A satellite communication link transmission intrusion detection method and system based on honey badger algorithm
By proposing an improved satellite communication link intrusion detection method based on the honey badger algorithm, this method utilizes color Wiener filtering and Tasmanian devil optimization algorithm to select features, and combines it with the self-attention driven adversarial network model SA-PVAEGAN-HBA to solve the problems of long detection time and low accuracy in satellite communication links, thus achieving efficient and accurate intrusion detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI SHIP & SHIPPING RES INST CO LTD
- Filing Date
- 2023-10-10
- Publication Date
- 2026-07-31
AI Technical Summary
Existing satellite communication link intrusion detection methods are time-consuming and have low accuracy, resulting in high communication transmission link overhead and making them difficult to adapt to the unique characteristics of satellite communication transmission links.
An improved method based on the honey badger algorithm is adopted. By collecting satellite communication link traffic data, color Wiener filtering is used to eliminate redundant information and recover missing values. The optimal features are selected by combining the Tasmanian devil optimization algorithm. Finally, a self-attention driven temporary variational autoencoder generative adversarial network model SA-PVAEGAN-HBA optimized by the honey badger algorithm is introduced for classification and anomaly detection.
It achieves low-time, high-precision, and low-overhead satellite communication link intrusion detection, improving the accuracy and efficiency of detection and reducing computation time.
Smart Images

Figure CN117220990B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of satellite communication link transmission intrusion detection, and in particular to a satellite communication link transmission intrusion detection method and system based on an improved honey badger algorithm. Background Technology
[0002] The Arctic shipping routes, as important maritime passages, consist of the Northeast Passage, the Northwest Passage, and the Central Passage. Although the Northeast Passage has achieved regular commercial operation, incomplete navigational environmental data in the Arctic region, relatively lagging communication infrastructure, and a lack of navigational aids, lighthouses, and coastal radio services make it difficult to rely on ship-to-shore communication for warnings and hazard alerts. Furthermore, due to relatively limited experience navigating in the Arctic region, ships navigating in this area face high safety risks.
[0003] The message service system of my country's BeiDou Navigation Satellite System provides a new avenue for information transmission in the Arctic region. Satellite communication networks, due to their advantages of wide coverage, high capacity, and long-distance transmission, are widely used in navigation, aerospace, broadcasting, and disaster relief. However, as the network scale continues to expand, intrusions into satellite communication transmission links occur frequently. Therefore, how to detect anomalies in satellite communication networks to ensure their normal and efficient operation has become a current research focus.
[0004] With the development of satellite communication transmission links and the increasing connectivity of unmanned system networks, security and privacy have become major concerns. Existing intrusion detection methods are not only time-consuming but also have low accuracy and detection rates. Due to the differences between satellite communication transmission links and typical computer networks in terms of terminal types, data transmission, and network topology, some traditional network intrusion detection techniques are no longer applicable. In identifying intruders involved in unknown attacks, satellite communication transmission link intrusion detection must possess high accuracy to ensure low overhead on the satellite communication transmission link.
[0005] Therefore, providing an efficient, simple, and widely applicable intrusion detection method has become a technical problem to be solved by those skilled in the art. Summary of the Invention
[0006] To address the problems of long processing time, low accuracy, and high overhead in existing satellite communication link intrusion detection technologies, this invention proposes a satellite communication link intrusion detection method and system based on an improved honey badger algorithm. By collecting satellite communication link traffic data, processing the data, selecting optimal features, and classifying the traffic data based on these features, the detection model achieves higher accuracy and shorter computation time. This results in low-time, high-accuracy, and low-overhead detection of satellite communication link intrusions.
[0007] The present invention provides the following specific solution:
[0008] A satellite communication link transmission intrusion detection method based on an improved honey badger algorithm includes the following steps:
[0009] S1. Data Collection: Collect ship satellite communication transmission link traffic data;
[0010] S2. Data Preprocessing: In the preprocessing stage, a color Wiener filter is used to eliminate redundant information in the data and restore missing values. The redundant information may be some duplicate or irrelevant data existing in the satellite communication transmission link data, and the missing values may be data lost in the satellite communication transmission link data due to transmission errors or insufficient sampling. In the preprocessing stage, a color Wiener filter is used to eliminate redundant information in the data and restore missing values.
[0011] S3. Feature Selection: Using the preprocessed data from S2 as input for feature selection, the Tasmanian devil optimization algorithm is used to obtain candidate solutions in the Tasmanian devil population by setting an objective function. The algorithm iteratively eliminates candidate solutions of low quality or local optima, ultimately obtaining the optimal feature. The objective function set in the Tasmanian devil optimization algorithm is:
[0012]
[0013] In the formula, FF represents the objective function value, F i This represents the objective function value obtained from the i-th candidate solution;
[0014] S4. Satellite Communication Link Transmission Intrusion Detection: Based on the optimal features obtained in S3, a self-attention-driven temporary variational autoencoder optimized by the Honey Badger Algorithm (HBA) is introduced, and a generative adversarial network model (SA-PVAEGAN-HBA) is used to classify and detect anomalies in satellite communication transmission link traffic data.
[0015] Preferably, the specific steps for using color Wiener filtering in S2 to eliminate redundant information in the data and recover missing values are as follows:
[0016] S21: Determine the minimum and maximum values of the input dataset;
[0017] d i =I i +λ i (2)
[0018] Where, d i I represents the observed input data. i and λ i This indicates irrelevant information from the input data;
[0019] S22: Use CWF filtering to remove random values;
[0020]
[0021] In the formula, and Representing dimensional features, Let M represent the mean vector of the preprocessed data, and let M represent the CWF filter, which is determined by minimizing the mean square error (MSE) between the original data and the preprocessed data. The MSE is calculated by equation (4):
[0022]
[0023] S23: In the original input data, the preprocessed data is calculated according to formula (5):
[0024] M = CM(OM + ON) (5)
[0025] Where CM represents the covariance measure and CN represents unwanted information.
[0026] Preferably, the specific steps for selecting the optimal feature using the Tasmanian devil optimization algorithm in S3 are as follows:
[0027] S31. Population initialization: Randomly generate the initial population of TDO according to the constraints of feature selection, and score the members of the TDO population according to their positions in the search space;
[0028]
[0029] In the formula, Y represents the Tasmanian devil population, Y i Let y represent the i-th candidate solution. i,j Let N represent the candidate values for the j-th variable, N represent the number of searches for Tasmanian devils, and M represent the number of times the data was preprocessed.
[0030] S32. Randomly generate input parameters as candidate solutions: After initialization, based on the search space and boundary conditions of the problem described in S31, randomly generate a set of input parameters as candidate solutions for the Tasmanian Badger Optimization Algorithm (TDO), i.e., a set of possible feature subsets; at the beginning of each optimization round, randomly set the input parameters to allow them to explore different search regions; adjust the generation of input parameters according to hyperparameters, including population size, number of iterations, and exploration factor;
[0031] S33. Evaluating the quality of candidate solutions through the objective function: The quality of input parameters is evaluated through the objective function, which reflects the degree to which the characteristics of the selected input parameters conform to the problem objective; the objective function is shown in equation (1):
[0032]
[0033] In the formula, FF represents the objective function value, F i This represents the objective function value obtained from the i-th candidate solution;
[0034] During the iteration process, the candidate solutions to the problem described in S32 are substituted into the objective function to solve for the objective function value; the quality of the candidate solutions is obtained by analyzing the objective function value.
[0035] S34. Update the best member in the Tasmanian devil population based on the quality of the candidate solutions in S33. After iteration, obtain the optimal feature: TDO explores different regions in the scan search space to identify the original optimal region. Update the best member in the Tasmanian devil population based on either the carrion feeding strategy or the prey feeding strategy. Iterate and finally select the best feature.
[0036] S341: Carrion feeding strategy: The positions of other population members in the search space are assumed to be carrion locations; the k-th population member is selected as the target carrion for the i-th Tasmanian devil; k is randomly selected from 1 to N; the characteristics of random selection are represented in equation (7) as follows:
[0037] D i =Y k (7)
[0038] In the formula, i = 1, 2, ..., N and k ∈ {1, 2, ..., N | k ≠ i}, D i This represents the feature chosen by the i-th Tasmanian devil;
[0039] Based on the selected carrion, calculate the Tasmanian devil's new position in the search space: In the Tasmanian devil's movement simulation under this strategy, if the objective function value of the carrion is good, the Tasmanian devil moves towards the carrion, otherwise it moves away from the carrion; after calculating the Tasmanian devil's new position, if the objective function value at the new position is good, the new position is accepted, otherwise it remains at the original position.
[0040] S342: Selecting the optimal feature through prey-feeding strategy: The Tasmanian devil's prey-feeding process consists of two stages: In the first stage, it selects prey by scanning the area and attacks it; In the second stage, after approaching the prey, it chases the prey to stop it and begins to eat; The positions of other population members are assumed to be the positions of the prey, and the kth population member is randomly selected as the prey, where k is a natural random number between 1 and N, relative to i; The process is simulated in equation (8) as follows:
[0041] Q i =Y k ;i=1,2,...,N,k∈{1,2,...,N|k≠i} (8)
[0042] Q i Y represents the optimal feature selected by the Tasmanian devil. k This represents the k-th candidate solution;
[0043] Once the prey's location is determined, a new location is calculated for the Tasmanian devil. When calculating this new location, if the selected prey has a better objective function value, the Tasmanian devil will move towards it; otherwise, it will move away from the location. If the Tasmanian devil's new location improves the objective function value, it will replace the previous location.
[0044] S35: When all TDO members have been updated, one iteration of the algorithm ends; new values are calculated for the Tasmanian devil's position and objective function; then, the algorithm enters the next iteration, following S33-S34, and continues the TDO population update process until the algorithm iteration ends; during these iterations, TDO updates and stores the best candidate solution, and after the algorithm is fully implemented, TDO introduces the best candidate solution as the optimal feature.
[0045] Preferably, the specific steps for classifying and detecting anomalies in satellite communication transmission link traffic data in S4 are as follows:
[0046] S41. In step S3, the self-attention-driven temporary variational autoencoder generative adversarial network model SA-PVAEGAN is trained based on the training set after feature filtering; the model is evaluated and validated using the test set.
[0047] S42. Use the honey badger algorithm to optimize the optimal parameters of the adversarial network model, and apply HBA to fine-tune the weights and bias parameters of SA-PVAEGAN.
[0048] S43. Intrusion detection is performed using a trained adversarial network model, namely SA-PVAEGAN-HBA. The adversarial network model SA-PVAEGAN consists of three modules: a discriminator, a variational autoencoder, and a classifier. The discriminator distinguishes whether the input sample is a real sample or a virtual sample. The variational autoencoder includes an encoder and a generator. The generator uses the latent vector and random latent vector generated by the encoder to create virtual hyperspectral samples. The classifier classifies the input real samples and virtual samples.
[0049] Preferably, in step S42, the step of optimizing the optimal parameters of the honey badger algorithm model is as follows:
[0050] S421. Population Initialization: Population initialization is performed randomly within a set boundary range.
[0051] a i =lb i +s1×(ub i -lb i ), s i (9)
[0052] In the formula, a i The i-th potential solution in N populations, lb i and ub i These refer to the lower and upper boundaries of the search domain, respectively.
[0053] S422, Random Generation: After initialization, input parameters are randomly generated, and the best fitness value is selected based on their explicit hyperparameter states.
[0054] S423, Fitness Function: Creates a random solution from the initial values, and the resulting random solution is (D... i ) and z random Substituting the parameter values into the objective function, the fitness value is calculated. The higher the fitness value, the closer the current random solution is to the optimal solution. By solving the objective function, the parameter values (D) of the SAPVAEGAN classifier are optimized. i ) and z random Its expression is:
[0055] Fitness function =Optimization[(D i )and(Z random (10)
[0056] In the formula (D) i ) and z random These are the parameter values of the classifier;
[0057] S424. Update the density factor to optimize (D)i The density factor (α) controls time-varying randomization to ensure a smooth transition from exploration to development; the decreasing factor α, which decreases with the number of iterations, is updated to reduce randomness over time.
[0058] S425. Honey badger foraging behavior to optimize z random The intensity is related to the concentration of prey and the distance between the prey and the i-th honey badger, L i It is the intensity of the prey's scent. If the scent intensity is high, the honey badger will move quickly, and vice versa.
[0059] S426. Termination: Check if the attack classification meets the stopping condition. Otherwise, iterate and repeat steps S423-S425 until the stopping condition is met. Finally, the SA-PVAEGAN classifier accurately detects the attack type through HBA.
[0060] Preferably, in step S43, the discriminator contains four convolutional layers, each with a kernel size of 3*3; the first two convolutional layers are applied before the self-attention module, and the output of the last convolutional layer is converted into a feature vector representation, and the normality of the data is evaluated by applying the Sigmoid process; the discriminator also incorporates label information, which is dimensionality reduced by a fully connected layer.
[0061] Preferably, in step S43, the variational autoencoder consists of two components: an encoder and a generator; the generator G i Virtual hyperspectral samples are created using latent vectors and then transferred from normal data to the latent vector space by an encoder F. The encoder F consists of two spectral space feature extraction networks with the same network architecture: one spectral space feature extraction network is used to obtain the mean vector μ, and the other is used to determine the covariance f of the latent vector space.
[0062] Preferably, the encoder's spectral spatial feature extraction network includes four one-dimensional convolutional layers with 5*1 kernels; a self-attention mechanism is used in the first and second layers.
[0063] Preferably, the generator G i Four transposed convolutional layers and two fully connected layers are configured. The two fully connected layers are used to reshape the latent vectors and associated labels, converting them into three-dimensional data cubes, which are then transposed onto the transposed convolutional layers. The kernel size of the transposed convolutional layers is 3×3. Finally, a simulated hyperspectral sample is obtained. The latent vectors are generated by the encoder of a variational autoencoder (VAE) to generate virtual hyperspectral samples from normal data, a low-dimensional vector used to represent data that can capture the latent features and structure of the data.
[0064] Preferably, in step S43, the classifier includes: a spectral feature extraction network consisting of five one-dimensional convolutional layers with 1*5 kernels and a spatial feature extraction network consisting of five two-dimensional convolutional layers with 3*3 kernels; in the classifier, spectral and spatial information are fused and passed to two fully connected layers.
[0065] Preferably, a satellite communication link transmission intrusion detection system based on an improved honey badger algorithm includes:
[0066] The module includes an acquisition module, a preprocessing module, a feature selection module, and a satellite communication transmission link intrusion detection module.
[0067] The acquisition module acquires satellite communication transmission link data.
[0068] The preprocessing module uses CWF technology to eliminate redundant information and recover missing values in the communication transmission link data. The redundant information may be some duplicate or irrelevant data, and the missing values may be some data lost due to transmission errors or insufficient sampling in the satellite communication transmission link data.
[0069] The feature selection module uses the preprocessed communication transmission link data as input for feature selection and employs the Tasmanian Badger Optimization Algorithm (TDO) to select the optimal feature.
[0070] The satellite communication transmission link intrusion detection module, based on optimal features, introduces a self-attention-driven temporary variational autoencoder generative adversarial network (SA-PVAEGAN-HBA) optimized by the Honey Badger Algorithm (HBA) to classify and detect anomalies in satellite communication transmission link traffic data.
[0071] This invention provides a satellite communication link transmission intrusion detection method and system based on the improved honey badger algorithm. First, satellite communication transmission link traffic data is collected from ships. Color Wiener filtering is used to preprocess the data, eliminating redundant information and missing values while retaining data features and information, thus improving data quality and integrity. Second, the preprocessed data is used as input for feature selection. The Tasmanian Badger optimization algorithm is used to select the optimal features, reducing data dimensionality and complexity, decreasing computational load and storage pressure, and improving the accuracy and generalization ability of the classifier. Third, this invention introduces the honey badger algorithm to optimize the weights and bias parameters of the self-attention-driven temporary variational autoencoder generative adversarial network, accelerating the model's convergence speed and improving its stability and robustness. Finally, the SA-PVAEGAN-HBA model is used to classify and detect anomalies in the satellite communication transmission link data. Virtual samples are generated using latent vectors, enhancing the model's learning and discriminative abilities, achieving high-precision satellite communication transmission link intrusion detection. Attached Figure Description
[0072] Figure 1 This is a flowchart of the satellite communication link transmission intrusion detection method based on the honey badger algorithm of the present invention.
[0073] Figure 2 This is a flowchart of the honey badger optimization algorithm in this invention.
[0074] Figure 3 This is a structural diagram of SA-PVAEGAN in this invention.
[0075] Figure 4 This is a schematic diagram of a satellite communication link transmission intrusion detection system based on an improved honey badger algorithm, provided as an embodiment of the present invention.
[0076] Figure 5 This is a schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0077] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0078] Example 1:
[0079] like Figure 1 As shown, a satellite communication link transmission intrusion detection method based on an improved honey badger algorithm includes the following steps:
[0080] S1. Data Collection: Collect ship satellite communication transmission link traffic data;
[0081] S2. Data Preprocessing: In the preprocessing stage, a color Wiener filter is used to eliminate redundant information in the data and restore missing values. The redundant information may be some duplicate or irrelevant data existing in the satellite communication transmission link data, and the missing values may be data lost in the satellite communication transmission link data due to transmission errors or insufficient sampling. In the preprocessing stage, a color Wiener filter is used to eliminate redundant information in the data and restore missing values.
[0082] S3. Feature Selection: Using the preprocessed data from S2 as input for feature selection, the Tasmanian devil optimization algorithm is used to obtain candidate solutions in the Tasmanian devil population by setting an objective function. The algorithm iteratively eliminates candidate solutions of low quality or local optima, ultimately obtaining the optimal feature. The objective function set in the Tasmanian devil optimization algorithm is:
[0083]
[0084] In the formula, FF represents the objective function value, F i This represents the objective function value obtained from the i-th candidate solution;
[0085] S4. Satellite Communication Link Transmission Intrusion Detection: Based on the optimal features obtained in S3, a self-attention-driven temporary variational autoencoder optimized by the Honey Badger Algorithm (HBA) is introduced, and a generative adversarial network model (SA-PVAEGAN-HBA) is used to classify and detect anomalies in satellite communication transmission link traffic data.
[0086] Preferably, the specific steps for using color Wiener filtering in S2 to eliminate redundant information in the data and recover missing values are as follows:
[0087] S21: Determine the minimum and maximum values of the input dataset;
[0088] d i =I i +λ i (2)
[0089] Where, d i I represents the observed input data. i and λ i This indicates irrelevant information from the input data;
[0090] S22: Use CWF filtering to remove random values;
[0091]
[0092] In the formula, and Representing dimensional features, Let M represent the mean vector of the preprocessed data, and let M represent the CWF filter, which is determined by minimizing the mean square error (MSE) between the original data and the preprocessed data. The MSE is calculated by equation (4):
[0093]
[0094] S23: In the original input data, the preprocessed data is calculated according to formula (5):
[0095] M = OM(OM + ON) (5)
[0096] Where CM represents the covariance measure and CN represents unwanted information.
[0097] like Figure 2 As shown, the specific steps for selecting the optimal feature using the Tasmanian devil optimization algorithm in S3 are as follows:
[0098] S31. Population initialization: Randomly generate the initial population of TDO according to the constraints of feature selection, and score the members of the TDO population according to their positions in the search space;
[0099]
[0100] In the formula, Y represents the Tasmanian devil population, Y i Let y represent the i-th candidate solution. i,j Let N represent the candidate values for the j-th variable, N represent the number of searches for Tasmanian devils, and M represent the number of times the data was preprocessed.
[0101] S32. Randomly generate input parameters as candidate solutions: After initialization, based on the search space and boundary conditions of the problem described in S31, randomly generate a set of input parameters as candidate solutions for the Tasmanian Badger Optimization Algorithm (TDO), i.e., a set of possible feature subsets; at the beginning of each optimization round, randomly set the input parameters to allow them to explore different search regions; adjust the generation of input parameters according to hyperparameters, including population size, number of iterations, and exploration factor;
[0102] S33. Evaluating the quality of candidate solutions through the objective function: The quality of input parameters is evaluated through the objective function, which reflects the degree to which the characteristics of the selected input parameters conform to the problem objective; the objective function is shown in equation (1):
[0103]
[0104] In the formula, FF represents the objective function value, F i This represents the objective function value obtained from the i-th candidate solution;
[0105] During the iteration process, the candidate solutions to the problem described in S32 are substituted into the objective function to solve for the objective function value; the quality of the candidate solutions is obtained by analyzing the objective function value.
[0106] S34. Update the best member in the Tasmanian devil population based on the quality of the candidate solutions in S33. After iteration, obtain the optimal feature: TDO explores different regions in the scan search space to identify the original optimal region. Update the best member in the Tasmanian devil population based on either the carrion feeding strategy or the prey feeding strategy. Iterate and finally select the best feature.
[0107] S341: Carrion feeding strategy: The positions of other population members in the search space are assumed to be carrion locations; the k-th population member is selected as the target carrion for the i-th Tasmanian devil; k is randomly selected from 1 to N; the characteristics of random selection are represented in equation (7) as follows:
[0108] D i =Y k (7)
[0109] In the formula, i = 1, 2, ..., N and k ∈ {1, 2, ..., N | k ≠ i}, D i This represents the feature chosen by the i-th Tasmanian devil;
[0110] Based on the selected carrion, calculate the Tasmanian devil's new position in the search space: In the Tasmanian devil's movement simulation under this strategy, if the objective function value of the carrion is good, the Tasmanian devil moves towards the carrion, otherwise it moves away from the carrion; after calculating the Tasmanian devil's new position, if the objective function value at the new position is good, the new position is accepted, otherwise it remains at the original position.
[0111] S342: Selecting the optimal feature through prey-feeding strategy: The Tasmanian devil's prey-feeding process consists of two stages: In the first stage, it selects prey by scanning the area and attacks it; In the second stage, after approaching the prey, it chases the prey to stop it and begins to eat; The positions of other population members are assumed to be the positions of the prey, and the kth population member is randomly selected as the prey, where k is a natural random number between 1 and N, relative to i; The process is simulated in equation (8) as follows:
[0112] Q i =Y k ;i=1,2,...,N,k∈{1,2,...,N|k≠i} (8)
[0113] Q i Y represents the optimal feature selected by the Tasmanian devil. k This represents the k-th candidate solution;
[0114] Once the prey's location is determined, a new location is calculated for the Tasmanian devil. When calculating this new location, if the selected prey has a better objective function value, the Tasmanian devil will move towards it; otherwise, it will move away from the location. If the Tasmanian devil's new location improves the objective function value, it will replace the previous location.
[0115] S35: When all TDO members have been updated, one iteration of the algorithm ends; new values are calculated for the Tasmanian devil's position and objective function; then, the algorithm enters the next iteration, following S33-S34, continuing the TDO population update process until the algorithm iteration ends; during these iterations, TDO updates and stores the best candidate solution, and after the algorithm is fully implemented, TDO introduces the best candidate solution as the optimal feature.
[0116] Preferably, the specific steps for classifying and detecting anomalies in satellite communication transmission link traffic data in S4 are as follows:
[0117] S41. In step S3, the self-attention-driven temporary variational autoencoder generative adversarial network model SA-PVAEGAN is trained based on the training set after feature filtering; the model is evaluated and validated using the test set.
[0118] S42. Use the honey badger algorithm to optimize the optimal parameters of the adversarial network model, and apply HBA to fine-tune the weights and bias parameters of SA-PVAEGAN.
[0119] S43. Intrusion detection is performed using a trained adversarial network model, namely SA-PVAEGAN-HBA. Figure 3 As shown, the adversarial network model SA-PVAEGAN consists of three modules: a discriminator, a variational autoencoder, and a classifier. The discriminator distinguishes whether the input sample is a real sample or a virtual sample. The variational autoencoder includes an encoder and a generator. The generator uses the latent vectors generated by the encoder and random latent vectors to create virtual hyperspectral samples. The classifier classifies the input real samples and virtual samples.
[0120] Preferably, in step S42, the step of optimizing the optimal parameters of the honey badger algorithm model is as follows:
[0121] S421. Population Initialization: Population initialization is performed randomly within a set boundary range.
[0122] a i =lb i +s1×(ub i -lb i ), s i (9)
[0123] In the formula, a i The i-th potential solution in N populations, lb i and ub i These refer to the lower and upper boundaries of the search domain, respectively.
[0124] S422, Random Generation: After initialization, input parameters are randomly generated, and the best fitness value is selected based on their explicit hyperparameter states.
[0125] S423, Fitness Function: Creates a random solution from the initial values, and the resulting random solution is (D... i ) and z random Substituting the parameter values into the objective function, the fitness value is calculated. The higher the fitness value, the closer the current random solution is to the optimal solution. By solving the objective function, the parameter values (D) of the SAPVAEGAN classifier are optimized. i ) and z random Its expression is:
[0126] Fitness function =Optimization[(D i )and(Z random (10)
[0127] In the formula (D) i ) and z random These are the parameter values of the classifier;
[0128] S424. Update the density factor to optimize (D) i The density factor (α) controls time-varying randomization to ensure a smooth transition from exploration to development; the decreasing factor α, which decreases with the number of iterations, is updated to reduce randomness over time.
[0129] S425. Honey badger foraging behavior to optimize z randomm The intensity is related to the concentration of prey and the distance between the prey and the i-th honey badger, L i It is the intensity of the prey's scent. If the scent intensity is high, the honey badger will move quickly, and vice versa.
[0130] S426. Termination: Check if the attack classification meets the stopping condition. Otherwise, iterate and repeat steps S423-S425 until the stopping condition is met. Finally, the SA-PVAEGAN classifier accurately detects the attack type through HBA.
[0131] Preferably, in step S43, the discriminator comprises four convolutional layers, each with a 3*3 kernel size; the first two convolutional layers are applied before the self-attention module, and the output of the last convolutional layer is converted into a feature vector representation, and the normality of the data is evaluated by applying a Sigmoid process; the discriminator also incorporates label information, which is subjected to dimensionality reduction processing through a fully connected layer; in this embodiment, the discriminator D i The loss function is shown in equation (11):
[0132]
[0133] The first term is the GAN gradient penalty loss between a and H(z|b), which can improve the stability of the model. The second term is the discriminator loss, used to determine H(z|b). random Whether |b) is true or false is shown in formula (12):
[0134]
[0135]
[0136] Where z represents the latent vector generated by the encoder, z random Let z represent a randomly generated latent vector, and H(a|b) represent a virtual sample generated by the generator based on z and the relevant labels. random |b)) indicates that the generator is based on z random The generated virtual samples have associated labels, where b represents the label.
[0137] Preferably, in step S43, the variational autoencoder consists of two components: an encoder and a generator; the generator G i Virtual hyperspectral samples are created using latent vectors and then transferred from normal data to the latent vector space by encoder F. The encoder F consists of two spectral space feature extraction networks with the same network architecture: one spectral space feature extraction network is used to obtain the mean vector μ, and the other is used to determine the covariance f of the latent vector space. In this embodiment, after obtaining the mean vector μ and the covariance f, the latent vector is obtained using equation (14).
[0138]
[0139] Where z represents the potential vector.
[0140] Preferably, the encoder's spectral spatial feature extraction network includes four one-dimensional convolutional layers with 5*1 kernels; a self-attention mechanism is used in the first and second layers.
[0141] Preferably, the generator g i Four transposed convolutional layers and two fully connected layers are configured. The two fully connected layers are used to reshape the latent vectors and associated labels, converting them into three-dimensional data cubes, which are then transposed onto the transposed convolutional layers. The kernel size of the transposed convolutional layers is 3×3. Finally, a simulated hyperspectral sample is obtained. The latent vectors are generated by the encoder of a variational autoencoder (VAE) to generate virtual hyperspectral samples from normal data, a low-dimensional vector used to represent data that can capture the latent features and structure of the data.
[0142] Preferably, in step S43, the classifier includes: a spectral feature extraction network consisting of five one-dimensional convolutional layers with 1*5 kernels and a spatial feature extraction network consisting of five two-dimensional convolutional layers with 3*3 kernels; in the classifier, spectral and spatial information are fused and passed to two fully connected layers; in this embodiment, the LC loss function is as shown in equation (15):
[0143]
[0144] The first term is the classification result loss *a*, the second term is the sum of the paired feature matching losses between *a* and H(a|b), and the last term is the classification result (H(z)). random |b)) loss; λ1 and λ2 are The weights and random loss are shown in equation (16).
[0145]
[0146]
[0147]
[0148] Among them, e C This represents the attribute of the intermediate layer of the classifier, a real Let z represent the actual sample, and az represent the virtual sample generated after inputting the encoded latent vector z into the generator. This indicates that the latent vector will be created randomly. The virtual sample generated after inputting into the generator.
[0149] Example 2:
[0150] A satellite communication link transmission intrusion detection system based on an improved honey badger algorithm, comprising:
[0151] The module includes an acquisition module, a preprocessing module, a feature selection module, and a satellite communication transmission link intrusion detection module.
[0152] The acquisition module acquires satellite communication transmission link data.
[0153] The preprocessing module uses CWF technology to eliminate redundant information and recover missing values in the communication transmission link data. The redundant information may be some duplicate or irrelevant data, and the missing values may be some data lost due to transmission errors or insufficient sampling in the satellite communication transmission link data.
[0154] The feature selection module uses the preprocessed communication transmission link data as input for feature selection and employs the Tasmanian Badger Optimization Algorithm (TDO) to select the optimal feature.
[0155] The satellite communication transmission link intrusion detection module, based on optimal features, introduces a self-attention-driven temporary variational autoencoder generative adversarial network (SA-PVAEGAN-HBA) optimized by the Honey Badger Algorithm (HBA) to classify and detect anomalies in satellite communication transmission link traffic data.
[0156] Figure 5This is a structural block diagram of an electronic device provided in an embodiment of the present invention. The electronic device includes a memory 402, a processor 401, and a communication interface 403. The memory 402, processor 401, and communication interface 403 are electrically connected directly or indirectly to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines. The memory 402 can be used to store software programs and modules, such as the program instructions / modules corresponding to a production time adjustment and analysis system provided in this application embodiment. The processor 401 executes the software programs and modules stored in the memory 402 to perform various functional applications and data processing. The communication interface 403 can be used for signaling or data communication with other node devices. The memory 402 may be, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.
[0157] Processor 401 can be an integrated circuit chip with signal processing capabilities. Processor 401 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0158] It should be noted that the specific embodiments described above enable those skilled in the art to more fully understand the present invention, but do not limit the present invention in any way. Therefore, although the present invention has been described in detail with reference to the accompanying drawings and embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the present invention. In short, all technical solutions and improvements that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the present invention patent.
Claims
1. A satellite communication link transmission intrusion detection method based on an improved honey badger algorithm, characterized in that, Includes the following steps: S1. Data Collection: Collect ship satellite communication transmission link traffic data; S2. Data Preprocessing: In the preprocessing stage, color Wiener filtering is used to eliminate redundant information in the data and recover missing values. The redundant information may be some duplicate or irrelevant data that exists in the satellite communication transmission link data. The missing values may be data that is lost in the satellite communication transmission link data due to transmission errors or insufficient sampling. The preprocessing stage uses color Wiener filtering to eliminate redundant information in the data and recover missing values; S3. Feature Selection: Using the preprocessed data from S2 as input for feature selection, the Tasmanian devil optimization algorithm is used to obtain candidate solutions in the Tasmanian devil population by setting an objective function. The algorithm iteratively eliminates candidate solutions of low quality or local optima, ultimately obtaining the optimal feature. The objective function set in the Tasmanian devil optimization algorithm is: (1) FF represents the objective function value, FF represents the objective function value of the i-th candidate solution; S4. Satellite communication link transmission intrusion detection: Based on the optimal features obtained in S3, a self-attention-driven temporary variational autoencoder optimized by the Honey Badger Algorithm (HBA) is introduced, and a generative adversarial network model (SA-PVAEGAN-HBA) is used to classify and detect anomalies in satellite communication transmission link traffic data. The specific steps for selecting the optimal feature using the Tasmanian devil optimization algorithm in S3 are as follows: S31. Population initialization: Randomly generate the initial population of TDO according to the constraints of feature selection, and score the members of the TDO population according to their positions in the search space; (6) wherein denotes the population of badgers, denotes the i-th candidate solution, denotes the candidate value of the j-th variable, N denotes the number of times the badger is searched, and M denotes the number of times the data is preprocessed; S32. Randomly generate input parameters as candidate solutions: After initialization, based on the search space and boundary conditions of the problem in S31, randomly generate a set of input parameters as candidate solutions for the Tasmanian Badger Optimization Algorithm (TDO), i.e., a set of possible feature subsets; at the beginning of each round of optimization, randomly set the input parameters so that they can explore different search regions; adjust the generation of input parameters according to hyperparameters, including population size, number of iterations, and exploration factor; S33. Evaluating the quality of candidate solutions through the objective function: The quality of the input parameters is evaluated through the objective function, which reflects the degree to which the characteristics of the selected input parameters conform to the problem objective; the objective function is shown in equation (1): (1) wherein denotes the objective function value, denotes the objective function value of the i-th candidate solution; During the iteration process, the candidate solutions to the problem described in S32 are substituted into the objective function to solve for the objective function value; The quality of candidate solutions is determined by analyzing the objective function values. S34. Update the best member in the Tasmanian devil population based on the quality of the candidate solutions in S33. After iteration, obtain the optimal feature: TDO explores different regions in the scan search space to identify the original optimal region. Update the best member in the Tasmanian devil population based on either the carrion feeding strategy or the prey feeding strategy. Iterate and finally select the best feature. S341: Carrion feeding strategy: The positions of other population members in the search space are assumed to be carrion locations; the k-th population member is selected as the target carrion for the i-th Tasmanian devil; k is randomly selected from 1 to N; the characteristics of random selection are represented in equation (7) as follows: (7) wherein and , represents the selected feature of the ith badger. Based on the selected carrion, calculate the Tasmanian devil's new position in the search space: In the Tasmanian devil's movement simulation under this strategy, if the objective function value of the carrion is good, the Tasmanian devil moves towards the carrion, otherwise it moves away from the carrion; after calculating the Tasmanian devil's new position, if the objective function value at the new position is good, the new position is accepted, otherwise it remains at the original position. S342: Selecting the optimal feature through prey-feeding strategy: The Tasmanian devil's prey-feeding process consists of two stages: in the first stage, it selects prey by scanning the area and attacks it; in the second stage, after approaching the prey, it chases the prey to stop it and begins to eat; the positions of other population members are assumed to be the positions of the prey, and the kth population member is randomly selected as the prey, where k is a natural random number between 1 and N, relative to i; the process is simulated in equation (8) as follows: (8) wherein denotes the optimal feature selected by the meerkat, denotes the kth candidate solution; Once the prey's location is determined, a new location is calculated for the Tasmanian devil. When calculating this new location, if the selected prey has a better objective function value, the Tasmanian devil will move towards it; otherwise, it will move away from the location. If the Tasmanian devil's new location improves the objective function value, it will replace the previous location. S35: When all TDO members have been updated, one iteration of the algorithm ends; new values are calculated for the Tasmanian devil's position and objective function; then, the algorithm enters the next iteration, following S33-S34, to continue the TDO population update process until the algorithm iteration ends; during these iterations, TDO updates and stores the best candidate solution, and after the algorithm is fully implemented, TDO introduces the best candidate solution as the optimal feature; The specific steps for classifying and detecting anomalies in satellite communication transmission link traffic data in S4 are as follows: S41. In step S3, the self-attention-driven temporary variational autoencoder generative adversarial network model SA-PVAEGAN is trained based on the training set after feature selection; the model is evaluated and validated using the test set. S42. Use the honey badger algorithm to optimize the optimal parameters of the adversarial network model, and apply HBA to fine-tune the weights and bias parameters of SA-PVAEGAN. S43. Intrusion detection is performed using a trained adversarial network model, namely SA-PVAEGAN-HBA. The adversarial network model SA-PVAEGAN consists of three modules: a discriminator, a variational autoencoder, and a classifier. The discriminator distinguishes whether the input sample is a real sample or a virtual sample. The variational autoencoder includes an encoder and a generator. The generator uses the latent vector and random latent vector generated by the encoder to create virtual hyperspectral samples. The classifier classifies the input real samples and virtual samples.
2. The method for detecting intrusion in satellite communication link transmission based on the meerkat algorithm improvement according to claim 1, characterized in that, The specific steps to eliminate redundant information and recover missing values in the data using color Wiener filtering in S2 are as follows: S21: Determine the minimum and maximum values of the input dataset; (2) in, This represents the observed input data. and This indicates irrelevant information from the input data; S22: Use CWF filtering to remove random values; (3) wherein and denotes a dimensional feature, denotes a mean vector of the pre-processed data, M denotes a CWF filter determined by minimizing the mean square error (MSE) between the original data and the pre-processed data, the MSE being calculated by equation (4): (4) S23: In the original input data, the preprocessed data is calculated according to formula (5): (5) Where CM represents the covariance measure and CN represents unwanted information.
3. The method as claimed in claim 1, wherein the method for detecting the intrusion in the satellite communication link based on the improved meerkat algorithm is characterized by, In step S42, the steps for optimizing the optimal parameters of the honey badger algorithm model are as follows: S421. Population Initialization: Population initialization is performed randomly within a set boundary range. (9) wherein denotes the i-th potential solution in N populations, and denotes the lower and upper bound of the search domain, respectively; S422, Random Generation: After initialization, input parameters are randomly generated, and the best fitness value is selected based on their explicit hyperparameter states. S423, Fitness Function: Creates a random solution from the initial values, and the resulting random solution is... and The parameter values are substituted into the objective function to calculate its fitness value. The higher the fitness value, the closer the current random solution is to the optimal solution. By solving the objective function, the parameter values of the SAPVAEGAN classifier are optimized. and Its expression is: (10) In the formula and These are the parameter values of the classifier; S424, update the density factor to optimize : density factor Controlling time-varying randomization to ensure smooth transition from exploration to exploitation; Updating a decreasing factor with decreasing iteration number to reduce randomness over time: S425. Honey badger foraging behavior to be optimized The intensity is related to the concentration of prey and the distance between the prey and the i-th honey badger. It is the intensity of the prey's scent. If the scent intensity is high, the honey badger will move quickly, and vice versa. S426. Termination: Check if the attack classification meets the stopping condition. Otherwise, iterate and repeat steps S423-S425 until the stopping condition is met. Finally, the SA-PVAEGAN classifier accurately detects the attack type through HBA.
4. The satellite communication link transmission intrusion detection method based on the honey badger algorithm improved according to claim 1, characterized in that, In step S43, the discriminator contains four convolutional layers, each with a kernel size of 3*3. The first two convolutional layers are applied before the self-attention module, and the output of the last convolutional layer is converted into a feature vector representation. The normality of the data is evaluated by applying the Sigmoid process. The discriminator also incorporates label information, which is dimensionality reduced by a fully connected layer.
5. The satellite communication link transmission intrusion detection method based on the honey badger algorithm improved according to claim 1, characterized in that, In step S43, the variational autoencoder consists of two components: an encoder and a generator; the generator... Virtual hyperspectral samples are created using latent vectors and then transferred from normal data to the latent vector space by an encoder F. The encoder F consists of two spectral space feature extraction networks with the same network architecture: one spectral space feature extraction network is used to obtain the mean vector μ, and the other is used to determine the covariance f of the latent vector space.
6. The method for detecting input intrusion in a satellite communication link based on the meerkat algorithm improvement according to claim 5, characterized in that, The encoder's spectral spatial feature extraction network includes four one-dimensional convolutional layers with 5*1 kernels; a self-attention mechanism is used in the first and second layers.
7. The method as claimed in claim 5, wherein the method for detecting the intrusion in the satellite communication link based on the improved meerkat algorithm is characterized by, The generator The system uses four transposed convolutional layers and two fully connected layers. Two fully connected layers are used to reshape the data containing latent vectors and associated labels, converting it into a 3D data cube, which is then transposed into the transposed convolutional layers. The kernel size of the transposed convolutional layers is [missing information]. Finally, a simulated hyperspectral sample is obtained; the latent vector is generated by the encoder of the variational autoencoder (VAE) to generate virtual hyperspectral samples from normal data, a low-dimensional vector for representing data that can capture the latent features and structure of the data.
8. The satellite communication link transmission intrusion detection method based on the honey badger algorithm improved according to claim 1, characterized in that, In step S43, the classifier includes: a spectral feature extraction network consisting of five one-dimensional convolutional layers with 1*5 kernels and a spatial feature extraction network consisting of five two-dimensional convolutional layers with 3*3 kernels; in the classifier, spectral and spatial information are fused and passed to two fully connected layers.
9. A honey badger algorithm based improved satellite communication link intrusion detection system formed by the method of any one of claims 1-8, wherein, include: The module includes an acquisition module, a preprocessing module, a feature selection module, and a satellite communication transmission link intrusion detection module. The acquisition module acquires satellite communication transmission link data; The preprocessing module uses CWF technology to eliminate redundant information and recover missing values in the communication transmission link data. The redundant information may be some duplicate or irrelevant data, and the missing values may be some data lost due to transmission errors or insufficient sampling in the satellite communication transmission link data. The feature selection module takes the preprocessed communication transmission link data as input for feature selection and uses the Tasmanian devil optimization algorithm (TDO) to select the optimal feature. The satellite communication transmission link intrusion detection module, based on optimal features, introduces a self-attention-driven temporary variational autoencoder generative adversarial network (SA-PVAEGAN-HBA) optimized by the Honey Badger Algorithm (HBA) to classify and detect anomalies in satellite communication transmission link traffic data.