Network traffic attack detection method, system and storage medium based on federated learning
By adopting a federated learning architecture in cyber attack detection, central servers and clients jointly build and optimize the model, the problem of low detection accuracy caused by data silos is solved, and more efficient and privacy-protected cyber attack detection is achieved.
Patent Information
- Application Number
- CN202211479971.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-23
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-11-23
AI Technical Summary
Existing machine learning and deep learning-based network attack detection technology has led to client data silos and low detection accuracy due to data privacy protection considerations.
Using a network traffic attack detection method based on federated learning, the central server builds a global model, and the client builds a local model, and by identifying network traffic characteristics, preprocessing data, performing model training and iterative optimization, the attack traffic judgment of network traffic is realized.
Without sharing data, the data island problem is effectively solved, the accuracy and performance of network attack detection is improved, and privacy protection is enhanced.
Smart Images

Figure CN115883152B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and in particular to a network traffic attack detection method, system and storage medium based on federated learning. Background Art
[0002] The rapid development of Internet technology has facilitated people's lives, but it has also promoted the spread and diffusion of network attacks. In real life, common means of network attacks include network monitoring, malicious code, password cracking, denial of service attacks, vulnerability exploitation, website data theft, social engineering attacks, APT, etc. These attacks are hidden in network traffic and are used and developed by cyber criminals, underground hacker industry, hacktivists and attackers with national backgrounds, resulting in highly technical network threats, causing huge losses to the national economy and people's livelihood.
[0003] Currently, machine learning-based detection and deep learning-based network attack detection use the powerful data analysis and learning capabilities of intelligent algorithms and are considered to be effective network attack detection methods. However, due to data privacy protection considerations, there are data silos between client data. When the network attack detection model trained on the server is applied on the client, the attack detection accuracy will be low.
[0004] In order to solve the data island problem and improve the accuracy of network attack detection without sharing data, a network traffic attack detection method, system and storage medium based on federated learning are proposed. Summary of the invention
[0005] The embodiments of the present invention propose a network traffic attack detection method, system and storage medium based on federated learning, so as to at least solve the problem of data islands existing without sharing data and the problem of low accuracy of network attack detection in the related technology.
[0006] According to an embodiment of the present invention, a network traffic attack detection method based on federated learning is proposed, comprising:
[0007] Build a global model for traffic attack detection on the central server and a local model for traffic attack detection on the client;
[0008] The client identifies attack traffic based on network traffic characteristics and generates a traffic data set;
[0009] The client preprocesses the identified traffic data set and sends it to the central server;
[0010] The central server trains the global model based on the preprocessed traffic dataset;
[0011] The client synchronizes the structural parameters of the global model and trains the local model;
[0012] Input unknown traffic data into the local model to determine attack traffic.
[0013] In an exemplary embodiment, the construction of a global model for traffic attack detection on a central server and the construction of a local model for traffic attack detection on a client include the following steps:
[0014] Build a global model based on the CNN algorithm on the central server;
[0015] Each local client builds a local detection model based on the CNN algorithm; the local model of the client has the same network structure as the global model of the central server.
[0016] In an exemplary embodiment, the network traffic characteristics include any one or a combination of connection time, protocol type, historical connection record, target host, service type, and traffic size.
[0017] In an exemplary embodiment, the client identifies attack traffic according to network traffic characteristics and generates a traffic data set, including the steps of:
[0018] Calculate direct feature correlation based on connection time matching degree and / or protocol type matching degree of network traffic;
[0019] Calculate the statistical feature correlation based on the correlation between the current connection and the connection records within the set historical time period;
[0020] The attack traffic matching degree is calculated according to the direct feature correlation degree and / or the statistical feature correlation degree, and the network traffic whose attack traffic matching degree is greater than the set threshold is identified as attack traffic to generate a traffic data set.
[0021] In an exemplary embodiment, the step of calculating the statistical feature correlation degree according to the correlation between the current connection and the connection records within a set historical time period comprises the following steps:
[0022] Calculate the connection quantity correlation according to the number of connections with the same target host as the current connection in a set historical time period and / or the number of connections with the same service as the current connection in a set historical time period;
[0023] Calculate the connection type association degree according to the similarity between the current connection and the target host connected in the set historical time period and / or the similarity between the service type of the current connection and the connection in the set historical time period;
[0024] Calculate the connection change correlation according to the traffic change measurement value between the current connection and the connection in the set historical time period and / or the duration change measurement value between the current connection and the connection in the set historical time period;
[0025] The statistical feature correlation is calculated according to the positive correlation between the connection quantity correlation and / or the connection type correlation and / or the connection change correlation and the statistical feature correlation.
[0026] In an exemplary embodiment, the client preprocesses the identified traffic data set, including calculating any one or a combination of the mean of the data set, the data volume of the data set, the variance of the data set, the maximum instantaneous change of the data set, the minimum instantaneous change of the data set, and the data convergence evaluation value of the data set.
[0027] In an exemplary embodiment, the central server trains the global model based on the preprocessed traffic data set, comprising the steps of:
[0028] The central server receives the pre-processed traffic data set information from each client based on HTTP;
[0029] The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the data information of each client to obtain global data set information;
[0030] Train the global model according to the global data set information and save the obtained global model structure parameters into an array;
[0031] The structural parameter array matrix of the global model is sent to each client simultaneously based on HTTP.
[0032] In an exemplary embodiment, the client synchronizes the structural parameters of the global model and trains the local model, including the steps of:
[0033] The client receives the structure parameter array of the global model sent by the central server based on HTTP;
[0034] The client's local model synchronizes the structural parameters of the global model;
[0035] The traffic data set on the client is input into the local model to train the local model;
[0036] The client sends the trained local model structure parameters to the central server based on HTTP;
[0037] The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the structural parameters of each local model and uses this to train the global model to obtain the structural parameters of the global model;
[0038] The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the structural parameters of each local model and uses this to train the global model to obtain the structural parameters of the global model;
[0039] Repeat the above steps until the specified number of model iterations is reached to complete the training of the local model.
[0040] A computer-readable storage medium stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute the above method.
[0041] According to another embodiment of the present invention, a network traffic attack detection system based on federated learning is provided, comprising:
[0042] Central server;
[0043] Client processor;
[0044] Memory;
[0045] as well as
[0046] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the central server and / or client processor, the programs causing the computer to perform the above method.
[0047] The network traffic attack detection method, system and storage medium based on federated learning of the present invention have the following advantages:
[0048] (1) Based on the federated learning architecture and utilizing the decentralized computing paradigm, the isolated data training models of each client are integrated and trained on the central server. Compared with the traditional technical solution of training the network attack detection model only on the central server, this can effectively expand the detection model of each client and enhance the accuracy of traffic attack detection of each client on the basis of privacy protection.
[0049] (2) The statistical feature correlation is calculated based on the current connection and the target host connected within a set historical time period and / or the connection service type and / or the traffic change measurement value and / or the connection duration change measurement value. Compared with the traditional technical solution of identifying attack traffic only based on the characteristics of the current connection, the change of network traffic over a period of time can be identified, effectively improving the accuracy of attack traffic identification.
[0050] (3) Each client calculates the attack traffic matching degree based on the connection time of the network traffic, the direct feature correlation of the protocol type, and the statistical feature correlation between the current connection and the connection records in the set historical time period, and uses this to identify the attack traffic. Compared with the traditional technical solution that only identifies the attack traffic based on a single feature, this can comprehensively and effectively evaluate the attack features of the network traffic and improve the accuracy of attack traffic identification.
[0051] (4) Each client obtains the client's data set information by calculating the mean and / or data volume and / or variance and / or instantaneous change maximum value and / or instantaneous change minimum value and / or data aggregation evaluation value of the data set. The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the data information of each client to obtain the global data set information and uses it for model training. Compared with the traditional technical solution of training the model only through the data set, the final model can have a higher fit to the data set on each client, effectively improving the performance of traffic attack detection on each client. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 is a flow chart of a network traffic attack detection method based on federated learning according to an embodiment of the present invention;
[0053] Figure 2 is a flowchart of sub-step S01 of an embodiment of the present invention;
[0054] Figure 3 is a flowchart of sub-step S02 of an embodiment of the present invention;
[0055] Figure 4 is a flowchart of sub-step S022 of an embodiment of the present invention;
[0056] Figure 5 is a flowchart of sub-step S04 of an embodiment of the present invention;
[0057] Figure 6 is a flowchart of sub-step S05 of an embodiment of the present invention;
[0058] Figure 7 It is a structural diagram of a network traffic attack detection system based on federated learning according to an embodiment of the present invention. DETAILED DESCRIPTION
[0059] The present invention is described in detail below in conjunction with specific embodiments. The following embodiments will help those skilled in the art to further understand the invention, but are not intended to limit the present invention in any form. It should be noted that, for those of ordinary skill in the art, several changes and improvements can be made without departing from the concept of the present invention. These all belong to the protection scope of the present invention.
[0060] A network traffic attack detection method based on federated learning according to an embodiment of the present invention is shown in the flowchart as follows: Figure 1 As shown, the steps include:
[0061] Step S01: constructing a global model for traffic attack detection on a central server and a local model for traffic attack detection on a client;
[0062] Step S02: The client identifies attack traffic according to network traffic characteristics and generates a traffic data set;
[0063] Step S03: The client pre-processes the marked traffic data set and sends it to the central server;
[0064] Step S04: the central server trains the global model according to the preprocessed traffic data set;
[0065] Step S05: The client synchronizes the structural parameters of the global model and trains the local model;
[0066] Step S06: input unknown traffic data into the local model to determine attack traffic.
[0067] In an exemplary embodiment, the step S01, the flow chart is as follows Figure 2 As shown, including:
[0068] Step S011: construct a global model based on the CNN algorithm on the central server;
[0069] Step S012: Each local client builds a local detection model based on the CNN algorithm; the local model of the client has the same network structure as the global model of the central server. In this embodiment, the central server uses Python language to build a CNN network model based on the Pytorch framework. G (w k ) is used as the global model for traffic attack detection. The network structure includes 1 input layer, 4 convolutional layers, 4 pooling layers, 1 connection layer, and 1 output layer. The convolution kernel of the pooling layer is a 1-dimensional convolution kernel with a length of 10. Assuming there are k local clients and the data set on each client is X k , based on the Pytorch framework, use Python language to build a CNN network model f on each local client k (w k ) as the local detection model; the CNN network model of the client has the same network structure as the CNN network model of the central server, including 1 input layer, 4 convolution layers, 4 pooling layers, 1 connection layer, and 1 output layer; the convolution kernel of the pooling layer is a 1-dimensional convolution kernel with a length of 10.
[0070] In an exemplary embodiment, the network traffic features include any one or more combinations of connection time, protocol type, historical connection record, target host, service type, and traffic size. In this embodiment, all traffic passing through the client network card is collected based on Netfilter, and the extracted traffic features include any one or more combinations of connection time, protocol type, historical connection record, target host, service type, and traffic size.
[0071] In an exemplary embodiment, the step S02, the flow chart is as follows Figure 3 As shown, including:
[0072] Step S021, calculating the direct feature correlation degree according to the connection time matching degree and / or the protocol type matching degree of the network traffic;
[0073] Step S022: Calculate the statistical feature correlation degree according to the correlation between the current connection and the connection records within the set historical time period;
[0074] Step S023: Calculate the attack traffic matching degree according to the direct feature correlation degree and / or the statistical feature correlation degree, identify the network traffic whose attack traffic matching degree is greater than the set threshold as attack traffic, and generate a traffic data set.
[0075] In an exemplary embodiment, the step S021, calculating the direct feature correlation based on the connection time matching degree and / or protocol type matching degree of the network traffic, is: calculating the direct feature correlation based on the positive correlation between the matching degree between the connection time of the network traffic and the attack occurrence time and the direct feature correlation; calculating the direct feature correlation based on the positive correlation between the matching degree between the protocol type of the network traffic and the attack type and the direct feature correlation; calculating the direct feature correlation based on the weighted sum or product of the matching degree between the connection time of the network traffic and the attack occurrence time and the matching degree between the protocol type of the network traffic and the attack type and the direct feature correlation, any one of which is represented by the variable d.
[0076] In an exemplary embodiment, the step S022, the flow chart is as follows Figure 4 As shown, including:
[0077] Step S0221, calculating the connection quantity correlation degree according to the number of connections with the same target host as the current connection in a set historical time period and / or the number of connections with the same service as the current connection in a set historical time period;
[0078] Step S0222: Calculate the connection type association degree according to the similarity between the current connection and the target host connected in the set historical time period and / or the similarity between the service type of the current connection and the connection in the set historical time period;
[0079] Step S0223, calculating the connection change correlation according to the flow change measurement value between the current connection and the connection in the set historical time period and / or the duration change measurement value between the current connection and the connection in the set historical time period;
[0080] Step S0224: Calculate the statistical feature correlation degree according to the positive correlation between the connection quantity correlation degree and / or the connection type correlation degree and / or the connection change correlation degree and the statistical feature correlation degree.
[0081] In this embodiment, the calculation of the connection quantity correlation degree based on the number of connections with the same target host currently connected in a set historical time period (set as the past two seconds in this embodiment) and / or the number of connections with the same service currently connected in a set historical time period is: calculating the connection quantity correlation degree based on the positive correlation between the number of connections with the same target host currently connected in a set historical time period (or the ratio of the number of connections connected to the same target host to the total number of connections) and the connection quantity correlation degree, calculating the connection quantity correlation degree based on the positive correlation between the number of connections with the same service currently connected in a set historical time period (or the ratio of the number of connections connected to the same service to the total number of connections) and the connection quantity correlation degree, and any one of the positive correlations between the number of connections with the same target host currently connected in a set historical time period and the number of connections with the same service currently connected in a set historical time period and the connection quantity correlation degree, and the connection quantity correlation degree is represented by a variable e.
[0082] The calculation of the connection type association degree according to the similarity between the current connection and the target host connected in the set historical time period and / or the similarity between the current connection and the service type connected in the set historical time period is: the connection type association degree is calculated according to the positive correlation between the similarity between the current connection and the target host connected in the set historical time period (set as the past two seconds in this embodiment) (calculated according to the proportion of connections to the same target host and / or the positive correlation between the type association degree of the connected target host and the target host similarity) and the connection type association degree, and the similarity between the current connection and the service type connected in the set historical time period (set as the past two seconds in this embodiment) (calculated according to the proportion of connections to the same service type and / or the connection service type similarity). The connection type association degree is calculated based on the positive correlation between the association degree of the service type and the service type similarity) and the connection type association degree, the connection type association degree is calculated based on the positive correlation between the target host similarity (calculated based on the proportion of connections to the same target host and / or the positive correlation between the type association degree of the connected target host and the target host similarity) and the service type similarity (calculated based on the proportion of connections to the same service type and / or the positive correlation between the association degree of the connection service type and the service type similarity) and the connection type association degree, and the connection type association degree is represented by the variable w.
[0083] The calculation of the connection change correlation degree based on the flow change metric value between the current connection and the connection in the set historical time period and / or the duration change metric value between the current connection and the connection in the set historical time period is: the connection change correlation degree is calculated based on the positive correlation between the flow change metric value between the current connection and the connection in the set historical time period (the flow change metric value is the difference between the flow value of the current connection and the average flow value of the connection in the set time period and / or the average change amount of the flow value of the connection between the current connection and the set time period and / or the variance of the flow value of the connection between the current connection and the set time period and / or the flow value change extreme value of the flow value of the connection between the current connection and the set time period) and the connection change correlation degree, the connection change correlation degree is calculated based on the flow change metric value between the current connection and the connection in the set historical time period The connection change correlation degree is calculated based on the positive correlation between the connection duration change metric value (the duration change metric value is the difference between the duration of the current connection and the average duration of the connection within a set time period and / or the average change in the connection duration between the current connection and the set time period and / or the variance of the connection duration between the current connection and the set time period and / or the extreme value of the change in the connection duration between the current connection and the set time period) and the connection change correlation degree, and any one of the connection change correlation degrees is calculated based on the positive correlation between the flow change metric value of the current connection and the connection within a set historical time period and the duration change metric value of the current connection and the connection within a set historical time period and the connection change correlation degree, and the connection change correlation degree is represented by the variable y.
[0084] The calculation of the statistical feature correlation degree based on the positive correlation between the connection quantity correlation degree and / or the connection type correlation degree and / or the connection change correlation degree and the statistical feature correlation degree is performed according to any implementation method described in Table A below, and the statistical feature correlation degree is represented by the variable x.
[0085] A1 to A7 in Table A represent different implementation methods for calculating statistical feature correlations. For ease of expression, the statistical feature correlation x in Table A represents the statistical feature correlation between a third-party library and a vulnerability library. The connection quantity correlation e, connection type correlation w, and connection change correlation y are calculated using the methods described in any of the above implementation methods.
[0086] Table A Different implementation methods for calculating the correlation of statistical features
[0087]
[0088]
[0089]
[0090]
[0091]
[0092]
[0093]
[0094]
[0095] In an exemplary embodiment, the step S023 comprises the steps of:
[0096] The direct feature correlation degree d is calculated according to the method described in any of the above implementations, and the statistical feature correlation degree x is calculated according to the method described in any of the implementations in Table A, and the attack traffic matching degree z=u1·d is calculated according to the positive correlation between the direct feature correlation degree d and / or the statistical feature correlation degree x and the attack traffic matching degree. u 2+u3·x u4 +u5 or z = u6·d u7 ·x u5 +u9, where u1, u2 (u2>0), u3, u4 (u4>0), u5, u6, u7 (u7>0), u8 (u8>0), and u9 are calculation coefficients obtained by prior training;
[0097] The attack traffic matching threshold is set as Z in advance, and the network traffic with attack traffic matching degree greater than the set threshold is identified as attack traffic, generating a traffic data set, recorded as X k .
[0098] In an exemplary embodiment, the client performs preprocessing on the marked traffic data set, including calculating the mean of the data set, calculating the data volume of the data set, calculating the variance of the data set, calculating the maximum instantaneous change of the data set, calculating the minimum instantaneous change of the data set, and calculating any one or a combination of the data convergence evaluation value of the data set. In this embodiment, the data volume, mean and variance of the data set are used as examples to represent the distribution information of the data set, and the sample data volume n of the data set is calculated. k , mean μ k and variance σ k , as the distribution information of the data set; and the distribution information of the data set (μ n ,μ k ,σ k ) is sent to a central server based on HTTP.
[0099] In an exemplary embodiment, the step S04, the flow chart is as follows Figure 5 As shown, including:
[0100] Step S041: The central server receives the pre-processed traffic data set information from each client based on HTTP;
[0101] Step S042: the central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the data information of each client to obtain global data set information;
[0102] Step S043, training the global model according to the global data set information and saving the obtained global model structure parameters into an array;
[0103] Step S044: Send the structural parameter array matrix of the global model to each client simultaneously based on HTTP.
[0104] In this embodiment, the central server receives the data set distribution information of each client based on HTTP (n k ,μ k ,σ k ).
[0105] The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the data information of each client to obtain global data set information. The mean fusion is to calculate the data set distribution information of each client (n k ,μ k ,σ k ) to obtain the distribution information of the global data set (μ G ,σ G ); The extreme value fusion is the data set distribution information of each client (n k ,μ k ,σ k ) to obtain the distribution information of the global data set (μ G ,σ G ); The maximum confidence fusion is based on the different confidence weights of different clients (pre-set according to the location, type, historical attack times and other information of the client) to the distribution information of the data set of each client (n k ,μ k ,σ k ) is weighted averaged to obtain the distribution information of the global data set (μ G ,σ G ). In the central server, according to the distribution information of the fused global dataset (μ G ,v G ) for the CNN global model f G (w k ) to initialize and save the structural parameters of the global model to an array.
[0106] The initialized global model is expressed as formula (1):
[0107]
[0108] Among them, the structural parameters of the global model are expressed as
[0109] In step S044, the central server constructs a matrix of the structural parameter array of the global model and sends it to each client simultaneously based on HTTP.
[0110] In an exemplary embodiment, the step S05, the flow chart is as follows Figure 6 As shown, the steps include:
[0111] Step S051: The client receives the structural parameter array of the global model sent by the central server based on HTTP;
[0112] Step S052: The local model of the client synchronizes the structural parameters of the global model;
[0113] Step S053: input the traffic data set on the client into the local model to train the local model;
[0114] Step S054: The client sends the trained local model structure parameters to the central server based on HTTP;
[0115] Step S055: The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the structural parameters of each local model and uses this to train the global model to obtain the structural parameters of the global model;
[0116] Step S056: Repeat the above steps until the specified number of model iterations is reached to complete the training of the local model.
[0117] In this embodiment, at the kth client, the structural parameter array of the global model sent by the central server is received based on HTTP. Then, the CNN local model synchronizes the structural parameters of the global model and then converts the dataset X k , input to the CNN local detection model, train the local model, and get the local model as f k (w k ) ; Parameters w of the local model k Save to data.
[0118] When the local model training is completed on each client, the structural parameters of the local model are sent to the central server based on HTTP.
[0119] The central server receives the local model structure parameters w from each client based on HTTP. k; Then, the local models of each client received are subjected to mean fusion and / or extreme value fusion and / or maximum confidence fusion and used to train the global model to obtain the structural parameters of the global model, and the structural parameters of the global model are saved in an array;
[0120] In the central server, the fused global model is expressed as formula (2):
[0121]
[0122] Among them, the structural parameters of the global model are expressed as w G .
[0123] Repeat steps (7)-(14) and the number of model parameter iterations of the central server and the client is 200. The aggregation model training of the central server is completed and the trained aggregation model parameter array w is converted to G Based on HTTP, the client's CNN local model synchronizes the structural parameters w of the global model. G , complete the training of the local model.
[0124] In step S06, after the unknown traffic data is input into the trained local model, the attack traffic in the unknown traffic data is determined, and an alarm is issued if attack traffic is detected.
[0125] The KDDCUP99 dataset was used as the experimental verification dataset to verify the detection method proposed in this embodiment. The number of clients is 5, and the dataset on each client is sampled from the overall dataset according to Laplace. After 200 iterations of the central server and client model parameters, the central server was finally synchronized to each client, and the accuracy of traffic attack detection for each client exceeded 95%, and the overall detection accuracy reached 97%.
[0126] A network traffic attack detection system based on federated learning according to an embodiment of the present invention is shown in the structural diagram as follows: Figure 7 As shown, including:
[0127] Central server;
[0128] Client processor;
[0129] Memory;
[0130] as well as
[0131] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the central server and / or client processor, the programs causing the computer to perform the above method.
[0132] Of course, those skilled in the art should realize that the above embodiments are only used to illustrate the present invention, and are not intended to limit the present invention. As long as they are within the scope of the present invention, any changes or modifications to the above embodiments will fall within the protection scope of the present invention.
Claims
1. A network traffic attack detection method based on federated learning, It is characterized in that include: Build a global model for traffic attack detection on the central server and a local model for traffic attack detection on the client; The client identifies attack traffic based on network traffic characteristics and generates a traffic data set; The client identifies attack traffic according to network traffic characteristics and identifies and generates a traffic data set, including the steps of: calculating a direct feature correlation degree according to a connection time matching degree and / or a protocol type matching degree of the network traffic; calculating a statistical feature correlation degree according to a correlation between a current connection and a connection record within a set historical time period; calculating an attack traffic matching degree according to the direct feature correlation degree and / or the statistical feature correlation degree, identifying network traffic with an attack traffic matching degree greater than a set threshold as attack traffic, and generating a traffic data set; The method of calculating the statistical feature correlation degree according to the correlation between the current connection and the connection records in the set historical time period includes the following steps: calculating the connection quantity correlation degree according to the number of connections with the same target host as the current connection in the set historical time period and / or the number of connections with the same service as the current connection in the set historical time period; calculating the connection type correlation degree according to the similarity between the current connection and the target host connected in the set historical time period and / or the similarity between the current connection and the service type connected in the set historical time period; calculating the connection change correlation degree according to the flow change measurement value between the current connection and the connection in the set historical time period and / or the duration change measurement value between the current connection and the connection in the set historical time period; calculating the statistical feature correlation degree according to the positive correlation between the connection quantity correlation degree and / or the connection type correlation degree and / or the connection change correlation degree and the statistical feature correlation degree; The client preprocesses the identified traffic data set and sends it to the central server; The client performs preprocessing on the marked traffic data set, including calculating any one or a combination of the mean of the data set, the amount of data in the data set, the variance of the data set, the maximum instantaneous change of the data set, the minimum instantaneous change of the data set, and the data convergence evaluation value of the data set; The central server trains the global model based on the preprocessed traffic dataset; The client synchronizes the structural parameters of the global model and trains the local model; Input unknown traffic data into the local model to determine attack traffic.
2. According to the network traffic attack detection method based on federated learning in claim 1, It is characterized in that The method of constructing a global model for flow attack detection on a central server and a local model for flow attack detection on a client comprises the following steps: Build a global model based on the CNN algorithm on the central server; Each local client builds a local detection model based on the CNN algorithm; the local model of the client has the same network structure as the global model of the central server.
3. According to the network traffic attack detection method based on federated learning in claim 2, It is characterized in that The network traffic characteristics include any one or a combination of connection time, protocol type, historical connection records, target host, service type, and traffic size.
4. According to the network traffic attack detection method based on federated learning in claim 1, It is characterized in that The central server trains the global model according to the preprocessed traffic data set, including the steps of: The central server receives the pre-processed traffic data set information from each client based on HTTP; The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the data information of each client to obtain global data set information; Train the global model according to the global data set information and save the obtained global model structure parameters into an array; The structural parameter array matrix of the global model is sent to each client simultaneously based on HTTP.
5. The network traffic attack detection method based on federated learning according to claim 1, It is characterized in that The client synchronizes the structural parameters of the global model and trains the local model, including the steps of: The client receives the structure parameter array of the global model sent by the central server based on HTTP; The client's local model synchronizes the structural parameters of the global model; The traffic data set on the client is input into the local model to train the local model; The client sends the trained local model structure parameters to the central server based on HTTP; The central server performs mean fusion and / or extreme value fusion and / or maximum confidence fusion on the structural parameters of each local model and uses this to train the global model to obtain the structural parameters of the global model; Repeat the above steps until the specified number of model iterations is reached to complete the training of the local model.
6. A computer-readable storage medium storing a computer program for electronic data exchange, in, The computer program enables a computer to execute the method according to any one of claims 1 to 5.
7. A network traffic attack detection system based on federated learning, Features include: Central server; Client processor; Memory; as well as One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by the central server and / or client processor, the programs causing a computer to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Network threat collaborative defense system and method based on information sharing
CN112217626A