Anti-interference method, device and computer equipment for an industrial wireless network
By real-time monitoring and optimization of industrial wireless network performance data, combining LSTM neural network and random forest machine learning model for abnormal detection, and using the Starberg game model to select anti-interference channels, the problem of inaccurate detection of intelligent interference attacks is solved and the security and reliability of the network is improved.
Patent Information
- Application Number
- CN202410067687.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-17
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-01-17
AI Technical Summary
When facing intelligent jamming attacks, the existing technology lacks real-time monitoring of industrial wireless network performance data, resulting in insufficient detection and defense of jamming attacks.
By collecting industrial wireless network performance parameters, time-series data sets are constructed, and the data sets are optimized using correlation and collinear analysis. Anomaly classification is performed using LSTM neural network, a random forest machine learning model performs anomaly classification process of node communication feature vectors, and finally a Starberg game model is constructed to select the optimal anti-interference channel.
Real-time performance monitoring and abnormal detection of industrial wireless networks are realized, the accuracy and anti-interference ability of interference attack detection are improved, and the reliability and security of the network are ensured.
Smart Images

Figure CN117858090B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things network security in the field of information security, and particularly to an anti-interference method, device and computer device for industrial wireless networks. Background Art
[0002] In order to achieve high-reliability and low-power communication, the Time Slotted Channel Hopping (TSCH) technology has been introduced in industrial wireless networks. This technology is widely used in the IEEE 802.15.4e protocol standard, which is designed specifically for Low-Power Wireless Sensor Networks (LPWSNs) in industrial environments. As one of its important communication mechanisms, TSCH divides time into small time slots and hops frequencies in different time slots to achieve multipath transmission and spectrum diversity. This design enables the network to maintain a stable communication connection in an industrial environment affected by interference. However, attackers can analyze the time slot and frequency information of nodes by listening to network traffic, and then launch interference attacks to disrupt the normal operation of the network. The intelligent interference attack is a specific attack method against TSCH networks. The attacker precisely interferes with specific time slots and frequencies to disrupt the communication of network nodes. This may lead to packet loss, increased communication latency, and even network collapse. Therefore, it is of great security significance to establish a set of detection and security defense methods for interference attacks in industrial wireless networks based on time slot hopping.
[0003] Currently, the intelligent methods of industrial Internet of Things (IIoT) intrusion detection systems (IDS) mainly include methods based on machine learning (ML) and deep learning (DL). Facing the threat of intelligent interference attacks, it may lead to serious consequences such as data leakage, device damage, and production interruption. Therefore, effective security methods are needed to protect industrial IoT systems. The application of intelligent methods in intrusion detection systems mainly uses machine learning or deep learning to build models of network behavior, and then judges whether there are abnormalities or attacks in network traffic according to the models. However, there are relatively few invention patents and related literature on interference attacks that jointly analyze industrial IoT network performance data and node packet data based on the combination of machine learning and deep learning.
[0004] In the research on interference attack defense strategies, game models are a hot topic in this field. Game models comprehensively analyze the dynamic interaction between intelligent interference attacks and TSCH networks, considering not only the strategies of attackers but also the adaptive competition relationships among network nodes. Through in-depth research on game models, researchers have proposed a series of intelligent frequency hopping strategies based on game theory, aiming to enable TSCH networks to more flexibly respond to the changing strategies of attackers.
[0005] When existing game models are applied to information decision-making in industrial Internet of Things, they suffer from the problems of ignoring uncertainty, complexity, and real-time nature. Uncertainty factors such as sensor data noise, communication delays, and device failures will affect the information accuracy of game models. Some game models ignore the influence of such factors and cannot guarantee the reliability of actual scenario applications; at the same time, complex network topologies increase the difficulty of modeling and solving game models. The models require long-time calculations and analyses, and most game models will not meet the real-time requirements; therefore, it is necessary to improve the reliability, accuracy, and real-time nature of game models in industrial Internet of Things information decision-making by researching and improving aspects such as the modeling method, algorithm solving, and decision evaluation of game models.
[0006] Most of the existing interference detection methods are for detecting interference attacks based on node packet data analysis, lacking real-time monitoring and data collection of network performance parameters, and unable to accurately reflect the real-time operation actions and states of industrial wireless networks, resulting in inaccurate interference attack detection and anti-interference defense. Summary of the Invention
[0007] To solve the problem in the prior art that the industrial Internet of Things system lacks monitoring of network performance data when being subjected to intelligent interference attacks, resulting in inaccurate interference attack detection and defense of the network, the present invention provides an anti-interference method, device, and computer device for industrial wireless networks.
[0008] To achieve the above object, the present invention provides the following technical solutions:
[0009] An anti-interference method for an industrial wireless network, the method includes:
[0010] Collect industrial wireless network performance parameters and construct a time series data set;
[0011] Optimize the time series data set by using correlation and collinearity analysis, and combine the screened and optimized performance parameters into an optimized data set;
[0012] Use an LSTM neural network to perform anomaly classification processing on the optimized data set, and obtain the anomaly situation of network performance according to the classification result;
[0013] When network performance anomalies are detected, communication nodes collect the network's packet reception and transmission data, extract node communication feature vectors from the packet reception and transmission data, and use a random forest machine learning model to perform anomaly classification on the node communication feature vectors. Based on the classification results, adjacent abnormal communication nodes and normal communication nodes are obtained;
[0014] Select the interference channel sequence of the abnormal communication node and the anti-interference channel sequence of the current communication node. Construct a Stackelberg game model based on the interference channel sequence and the anti-interference channel sequence, solve the game equilibrium solution of the game model, and select the optimal anti-interference channel according to the game equilibrium solution.
[0015] Further, the performance parameters include packet transmission rate, signal-to-noise ratio, expected transmission number, and energy consumption.
[0016] Further, the packet reception and transmission data includes packet size, transmission time, target node IP, and protocol type. The communication feature vector is a new feature value generated by dividing the packet reception and transmission data into several frames in seconds.
[0017] Further, the construction of the LSTM neural network includes: constructing multiple LSTM layers and fully connected layers, determining the number of neurons in the LSTM layer according to network complexity and network performance parameters; adding Dropout layers between multiple LSTM layers; and selecting non-linear hyperbolic tangent activation functions and Sigmoid activation functions for the threshold mechanism and output layer in the control unit of the LSTM layer, respectively.
[0018] Further, the steps of constructing a Stackelberg game model based on the interference channel sequence and the anti-interference channel sequence include: creating a set of interference channel sequence strategies and a corresponding probability matrix of the interference channel sequence for the abnormal communication node, creating a set of anti-interference channel sequence strategies and a corresponding probability matrix of the anti-interference channel sequence for the current communication node; setting the abnormal communication node as the leader and the current communication node as the follower; using the Q-learning algorithm and the random selection theory to solve the game Nash equilibrium solution of the model, and selecting the optimal anti-interference channel according to the equilibrium solution.
[0019] Further, optimizing the time series data set by using correlation and collinearity analysis specifically includes: obtaining the correlation between time series data set parameters through the Pearson correlation coefficient; obtaining the collinearity between time series data set parameters through the variance inflation factor of multivariate regression analysis.
[0020] Further, the Pearson correlation coefficient between two performance parameters is:
[0021]
[0022] where f 1 and f2 is a performance parameter, x i and y i are the performance parameters f 1 and f 2 eigenvalues, represents the arithmetic mean of the performance parameter f j where N is a positive integer.
[0023] Furthermore, the variance inflation factor of the multiple regression analysis is:
[0024]
[0025]
[0026] where i = 1, 2, 3, …, k, k is a positive integer, R i 2 is the coefficient of determination after the regression analysis of the i-th dependent variable performance parameter against the remaining k - 1 independent variable performance parameters, y i , represent the actual value, predicted value, and mean value of the i-th performance parameter respectively.
[0027] An anti-interference device for an industrial wireless network, comprising:
[0028] A first data collection module, configured to collect industrial wireless network performance parameters and construct a time series data set;
[0029] A first anomaly detection module, configured to optimize the time series data set by using correlation and collinearity analysis, combine the screened and optimized performance parameters into an optimized data set; perform anomaly classification processing on the optimized data set by using an LSTM neural network, and obtain the anomaly situation of the network performance according to the classification result;
[0030] A second data collection module, configured to collect the packet receiving and sending data of the network by a communication node, and extract the node communication feature vector from the packet receiving and sending data;
[0031] A second anomaly detection module, configured to perform anomaly classification processing on the node communication feature vector by using a random forest machine learning model, and obtain adjacent anomaly communication nodes and normal communication nodes according to the classification result;
[0032] A defense module, configured to select the interference channel sequence of the anomaly communication node and the anti-interference channel sequence of the current communication node, construct a Stackelberg game model according to the interference channel sequence and the anti-interference channel sequence, solve the game equilibrium solution of the game model, and select the optimal anti-interference channel according to the game equilibrium solution.
[0033] A computer device includes a memory and a processor. The memory stores computer execution instructions, and the processor executes the computer execution instructions stored in the memory to implement an anti-interference method for an industrial wireless network as described above.
[0034] The anti-interference method for an industrial wireless network provided by the present invention has the following beneficial effects:
[0035] By real-time monitoring and data collection of network performance parameters, the present invention can accurately reflect the real-time operation actions and states of the industrial wireless network, providing reliable data support for subsequent anti-interference methods; using correlation and collinearity analysis to optimize the time series data set, this step can eliminate irrelevant parameters and reduce data redundancy, improve data quality, simplify the data set, and enhance the anomaly detection ability of the industrial wireless network; then, using the LSTM neural network to perform anomaly classification on the optimized data set, real-time monitoring and classification are realized in the continuously updated data stream, and abnormal situations of network performance are timely discovered and identified, providing timely data support and decision-making basis for subsequent interference defense and network optimization; then, only when the network performance parameters are abnormal, the communication node will collect packet sending and receiving data, and then extract the node communication feature vector from the packet sending and receiving data. On the one hand, it can reduce the number of self-anomaly detections of the communication node to achieve the purpose of energy saving, and on the other hand, use the random forest machine learning model for anomaly classification to obtain the abnormal situation of the current communication node, which can realize automatic anomaly detection, reduce the need for manual intervention, and improve the efficiency and accuracy of the entire anomaly processing process; the game solution method based on the Stackelberg game model has a certain degree of self-adaptability and robustness. When new interference situations occur in the network, the game equilibrium solution can be recalculated to achieve adaptive interference resistance and network optimization. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the embodiments of the present invention and their design schemes, the accompanying drawings required for this embodiment will be briefly introduced below. The accompanying drawings in the following description are only partial embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0037] Figure 1 Schematic diagram of constructing an anomaly detection model based on network performance data for an embodiment of the present invention.
[0038] Figure 2 Schematic diagram of constructing an anomaly detection model based on node packet data for an embodiment of the present invention.
[0039] Figure 3 Schematic diagram of an anti-interference attack security defense mechanism for an embodiment of the present invention.
[0040] Figure 4 It is a schematic diagram of the overall architecture of the device according to an embodiment of the present invention. Specific embodiments
[0041] In order to enable those skilled in the art to better understand the technical solution of the present invention and be able to implement it, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the protection scope of the present invention.
[0042] Time slot hopping is a core technology in current industrial wireless networks. Aiming at the interference attack problem of time slot hopping in industrial wireless networks, the present invention provides an anti-interference method for industrial wireless networks, which supports anomaly detection of industrial wireless network performance data and node packet data, and security defense and avoidance of interference attacks. This method effectively improves the reliability and security of industrial wireless networks in an interference attack environment.
[0043] This solution collects key performance parameters of the TSCH network through a Network Performance Analyzer (NPA) to construct a time series data set for subsequent analysis. The data set is optimized by correlation and collinearity analysis, and key indicators are selected to construct the final feature set to improve the interpretability and generalization ability of the model. Then, an LSTM (Long Short-Term Memory) neural network is used for anomaly classification processing to capture temporal and long-term dependencies and effectively identify anomalies in network performance. Next, a random forest algorithm is used for intelligent attack detection of nodes based on packet data, features are extracted from detailed packet data, and a machine learning model is constructed to achieve real-time detection of intelligent attacks. Finally, through the Stackelberg game model, the interference attack and defense problem is modeled as a game, enabling nodes to dynamically adjust channel selection, reducing channel conflicts with intelligent interference nodes, and thus effectively reducing the impact of interference.
[0044] Method embodiments
[0045] The present invention provides an anti-interference method for industrial wireless networks, including the following steps:
[0046] Step 1: Collect industrial wireless network performance parameters and construct a time series data set.
[0047] Specifically, as Figure 1As shown, the network performance analyzer (NPA) is used to collect the performance parameters related to the TSCH network. Relevant parameters are configured to achieve real-time performance monitoring, and the key performance indicators of each node are recorded, such as Packet Delivery Ratio (PDR), Signal to Noise Ratio (SNR), Expected Transmission Count (EXT), Energy Consumption (EC), etc. The performance parameter sets are collected in the environments with and without interference attacks respectively. Finally, by organizing the collected multi-index performance parameter data, an ordered time-series data set is formed, and its timeliness and integrity contribute to the effective implementation of subsequent intelligent interference attack detection.
[0048] Step 2: Optimize the time-series data set by using correlation and collinearity analysis, and combine the screened and optimized performance parameters into an optimized data set.
[0049] Specifically, the above time-series data set is screened and processed to establish an optimized data set. By calculating the Pearson correlation coefficient, the strength and direction of the linear relationship between the performance parameters of the indicators are evaluated. At the same time, multivariate regression analysis is used for collinearity detection to deeply understand the correlation and collinearity between the indicators. Before performing correlation and collinearity analysis, outlier detection and processing are carried out on the time-series data set to improve the accuracy of the analysis results. Then, based on the results of correlation and collinearity analysis, the indicators that are most critical for interference attack detection and network security defense are selected to form the final feature set. Finally, the screened and optimized features are combined into an optimized data set. This process helps to ensure that the selected feature set has less correlation and weaker collinearity, which can improve the interpretability and generalization ability of the model using this data subsequently, so as to meet better anti-interference ability and security. Appropriate numbers of communication nodes are added according to the actual network requirements to construct the TSCH network.
[0050] This example includes two types of experimental environments, namely the normal experimental environment without interference nodes and the intelligent interference attack experimental environment with interference nodes.
[0051] Configure the network performance analyzer (NPA) on each communication node to collect relevant performance parameters, including performance parameters such as Packet Delivery Ratio (PDR), Signal to Noise Ratio (SNR), Expected Transmission Count (EXT), Energy Consumption (EC), etc.; start the network and save the collected time-series performance data.
[0052] Specifically, outliers in the saved time-series dataset are detected, and the visualization method of box plot is used to check the data distribution. Data points in the dataset that are less than the lower quartile minus 1.5 times the interquartile range or greater than the upper quartile plus 1.5 times the interquartile range are defined as outliers. The linear interpolation method is used to correct the adjacent time-series data (t 1 ,y 1 ) and (t 3 ,y 3 ) according to the following formula:
[0053]
[0054] where t 2 is the time-axis value of the outlier index. Data points in the dataset that are less than the lower edge or greater than the upper edge are defined as extreme outliers and are directly deleted.
[0055] The Pearson product-moment correlation coefficient (PCC) is used to evaluate the strength and direction of the linear relationship between index performance parameters. The correlation coefficient between each pair of index performance parameters is:
[0056]
[0057] where f 1 and f 2 are performance parameters, x i and y i are the eigenvalue of performance parameters f 1 and f 2 respectively, represents the arithmetic mean of performance parameter f j , and N is a positive integer. Features with the absolute value of the Pearson correlation coefficient within 0.39 (inclusive) are selected as subsequent analysis indicators.
[0058] The variance inflation factor (VIF) is used to evaluate the collinearity degree between index performance parameters. The variance inflation factor of index performance parameters:
[0059]
[0060]
[0061] where i = 1, 2, 3, …, k, k is a positive integer, R i 2 is the coefficient of determination after the i-th dependent variable performance parameter is regressed against the remaining k - 1 independent variable performance parameters, yi , respectively represent the actual value, predicted value, and mean value of the i-th performance parameter.
[0062] For the time series data set analyzed by correlation and collinearity above, the performance parameters after screening and optimization are combined into an optimized data set. The optimized data set is subjected to data normalization processing. The Min-Max Scaling method is selected to maintain the relative relationship and proportional relationship between the original data:
[0063]
[0064] where X, X min , and X max respectively represent the original value, minimum value, and maximum value of the original index data;
[0065] Step 3: Use an LSTM neural network to perform anomaly classification on the optimized data set, and obtain the anomaly situation of the network performance according to the classification results.
[0066] Specifically, create a Sequential model, and select an appropriate number of LSTM layer neurons according to the network complexity and data set characteristics. Add a Dropout layer between the LSTM layers to prevent overfitting problems. The threshold mechanism in the control unit and the output layer respectively select the Sigmoid activation function (S-shaped function) and the non-linear Tanh activation function (hyperbolic tangent function) to help limit the gradient propagation and make it easier to train to increase the non-linearity. The output layer is a single neuron with a Tanh activation function for binary classification problems, representing normal and abnormal categories.
[0067] Select the binary cross entropy loss function (Binary cross entropy, BCE):
[0068]
[0069] where y is the true binary classification label, is the model prediction output. The optimizer algorithm selects Adam (Adaptive Moment Estimation):
[0070]
[0071] where η represents the learning rate, and respectively represent the estimated values of the first moment and the second moment after bias correction. The prediction evaluation system selects accuracy, precision, and recall to evaluate the model performance.
[0072] Set the batch size and the number of epochs, and determine the optimal hyperparameters through cross-validation.
[0073] The trained network model is deployed in the cloud server. By receiving the time-series performance data sent by the border router, it judges whether there is an intelligent interference attack behavior in the network. When there is an intelligent interference attack behavior in the network, the following steps are used to locate specifically which nodes are interfered and attacked and become abnormal communication nodes. The LSTM neural network has excellent sequence modeling ability and long-term and short-term memory ability, can more accurately reflect the complex time-series characteristics and abnormal situations in the network, and improve the accuracy and stability of anomaly detection.
[0074] Step 4: When network performance anomalies are found, the communication nodes collect the network's packet reception and transmission data, then extract the node communication feature vectors from the packet reception and transmission data, and use a random forest machine learning model to perform anomaly classification processing on the node communication feature vectors, and obtain adjacent abnormal communication nodes and normal communication nodes according to the classification results.
[0075] Specifically, as Figure 2 shown, each communication node collects packet reception and transmission data, including packet size, transmission time, target node IP, protocol type information. Ensure that sufficient sample data is obtained during the collection process and cover the situations of normal communication and intelligent interference attack types; divide the original data into several frames in seconds to generate new feature values, and establish a new feature vector dataset through statistical calculation.
[0076] Complete the node intelligent attack detection based on packet data by using the machine learning algorithm of random forest. First, collect detailed packet reception and transmission data from each node, including key information such as packet size, transmission time, target node IP, protocol type, etc. Extract key features from the packet data to form a node communication feature vector dataset, and the labels of the dataset include normal communication simulation and communication simulation with intelligent interference attack.
[0077] Divide the dataset into a training set and a test set, and build a random forest machine learning model based on the node communication feature vectors. The model uses the k-fold cross-validation method to improve the generalization ability of the training results. Calculate the accuracy, precision, recall, and F1 value to evaluate the model effect and select appropriate hyperparameters;
[0078] Deploy the trained random forest model to the node network, detect the node communication data in real time, and update the model regularly to adapt to the changing network environment.
[0079] Construct a random forest machine learning model based on the node communication feature vector, and learn the differences between intelligent attacks and normal communications through training. Deploy the trained random forest model into the node network to detect and judge the node communication data in real time, obtain the adjacent abnormal communication nodes and normal communication nodes of the current communication node. By obtaining the adjacent abnormal communication nodes and normal communication nodes, the specific nodes with abnormalities in the network can be quickly located, which helps to take measures in time for interference troubleshooting and repair, and improve the stability and reliability of the network.
[0080] Step 5: Select the interference channel sequence of the abnormal communication node and the anti-interference channel sequence of the current communication node, construct a Stackelberg game model based on the interference channel sequence and the anti-interference channel sequence, solve the game equilibrium solution of the game model, and select the optimal anti-interference channel according to the game equilibrium solution.
[0081] Specifically, as Figure 3 shown, construct a Stackelberg game model with the interference channel sequence selected by the above abnormal communication node and the anti-interference channel sequence selected by the current communication node, use the random selection theory and Q-learning algorithm to solve the game equilibrium solution, and the communication node dynamically adjusts its channel selection to reduce the channel conflict with the intelligent interference node, thereby reducing the impact of interference. The specific process is as follows:
[0082] Create a set of strategies a u = {a 1 , a 2 , …, a n} of the interference channel sequences selected by the adjacent abnormal communication nodes of the current communication node and the corresponding probability matrix of the selected channel sequences, and create a set of strategies a j = {a n+1 , a n+2 , …, a 2n} of the anti-interference channel sequences selected by the current communication node and the corresponding probability matrix of the selected channel sequences; the probability matrix is created using the random selection theory;
[0083] Construct a Stackelberg game model based on the interference channel sequence selected by the abnormal communication node and the anti-interference channel sequence selected by the current communication node. Assume that the abnormal communication node is the leader and the current communication node is the follower in the game;
[0084] Define the utility functions of the abnormal communication node (interference node) and the current communication node to represent the effects of their channel selection in anti-interference and interference execution in the game. The Q-learning algorithm and the random selection theory are used to solve the Nash equilibrium solution of the game. The current communication node selects the optimal hopping channel according to the final Nash equilibrium solution, so that the current communication node dynamically adjusts the channel selection, reduces the channel conflict with the intelligent interference node, effectively reduces the impact of interference, and improves the accuracy of network interference attack detection.
[0085] The prior art generally only considers the detection method for node packet data combined with machine learning algorithms. The present invention establishes a multi-index parameter data set. By collecting and analyzing the multi-index performance parameters of the TSCH network, more comprehensive and accurate performance monitoring results are obtained, which helps the effective implementation of subsequent intelligent interference attack detection.
[0086] The machine learning and deep learning methods adopted in the prior art do not perform statistical analysis on the indicators at the feature selection level, resulting in certain limitations in the interpretability and generalization of the model. In the process of screening and processing the indicator variables, the present invention constructs an optimized data set through methods such as calculating the Pearson correlation coefficient and multivariate regression analysis, improving the interpretability and generalization ability of the model.
[0087] The prior art rarely takes into account the temporal nature of network performance data. Most neural networks are unable to dynamically learn the features and patterns in the sequence when processing sequence data. The present invention introduces an LSTM neural network to perform abnormal classification processing on the time-series data set of the slot-hopping industrial wireless network, which can effectively capture the long-term dependence relationship of temporality and memory, and realize the effective classification of network performance anomalies.
[0088] The game models in the prior art cannot be adjusted according to the changes in the environment and the strategies of the attackers, and cannot fully adapt to the changing interference environment and intelligent attacks. The present invention constructs a frequency-hopping defense strategy by combining Stackelberg game knowledge, which is more dynamic than other strategies, has stronger anti-interference ability, and has a solid theoretical support.
[0089] Device Embodiment
[0090] The present invention provides an anti-interference device for an industrial wireless network, specifically as Figure 4 shown, including a network performance data collection module (the first data collection module), an anomaly detection module based on network performance data (the first anomaly detection module), a node packet data collection module (the second data collection module), an anomaly detection module based on node packet data (the second anomaly detection module), and an anti-interference attack security defense module (the defense module).
[0091] (1) Network Performance Data Collection Module
[0092] Collect TSCH network-related performance parameters through a Network Performance Analyzer (NPA). Configure relevant parameters to achieve real-time performance monitoring and record key performance indicators of each node, such as Packet Delivery Ratio (PDR), Signal-to-Noise Ratio (SNR), Expected Transmission (EXT), Energy Consumption (EC), etc. Collect performance parameter sets in both interference attack and non-interference attack environments. Finally, organize the collected multi-metric performance parameter data to form an ordered time-series data set, and its timeliness and completeness contribute to the effective implementation of subsequent intelligent interference attack detection.
[0093] (2) Abnormal Detection Module Based on Network Performance Data
[0094] The LSTM model deployed in the cloud server analyzes the time-series performance data sent by the TSCH network through the border router, and realizes the detection of the binary classification problem of normal and interference anomalies through feature extraction and pattern recognition. The module combines deep learning and time-series analysis methods to achieve real-time monitoring and anomaly detection of the TSCH network.
[0095] (3) Node Packet Data Collection Module
[0096] The collection module collects the packet sending and receiving data of each communication node, including information such as packet size, sending time, target node IP, protocol type, etc., divides it into several frames in seconds to generate new feature values, and establishes a new feature vector data set through statistical calculation. The main function of this module is to collect, process and transform node communication data and convert it into feature vector data available for subsequent modules.
[0097] (4) Abnormal Detection Module Based on Node Packet Data
[0098] Use a random forest machine learning model to perform real-time detection on node communication data. The trained random forest model is deployed in the network node to detect node communication data in real time and update the model regularly to adapt to the changing network environment. The main function of this module is to achieve the detection and early warning of intelligent interference attacks and ensure the security and reliability of node communication data.
[0099] (5) Anti-Interference Attack Security Defense Module
[0100] The anti-jamming security defense module is a key component deployed in each network node, aiming to solve the anti-jamming attack problem. By establishing a Stackelberg game model and a utility function, a game equilibrium solution is achieved between the anti-jamming channel sequence selected by the current communication node (communication node) and the interference channel sequence selected by the abnormal communication node (jamming node), so as to select the optimal frequency hopping channel strategy to resist interference. This module continuously iteratively updates the strategy set, quickly responds to jamming attacks, and improves the security and reliability of the network. This module ensures the self-defense ability at the node level and effectively protects the integrity and confidentiality of communication data.
[0101] Device Embodiment
[0102] The present invention provides a computer device, including a memory and a processor. The memory stores computer execution instructions, and the processor executes the computer execution instructions stored in the memory to implement an anti-jamming method for an industrial wireless network as described above. The method has been described in detail in the method embodiment and will not be elaborated here.
[0103] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0104] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0105] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions specified in Figure 1 one or more flows and / or blocks Figure 1The functions specified in one or more boxes.
[0106] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps of the functions specified in Figure 1 one process or more processes and / or boxes Figure 1 the functions specified in one box or more boxes.
[0107] It should be noted that the above-described specific embodiments can enable those skilled in the art to understand the present invention more comprehensively, but do not limit the present invention in any way. Therefore, although the present specification and embodiments have described the present invention in detail, those skilled in the art should understand that the present invention can still be modified or equivalently replaced; and all technical solutions and improvements that do not depart from the spirit and scope of the present invention are covered by the protection scope of the patent of the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.
Claims
1. An anti-interference method for an industrial wireless network, characterized in that: The method comprises: Collect industrial wireless network performance parameters and build a time series data set; Optimizing the time series data set by using correlation and collinearity analysis, and combining the screened and optimized performance parameters into an optimized data set; An LSTM neural network is used to perform abnormal classification processing on the optimized data set, and the abnormal situation of network performance is obtained according to the classification result; When abnormal network performance is found, the communication node collects the network's packet transmission and reception data, extracts the node communication feature vector from the packet transmission and reception data, and uses the random forest machine learning model to perform abnormal classification processing on the node communication feature vector, and obtains adjacent abnormal communication nodes and normal communication nodes according to the classification results; Selecting an interference channel sequence of an abnormal communication node and an anti-interference channel sequence of a current communication node, constructing a Starberg game model according to the interference channel sequence and the anti-interference channel sequence, solving a game equilibrium solution of the game model, and selecting an optimal anti-interference channel according to the game equilibrium solution; The step of constructing the Starberg game model according to the interference channel sequence and the anti-interference channel sequence includes: creating an interference channel sequence strategy set and a probability matrix of the corresponding interference channel sequence for the abnormal communication node, and creating an anti-interference channel sequence strategy set and a probability matrix of the corresponding anti-interference channel sequence for the current communication node; setting the abnormal communication node as a leader and the current communication node as a follower; using the Q learning algorithm and random selection theory to solve the game Nash equilibrium solution of the model, and selecting the optimal anti-interference channel according to the equilibrium solution; The optimization of the time series data set by using correlation and collinearity analysis specifically includes: obtaining the correlation between the performance parameters of the time series data set by using the Pearson correlation coefficient; obtaining the collinearity between the performance parameters of the time series data set by using the variance inflation factor of the multivariate regression analysis; The Pearson correlation coefficient between two performance parameters is: Among them, f1 and f2 are performance parameters, x i and i are the characteristic values of performance parameters f1 and f2, Representative performance parameter f j The arithmetic mean of , N is a positive integer; The variance inflation factor for the multivariate regression analysis is: Where i = 1, 2, 3, ..., k, k is a positive integer, R i 2 is the judgment coefficient after regression analysis of the i-th dependent variable performance parameter on the remaining k-1 independent variable performance parameters, y i , Represent the actual value, predicted value and mean value of the i-th performance parameter respectively.
2. The anti-interference method in an industrial wireless network according to claim 1, characterized in that: The performance parameters include data packet transmission rate, signal-to-noise ratio, expected transmission number, and energy consumption.
3. The anti-interference method in an industrial wireless network according to claim 1, characterized in that: The packet data includes data packet size, sending time, target node IP and protocol type, and the communication feature vector is a new feature value generated by dividing the packet data into several frames per second.
4. The anti-interference method in an industrial wireless network according to claim 1, characterized in that: The construction of the LSTM neural network includes: constructing multiple LSTM layers and fully connected layers, determining the number of LSTM layer neurons according to the network structure and network performance parameters; adding a Dropout layer between multiple LSTM layers; and selecting a Sigmoid activation function and a nonlinear hyperbolic tangent activation function in a threshold mechanism in a control unit of the LSTM layer and an output layer, respectively.
5. An anti-interference device for an industrial wireless network, characterized in that: include: A first data collection module is used to collect industrial wireless network performance parameters and construct a time series data set; The first anomaly detection module is used to optimize the time series data set by using correlation and collinearity analysis, and combine the screened and optimized performance parameters into an optimized data set; use an LSTM neural network to perform anomaly classification processing on the optimized data set, and obtain the abnormal situation of network performance according to the classification result; The second data collection module is used for the communication node to collect the packet data of the network, and then extract the node communication feature vector from the packet data; A second anomaly detection module is used to perform anomaly classification processing on the node communication feature vector using a random forest machine learning model, and obtain adjacent abnormal communication nodes and normal communication nodes according to the classification results; A defense module, used to select an interference channel sequence of an abnormal communication node and an anti-interference channel sequence of a current communication node, construct a Starberg game model according to the interference channel sequence and the anti-interference channel sequence, solve the game equilibrium solution of the game model, and select the optimal anti-interference channel according to the game equilibrium solution; The step of constructing the Starberg game model according to the interference channel sequence and the anti-interference channel sequence includes: creating an interference channel sequence strategy set and a probability matrix of the corresponding interference channel sequence for the abnormal communication node, and creating an anti-interference channel sequence strategy set and a probability matrix of the corresponding anti-interference channel sequence for the current communication node; setting the abnormal communication node as a leader and the current communication node as a follower; using the Q learning algorithm and random selection theory to solve the game Nash equilibrium solution of the model, and selecting the optimal anti-interference channel according to the equilibrium solution; The optimization of the time series data set by using correlation and collinearity analysis specifically includes: obtaining the correlation between the performance parameters of the time series data set by using the Pearson correlation coefficient; obtaining the collinearity between the performance parameters of the time series data set by using the variance inflation factor of the multivariate regression analysis; The Pearson correlation coefficient between two performance parameters is: Among them, f1 and f2 are performance parameters, x i and i are the characteristic values of performance parameters f1 and f2, Representative performance parameter f j The arithmetic mean of , N is a positive integer; The variance inflation factor for the multivariate regression analysis is: Where i = 1, 2, 3, ..., k, k is a positive integer, R i 2 is the judgment coefficient after regression analysis of the i-th dependent variable performance parameter on the remaining k-1 independent variable performance parameters, y i , Represent the actual value, predicted value and mean value of the i-th performance parameter respectively.
6. A computer device comprising a memory and a processor, characterized in that: The memory stores computer-executable instructions, and the processor executes the computer-executable instructions stored in the memory to implement an anti-interference method for an industrial wireless network according to any one of claims 1 to 4.
Citation Information
Patent Citations
An incomplete information intelligent anti-interference method based on reinforcement learning
CN109274456A
Reinforcement learning non-zero and non-cooperative multi-agent security communication power control method
CN113973362A