A knowledge graph-based network traffic anomaly detection method and system

By adopting a knowledge graph-based network traffic anomaly detection method, the detection challenge of encrypted traffic analysis in the Internet of Things (IoT) environment is solved, achieving efficient anomaly detection and resource optimization, adapting to the multi-level collaborative needs of IoT, and improving detection accuracy and system performance.

CN120498844BActive Publication Date: 2025-11-07TIANJIN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510811987.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-11-07
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

Existing network anomaly detection technologies are ill-suited for encrypted traffic analysis in IoT environments. They suffer from high computational complexity, are unable to respond in real time in resource-constrained environments, and lack information sharing and collaboration mechanisms between different levels, resulting in limited detection accuracy and applicability.

Method used

The knowledge graph-based network traffic anomaly detection method achieves anomaly detection of encrypted traffic by extracting protocol-aware metadata features, constructing multi-level knowledge graphs, and coordinating information between levels, and by using probabilistic reasoning and adaptive resource allocation.

Benefits of technology

It enables anomaly detection of encrypted traffic without decryption, improving detection accuracy, reducing system computational load, lowering network transmission overhead, and supporting multi-level collaboration and resource optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498844B_ABST
    Figure CN120498844B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, and discloses a network traffic anomaly detection method and system based on a knowledge graph, wherein the network traffic anomaly detection method comprises the following steps: protocol-aware metadata feature extraction: metadata features not involving content privacy are extracted from encrypted network traffic through a deep packet inspection technology, including traffic statistical features, time sequence features and connection relationship features; multi-level knowledge graph construction: based on the extracted metadata features, corresponding knowledge graphs are respectively constructed according to network architecture at a device layer, a gateway layer and a cloud layer, and respectively represent device behavior, network activity and global security information; the method does not depend on traffic decryption operation, and only by analyzing metadata features of network traffic, effective identification of abnormal behavior in encrypted traffic is realized, so that the detection accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, more particularly, it relates to a network traffic anomaly detection method and system based on a knowledge graph. BACKGROUND

[0002] With the development of 5G technology and the wide application of Internet of Things devices, network traffic is growing explosively, and encrypted transmission has become the mainstream way to protect data security. However, the existing network anomaly detection technology has the following shortcomings in dealing with encrypted traffic analysis in the Internet of Things environment:

[0003] Traditional Deep Packet Inspection (DPI) technology relies on the analysis of traffic content, and needs to be decrypted and analyzed when facing encrypted traffic, which has large computational overhead and often infringes on user privacy;

[0004] Existing anomaly detection methods mostly use single models, which are difficult to adapt to the characteristics of diverse device types, resource constraints and multiple protocols in the Internet of Things environment, resulting in limited detection accuracy and applicability;

[0005] The Internet of Things architecture usually presents a hierarchical structure (device-edge-cloud), but traditional detection methods lack information sharing and collaborative mechanisms between levels, and each layer of information forms an "island", which cannot build a global security view;

[0006] In a high-concurrency environment, especially in resource-constrained edge computing scenarios, traditional computationally intensive detection models are difficult to meet real-time response requirements, affecting system usability.

[0007] Existing network traffic anomaly detection methods mainly target enterprise network environments and do not consider the special nature of the Internet of Things, do not solve the problems of encrypted traffic analysis and multi-level collaboration, and have high computational complexity, making it difficult to apply in resource-constrained environments.

[0008] Therefore, there is an urgent need for a network anomaly detection method that can analyze encrypted traffic without decryption, adapt to the heterogeneous environment of the Internet of Things, support multi-level collaboration and ensure computational efficiency. SUMMARY

[0009] The present application provides a network traffic anomaly detection method and system based on a knowledge graph, which solves the technical problem of network traffic anomaly detection in related technologies.

[0010] The present application provides a network traffic anomaly detection method based on a knowledge graph, comprising the following steps:

[0011] Protocol-aware metadata feature extraction: Extract metadata features that do not involve content privacy from encrypted network traffic through deep packet inspection techniques, including traffic statistics features, time series features, and connection relationship features;

[0012] Multi-level knowledge graph construction: Based on the extracted metadata features, construct corresponding knowledge graphs at the device layer, gateway layer, and cloud layer according to the network architecture, representing device behavior, network activity, and global security information, respectively;

[0013] Inter-level information collaboration: Establish cross-level knowledge transfer protocols for the constructed multi-level knowledge graphs to achieve information sharing and collaboration between different levels of detection systems, ensuring consistency and integrity of information at each level;

[0014] Probabilistic relationship reasoning detection based on knowledge graph: Use the constructed knowledge graph and collaborative information to perform probabilistic relationship reasoning, calculate edge confidence, and apply a multi-dimensional anomaly scoring model to identify abnormal behavior;

[0015] Resource adaptive allocation and detection task scheduling: Based on the detection results and priorities, combine the resource status of different levels of devices to adaptively allocate computing resources and dynamically schedule detection tasks, optimizing the overall performance of the system.

[0016] As a further optimization scheme of the present application, the protocol-aware metadata feature extraction step specifically includes:

[0017] Traffic session identification and preprocessing: Divide network traffic into sessions according to pre-set protocol rules;

[0018] Protocol feature identification: Identify the protocol types used in network communication by analyzing the basic features in network traffic;

[0019] Metadata feature extraction: Extract metadata features from data of different protocol types and construct feature vectors, including:

[0020] Data flow statistics features, time series features, connection relationship features, and protocol behavior features.

[0021] Feature dimension reduction and normalization: Apply principal component analysis algorithm to the generated feature vector set for dimension reduction processing, and normalize each dimension feature to obtain a standardized feature vector set :

[0022] ;

[0023] where, represents the normalized feature vector set; represents the normalization operation function; represents the principal component analysis algorithm; Represents a set of metadata feature vectors; This represents the target dimension after dimensionality reduction.

[0024] As a further optimization of the present invention, the multi-level knowledge graph construction step specifically includes:

[0025] Lightweight Behavioral Pattern Graph Construction at the Device Layer: Constructing a lightweight behavioral pattern graph based on the network traffic characteristics of a single IoT device;

[0026] Gateway layer regional network behavior graph construction: Based on the communication characteristics of all devices managed by the gateway, a regional network behavior graph is constructed;

[0027] Cloud Global Association Graph Construction: Integrating multiple gateway layer graphs to construct a global association graph;

[0028] Knowledge graph indexing and storage optimization: Implement indexing and storage optimization for the constructed multi-level knowledge graph.

[0029] As a further optimization of the present invention, the inter-level information collaboration step specifically includes:

[0030] Adaptive sampling and aggregation algorithm: To meet the information exchange needs between different network layers, an adaptive sampling and aggregation algorithm is implemented to balance information integrity and transmission efficiency;

[0031] Construction of two-way information flow channels: Establish two-way information flow channels between multi-level knowledge graphs to enable the efficient exchange of key information between upper and lower level systems;

[0032] Information Compression and Recovery: A method for compressing and recovering map information, addressing the bandwidth limitations of the Internet of Things (IoT) environment;

[0033] Collaborative Decision Making and Feedback Optimization: Based on the results of multi-level information fusion, a collaborative decision making and feedback optimization method is implemented.

[0034] As a further optimization of the present invention, the inter-level information collaboration step specifically includes: the calculation formula for adaptive sampling is:

[0035] ;

[0036] in, Represents the sampling function; Indicates the first A knowledge graph to be sampled; This represents the sampling rate parameter; Represents nodes in the graph; Representation of the spectrum The set of all nodes in; a function representing importance scores of computing nodes ; a function representing node adaptive threshold based on sampling rate ; a function representing edges in a graph ; a function representing a set of all edges in a graph ; a function representing computing edge weights; a function representing edge adaptive threshold based on sampling rate ;

[0037] As a further optimization scheme of the present application, the knowledge graph-based probabilistic relationship reasoning detection step specifically comprises:

[0038] Device behavior fingerprint generation: based on the device nodes and their associated relationships in the multi-level knowledge graph, a unique behavior fingerprint is generated for each device;

[0039] Path probability reasoning algorithm: based on the relationship paths between entities in the knowledge graph, a path probability reasoning algorithm is implemented to identify abnormal entity association patterns;

[0040] Multi-dimensional anomaly scoring model: a multi-dimensional anomaly scoring model is constructed, taking into account multiple abnormal indicators of device behavior;

[0041] Decision tree integrated decision: based on multi-dimensional anomaly scoring, a decision tree integrated model is applied for the final anomaly decision.

[0042] As a further optimization scheme of the present application, the behavior fingerprint generation function of the device is represented as:

[0043] ;

[0044] wherein, a function representing behavior fingerprint generation of a device ; a device node ; a hash function ; a protocol node associated with the device ; a relationship feature between the device and the protocol ; a hierarchical knowledge graph ;

[0045] The behavior fingerprint is further organized into a fingerprint library to support fast retrieval:

[0046] ;

[0047] wherein, represents a device behavior fingerprint database; represents a th device node; represents a behavior fingerprint of a device ; represents a category of a device ; represents a set of device nodes;

[0048] For a newly observed device behavior, calculate its current fingerprint and the deviation degree of the historical fingerprint:

[0049] ;

[0050] wherein, represents a behavior deviation degree of a device at time ; represents a device node; represents a current time point; represents a function for calculating the distance between two fingerprints; represents a current behavior fingerprint of a device at time ; represents a historical behavior fingerprint of a device .

[0051] As a further optimization scheme of the present application, the resource adaptive allocation and detection task scheduling step specifically includes:

[0052] Hierarchical task priority evaluation: build a hierarchical task priority evaluation model to assign reasonable execution priority to different detection tasks;

[0053] Multi-objective resource allocation algorithm: based on task priority and current available resource status, implement a multi-objective resource allocation algorithm;

[0054] Load balancing and task migration: implement load balancing and task migration methods to dynamically adjust task distribution to avoid resource bottlenecks;

[0055] Resource usage efficiency monitoring and optimization: build a resource usage efficiency monitoring and optimization system to continuously evaluate and improve resource allocation strategies.

[0056] As a further optimization scheme of the present application, the expression of the multi-objective resource allocation algorithm is:

[0057] ;

[0058] wherein, represents an optimal resource allocation scheme; represents a resource allocation scheme that maximizes the objective function ; represents a summation operation on all tasks; represents the total number of tasks; represents the priority score of the th task; represents the th detection task; represents a performance evaluation function; represents the resources allocated to the th task; represents a constraint condition of the optimization problem; represents the amount of resources allocated to the th task; represents the total amount of resources available in the current system.

[0059] A network traffic anomaly detection system based on a knowledge graph, for the network traffic anomaly detection method based on a knowledge graph described above, characterized in that it comprises:

[0060] Protocol-aware metadata feature extraction module: used for extracting metadata features that do not involve content privacy from encrypted network traffic;

[0061] Multi-level knowledge graph construction module: used for constructing corresponding knowledge graphs at the device layer, gateway layer and cloud layer respectively;

[0062] Inter-level information collaboration module: used for information sharing and collaboration between different levels of detection systems;

[0063] Knowledge graph-based probabilistic relationship reasoning detection module: used for probabilistic relationship inference using a knowledge graph to identify abnormal behavior;

[0064] Resource adaptive allocation and detection task scheduling module: used for adaptive allocation of computing resources and scheduling of detection tasks according to the resource status of different levels of devices.

[0065] The method of the present application has the advantages that it does not rely on traffic decryption operation, and only by analyzing the metadata features of network traffic, it realizes effective identification of abnormal behavior in encrypted traffic, thereby improving the detection accuracy; and through the hierarchical knowledge graph structure and inter-level collaborative system, it realizes the security information sharing and collaboration of Internet of Things devices at each level, reduces the system computing load and reduces the network transmission overhead. BRIEF DESCRIPTION OF DRAWINGS

[0066] Figure 1 is a whole flow chart of a network traffic anomaly detection method based on a knowledge graph according to the present application;

[0067] Figure 2 is a detailed flow chart of a protocol-aware metadata feature extraction step according to the present application;

[0068] Figure 3 is a detailed flow chart of a multi-level knowledge graph construction according to the present application;

[0069] Figure 4 is a detailed flow chart of inter-level information coordination according to the present application;

[0070] Figure 5 is a detailed flow chart of a probability relation reasoning detection based on a knowledge graph according to the present application;

[0071] Figure 6 is a detailed flow chart of resource adaptive allocation and detection task scheduling according to the present application. DETAILED DESCRIPTION

[0072] The subject matter described herein will now be discussed with reference to example implementations. It should be understood that the discussion of these implementations is merely meant to provide a better understanding of the subject matter described herein and can include changes, modifications, additions or omissions of the functions and arrangements of the elements discussed without departing from the scope of the present description. Various examples can omit, substitute or add various procedures or components as appropriate, and the examples described can be combined together to describe yet further examples.

[0073] In at least one embodiment of the present application, a network traffic anomaly detection method based on a knowledge graph is disclosed, as shown in Figures 1 to 6 , comprising the following steps:

[0074] Step 1, protocol-aware metadata feature extraction: extracting metadata features that do not involve content privacy from encrypted network traffic through deep packet inspection technology, including traffic statistical features, time series features and connection relationship features;

[0075] This step extracts metadata features that do not involve privacy from encrypted network traffic, establishes a feature set that meets privacy protection requirements, and specifically includes the following sub-steps:

[0076] Step 1.1, traffic data preprocessing;

[0077] Apply a protocol recognition algorithm to preprocess the input raw network traffic data, divide the traffic into sessions according to the five-tuple (source IP, destination IP, source port, destination port, protocol type), and form a traffic session set. This step does not decrypt the encrypted content, but only analyzes the transmission characteristics of the traffic.

[0078] Step 1.2, Protocol adaptive feature extractor construction;

[0079] For different types of Internet of Things communication protocols, a set of protocol adaptive feature extractors is constructed:

[0080] ;

[0081] Among them, , , respectively represent the feature extractor suitable for the first , , protocol, represent the total number of protocol types supported by the system;

[0082] Each extractor contains the following key components:

[0083] Time feature component: extract time interval distribution, periodicity pattern and other time sequence features of traffic;

[0084] Spatial feature component: extract packet size distribution, data direction ratio and other spatial features;

[0085] Behavioral feature component: extract connection establishment mode, session duration and other behavioral features.

[0086] The selection of feature extractors is automatically triggered by the protocol identification result, represented as:

[0087] ;

[0088] Among them, represents the feature extractor function selected for the protocol , represents the identified protocol type, represents the first protocol set, represents the feature extractor suitable for the first protocol.

[0089] Step 1.3, Metadata feature vector generation;

[0090] Apply the protocol adaptive feature extractor to the preprocessed traffic session to generate a set of metadata feature vectors:

[0091] ;

[0092] Among them, represents the set of metadata feature vectors, , , They represent the first , , Feature vector of a traffic session Indicates the total number of traffic sessions;

[0093] Each feature vector The characteristic representation corresponding to a traffic session is calculated as follows:

[0094] ;

[0095] Specifically, The protocol type is conversation

[0096] in, Indicates the first Feature vector of a traffic session; Indicates the first Feature extractor functions; Indicates the first One network traffic session; Indicates the protocol type; Indicates the first A collection of class protocols; Mathematical symbols that indicate "belong to".

[0097] Step 1.4: Feature dimensionality reduction and normalization;

[0098] The generated feature vector set is subjected to dimensionality reduction using principal component analysis, and the features of each dimension are normalized to obtain a standardized feature vector set. :

[0099] ;

[0100] in, This represents the set of normalized eigenvectors. This represents the normalization operation function; This represents the principal component analysis algorithm; Represents a set of metadata feature vectors; This represents the target dimension after dimensionality reduction.

[0101] Through steps 1.1 to 1.4, the present invention is able to extract rich metadata features from encrypted traffic, providing key input for subsequent anomaly detection without infringing on user privacy.

[0102] Step 2, Multi-level Knowledge Graph Construction: Based on the extracted metadata features, and according to the network architecture, corresponding knowledge graphs are constructed at the device layer, gateway layer, and cloud layer, respectively, representing device behavior, network activity, and global security information;

[0103] This step is based on the hierarchical structure of the Internet of Things network, and constructs three-level knowledge graph of device layer, gateway layer and cloud layer to realize anomaly detection of different granularity, which includes the following steps:

[0104] Step 2.1, construction of lightweight behavior pattern graph of device layer;

[0105] For the network traffic characteristics of a single Internet of Things device, a lightweight behavior pattern graph is constructed:

[0106] ;

[0107] Among them, indicates the lightweight behavior pattern graph of the device layer, is a set of device nodes, including a single device node and its communication opposite node; is a set of protocols, including communication protocol nodes used by devices; is a set of behavior relationships, describing the communication relationship between devices and protocols, devices and devices.

[0108] The graph construction process uses the following mapping function:

[0109] ;

[0110] Among them, indicates the device layer mapping function, which is used to map the feature vector to the device layer knowledge graph; indicates the normalized feature vector set; indicates the mathematical symbol of the mapping relationship; indicates the lightweight behavior pattern graph of the device layer.

[0111] This function maps the normalized feature vector to the nodes and edges in the graph, which is implemented as:

[0112] ;

[0113] Among them, indicates the operation of creating a device node, indicates the device node; indicates the function of extracting device information from the feature vector; indicates the operation of creating the connection relationship between the device node and the protocol node, connecting the device node and the protocol node; indicates the function of extracting protocol information from the feature vector; represents an operation of creating a connection relationship between device nodes, connecting a first device node and a second device node; represents a function of extracting peer device information from a first feature vector; represents a second normalized feature vector.

[0114] Step 2.2, gateway layer regional network behavior graph construction;

[0115] Based on the communication characteristics of all devices managed by the gateway, a regional network behavior graph is constructed:

[0116] ;

[0117] wherein, represents a gateway layer regional network behavior graph, is a set of device nodes in the region; is a set of protocol nodes used in the region; is a set of behavior relationships in the region; is a set of device classification nodes in the region, indicating the functional categories of devices.

[0118] The gateway layer graph is constructed by aggregating the device layer graph and adding device category information:

[0119] ;

[0120] wherein, represents a gateway layer regional network behavior graph, , , represent the behavior pattern graphs of the first, , , device, represents the total number of devices, represents a graph aggregation function, represents a device classification function for mapping devices to their functional categories, represents a set operator, represents a set of device nodes in the region.

[0121] Step 2.3, cloud layer global correlation graph construction;

[0122] Integrate multiple gateway layer graphs to construct a global correlation graph:

[0123] ;

[0124] ​​​​wherein, represents the cloud layer global correlation graph; is the global network device node set; is the global network protocol node set; is the global network behavior relationship set; is the global network device classification node set; is the abnormal type node set, representing known abnormal behavior patterns.

[0125] The cloud layer graph construction uses a distributed graph computing framework to merge and simplify the gateway layer graph:

[0126] ;

[0127] wherein, represents the cloud layer global correlation graph, , , respectively represent the regional network behavior graphs of the first , , , , respectively represent the sampling rate parameters of the first , , represents the total number of gateways, represents the graph merging function, represents the pre-defined abnormal pattern set, represents the sampling function, represents the set merging operator.

[0128] Step 2.4, graph index and storage optimization;

[0129] To improve the efficiency of graph query and reasoning, the constructed multi-level knowledge graph is implemented with index and storage optimization:

[0130] wherein, represents the index set established for the graph ; represents the knowledge graph that needs to be indexed; , and respectively represent node index, edge index and pattern index functions, through which elements in the graph can be quickly located and retrieved.

[0131] Storage uses a hierarchical architecture, and graph data is allocated to different storage layers according to access frequency:​​

[0132] wherein, represents a function according to different hierarchical storage graph , represents a knowledge graph that needs to be stored, represents a storage hierarchy, , and represent memory storage, SSD storage and disk storage functions, respectively.

[0133] Through steps 2.1 to 2.4, the embodiment constructs a multi-level knowledge graph adapted to the Internet of Things environment, providing a structured knowledge representation for subsequent anomaly detection and relationship reasoning.

[0134] Step 3, inter-level information coordination: for the constructed multi-level knowledge graph, a cross-level knowledge transfer protocol is established to realize information sharing and collaboration of different levels of detection systems, and to ensure the consistency and integrity of information at each level;

[0135] This step establishes a collaborative work system between multi-level knowledge graphs, realizes information sharing and collaboration between different levels of detection systems, and specifically includes the following steps:

[0136] Step 3.1, adaptive sampling and aggregation algorithm;

[0137] For the information exchange needs between different network levels, an adaptive sampling and aggregation algorithm is implemented to balance information integrity and transmission efficiency:

[0138] ;

[0139] wherein, represents a sampling function; represents the th knowledge graph to be sampled; represents a sampling rate parameter; represents a node in the graph; represents all node sets in the graph ; represents a function for calculating the importance score of a node ; represents a node adaptive threshold function based on the sampling rate ; represents an edge in the graph; represents all edge sets in the graph ; represents a function for calculating the weight of an edge ; denotes a node adaptive threshold function based on sampling rate ; denotes a set-merge operator.

[0140] and The calculation formula is:

[0141] ;

[0142] ;

[0143] wherein, denotes a node adaptive threshold function based on sampling rate , denotes an edge adaptive threshold function based on sampling rate ; denotes a base threshold value of node importance; denotes a base value of edge threshold; denotes an adjustment parameter of node threshold, denotes an adjustment parameter of edge threshold, denotes a sampling rate parameter; denotes a multiplication operator; denotes an adjustment factor for reducing the threshold as the sampling rate increases; denotes a scaling factor adjusted according to the sampling rate.

[0144] After sampling, the sampling results are integrated into a higher-level graph representation by an aggregation algorithm:

[0145] ;

[0146] wherein, denotes an aggregation function, , , denote the first , , knowledge graphs to be aggregated, denotes the total number of knowledge graphs, denotes a graph fusion function, which realizes a consistent representation of multiple graphs through node merging and relationship integration, denotes a sampling function, denotes the th knowledge graph to be sampled, denotes a sampling rate parameter applied to the th graph, denotes an index The value range of is an integer from to .

[0147] Step 3.2, two-way information flow channel construction;

[0148] Establish a two-way information flow channel between multi-level knowledge graphs, so that upper and lower level systems can efficiently exchange key information:

[0149] ;

[0150] Among them, represents the two-way information flow channel established between the graph and ; represents the lower level knowledge graph; represents the higher level knowledge graph; represents the uplink channel that transmits information from the low-level graph to the high-level graph ; represents the downlink channel that transmits information from the high-level graph to the low-level graph .

[0151] The calculation formula is:

[0152] ;

[0153] Among them, represents the abnormal feature information extracted from the low-level graph ; represents the local anomaly detection result executed on the low-level graph ;

[0154] The calculation formula is:

[0155] ;

[0156] Among them, represents the global pattern information extracted from the high-level graph ; represents the detection strategy information generated from the high-level graph ;

[0157] Through the two-way channel, real-time information sharing between levels is realized, avoiding the "information island" problem.

[0158] Step 3.3, information compression and recovery;

[0159] Aiming at the characteristics of bandwidth limitation in the Internet of Things environment, a compression and recovery method of graph information is realized:

[0160] ;

[0161] Among them, represents a graph compression function, which is used to compress the knowledge graph into a smaller representation form; represents the knowledge graph to be compressed; represents the compression rate parameter; represents an encoding function that converts the graph into a compressed representation; represents an encoding dictionary generated based on the characteristics of the graph , which is used to support the compression process.

[0162] The compressed graph is recovered at the target level:

[0163] ;

[0164] Among them, represents a graph recovery function, which is used to restore the compressed graph to its original form, represents the graph processed by the compression function, which is the compressed graph representation, represents a decoding function, represents an encoding dictionary generated based on the characteristics of the graph , which is used to support the compression process.

[0165] Through the compression and recovery method, the amount of data transmitted between levels is significantly reduced, and the communication efficiency is improved.

[0166] Step 3.4, collaborative decision-making and feedback optimization;

[0167] Based on the multi-level information fusion result, a collaborative decision-making and feedback optimization method is realized:

[0168] ;

[0169] Among them, represents the final decision function for network events; represents the network event to be evaluated; represents a decision combination function, which is used to fuse the detection results of different levels; represents a local decision function for events on the device layer knowledge graph; represents the device layer knowledge graph; represents a regional decision function for events on the gateway layer knowledge graph; The gateway layer knowledge graph is represented as G G. The global decision function for events on the cloud layer knowledge graph is represented as F C. The cloud layer knowledge graph is represented as G C.

[0170] The decision results optimize the detection models of each level through the feedback channel:

[0171] ;

[0172] wherein, represents a feedback function for feeding back the decision results to the knowledge graph; represents the final decision result for network events; represents a network event to be evaluated; represents the first level knowledge graph; represents a graph updating function for updating the knowledge graph; represents a function for learning new knowledge from the decision results, which is used to extract knowledge that can be used to update the graph.

[0173] Through steps 3.1 to 3.4, the embodiment establishes an efficient inter-level information collaboration system, realizes deep collaboration between different levels of detection systems, and improves the overall detection efficiency and accuracy.

[0174] Step 4, probability relationship reasoning detection based on knowledge graph: using the constructed knowledge graph and collaborative information, performing probability relationship inference, calculating edge confidence and applying a multi-dimensional anomaly scoring model to identify abnormal behavior;

[0175] This step uses the reasoning ability of the knowledge graph to identify network abnormal behavior without decrypting the traffic through probability relationship inference, which includes the following sub-steps:

[0176] Step 4.1, device behavior fingerprint generation;

[0177] Based on the device nodes and their associated relationships in the multi-level knowledge graph, a unique behavior fingerprint is generated for each device for fast anomaly detection:

[0178] ;

[0179] wherein, represents a device behavior fingerprint generation function; represents a device node; represents a hash function; represents a protocol node associated with the device; represents the relationship characteristics between the device and the protocol; representing device nodes with protocol nodes there is a relationship between ; representing hierarchical knowledge graph.

[0180] Behavior fingerprints are further organized into a fingerprint library, supporting fast retrieval:

[0181] ;

[0182] wherein, representing device behavior fingerprint database; representing the th device node; representing the behavior fingerprint of the device ; representing the category of the device ; representing a set of device nodes.

[0183] For a newly observed device behavior, calculate its current fingerprint and the deviation degree of the historical fingerprint:

[0184] ;

[0185] wherein, representing the behavior deviation degree of the device at time ; representing a device node; representing the current time point; representing a function for calculating the distance between two fingerprints; representing the current behavior fingerprint of the device at time ; representing the historical behavior fingerprint of the device .

[0186] Step 4.2, path probability reasoning algorithm;

[0187] Based on the relationship path between entities in the knowledge graph, the path probability reasoning algorithm is realized to identify abnormal entity association patterns:

[0188] ;

[0189] wherein, representing the conditional probability of reaching node given node ; representing the target node; representing the starting node; Indicates from node To the node The set of all possible paths; Indicates from node To the node A specific path; Representing a path The weight value; Represents a set All paths Sum the weights; Indicates from node To the node The total number of paths;

[0190] The calculation method is as follows:

[0191] ;

[0192] in, Representing a path The weights; This symbol represents a chain multiplication, which multiplies the confidence scores of all edges on the path. Representing a path Each edge on ; Representing an edge Confidence level; This represents the length penalty factor, used to control the degree to which path length affects the weight; Representing a path The length.

[0193] The likelihood of a device malfunction is assessed by calculating the path probability between the device and known anomalous patterns.

[0194]

[0195] in, Represents device node Abnormal scores; This indicates the equipment to be evaluated; The operator that retrieves the maximum value; Nodes representing exception types; This represents the set of all nodes of different exception types. Indicates from set All exception type nodes ; Indicates in known equipment In the case of reaching an abnormal type node The conditional probability.

[0196] The specific implementation of the path probability inference algorithm includes the following key components and technical details:

[0197] Bidirectional search optimization: To improve the efficiency of path search in large-scale graphs, the algorithm uses a bidirectional search strategy, starting from both the start node and the target node, and merging paths when they meet at intermediate nodes. In the implementation, a priority queue is used to manage the search front, with high-confidence paths being explored first:

[0198] ;

[0199] ;

[0200] where, represents the priority queue for forward search, used to search from the start node to the target node; represents the priority queue for backward search, used to search from the target node to the start node; represents the operation of adding an element to the priority queue; represents the current graph node being processed; represents the path from the start node (or target node) to the current node; represents the cumulative confidence score of the path, used for sorting in the priority queue to ensure that high-confidence paths are explored first;

[0201] Specifically, nodes are sorted by path cumulative confidence to achieve optimal path-first search;

[0202] Path pruning mechanism: To avoid combinatorial explosion, a three-level pruning strategy is introduced:

[0203] Length pruning: Discard paths whose length exceeds a pre-set threshold ;

[0204] Confidence pruning: Discard paths whose cumulative confidence is below a threshold ;

[0205] Redundant path pruning: When two paths pass through the same set of key nodes and one of them has significantly lower confidence, keep the high-confidence path.

[0206] Edge confidence calculation: The confidence of an edge is calculated as follows:

[0207] ;

[0208] where, represents the confidence of edge ; represents the observation frequency of edge ; representing edges semantic similarity between connected entities; representing edges temporal correlation; , , representing the weight coefficients of observation frequency, semantic similarity, and temporal correlation, respectively.

[0209] Path probability caching and incremental update: To improve inference efficiency, the system maintains a path probability cache and processes graph changes through an incremental update mechanism:

[0210] ;

[0211] wherein, represents the conditional probability from node to node after the graph update; represents the conditional probability from node to node before the graph update; represents the total number of paths from node to node before the graph update; represents the number of paths from node to node affected by the graph change; represents the newly added path set from node to node after the graph update; represents a single path in the newly added path set; represents the weight value of path ; represents the sum of the weights of all newly added paths.

[0212] In actual network security monitoring applications, this path probability inference algorithm exhibits the following characteristics and application cases:

[0213] Zero-day vulnerability correlation detection: In a large enterprise network deployment, this algorithm successfully identified the implicit correlation between a device and a known vulnerability pattern. Although the device was not explicitly marked as having a vulnerability, by analyzing the similarity of its communication pattern with known vulnerable devices, the system calculated a high path probability, detected potential risks in advance, and avoided a data leakage incident.

[0214] Multi-hop attack chain identification: The system can identify complex multi-hop attack paths formed by attackers through multiple intermediate devices. In a certain industrial control network, the algorithm identified a six-hop attack path from the external network to the critical control system, which utilized a propagation chain composed of multiple seemingly unrelated devices, making it difficult for traditional single-point detection methods to discover such complex correlations.

[0215] Abnormal behavior propagation prediction: By analyzing the path probabilities between nodes, the algorithm can predict the potential propagation path of abnormal behavior. In the early stages of a ransomware attack, the system accurately predicted the next batch of high-risk devices that could be infected based on the behavior patterns of the first few infected devices, allowing administrators to take targeted protective measures.

[0216] Dynamic trust relationship evaluation: In a dynamically changing network environment, the algorithm can continuously update the trust relationships between entities. For example, in a cloud-edge-end collaborative Internet of Things architecture, the trust relationship between edge gateways and cloud platforms will be dynamically adjusted according to communication patterns and security events, ensuring that abnormal nodes can be isolated in a timely manner to prevent risk spread.

[0217] Step 4.3, multi-dimensional abnormal scoring model;

[0218] Construct a multi-dimensional abnormal scoring model, considering multiple abnormal indicators of device behavior:

[0219] ;

[0220] Where, represents the comprehensive abnormal score of device ; represents the device being evaluated; represents the total number of abnormal indicators; represents the weight coefficient of the th indicator; represents the th abnormal indicator function value of device ; represents the weighted sum operation on all abnormal indicators;

[0221] represents the th abnormal indicator function, including but not limited to:

[0222] Behavior deviation degree:

[0223] ;

[0224] Where, represents the behavior deviation degree indicator of device ; represents the device being evaluated; representing device at time behavior deviation function; representing the current time point;

[0225] relationship abnormality:

[0226] ;

[0227] wherein, representing device relationship abnormality index; representing the device to be evaluated; representing device relationship abnormality scoring function in the knowledge graph;

[0228] communication mode change rate:

[0229] ;

[0230] wherein, representing device communication mode change rate index; representing the device to be evaluated; representing device communication mode function; representing the function for calculating the communication mode change rate;

[0231] resource usage abnormality:

[0232] ;

[0233] wherein, representing device resource usage abnormality index; representing the device to be evaluated; representing the function for calculating the resource usage abnormality degree of the device; Specifically,

[0234] satisfies ;

[0235] wherein, representing the sum operation of the weights of all abnormality indexes; representing the index of the index, from 1 to ; representing the total number of abnormality indexes; representing the weight coefficient of the th index; representing the sum of all weight coefficients is equal to 1, ensuring weight normalization; ​

[0236] The weights are determined by the following adaptive method:

[0237] ;

[0238] wherein, represents the effectiveness score of the i-th indicator, represents the sum of the effectiveness scores of all abnormal indicators, represents the effectiveness score of the i-th indicator.

[0239] The specific implementation of the multi-dimensional abnormality scoring model is based on the following components and structures:

[0240] Feature extractor: For each abnormal indicator, a dedicated feature extractor is constructed to extract relevant information from the knowledge graph. For example, the communication pattern change rate feature extractor extracts time series features from the historical communication records of the device node, calculates statistical features in each time window through the sliding window algorithm, and then analyzes the pattern change trend.

[0241] Abnormality quantification method: For each type of abnormal indicator, a special quantification method is used to calculate the abnormality degree. The behavior deviation degree is calculated by Mahalanobis distance to calculate the deviation degree of the current behavior from the historical behavior, the relationship abnormality degree is quantified by the path probability in the graph, and the resource usage abnormality degree is calculated based on the statistical distribution characteristics of resource usage Z-score.

[0242] Adaptive weight learning: The weight learning module records the contribution of each indicator in the historical detection based on the feedback loop mechanism, and dynamically adjusts the weight using reinforcement learning method. The learning algorithm is based on the following update formula:

[0243] ;

[0244] wherein, represents the weight of the i-th indicator at the j-th iteration; represents the weight of the i-th indicator at the j-th iteration; represents the learning rate; represents the feedback reward of the detection result at the j-th iteration; represents the mean value of the historical detection result feedback reward; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; represents the abnormality measure value of the i-th indicator at the j-th iteration; ​​The mean value of the historical abnormality metric value of the index.

[0245] Abnormal threshold adaptation: The model adopts a dynamic threshold mechanism, automatically adjusting the abnormality judgment threshold according to the device type, environmental conditions, and historical abnormality distribution. The threshold calculation formula is:

[0246] ;

[0247] wherein, represents the dynamic abnormality threshold of the device ; represents the device to be evaluated; represents the base threshold, which is the reference value for dynamic threshold calculation; represents the adjustment parameter of the device , used to control the influence degree of volatility on the threshold; represents the behavior volatility metric of the device , quantifying the instability of device behavior; represents the multiplication operation.

[0248] In actual network environment applications, the multi-dimensional abnormality scoring model exhibits the following advantages and specific application cases:

[0249] Heterogeneous device adaptability: In an industrial internet environment containing different types of IoT devices (such as cameras, smart speakers, sensor networks), the model can automatically identify the normal behavior characteristics of various devices and adjust the weight distribution of abnormality indicators accordingly. For example, for data transmission intensive devices, the communication mode change rate indicator has a higher weight, while for state sensitive devices, the behavior deviation degree indicator has a larger weight.

[0250] Low false alarm rate implementation: In the deployment of a large-scale smart city project, the model reduces the false alarm rate through adaptive weight learning while maintaining a high detection rate. When new attacks occur, the model enhances the weight of relationship abnormality degree, improving the sensitivity to unknown attack patterns.

[0251] Incremental learning capability: The model supports online incremental learning, enabling continuous learning and adjustment of abnormality scoring strategies from newly observed network behavior. In a 6-month long-term running test, the detection accuracy of the model showed an upward trend, proving its continuous learning and improvement capability.

[0252] Seasonal behavior adaptation: For network environments with obvious time patterns (such as commercial office networks), the model can identify and adapt to normal seasonal behavior changes, automatically adjusting the abnormality threshold for each period, avoiding false alarms caused by behavior differences between working hours and non-working hours.

[0253] Step 4.4, decision tree integrated decision;

[0254] Based on the multi-dimensional anomaly score, the final anomaly decision is made by applying the decision tree ensemble model:

[0255] ;

[0256] wherein, represents the final anomaly decision result of the equipment ; represents the equipment to be evaluated; represents the multi-dimensional anomaly score of the equipment ; , , respectively represent the judgment results of the first , , decision tree on the anomaly score of the equipment ; represents the total number of decision trees in the decision tree ensemble model; represents the ensemble function;

[0257] The weighted voting method is adopted, and the calculation formula is as follows:

[0258] ;

[0259] wherein, represents the output result of the ensemble function, i.e. the final anomaly decision (1 represents anomaly, and 0 represents normal); represents the voting result set of all decision trees; represents the judgment result of the first decision tree (1 represents anomaly, and 0 represents normal); represents the total number of decision trees in the decision tree ensemble model; represents the weight coefficient of the first decision tree, reflecting the importance of the decision tree in the final decision; represents the sum of the weighted voting of all decision trees; represents the decision threshold.

[0260] The decision result is further subdivided into anomaly types:

[0261] ;

[0262] wherein, represents the anomaly type decision result of the equipment ; represents the equipment to be evaluated; represents a certain anomaly type; represents a set of all possible anomaly types represents an anomaly type belongs to a set of anomaly types ; represents a device condition that is determined to be abnormal represents the probability that a device belongs to an anomaly type under the condition that it is determined to be abnormal represents the independent variable at which the function reaches a maximum value.

[0263] The specific implementation of the decision tree ensemble model adopts a Gradient Boosting Decision Tree (GBDT) structure, which includes the following key components:

[0264] Basic decision tree builder: used to build individual decision trees, using the Classification and Regression Tree (CART) algorithm, with a maximum depth limit of 5 layers to balance model complexity and generalization ability. The decision tree takes multi-dimensional anomaly score features as input and selects the best split point through the information gain ratio criterion.

[0265] Serial training process: the model is trained iteratively, with a new decision tree added at each iteration to fit the residual of the previous stage model. The training process uses the following loss function:

[0266] ;

[0267] where, represents the loss function, which measures the difference between the model's predicted value and the true value; represents the true label vector; represents the predicted label vector; represents the sample index; represents the total number of samples; represents the true label value of the th sample; represents the predicted label value of the th sample; represents the natural logarithm function; represents the summation operation over all samples.

[0268] Feature importance evaluation: the ensemble model automatically evaluates the importance of each feature and dynamically adjusts the weight of each decision tree to improve sensitivity to key abnormal features.

[0269] In IoT environment applications, the model has the following adaptive features:

[0270] Lightweight implementation: The model is optimized for resource-constrained edge devices, supports incremental updates and model quantization, and the computational complexity of a single prediction operation is controlled at O (log n) level.

[0271] Distributed deployment: The decision tree ensemble model supports distributed deployment on different levels of devices, low-level devices can deploy simplified models, and high-level devices deploy complete models to realize hierarchical decision-making.

[0272] Interpretability guarantee: Unlike black box models, the decision tree ensemble model retains high interpretability, the system can generate decision path explanations to explain the key features and thresholds of abnormal judgment, which helps security analysts understand and verify detection results.

[0273] In practical application scenarios, such as intelligent home network security monitoring systems, the decision tree ensemble model successfully detects IoT device firmware tampering attacks through encrypted traffic transmission. The model analyzes multi-dimensional indicators such as device communication mode changes and traffic periodicity deviations to identify abnormal behavior patterns before the actual attack occurs, and classifies them as high-risk firmware operations based on device type information, triggering security intervention and preventing further spread of attacks.

[0274] Through steps 4.1 to 4.4, this embodiment realizes knowledge graph-based probabilistic relationship reasoning detection, which can accurately identify abnormal behavior in the network without decrypting traffic and give corresponding abnormal type judgments.

[0275] Step 5, resource adaptive allocation and detection task scheduling: According to the detection results and priorities, combined with the resource status of different levels of devices, the computing resources are adaptively allocated and the detection tasks are dynamically scheduled to optimize the overall performance of the system;

[0276] This step realizes the dynamic scheduling and load balancing of detection tasks according to the computing resource status of different levels, ensures the real-time response ability of the system in a high-concurrency environment, and specifically includes the following steps:

[0277] Step 5.1, hierarchical task priority evaluation;

[0278] Construct a hierarchical task priority evaluation model to assign reasonable execution priorities to different detection tasks:

[0279] ;

[0280] Where, represents the priority score of the task; represents the detection task to be evaluated; represents a threat level assessment function related to the task; represents a task urgency assessment function; represents a task resource demand assessment function; , , respectively represent the weight coefficients of the threat level, task urgency factor, and resource demand factor, satisfying .

[0281] The weight coefficients are dynamically adjusted based on different levels of security concerns:

[0282] ;

[0283] wherein, , , respectively represent the weight coefficients of the device layer, gateway layer, and cloud layer threat level assessment factors; , , respectively represent the weight coefficients of the device layer, gateway layer, and cloud layer task urgency assessment factors; , , respectively represent the weight coefficients of the device layer, gateway layer, and cloud layer resource demand assessment factors.

[0284] This reflects the characteristics that the device layer pays more attention to direct threats, the cloud layer pays more attention to global planning, and the device layer pays more attention to resource consumption.

[0285] Step 5.2, multi-objective resource allocation algorithm;

[0286] Based on the task priority and the current available resource status, a multi-objective resource allocation algorithm is implemented:

[0287] ;

[0288] wherein, represents the optimal resource allocation scheme; represents the resource allocation scheme that maximizes the objective function ; represents the summation operation on all tasks; represents the total number of tasks; represents the priority score of the th task; represents the th detection task; represents the performance evaluation function; represents the resource allocated to the task ; represents the constraint condition of the optimization problem; represents the amount of resources allocated to the task ; represents the total amount of resources available in the current system.

[0289] For the heterogeneity of the Internet of Things environment, the resource allocation also needs to consider the device capability matching degree:

[0290] ;

[0291] wherein, represents the compatibility score between the task and the device; represents the detection task to be allocated; represents the device available for executing the task; represents the total number of dimensions of the capability matching degree evaluation; represents the index of the capability dimension, taking a value in the range of 1 to ; represents the weight coefficient of the th capability dimension; represents the matching degree evaluation function of the task and the device in the th capability dimension; represents the summation operation on all capability dimensions.

[0292] Step 5.3, load balancing and task migration;

[0293] The load balancing and task migration method is implemented to dynamically adjust the task distribution to avoid resource bottlenecks:

[0294] ;

[0295] wherein, represents the load imbalance degree of the device set ; represents the device set; represents a certain device in the set S; represents the load of the device ; represents the maximum value of the load of all devices in the set ; represents the minimum value of the load of all devices in the set ; represents the average value of the load of all devices in the set S.

[0296] When the imbalance degree exceeds the threshold value, task migration is triggered:

[0297] ;

[0298] wherein, represents a set of task migration; represents the i-th task to be migrated; represents the i-th source device (the device currently running the task); represents the i-th target device (the device to which the task will be migrated); represents the load of the source device ; represents the load of the target device ; represents the high load threshold; represents the low load threshold.

[0299] Task migration selects the optimal task and target device combination:

[0300] ;

[0301] wherein, represents the optimal task migration scheme; represents finding the combination that maximizes the following expression among all possible task and target device combinations; represents the task to be migrated; represents the target device to which the task will be migrated; represents the source device where the task is currently located; represents the benefit of migrating the task from the source device to the target device; represents the cost required to migrate the task from the source device to the target device.

[0302] Step 5.4, resource usage efficiency monitoring and optimization;

[0303] Build a resource usage efficiency monitoring and optimization system to continuously evaluate and improve resource allocation strategies:

[0304] ;

[0305] wherein, represents the resource usage efficiency of the task; represents the detection task to be evaluated; represents the performance of the task, such as detection accuracy, response speed, and other indicators; represents the amount of resources consumed by the task, such as CPU usage, memory usage, etc.

[0306] Periodically collect efficiency indicators of each detection task to identify inefficient tasks:

[0307] ;​​​

[0308] wherein, represents a set of inefficient tasks; represents a detection task being evaluated; represents the resource usage efficiency of a task; represents an efficiency threshold, below which a task is considered inefficient;

[0309] Resource configuration optimization or algorithm replacement is performed on inefficient tasks:

[0310]

[0311] wherein, represents the optimal configuration obtained after optimization of a task; represents a detection task that needs to be optimized; represents finding the configuration that maximizes the following expression among all possible configurations; represents the possible configuration parameter combinations of a task; represents the resource usage efficiency of a task under a specific configuration;

[0312] At the same time, the future resource demand trend is predicted through historical data analysis:

[0313] ;

[0314] wherein, represents the predicted resource demand at a future time point ; represents the current time point; represents the predicted time span, i.e., the length of time predicted from the current time into the future; represents the historical resource demand data from a past time point to the current time point ; represents the length of the time window for historical data collection; represents the prediction function for predicting future demand based on historical data; represents the time interval from time point to time point .

[0315] Through steps 5.1 to 5.4, the present embodiment realizes adaptive allocation of detection system resources, and can dynamically adjust the computing resource allocation strategy according to the resource status and task priority at different levels, to ensure the real-time response capability of the system in a high-concurrency environment.

[0316] The embodiment combines knowledge graph and encrypted traffic analysis method to construct an efficient and scalable Internet of Things network traffic anomaly detection method, and the main technical effects include:

[0317] Efficient encrypted traffic anomaly detection capability: independent of traffic decryption operation, only by analyzing the metadata characteristics of network traffic, the effective identification of abnormal behavior in encrypted traffic is realized. In a large-scale test environment, the detection accuracy is improved; the detection delay is reduced from seconds to milliseconds, realizing near real-time anomaly detection response.

[0318] Resource efficient utilization and multi-level cooperation: through the hierarchical knowledge graph structure and inter-layer cooperative system, the embodiment realizes the security information sharing and cooperation of Internet of Things devices at each level. Compared with the traditional centralized detection architecture, the system computing load is reduced, and the network transmission overhead is reduced, which is especially suitable for resource-constrained Internet of Things environment. At the same time, the multi-level cooperative system enables the detection system to make more accurate judgments under the overall view, reducing the false alarm rate.

[0319] Adaptability and scalability: the protocol adaptive feature extraction method enables the embodiment to adapt to diversified Internet of Things devices and communication protocols, without the need for retraining for each new protocol. The system supports linear expansion of the number of devices, and the performance only decreases logarithmically, which can cope with various scenarios from small local area networks to large-scale Internet of Things environments.

[0320] Privacy protection and security compliance: by analyzing only the metadata characteristics and not the decrypted content, the embodiment realizes effective security monitoring while protecting user data privacy, in line with modern network security regulations. Compared with traditional deep packet inspection methods, the embodiment maintains similar detection effects while completely avoiding the analysis of encrypted content, effectively preventing the risk of sensitive information leakage.

[0321] Resource adaptive allocation effect: the resource adaptive allocation system enables the system to dynamically adjust the allocation of computing resources according to the threat score and detection task priority, ensuring that critical anomaly detection tasks have sufficient resources. In the case of resource fluctuations, compared with traditional static allocation schemes, the system performance degradation is reduced, and the system robustness is greatly improved. Through dynamic load balancing, the system can still operate stably during peak periods.

[0322] In summary, the embodiment innovatively combines knowledge graph and encrypted traffic analysis method to solve the problem of encrypted traffic anomaly detection in Internet of Things environment, and realizes efficient, scalable, and privacy-protected network security monitoring capability, providing strong support for 5G / 6G era Internet of Things security.

[0323] Application examples of the embodiment

[0324] 1. Application scenario of smart city IoT security monitoring system:

[0325] This implementation focuses on the application in a certain smart city project, which contains more than 50,000 IoT devices, covering intelligent cameras, environmental sensors, traffic control devices, and other types. The system needs to effectively identify device abnormal behavior without decrypting traffic, prevent various network attacks, and meet privacy protection regulations.

[0326] This application scenario has the following characteristics:

[0327] Multiple device types and complex communication protocols (including MQTT, CoAP, HTTPS, etc.);

[0328] Limited computing resources on edge devices, with most processing done in resource-constrained environments;

[0329] Network traffic peak of 15 GB / minute, 99% encrypted transmission;

[0330] Average response time for security incidents is less than 500 milliseconds.

[0331] Smart city IoT device distribution and traffic characteristics are shown in the following table:

[0332] .

[0333] 2. Multi-level knowledge graph construction example:

[0334] In actual deployment, the system constructs a three-level knowledge graph structure, and the size and characteristics of each level of knowledge graph are as follows:

[0335] The actual construction results of the multi-level knowledge graph are shown in the following table:

[0336] .

[0337] 3. Probability relationship reasoning detection example:

[0338] In actual application, the system successfully detects multiple hidden attacks through path probability reasoning algorithms. The following is a detection case of a smart camera firmware implanted Trojan:

[0339] The camera device behaves normally, but the system detects a slight anomaly in its communication mode. Through the path probability reasoning algorithm, the correlation between the device and known abnormal patterns is calculated, and the result shows that it has a high correlation with the "firmware implanted backdoor" pattern.

[0340] The path probability reasoning detection results are shown in the following table:

[0341] .

[0342] 4. Multi-level cooperative detection instance:

[0343] In a large-scale DDoS attack, the multi-level cooperative system of the embodiment shows significant advantages. Attackers try to use IoT devices distributed in different regions to launch low-intensity, long-duration DDoS attacks to evade traditional detection systems.

[0344] The multi-level cooperative detection process and results are shown in the following table:

[0345] .

[0346] 5. Resource adaptive allocation instance:

[0347] During system deployment, the resource adaptive allocation strategy significantly improves the performance stability of the system during peak periods.

[0348] The following table shows the system performance comparison before and after resource adaptive allocation:

[0349] .

[0350] 6. Core technology effect verification:

[0351] Through actual deployment and long-term operation in a smart city environment, the two core technology effects of the embodiment are verified: encrypted traffic anomaly detection capability and system resource efficient utilization capability.

[0352] The encrypted traffic anomaly detection capability verification results are shown in the following table:

[0353] .

[0354] The system resource utilization efficiency verification results are shown in the following table:

[0355] .

[0356] The above results verify that the embodiment significantly reduces system resource consumption while maintaining high detection accuracy, making it particularly suitable for distributed deployment in an IoT environment. Compared with traditional detection methods, the detection accuracy is improved by 32.7%, while the resource consumption is reduced by about 65%, achieving the expected technical effects of the technical solution.

[0357] The above describes embodiments of the present application, but the embodiments are not limited to the specific embodiments described above, which are only illustrative and not limiting. Those skilled in the art can make more forms of equivalent embodiments under the inspiration of the embodiments, which are all within the protection scope of the embodiments.

Claims

1. A knowledge graph based network traffic anomaly detection method, characterized in that, The method comprises the following steps: Protocol-aware metadata feature extraction: extracting metadata features that do not involve content privacy from encrypted network traffic through deep packet inspection technology, including traffic statistical features, time series features, and connection relationship features; Multi-level knowledge graph construction: based on the extracted metadata features, according to the network architecture, a corresponding knowledge graph is constructed at the device layer, gateway layer, and cloud layer respectively, representing device behavior, network activity, and global security information respectively; Inter-level information collaboration: for the constructed multi-level knowledge graph, a cross-level knowledge transfer protocol is established to realize information sharing and collaboration between different levels of detection systems, ensuring the consistency and integrity of information at each level; Knowledge graph-based probabilistic relationship reasoning detection: using the constructed knowledge graph and collaborative information, probabilistic relationship inference is performed, edge confidence is calculated, and a multi-dimensional anomaly scoring model is applied to identify abnormal behavior; Resource adaptive allocation and detection task scheduling: according to the detection results and priorities, combined with the resource status of devices at different levels, the computing resources are adaptively allocated and the detection tasks are dynamically scheduled to optimize the overall performance of the system; The protocol-aware metadata feature extraction step specifically includes: Traffic session identification and preprocessing: dividing network traffic into sessions according to pre-set protocol rules; Protocol feature identification: identifying the protocol type used in network communication by analyzing the basic features of network traffic; Metadata feature extraction: extracting metadata features from data of different protocol types and constructing feature vectors, including: Data flow statistical features, time series features, connection relationship features, and protocol behavior features; Feature dimension reduction and normalization: apply principal component analysis algorithm to the generated feature vector set for dimension reduction processing, and normalize each dimension feature to obtain a standardized feature vector set : ; wherein, represents a normalized feature vector set; represents a normalization operation function; represents a principal component analysis algorithm; represents a metadata feature vector set; represents a target dimension after dimension reduction. 2.The knowledge graph-based network traffic anomaly detection method of claim 1, wherein, The multi-level knowledge graph construction step specifically includes: Device layer lightweight behavior pattern graph construction: constructing a lightweight behavior pattern graph for the network traffic features of a single IoT device; Gateway layer regional network behavior graph construction: constructing a regional network behavior graph based on the communication features of all devices managed by the gateway; Cloud layer global correlation graph construction: integrating multiple gateway layer graphs to construct a global correlation graph; Graph indexing and storage optimization: implementing indexing and storage optimization on the constructed multi-level knowledge graph. 3.The knowledge graph-based network traffic anomaly detection method of claim 1, wherein, The inter-level information collaboration step specifically includes: Adaptive sampling and aggregation algorithm: implementing an adaptive sampling and aggregation algorithm to balance information integrity and transmission efficiency for information exchange requirements between different network levels; Bidirectional information flow channel construction: establishing bidirectional information flow channels between multi-level knowledge graphs to enable efficient exchange of key information between upper and lower level systems; Information compression and recovery: implementing graph information compression and recovery methods for the characteristics of bandwidth limitations in IoT environments; Collaborative decision-making and feedback optimization: based on multi-level information fusion results, implementing collaborative decision-making and feedback optimization methods. 4.The knowledge graph-based network traffic anomaly detection method of claim 1, wherein, The inter-level information collaboration step specifically includes: the calculation formula of adaptive sampling is: ; in, Represents the sampling function; Indicates the first A knowledge graph to be sampled; This represents the sampling rate parameter; Represents nodes in the graph; Representation of the spectrum The set of all nodes in; Represents a computing node The function of importance score; Indicates based on sampling rate Node adaptive threshold function; Represents the edges in the graph; Representation of the spectrum The set of all edges in; Indicates the computation of edges A function of weights; Indicates based on sampling rate The edge adaptive threshold function; This represents the set union operator. 5.The knowledge graph-based network traffic anomaly detection method of claim 1, wherein, The knowledge graph-based probabilistic relationship reasoning detection step specifically includes: Device behavior fingerprint generation: generating a unique behavior fingerprint for each device based on the device nodes and their associated relationships in the multi-level knowledge graph; Path probability reasoning algorithm: based on the relationship between entities in the knowledge graph, realize the path probability reasoning algorithm, identify abnormal entity association mode; Multi-dimensional anomaly scoring model: build a multi-dimensional anomaly scoring model, considering multiple abnormal indicators of device behavior; Decision tree integrated decision: based on multi-dimensional anomaly scoring, apply decision tree integrated model for final anomaly decision.

6. The network traffic anomaly detection method based on a knowledge graph according to claim 5, characterized in that, The behavior fingerprint generation function of the device is represented as: ; wherein, representing a device behavior fingerprint generation function; representing a device node; representing a hash function; representing a protocol node associated with a device; representing a relationship characteristic between a device and a protocol; representing a device node and a protocol node have a relationship ; representing a hierarchical knowledge graph; The behavior fingerprint is further organized into a fingerprint library to support fast retrieval: ; wherein, represents a database of device behavior fingerprints; represents a first device node; represents a behavior fingerprint of a device ; represents a category of a device ; represents a set of device nodes; For newly observed device behavior, calculate the deviation degree of its current fingerprint and historical fingerprint: ; wherein, representing a device at a time of a behavior deviation; representing a device node; representing a current time point; representing a function to calculate the distance between two fingerprints; representing a device at a time of a current behavior fingerprint; representing a device of a historical behavior fingerprint.

7. The network traffic anomaly detection method based on a knowledge graph according to claim 1, characterized in that, The resource adaptive allocation and detection task scheduling steps specifically include: Hierarchical task priority evaluation: build a hierarchical task priority evaluation model to assign appropriate execution priority to different detection tasks; Multi-objective resource allocation algorithm: based on task priority and current available resource status, realize multi-objective resource allocation algorithm; Load balancing and task migration: implement load balancing and task migration method, dynamically adjust task distribution to avoid resource bottleneck; Resource usage efficiency monitoring and optimization: build a resource usage efficiency monitoring and optimization system to continuously evaluate and improve resource allocation strategies. 8.The knowledge graph based network traffic anomaly detection method of claim 7, wherein, The expression of the multi-objective resource allocation algorithm is: ; wherein, represents an optimal resource allocation scheme; represents a resource allocation scheme that maximizes the objective function ; represents a summation operation over all tasks; represents the total number of tasks; represents the priority score of the th task; represents the th detection task; represents a performance evaluation function; represents the resources allocated to the task ; represents the constraint conditions of the optimization problem; represents the amount of resources allocated to the task ; represents the total amount of resources available in the current system. 9.A knowledge graph based network traffic anomaly detection system configured to perform the knowledge graph based network traffic anomaly detection method of any one of claims 1-8. Including: Protocol-aware metadata feature extraction module: used to extract metadata features that do not involve content privacy from encrypted network traffic; Multi-level knowledge graph construction module: used to construct corresponding knowledge graphs at device layer, gateway layer and cloud layer respectively; Inter-level information collaboration module: used to realize information sharing and collaboration of different level detection systems; Knowledge graph-based probabilistic relationship reasoning detection module: used to use knowledge graph to infer probabilistic relationships and identify abnormal behavior; Resource adaptive allocation and detection task scheduling module: used to adaptively allocate computing resources and schedule detection tasks according to the resource status of different level devices.

Citation Information

Patent Citations

  • Malicious traffic detection method based on semantic map

    CN117375874A

  • Abnormal network traffic analysis method and system based on deep learning

    CN118984250A