distance.

[0027] Therefore, by The n function codes and the previous frame data of the current frame data Calculate the Hamming distance of n function codes respectively, and you can get n action values These n action values It can describe the actions generated by the reading process of all registers in the Modbus / TCP Internet of Things.

[0028] 2. According to the action value corresponding to each function code, get the description of the current frame data The action feature vector of the function code change : .

[0029] Where, Respectively represent the current frame data The action value corresponding to the first function code and the current frame data The action value corresponding to the second function code and the current frame data The action value corresponding to the nth function code.

[0030] Current frame data There are n function codes in total, and n action values corresponding to n function codes , get the data describing the current frame The action feature vector of the function code change .

[0031] By performing the above calculation on each frame of Modbus / TCP IoT protocol data, we can obtain the action feature vector that describes the change of the function code of each frame of data.

[0032] 2. Time interval vector calculation.

[0033] The time interval for each function code in each frame of Modbus / TCP IoT protocol of the roadside heterogeneous device network to read the previous register with the same number is calculated to obtain a time interval vector.

[0034] Specifically, calculate the current frame data The time interval between the last read of the same register for each function code , forming a time interval vector describing the time interval : .

[0035] Where, Respectively represent the current frame data The first function code of the last read time interval of the same register, the current frame data The second function code of the last read time interval of the same register, the current frame data The time interval since the last reading of the same register for the nth function code.

[0036] By performing the above calculation on each frame of Modbus / TCP IoT protocol data, a time interval vector describing the time interval of each frame of data can be obtained.

[0037] 3. Construction of network behavior vector.

[0038] A network behavior vector for describing the network behavior in the roadside heterogeneous device network is constructed by using the action feature vector and the time interval vector.

[0039] Specifically, based on the action feature vector describing the change of the function code of each frame data and a time interval vector describing the time interval of each frame of data , constructing a network behavior vector for describing the network behavior in the roadside heterogeneous equipment network : .

[0040] Each network behavior vector They all describe a normal behavior in a roadside heterogeneous device network. These network behavior vectors effectively describe the behavioral characteristics of normal network data and are suitable for anomaly detection in machine learning.

[0041] 4. Network behavior vector clustering.

[0042] Since the data of the roadside heterogeneous equipment network has time series properties, the present invention uses an anomaly detection model based on a clustering algorithm to cluster network behavior vectors. Unlike the existing anomaly detection model that uses the K-Means algorithm, the anomaly detection model of the present invention uses the K-Shape clustering algorithm to cluster time series data, such as Figure 3 shown.

[0043] The K-Shape clustering algorithm is an improvement on the K-Means algorithm. It improves the distance calculation method and optimizes the centroid calculation method. On the one hand, it supports amplitude scaling and translation invariance. On the other hand, it has high computational efficiency and does not require manual parameter setting. Similar to the principle of K-Means clustering, the K-Shape algorithm draws an elbow diagram based on the clustering results in this algorithm, such as Figure 4 As shown, the number of clusters K for the optimal clustering is determined, and the center point of each cluster is obtained.

[0044] It should be noted that the anomaly detection model based on the clustering algorithm itself does not belong to the concept proposed by the present invention. The present invention only replaces the K-Means algorithm in the existing anomaly detection model based on the clustering algorithm with the K-Shape clustering algorithm and uses it as an optimization method to cluster and detect anomalies in the network behavior vector proposed by the present invention.

[0045] Therefore, by clustering the network behavior vectors constructed from the normal network data of the roadside heterogeneous equipment network using an anomaly detection model based on a clustering algorithm, the center point and threshold distance of each cluster can be obtained.

[0046] 5. Intrusion detection.

[0047] Intrusion detection can be achieved by judging whether the data point is abnormal data based on whether the network behavior vector of the data point in the network data of the roadside heterogeneous equipment network meets the characteristics of the outlier.

[0048] Specifically, whether the network behavior vector of a data point in the network data of the roadside heterogeneous equipment network meets the characteristics of an outlier can be determined in the following way: the Euclidean distance between the network behavior vector of the data point and the center point of the nearest cluster in the hyperplane is calculated, and the threshold distance of the cluster obtained based on the normal network data of the roadside heterogeneous equipment network is compared. If the Euclidean distance of the data point exceeds the threshold distance, it is determined to meet the characteristics of an outlier. The schematic diagram of outlier determination is shown in the figure below. Figure 5 As shown in the figure, 1 is an outlier, 2 is a normal point, and 3 is the threshold of each cluster. If the data point meets the characteristics of an outlier, it means that the data point is abnormal data and may be potential zero-day attack data.

[0049] Figure 6 The figure shows the schematic diagram of the intrusion detection system for the roadside heterogeneous equipment network of the present invention. Figure 6 As shown, the intrusion detection system for a roadside heterogeneous device network of the present invention includes: Motion feature vector calculation module.

[0050] The action feature vector calculation module is used to calculate the action feature value describing the change of the function code in the two frames of data before and after according to the function code in each frame of the Modbus / TCP Internet of Things protocol of the roadside heterogeneous equipment network, and obtain the action feature vector.

[0051] Time interval vector calculation module.

[0052] The time interval vector calculation module is used to calculate the time interval for each function code in each frame data of the Modbus / TCP Internet of Things protocol of the roadside heterogeneous device network to read the previous register with the same number, and obtain the time interval vector.

[0053] Network behavior vector building blocks.

[0054] The network behavior vector construction module is used to construct a network behavior vector for describing the network behavior in the roadside heterogeneous device network through the action feature vector and the time interval vector.

[0055] Network behavior vector clustering module.

[0056] The network behavior vector clustering module is used to cluster the network behavior vectors constructed from normal network data of the roadside heterogeneous equipment network to obtain the center point and threshold distance of each cluster.

[0057] Intrusion detection module.

[0058] The intrusion detection module is used to determine whether a data point in the network data of the roadside heterogeneous equipment network is abnormal data based on whether the network behavior vector of the data point meets the characteristics of an outlier, thereby realizing intrusion detection.

[0059] In addition, the present invention also provides an intrusion detection device for a roadside heterogeneous device network, which includes: one or more processors; a memory for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the intrusion detection method for a roadside heterogeneous device network as described above.

[0060] Finally, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the intrusion detection method for a roadside heterogeneous device network as described above.

[0061] Finally, it should be noted that the above embodiments are intended only to illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention. Those skilled in the art may, based on the principles of the present invention, modify or replace the technical solutions of the present invention with equivalents without departing from the essence and scope of the technical solutions of the present invention.

Claims

1. A method for intrusion detection of a roadside heterogeneous equipment network, characterized in that: include: Step 1: Based on the function code in each frame of Modbus / TCP IoT protocol data of the roadside heterogeneous device network, calculate the action feature value that describes the change of each function code in the two frames of data before and after, and obtain the action feature vector; Step 2: Calculate the time interval between each function code in each frame of Modbus / TCP IoT protocol of the roadside heterogeneous device network and the reading of the previous register with the same number, and obtain a time interval vector; Step 3: constructing a network behavior vector for describing the network behavior in the roadside heterogeneous device network using the action feature vector and the time interval vector; Step 4: Cluster the network behavior vectors constructed from the normal network data of the roadside heterogeneous equipment network using an anomaly detection model based on a clustering algorithm to obtain the center point and threshold distance of each cluster; Step 5: Determine whether the data point is abnormal data based on whether the network behavior vector of the data point in the network data of the roadside heterogeneous equipment network meets the characteristics of an outlier, so as to perform intrusion detection.

2. The intrusion detection method for a roadside heterogeneous equipment network according to claim 1, characterized in that: The step 1 specifically includes: By calculating the Hamming distance between each function code of the two frames of data, the action value used to describe the process of reading all registers in the Modbus / TCP Internet of Things is generated: Where, Indicates the current frame data The action value corresponding to the i-th function code, Indicates the current frame data The i-th function code, Indicates the previous frame data of the current frame data The i-th function code, Indicates calculation of Hamming distance.

3. The intrusion detection method for a roadside heterogeneous equipment network according to claim 2, characterized in that: The step one further comprises: According to the action value corresponding to each function code, the data describing the current frame is obtained. The action feature vector of the function code change : Where, Respectively represent the current frame data The action value corresponding to the first function code and the current frame data The action value corresponding to the second function code and the current frame data The action value corresponding to the nth function code.

4. The intrusion detection method for a roadside heterogeneous equipment network according to claim 3, characterized in that: The second step is specifically to calculate the current frame data: The time interval between the last read of the same register for each function code , forming a time interval vector describing the time interval : Where, Respectively represent the current frame data The first function code of the last read time interval of the same register, the current frame data The second function code of the last read time interval of the same register, the current frame data The time interval since the last reading of the same register for the nth function code.

5. The intrusion detection method for a roadside heterogeneous equipment network according to claim 4, characterized in that: The network behavior vector constructed in step 3 for: .

6. The intrusion detection method for a roadside heterogeneous device network according to any one of claims 1 to 5, characterized in that: The clustering algorithm used in step 4 is the Shape clustering algorithm.

7. The intrusion detection method for a roadside heterogeneous equipment network according to claim 6, characterized in that: In step five, whether the network behavior vector of a data point in the network data of the roadside heterogeneous equipment network satisfies the characteristics of an outlier is determined in the following manner: the Euclidean distance between the network behavior vector of the data point and the center point of the nearest cluster in the hyperplane is calculated, and compared with the threshold distance of the cluster obtained based on the normal network data of the roadside heterogeneous equipment network. If the Euclidean distance of the data point exceeds the threshold distance, it is determined to meet the characteristics of an outlier.

8. An intrusion detection system for roadside heterogeneous equipment networks, characterized in that: include: An action feature vector calculation module is used to calculate the action feature value describing the change in the function code between the previous and next frames of data based on the function code in each frame of the Modbus / TCP Internet of Things protocol of the roadside heterogeneous device network, thereby obtaining an action feature vector; A time interval vector calculation module is used to calculate the time interval between each function code in each frame of Modbus / TCP IoT protocol data of the roadside heterogeneous device network and the previous register with the same number, thereby obtaining a time interval vector; A network behavior vector construction module, configured to construct a network behavior vector for describing the network behavior in the roadside heterogeneous device network using the action feature vector and the time interval vector; A network behavior vector clustering module is used to cluster network behavior vectors constructed from normal network data of the roadside heterogeneous equipment network to obtain the center point and threshold distance of each cluster; The intrusion detection module is used to determine whether a data point in the network data of the roadside heterogeneous equipment network is abnormal data based on whether the network behavior vector of the data point meets the characteristics of an outlier, thereby realizing intrusion detection.

9. An intrusion detection device for a roadside heterogeneous device network, characterized in that: include: one or more processors; a memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the intrusion detection method for a roadside heterogeneous device network as described in any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the intrusion detection method for a roadside heterogeneous device network as described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Status monitoring, storage and reporting for optical transceivers by tracking operating parameter variations

    CN105191182A

  • Invasion detection analysis method based on Modbus / Tcp

    CN105429963A

  • Industrial control system anomaly detection method based on dual-contour model

    CN106502234A

  • FCM-GASVM-based industrial control system intrusion detection method

    CN109143848A

  • Vehicle-mounted network intrusion detection method and computer readable storage medium

    CN111030962A

Cited By

  • Narrowband satellite voice communication noise reduction system and method

    CN121617408A