Intrusion detection method, system and electronic equipment based on formal concept analysis
Through the intrusion detection method of formal concept analysis, a network attack concept library and attack concept set are constructed, which solves the problem of difficulty in tracing the source and formulating a unified defense plan in existing technologies, and achieves the effect of quickly identifying network intrusions and improving network security.
Patent Information
- Application Number
- CN202211366614.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-01
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-11-01
AI Technical Summary
Existing intrusion detection technologies are based on machine learning and deep learning. It is difficult to obtain knowledge about network attacks from the model, difficult to trace the source and formulate a unified defense plan, and it is prone to overfitting, which reduces the versatility of the model.
An intrusion detection method based on formal concept analysis is adopted. By collecting and preprocessing network intrusion connection information, a network attack concept library is constructed. The type of network attack is determined by using the attribution degree, and the attack concept set is integrated to find a unified defense strategy.
Quickly identify network intrusion connections, improve network security, provide knowledge and correlation of network attacks, and improve the versatility and defense capabilities of the model.
Smart Images

Figure CN115720157B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet technology, and in particular to an intrusion detection method based on formal concept analysis. The present invention also relates to an intrusion detection system and electronic equipment based on formal concept analysis. Background Art
[0002] With the rapid development of the Internet of Things (IoT), an increasing number of industries impacting public life and national security are becoming increasingly connected to the internet. Cyberspace is flooded with cyberattacks aimed at stealing data or disrupting network systems. Identifying these attacks and making appropriate defensive decisions is a critical research topic in the current cybersecurity field. Intrusion detection technology, a key technology for identifying network attacks, has been extensively studied by cybersecurity scholars. Based on network traffic datasets, intrusion detection utilizes machine learning or deep learning methods to train intrusion detection models. These intrusion detection models monitor traffic entering and exiting the protected network, identify suspicious attacks, determine their type, and then take appropriate defensive actions.
[0003] Existing intrusion detection is mainly based on machine learning and deep learning. Such training methods do not conform to human cognitive habits. It is difficult for relevant practitioners to obtain knowledge about corresponding network attacks from the model, which is not conducive to attack tracing. It is also difficult to obtain the correlation between different network attacks from the model. In the face of different network attacks, it is difficult to formulate a unified defense plan; on the other hand, machine learning and deep learning are prone to overfitting, which reduces the versatility of the model.
[0004] Therefore, how to provide a solution to the problem, which can quickly find network intrusion connections in the current network and improve the security of the network, has become a goal that needs to be completed urgently by those skilled in the art. Summary of the Invention
[0005] In order to solve the above technical problems, the main purpose of the present invention is to provide an intrusion detection method based on formal concept analysis, which can quickly find network intrusion connections in the current network and improve the security of the network. In addition, the present invention also provides an intrusion detection system and electronic equipment based on formal concept analysis, which also have the above beneficial effects.
[0006] To achieve the above-mentioned object, the present invention provides an intrusion detection method based on formal concept analysis, which comprises: collecting network intrusion connection information, wherein the network intrusion connection information comprises network connection data, attributes, and network attack types; performing single-value preprocessing on the network intrusion connection information to obtain a network intrusion data table, wherein the network intrusion data table comprises: network connection data, attributes, and network attack types; constructing a network attack concept library based on the network intrusion data table, wherein the network attack concept library comprises a set of common attributes of all network connection data of any network attack type, denoted as i=1,2,3,…,N, where N is the number of network attack types contained in the data; collecting the current network connection information in the protected system, performing the single-value preprocessing on the current network connection information, obtaining a current network connection data table, the current network connection data table including: network connection data, attributes, constructing a current attribute set B based on the attributes in the current network connection data table test ,like It is determined that there is type i network attack in the current network connection information.
[0007] Furthermore, in the intrusion detection method based on formal concept analysis provided by the present invention, the method further includes:
[0008] Combined with the current attribute set B test and stated Get the attribution degree σ i ,
[0009]
[0010] When the attribute degree σ i When it is greater than the first threshold, it is determined that the current network connection information contains the i-th type of network attack;
[0011] External output attribution σ i .
[0012] Furthermore, in the intrusion detection method based on formal concept analysis provided by the present invention, the set of common attributes of all network connections of any network attack type is i=1,2,3,…,N;the construction method is:
[0013] In the network intrusion data table, each network connection data has one or more attributes; each attribute corresponds to one or more network connection data;
[0014] Assume that the set of network connection data of all network attack types is D={D i |i=1,2,3,…,N};D iis a set of all network connection data corresponding to a certain type of network attack;
[0015] The set of common attributes of all network connections of the arbitrary type of network attack is represented as
[0016] The set of all network connections corresponding to is represented as
[0017] Further, in the intrusion detection method based on formal concept analysis provided by the application, the method further comprises:
[0018] Constructing an attack concept set H, comprising the following steps:
[0019] Definition 2 D is the power set of set D, and for |F|≥2, if then (F ** ,F * ) is a hyper-concept of a network attack concept;
[0020] Finding all hyper-concepts of network attack concepts, and fusing the network attack concepts and the hyper-concepts to obtain an attack concept set H, wherein the attack concept set H satisfies, (A2,B2)∈H, if and then (A1,B1)≤(A2,B2);
[0021] When satisfies and then the i and j types of network attacks are classified into one category.
[0022] It should be noted that after the i and j types of network attacks are classified into one category, a unified defense strategy can be adopted for the i and j types of network attacks. The technical solution provided by the application provides a network attack classification method, and network attacks of the same category can seek a unified defense strategy.
[0023] Further, in the intrusion detection method based on formal concept analysis provided by the application, the "univalue preprocessing of the network intrusion connection information" comprises the following steps:
[0024] Each network connection data in the network intrusion connection information is taken as a row, and arranged by row to obtain a network intrusion data table; wherein each network connection data is called an object and placed in the first column of the network intrusion data table, the column labels between the first column and the last column are called attributes, and the column label of the last column is a network attack type.
[0025] Furthermore, in the intrusion detection method based on formal concept analysis provided by the present invention, the step of "pre-processing the network intrusion connection information into a single value" further includes the following steps:
[0026] All attributes of the network connection data are converted into single-value attributes and filled into the network intrusion data table.
[0027] Furthermore, in the intrusion detection method based on formal concept analysis provided by the present invention, the “changing all attributes of the network connection data into single-valued attributes” specifically includes:
[0028] For attributes that have only two possible values, mark the attribute value as {0,1};
[0029] For a discrete value attribute a, if its value range is {a1,a2,a3,…,a n}, then n single-valued attributes are used to replace the multi-valued attribute a, and the attribute set composed of n single-valued attributes is:
[0030] {a=a1,a=a2,a=a3,…,a=a n}
[0031] If a=a i ,i=1,2,3,…,n, then attribute a=a i The value of is 1, and the values of the remaining n-1 single-valued attributes are 0;
[0032] For a continuous value attribute b, if its value range is [b min ,b max ], the value range is divided into m parts, that is:
[0033]
[0034] Use m single-valued attributes to replace the continuous multi-valued attribute b. The attribute set composed of m single-valued attributes is
[0035]
[0036] If the value of a multi-valued attribute b of an object is
[0037]
[0038] but:
[0039] Single-valued attributes The value of is 0,
[0040] Single-valued attributes The value of is 1;
[0041] For the segmented continuous attribute, first, according to the discrete multi-value attribute processing, then according to the continuous multi-value attribute processing;
[0042] For the numerical discrete multi-value attribute, if the discrete number is greater than the set value K, it is considered as a continuous multi-value attribute.
[0043] Further, in the intrusion detection method based on formal concept analysis provided by the application, the "collecting network intrusion connection information" comprises the following steps:
[0044] Using public network attack data set; and / or
[0045] Using the network attack database and data probe of the enterprise itself, collecting data according to the needs of the enterprise itself.
[0046] In addition, the application further provides a system for the intrusion detection method based on formal concept analysis, which comprises: a first collecting module for collecting network intrusion connection information; a first preprocessing module for performing single value preprocessing on the network intrusion connection information; a first constructing module for constructing a network attack concept library based on the network intrusion data table; a second collecting module for collecting current network connection information in a protected system; a second preprocessing module for performing the single value preprocessing on the current network connection information; a second constructing module for constructing a current attribute set B test based on the attributes in the current network connection data table; and a comparison and determination module connected with the first constructing module and the second constructing module.
[0047] In addition, the application further provides an electronic device, which comprises: a computer program for executing the intrusion detection method based on formal concept analysis; a memory for storing the computer program; and a processor for running the computer program.
[0048] The intrusion detection method based on formal concept analysis provided by the application specifically comprises the following technical contents: collecting network intrusion connection information, wherein the network intrusion connection information comprises network connection data, attributes and network attack types; performing single value preprocessing on the network intrusion connection information to obtain a network intrusion data table, wherein the network intrusion data table comprises network connection data, attributes and network attack types; constructing a network attack concept library based on the network intrusion data table, wherein the network attack concept library comprises a set of public attributes of all network connections of any network attack type, denoted as i=1,2,3,…,N, where N is the number of network attack types contained in the data; collecting the current network connection information in the protected system, performing the single-value preprocessing on the current network connection information, obtaining a current network connection data table, the current network connection data table including: network connection data, attributes, constructing a current attribute set B based on the attributes in the current network connection data table test ,like It is determined that there is a type i network attack in the current network connection information. Compared with the existing technology, the technical solution of the present invention collects and pre-processes the network intrusion connection information in advance to form a set of common attributes of all network connections including any type of network attack. Sort out the network connections collected in real time to get the current attribute set B test ,like It can be considered that there are network attack type network connections in the current network connection information; the technical solution provided by this application can quickly find network intrusion connections in the current network and improve network security. The present invention also provides an intrusion detection system and electronic device based on formal concept analysis, which also have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only embodiments of the present invention. Those skilled in the art can also derive other drawings based on the provided drawings without inventive work.
[0050] Figure 1 The present invention is directed to an intrusion detection method based on formal concept analysis.
[0051] Figure 2 It is a Hasse diagram of the concept set H involved in the embodiment of the present invention. DETAILED DESCRIPTION
[0052] To facilitate understanding of the present invention, the present invention will be described more fully below with reference to the accompanying drawings. The drawings illustrate exemplary embodiments of the present invention. However, the present invention may be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and comprehensive understanding of the present invention.
[0053] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention.
[0054] In order to better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the drawings and specific implementation methods of the specification. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. In the absence of conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0055] Specific reference Figures 1 to 2 As shown, the present invention provides an intrusion detection method based on formal concept analysis, which specifically includes the following technical contents: collecting network intrusion connection information, wherein the network intrusion connection information includes network connection data, attributes, and network attack types; performing single-value preprocessing on the network intrusion connection information to obtain a network intrusion data table, wherein the network intrusion data table includes: network connection data, attributes, and network attack types; based on the network intrusion data table, constructing a network attack concept library, wherein the network attack concept library includes a set of common attributes of all network connections of any network attack type, denoted as i=1,2,3,…,N, where N is the number of network attack types contained in the data; collecting the current network connection information in the protected system, performing the single-value preprocessing on the current network connection information, obtaining a current network connection data table, the current network connection data table including: network connection data, attributes, constructing a current attribute set B based on the attributes in the current network connection data table test ,like It is determined that there is a type i network attack in the current network connection information. Compared with the existing technology, the technical solution of the present invention collects and pre-processes the network intrusion connection information in advance to form a set of common attributes of all network connections including any type of network attack. Sort out the network connections collected in real time to get the current attribute set B test ,like It can be considered that there are network attack type network connections in the current network connection information; the technical solution provided by this application can quickly find network intrusion connections in the current network and improve network security. The present invention also provides an intrusion detection system and electronic device based on formal concept analysis, which also have the above-mentioned beneficial effects.
[0056] Specifically, in an embodiment of the present invention, the method further includes:
[0057] Combined with the current attribute set B test and stated Get the attribution degree σ i ,
[0058]
[0059] When the attribute degree σ i When it is greater than the first threshold, it is determined that the current network connection information contains the i-th type of network attack;
[0060] External output attribution σ i .
[0061] Among them, the embodiments of the present invention appear Represents the empty set.
[0062] Specifically, in the embodiment of the present invention, the set of common attributes of all network connections of any network attack type is i=1,2,3,…,N;the construction method is:
[0063] In the network intrusion data table, each network connection data has one or more attributes; each attribute corresponds to one or more network connection data;
[0064] Assume that the set of network connections of any network attack type is D = {D i |i=1,2,3,…,N};D i It is a collection of all network connection data corresponding to a certain type of network attack;
[0065] Then the set of common attributes of all network connections of any network attack type is expressed as
[0066] Then the set of all network connections corresponding to the network connection attributes of any network attack type is expressed as
[0067] Specifically, in an embodiment of the present invention, the method further includes:
[0068] Constructing the attack concept set H includes the following steps:
[0069] Definition 2 D is the power set of set D, |F|≥2, if Then (F ** ,F * ) is a superconcept of the concept of cyber attack;
[0070] Find the super concepts of all network attack concepts, merge the network attack concepts and super concepts to obtain the attack concept set H, which satisfies: (A2,B2)∈H, if and Then (A1,B1)≤(A2,B2);
[0071] when satisfy and Then the two network attack types i and j are classified into one category.
[0072] It should be noted that after classifying the two network attack types i and j into one category, a unified defense strategy can be adopted for the two network attack types i and j. The technical solution provided by this application provides a classification method for network attacks, and a unified defense strategy can be sought for network attacks of the same category.
[0073] Specifically, in the embodiment of the present invention, the “performing a single-value pre-processing on the network intrusion connection information” includes the following steps:
[0074] Each network connection data in the network intrusion connection information is taken as a row and arranged by row to obtain a network intrusion data table; wherein, each network connection data is called an object and is placed in the first column of the network intrusion data table, the column labels between the first column and the last column are called attributes, and the column label of the last column is the network attack type.
[0075] Specifically, in the embodiment of the present invention, the “performing a univalued pre-processing on the network intrusion connection information” further includes the following steps:
[0076] All attributes of the network connection data are converted into single-value attributes and filled into the network intrusion data table.
[0077] Specifically, in the embodiment of the present invention, “changing all attributes of the network connection data into single-valued attributes” specifically includes:
[0078] For attributes that have only two possible values, mark the attribute value as {0,1};
[0079] For a discrete value attribute a, if its value range is {a1,a2,a3,…,a n}, then n single-valued attributes are used to replace the multi-valued attribute a, and the attribute set composed of n single-valued attributes is:
[0080] {a=a1,a=a2,a=a3,…,a=a n}
[0081] If a=a i,i=1,2,3,…,n, then attribute a=a i The value of is 1, and the values of the remaining n-1 single-valued attributes are 0;
[0082] For a continuous value attribute b, if its value range is [b min ,b max ], the value range is divided into m parts, that is:
[0083]
[0084] Use m single-valued attributes to replace the continuous multi-valued attribute b. The attribute set composed of m single-valued attributes is
[0085]
[0086] If the value of a multi-valued attribute b of an object is:
[0087]
[0088] but:
[0089] Single-valued attributes The value of is 0,
[0090] Single-valued attributes The value of is 1;
[0091] For piecewise continuous attributes, they are first processed as discrete multi-valued attributes and then as continuous multi-valued attributes;
[0092] For a numerical discrete multi-valued attribute, if the number of discrete values is greater than the set value K, it is considered a continuous multi-valued attribute.
[0093] Specifically, in an embodiment of the present invention, the “collecting network intrusion connection information” includes the following steps:
[0094] Leverage publicly available cyberattack datasets; and / or
[0095] Utilize the company's own network attack database and data probes to collect data according to its own needs.
[0096] In addition, the present invention also provides a system for intrusion detection method based on formal concept analysis, which includes: a first collection module for collecting network intrusion connection information; a first preprocessing module for performing single-value preprocessing on the network intrusion connection information; a first construction module for constructing a network attack concept library based on the network intrusion data table; a second collection module for collecting current network connection information in the protected system; a second preprocessing module for performing single-value preprocessing on the current network connection information; a current attribute set B based on the attributes in the current network connection data table.test a second building module; and a comparison and determination module connected to the data of the first building module and the second building module.
[0097] In addition, the present solution also provides an electronic device, comprising: a computer program for executing the intrusion detection method based on formal concept analysis as described above; a memory for storing the computer program; and a processor for running the computer program.
[0098] The following is a more detailed description of the background and overall solution of the embodiments of the present invention:
[0099] This invention builds an intrusion detection model based on the human cognitive process of knowledge, utilizing formal concept analysis. On the one hand, the model directly derives knowledge about network attacks, defines network attack concepts, and describes the relationships between different network attacks. This helps network administrators understand network attacks, trace their origins, and find unified solutions for similar attacks, saving manpower and resources. On the other hand, the definition of approximate network attack concepts can describe the degree of similarity between network traffic and a specific network attack, improving the model's versatility while also providing defense against unknown network attacks.
[0100] This paper mimics the human cognitive process and applies the method of formal concept analysis to the field of network security. It analyzes network traffic data sets, extracts network attack concepts from them, and uses these concepts to identify whether the traffic in the protected network is a network attack, and if so, what type of network attack it is. The specific steps are as follows:
[0101] Step 1: Collect network intrusion connection information, including but not limited to:
[0102] 1) Use public network attack datasets, such as the UNSW-NB15 dataset and the CIC-IDS-2017 dataset.
[0103] 2) Leverage the enterprise's own network attack database and data probes to collect data based on its needs. The collected data features include, but are not limited to, basic TCP connection features, TCP connection content features, time-based network traffic statistics, and host-based network traffic statistics.
[0104] Step 2: Preprocess the network attack data. Each network connection data point is treated as a row and arranged row by row to create a network intrusion data table. Each network connection data point is called an object. Column labels except the last column are called attributes. The last column is used to identify the network attack type. Each cell in the table represents the value of a specific attribute of an object.
[0105] Make all attributes single-valued:
[0106] For attributes that have only two possible values, mark the attribute value as {0,1};
[0107] For a discrete multi-valued attribute a, if its value range is {a1,a2,a3,…,a n}, then n single-valued attributes are used to replace the multi-valued attribute a, and the attribute set composed of n single-valued attributes is
[0108] {a=a1,a=a2,a=a3,…,a=a n}
[0109] If a=a i ,i=1,2,3,…,n, then attribute a=a i The value of is 1, and the values of the remaining n-1 single-valued attributes are 0.
[0110] For a continuous multi-valued attribute b, if its value range is [b min ,b max ], then the value range is divided into m parts, that is
[0111]
[0112] Use m single-valued attributes to replace the continuous multi-valued attribute b. The attribute set composed of m single-valued attributes is
[0113]
[0114] If the value of a multi-valued attribute b of an object is
[0115]
[0116] but
[0117] Single-valued attributes The value of is 0,
[0118] Single-valued attributes The value of is 1.
[0119] For piecewise continuous attributes, they are first processed as discrete multi-valued attributes and then as continuous multi-valued attributes;
[0120] For a numerical discrete multi-valued attribute, if the number of discrete values is greater than the set value K, it is considered to be a continuous multi-valued attribute.
[0121] After the above operations, the single-value attribute form of the network connection (object) is obtained. The set G of all connection data (objects) is called the object set, and the set B of all single-value attributes is called the attribute set. Define the binary relationship I between G and B. right (M is a set of attributes), (g,b)∈I means that object g has attribute b (attribute value is 1). The triple (G,M,I) defined in this way is called the network connection form background, which is equivalent to the single-valued attribute form of the network connection.
[0122] Step 3: Define the object (network connection) of the network attack - attribute (feature) operator "*", have
[0123] (A is the object (network connection), and A* is the set of all features of the object)
[0124] (B is an attribute (feature), and B* is the set of all objects (network connections) with that attribute)
[0125] Among them, A * Represents the set of common features of all network connections in the network connection subset A, B * represents the set of network connections with all the features in feature set B. For a pair of sets (A, B), if A * =B and B * =A, then (A, B) is called a network connection concept (corresponding to each other).
[0126] Step 4: Define the concept of network attack. Given a network connection form background (G, M, I), many network connection concepts can be defined on it. For example, starting from each object and attribute, a network connection concept can be obtained by acting twice continuously, that is, ({a} ** ,{a} * ) and ({b} * ,{b} ** When the network connection form background contains a large amount of data, finding all network connection concepts requires a large amount of computing resources. Fortunately, not all network connection concepts are important. As an intrusion detection technology, the present invention only focuses on network connection concepts that can reflect network attacks.
[0127] Using the label (type) in the last column of the data, the networks with the same attack type are connected into a set, and D = {D i |i=1,2,3,…,N}, where N is the number of network attack types contained in the data, D i It is a collection of all network connections (objects) corresponding to a certain network attack (type). definition The concept of network attack (including objects and attributes). (D, A, G)
[0128] In particular, if erroneous data is present during data collection, the public attributes of cyberattacks may be reduced, or even In order to prevent erroneous data from affecting the generation of network attack concepts, it is necessary to check for outliers in the data preprocessing stage.
[0129] On the other hand, in order to increase fault tolerance, when producing network attack concepts, D i The data is divided into p parts, Find the common attributes of each like Then D ik There is error data in the . Set all public attributes without error data to Find the intersection (∩) to get the correct common attribute set of type i network attacks For the intersection.
[0130] For the sake of convenience, in the following text are equivalent to here
[0131] After the above processing, if D i For network objects, For the associated objects of the features of the same type of attack objects, it means that the partitioning of the continuous multi-valued attributes in step 2 is not fine enough, and the number of partitions needs to be further increased until Approaching 1.
[0132] Step 5: Find the super-concept of the network attack concept and evaluate the relationship between different network attacks in order to find the same solution for different network projects. D is the power set of set D, |F|≥2, if Then (F ** ,F * ) is a super concept of the network attack concept. For example, when |F|=2, (F ** ,F * ) can be expressed as
[0133]
[0134] Find the super concepts of all network attack concepts, merge the network attack concepts and super concepts to get the attack concept set H (H = all (F ** ,F * )), define the partial order relationship between all concepts in the concept set H, that is like and Then (A1,B1)≤(A2,B2).
[0135] According to the partial order relationship of H, the Hasse diagram of the concept set H is obtained and visualized. From the Hasse diagram, we can see the classification relationship of all network attacks, such as Figure 2 The following is an example of a Hasse diagram with |D| = 5. satisfy and Then, the two network attack types i and j can be classified into one category under certain granularity, and it is expected that a unified defense method can be sought.
[0136] Step 6: Utilize the cyber attack concepts obtained in step 4 i=1,2,3,…,N for attack identification. Use data probe to obtain the current network connection in the protected system, and use the method in step 2 to single-value the attributes (features) of the current network connection. Count all the attributes (features) of the current network connection that have a value of 1 to form the attribute (feature) set B test ,like Then the current network connection has the i-th type of network attack, and intrusion detection is implemented.
[0137] Step 7: Due to the diverse nature of network attacks, existing network attack databases are unable to capture new attacks. As network attacks evolve, some of their characteristics may change, potentially deceiving intrusion detection systems. Therefore, we introduce the concept of approximate network attacks and define the degree of network attack approximation to identify unknown network attacks and potential threats. We compare the attributes of the current network connection with those of the network attack concept and define the degree to which the current network connection belongs to a particular network attack concept.
[0138]
[0139] Using the attribution degree σ i It can identify unknown network attacks and determine the degree of attribution of the current network connection to all network attack concepts. If there is at least one σ i If it is greater than the set value (assuming it is 80%), the current network connection is considered to be a type i network attack, and its attribution degree σ is fed back i .
[0140] In the description provided herein, numerous specific details are described. However, it is understood that embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques are not shown in detail so as not to obscure the understanding of this description.
[0141] Similarly, it should be understood that in order to streamline the present disclosure and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the invention, various features of the invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Accordingly, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the invention.
[0142] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition may be divided into multiple submodules or subunits or subcomponents. All features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed herein may be combined in any combination, except that at least some of such features and / or processes or units are mutually exclusive. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.
[0143] Furthermore, those skilled in the art will appreciate that although some embodiments described herein include certain features included in other embodiments but not other features, combinations of features from different embodiments are intended to be within the scope of the present invention and to form different embodiments. For example, in the claims below, any of the claimed embodiments may be used in any combination.
[0144] It should be noted that the above embodiments illustrate rather than limit the invention, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between brackets should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising several different elements and by means of appropriately programmed computers. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.
Claims
1. An intrusion detection method based on formal concept analysis, characterized in that: Including steps: Collecting network intrusion connection information, including network connection data, attributes, and network attack types; Performing a single-value preprocessing on the network intrusion connection information to obtain a network intrusion data table, wherein the network intrusion data table includes: network connection data, attributes, and network attack type; Based on the network intrusion data table, a network attack concept library is constructed. The network attack concept library includes a set of common attributes of all network connections of any network attack type, which is recorded as Where N is the number of network attack types contained in the data; Collecting current network connection information in the protected system, performing the single-value preprocessing on the current network connection information, and obtaining a current network connection data table, wherein the current network connection data table includes: network connection data and attributes; Construct current attribute set B based on the attributes in the current network connection data table test ,like It is determined that there is a type i network attack in the current network connection information; A collection of network connection attributes for any of the aforementioned network attack types The construction method is: In the network intrusion data table, each network connection data has one or more attributes; each attribute corresponds to one or more network connection data; Assume that the set of network connections of any network attack type is D = {D i |i=1,2,3,…,N};D i It is a collection of all network connection data corresponding to a certain type of network attack; Then the set of common attributes of all network connections of any network attack type is expressed as Where "*" is the object-attribute operator of the network attack; Then the set of all network connections corresponding to the network connection attributes of any network attack type is expressed as The intrusion detection method based on formal concept analysis also includes: Constructing the attack concept set H includes the following steps: Definition 2 D is the power set of set D, like Then (F ** ,F * ) is a superconcept of the concept of cyber attack; Find the super concepts of all network attack concepts, merge the network attack concepts and super concepts to obtain the attack concept set H, and the partial order relationship of the attack concept set H satisfies: like and Then (A1, B1) ≤ (A2, B2), and the attack concept set H is visualized according to the partial order relation; when satisfy and Then the two network attack types i and j are classified into one category.
2. The intrusion detection method based on formal concept analysis according to claim 1, characterized in that: The method further comprises the steps of: Combined with the current attribute set B test and stated Get the attribution degree σ i , When the attribute degree σ i When it is greater than the first threshold, it is determined that the current network connection information contains the i-th type of network attack; External output attribution σ i .
3. The intrusion detection method based on formal concept analysis according to any one of claim 1, characterized in that: The “performing a single-value preprocessing on the network intrusion connection information” includes the following steps: Each network connection data in the network intrusion connection information is taken as a row and arranged by row to obtain a network intrusion data table; wherein, each network connection data is called an object and is placed in the first column of the network intrusion data table, the column labels between the first column and the last column are called attributes, and the column label of the last column is the network attack type.
4. The intrusion detection method based on formal concept analysis according to claim 3, characterized in that: The "pre-processing the network intrusion connection information into a single value" further includes the following steps: All attributes of the network connection data are converted into single-value attributes and filled into the network intrusion data table.
5. The intrusion detection method based on formal concept analysis according to claim 4 is characterized in that: The “changing all attributes of the network connection data into single-valued attributes” specifically includes: For attributes that have only two possible values, mark the attribute value as {0,1}; For a discrete value attribute a, if its value range is {a1,a2,a3,…,a n }, then n single-valued attributes are used to replace the multi-valued attribute a, and the attribute set composed of n single-valued attributes is: {a=a1,a=a2,a=a3,…,a=a n } If a=a i ,i=1,2,3,…,n, then attribute a=a i The value of is 1, and the values of the remaining n-1 single-valued attributes are 0; For a continuous value attribute b, if its value range is [b min ,b max ], the value range is divided into m parts, that is: Replace the continuous multi-valued attribute b with m single-valued attributes. The attribute set composed of m single-valued attributes is: If the value of a multi-valued attribute b of an object is: but: Single-valued attributes The value of is 0, Single-valued attributes The value of is 1; For piecewise continuous attributes, they are first processed as discrete multi-valued attributes and then as continuous multi-valued attributes; For a numerical discrete multi-valued attribute, if the number of discrete values is greater than the set value K, it is considered a continuous multi-valued attribute.
6. The intrusion detection method based on formal concept analysis according to claim 3, characterized in that: The "collecting network intrusion connection information" includes the following steps: Leverage publicly available cyberattack datasets; and / or Utilize the company's own network attack database and data probes to collect data according to its own needs.
7. A system using the intrusion detection method based on formal concept analysis according to any one of claims 1 to 6, characterized in that: The system includes: A first collection module for collecting network intrusion connection information; A first pre-processing module for performing a univalued pre-processing on the network intrusion connection information; A first building module for building a network attack concept library based on the network intrusion data table; A second collection module for collecting current network connection information in the protected system; A second pre-processing module configured to perform the univalue pre-processing on the current network connection information; Used to construct the current attribute set B based on the attributes in the current network connection data table test The second building block of A comparison and determination module is data-connected to the first building module and the second building module.
8. An electronic device, characterized in that: include: A computer program, wherein the computer program is used to execute the intrusion detection method based on formal concept analysis according to any one of claims 1 to 6; a memory for storing the computer program; A processor is configured to run the computer program.
Citation Information
Patent Citations
Industrial control system network intrusion detection method and system based on ternary concept analysis
CN112804247A