A network monitoring method and system based on heterogeneous interface
By using neural network models and support vector machine models in network monitoring, feature extraction and state judgment of network data flow is solved, and the problem of inability to effectively monitor potential data abnormalities in the prior art is improved, and the accuracy of network status monitoring and data security control capabilities are improved.
Patent Information
- Application Number
- CN202210537557.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-18
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2042-05-18
AI Technical Summary
The existing network monitoring methods mainly rely on hardware devices to perform triggered monitoring, and cannot effectively monitor potential data abnormalities, and the accuracy of security identification is low.
The network monitoring method based on the heterogeneous interface is adopted to process the network data flow feature matrix through the neural network model, extract the expression and preliminary judgment results in the high-dimensional feature space, and combine the covariance matrix and the support vector machine model to determine the network state type.
It improves the accuracy of network status monitoring, can effectively detect potential data abnormalities and quickly respond to intrusion abnormalities, and improves network data security control capabilities.
Smart Images

Figure CN114826765B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of digital information transmission, and in particular relates to a network monitoring method and system based on a heterogeneous interface. Background Art
[0002] Network data security monitoring generally uses bypass mirroring / splitting business access traffic, analyzes data flows based on big data technology, and semi-automatically combs data assets to identify the distribution of core business and sensitive data. It monitors the interconnection, flow, and operation of key data assets, discovers illegal access or operation of border data, quickly locates problems, analyzes abnormal operation behaviors, and builds a three-dimensional and comprehensive network data security management and control capability. However, the current monitoring of network conditions often uses trigger monitoring performed by hardware devices, that is, abnormal trigger messages or alarms, but this method cannot monitor potential data anomalies, and the accuracy of general network monitoring security identification is low. Summary of the invention
[0003] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides a network monitoring method and system based on a heterogeneous interface, which uses a neural network model to process the network data flow feature matrix to extract its expression in a high-dimensional feature space and a preliminary judgment result, and at the same time takes into account the analysis of the intuitive feature data of the network data flow, by calculating the covariance matrix of the first feature matrix, and calculating the eigenvalue of the covariance matrix, the eigenvector corresponding to the eigenvalue is used as the second eigenvector, and further splicing is performed based on the first eigenvector and the second eigenvector to obtain a spliced eigenvector; based on the spliced eigenvector and the support vector machine model, the network state type is determined; by judging if the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
[0004] According to one aspect of the present application, a network monitoring method based on a heterogeneous interface is provided, the method comprising:
[0005] Receiving a monitoring request, the monitoring request including a heterogeneous interface ID and a monitoring time; capturing a network data flow passing through the heterogeneous interface according to the monitoring request, and performing a preprocessing operation on the network data flow to generate a first feature matrix;
[0006] Inputting the first feature matrix into the first neural network model to obtain a first feature vector; at the same time, calculating the covariance matrix of the first feature matrix, and calculating the eigenvalues of the covariance matrix, and using the eigenvector corresponding to the eigenvalue as the second eigenvector;
[0007] The first feature vector and the second feature vector are concatenated to obtain a concatenated feature vector; based on the concatenated feature vector and a support vector machine model, a network state type is determined; wherein the first neural network model and the support vector machine model include a plurality of defined network state types.
[0008] Preferably, the pre-processing operation includes:
[0009]
[0010] Among them, X is the network data flow, M is the first feature matrix, W is the preprocessing weight matrix, and b is the offset.
[0011] Preferably, concatenating the first feature vector and the second feature vector to obtain a concatenated feature vector comprises:
[0012] Determine a concatenated vector of the first eigenvector and the second eigenvector, wherein the dimension of the concatenated vector is the sum of the dimensions of the first eigenvector and the second eigenvector;
[0013] The first feature vector and the second feature vector are spliced based on the splicing vector to obtain a splicing feature vector.
[0014] Preferably, each layer of the first neural network model includes convolution processing, maximum pooling processing along the first feature matrix and activation processing on the input data in the forward transfer of the layer, wherein, during the activation processing, the activation value of any neuron is stopped with a certain probability by randomly selecting neuron nodes for operation; the input of the first layer of the first neural network model is the first feature matrix, and the output is the first feature vector and the preliminary judgment result of the network status.
[0015] Preferably, the network status type is determined based on the concatenated feature vector and the support vector machine model, wherein the support vector machine model includes the defined network status type, including:
[0016] Predefine network status types as abnormal status and normal status, wherein the abnormal status at least includes offline abnormality and / or intrusion abnormality; and the network data flow passing through the heterogeneous interface under the corresponding network status type;
[0017] Based on the concatenated feature vector and the support vector machine model, the current network state type is determined. If the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
[0018] Preferably, the method further comprises:
[0019] If the determined network status type is an intrusion anomaly, the system disconnection operation is triggered, and the user is prompted and a warning message is displayed;
[0020] If the determined network status type is normal, the transmission rate of the heterogeneous interface is obtained, and the information is displayed to the user; wherein the displayed information includes the heterogeneous interface ID and the transmission rate fluctuation graph.
[0021] In addition, according to another aspect of the present application, a network monitoring system based on a heterogeneous interface is provided, the system comprising:
[0022] The capture and preprocessing module receives a monitoring request, wherein the monitoring request includes a heterogeneous interface ID and a monitoring time; captures a network data flow passing through the heterogeneous interface according to the monitoring request, and performs a preprocessing operation on the network data flow to generate a first feature matrix;
[0023] The feature generation module inputs the first feature matrix into the first neural network model to obtain a first feature vector; at the same time, calculates the covariance matrix of the first feature matrix, and calculates the eigenvalues of the covariance matrix, and uses the eigenvector corresponding to the eigenvalue as the second eigenvector;
[0024] The monitoring status determination module concatenates the first feature vector and the second feature vector to obtain a concatenated feature vector; determines the network status type based on the concatenated feature vector and a support vector machine model; wherein the first neural network model and the support vector machine model include a plurality of defined network status types.
[0025] Preferably, the pre-processing operation includes:
[0026]
[0027] Among them, X is the network data flow, M is the first feature matrix, W is the preprocessing weight matrix, and b is the offset;
[0028] The first feature vector and the second feature vector are concatenated to obtain a concatenated feature vector, including: determining a concatenated vector of the first feature vector and the second feature vector, wherein the dimension of the concatenated vector is the sum of the dimensions of the first feature vector and the second feature vector;
[0029] The first feature vector and the second feature vector are spliced based on the splicing vector to obtain a splicing feature vector.
[0030] Preferably, each layer of the first neural network model includes convolution processing, maximum pooling processing along the first feature matrix and activation processing on the input data in the forward transfer of the layer, wherein, during the activation processing, the activation value of any neuron is stopped with a certain probability by randomly selecting neuron nodes for operation; the input of the first layer of the first neural network model is the first feature matrix, and the output is the first feature vector and the preliminary judgment result of the network status.
[0031] Preferably, the network status type is determined based on the concatenated feature vector and the support vector machine model, wherein the support vector machine model includes the defined network status type, including:
[0032] Predefine network status types as abnormal status and normal status, wherein the abnormal status at least includes offline abnormality and / or intrusion abnormality; and the network data flow passing through the heterogeneous interface under the corresponding network status type;
[0033] Based on the concatenated feature vector and the support vector machine model, the current network state type is determined. If the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
[0034] The network monitoring method and system based on heterogeneous interfaces provided by the present invention use a neural network model to process a network data flow feature matrix to extract its expression in a high-dimensional feature space and a preliminary judgment result, and at the same time take into account the analysis of intuitive feature data of the network data flow, calculate the covariance matrix of the first feature matrix, and calculate the eigenvalue of the covariance matrix, use the eigenvector corresponding to the eigenvalue as the second eigenvector, and further perform splicing based on the first eigenvector and the second eigenvector to obtain a spliced eigenvector; determine the network state type based on the spliced eigenvector and a support vector machine model; and determine the current network state type as the final network state type by judging that if the current network state type is consistent with the preliminary judgment result of the network state, thereby improving the accuracy of network state monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 A flowchart of a schematic diagram of a network monitoring method based on a heterogeneous interface according to an embodiment of the present invention;
[0036] Figure 2 The present invention is a schematic diagram of the structure of a network monitoring system based on a heterogeneous interface according to an embodiment of the present invention. DETAILED DESCRIPTION
[0037] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more comprehensive and complete and fully convey the concept of the example embodiments to those skilled in the art.
[0038] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present application. However, those skilled in the art will appreciate that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, known methods, devices, realizations or operations are not shown or described in detail to avoid blurring the various aspects of the application.
[0039] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0040] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0041] The implementation details of the technical solution of the embodiment of the present application are described in detail below:
[0042] See also Figure 1 , Figure 1 FIG. 1 is a flow chart of a network monitoring method based on a heterogeneous interface disclosed in an embodiment of the present invention. Figure 1 As shown, a network monitoring method based on a heterogeneous interface according to an embodiment of the present invention includes:
[0043] S1, receiving a monitoring request, the monitoring request including a heterogeneous interface ID and a monitoring time; according to the monitoring request, capturing a network data flow passing through the heterogeneous interface, and performing a preprocessing operation on the network data flow to generate a first feature matrix;
[0044] S2, inputting the first feature matrix into the first neural network model to obtain a first eigenvector; at the same time, calculating the covariance matrix of the first feature matrix, and calculating the eigenvalues of the covariance matrix, and using the eigenvector corresponding to the eigenvalue as the second eigenvector;
[0045] S3, concatenating the first feature vector and the second feature vector to obtain a concatenated feature vector; determining the network state type based on the concatenated feature vector and a support vector machine model; wherein the first neural network model and the support vector machine model include a plurality of defined network state types.
[0046] In this embodiment, the special-shaped interface includes a special-shaped USB interface or other network transmission interface.
[0047] Preferably, the pre-processing operation includes:
[0048]
[0049] Among them, X is the network data flow, M is the first feature matrix, W is the preprocessing weight matrix, and b is the offset.
[0050] Preferably, concatenating the first feature vector and the second feature vector to obtain a concatenated feature vector comprises:
[0051] Determine a concatenated vector of the first eigenvector and the second eigenvector, wherein the dimension of the concatenated vector is the sum of the dimensions of the first eigenvector and the second eigenvector;
[0052] The first feature vector and the second feature vector are spliced based on the splicing vector to obtain a splicing feature vector.
[0053] In this embodiment, specifically, if the first eigenvector is x i =[x i1 , x i2 , x i3 , x i4 , x i5 … x ia ], the second eigenvector is y i =[y i1 , y i2 , y i3 , y i4 , y i5 … y ib ], where i=1,2…n. Set the concatenation vector u=[ u1, u2,u3, u4… u a+b ]; the concatenated feature vector is K i =[u1x i1 , u2x i2 , u3x i3 , u4x i4 , u5x i5 … u a x ia, u a+1 yi1 ,u a+2 y i2 , u a+3 y i3 , u a+4 y i4 , u a+5 y i5 … u a+b y ib ].
[0054] Preferably, each layer of the first neural network model includes convolution processing, maximum pooling processing along the first feature matrix and activation processing on the input data in the forward transfer of the layer, wherein, during the activation processing, the activation value of any neuron is stopped with a certain probability by randomly selecting neuron nodes for operation; the input of the first layer of the first neural network model is the first feature matrix, and the output is the first feature vector and the preliminary judgment result of the network status.
[0055] Preferably, the network status type is determined based on the concatenated feature vector and the support vector machine model, wherein the support vector machine model includes the defined network status type, including:
[0056] Predefine network status types as abnormal status and normal status, wherein the abnormal status at least includes offline abnormality and / or intrusion abnormality; and the network data flow passing through the heterogeneous interface under the corresponding network status type;
[0057] Based on the concatenated feature vector and the support vector machine model, the current network state type is determined. If the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
[0058] Preferably, the method further comprises:
[0059] If the determined network status type is an intrusion anomaly, the system disconnection operation is triggered, and the user is prompted and a warning message is displayed;
[0060] If the determined network status type is normal, the transmission rate of the heterogeneous interface is obtained, and the information is displayed to the user; wherein the displayed information includes the heterogeneous interface ID and the transmission rate fluctuation graph.
[0061] See also Figure 2 , Figure 2 Schematic diagram of a network monitoring system based on heterogeneous interfaces disclosed in an embodiment of the present invention. Figure 2 As shown, a network monitoring system based on a heterogeneous interface according to an embodiment of the present invention includes:
[0062] The capture and preprocessing module 10 receives a monitoring request, wherein the monitoring request includes a heterogeneous interface ID and a monitoring time; according to the monitoring request, captures a network data flow passing through the heterogeneous interface, and performs a preprocessing operation on the network data flow to generate a first feature matrix;
[0063] The feature generation module 20 inputs the first feature matrix into the first neural network model to obtain a first feature vector; at the same time, calculates the covariance matrix of the first feature matrix, and calculates the eigenvalues of the covariance matrix, and uses the eigenvector corresponding to the eigenvalue as the second eigenvector;
[0064] The monitoring status determination module 30 concatenates the first feature vector and the second feature vector to obtain a concatenated feature vector; determines the network status type based on the concatenated feature vector and the support vector machine model; wherein the first neural network model and the support vector machine model include a plurality of defined network status types.
[0065] Preferably, the pre-processing operation includes:
[0066]
[0067] Among them, X is the network data flow, M is the first feature matrix, W is the preprocessing weight matrix, and b is the offset;
[0068] The first feature vector and the second feature vector are concatenated to obtain a concatenated feature vector, including: determining a concatenated vector of the first feature vector and the second feature vector, wherein the dimension of the concatenated vector is the sum of the dimensions of the first feature vector and the second feature vector;
[0069] The first feature vector and the second feature vector are spliced based on the splicing vector to obtain a splicing feature vector.
[0070] Preferably, each layer of the first neural network model includes convolution processing, maximum pooling processing along the first feature matrix and activation processing on the input data in the forward transfer of the layer, wherein, during the activation processing, the activation value of any neuron is stopped with a certain probability by randomly selecting neuron nodes for operation; the input of the first layer of the first neural network model is the first feature matrix, and the output is the first feature vector and the preliminary judgment result of the network status.
[0071] Preferably, the network status type is determined based on the concatenated feature vector and the support vector machine model, wherein the support vector machine model includes the defined network status type, including:
[0072] Predefine network status types as abnormal status and normal status, wherein the abnormal status at least includes offline abnormality and / or intrusion abnormality; and the network data flow passing through the heterogeneous interface under the corresponding network status type;
[0073] Based on the concatenated feature vector and the support vector machine model, the current network state type is determined. If the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
[0074] In addition, the system also includes a display module, which is used to: if the determined network status type is an intrusion anomaly, trigger the system network disconnection operation, prompt the user, and display warning information; if the determined network status type is normal, obtain the transmission rate of the heterogeneous interface and display the information to the user; wherein the display information includes the heterogeneous interface ID and the transmission rate fluctuation graph.
[0075] In the scheme of the above-mentioned embodiment of the present invention, the provided network monitoring method and system based on heterogeneous interface receive a monitoring request, wherein the monitoring request includes a heterogeneous interface ID and a monitoring time; according to the monitoring request, capture the network data flow passing through the heterogeneous interface, and perform a preprocessing operation on the network data flow to generate a first feature matrix; input the first feature matrix into a first neural network model to obtain a first feature vector; at the same time, calculate the covariance matrix of the first feature matrix, and calculate the eigenvalue of the covariance matrix, and use the eigenvector corresponding to the eigenvalue as the second eigenvector; perform splicing on the first eigenvector and the second eigenvector to obtain a spliced feature vector; determine the network status type based on the spliced feature vector and a support vector machine model; wherein the first neural network model and the support vector machine model include a plurality of defined network status types.
[0076] The network data flow feature matrix is processed by using a neural network model to extract its expression in a high-dimensional feature space and a preliminary judgment result, and at the same time, the analysis of the intuitive feature data of the network data flow is taken into consideration. The covariance matrix of the first feature matrix is calculated, and the eigenvalue of the covariance matrix is calculated. The eigenvector corresponding to the eigenvalue is used as the second eigenvector, and further splicing is performed based on the first eigenvector and the second eigenvector to obtain a spliced feature vector; the network state type is determined based on the spliced feature vector and a support vector machine model; if the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type, thereby improving the accuracy of network state monitoring.
[0077] The embodiment of the present invention further discloses a computer storage medium, on which a computer program is stored. When the computer program is run by a processor, the method described above is executed.
[0078] The embodiment of the present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. The processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device performs the method described in the above various optional implementations.
[0079] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0080] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or it can be an electrical, mechanical or other form of connection.
[0081] The units described as separate components may or may not be physically separated. As a unit, it can be appreciated by those skilled in the art that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0082] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0083] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a grid device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0084] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A network monitoring method based on heterogeneous interfaces, characterized in that: The method comprises: Receiving a monitoring request, the monitoring request including a heterogeneous interface ID and a monitoring time; capturing a network data flow passing through the heterogeneous interface according to the monitoring request, and performing a preprocessing operation on the network data flow to generate a first feature matrix; Inputting the first feature matrix into the first neural network model to obtain a first feature vector; at the same time, calculating the covariance matrix of the first feature matrix, and calculating the eigenvalues of the covariance matrix, and using the eigenvector corresponding to the eigenvalue as the second eigenvector; Concatenate the first feature vector and the second feature vector to obtain a concatenated feature vector; determine the network state type based on the concatenated feature vector and a support vector machine model; wherein the first neural network model and the support vector machine model include a plurality of defined network state types; The pre-processing operation comprises: Among them, X is the network data flow, M is the first feature matrix, W is the preprocessing weight matrix, and b is the offset; The first feature vector and the second feature vector are concatenated to obtain a concatenated feature vector, including: Determine a concatenated vector of the first eigenvector and the second eigenvector, wherein the dimension of the concatenated vector is the sum of the dimensions of the first eigenvector and the second eigenvector; Based on the splicing vector, the first feature vector and the second feature vector are spliced to obtain a spliced feature vector; Each layer of the first neural network model includes convolution processing, maximum pooling processing along the first feature matrix and activation processing on the input data in the forward transmission of the layer, wherein in the activation processing, the activation value of any neuron is stopped with a certain probability by randomly selecting neuron nodes for operation; the input of the first layer of the first neural network model is the first feature matrix, and the output is the first feature vector and the preliminary judgment result of the network state; Based on the concatenated feature vector and the support vector machine model, the network status type is determined, and the support vector machine model includes the defined network status type, including: Predefine network status types as abnormal status and normal status, wherein the abnormal status at least includes offline abnormality and / or intrusion abnormality; and capture network data flows passing through the heterogeneous interface under the corresponding network status type; Based on the concatenated feature vector and the support vector machine model, the current network state type is determined. If the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
2. The network monitoring method based on heterogeneous interfaces according to claim 1 is characterized in that: The method further comprises: If the determined network status type is an intrusion anomaly, the system disconnection operation is triggered, and the user is prompted and a warning message is displayed; If the determined network status type is normal, the transmission rate of the heterotype interface is obtained, and display information is displayed to the user; wherein the display information includes the heterotype interface ID and a transmission rate fluctuation graph.
3. A network monitoring system based on a heterogeneous interface, the network monitoring system being used to execute the method according to any one of claims 1 to 2, characterized in that: The system comprises: The capture and preprocessing module receives a monitoring request, wherein the monitoring request includes a heterogeneous interface ID and a monitoring time; captures a network data flow passing through the heterogeneous interface according to the monitoring request, and performs a preprocessing operation on the network data flow to generate a first feature matrix; The feature generation module inputs the first feature matrix into the first neural network model to obtain a first feature vector; at the same time, calculates the covariance matrix of the first feature matrix, and calculates the eigenvalues of the covariance matrix, and uses the eigenvector corresponding to the eigenvalue as the second eigenvector; The monitoring state determination module concatenates the first feature vector and the second feature vector to obtain a concatenated feature vector; determines the network state type based on the concatenated feature vector and a support vector machine model; wherein the first neural network model and the support vector machine model include a plurality of defined network state types; The pre-processing operation comprises: Among them, X is the network data flow, M is the first feature matrix, W is the preprocessing weight matrix, and b is the offset; The first feature vector and the second feature vector are concatenated to obtain a concatenated feature vector, including: determining a concatenated vector of the first feature vector and the second feature vector, wherein the dimension of the concatenated vector is the sum of the dimensions of the first feature vector and the second feature vector; Based on the splicing vector, the first feature vector and the second feature vector are spliced to obtain a spliced feature vector; Each layer of the first neural network model includes convolution processing, maximum pooling processing along the first feature matrix and activation processing on the input data in the forward transfer of the layer, wherein, during the activation processing, the activation value of any neuron is stopped with a certain probability by randomly selecting neuron nodes for operation; the input of the first layer of the first neural network model is the first feature matrix, and the output is the first feature vector and the preliminary judgment result of the network status.
4. The network monitoring system based on heterogeneous interfaces according to claim 3 is characterized in that: Based on the concatenated feature vector and the support vector machine model, the network status type is determined, and the support vector machine model includes the defined network status type, including: Predefine network status types as abnormal status and normal status, wherein the abnormal status at least includes offline abnormality and / or intrusion abnormality; and capture network data flows passing through the heterogeneous interface under the corresponding network status type; Based on the concatenated feature vector and the support vector machine model, the current network state type is determined. If the current network state type is consistent with the preliminary judgment result of the network state, the current network state type is determined as the final network state type.
Citation Information
Patent Citations
Network intrusion detection method and device based on multi-network model and electronic equipment
CN111553381A