A network attack detection method and device based on deep k-nearest neighbors

A deep network and network attack technology, applied in secure communication devices, neural learning methods, biological neural network models, etc., can solve the problems of low model robustness and poor performance, and achieve good robustness, accuracy and credibility. Effect

CN113438239BActive Publication Date: 2022-04-19HANGZHOU DIANZI UNIV
4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2022-04-19

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a network attack detection method and device based on depth k nearest neighbors, constructs a deep network model for network attack detection, uses training sample data to train the deep network model, obtains the trained deep network model, and uses the training sample data Input it into the trained deep network model, obtain the output of the training sample data in each layer of the deep network model, and input the corrected sample data into the trained deep network model, and calculate the sum of the distance features corresponding to the corrected sample data. Data set, and then input the data to be detected into the trained deep network model, combined with DkNN analysis, to obtain the prediction result. The technical scheme of the invention has good robustness, and obtains more accurate credibility of the predicted classification results.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the field of network attack defense and deep learning, and specifically relates to a network attack detection method and device based on deep k-nearest neighbors, which are used for intrusion detection in vulnerable network environments. Background technique

[0002] With the development and maturity of the Internet, the Internet has gradually become a highly shared and free environment. The networking and intelligence of all walks of life have begun to flourish. But at the same time, various malicious network activities and cyber crimes occur frequently, and the information security of network users is seriously threatened.

[0003] In order to solve the above problems, the intrusion detection system, as a representative network defense technology, has become popular again in recent years. The intrusion detection system obtains the characteristics of the attack activity by analyzing the attack activity after the event, and w...

Examples

Embodiment Construction

[0054] In order to make the purpose, technical solution and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain the present application, not to limit the present application.

[0055] The overall intrusion detection process of this application includes data preprocessing, model building and compilation, model training, and DkNN analysis, such as figure 1 As shown, a network attack detection method based on deep k-nearest neighbors, including:

[0056] Step S1 , preprocessing the sample data, and dividing the preprocessed sample data into training sample data and calibration sample data.

[0057] In an example, the preprocessing of the sample data includes:

[0058] Delete meaningless fields in the sample data, and map the IP addresses in the source IP address a...