A method and system for protecting information security onboard a civil passenger aircraft
By mining the correlation between airborne communication data packets and intrusion behavior data classification, combined with feature embedding operators and attention networks, the accuracy problem of intrusion detection algorithms when samples are insufficient is solved, and high-precision intrusion behavior detection is achieved in the network security protection system of civil airliners.
Patent Information
- Application Number
- CN202410762972.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-13
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-06-13
AI Technical Summary
In existing civil airliner onboard network security protection systems, intrusion detection algorithms have difficulty accurately detecting intrusion behaviors when the number of samples is insufficient, resulting in insufficient accuracy in network attack detection.
By mining the correlation between airborne communication data packets and alternative intrusion behavior data classification, utilizing the feature embedding operator and attention network in the intrusion behavior detection algorithm, combining the first and second intrusion behavior representation vectors for data classification reasoning, the intrusion behavior type is determined, and the detection accuracy is improved through the weighted fusion support coefficient.
When the number of samples is insufficient, the accuracy of intrusion behavior detection is improved, ensuring the accurate classification of intrusion behavior and enhancing the protection capabilities of the civil airliner network security protection system.
Smart Images

Figure CN118432937B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and more specifically, to a method and system for protecting information security onboard a civil passenger aircraft. Background Art
[0002] With the rapid development of information technology, modern civil airliners increasingly rely on onboard network systems to implement various functions and services. However, this also poses potential cybersecurity threats to aircraft. Because aircraft internal networks are connected to ground networks and the internet, risks such as hacker intrusion, malware infection, and data leakage become possible. These cyberattacks could seriously impact aircraft safety, reliability, and operability, endangering the lives of passengers and crew. To address these threats, the aviation industry has developed relevant regulations and standards, such as guidelines and requirements from the Associated Avionics Consortium (ARINC), the International Civil Aviation Organization (ICAO), and the European Aviation Safety Agency (EASA). In line with these requirements, a series of measures have been implemented to protect aircraft onboard cybersecurity. Firewalls and intrusion detection systems (i.e., onboard cybersecurity protection systems) are deployed within aircraft internal networks. These systems monitor network traffic, promptly identify potential attacks, and prevent them from further intrusion into aircraft systems. Currently, intrusion detection systems that incorporate artificial intelligence algorithms to detect network traffic are becoming a trend. Ensuring that AI algorithms can accurately detect intrusions is a key area of continuous improvement. Summary of the Invention
[0003] The purpose of this application is to provide a method and system for protecting the security of information on board a civil passenger aircraft to ensure accurate detection of intrusion behavior.
[0004] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by practice of the present application.
[0005] According to one aspect of an embodiment of the present application, a method for protecting information security onboard a civil passenger aircraft is provided, which is applied to an onboard network security protection system. The method includes:
[0006] Acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications, wherein the first airborne communication data packet is a communication data packet for determining an intrusion behavior type among the plurality of candidate intrusion behavior data classifications;
[0007] Acquire a second airborne communication data packet corresponding to each of the plurality of candidate intrusion behavior data classifications, wherein a commonality measurement result between the second airborne communication data packet and the first airborne communication data packet satisfies a preset measurement condition;
[0008] mining first intrusion behavior representation vectors corresponding to the first airborne communication data packet and the multiple candidate intrusion behavior data classifications, where the first intrusion behavior representation vectors are used to represent the associations between the multiple candidate intrusion behavior data classifications and the first airborne communication data packet;
[0009] mining second intrusion behavior characterization vectors corresponding to the first airborne communication data packet and a plurality of second airborne communication data packets, where the second intrusion behavior characterization vectors are used to characterize the associations between the plurality of second airborne communication data packets and the first airborne communication data packet;
[0010] Intrusion behavior data classification reasoning is performed based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and a first intrusion behavior data classification corresponding to the first airborne communication data packet is determined from the multiple alternative intrusion behavior data classifications, where the first intrusion behavior data classification is used to represent the intrusion behavior type corresponding to the first airborne communication data packet.
[0011] In some possible designs, performing intrusion behavior data classification reasoning based on the first intrusion behavior representation vector and the second intrusion behavior representation vector, and determining the first intrusion behavior data classification corresponding to the first airborne communication data packet from the multiple candidate intrusion behavior data classifications, includes:
[0012] Performing intrusion behavior data classification reasoning on the first intrusion behavior representation vector based on the first intrusion behavior mapping operator in the intrusion behavior detection algorithm to obtain first support coefficients corresponding to each of the multiple candidate intrusion behavior data classifications;
[0013] Performing intrusion behavior data classification reasoning on the second intrusion behavior representation vector based on the second intrusion behavior mapping operator in the intrusion behavior detection algorithm to obtain second support coefficients corresponding to multiple candidate intrusion behavior data classifications;
[0014] Integrating the first support coefficient and the second support coefficient to obtain classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications;
[0015] The first intrusion behavior data category corresponding to the first airborne communication data packet is determined from the multiple candidate intrusion behavior data categories according to the classification support coefficients corresponding to the multiple candidate intrusion behavior data categories.
[0016] In some possible designs, the first support coefficient and the second support coefficient are integrated to obtain the classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications, including:
[0017] Determining a plurality of airborne communication data packet learning samples included in a learning sample set of the intrusion behavior detection algorithm, wherein the intrusion behavior data classifications corresponding to the plurality of airborne communication data packet learning samples belong to one or more of the plurality of candidate intrusion behavior data classifications;
[0018] Obtaining a first number of airborne communication data packet learning samples corresponding to each of the plurality of candidate intrusion behavior data categories;
[0019] Determine, based on the first number, a first impact factor corresponding to the first support coefficient and a second impact factor corresponding to the second support coefficient, wherein the first number is positively correlated with the first impact factor and the first number is negatively correlated with the second impact factor;
[0020] The first support coefficient and the second support coefficient are integrated according to the first influencing factor and the second influencing factor to obtain classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications.
[0021] In some possible designs, the multiple candidate intrusion behavior data categories include a first candidate intrusion behavior data category; and obtaining second airborne communication data packets corresponding to each of the multiple candidate intrusion behavior data categories includes:
[0022] Acquire multiple candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification;
[0023] Determine the communication data packet commonality measurement results between the multiple alternative airborne communication data packets and the first airborne communication data packet, and determine the p alternative airborne communication data packets with the largest communication data packet commonality measurement results between the multiple alternative airborne communication data packets and the first airborne communication data packet as the second airborne communication data packets corresponding to the first alternative intrusion behavior data classification; wherein p≥1.
[0024] In some possible designs, determining communication packet commonality measurement results between the multiple candidate airborne communication data packets and the first airborne communication data packet, and determining p candidate airborne communication data packets having the largest communication packet commonality measurement results with the first airborne communication data packet among the multiple candidate airborne communication data packets as second airborne communication data packets corresponding to the first candidate intrusion behavior data classification includes:
[0025] Acquire multiple component data clusters corresponding to the first airborne communication data packet, and determine the association of the component data clusters corresponding to each of the multiple candidate airborne communication data packets, wherein the component data cluster association is used to characterize the association between the multiple component data clusters and the candidate airborne communication data packets;
[0026] Determining, based on the association of the constituent data clusters, commonality measurement results corresponding to each of the plurality of candidate airborne communication data packets;
[0027] P candidate airborne communication data packets with the largest commonality measurement results with the first airborne communication data packet among the multiple candidate airborne communication data packets are obtained and determined as second airborne communication data packets corresponding to the first candidate intrusion behavior data classification.
[0028] In some possible designs, determining communication packet commonality measurement results between the multiple candidate airborne communication data packets and the first airborne communication data packet, and determining p candidate airborne communication data packets having the largest communication packet commonality measurement results with the first airborne communication data packet among the multiple candidate airborne communication data packets as second airborne communication data packets corresponding to the first candidate intrusion behavior data classification includes:
[0029] Obtaining a first data packet representation vector corresponding to the first airborne communication data packet, and obtaining a candidate data packet representation vector corresponding to each of the plurality of candidate airborne communication data packets;
[0030] Based on a preset feature clustering strategy, the feature domains where the multiple candidate data packet representation vectors are located are divided into multiple sub-feature domains, each of the multiple sub-feature domains corresponds to a cluster representative representation vector;
[0031] Determining spatial similarities between a plurality of cluster representative representation vectors and the first data packet representation vector;
[0032] Obtaining u cluster representative representation vectors having the greatest spatial similarity with the first data packet representation vector from the plurality of cluster representative representation vectors, where u≥1;
[0033] Determining the spatial similarity between the first data packet representation vector and the candidate data packet representation vectors in the u sub-feature domains corresponding to the u cluster representative representation vectors;
[0034] The candidate airborne communication data packets corresponding to the p candidate data packet representation vectors having the greatest spatial similarity with the first data packet representation vector among the candidate data packet representation vectors in the u sub-feature domains are determined as the second airborne communication data packets.
[0035] In some possible designs, mining the second intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of second airborne communication data packets includes:
[0036] Classify and combine the first airborne communication data packet with the multiple candidate intrusion behavior data to obtain multiple first combined communication data;
[0037] Based on the first feature embedding operator in the intrusion behavior detection algorithm, the first intrusion behavior sub-representation vectors corresponding to each of the multiple first combined communication data are mined, and the multiple first intrusion behavior sub-representation vectors are used as the first intrusion behavior representation vector, wherein a first intrusion behavior sub-representation vector is used to represent the correlation between an alternative intrusion behavior data classification and the first airborne communication data packet.
[0038] In some possible designs, mining the second intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of second airborne communication data packets includes:
[0039] Performing data combination processing on the first airborne communication data packet and the plurality of second airborne communication data packets respectively to obtain the plurality of second combined communication data;
[0040] Based on the second feature embedding operator in the intrusion behavior detection algorithm, the second intrusion behavior sub-representation vectors corresponding to each of the multiple second combined communication data are mined, and the multiple second intrusion behavior sub-representation vectors are used as the second intrusion behavior representation vector, wherein a second intrusion behavior sub-representation vector is used to represent the correlation between a second airborne communication data packet and the first airborne communication data packet.
[0041] According to another aspect of an embodiment of the present application, a safety protection device is provided, comprising:
[0042] a target data acquisition module, configured to acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications, wherein the first airborne communication data packet is a communication data packet for determining an intrusion behavior type among the plurality of candidate intrusion behavior data classifications;
[0043] a reference data acquisition module, configured to acquire second airborne communication data packets corresponding to each of the plurality of candidate intrusion behavior data classifications, wherein a commonality measurement result between the second airborne communication data packet and the first airborne communication data packet satisfies a preset measurement condition;
[0044] a first feature mining module, configured to mine first intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of candidate intrusion behavior data classifications, the first intrusion behavior representation vectors being used to represent the associations between the plurality of candidate intrusion behavior data classifications and the first airborne communication data packet;
[0045] A second feature mining module is used to mine second intrusion behavior representation vectors corresponding to the first airborne communication data packet and multiple second airborne communication data packets, wherein the second intrusion behavior representation vector is used to represent the association between the multiple second airborne communication data packets and the first airborne communication data packet respectively;
[0046] An intrusion behavior classification module is used to perform intrusion behavior data classification reasoning based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and determine the first intrusion behavior data classification corresponding to the first airborne communication data packet from the multiple alternative intrusion behavior data classifications, wherein the first intrusion behavior data classification is used to represent the intrusion behavior type corresponding to the first airborne communication data packet.
[0047] According to another aspect of an embodiment of the present application, there is provided an airborne network security protection system, comprising:
[0048] processor;
[0049] and a memory for storing executable instructions for the processor;
[0050] The processor is configured to perform the above method by executing the executable instructions.
[0051] This application has the following beneficial effects:
[0052] The embodiment of the present application provides a method and system for protecting airborne information security of a civil passenger aircraft. The method and system are based on mining a first intrusion behavior characterization vector corresponding to a first airborne communication data packet and a plurality of alternative intrusion behavior data classifications, and mining a second intrusion behavior characterization vector corresponding to a first airborne communication data packet and a plurality of second airborne communication data packets (approximate data packets of the first airborne communication data packet under each alternative intrusion behavior data classification). The method and system perform intrusion behavior data classification reasoning on the first airborne communication data packet based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector to determine the intrusion behavior data classification of the first airborne communication data packet. When performing intrusion behavior data classification reasoning on the first airborne communication data packet, the intrusion behavior type of the first airborne communication data packet is determined based on the correlation between the first airborne communication data packet and the intrusion behavior data classification and the correlation between the first airborne communication data packet and the approximate data packet. In the intrusion behavior detection algorithm debugged when the number of samples is insufficient, if an intrusion behavior data classification is not in the debugging sample of the intrusion behavior detection algorithm, the intrusion behavior detection algorithm can determine the approximate data packet of the first airborne communication data packet as the extended information to infer the support coefficient of the first airborne communication data packet corresponding to the intrusion behavior data classification, so as to increase the accuracy of the intrusion behavior data classification inference of the airborne communication data packet.
[0053] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and those skilled in the art can derive other drawings based on these drawings without inventive effort.
[0055] Figure 1 This is a flow chart of a method for protecting information security onboard a civil passenger aircraft provided in an embodiment of the present application.
[0056] Figure 2 This is a schematic diagram of the functional module architecture of the safety protection device provided in an embodiment of the present application.
[0057] Figure 3 This is a schematic diagram of the composition of an airborne network security protection system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0058] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art.
[0059] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner.In the following description, many specific details are provided so as to provide a full understanding of the embodiments of the present application. However, it will be appreciated by those skilled in the art that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps etc. can be adopted. In other cases, known methods, devices, implementations or operations are not shown or described in detail to avoid blurring the various aspects of the application.
[0060] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically separate entities. That is, these functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0061] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.
[0062] Please refer to Figure 1The civil passenger aircraft airborne information security protection method provided in the embodiment of the present application includes the following steps:
[0063] Step S110: Acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications.
[0064] In this embodiment of the present application, the first airborne communication data packet is a communication data packet intended to determine the intrusion behavior type from among multiple candidate intrusion behavior data classifications. As an implementation, the first airborne communication data packet is a data stream obtained by monitoring and collecting data from an aircraft (civilian passenger aircraft) onboard network (it is understood that this process is conducted within the scope permitted by laws and regulations and has been approved by passengers before network use). This data may include data such as protocol type, source IP address, destination IP address, port number, and service type. It is understood that to facilitate data processing by the subsequent machine learning network of this application, this embodiment of the application may convert data that cannot be directly processed (such as discrete data) into computer-readable numerical data (such as binary data). Specifically, one-hot encoding can be used to process categorical features, and then the encoded data is normalized to ensure that the numerical ranges of different features are consistent. Various normalization methods can be used for this, such as maximum-minimum scaling and Z-score normalization. Based on this, the processed airborne communication data packet is obtained.
[0065] In one embodiment, the plurality of candidate intrusion behavior data categories are preset plurality of intrusion behavior data categories. One candidate intrusion behavior data category includes communication data corresponding to one intrusion behavior. The plurality of candidate intrusion behavior data categories and the intrusion communication data corresponding to each of the plurality of candidate intrusion behavior data categories are obtained.
[0066] Step S120: obtaining second airborne communication data packets corresponding to respective ones of a plurality of candidate intrusion behavior data categories.
[0067] The commonality measurement result between the first airborne communication data packet and the second airborne communication data packet satisfies a preset measurement condition. As an embodiment, a second airborne communication data packet corresponding to each of a plurality of candidate intrusion behavior data classifications is obtained from an airborne network communication database, the airborne network communication database being an airborne network communication database stored in an airborne network protection system, the airborne network communication database storing a plurality of candidate airborne communication data packets corresponding to the plurality of candidate intrusion behavior data classifications, the plurality of candidate airborne communication data packets stored in the airborne network communication database being airborne communication data packets for which intrusion behavior identification has been performed.
[0068] In one embodiment, the number of communication data packets included in the second airborne communication data packet may be one or more. Optionally, each of the multiple candidate intrusion behavior data classifications corresponds to multiple candidate airborne communication data packets; the multiple candidate intrusion behavior data classifications include a first candidate intrusion behavior data classification, and a second airborne communication data packet that satisfies a commonality measurement result condition with the first airborne communication data packet is determined from the multiple candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification.
[0069] As an implementation method, multiple alternative airborne communication data packets corresponding to a first alternative intrusion behavior data classification are obtained; communication data packet commonality measurement results between the multiple alternative airborne communication data packets and the first airborne communication data packet are determined, and the p alternative airborne communication data packets with the largest communication data packet commonality measurement results with the first airborne communication data packet among the multiple alternative airborne communication data packets are determined as second airborne communication data packets, p≥1.
[0070] As an implementation, the commonality measurement result of the data packets indicates the degree of similarity between two airborne communication data packets. This determination can be achieved through spatial similarity calculation. Spatial similarity is an algorithm that evaluates the corresponding feature similarity by calculating the distance between two vectors in a feature space. Specifically, the data packet representation vectors corresponding to the data packets (vectors representing the characteristics of the communication data packets) are obtained, and the spatial similarity between the data packet representation vectors is calculated to obtain the commonality measurement result between the communication data packets. The smaller the distance between the data packet representation vectors, the greater the spatial similarity, and the greater the commonality measurement result between the communication data packets. As an implementation, spatial similarity can be obtained by calculating Euclidean distance or other distance calculation methods.
[0071] Step S130 : mining a first intrusion behavior representation vector corresponding to the first airborne communication data packet and a plurality of candidate intrusion behavior data classifications.
[0072] The first intrusion behavior representation vector is used to represent the association between multiple candidate intrusion behavior data classifications and the first airborne communication data packet. As an embodiment, the first airborne communication data packet is combined with multiple candidate intrusion behavior data classifications to obtain multiple first combined communication data. Based on the first feature embedding operator in the intrusion behavior detection algorithm, the first intrusion behavior sub-representation vectors corresponding to each of the multiple first combined communication data are mined, and the multiple first intrusion behavior sub-representation vectors are used as the first intrusion behavior representation vector, wherein the first intrusion behavior sub-representation vector is used to represent the association between an alternative intrusion behavior data classification and the first airborne communication data packet.
[0073] In one embodiment, the intrusion behavior detection algorithm includes a first feature embedding operator comprising a first low-dimensional mapping network (i.e., embedding network) and a first attention network. The first low-dimensional mapping network performs low-dimensional mapping on multiple first combined communication data to complete encoding and obtain multiple first encoding vectors. After obtaining the multiple first encoding vectors, the multiple first encoding vectors are input into the first attention network, and the first encoding sub-vectors corresponding to each of the multiple first encoding vectors are mined based on the attention strategy of the first attention network.
[0074] For example, the first encoding vector includes a data cluster representation vector for each constituent data cluster, which is obtained by vector addition of the constituent encoding vector of the constituent data cluster and the position encoding vector of the constituent data cluster position; the obtained constituent data cluster representation array is input into the first attention network to obtain the first encoding sub-vector, and the constituent data cluster representation array is a two-dimensional array, in which each row is a data cluster representation vector of a constituent data cluster.
[0075] Step S140 : mining second intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of second airborne communication data packets.
[0076] The second intrusion behavior representation vector is used to represent the correlation between multiple second airborne communication data packets and the first airborne communication data packet. As an embodiment, the first airborne communication data packet is combined with multiple second airborne communication data packets to obtain multiple second combined communication data. Based on the second feature embedding operator in the intrusion behavior detection algorithm, the second intrusion behavior sub-representation vector corresponding to each of the multiple second combined communication data is mined, and the multiple second intrusion behavior sub-representation vectors are used as the second intrusion behavior representation vector, wherein the second intrusion behavior sub-representation vector represents the correlation between a second airborne communication data packet and the first airborne communication data packet.
[0077] As an implementation method, the intrusion behavior detection algorithm also includes a second feature embedding operator, which includes a second low-dimensional mapping network and a second attention network; based on the second low-dimensional mapping network, low-dimensional mapping is performed on multiple second combined communication data to complete encoding and obtain multiple second encoding vectors.
[0078] The first attention network and the second attention network are different attention networks, and the first low-dimensional mapping network and the second low-dimensional mapping network are different low-dimensional mapping networks.
[0079] As an implementation method, for the first candidate intrusion behavior data classification, if the second airborne communication data packet includes multiple airborne communication data packets, the present application sequentially combines the first airborne communication data packet with the multiple airborne communication data packets to obtain second combined communication data. After obtaining multiple second encoding vectors, the multiple second encoding vectors are input into the second attention network, and the second encoding sub-vectors corresponding to each of the multiple second encoding vectors are mined based on the attention strategy of the second attention network. The process for obtaining the first encoding sub-vector can be referred to.
[0080] Step S150 : performing intrusion behavior data classification reasoning based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and determining a first intrusion behavior data classification corresponding to the first airborne communication data packet from a plurality of candidate intrusion behavior data classifications.
[0081] The first intrusion behavior data classification can represent the intrusion behavior type corresponding to the first airborne communication data packet. Based on the first intrusion behavior mapping operator in the intrusion behavior detection algorithm, the first intrusion behavior characterization vector is subjected to intrusion behavior data classification reasoning to obtain first support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications. Based on the second intrusion behavior mapping operator in the intrusion behavior detection algorithm, the second intrusion behavior characterization vector is subjected to intrusion behavior data classification reasoning to obtain second support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications. The first support coefficient and the second support coefficient are integrated, for example, by weighted fusion, to obtain classification support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications. Based on the classification support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications, the first intrusion behavior data classification corresponding to the first airborne communication data packet is determined from the multiple alternative intrusion behavior data classifications.
[0082] As an embodiment, the intrusion behavior detection algorithm includes a first intrusion behavior mapping operator and a second intrusion behavior mapping operator, wherein the first intrusion behavior mapping operator includes a first feedforward neural unit (FFN), and the second intrusion behavior mapping operator includes a second feedforward neural unit. Multiple first intrusion behavior sub-representation vectors, namely, first intrusion behavior representation vectors, are input into the first feedforward neural unit, and a first support coefficient corresponding to each of multiple candidate intrusion behavior data classifications is output. This is the support coefficient determined based on the correlation between the first airborne communication data packet and the multiple candidate intrusion behavior data classifications. The second intrusion behavior representation vector is input into the second feedforward neural unit, and a second support coefficient corresponding to each of the multiple candidate intrusion behavior data classifications is output. This is the support coefficient determined based on the correlation between the first airborne communication data packet and the multiple second airborne communication data packets. In this embodiment of the present application, the support coefficient can be a probability or a confidence level.
[0083] In one embodiment, a first impact factor corresponding to the first support coefficient and a second impact factor corresponding to the second support coefficient are determined; based on the first impact factor and the second impact factor, a fusion coefficient of the first support coefficient and the second support coefficient is determined (e.g., a weighted average is calculated), and the fusion coefficient is determined as the classification support coefficient. In this embodiment of the present application, the impact factor can be represented as a weight.
[0084] As an implementation method, the first impact factor and the second impact factor can be predetermined or obtained through algorithm debugging. The impact factor is essentially a weight. For example, if the first impact factor and the second impact factor are predetermined, such as assuming that the first impact factor and the second impact factor are both 0.5, then for an alternative intrusion behavior data classification, after obtaining the first support coefficient and the second support coefficient corresponding to the alternative intrusion behavior data classification, the average of the first support coefficient and the second support coefficient is obtained and determined as the classification support coefficient of the alternative intrusion behavior data classification.
[0085] Optionally, the first influencing factor and the second influencing factor are influencing factors determined based on training data of the intrusion behavior detection algorithm; multiple airborne communication data packet learning samples included in the learning sample set of the intrusion behavior detection algorithm are determined, and the intrusion behavior data classifications corresponding to the multiple airborne communication data packet learning samples belong to one or more of multiple alternative intrusion behavior data classifications; a first number of airborne communication data packet learning samples corresponding to each of the multiple alternative intrusion behavior data classifications is obtained; based on the first number, a first influencing factor corresponding to the first support coefficient and a second influencing factor corresponding to the second support coefficient are determined, the first number is positively correlated with the first influencing factor, i.e., positively correlated, and the first number is negatively correlated with the second influencing factor, i.e., anti-correlated; based on the first influencing factor and the second influencing factor, the first support coefficient and the second support coefficient are integrated to obtain the classification support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications. The multiple airborne communication data packet learning samples in the learning sample set of the intrusion behavior detection algorithm are learning samples fitted by the intrusion behavior detection algorithm during the debugging process.
[0086] For example, if the initial impact factor of the first support coefficient is 0.5 and the initial impact factor of the second support coefficient is 0.5, if the first number is larger, it means that the intrusion behavior detection algorithm has completed the fitting of sufficient samples for the alternative intrusion behavior data classification. Based on this, if the first number is within the first number range, the initial impact factor of the first support coefficient is modified from 0.5 to 0.7, and the initial impact factor of the second support coefficient is modified from 0.5 to 0.3.
[0087] Adjusting the influence factors corresponding to the first support coefficient and the second support coefficient based on the number of fitting data of the alternative intrusion behavior data classification can alleviate the influence of data with similar structures but different purposes during algorithm reasoning.
[0088] After obtaining the classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications, m candidate intrusion behavior data classifications with the largest classification support coefficients are taken as the first intrusion behavior data classification, where m≥1.
[0089] For example, an intrusion behavior data classification set is set, which includes multiple alternative intrusion behavior data classifications, and each intrusion behavior data classification corresponds to an intrusion behavior data classification label; the airborne communication data packet quantity set includes an alternative airborne communication data packet corresponding to each alternative intrusion behavior data classification, and the alternative airborne communication data packet is the airborne communication data packet stored in the airborne network communication database; after the intrusion behavior data classification reasoning of the latest acquired airborne communication data packet is completed, the corresponding airborne communication data packet quantity is updated based on the identified intrusion behavior data classification, and the update time is saved.
[0090] As an implementation method, before saving the first airborne communication data packet into the airborne network communication database and updating the airborne network communication database, multiple alternative airborne communication data packets corresponding to the first intrusion behavior data classification can be obtained, wherein the multiple alternative airborne communication data packets belong to the first intrusion behavior data classification, and then the commonality measurement results between the multiple alternative airborne communication data packets and the first airborne communication data packet are determined. When the commonality measurement result between the target alternative airborne communication data packet and the first airborne communication data packet in the multiple alternative airborne communication data packets is not less than the commonality measurement result threshold, the first airborne communication data packet is not saved into the airborne network communication database. For example, if the commonality measurement result between the target alternative airborne communication data packet and the first airborne communication data packet is not less than the commonality measurement result threshold in the multiple alternative airborne communication data packets, it means that the target alternative airborne communication data packet is exactly the same as the first airborne communication data packet, and then there is no need to save it repeatedly, thereby reducing the noise in the airborne network communication database.
[0091] In summary, the civil passenger aircraft airborne information security protection method provided in the embodiment of the present application is based on mining the first intrusion behavior characterization vector corresponding to the first airborne communication data packet and multiple alternative intrusion behavior data classifications, and mining the second intrusion behavior characterization vector corresponding to the first airborne communication data packet and multiple second airborne communication data packets (approximate data packets of the first airborne communication data packet under each alternative intrusion behavior data classification), and performing intrusion behavior data classification inference on the first airborne communication data packet based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector to determine the intrusion behavior data classification of the first airborne communication data packet. When performing intrusion behavior data classification inference on the first airborne communication data packet, the intrusion behavior type of the first airborne communication data packet is determined based on the correlation between the first airborne communication data packet and the intrusion behavior data classification and the correlation between the first airborne communication data packet and the approximate data packet; then, in the intrusion behavior detection algorithm debugged when the number of samples is insufficient, if an intrusion behavior data classification is not in the debugging sample of the intrusion behavior detection algorithm, the intrusion behavior detection algorithm can be based on determining the approximate data packet of the first airborne communication data packet as the extended information to infer the support coefficient of the first airborne communication data packet corresponding to the intrusion behavior data classification, so as to increase the accuracy of the intrusion behavior data classification inference on the airborne communication data packet.
[0092] In the method provided in the present application, separate reasoning is adopted to ensure the accuracy of the first support coefficient and the second support coefficient obtained by reasoning, and then the classification support coefficient is obtained based on the weighted fusion of the first support coefficient and the second support coefficient to determine the intrusion behavior data classification of the first airborne communication data packet, and the influence of the two support coefficients on the final reasoning result is adjusted, thereby improving the accuracy of the intrusion behavior data classification reasoning.
[0093] This application is based on calculating the communication data packet commonality measurement results between the first airborne communication data packet and the alternative airborne communication data packets corresponding to each alternative intrusion behavior data classification, and obtaining the approximate data packet corresponding to the first airborne communication data packet under each alternative intrusion behavior data classification from the airborne network communication database. The algorithm can determine the support coefficient of the first airborne communication data packet belonging to the intrusion behavior data classification corresponding to the approximate data packet based on the correlation between the approximate data packet and the first airborne communication data packet, thereby overcoming the problem of insufficient classification accuracy of the algorithm for the specified intrusion behavior data classification when the number of samples of the specified intrusion behavior data classification is insufficient.
[0094] This application is based on the data combination of the first airborne communication data packet and the alternative intrusion behavior data classification, and after mining the intrusion behavior representation vector corresponding to the combined communication data, performs classification reasoning, and fully mines the correlation between the first airborne communication data packet and the alternative intrusion behavior data classification; based on the data combination of the first airborne communication data packet and the second airborne communication data packet, mining the intrusion behavior representation vector corresponding to the combined communication data and performing classification reasoning, fully mines the correlation between the first airborne communication data packet and the second airborne communication data packet, improves the embedding effect of the algorithm, and thus increases the accuracy of classification reasoning.
[0095] As another embodiment, the method provided in this application includes the following steps:
[0096] Step S210: Acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications.
[0097] The first airborne communication data packet is a communication data packet intended to determine the intrusion behavior type from a plurality of candidate intrusion behavior data classifications. As an embodiment, the plurality of candidate intrusion behavior data classifications are a plurality of intrusion behavior data classifications preset by a developer.
[0098] Step S220: Acquire multiple candidate airborne communication data packets from the airborne network communication database.
[0099] In one embodiment, the airborne network communication database is an airborne network communication database stored in the airborne network security protection system, and the airborne network communication database stores multiple candidate airborne communication data packets, each of which is an airborne communication data packet that has undergone intrusion behavior detection. The multiple candidate airborne communication data packets in the airborne network communication database are divided into multiple candidate intrusion behavior data categories, and each candidate intrusion behavior data category corresponds to multiple candidate airborne communication data packets.
[0100] Step S230: Acquire multiple component data clusters corresponding to the first airborne communication data packet, and determine the relevance of the component data clusters corresponding to the multiple candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification.
[0101] The component data cluster relevance characterizes the relevance between the multiple component data clusters and the candidate airborne communication data packets. For example, the component data clusters corresponding to the first airborne communication data packet can be obtained by performing component data cluster decomposition processing on the first airborne communication data packet, where the component data clusters are data component units in the airborne communication data packet, including at least one data item. After obtaining the multiple component data clusters, the occurrence rate of each component data cluster in the specified candidate airborne communication data packet is determined. The data packet capacity of the specified candidate airborne communication data packet is determined, as well as the average capacity of the multiple candidate airborne communication data packets. Based on the component data cluster occurrence rate, data packet capacity, and average capacity, the relevance between each component data cluster and the specified candidate airborne communication data packet is determined.
[0102] Step S240 : determining commonality measurement results corresponding to the plurality of candidate airborne communication data packets according to the association of the constituent data clusters.
[0103] The commonality measurement result represents the communication data packet commonality measurement result between the candidate airborne communication data packet and the first airborne communication data packet. As an embodiment, after determining the component data cluster associations corresponding to multiple component data clusters, the correlation values corresponding to the multiple component data cluster associations are fused, for example, by weighted summation, and the result is determined as the commonality measurement result between the candidate airborne communication data packet and the first airborne communication data packet. When fusion is performed on the correlation values corresponding to the multiple component data cluster associations, the influence coefficient (weight) corresponding to each component data cluster includes one or more of a database influence coefficient and a data packet influence coefficient.
[0104] As an implementation method, the database impact coefficient represents the impact of the data cluster on the entire airborne network communication database. For example, the database impact coefficient can be calculated as follows:
[0105] Wb=log(M / H)
[0106] Wherein, M is the number of airborne communication data packets contained in the entire airborne network communication database, and H is the number of airborne communication data packets that comprise the data cluster.
[0107] As an embodiment, the data packet influence coefficient is used to characterize the influence of the constituent data clusters on the first airborne communication data packet. For example, the data packet influence coefficient of each constituent data cluster in the first airborne communication data packet is determined based on the occurrence rate of each constituent data cluster in the first airborne communication data packet. The data packet influence coefficient can be calculated as follows:
[0108] Wc=(N / K)
[0109] Wherein, N is the number of the data clusters contained in the data packet, and K is the total number of data clusters in the airborne communication data packet.
[0110] Step S250: obtaining a first candidate airborne communication data packet having the largest commonality measurement result with the first airborne communication data packet among a plurality of candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification.
[0111] In other words, the p alternative airborne communication data packets with the largest commonality measurement results with the first airborne communication data packet among multiple alternative airborne communication data packets are determined as the second airborne communication data packets corresponding to the first alternative intrusion behavior data classification, wherein the first alternative airborne communication data packet is a communication data packet in the second airborne communication data packet.
[0112] For example, the first candidate airborne communication data packet having the largest commonality measurement result with the first airborne communication data packet among multiple candidate airborne communication data packets is determined as an approximate data packet that meets the commonality measurement result requirements with the first airborne communication data packet under the first candidate intrusion behavior data classification.
[0113] Step S260: obtaining a first data packet representation vector corresponding to the first airborne communication data packet, and obtaining candidate data packet representation vectors corresponding to each of a plurality of candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification.
[0114] For example, based on the commonality measurement result matching library, an approximate data packet that meets the commonality measurement result requirements of the first airborne communication data packet is obtained. Prior to this, multiple candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification and the first airborne communication data packet are quantitatively represented to obtain corresponding multiple candidate data packet representation vectors and the first data packet representation vector.
[0115] Step S270 : Based on a preset feature clustering strategy, the feature domain where the multiple candidate data packet representation vectors are located is divided into multiple sub-feature domains.
[0116] As an implementation method, the preset feature clustering strategy, also known as a clustering strategy, groups candidate data packet representation vectors corresponding to similar candidate airborne communication data packets into a single category. Specifically, in the feature domain (i.e., the space after data quantization), the feature domain containing candidate data packet representation vectors whose spatial similarity exceeds a similarity threshold is divided into a sub-feature domain. Each of the multiple sub-feature domains corresponds to a cluster representative representation vector, which is a vector representing all candidate data packet representation vectors in the corresponding sub-feature domain, i.e., the centroid of a cluster.
[0117] As an implementation method, the cluster representative representation vector can be determined in advance. That is, after determining the feature domains in which multiple candidate data packet representation vectors are located, multiple cluster representative representation vectors are evenly set. For the first cluster representative representation vector, the candidate data packet representation vectors among the multiple candidate data packet representation vectors whose spatial similarity with the first cluster representative representation vector is greater than a similarity threshold are divided into the sub-feature domain to which the first cluster representative representation vector belongs. It can be understood that when determining and setting the cluster representative representation vector and its corresponding similarity threshold, it is ensured that the multiple sub-feature domains obtained by the division can include all candidate data packet representation vectors.
[0118] As an implementation method, the cluster representative characterization vector is determined after the division of multiple sub-feature domains is completed, that is, after the sub-feature domains are divided, the center vector of the sub-feature domain is determined as the cluster representative characterization vector; or the vector with the smallest sum of spatial similarities with the alternative data packet characterization vectors in the sub-feature domain is determined as the cluster representative characterization vector, or the vector in the sub-feature domain with the largest spatial similarity with the alternative data packet characterization vectors less than a set value, in other words, the vector in the range with the densest alternative data packet characterization vectors in the sub-feature domain is determined as the cluster representative characterization vector.
[0119] Step S280 : determining spatial similarities between the plurality of cluster representative representation vectors and the first data packet representation vector.
[0120] For example, the spatial similarity between the cluster representative representation vector of each sub-feature domain and the representation vector of the first data packet is determined.
[0121] Step S290 : Obtain u cluster representative representation vectors having the greatest spatial similarity with the first data packet representation vector from among the plurality of cluster representative representation vectors, where u≥1.
[0122] Step S310 : determining a second candidate airborne communication data packet from the candidate airborne communication data packets corresponding to the candidate data packet representation vectors in the u sub-feature domains corresponding to the u cluster representative representation vectors.
[0123] That is, the spatial similarity between the first data packet representation vector and the candidate data packet representation vectors in the u sub-feature domains corresponding to the u cluster representative representation vectors is determined, and the candidate airborne communication data packets corresponding to the p candidate data packet representation vectors in the u sub-feature domains that have the greatest spatial similarity with the first data packet representation vector are determined as the second airborne communication data packet, where the second candidate airborne communication data packet is one of the second airborne communication data packets, and p = 1. This means that under the first candidate intrusion behavior data classification, another similar data packet that meets the commonality measurement result condition with the first airborne communication data packet is identified.
[0124] Step S311 : determining a second airborne communication data packet according to the first candidate airborne communication data packet and the second candidate airborne communication data packet.
[0125] For example, based on determining from the airborne network communication database two approximate data packets that meet the commonality measurement result requirements with the first airborne communication data packet under the first alternative intrusion behavior data classification, the two approximate data packets are sequentially combined, for example, directly spliced together, to obtain a second airborne communication data packet. As an embodiment, the communication data packet commonality measurement result between the first alternative airborne communication data packet and the second alternative airborne communication data packet is determined; if the communication data packet commonality measurement result between the first alternative airborne communication data packet and the second alternative airborne communication data packet is not less than the commonality measurement result threshold, the first alternative airborne communication data packet or the second alternative airborne communication data packet is determined as the second airborne communication data packet. For example, assuming that the commonality measurement result threshold is 1, that is, the first alternative airborne communication data packet and the second alternative airborne communication data packet are completely consistent, it is sufficient to determine only one of them as the second airborne communication data packet, such as randomly determining one or determining one according to the content commonality measurement method. When determined in accordance with the content commonality measurement method, the first content commonality measurement result between the second airborne communication data packet and the first alternative airborne communication data packet can be determined based on the content commonality measurement result; the second content commonality measurement result between the second airborne communication data packet and the second alternative airborne communication data packet is obtained; when the first content commonality measurement result is greater than the second content commonality measurement result, the first alternative airborne communication data packet is determined as the second airborne communication data packet; when the first content commonality measurement result is less than the second content commonality measurement result, the second alternative airborne communication data packet is determined as the second airborne communication data packet; when the first content commonality measurement result is equal to the second content commonality measurement result, the first alternative airborne communication data packet or the second alternative airborne communication data packet is determined as the second airborne communication data packet.
[0126] Step S312: mining a first intrusion behavior representation vector corresponding to the first airborne communication data packet and a plurality of candidate intrusion behavior data classifications.
[0127] As an implementation method, the first airborne communication data packet is respectively combined with multiple alternative intrusion behavior data classifications to obtain multiple first combined communication data; as an implementation method, the intrusion behavior detection algorithm includes a first feature embedding operator, which includes a first low-dimensional mapping network and a first attention network; the multiple first combined communication data are encoded based on the first low-dimensional mapping network to obtain multiple first encoding vectors; the multiple first encoding vectors are input into the first attention network, and the first encoding sub-vectors corresponding to the multiple first encoding vectors are mined according to the self-attention mechanism in the first attention network, and the multiple first encoding sub-vectors are used as the first intrusion behavior representation vectors, wherein the first encoding sub-vector is used to represent the correlation between an alternative intrusion behavior data classification and the first airborne communication data packet.
[0128] Step S313: mining a plurality of second intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of second airborne communication data packets.
[0129] As an implementation method, a first airborne communication data packet is respectively combined with multiple second airborne communication data packets to obtain multiple second combined communication data; as an implementation method, the intrusion behavior detection algorithm also includes a second feature embedding operator, which includes a second low-dimensional mapping network and a second attention network; the multiple second combined communication data are encoded based on the second low-dimensional mapping network to obtain multiple second encoding vectors; the multiple second encoding vectors are input into the second attention network, and the second encoding sub-vectors corresponding to the multiple second encoding vectors are mined according to the attention strategy (attention) in the second attention network, and the multiple second encoding sub-vectors are used as second intrusion behavior representation vectors, wherein the second encoding sub-vector represents the correlation between a second airborne communication data packet and the first airborne communication data packet.
[0130] Step S314 , performing intrusion behavior data classification reasoning based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and determining a first intrusion behavior data classification corresponding to the first airborne communication data packet from a plurality of candidate intrusion behavior data classifications.
[0131] The first intrusion behavior data classification indicates the intrusion behavior type corresponding to the first airborne communication data packet.
[0132] Based on the intrusion behavior detection algorithm, intrusion behavior data classification reasoning is performed according to the first intrusion behavior characterization vector to determine the first support coefficient corresponding to each of the multiple alternative intrusion behavior data classifications; based on the intrusion behavior detection algorithm, intrusion behavior data classification reasoning is performed according to the second intrusion behavior characterization vector to obtain the second support coefficient corresponding to each of the multiple alternative intrusion behavior types; the first support coefficient and the second support coefficient are integrated to obtain the classification support coefficient corresponding to each of the multiple alternative intrusion behavior data classifications; based on the classification support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications, the first intrusion behavior data classification corresponding to the first airborne communication data packet is determined from the multiple alternative intrusion behavior data classifications.
[0133] In summary, the civil passenger aircraft airborne information security protection method provided in the embodiment of the present application is based on mining the first intrusion behavior characterization vector corresponding to the first airborne communication data packet and multiple alternative intrusion behavior data classifications, and mining the second intrusion behavior characterization vector corresponding to the first airborne communication data packet and multiple second airborne communication data packets (approximate data packets of the first airborne communication data packet under each alternative intrusion behavior data classification), and performing intrusion behavior data classification inference on the first airborne communication data packet based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector to determine the intrusion behavior data classification of the first airborne communication data packet. When performing intrusion behavior data classification inference on the first airborne communication data packet, the intrusion behavior type of the first airborne communication data packet is determined based on the correlation between the first airborne communication data packet and the intrusion behavior data classification and the correlation between the first airborne communication data packet and the approximate data packet; then, in the intrusion behavior detection algorithm debugged when the number of samples is insufficient, if an intrusion behavior data classification is not in the debugging sample of the intrusion behavior detection algorithm, the intrusion behavior detection algorithm can be based on determining the approximate data packet of the first airborne communication data packet as the extended information to infer the support coefficient of the first airborne communication data packet corresponding to the intrusion behavior data classification, so as to increase the accuracy of the intrusion behavior data classification inference on the airborne communication data packet.
[0134] The method provided in an embodiment of the present application determines communication data packets from an airborne network communication database that meet the commonality measurement result conditions based on calculating the commonality measurement results of the constituent data clusters, thereby improving the accuracy of the approximate data packets determined. This embodiment of the present application obtains the spatial similarity between a first airborne communication data packet and multiple centroids, determines the centroids that meet the spatial similarity conditions, and then performs spatial similarity calculations on candidate communication data packets within the centroids that meet the conditions to obtain communication data packets that meet the commonality measurement result conditions, thereby avoiding the need to calculate the overall spatial similarity of the airborne network communication database, which would incur additional computational overhead.
[0135] The following describes the debugging process of the intrusion behavior detection algorithm provided by the embodiment of the present application, which specifically includes:
[0136] Step S410: acquiring a first airborne communication data packet learning sample and a reference intrusion behavior data classification corresponding to the first airborne communication data packet learning sample from an airborne network communication data sample library, and acquiring a plurality of candidate intrusion behavior data classifications.
[0137] The first airborne communication data packet learning sample is a communication data packet for determining an intrusion behavior type among multiple candidate intrusion behavior data classifications. The reference intrusion behavior data classification corresponding to the first airborne communication data packet learning sample is the actual intrusion behavior data classification marked with the first airborne communication data packet learning sample.
[0138] As an implementation method, the airborne network communication data sample library includes multiple airborne communication data packet learning samples, and the first airborne communication data packet learning sample is any airborne communication data packet learning sample among the multiple airborne communication data packet learning samples that has not undergone algorithm debugging.
[0139] As an implementation manner, the plurality of candidate intrusion behavior data classifications are a plurality of preset intrusion behavior data classifications, or the plurality of candidate intrusion behavior data classifications are intrusion behavior data classifications included in an airborne network communication data sample library.
[0140] Optionally, before obtaining the first airborne communication data packet learning sample from the airborne network communication data sample library, the method includes: obtaining an alternative airborne network communication database, performing data enhancement on multiple airborne communication data packet learning samples in the alternative airborne network communication database; and expanding the alternative airborne network communication database based on the results of the enhancement of the multiple airborne communication data packet learning samples to obtain the airborne network communication data sample library. The data enhancement method is, for example, based on manual operations such as data modification, addition, and deletion.
[0141] Optionally, before obtaining the first airborne communication data packet learning sample from the airborne network communication data sample library, the method also includes: obtaining an alternative airborne network communication database, the alternative airborne network communication database including multiple alternative airborne communication data packets, and the multiple alternative airborne communication data packets are respectively labeled with alternative intrusion behavior data classifications; performing intrusion behavior data classification inference on the multiple alternative airborne communication data packets based on the target intrusion behavior detection algorithm to obtain target intrusion behavior data classifications corresponding to the multiple alternative airborne communication data packets; determining target alternative airborne communication data packets with different alternative intrusion behavior data classifications and target intrusion behavior data classifications among the multiple alternative airborne communication data packets; updating the intrusion behavior classification labels corresponding to the target alternative airborne communication data packets, and updating the alternative airborne network communication database, and using the updated alternative airborne network communication database as the airborne network communication data sample library. Among them, the target intrusion behavior detection algorithm is, for example, the intrusion behavior detection algorithm obtained in the last debugging.
[0142] Step S420: obtaining second airborne communication data packet learning samples corresponding to a plurality of candidate intrusion behavior data classifications from an airborne network communication data sample library.
[0143] Among them, the commonality measurement result between the first airborne communication data packet learning sample and the second airborne communication data packet learning sample meets the preset measurement condition.
[0144] For details, please refer to the above description of steps S220 to S311 for obtaining the second airborne communication data packet from the airborne network communication database.
[0145] Step S430, based on the alternative intrusion behavior detection algorithm, mine the first intrusion behavior sample representation vector corresponding to the first airborne communication data packet learning sample and multiple candidate intrusion behavior data classifications, and mine the second intrusion behavior sample representation vector corresponding to the first airborne communication data packet learning sample and multiple second airborne communication data packet learning samples.
[0146] As an implementation method, a first airborne communication data packet learning sample is combined with multiple candidate intrusion behavior data classifications to obtain multiple first combined communication data samples; the multiple first combined communication data samples are embedded and encoded based on the candidate intrusion behavior detection algorithm to obtain multiple first sample encoding vectors; the first sub-intrusion behavior sample representation vectors corresponding to each of the multiple first sample encoding vectors are mined based on the candidate intrusion behavior detection algorithm, and the multiple first sub-intrusion behavior sample representation vectors are used as first intrusion behavior sample representation vectors. The first sub-intrusion behavior sample representation vector represents the correlation between an alternative intrusion behavior data classification and the first airborne communication data packet learning sample.
[0147] As an implementation method, a first airborne communication data packet learning sample is combined with multiple second airborne communication data packet learning samples to obtain multiple second combined communication data samples; the multiple second combined communication data samples are embedded and encoded based on an alternative intrusion behavior detection algorithm to obtain multiple second sample encoding vectors; and the multiple second sub-intrusion behavior sample representation vectors corresponding to each of the multiple second sample encoding vectors are mined based on the alternative intrusion behavior detection algorithm, and the multiple second sub-intrusion behavior sample representation vectors are used as second intrusion behavior sample representation vectors. The second sub-intrusion behavior sample representation vector represents the correlation between a second airborne communication data packet learning sample and a first airborne communication data packet learning sample.
[0148] For example, the alternative intrusion behavior detection algorithm includes a feature embedding operator for embedding and encoding the first airborne communication data packet learning example with the specified intrusion behavior data classification and the second airborne communication data packet learning example corresponding to the specified intrusion behavior data classification, thereby mining data features. The alternative intrusion behavior detection algorithm specifically adopts a dual-tower architecture. The feature embedding operator includes a first low-dimensional mapping network and a first attention network, which are used to encode the first airborne communication data packet learning example with the specified intrusion behavior data classification and represent the association between the first airborne communication data packet learning example and the specified intrusion behavior data classification based on the first attention network. Simultaneously, as the other "tower", the feature embedding operator includes a second low-dimensional mapping network and a second attention network, which are used to encode the first airborne communication data packet learning example with the second airborne communication data packet learning example corresponding to the specified intrusion behavior data classification and represent the association between the first airborne communication data packet learning example and the second airborne communication data packet learning example corresponding to the specified intrusion behavior data classification based on the second attention network.
[0149] Step S440 , performing intrusion behavior data classification inference based on the first intrusion behavior sample representation vector and the second intrusion behavior sample representation vector, and determining the inferred intrusion behavior data classification corresponding to the first airborne communication data packet learning sample from multiple candidate intrusion behavior data classifications.
[0150] Among them, based on the alternative intrusion behavior detection algorithm, intrusion behavior data classification reasoning is performed according to the first intrusion behavior sample representation vector to determine the first sample support coefficient corresponding to each of the multiple alternative intrusion behavior data classifications; based on the alternative intrusion behavior detection algorithm, intrusion behavior data classification reasoning is performed according to the second intrusion behavior sample representation vector to obtain the second sample support coefficient corresponding to each of the multiple alternative intrusion behavior data classifications; the first sample support coefficient and the second sample support coefficient are integrated to obtain the inference classification support coefficient corresponding to each of the multiple alternative intrusion behavior data classifications; based on the inference classification support coefficients corresponding to each of the multiple alternative intrusion behavior data classifications, the inference intrusion behavior data classification corresponding to the first airborne communication data packet learning sample is determined from the multiple alternative intrusion behavior data classifications.
[0151] For example, the alternative intrusion behavior detection algorithm includes a classification mapping operator, which includes a first feedforward neural unit, and the first feedforward neural unit is used to infer the correlation score between the first airborne communication data packet learning sample and the specified intrusion behavior data classification; the classification mapping operator also includes a second feedforward neural unit, and the second feedforward neural unit is used to infer the correlation score between the first airborne communication data packet learning sample and the second airborne communication data packet learning sample corresponding to the specified intrusion behavior data classification, and the mean of the scores is determined as the correlation score of the specified intrusion behavior data classification, thereby obtaining the inference classification support coefficient of the specified intrusion behavior data classification.
[0152] As an implementation method, based on sorting the correlation scores corresponding to all intrusion behavior data classifications, the intrusion behavior data classification with the greatest correlation (i.e., the inferred intrusion behavior data classification) is obtained to complete the identification of the intrusion behavior type of the first airborne communication data packet learning sample.
[0153] Step S450 : debugging the candidate intrusion behavior detection algorithm based on the difference between the reference intrusion behavior data classification and the inferred intrusion behavior data classification to obtain an intrusion behavior detection algorithm.
[0154] Among them, the intrusion behavior detection algorithm is used to infer the intrusion behavior data classification of the airborne communication data packet to determine the intrusion behavior type of the airborne communication data packet. As an implementation method, the alternative intrusion behavior detection algorithm can be debugged based on the cross entropy function. When the number of debugging times of the algorithm reaches a preset maximum number, or the detection error of the algorithm is less than the preset minimum error, the debugging is stopped to obtain the intrusion behavior detection algorithm.
[0155] It should be noted that although the steps of the method of the present application are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all steps must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.
[0156] The following introduces an embodiment of the device of the present application, which can be used to implement the civil passenger aircraft onboard information security protection method in the above-mentioned embodiment of the present application. Figure 2 The structural block diagram of the safety protection device provided in the embodiment of the present application is schematically shown. Figure 2 As shown, the safety protection device 200 includes:
[0157] The target data acquisition module 210 is configured to acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications, wherein the first airborne communication data packet is a communication data packet for determining an intrusion behavior type among the plurality of candidate intrusion behavior data classifications;
[0158] The reference data acquisition module 220 is configured to acquire a second airborne communication data packet corresponding to each of the plurality of candidate intrusion behavior data classifications, wherein a commonality measurement result between the second airborne communication data packet and the first airborne communication data packet satisfies a preset measurement condition;
[0159] A first feature mining module 230 is configured to mine first intrusion behavior representation vectors corresponding to the first airborne communication data packet and the multiple candidate intrusion behavior data classifications, wherein the first intrusion behavior representation vectors are used to represent the associations between the multiple candidate intrusion behavior data classifications and the first airborne communication data packet;
[0160] A second feature mining module 240 is configured to mine second intrusion behavior representation vectors corresponding to the first airborne communication data packet and a plurality of second airborne communication data packets, wherein the second intrusion behavior representation vectors are used to represent the associations between the plurality of second airborne communication data packets and the first airborne communication data packet;
[0161] The intrusion behavior classification module 250 is used to perform intrusion behavior data classification reasoning based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and determine the first intrusion behavior data classification corresponding to the first airborne communication data packet from the multiple alternative intrusion behavior data classifications, and the first intrusion behavior data classification is used to represent the intrusion behavior type corresponding to the first airborne communication data packet.
[0162] The specific details of the safety protection device provided in each embodiment of the present application have been described in detail in the corresponding method embodiments and will not be repeated here.
[0163] Figure 3 The following schematically shows a block diagram of a computer system structure for implementing an airborne network security protection system according to an embodiment of the present application.
[0164] It should be noted that Figure 3 The computer system 300 of the airborne network security protection system shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0165] like Figure 3 As shown, the computer system 300 includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage part 308 into the random access memory (RAM) 303. Various programs and data required for system operation are also stored in the random access memory 303. The CPU 301, the read-only memory 302, and the random access memory 303 are connected to each other via a bus 304. An input / output interface 305 (i.e., an I / O interface) is also connected to the bus 304.
[0166] The following components are connected to the input / output interface 305: an input section 306 including a keyboard, a mouse, and the like; an output section 307 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 308 including a hard disk; and a communication section 309 including a network interface card such as a local area network card or a modem. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the input / output interface 305 as needed. A storage medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 310 as needed, so that computer programs read therefrom can be installed into the storage section 308 as needed.
[0167] In particular, according to an embodiment of the present application, the processes described in the various method flow charts can be implemented as computer software programs. For example, an embodiment of the present application includes a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for executing the methods shown in the flow charts. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 309 and / or installed from the storage medium 311. When the computer program is executed by the central processing unit 301, the various functions defined in the system of the present application are performed.
[0168] It should be noted that the computer-readable medium shown in the embodiment of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by an instruction execution system, device or device or used in combination with it. In the present application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0169] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0170] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiment of the application, the features and functions of two or more modules or units described above can be concretized in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.
[0171] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0172] Those skilled in the art will readily appreciate other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of this application and include common knowledge or customary techniques in the art that are not disclosed herein.
[0173] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A method for protecting information security onboard a civil passenger aircraft, characterized in that: Applied to an airborne network security protection system, the method includes: Acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications, wherein the first airborne communication data packet is a communication data packet for determining an intrusion behavior type among the plurality of candidate intrusion behavior data classifications; Acquire a second airborne communication data packet corresponding to each of the plurality of candidate intrusion behavior data classifications, wherein a commonality measurement result between the second airborne communication data packet and the first airborne communication data packet satisfies a preset measurement condition; mining first intrusion behavior representation vectors corresponding to the first airborne communication data packet and the multiple candidate intrusion behavior data classifications, where the first intrusion behavior representation vectors are used to represent the associations between the multiple candidate intrusion behavior data classifications and the first airborne communication data packet; mining second intrusion behavior characterization vectors corresponding to the first airborne communication data packet and a plurality of second airborne communication data packets, where the second intrusion behavior characterization vectors are used to characterize the associations between the plurality of second airborne communication data packets and the first airborne communication data packet; Intrusion behavior data classification reasoning is performed based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and a first intrusion behavior data classification corresponding to the first airborne communication data packet is determined from the multiple alternative intrusion behavior data classifications, where the first intrusion behavior data classification is used to represent the intrusion behavior type corresponding to the first airborne communication data packet.
2. The method according to claim 1, characterized in that The performing intrusion behavior data classification reasoning based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and determining the first intrusion behavior data classification corresponding to the first airborne communication data packet from the multiple candidate intrusion behavior data classifications, includes: Performing intrusion behavior data classification reasoning on the first intrusion behavior representation vector based on the first intrusion behavior mapping operator in the intrusion behavior detection algorithm to obtain first support coefficients corresponding to each of the multiple candidate intrusion behavior data classifications; Performing intrusion behavior data classification reasoning on the second intrusion behavior representation vector based on the second intrusion behavior mapping operator in the intrusion behavior detection algorithm to obtain second support coefficients corresponding to multiple candidate intrusion behavior data classifications; Integrating the first support coefficient and the second support coefficient to obtain classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications; The first intrusion behavior data category corresponding to the first airborne communication data packet is determined from the multiple candidate intrusion behavior data categories according to the classification support coefficients corresponding to the multiple candidate intrusion behavior data categories.
3. The method according to claim 2, characterized in that The integrating the first support coefficient and the second support coefficient to obtain the classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications includes: Determining a plurality of airborne communication data packet learning samples included in a learning sample set of the intrusion behavior detection algorithm, wherein the intrusion behavior data classifications corresponding to the plurality of airborne communication data packet learning samples belong to one or more of the plurality of candidate intrusion behavior data classifications; Obtaining a first number of airborne communication data packet learning samples corresponding to each of the plurality of candidate intrusion behavior data categories; Determine, based on the first number, a first impact factor corresponding to the first support coefficient and a second impact factor corresponding to the second support coefficient, wherein the first number is positively correlated with the first impact factor and the first number is negatively correlated with the second impact factor; The first support coefficient and the second support coefficient are integrated according to the first influencing factor and the second influencing factor to obtain classification support coefficients corresponding to the multiple candidate intrusion behavior data classifications.
4. The method according to claim 1, wherein The plurality of candidate intrusion behavior data categories include a first candidate intrusion behavior data category; and obtaining second airborne communication data packets corresponding to each of the plurality of candidate intrusion behavior data categories includes: Acquire multiple candidate airborne communication data packets corresponding to the first candidate intrusion behavior data classification; Determine the communication data packet commonality measurement results between the multiple alternative airborne communication data packets and the first airborne communication data packet, and determine the p alternative airborne communication data packets with the largest communication data packet commonality measurement results between the multiple alternative airborne communication data packets and the first airborne communication data packet as the second airborne communication data packets corresponding to the first alternative intrusion behavior data classification; wherein p≥1.
5. The method according to claim 4, characterized in that The determining of communication data packet commonality measurement results between the multiple candidate airborne communication data packets and the first airborne communication data packet, and determining p candidate airborne communication data packets having the largest communication data packet commonality measurement results with the first airborne communication data packet among the multiple candidate airborne communication data packets as second airborne communication data packets corresponding to the first candidate intrusion behavior data classification, includes: Acquire multiple component data clusters corresponding to the first airborne communication data packet, and determine the association of the component data clusters corresponding to each of the multiple candidate airborne communication data packets, wherein the component data cluster association is used to characterize the association between the multiple component data clusters and the candidate airborne communication data packets; Determining, based on the association of the constituent data clusters, commonality measurement results corresponding to each of the plurality of candidate airborne communication data packets; P candidate airborne communication data packets with the largest commonality measurement results with the first airborne communication data packet among the multiple candidate airborne communication data packets are obtained and determined as second airborne communication data packets corresponding to the first candidate intrusion behavior data classification.
6. The method according to claim 4, characterized in that The determining of communication data packet commonality measurement results between the multiple candidate airborne communication data packets and the first airborne communication data packet, and determining p candidate airborne communication data packets having the largest communication data packet commonality measurement results with the first airborne communication data packet among the multiple candidate airborne communication data packets as second airborne communication data packets corresponding to the first candidate intrusion behavior data classification, includes: Obtaining a first data packet representation vector corresponding to the first airborne communication data packet, and obtaining a candidate data packet representation vector corresponding to each of the plurality of candidate airborne communication data packets; Based on a preset feature clustering strategy, the feature domains where the multiple candidate data packet representation vectors are located are divided into multiple sub-feature domains, each of the multiple sub-feature domains corresponds to a cluster representative representation vector; Determining spatial similarities between a plurality of cluster representative representation vectors and the first data packet representation vector; Obtaining u cluster representative representation vectors having the greatest spatial similarity with the first data packet representation vector from the plurality of cluster representative representation vectors, where u≥1; Determining the spatial similarity between the first data packet representation vector and the candidate data packet representation vectors in the u sub-feature domains corresponding to the u cluster representative representation vectors; The candidate airborne communication data packets corresponding to the p candidate data packet representation vectors having the greatest spatial similarity with the first data packet representation vector among the candidate data packet representation vectors in the u sub-feature domains are determined as the second airborne communication data packets.
7. The method according to any one of claims 1 to 6, characterized in that The mining of second intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of second airborne communication data packets includes: Classify and combine the first airborne communication data packet with the multiple candidate intrusion behavior data to obtain multiple first combined communication data; Based on the first feature embedding operator in the intrusion behavior detection algorithm, the first intrusion behavior sub-representation vectors corresponding to each of the multiple first combined communication data are mined, and the multiple first intrusion behavior sub-representation vectors are used as the first intrusion behavior representation vector, wherein a first intrusion behavior sub-representation vector is used to represent the correlation between an alternative intrusion behavior data classification and the first airborne communication data packet.
8. The method according to any one of claims 1 to 6, characterized in that The mining of second intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of second airborne communication data packets includes: Performing data combination processing on the first airborne communication data packet and the plurality of second airborne communication data packets respectively to obtain the plurality of second combined communication data; Based on the second feature embedding operator in the intrusion behavior detection algorithm, the second intrusion behavior sub-representation vectors corresponding to each of the multiple second combined communication data are mined, and the multiple second intrusion behavior sub-representation vectors are used as the second intrusion behavior representation vector, wherein a second intrusion behavior sub-representation vector is used to represent the correlation between a second airborne communication data packet and the first airborne communication data packet.
9. A safety protection device, characterized in that: include: a target data acquisition module, configured to acquire a first airborne communication data packet and a plurality of candidate intrusion behavior data classifications, wherein the first airborne communication data packet is a communication data packet for determining an intrusion behavior type among the plurality of candidate intrusion behavior data classifications; a reference data acquisition module, configured to acquire second airborne communication data packets corresponding to each of the plurality of candidate intrusion behavior data classifications, wherein a commonality measurement result between the second airborne communication data packet and the first airborne communication data packet satisfies a preset measurement condition; a first feature mining module, configured to mine first intrusion behavior representation vectors corresponding to the first airborne communication data packet and the plurality of candidate intrusion behavior data classifications, the first intrusion behavior representation vectors being used to represent the associations between the plurality of candidate intrusion behavior data classifications and the first airborne communication data packet; A second feature mining module is used to mine second intrusion behavior representation vectors corresponding to the first airborne communication data packet and multiple second airborne communication data packets, wherein the second intrusion behavior representation vector is used to represent the association between the multiple second airborne communication data packets and the first airborne communication data packet respectively; An intrusion behavior classification module is used to perform intrusion behavior data classification reasoning based on the first intrusion behavior characterization vector and the second intrusion behavior characterization vector, and determine the first intrusion behavior data classification corresponding to the first airborne communication data packet from the multiple alternative intrusion behavior data classifications, wherein the first intrusion behavior data classification is used to represent the intrusion behavior type corresponding to the first airborne communication data packet.
10. An airborne network security protection system, characterized in that: include: processor; and a memory for storing executable instructions for the processor; The processor is configured to perform the method according to any one of claims 1 to 8 by executing the executable instructions.
Citation Information
Patent Citations
System and method for providing security aboard a moving platform
CN102461118A
Big data privacy information analysis method and system based on artificial intelligence
CN113468604A