Adversarial Attack Defense Method, Device, Equipment, Medium and Product
By performing feature changes and image conversion on traffic samples, generating adversarial samples and amplifying the training data set of detection models, the problem of inaccuracy and efficiency of adversarial attack defense in the prior art is solved, and more efficient attack traffic detection and defense is achieved.
Patent Information
- Application Number
- CN202410311602.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-03-19
AI Technical Summary
The prior art is difficult to improve accuracy and efficiency when defending against adversarial attacks, especially in obtaining feature space and model training of adversarial samples.
By making changes to the packet characteristics of the traffic sample and converting it to an image format, adding image characteristics of the attack traffic, generating the first and second adversarial samples. These adversarial samples are used together with the original traffic samples to train the detection model, amplify the training dataset and improve the robustness of the model.
This method significantly improves the accuracy and efficiency of adversarial attack defense by generating a large number of adversarial samples and amplifying the training dataset of detection models, and can more effectively detect and defend attack traffic.
Smart Images

Figure CN118802286B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and more specifically, to a method, device, equipment, medium and product for countering attack defense. Background Art
[0002] The existing defense methods against adversarial attacks mainly have the following technical problems: 1) Correction of the traffic data to be tested. This type of method generally requires obtaining the feature space of the adversarial sample and retraining the model. Since the sample itself is highly concealed, it is difficult to obtain. Secondly, even if a large number of adversarial samples are generated, it is difficult to map them to real traffic samples and verify their effectiveness; 2) Correction of the model structure. This type of method often increases the complexity of the model, and the model can only provide effective defense against very limited adversarial attacks; 3) Use of additional network detection. This type of method usually requires a large amount of additional training data. Since there are currently few public data sets for encrypted traffic, and there is no public data set for attack traffic simulated using adversarial networks, training additional networks greatly increases the training cost of adversarial attacks and affects the accuracy of the final target classification model.
[0003] Therefore, how to improve the accuracy and efficiency of defense against adversarial attacks has become a technical problem that needs to be urgently solved in the industry. Summary of the invention
[0004] The present application provides an anti-attack defense method, device, equipment, medium and product to solve the technical problem of how to improve the accuracy and efficiency of anti-attack defense in the prior art.
[0005] In a first aspect, the present application provides a method for countering attack defense, comprising:
[0006] Modify the data packet characteristics of the traffic sample to obtain the first adversarial sample;
[0007] Converting the data format of the traffic sample into an image format, and adding the image features of the attack traffic to the image corresponding to the traffic sample to obtain a second adversarial sample;
[0008] An initial detection model is trained based on the traffic sample, the first adversarial sample and the second adversarial sample to obtain a detection model; the detection model is used to detect whether the traffic to be tested is attack traffic to defend against the attack traffic.
[0009] In some embodiments, converting the data format of the traffic sample into an image format includes:
[0010] Determine the session scope of each data packet based on the session duration and session interval of each data packet of each traffic sample;
[0011] Remove a preset number of data packets within the session based on the byte sizes of the respective data packets;
[0012] Locate multiple clusters in the data packets that have not been removed based on a breadth - first algorithm; Any cluster includes a group of data packets with similar packet lengths;
[0013] Determine a reference packet length based on the average packet lengths of the data packets in each cluster;
[0014] Correct the packet lengths of each non - removed data packet based on the reference packet length and perform data format conversion on the corrected data packets.
[0015] In some embodiments, after obtaining the detection model, it further includes:
[0016] Input the traffic to be detected into the detection model to obtain a first detection result output by the detection model;
[0017] Input the traffic to be detected into a constructed anti - noise codec filter to obtain the processed traffic to be detected output by the anti - noise codec filter; The anti - noise codec filter is used to perform low - dimensional compression on the high - dimensional features of the traffic to be detected and remove the noise part of the traffic to be detected;
[0018] Input the processed traffic to be detected into the detection model to obtain a second detection result output by the detection model;
[0019] Determine whether the traffic to be detected is attack traffic based on the first detection result and the second detection result.
[0020] In some embodiments, the anti - noise codec filter is constructed based on the following steps:
[0021] Input a sample image into an anti - noise encoder to obtain the low - dimensional features corresponding to the sample image output by the anti - noise encoder; The sample image includes a traffic sample image and an adversarial sample image; The adversarial sample image includes a first adversarial sample image and a second adversarial sample image;
[0022] Input the low - dimensional features into an anti - noise decoder to obtain a reconstructed image output by the anti - noise decoder; The reconstructed image includes a first reconstructed image of the traffic sample image and a second reconstructed image of the adversarial sample;
[0023] Compare the first reconstructed image with the second reconstructed image based on a root - mean - square error function and perform parameter tuning on an initial anti - noise codec filter based on the comparison result to obtain the anti - noise codec filter.
[0024] In some embodiments, determining whether the traffic to be measured is attack traffic based on the first detection result and the second detection result includes:
[0025] When the first detection result and the second detection result are the same and the detection result is attack traffic, put the traffic to be measured into the traffic sample library and issue an alarm;
[0026] When the first detection result and the second detection result are the same and the detection result is non-attack traffic, release the traffic to be measured;
[0027] When the first detection result and the second detection result are different, put the traffic to be measured into the traffic sample library and issue an alarm.
[0028] In some embodiments, changing the packet characteristics of the traffic sample to obtain a first adversarial sample includes:
[0029] Clean the data of the packets of the traffic sample;
[0030] Obtain the packet characteristics of the cleaned packets;
[0031] Add interference factors during the process of processing the packet characteristics to obtain the first adversarial sample.
[0032] In a second aspect, the present application provides an anti-attack defense device, including:
[0033] A change module, configured to change the packet characteristics of the traffic sample to obtain a first adversarial sample;
[0034] A conversion module, configured to convert the data format of the traffic sample into an image format and add the image characteristics of the attack traffic to the image corresponding to the traffic sample to obtain a second adversarial sample;
[0035] A training module, configured to train an initial detection model based on the traffic sample, the first adversarial sample, and the second adversarial sample to obtain a detection model; the detection model is used to detect whether the traffic to be measured is attack traffic to defend against attack traffic.
[0036] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to implement the above method when executing the program through the computer program.
[0037] In a fourth aspect, an embodiment of the present application provides a non-transitory computer-readable storage medium, on which a computer program is stored, and the computer program implements the above method when executed by a processor.
[0038] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above method.
[0039] The adversarial attack defense method, device, equipment, medium and product provided by the embodiments of the present application can obtain a large number of adversarial samples by changing the packet characteristics of traffic samples at the packet level, converting the data format of traffic samples into an image format, and adding the image characteristics of attack traffic to the image; by using the adversarial samples and traffic samples as training samples to train the initial detection model, the training data set of the detection model is fully expanded, the robustness of the detection model is improved, and thus the defense accuracy and efficiency against adversarial attacks are improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0041] Figure 1 It is one of the schematic flowcharts of the adversarial attack defense method provided by the embodiments of the present application;
[0042] Figure 2 It is the schematic flowchart of active defense provided by the embodiments of the present application;
[0043] Figure 3 It is the schematic flowchart of training a noise-resistant codec filter provided by the embodiments of the present application;
[0044] Figure 4 It is the second of the schematic flowcharts of the adversarial attack defense method provided by the embodiments of the present application;
[0045] Figure 5 It is the schematic structural diagram of the adversarial attack defense device provided by the embodiments of the present application;
[0046] Figure 6 It is the schematic structural diagram of the electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] To make the objectives, technical solutions, and advantages of this application clearer, the following will clearly and completely describe the technical solutions in this application with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.
[0048] It should be noted that the terms "first", "second", etc. in this application are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or modules does not necessarily have to be limited to those steps or modules clearly listed, but may include other steps or modules not clearly listed or inherent to these processes, methods, products, or devices.
[0049] The counterattack defense method provided in the embodiments of this application is applicable to a terminal, which can be various electronic devices with a display screen and supporting web browsing, including but not limited to servers, smart phones, tablet computers, laptop computers, and desktop computers, etc.
[0050] Figure 1 One of the flow diagrams of the counterattack defense method provided in the embodiments of this application is as Figure 1 shown, and this method includes step 110, step 120, and step 130. The flow steps of this method are only one possible implementation manner of this application.
[0051] Step 110: Modify the packet characteristics of the traffic sample to obtain a first countermeasure sample.
[0052] Specifically, the execution entity of the counterattack defense method provided in the embodiments of this application is a counterattack defense device, which can be an independent hardware device set in the terminal or a software program running in the terminal. For example, when the terminal is a mobile phone, the counterattack defense device can be embodied as an application program such as a defense software in the mobile phone.
[0053] Adversarial sample technology is a way to affect the judgment results of deep learning models by slightly changing image information. General traffic data can be understood as one-dimensional data. Usually, the traffic data used in experiments is collected through Wireshark or Tshark. If adversarial samples are to be generated from traffic data, the one-dimensional data can be mapped into a two-dimensional image, and the traffic data can be preprocessed into a model training set for the convenience of model training. Both Wireshark and Tshark are network packet analysis tools
[0054] Compared with generating adversarial samples of images, there are three difficulties in generating adversarial samples of traffic: (1) Constrained by network protocol specifications, that is, in order to ensure that the perturbed network traffic can still be transmitted in the live network, it is necessary to ensure that it still complies with network protocol specifications after adding perturbations. (2) Constrained by maintaining malicious functions, that is, the processed traffic should ensure that the original malicious attack purpose still exists after adding perturbations. (3) Constrained by ensuring consistency, that is, if the perturbation object is the feature vector of malicious traffic, the relative relationship between each feature also needs to be considered when applying perturbations. Malicious traffic can also be called attack traffic. Attack traffic refers to the data traffic with malicious intentions transmitted in the network
[0055] A traffic sample refers to a set of data in network packets or traffic. Traffic samples can be normal network communication packets or malicious traffic packets containing malicious behaviors or attack payloads
[0056] An adversarial sample refers to a sample with interference information added to a traffic sample
[0057] The adversarial sample generation method used in the embodiments of this application includes feature space attack. The feature space attack mode mainly focuses on feature operations at the packet level, including features such as the total number of packets in a session, the total number of bytes, and the duration of continuous connection. By changing the packet features of the traffic sample, a first adversarial sample can be obtained
[0058] Step 120: Convert the data format of the traffic sample into an image format, and add the image features of the attack traffic to the corresponding image of the traffic sample to obtain a second adversarial sample
[0059] Specifically, the adversarial sample generation method used in the embodiments of this application also includes traffic space attack. Traffic space attack means that on the basis of the binary data of the traffic sample, it is converted into an image, and the image features of the attack traffic are superimposed on the corresponding image of the traffic sample, and then deceptive traffic is generated to obtain a second adversarial sample. Among them, the image can be two-dimensional
[0060] By combining feature space attacks and traffic space attacks, adversarial samples are generated simultaneously at the traffic packet level and the binary data level, avoiding three major implementation difficulties that are prone to occur during the process of generating adversarial samples for traffic, including protocol constraints, maintaining functionality, and relevant feature consistency.
[0061] Step 130: Train an initial detection model based on traffic samples, first adversarial samples, and second adversarial samples to obtain a detection model; the detection model is used to detect whether the traffic to be tested is attack traffic for defending against attack traffic.
[0062] Specifically, by processing traffic samples from two aspects of feature space attacks and traffic space attacks, a large number of first adversarial samples and a large number of second adversarial samples can be generated. Using the traffic samples, first adversarial samples, and second adversarial samples as the training samples of the initial detection model to train the initial detection model, a detection model is obtained.
[0063] The detection model is a neural network model used to detect whether the traffic to be tested is attack traffic, such as the ensemble learning model LightGBM. LightGBM is a machine learning algorithm based on the gradient boosting framework.
[0064] Input the traffic to be tested into the detection model, and the detection result output by the detection model can be obtained. By analyzing the detection result, it can be determined whether the traffic to be tested is attack traffic, so as to defend against it.
[0065] The adversarial attack defense method provided by the embodiments of the present application can obtain a large number of adversarial samples by changing the packet features of traffic samples at the data packet level, converting the data format of traffic samples into an image format, and adding image features of attack traffic to the image; by using the adversarial samples and traffic samples as training samples to train the initial detection model, the training data set of the detection model is fully expanded, the robustness of the detection model is improved, and thus the defense accuracy and efficiency of adversarial attacks are improved.
[0066] It should be noted that each embodiment of the present application can be freely combined, the order can be swapped, or each can be executed alone, and does not need to rely on or depend on a fixed execution order.
[0067] In some embodiments, step 110 includes:
[0068] Perform data cleaning on the data packets of traffic samples;
[0069] Obtain the packet features of the cleaned data packets;
[0070] Add interference factors during the process of processing the packet features to obtain the first adversarial samples.
[0071] Specifically, Figure 2 it is a schematic flowchart of active defense provided by an embodiment of the present application; as Figure 2 shown, feature extraction is performed on traffic samples from the feature space level. At the same time, the traffic samples are binary-converted and image-processed, and binary data features of attack traffic samples are extracted based on the morphology of attack traffic data samples, and binary noise data is superimposed on the second adversarial sample image to achieve active defense.
[0072] A large number of captured packet capture (pcap) traffic packets can be data-cleaned, that is, the data packets of the traffic samples are data-cleaned.
[0073] Data cleaning includes deleting duplicate or damaged traffic packet files and cleaning interference data. In the process of collecting data packets of traffic samples, there will be, for example, Transmission Control Protocol (TCP) handshake packets and some related interference data at the data link layer. Cleaning these data can reduce its interference with model training.
[0074] Packet feature extraction is performed on the cleaned traffic data. For example, the original traffic data of the traffic samples can be converted into a traffic set according to the source Internet Protocol (IP), destination IP, source port, destination port, and transmission protocol quintuple. In addition, each encrypted traffic data is spliced based on the TCP handshake timestamp to form a time series feature, and at the same time, protocol features, certificate features, time series features, and the size of the data packet bytes of the traffic data are extracted.
[0075] After feature extraction, the feature format is standardized, and interference factors are added during the processing to obtain a first adversarial sample, that is, noise data is obtained through incremental processing.
[0076] The adversarial attack defense method provided by the embodiment of the present application can generate a large number of first adversarial samples through feature space attacks, and can effectively expand the number of adversarial samples.
[0077] In some embodiments, step 120 includes:
[0078] Determine the session range of each data packet based on the session duration and session interval of each data packet of each traffic sample;
[0079] Remove a preset number of data packets within the session range based on the size of the bytes of each data packet;
[0080] Locate multiple clusters in the unremoved data packets based on the breadth - first algorithm; any cluster includes a group of data packets with similar packet lengths.
[0081] Determine the reference packet length based on the average packet lengths of the data packets in each cluster.
[0082] Correct the packet lengths of each unremoved data packet based on the reference packet length, and perform data format conversion on the corrected data packets.
[0083] Specifically, the embodiment of the present application proposes a method for automatically and dynamically selecting the reference packet length according to the session byte number characteristics, and the detailed content is as follows:
[0084] According to the session duration of each data packet in each traffic sample and the session interval between sessions, judge the session duration range L; then remove a preset number of data packets within this range. For example, remove the two data packets with the least number of bytes within the range L; use the breadth - first algorithm to quickly locate n clusters in the remaining data packets. Any cluster includes a group of data packets with similar packet lengths. For example, the absolute value of the difference between the byte numbers of any two data packets within these n clusters is less than 1 / 2 of the difference between the median packet lengths of the two clusters.
[0085] Calculate the average value A of the m packet lengths within each cluster, and compare the average value A with 2 a , and select a value M that satisfies 2 a < M < 2 a+2 as the reference packet length. Fix the traffic packet length uniformly at M bytes. For example, supplement 0x00 at the end of the traffic packet if it does not meet M, and trim the traffic packet if it is greater than M bytes; finally, convert the traffic packet of M bytes into a TFrecord file and store it for model training. The TFrecord file is a binary data format used to efficiently store and read data.
[0086] Figure 2 On the right in Figure 2 is the adversarial sample generator part. Here, the adversarial samples can, according to system requirements, collect the required attack traffic pcap data packets, then perform image processing on the attack traffic samples, that is, process the malicious traffic data, and input the processing result into the noise generator to obtain traffic noise. Then superimpose the noise on the image of the traffic sample to generate the second adversarial sample of the traffic.
[0087] The adversarial attack defense method provided by the embodiment of the present application can generate a large number of second adversarial samples through the traffic space attack method, and can effectively expand the number of adversarial samples.
[0088] In some embodiments, the noise-resistant encoding and decoding filter is constructed based on the following steps:
[0089] Input the sample image into the noise-resistant encoder to obtain the low-dimensional features corresponding to the sample image output by the noise-resistant encoder; the sample image includes a traffic sample image and an adversarial sample image; the adversarial sample image includes a first adversarial sample image and a second adversarial sample image;
[0090] Input the low-dimensional features into the noise-resistant decoder to obtain the reconstructed image output by the noise-resistant decoder; the reconstructed image includes a first reconstructed image of the traffic sample image and a second reconstructed image of the adversarial sample;
[0091] Compare the first reconstructed image with the second reconstructed image based on the root mean square error function, and optimize the parameters of the initial noise-resistant encoding and decoding filter based on the comparison result to obtain the noise-resistant encoding and decoding filter.
[0092] Specifically, the noise-resistant encoding and decoding filter can denoise the adversarial sample. The feedforward verification part of the noise-resistant encoding and decoding filter performs feature comparison based on the feature space of the traffic, which can effectively solve the problem of difficult identification of adversarial attacks caused by the mapping problem from traffic features to traffic samples. The passive defense process of this application is to use the noise-resistant encoding filter to reconstruct the feature space of the traffic to be measured and compare it with the normal traffic to judge, so as to realize the passive defense against adversarial attacks.
[0093] The noise-resistant encoding and decoding filter can compress the high-dimensional features of the image into low dimensions, discard the noise part, retain the information consistent with the original traffic sampling, and then restore and reconstruct the sampling information into the original traffic data.
[0094] Figure 3 It is a schematic flow chart of training the noise-resistant encoding and decoding filter provided by the embodiments of this application; as Figure 3 shown, the noise-resistant encoding and decoding filter includes a noise-resistant encoder, a noise-resistant decoder, and a comparator.
[0095] The noise-resistant decoder receives the original image (i.e., the traffic sample image) and the adversarial sample (i.e., the adversarial sample image), inputs the two types of data into the noise-resistant encoder respectively to obtain their respective low-dimensional features. At this time, it is a denoising process for the noise-resistant traffic; then, the noise-resistant decoder restores the low-dimensional feature data respectively to obtain a first reconstructed image of the traffic sample image and a second reconstructed image of the adversarial sample; input the two image data into the comparator for comparison.
[0096] The comparator uses the root mean square error to determine the difference between the two, and simultaneously sets the threshold of the difference between the two and the sampling compliance times of the comparator. If the threshold is exceeded, the information is fed back to the anti-noise encoding and decoding filter to optimize the parameters of the filter. When the comparator result does not exceed the threshold within the preset sampling compliance times, an instruction to terminate the encoding and decoding filter optimization is output, and finally the anti-noise encoding and decoding filter model is recorded and applied to the encrypted malicious traffic identification system against adversarial attacks.
[0097] The noise encoding and decoding filter of this application removes the low-order information of the traffic to be measured by compressing and downsampling the input normal and malicious images through an anti-noise encoder, and restores all the information of the image through an anti-noise decoder. Then, the root mean square error function is used to judge the two types of results and continuously optimize the parameters of the anti-noise encoding and decoding filter. Finally, an anti-noise encoding and decoding filter that can filter adversarial samples is obtained. This filter first filters the input encrypted traffic data, filters out the malicious information with hidden attack behaviors in the traffic, and can ensure that the traffic data sent to the detection model is real data rather than adversarial samples.
[0098] The adversarial attack defense method provided by the embodiments of this application denoises the traffic to be measured introduced into the model by using the passive defense method of the anti-noise encoding and decoding filter, realizes the non-aggression of the traffic input to the detection model, and ensures the effective defense against the adversarial attacks of the attacker on the encrypted malicious traffic.
[0099] In some embodiments, after step 130, it further includes:
[0100] Input the traffic to be measured into the detection model to obtain the first detection result output by the detection model;
[0101] Input the traffic to be measured into the constructed anti-noise encoding and decoding filter to obtain the processed traffic to be measured output by the anti-noise encoding and decoding filter; the anti-noise encoding and decoding filter is used to compress the high-dimensional features of the traffic to be measured into low dimensions and remove the noise part of the traffic to be measured;
[0102] Input the processed traffic to be measured into the detection model to obtain the second detection result output by the detection model;
[0103] Determine whether the traffic to be measured is attack traffic based on the first detection result and the second detection result.
[0104] Determining whether the traffic to be measured is attack traffic based on the first detection result and the second detection result includes:
[0105] In the case where the first detection result and the second detection result are the same and the detection result is attack traffic, put the traffic to be measured into the traffic sample library and issue an alarm;
[0106] When the first detection result is the same as the second detection result and the detection result is non - attack traffic, the traffic to be tested is allowed to pass;
[0107] When the first detection result is different from the second detection result, the traffic to be tested is put into the traffic sample library and an alarm is issued.
[0108] Specifically, Figure 4 This is the second flowchart of the anti - attack defense method provided by the embodiments of the present application. As Figure 4 shown, the method includes:
[0109] Step 1: Obtain traffic samples.
[0110] Collect traffic data of relevant non - attack traffic and attack traffic according to the type of business system deployed.
[0111] For example, collect botnet and DDoS - like malicious traffic for low - interaction business systems; collect Webshell, Godzilla, and injection - like malicious traffic for high - interaction business systems. Or select open - source data sets such as NFD - 2019 and CUT - 13 from Stratosphere Lab, etc.
[0112] Step 2: Traffic cleaning.
[0113] Clean the traffic data of the collected traffic samples. First, delete duplicate or damaged traffic packet files. Since there will be, for example, TCP handshake packets and some related interference data at the data link layer during the collection process in the real environment, cleaning these data can reduce their interference with model training.
[0114] Step 3: Obtain the first adversarial sample.
[0115] Extract features and purify samples from the traffic data. Actively add noise to the statistical features of the traffic in the feature space to obtain adversarial sample data in the feature space, that is, obtain the first adversarial sample.
[0116] Step 4: Conversion of traffic data to binary data.
[0117] Standardize the data format of the traffic samples. According to the packet features of the encrypted traffic session, fix the traffic packet length uniformly at the reference packet length.
[0118] Step 5: Generate two - dimensional image data.
[0119] Convert the one - dimensional traffic data into two - dimensional image data. First, use Numpy to convert the above - mentioned traffic packets of M bytes into a one - dimensional array, and then increase the dimension to Two-dimensional array. Numpy (Numerical Python) is an open-source scientific computing library.
[0120] Step 6: Generate two-dimensional image data.
[0121] Use Numpy to Convert the two-dimensional array into image data and store it. Steps 4 to 6 can be called the "flow data dimensionality increase process."
[0122] Step 7: Add noise to the image data.
[0123] Back up the image data generated in Step 6 to the adversarial sample generation system. This system generates perturbations based on the two-dimensional image information of the collected attack traffic data, that is, generates noise data; then randomly superimposes the perturbation data on the backup data of the image data generated in Step 6 and stores it.
[0124] Step 8: Generate TF_record files.
[0125] Generate TF_record files of TensorFlow for the image data in Step 6 and Step 7 respectively, and store them for model training.
[0126] TensorFlow is an open-source machine learning framework used to build and train various machine learning models. TF_record is a binary file format in TensorFlow for storing data.
[0127] Step 9: Extract features.
[0128] Use EfficientNet-L2 to perform high-level feature extraction on the above image data, and merge the extracted feature content with various statistical features in Step 3 into the original traffic feature set. EfficientNet is an efficient convolutional neural network architecture.
[0129] Step 10: Model training.
[0130] Input the above feature set into LightGBM for model training. After tuning, put the model online and apply it to the business system, waiting for the real traffic input of the business system.
[0131] Step 11: Input the traffic to be tested.
[0132] When the real business system generates access request traffic (this traffic is the traffic to be tested, called the sample to be tested in Figure 4 ), for the traffic to be tested, a part of it directly inputs the original traffic to be tested into the tuned and online detection model, and the other part of the mirrored traffic is input into the detection model after passing through the anti-noise encoding and decoding filter.
[0133] Step 12: Detect the traffic to be measured.
[0134] After passing through the model, the two types of traffic to be measured are compared based on the model judgment results. If the comparison results are inconsistent, the traffic to be measured is retained and input into the adversarial sample generation system to generate an alarm. If the comparison results are consistent, it is determined whether it is attack traffic. If it is attack traffic, the traffic to be measured is also retained and input into the adversarial sample generation system to generate an alarm. If it is not attack traffic, the traffic to be measured is released to the business system.
[0135] The adversarial attack defense method provided by the embodiments of the present application organically combines active defense technology and passive defense technology. On the one hand, the prior knowledge of active defense technology is used to improve the robustness of the model. On the other hand, the input traffic information obtained by passive defense is collected and supplemented, which can optimize the active defense strategy, so that the system has stronger adaptability. It can collect traffic data information in real time using the attack traffic generated by real business and generate adversarial samples, and strengthen the detection model.
[0136] Next, the adversarial attack defense device provided by the embodiments of the present application will be described. The adversarial attack defense device described below can be correspondingly referred to the adversarial attack defense method described above.
[0137] Figure 5 It is a schematic structural diagram of the adversarial attack defense device provided by the embodiments of the present application. As Figure 5 shown, the device includes a modification module 510, a conversion module 520, and a training module 530.
[0138] The modification module is used to modify the data packet features of the traffic sample to obtain the first adversarial sample;
[0139] The conversion module is used to convert the data format of the traffic sample into an image format, and add the image features of the attack traffic to the image corresponding to the traffic sample to obtain the second adversarial sample;
[0140] The training module is used to train the initial detection model based on the traffic sample, the first adversarial sample, and the second adversarial sample to obtain a detection model; the detection model is used to detect whether the traffic to be measured is attack traffic to defend against attack traffic.
[0141] Specifically, according to the embodiments of the present application, any multiple of the modification module, the conversion module, and the training module can be combined and implemented in one module, or any one of them can be split into multiple modules.
[0142] Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module.
[0143] According to an embodiment of the present application, at least one of the modification module, the conversion module, and the training module can be at least partially implemented as a hardware circuit, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-chip, a system-on-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable way of integrating or packaging circuits, etc., implemented by hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in an appropriate combination of any several of them.
[0144] Alternatively, at least one of the modification module, the conversion module, and the training module can be at least partially implemented as a computer program module, which can execute corresponding functions when the computer program module is run.
[0145] The anti-adversarial attack defense device provided by the embodiments of the present application can obtain a large number of adversarial samples by changing the packet features of traffic samples at the packet level, converting the data format of traffic samples into an image format, and adding the image features of attack traffic to the image; by using the adversarial samples and traffic samples as training samples to train the initial detection model, the training data set of the detection model is fully expanded, the robustness of the detection model is improved, and thus the defense accuracy and efficiency against adversarial attacks are improved.
[0146] In some embodiments, the conversion module is specifically configured to:
[0147] Determine the session range of each packet based on the session duration and session interval of each packet of each traffic sample;
[0148] Remove a preset number of packets within the session range based on the byte size of each packet;
[0149] Locate multiple clusters in the unremoved packets based on the breadth-first algorithm; each cluster includes a group of packets with similar packet lengths;
[0150] Determine the reference packet length based on the average packet length of the packets in each cluster;
[0151] Correct the packet lengths of each unremoved packet based on the reference packet length, and perform data format conversion on the corrected packets.
[0152] In some embodiments, the anti-adversarial attack defense device further includes a detection module, and the detection module is specifically configured to:
[0153] Input the traffic to be measured into the detection model to obtain a first detection result output by the detection model;
[0154] Input the traffic to be measured into the constructed anti-noise encoding and decoding filter to obtain the processed traffic to be measured output by the anti-noise encoding and decoding filter; the anti-noise encoding and decoding filter is used to perform low-dimensional compression on the high-dimensional features of the traffic to be measured and remove the noise part of the traffic to be measured;
[0155] Input the processed traffic to be measured into the detection model to obtain the second detection result output by the detection model;
[0156] Determine whether the traffic to be measured is attack traffic based on the first detection result and the second detection result.
[0157] In some embodiments, the anti-noise encoding and decoding filter is constructed based on the following steps:
[0158] Input the sample image into the anti-noise encoder to obtain the low-dimensional features corresponding to the sample image output by the anti-noise encoder; the sample image includes a traffic sample image and an adversarial sample image; the adversarial sample image includes a first adversarial sample image and a second adversarial sample image;
[0159] Input the low-dimensional features into the anti-noise decoder to obtain the reconstructed image output by the anti-noise decoder; the reconstructed image includes a first reconstructed image of the traffic sample image and a second reconstructed image of the adversarial sample;
[0160] Compare the first reconstructed image with the second reconstructed image based on the root mean square error function, and optimize the parameters of the initial anti-noise encoding and decoding filter based on the comparison result to obtain the anti-noise encoding and decoding filter.
[0161] In some embodiments, the detection module further includes an alarm sub-module, and the alarm sub-module is specifically used for:
[0162] In the case where the first detection result and the second detection result are the same and the detection result is attack traffic, put the traffic to be measured into the traffic sample library and issue an alarm;
[0163] In the case where the first detection result and the second detection result are the same and the detection result is non-attack traffic, release the traffic to be measured;
[0164] In the case where the first detection result and the second detection result are different, put the traffic to be measured into the traffic sample library and issue an alarm.
[0165] In some embodiments, the modification module is specifically used for:
[0166] Perform data cleaning on the data packets of the traffic sample;
[0167] Obtain the packet features of the cleaned data packets;
[0168] Add interference factors during the process of processing the packet features to obtain the first adversarial sample.
[0169] It should be noted here that the adversarial attack defense device provided in the embodiments of the present application can implement all the method steps implemented in the above-mentioned embodiments of the adversarial attack defense method, and can achieve the same technical effects. Therefore, the same parts and beneficial effects as those in the method embodiments will not be specifically described in this embodiment.
[0170] Figure 6 The following is a schematic structural diagram of the electronic device provided in the embodiments of the present application. As Figure 6 shown, the electronic device may include: a processor 610, a communication interface 620, a memory 630, and a communication bus 640. Among them, the processor 610, the communication interface 620, and the memory 630 communicate with each other through the communication bus 640. The processor 610 can call the computer program in the memory 630 to execute the above method, for example, including:
[0171] Changing the packet characteristics of the traffic sample to obtain a first adversarial sample;
[0172] Converting the data format of the traffic sample into an image format, and adding the image characteristics of the attack traffic to the image corresponding to the traffic sample to obtain a second adversarial sample;
[0173] Training an initial detection model based on the traffic sample, the first adversarial sample, and the second adversarial sample to obtain a detection model; the detection model is used to detect whether the traffic to be tested is attack traffic to defend against attack traffic.
[0174] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software function modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.
[0175] On the other hand, an embodiment of the present application also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the methods provided in the above various embodiments.
[0176] On the other hand, an embodiment of the present application also provides a processor-readable storage medium, which stores a computer program for causing the processor to execute the methods provided in the above various embodiments.
[0177] The processor-readable storage medium may be any available medium or data storage device accessible by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid state drives (SSD)).
[0178] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0179] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disks, optical disks, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0180] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.
Claims
1. A method for defending against an attack, characterized in that: include: Modify the data packet characteristics of the traffic sample to obtain the first adversarial sample; Converting the data format of the traffic sample into an image format, and adding the image features of the attack traffic to the image corresponding to the traffic sample to obtain a second adversarial sample; Training an initial detection model based on the traffic sample, the first adversarial sample, and the second adversarial sample to obtain a detection model; Based on the detection model and the anti-noise codec filter, determining whether the traffic to be tested is attack traffic to defend against the attack traffic; The noise-resistant codec filter is constructed based on the following steps: Input a sample image into an anti-noise encoder to obtain a low-dimensional feature corresponding to the sample image output by the anti-noise encoder; the sample image includes a flow sample image and an adversarial sample image; the adversarial sample image includes a first adversarial sample image and a second adversarial sample image; Inputting the low-dimensional features into an anti-noise decoder to obtain a reconstructed image output by the anti-noise decoder; the reconstructed image includes a first reconstructed image of the traffic sample image and a second reconstructed image of the adversarial sample; The first reconstructed image is compared with the second reconstructed image based on a root mean square error function, and parameters of an initial anti-noise codec filter are optimized based on the comparison result to obtain the anti-noise codec filter.
2. The anti-attack defense method according to claim 1, characterized in that: The converting the data format of the traffic sample into an image format comprises: Determine the session scope of each data packet based on the session duration and session interval of each data packet of each traffic sample; Removing a preset number of data packets within the session range based on the byte size of each data packet; Locating multiple clusters in the unremoved data packets based on a breadth-first algorithm; any cluster includes a group of data packets with similar data packet lengths; Determine a benchmark data packet length based on the average data packet length of the data packets in each cluster; The data packet length of each data packet that has not been removed is corrected based on the reference data packet length, and the corrected data packet is converted into a data format.
3. The anti-attack defense method according to claim 1, characterized in that: After obtaining the detection model, the method further includes: Inputting the flow to be measured into the detection model to obtain a first detection result output by the detection model; The measured flow is input into the constructed anti-noise codec filter to obtain the processed measured flow output by the anti-noise codec filter; the anti-noise codec filter is used to perform low-dimensional compression on the high-dimensional features of the measured flow and remove the noise part of the measured flow; Inputting the processed flow to be measured into the detection model to obtain a second detection result output by the detection model; Determine whether the traffic to be tested is attack traffic based on the first detection result and the second detection result.
4. The method for countering attack according to claim 3, characterized in that: The determining whether the flow to be tested is attack flow based on the first detection result and the second detection result includes: When the first detection result is the same as the second detection result and the detection result is attack traffic, the traffic to be tested is placed in a traffic sample library and an alarm is issued; When the first detection result and the second detection result are the same and the detection result is non-attack traffic, releasing the traffic to be tested; When the first detection result is different from the second detection result, the flow to be tested is put into a flow sample library and an alarm is issued.
5. The anti-attack defense method according to claim 1, characterized in that: The step of changing the data packet feature of the traffic sample to obtain a first adversarial sample includes: Performing data cleaning on the data packets of the traffic sample; Obtaining data packet characteristics of the cleaned data packet; In the process of processing the data packet feature, interference factors are added to obtain the first adversarial sample.
6. A device for defending against attacks, characterized in that: include: A modification module, used for modifying the data packet characteristics of the traffic sample to obtain a first adversarial sample; A conversion module, used to convert the data format of the traffic sample into an image format, and add the image features of the attack traffic to the image corresponding to the traffic sample to obtain a second adversarial sample; A training module, used for training an initial detection model based on the traffic sample, the first adversarial sample and the second adversarial sample to obtain a detection model; Based on the detection model and the anti-noise codec filter, determining whether the traffic to be tested is attack traffic to defend against the attack traffic; The noise-resistant codec filter is constructed based on the following steps: Input a sample image into an anti-noise encoder to obtain a low-dimensional feature corresponding to the sample image output by the anti-noise encoder; the sample image includes a flow sample image and an adversarial sample image; the adversarial sample image includes a first adversarial sample image and a second adversarial sample image; Inputting the low-dimensional features into an anti-noise decoder to obtain a reconstructed image output by the anti-noise decoder; the reconstructed image includes a first reconstructed image of the traffic sample image and a second reconstructed image of the adversarial sample; The first reconstructed image is compared with the second reconstructed image based on a root mean square error function, and parameters of an initial anti-noise codec filter are optimized based on the comparison result to obtain the anti-noise codec filter.
7. An electronic device comprising a memory and a processor, characterized in that: The memory stores a computer program, and the processor is configured to execute the anti-attack defense method according to any one of claims 1 to 5 through the computer program.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the anti-attack defense method according to any one of claims 1 to 5 is implemented.
9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the anti-attack defense method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Detection and defense method based on FGSM anti-attack algorithm
CN111600835A
Preprocessing defense method aiming at target detection confrontation attack
CN114723663A