Malicious network traffic detection and analysis method based on artificial intelligence

By constructing an AI-based method for detecting malicious network traffic, combining time series and protocol attribute features, and utilizing network security knowledge graphs and dynamically adjusting noise covariance matrix parameters, the method solves the problems of low accuracy and high latency in traditional detection methods for novel malicious code and encrypted traffic, achieving efficient and real-time malicious traffic identification.

CN120934857APending Publication Date: 2025-11-11HENAN POLYTECHNIC
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202511171730.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-21
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Traditional methods for detecting malicious network traffic have low accuracy when facing new types of malicious code, variant attacks, and encrypted traffic. They are difficult to identify covert malicious traffic patterns, consume a lot of computing resources, and have high detection latency, which cannot meet the needs of real-time network security protection.

Method used

An AI-based method for detecting malicious network traffic is adopted. This method constructs a network traffic feature representation that includes time-series statistical features and protocol attribute features. It then combines a network security knowledge graph to identify associated entities, generates aggregated network traffic features, performs a probability assessment of malicious traffic, identifies similar malicious traffic patterns, generates detection prompt text, inputs it into the malicious traffic detection model, and dynamically adjusts the noise covariance matrix parameters to optimize the detection process.

Benefits of technology

It improves the accuracy and efficiency of malicious traffic detection, can identify complex malicious traffic patterns, reduces errors, enhances the robustness and adaptability of the model, and supports real-time network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934857A_ABST
    Figure CN120934857A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security detection, and discloses a malicious network traffic detection and analysis method based on artificial intelligence. The method comprises the following steps: acquiring network flow data through preset equipment, and constructing a network flow characteristic representation containing a time sequence statistical characteristic and a protocol attribute characteristic; determining a multi-level associated entity of each traffic fragment in combination with the network security knowledge graph, and aggregating the features to generate aggregated network traffic features; performing malicious probability evaluation on the aggregation features, and determining target malicious traffic by means of the maximum response value of the thermodynamic map; determining a similar malicious traffic mode based on the aggregation feature similarity; generating a detection prompt text in combination with the target malicious traffic and the similar mode, and inputting a preset model to output a detection result; and adjusting model noise covariance matrix parameter optimization detection according to the flow dynamic index. The method can comprehensively capture traffic characteristics, mine associated information, improve the accuracy and adaptability of malicious traffic detection, and effectively cope with malicious attacks in a complex network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security detection technology, specifically to a method for detecting and analyzing malicious network traffic based on artificial intelligence. Background Technology

[0002] With the rapid development of internet technology, network traffic has experienced explosive growth, and the concealment and diversity of malicious traffic are constantly evolving, posing a severe challenge to network security protection. Traditional methods for detecting malicious network traffic largely rely on signature matching and rule-based judgment. However, these methods often prove inadequate when facing new types of malicious code, variant attacks, and encrypted traffic.

[0003] Signature-based matching requires prior acquisition of malicious traffic characteristics and the establishment of a signature database. However, new types of malicious traffic lack known characteristics, making them difficult to identify effectively. Furthermore, attackers can easily bypass signature-based detection mechanisms by transforming or encrypting malicious traffic, leading to a significant drop in detection accuracy.

[0004] Most existing detection methods focus on analyzing individual traffic segments, neglecting the relationships between different traffic segments, making it difficult to detect covert malicious traffic patterns. As network attack methods become increasingly complex, malicious traffic often exhibits distributed and multi-stage characteristics. Relying solely on the analysis of individual traffic segments is insufficient to fully grasp attack behavior, easily leading to missed detections.

[0005] In terms of real-time performance, traditional detection methods often face problems such as high computational resource consumption and high detection latency when handling massive amounts of network traffic, making it difficult to meet the needs of real-time network security protection. How to improve detection speed while ensuring detection accuracy, and promptly detect and respond to malicious traffic attacks, has become an urgent problem to be solved in the current network security field. Summary of the Invention

[0006] The purpose of this invention is to provide a method for detecting and analyzing malicious network traffic based on artificial intelligence, so as to solve the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides a method for detecting and analyzing malicious network traffic based on artificial intelligence, the method comprising:

[0008] Network traffic data is acquired using a pre-set network traffic acquisition device to construct a network traffic feature representation that includes time-series statistical features and protocol attribute features.

[0009] Based on the network security knowledge graph, multiple related entities at different levels corresponding to each network traffic segment are identified, and the network traffic feature representation and related entity features are aggregated to generate aggregated network traffic features.

[0010] The aggregated network traffic characteristics are used to perform a malicious traffic probability assessment to obtain a heat map including the malicious probability distribution, so as to determine the target malicious traffic based on the maximum response value corresponding to the heat map.

[0011] Similar malicious traffic patterns are determined based on the similarity between different aggregated network traffic characteristics;

[0012] Generate detection prompt text based on the target malicious traffic and similar malicious traffic patterns;

[0013] The detection prompt text is input into a preset malicious traffic detection model, and the malicious traffic detection result is output.

[0014] Based on the calculation of the traffic dynamic index, the noise covariance matrix parameters of the malicious traffic detection model are adjusted according to the behavioral characteristics of network traffic data to optimize the detection process.

[0015] Preferably, the method for constructing a network traffic feature representation that includes time-series statistical features and protocol attribute features includes:

[0016] The network traffic data is input into a preset recurrent neural network to extract time series statistical features;

[0017] The network traffic data is input into a preset protocol parsing engine to extract protocol attribute features;

[0018] The time-series statistical features and the protocol attribute features are fused into a feature tensor. The dimensionality of the fused feature tensor is reduced by a dimensionality reduction layer to generate a network traffic feature representation with time-series dependence.

[0019] Preferably, the aggregation of the network traffic feature representation and associated entity features includes:

[0020] The current-level associated entities and their corresponding features are identified from the associated entities.

[0021] The feature attention weighting processing is applied to the features of the related entities to be processed and the network traffic features to generate updated network traffic features;

[0022] In the associated entities, determine the next level of the current level of the associated entities to be processed and the associated entity features corresponding to the associated entities to be processed;

[0023] Based on the features of the related entities to be processed and the updated network traffic features corresponding to the next level, feature attention weighting is performed to generate target updated network traffic features;

[0024] The target updated network traffic feature is determined as the updated network traffic feature, the next level is determined as the current level, and the process returns to determine the next level of the current level and the associated entity to be processed and the associated entity feature to be processed corresponding to the associated entity in the associated entity, until the current level is the highest level, and the updated network traffic feature corresponding to the highest level is determined as the aggregated network traffic feature.

[0025] Preferably, the malicious traffic probability assessment of the aggregated network traffic characteristics includes:

[0026] A malicious traffic segmentation architecture based on graph neural networks is constructed. The graph neural network segmentation architecture adopts an encoder-decoder structure. In the encoding stage, a feature importance screening mechanism is introduced to weight the aggregated network traffic features. In the decoding stage, an adaptive convolution module is embedded to dynamically adjust the receptive field to adapt to the feature changes of different traffic patterns.

[0027] The aggregated network traffic features are input into a graph neural network segmentation architecture, and a probability distribution map containing the malicious probability of each data point is output.

[0028] Based on the noise filtering process, discrete outliers in the probability distribution map are eliminated, and a heat map with regional connectivity is generated.

[0029] Preferably, determining the target malicious traffic based on the maximum response value corresponding to the heatmap includes:

[0030] Construct an objective function based on the maximum traffic density, minimum time variance, and maximum anomaly intensity index corresponding to the target malicious traffic;

[0031] The heatmap is optimized based on a preset objective function and a multi-objective genetic algorithm to obtain multiple candidate malicious traffic regions;

[0032] Multiple candidate malicious traffic regions are sorted using a non-dominated sorting algorithm, and the weight coefficient corresponding to each candidate malicious traffic region after sorting is calculated using the information entropy method.

[0033] Among multiple candidate malicious traffic regions, continuous regions with weight coefficients greater than a preset threshold are selected as target malicious traffic.

[0034] Preferably, determining similar malicious traffic patterns based on the similarity between different aggregated network traffic features includes:

[0035] Determine the similarity index between the aggregated network traffic characteristics corresponding to each network traffic segment and other aggregated network traffic characteristics;

[0036] The aggregated network traffic features corresponding to other network traffic segments with similarity indices greater than a preset similarity threshold are determined as similar malicious traffic patterns for each network traffic segment.

[0037] Preferably, generating detection prompt text based on the target malicious traffic and similar malicious traffic patterns includes:

[0038] Based on the aggregated network traffic characteristics, the vulnerability instance, attack mode, technical characteristics, and tactical characteristics corresponding to each network traffic segment are determined;

[0039] Generate a first associated path description text and a first traffic description text based on the vulnerability instance, attack mode, technical characteristics, and tactical characteristics corresponding to each network traffic segment;

[0040] Based on similar malicious traffic patterns, identify the vulnerability instances, attack patterns, technical characteristics, and tactical characteristics corresponding to similar network traffic segments for each network traffic segment;

[0041] Generate a second associated path description text and a second traffic description text based on the vulnerability instances, attack patterns, technical characteristics, and tactical characteristics corresponding to similar network traffic segments;

[0042] A detection prompt text is generated based on the first associated path description text, the first traffic description text, the second associated path description text, and the second traffic description text.

[0043] Preferably, the output malicious traffic detection results include:

[0044] Based on the detection prompt text and malicious traffic detection model, a detection result representation including malicious technology type and malicious tactic type is generated;

[0045] The detection results are then converted into executable response instructions.

[0046] Preferably, the step of adjusting the noise covariance matrix parameters of the malicious traffic detection model based on the traffic dynamic index calculation and the behavioral characteristics of network traffic data includes:

[0047] Obtain the behavioral feature sequence corresponding to the network traffic data, and calculate the dynamic change index of each fluctuation point based on the differences in fluctuation points, sequence differences, and differences in local sequence mean in the behavioral feature sequence.

[0048] The average dynamic change index for each time window is obtained based on the average dynamic change index.

[0049] Based on the distance between local behavioral feature sequences and the average dynamic change index, the behavioral anomaly index for each time window is calculated.

[0050] Obtain the dynamic traffic index corresponding to the network traffic data based on the abnormal behavior index.

[0051] Based on the flow dynamic index and the preset initial noise covariance matrix parameters, calculate the adjustment value of the noise covariance matrix parameters;

[0052] The adjustment value is applied to the noise covariance matrix parameters of the malicious traffic detection model.

[0053] Preferably, the adjustment values ​​for the parameters of the noise covariance matrix include:

[0054] The traffic dynamic index is normalized to obtain the normalized traffic dynamic index.

[0055] The normalized flow dynamic index is multiplied by the preset initial noise covariance matrix parameter to generate the adjustment value of the noise covariance matrix parameter.

[0056] Compared with the prior art, the beneficial effects of the present invention are:

[0057] By constructing a network traffic feature representation that incorporates both time-series statistical features and protocol attribute features, we can more comprehensively capture the essential attributes of network traffic. Time-series statistical features reflect the changing patterns of traffic over time, while protocol attribute features demonstrate the network protocol specifications followed by the traffic. The combination of the two enriches the feature representation and provides a more reliable foundation for subsequent malicious traffic detection.

[0058] By leveraging cybersecurity knowledge graphs to identify multiple related entities at different levels corresponding to each network traffic segment, and aggregating network traffic feature representations and related entity features to generate aggregated network traffic features, it is helpful to uncover hidden correlations behind network traffic. The related entities at different levels encompass various elements related to traffic; through aggregation, scattered feature information can be integrated, enhancing the ability to identify complex malicious traffic and avoiding the one-sidedness caused by analyzing individual features in isolation.

[0059] By assessing the probability of malicious traffic based on aggregated network traffic characteristics, a heatmap containing the probability distribution of malicious activity is obtained. The target malicious traffic is then identified based on the maximum response value corresponding to the heatmap, making the identification process more intuitive and accurate. The heatmap clearly displays the probability distribution of malicious activity corresponding to different traffic characteristics, while the maximum response value accurately pinpoints the most likely target as malicious traffic, reducing the subjectivity and error of human judgment.

[0060] Identifying similar malicious traffic patterns based on the similarity between the characteristics of different aggregated network traffic helps in discovering common malicious attack behaviors. The identification of similar malicious traffic patterns helps analysts grasp the evolutionary patterns and attack trends of malicious traffic, providing a reference for the formulation of network security protection strategies and improving the early warning capability against new types of malicious attacks.

[0061] The system generates detection alert text based on the target malicious traffic and similar malicious traffic patterns, and inputs this text into a pre-defined malicious traffic detection model to output detection results, thus automating and intelligently managing the detection process. The detection alert text centralizes key malicious traffic information, guiding the detection model to perform analysis and judgment more efficiently, reducing manual intervention and improving detection efficiency.

[0062] Based on the calculation of the traffic dynamic index, the noise covariance matrix parameters of the malicious traffic detection model are adjusted according to the behavioral characteristics of network traffic data, enabling the model to adapt to dynamic changes in network traffic. Network traffic is real-time and dynamic; dynamic adjustment of model parameters ensures detection performance under different traffic scenarios, enhancing the model's robustness and adaptability, and better enabling it to cope with complex and ever-changing network environments. Attached Figure Description

[0063] Figure 1 This is a schematic diagram illustrating the working principle of the AI-based network malicious traffic detection and analysis method described in this invention.

[0064] Figure 2 A flowchart for constructing a representation of network traffic characteristics;

[0065] Figure 3 A flowchart for assessing the probability of malicious traffic;

[0066] Figure 4 A flowchart for identifying target malicious traffic;

[0067] Figure 5 A flowchart for generating detection prompt text. Detailed Implementation

[0068] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0069] Please see Figure 1 This invention provides a method for detecting and analyzing malicious network traffic based on artificial intelligence, the method comprising:

[0070] Raw network traffic data is acquired using pre-set network traffic acquisition devices. A multi-dimensional network traffic feature representation, including time-series statistical features and protocol attribute features, is constructed. Based on a network security knowledge graph, multi-level associated entities corresponding to each network traffic segment are identified. A feature aggregation mechanism is used to fuse the network traffic feature representation and associated entity features to generate aggregated network traffic features. A malicious traffic probability assessment module processes the aggregated network traffic features, outputting a heatmap of the malicious probability distribution. The target malicious traffic is located based on the maximum response value of the heatmap. A similarity calculation module identifies similar malicious traffic patterns among different aggregated network traffic features. The target malicious traffic and similar malicious traffic patterns are converted into detection prompt text, which is then input into a pre-set malicious traffic detection model to generate detection results. The noise covariance matrix parameters of this model are dynamically adjusted based on a traffic dynamic index to optimize the detection process.

[0071] Example 1: See Figure 2 Network traffic data is captured in real time by a pre-set network traffic acquisition device, forming a raw data stream. This data stream is segmented into fixed-duration network traffic segments, each containing a set of data packets from a continuous time series. The pre-set recurrent neural network employs a long short-term memory structure, with its input layer receiving standardized time-series data. The extraction process of time-series statistical features involves multiple computational dimensions: for the data packet arrival time interval sequence, the mean, variance, and autocorrelation coefficient within the sliding window are calculated; for the byte traffic sequence, the kurtosis, skewness, and slope of the uplink / downlink traffic within the statistical window are calculated; for the data packet size distribution, the proportion of data packets in different size intervals and the distribution entropy value are recorded. The hidden state vector of the recurrent neural network is iteratively updated at each time step, and the output vector at the final time step serves as the representation of the time-series statistical features, which has the ability to capture the traffic dynamics of the preceding 120 time steps.

[0072] The protocol parsing engine consists of multiple processing modules. First, it performs protocol identification: based on port number and payload feature matching, it determines transport layer protocols such as TCP, UDP, and ICMP, and application layer protocols such as HTTP, DNS, and FTP. For HTTP, it extracts the request method type, response status code, number of header field key-value pairs, and length of key fields. For TCP, it parses the flag combination pattern and window scaling factor. For encrypted traffic, it records the handshake protocol version and certificate feature hash value. Protocol attribute features are converted into numerical vectors through feature engineering: discrete features undergo one-hot encoding, continuous features are normalized, and enumerated features are mapped to preset index values. Finally, a multi-dimensional attribute feature representation is formed, including a protocol type identifier, field feature vectors, and anomaly flags.

[0073] The feature tensor fusion operation spatially aligns the time-series statistical feature vectors with the protocol attribute feature vectors. The time-series feature vectors are reshaped into two-dimensional matrices, with rows corresponding to time steps and columns corresponding to feature channels. The protocol attribute features are extended to the same time-step dimension via a broadcast mechanism, forming feature cubes of equal dimensions. The two feature cubes are then concatenated along the channel dimensions to generate a fused three-dimensional feature tensor. The three dimensions of this tensor represent the time step size, feature type, and channel depth, respectively.

[0074] The dimensionality reduction layer employs feature transformation techniques to process the 3D feature tensor. First, principal component analysis is performed on the feature channels: the covariance matrix of each feature channel is calculated, and its eigenvalues ​​and eigenvectors are solved. Principal components with a cumulative contribution rate exceeding a set threshold are retained, forming a feature projection matrix. The original feature tensor is multiplied by this projection matrix in the channel dimension to compress the channel dimension. Subsequently, max pooling is performed in the time dimension: a sliding window with a step size of 5 is used to extract the maximum feature value in the local time domain, reducing the time dimension resolution. The final output network traffic feature representation has a reduced number of time steps and compressed feature channels, while retaining the key spatiotemporal correlation characteristics of the original tensor. This feature representation is scaled through a normalization layer before being output to subsequent processing modules.

[0075] The hidden layer structure of the recurrent neural network contains 128 memory units. Its forget gate uses a sigmoid activation function to control the decay rate of historical information, while the input gate adjusts the fusion weights of the current information. The network input is a standardized five-dimensional time series: timestamp interval sequence, source port sequence, destination port sequence, upstream byte sequence, and downstream byte sequence. The network output layer connects to a fully connected layer, mapping the hidden state of the final time step to a 128-dimensional time series statistical feature vector.

[0076] The protocol parsing engine includes a dedicated processing pipeline. The deep packet inspection module identifies payload characteristics: it performs regular expression matching on HTTP payloads to extract key fields and queries domain names and resource record types for DNS payload records. The traffic reassembly module handles IP fragmentation and TCP stream reassembly, ensuring the integrity of application-layer protocol parsing. The anomaly detection submodule flags unconventional protocol interactions: it detects communication via uncommon ports, malformed packet structures, and unusual flag combinations. The parsing results are structured and stored in JSON format, and the feature conversion layer serializes them into a 256-dimensional protocol attribute feature vector.

[0077] The 3D feature tensor construction process involves data validation: checking feature vector dimensionality consistency, handling missing values, and eliminating feature scale differences. The concatenated tensor has a dimension of [time step × original number of feature channels × 2], where the time step is fixed at 50 and the original number of feature channels is 128. Dimensionality reduction is performed in two stages: the first stage uses principal component analysis to compress the channel dimension from 256 to 64; the second stage uses a 5×1 pooling kernel to compress the time step dimension to 10. The final output network traffic feature representation has a dimension of [10×64], and the feature vector norm is controlled within a unit interval using an L2 regularization layer.

[0078] Example 2: See Figure 3 The cybersecurity knowledge graph stores entity relationship data, including entity types such as IP addresses, domain names, and certificate hashes, along with their hierarchical relationships. When determining the entities to be processed at the current level, the graph is traversed along a pre-defined path, starting from the source IP address node corresponding to the network traffic segment. First-level related entities include the target IP address and communication port number; second-level related entities extend to domain name registration information and SSL certificates; third-level related entities are associated with malicious file hashes from the threat intelligence database. The features of each level's entities to be processed are converted into 256-dimensional vectors through an entity embedding layer.

[0079] During the feature attention weighting process, the cosine similarity between the feature vector of the related entity to be processed and the network traffic feature representation vector is calculated. This similarity value is then normalized using Softmax to form the attention weight distribution. A weighted summation operation is performed on the network traffic feature representation: each row vector of the feature representation matrix is ​​multiplied by its corresponding weight coefficient and then linearly summed. This process generates an updated network traffic feature matrix, whose dimensions remain consistent with the original network traffic feature representation.

[0080] Upon moving to the next level of processing, the update result of the current level is used as the input for new network traffic features. The second level of related entities to be processed is identified: through the knowledge graph relationship chain, entities such as domain name registrar information, certificate authorities, and certificate validity periods are parsed. The feature vectors of these entities are then used to recalculate attention weights with the updated network traffic feature matrix. The calculation process employs the same mechanism: cosine similarity calculation, weight normalization, and weighted summation of the row vectors of the feature matrix. The target updated network traffic feature matrix is ​​then output.

[0081] The hierarchical iterative processing continues, with a maximum level threshold of 3. When the processing reaches the third level, it acquires related entities such as malicious file features and attacker infrastructure features from the threat intelligence. A final round of attention-weighted processing is performed, fusing the third-level related entity features with the currently updated network traffic features. The feature matrix output after the highest-level processing is the aggregated network traffic feature, which integrates the original traffic characteristics and the three-level related entity information.

[0082] The constructed graph neural network segmentation architecture comprises encoder and decoder components. The encoder employs a three-layer graph convolutional network structure, with each layer containing a feature importance filtering module. This module calculates the betweenness centrality of each node in the aggregated network traffic feature graph: it counts the frequency of each node's occurrence in all shortest paths. The centrality score is mapped to a value in the [0,1] interval using the Sigmoid function, serving as the feature recalibration coefficient. The original feature values ​​are then multiplied element-wise by their corresponding coefficients to complete the feature importance weighting.

[0083] The decoder comprises an upsampling layer and an adaptive convolution module. The upsampling layer doubles the resolution of the feature map through bilinear interpolation. The adaptive convolution module dynamically selects the kernel size: it calculates the average gradient magnitude of each 3×3 local region on the feature map. A 5×5 convolution kernel is used when the gradient magnitude exceeds a threshold of 0.15; otherwise, a 3×3 convolution kernel is used. This module outputs a feature map with the same spatial resolution as the original traffic data.

[0084] The process of generating the malicious probability distribution map is as follows: A 1×1 convolutional layer is connected at the end of the decoder to compress the number of channels to 2, corresponding to the benign probability and malicious probability channels respectively. The output values ​​are converted into a probability distribution using the Softmax activation function, forming the initial probability distribution map. Each pixel in this distribution map contains two probability values, representing the classification probability of the corresponding network data unit.

[0085] Noise filtering technology is employed during the heatmap generation stage. Median filtering is performed on the initial probability distribution map: a 5×5 sliding window is set, and 25 malicious probability values ​​are extracted within the window. After sorting by numerical value, the 13th value is taken as the new probability value for the window center point. This operation eliminates isolated outliers while maintaining the integrity of region boundaries. In the filtered probability distribution map, regions with a malicious probability exceeding 0.85 are marked in red, the 0.6-0.85 range in yellow, and below 0.6 in blue, forming a heatmap with continuous color blocks. In this heatmap, red areas represent high-confidence malicious traffic clusters.

[0086] The encoder's graph convolutional layers are configured with residual connection structures. Each layer's output features are element-wise added to the input features, preserving the original feature information. The adjacency matrix for graph convolution operations is constructed using node distances: the Euclidean distance between feature nodes in the feature space is calculated, and nodes with a distance less than 0.35 are connected. The weight matrix is ​​initialized based on node similarity and dynamically updated during training. Batch normalization layers are inserted between the decoder's upsampling layers and convolutional layers to accelerate model convergence. The final output heatmap is rendered in real-time by a graphics processing unit and can be visualized on a traffic monitoring interface.

[0087] Example 3: See Figure 4 The heatmap presents the probability distribution of malicious activity in the network traffic data space, with its horizontal and vertical axes corresponding to the time and address dimensions, respectively. Based on the traffic density, temporal distribution, and anomaly intensity characteristics that target malicious traffic should possess, a multi-objective optimization function is established. This function is defined as follows:

[0088]

[0089] Where: r represents the candidate malicious traffic region; D r The number of data packets per unit area (traffic density) within region r; Let I be the variance of timestamps within region r (time variance); r D is the weighted average of the probability values ​​of malice within region r (anomaly intensity index); max , I max These represent the global maximum flow density, maximum time variance, and maximum anomaly intensity, respectively; ω1, ω2, and ω3 are preset weighting coefficients that satisfy ω1+ω2+ω3=1;

[0090] A non-dominated sorting genetic algorithm with an elitist strategy is employed to solve this multi-objective problem. During initialization, 200 candidate region chromosomes are generated, each encoding four parameters: start time, duration, source address range, and destination address range. The evolutionary operation includes the following steps: a tournament selection mechanism selects the top 50% of individuals based on fitness; a two-point crossover operation is performed on the selected individuals, with a crossover probability of 0.85; a Gaussian mutation operator is used, with the mutation intensity decreasing linearly from 0.1 to 0.01 with each iteration. Each iteration retains the non-dominated solution set on the Pareto front, with a maximum iteration count limited to 50 rounds. Upon termination, the algorithm outputs the Pareto optimal solution set, which contains multiple non-dominated candidate malicious traffic regions.

[0091] A non-dominated sorting hierarchical process is performed on the Pareto solution set. The first level contains candidate regions not dominated by any other solution; the second level contains regions dominated only by solutions in the first level; and so on for subsequent levels. Each candidate region is assigned a corresponding level number, with smaller numbers indicating higher region quality. Region weight coefficients are calculated based on information entropy: the malicious probability distribution of each data point within the region is statistically analyzed, and the Shannon entropy value H of the probability distribution is calculated. r Combined with the area A r Calculate the weights:

[0092]

[0093] Among them: W r H represents the weight coefficient of candidate region r, k is the region index variable, n is the total number of candidate regions, and H is the weight coefficient of candidate region r. k The malicious probability distribution of region k is given by Shannon entropy, A. k The area of ​​the k-th region. The weighting coefficient reflects the combined importance of the region in terms of probability distribution dispersion and spatial scale.

[0094] Set a weight threshold of 0.7 for region filtering: when W r Candidate regions are retained when the ratio is ≥0.7. Spatial continuity checks are performed on the retained regions: in the time-address two-dimensional plane, the boundaries of the regions are checked for overlap or adjacency; regions with a spatial distance of less than 10 pixels are merged; fragmented regions with an isolated area ratio of less than 0.1% of the total plane area are removed. The resulting continuous spatial region is identified as the target malicious traffic region, and its spatial coordinates are mapped back to the original network traffic data time series.

[0095] The similar malicious traffic pattern recognition module processes aggregated network traffic features from all network traffic segments. Each segment corresponds to a 128-dimensional feature vector stored in the feature database. The similarity index between feature vectors is calculated using a standardized Euclidean distance metric.

[0096]

[0097] Where: d ij Let v represent the standardized Euclidean distance between the i-th network traffic segment and the j-th network traffic segment. ik v is the k-th dimension component of the i-th eigenvector. jk Let σ be the eigenvalue of the j-th network traffic segment in the k-th dimension. k Let be the standard deviation of all feature vectors in the k-th dimension. Set the similarity threshold θ = 0.85. When d ij When ≤θ, segment j is determined to be a similar malicious traffic pattern to segment i.

[0098] Establish a similar pattern relationship graph: using network traffic segments as nodes, and edge weights between nodes. A community detection algorithm is used to identify highly cohesive subgraphs, each representing a cluster of similar malicious traffic patterns. Pattern feature extraction: Principal component analysis is performed on all feature vectors within the cluster, retaining the principal component directions with a cumulative contribution rate of over 90%, forming a pattern feature template vector. This template vector is matched and verified against the feature vectors corresponding to the target malicious traffic region. When the cosine similarity exceeds 0.9, the target malicious traffic is confirmed to belong to that pattern cluster. The final output structure includes the spatial coordinates of the target malicious traffic region, the cluster number it belongs to, and a set of typical feature vectors within the cluster.

[0099] The similarity calculation process is accelerated using a distributed architecture. The feature library is divided into 32 shards and stored on different computing nodes, with each node maintaining normalization parameters for its local feature vectors. Distance calculation tasks are assigned using a MapReduce model: the Map phase computes partial distance components of local feature vectors in parallel on each node; the Reduce phase aggregates the global standard deviation parameters and completes the final distance synthesis. Threshold filtering is performed in a distributed key-value database, and a feature index is established to support real-time similar segment retrieval. Pattern cluster data is persistently stored in a graph database, supporting multi-dimensional queries based on attributes such as time range and source address range.

[0100] Example 4: See Figure 5 The system aggregates network traffic features to analyze attack elements. This engine includes a feature mapping layer and a knowledge base query interface. Taking the traffic segment within the time window 2023-05-12T14:30:00Z as an example, its aggregated feature vector triggers the following parsing rules: outliers in feature dimensions 37-42 match the CVE-2023-1234 vulnerability feature template; the pattern activation ATT&CK framework T1190 attack identifier in dimensions 89-95; the protocol offset in dimensions 128-135 corresponds to the credential theft technique T1212; and the time series fluctuation pattern is associated with the tactic TA0001 initial access.

[0101] Table 1: Structured storage table of parsing results.

[0102] Traffic timestamp Vulnerability Examples Attack Mode Technical features Tactical characteristics 2023-05-12T14:30:00Z CVE-2023-1234 T1190 T1212 TA0001 2023-05-12T14:31:20Z CVE-2023-5678 T1068 T1059 TA0002

[0103] When generating the first associated path description text, the knowledge graph query interface performs path traversal: starting from the vulnerability instance CVE-2023-1234 node, it is associated with the ATT&CK technology node T1212 in two steps. After the path description template is filled, the generated text is: "Detected CVE-2023-1234 vulnerability exploit chain, implemented T1212 credential theft technology through T1190 attack mode, belonging to TA0001 tactical phase". The first traffic description text extracts abnormal fields from the protocol attribute features: the HTTP request header contains an abnormal Content-Length value of 3582, the User-Agent field is missing, and a Base64 encoded string is detected in the cookie. The generated text is: "14:30:00 Source IP 192.168.1.15 Abnormal HTTP request: missing User-Agent, abnormal Content-Length, cookie contains encoded payload".

[0104] Network traffic segments corresponding to similar malicious traffic patterns are parsed synchronously. When the similarity module marks the time window 2023-05-12T14:31:20Z as a similar segment, its parsing result triggers the CVE-2023-5678 vulnerability instance. A second associated path description text is generated: "Associated with the similar event CVE-2023-5678 vulnerability exploitation, using the T1068 attack mode to execute the T1059 command script technique, belonging to the TA0002 tactic." The second traffic description text is generated based on protocol characteristics: "14:31:20 Source IP 192.168.1.20 Abnormal DNS query: txt record request for an unconventional domain name, response packet contains PowerShell command fragments."

[0105] The detection prompt text generation module adopts a four-segment template structure:

[0106] Description of the associated path of the target event;

[0107] Description of target event traffic characteristics;

[0108] Description of similar event association paths;

[0109] Description of similar event traffic characteristics;

[0110] The template engine injects the aforementioned parsing results into the corresponding fields to form a complete prompt text: "Alert Event 14:30:00: CVE-2023-1234 exploit chain detected, implementing T1212 credential theft technique (TA0001) through T1190 attack mode. Traffic characteristics: Source IP 192.168.1.15 abnormal HTTP request missing User-Agent, Content-Length abnormal value 3582, Cookie contains Base64 payload. Related similar event 14:31:20: CVE-2023-5678 exploit uses T1068 attack mode to execute T1059 command script technique (TA0002). Traffic characteristics: Source IP 192.168.1.20 abnormal DNS query txt record, response contains PowerShell commands."

[0111] The malicious traffic detection model employs a 12-layer Transformer architecture. The input layer receives the segmented prompt text sequence. The positional encoding layer injects temporal information, and a self-attention mechanism calculates the association weights of key elements in the text. The model's output layer connects to a classification head: the technology type classifier outputs a 128-dimensional vector corresponding to the probability distribution of ATT&CK technology IDs, and the tactical type classifier outputs a 14-dimensional vector corresponding to the probability distribution of tactical stages. Using the example prompt text input, the probability value of the technology type output vector at index T1212 is 0.92, and the probability value of the tactical type output vector at index TA0001 is 0.87.

[0112] The detection results indicate that the conversion module maintains a response rule base. When the technology type is T1212 and the probability is greater than 0.8, the response instruction type code "R03" is generated; when the tactical type is TA0001 and the probability is greater than 0.7, the instruction code "T01" is appended. The rule engine maps the code combination to specific operations: R03 triggers the instruction "block all outbound connections from the source IP", and T01 triggers the instruction "report to the security operations center and create an event ticket". The final generated machine-executable instruction set is: {"action": "block_ip", "target": "192.168.1.15"}, {"action": "create_ticket", "severity": "high"}.

[0113] Traffic feature description text generation follows a feature priority rule: protocol anomaly fields take precedence over regular fields, and encrypted payload features take precedence over plaintext features. Time descriptions are accurate to the millisecond level, and IP addresses are labeled with geographic information tags. Conflict detection is implemented during response command generation: when multiple rules trigger contradictory operations, the rule with the highest threat level takes precedence. Command sets are distributed to execution terminals such as network firewalls, log analysis systems, and work order management systems via message queues for coordinated responses.

[0114] Example 5: The behavioral feature sequence of network traffic data is obtained through a sliding window mechanism with a window length of 5 seconds. Three core indicators are statistically analyzed for each time window: standard deviation of packet count, uplink / downlink traffic ratio, and protocol type distribution entropy. Fluctuation point difference calculation: Adjacent extreme points in the behavioral feature sequence are marked, and the arithmetic mean of the absolute differences of feature values ​​between consecutive fluctuation points is calculated. Sequence difference processing: First-order difference operation is performed on the feature sequence, and the root mean square value of the difference sequence is taken as the quantification indicator. Local sequence mean difference analysis: Using 10 consecutive time windows as local units, the mean of the feature sequence within each unit is calculated; the difference between the means of adjacent units is compared, and the absolute value of the maximum difference is recorded.

[0115] The dynamic change index is synthesized using a weighted calculation model. The difference value of fluctuation points is assigned a weight of 0.4, the sequence difference value is assigned a weight of 0.3, and the difference value of local means is assigned a weight of 0.3. After logarithmic transformation, the three parameters are weighted and a geometric mean is calculated to output the dynamic change index for each fluctuation point. This index ranges from 0 to 1; a higher value indicates a more drastic change in flow behavior.

[0116] The average dynamic change index is calculated using 20 time windows as the basic unit. The dynamic change index of all fluctuation points within a unit is taken as a moving average, and the window sliding step is set to 5 time windows. When the number of fluctuation points within a unit is less than 3, the unit range is automatically expanded to include at least 3 valid fluctuation points. The calculation results form a new time series reflecting the macroscopic trend of changes in flow behavior.

[0117] The behavioral anomaly index calculation relies on two inputs. First, the distance of local behavioral feature sequences is calculated: feature sequence segments of 15 windows before and after the current time point are extracted, and the dynamic time warping distance between these segments and the historical baseline sequence is calculated. The historical baseline sequence is taken from a typical pattern library of similar traffic within the last 24 hours. Second, combined with the average dynamic change index corresponding to the current time window, a dual judgment condition is set: when the dynamic time warping distance exceeds 2.3 times the historical average distance and the average dynamic change index is greater than 0.65, the behavioral anomaly index is assigned a value of 1; otherwise, it is assigned a value of 0. This binarized index directly marks the abnormal state of traffic.

[0118] The Traffic Dynamics Index is generated statistically over a time dimension. It uses a 1-minute time unit to count the percentage of windows with an anomaly index of 1 within that unit. This percentage is then smoothed using an exponential smoothing factor of 0.25 to output the final Traffic Dynamics Index. The index value ranges from [0,1], reflecting the real-time trend of anomalies in network traffic behavior.

[0119] The noise covariance matrix parameter adjustment process includes a numerical transformation step. The preset initial noise covariance matrix parameters are derived from the Kalman filter initialization configuration of the malicious traffic detection model. The traffic dynamic exponent undergoes linear normalization: a baseline of 0.15 is set, exponents below the baseline are mapped to 0, and those above the baseline are scaled proportionally to [0,1]. The normalized result is then multiplied by the initial parameters using a Hadamard product, i.e., element-wise multiplication of the matrix.

[0120] The adjustment values ​​are applied using an incremental update mechanism. The malicious traffic detection model maintains a real-time copy of the noise covariance matrix, reading the latest traffic dynamic index every 5 seconds. The calculated adjustment values ​​are updated to the current parameters using a weighted mixing method: new parameter = current parameter × 0.7 + adjustment value × 0.3. The updated noise covariance matrix takes effect immediately, changing the Kalman filter's estimation weights for observed noise. When the traffic dynamic index remains above 0.8 for 3 consecutive minutes, a parameter reset procedure is triggered, restoring the initial noise covariance matrix settings.

[0121] The implementation details of the Kalman filter involve the correction of the state transition matrix. The network traffic state vector includes three dimensions: packet rate, connection frequency, and proportion of abnormal requests. Adjusting the noise covariance matrix directly affects the confidence assignment of the observation equation. Under high-traffic dynamic exponential conditions, the system automatically reduces the observation noise covariance, enhancing the model's sensitivity to real-time traffic data; under low-exponential conditions, it increases the observation noise covariance, strengthening the model's historical state memory capability. This dynamic adjustment mechanism enables the detection model to adapt to the non-steady-state characteristics of network traffic.

[0122] The generation of behavioral feature sequences employs a distributed stream processing architecture. The standard deviation of packet counts is calculated using the sample standard deviation formula for packet counts within a window. The uplink-to-downlink traffic ratio is calculated as the logarithm of the ratio of total uplink bytes to total downlink bytes. The protocol type distribution entropy is calculated based on the information entropy formula for the frequency of different protocols within a window. These three feature values ​​are standardized using Z-scores and then concatenated into a behavioral feature vector. The maintenance of historical baseline sequences uses an incremental update algorithm, refreshing the reference sequence library every 24 hours based on typical daily traffic patterns. Dynamic time-warped distance calculation uses an accelerated approximation algorithm, keeping computation time to the millisecond level while maintaining accuracy.

[0123] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0124] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for detecting and analyzing malicious network traffic based on artificial intelligence, comprising: Network traffic data is acquired using pre-set network traffic acquisition devices to construct a network traffic feature representation that includes time-series statistical features and protocol attribute features. Based on the network security knowledge graph, multiple related entities at different levels corresponding to each network traffic segment are identified, and the network traffic feature representation and related entity features are aggregated to generate aggregated network traffic features. The aggregated network traffic characteristics are used to perform a malicious traffic probability assessment to obtain a heat map including the malicious probability distribution, so as to determine the target malicious traffic based on the maximum response value corresponding to the heat map. Similar malicious traffic patterns are determined based on the similarity between different aggregated network traffic characteristics; Generate detection prompt text based on the target malicious traffic and similar malicious traffic patterns; The detection prompt text is input into a preset malicious traffic detection model, and the malicious traffic detection result is output. Based on the calculation of the traffic dynamic index, the noise covariance matrix parameters of the malicious traffic detection model are adjusted according to the behavioral characteristics of network traffic data to optimize the detection process.

2. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein the step of constructing a network traffic feature representation including time-series statistical features and protocol attribute features includes: The network traffic data is input into a preset recurrent neural network to extract time series statistical features; The network traffic data is input into a preset protocol parsing engine to extract protocol attribute features; The time-series statistical features and the protocol attribute features are fused into a feature tensor. The dimensionality of the fused feature tensor is reduced by a dimensionality reduction layer to generate a network traffic feature representation with time-series dependence.

3. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein the aggregation of the network traffic feature representation and associated entity features includes: The current-level associated entities and their corresponding features are identified from the associated entities. The feature attention weighting processing is applied to the features of the related entities to be processed and the network traffic features to generate updated network traffic features; In the associated entities, determine the next level of the current level of the associated entities to be processed and the associated entity features corresponding to the associated entities to be processed; Based on the features of the related entities to be processed and the updated network traffic features corresponding to the next level, feature attention weighting is performed to generate target updated network traffic features; The target updated network traffic feature is determined as the updated network traffic feature, the next level is determined as the current level, and the process returns to determine the next level of the current level and the associated entity to be processed and the associated entity feature to be processed corresponding to the associated entity in the associated entity, until the current level is the highest level, and the updated network traffic feature corresponding to the highest level is determined as the aggregated network traffic feature.

4. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein the malicious traffic probability assessment of the aggregated network traffic features includes: Construct a malicious traffic segmentation architecture based on graph neural networks; The graph neural network segmentation architecture adopts an encoder-decoder structure, and introduces a feature importance screening mechanism in the encoding stage to weight the aggregated network traffic features; An adaptive convolutional module is embedded in the decoding stage to dynamically adjust the receptive field to adapt to the feature changes of different traffic patterns. The aggregated network traffic features are input into a graph neural network segmentation architecture, and a probability distribution map containing the malicious probability of each data point is output. Based on the noise filtering process, discrete outliers in the probability distribution map are eliminated, and a heat map with regional connectivity is generated.

5. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein determining the target malicious traffic based on the maximum response value corresponding to the heatmap includes: Construct an objective function based on the maximum traffic density, minimum time variance, and maximum anomaly intensity index corresponding to the target malicious traffic; The heatmap is optimized based on a preset objective function and a multi-objective genetic algorithm to obtain multiple candidate malicious traffic regions; Multiple candidate malicious traffic regions are sorted using a non-dominated sorting algorithm, and the weight coefficient corresponding to each candidate malicious traffic region after sorting is calculated using the information entropy method. Among multiple candidate malicious traffic regions, continuous regions with weight coefficients greater than a preset threshold are selected as target malicious traffic.

6. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein determining similar malicious traffic patterns based on the similarity between different aggregated network traffic features includes: Determine the similarity index between the aggregated network traffic characteristics corresponding to each network traffic segment and other aggregated network traffic characteristics; The aggregated network traffic features corresponding to other network traffic segments with similarity indices greater than a preset similarity threshold are determined as similar malicious traffic patterns for each network traffic segment.

7. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein generating detection prompt text based on the target malicious traffic and similar malicious traffic patterns includes: Based on the aggregated network traffic characteristics, the vulnerability instance, attack mode, technical characteristics, and tactical characteristics corresponding to each network traffic segment are determined; Generate a first associated path description text and a first traffic description text based on the vulnerability instance, attack mode, technical characteristics, and tactical characteristics corresponding to each network traffic segment; Based on similar malicious traffic patterns, identify the vulnerability instances, attack patterns, technical characteristics, and tactical characteristics corresponding to similar network traffic segments for each network traffic segment; Generate a second associated path description text and a second traffic description text based on the vulnerability instances, attack patterns, technical characteristics, and tactical characteristics corresponding to similar network traffic segments; A detection prompt text is generated based on the first associated path description text, the first traffic description text, the second associated path description text, and the second traffic description text.

8. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein the output of malicious traffic detection results includes: Based on the detection prompt text and malicious traffic detection model, a detection result representation including malicious technology type and malicious tactic type is generated; The detection results are then converted into executable response instructions.

9. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 1, wherein adjusting the noise covariance matrix parameters of the malicious traffic detection model based on the dynamic index calculation of traffic and the behavioral characteristics of network traffic data includes: Obtain the behavioral feature sequence corresponding to the network traffic data, and calculate the dynamic change index of each fluctuation point based on the differences in fluctuation points, sequence differences, and differences in local sequence mean in the behavioral feature sequence. The average dynamic change index for each time window is obtained based on the average dynamic change index. Based on the distance between local behavioral feature sequences and the average dynamic change index, the behavioral anomaly index for each time window is calculated. Obtain the dynamic traffic index corresponding to the network traffic data based on the abnormal behavior index. Based on the flow dynamic index and the preset initial noise covariance matrix parameters, calculate the adjustment value of the noise covariance matrix parameters; The adjustment value is applied to the noise covariance matrix parameters of the malicious traffic detection model.

10. The method for detecting and analyzing malicious network traffic based on artificial intelligence according to claim 9, wherein the adjustment values ​​for calculating the noise covariance matrix parameters include: The traffic dynamic index is normalized to obtain the normalized traffic dynamic index. The normalized flow dynamic index is multiplied by the preset initial noise covariance matrix parameter to generate the adjustment value of the noise covariance matrix parameter.

Citation Information

Cited By

  • Botnet traffic detection method and device and related equipment

    CN121356912A

  • Monitoring equipment communication anomaly detection method and system

    CN121509284A

  • A monitoring device communication anomaly detection method and system

    CN121509284B