Ensemble learning network intrusion detection method based on DHR architecture

Through the integrated learning network intrusion detection method of DHR architecture, the classifier's credibility is dynamically updated using heterogeneous sub-models and Bayesian decisions, solving the high performance and robustness of network traffic classifiers in complex scenarios, and achieving the improvement of high accuracy and adaptability.

CN116055169BActive Publication Date: 2025-09-02SOUTHEAST UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310035089.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-10
Publication Date
2025-09-02
Estimated Expiration
2043-01-10

AI Technical Summary

Technical Problem

Existing network traffic classifiers are difficult to maintain high performance and robustness in the face of complex attack scenarios, traditional defense strategies are difficult to migrate, and there are problems such as large computing overhead, relying on manual features and poor interpretability.

Method used

The integrated learning network intrusion detection method based on DHR architecture is adopted, and by building a variety of heterogeneous sub-models, combining Bayesian decision-making and model scheduling mechanisms, the confidence index of the basic classifier is dynamically updated to realize traffic feature extraction and redundant deployment of classifiers.

Benefits of technology

It improves the accuracy and robustness of attack detection in complex scenarios, enhances the system's adaptability and security, balances the weight of the classifier in fine-grainedness, and improves the sensitivity to intrusion behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116055169B_ABST
    Figure CN116055169B_ABST
Patent Text Reader

Abstract

This invention discloses an ensemble learning network intrusion detection method based on the DHR architecture, applied to malicious traffic classification and intrusion detection in cyberspace. The method includes the following steps: extracting effective statistical features from raw traffic data; constructing a model library containing multiple basic classifiers with different principles (i.e., heterogeneous structures); establishing an intrusion detection system through ensemble learning; integrating decisions using Bayesian theorem; and real-time monitoring of model status to guide scheduling. Compared with existing technologies, this method integrates multiple classification sub-models, balancing the weights of each basic classifier and sub-model at a fine-grained level, achieving high accuracy and robustness against unknown attacks in complex scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to an integrated learning network intrusion detection method based on a dynamic heterogeneous redundancy (DHR) architecture, and belongs to the technical field of information security. Background Art

[0002] With the rapid development and widespread adoption of the Internet of Things (IoT) and 5G, the scale and differentiation of cyberspace are becoming increasingly prominent, and the security threats they face are becoming increasingly severe. As a proactive and effective security protection strategy, intrusion detection technology monitors network traffic, identifies intrusions, and issues alerts. By collecting and cleaning raw network traffic and extracting features from it, intrusion detection systems classify network traffic as benign or malicious.

[0003] Currently, a large number of experts and scholars are conducting research on network traffic classification technologies. Traditional traffic classifiers are based on packet inspection, focusing on discovering patterns or keywords within packets that aid classification. In recent years, with the widespread application of machine learning and deep learning technologies in various fields, methods based on statistical or time series features have become a popular research direction in traffic classification. Machine learning methods focus on feature selection by domain experts, while deep learning methods can independently select features, thereby learning highly complex models.

[0004] However, traffic classifiers based on packet inspection are computationally expensive and inefficient; methods based on single machine learning rely too heavily on artificial feature extraction; and methods based on deep learning suffer from poor interpretability. More importantly, intrusion detection models face a wider range of unknown security threats in different scenarios, making traditional defense strategies difficult to migrate across. Therefore, developing attack-tolerant traffic classifiers—those that classify traffic in the presence of one or more attack types, ensuring high performance in complex attack scenarios—is a pressing challenge in this field.

[0005] The Dynamic Heterogeneous Redundancy (DHR) architecture constructs a universal model by combining multiple functionally equivalent, structurally distinct sub-models. Furthermore, some scholars have proposed that integrating multiple simple prediction models can achieve complexity and diversity to improve the generalization performance of classifiers on unobserved data. Therefore, to address the aforementioned issues and considering the advantages of DHR technology in defending against various cybersecurity threats (such as unknown vulnerabilities, backdoors, and Trojans), we construct DHR sub-models by integrating simple machine learning models. Furthermore, with the help of the DHR architecture, a more universal model is constructed from the integrated sub-models, enabling the universal model to achieve both high performance, robustness, and security. Summary of the Invention

[0006] Technical Problem: The present invention is dedicated to solving the problem of intrusion detection in the presence of data poisoning attacks or model attacks.

[0007] Technical solution: To solve the above problems, the present invention discloses a new algorithm for network intrusion detection and proposes an integrated learning network intrusion detection method based on the DHR architecture, which includes the following steps:

[0008] S1, traffic feature extraction: pre-process the original traffic data, extract and save effective statistical features, and use them as input to the intrusion detection system;

[0009] S2, model library construction;

[0010] S3, heterogeneous model integration: randomly extract several basic classifiers from the model library and integrate them to obtain a sub-model, and redundantly deploy multiple heterogeneous sub-models in the system;

[0011] S4, Bayesian decision: The input in S1 is copied and distributed to each basic classifier. Each basic classifier makes a decision independently, and the final output of each sub-model and system is obtained through Bayes theorem.

[0012] S5, model scheduling: monitor the operating status of the basic classifier and sub-model in real time, and replace them according to certain strategies.

[0013] As an improvement of the present invention, step S2 further includes:

[0014] S21, select a variety of basic classifiers with different principles to form a model library, including: neural network, gradient boosting tree, support vector machine, random forest, naive Bayes and other basic classifiers to form a model library;

[0015] S22, uses randomly sampled labeled traffic samples to pre-train several similar basic classifiers using the autonomous aggregation method;

[0016] S23, the accuracy rate obtained by cross-validation is used as the credibility index θ of the basic classifier.

[0017] As an improvement of the present invention, step S4 further includes:

[0018] S41, sub-model M i The probability that the classification result is benign is:

[0019]

[0020] Among them, 0 represents benign, 1 represents malignant, and y i For sub-model M i The classification result, Y i For sub-model Mi The set of output results of each basic classifier in .

[0021] S42, the probability that the classification result of system M is benign is:

[0022]

[0023] Among them, y is the classification result of system M, and Y is the set of output results of each sub-model in system M.

[0024] As an improvement of the present invention, step S5 further includes:

[0025] S51, using the time window T as the update interval of the credibility index θ, records the accuracy θ of the basic classifier within a time window T , then the updated Where λ is the proportional coefficient, λ∈(0,1].

[0026] S52, when the confidence index θ of the basic classifier decreases to the threshold θ th When (θ<θ th ), remove the basic classifier from the sub-model, and obtain a similar classifier with a credibility index higher than the threshold from the model library and add it to the sub-model.

[0027] S53, when all basic classifiers of the sub-model have undergone the replacement operation described in S52, the sub-model is removed from the system, and a number of basic classifiers of different categories are randomly selected from the model library to form a new sub-model and add it to the system.

[0028] As an improvement of the present invention, step S41 further includes:

[0029] S411, P(y i =0) is the sub-model M i The proportion of benign cases in the results of the basic classifier;

[0030] S412, P(Y i |y i =0) is the probability that the basic classifier obtains the current output result when the traffic is benign. The probability that each basic classifier obtains the correct output is its credibility index θ. Since the basic classifiers in the sub-model are independent of each other, we get Y i The probability of is the product of the probabilities of obtaining the output of each basic classifier.

[0031] As an improvement of the present invention, step S42 further includes:

[0032] S421, P(y=0) is the proportion of the results of the submodel of system M that are judged to be benign;

[0033] In step S422, P(Y|y=0) is the probability that the submodel will obtain the current output when the traffic is benign. The probability of each submodel obtaining the correct output is the weighted average of the confidence indicators θ of the included basic classifiers. Under heterogeneous conditions, the probability of obtaining Y is the product of the probabilities of obtaining the output of each submodel.

[0034] Beneficial effects: Compared with the existing technology, the present invention proposes an integrated learning network intrusion detection method based on the DHR architecture, which integrates multiple classification sub-models and still has high accuracy and robustness in the face of unknown attacks in complex scenarios; it takes into account the credibility of each basic classifier and uses Bayesian theorem to make decisions, and balances the weights of each basic classifier and sub-model in a fine-grained manner, is sensitive to intrusion behavior, and enhances the security of the system; the credibility of the basic classifier is regularly updated to improve the adaptive ability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 This is a framework diagram of the method of the present invention. DETAILED DESCRIPTION

[0036] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.

[0037] Example 1: See Figure 1 , an integrated learning network intrusion detection method based on DHR architecture, comprising the following steps:

[0038] S1, Traffic Feature Extraction: Preprocess the raw traffic data to extract and save valid statistical features, which are used as input to the intrusion detection system. Valid statistical features are those that can be recognized by the classifier and reflect the properties of the traffic itself. These may include average packet length, minimum arrival time, etc.

[0039] S2, model library construction: select basic classifiers such as neural network, gradient boosting tree, support vector machine, random forest, naive Bayes, etc. to form the model library. The specific steps are as follows:

[0040] S21, select a variety of basic classifiers with different principles to form a model library, including but not limited to: neural network, gradient boosting tree, support vector machine, random forest, naive Bayes, etc. The selection of different types of basic classifiers should follow different principles to achieve heterogeneity.

[0041] S22, use randomly sampled labeled traffic samples to pre-train several similar basic classifiers using the autonomous aggregation method. Specifically, for each classifier, several classifiers with different parameters should be trained for sub-model replacement in the system.

[0042] S23, the accuracy rate obtained by cross-validation is used as the credibility index θ of the basic classifier. At the same time, the initial credibility index θ of the newly trained basic classifier should also satisfy θ≥θ th .

[0043] S3, heterogeneous model integration: randomly extract several basic classifiers from the model library and integrate them to obtain a sub-model, and redundantly deploy multiple heterogeneous sub-models in the system. The system structure is as follows Figure 1 As shown in Figure 3, the intrusion detection system consists of several sub-models, and each sub-model consists of several basic classifiers.

[0044] S4, Bayesian decision: The input in S1 is copied and distributed to each basic classifier. Each basic classifier makes a decision independently. The final output of each sub-model and system is obtained through Bayes' theorem. The specific steps are as follows:

[0045] S41, sub-model M i The probability that the classification result is benign is:

[0046]

[0047] Among them, 0 represents benign, 1 represents malignant, and y i For sub-model M i The classification result, Y i For sub-model M i The set of output results of each basic classifier in .

[0048] S411, P(y i =0) is the sub-model M i The proportion of benign cases among the results of the basic classifier is the prior probability that the classification result is benign.

[0049] S412, P(Y i |y i =0) is the probability that the basic classifier obtains the current output result when the traffic is benign, that is, the likelihood value. The probability that each basic classifier obtains the correct output is its credibility index θ. Since the basic classifiers in the sub-model are independent of each other, we get Y i The probability of is the product of the probabilities of obtaining the output of each basic classifier.

[0050] S42, the probability that the classification result of system M is benign is:

[0051]

[0052] Among them, y is the classification result of system M, and Y is the set of output results of each sub-model in system M.

[0053] S421, P(y=0) is the proportion of the results of the submodel of system M that are judged to be benign;

[0054] In step S422, P(Y|y=0) is the probability that the submodel will obtain the current output when the traffic is benign. The probability of each submodel obtaining the correct output is the weighted average of the confidence indicators θ of the included basic classifiers. Under heterogeneous conditions, the probability of obtaining Y is the product of the probabilities of obtaining the output of each submodel.

[0055] S5, model scheduling: monitor the running status of the basic classifier and sub-model in real time and replace them according to a certain strategy. The specific steps are as follows:

[0056] S51, using the time window T as the update interval of the credibility index θ, records the accuracy θ of the basic classifier within a time window T , then the updated Where λ is the proportional coefficient, λ∈(0,1]. The value of the proportional coefficient λ reflects the administrator's emphasis on historical time window information and current time window information. The larger λ is, the more the system pays attention to the model with higher accuracy in historical judgment and has stronger robustness; conversely, the smaller λ is, the more the system pays attention to the accuracy in the current time window, that is, the more adaptable it is.

[0057] S52, when the confidence index θ of the basic classifier decreases to the threshold θ th When (θ<θ th ), remove the base classifier from the sub-model, and obtain a similar classifier from the model library with a credibility index above the threshold and add it to the sub-model. The purpose of updating the credibility index is to iteratively update the base classifier (updating the base classifier's parameters). This replacement gives the system dynamics, which is reflected in its diversity.

[0058] S53: After all base classifiers in a sub-model have been replaced as described in S52, the sub-model is removed from the system and a new sub-model is added to the system by randomly selecting several base classifiers of different categories from the model library. After all base classifiers in a sub-model have been replaced, replacing the sub-model (updating the base classifier categories) improves the dynamics of the current system in another dimension, manifesting in complexity.

[0059] It should be noted that the above embodiments are not intended to limit the scope of protection of the present invention, and equivalent changes or substitutions made on the basis of the above technical solutions fall within the scope of protection of the claims of the present invention.

Claims

1. An integrated learning network intrusion detection method based on DHR architecture, characterized in that: The method comprises the following steps: S1, traffic feature extraction: pre-process the original traffic data, extract and save effective statistical features, and use them as input to the intrusion detection system; S2, model library construction; S3, heterogeneous model integration: randomly extract several basic classifiers from the model library and integrate them to obtain a sub-model, and redundantly deploy multiple heterogeneous sub-models in the system; S4, Bayesian decision: The input in S1 is copied and distributed to each basic classifier. Each basic classifier makes a decision independently, and the final output of each sub-model and system is obtained through Bayes' theorem; S5, model scheduling: real-time monitoring of the operating status of the basic classifier and sub-model, and replacement based on a certain strategy; The step S5 further comprises: S51, using the time window T as the update interval of the credibility index θ, records the accuracy θ of the basic classifier within a time window T , then the updated Where λ is the proportional coefficient, λ∈(0,1], S52, when the confidence index θ of the basic classifier decreases to the threshold θ th When (θ<θ th ), remove the basic classifier from the sub-model, and obtain a similar classifier with a credibility index higher than the threshold from the model library and add it to the sub-model. S53, when all basic classifiers of the sub-model have undergone the replacement operation described in S52, the sub-model is removed from the system, and a number of basic classifiers of different categories are randomly selected from the model library to form a new sub-model and add it to the system.

2. The DHR architecture-based integrated learning network intrusion detection method according to claim 1, wherein: The step S2 further comprises: S21, select a variety of basic classifiers with different principles to form a model library, including: neural network, gradient boosting tree, support vector machine, random forest, and naive Bayes basic classifier to form a model library; S22, uses randomly sampled labeled traffic samples to pre-train several similar basic classifiers using the autonomous aggregation method; S23, the accuracy rate obtained by cross-validation is used as the credibility index θ of the basic classifier.

3. The DHR architecture-based integrated learning network intrusion detection method according to claim 1, wherein: The step S4 further comprises: S41, sub-model M i The probability that the classification result is benign is: Among them, 0 represents benign, 1 represents malignant, and y i For sub-model M i The classification result, Y i For sub-model M i The set of output results of each basic classifier in, S42, the probability that the classification result of system M is benign is: Among them, y is the classification result of system M, and Y is the set of output results of each sub-model in system M.

4. The method for network intrusion detection based on an integrated learning architecture of DHR according to claim 3, wherein: The step S41 further includes: S411, P(y i =0) is the sub-model M i The proportion of benign cases in the results of the basic classifier; S412, P(Y i |y i =0) is the probability that the basic classifier obtains the current output result when the traffic is benign. The probability that each basic classifier obtains the correct output is its credibility index θ. Since the basic classifiers in the sub-model are independent of each other, we get Y i The probability of is the product of the probabilities of obtaining the output of each basic classifier.

5. The DHR architecture-based integrated learning network intrusion detection method according to claim 3, wherein: The step S42 further includes: S421, P(y=0) is the proportion of the results of the submodel of system M that are judged to be benign; S422, P(Y|y=0) is the probability that the sub-model obtains the current output result when the traffic is benign. The probability of each sub-model obtaining the correct output is the weighted average of the credibility index θ of the basic classifier it contains. Under heterogeneous conditions, the probability of obtaining Y is the product of the probabilities of obtaining the output of each sub-model.

Citation Information

Patent Citations

  • Dual-mode intrusion detection device based on integrated machine learning algorithm

    CN110213287A

  • Power grid network intrusion event detection and identification method based on ensemble learning

    CN115277113A