A bert-based network security detection individual system
By utilizing a Bert-based individual network security detection system with dynamic feature extraction and real-time adaptation modules, the system addresses the challenge of capturing complex patterns and hidden relationships in existing technologies. This enables efficient detection and immediate response to emerging threats, thereby improving the accuracy and efficiency of network security detection.
Patent Information
- Application Number
- CN202411099676.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-12
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-08-12
AI Technical Summary
Existing cybersecurity detection methods struggle to effectively capture complex patterns and hidden relationships in data, resulting in low detection accuracy and efficiency when facing new attacks and complex threats.
A BERT-based network security detection system for individual soldiers is adopted, including a dynamic feature extraction module, a multi-level detection module, a real-time adaptation module, an intelligent response module, and a behavior analysis module. It uses the BERT model to extract features from network traffic and logs, and combines federated learning and online learning technologies to dynamically adjust the detection model, monitor and respond to threats in real time, and automatically.
It improves the accuracy and efficiency of network security detection, can adapt to new threats in real time, reduce false positives and false negatives, provide immediate and effective defense measures, and help security teams quickly identify and respond to complex attacks.
Smart Images

Figure CN118784360B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the field of network security detection, and in particular to a network security detection individual system based on Bert. BACKGROUND
[0002] Bert (Bidirectional Encoder Representations from Transformers) is a new natural language processing model proposed by Google, which adopts a bidirectional encoder structure and a self-attention mechanism and can perform well in understanding the context relationship of texts. Bert has achieved remarkable results in multiple natural language processing tasks. With the rapid development of the Internet, the means and methods of network attacks are also evolving.
[0003] In the prior art, a network security individual system based on network space asset detection with the announcement number CN117375891A is disclosed, which relates to the technical field of network security and aims to build a power information asset fingerprint library, create a plug-in-based vulnerability testing framework, realize automatic vulnerability detection, improve the ability of the company's network security team to mine vulnerabilities and check hidden dangers, improve the work efficiency of vulnerability mining personnel, enhance the comprehensiveness and standardization of vulnerability discovery, and can be used to support the company's network security hidden danger checking and actual combat attack and defense work, and also plays an important role in the company's information security inspection and information security supervision work. At the same time, a company network security intelligence sharing knowledge base is established to provide an exchange platform for red and blue team members and improve the actual combat ability of network security personnel.
[0004] At present, common network security detection methods include intrusion detection systems, firewalls, anti-virus software, etc. They compare network traffic and user behavior with known attack patterns to identify potential security threats. In addition, some systems also use simple anomaly detection techniques based on statistical models of network behavior to identify abnormal behavior. These methods perform well in detecting traditional types of network attacks such as viruses, worms, and basic denial-of-service attacks. These methods work well in dealing with known threats, but often perform poorly when faced with new attacks and complex threats. Especially for rule-based detection methods, it is difficult to adapt to the changing attack patterns. Therefore, it is necessary to design a network security detection individual system based on Bert that can capture complex patterns and hidden relationships in data, thereby improving the accuracy and efficiency of detection. SUMMARY
[0005] (I) Technical problems solved
[0006] To solve the problems in the background art, the application provides a network security detection individual system based on Bert, which has the advantages of being able to capture complex patterns and hidden relationships in data, thereby improving the accuracy and efficiency of detection, and solving the problems in the background art.
[0007] (II) Technical Solution
[0008] To achieve the above-mentioned purpose of being able to capture complex patterns and hidden relationships in data, thereby improving the accuracy and efficiency of detection, the present application provides the following technical solution: a network security detection single-soldier system based on Bert, comprising a dynamic feature extraction module, a multi-level detection module, a real-time adaptation module, an intelligent response module and a behavior analysis module.
[0009] The dynamic feature module dynamically extracts the features of network traffic and logs using the BERT model, capturing complex semantic and temporal patterns.
[0010] The multi-level detection module is used to perform multi-level threat detection on the extracted features, using a lightweight model for preliminary screening and a deep model for analysis.
[0011] The real-time adaptation module is used to monitor real-time network traffic and logs, dynamically adjusting the detection model and parameters, using federated learning and online learning techniques to enable the system to update the model without stopping operation, adapting to new threats.
[0012] The intelligent response module is used to generate warnings and automatically take corresponding measures based on the detection results.
[0013] The behavior analysis module is used to analyze the detected threat behavior in depth, trace the attack source, and provide attack path and behavior pattern analysis.
[0014] Preferably, the dynamic feature module includes a data embedding module, a temporal pattern extraction module and a self-attention mechanism module, the data embedding module is used to convert raw network traffic data and log data into embedded representations that can be processed by the model; the temporal pattern extraction module is used to extract temporal patterns in network traffic and logs, capturing the time dependence and sequential relationship of data; the self-attention mechanism module uses self-attention mechanism to model global dependency relationships of data and identify features and relationships.
[0015] Further, the above-mentioned scheme uses the embedding layer of BERT to convert the original data into high-dimensional vectors, capturing the semantic and contextual information of the data; capturing the time dependence and sequential relationship of data, achieved through a temporal convolution network model.
[0016] Preferably, the multi-level detection module includes a preliminary screening module and a deep analysis module; the preliminary screening module is used for quickly screening network traffic and log data, identifying abnormalities and potential threats, filtering out normal background traffic, using a lightweight machine learning model or rule engine for preliminary detection, quickly identifying and marking suspicious data; the deep analysis module is used for analyzing suspicious data marked by the preliminary screening module, identifying complex and hidden attack patterns, using a deep learning model for in-depth analysis, extracting features and patterns.
[0017] Preferably, the real-time adaptation module includes a federated learning module, an online learning module, and an adaptive parameter adjustment module; the federated learning module is used for collaborative training and updating of the model using distributed machine learning techniques without centralized data; the online learning module is used for dynamically updating the model based on real-time streaming data, continuously learning patterns and features in new data; the adaptive parameter adjustment module is used to dynamically adjust the parameters and thresholds of the model according to real-time detection conditions and feedback.
[0018] Further, the above scheme is adopted, and each node shares model parameters rather than data, ensuring data privacy while continuously optimizing and updating the detection model, and improving the system's adaptability to new threats; the model can be continuously updated and improved during operation, quickly adapting to new attack methods and environmental changes, and maintaining the leading edge of detection capabilities; by automatically adjusting detection parameters, the system can maintain efficient and accurate threat detection under different network environments and loads, reducing false positives and false negatives.
[0019] Preferably, the intelligent response module includes an automated response module and an intelligent decision-making module; the automated response module is used to automatically execute predefined response measures; the intelligent decision-making module uses machine learning and reinforcement learning techniques to dynamically generate response strategies based on detected threats and current network conditions.
[0020] Further, the above scheme is adopted, such as isolating infected devices, blocking malicious traffic, and modifying firewall rules, to quickly take action after detecting threats, reduce the impact and spread of threats, and ensure the immediacy and effectiveness of network security; based on detected threats and current network conditions, dynamically generate the best response strategy, provide optimized response measures when facing complex and variable threats, improve response efficiency and effectiveness, and reduce human decision-making errors and delays.
[0021] Preferably, the behavior analysis module includes an attack behavior identification module and an attack path analysis module; the attack behavior identification module identifies and classifies different types of attack behaviors by analyzing network traffic and log data; the attack path analysis module is used to track and analyze the activity path of the attacker in the network, draw an attack path diagram, and show the action steps and targets of the attacker.
[0022] The attack path analysis module is used to track and analyze the activity path of the attacker in the network, draw an attack path diagram, and show the action steps and targets of the attacker
[0023] Further, the above scheme is used to identify and classify different types of attack behaviors, such as DDoS, SQL injection, and phishing, to classify and identify detected abnormal behaviors using machine learning and pattern recognition techniques, to help the security team quickly understand the current threat type and characteristics; through behavior chain analysis and graph neural network, the action strategy and purpose of the attacker are understood in depth, and the visualization of the attack source and attack path is provided to help formulate effective defense and response strategies.
[0024] A network security detection single-person method based on Bert, comprising the following steps:
[0025] S1: Collect network traffic data and log data from various network devices and log systems, and label the data to identify normal traffic and abnormal traffic;
[0026] S2: Convert text data into embedding vectors using the BERT model to capture semantic information of the text, combine BERT embedding and time series features, extract multi-dimensional features, and form feature vectors;
[0027] S3: Input the extracted feature vectors into a machine learning model for training, and use labeled data for supervised learning;
[0028] S4: Deploy the trained model in the network environment, monitor network traffic and log data in real time, and use the trained model to analyze and detect real-time data to identify potential security threats and abnormal behaviors;
[0029] S5: In-depth analysis of detected threat behaviors through behavior analysis and graph neural network to identify attack patterns and paths, and draw attack route maps;
[0030] S6: Use online learning and federated learning to update and optimize the detection model in real time, and share model parameters and updates between different network nodes.
[0031] Preferably, S2 further comprises extracting features from time series data, concatenating text embedding and time series features to form a comprehensive feature vector, calculating the interaction feature between text and time series features to capture the potential relationship between the two, using attention mechanism to calculate the correlation between the two features and generating a weighted feature vector, text embedding vector: T = [T1, T2,..., T m ], time series feature vector: S = [S1, S2,..., S n ], similarity score is calculated using dot product, formula as follows:
[0032]
[0033] Wherein, e ij represents the similarity between text embedding T i and time series feature S j , T ik and S jk represent the kth element of T i and S j , respectively, T i represents the i-th text embedding vector, with dimension d; S j represents the j-th time series feature vector, with dimension d.
[0034] The similarity score is normalized using the Softmax function to obtain the attention weight, the calculation formula is as follows:
[0035]
[0036] Wherein, α ij represents the importance weight of time series feature S j to text embedding T i , e ij represents the similarity between text embedding T i and time series feature vector S j , e ik represents the similarity between text embedding vector T i and time series feature vector S k .
[0037] The weighted feature vector is obtained by weighted sum of time series feature vector using attention weight, the calculation formula is as follows:
[0038]
[0039] Wherein, I i is the weighted feature vector corresponding to T i , with dimension d.
[0040] The generated weighted feature vector I i is combined with the text embedding vector T i to form the final interaction feature vector, as follows:
[0041] F i = [T i ; I i ]
[0042] where F i represents the final interaction feature vector, I i represents the weighted feature vector corresponding to T i , and [T i ; I i ] represents concatenating T i and I i to form a new feature vector with a dimension of 2d.
[0043] Preferably, the S4 further includes collecting network traffic data in real time through a network traffic analyzer, managing and processing real-time data streams using a real-time data processing framework, processing real-time data in batches according to time windows or fixed sizes, deploying trained models on edge devices, servers, or the cloud, managing and expanding using containerization technology, performing model inference on each batch of real-time data, calculating feature vectors, and detecting potential threats and abnormal behavior through the model, detecting abnormal data points using the local outlier factor algorithm.
[0044] Further to the above scheme, the S4 further includes collecting network traffic data in real time through a network traffic analyzer, managing and processing real-time data streams using a real-time data processing framework, processing real-time data in batches according to time windows or fixed sizes for batch analysis by the model, deploying trained models on edge devices, servers, or the cloud, managing and expanding using containerization technology, performing model inference on each batch of real-time data, calculating feature vectors, and detecting potential threats and abnormal behavior through the model, detecting abnormal data points using the local outlier factor algorithm, identifying specific attack patterns such as DDoS attacks, data breaches, and malware propagation based on the detection results, dynamically updating the model through online learning algorithms to adapt to new threats and attack patterns, periodically retraining the model to incorporate the latest threat intelligence and historical data, and maintaining the accuracy and effectiveness of the model.
[0045] Preferably, entities in the system are taken as nodes in the graph, interactions between them are taken as edges in the graph, feature vectors are generated for each node and edge, GCN is used to capture features of nodes and their neighbors, embedding vectors of each node are extracted through graph convolution operation, attention mechanism is introduced using GAT, weights of neighbor nodes are dynamically adjusted, node embedding vectors are combined to generate embedding representation of the entire graph, graph embedding is clustered to identify similar behavior patterns, potential attack groups are detected, abnormal nodes and edges are identified using anomaly detection algorithms, potential threat behaviors are marked, features of abnormal nodes and edges are analyzed, attack patterns are identified, and activity paths of attackers are tracked to identify attack paths from initial intrusion points to targets.
[0046] (III) Advantages
[0047] Compared with the prior art, the present application provides a network security detection single-person system based on Bert, which has the following advantages:
[0048] The present application deploys a trained model in a network environment, monitors network traffic and log data in real time, analyzes and detects real-time data using the trained model, identifies potential security threats and abnormal behaviors, and analyzes detected threat behaviors in depth through behavior analysis and graph neural networks to identify attack patterns and paths, draw attack route maps, and capture complex patterns and hidden relationships in data, thereby improving the accuracy and efficiency of network security detection. BRIEF DESCRIPTION OF DRAWINGS
[0049] Figure 1 The present application is a structural schematic diagram. DETAILED DESCRIPTION
[0050] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0051] As Figure 1 shown, the present application provides a technical solution: a network security detection single-person system based on Bert, comprising a dynamic feature extraction module, a multi-level detection module, a real-time adaptation module, an intelligent response module, and a behavior analysis module.
[0052] The multi-level detection module is used for multi-level threat detection of the extracted features, and a lightweight model is used for preliminary screening, and a deep model is used for analysis.
[0053] The real-time adaptation module is used to monitor real-time network traffic and logs, dynamically adjust detection models and parameters, and use federated learning and online learning techniques to enable the system to update models without stopping operation, adapt to emerging threats;
[0054] The intelligent response module is used to generate warnings and automatically take corresponding measures according to detection results;
[0055] The behavior analysis module is used to in-depth analyze detected threat behaviors, trace attack sources, and provide attack path and behavior pattern analysis;
[0056] The dynamic feature module includes a data embedding module, a time series pattern extraction module, and a self-attention mechanism module. The data embedding module is used to convert raw network traffic data and log data into embedded representations that can be processed by models. The original data is converted into high-dimensional vectors using the embedding layer of BERT to capture semantic and contextual information. The time series pattern extraction module is used to extract time series patterns in network traffic and logs to capture temporal dependencies and sequential relationships. This is achieved through a time series convolutional network model. The self-attention mechanism module uses self-attention mechanisms to model global dependencies in data and identify features and relationships.
[0057] The multi-level detection module includes a preliminary screening module and a deep analysis module. The preliminary screening module is used to quickly screen network traffic and log data, identify obvious anomalies and potential threats, and filter out normal background traffic. Lightweight machine learning models or rule engines are used for preliminary detection to quickly identify and label suspicious data. The deep analysis module is used to analyze suspicious data labeled by the preliminary screening module in detail, identify complex and hidden attack patterns, and use deep learning models for in-depth analysis to extract features and patterns.
[0058] The real-time adaptation module includes a federated learning module, an online learning module, and an adaptive parameter adjustment module. The federated learning module uses distributed machine learning techniques to collaboratively train and update models without centralized data. Each node shares model parameters rather than data, ensuring data privacy while continuously optimizing and updating detection models to improve the system's ability to adapt to new threats. The online learning module is used to dynamically update models based on real-time streaming data, continuously learning patterns and features in new data to enable models to update and improve during operation, quickly adapt to new attack methods and environmental changes, and maintain the forefront of detection capabilities. The adaptive parameter adjustment module dynamically adjusts model parameters and thresholds based on real-time detection and feedback to optimize detection performance. By automatically adjusting detection parameters, the system can maintain high efficiency and accuracy in threat detection under different network environments and loads, reducing false positives and false negatives.
[0059] The intelligent response module includes an automated response module and an intelligent decision module. The automated response module is used to automatically execute predefined response measures, such as isolating infected devices, blocking malicious traffic, and modifying firewall rules, to quickly take action after detecting threats, reduce the impact and spread of threats, and ensure the immediacy and effectiveness of network security. The intelligent decision module uses machine learning and reinforcement learning techniques to dynamically generate optimal response strategies based on detected threats and current network conditions, providing optimized response measures when facing complex and variable threats, improving response efficiency and effectiveness, and reducing human decision errors and delays.
[0060] The behavior analysis module includes an attack behavior identification module and an attack path analysis module. The attack behavior identification module identifies and classifies different types of attack behaviors, such as DDoS, SQL injection, and phishing, by analyzing network traffic and log data, using machine learning and pattern recognition techniques to classify and identify detected abnormal behaviors, helping security teams quickly understand current threat types and characteristics. The attack path analysis module is used to track and analyze the activity path of attackers in the network, draw attack path diagrams, and display the action steps and targets of attackers. Through behavior chain analysis and graph neural networks, the action strategy and purpose of attackers are deeply understood, providing visual display of attack sources and attack paths to help develop effective defense and response strategies.
[0061] A Bert-based network security detection single-person method, comprising the following steps:
[0062] S1: Collect network traffic data and log data from various network devices and log systems, and label the data to identify normal traffic and abnormal traffic;
[0063] S2: Use the BERT model to convert text data into embedding vectors to capture semantic information of the text, combine BERT embedding and time series features, extract multi-dimensional features, and form a feature vector;
[0064] From the time series data, extract features, concatenate text embedding and time series features to form a comprehensive feature vector, calculate the interaction features between text and time series features, capture the potential relationship between the two, use attention mechanism to calculate the correlation between the two features, and generate a weighted feature vector. Text embedding vector: T = [T1, T2,..., T m ], time series feature vector: S = [S1, S2,..., S n ], similarity score is calculated using dot product, formula as follows:
[0065]
[0066] Where, eij Indicates text embedding T i and time series features S j The similarity between them, T ik and S jk T represents respectively i and S j The k-th element, T i S represents the vector containing the i-th text embedding, with dimension d; j Let represent the j-th time series feature vector, with dimension d;
[0067] The similarity scores are normalized using the Softmax function to obtain the attention weights, calculated as follows:
[0068]
[0069] Where, α ij Representing the time series features S j Text embedding T i Importance weight, e ij Indicates text embedding T i and time series feature vector S j The similarity between them, e ik Represents the text embedding vector T i and time series feature vector S k The similarity between them;
[0070] The time series feature vectors are weighted and summed using attention weights to obtain a weighted feature vector, calculated as follows:
[0071]
[0072] Among them, I i Is with T i The corresponding weighted feature vector has a dimension of d;
[0073] The generated weighted feature vector I i With text embedding vector T i The final interactive feature vector is formed by combining these features, as shown in the following formula:
[0074] F i =[T i ;I i ]
[0075] Among them, F i I represents the final interaction feature vector. i The weighted summation obtained with respect to T i The corresponding weighted feature vector, [T i ;I i ] indicates that Ti and I i Concatenate them together to form a new feature vector with dimension 2d;
[0076] S3: Input the extracted feature vector into the machine learning model for training, and use the labeled data for supervised learning;
[0077] S4: Deploy the trained model in the network environment, real-time monitor network traffic and log data, use the trained model to analyze and detect real-time data, identify potential security threats and abnormal behavior;
[0078] Collect network traffic data in real time through network traffic analyzer, use real-time data processing framework to manage and process real-time data stream, process real-time data in batches according to time window or fixed size, so that the model can analyze in batches, deploy the trained model in edge device, server or cloud, use containerization technology for management and expansion, perform model inference on each batch of real-time data, calculate feature vector, and detect potential threats and abnormal behavior through model, use local outlier factor algorithm to detect abnormal data points, identify specific attack patterns such as DDoS attack, data leakage, malware propagation, etc. according to detection results, dynamically update model through online learning algorithm, adapt to new threats and attack patterns, retrain model regularly, incorporate the latest threat intelligence and historical data, and maintain the accuracy and effectiveness of the model;
[0079] S5: Analyze the detected threat behavior in depth through behavior analysis and graph neural network, identify attack patterns and paths, and draw attack route map;
[0080] The entities in the system are taken as nodes in the graph, and the interactions between them are taken as edges in the graph. Feature vectors are generated for each node and edge. GCN is used to capture the features of nodes and their neighbors. Embedding vectors of each node are extracted through graph convolution operations. On the basis of GCN, graph attention network (GAT) is used to dynamically adjust the weight of each neighbor node by introducing attention mechanism. The attention mechanism can assign different weights according to the similarity or importance between nodes, so that the model can learn the features of nodes more effectively. Through GAT, the model can automatically focus on more important neighbor nodes, thereby generating more representative node embedding vectors. The embedding vectors of all nodes in the graph are combined to generate the embedding representation of the entire graph. This can be achieved by averaging, pooling or other aggregation operations on the embedding vectors of all nodes. The generated graph embedding representation can be used for further behavior pattern analysis. The graph embedding is clustered to identify similar behavior patterns, detect potential attack groups, use anomaly detection algorithms to identify abnormal nodes and edges, label potential threat behaviors, analyze the features of abnormal nodes and edges, identify attack patterns, track the activity path of attackers, and identify the attack path from the initial intrusion point to the target.
[0081] S6: Use online learning and federated learning to update and optimize the detection model in real time, and share model parameters and updates between different network nodes.
[0082] It should be noted that, in this paper, relational terms such as first and second are used only to distinguish one entity or operation from another, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment.
[0083] Although embodiments of the present application have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.
Claims
1. A Bert-based network security detection individual system, characterized in that, The system comprises a dynamic feature extraction module, a multi-level detection module, a real-time adaptation module, an intelligent response module, and a behavior analysis module. The dynamic feature extraction module uses the BERT model to dynamically extract features of network traffic and logs, capturing complex semantic and temporal patterns. The multi-level detection module is used for multi-level threat detection of the extracted features, using a lightweight model for preliminary screening and a deep model for analysis. The real-time adaptation module monitors real-time network traffic and logs, dynamically adjusts detection models and parameters, and uses federated learning and online learning techniques to enable the system to update models without stopping operation, adapting to emerging threats. The intelligent response module generates warnings and automatically takes corresponding measures based on the detection results. The behavior analysis module in-depth analyzes the detected threat behaviors, traces the attack source, and provides attack path and behavior pattern analysis. The dynamic feature extraction module includes a data embedding module, a temporal pattern extraction module, and a self-attention mechanism module. The data embedding module converts raw network traffic data and log data into embedded representations that can be processed by the model. The temporal pattern extraction module extracts temporal patterns in network traffic and logs, capturing temporal dependencies and sequential relationships of data. The self-attention mechanism module uses self-attention mechanisms to model global dependencies of data and identify features and relationships. The multi-level detection module includes a preliminary screening module and a deep analysis module. The preliminary screening module quickly screens network traffic and log data, identifies anomalies and potential threats, filters out normal background traffic, and uses lightweight machine learning models or rule engines for preliminary detection to quickly identify and label suspicious data. The deep analysis module analyzes suspicious data labeled by the preliminary screening module, identifies complex and hidden attack patterns, and uses deep learning models for in-depth analysis to extract features and patterns. The real-time adaptation module includes a federated learning module, an online learning module, and an adaptive parameter adjustment module. The federated learning module uses distributed machine learning techniques to collaboratively train and update models without centralized data. The online learning module dynamically updates models based on real-time streaming data, continuously learning patterns and features in new data. The adaptive parameter adjustment module dynamically adjusts model parameters and thresholds based on real-time detection and feedback. The intelligent response module includes an automated response module and an intelligent decision-making module. The automated response module automatically executes predefined response measures. The intelligent decision-making module uses machine learning and reinforcement learning techniques to dynamically generate response strategies based on detected threats and current network situation. The behavior analysis module includes an attack behavior identification module and an attack path analysis module. The attack behavior identification module identifies and classifies different types of attack behaviors by analyzing network traffic and log data. The attack path analysis module traces and analyzes the activity path of attackers in the network, draws attack path diagrams, and displays the steps and targets of attackers. The network security detection single-person system further comprises the following steps: S1: Collect network traffic data and log data from various network devices and log systems, label the data, and identify normal traffic and abnormal traffic; S2: Convert text data into embedding vectors using the BERT model to capture semantic information of the text, combine BERT embedding and time series features, extract multi-dimensional features, and form feature vectors; S3: Input the extracted feature vectors into a machine learning model for training, and use labeled data for supervised learning; S4: Deploy the trained model in the network environment, monitor network traffic and log data in real time, analyze and detect real-time data using the trained model, identify potential security threats and abnormal behavior; S5: Analyze the detected threat behavior in depth through behavior analysis and graph neural networks, identify attack patterns and paths, and draw attack route maps; S6: Use online learning and federated learning to update and optimize the detection model in real time, and share model parameters and updates between different network nodes.
2. The Bert-based network security detection individual system according to claim 1, wherein, The S4 further comprises: Collect network traffic data in real time through a network traffic analyzer, use a real-time data processing framework to manage and process real-time data streams, process real-time data in batches according to time windows or fixed sizes, deploy the trained model on edge devices, servers or the cloud, use containerization technology for management and expansion, perform model inference on each batch of real-time data, calculate feature vectors, and detect potential threats and abnormal behavior through the model, and use the local outlier factor algorithm to detect abnormal data points.
3. The Bert-based network security detection individual system according to claim 1, wherein, The S5 further comprises: Treat entities in the system as nodes in a graph, treat interactions between them as edges in the graph, generate feature vectors for each node and edge, use GCN to capture features of nodes and their neighbors, extract embedding vectors for each node through graph convolution operations, use GAT to introduce an attention mechanism, dynamically adjust the weights of neighbor nodes, combine node embedding vectors, generate embedding representations of the entire graph, cluster graph embeddings, identify similar behavior patterns, detect potential attack groups, use anomaly detection algorithms to identify abnormal nodes and edges, label potential threat behavior, analyze features of abnormal nodes and edges, identify attack patterns, track activity paths of attackers, and identify attack paths from initial intrusion points to targets.
Citation Information
Patent Citations
Network security individual soldier system and method based on network space asset detection
CN117375891A