A Plaintext Detection and Alarm System Based on Multidimensional Feature Fusion and Fourier Transform
By combining multi-dimensional feature fusion and Fourier transform technology in the field of network security, and using machine learning algorithms to train classification judgment models, the problem of difficulty in accurately detecting plaintext data transmission in the existing technology is solved, achieving higher detection accuracy and reduction of plaintext transmission.
Patent Information
- Application Number
- CN202410993991.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-24
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-07-24
AI Technical Summary
The prior art is difficult to effectively and accurately detect and alarm the transmission of plain text data, and the plain text transmission phenomenon in the internal network cannot be accurately avoided.
A plaintext detection alarm system based on multi-dimensional feature fusion and Fourier transform is used to train a classification judgment model through the combination of acquisition unit, processing unit, calculation unit, judgment unit and inspection unit, and a machine learning algorithm is used to train a classification judgment model to judge that the data packet is plaintext or ciphertext.
It improves the accuracy of detection of plaintext data during data packet transmission and reduces the phenomenon of plaintext transmission in the internal network.
Smart Images

Figure CN118900196B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a plaintext detection and alarm system based on multi-dimensional feature fusion and Fourier transform. Background Art
[0002] In the current network security environment, enterprises and organizations have higher and higher requirements for data security. However, due to software implementation problems or improper configurations, there is a phenomenon of plaintext data transmission in the internal network, which provides an opportunity for malicious attackers to steal data using sniffer tools. There are a large number of security threats and attacks in the field of network security. In order to protect against and prevent network security threats, it is necessary to introduce multi-dimensional feature fusion and Fourier transform technologies for analysis and detection, so as to identify and respond in a timely manner.
[0003] The multi-dimensional feature fusion technology can fuse a variety of different feature information together to form a comprehensive feature vector for data analysis and classification. The Fourier transform technology can transform a signal (such as network traffic) into the frequency domain. By analyzing and extracting the frequency, some useful information in the signal can be found. These two technologies are widely used in the field of network security and can identify attack traffic, abnormal traffic, etc.
[0004] Patent No. CN2019108454664 discloses a voice tampering detection method based on multi-feature fusion, which detects whether a voice file is spliced, and includes the following steps: Step S1, frame the voice data to be detected and divide it into multiple groups of voice data frames; Step S2, extract multi-dimensional features from each group of voice data frames; Step S3, construct a model based on Attention-RNN as a classifier; Step S4, input the multi-dimensional features extracted in Step S2 into the trained classifier to determine whether the current frame of voice is tampered. The method of the above invention can effectively mine the differences between the front and back features in the voice signal by extracting frame-level features, combine multiple features, and make the voice feature mining more abundant. By using the attention mechanism to assign different importance to the local parts of the same sample, the features of the time-series signal are automatically learned.
[0005] Patent No. CN2017107739554 discloses a harmonic detection method based on discrete Fourier transform, which includes a harmonic detection method based on discrete Fourier transform, characterized by collecting three-phase currents on the grid side within a set period and performing discrete processing on the collected three-phase currents; constructing a calculation model for the fundamental active current amplitude and fundamental reactive current amplitude of the three-phase currents; performing a forward discrete Fourier transform on the three-phase currents collected on the grid side through a sliding window iteration method to obtain the fundamental active current amplitude and fundamental reactive current amplitude of the three-phase currents respectively; calculating the positive sequence component of the fundamental active current of the three-phase currents by coordinate transformation; and calculating the detected three-phase harmonic currents according to the collected three-phase currents and the positive sequence component of the fundamental active current.
[0006] Although the above patents all use multi-dimensional feature fusion or Fourier transform to detect information data, a single processing method cannot effectively and accurately detect and alarm the transmission of plaintext data, and the phenomenon of plaintext transmission in the internal network cannot be accurately avoided. Summary of the Invention
[0007] The purpose of the present invention is to provide a plaintext detection and alarm system based on multi-dimensional feature fusion and Fourier transform, which can fuse multi-dimensional feature fusion and Fourier transform, and use machine learning algorithms to train a classification and judgment model to judge whether a data packet is plaintext or ciphertext; to improve the detection accuracy of plaintext data during the data packet transmission process; and to reduce the phenomenon of plaintext transmission in the internal network.
[0008] The present invention uses the following technical solutions:
[0009] A plaintext detection and alarm system based on multi-dimensional feature fusion and Fourier transform includes a collection unit, a processing unit, a measurement unit, a judgment unit, and an inspection unit; wherein,
[0010] The collection unit is used to collect data packets during the data transmission process;
[0011] The processing unit is used to preprocess the collected data packets to obtain multi-dimensional features of the ordinary data payload after removing the special fields of the data payload;
[0012] The measurement unit is used to perform multi-dimensional feature fusion and Fourier transform on the preprocessed data packets to obtain a comprehensive feature vector;
[0013] The judgment unit is used to classify and judge the comprehensive feature vector using a preset classification and judgment model, and optimize the data packet using a miscellaneous information database;
[0014] The inspection unit is used to re-verify the data packets that have completed the classification and judgment.
[0015] Preferably, the acquisition unit continuously samples the packet set during data transmission; the data transmission process includes but is not limited to gateways and / or routers; the packet set includes a number of packets, and each packet contains a data payload and a protocol header.
[0016] Preferably, the process of the processing unit preprocessing the packets is as follows:
[0017] S1: Extract the data payload and protocol header of each packet;
[0018] P i = D i ⊙ H i (1)
[0019] Among them, i represents the packet number, P i represents the i-th packet, D i represents the data payload of the i-th packet, ⊙ represents the Hadamard outer product, and H i represents the protocol header of the i-th packet;
[0020] S2: Identify and remove the special fields of the data payload using the protocol type to obtain the ordinary data payload;
[0021]
[0022] Among them, D i ′ represents the ordinary data payload of the i-th packet, special_fields() represents the special field removal function, T i represents the protocol type of the i-th packet, represents the Hadamard inner product;
[0023] S3: Calculate and obtain the multi-dimensional features of the ordinary data payload; the multi-dimensional features include but are not limited to the entropy value H(D i ′ ), the byte frequency distribution F(D i ′ ), the data length L(D i ′ ), and the temporal feature T(D i ′ ).
[0024] Preferably, the process of the measurement unit calculating the preprocessed packets is as follows:
[0025] First, perform a fast Fourier transform on the ordinary data payload to obtain the frequency domain features of the ordinary data payload;
[0026] F f (D i ′) = FFT(D i ′ ) (3)
[0027] Among them, F f (D′ i ) represents the frequency-domain feature of the ordinary data payload, and FFT() represents the fast Fourier function;
[0028] Then, the multi-dimensional feature and the frequency-domain feature are fused into the comprehensive feature vector V i ;
[0029] V i = [H(D′ i ), F(D′ i ), L(D′ i ), T(D′ i ), F f (D′ i )] (4).
[0030] Preferably, the process of the judgment unit classifying and judging the comprehensive feature vector is as follows:
[0031] A: Use the data set constructed by the historical comprehensive feature vectors and the machine learning algorithm to iteratively train the classification judgment model;
[0032] M = TrainModel(V1, V2,..., V n ) (5)
[0033] Among them, M represents the classification judgment model, TrainModel() represents the machine learning algorithm, and V n represents the nth historical comprehensive feature vector;
[0034] B: Input the comprehensive feature vectors of each data packet into the classification judgment model and compare them with the entropy threshold H t to obtain the classification judgment result; the classification judgment result is plaintext or ciphertext;
[0035] Result(P() = M(Vi) (6)
[0036] Among them, ResuIt() represents the classification judgment result;
[0037] C: Use the clutter information database to optimize the data payload of the data packet to reduce the false alarm situation of the classification judgment result; the clutter information database includes the protocol header and special fields;
[0038]
[0039] Among them, D″ iThe optimized data payload is denoted as, and known_fields() represents the cluttered information database.
[0040] Preferably, the classification judgment model includes a feature separation layer, an iterative training layer, and an identification and classification layer; the feature separation layer first performs non-linear processing on the historical comprehensive feature vector to obtain a historical feature matrix;
[0041]
[0042] Among them, MP n represents the historical feature matrix, SBox[] represents the substitution box function, and ABox[] represents the permutation box function. represents the vector sum, and x (k,n) represents the chaotic sequence of the nth item and the kth dimension;
[0043] Then, the historical feature matrix is input into the iterative training layer, and several iterations of training are performed using the multi-scale attention mechanism to obtain a feature weight matrix; the iterative training layer includes 4 3X3 convolutional layers, 2 3X3 max pooling layers, 6 residual blocks with parallel Inception V3 blocks, 3 global pooling layers, 2 dimension expansion layers, 3 Sigmoid activation functions, 3 normalization layers, and 3 5X5 convolutional layers; the 4 3X3 convolutional layers are in parallel with the concatenated 3 5X5 convolutional layers and 3 3X3 max pooling layers, and are concatenated with 2 normalization layers;
[0044] Finally, the identification and classification layer optimizes and updates the feature weight matrix to obtain the classification judgment result; the identification and classification layer includes 4 Inception V1 blocks, 3 Inception V4 blocks, 2 5X5 upsampling layers, 2 3X3 average pooling layers, and 2 MISH activation functions.
[0045] Preferably, the verification unit uses an advanced statistical algorithm to perform secondary verification on the data packet with the classification judgment result of plaintext: if KS_statistic(D i ″ ) ≤ F t , then the data packet is plaintext; if KS_statistic(D i ″ ) > F t , then the data packet is ciphertext; KS_statistic() represents the Kolmogorov-Smirnov test algorithm, and F t represents the feature threshold; the advanced statistical algorithm includes but is not limited to the Kolmogorov-Smirnov test algorithm.
[0046] After fusing multi-dimensional features and Fourier transform, the present invention trains a classification and judgment model using a machine learning algorithm to determine whether a data packet is plaintext or ciphertext; this improves the detection accuracy of plaintext data during data packet transmission; and reduces the phenomenon of plaintext transmission in the internal network. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] To more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.
[0048] Figure 1 It is a schematic diagram of the principle of the plaintext detection and alarm system. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0049] The present invention will be described in detail below with reference to the drawings and embodiments:
[0050] As Figure 1 shown, a plaintext detection and alarm system based on multi-dimensional feature fusion and Fourier transform according to the present invention includes a collection unit, a processing unit, a measurement unit, a judgment unit, and an inspection unit; among them,
[0051] The collection unit is used to collect data packets during data transmission;
[0052] In the present invention, the collection unit continuously samples the data packet set during data transmission; the data transmission process includes but is not limited to gateways and / or routers; the data packet set includes several data packets, and each data packet contains a data payload and a protocol header;
[0053] The processing unit is used to preprocess the collected data packets to obtain multi-dimensional features of the ordinary data payload after removing the special fields of the data payload;
[0054] In the present invention, the process of the processing unit preprocessing the data packets is as follows:
[0055] S1: Extract the data payload and protocol header of each data packet;
[0056] P i = D i ⊙ H i (1)
[0057] Among them, i represents the data packet number, P i represents the i-th data packet, D i represents the data payload of the i-th data packet, ⊙ represents the Hadamard outer product, and H iRepresents the protocol header of the i-th data packet;
[0058] S2: Identify and remove the special fields of the data payload using the protocol type to obtain the ordinary data payload;
[0059]
[0060] where D i v represents the ordinary data payload of the i-th data packet, special_fields() represents the special field removal function, and T i represents the protocol type of the i-th data packet, represents the Hadamard inner product;
[0061] S3: Calculate and obtain the multi-dimensional features of the ordinary data payload; The multi-dimensional features include but are not limited to the entropy value H(D i ′ ), the byte frequency distribution F(D i ′ ), the data length L(D i ′ ), and the temporal feature T(D i ′ ).
[0062] In this embodiment, the entropy value represents a measure of uncertainty or information amount in the system and is often used to evaluate the randomness and complexity of data;
[0063] The frequency distribution is used to describe the frequency or proportion of different values appearing in the data and is often used to analyze the central tendency and dispersion degree of the data;
[0064] The temporal feature is used to describe the pattern and law of data changing over time and is often used in time series analysis and prediction;
[0065] The Hadamard inner product represents a way of matrix operation, and the matrix obtained by multiplying elements one by one is often used in signal processing and data compression;
[0066] The protocol header represents the control information part in the data packet, which is used to identify the protocol type and transmission information of the data packet and helps network devices correctly parse and process the data packet;
[0067] Protocol type identification refers to determining the communication protocol type used by analyzing the protocol header of the data packet and is often used in network traffic analysis and protocol parsing;
[0068] The measurement unit is used to perform multi-dimensional feature fusion and Fourier transform on the preprocessed data packet to obtain a comprehensive feature vector;
[0069] In the present invention, the process of the measurement unit calculating the preprocessed data packet is as follows:
[0070] First, perform a fast Fourier transform on the ordinary data payload to obtain the frequency-domain characteristics of the ordinary data payload;
[0071] F f (D′ i ) = FFT(D′ i ) (3)
[0072] where F f (D′ i ) represents the frequency-domain characteristics of the ordinary data payload, and FFT() represents the fast Fourier function;
[0073] Then, fuse the multi-dimensional characteristics and the frequency-domain characteristics into a comprehensive feature vector V i ;
[0074] V i = [H(D′ i ), F(D′ i ), L(D′ i ), T(D′ i ), F f (D′ i )] (4);
[0075] In this embodiment, the fast Fourier transform represents a mathematical transform that converts a signal from the time domain to the frequency domain, and reveals the periodicity and frequency characteristics of the signal by analyzing the frequency components of the signal;
[0076] A judgment unit, configured to classify and judge the comprehensive feature vector by using a preset classification and judgment model, and optimize the data packet by using a clutter information database;
[0077] In this embodiment, the clutter information database is used to store databases of protocol headers and special fields, and is also used to optimize and reduce false alarms in data classification;
[0078] In the present invention, the process of the judgment unit classifying and judging the comprehensive feature vector is as follows:
[0079] A: Use a data set constructed from historical comprehensive feature vectors and a machine learning algorithm to iteratively train the classification and judgment model;
[0080] M = TrainModel(V1, V2,..., V n ) (5)
[0081] where M represents the classification and judgment model, Train / Model() represents the machine learning algorithm, and V n represents the nth historical comprehensive feature vector; the machine learning algorithm can adopt a neural network;
[0082] B: Input the comprehensive feature vectors of each data packet into the trained classification and judgment model, and compare them with the entropy threshold H t to obtain the classification and judgment result; the classification and judgment result is plaintext or ciphertext;
[0083] Result(P i ) = M(V i ) (6)
[0084] where Result() represents the classification and judgment result;
[0085] In the present invention, the classification and judgment model includes a feature separation layer, an iterative training layer, and an identification and classification layer; the feature separation layer first performs non-linear processing on the historical comprehensive feature vectors to obtain a historical feature matrix;
[0086]
[0087] where, MP n represents the historical feature matrix, SBox[] represents the substitution box function, ABox[] represents the permutation box function, represents the vector AND, x (k,n) represents the chaotic sequence of the nth item and the kth dimension;
[0088] Then input the historical feature matrix into the iterative training layer, and use the multi-scale attention mechanism to perform several iterations of training to obtain a feature weight matrix; the iterative training layer includes 4 3X3 convolutional layers, 2 3X3 max-pooling layers, 6 residual blocks with 6 parallel Inception V3 blocks, 3 global pooling layers, 2 dimension expansion layers, 3 Sigmoid activation functions, 3 normalization layers, and 3 5X5 convolutional layers; the 4 3X3 convolutional layers are in parallel with the cascaded 3 5X5 convolutional layers and 3 3X3 max-pooling layers, and are cascaded with 2 normalization layers;
[0089] Finally, use the identification and classification layer to optimize and update the feature weight matrix to obtain the classification and judgment result; the identification and classification layer includes 4 Inception V1 blocks, 3 Inception V4 blocks, 2 5X5 upsampling layers, 2 3X3 average pooling layers, and 2 MISH activation functions;
[0090] In this embodiment, the feature separation layer represents a part of the machine learning model, and is also used to extract and separate different features of the input data for subsequent feature processing and classification;
[0091] The multi-scale attention mechanism is a technique in machine learning, which improves the feature extraction and classification ability of the model by paying attention to different features of the data at different scales;
[0092] The Inception block is a structure in a convolutional neural network that extracts features through convolutional kernels of different scales, improving the model's feature extraction ability and classification effect.
[0093] The residual block is a structure in deep learning that alleviates the vanishing gradient problem by adding skip connections, improving the training effect of deep networks.
[0094] The Sigmoid activation function is a common activation function that maps the input to values between 0 and 1 and is often used in binary classification problems;
[0095] The ReLU activation function represents a common activation function that maps values less than 0 in the input to 0 and keeps values greater than 0 unchanged, and is often used in deep learning models;
[0096] The MISH activation function is a new type of activation function that maps the input in a smooth manner, improving the classification accuracy and convergence speed of the model;
[0097] The dimension expansion layer is a layer in a deep learning model that enhances the model's expressive ability and classification effect by increasing the dimension of features;
[0098] The working principle of the classification and judgment model is as follows:
[0099] The classification and judgment model can be divided into three parts, namely the feature separation layer, the iterative training layer, and the recognition and classification layer.
[0100] First, the feature separation layer performs non-linear processing on the historical comprehensive feature vector to obtain the historical feature matrix. This process is mainly used for feature preprocessing and extraction to obtain the high-dimensional feature expression of the data. Among them, non-linear processing can be carried out using activation functions, such as common functions like ReLU.
[0101] Then, the historical feature matrix is input into the iterative training layer and undergoes several iterations of training through a multi-scale attention mechanism to obtain the feature weight matrix. The iterative training layer is mainly composed of multiple convolutional layers, pooling layers, residual blocks, global pooling layers, activation functions, normalization layers, and expansion layers, etc. These layers perform multi-layer processing and information extraction on the input data through different parameter adjustments and connection methods to achieve feature optimization and abstraction. The multi-scale attention mechanism of the iterative training layer means that convolutional kernels at different levels can focus on features of different dimensions to achieve a more accurate representation.
[0102] Finally, the feature weight matrix is optimized and updated, and then input into the recognition and classification layer for classification judgment. The recognition and classification layer mainly consists of a convolutional layer, Inception blocks, an upsampling layer, an average pooling layer, and activation functions. Through different layers and modules, the features are abstracted more complexly and comprehensively, and the classification results are finally output. Among them, the Inception block is a special convolutional neural network block with better feature extraction and processing capabilities. In addition, the upsampling layer and the average pooling layer can make the feature resolution higher, which helps to extract detailed information better. The MISH activation function can improve the classification accuracy of the model.
[0103] In summary, the classification judgment model adopts multiple layers and technologies, and combines algorithms such as non-linear processing, attention mechanism, residual, and Inception network, achieving good classification effects and generalization performance.
[0104] C: Optimize the data payload of the data packet using the clutter information database to reduce false alarms in the classification judgment results; the clutter information database includes protocol headers and special fields;
[0105]
[0106] Among them, D i ″ represents the optimized data payload, and known_fields() represents the clutter information database;
[0107] A verification unit is used to verify the data packet that has completed the classification judgment again;
[0108] In the present invention, the verification unit uses an advanced statistical algorithm to perform secondary verification on the data packet whose classification judgment result is plaintext: if KS_statistic(D i ″ ) ≤ F t , then the data packet is plaintext; if KS_statistic(D i " ) > F t , then the data packet is ciphertext; KS_statistic() represents the Kolmogorov-Smirnov test algorithm, and F t represents the feature threshold; the advanced statistical algorithm includes but is not limited to the Kolmogorov-Smirnov test algorithm;
[0109] In this embodiment, the Kolmogorov-Smirnov test is a statistical test method used to compare whether there are significant differences in the distributions of two samples, and is often used in data analysis and verification.
[0110] Example:
[0111] When the plaintext detection and alarm system is used for monitoring and alarming the plaintext data transmission in the internal and external communications of an enterprise: During the data transmission process, first, the acquisition unit continuously samples each packet set passing through the gateway and / or router; the packet set includes several packets, and each packet contains a data payload and a protocol header; the processing unit extracts the data payload and the protocol header of each packet, and then uses the protocol type to identify and remove the special fields of the data payload to obtain the ordinary data payload, and calculates and obtains the multi-dimensional features of the ordinary data payload: entropy value, byte frequency distribution, data length, and timing features;
[0112] Then, the measurement unit performs a fast Fourier transform on the ordinary data payload to obtain the frequency domain features of the ordinary data payload; and fuses the multi-dimensional features and the frequency domain features into a comprehensive feature vector; subsequently, the judgment unit uses the data set constructed by the historical comprehensive feature vectors and the machine learning algorithm to iteratively train the classification judgment model; then, inputs the comprehensive feature vectors of each packet into the classification judgment model, and compares them with the entropy threshold H t to obtain the classification judgment result: plaintext or ciphertext; at the same time, optimizes the data payload of the packet using the clutter information database to reduce the false alarm situation of the classification judgment result; the clutter information database includes the protocol header and the special fields;
[0113] Finally, the verification unit uses the advanced statistical algorithm to perform a secondary verification on the packets whose classification judgment result is plaintext: if KS_statistic(D i " ) ≤ F t , then the packet is plaintext; if KS_statistic(D i ″ ) > F t , then the packet is ciphertext; KS_statistic() represents the Kolmogorov-Smirnov test algorithm, and F t represents the feature threshold.
Claims
1. A plaintext detection alarm system based on multi-dimensional feature fusion and Fourier transform, characterized by: It includes a collection unit, a processing unit, a measurement unit, a judgment unit and a testing unit; wherein, A collection unit, used for collecting data packets during data transmission; A processing unit, used for preprocessing the collected data packets to obtain multi-dimensional features of the common data payload with special fields of the data payload removed; A calculation unit, used for performing multi-dimensional feature fusion and Fourier transformation on the pre-processed data packets to obtain a comprehensive feature vector; A judgment unit, used to classify the comprehensive feature vector using a preset classification judgment model, and optimize the data packet using a messy information database; A verification unit, used to re-verify the data packets that have completed the classification judgment; The process of the calculation unit calculating the pre-processed data packets is as follows: First, a fast Fourier transform is performed on the common data payload to obtain the frequency domain characteristics of the common data payload; F f (D i ′ )=FFT(D i ′ ) (3) Among them, F f (D i ′ ) represents the frequency domain characteristics of normal data load, D i ′ represents the normal data load of the ith data packet, and FFT() represents the fast Fourier function; Then, the multi-dimensional features and frequency domain features are fused into a comprehensive feature vector; V i =[H(D i ′ ),F(D i ′ ),L(D i ′ ),T(D i ′ ),F f (D i ′ )] (4) Among them, V i represents the comprehensive feature vector, H(D i ′ ) represents the entropy value, F(D i ′ ) represents the byte frequency distribution, L(D i ′ ) indicates the data length, T(D i ′ ) represents the time series characteristics; The process of the judgment unit classifying and judging the comprehensive feature vector is as follows: A: Use the data set constructed from historical comprehensive feature vectors and machine learning algorithms to iteratively train the classification judgment model; M=TrainModel(V1,V2,…,V n ) (5) Among them, M represents the classification judgment model, TrainModel() represents the machine learning algorithm, and V n represents the nth historical comprehensive feature vector; B: Input the comprehensive feature vector of each data packet into the classification judgment model and compare it with the entropy threshold H t Compare to obtain the classification result; the classification result is plain text or cipher text; Result(P i )=M(V i ) (6) Among them, Result() represents the classification result, P i represents the i-th data packet; C: Optimize the data load of the data packet using the messy information database to reduce the false positives of the classification judgment results; the messy information database includes the protocol header and special fields; Among them, D i ″ represents the optimized data load, known_fields() represents the messy information database, T i Indicates the protocol type of the ith data packet, H i represents the protocol header of the ith data packet, D i Represents the data payload of the i-th data packet.
2. The plaintext detection alarm system based on multi-dimensional feature fusion and Fourier transform according to claim 1 is characterized in that: The acquisition unit continuously samples the data packet set during the data transmission process; The data transmission process includes a gateway and / or a router; the data packet set includes a plurality of data packets, each of which includes a data payload and a protocol header.
3. The plaintext detection alarm system based on multi-dimensional feature fusion and Fourier transform according to claim 1 is characterized in that: The process of the processing unit preprocessing the data packet is as follows: S1: extract the data payload and protocol header of each data packet; P i =D i ⊙H i (1) Where i represents the packet number, ⊙ represents the Hadamard outer product; S2: Use the protocol type to identify and remove the special fields of the data payload to obtain the normal data payload; Among them, special_fields() represents the special field removal function. represents the Hadamard inner product; S3: Calculate and obtain multi-dimensional features of common data payloads; multi-dimensional features include entropy value, byte frequency distribution, data length, and timing features.
4. The plaintext detection alarm system based on multi-dimensional feature fusion and Fourier transform according to claim 1 is characterized in that: The classification judgment model includes a feature separation layer, an iterative training layer and a recognition classification layer; the feature separation layer first performs nonlinear processing on the historical comprehensive feature vector to obtain a historical feature matrix; Among them, MP n represents the historical feature matrix, SBox[] represents the substitution box function, ABox[] represents the permutation box function, Represents vector and, x (k,n) represents the chaotic sequence of the nth item and the kth dimension; Then the historical feature matrix is input into the iterative training layer, and the multi-scale attention mechanism is used to perform several iterative trainings to obtain the feature weight matrix; the iterative training layer includes 4 3X3 convolutional layers, 2 3X3 maximum pooling layers, 6 residual blocks of Inception V3 blocks in parallel, 3 global pooling layers, 2 dimension expansion layers, 3 Sigmoid activation functions, 3 normalization layers and 3 5X5 convolutional layers; the 4 3X3 convolutional layers are connected in parallel with the 3 5X5 convolutional layers and 3 3X3 maximum pooling layers in series, and are connected in series with 2 normalization layers; Finally, the recognition and classification layer is used to optimize and update the feature weight matrix to obtain the classification judgment result; the recognition and classification layer includes 4 Inception V1 blocks, 3 Inception V4 blocks, 2 5X5 upsampling layers, 2 3X3 average pooling layers and 2 MISH activation functions.
5. The plaintext detection alarm system based on multi-dimensional feature fusion and Fourier transform according to claim 1 is characterized in that: The verification unit uses an advanced statistical algorithm to perform a secondary verification on the data packet whose classification result is plain text: if KS_statistic(D i ″ )≤F t , then the data packet is plain text; if KS_statistic(D i ″ )>F t , then the data packet is ciphertext; KS_statistic() represents the Kolmogorov-Smirnov test algorithm, F t Represents feature threshold; advanced statistical algorithms include Kolmogorov-Smirnov test algorithm.
Citation Information
Patent Citations
Network traffic classification model training method, classification method and training device
CN117076923A
Unsupervised time sequence anomaly detection method based on multi-dimensional feature fusion
CN117556311A