Load feature extraction method, device, electronic device and storage medium

By extracting the target word vector of the target load from the network traffic data, and using rules to generate models, including the target text classification model and interpretation model, to extract the target characteristics of the target load, the problem of low accuracy in the extraction of load flow characteristics in different scenarios is solved, and the extraction efficiency and accuracy are improved.

CN118094185BActive Publication Date: 2025-05-02WEBRAY TECH BEIJING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410198983.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-22
Publication Date
2025-05-02
Estimated Expiration
2044-02-22

AI Technical Summary

Technical Problem

In the prior art, the accuracy of the flow feature extraction of download loads in different scenarios is low.

Method used

By obtaining the current network traffic data of the network, determining the target word vector of the target payload, and inputting it into the rule to generate a model. The generation model includes the target text classification model and the interpretation model, which is used to extract the target features of the target payload.

Benefits of technology

The accuracy and efficiency of target feature extraction of target loads in different scenarios is improved, and the accurate feature extraction of target loads carried by network traffic data is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118094185B_ABST
    Figure CN118094185B_ABST
Patent Text Reader

Abstract

The present invention provides a load feature extraction method, device, electronic device and storage medium, which relate to the field of computer technology. The method includes: obtaining the current network traffic data of the network, the network traffic data carries the target load; based on the target load, determining the target word vector corresponding to the target load; inputting the target word vector into a rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load. Through the rule generation model, the target feature of the target load carried by the network traffic data is accurately extracted. Since the rule generation model is determined by historical network traffic data from different sources, the accuracy and efficiency of the target feature extraction of the target load in different scenarios can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a load feature extraction method, device, electronic equipment and storage medium. Background Art

[0002] Since the network environment involves large-scale traffic data and is affected by various threats and attacks, the security performance of the current network environment has been reduced. By automatically extracting key features of the payload, real-time detection of network traffic data is achieved, and traffic rules based on the payload are generated. Real-time network alarms are issued according to the generated rules, which can effectively protect the information security of the network itself.

[0003] At present, there have been many studies trying to automatically extract the traffic feature rules of the payload. For example, the Longest Common Subsequence (LCS) algorithm extracts the common substrings in the payload to form rules, but this method does not consider the distinguishability of label rules from normal traffic and is not applicable in large-scale heterogeneous scenarios. In addition, there is a malware traffic feature extraction algorithm based on the Latent Dirichlet Allocation (LDA) topic model, which can effectively extract key features from malicious topics. However, the effectiveness of the algorithm depends on accurate manual labeling, and the stability of the extraction performance in different scenarios is difficult to guarantee, resulting in low accuracy in the extraction of traffic features of the payload in different scenarios. Summary of the invention

[0004] The present invention provides a load feature extraction method, device, electronic device and storage medium, which are used to solve the problem of low accuracy in extracting flow features of loads in different scenarios in the prior art.

[0005] The present invention provides a load feature extraction method, comprising:

[0006] Acquire current network traffic data of the network, wherein the network traffic data carries a target payload;

[0007] Based on the target load, determining a target word vector corresponding to the target load;

[0008] The target word vector is input into a rule generation model to obtain the target features of the target load output by the rule generation model; the target features represent key fields of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target features of the target load.

[0009] According to a load feature extraction method provided by the present invention, the rule generation model includes a target text classification model and an interpretation model;

[0010] The step of inputting the target word vector into a rule generation model to obtain a target feature of the target payload output by the rule generation model includes:

[0011] The target word vector is input into the target text classification model to obtain a classification result output by the target text classification model; the classification result indicates the source of the target load; the target text classification model is trained based on sample word vectors corresponding to historical network traffic data from different sources and the source corresponding to the historical network traffic data; the target text classification model is used to classify the network traffic data;

[0012] The classification result is input into the explanation model to obtain the target feature of the target load output by the explanation model; the explanation model is used to explain the classification result.

[0013] According to a load feature extraction method provided by the present invention, determining a target word vector corresponding to the target load based on the target load includes:

[0014] Decoding the target payload to obtain a decoded payload text;

[0015] The decoded payload text is converted into a word vector to obtain a target word vector.

[0016] According to a load feature extraction method provided by the present invention, the target text classification model is trained based on the following steps:

[0017] Obtain a sample word vector set; the sample word vector set includes sample word vectors corresponding to historical network traffic data from different sources;

[0018] Based on each of the sample word vectors, an initial text classification model is trained to obtain the target text classification model.

[0019] According to a load feature extraction method provided by the present invention, the step of obtaining a sample word vector set includes:

[0020] Acquire historical network traffic data from different sources; the historical network traffic data carries a sample payload;

[0021] Decoding the historical network traffic data from different sources respectively to obtain decoded sample payload texts;

[0022] The decoded sample payload text is converted into a word vector to obtain sample word vectors corresponding to historical network traffic data from different sources.

[0023] According to a load feature extraction method provided by the present invention, the word vector conversion method is a bag-of-words model or an N-gram grammar model.

[0024] The present invention also provides a load feature extraction device, comprising:

[0025] An acquisition module, used to acquire current network traffic data of the network, wherein the network traffic data carries a target load;

[0026] A determination module, configured to determine a target word vector corresponding to the target load based on the target load;

[0027] A feature extraction module is used to input the target word vector into a rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load.

[0028] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any of the load feature extraction methods described above is implemented.

[0029] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the load feature extraction method described in any one of the above is implemented.

[0030] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the load feature extraction method described above is implemented.

[0031] The load feature extraction method, device, electronic device and storage medium provided by the present invention obtain the current network traffic data of the network, and the network traffic data carries the target load; based on the target load, determine the target word vector corresponding to the target load; input the target word vector into the rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load. Through the rule generation model, the target feature of the target load carried by the network traffic data can be accurately extracted. Since the rule generation model is determined by historical network traffic data from different sources, it can improve the accuracy and efficiency of target feature extraction of the target load in different scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0033] Figure 1 It is one of the flow charts of the load feature extraction method provided by the present invention;

[0034] Figure 2 This is the second flow chart of the load feature extraction method provided by the present invention;

[0035] Figure 3 It is a schematic diagram of the target text classification model training and the interpretation model extracting target features provided by the present invention;

[0036] Figure 4 It is a structural schematic diagram of the load characteristic extraction device provided by the present invention;

[0037] Figure 5 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0038] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0039] Combine the following Figure 1-Figure 3 The load feature extraction method of the present invention is described.

[0040] Figure 1 is one of the flow charts of the load feature extraction method provided by the present invention, such as Figure 1 As shown, the method includes steps 101 to 103; wherein,

[0041] Step 101, obtaining current network traffic data of the network, wherein the network traffic data carries a target load.

[0042] It should be noted that the load feature extraction method provided by the present invention is suitable for the scenario of network security alarm. The executor of the method can be a load feature extraction device, such as an electronic device, or a control module in the load feature extraction device for executing the load feature extraction method.

[0043] Specifically, the network flow data is the network flow data, the target load is the effective load in the network flow data, and the network flow data carries the target load. Through the real-time operation of the network, the current network flow data of the network can be obtained.

[0044] Step 102: Based on the target load, determine the target word vector corresponding to the target load.

[0045] Specifically, the target word vector represents the word vector corresponding to the payload text after decoding the target payload. According to the obtained target payload, the target word vector corresponding to the target payload can be further determined.

[0046] Step 103, input the target word vector into the rule generation model to obtain the target features of the target load output by the rule generation model; the target features represent the key fields of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target features of the target load.

[0047] Specifically, based on historical network traffic data from different sources, a rule generation model can be determined; wherein the rule generation model is used to extract target features of the target payload, and the target features represent key fields of the target payload.

[0048] By inputting the target word vector into the rule generation model, the target features of the target load output by the rule generation model can be obtained.

[0049] The load feature extraction method provided by the present invention obtains the current network traffic data of the network, and the network traffic data carries the target load; based on the target load, determines the target word vector corresponding to the target load; inputs the target word vector into the rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load. Through the rule generation model, the target feature of the target load carried by the network traffic data is accurately extracted. Since the rule generation model is determined by historical network traffic data from different sources, it can improve the accuracy and efficiency of the target feature extraction of the target load in different scenarios.

[0050] Optionally, a specific implementation of step 102 includes:

[0051] The target payload is decoded to obtain a decoded payload text; and the decoded payload text is converted into a word vector to obtain a target word vector.

[0052] Specifically, by decoding the target payload carried by the network traffic data, the decoded payload text can be obtained. For example, the effective payload field in the decoded payload text is "GET / HTTP / 1.1\r\nHost:\r\nUser-Agent:Mozilla / 5.0(compatible; Censys-Inspect / 1.1; +https: / / about.censys.io / )\r\nAccept:* / *\r\nAccept-Encoding: gzip\r\n\r\n". Then, the decoded payload text is converted into a word vector to obtain the target word vector.

[0053] It should be noted that the decoded payload text usually contains a large number of invalid characters, such as IP, port, non-readable bytes, date or variable numbers. After decoding and obtaining the decoded payload text, these invalid characters need to be removed.

[0054] Optionally, the word vector is converted using a bag-of-words model or an N-gram grammar model.

[0055] Specifically, word vector conversion can use the N-gram model to decompose the word vector and convert the payload text into a digital vector that can be recognized by the text classification model, or use the bag-of-words model to segment the words and convert the payload text composed of words after segmentation into a word vector composed of 0 and 1.

[0056] Optionally, the rule generation model includes a target text classification model and an interpretation model; the specific implementation of the above step 103 includes:

[0057] (1) The target word vector is input into the target text classification model to obtain a classification result output by the target text classification model; the classification result indicates the source of the target load; the target text classification model is trained based on sample word vectors corresponding to historical network traffic data from different sources and the sources corresponding to the historical network traffic data; the target text classification model is used to classify the network traffic data.

[0058] Specifically, the target text classification model can be a natural language processing model, such as a recurrent neural network (RNN) model or a gated recurrent unit (GRU) model. The target word vector is input into the target text classification model to obtain the classification result output by the target text classification model, wherein the classification result indicates the source of the target load, and thus the mapping platform from which the network traffic data comes can be obtained.

[0059] The target text classification model is trained based on the sample word vectors corresponding to the historical network traffic data from different sources and the sources corresponding to the historical network traffic data; during the training process, the sources corresponding to the historical network traffic data are used as the label data corresponding to the sample word vectors. After the training is completed, the target text classification model is obtained, and the network traffic data is classified using the target text classification model to determine which mapping platform the network traffic data comes from.

[0060] (2) Inputting the classification result into the explanation model to obtain the target feature of the target load output by the explanation model; the explanation model is used to explain the classification result.

[0061] Specifically, model inference is a method for logically inferring black-box machine learning models. Classic methods include Local Interpretable Model-Agnostic Explanations (LIME) based on sampling and fitting, SHapley Additive ExPlanations (SHAP) based on game theory, etc. The explanation model can be a LIME model or a SHAP model. The explanation model is used to explain the classification results, that is, to select words or phrases that are important to the classification results. The classification results are input into the explanation model to obtain the target features of the target load output by the explanation model.

[0062] It should be noted that the target classification model can be used to obtain the category of the target payload carried by the current network traffic data, but in order to know the key features in the target payload, the interpretation model needs to extract the key parts of the target payload to form a keyword combination. For example, the valid key fields represented by the target features output by the interpretation model are: ['User-Agent', 'CensysInspect', 'https', 'censys', 'Mozilla', 'compatible', 'about'], and it has been verified that the extracted valid key fields only belong to the Censys platform.

[0063] Figure 2 This is the second flow chart of the load feature extraction method provided by the present invention. Figure 2 As shown, the method includes steps 201 to 205; wherein,

[0064] Step 201, obtaining the current network traffic data of the network, where the network traffic data carries the target load.

[0065] Step 202: decode the target payload to obtain a decoded payload text.

[0066] Step 203, performing word vector conversion on the decoded payload text to obtain a target word vector.

[0067] Step 204, input the target word vector into the target text classification model to obtain the classification result output by the target text classification model; the classification result represents the source of the target load.

[0068] Step 205, input the classification result into the explanation model to obtain the target feature of the target load output by the explanation model; the target feature represents the key field of the target load.

[0069] Optionally, the target text classification model is trained based on the following steps:

[0070] (1) Obtaining a set of sample word vectors; the set of sample word vectors includes sample word vectors corresponding to historical network traffic data from different sources; training an initial text classification model based on each of the sample word vectors to obtain the target text classification model.

[0071] Specifically, historical network traffic data from different sources are obtained, and sample word vectors corresponding to the historical network traffic data are determined, that is, the payload of historical network traffic data from known sources historically collected by the mapping platform is decoded and converted into vector form, and each sample word vector is stored in a sample word vector set.

[0072] In the process of training the initial text classification model using the sample word vector set, each sample word vector is input into the initial text classification model to obtain the classification result output by the initial text classification model; the loss value is calculated according to the classification result output by the initial text classification model and the source (label data) corresponding to the sample word vector; according to the loss value, it is judged whether the training meets the training end condition, and the training end condition is that the loss value tends to be stable or the training reaches the maximum number of iterations; the above training steps are repeated until the training end condition is met to obtain the target text classification model.

[0073] Optionally, obtaining a sample word vector set includes:

[0074] Obtain historical network traffic data from different sources; the historical network traffic data carries a sample payload; decode the historical network traffic data from different sources respectively to obtain decoded sample payload text; perform word vector conversion on the decoded sample payload text to obtain sample word vectors corresponding to the historical network traffic data from different sources.

[0075] Specifically, historical network traffic data from surveying and mapping platforms of different sources are obtained, wherein the historical network traffic data carries sample payloads; the historical network traffic data from different sources are decoded to obtain decoded sample payload texts. The decoded sample payload texts are then converted into word vectors using a bag-of-words model or an N-gram grammar model to obtain sample word vectors corresponding to the historical network traffic data from different sources.

[0076] Figure 3 Schematic diagram of the target text classification model training and the target feature extraction of the interpretation model provided by the present invention, such as Figure 3 As shown, including:

[0077] Step 301: Acquire historical network traffic data from different sources, where the historical network traffic data carries a sample payload.

[0078] Step 302: Decode the historical network traffic data from different sources to obtain decoded sample payload text, for example, \x16\x03\x01\x00\xee\x01\x00\x00\xea\x03\x03\xc9\xbaf\xaf\xfcw\xad\xf5\x07b\xa7\x82\x8d\x80\xf6\x08\xefq\x98\x01\xfe\xd3\xc4\x0c\xe0\x0c\n\x9bU\xc8\xa1; GET / HTTP / 1.1 / nHost:\r\nCookie:remember Me=1\r\n\r\n;\x00\x03\x00\x01\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x0f\x00;\x00\x00\x00\x00\x00\x01\x00\x0 0\x00\x00\x00\x00\t_services\x07_dns-sd\x04_udp\x05l0cal\x00\x0c\x00\x01; GET / HTTP / 1.1 / r / nHost\r\nUser-Agent:Expanse,a Palo Alto Networkscompany, searches across the global IPv4 space multiple;...;

[0079] Step 303: Segment the decoded sample payload text to obtain multiple words; for example, Censyslnspect, \x01\x82\x00\x00\x00\x01, rememberMe=1, \x17\xd93\x14o, DEDHCODIDJCODBDFDCCODGDHCACACACA, compatible, k\x92\xf5e\x1c\xaa\xbb, Palo AltoNetworks.

[0080] Step 304: perform word vector conversion on multiple words, that is, convert the text composed of words after word segmentation into word vectors composed of 0 and 1, and obtain sample word vectors corresponding to historical network traffic data from different sources.

[0081] Step 305: Based on each sample word vector, train the initial text classification model to obtain a target text classification model.

[0082] Step 306: After the target text classification model is trained, the current network traffic data of the network is obtained, and the network traffic data carries the target load; the target word vector corresponding to the target load is determined.

[0083] Step 307: Input the target word vector into the target text classification model to obtain the classification result output by the target text classification model, for example, search engines (Shodan, FOFA and Censys).

[0084] Step 308: Input the classification result into the explanation model (LIME) to obtain the target features of the target load output by the explanation model.

[0085] It should be noted that this application performs word segmentation on the load in the historical network traffic data, constructs sample word vectors, uses the sample word vectors to train the initial text classification model, and uses the trained target text classification model to classify the current network traffic data, and uses the interpretation model to extract the key fields of the load carried by the network traffic data. This application supports the extraction of key fields for 90 surveying and mapping platforms, including common surveying and mapping platforms, such as Shodan, Censys, FOFA, RaySpace, Zoomeye and other platforms, and the classification accuracy is 98%.

[0086] For example, 1) Enter the payload field of the decoded payload text: GET / HTTP / 1.1\r\nHost:\r\nUser-Agent:Mozilla / 5.0(compatible; Censys-Inspect / 1.1; +https: / / about.censys.io / )\r\nAccept:* / *\r\nAccept-Encoding: gzip\r\n\r\n"; the valid key fields extracted by the rule generation model of this application are: ['User-Agent', 'CensysInspect', 'https', 'censys', 'Mozilla', 'compatible', 'about']. It has been verified that the extracted valid key fields only belong to the Censys platform.

[0087] 2) Enter the decoded payload text in the Payload field: \x01\x82\x00\x00\x00\x01,\xef:\xe7\x89\xfeH\xaf\xac\xf8\xc1Pq\xd7\xc3\xe8S\x8a\xd6:\x17\xd93\x14o)S}\xbb\xbb\x97b\xce\xb6\x0b\x9b\xb97>\x01\xcfv\xae\x a0E\xb6D\xea\xe1\xeaA\xc4\xdb\xee\t\xac\xfb\xf0\x84)k\xbbc\x18]V\x85V\xc5_\x05T\x0bt\ xc4\x0b\xbe\xb5w\xbcM=[1\xe1\x06\x9c\xfd\xd3g^\xe3\x01\x9bK\xd7\xfc>\xffk\xaf\x95\x99\ xfb\xdbH\x90\x8bD\x88`k\x92\xf5e\x1c\xaa\xbb{_LP\x15\x85\x1e\x0e\x8f\xdd\xc5J; The valid key fields extracted by the rule generation model of this application are: ['\\x01\\x82\\x00\\x00\\x00\\x01', '\\xbb\\xbb\\x97b\\xce\\xb6\\x0b\\x The extracted valid key fields only belong to the Recyber platform.

[0088] The load feature extraction method provided by the present invention automatically extracts keywords (target features) in the load as label rules for batches of network space mapping request data, and uses the generated label rules as the basis for real-time detection of mapping data. Starting from the task goal of payload feature extraction, by training a deep model (target text classification model), not only the classification results given by the model are obtained, the question of "what" is answered, that is, which mapping platform the traffic comes from, but also the mouth of the large-scale sample model can be opened to let it answer the question of "why" to generate the most intuitive various feature rules (target features) in traditional network security, and the source of the current mapping traffic can be quickly identified through such rules. The process of extracting rules not only does not rely on manual extraction by humans, but also the labels (sources) can be applied to large-scale heterogeneous scenarios (i.e., different mapping platforms) through the extraction rules, and the extracted rules can be combined with network intrusion detection systems (suricata), intrusion detection systems and intrusion prevention systems (Intrusion Detection & Prevention System, IDP), network intrusion prevention systems (SNORT), etc., to realize real-time alarm of mapping traffic.

[0089] The load characteristic extraction device provided by the present invention is described below. The load characteristic extraction device described below and the load characteristic extraction method described above can be referred to each other.

[0090] Figure 4 is a schematic diagram of the structure of the load feature extraction device provided by the present invention, such as Figure 4 As shown, the load feature extraction device 400 includes: a first acquisition module 401, a determination module 402 and a feature extraction module 403; wherein,

[0091] The first acquisition module 401 is used to acquire the current network traffic data of the network, wherein the network traffic data carries the target load;

[0092] A determination module 402 is used to determine a target word vector corresponding to the target load based on the target load;

[0093] The feature extraction module 403 is used to input the target word vector into the rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load.

[0094] The load feature extraction device provided by the present invention obtains the current network traffic data of the network, and the network traffic data carries the target load; based on the target load, determines the target word vector corresponding to the target load; inputs the target word vector into the rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load. Through the rule generation model, the target feature of the target load carried by the network traffic data can be accurately extracted. Since the rule generation model is determined by historical network traffic data from different sources, it can improve the accuracy and efficiency of the target feature extraction of the target load in different scenarios.

[0095] Optionally, the rule generation model includes a target text classification model and an interpretation model; the feature extraction module 403 is specifically used for:

[0096] The target word vector is input into the target text classification model to obtain a classification result output by the target text classification model; the classification result indicates the source of the target load; the target text classification model is trained based on sample word vectors corresponding to historical network traffic data from different sources and the source corresponding to the historical network traffic data; the target text classification model is used to classify the network traffic data;

[0097] The classification result is input into the explanation model to obtain the target feature of the target load output by the explanation model; the explanation model is used to explain the classification result.

[0098] Optionally, the determining module 402 is specifically configured to:

[0099] Decoding the target payload to obtain a decoded payload text;

[0100] The decoded payload text is converted into a word vector to obtain a target word vector.

[0101] Optionally, the load feature extraction device 400 further includes:

[0102] A second acquisition module is used to acquire a sample word vector set; the sample word vector set includes sample word vectors corresponding to historical network traffic data from different sources;

[0103] The training module is used to train the initial text classification model based on each of the sample word vectors to obtain the target text classification model.

[0104] Optionally, the second acquisition module is specifically used to:

[0105] Acquire historical network traffic data from different sources; the historical network traffic data carries a sample payload;

[0106] Decoding the historical network traffic data from different sources respectively to obtain decoded sample payload texts;

[0107] The decoded sample payload text is converted into a word vector to obtain sample word vectors corresponding to historical network traffic data from different sources.

[0108] Optionally, the word vector conversion method is a bag-of-words model or an N-gram grammar model.

[0109] Figure 5 is a schematic diagram of the physical structure of an electronic device provided by the present invention, such as Figure 5 As shown, the electronic device 500 may include: a processor 510, a communication interface 520, a memory 530 and a communication bus 540, wherein the processor 510, the communication interface 520 and the memory 530 communicate with each other through the communication bus 540. The processor 510 may call the logic instructions in the memory 530 to execute the load feature extraction method, which includes: obtaining the current network traffic data of the network, the network traffic data carries the target load; based on the target load, determining the target word vector corresponding to the target load; inputting the target word vector into the rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on the historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load.

[0110] In addition, the logic instructions in the above-mentioned memory 530 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0111] On the other hand, the present invention also provides a computer program product, which includes a computer program, and the computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the load feature extraction method provided by the above methods, and the method includes: obtaining the current network traffic data of the network, and the network traffic data carries a target load; based on the target load, determining a target word vector corresponding to the target load; inputting the target word vector into a rule generation model to obtain the target feature of the target load output by the rule generation model; the target feature represents the key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load.

[0112] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the load feature extraction method provided by the above-mentioned methods, the method comprising: obtaining current network traffic data of the network, the network traffic data carrying a target load; based on the target load, determining a target word vector corresponding to the target load; inputting the target word vector into a rule generation model to obtain a target feature of the target load output by the rule generation model; the target feature represents a key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load.

[0113] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0114] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0115] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A load feature extraction method, characterized in that: include: Acquire current network traffic data of the network, wherein the network traffic data carries a target payload; Based on the target load, determining a target word vector corresponding to the target load; Inputting the target word vector into a rule generation model to obtain a target feature of the target load output by the rule generation model; The target feature represents a key field of the target payload; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target payload; The rule generation model includes a target text classification model and an interpretation model; The step of inputting the target word vector into a rule generation model to obtain a target feature of the target payload output by the rule generation model includes: The target word vector is input into the target text classification model to obtain a classification result output by the target text classification model; the classification result indicates the source of the target load; the target text classification model is trained based on sample word vectors corresponding to historical network traffic data from different sources and the source corresponding to the historical network traffic data; the target text classification model is used to classify the network traffic data; The classification result is input into the explanation model to obtain the target feature of the target load output by the explanation model; the explanation model is used to explain the classification result, that is, to select words or phrases that are important to the classification result; the explanation model is a local interpretability model diagnosis explanation LIME model or a Shapley sum explanation SHAP model.

2. The load feature extraction method according to claim 1, characterized in that: The determining, based on the target load, a target word vector corresponding to the target load includes: Decoding the target payload to obtain a decoded payload text; The decoded payload text is converted into a word vector to obtain a target word vector.

3. The load feature extraction method according to claim 1 or 2, characterized in that: The target text classification model is trained based on the following steps: Obtain a sample word vector set; the sample word vector set includes sample word vectors corresponding to historical network traffic data from different sources; Based on each of the sample word vectors, an initial text classification model is trained to obtain the target text classification model.

4. The load feature extraction method according to claim 3, characterized in that: The obtaining of a sample word vector set includes: Acquire historical network traffic data from different sources; the historical network traffic data carries a sample payload; Decoding the historical network traffic data from different sources respectively to obtain decoded sample payload texts; The decoded sample payload text is converted into a word vector to obtain sample word vectors corresponding to historical network traffic data from different sources.

5. The load feature extraction method according to claim 2 or 4, characterized in that: The word vector conversion method is a bag-of-words model or an N-gram grammar model.

6. A load feature extraction device, characterized in that: include: An acquisition module, used to acquire current network traffic data of the network, wherein the network traffic data carries a target load; A determination module, configured to determine a target word vector corresponding to the target load based on the target load; A feature extraction module, used for inputting the target word vector into a rule generation model to obtain a target feature of the target load output by the rule generation model; the target feature represents a key field of the target load; the rule generation model is determined based on historical network traffic data from different sources, and the rule generation model is used to extract the target feature of the target load; The rule generation model includes a target text classification model and an interpretation model; the feature extraction module is specifically used for: Inputting the target word vector into the target text classification model to obtain a classification result output by the target text classification model; the classification result indicates the source of the target payload; The target text classification model is obtained by training based on sample word vectors corresponding to historical network traffic data from different sources and the sources corresponding to the historical network traffic data; the target text classification model is used to classify the network traffic data; Inputting the classification result into the explanation model to obtain the target feature of the target load output by the explanation model; The explanation model is used to explain the classification result, that is, to select words or phrases that are important to the classification result; the explanation model is a local interpretability model diagnosis explanation LIME model or a Shapley sum explanation SHAP model.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the load feature extraction method according to any one of claims 1 to 5 is implemented.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the load feature extraction method according to any one of claims 1 to 5 is implemented.

9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the load feature extraction method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • SQL injection attack detection method and device based on HTTP flow, equipment and medium

    CN115333776A

  • Network traffic processing method and device, equipment and storage medium

    CN116599907A