An Intrusion Detection Method Based on Deep Learning in a Software-Defined Network Environment

By using an adaptive polling mechanism to obtain network traffic information in the SDN environment and building a SAE-GRU model for traffic detection, the problems of low intrusion detection efficiency and high misjudgment rate in the existing technology are solved, and efficient and automated network intrusion detection and protection are achieved.

CN116260616BActive Publication Date: 2025-05-27CHONGQING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211655516.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-21
Publication Date
2025-05-27
Estimated Expiration
2042-12-21

AI Technical Summary

Technical Problem

The prior art is difficult to achieve efficient and stable intrusion detection in a software-defined network (SDN) environment. The traditional polling mechanism acquires network information in a timely manner and has too heavy load. The existing intrusion detection scheme has high misjudgment rate, difficult feature selection, long training time and insufficient samples.

Method used

A deep learning-based intrusion detection method is proposed, which obtains network traffic information through an adaptive polling mechanism between the controller and the OpenFlow switch, and constructs a SAE-GRU model to perform feature extraction and classification detection of traffic data.

Benefits of technology

Real-time monitoring and abnormal detection of network traffic in the SDN environment is realized, the error judgment rate and feature selection difficulty are reduced, detection efficiency and recognition rate are improved, malicious traffic can be automatically identified and filtered, and network security can be effectively protected.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116260616B_ABST
    Figure CN116260616B_ABST
Patent Text Reader

Abstract

The present invention claims protection for an intrusion detection method based on deep learning in an SDN (Software-Defined Network) environment. For the traffic information flowing through the SDN network, the controller polls the flow table in the switch at a fixed rate to statistically analyze the traffic information. However, if the polling time is too long, it will lead to the inability to obtain network traffic information in a timely manner, thereby affecting the judgment of network intrusion detection. If the time is too short, it will cause an excessive load on the controller. The present invention proposes an adaptive network traffic sampling method based on the change of Renyientropy (Renyi entropy) of the source IP address for collecting traffic data in the SDN network. For intrusion detection, an intrusion detection model combining SAE-GRU (Sparse Autoencoder-Gated Recurrent Unit Neural Network) is proposed to identify abnormal network traffic. When the traffic is determined to be abnormal traffic, the controller issues a flow table to discard the abnormal traffic. The present invention can collect SDN network traffic information more real-time and accurately and identify abnormal traffic in the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of intrusion detection in software-defined networks, and particularly relates to an intrusion detection method based on deep learning in a software-defined network environment. Background Art

[0002] Facing network security threats, the attack methods of traditional networks are still effective against SDN, and the centralized characteristics of the SDN architecture introduce new fault points and attack surfaces, making it more likely to become the target of attackers. Facing these challenges, the research on efficient and stable intrusion detection and defense mechanisms has very important value and significance. At present, the SDN controller polling mechanism obtains network information at fixed time intervals for global monitoring and supervision of the entire network. However, with a fixed polling frequency, the controller cannot obtain real-time network information in a timely manner. If it is too frequent, it will cause an excessive load on the controller and the communication link; in response to this situation, a method for obtaining real-time network traffic information by means of an adaptive polling mechanism is designed.

[0003] On the other hand, current intrusion detection schemes are generally divided into three categories: 1. Statistic-based detection schemes, which mainly judge whether there is an anomaly by statistically analyzing some information in the traffic, such as information entropy. However, this method has a high false positive rate and cannot effectively identify abnormal traffic. 2. Machine learning-based detection schemes, and the main problems of this scheme are feature selection and detection accuracy. 3. Detection methods based on deep learning require a large number of training samples, and the training time is long. There is also the availability of the network intrusion model dataset, and the samples considered are not sufficient to cover application behaviors. Based on the above problems, an intrusion detection method based on deep learning in an SDN environment is designed in this paper. Summary of the Invention

[0004] The present invention aims to solve the above problems of the prior art. An intrusion detection method based on deep learning in a software-defined network environment is proposed. The technical solution of the present invention is as follows:

[0005] An intrusion detection method based on deep learning in a software-defined network environment, which includes the following steps:

[0006] Step a, the controller polls the OpenFlow switch at an interval time t by sending an ofpt_multipart_request (OpenFlow message type - multipart request) message, and the OpenFlow switch returns the designed statistical information in the flow table to the traffic information collection module of the controller through an ofpt_multipart_reply (OpenFlow message type - multipart response) message for collection and processing;

[0007] Step b: Based on the data collected by the controller's traffic information acquisition module, count the number of source IP addresses and calculate the Renyi entropy per unit time. When the entropy value exceeds the threshold, reduce the polling interval time t to accelerate the extraction of flow table features; otherwise, increase the polling interval t value.

[0008] Step c: Construct an SAE-GRU (Sparse Autoencoder - Gated Recurrent Unit Neural Network) model. This model re-extracts data features through a sparse autoencoder to reduce the data dimension. The data after dimension reduction is classified and detected by the GRU gated recurrent unit deep neural network to determine whether it is intrusion traffic; the data with annotations is input into this model for training, and the best model is obtained after training. The model is imported into the controller to achieve real-time monitoring of network traffic anomalies and to detect whether there are network attacks in real time.

[0009] Step d: The controller detection module loads the weights of the best model obtained after training to determine whether the real-time network traffic is abnormal attack traffic; the controller issues a flow table for abnormal data packet information, causing the switch to discard the data, and normal traffic data packets are released normally.

[0010] Furthermore, in step a, the traffic information acquisition module in the controller obtains information including the average number of packets in the flow table, the rate of a single flow, and the source IP rate through packets. Among them,

[0011] Average number of packets in the flow table:

[0012]

[0013] In the formula, S packet_num represents the total number of packets within the period T, and S flow_num represents the total number of flows within the period T;

[0014] Calculation formula for the rate of a single flow:

[0015]

[0016] In the formula, b n is the value of the byte_count field in the Flow_Stats_Reply message during the nth polling, representing the number of bytes that have been processed by this flow table so far. t n represents the time that the current flow table has existed, and V n is the rate of a single flow within the interval between two pollings.

[0017] Calculation formula for the source IP speed:

[0018]

[0019] Where c n is the number of source IP values during the nth polling, representing the number of source IPs that have been processed by this flow table so far, and t n represents the time that the current flow table has existed.

[0020] Furthermore, the formula for calculating the α-order Renyi entropy of the source IP addresses within the calculation window in step b is:

[0021]

[0022] Where n represents that there are n possible values, x is a discrete random variable with one of the possible results, and p i is the probability of the random variable x, satisfying p i ≥0, α≥0, α≠1;

[0023] When the network Renyi entropy value does not exceed the threshold within a certain period of time, gradually restore and expand the controller polling interval, and slow down the feature extraction speed;

[0024] t n = max(t n-1 *n, 1) #(5)

[0025] Where n represents the multiple of the threshold, t n-1 represents the polling time of the previous round, and t n represents the current polling time.

[0026] Furthermore, in step c, use the SAE-GRU model to process the data input into the sparse autoencoder:

[0027] H(x) = σ(Wx + b) #(6)

[0028] Y = σ(W’H + b’) #(7)

[0029] Where x represents the original features of the network dataset. W ∈ R (the set of real numbers) is the weight matrix of the encoding layer, b ∈ R (the set of real numbers) represents the bias vector of the encoding layer; σ represents the sigmoid activation function, and then the constructed features are decoded through formula (7), W’ represents the weight matrix of the decoding layer, b’ represents the bias vector of the decoding layer, and finally Y is obtained, representing the reconstructed features;

[0030] Train the sparse autoencoder, optimize the four parameters in the sparse autoencoder, and the autoencoder judges whether the training result is accurate through the difference between the output and the input of the neural network, and use the L2 norm loss function to train it, that is:

[0031]

[0032] In the formula: m represents the number of input samples, λ is the L2 regularization coefficient, which is used to reduce the magnitude of the weights to prevent overfitting; the first term is the mean of the sum of squared errors, the second term is the regularization term or weight decay term, W is the weight matrix of the encoding layer, and W’ represents the weight matrix of the decoding layer. The performance of the sparse autoencoder in SAE-GRU is mainly determined by the number of hidden layers, the number of units, and the sparsity constant; different sparse autoencoders are trained by using the enumeration method to select parameters to achieve the best performance.

[0033] Further, in step c, the autoencoded data is used as the input of the SAE-GRU classification model;

[0034] R t = σ(W r X t + H t-1 W r + b r ) #(9)

[0035] Z t = σ(W z X t + H t-1 W Z + b z ) #(10)

[0036]

[0037] In the formula, Z t , r t respectively represent the update gate and the weight gate, H t represents the memory, represents the candidate set; W z , W r , W h are weight matrices; b r , b z , b n are the corresponding bias vectors; σ is the sigmoid function; tanh is the activation function; H t is the output at time t.

[0038] The stochastic gradient descent method SGD is used as the optimizer to determine the convergence direction, and the cross-entropy is used as the loss function for model training to calculate the update error.

[0039] Further, in step d, the controller detection module loads the best model weights obtained after training, and determines whether the real-time network traffic is abnormal attack traffic. The controller issues a flow table to the switch for the IP address determined to be abnormal traffic. When the switch receives the flow table, it will match the IP address and discard the abnormal data. The advantages and beneficial effects of the present invention are as follows:

[0040] In view of the problem of network intrusion detection in the SDN network environment, the present invention proposes an adaptive network traffic sampling method based on the change of Renyi entropy of the source IP address, which is used to collect traffic data in the SDN network, so that the original fixed-interval sampling frequency can achieve adaptive sampling, so as to obtain network traffic information more timely and reduce the network traffic load. For intrusion detection, an intrusion detection model combining SAE-GRU (Sparse Autoencoder - Gated Recurrent Unit Neural Network) is proposed to identify abnormal network traffic. As an improvement, it is constructed by using the authoritative intrusion detection data sets recognized at home and abroad, which can cover the behaviors of the vast majority of current malicious application programs and has a good recognition rate. It solves the problem of manually analyzing network traffic and setting interception rules, and realizes the automatic detection of aggressive traffic in the network and filtering of malicious traffic.

[0041] The advantages of the present invention compared with the prior art are as follows: it solves the problem that the SDN controller fails to obtain network traffic data in a timely manner and realizes adaptive polling to obtain network data traffic; through the detection using the SAE-GRU model, it realizes the automatic detection of aggressive traffic in the network and filters according to the identified malicious traffic, and can effectively protect the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is an experimental flowchart of SDN network intrusion detection provided by the preferred embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0043] Next, the technical solutions in the embodiments of the present invention will be clearly and detailedly described in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.

[0044] The technical solution for the present invention to solve the above technical problems is as follows:

[0045] An intrusion detection method based on deep learning in a software-defined network environment of the present invention has the following specific real-time solutions:

[0046] Step a, the controller polls the OpenFlow switch at an interval of time t by sending an ofpt_multipart_request (OpenFlow message type - multipart request) message, and the OpenFlow switch returns the designed statistical information in the flow table to the traffic information collection module of the controller through an ofpt_multipart_reply (OpenFlow message type - multipart response) message for collection and processing.

[0047] Step b: Based on the data collected by the controller's traffic information acquisition module, count the number of source IP addresses and calculate the Renyi entropy per unit time. When the entropy value exceeds the threshold, reduce the polling interval time t to accelerate the extraction of flow table features; otherwise, increase the polling interval t value.

[0048] Step c: Construct an SAE-GRU (Sparse Autoencoder - Gated Recurrent Unit Neural Network) model. This model re-extracts data features through a sparse autoencoder to reduce the data dimension. The data after dimension reduction is classified and detected by the GRU gated recurrent unit deep neural network to determine whether it is intrusion traffic; the data with annotations is input into this model for training. After training, the best model is obtained, and the model is imported into the controller to achieve real-time monitoring of network traffic anomalies and to detect in real time whether there are network attacks.

[0049] Step d: The controller detection module loads the weights of the best model obtained after training and determines whether the real-time network traffic is abnormal attack traffic. The controller issues a flow table for abnormal data packet information, causing the switch to discard the data, and normally releasing the normal traffic data packets.

[0050] Furthermore, in step a, the traffic information acquisition module in the controller obtains information including the average number of packets in the flow table, the rate of a single flow, and the source IP rate through packets. Among them,

[0051] Average number of packets in the flow table:

[0052]

[0053] In the formula, S packet_num represents the total number of packets within the period T, and S flow_num represents the total number of flows within the period T;

[0054] Calculation formula for the rate of a single flow:

[0055]

[0056] In the formula, b n is the value of the byte_count field in the Flow_Stats_Reply message during the nth polling, representing the number of bytes that have been processed by this flow table so far. t n represents the time that the current flow table has existed, and V n is the rate of a single flow within the interval between two pollings.

[0057] Calculation formula for the source IP speed:

[0058]

[0059] where c n is the number of source IP values during the nth polling, representing the number of source IPs that have been processed by this flow table so far, and t n represents the time that the current flow table has existed.

[0060] In the step b, the formula for calculating the α-order Renyi entropy of the source IP addresses within the window is:

[0061]

[0062] where n represents that there are n possible values, x is a discrete random variable with one of the possible outcomes, and p i is the probability of the random variable x, satisfying p i ≥0, α≥0, α≠1;

[0063] When the network Renyi entropy value does not exceed the threshold within a certain period of time, gradually restore and expand the polling interval of the controller, and slow down the feature extraction speed;

[0064] t n = max(t n-1 *n, 1) #(5)

[0065] where n represents the multiple of the threshold, and t n represents the polling time of the previous round.

[0066] In the step c, use the SAE-GRU model to process the data input into the sparse autoencoder:

[0067] H(x) = σ(Wx + b) #(6)

[0068] Y = σ(W’H + b’) #(7)

[0069] where x represents the original features of the network dataset. W ∈ R (the set of real numbers) is the weight matrix of the encoding layer, b ∈ R (the set of real numbers) represents the bias vector of the encoding layer; σ represents the sigmoid activation function, and then the constructed features are decoded through formula (7), W’ represents the weight matrix of the decoding layer, b’ represents the bias vector of the decoding layer, and finally Y is obtained, representing the reconstructed features;

[0070] Train the sparse autoencoder, optimize the four parameters in the sparse autoencoder, and the autoencoder judges whether the training result is accurate through the difference between the output and the input of the neural network, and use the L2 norm loss function to train it, that is:

[0071]

[0072] Where: m represents the number of input samples, λ is the L2 regularization coefficient, which is used to reduce the magnitude of the weights to prevent overfitting; the first term is the mean of the sum of squared errors, the second term is the regularization term or weight decay term, W is the weight matrix of the encoding layer, and W’ represents the weight matrix of the decoding layer. The performance of the sparse autoencoder in SAE-GRU is mainly determined by the number of hidden layers, the number of units, and the sparsity constant; different sparse autoencoders are trained by using the enumeration method to select parameters to achieve the best performance.

[0073] Use the autoencoded data as the input of the SAE-GRU classification model;

[0074] R t = σ(W r X t + H t-1 W r + b r )#(9)

[0075] Z t = σ(W z X t + H t-1 W Z + b z )#(10)

[0076]

[0077] Where, Z t 、r t represent the update gate and the weight gate respectively, H t represents the memory, represents the candidate set; W z 、W r 、W h are weight matrices; b r 、b z 、b n are the corresponding bias vectors; σ is the sigmoid function; tanh is the activation function; H t is the output at time t.

[0078] Use the Stochastic Gradient Descent (SGD) method as the optimizer to determine the convergence direction, and use the Cross-Entropy as the loss function for model training to calculate the update error.

[0079] In the step d, based on the above classification algorithm, the controller detection module loads the best model weights obtained after training, and determines whether the real-time network traffic is abnormal attack traffic. The controller issues a flow table to the switch for the IP address determined to be abnormal traffic. When the switch receives the flow table, it will match the IP address and discard the abnormal data.

[0080] The systems, devices, modules or units illustrated in the above embodiments may be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0081] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.

[0082] The above embodiments should be understood as being only for illustrative purposes of the present invention and not for limiting the protection scope of the present invention. After reading the content described in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.

Claims

1. A deep learning-based intrusion detection method in a software-defined network environment. It is characterized in that The following steps are involved: Step a, the controller polls the OpenFlow switch by sending ofpt_multipart_request (openflow message type_multipart request) messages at intervals t, and the OpenFlow switch returns the designed statistical information in the flow table to the flow information collection module of the controller through ofpt_multipart_reply (openflow message type_multipart response) messages for collection and processing; Step b, using the data collected by the controller traffic information collection module, counting the number of source IP addresses and calculating the Renyi entropy per unit time, when the entropy value exceeds the threshold, reducing the polling interval t to speed up the extraction of flow table features; otherwise, increasing the polling interval t value; Step c, constructing a SAE-GRU sparse autoencoder-recurrent gate unit neural network model, which re-extracts data features through a sparse autoencoder, reduces the data dimension, and classifies and detects the reduced-dimensional data through a GRU recurrent gate unit deep neural network to determine whether it is intrusion traffic; inputting the labeled data into the model for training, obtaining the best model after training, and importing the model into the controller to realize real-time monitoring of network traffic anomalies and detect whether there is a network attack in real time; Step d, the controller detection module loads the best model weight obtained after training, and determines whether the real-time network traffic is abnormal attack traffic; The controller sends a flow table for abnormal data message information, so that the switch discards the data and allows normal traffic data messages to pass normally.

2. According to claim 1, a deep learning-based intrusion detection method in a software-defined network environment, It is characterized in that In step a, the flow information collection module in the controller obtains information including the average number of packets in the flow table, the rate of a single flow, and the source IP rate through the message, wherein: Average number of packets in flow table: Where S packet_num represents the total number of packets within the period T, and S flow_num represents the total number of flows within the period T; The rate calculation formula for a single flow is: Wherein, b n is the value of the byte_count field in the Flow_Stats_Reply flow table statistics reply message during the nth polling, representing the number of bytes that have been processed by this flow table so far. t n represents the time that the current flow table has existed. V n is the rate of a single flow within the polling interval between two polls; Source IP speed calculation formula: where c n is the number of source IP values during the nth polling, representing the number of source IPs that have been processed by this flow table so far, and t n represents the time that the current flow table has existed.

3. According to claim 1, a deep learning-based intrusion detection method in a software-defined network environment, It is characterized in that The formula for calculating the α-order Renyi entropy of the source IP address in the window in step b is: Wherein, n represents that there are n values, x is a discrete random variable with possible results, and p i is the probability of the random variable x, satisfying p i ≥0, α≥0, α≠1; When the network renyi entropy value does not exceed the threshold for a certain period of time, the controller polling interval is gradually restored to slow down the feature extraction speed; t n = max(t n-1 * n, 1) #(5) In the formula, n represents the multiple of the threshold, and t n-1 represents the polling time of the previous round, and t n represents the current polling time.

4. According to claim 1, a deep learning-based intrusion detection method in a software-defined network environment, It is characterized in that In step c, the SAE-GRU model is used to process the sparse autoencoder of the data input: H(x)=σ(Wx+b)#(6) Y=σ(W'H+b')#(7) Wherein, x represents the original features of the network dataset; W ∈ R (the set of real numbers) is the weight matrix of the encoding layer, and b ∈ R (the set of real numbers) represents the bias vector of the encoding layer; σ represents the sigmoid activation function, and then the constructed features are decoded through formula (7). W' represents the weight matrix of the decoding layer, and b' represents the bias vector of the decoding layer, and finally Y is obtained, representing the reconstructed features; The sparse autoencoder is trained to optimize the four parameters in the sparse autoencoder. The autoencoder judges whether the training result is accurate by the difference between the output and the input of the neural network, and uses the L2 norm loss function to train it, that is: Where: m represents the number of input samples, and λ is the L2 regularization coefficient, which is used to reduce the size of the weights to prevent overfitting; the first item is the mean of the sum of squared errors, the second item is the regularization item or the weight decay item, W is the weight matrix of the encoding layer, and W' represents the weight matrix of the decoding layer. The performance of the sparse autoencoder in SEA-GRU is mainly determined by the number of hidden layers, the number of units, and the sparse constant; different sparse autoencoders are trained by using the enumeration method to select parameters to achieve the best performance.

5. A deep learning-based intrusion detection method in a software-defined network environment according to claim 4, characterized in that in the step c, the autoencoded data is used as the input of the SAE-GRU classification model; R t = σ(W r X t + H t-1 W r + b r )#(9) Z t = σ(W z X t + H t-1 W Z + b z )#(10) where, Z t , r t represent the update gate and the weight gate respectively, H t represents the memory, represents the candidate set; W z , W r , W h are weight matrices; b r , b z , b n are the corresponding bias vectors; σ is the sigmoid function; tanh is the activation function; H t is the output at time t; The stochastic gradient descent method SGD is used as the optimizer to determine the convergence direction, and the cross-entropy is used as the loss function for model training to calculate the update error.

6. A deep learning-based intrusion detection method in a software-defined network environment according to claim 5, characterized in that in the step d, the controller detection module loads the best model weights obtained after training, and judges whether the real-time network traffic is abnormal attack traffic; the controller issues a flow table to the switch for the IP address judged to be abnormal traffic. When the switch receives the flow table, it will match the IP address and discard the abnormal data.

Citation Information

Patent Citations

  • Deep convolutional network heterogeneous architecture

    CN108268941A

  • Reliability enhancements for multi-access traffic management

    US20220109622A1