Intrusion detection method, system, electronic device and storage medium

By crawling and analyzing data packets on the IDS node, processing features using GEP algorithm, and determining them in combination with intrusion feature samples, the problems of excessive computing resources and excessive analysis times in the existing intrusion detection system are solved, and efficient and reliable intrusion detection is achieved.

CN114091580BActive Publication Date: 2025-05-02GUANGXI ZHUANG AUTONOMOUS REGION COMM IND SERVICE CO LTD TECH SERVICE BRANCH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111293301.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-03
Publication Date
2025-05-02
Estimated Expiration
2041-11-03

AI Technical Summary

Technical Problem

The existing intrusion detection system is based on complicated calculations and processing, occupying a large amount of computing resources, affecting the normal use of the machine, and the traditional static intrusion analysis method analyzes too many times.

Method used

An intrusion detection method is proposed, by grabbing data packets flowing into the IDS node, analyzing data packets, extracting features to be intruded detection, using GEP algorithm to process features, and combining proven intrusion feature samples for intrusion determination.

Benefits of technology

It improves the efficiency and accuracy of intrusion feature detection, reduces the use of computing resources, and reduces the number of analysis, thereby achieving fast, reliable and stable intrusion detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114091580B_ABST
    Figure CN114091580B_ABST
Patent Text Reader

Abstract

The present invention discloses an intrusion detection method, system, electronic device and storage medium. The method first captures incoming data packets at an IDS node, then parses the incoming data packets to obtain data packet parsing results, and then quickly selects redundant and useless features based on a GEP algorithm, without involving too many linear transformation operations, and can improve the efficiency of intrusion feature detection. The processed feature set to be detected for intrusion is judged according to confirmed intrusion feature samples, thereby ensuring fast calculation and obtaining reliable and stable results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network intrusion detection, and in particular to an intrusion detection method, system, electronic equipment and storage medium. Background Art

[0002] In the early days of the Internet, people were more concerned about pure connectivity, with the ultimate goal of establishing the Internet without any restrictions. As everything has two sides, the convenience of the Internet has brought negative problems to people, and crimes using the Internet, such as computer virus attacks, information leaks, and online fraud, are increasing.

[0003] The complexity of network security itself makes passive defense methods inadequate and weak in protecting against certain attacks. Not all threats come from outside the firewall. In addition, with the booming development of the information age, intrusion tutorials are everywhere and various tools are readily available, making intrusion much easier. There are many intrusion detection systems on the market, but most of them are based on complex calculations and processing to get results, which takes up a lot of computing resources and even affects the normal use of the machine. For example, traditional static intrusion analysis methods (used by firewalls and antivirus software) usually have millions of analysis times, which takes up a lot of computing resources. Summary of the invention

[0004] The present invention aims to at least solve the technical problems existing in the prior art. To this end, the present invention provides an intrusion detection method, system, electronic device and storage medium.

[0005] A first aspect of the present invention provides an intrusion detection method, comprising the following steps:

[0006] Capture the data packets flowing into the IDS node;

[0007] Parsing the data packet to obtain a data packet parsing result;

[0008] Extracting a plurality of intrusion detection features from the data packet parsing result to form an intrusion detection feature set, performing feature processing on the intrusion detection feature set by using a GEP algorithm to obtain a processed intrusion detection feature set;

[0009] An intrusion determination is performed on the processed feature set to be intrusion detected according to the confirmed intrusion feature samples to obtain an intrusion determination result.

[0010] According to the embodiments of the present invention, there are at least the following technical effects:

[0011] This method first captures the incoming data packets at the IDS node, then parses the incoming data packets to obtain the data packet parsing results, and then quickly selects redundant and useless features based on the GEP algorithm. It does not involve too many linear transformation operations, and can improve the efficiency of intrusion feature detection. The processed intrusion detection feature set is judged based on the confirmed intrusion feature samples, ensuring fast calculation while obtaining reliable and stable results.

[0012] A second aspect of the present invention provides an intrusion detection system, comprising:

[0013] The data packet capture module is used to capture the data packets flowing into the IDS node;

[0014] A data packet parsing module, used to parse the data packet and obtain a data packet parsing result;

[0015] The data packet analysis module includes a classifier submodule and an evaluation submodule. The classifier submodule is used to extract multiple intrusion detection features from the data packet analysis results to form an intrusion detection feature set, and perform feature processing on the intrusion detection feature set through the GEP algorithm to obtain a processed intrusion detection feature set; the evaluation submodule is used to perform intrusion judgment on the processed intrusion detection feature set according to the confirmed intrusion feature samples to obtain an intrusion judgment result;

[0016] The data packet alarm module is used to send out an alarm signal when there is an intrusion feature in the processed intrusion detection feature set.

[0017] According to a third aspect of the present invention, an electronic device is provided, comprising at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions executable by the at least one control processor, and the instructions are executed by the at least one control processor so that the at least one control processor can perform the above-mentioned intrusion detection method.

[0018] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the above-mentioned intrusion detection method.

[0019] It can be understood that the beneficial effects of the second to fourth aspects compared with the related art are the same as the beneficial effects of the first aspect compared with the related art. Please refer to the relevant description in the first aspect, and no further details will be given here.

[0020] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:

[0022] Figure 1 A schematic diagram of an architecture for implementing an intrusion detection system provided by an embodiment of the present invention;

[0023] Figure 2 A schematic diagram of the architecture of a data packet analysis module provided by one embodiment of the present invention;

[0024] Figure 3 A schematic diagram of a flow chart of executing an intrusion detection method provided by an embodiment of the present invention;

[0025] Figure 4 A schematic diagram of a flow chart of executing an intrusion detection method provided in another embodiment of the present invention. DETAILED DESCRIPTION

[0026] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.

[0027] There are many intrusion detection systems on the market, but most of them are based on complex calculations and processing to get results, which takes up a lot of computing resources and even affects the normal use of the machine. For example, traditional static intrusion analysis methods (used by firewalls and antivirus software) usually have millions of analyses, which takes up a lot of computing resources.

[0028] In order to solve the above technical defects, refer to Figure 1 and Figure 2 According to an embodiment of the present invention, an intrusion detection system is provided, including: a data packet capture module 100, a data packet parsing module 200, a data packet analysis module 300 and a data packet alarm module 400, wherein:

[0029] The data packet capture module 100 is used to capture data packets flowing into the nodes of the IDS.

[0030] The data packet analysis module 200 is used to analyze the data packet and obtain the data packet analysis result.

[0031] A data packet is a unit of data in network communication transmission, including a header and a payload. The header contains a description of the data carried by the data packet, and the payload contains the data packet body or data, which is the actual data sent by the data packet. The data packet in the Transmission Control Protocol (TCP) / Internet Protocol (IP) protocol communication transmission is at the third network layer and the fourth transport layer of the Open Internet (OSI) model.

[0032] The data packet parsing module 200 parses the data packet according to the protocol decoding, wherein the third layer protocol identifier, the fourth layer protocol identifier, the port number and the uniform resource locator (URL) of the data packet can be parsed out, and part of the data packet content can also be decoded.

[0033] A set of specific examples of the data packet parsing module 200 are provided below, and the specific steps are as follows:

[0034] For example, the packet: BH6*He397d920800a7C6JK$0622PXLe76500801293ktzA2%11467e46

[0035] 984567312098456731209845673120984567312098456731209845673120,

[0036] Among them, BH6*He397d920800a7C6JK$0622PXLe76500801293ktzA2%11467e46 is the header part of the data packet, and 98456731209845673120984567312098456731209845673120 is the payload part of the data packet.

[0037] Step (1): The data packet parsing module 200 defines the third-layer protocol identifier in accordance with the protocol. The 4 bytes starting from the 13th byte of the data packet define the third-layer protocol identifier. Therefore, the IDS (intrusion detection system) node skips the first 12 bytes of the data packet and directly reads the third-layer protocol identifier "0800" to obtain the third-layer protocol identifier of the data packet.

[0038] Step (2): "0800" represents the IP protocol, and the fourth layer protocol identifier is defined starting from the 24th byte of the data packet. Therefore, the IDS node skips the middle bytes of the data packet, jumps to the 24th byte and directly reads the fourth layer protocol identifier "06", thereby obtaining the fourth layer protocol identifier of the data packet.

[0039] Step (3): “06” represents the TCP protocol, and the TCP port number is defined in the 35th byte of the data packet. Therefore, the IDS node skips the middle bytes of the data packet, jumps to the 35th byte and directly reads the port number “0080” to obtain the port packet of the data packet.

[0040] Step (4): "0080" represents the Hypertext transfer protocol (HTTP). In HTTP, the URL starts at the 55th byte, so the IDS node skips the middle bytes of the data packet and jumps to the 55th byte to read the URL, thereby obtaining the URL and part of the data packet content.

[0041] The data packet parsing module 200 of this system adopts the node analysis data packet technology of IDS and utilizes the high regularity of the network protocol to skip some bytes in the data packet and directly obtain the port number, URL and part of the data packet content, greatly improving the efficiency of data packet parsing.

[0042] The data packet analysis module 300 includes a classifier submodule 310 and an evaluation submodule 330. The classifier submodule 310 is used to extract multiple intrusion detection features from the data packet parsing results to form an intrusion detection feature set, and perform feature processing on the intrusion detection feature set through the GEP algorithm to obtain a processed intrusion detection feature set; the evaluation submodule 330 is used to perform intrusion judgment on the processed intrusion detection feature set based on the confirmed intrusion feature samples to obtain an intrusion judgment result.

[0043] In some embodiments, the confirmed intrusion feature samples are derived from an existing database. The database is mainly used to store the confirmed intrusion feature samples and transmit the confirmed intrusion feature samples to the inference engine submodule 320 and the evaluation submodule 330; it is also used to receive the intrusion features confirmed by experts.

[0044] In some embodiments, the classifier submodule 310 mainly performs the following working steps:

[0045] Step (1): Extract the features to be detected for intrusion from the data packet analysis results, and set the feature set to be detected for intrusion, wherein the feature set to be detected for intrusion includes port, URL, data packet content, angular second-order moment, correlation, entropy, contrast, inverse moment, average sum, sum entropy, variance sum, difference average, inertia and difference variance, etc., wherein port, URL, data packet content are derived from the data packet analysis results; angular second-order moment, correlation, entropy, contrast, inverse moment, average sum, sum entropy, variance sum, difference average, inertia and difference variance, etc. are derived from the statistical results between the existing ports, URL, data packet content in the database and the ports, URL, data packet content in the data packet analysis results. Set the population size n, subpopulation size m, maximum evaluation times (i.e., the number of cycles of the GEP algorithm) 500, gene length, number of genes, mutation probability, insertion probability, insertion length and recombination probability.

[0046] The feature set data to be detected is defined as population P t = {X1, X2, ..., X n}, where n is the number of dimensions of the intrusion detection feature set, calculate the population P t The fitness of each characteristic element in;

[0047] Step (2): For population P t The n characteristic elements in the gene expression programming are selected, mutated, inserted and recombined to generate m new characteristic elements, and the m new characteristic elements are combined into a subpopulation O t , calculate the subpopulation O t The fitness of each characteristic element in , wherein the characteristic element with the largest fitness is the optimal characteristic element. It is worth noting that the selection, mutation, insertion and recombination of gene expression programming are well known in the GEP algorithm, and its principle will not be introduced here.

[0048] Step (3): Set the population P t n characteristic elements and subpopulation O in t The m characteristic elements in form a temporary population P t ′, calculate the temporary population P t The fitness of each characteristic element in ′, and then delete the temporary population P t ′, and obtain the first m characteristic elements with the largest fitness, and obtain a new generation population P consisting of n characteristic elements t+1 ;

[0049] Step (4): If the current number of evaluations is less than or equal to 500, then the population P t+1 Let be the population P t , jump to step (2); if the current evaluation times are greater than 500, jump out of the loop and set the population P t+1 As the processed feature set for intrusion detection.

[0050] In some embodiments, the data packet analysis module 300 further includes an inference engine submodule 320, wherein the inference engine submodule 320 mainly performs the following working steps:

[0051] Step (1): receiving the processed feature set to be intrusion detected output by the classifier submodule 310 as the initial input condition of the inference engine.

[0052] Step (2): Obtain confirmed intrusion feature samples from the database, and obtain the URL address, port, and data packet content data in the data packet parsing results as prior information for the inference engine.

[0053] Step (3): Based on the initial input conditions and prior information of the inference engine, the Bayesian inference rule is used to infer whether there is intrusion behavior in the data packet.

[0054] Step (4): The new feature facts obtained after the reasoning calculation are used as new input conditions for reasoning analysis;

[0055] Step (5): Repeat steps (2) to (4) until no new feature facts are generated. The reasoning analysis of the inference engine reaches a stable state, the reasoning process ends, and the evaluation result is output.

[0056] The evaluation results obtained in step (5) will be fed back to the database, and after confirmation by experts, the intrusion features in the data packet will be stored in the database.

[0057] Based on the above embodiment with the inference engine submodule 320, the evaluation submodule 330 mainly performs the following working steps:

[0058] Step (1): Take the processed intrusion detection feature set as the premise set {P1, P2, ...P i , ...P j , ...P n}; n represents the number of dimensions.

[0059] Step (2): Calculate the intrusion coefficient a of each feature element in the premise set according to the preset operator set θ = {AND, OR}:

[0060] In some embodiments, the preset operator set includes at least one of operators OR2, AND2, GOE2B, and GOE2C, where OR2 means: if P i ≥0 or P j ≥0, then 1, else0; AND2 means: if P i ≥0 and P j ≥0, then1, else0; GOE2B means: if Pi ≥P j , then 1, else 0; GOE2C means: if P i ≥P j ,then(P i +P j ), else(P i =P j ).

[0061] Step (3): Calculate the intrusion credibility of each feature element in the premise set according to the following formula:

[0062]

[0063] Among them, b represents the intrusion credibility, a represents the intrusion coefficient, and U represents the variance of the confirmed intrusion feature samples;

[0064] Step (4): Calculate the product c = a*b between the intrusion coefficient and the intrusion credibility.

[0065] Step (5): If c is greater than the intrusion threshold, then there is an intrusion feature. The intrusion threshold is not limited here.

[0066] The data packet alarm module 400 is used to send out an alarm signal when there is an intrusion feature. For example, when c is greater than the intrusion threshold, an alarm signal is sent out. There is no restriction on the alarm signal, and the alarm signal can be a sound signal or a light signal.

[0067] The system includes a data packet capture module that captures incoming data packets at the node of the IDS; then the data packet parsing module is used to parse the incoming data packets, and the data packet parsing results are sent to the data packet analysis module. The data packet parsing module adopts the node analysis data packet technology of the IDS, and uses the high regularity of the network protocol to skip some bytes in the data packet and directly obtain the port number, URL and part of the data packet content, which greatly improves the efficiency of data packet parsing. The data packet analysis module intelligently analyzes the data packet content through the classifier submodule, the inference engine submodule and the evaluation submodule, makes judgments and gives warnings. The classifier submodule quickly selects redundant and useless features based on the GEP algorithm, does not involve too many linear transformation operations, and can improve the efficiency of intrusion feature detection; the inference engine submodule uses the URL address, port, and data packet content data in the confirmed intrusion feature samples and the data packet parsing results to use the Bayesian inference rule to reason and analyze the intrusion features, which can improve the effectiveness of intrusion feature detection; the evaluation submodule uses statistical methods to make judgments, and the results are more reliable and stable, and the calculation speed is faster, which ensures fast calculations while obtaining reliable and stable results. This system uses IDS node analysis package technology, takes advantage of the high regularity of network protocols, uses the GEP algorithm to quickly select redundant and useless features, and uses statistical methods to judge. The results are more reliable and stable, and the calculation speed is faster, ensuring fast calculation while obtaining reliable and stable results. Compared with traditional static intrusion analysis methods (used by firewalls and antivirus software), the number of analyses is reduced from millions to thousands, which is more effective and faster.

[0068] Reference Figure 3 and Figure 4 An embodiment of the present invention provides an intrusion detection method, comprising the following steps:

[0069] Step S100: Capture data packets flowing into the IDS node.

[0070] Step S300: parse the data packet to obtain the data packet parsing result.

[0071] In some embodiments, the data packet is BH6*He397d920800a7C6JK$0622PXLe76500801293ktzA2%11467e46

[0072] 9845673120984567312098456731209845673120984567312098456731209845673120, wherein BH6*He397d920800a7C6JK$0622PXLe76500801293ktzA2%11467e46 is the header part of the data packet, and 984567312098456731209845673120984567312098456731200 is the payload part of the data packet. Step S300 specifically includes the following steps:

[0073] Step S301, according to the protocol provisions for the data packet, the 4 bytes starting from the 13th byte of the data packet define the third-layer protocol identifier, so the IDS node skips the first 12 bytes of the data packet and directly reads the third-layer protocol identifier "0800" to obtain the third-layer protocol identifier of the data packet.

[0074] In step S302, "0800" represents the IP protocol, and the fourth layer protocol identifier is defined starting from the 24th byte of the data packet. Therefore, the IDS node skips the middle bytes of the data packet, jumps to the 24th byte and directly reads the fourth layer protocol identifier "06", thereby obtaining the fourth layer protocol identifier of the data packet.

[0075] Step S303, "06" represents the TCP protocol, and the TCP port number is defined in the 35th byte of the data packet. Therefore, the IDS node skips the middle bytes of the data packet, jumps to the 35th byte to directly read the port number "0080", and obtains the port packet of the data packet.

[0076] Step S304, "0080" represents Hypertext transfer protocol (HTTP). In HTTP, the URL starts at the 55th byte, so the IDS node skips the middle bytes of the data packet, jumps to the 55th byte to read the URL, and obtains the URL and part of the data packet content.

[0077] In this embodiment, the IDS node analysis data packet technology is adopted, and the high regularity of the network protocol is utilized to skip some bytes in the data packet and directly obtain the port number, URL and part of the data packet content, thereby greatly improving the efficiency of data packet parsing.

[0078] Step S500: extract multiple intrusion detection features from the data packet analysis result to form an intrusion detection feature set, perform feature processing on the intrusion detection feature set through a GEP algorithm, and obtain a processed intrusion detection feature set.

[0079] In some embodiments, step S500 specifically includes the following steps:

[0080] Step S501: Take the feature set to be detected as the population P t = {X1, X2, ..., X n}, calculate the population P t The fitness of each characteristic element in; where n represents the number of dimensions, X n Represents the population P t The nth characteristic element of .

[0081] Step S502: for population P t Each characteristic element in performs selection, mutation, insertion and recombination of gene expression programming to obtain a subpopulation O consisting of m characteristic elements. t , calculate the subpopulation O t The fitness of each characteristic element in .

[0082] Step S503: Set the population P t and subpopulation O t Merge into temporary population P t ′, delete the temporary population P t ′, and obtain the population P consisting of n characteristic elements. t+1 .

[0083] Step S504: If the current number of cycles is less than or equal to the preset number of cycles, the population P t+1 Let be the population P t , jump to step S502; if the current number of loops is greater than the preset number of loops, jump out of the loop and set the population P t+1 As the processed feature set for intrusion detection.

[0084] This embodiment uses the GEP algorithm to quickly select redundant and useless features without involving too many linear transformation operations, thereby improving the efficiency of intrusion feature detection.

[0085] Step S600: Based on the confirmed intrusion feature samples and the URL address, port, and data packet content data extracted from the data packet parsing results, the Bayesian inference rule is used to perform inference calculations on the processed intrusion detection feature set to determine whether there is an intrusion feature in the processed intrusion detection feature set.

[0086] This embodiment uses the verified intrusion feature samples and the URL address, port, and data packet content data in the data packet analysis results to perform reasoning analysis on the intrusion features using Bayesian inference rules, which can improve the effectiveness of intrusion feature detection.

[0087] Step S700: Perform intrusion determination on the processed feature set to be intrusion detected according to the confirmed intrusion feature samples to obtain an intrusion determination result.

[0088] Step S701: Calculate the intrusion coefficient of each feature element in the processed intrusion detection feature set according to a preset operator set.

[0089] The preset operator set includes at least one of the operators OR2, AND2, GOE2B and GOE2C. The operation function represented by OR2 is: if P i ≥0 or P j ≥0, then 1, elseO; AND2 represents the operation function: if P i ≥0 and P j ≥0, then 1, else0; the operation function represented by GOE2B is: if P i ≥P j , then 1, else 0; the operation function represented by GOE2C is: if P i ≥P j ,then(P i +P j ), else(P i =P j ), where P i represents the i-th feature element in the processed intrusion detection feature set, P j Represents the jth feature element in the processed intrusion detection feature set.

[0090] Step S702: Calculate the intrusion credibility of each feature element in the intrusion detection feature set after processing according to the following formula:

[0091]

[0092] Among them, b represents the intrusion credibility, a represents the intrusion coefficient, and U represents the variance of the confirmed intrusion feature samples.

[0093] Step S703: Calculate the product of the intrusion coefficient and the intrusion credibility.

[0094] Step S704: If the product is greater than the intrusion threshold, then the processed intrusion detection feature set contains intrusion features.

[0095] In this embodiment, a statistical method is used for evaluation, and the result is more reliable and stable, and the calculation speed is faster, thereby ensuring fast calculation while obtaining reliable and stable results.

[0096] Step S900: If the processed intrusion detection feature set contains intrusion features, an alarm signal is issued.

[0097] The method first captures the incoming data packets at the node of the IDS; then parses the incoming data packets to obtain the data packet parsing results, adopts the node analysis data packet technology of the IDS, and utilizes the high regularity of the network protocol to skip some bytes in the data packet, directly obtain the port number, URL and part of the data packet content, and greatly improves the efficiency of data packet parsing. Then, based on the GEP algorithm, redundant and useless features are quickly selected, without involving too many linear transformation operations, which can improve the efficiency of intrusion feature detection; using the URL address, port, and data packet content data in the verified intrusion feature samples and the data packet parsing results, the Bayesian inference rule is used to reason and analyze the intrusion features, which can improve the effectiveness of intrusion feature detection; using statistical methods for judgment, the results are more reliable and stable, and the calculation speed is faster, ensuring fast calculation while obtaining reliable and stable results. The method adopts the node analysis packet technology of the IDS, utilizes the high regularity of the network protocol, and adopts the GEP algorithm to quickly select redundant and useless features, and uses statistical methods for judgment, the results are more reliable and stable, and the calculation speed is faster, ensuring fast calculation while obtaining reliable and stable results. Compared with traditional static intrusion analysis methods (used by firewalls and antivirus software), the number of analyses is reduced from millions to thousands, which is more effective and faster.

[0098] An embodiment of the present application provides an electronic device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor.

[0099] The processor and the memory may be connected via a bus or other means.

[0100] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0101] It should be noted that the electronic device in this embodiment can constitute Figure 1 Part of the system architecture in the illustrated embodiments, these embodiments all belong to the same inventive concept, so these embodiments have the same implementation principles and technical effects, and will not be described in detail here.

[0102] The non-transient software program and instructions required to implement the intrusion detection method of the above embodiment are stored in the memory, and when executed by the processor, the above embodiment method is executed, for example, the above described intrusion detection method is executed. Figure 3 Method steps S100 to S900 in.

[0103] The terminal embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0104] In addition, an embodiment of the present application also provides a computer-readable storage medium, which stores computer-executable instructions. The computer-executable instructions are executed by a processor or a controller, for example, by a processor in the above electronic device embodiment, so that the above processor can execute the intrusion detection method in the above embodiment, for example, execute the above described Figure 3 In another example, the method steps S100 to S900 are executed by a processor in the device connector embodiment, so that the processor can execute the intrusion detection method in the embodiment, for example, executing the above described Figure 3 Method steps S100 to S900 in.

[0105] It will be appreciated by those skilled in the art that all or some of the steps and systems in the disclosed method above may be implemented as software, firmware, hardware and appropriate combinations thereof. Some physical components or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or a non-transitory medium) and a communication medium (or a temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that may be used to store desired information and may be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium. In the description of this specification, the description of reference terms "one embodiment", "some embodiments", "illustrative embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0106] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.

Claims

1. An intrusion detection method, characterized in that: The steps include: Capture the data packets flowing into the IDS node; Parsing the data packet to obtain a data packet parsing result; Extracting a plurality of intrusion detection features from the data packet parsing result to form an intrusion detection feature set, and performing feature processing on the intrusion detection feature set by using a GEP algorithm to obtain a processed intrusion detection feature set; performing feature processing on the intrusion detection feature set by using a GEP algorithm to obtain a processed intrusion detection feature set includes: Step S501: Use the feature set to be detected as a population , calculate the population The fitness of each characteristic element in ; where Indicates the number of dimensions, Represents population No. characteristic elements; Step S502: Each feature element in performs selection, mutation, insertion and recombination of gene expression programming, and obtains subpopulations consisting of characteristic elements , calculate the subpopulation The fitness of each characteristic element in; Step S503: and subpopulations Merge into temporary population , delete the temporary population The top fitness characteristic elements, obtained by A population composed of characteristic elements ; Step S504: If the current number of cycles is less than or equal to the preset number of cycles, Let be the population , jump to step S502; if the current number of cycles is greater than the preset number of cycles, jump out of the cycle and set the population As the processed feature set to be detected by intrusion; An intrusion determination is performed on the processed feature set to be intrusion detected according to the confirmed intrusion feature samples to obtain an intrusion determination result.

2. The intrusion detection method according to claim 1, characterized in that: Also includes: Based on the confirmed intrusion feature samples and the URL address, port, and data packet content data extracted from the data packet parsing results, the Bayesian inference rule is used to perform inference calculations on the processed intrusion detection feature set to determine whether there is an intrusion feature in the processed intrusion detection feature set.

3. The intrusion detection method according to claim 1, characterized in that: The step of performing intrusion determination on the processed feature set to be intrusion detected based on the confirmed intrusion feature samples to obtain an intrusion determination result includes: Calculate the intrusion coefficient of each feature element in the processed intrusion detection feature set according to a preset operator set; The intrusion credibility of each feature element in the processed intrusion detection feature set is calculated according to the following formula: Among them, the Indicates the intrusion credibility. represents the intrusion coefficient, represents the variance of the confirmed invasion signature samples; Calculating the product between the intrusion coefficient and the intrusion credibility; If the product is greater than the intrusion threshold, then the processed feature set to be detected for intrusion contains intrusion features.

4. The intrusion detection method according to claim 3, characterized in that: The preset operator set includes at least one of operators OR2, AND2, GOE2B and GOE2C, and the operation function represented by OR2 is: ; The operation function represented by AND2 is: ; The operation function represented by the GOE2B is: ; The operation function represented by the GOE2C is: ;in, Represents the first characteristic elements, Represents the first feature element.

5. The intrusion detection method according to claim 3, characterized in that: Also includes: If the processed intrusion detection feature set contains intrusion features, an alarm signal is issued.

6. An intrusion detection system, characterized in that: include: The data packet capture module is used to capture the data packets flowing into the IDS node; A data packet parsing module, used to parse the data packet and obtain a data packet parsing result; The data packet analysis module includes a classifier submodule and an evaluation submodule. The classifier submodule is used to extract multiple intrusion detection features from the data packet analysis results to form an intrusion detection feature set, and perform feature processing on the intrusion detection feature set through the GEP algorithm to obtain a processed intrusion detection feature set; the evaluation submodule is used to perform intrusion judgment on the processed intrusion detection feature set according to the confirmed intrusion feature samples to obtain an intrusion judgment result; The step of performing feature processing on the feature set to be detected by intrusion by using the GEP algorithm to obtain the processed feature set to be detected by intrusion includes: Step S501: Use the feature set to be detected as a population , calculate the population The fitness of each characteristic element in ; where Indicates the number of dimensions, Represents population No. characteristic elements; Step S502: Each feature element in performs selection, mutation, insertion and recombination of gene expression programming, and obtains subpopulations consisting of characteristic elements , calculate the subpopulation The fitness of each characteristic element in; Step S503: and subpopulations Merge into temporary population , delete the temporary population The top fitness characteristic elements, obtained by A population composed of characteristic elements ; Step S504: If the current number of cycles is less than or equal to the preset number of cycles, Let be the population , jump to step S502; if the current number of cycles is greater than the preset number of cycles, jump out of the cycle and set the population As the processed feature set to be detected by intrusion; The data packet alarm module is used to send out an alarm signal when there is an intrusion feature in the processed intrusion detection feature set.

7. The intrusion detection system according to claim 6, characterized in that: The data packet analysis module also includes an inference engine submodule, which is used to use Bayesian inference rules to perform inference calculations on the processed intrusion detection feature set based on confirmed intrusion feature samples and URL addresses, ports, and data packet content data extracted from the data packet parsing results, so as to determine whether there are intrusion features in the processed intrusion detection feature set.

8. An electronic device, characterized in that: It includes at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions that can be executed by the at least one control processor, and the instructions are executed by the at least one control processor so that the at least one control processor can execute the intrusion detection method described in any one of claims 1 to 5.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the intrusion detection method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Intrusion detection system (IDS) analysis method and intrusion detection system

    CN104135490A

  • Power grid malicious data injection detection method based on GEP-CNN

    CN111353153A