Network security situation prediction method, system and application based on Tranformer-CNN model

By combining Transformer's attention mechanism and CNN convolutional operation, the problem of difficulty in achieving high accuracy, large calculation amount and long calculation time in the prior art is solved, and efficient and accurate network security situation prediction is achieved.

CN116346392BActive Publication Date: 2025-05-13STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211500470.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2025-05-13
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

The existing network security situation prediction methods are difficult to fully consider the timing relationship, which makes it difficult to achieve high-precision prediction, with large calculation amounts and long calculation time.

Method used

The network security situation prediction method based on the Transformer-CNN model is adopted, and the high-precision network security situation prediction is achieved through the combination of Transformer's attention mechanism and the convolutional operation of CNN.

Benefits of technology

It reduces the amount of calculation, shortens the calculation time, realizes high-precision network security situation prediction, and can effectively deal with the ever-changing attack methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346392B_ABST
    Figure CN116346392B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security situation prediction method, system and application based on a Tranformer-CNN model, and the method includes the following prediction steps: S11, obtaining network security situation data; S12, preprocessing the network security situation data, and constructing a real-time sample of the network security situation data; S13, inputting the real-time sample of the network security situation data into the Tranformer-CNN model, and outputting a prediction result after calculation; the Tranformer-CNN model includes a Transformer unit and a CNN unit, the Transformer unit calculates the network security situation data sample, and outputs the calculation to the CNN unit; the CNN unit calculates the key information extracted by the Transformer unit again, and outputs the prediction result. The present invention proposes a deep learning model based on an attention mechanism plus a convolutional neural network to process network security situation perception and prediction analysis with time series characteristics, which reduces the amount of calculation and shortens the calculation time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security situation prediction method and system based on a Tranformer-CNN model and applications thereof. Background Art

[0002] With the continuous development of network and information technology, people's security awareness has gradually improved. They no longer believe that the network is safe. On the contrary, people are more willing to believe that network attacks are inevitable and normalized. Since people cannot prevent attacks, it is particularly important to identify and discover attacks in advance.

[0003] At the same time, with the release of the National Cybersecurity Level Protection System 2.0, the security protection concept has shifted from the past passive defense to active protection and intelligent protection. There is an urgent need for intelligent network security situation awareness and prediction technologies that keep pace with the trend of the times.

[0004] In addition, the Internet of Things and cloud technology are developing at a rapid pace. Many disruptive new technologies have introduced many new security issues, and various network attack methods are emerging in an endless stream.

[0005] Existing network security situation prediction methods mainly include situation prediction methods based on discrete models, continuous models and common machine learning. Due to the temporal correlation between situation data and the long time series, existing network security situation prediction methods cannot fully consider these temporal relationships and achieve high-precision prediction.

[0006] In the problem of time series prediction, the widely used technologies at this stage are still mainly linear regression, ARMA, ARIMA and other linear models based on time features. Even LSTM, TCN and other artificial intelligence models have problems such as complex models, too many weights, and inability to focus when processing long sequences. At the same time, there are problems such as serious gradient information loss for long sequence samples. In addition, when the time span is large and the network is deep, the amount of calculation is large and the calculation is time-consuming. Summary of the invention

[0007] The purpose of the present invention is to provide a network security situation prediction method based on the Tranformer-CNN model, which adopts the Tranformer attention mechanism plus convolutional neural network to achieve high-precision prediction, reduce the amount of calculation, shorten the calculation time, and solve the problems of difficulty in achieving high-precision prediction, long calculation time and large amount of calculation in network security situation perception and prediction in the prior art.

[0008] The present invention is achieved through the following technical solutions:

[0009] The network security situation prediction method based on the Tranformer-CNN model includes the following prediction steps:

[0010] S11. Obtain network security situation data;

[0011] S12, pre-processing the network security situation data to construct a real-time sample of the network security situation data;

[0012] S13, inputting the real-time sample of network security situation data into the Tranformer-CNN model, performing calculations and outputting prediction results;

[0013] The Tranformer-CNN model includes a Transformer unit and a CNN unit. The Transformer unit operates on a network security situation data sample and outputs the operation result to the CNN unit; the CNN unit re-operates on the key information extracted by the Transformer unit and outputs the prediction result.

[0014] In some embodiments, the Tranformer-CNN model also includes a fully connected layer, and the prediction result output by the convolutional neural network CNN is also input into the fully connected layer for data integration and classification prediction before output.

[0015] In some embodiments, the method further comprises the following model training step before the prediction step:

[0016] S01. Acquisition of training data: Acquiring stored network security situation data or acquiring network security situation data through experiments;

[0017] S02, preprocessing the network security situation data obtained in step S01 to construct a network security situation data training sample;

[0018] S03. Use network security situation data training samples to train the Tranformer-CNN model.

[0019] In some embodiments, the preprocessing in step S02 and step S12 both include the following steps:

[0020] Data cleaning: Check the acquired network security situation data and correct abnormal data;

[0021] Data padding: Based on the maximum time T that a network attack takes, network security situation data that is less than T in length is padded with zeros to a length of T;

[0022] Masking and filling: Mask the data at the 0 position in the data filling step;

[0023] Position encoding: adding position vectors to the data.

[0024] In some embodiments, when step S01 extracts network security situation data through experiments, it includes the following steps:

[0025] S001. Determine the set of network attack methods (N) , N is the total number of means of network attack;

[0026] S002, Attack from the set (N) Select a network attack method that has not been selected before Attack n Let n be a fictitious number, where n is the number of the network attack method, n is a positive integer, and 1≤n≤N;

[0027] S003, record the nth network attack method Attack n The values ​​of the network state information variables at each unit time interval t in the time process T from the beginning to the completion of the attack j is the number of each state information variable;

[0028] S004, combined with the state information variables at time point t Calculate the network security situation score at time t J is the number of state information variables;

[0029] S005, the state information variable of the nth network attack method and Cybersecurity Posture Score Splice into samples

[0030] S006, determine the network attack means set Attack (N) The value of Attack n Whether all the items have been taken out, if not, return to step S002; otherwise, go to step S007;

[0031] S007. All samples Combined into a sample matrix X N×T .

[0032] In some embodiments, in the preprocessing of step S02, in the position encoding step, the sample matrix X N×T Each of When combined with the position vector, a network security situation data training sample is formed. The network security situation data training sample includes network security situation data and prediction labels, which are network security situation scores

[0033] In some embodiments, the network security situation data includes protocol type, network service, source IP and destination IP.

[0034] In some embodiments, the Multi-headAttention layer of the encoding component and the decoding component of the Transformer unit both have 8 self-attention heads.

[0035] Another object of the present invention is to provide a network security situation prediction system based on the Tranformer-CNN model, comprising:

[0036] Data acquisition unit: acquire network security situation data;

[0037] Data preprocessing unit: used to preprocess network security situation data and construct real-time samples of network security situation data;

[0038] A network security number prediction unit, including a Tranformer-CNN model, is used to receive real-time samples of network security situation data, calculate through the Tranformer-CNN model, and output prediction results;

[0039] The Tranformer-CNN model includes a Transformer unit, a CNN unit and a fully connected layer, wherein the CNN unit is connected to the decoding component of the Transformer unit, and the output of the CNN unit is connected to the fully connected layer;

[0040] The Transformer unit operates on the network security situation data sample and outputs the operation result to the CNN unit; the CNN unit re-operates on the key information extracted by the Transformer unit, and the operation result is output through the fully connected layer.

[0041] In some embodiments, the data preprocessing unit includes:

[0042] Data cleaning unit: checks the acquired network security situation data and corrects abnormal data;

[0043] Data filling unit: according to the longest time T that a network attack takes, network security situation data with a length less than T is padded with zeros to a length of T;

[0044] Shielding filling unit: masking the data at the 0-filled position in the data filling step;

[0045] Position encoding component: Add position vectors to the data.

[0046] In some embodiments, the network security situation prediction system based on the Tranformer-CNN model further includes a training sample construction unit for extracting network security situation data through experiments, and the training sample construction unit creates a set of network attack means Attack (N) All network attack methods in Attack n , N is the total number of network attack methods, n is the number of network attack methods, n is a positive integer, and 1≤n≤N; for each network attack method Attack n , record the values ​​of each network state information variable at each unit time interval t in the time process T from the beginning to the completion of the attack is the number of each state information variable; combined with each state information variable at time point t Calculate the network security situation score at time t The status information variables of each network attack method and Cybersecurity Posture Score Splice into samples All samples Combined into a sample matrix X N ×T , forming training samples for building network security situation data.

[0047] Another object of the present invention is to provide an application of the above-mentioned network security situation prediction system based on the Tranformer-CNN model, which is used to process network security situation data with long time series characteristics and predict network security situation.

[0048] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0049] The present invention proposes a deep learning model based on the attention mechanism plus a convolutional neural network to process network security situation awareness and predictive analysis with time series characteristics, which reduces the amount of calculation and shortens the calculation time. It can achieve active prediction and intelligent protection, effectively respond to ever-changing attack methods, and make correct decisions when facing new attack methods and unprecedented attack types.

[0050] The present invention adopts the Tranformer-CNN model, which integrates the advantages of Tranformer and CNN, highlights the main information, grasps the essential characteristics of the sample, and makes the model more generalizable. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative work. In the drawings:

[0052] Figure 1 An implementation method of using a network security situation prediction system based on a Tranformer-CNN model for a data acquisition system of a power grid;

[0053] Figure 2 This is a schematic diagram of the structure of the Transformers-CNN model;

[0054] Figure 3 Compute process intent for self-attention;

[0055] Figure 4 It is the forward propagation flow chart;

[0056] Figure 5 Schematic diagram of the connection between CNN and linear activation layer. DETAILED DESCRIPTION

[0057] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with embodiments and drawings. The exemplary embodiments of the present invention and their description are only used to explain the present invention and are not intended to limit the present invention.

[0058] [Example 1]

[0059] In this embodiment, a network security situation prediction method based on Tranformer-CNN first collects data, and collects various state information of the network during operation by burying data collectors, intelligent meters, manual collection, etc. in the network, so as to provide for subsequent model research and learning; secondly, data processing is performed. Since most of the collected data are in various forms and have diverse contents, it is necessary to pre-process the data (including data completion, data standardization, etc.); then the network data is divided into time series samples; finally, the data samples are integrated and passed into the model, and the network security situation is perceived and predicted based on the network status data and the comprehensive score. Each step is described in detail below.

[0060] Step 1: Data Collection

[0061] First, data extraction of network security situation is performed according to the following data collection model. The extraction method is as follows:

[0062] 1) Determine the various means of network attack (N) , N is the total number of means of network attack;

[0063] 2) From the set Attack (N) Select a network attack method Attack n Make a fictitious statement, n is the number of the network attack method, n = 1, 2, 3..., N;

[0064] 3) Record the nth network attack method Attack n The values ​​of the network state information variables at each unit time interval t in the time process T from the beginning to the completion of the attack j is the number of each state information variable;

[0065] 4) According to the network situation evaluation model, combined with the state information variables at time point t Calculate the network security situation score at time t J is the number of state information variables; in this step, the network situation evaluation model is mainly used for data labeling, that is, a predetermined labeling method is used to label the current data sample, and the labeling method is the network situation evaluation model. According to the labeling method, it can be divided into: directly summing and labeling the sample data; or weighted averaging the sample data, etc. Both methods are acceptable in this embodiment.

[0066] 5) The state information variable of the nth network attack method and Cybersecurity Posture Score Splice into samples

[0067] 6) Determine the network attack method set Attack (N) The value of Attack n Have all the options been selected? If not, select a network attack method that has not been selected before. n Return to step 2; otherwise, proceed to step 7;

[0068] 7) All samples Combined into a sample matrix X N×T .

[0069] In other embodiments, the experiment may be repeated multiple times to increase the data set.

[0070] In other optional embodiments, if training data exists, the data extraction process can be skipped and the data preprocessing stage can be directly entered, that is, the method does not include step one, and is directly implemented from the following step two.

[0071] Figure 1Provided is an implementation method of using a network security situation prediction system based on a Tranformer-CNN model for a data acquisition system of a power grid. In this embodiment, the data acquisition system buries a data collector in the network to collect network security situation data.

[0072] Step 2: Data preprocessing, including the following five steps: data cleaning, data padding, mask padding, position encoding, generating training samples and predicting labels.

[0073] (1) Data cleaning

[0074] Since it is difficult to ensure the integrity and reliability of data in actual operation, abnormal data, null values, etc. will be introduced more or less during the data collection process, so data analysis and verification must be performed before entering the Tranformer-CNN model. Data is divided into true anomalies and false anomalies. True anomalies refer to errors in the operation process of the data collection system, or incorrect records, omissions, etc.; false anomalies refer to the normal operation of the data collection system, but the data deviates from the overall situation. It is an anomaly caused by an attack, reflecting the insecurity of the network state, and this data cannot be easily removed and modified. The judgment of true and false anomalies can be made by humans. In this embodiment, the system mainly processes true anomalies, and uses a box plot method for inspection. The detected abnormal data is filled and corrected with the mean of the feature (data) at adjacent time points. The box plot verification and correction method is a prior art and will not be repeated in this embodiment.

[0075] (2) Data padding

[0076] Since each attack takes a different amount of time, their sample lengths are also different. In order to uniformly input them into the encoder of the Transformers-CNN model, padding is required first. Suppose the longest time a network attack takes is T, then for attacks that are less than T in length, they need to be padded to T lengths, and their dimensional shape becomes [T×J], and the batch input shape is [N×T×J]. The values ​​at the padded positions are naturally all 0, and J is the number of state information variables.

[0077] (3) Padding Mask

[0078] For the samples after padding, that is, after setting a uniform length T, after padding the shorter sequence with 0 to length T, these 0-filled data should not be focused on in the subsequent attention mechanism, so masking is required. Specifically, a very large negative number (negative infinity) is added to these positions, so that after softmax, the weights of these positions will be close to 0. The padding mask is actually a tensor, and each tensor is a boolean (Boolean variable), which has only two values: true and false. The place with the value of false is the place to be processed, that is, the position with the true value. For each After shielding and filling, the shielding and filling data PaddingMask can be obtained n .

[0079] (4) Position Embedding

[0080] If the completed sample vector is directly input into the Transformer-CNN encoder, the position order relationship in the sample is not considered. At this time, a position vector needs to be added. The position vector has a specific way in model training, which can represent the position at each moment or the distance between different moments. In short, the core idea is to provide effective distance information during attention calculation.

[0081] Regarding position embedding, there are two solutions:

[0082] a) Learned Positional Embedding, absolute position encoding, directly randomly initialize a position embedding for different positions, and use this position embedding as a parameter for training;

[0083] b) Sinusoidal Position Embedding, relative position encoding, that is, trigonometric function encoding.

[0084] In this embodiment, the second position encoding method is selected. Since the position encoding Position embedding and the sample are add (and) operations, its dimension shape is naturally [T×J]. The specific calculation formula is as follows:

[0085]

[0086] where pos∈[0,1,2,...,T-1], k∈[0,1,2,...,J / 2].

[0087] In the above formula, PE (Position Embedding) represents the position encoding of different state information variables, k is a variable, and its value is

[0088] [0-J / 2], by changing the value of k from 0 to J / 2, the position encoding calculation of all state information variables is completed, pos

[0089] The position index of the status information variable is also its absolute position.

[0090] (5) Generate training samples and prediction labels

[0091] Will With Padding Mask n They are spliced ​​together to form a complete training sample X. The final training data has a dimension shape of [N, 2, T, J], which is then input into the Transformers-CNN model for situation awareness and prediction training.

[0092] Step 3: Network security situation prediction

[0093] Collect network security situation data, pre-process the network security situation data according to the method of step 2, generate real-time samples of network security situation data, input the real-time samples of network security situation data into the Tranformer-CNN model, and output the prediction results after calculation, wherein the prediction results include the network security situation score.

[0094] The Tranformer-CNN model includes a Transformer unit and a CNN unit. The Transformer unit operates on a network security situation data sample, extracts key information and outputs it to the CNN unit; the CNN unit operates again on the key information extracted by the Transformer unit and outputs a prediction result.

[0095] In the Transformer unit, self-attention is handled as follows Figure 3 As shown:

[0096] a) Input the processed sample X;

[0097] b) Divide into 8 self-attention heads and multiply the input X with the corresponding weight matrix;

[0098] c) Use the obtained Q, K, V matrices to calculate attention;

[0099] d) Output Z iThe matrices are concatenated and then multiplied by the weight matrix W o , get the output layer Z;

[0100] The specific update formula is as follows:

[0101] Q i =QW i Q ,K i =KW i K ,V i =VW i V ,i=0,…,7

[0102] Z i =Attention(Q i ,K i ,V i ),i=0,…,7

[0103] MultiHead(Q,K,V)=Concat(Z0,…,Z7)W o

[0104] here, represents the real number space domain, and i is the number of the self-attention head.

[0105] The attention calculation formula is:

[0106] In the Transformer unit, the structure and processing of Feed-Forward Networks are as follows Figure 4 As shown in the figure, the Feed-Forward Networks mainly has a 4-layer structure, which is the first linear connection layer linear 1, the Relu activation layer, the Dropout layer, and the second linear connection layer linear 2. In the Feed-Forward Networks, the output data of the self-attention layer is first integrated by the first linear layer linear 1, then activated by the Relu activation function of the Relu activation layer, and then randomly deletes neuron nodes through the Dropout layer to randomly discard some data, and finally outputs the predicted category after integration by the second linear connection layer linear 2. The integration of the data by the first linear layer linear 1 and the second linear connection layer linear 2 is mainly weighted summation.

[0107] like Figure 5 As shown, the connection between CNN and Transformer units and fully connected layers is:

[0108] CNN receives data from the forward propagation network of the decoding component of the Transformer unit, and after calculation, it is output through the fully connected layer, where the fully connected layer uses a linear activation layer Linear.

[0109] In this embodiment, a Transformer structure based on self-attention is adopted to effectively solve the problem of poor encoding effect of long sequences.

[0110] In the prior art, network security situation data is mainly still in the form of cross-sectional data during the current neural network processing process. This embodiment introduces the characteristic of time and combines the simple cross-sectional data of network security situation with the time series data to form a panel data sample matrix X N×T . Since the network is always in an open state, its time series is generally long. For traditional methods, the model often cannot accurately find its rules and is difficult to predict. In response to this problem, this embodiment introduces transformer and CNN neural network to extract key information to reduce the impact of this problem. In addition, since the network security situation is in an exposed state, it is always facing external intervention (such as various network attacks), and the characteristics faced by the network security situation and the states that need to be considered are also much higher than general data prediction problems. The network security situation panel data constructed by this application fully considers the characteristics of the network security situation and can well characterize the network security situation information. At the same time, the introduced model also fully considers the characteristics of the data. Transformer can accurately extract key information of long time series data, and CNN can reduce the problem of too much network security situation feature data. Therefore, this embodiment constructs the network security situation panel data. For the problems existing in the constructed panel data, a newer model combining Transformer and CNN is introduced for targeted processing, which effectively solves the problem of poor encoding effect of long sequences, and can control the amount of calculation and short prediction time.

[0111] [Example 2]

[0112] This embodiment provides a network security situation prediction system based on a Tranformer-CNN model, including:

[0113] Data acquisition unit: acquires network security situation data such as protocol_type (protocol type), service (network service), src_ip (source ip), dst_ip (destination ip), etc.

[0114] Data preprocessing unit: used to preprocess network security situation data and construct real-time samples of network security situation data;

[0115] The network security number prediction unit includes a Tranformer-CNN model, which is used to receive real-time samples of network security situation data, calculate through the Tranformer-CNN model, and output the prediction result.

[0116] like Figure 2 As shown, the Tranformer-CNN model includes a Transformer unit, a CNN unit and a fully connected layer, the CNN unit is connected to the decoding component of the Transformer unit, and the output of the CNN unit is connected to the fully connected layer;

[0117] The Transformer unit operates on the network security situation data sample, extracts key information and outputs it to the CNN unit; the CNN unit again operates on the key information extracted by the Transformer unit, and the operation result is output through the fully connected layer.

[0118] Wherein, the data preprocessing unit includes:

[0119] Data cleaning unit: inspects the acquired network security situation data and corrects abnormal data. In this embodiment, the system uses a box plot to inspect and fills and corrects the abnormal data detected with the mean value of the feature (data) at adjacent time points;

[0120] Data filling unit: according to the longest time T that a network attack takes, network security situation data with a length less than T is padded with zeros to a length of T;

[0121] Shielding filling unit: masking the data at the 0-filled position in the data filling step;

[0122] Position encoding component: Add position vectors to the data.

[0123] The Transformer unit includes an encoding component and a decoding component, wherein the encoding component and the decoding component both have a Muli-head Attention layer, two Add&Norm layers and a forward propagation network, the input of one Add&Norm layer is connected to the output of the Muli-head Attention layer and connected to the forward propagation network, the output of the forward propagation network is connected to the input of another Add&Norm layer, and each Muli-head Attention layer has 8 self-attention heads. In some embodiments, the network security situation prediction system based on the Tranformer-CNN model also includes a training sample construction unit for extracting network security situation data through experiments, and the training sample construction unit creates a set of network attack methods Attack (N) All network attack methods in Attackn , N is the total number of network attack methods, n is the number of network attack methods, n is a positive integer, and 1≤n≤N; for each network attack method Attack n , record the values ​​of each network state information variable at each unit time interval t in the time process T from the beginning to the completion of the attack j is the number of each state information variable; according to the network situation evaluation model, combined with the state information variables at time t Calculate the network security situation score at time t The status information variables of each network attack method and Cybersecurity Posture Score Splice into samples All samples Combined into a sample matrix X N×T , forming training samples for building network security situation data.

[0124] The above-mentioned network situation evaluation model is mainly used for data labeling, that is, using a pre-defined labeling method to label the current data sample. The labeling method is the network situation evaluation model. According to the labeling method, it can be divided into: directly summing and labeling the sample data; or weighted averaging the sample data, etc. Both methods are acceptable in this embodiment.

[0125] Concatenation refers to concatenating two vectors into one vector. For example, the concatenation of vectors [11.2, 13.5, …, 12.3] and vector [20.5] results in the vector [11.2, 13.5, …, 12.3, 20.5].

[0126] In this embodiment, when predicting, Figure 2 As shown in the figure, after data cleaning and data padding, the network security situation data forms a sample with a sequence length of T, a sample size of N, and a number of sample state information variables (also called the number of sample features) of J; after the sample is masked and padded (Padding Mask), the data filled with 0 is masked to form a sample with the maximum sequence length; the position code is generated according to the position of each data in the sample with the maximum sequence length. The sample with the maximum sequence length and the position code are input into the Transformer for position embedding and other feature extraction, and are sent to the Muli-head Attention layer of the encoding component of the Transformer unit, and are processed and outputted after being processed by the Add&Norm layer, the forward propagation network, and another Add&Norm layer in sequence. The data outputted by the Add&Norm layer of the decoding component of the Transformer unit is sent to the CNN for processing and then outputted through the fully connected layer.

[0127] In fact, Figure 2 The overall model can be identified as a network security situation prediction model. After the network security situation data enters the model, it is sequentially encoded (including padding, padding Mask, Position Embedding, etc.), processed by two layers of transformers, processed by CNN layers, and processed by fully connected layers for data integration and classification prediction.

[0128] [Example 3]

[0129] This embodiment provides a network security situation prediction method based on the Tranformer-CNN model. The Tranformer-CNN model used in this method is a Tranformer-CNN model that has been trained in advance. In this embodiment, there is no need to prepare training samples and train the model. The prediction steps are as follows:

[0130] S11. Obtain network security situation data, which includes but is not limited to protocol_type (protocol type), service (network service), src_ip (source ip), dst_ip (destination ip), etc.;

[0131] S12, pre-processing the network security situation data to construct a real-time sample of the network security situation data;

[0132] S13, inputting the real-time sample of network security situation data into the Tranformer-CNN model, performing calculations and outputting prediction results;

[0133] The Tranformer-CNN model includes a Transformer unit, a CNN unit and a fully connected layer. The Transformer unit operates on a sample of network security situation data, extracts key information and outputs it to the CNN unit; the CNN unit operates again on the key information extracted by the Transformer unit and outputs a prediction result; the prediction result output by the convolutional neural network CNN is also input into the fully connected layer for data integration and classification prediction before output, and the data integration here is mainly weighted summation.

[0134] The preprocessing in step S12 includes the following steps:

[0135] Data cleaning: Check the acquired network security situation data and correct the abnormal data. In this step, the network security situation data is checked by using the box plot verification method, and the abnormal data is filled and corrected with the mean value of the feature (data) at adjacent time points.

[0136] Data padding: Based on the maximum time T that a network attack takes, network security situation data that is less than T in length is padded with zeros to a length of T;

[0137] Masking and filling: Mask the data at the 0 position in the data filling step;

[0138] Position encoding: adding position vectors to the data;

[0139] Data merging: Merge the position vector with the masked and filled data to obtain a real-time sample of network security situation data.

[0140] [Example 4]

[0141] This embodiment provides an application of a network security situation prediction system based on the Tranformer-CNN model of Embodiment 2, which is used to process network security situation data with long time series characteristics and predict network security situation.

[0142] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A network security situation prediction method based on the Tranformer-CNN model, characterized in that: The prediction steps include: S11. Obtain network security situation data; S12, pre-processing the network security situation data to construct a real-time sample of the network security situation data; S13, inputting the real-time sample of network security situation data into the Tranformer-CNN model, performing calculations and outputting prediction results; The Tranformer-CNN model includes a Transformer unit and a CNN unit. The Transformer unit operates on the network security situation data sample and outputs the operation result to the CNN unit. The CNN unit re-operates on the key information extracted by the Transformer unit and outputs the prediction result. The Transformer unit includes an encoding component and a decoding component, wherein both the encoding component and the decoding component have a Muli-head Attention layer, two Add&Norm layers and a forward propagation network, wherein the input of one Add&Norm layer is connected to the output of the Muli-head Attention layer and connected to the forward propagation network, the output of the forward propagation network is connected to the input of another Add&Norm layer, and another Add&Norm layer of the decoding component is connected to the CNN unit; The Tranformer-CNN model also includes a fully connected layer, and the prediction results output by the CNN unit are also input into the fully connected layer for data integration and classification prediction before output.

2. The network security situation prediction method based on the Tranformer-CNN model according to claim 1 is characterized in that: The method further includes the following model training step before the prediction step: S01. Acquisition of training data: Acquiring stored network security situation data or acquiring network security situation data through experiments; S02, preprocessing the network security situation data obtained in step S01 to construct a network security situation data training sample; S03. Use network security situation data training samples to train the Tranformer-CNN model.

3. The network security situation prediction method based on the Tranformer-CNN model according to claim 1 is characterized in that: The preprocessing in step S02 and step S12 both include the following steps: Data cleaning: Check the acquired network security situation data and correct abnormal data; Data padding: Based on the maximum time T that a network attack takes, network security situation data that is less than T in length is padded with zeros to a length of T; Masking and filling: Mask the data at the 0 position in the data filling step; Position encoding: adding position vectors to the data.

4. The network security situation prediction method based on the Tranformer-CNN model according to claim 3 is characterized in that: Step S01 extracts network security situation data through experiments, including the following steps: S001. Determine the set of network attack methods (N) , N is the total number of means of network attack; S002, Attack from the set (N) Select a network attack method that has not been selected before Attack n Let n be a fictitious number, where n is the number of the network attack method, n is a positive integer, and 1≤n≤N; S003, record the nth network attack method Attack n The values ​​of the network state information variables at each unit time interval t in the time process T from the beginning to the completion of the attack j is the number of each state information variable; S004, combined with the state information variables at time point t Calculate the network security situation score at time t J is the number of state information variables; S005, the state information variable of the nth network attack method and Cybersecurity Posture Score Splice into samples S006, determine the network attack means set Attack (N) The value of Attack n Whether all the items have been taken out, if not, return to step S002; otherwise, go to step S007; S007. All samples Combined into a sample matrix X N×J .

5. The network security situation prediction method based on the Tranformer-CNN model according to claim 4 is characterized in that: In the preprocessing of step S02, in the position encoding step, the sample matrix X N×J Each of When combined with the position vector, a network security situation data training sample is formed. The network security situation data training sample includes network security situation data and prediction labels, which are network security situation scores 6. The network security situation prediction method based on the Tranformer-CNN model according to any one of claims 1 to 5, characterized in that: The network security situation data includes protocol type, network service, source IP and destination IP.

7. The network security situation prediction system based on Tranformer-CNN model is characterized by: include: Data acquisition unit: acquire network security situation data; Data preprocessing unit: used to preprocess network security situation data and construct real-time samples of network security situation data; A network security situation prediction unit, including a Tranformer-CNN model, is used to receive real-time samples of network security situation data, and output prediction results through Tranformer-CNN model calculations; The Tranformer-CNN model includes a Transformer unit, a CNN unit and a fully connected layer, wherein the CNN unit is connected to the decoding component of the Transformer unit, and the output of the CNN unit is connected to the fully connected layer; The Transformer unit operates on the network security situation data sample and outputs the operation result to the CNN unit; the CNN unit performs another operation on the key information extracted by the Transformer unit, and the operation result is output through the fully connected layer; the fully connected layer performs data integration and classification prediction processing on the operation result output by the CNN unit and then outputs it; The Transformer unit includes an encoding component and a decoding component, wherein the encoding component and the decoding component both have a Muli-head Attention layer, two Add&Norm layers and a forward propagation network, wherein the input of one Add&Norm layer is connected to the output of the Muli-head Attention layer and connected to the forward propagation network, the output of the forward propagation network is connected to the input of another Add&Norm layer, and the other Add&Norm layer of the decoding component is connected to the CNN unit.

8. The network security situation prediction system based on Tranformer-CNN model according to claim 7 is characterized in that: The data preprocessing unit comprises: Data cleaning unit: checks the acquired network security situation data and corrects abnormal data; Data filling unit: according to the longest time T that a network attack takes, network security situation data with a length less than T is padded with zeros to a length of T; Shielding filling unit: masking the data at the 0-filled position in the data filling step; Position encoding component: Add position vectors to the data.

9. The network security situation prediction system based on Tranformer-CNN model according to claim 8 is characterized in that: The invention also includes a training sample construction unit for extracting network security situation data through experiments, and the training sample construction unit is a fictitious network attack means set Attack (N) All network attack methods in Attack n , N is the total number of network attack methods, n is the number of network attack methods, n is a positive integer, and 1≤n≤N; for each network attack method Attack n , record the values ​​of each network state information variable at each unit time interval t in the time process T from the beginning to the completion of the attack j is the number of each state information variable; combined with each state information variable at time t Calculate the network security situation score at time t The status information variables of each network attack method and Cybersecurity Posture Score Splice into samples All samples Combined into a sample matrix X N×J , forming training samples for building network security situation data.

10. The application of the network security situation prediction system based on the Tranformer-CNN model as claimed in claim 7, characterized in that: Used to process network security situation data with long time series characteristics and predict network security situation.