Network security intrusion detection system and method fused with graph neural network
By using a deep detection model based on graph neural networks, an adaptive protection strategy is constructed, which solves the problems of insufficient identification ability and poor adaptability of traditional network intrusion detection systems in complex network attacks, and achieves accurate identification and intelligent protection against covert attacks.
Patent Information
- Application Number
- CN202511200513.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-08-26
AI Technical Summary
Traditional network intrusion detection systems are inadequate in identifying complex network attacks, have poor adaptability to protection strategies, and lack intelligent response mechanisms, making it difficult to meet the security protection needs of the modern network environment.
By employing a fusion graph neural network approach, a deep detection model based on graph neural networks is constructed to achieve graph convolutional modeling and message passing analysis of multi-source traffic data, generate adaptive protection strategies, and identify and respond to covert attacks.
It improves the early detection capability of covert and coordinated attacks, enhances the system's detection accuracy and response efficiency, enables proactive defense against unknown and mutated attacks, and solves the problems of rigid strategies and unreasonable resource allocation in traditional systems.
Smart Images

Figure CN120856447A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a network security intrusion detection system and method that integrates graph neural networks. Background Technology
[0002] With the continuous evolution of cyberattack techniques and the increasing complexity of attack methods, traditional intrusion detection systems based on signature matching and statistical analysis are no longer sufficient to meet the challenges of current cybersecurity threats. Modern cyberattacks are characterized by strong concealment, high variability, and complex coordination. Attackers often employ advanced attack strategies such as multi-stage penetration, distributed coordination, and dynamic transformation, significantly reducing the effectiveness of traditional detection methods.
[0003] Existing intrusion detection technologies suffer from the following limitations: First, signature-based detection methods heavily rely on predefined rules based on known attack patterns, resulting in insufficient ability to identify zero-day attacks and variant attacks. Second, traditional detection systems employ a single-point monitoring architecture, lacking a holistic analysis of the correlation between network traffic patterns and node behavior, making it difficult to detect cross-node coordinated attacks and distributed intrusion behaviors. Third, existing systems have relatively rigid detection strategies and response mechanisms, unable to dynamically optimize based on changes in the network environment and the evolution of attack characteristics, leading to low detection accuracy and inefficient resource allocation. Furthermore, traditional methods suffer from poor real-time performance and high false alarm rates when processing large-scale network data, making it difficult to meet the security protection needs of modern complex network environments. Summary of the Invention
[0004] This invention discloses a network security intrusion detection system and method that integrates graph neural networks. It aims to solve the technical problems of traditional intrusion detection systems, such as insufficient ability to identify complex network attacks, poor adaptability of protection strategies, and lack of intelligent response mechanisms. By constructing a deep detection model based on graph neural networks and establishing an adaptive protection strategy generation mechanism, it achieves accurate identification and intelligent protection against covert attacks, improves the accuracy, real-time performance, and adaptability of network security protection, and provides reliable security for the modern network environment.
[0005] The first aspect of this invention proposes a network security intrusion detection method incorporating graph neural networks, comprising the following steps: Collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. Perform graph convolution modeling on the multi-source traffic data to construct an induced topology graph. Based on the induced topology graph, message passing analysis is performed to identify attack response patterns. Graph attention is then performed on the attack response patterns to generate attention vectors. Anomaly resonance amplification is performed on the attention vectors to generate node embedding representations. Graph convolution propagation is then performed on the node embedding representations to generate resonance enhancement domains. Deep graph learning is performed on the features of the inducing nodes to extract an attack behavior graph. Graph pooling is performed on the attack behavior graph to obtain the attack intent encoding. Graph inversion mapping is performed on the attack intent encoding to generate a protection strategy representation. Based on the protection strategy representation, dynamic topology transformation is constructed to generate an adaptive protection table. Multi-layer graph propagation is performed on the resonant enhancement domain to identify covert attack subgraphs. Graph fusion is performed on the covert attack subgraphs to generate camouflage graph embeddings. Topology reshaping is performed on the camouflage graph embeddings to generate a confusing network structure. Based on the confusing network structure and the adaptive protection table, an adversarial detection strategy is generated. The adversarial detection strategy is decomposed into multi-layer detection rules, and the multi-layer detection rules are graph-optimized and sorted to generate an interleaved detection sequence. A graph countermeasure matrix is generated based on the interleaved detection sequence. Based on the graph countermeasure matrix, an active defense prediction is generated. The active defense prediction is then evaluated using graph classification to generate an adaptive response signal, thus completing the intrusion detection.
[0006] A second aspect of this invention proposes a network security intrusion detection system that integrates graph neural networks, comprising: The data acquisition module is used to collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. The multi-source traffic data is used to perform graph convolution modeling to construct an induced topology graph. The message passing module is used to perform message passing analysis and identify attack response patterns based on the induced topology graph, perform graph attention calculation on the attack response patterns to generate attention vectors, perform abnormal resonance amplification on the attention vectors to generate node embedding representations, and perform graph convolution propagation on the node embedding representations to generate resonance enhancement domains. The attack learning module is used to extract an attack behavior map by deep graph learning on the features of the inducing node, obtain the attack intent encoding by graph pooling from the attack behavior map, generate a protection strategy representation by graph inversion mapping of the attack intent encoding, and construct an adaptive protection table based on the protection strategy representation by dynamic topology transformation. The topology reshaping module is used to perform multi-layer graph propagation to identify covert attack subgraphs in the resonant enhancement domain, perform graph fusion to generate camouflage graph embeddings in the covert attack subgraphs, perform topology reshaping on the camouflage graph embeddings to generate a confusing network structure, and generate an adversarial detection strategy based on the association between the confusing network structure and the adaptive protection table. The detection optimization module is used to decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence. The response output module is used to generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete the intrusion detection.
[0007] The beneficial effects of this invention are reflected in the following points: 1. By constructing an induced topology graph through multi-source traffic data acquisition and graph convolution modeling, and combining message passing analysis and graph attention calculation to identify attack response patterns, an intelligent conversion from raw network traffic to attack pattern recognition is achieved. This solves the problem that traditional methods cannot effectively capture complex relationships between network nodes, and improves the early detection capability of covert and coordinated attacks. 2. By using deep graph learning technology to extract attack behavior graphs and construct an adaptive protection table, and identifying covert attack subgraphs and generating confusing network structures through multi-layer graph propagation, an intelligent mapping from attack feature analysis to protection strategy generation is achieved. This solves the problems of rigid strategies and poor adaptability in traditional protection systems, and improves the system's proactive defense capability against unknown and mutated attacks. 3. By generating a graph countermeasure matrix through multi-layer decomposition of adversarial detection strategies and optimization of interleaved detection sequences, and combining proactive defense prediction and time difference bottleneck analysis to achieve adaptive response signal generation, a closed-loop control from detection strategy configuration to intelligent response execution is completed. This solves the problems of lack of intelligence in the response mechanism and unreasonable resource allocation in traditional systems, and achieves a dual improvement in detection accuracy and response efficiency.
[0008] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0009] The accompanying drawings illustrate specific examples of the technical solutions described in this invention and, together with the detailed embodiments, form part of the specification, serving to explain the technical solutions, principles, and effects of this invention.
[0010] Unless otherwise specified or defined, the same reference numerals in different figures represent the same or similar technical features, and different reference numerals may be used to represent the same or similar technical features.
[0011] Figure 1 This is a flowchart illustrating a network security intrusion detection method that integrates graph neural networks according to the present invention.
[0012] Figure 2 This is a structural block diagram of a network security intrusion detection system that integrates graph neural networks according to the present invention. Detailed Implementation
[0013] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0014] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.
[0015] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.
[0016] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0017] The technical solutions of the embodiments of this application will be described below.
[0018] like Figure 1 As shown, this embodiment of the invention provides a network security intrusion detection method that integrates graph neural networks, including the following steps S110-S160: Step S110: Collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. Perform graph convolution modeling on the multi-source traffic data to construct an induced topology graph.
[0019] Specifically, traffic monitoring devices deployed at key network nodes and boundary devices capture data packets and connection information transmitted in the network in real time. Deep packet inspection technology and flow statistical analysis methods are employed to extract key characteristics such as node communication behavior, data transmission patterns, and connection topology from raw network traffic. The monitoring equipment includes network probes, traffic analyzers, and distributed sensor nodes, deployed in a hybrid star and mesh topology to ensure network coverage integrity and monitoring accuracy. Multi-source traffic data includes two main categories: normal node characteristics and induced node characteristics. Normal node characteristics reflect the standard communication behavior of legitimate users and devices in the network, including attributes such as communication frequency, data traffic volume, connection duration, and protocol distribution. Induced node characteristics are obtained by proactively implanting specially designed monitoring nodes that can simulate various network behavior patterns, inducing potential attackers to expose their attack intentions and behavioral characteristics. The data acquisition system employs a high-frequency sampling and caching mechanism, with a sampling frequency set to thousands of times per second and a cache capacity configured at the GB level to ensure data integrity under high traffic loads. All collected traffic data is aggregated to a central analysis platform via an encrypted transmission channel, equipped with a real-time processing engine and a massive storage system.
[0020] In some embodiments, the step of constructing an induced topology graph by graph convolution modeling of the multi-source traffic data includes: generating a node baseline template based on the normal node features; forming a feature-template coupling relationship by combining the induced node features and the node baseline template; extracting stable graph connection regions within the feature-template coupling relationship; and forming an induced topology graph based on the topology weights of the stable graph connection regions.
[0021] A baseline template for nodes is generated based on normal node characteristics. These characteristics include multi-dimensional attributes such as communication frequency distribution, packet size statistics, connection duration distribution, and protocol usage ratio. Cluster analysis is used to group normal nodes according to the similarity of their behavioral characteristics, with each cluster representing a typical normal node behavior pattern. The baseline template is constructed using statistical modeling methods to calculate statistical parameters such as the mean, standard deviation, quantiles, and distribution function of each type of normal node characteristic. A probability distribution model of node behavior is established, using a Gaussian mixture model to describe the distribution characteristics of normal node characteristics; the model parameters are determined using maximum likelihood estimation. The baseline template includes the normal range and trends of behavioral characteristics, serving as a reference standard for subsequent anomaly detection and induction analysis. The template generation process employs a sliding time window technique, with the window length determined based on the periodicity of network traffic, typically set to hourly or daily time scales. A temporal evolution mechanism for the template is established, periodically adjusting the baseline template parameters according to changes in the network environment and the evolution of user behavior.
[0022] A feature-template coupling relationship is formed by combining induced node features and node baseline templates. The acquired induced node features are correlated with the established node baseline templates, and the coupling relationship between them is established through comparison and mapping. The construction of the feature-template coupling relationship employs multi-dimensional similarity calculation methods, including Euclidean distance, cosine similarity, and Mahalanobis distance. The coupling strength between the induced node features and the baseline template is calculated using a similarity function; high coupling strength indicates that the induced node behavior is close to the normal pattern, while low coupling strength indicates significant behavioral deviation. A dynamic adjustment mechanism for the coupling relationship is established, updating the coupling parameters in real time based on the temporal changes of the induced node features and the evolution of the baseline template. The mathematical representation of the coupling relationship is in the form of an association matrix C=[c_ij], where c_ij represents the coupling strength between the i-th induced node feature and the j-th baseline template component. Principal component analysis is used to reduce the dimensionality of the coupling relationship, extracting the main coupling patterns and secondary coupling components. A stability evaluation index for the coupling relationship is established, assessing the stability of the relationship by calculating the temporal variance and spatial distribution characteristics of the coupling strength.
[0023] Stable graph connectivity regions are extracted within feature-template coupling relationships. A combined approach of connectivity strength analysis and temporal stability assessment is employed. Connectivity strength is determined by calculating the weight values between adjacent nodes in the coupling relationship; regions with high and evenly distributed weight values are labeled as strongly connected regions. Temporal stability assessment analyzes the changing characteristics of the coupling relationship over time, calculating the temporal variance and trend of connectivity strength. A stable graph connectivity region is defined as a spatial region where the connectivity strength exceeds a set threshold and temporal stability meets the persistence requirement. Connectivity analysis methods from graph theory are used to identify the boundaries and extents of connectivity regions, and depth-first search and breadth-first search algorithms are used to traverse the graph structure. A quality assessment system for connectivity regions is established, including graph structure indicators such as connectivity density, average path length, clustering coefficient, and modularity. Multiple identified stable graph connectivity regions are ranked by importance, and processing priorities are determined based on region size, connectivity strength, and network location. Inter-region correlation analysis is established to study the interactions and influences between different stable graph connectivity regions.
[0024] Using the extracted stable graph connection region information, the topological weights of each node and edge in the graph are calculated to construct a complete induced topological graph structure. The calculation of topological weights comprehensively considers factors such as the importance of nodes in the stable graph connection regions, connection strength, and network position. Node weights are calculated using centrality measures, including degree centrality, betweenness centrality, and eigenvector centrality. Edge weights are determined based on the feature similarity and communication frequency of the nodes connecting the two ends. The weight calculation formula is w_ij=α·sim(i,j)+β·freq(i,j), where sim(i,j) is the feature similarity between nodes i and j, freq(i,j) is the communication frequency, and α and β are weight coefficients. The induced topological graph is constructed using a weighted graph representation, and the adjacency matrix of the graph simultaneously contains connection relationships and weight information. A hierarchical structure of the graph is established, dividing the graph into a core layer, a middle layer, and an edge layer based on the importance and functional characteristics of the nodes. Graph layout algorithms are used to spatially arrange the induced topological graph, employing force-directed layout or hierarchical layout methods to achieve a reasonable distribution of nodes. A dynamic evolution model of the graph is established to describe the changes in the induced topology graph over time and with network conditions. Topological characteristics of the resulting induced topology graph are analyzed, and structural parameters such as the graph's diameter, average clustering coefficient, and small-world properties are calculated.
[0025] Step S120: Based on the induced topology graph, perform message passing analysis to identify the attack response pattern, perform graph attention calculation on the attack response pattern to generate an attention vector, perform abnormal resonance amplification on the attention vector to generate a node embedding representation, and perform graph convolution propagation on the node embedding representation to generate a resonance enhancement domain.
[0026] Specifically, message passing analysis is performed based on the induced topology graph to identify attack response patterns. The message passing analysis employs an asynchronous message propagation protocol, where each node calculates the message passing strength based on the state information and connection weights of its neighbors. The message passing mechanism follows the aggregation-update framework of graph neural networks, where nodes collect messages from their neighbors and then perform information fusion and state updates. Attack response pattern identification is based on the degree of abnormal deviation in node behavior; when a node's message passing pattern significantly differs from the normal baseline template, the node is marked as a potential attack response point. The attack response strength calculation formula is established as R = Σw_ij × |m_i - m_baseline|, where R is the response strength, w_ij is the connection weight, m_i is the message feature of node i, and m_baseline is the baseline message pattern. The message passing process employs a multi-round iterative mechanism, where the node state is updated based on the received messages in each iteration. The number of iterations is determined by the diameter of the graph and the convergence condition. Attack response patterns include different types such as single-point attack patterns, cooperative attack patterns, and cascading attack patterns, each corresponding to specific message passing characteristics and node response patterns. A feature extraction method for pattern recognition is established to extract identification features of attack patterns from the temporal features, spatial distribution, and intensity changes of message transmission.
[0027] Attention vectors are generated by graph attention computation on attack response patterns. A multi-head attention architecture is employed, with each attention head focusing on different aspects of the attack response pattern. Attention weights are calculated based on the similarity of node features and the intensity of the attack response, and attention coefficients are normalized using a softmax function. The mathematical expression of the attention mechanism is the scaled dot product attention form: Attention(Q,K,V)=softmax(QK^T / √d_k)V, where Q, K, and V are the query, key, and value matrices, respectively, and d_k is the dimension of the key vector. Multi-head attention is achieved by computing multiple attention functions in parallel and concatenating the results. The final output attention vector contains the importance information of the attack response pattern across different dimensions. The generation of attention vectors considers the temporal dependence and spatial locality of attack response patterns, and enhances the accuracy of attention computation through position encoding and neighborhood awareness mechanisms. An interpretability analysis of the attention weights is established, and visualization techniques are used to demonstrate the contribution of different nodes and connections in attack detection. The dimension of the attention vector is determined based on the graph size and computational complexity requirements, typically set to a high-dimensional vector of tens to hundreds of dimensions. Attention dropout is used to improve the model's generalization ability, and some attention connections are randomly disabled to prevent overfitting.
[0028] In some embodiments, generating node embedding representations by performing anomalous resonance amplification on the attention vector includes: segmenting the attention vector into a dominant frequency band and an auxiliary frequency band; transmitting a signal scanning path from the dominant frequency band to the auxiliary frequency band; recording the positions of intensity abrupt increases on the signal scanning path to form a set of abrupt increase points; and marking the point with the highest intensity in the set of abrupt increase points to generate a node embedding representation.
[0029] The attention vector is decomposed and segmented according to its frequency domain characteristics to identify the dominant frequency bands with concentrated energy and the auxiliary frequency bands with dispersed energy. A Fast Fourier Transform (FFT) technique is used to convert the time-domain attention signal into a frequency-domain representation, obtaining the amplitude and phase information of each frequency component. Dominant frequency band identification is based on energy distribution analysis, calculating the power spectral density of each frequency component. A frequency band is designated as dominant when its power density exceeds a predetermined proportion of the total energy. Auxiliary frequency bands are defined as the remaining frequency components other than the dominant bands; these bands typically contain noise signals and minor attack characteristics. An adaptive threshold mechanism for frequency band segmentation is established, with the threshold dynamically adjusted based on the overall energy distribution and signal-to-noise ratio of the attention vector. A multi-resolution analysis method is used to perform wavelet decomposition on the attention vector, identifying the distribution characteristics of dominant and auxiliary frequency bands at different scales. Dominant frequency bands typically correspond to the main features and key response patterns of attack behavior, while auxiliary frequency bands may contain detailed attack information and concealed features. A frequency band importance evaluation index is established, determining the relative importance of each frequency band by calculating its contribution to attack detection performance.
[0030] The signal scanning path is constructed from the dominant frequency band to the auxiliary frequency band. Frequency modulation technology is used to construct the signal scanning path, starting from the center frequency of the dominant band and gradually scanning towards the frequency range of the auxiliary band. The scanning process employs linear or logarithmic frequency modulation, with the rate of change of the scanning frequency determined according to the bandwidth and resolution requirements of the frequency band. An amplitude modulation mechanism for the scanning signal is established, and the intensity of the scanning signal is adjusted according to the energy distribution and propagation distance of the dominant frequency band. The mathematical description of the signal propagation path uses the transfer function form H(ω) = Y(ω) / X(ω), where Y(ω) is the frequency domain representation of the output signal, and X(ω) is the frequency domain representation of the input scanning signal. The selection of the scanning path considers the correlation and coupling strength between frequency bands, prioritizing paths between frequency bands with high correlation. A multi-path parallel scanning strategy is adopted, simultaneously detecting signal propagation in multiple directions and frequency ranges. A real-time monitoring mechanism is established to record the attenuation, distortion, and reflection characteristics of the scanning signal during propagation.
[0031] A burst point set is formed by recording the locations of intensity spikes along the signal scanning path. A combination of gradient analysis and threshold determination is used; a spike is identified when the rate of change of signal intensity exceeds a set threshold. A mathematical criterion for spike detection, |dI / dx|>threshold, is established, where I is the signal intensity, x is the position coordinate on the propagation path, and threshold is the spike detection threshold. A sliding window technique is used for real-time analysis of signal intensity, with the window size determined based on the signal variation characteristics and detection accuracy requirements. The location records of spike points include key information such as spatial coordinates, timestamps, and intensity values, forming a complete spike event database. A classification system for spike points is established, categorizing them into different types based on the amplitude, duration, and frequency characteristics of the intensity spikes. Cluster analysis is used to spatially group spike points, identifying their distribution patterns and clustering characteristics. The construction of the spike point set considers spatiotemporal correlation; adjacent spike points may belong to the same attack event or related security threats. A validity screening mechanism for spike points is established to exclude false spikes caused by noise and system disturbances.
[0032] The node embedding representation is generated by labeling the point with the highest intensity in the burst point set. A global optimization method is used to search for the location of the point with the highest intensity value in the entire burst point set. A standardization method for intensity comparison is established to convert the intensity values at different locations and times into comparable standardized values. The label of the maximum intensity point includes complete attributes such as location coordinates, intensity value, frequency features, and time information. The generation of node embedding representations is based on the feature vectorization of the maximum intensity point, converting the multi-dimensional attributes of the point into fixed-dimensional embedding vectors. A nonlinear mapping method is used to map the original features of the intensity points to the embedding space, preserving the relative relationships and distance information between features. A standardization processing mechanism for the embedding vectors is established to ensure that the embedding representations of different nodes have the same numerical range and distribution characteristics. The final output of the node embedding representation adopts a dense vector format, which facilitates subsequent graph neural network processing and similarity calculation.
[0033] A resonant enhancement domain is generated by graph convolution propagation on the node embedding representation. Graph convolution propagation adopts a combination of spectral domain convolution and spatial domain convolution. Spectral domain convolution uses the Laplacian matrix of the graph for global information propagation, while spatial domain convolution extracts local features through neighborhood aggregation. The mathematical expression of the graph convolutional layer is H^(l+1)=σ(D^(-1 / 2)AD^(-1 / 2)H^(l)W^(l)), where A is the adjacency matrix, D is the degree matrix, H^(l) is the feature matrix of the l-th layer, and W^(l) is the trainable parameter matrix. The formation of the resonant enhancement domain is based on the multi-layer cumulative effect of graph convolution propagation. Each convolutional layer expands the information propagation range and enhances the expressive power of features. An adaptive selection mechanism for propagation depth is established to determine the optimal number of convolutional layers based on the graph size and task complexity. Residual connections and batch normalization techniques are used to stabilize the training process of deep graph convolutional networks. The spatial range of the resonant enhancement domain is determined by calculating the effective receptive field. The size of the receptive field reflects the range of graph structure that the nodes can perceive. Design a boundary detection method for the enhancement domain to identify the effective range and attenuation boundary of the resonance effect.
[0034] Step S130: Deep graph learning is performed on the features of the induced nodes to extract the attack behavior graph. Graph pooling is performed on the attack behavior graph to obtain the attack intent encoding. Graph inversion mapping is performed on the attack intent encoding to generate the protection strategy representation. Dynamic topology transformation is constructed based on the protection strategy representation to generate an adaptive protection table.
[0035] Specifically, deep graph learning is used to extract attack behavior maps from the features of induced nodes. A hybrid architecture combining graph convolutional neural networks and graph attention networks is employed for deep graph learning. The first layer is a feature embedding layer, mapping the features of induced nodes to a unified vector space. The second and third layers are graph convolutional layers, learning the local structural features and global positional information of nodes through a neighborhood information aggregation mechanism. The fourth layer is a graph attention layer, calculating the attention weights between nodes and highlighting important attack correlations. The construction of the attack behavior map is based on the learned node representations and edge weights. Nodes in the map represent attack entities, and edges represent the propagation paths and impact relationships of attack behaviors. A hierarchical structure is established for the map, dividing attack behaviors into multiple levels according to severity and scope of impact, with each level corresponding to a different level of security threat. The attack behavior map contains key information such as attack source identification, attack path tracing, attack target prediction, and attack impact assessment. A graph contrastive learning method is used to enhance the distinguishability of attack behavior patterns, extracting unique features of attack behaviors through positive and negative sample comparison learning.
[0036] Attack intent encoding is obtained through graph pooling from the attack behavior graph. A hierarchical pooling strategy is adopted, including three levels: node-level pooling, subgraph-level pooling, and full-graph pooling. Node-level pooling aggregates local features of nodes through max pooling or average pooling operations, retaining the most important attack feature information. Subgraph-level pooling divides the attack behavior graph into several semantically related subgraphs, each corresponding to a specific attack intent pattern. Full-graph pooling compresses the entire attack behavior graph into a fixed-dimensional vector representation, forming a global encoding of the attack intent. The generation of the attack intent encoding uses learnable pooling parameters, and the pooling weights are optimized through backpropagation to achieve the best encoding effect. A multi-scale pooling mechanism is established to extract feature information of attack intent at different spatial scales, capturing multi-level intents from fine-grained attack behaviors to coarse-grained attack strategies. The attack intent encoding includes key attribute information such as attack type, attack intensity, attack duration, and attack coverage. An attention-guided pooling method is adopted, assigning different pooling weights according to the importance of the attack behavior to highlight the representation of key attack intents.
[0037] In some embodiments, the step of generating a protection strategy representation by graph inversion mapping of the attack intent encoding includes: performing malicious information interception and identification on the attack intent encoding to generate an interception blank area; performing security gain evaluation based on the interception blank area to form a gain coefficient; generating continuous security coverage through mapping interpolation using the gain coefficient; and performing feature extraction based on the continuous security coverage to generate a protection strategy representation.
[0038] Malicious information interception and identification of attack intent encoding generates interception blank areas. A multi-layered detection strategy is employed, including three levels: syntax layer detection, semantic layer detection, and behavioral layer detection. Syntax layer detection identifies anomalous encoding formats and data distributions by analyzing the structural features and data patterns of the encoding. Semantic layer detection identifies potential malicious semantics and attack targets by understanding the meaning and intent of the encoding. Behavioral layer detection identifies malicious attack behaviors by analyzing the behavioral patterns and consequences corresponding to the encoding. Interception processing employs information isolation and content filtering techniques to separate and remove identified malicious information from the original encoding. Interception blank areas are defined as empty regions formed in the encoding space after the removal of malicious information; these regions originally contained attack-related information content. A geometric feature description of the blank areas is established, including their location, size, shape, and boundary features. Topological analysis methods are used to study the connectivity and distribution patterns of interception blank areas, identifying the relationships between different blank areas. An importance assessment index for blank areas is established to determine the security value of the blank areas based on the degree of danger and scope of impact of the intercepted malicious information.
[0039] A gain coefficient is generated based on the security gain assessment of the intercepted blank areas. A multi-factor analysis method is employed, comprehensively considering factors such as the locational importance, coverage, and protection potential of the intercepted blank areas. A gain calculation model is established: G = α × S + β × C + γ × P, where G is the security gain, S is the importance score of the blank area, C is the coverage coefficient, P is the protection potential index, and α, β, and γ are weighting parameters. The importance score is determined by analyzing the criticality of the blank area in the attack path and its impact on the attack success rate. The coverage coefficient reflects the number of network nodes that the blank area can protect and the number of attack vectors it covers. The protection potential index represents the degree of security performance improvement obtained after deploying protective measures in the blank area. The calculation of the gain coefficient considers time factors and dynamic changes, establishing a time-varying gain model to describe the evolution of the gain coefficient over time. Sensitivity analysis is used to assess the influence of different factors on the gain coefficient and identify key factors affecting the security gain. A standardization mechanism for the gain coefficient is established, converting gain indices with different dimensions and numerical ranges into unified standardized coefficients.
[0040] For example, generating continuous security coverage through mapping interpolation of the gain coefficient includes: identifying coverage abrupt change features based on the gain coefficient to determine an observation window, wherein the coverage abrupt change features include the rate of change of security intensity, coverage duration interval, and decay gradient; tracing the security evolution process along the observation window to form a security situation map; extracting the coverage coordinates of each critical point in the security situation map; and arranging the coverage coordinates according to their security levels to generate continuous security coverage.
[0041] The observation window is determined based on the gain coefficient to identify coverage abrupt changes. Change rate analysis and gradient detection methods are used to identify coverage abrupt changes, calculating the first and second derivatives of the gain coefficient in time and space. The rate of change of safety intensity is determined by calculating the difference in gain coefficients between adjacent time points or spatial points; when the rate of change exceeds a set threshold, it is marked as an abrupt change feature. The coverage duration interval represents the time or spatial range within which the abrupt change feature remains stable, determined by analyzing the duration and impact range of the rate of change. The decaying gradient describes the attenuation process of the abrupt change feature regressing from its peak to a normal level; gradient parameters are calculated by fitting the attenuation curve. The determination of the observation window comprehensively considers the intensity, duration, and impact range of the abrupt change feature, and the window size is adaptively adjusted according to the spatiotemporal scale of the abrupt change feature. A multi-resolution observation mechanism is established, setting observation windows at different time and spatial scales to capture abrupt changes at different levels. A sliding window technique is used to dynamically adjust the observation window, with the window position and size changing as the abrupt change feature evolves. A window overlap handling mechanism is established; when multiple observation windows overlap, priority rules are used to determine the main observation area.
[0042] A security situation map is generated by tracing the security evolution process along an observation window. Using a state-space approach, security states are represented as multi-dimensional state vectors, and the trajectory of these vectors over time is tracked. A state transition model is established to describe the transition relationships and probabilities between security states; model parameters are determined through historical data statistics and expert knowledge. The security situation map is constructed using graph theory, where nodes represent different security states, and edges represent transition relationships and evolution paths between states. The situation map includes attribute information for state nodes, such as key parameters like security level, threat level, coverage intensity, and duration. A Markov chain model is used to describe the stochastic evolution of security states, and the probability distribution of future security situations is calculated using the state transition matrix. A hierarchical structure is established for the situation map, decomposing the complex security evolution process into multiple levels and stages, each corresponding to different time scales and security concerns.
[0043] Coverage coordinates of critical points are extracted from the security situation map. Critical points are defined as key locations such as inflection points in security status, jump points in threat levels, extreme points of coverage intensity, and bifurcation points of evolution paths. Critical point identification employs key node detection methods from graph theory, including centrality indices such as degree centrality, betweenness centrality, and eigenvector centrality. Mathematical criteria for critical points are established, determining their importance ranking by calculating the local features and global impact of nodes. Coverage coordinate extraction includes the precise location of critical points on the time and spatial axes, as well as corresponding security levels and coverage intensity attributes. Precise positioning techniques are used to determine the coordinate values of critical points, and interpolation and fitting methods are used to improve coordinate accuracy. A coordinate system standardization process is established, converting coordinates with different dimensions and numerical ranges into a unified standardized coordinate system. A coordinate data storage format is designed to support efficient coordinate querying, sorting, and analysis operations. A coordinate correlation analysis method is established to study the spatial and temporal relationships between different critical points. Cluster analysis is performed on the extracted coverage coordinates to identify critical point groups and distribution patterns with similar characteristics.
[0044] Continuous secure coverage is generated by arranging coverage coordinates according to their security level. A multi-criteria sorting method is used, comprehensively considering factors such as coverage intensity, threat level, impact range, and response priority. A security level classification standard is established, dividing coverage coordinates into different levels according to security importance: critical, important, general, and minor. A stable sorting technique is employed during the arrangement process to ensure that coordinates of the same security level maintain their original relative positions. Continuous secure coverage is generated by connecting the arranged coverage coordinates, using spline interpolation or Bézier curve fitting techniques to construct smooth coverage boundaries. A coverage continuity check mechanism is established to ensure the spatial and temporal continuity and consistency of the generated secure coverage. Piecewise linear interpolation is used to handle abrupt changes in coverage intensity, maintaining the physical rationality of the coverage distribution. An optimization method for coverage range is designed, adjusting interpolation parameters and boundary conditions to optimize the distribution effect of secure coverage.
[0045] Protection strategy representations are generated based on feature extraction from continuous security coverage. Multi-scale analysis methods are used to extract coverage features at different spatial and temporal scales. Spatial features include geometric features such as coverage intensity distribution, coverage boundary shape, coverage connectivity, and coverage density. Temporal features include dynamic features such as coverage evolution trends, coverage stability, and coverage response speed. A feature vector construction method is established to organize the extracted multi-dimensional features into a structured feature vector representation. The generation of the protection strategy representation employs feature encoding technology to convert the feature vectors into a machine-readable strategy description format. The strategy representation includes core elements such as protection type, protection strength, protection range, and protection timing. Semantic mapping methods are used to convert numerical features into semantic protection strategy descriptions, improving the understandability and operability of the strategy. A standardized format for the strategy representation is established to ensure interface compatibility between the generated protection strategy and existing security systems.
[0046] An adaptive protection table is generated based on a dynamic topology transformation constructed from the protection policy representation. The dynamic topology transformation employs graph transformation theory to convert the static protection policy representation into a dynamic network topology. Topology transformation includes operations such as node reconfiguration, edge weight adjustment, and path rerouting, enhancing the system's protection capabilities by altering network connectivity and communication paths. The adaptive protection table is constructed considering real-time changes in network status and the dynamic evolution of attack threats, establishing an automatic adjustment mechanism for the protection policy. The protection table contains key information such as protection node configuration, protection path planning, protection resource allocation, and protection priority settings. Reinforcement learning is used to train the adaptive adjustment policy, learning the optimal protection decision through interaction with the environment. A multi-version management mechanism for the protection table is established to support protection configurations for different security levels and application scenarios. A rapid deployment interface for the protection table is designed to enable real-time activation and dynamic switching of protection policies.
[0047] Step S140: Perform multi-layer graph propagation on the resonance enhancement domain to identify the hidden attack subgraph, perform graph fusion on the hidden attack subgraph to generate a disguised graph embedding, perform topological reshaping on the disguised graph embedding to generate a confusing network structure, and generate an adversarial detection strategy based on the association between the confusing network structure and the adaptive protection table.
[0048] Specifically, a multi-layer graph propagation method is used to identify covert attack subgraphs within the resonant enhancement domain. A recursive message passing mechanism propagates the multi-layer graph, with each layer expanding the receptive field of information propagation and gradually revealing deeply hidden attack relationships. The first layer focuses on direct neighbor connections within the resonant enhancement domain, extracting local attack features and short-range dependencies. The second and third layers extend to two-hop and three-hop neighbors, capturing medium-distance attack cooperation patterns and propagation paths. The deep propagation layer is responsible for identifying long-distance attack strategy associations and global attack layouts. Covert attack subgraph identification is based on abnormal structure pattern detection; subgraphs whose topological features significantly deviate from normal network structures are marked as covert attack targets. A subgraph importance evaluation index is established, comprehensively considering factors such as subgraph size, connection density, centrality, and propagation influence. A graph attention mechanism is employed to enhance the detection capability of covert features, highlighting key attack nodes and connections through attention weights. A multi-scale subgraph detection method is established to identify various covert patterns ranging from single-node attacks to large-scale cooperative attacks at different granularities.
[0049] A graph fusion method is used to generate camouflaged graph embeddings for covert attack subgraphs. An adversarial training framework is designed to fuse the graphs. The generator is responsible for embedding the attack subgraph into the normal graph, and the discriminator is responsible for distinguishing whether the fused graph structure contains attack components. The camouflage mechanism mimics the topological features and statistical properties of normal networks, making the attack subgraph difficult to identify by traditional detection methods after fusion. The embedding process adopts a variational graph autoencoder architecture, compressing the high-dimensional graph structure into low-dimensional embedding vectors while preserving the graph's topological characteristics and semantic information. An embedding quality evaluation system is established, evaluating the performance of the embedding representation through metrics such as reconstruction error, structure preservation, and camouflage effect. The camouflaged graph embedding consists of two parts: the original attack features and the camouflage mask features. The former retains the core functionality of the attack, while the latter provides the appearance features of the camouflage. A multi-level fusion strategy is adopted, performing feature fusion and embedding generation at the node level, edge level, and subgraph level. An adaptive adjustment mechanism for fusion parameters is established to dynamically adjust the fusion strength and camouflage degree according to the attack type and target network characteristics.
[0050] In some embodiments, the step of topologically reshaping the camouflaged graph embedding to generate a deceptive network structure includes: constructing a connection time series based on the camouflaged graph embedding; performing topological change analysis on the connection time series to form change moment markers; dividing the connection time series into a stable period and a perturbation period using the change moment markers as boundaries; and comparing the structural distribution characteristics of the stable period and the perturbation period to generate a deceptive network structure.
[0051] A connection time series is constructed based on camouflage graph embedding. A sliding time window method is used to embed the camouflage graph onto the time axis, dividing it into continuous time segments. Each segment corresponds to the network connection state within a time window. The size of the time window is determined based on the network's dynamic characteristics and the frequency of connection changes, typically set to a minute or hourly time scale. The connection state is represented using an adjacency matrix time series form A(t) = [a_ij(t)], where a_ij(t) represents the connection state and weight between nodes i and j at time t. The sequence construction process considers dynamic events such as connection establishment, disconnection, strength changes, and direction changes, recording the complete evolution of connections through event tagging and state transitions. A method for calculating the connection change rate is established, quantifying the network's dynamic activity by statistically analyzing the frequency and magnitude of connection changes per unit time. Data compression techniques are used to optimize the storage of the time series, reducing storage space through differential coding and sparse representation. A fast query interface for the sequence is designed, supporting efficient data retrieval based on time range, node identifier, and connection type.
[0052] Topological change analysis is performed on connection time series to generate change moment markers. Time series analysis of topological changes using graph metrics includes monitoring changes in structural features such as node degree distribution, clustering coefficient, average path length, and network diameter. Change detection employs statistical process control methods, identifying change points exceeding normal fluctuation ranges by calculating the moving average and control limits of topological metrics. A change significance assessment standard is established; when the change magnitude of a topological metric exceeds a set multiple of the historical standard deviation, it is marked as a significant change moment. Change moment markers include detailed information such as timestamp, change type, change magnitude, and impact range. Multi-scale change detection methods are used to identify change events at different temporal resolutions, ranging from micro-connectivity changes to macro-structural reorganizations. A change pattern classification system is established, categorizing change events into sudden, gradual, periodic, and random types based on their duration, impact range, and intensity. A clustering analysis method for change moments is designed to identify groups of change events that are temporally close and have similar characteristics.
[0053] The connection time series is divided into stable and turbulent periods by using change time markers as boundaries. A stable period is defined as the time interval during which the network topology remains relatively stable between two adjacent change time markers, with small amplitude and low frequency of connection changes. A turbulent period is defined as the time interval centered on the change time marker, during which the network structure undergoes significant changes or drastic fluctuations. An adaptive boundary determination method is used for time segmentation, dynamically adjusting the boundary positions of stable and turbulent periods based on the intensity and impact range of the change time markers. Statistical analysis of time segment lengths is established to calculate the average duration, length distribution, and periodicity characteristics of stable and turbulent periods. Overlapping window processing technology is employed to avoid information loss when change time markers are too densely packed. Time segment quality evaluation indicators are established, including performance indicators such as intra-segment connection stability, inter-segment difference significance, and segmentation boundary accuracy. A standardization method for time segments is designed to convert time segments of different lengths into a fixed-length standardized representation, facilitating subsequent comparative analysis. Inter-segment correlation analysis is established to study the interrelationships and transformation patterns between adjacent stable and turbulent periods.
[0054] For example, the step of generating a confusing network structure by comparing the structural distribution characteristics of the stable period and the perturbation period includes: converting the topological sequence of the stable period into a structural accumulation sequence; misaligning and superimposing the topological sequence of the perturbation period onto the structural accumulation sequence to form a structural difference map; extracting the topological jump accumulation in the structural difference map; and generating a confusing network structure according to the distribution density of the topological jump accumulation.
[0055] The topological sequence during the stable period is transformed into a structural cumulative sequence. The cumulative transformation of the topological sequence employs the discrete integral method, calculating the cumulative sum of topological features over time: C(t) = Σ[τ=0→t]T(τ), where T(τ) is the topological feature value at time τ, and C(t) is the accumulated structural amount up to time t. The accumulation process considers the weight differences of different topological features, highlighting the contribution of important structural features through a weighted accumulation method. A normalization mechanism for the cumulative sequence is established, converting accumulated values with different dimensions and numerical ranges into a unified standardized representation. A moving average technique is used to smooth the cumulative sequence, eliminating noise fluctuations and anomalous jumps during the accumulation process. The structural cumulative sequence contains multi-dimensional cumulative information, including cumulative degree features, cumulative clustering features, cumulative path features, and cumulative connectivity features. A cumulative rate analysis method is established, identifying the rapid and slow stages of structural accumulation by calculating the derivative of the cumulative sequence. A storage format for the cumulative sequence is designed, employing compression coding techniques to reduce the storage overhead of the sequence data.
[0056] The topological sequence during the perturbation period is misaligned and superimposed onto the structural accumulation sequence to form a structural difference map. Based on time-shifting technology, the perturbation period sequence is shifted along the time axis and then superimposed with the accumulation sequence, resulting in the calculation D(t) = C(t) + α × T_d(t-δ), where C(t) is the structural accumulation sequence, T_d(t-δ) is the perturbation period sequence with a time shift of δ, and α is the superposition weighting coefficient. The time shift δ is determined through correlation analysis and cross-correlation function calculations, selecting the shift value that maximizes the correlation or difference between the two sequences. The superposition weighting coefficient α is dynamically adjusted based on the perturbation intensity and the accumulation baseline to ensure that the superimposed difference map has appropriate contrast and resolution. The structural difference map is constructed using a multi-channel superposition method, with independent misaligned superposition and difference calculations performed on different types of topological features. A visualization method for the superposition effect is established, using color coding and contour maps to visually display the spatial distribution of structural differences. Difference enhancement technology is used to process the superposition results, highlighting key structural difference features through contrast adjustment and edge sharpening. Establish a resolution control mechanism for the difference map, and adjust the temporal and spatial resolution of the difference map according to the required analytical accuracy.
[0057] The cumulative amount of topological transitions is extracted within the structural difference map. Transition locations are identified by calculating the spatial and temporal gradients of the difference map, based on gradient analysis and edge detection methods. A threshold criterion is used for transition detection. ,in Let be the gradient magnitude of the difference map, and threshold be the jump detection threshold. The cumulative amount is extracted using the region integration method, calculating the cumulative integral of the difference value A=∫∫[Region]D(x,t)dxdt within the identified jump region. A jump intensity grading system is established, classifying jump events into different levels such as strong jumps, moderate jumps, and weak jumps based on the magnitude of the cumulative amount. Morphological processing techniques are used to regularize the jump regions, eliminating isolated jump points and filling jump gaps through dilation and erosion operations. A time-series analysis method for jump cumulative amounts is established to study the temporal distribution and evolution trend of jump events. Statistical feature extraction of cumulative amounts is designed, including statistical parameters such as mean, variance, skewness, and kurtosis. A clustering analysis method for cumulative amounts is established to group and classify jump events based on their numerical characteristics and spatial location.
[0058] A confusing network structure is generated based on the distribution density of the cumulative quantities of topological transitions. The distribution density is calculated using a kernel density estimation method, employing a Gaussian kernel function or other kernel functions to calculate the probability density distribution of the cumulative quantities in space: ρ(x) = (1 / nh)Σ[i=1→n]K((x-xi) / h), where K is the kernel function, h is the bandwidth parameter, and xi is the location coordinate of the cumulative quantities. Density sampling techniques are used to generate the confusing network structure, increasing the density of nodes and connections in high-density regions and reducing structural complexity in low-density regions. A probabilistic model for structure generation is established, determining the generation probability and location distribution of network elements based on the density distribution. A Poisson point process is used to simulate the random distribution of nodes, with the node density function determined based on the cumulative quantity density distribution. Connection generation uses a distance-dependent probabilistic model, where the connection probability is related to the distance between nodes and the local density. A structural constraint mechanism is established to ensure that the generated confusing network meets basic requirements such as connectivity, stability, and functionality. A structural optimization method is designed, using a genetic algorithm or simulated annealing algorithm to optimize the topological parameters and connection patterns of the confusing network.
[0059] Adversarial detection strategies are generated based on the association between a deceptive network structure and an adaptive protection table. The formulation of these strategies is grounded in game theory, modeling the attacker and defender as two sides in a game and analyzing their policy spaces and equilibrium solutions. Strategy generation considers the deceptive characteristics of the deceptive network structure and the protective capabilities of the adaptive protection table, optimizing the overall protection effect through strategy matching and resource allocation. An adversarial strength evaluation model is established to quantify the degree of adversarial interaction and the probability of victory or defeat between the deceptive attack and the protection strategy. Reinforcement learning is used to train the adaptive adversarial strategy, learning the optimal detection and response strategies through repeated interactions with the deceptive attack. The adversarial detection strategy incorporates multiple methods, including active detection, passive monitoring, induced analysis, and counter-attacks. A dynamic strategy switching mechanism is established to adjust the detection strategy in real time based on changes in the attack posture and feedback on the adversarial effect. A collaborative execution framework for the strategy is designed to improve the success rate and robustness of adversarial detection through the collaborative work of multiple detection modules.
[0060] Step S150: Decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence.
[0061] Specifically, the adversarial detection strategy is decomposed into multi-layered detection rules. A function-oriented hierarchical partitioning method is designed, decomposing the adversarial detection strategy into three core layers: the front-end perception layer, the middle analysis layer, and the back-end decision layer, according to the detection target, processing level, and response mechanism. The front-end perception layer detection rules focus on the collection and initial filtering of raw data, including basic detection components such as traffic capture rules, abnormal traffic identification rules, and real-time monitoring rules. The middle analysis layer detection rules are responsible for deep data mining and pattern recognition, identifying and analyzing complex attacks through association analysis rules, behavioral modeling rules, and threat assessment rules. The back-end decision layer detection rules handle advanced threat determination and response strategy selection, including decision-making components such as threat level determination rules, response strategy matching rules, and countermeasure activation rules. Information transmission interfaces between layers are established, achieving coordination and cooperation between different detection rules through standardized data formats and communication protocols. A modular encapsulation mechanism for the rules is designed, with each detection rule containing three standardized components: an input interface, processing logic, and an output interface.
[0062] In some embodiments, the step of generating an interleaved detection sequence by graph optimization sorting of the multi-layer detection rules includes: converting the multi-layer detection rules into a priority vector field; finding a resource balancing core in the priority vector field; propagating rules from the resource balancing core to form an initial permutation domain; and performing boundary convergence on the initial permutation domain to form an interleaved detection sequence.
[0063] Multi-layer detection rules are converted into a priority vector field. A feature space mapping method is used to transform the vector field, mapping the attribute features of each detection rule to a vector point in the vector field. The vectorized representation of the detection rule includes multiple feature dimensions such as rule type, execution complexity, resource requirements, detection accuracy, and response time. Priority is calculated using the analytic hierarchy process (AHP), determining the relative weights of each feature dimension by constructing a judgment matrix and calculating eigenvectors. The vector field is constructed using continuous interpolation techniques to establish a smooth, continuous field distribution between discrete rule vector points. A field strength calculation method is established: |F(x,y)|=√(Fx...) and Analyze the topological properties and flow characteristics of the vector field. 2 +Fy 2 Fx and Fy represent the components of the vector field in the x and y directions, respectively. A multi-resolution field representation technique is employed to construct a hierarchical representation of the vector field at different precision levels. Boundary condition treatments for the vector field are designed, employing periodic or absorbing boundary conditions in the boundary regions of the field. The curl and divergence of the field are calculated using... This study seeks resource balancing cores within a priority vector field. A global analysis of the constructed priority vector field identifies key core locations capable of detecting optimal resource allocation and load balancing. Critical point analysis from field theory is employed to search for resource balancing cores, identifying candidate core locations by finding zeros, saddle points, and extreme points in the vector field. A balance evaluation function is established: E(x,y) = w1·R(x,y) + w2·P(x,y) - w3·C(x,y), where R is resource utilization, P is a performance index, C is a cost function, and w1, w2, and w3 are weighting coefficients. Gradient analysis ∇E=0 is used to solve for the extreme points of the balance function, and the stability of these extreme points is assessed through eigenvalue analysis of the Hessian matrix. A competitive selection mechanism involving multiple candidate cores is established, selecting the optimal resource balancing core from multiple candidate locations through performance comparison and stability analysis. A dynamic tracking algorithm for the cores is designed to monitor the migration trajectory of the balancing cores as system load and rule configuration change. Robustness analysis is employed to assess the sensitivity of the core location to parameter disturbances, ensuring that the selected equilibrium core possesses strong anti-interference capabilities. An influence domain analysis of the core is established, determining its effective influence range by calculating the potential function distribution around the core. The characteristic description of the resource equilibrium core includes key parameters such as spatial coordinates, equilibrium strength, stability index, and influence radius.
[0064] Starting from the resource equilibrium core, rule propagation forms an initial permutation domain. From this defined core, a diffusion propagation mechanism is used to propagate the permutation information of the detection rules to the surrounding space, gradually constructing an initial permutation domain covering the entire vector field. An anisotropic diffusion model is employed, with the propagation speed and direction determined based on the local characteristics and gradient direction of the vector field. A propagation control equation is established. Where u is the propagation density, D is the diffusion tensor, and S is the source term. The propagation process considers the interactions and competition between rules, and the nonlinear dynamics of rule propagation are modeled using a reaction-diffusion equation. Wavefront tracing technology is used to monitor the evolution of the propagation boundary, recording dynamic characteristics such as the position, shape, and propagation velocity of the propagation wavefront. A propagation impedance model is established, considering the hindering effect of obstacle regions and low-priority regions in the vector field on the propagation process. A multi-source propagation mechanism is designed, where multiple propagation sources are simultaneously activated when multiple equilibrium cores exist, forming complex arrangement patterns through the convergence and interference of propagation wavefronts. A propagation termination condition is established, stopping the propagation process when the propagation intensity decays below a threshold or reaches the field boundary. The characteristics of the initial arrangement domain include geometric and physical properties such as propagation coverage, density distribution, propagation time, and boundary shape.
[0065] The initial permutation domain is converged at the boundary to form an interleaving detection sequence. Based on the constructed initial permutation domain, boundary optimization and convergence techniques are used to finely adjust the shape and extent of the permutation domain, generating the final interleaving detection sequence. According to the variational principle, a boundary-optimized energy functional is established. Where Γ is the boundary curve, k is the curvature, f is the constraint function, and λ is the Lagrange multiplier. The convergence process employs gradient descent to solve the variational problem, iteratively updating the boundary shape until convergence to the optimal configuration. Convergence constraints are established to ensure the converged boundary meets the requirements for detection coverage integrity and connectivity. A multi-scale convergence strategy is adopted, gradually refining the boundary from a coarse initial boundary to a precise optimal boundary. A convergence stability control mechanism is designed to avoid oscillations and divergences during convergence through adaptive step size and convergence monitoring. Boundary topology preservation constraints are established to ensure the basic topological structure of the boundary remains unchanged during convergence. The generation of the interleaved detection sequence is based on the internal structure of the converged permutation domain, generating an ordered execution sequence through spatial sampling and rule-based sorting. Sequence optimization techniques are used to further optimize the generated initial sequence, improving execution efficiency through local search and sequence rearrangement.
[0066] A graph countermeasure matrix is generated based on interleaved detection sequences. A sparse matrix representation is used, where row indices correspond to known attack types and variants, column indices correspond to individual detection rules in the interleaved detection sequence, and matrix element values represent the countermeasure effectiveness and matching degree of a specific rule against a specific attack. Countermeasure effectiveness is quantified through statistical analysis of historical detection data, evaluating rule performance by calculating metrics such as detection success rate, false positive rate, and false negative rate. A sparse storage and fast query mechanism for the matrix is established, employing compressed row storage format and hash indexing technology to improve the computational efficiency of matrix operations. An incremental update algorithm for the matrix is designed to enable rapid expansion and adjustment of the matrix when new attack types are discovered or new detection rules are added. Matrix factorization techniques are used to extract major countermeasure patterns, identifying key attack-countermeasure correlation patterns through singular value decomposition or non-negative matrix factorization. An intelligent recommendation system for countermeasure strategies is established, automatically selecting the optimal combination of countermeasure strategies from the matrix based on currently detected attack characteristics.
[0067] Step S160: Generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete the intrusion detection.
[0068] Specifically, proactive defense predictions are generated based on graph countermeasure matrices. The proactive defense prediction uses matrix-vector multiplication P=M×V, where P is the prediction vector, M is the graph countermeasure matrix, and V is the current threat feature vector. The prediction generation process considers the temporal evolution characteristics of attack behavior, predicting the next action and target selection of the attack through time series analysis and trend extrapolation. A multi-step prediction mechanism is established to predict not only immediate attack behavior but also the medium- and long-term development trends and possible mutation paths of the attack. The prediction results include key information such as attack type probability, attack time window, attack target node, and attack intensity level. A probabilistic graphical model is used to describe the uncertainty of the prediction, and Bayesian networks and Markov chains are used to model the randomness and conditional dependence of attack behavior. A prediction confidence calculation method is established, and the credibility of the prediction results is evaluated through historical prediction accuracy and current data quality. A hierarchical output mechanism for the prediction results is designed, classifying the prediction results into three levels according to the threat level and urgency: immediate warning, medium-term attention, and long-term monitoring.
[0069] In some embodiments, the step of performing graph classification evaluation on the active defense prediction to generate an adaptive response signal includes: identifying time difference bottlenecks in the active defense prediction to generate transmission time difference and computation time difference; using the transmission time difference to evaluate the correlation of the computation time difference to form a time difference correlation graph; generating key time difference factors through principal component decomposition of the time difference correlation graph; and implementing response adjustment according to the key time difference factors to generate an adaptive response signal.
[0070] The proactive defense prediction process identifies and addresses bottlenecks in transmission and computation time differences. An end-to-end latency decomposition method breaks down the total processing time of proactive defense prediction into components such as data transmission latency, computation latency, storage access latency, and communication coordination latency. Transmission time difference is measured using timestamp technology, with precise timestamps set at the start and end points of data transmission. Accurate transmission latency data is obtained by calculating the time difference. Computation time difference is identified through CPU performance monitoring and task scheduling analysis, quantifying computation time consumption by monitoring processor utilization, memory access patterns, and instruction execution cycles. A precision control mechanism for time difference measurement is established, employing high-precision timers and synchronous clocks to ensure accuracy and consistency. Statistical analysis methods are used to process the measured time difference data, calculating statistical parameters such as average time difference, time difference variance, and time difference distribution characteristics. A classification standard for time differences is established, categorizing them into minor, moderate, and severe time differences based on their magnitude and impact.
[0071] A time difference correlation diagram is generated by evaluating the correlation between transmission time difference and computation time difference. Statistical methods such as Pearson correlation coefficient and Spearman rank correlation coefficient are used to assess the correlation strength, quantifying the linear and nonlinear correlation strength between transmission time difference and computation time difference. The correlation strength coefficient is calculated using the formula r=Σ(xi-xm)(yi-ym) / √[Σ(xi-xm)]. 2 ×Σ(yi-ym) 2 ], where xi represents the i-th sample value of the transmission time difference, yi represents the i-th sample value of the calculated time difference, xm represents the mean of the transmission time difference samples, and ym represents the mean of the calculated time difference samples. The time difference correlation graph is constructed using a weighted graph representation, where nodes represent different time difference measurement points, and edge weights represent the correlation strength between nodes. Connectivity analysis methods from graph theory are used to identify strongly connected components and critical paths in the time difference correlation graph, revealing the main channels and influencing mechanisms of time difference propagation. Topological feature analysis of the correlation graph is established, and the structural characteristics of the correlation graph are described by indices such as the clustering coefficient, average path length, and node degree distribution. A graph segmentation algorithm is used to divide the time difference correlation graph into modules, identifying time difference groups and substructures with similar correlation characteristics.
[0072] Key time difference factors are generated through principal component decomposition (PCD) of the time difference correlation graph. PCD is applied to the constructed time difference correlation graph to extract key time difference factors and main variation patterns affecting system performance using dimensionality reduction techniques. PCD employs eigenvalue decomposition, decomposing the adjacency matrix of the time difference correlation graph into eigenvalues A = QΛQ^T, where Q is the eigenvector matrix and Λ is the eigenvalue diagonal matrix. Key time difference factors are identified based on the eigenvalue ranking, selecting the eigenvectors corresponding to the largest eigenvalues as the primary time difference factors. A variance contribution rate calculation method is established, determining the number of principal components to retain by analyzing the variance contribution rate of each principal component. Factor loading analysis is used to interpret the physical meaning of each principal component, identifying system bottlenecks and performance influencing factors corresponding to each key time difference factor. A factor score calculation method is established, projecting the original time difference data onto the principal component space to obtain the score value of each sample on the key time difference factors. An importance ranking mechanism is designed to rank the key time difference factors based on eigenvalue size and variance contribution rate. Stability analysis of the factors was conducted, and the robustness of key time zone factors was evaluated through perturbation analysis and sensitivity testing. The outputs of the key time zone factors were formatted as standardized vectors to facilitate subsequent response calibration and parameter optimization.
[0073] An adaptive response signal is generated by adjusting the response based on the key time difference factor. Based on the feedback control principle, the key time difference factor is used as the control input, and the system's response characteristics are adjusted through a proportional-integral-derivative controller. The adjustment objective function is established as J=Σwi×fi. 2Where fi is the deviation value of the i-th key time difference factor, and wi is the corresponding weight coefficient. The calibration process adopts the gradient descent optimization method, gradually reducing the deviation of the time difference factor and the system performance loss by iteratively adjusting the response parameters. A multi-objective calibration strategy is established to simultaneously optimize multiple performance indicators such as response speed, accuracy, and resource consumption. The generation of adaptive response signals considers the dynamic characteristics of the system and environmental changes, and ensures the effectiveness and adaptability of the response signals through adaptive parameter adjustment. Signal modulation technology is used to encode and modulate the generated response signals to ensure reliable transmission in complex network environments. A signal priority management mechanism is established to assign execution priorities to different response signals according to threat level and time urgency. The output of the adaptive response signal contains complete response instruction information such as signal type, parameter configuration, execution timing, and expected effect, realizing comprehensive detection, analysis, and response to network intrusion behavior, and completing the closed-loop control process of the entire intrusion detection system.
[0074] To implement the network security intrusion detection method based on the fused graph neural network corresponding to the above method embodiments, and to achieve the corresponding functions and technical effects. See also Figure 2 , Figure 2 This diagram illustrates a structural block diagram of a network security intrusion detection system 200 incorporating graph neural networks according to an embodiment of this application. For ease of explanation, only the parts relevant to this embodiment are shown. The network security intrusion detection system 200 incorporating graph neural networks provided in this embodiment includes: Data acquisition module 201 is used to collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. The multi-source traffic data is used to perform graph convolution modeling to construct an induced topology graph. The message passing module 202 is used to perform message passing analysis and identify attack response patterns based on the induced topology graph, perform graph attention calculation on the attack response patterns to generate attention vectors, perform abnormal resonance amplification on the attention vectors to generate node embedding representations, and perform graph convolution propagation on the node embedding representations to generate resonance enhancement domains. Attack learning module 203 is used to perform deep graph learning on the features of the inducing node to extract the attack behavior graph, perform graph pooling to obtain the attack intent encoding from the attack behavior graph, perform graph inversion mapping on the attack intent encoding to generate a protection strategy representation, and construct a dynamic topology transformation based on the protection strategy representation to generate an adaptive protection table. The topology reshaping module 204 is used to perform multi-layer graph propagation to identify covert attack subgraphs in the resonance enhancement domain, perform graph fusion to generate camouflage graph embeddings in the covert attack subgraphs, perform topology reshaping on the camouflage graph embeddings to generate a confusing network structure, and generate an adversarial detection strategy based on the association between the confusing network structure and the adaptive protection table. The detection optimization module 205 is used to decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence. The response output module 206 is used to generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete the intrusion detection.
[0075] The aforementioned network security intrusion detection system 200 based on fused graph neural networks can implement the network security intrusion detection method based on fused graph neural networks described in the above method embodiments. The options in the above method embodiments are also applicable to this embodiment and will not be detailed here. The remaining content of this application's embodiments can be referred to the content of the above method embodiments, and will not be repeated in this embodiment.
[0076] The purpose of the above embodiments is to reproduce and derive the technical solution of the present invention by way of example, and to fully describe the technical solution, purpose and effect of the present invention. The purpose is to enable the public to have a more thorough and comprehensive understanding of the disclosure of the present invention, and not to limit the scope of protection of the present invention.
[0077] The above embodiments are not an exhaustive list based on the present invention, and there may be many other embodiments not listed. Any substitutions and improvements made without departing from the concept of the present invention are within the protection scope of the present invention.
Claims
1. A network security intrusion detection method incorporating graph neural networks, characterized in that, include: Collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. Perform graph convolution modeling on the multi-source traffic data to construct an induced topology graph. Based on the induced topology graph, message passing analysis is performed to identify attack response patterns. Graph attention is then performed on the attack response patterns to generate attention vectors. Anomaly resonance amplification is performed on the attention vectors to generate node embedding representations. Graph convolution propagation is then performed on the node embedding representations to generate resonance enhancement domains. Deep graph learning is performed on the features of the inducing nodes to extract an attack behavior graph. Graph pooling is performed on the attack behavior graph to obtain the attack intent encoding. Graph inversion mapping is performed on the attack intent encoding to generate a protection strategy representation. Based on the protection strategy representation, dynamic topology transformation is constructed to generate an adaptive protection table. Multi-layer graph propagation is performed on the resonant enhancement domain to identify covert attack subgraphs. Graph fusion is performed on the covert attack subgraphs to generate camouflage graph embeddings. Topology reshaping is performed on the camouflage graph embeddings to generate a confusing network structure. Based on the confusing network structure and the adaptive protection table, an adversarial detection strategy is generated. The adversarial detection strategy is decomposed into multi-layer detection rules, and the multi-layer detection rules are graph-optimized and sorted to generate an interleaved detection sequence. A graph countermeasure matrix is generated based on the interleaved detection sequence. Based on the graph countermeasure matrix, an active defense prediction is generated. The active defense prediction is then evaluated using graph classification to generate an adaptive response signal, thus completing the intrusion detection.
2. The method according to claim 1, characterized in that, The step of constructing an induced topology graph by performing graph convolution modeling on the multi-source traffic data includes: Generate a node baseline template based on the normal node characteristics; The induced node features and the node baseline template are combined to form a feature-template coupling relationship; Extract the stable graph connection region within the feature-template coupling relationship; An induced topology graph is formed based on the topology weights of the connection regions of the stable graph.
3. The method according to claim 1, characterized in that, The step of generating node embedding representations by performing anomalous resonance amplification on the attention vector includes: The attention vector is segmented into a dominant frequency band and an auxiliary frequency band; The signal scanning path is transmitted from the dominant frequency band to the auxiliary frequency band; Record the positions of intensity spikes along the signal scanning path to form a set of spike points; The point with the highest intensity in the set of sudden increase points is marked to generate a node embedding representation.
4. The method according to claim 1, characterized in that, The step of encoding the attack intent and performing graph inversion mapping to generate a protection strategy representation includes: Malicious information interception and identification are performed on the encoded attack intent to generate an interception blank area; A gain coefficient is generated based on the intercepted blank area; Continuous security coverage is generated by mapping interpolation using the gain coefficients; Based on the continuous security coverage, feature extraction is performed to generate a protection strategy representation.
5. The method according to claim 1, characterized in that, The step of topologically reshaping the camouflaged graph embedding to generate a deceptive network structure includes: Construct a connection time series based on the camouflage graph embedding; Perform topological change analysis on the connection time series to generate change time markers; The connected time series is divided into a stable period and a perturbation period, with the change time markers as the boundary; A confusing network structure is generated by comparing the structural distribution characteristics of the stable period and the perturbation period.
6. The method according to claim 1, characterized in that, The step of performing graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence includes: Convert the multi-layer detection rules into a priority vector field; Find the resource balancing core in the priority vector field; Starting from the resource balancing core, rules are propagated to form an initial permutation domain; The initial permutation domain is subjected to boundary convergence to form an interleaving detection sequence.
7. The method according to claim 1, characterized in that, The step of performing graph classification evaluation on the active defense prediction to generate an adaptive response signal includes: The active defense prediction is used to identify time difference bottlenecks and generate transmission time difference and computation time difference. The correlation between the transmission time difference and the calculated time difference is evaluated to form a time difference correlation graph. Key time difference factors are generated through principal component decomposition using the aforementioned time difference correlation diagram; An adaptive response signal is generated by implementing response calibration based on the key time difference factors.
8. The method according to claim 4, characterized in that, The process of generating continuous security coverage through mapping interpolation of the gain coefficients includes: The observation window is determined by identifying coverage abruptness features based on the gain coefficient. These coverage abruptness features include the rate of change of security strength, coverage duration interval, and decay gradient. A security situation map is generated by tracing the security evolution process along the observation window; Extract the coverage coordinates of each critical point within the security situation map; Continuous secure coverage is generated by arranging the coverage coordinates according to their security levels.
9. The method according to claim 5, characterized in that, The step of generating a confusing network structure by comparing the structural distribution characteristics of the stable period and the perturbation period includes: This converts the topological sequence of the stable period into a structurally accumulated sequence. The topological sequence of the perturbation period is misaligned and superimposed onto the structural accumulation sequence to form a structural difference map; Extract the topological jump accumulation within the structural difference map; A confusing network structure is generated based on the distribution density of the cumulative amount of the topological jump.
10. A network security intrusion detection system integrating graph neural networks, characterized in that, include: The data acquisition module is used to collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. The multi-source traffic data is used to perform graph convolution modeling to construct an induced topology graph. The message passing module is used to perform message passing analysis and identify attack response patterns based on the induced topology graph, perform graph attention calculation on the attack response patterns to generate attention vectors, perform abnormal resonance amplification on the attention vectors to generate node embedding representations, and perform graph convolution propagation on the node embedding representations to generate resonance enhancement domains. The attack learning module is used to extract an attack behavior map by deep graph learning on the features of the inducing node, obtain the attack intent encoding by graph pooling from the attack behavior map, generate a protection strategy representation by graph inversion mapping of the attack intent encoding, and construct an adaptive protection table based on the protection strategy representation by dynamic topology transformation. The topology reshaping module is used to perform multi-layer graph propagation to identify covert attack subgraphs in the resonant enhancement domain, perform graph fusion to generate camouflage graph embeddings in the covert attack subgraphs, perform topology reshaping on the camouflage graph embeddings to generate a confusing network structure, and generate an adversarial detection strategy based on the association between the confusing network structure and the adaptive protection table. The detection optimization module is used to decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence. The response output module is used to generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete the intrusion detection.
Citation Information
Patent Citations
Mobile behavior map construction method for spatio-temporal data
CN112749209A
Large language model-based antagonism prompt detection method and device, and medium
CN120297419A
Network attack dynamic detection and security protection method and system based on artificial intelligence
CN120342748A
Network attack path prediction method and system based on knowledge graph
CN120434050A
System for detecting malicious nodes in a wireless sensor network and a method thereof
US20250234201A1
Cited By
Network encryption attack detection method based on deep learning
CN121309209A
Dynamic store resource allocation method based on service reservation data
CN121684108A
A store resource dynamic allocation method based on service reservation data
CN121684108B
Microgrid endogenous toughness control method and device, electronic equipment and medium
CN121923936A
Microgrid Intrinsic Resilience Control Methods, Devices, Electronic Equipment and Medium
CN121923936B