An Attack Behavior Recognition Method and System for Edge Computing Networks

By constructing a triangle area map and combining a deep neural network model, the spatiotemporal features of edge computing networks are extracted and fused, and the problem of insufficient accuracy of attack behavior recognition under high-dimensional data is solved, and higher recognition accuracy is achieved.

CN116389133BActive Publication Date: 2025-07-25GUANGXI UNIVERSITY OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310389362.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-13
Publication Date
2025-07-25
Estimated Expiration
2043-04-13

AI Technical Summary

Technical Problem

Existing machine learning algorithms face problems in edge computing networks such as high-dimensional network traffic data, incomplete mining of attack behavior characteristics, and difficulty in fusion of space-time features, resulting in insufficient recognition accuracy.

Method used

A triangular area map of feature correlation was constructed using multivariate correlation analysis method, combining spatial feature mining module, timing feature mining module and deep neural network classification module, and extracting and fusing spatiotemporal features through convolutional neural networks and bidirectional long and short-term memory networks, and using attention mechanisms to identify attack behaviors.

Benefits of technology

It improves the accuracy of edge computing network attack behavior recognition, improves accuracy, accuracy, recall and F1-Score, and solves the problem of incomplete feature mining under high-dimensional data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389133B_ABST
    Figure CN116389133B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for identifying attack behaviors in an edge computing network, which relates to the field of network security technology. The method includes: constructing a triangle area graph of features to be detected with feature correlation by using a multivariate correlation analysis method according to preset features in the traffic data to be detected, and inputting the triangle area graph of features to be detected into an attack behavior recognition model to output an attack behavior recognition result; the attack behavior recognition model is obtained by training an attack behavior recognition network according to a network traffic data set; the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is used to extract the spatial features of the triangle area graph of features to be detected, the temporal feature mining module is used to extract the temporal features of the triangle area graph of features to be detected, and the deep neural network classification module is used to fuse the spatial features and the temporal features and then identify attack behaviors. The present invention improves the accuracy of network attack behavior recognition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method and system for identifying attack behaviors in an edge computing network. Background Art

[0002] In recent years, while the rapidly developing edge computing network brings convenient services to people, it also exposes a large number of security problems. In particular, the network attack means against edge computing network services are becoming more sophisticated, and the attack behavior hiding methods are also becoming more sophisticated. This not only seriously affects the production operations of enterprises, but also constantly threatens national information security. The edge computing network attack behavior detection model based on machine learning algorithms is a research hotspot in the current industrial and academic circles.

[0003] Existing work has proposed various models including decision tree (DT), support vector machine (SVM), convolutional neural network (CNN), and recurrent neural network (RNN). When dealing with network traffic with a small amount of data and a low feature dimension, relatively excellent recognition effects can be achieved. However, with the increase in edge computing network devices, in the case of unlabeled, high-dimensional, small device bandwidth, and scarce computing resources in the dataset, the advantages of traditional machine learning algorithms no longer exist. At the same time, a large number of research works focus on training CNN and long short-term memory network (LSTM) in series to extract spatio-temporal features of network traffic to improve the attack recognition effect. However, this approach ignores the differences between spatial features and temporal features, as well as the fact that a large amount of effective information is easily lost during the training process of the double-layer model, resulting in incomplete feature mining. In addition, high-dimensional network traffic datasets often contain redundant and irrelevant features, making model training difficult.

[0004] Therefore, traditional machine learning algorithms still face challenges such as high-dimensional network traffic data, incomplete mining of attack behavior features, and difficulty in spatio-temporal feature fusion. There is an urgent need for a method for identifying attack behaviors in an edge computing network based on spatio-temporal feature fusion. Summary of the Invention

[0005] The purpose of the present invention is to provide a method and system for identifying attack behaviors in an edge computing network, which improves the accuracy of network attack behavior recognition.

[0006] To achieve the above object, the present invention provides the following solution:

[0007] A method for identifying attack behaviors in an edge computing network includes:

[0008] Obtaining the traffic data to be detected in the edge computing network;

[0009] According to the preset features in the traffic data to be detected, a triangular area graph of feature correlation is constructed using the method of multivariate correlation analysis, denoted as the triangular area graph to be detected;

[0010] The triangular area graph to be detected is input into the attack behavior recognition model, and the attack behavior recognition result is output;

[0011] The attack behavior recognition model is obtained by training the attack behavior recognition network based on the network traffic data set; the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is used to extract the spatial features of the triangular area graph to be detected, the temporal feature mining module is used to extract the temporal features of the triangular area graph to be detected, and the deep neural network classification module is used to fuse the spatial features and temporal features and then perform attack behavior recognition.

[0012] Optionally, the spatial feature mining module includes a convolutional neural network, and the temporal feature mining module includes a bidirectional long short-term memory network; the convolutional neural network includes a first one-dimensional vector convolutional layer, a first max pooling layer, a second one-dimensional vector convolutional layer, a second max pooling layer, a third one-dimensional vector convolutional layer, a third max pooling layer, and a fully connected layer connected in sequence.

[0013] Optionally, the training of the attack behavior recognition network specifically includes:

[0014] Preprocess the network traffic data set;

[0015] Perform feature selection based on information gain on the preprocessed network traffic data set to obtain the preset features;

[0016] For the preprocessed network traffic data set, the preset features are screened out from each sample to form a preset feature sample;

[0017] For each preset feature sample, a triangular area graph of feature correlation is constructed using the method of multivariate correlation analysis, denoted as the triangular area graph to be trained; the triangular area graph to be trained and the label form a training sample, and the training samples form a training set;

[0018] Train the attack behavior recognition network according to the training set.

[0019] Optionally, the format of the network traffic data set is the CSV file format;

[0020] The preprocessing of the network traffic data set specifically includes:

[0021] For non-numeric values, infinite values, and null values in the network traffic dataset, replace the non-numeric values with the mean of the column where the non-numeric values are located, replace the infinite values with the mean of the column where the infinite values are located, and replace the null values with the mean of the column where the null values are located to obtain a dataset after mean processing;

[0022] One-Hot encode the categorical features in the dataset after mean processing into numerical features, and normalize all the features after encoding processing to obtain a preprocessed network traffic dataset.

[0023] Optionally, perform feature selection based on information gain on the preprocessed network traffic dataset to obtain the preset features, specifically including:

[0024] Calculate the information gain of each feature in the preprocessed network traffic dataset according to the formula g(DataSet,f) = H(DataSet) - H(DataSet|f);

[0025] Sort the information gain from high to low, and take the top k features as the preset features;

[0026] Among them, g(DataSet,f) represents the information gain of feature f, H(DataSet) is the empirical entropy of the preprocessed network traffic dataset, H(DataSet|f) is the conditional empirical entropy, and DataSet represents the preprocessed network traffic dataset.

[0027] Optionally, according to the preset features in the traffic data to be detected, use the multiple correlation analysis method to construct a triangular area graph of feature correlation, denoted as the triangular area graph to be detected, specifically including:

[0028] Use the triangular area method to map and extract the set relationship between every two preset features in the preset features of the traffic data to be detected: project two preset features onto a two-dimensional Euclidean subspace, obtain the mapping of the two-dimensional column vector in the Cartesian coordinate system by connecting the origin with the projections of the two preset features, and obtain the triangular area;

[0029] Multiple triangular areas form a triangular area matrix;

[0030] Convert the element values in the triangular area matrix to grayscale to obtain a triangular area graph.

[0031] Optionally, the deep neural network classification module includes an attention mechanism; the attention mechanism is used to calculate the weights of spatial features and temporal features, and perform weighted summation on the spatial features and temporal features according to the weights of spatial features and temporal features to obtain fused features.

[0032] The present invention discloses an attack behavior recognition system for an edge computing network, including:

[0033] A module for obtaining traffic data to be detected, which is used to obtain the traffic data to be detected in the edge computing network;

[0034] A module for constructing a triangle area graph, which is used to construct a triangle area graph of feature correlation by using a multivariate correlation analysis method according to preset features in the traffic data to be detected, denoted as the triangle area graph to be detected;

[0035] An attack behavior recognition module, which is used to recognize attack behaviors on the triangle area graph to be detected and obtain an attack behavior recognition result;

[0036] The attack behavior recognition model is obtained by training an attack behavior recognition network according to a network traffic data set; the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is used to extract the spatial features of the triangle area graph to be detected, the temporal feature mining module is used to extract the temporal features of the triangle area graph to be detected, and the deep neural network classification module is used to fuse the spatial features and temporal features and then perform attack behavior recognition.

[0037] According to the specific embodiments provided by the present invention, the present invention discloses the following technical effects:

[0038] The present invention extracts spatial features through a spatial feature mining module, extracts temporal features through a temporal feature mining module, and performs attack behavior recognition based on the spatio-temporal feature fusion after fusing the spatial features and temporal features, making full use of the spatio-temporal features in the network traffic, thereby improving the accuracy of network attack behavior recognition. Description of the Drawings

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0040] Figure 1 It is a schematic flow chart of an attack behavior recognition method for an edge computing network provided by an embodiment of the present invention;

[0041] Figure 2 It is a detailed schematic flow chart of an attack behavior recognition method for an edge computing network provided by an embodiment of the present invention;

[0042] Figure 3Schematic diagram of the attack behavior recognition network structure provided by an embodiment of the present invention;

[0043] Figure 4 Schematic diagram of a system structure for attack behavior recognition in an edge computing network provided by an embodiment of the present invention. Detailed implementation manners

[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0045] The purpose of the present invention is to provide a method and system for attack behavior recognition in an edge computing network, which improves the accuracy of network attack behavior recognition.

[0046] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0047] Embodiment 1

[0048] As Figure 1 shown, a method for attack behavior recognition in an edge computing network provided by an embodiment of the present invention includes the following steps.

[0049] Step 101: Obtain the traffic data to be detected in the edge computing network.

[0050] Step 102: According to the preset features in the traffic data to be detected, use the multivariate correlation analysis method to construct a triangular area graph of feature correlation, denoted as the to-be-detected triangular area graph.

[0051] According to the preset features in the traffic data to be detected, using the multivariate correlation analysis method to construct a triangular area graph of feature correlation (Triangle area map, TAM), denoted as the to-be-detected triangular area graph, specifically includes:

[0052] Using the triangular area method to map and extract the correlation information between every two preset features in the preset features of the traffic data to be detected: project the two preset features onto a two-dimensional Euclidean subspace, and obtain the mapping of the two-dimensional column vector in the Cartesian coordinate system by connecting the origin with the projections of the two preset features to obtain the triangular area.

[0053] Multiple triangular areas form a triangular area matrix (TAM matrix).

[0054] Normalize the element values in the triangle area matrix to the interval [0, 1], and then multiply by 255 to obtain the grayscale value matrix of the triangle area map. Read the matrix through the Image library function and convert the values therein to grayscale to obtain the triangle area map (TAM map).

[0055] The traffic data to be detected in step 102 is the preprocessed traffic data.

[0056] Step 103: Input the triangle area map to be detected into the attack behavior recognition model, and output the attack behavior recognition result.

[0057] The attack behavior recognition model is obtained by training the attack behavior recognition network based on the network traffic data set; as Figure 3 shown, the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is used to extract the spatial features of the triangle area map to be detected, the temporal feature mining module is used to extract the temporal features of the triangle area map to be detected, and the deep neural network classification module is used to fuse the spatial features and temporal features and then perform attack behavior recognition.

[0058] As Figure 3 shown, the spatial feature mining module includes a convolutional neural network, and the temporal feature mining module includes a bidirectional long short-term memory network; the convolutional neural network includes a first one-dimensional vector convolutional layer, a first max pooling layer, a second one-dimensional vector convolutional layer, a second max pooling layer, a third one-dimensional vector convolutional layer, a third max pooling layer, and a fully connected layer connected in sequence.

[0059] Both the first one-dimensional vector convolutional layer and the third one-dimensional vector convolutional layer are convolutional layers with 16 convolutional kernels, a convolutional kernel size of 3, and a stride of 2; the second one-dimensional vector convolutional layer has 32 convolutional kernels, a convolutional kernel size of 3, and a stride of 2. The activation functions of the three one-dimensional vector convolutional layers all use the rectified linear unit ReLU. The pooling sizes of the first, second, and third max pooling layers are all 2.

[0060] The fully connected layer is a fully connected layer containing 16 units and uses L2 regularization.

[0061] The bidirectional long short-term memory network (BiLSTM) includes a forward long short-term memory network layer (FLSTM) and a backward long short-term memory network layer (BLSTM). At time t, BiLSTM performs forward temporal feature extraction on the training sample X t as follows:

[0062]

[0063] At time t, BiLSTM performs forward temporal feature extraction on the training sample Xt The reverse time series feature extraction is as follows:

[0064]

[0065] where i t is the input gate at time t, σ is the sigmoid function, W i is the input gate weight, h t-1 is the hidden layer state at time t - 1, h t+1 is the hidden layer state at time t + 1, b i is the input gate bias value, f t is the forget gate at time t, W f is the forget gate weight, b f is the forget gate bias value, q t is the temporary cell state at time t, tanh is the hyperbolic tangent function, W q is the temporary cell state weight, b q is the temporary cell state bias value, o t is the output gate at time t, W o is the output gate weight, b o is the output gate bias value, c t is the cell state at time t, C t-1 is the cell state at time t - 1, C t+1 is the cell state at time t + 1, b t is the output at time t, * is the matrix inner product operation. At time t, the time series features extracted by BiLSTM are where represents the forward features extracted, represents the reverse features extracted.

[0066] The deep neural network classification module includes an attention mechanism; the attention mechanism is used to calculate the weights W SF of the spatial features and the weights W TSF of the time series features, and perform a weighted sum of the spatial features and the time series features according to the weights of the spatial features and the weights of the time series features to obtain the fused features.

[0067] The spatial feature mining module based on a convolutional neural network and the temporal feature mining module based on a bidirectional long short-term memory network are trained in parallel. The spatially mined features (Spatial Features, SF) and temporally mined features (TimeSeries Feature, TSF) are fed into a spatio-temporal feature fusion module based on an attention mechanism. The attention mechanism calculates their respective weights, and the weighted sum is used to obtain the spatio-temporal fusion features (Spatio-Temporal FusionFeatures, STF) as follows:

[0068] STF = SF · W SF + TSF · W TSF 。

[0069] In the deep neural network classification module, the deep neural network includes an input layer with 32 input units, two fully connected layers with 64 and 32 units respectively, the activation function is the rectified linear unit ReLU, and a random inactivation (Dropout) layer with a dropout rate of 0.5 is added after each fully connected layer. Finally, there is an output layer, the loss function is cross-entropy, and the activation function is Softmax to obtain the recognition result of the traffic data to be detected. If the recognition result is a network attack behavior, the network behavior is intercepted and the administrator is notified. If the recognition result is benign network traffic, the traffic is allowed to pass through normally.

[0070] Before step 101, as Figure 2 shown, the present invention also includes edge computing network traffic data collection. The specific steps for collecting edge computing network traffic data include:

[0071] Collect an edge computing network traffic dataset containing attack behaviors from the real edge computing network environment and the Internet, save the collected traffic data as a PCAP format file, and use Python to write script code to call the Wireshark software to convert the PCAP file into a CSV file format to generate a network traffic dataset. Each record represents a traffic sample, and the i-th traffic sample flow i is represented as n feature columns and 1 label Label, flow i = {C1, C2,..., C n , Label}.

[0072] The edge computing network specifically includes the Internet of Things.

[0073] The training of the attack behavior recognition network specifically includes:

[0074] Preprocess the network traffic dataset.

[0075] The preprocessing of the network traffic dataset specifically includes:

[0076] For non-numeric (Not a Number, Nan), infinite (Infinity, Inf), and null values in the network traffic dataset, they are replaced with the column mean of their respective columns. Specifically: the non-numeric values are replaced with the mean of the column where the non-numeric values are located, the infinite values are replaced with the mean of the column where the infinite values are located, and the null values are replaced with the mean of the column where the null values are located, resulting in a dataset after mean processing.

[0077] The method for calculating the column mean is:

[0078]

[0079] where Mean j is the column mean, flow i .C j is the j-th feature of the i-th traffic sample, m is the number of traffic samples, and n is the number of features.

[0080] The categorical features in the dataset after mean processing are One-Hot encoded into numerical features, and all the encoded features are Min-Max normalized to scale the features between 0 and 1, resulting in a preprocessed network traffic dataset.

[0081] The normalization method is:

[0082]

[0083] where C j new is the value after normalization, C j is the original value of the j-th feature before normalization, C j max and C j min are the maximum and minimum values of each feature respectively.

[0084] The preprocessed network traffic dataset is split into a training set (TrainSet) for training the edge computing network attack behavior recognition model, a validation set (ValidationSet) for validating the training model, and a test set (TestSet) for testing the effect of the final model.

[0085] Feature selection based on information gain is performed on the preprocessed network traffic dataset to obtain the preset features, specifically including:

[0086] Calculate the information gain of each feature in the preprocessed network traffic dataset according to the formula g(DataSet,f) = H(DataSet) - H(DataSet|f).

[0087] Sort the information gains from high to low, take the first k features as the preset features, delete the useless features, and obtain flow i ={f1, f2,..., fk, Label}. f1, f2, and fk are the 1st, 2nd, and kth preset features respectively.

[0088] Among them, g(DataSet, f) represents the information gain of feature f, H(DataSet) is the empirical entropy of the preprocessed network traffic dataset, H(DataSet|f) is the conditional empirical entropy, and DataSet represents the preprocessed network traffic dataset.

[0089] For the preprocessed network traffic dataset, screen out the preset features from each sample to form preset feature samples.

[0090] For each preset feature sample, use the multiple correlation analysis method to construct a triangular area diagram of feature correlation, denoted as the triangular area diagram to be trained.

[0091] Use the multiple correlation analysis method to construct a triangular area diagram of feature correlation, specifically including: use the triangular area method to map and extract the set relationship between the qth and pth features in flow i ={f1, f2,..., fk}: Project the sample flow i onto the (q - p) two-dimensional Euclidean subspace, y i,q,p =[ε q ε p T =[f i q f i p T , (1 <= i <= m, 1 <= q, p <= k, q!= p), the variable ε q =[e q,1 , e q,2 ,..., e q,k , ε p =[e p,1 , e p,2 ,..., e p,k , where e q,q = 1, e k,k = 1, and other elements are 0, y i,q,p is the two-dimensional column vector obtained by projecting the qth and pth features of the ith sample through the variable ε q and the variable ε p in the Cartesian coordinate system by connecting the origin and f i q and f i p ​​Mapping on the subspace, f i q and f i p represent the mapping values of the two-dimensional column vector with respect to the q-th and p-th indices. The constructed triangle area is Tr i q,p , which is:

[0092]

[0093] The obtained TAM matrix is:

[0094]

[0095] Convert the TAM matrix into a TAM graph according to the numerical size for feature mining in the edge computing network attack behavior recognition method.

[0096] The training samples are composed of the triangle area graph to be trained and labels, and the training samples form a training set.

[0097] Train the attack behavior recognition network according to the training set to obtain a trained attack behavior recognition model. The format of the network traffic data set is the CSV file format.

[0098] The attack behavior recognition model is trained using the TensorFlow framework on a device with an AMD EPYC 7T83 CPU and an NVIDIA GeForce RTX 3090 GPU. The parameters of the neural network are initialized in the Xavier manner. The cross-entropy loss function is selected as the loss function, the Adam optimizer is used for the optimization algorithm, the backpropagation algorithm is used to update the network parameters. The UNSW-NB15 data set and the CICIDS2017 data set, which are edge computing network intrusion detection benchmark data sets, are selected as the model training data sets, and four evaluation criteria, namely accuracy, precision, recall, and F1-Score, are selected for evaluation.

[0099] The present invention provides a method for identifying attack behaviors in an edge computing network. By using a feature selection module, important features are selected, invalid features are deleted, and the feature dimension is reduced. Through a parallel spatio-temporal feature mining module, the spatial features and temporal features of the edge computing network traffic are mined. Combining the attention mechanism, the spatially and temporally mined features are fused into spatio-temporal fusion features, which are input into a deep neural network recognition model to identify attack behaviors in the edge computing network. This solves the problem that traditional machine learning models cannot handle high-dimensional edge computing network traffic, overcomes the problem of incomplete mining of attack behavior features by traditional single models, and overcomes the problem that the cascaded model ignores the differences between spatial and temporal features, resulting in the easy loss of a large amount of valid information during the model training process. Improvements are achieved in all four indicators of accuracy, precision, recall, and F1-Score.

[0100] The present invention solves the problems of high-dimensional network traffic data, incomplete mining of attack behavior features, and difficult spatio-temporal feature fusion when using machine learning technology to identify attack behaviors in an edge computing network.

[0101] Embodiment 2

[0102] As Figure 4 shown, an attack behavior recognition system for an edge computing network provided in this embodiment includes:

[0103] A to-be-detected traffic data acquisition module 201, configured to acquire to-be-detected traffic data of the edge computing network.

[0104] A triangle area graph construction module 202, configured to construct a triangle area graph of feature correlation according to preset features in the to-be-detected traffic data by using a multivariate correlation analysis method, denoted as the to-be-detected triangle area graph.

[0105] An attack behavior recognition module 203, configured to perform attack behavior recognition on the to-be-detected triangle area graph to obtain an attack behavior recognition result.

[0106] The attack behavior recognition model is obtained by training an attack behavior recognition network according to a network traffic data set; the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is configured to extract the spatial features of the to-be-detected triangle area graph, the temporal feature mining module is configured to extract the temporal features of the to-be-detected triangle area graph, and the deep neural network classification module is configured to fuse the spatial features and temporal features and then perform attack behavior recognition.

[0107] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other.

[0108] Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present invention. At the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the present invention.

Claims

1. An attack behavior recognition method for edge computing networks, characterized in that, Including: Obtain the traffic data to be detected in the edge computing network; According to the preset features in the traffic data to be detected, use the multiple correlation analysis method to construct a triangular area graph of feature correlation, denoted as the triangular area graph to be detected; Input the triangular area graph to be detected into the attack behavior recognition model, and output the attack behavior recognition result; The attack behavior recognition model is obtained by training the attack behavior recognition network based on the network traffic data set; the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is used to extract the spatial features of the triangular area graph to be detected, the temporal feature mining module is used to extract the temporal features of the triangular area graph to be detected, and the deep neural network classification module is used to fuse the spatial features and temporal features and then perform attack behavior recognition; The training of the attack behavior recognition network specifically includes: Preprocess the network traffic data set; Perform feature selection based on information gain on the preprocessed network traffic data set to obtain the preset features; For the preprocessed network traffic data set, screen out the preset features from each sample to form a preset feature sample; For each preset feature sample, use the multiple correlation analysis method to construct a triangular area graph of feature correlation, denoted as the triangular area graph to be trained; the triangular area graph to be trained and the label form a training sample, and the training samples form a training set; Train the attack behavior recognition network according to the training set; Performing feature selection based on information gain on the preprocessed network traffic data set to obtain the preset features specifically includes: Calculate the information gain of each feature in the preprocessed network traffic data set according to the formula g(DataSet,f) = H(DataSet) - H(DataSet|f); Sort the information gain from high to low, and take the first k features as the preset features; Among them, g(DataSet,f) represents the information gain of feature f, H(DataSet) is the empirical entropy of the preprocessed network traffic data set, H(DataSet|f) is the conditional empirical entropy, and DataSet represents the preprocessed network traffic data set; According to the preset features in the traffic data to be detected, using the multiple correlation analysis method to construct a triangular area graph of feature correlation, denoted as the triangular area graph to be detected, specifically includes: Use the triangular area method to map and extract the set relationship between every two preset features in the preset features of the traffic data to be detected: project two preset features onto a two-dimensional Euclidean subspace, obtain the mapping of the two-dimensional column vector in the Cartesian coordinate system by connecting the origin with the projections of the two preset features, and obtain the triangular area; Multiple triangular areas form a triangular area matrix; Convert the element values in the triangular area matrix to grayscale to obtain a triangular area graph; Construct a triangular area chart of feature correlation using the multiple correlation analysis method, specifically including: mapping and extracting flow using the triangular area method i = the set relationship between the q-th and p-th features in {f1, f2,..., fk}: project the sample flow i onto the (q - p)-dimensional Euclidean subspace, y i,q,p =[ε q ε p T =[f i q f i p T , (1 <= i <= m, 1 <= q, p <= k, q!= p); the variable ε q =[e q,1 , e q,2 ,..., e q,k , ε p =[e p,1 , e p,2 ,..., e p,k , where e q,q = 1, e k,k = 1, and other elements are 0; y i,q,p is the two-dimensional column vector obtained by projecting the q-th and p-th features of the i-th sample through the variable ε q and the variable ε p . In the Cartesian coordinate system, by connecting the origin and the mapping of f i q and f i p on the subspace, f i q and f i p represent the mapping values of the two-dimensional column vector with respect to the q-th and p-th indices. flow i is the i-th sample, m is the number of samples, and k is the number of preset features; f1, f2, and fk are the 1st, 2nd, and k-th preset features respectively;​​ The area of the constructed triangle is Tr i q,p : The obtained triangular area matrix is:

2. The attack behavior recognition method for an edge computing network according to claim 1, characterized in that The spatial feature mining module includes a convolutional neural network, and the temporal feature mining module includes a bidirectional long short-term memory network; the convolutional neural network includes a first one-dimensional vector convolutional layer, a first max pooling layer, a second one-dimensional vector convolutional layer, a second max pooling layer, a third one-dimensional vector convolutional layer, a third max pooling layer, and a fully connected layer connected in sequence.

3. The attack behavior recognition method for an edge computing network according to claim 2, wherein The format of the network traffic dataset is in CSV file format; Preprocessing the network traffic dataset specifically includes: For non-numeric values, infinite values, and null values in the network traffic dataset, replace the non-numeric values with the mean of the column where the non-numeric values are located, replace the infinite values with the mean of the column where the infinite values are located, and replace the null values with the mean of the column where the null values are located to obtain a dataset after mean processing; One-Hot encode the character features in the dataset after mean processing into numeric features, and normalize all the encoded features to obtain a preprocessed network traffic dataset.

4. The attack behavior recognition method for an edge computing network according to claim 1, wherein The deep neural network classification module includes an attention mechanism; the attention mechanism is used to calculate the weights of spatial features and temporal features, and perform weighted summation on the spatial features and temporal features according to the weights of spatial features and temporal features to obtain a fused feature.

5. An attack behavior recognition system for an edge computing network, characterized in that, Including: A module for obtaining traffic data to be detected, which is used to obtain traffic data to be detected in the edge computing network; A triangle area graph construction module, which is used to construct a triangle area graph of feature correlation using a multivariate correlation analysis method according to preset features in the traffic data to be detected, denoted as the triangle area graph to be detected; An attack behavior recognition module, which is used to perform attack behavior recognition on the triangle area graph to be detected to obtain an attack behavior recognition result; The attack behavior recognition model is obtained by training an attack behavior recognition network based on a network traffic dataset; the attack behavior recognition network includes a spatial feature mining module, a temporal feature mining module, and a deep neural network classification module; the spatial feature mining module is used to extract the spatial features of the triangle area graph to be detected, the temporal feature mining module is used to extract the temporal features of the triangle area graph to be detected, and the deep neural network classification module is used to perform attack behavior recognition after fusing spatial features and temporal features; The training of the attack behavior recognition network specifically includes: Preprocessing the network traffic dataset; Performing feature selection based on information gain on the preprocessed network traffic dataset to obtain the preset features; For the preprocessed network traffic dataset, filter out the preset features from each sample to form a preset feature sample; For each preset feature sample, construct a triangle area graph of feature correlation using a multivariate correlation analysis method, denoted as the triangle area graph to be trained; the triangle area graph to be trained and the label form a training sample, and the training samples form a training set; Training the attack behavior recognition network according to the training set; Performing feature selection based on information gain on the preprocessed network traffic dataset to obtain the preset features, specifically including: Calculate the information gain of each feature in the preprocessed network traffic dataset according to the formula g(DataSet,f) = H(DataSet) - H(DataSet|f); Sort the information gains from high to low, and use the top k features as the preset features; Among them, g(DataSet,f) represents the information gain of feature f, H(DataSet) is the empirical entropy of the preprocessed network traffic dataset, H(DataSet|f) is the conditional empirical entropy, and DataSet represents the preprocessed network traffic dataset; According to the preset features in the traffic data to be detected, use the multiple correlation analysis method to construct a triangular area graph of feature correlation, denoted as the triangular area graph to be detected, specifically including: Use the triangular area method to map and extract the set relationship between every two preset features in the preset features of the traffic data to be detected: project the two preset features onto a two-dimensional Euclidean subspace, obtain the mapping of the two-dimensional column vector in the Cartesian coordinate system by connecting the origin with the projections of the two preset features, and get the triangular area; Multiple triangular areas form a triangular area matrix; Convert the element values in the triangular area matrix to grayscale to obtain a triangular area graph; Construct a triangular area chart of feature correlation using the multivariate correlation analysis method, specifically including: mapping and extracting flow using the triangular area method i = the set relationship between the q-th and p-th features in {f1, f2,..., fk}: project the sample flow i onto the (q - p)-dimensional Euclidean subspace, y i,q,p =[ε q ε p T =[f i q f i p T , (1 <= i <= m, 1 <= q, p <= k, q!= p); the variable ε q =[e q,1 , e q,2 ,..., e q,k , ε p =[e p,1 , e p,2 ,..., e p,k , where e q,q = 1, e k,k = 1, and other elements are 0; y i,q,p is the two-dimensional column vector obtained by projecting the q-th and p-th features of the i-th sample through the variable ε q and the variable ε p . In the Cartesian coordinate system, by connecting the origin and the mapping of f i q and f i p on the subspace, f i q and f i p represent the mapping values of the two-dimensional column vector under the q-th and p-th indices. flow i is the i-th sample, m is the number of samples, and k is the number of preset features; f1, f2, and fk are the 1st, 2nd, and k-th preset features respectively;​​ The area of the constructed triangle is Tr i q,p : The obtained triangular area matrix is: