Hidden attacker identification method and device based on moving target defense system

By constructing a user-reverse proxy heterogeneous graph and graph neural network feature learning, combined with long short-term memory networks, the problem of identifying covert attackers in mobile target defense systems is solved, and accurate identification and blocking of intelligent attackers is achieved.

CN120785572APending Publication Date: 2025-10-14BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510652162.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-20
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

Existing mobile target defense systems have difficulty accurately identifying covert attackers, especially intelligent attackers who simulate legitimate user access patterns, resulting in low detection accuracy and the failure of traditional detection methods.

Method used

Construct a user-reverse proxy heterogeneous graph, use graph neural networks for feature learning, combine long short-term memory networks to track user behavior, identify abnormal users through classifiers, and adopt spatiotemporal feature analysis methods.

Benefits of technology

It significantly improves the ability to identify hidden attackers, accurately identifies persistent malicious attackers, and enhances the system's defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785572A_ABST
    Figure CN120785572A_ABST
Patent Text Reader

Abstract

The invention provides a hidden attacker identification method and device based on a moving target defense system, and belongs to the technical field of network security, the method comprises the following steps: constructing a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of a user and a reverse proxy in the current time step; performing feature learning on the user-reverse proxy heterogeneous graph by using a graph neural network to obtain spatial fusion features; based on the fusion spatio-temporal representation of the previous time step and the spatial fusion features, determining the fusion spatio-temporal representation of the current time step; and inputting the fused spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier. According to the method, the user characteristics and the agent side characteristics are jointly modeled through the user-directional agent heterogeneous graph, so that the limitation of evaluation only from the user characteristics is overcome; the spatial fusion features of a plurality of time steps are fused, spatial-temporal features are subjected to conjoint analysis, and persistent hostile attackers are accurately identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and device for identifying hidden attackers in a mobile target defense system. Background Art

[0002] With the rapid development of the internet and wireless communication technologies, the scale of botnets based on IoT devices continues to expand, making the threat of distributed denial of service (DDoS) attacks increasingly severe. These attacks utilize massive amounts of malicious traffic to occupy target system resources, preventing legitimate users from accessing critical services and severely impacting the availability and stability of online businesses. To combat DDoS attacks, a proxy-based moving target defense system is considered an effective defense strategy. This system utilizes a dynamically changing cluster of proxy servers, making it difficult for attackers to locate and sustain attacks on target servers. Specifically, legitimate users must obtain available proxy server addresses from a control server, and the accessibility of individual proxy servers can fluctuate over time. When a proxy server is attacked by a DDoS attack, the system dynamically adjusts user access paths, redistributing traffic to other proxy servers, thereby mitigating the attack's effectiveness.

[0003] Evaluating users from the user side is crucial in mobile target defense systems. It not only helps identify potential malicious behaviors, but also allows preventive measures to be taken before an attack occurs, thereby improving the system's defense capabilities. Currently, some mobile target defense systems have introduced user behavior evaluation mechanisms, such as screening potential malicious users based on access frequency, request patterns, and abnormal behavior detection. However, these methods still have many shortcomings, mainly reflected in the limited detection accuracy, making it difficult to effectively identify highly concealed intelligent attackers. With the evolution of attack technology, attackers have been able to use intelligent means to launch more covert distributed denial of service attacks, simulating normal user traffic, making attack traffic difficult to distinguish from normal access in a short period of time, thereby bypassing detection mechanisms based on traffic characteristics. In addition, if Figure 1 As shown in the figure, another type of attacker uses a decoy strategy. Instead of launching a direct attack, they steal the address of the mobile target defense system agent, obtain the target agent's access information, and then leak or transmit this information to the active attacker, thereby indirectly promoting the attack. This approach not only makes the attack traffic more dispersed and covert, but also reduces the effectiveness of traditional traffic detection mechanisms, further exacerbating the defense challenge.

[0004] Therefore, how to improve the accuracy of user behavior assessment in mobile target defense systems, accurately identify and block hidden attackers, especially intelligent attackers who can accurately simulate the access patterns of legitimate users, has become a technical problem that needs to be solved urgently in current research. Summary of the Invention

[0005] The application provides a method and device for identifying hidden attackers in a mobile target defense system, to solve the problem of low user behavior evaluation accuracy and difficulty in identifying hidden attackers in the prior art.

[0006] The application provides a method for identifying hidden attackers in a mobile target defense system, comprising the following steps: Construct a user-reverse proxy heterogeneous graph at the current time step, which reflects the interaction structure of users and reverse proxies at the current time step; Use a graph neural network to learn the features of the user-reverse proxy heterogeneous graph, to obtain spatial fusion features; Based on the fusion spatio-temporal representation of the previous time step and the spatial fusion features, determine the fusion spatio-temporal representation of the current time step; Input the fusion spatio-temporal representation of the current time step into a classifier to obtain the abnormal user identification result output by the classifier.

[0007] According to the method for identifying hidden attackers in a mobile target defense system provided by the application, for each user node in the user-reverse proxy heterogeneous graph, the spatial fusion features are calculated based on the following formula: ; Wherein, represents the user node The spatial fusion features at time step , represents an update function, represents the reverse proxy node interacting with the user node , represents the information interaction weight between the user node and the reverse proxy node , represents the vector representation of the reverse proxy node .

[0008] According to the method for identifying hidden attackers in a mobile target defense system provided by the application, the fusion spatio-temporal representation of the current time step is determined based on the fusion spatio-temporal representation of the previous time step and the spatial fusion features, comprising: Weighted aggregation processing is performed on the time interval between the current time step and the previous time step, the fusion spatio-temporal representation of the previous time step, and the spatial fusion features, to obtain an aggregated feature; Based on the aggregated feature, determine the fusion spatio-temporal representation of the current time step.

[0009] According to the application, a method for identifying hidden attackers in a mobile target defense system is provided, and a fusion spatio-temporal representation is calculated based on the following formula: ; Wherein, represents the fusion spatio-temporal representation of the time step , represents the spatial fusion feature of the time step , represents the fusion spatio-temporal representation of the time step , represents the time interval between the time step and the time step , represents a constant parameter, represents the weight of , represents the weight of , represents the weight of .

[0010] According to the application, a method for identifying hidden attackers in a mobile target defense system is provided, and the fusion spatio-temporal representation of the current time step is input into a classifier to obtain an abnormal user identification result output by the classifier, which comprises: The fusion spatio-temporal representation of the current time step is input into a classifier to obtain a user abnormal probability of each user output by the classifier; the user abnormal probability is the probability that the user is an abnormal user; Users with a user abnormal probability greater than a preset threshold are determined as abnormal users.

[0011] According to the application, a method for identifying hidden attackers in a mobile target defense system is provided, and after the fusion spatio-temporal representation of the current time step is input into a classifier to obtain an abnormal user identification result output by the classifier, the method further comprises: All abnormal users are marked as potential threats, and a ban operation is performed on all the abnormal users.

[0012] The application also provides a device for identifying hidden attackers in a mobile target defense system, which comprises the following modules: A heterogeneous graph construction module is configured to construct a user-reverse proxy heterogeneous graph of a current time step, wherein the user-reverse proxy heterogeneous graph reflects the interaction structure between users and reverse proxies in the current time step; A spatial feature learning module is configured to use a graph neural network to learn features of the user-reverse proxy heterogeneous graph to obtain a spatial fusion feature; a time domain information fusion module configured to determine a fusion spatio-temporal representation of a current time step based on a fusion spatio-temporal representation of a previous time step and the spatial fusion feature; an abnormal user identification module configured to input the fusion spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier.

[0013] The application further provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the identification method of a hidden attacker in a mobile target defense system according to any one of the above when executing the computer program.

[0014] The application further provides a non-transitory computer-readable storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement the identification method of a hidden attacker in a mobile target defense system according to any one of the above.

[0015] The application further provides a computer program product including a computer program, and the computer program is executed by a processor to implement the identification method of a hidden attacker in a mobile target defense system according to any one of the above.

[0016] The application provides an identification method and device of a hidden attacker in a mobile target defense system, which constructs a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of a user and a reverse proxy in the current time step, uses a graph neural network to learn a feature of the user-reverse proxy heterogeneous graph to obtain a spatial fusion feature, determines a fusion spatio-temporal representation of a current time step based on a fusion spatio-temporal representation of a previous time step and the spatial fusion feature, and inputs the fusion spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier. The application widens a spatial dimension by jointly modeling a user feature and a proxy feature through a user-direction proxy heterogeneous graph, overcomes the limitation of evaluation from only a user feature, tracks behavior changes of a user in multiple time periods by fusing spatial fusion features of multiple time steps, thereby capturing abnormalities in time sequence, and accurately identifies persistent malicious attackers by jointly analyzing spatio-temporal features, thereby significantly improving the identification ability of hidden attackers. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the present application or the prior art, the following will briefly introduce the drawings needed in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0018] Figure 1 is a flowchart of a mobile target attack defense system based on a multi-proxy server switching strategy in the prior art; Figure 2 is one of flowcharts of a method for identifying a hidden attacker in a mobile target defense system provided by the present application; Figure 3 is another of flowcharts of a method for identifying a hidden attacker in a mobile target defense system provided by the present application; Figure 4 is a structural schematic diagram of an apparatus for identifying a hidden attacker in a mobile target defense system provided by the present application; Figure 5 is a structural schematic diagram of an electronic device provided by the present application. DETAILED DESCRIPTION

[0019] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below with reference to the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of protection of the present application.

[0020] It should be noted that, in the description of the embodiments of the present application, the terms "comprise", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of another identical element in the process, method, article or device comprising the element. The terms "upper", "lower" and the like indicate the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the present application and simplify the description, and do not indicate or imply that the indicated device or element must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. Unless otherwise specified and limited, the terms "mount", "connect", "connect" should be understood broadly, for example, it can be a fixed connection, or a detachable connection, or an integral connection; it can be a mechanical connection, or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, or the internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0021] The terms "first", "second", and the like in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally a class, not limited to the number of objects, for example, the first object can be one or more. In addition, "and / or" means at least one of the connected objects, and the character " / ", generally indicates that the objects before and after are in a "or" relationship.

[0022] In the prior art, it is a very challenging problem to determine whether a user in a distributed denial of service defense system is abnormal, especially the same kind of solution usually relies heavily on user side features, such as traffic packet sending frequency, TCP connection number, etc. to determine whether the user is abnormal. However, this method has serious robustness problems when facing increasingly concealed attacks. First, this method is difficult to effectively detect attacks that simulate normal user traffic, such as HTTP DDoS attacks, Slowloris attacks, etc. Secondly, it cannot identify latent attackers who guide attacks. Such attackers do not directly launch attacks themselves, but constantly steal reverse proxy IP addresses in a mobile target defense system to guide attackers to launch attacks on the correct target. This extremely concealed attack method is easy to cause a large number of misjudgments and omissions, making traditional detection methods ineffective.

[0023] In view of the above problems, the present application provides a method and device for identifying concealed attackers in a mobile target defense system. Figure 2 is one of the flowcharts of the method for identifying concealed attackers in a mobile target defense system provided by the present application, as shown in Figure 2 The method comprises the following steps: S210, a user-reverse proxy heterogeneous graph of a current time step is constructed, and the user-reverse proxy heterogeneous graph reflects the interaction structure of users and reverse proxies in the current time step; S220, a graph neural network is used to learn features of the user-reverse proxy heterogeneous graph, and a spatial fusion feature is obtained; S230, based on the fusion spatio-temporal representation of the previous time step and the spatial fusion feature, a fusion spatio-temporal representation of the current time step is determined; S240, the fusion spatio-temporal representation of the current time step is input into a classifier, and an abnormal user identification result output by the classifier is obtained.

[0024] In the embodiment of the present application, the execution subject of the identification method of the hidden attacker in the mobile target defense system can be an identification device of the hidden attacker in the mobile target defense system, which can include but is not limited to a server, a desktop computer, a notebook computer, and the like. The execution subject of the identification method of the hidden attacker in the mobile target defense system can also be an identification system of the hidden attacker in the mobile target defense system, which belongs to the identification device of the hidden attacker in the mobile target defense system.

[0025] In S210, in order to fully capture the time dependence and spatial interaction characteristics of user behavior, different time snapshots are constructed into a user-reverse proxy heterogeneous graph to accurately depict user access patterns and evolution characteristics, which is expressed as: ; Wherein, each reflects the user-proxy interaction structure at the time step , which can intuitively describe the evolution of connection patterns of the system at different time steps.

[0026] It can be understood that the characteristic factors need to be collected before the user-reverse proxy heterogeneous graph is constructed. Optionally, the collected characteristic factors include the access frequency of the user, the total number of requests, the assigned proxy node, the number of times the user is attacked in the assigned proxy node, the throughput, memory, disk, and processor usage of the proxy, and the number of users assigned to the proxy; these characteristics are dynamically collected through a sliding time window to ensure the real-time and stability of the data.

[0027] In S220, a graph neural network (GNN) is used to learn the features of the user and the proxy node to extract the representation of the user and the proxy node at the current time step: ; Wherein, By encoding the graph topology structure and the node attribute, the adaptive aggregation of the spatial features is realized. The representation learning process ensures that the model can fully utilize the local neighborhood information of the node to improve the accuracy of the abnormal behavior detection.

[0028] In S230, a long short-term memory network is introduced to track the behavior evolution of the user in the proxy remapping period, so as to effectively capture the abnormal patterns in time sequence.

[0029] The embodiment of the present invention provides a method for identifying hidden attackers in a mobile target defense system, which constructs a user-reverse proxy heterogeneous graph for the current time step, wherein the user-reverse proxy heterogeneous graph reflects the interaction structure between the user and the reverse proxy in the current time step; uses a graph neural network to perform feature learning on the user-reverse proxy heterogeneous graph to obtain spatial fusion features; determines the fused spatiotemporal representation of the current time step based on the fused spatiotemporal representation of the previous time step and the spatial fusion features; inputs the fused spatiotemporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier. The present invention jointly models user features and agent-side features through a user-direction proxy heterogeneous graph, broadens the spatial dimension, and overcomes the limitations of evaluating only from user features; by fusing the spatial fusion features of multiple time steps, it tracks the behavioral changes of users in multiple time periods, thereby capturing anomalies in the time series; and accurately identifies persistent malicious attackers through joint analysis of spatiotemporal features, significantly improving the ability to identify hidden attackers.

[0030] In an optional embodiment, for each user node in the user-reverse proxy heterogeneous graph, the spatial fusion feature is calculated based on the following formula: ; in, Represents a user node At time step The spatial fusion features of represents the update function, Represents the user node There are interactive reverse proxy nodes , Represents a user node With reverse proxy node The information interaction weight between Reverse proxy node The vector representation of .

[0031] In the embodiment of the present invention, in the process of node processing in the graph neural network, a message passing process based on the attention mechanism is introduced to enhance the model's ability to represent user interaction patterns. Specifically, for each user node , calculate its Internal and proxy nodes The information interaction weights between them are calculated, and the adaptive weighting mechanism is used for feature aggregation.

[0032] The embodiment of the present invention provides a method for identifying hidden attackers in a mobile target defense system. By introducing an attention mechanism, the model can adaptively determine which information interactions are more important, and then assign different weights to information aggregation to obtain a feature vector that accurately describes the information interaction relationship between the user and the proxy node.

[0033] In an optional embodiment, determining the fused spatiotemporal representation of the current time step based on the fused spatiotemporal representation of the previous time step and the spatial fusion feature includes: Performing weighted aggregation processing on the time interval between the current time step and the previous time step, the fused spatiotemporal representation of the previous time step, and the spatial fusion feature to obtain an aggregated feature; Based on the aggregated features, a fused spatiotemporal representation of the current time step is determined.

[0034] In the embodiment of the present invention, in the process of capturing the long-term evolution of user behavior, a time perception mechanism is further introduced to enable the model to adapt to the influence of irregular time intervals. Specifically, in the state update process of the model, the time interval is explicitly introduced. As a dynamic adjustment factor to ensure that historical behavior information with a longer time span can still provide effective contributions to current decision-making: ; in, Represents the time step The fused spatiotemporal representation of represents the spatiotemporal fusion function, Represents the time step The spatial fusion features of Represents the time step The fused spatiotemporal representation of Represents the time step With time step time interval.

[0035] The method for identifying hidden attackers in a mobile target defense system provided by an embodiment of the present invention explicitly introduces time intervals as dynamic adjustment factors, thereby ensuring that historical behavior information with a large time span can still provide effective contributions to current decision-making, thereby realizing the identification of malicious attackers with strong concealment and long-term latent characteristics.

[0036] In an optional embodiment, the fused spatiotemporal representation is calculated based on the following formula: ; in, Represents the time step The fused spatiotemporal representation of Represents the time step The spatial fusion features of a fusion spatio-temporal representation of a time step a fusion spatio-temporal representation of a time step, a fusion spatio-temporal representation of a time step a time interval between time steps a constant parameter, a weight of a weight of a weight of a weight of a weight of a weight of a weight of

[0037] The method for identifying a concealed attacker in a mobile target defense system provided by the embodiments of the present application weights the control fusion feature, the fusion spatio-temporal representation of the previous time step and the time interval, thereby ensuring that the model maintains the robust detection capability for the concealed attacker in a long-term time span.

[0038] In an optional embodiment, the inputting the fusion spatio-temporal representation of the current time step into the classifier to obtain the abnormal user identification result output by the classifier comprises: inputting the fusion spatio-temporal representation of the current time step into the classifier to obtain a user anomaly probability of each user output by the classifier; the user anomaly probability is the probability that the user is an abnormal user; determining a user with a user anomaly probability greater than a preset threshold as an abnormal user.

[0039] In the embodiments of the present application, the fusion spatio-temporal representation is input into the classifier to identify an abnormal user: wherein, indicates whether the user is determined as a potential attacker at time .

[0040] The method for identifying a concealed attacker in a mobile target defense system provided by the embodiments of the present application identifies an abnormal user through a classifier, accurately detects a concealed attacker in a complex dynamic environment, and provides strong support for improving system security.

[0041] Table 1: Spatio-temporal anomaly detection algorithm

[0042] As shown in Table 1 and Figure 2 ​The attacker detection problem is converted into an abnormal user node screening problem in a space-time user-agent mapping graph. In the spatial feature aggregation process, an attention mechanism is introduced to balance the influence of the number of users and the size of different feature values on the evaluation results, so that the model is more robust and has generalization ability. In addition, a vector normalization method is proposed to adjust the vector dimension to realize feature normalization and improve detection stability. In order to further utilize time information, a long short-term memory network is used to aggregate the normalized vectors of multiple mapping graphs to extract time series features, and finally a classifier is used to accurately classify users. Compared with the traditional isolation forest method and other deep learning methods, the scheme has achieved better performance in detection accuracy, false positive rate and false negative rate.

[0043] Further, after inputting the fusion space-time representation of the current time step into the classifier to obtain the abnormal user identification result output by the classifier, the method further comprises: Mark all abnormal users as potential threats and perform a ban operation on all the abnormal users.

[0044] Specifically, the above space-time anomaly detection algorithm is triggered every time a new user-reverse agent interaction snapshot is generated. At this time, the proxy server uploads its state and related user information in the last time window. If the algorithm detects that the abnormal probability of some users is too high, it will be marked as a potential threat and perform a ban operation to enhance the security of the system.

[0045] In summary, the application provides a distributed denial of service attack detection model based on multiple agents. The input of the model includes the user-reverse agent mapping relationship of multiple time steps, and various feature indicators on the user side and the agent side. By combining these space-time information, a time series graph structure is constructed, and a graph neural network is used to aggregate spatial features to generate a normalized vector representation. Subsequently, a long short-term memory network is used to aggregate the vectors of multiple time steps to capture the long-term behavior patterns of attackers. Finally, the classifier is used to screen users deviating from the normal behavior pattern as abnormal users, achieving accurate identification of latent and direct attack type malicious users.

[0046] The following describes the identification device for hidden attackers in a mobile target defense system provided by the embodiments of the application. The identification device for hidden attackers in a mobile target defense system described below can be mutually corresponding to the identification method for hidden attackers in a mobile target defense system described above.

[0047] Figure 4 is a structural schematic diagram of the identification device for hidden attackers in a mobile target defense system provided by the application, like Figure 4As shown, the identification device of the hidden attacker in the mobile target defense system can include but is not limited to; The heterogeneous graph construction module 410 is configured to: construct a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of a user and a reverse proxy in the current time step; The spatial feature learning module 420 is configured to: perform feature learning on the user-reverse proxy heterogeneous graph using a graph neural network to obtain a spatial fusion feature; The time domain information fusion module 430 is configured to: determine a fusion spatio-temporal representation of a current time step based on a fusion spatio-temporal representation of a previous time step and the spatial fusion feature; The abnormal user identification module 440 is configured to: input the fusion spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier.

[0048] It should be noted that the identification device of the hidden attacker in the mobile target defense system provided by the embodiment of the present application can execute the identification method of the hidden attacker in the mobile target defense system described in any of the above embodiments when actually running, and the embodiment will not be repeated here.

[0049] Figure 5 An example of a schematic diagram of the physical structure of an electronic device is shown in FIG. 1. Figure 5 As shown, the electronic device can include a processor 510, a communications interface 520, a memory 530, and a communications bus 540, wherein the processor 510, the communications interface 520, and the memory 530 communicate with each other through the communications bus 540. The processor 510 can invoke logical instructions in the memory 530 to execute an identification method of a hidden attacker in a mobile target defense system, the method comprising: constructing a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of a user and a reverse proxy in the current time step; performing feature learning on the user-reverse proxy heterogeneous graph using a graph neural network to obtain a spatial fusion feature; determining a fusion spatio-temporal representation of a current time step based on a fusion spatio-temporal representation of a previous time step and the spatial fusion feature; inputting the fusion spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier.

[0050] Further, the logic instructions in the memory 530 described above can be implemented in the form of software functional units and sold or used as standalone products, which can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts that make contributions to the prior art, or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0051] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program can be stored on a non-transitory computer readable storage medium, and the computer program can be executed by a processor to enable a computer to execute the identification method of a hidden attacker in a mobile target defense system provided by the above-mentioned methods, the method comprising: constructing a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of users and reverse proxies in the current time step; performing feature learning on the user-reverse proxy heterogeneous graph using a graph neural network to obtain a spatial fusion feature; determining a fusion spatio-temporal representation of the current time step based on a fusion spatio-temporal representation of a previous time step and the spatial fusion feature; inputting the fusion spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier.

[0052] In yet another aspect, the present application also provides a non-transitory computer readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the identification method of a hidden attacker in a mobile target defense system provided by the above-mentioned methods, the method comprising: constructing a user-reverse proxy heterogeneous graph of a current time step, the user-reverse proxy heterogeneous graph reflecting an interaction structure of users and reverse proxies in the current time step; performing feature learning on the user-reverse proxy heterogeneous graph using a graph neural network to obtain a spatial fusion feature; determining a fusion spatio-temporal representation of the current time step based on a fusion spatio-temporal representation of a previous time step and the spatial fusion feature; Input the fused spatio-temporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier.

[0053] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place or distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.

[0054] Through the description of the above embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software and the necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.

[0055] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for identifying hidden attackers in a mobile target defense system, characterized in that: include: Constructing a user-reverse proxy heterogeneous graph at the current time step, wherein the user-reverse proxy heterogeneous graph reflects the interaction structure between the user and the reverse proxy at the current time step; Using a graph neural network to perform feature learning on the user-reverse proxy heterogeneous graph to obtain spatial fusion features; Determining a fused spatiotemporal representation of a current time step based on the fused spatiotemporal representation of a previous time step and the spatial fusion feature; The fused spatiotemporal representation of the current time step is input into a classifier to obtain an abnormal user identification result output by the classifier.

2. The method for identifying hidden attackers in a mobile target defense system according to claim 1, characterized in that: For each user node in the user-reverse proxy heterogeneous graph, the spatial fusion feature is calculated based on the following formula: ; in, Represents a user node At time step The spatial fusion features of represents the update function, Represents the user node There are interactive reverse proxy nodes , Represents a user node With reverse proxy node The information interaction weight between Reverse proxy node The vector representation of .

3. The method for identifying hidden attackers in a mobile target defense system according to claim 1, characterized in that: The determining of the fused spatiotemporal representation of the current time step based on the fused spatiotemporal representation of the previous time step and the spatial fusion feature includes: Performing weighted aggregation processing on the time interval between the current time step and the previous time step, the fused spatiotemporal representation of the previous time step, and the spatial fusion feature to obtain an aggregated feature; Based on the aggregated features, a fused spatiotemporal representation of the current time step is determined.

4. The method for identifying hidden attackers in a mobile target defense system according to claim 3, characterized in that: The fused spatiotemporal representation is calculated based on the following formula: ; in, Represents the time step The fused spatiotemporal representation of Represents the time step The spatial fusion features of Represents the time step The fused spatiotemporal representation of Represents the time step With time step time interval, Represents a constant parameter, express The weight of express The weight of express The weight of .

5. The method for identifying hidden attackers in a mobile target defense system according to claim 1, characterized in that: Inputting the fused spatiotemporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier includes: Inputting the fused spatiotemporal representation of the current time step into a classifier to obtain a user anomaly probability of each user output by the classifier; the user anomaly probability is the probability that the user is an abnormal user; Users whose abnormal probability is greater than a preset threshold are identified as abnormal users.

6. The method for identifying hidden attackers in a mobile target defense system according to claim 5, characterized in that: After inputting the fused spatiotemporal representation of the current time step into the classifier to obtain the abnormal user identification result output by the classifier, the method further includes: All abnormal users will be marked as potential threats and banned.

7. A device for identifying hidden attackers in a mobile target defense system, characterized in that: include: A heterogeneous graph construction module is used to: construct a user-reverse proxy heterogeneous graph at a current time step, wherein the user-reverse proxy heterogeneous graph reflects the interaction structure between the user and the reverse proxy at the current time step; A spatial feature learning module is used to: use a graph neural network to perform feature learning on the user-reverse proxy heterogeneous graph to obtain spatial fusion features; A time domain information fusion module is used to determine a fused spatiotemporal representation of a current time step based on the fused spatiotemporal representation of a previous time step and the spatial fusion feature; The abnormal user identification module is used to: input the fused spatiotemporal representation of the current time step into a classifier to obtain an abnormal user identification result output by the classifier.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the method for identifying a hidden attacker in a mobile target defense system according to any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for identifying a hidden attacker in a mobile target defense system according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method for identifying a hidden attacker in a mobile target defense system according to any one of claims 1 to 6 is implemented.