Virus traffic detection method and apparatus based on escape adversarial model
By adopting a virus traffic detection method based on an escape adversarial model, and using preset configuration information and an escape adversarial virus traffic detection model, the problem of abnormal transmission interface data and high false alarm rate in the existing technology is solved, and real-time monitoring and accurate detection are achieved.
Patent Information
- Application Number
- CN202411252637.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-09-09
AI Technical Summary
Existing methods for detecting network virus traffic cannot locate abnormal data on transmission interfaces in a timely and accurate manner, and they have a single detection perspective and a high false alarm rate.
A virus traffic detection method based on an escape adversarial model is adopted. By intercepting network traffic requests, target identification and traffic marking are performed using preset network traffic monitoring configuration information. Combined with the escape adversarial virus traffic detection model, multi-angle detection is performed to achieve real-time monitoring and anomaly detection.
It enables real-time monitoring of the transmission interface, accurately locates data anomalies, reduces false alarm rates, and improves the detection accuracy of virus traffic propagation events.
Smart Images

Figure CN119051960B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this application relate to the field of virus traffic detection, specifically to a virus traffic detection method and device based on an escape adversarial model. Background Technology
[0002] In today's internet environment, various virus propagation events occur every day. These events are often lost in the vast sea of the internet. Extracting and discovering these virus propagation events, and conducting in-depth analysis of their patterns to detect sudden virus outbreaks, is a pressing problem that needs to be solved in the field of cybersecurity technology.
[0003] Existing methods for detecting network virus traffic are typically: threshold-based methods, which issue an alarm immediately when network traffic exceeds a preset threshold; or statistical detection methods, which establish a set of network parameters during normal network operation and issue an alarm when the network parameters deviate from normal operating conditions.
[0004] However, the above detection methods still have the following technical problems: when real-time monitoring of a certain field of a certain transmission interface is required, it is not possible to locate interface data anomalies in a timely and accurate manner; and the detection of network anomalies is only performed for virus traffic propagation events, which has a relatively single detection angle and a high false alarm rate. Summary of the Invention
[0005] The summary section of this application is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.
[0006] Some embodiments of this application propose a virus traffic detection method, computer device, and computer-readable storage medium based on an escape adversarial model to solve one or more of the technical problems mentioned in the background section above.
[0007] In a first aspect, some embodiments of this application provide a virus traffic detection method based on an escape adversarial model. The method includes: intercepting a network traffic request sent by an access terminal in response to detection; determining whether the network traffic request is a target network traffic request based on preset network traffic monitoring configuration information, wherein the network traffic monitoring configuration information is information used to configure target network traffic data and network traffic monitoring strategies to be monitored; and, in response to determining that the network traffic request is a target network traffic request, marking the network traffic request to obtain a traffic-marked network traffic request, and transmitting the traffic-marked network traffic request through a corresponding transmission interface. The network traffic request data is sent to the server. Based on the network traffic monitoring strategy in the network traffic monitoring configuration information, initial virus traffic detection processing is performed on the network traffic request data to obtain initial virus traffic detection results. In response to determining that the initial virus traffic detection results meet the initial anomaly conditions, the network traffic request information sequence of the access terminal within a preset time period is read. The network traffic request information sequence is input into a pre-trained escape-resistant anti-virus traffic detection model to obtain network traffic virus detection results. In response to determining that the network traffic virus detection results meet the virus traffic detection conditions, the access terminal is blocked, and alarm information is sent to the associated virus traffic defense terminal.
[0008] In a second aspect, this application also provides a computer device, which includes a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein when the computer program is executed by the processor, it implements the method described in any implementation of the first aspect above.
[0009] Thirdly, this application also provides a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, it implements the method described in any of the implementations of the first aspect above.
[0010] The above embodiments of this application have the following beneficial effects: The virus traffic detection method based on the escape adversarial model of some embodiments of this application can accurately monitor a certain field of a certain transmission interface in real time, accurately locate whether the interface data is abnormal; and can perform network anomaly detection on virus traffic propagation events from multiple detection angles, reducing the false alarm rate. First, in response to detecting a network traffic request sent by an access terminal, the network traffic request is intercepted. Thus, each network traffic request can be detected. Second, based on preset network traffic monitoring configuration information, it is determined whether the network traffic request is a target network traffic request. The network traffic monitoring configuration information is information used to configure the target network traffic data and network traffic monitoring strategy to be monitored. Thus, it is possible to determine whether a network traffic request is a traffic request that needs virus detection, avoiding detection of all requests and wasting detection resources. Next, in response to determining that the network traffic request is a target network traffic request, the network traffic request is marked to obtain a marked network traffic request, and the marked network traffic request is sent to the server through the corresponding transmission interface. This not only reduces coupling with business logic and minimizes impact on existing business processes, but also enables real-time monitoring of network traffic data. Furthermore, when a network traffic request is identified as a target network traffic request, it can be tagged. Then, based on the network traffic monitoring strategy in the aforementioned network traffic monitoring configuration information, initial virus traffic detection processing is performed on the data of the aforementioned network traffic requests to obtain initial virus traffic detection results. This allows for initial detection of any anomalies in the network traffic requests. Subsequently, in response to the determination that the initial virus traffic detection results meet the initial anomaly conditions, the network traffic request information sequence of the aforementioned access terminal within a preset time period is read. This network traffic request information sequence is input into a pre-trained escape-based anti-virus traffic detection model to obtain network traffic virus detection results. This allows for network anomaly detection of virus traffic propagation events from multiple detection angles. Finally, in response to the determination that the aforementioned network traffic virus detection results meet the virus traffic detection conditions, the aforementioned access terminal is blocked, and alarm information is sent to associated virus traffic defense terminals. This allows for the blocking of abnormal access terminals. It can accurately monitor a specific field of a transmission interface in real time, accurately pinpointing whether the interface data is abnormal; and it can detect network anomalies in virus traffic propagation events from multiple detection angles, reducing the false alarm rate. Attached Figure Description
[0011] The above and other features, advantages, and aspects of the embodiments of this application will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.
[0012] Figure 1 This is a flowchart of some embodiments of the virus traffic detection method based on the escape adversarial model according to this application;
[0013] Figure 2 This is a schematic diagram of the structure of a computer device suitable for implementing some embodiments of this application. Detailed Implementation
[0014] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.
[0015] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0016] It should be noted that the concepts of "first" and "second" mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0017] It should be noted that the terms "a" and "a plurality of" used in this application are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0018] The names of the messages or information exchanged between multiple devices in the embodiments of this application are for illustrative purposes only and are not intended to limit the scope of these messages or information.
[0019] The present application will now be described in detail with reference to the accompanying drawings and embodiments.
[0020] Figure 1 A flowchart 100 of some embodiments of the virus traffic detection method based on the escape adversarial model according to this application is shown. The virus traffic detection method based on the escape adversarial model includes the following steps:
[0021] Step 101: In response to detecting a network traffic request sent by the access terminal, the network traffic request is intercepted.
[0022] In some embodiments, the execution entity (e.g., a computing device) of the virus traffic detection method based on the escape adversarial model can intercept the network traffic request in response to the detection of a network traffic request sent by an access terminal. The access terminal can refer to a user terminal.
[0023] For example, the access terminal can interact with the execution entity and perform operations on the execution entity to obtain the required network data. For instance, various applications can be installed on the execution entity. When the access terminal clicks on an application icon, it initiates a network request to the application's server to obtain the application's page information. At this point, the execution entity can intercept the network traffic request initiated by the access terminal. Alternatively, this network traffic request can be intercepted using packet capture tools with data interception capabilities, such as Fiddler. A network traffic request can refer to an access request, a network traffic allocation request, or a network data download / upload request.
[0024] Step 102: Determine whether the above network traffic request is the target network traffic request based on the preset network traffic monitoring configuration information.
[0025] In some embodiments, the aforementioned execution entity can determine whether the aforementioned network traffic request is a target network traffic request based on preset network traffic monitoring configuration information. The aforementioned network traffic monitoring configuration information is used to configure the target network traffic data and network traffic monitoring strategy to be monitored. The network traffic monitoring strategy may include: collecting and caching the data and time in the target network traffic request sent by the transmission interface; validating the target fields in the target network traffic request sent by the transmission interface according to target rules; collecting and caching the data and time in the network traffic response data of the received target network traffic request; replacing the values of specified fields in the network traffic response data of the received target network traffic request; and validating the specified fields in the network traffic response data of the received target network traffic request according to specified rules, etc. Here, the configuration method for the target network traffic data can be configured according to transmission interface data (such as interface name) or according to user identifier (ID).
[0026] In a practical application scenario, the aforementioned executing entity can determine whether the aforementioned network traffic request is the target network traffic request through the following steps:
[0027] The first step is to determine whether the transmission interface used for communication between the access terminal and the server is consistent with the transmission interface set in the network traffic monitoring configuration information. That is, to determine whether the transmission interface used for communication between the access terminal and the server is the same as the transmission interface set in the network traffic monitoring configuration information.
[0028] The second step is to confirm that the transmission interface settings are consistent and identify the above network traffic request as the target network traffic request.
[0029] The third step is to determine whether the user identifier of the aforementioned access terminal is consistent with the user identifier set in the network traffic monitoring configuration information.
[0030] The fourth step is to determine that the network traffic request matches the user identifier set in the network traffic monitoring configuration information, and to identify the above network traffic request as the target network traffic request.
[0031] The network traffic monitoring configuration information can be configured through the following steps:
[0032] The first step is to determine whether the content of the currently configured network traffic monitoring information has changed in response to the detected configuration operation of the network traffic monitoring information.
[0033] The second step is to respond to the confirmed change in content by using the configured network traffic monitoring configuration information as the new network traffic monitoring configuration information, and using the current time as the filename of the new network traffic monitoring configuration information.
[0034] The third step is to synchronize and update the new network traffic monitoring configuration information to the preset storage location and the corresponding gateway.
[0035] Fourth, in response to the detection of a change in network traffic monitoring configuration information, the new network traffic monitoring configuration information is retrieved from the aforementioned preset storage location.
[0036] The fifth step is to determine and cache the data and time in the target network traffic request sent by the transmission interface.
[0037] The sixth step is to validate the target fields in the target network traffic request sent by the transmission interface according to preset rules.
[0038] The seventh step is to cache the data and time in the traffic request response data of the received target network traffic request.
[0039] Step 8: Replace the value of the target field in the traffic request response data of the received target network traffic request.
[0040] Step 9: Verify the specified fields in the traffic request response data of the received target network traffic request according to the specified rules.
[0041] Step 10: In response to determining that the above network traffic request is a target network traffic request, globally monitor the operation behavior of the above access terminal, and cache the operation data and operation time.
[0042] Step 11: In response to the determination of a data verification anomaly, the cached data is reported and processed.
[0043] Step 103: In response to determining that the above network traffic request is a target network traffic request, the above network traffic request is marked with traffic tags to obtain a traffic-tagged network traffic request, and the traffic-tagged network traffic request is sent to the server through the corresponding transmission interface.
[0044] In some embodiments, the executing entity may, in response to determining that the network traffic request is a target network traffic request, perform traffic marking on the network traffic request to obtain a traffic-marked network traffic request, and send the traffic-marked network traffic request to the server through the corresponding transmission interface. Traffic marking may refer to traffic coloring. Traffic coloring is typically achieved by labeling the requested traffic so that the request carries this label information throughout the entire link. The executing entity may add a traffic coloring label field to the header information of the network traffic request.
[0045] Furthermore, in response to receiving traffic request response data corresponding to the aforementioned network traffic request sent by the aforementioned server, the aforementioned traffic request response data is intercepted.
[0046] In some embodiments, the execution entity may intercept the traffic request response data in response to receiving traffic request response data corresponding to the network traffic request sent by the server.
[0047] Furthermore, determine whether a traffic tag field exists in the aforementioned traffic request response data.
[0048] In some embodiments, the aforementioned execution entity may determine whether a traffic tag field exists in the aforementioned traffic request response data.
[0049] Furthermore, in response to the determination that a tag field exists, based on the network traffic monitoring strategy in the aforementioned network traffic monitoring configuration information, it is determined whether the tag field in the aforementioned traffic request response data is consistent with the filename of the locally cached network traffic monitoring configuration information.
[0050] In some embodiments, the execution entity may, in response to determining the existence of a tag field, determine whether the tag field in the traffic request response data is consistent with the filename of the locally cached network traffic monitoring configuration information, based on the network traffic monitoring policy in the network traffic monitoring configuration information.
[0051] Furthermore, in response to the determination that the file name is inconsistent, new traffic monitoring configuration information that matches the tag field in the traffic request response data is obtained from a preset storage location, and the traffic request response data is replaced according to the new traffic monitoring configuration information.
[0052] In some embodiments, the execution entity may, in response to determining that the file name is inconsistent, obtain new traffic monitoring configuration information that matches the tag field in the traffic request response data from a preset storage location, and replace the traffic request response data according to the new traffic monitoring configuration information.
[0053] Step 104: Based on the network traffic monitoring strategy in the above network traffic monitoring configuration information, perform initial virus traffic detection processing on the data of the above network traffic request to obtain the initial virus traffic detection result.
[0054] In some embodiments, the aforementioned execution entity may perform initial virus traffic detection processing on the data of the aforementioned network traffic request according to the network traffic monitoring policy in the aforementioned network traffic monitoring configuration information, and obtain an initial virus traffic detection result. For example, the detection processing may include: validating specified fields in the target network traffic request sent by the transmission interface according to specified rules; replacing the values of specified fields in the network traffic response data of the received target network traffic request; validating specified fields in the network traffic response data of the received target network traffic request according to specified rules, etc. Here, there are no restrictions on the setting of rules. The initial virus traffic detection result may indicate whether the network traffic request passes or fails the verification.
[0055] Step 105: In response to determining that the initial virus traffic detection result meets the initial abnormality condition, read the network traffic request sequence of the access terminal within a preset time period.
[0056] In some embodiments, the execution entity may, in response to determining that the initial virus traffic detection result meets the initial anomaly condition, read the network traffic request information sequence of the access terminal within a preset time period. The initial anomaly condition may be that the initial virus traffic detection result indicates that the network traffic request failed verification. The network traffic request information may include network traffic requests and network access behavior information. The network access behavior information may represent various browsing behaviors, click behaviors, download behaviors, and information transmission behaviors of the access terminal when accessing the application, as well as the domain name information and account information of the access terminal.
[0057] Step 106: Input the above network traffic request information sequence into the pre-trained escape anti-virus traffic detection model to obtain the network traffic virus detection result.
[0058] In some embodiments, the aforementioned execution entity can input the network traffic request sequence into a pre-trained evasion-based anti-virus traffic detection model to obtain network traffic virus detection results. The evasion-based anti-virus traffic detection model can be a pre-trained neural network model that takes network traffic requests as input and outputs network traffic virus detection sub-results. The network traffic virus detection results can include a sequence of network traffic virus detection sub-results, with each sub-result corresponding to one network traffic request. For example, the evasion-based anti-virus traffic detection model can be an unknown threat detection model based on traffic parsing, a deep domain adaptive model, an encrypted malicious traffic detection model, etc. An unknown threat detection model based on traffic parsing: This model trains a domain-partitioned network by designing an objective function, including a source domain private encoder, a target domain private encoder, a shared encoder, a shared decoder, and a classifier. It proposes a shared representation learning approach. Although this model was initially designed for image tasks, its structure and methods can be applied to traffic classification tasks. By introducing convolutional neural networks and recurrent neural networks as feature extraction components and combining adversarial learning, it comprehensively models the original information and effectively learns the shared representations between the source and target domains through a domain discriminator. Deep Domain Adaptive Model: This model uses a network structure based on spatiotemporal feature extraction methods for relevant representation learning and learns shared representations through adversarial learning. The model includes a shared representation discriminator network and a shared representation generator network. Through adversarial training, it learns the shared representations between the source and target domains, aiming to generate shared representations that cannot distinguish whether data comes from the source or target domain. Encrypted Malicious Traffic Detection Model: This model extracts behavioral features at three different levels: packet level, flow level, and host level. Multiple models are constructed to improve the ability to distinguish between black and white samples. Some models use multi-dimensional features for comprehensive analysis, while others use single-dimensional features with high black and white sample discrimination to mitigate potential overfitting and false alarm problems. The network traffic virus detection sub-result can indicate whether a network traffic request contains a virus or application virus. Network traffic request information can include network traffic requests and network access behavior information. Network access behavior information can represent various browsing, clicking, downloading, and data transmission behaviors of the accessing terminal when accessing applications, as well as the accessing terminal's domain name and account information.
[0059] Furthermore, escape-based anti-virus traffic detection models can be built upon Network Mimicry Defense (CMD) or the PETS penetration testing framework. Network Mimicry Defense (CMD): This is a defense theory and method for addressing unknown threats such as unknown vulnerabilities, backdoors, viruses, or Trojans at different application layers in cyberspace. Inspired by the biomimetic phenomenon, CMD introduces a multi-dimensional dynamic reconstruction mechanism to create strategic changes in dissimilar redundant construction elements within the target object, thus countering deterministic or uncertain threats in cyberspace. CMD not only provides an inherent security gain independent of traditional security measures (such as firewalls, intrusion detection, and antivirus software), but also offers resilient service capabilities with its inherent intensive attributes, or integrates mature defense technologies to achieve ultra-nonlinear defense effects. PETS Penetration Testing Framework: This is a framework that defines the true penetration testing process by establishing basic penetration testing principles. The PETS penetration testing framework includes pre-interaction, intelligence gathering, threat modeling, vulnerability analysis, penetration attack, post-penetration attack, and reporting phases. The core concept of this framework is to simulate attacker behavior through a series of steps, thereby assessing and improving the security of the target system. Each stage has its specific goals and tasks to ensure a comprehensive analysis and understanding of the security vulnerabilities and weaknesses of the target system.
[0060] Furthermore, the escape-based antivirus traffic detection model can be trained through the following steps:
[0061] The first step is to obtain a training sample set of network traffic requests. This training sample set includes: sample network traffic request information, sample network access behavior information, network traffic virus detection tags, and abnormal network access tags. Network traffic virus detection tags indicate whether a virus exists in the sample network traffic request information. Abnormal network access tags indicate whether abnormal / malicious access behavior exists in the sample network access behavior information.
[0062] The second step is to determine the initial escape-based anti-virus traffic detection model. This initial escape-based anti-virus traffic detection model includes: an initial virus traffic detection model and an initial abnormal network access behavior detection model. The initial abnormal network access behavior detection model includes: an initial classification network, a first initial feature extraction network, a second initial feature extraction network, a third initial feature extraction network, an initial fusion network, and an initial access behavior detection network. The initial virus traffic detection model can be an untrained network traffic model, an encrypted malicious traffic identification and adversarial model, a multi-level SEIR model, or an unknown threat detection model based on traffic parsing. The network traffic model is based on the idea of hierarchically dividing network traffic feature vectors, dividing traffic features into a basic feature set and a combined feature set. The basic feature set is extracted from network traffic in real time, such as traffic size, packet length information, and protocol information, while the combined feature set is adjusted in real time according to actual needs to describe specific attack behaviors. Through learning and training, normal and abnormal attack behavior models can be obtained, enabling real-time detection of such attack behaviors on the network. Encrypted Malicious Traffic Identification and Countermeasure Models: Effectively identifying encrypted traffic without decryption is a key focus in the current cybersecurity field. Research on encrypted malicious traffic identification mainly falls into three categories: rule-based methods, traditional machine learning-based methods, and deep learning-based methods. Rule-based methods utilize combinations, sorting, or fixed patterns of encrypted traffic fields for pattern matching, while machine learning and deep learning-based methods extract rules from samples for reasoning and decision-making, exhibiting high interpretability. Multi-Level SEIR Model: This is a cybersecurity model inspired by epidemiological SEIR models, categorizing network attack hardware into four classes: susceptible, exposed, infected, and recovered. By considering differences in network security and defense levels, and differentiating threats based on the specific probability and potential harm of network attacks, this model describes the spread of network attacks across various systems. Unknown Threat Detection Model Based on Traffic Parsing: This model trains a domain-partitioned network by designing a complex objective function, including a source domain private encoder, a target domain private encoder, a shared encoder, a shared decoder, and a classifier. It introduces the concept of adversarial learning, fully models the original information, and effectively learns the shared representations of the target and source domains through a domain discriminator for the detection of unknown threats.
[0063] Here, the aforementioned initial classification network can be a network that takes sample network access behavior information as input and outputs an initial access behavior classification information group. The initial access behavior classification information group can include initial access behavior information, initial domain name information, and initial access account information. For example, the initial classification network is used to classify the sample network access behavior information into its components: initial access behavior information, initial domain name information, and initial access account information.
[0064] The aforementioned first initial feature extraction network can be a classification model that takes initial access behavior classification information as input and outputs initial access behavior information, initial domain name information, and initial access account information. Here, the first initial feature extraction network can be divided into five layers:
[0065] The first layer, the first embedding layer, is used to vectorize the initial access behavior information to generate vectorized information about the initial access behavior. For example, the first embedding layer can be an embedding layer model.
[0066] The second layer, the second embedding layer, is used to vectorize the initial domain name information to generate vectorized initial domain name information. For example, the second embedding layer can be an embedding layer model.
[0067] The third layer, the third embedding layer, is used to vectorize the initial access account information to generate vectorized initial access account information. For example, the third embedding layer can be an embedding layer model.
[0068] The fourth layer is the convolutional layer, which includes three convolutional models: a first convolutional model, a second convolutional model, and a third convolutional model. The first convolutional model takes the vectorized information of the initial access behavior as input and outputs the convolutional information of that initial access behavior. The second convolutional model takes the vectorized information of the initial domain name as input and outputs the convolutional information of that initial domain name. The third convolutional model takes the vectorized information of the initial access account as input and outputs the convolutional information of that initial access account. For example, the first convolutional model could have a kernel of 7 and a stride of 1. The second convolutional model could have a kernel of 5 and a stride of 1. The third convolutional model could have a kernel of 3 and a stride of 1.
[0069] The fifth layer, the fully connected layer, is used to concatenate the initial access behavior convolutional information, the initial domain name convolutional information, and the initial access account convolutional information to generate the first initial feature information. For example, the fully connected layer can be a Denselayer (fully connected) model.
[0070] The aforementioned second initial feature extraction network can be a neural network model that takes initial domain name information as input and outputs initial domain name feature information. This second initial feature extraction network can include three layers:
[0071] The first layer, the embedding layer, is used to vectorize the initial domain name information to generate vectorized initial domain name information. For example, the embedding layer can be an embedding layer model.
[0072] The second layer is a convolutional layer, consisting of a first convolutional model and a second convolutional model. The first convolutional model takes the initial domain name vectorization information as input and outputs the first initial domain name convolutional information. The second convolutional model takes the first initial domain name convolutional information as input and outputs the second initial domain name convolutional information. For example, the first convolutional model could have a kernel of 7 and a stride of 1. The second convolutional model could have a kernel of 5 and a stride of 1.
[0073] The third layer, the fully connected layer, is used to transform the convolutional information of the second initial domain name to generate the initial domain name feature information. For example, the fully connected layer can be a Dense layer model.
[0074] The third initial feature extraction network can be a neural network model that takes initial access account information as input and outputs initial access account feature information. For example, the third initial feature extraction network can be a convolutional neural network model.
[0075] The third step is to select target network traffic request training samples from the above network traffic request training sample set and perform the following first training step:
[0076] 1. Input the sample network access behavior information included in the above-mentioned target network traffic request training samples into the initial classification network to obtain the initial access behavior classification information group. The initial access behavior classification information group includes: initial access behavior information, initial domain name information, and initial access account information.
[0077] 2. Input the above initial access behavior information into the first initial feature extraction network included in the above initial abnormal network access behavior detection model to obtain the initial access behavior feature information.
[0078] 3. Input the above initial domain name information into the second initial feature extraction network included in the above initial abnormal network access behavior detection model to obtain the initial domain name feature information.
[0079] 4. Input the above initial access account information into the third initial feature extraction network included in the above initial abnormal network access behavior detection model to obtain the initial access account feature information.
[0080] 5. Input the aforementioned initial access behavior feature information, initial domain name feature information, and initial access account feature information into the initial fusion network included in the initial abnormal network access behavior detection model to obtain the initial network access behavior feature fusion information. The initial fusion network can be a model that takes the initial access behavior feature information, initial domain name feature information, and initial access account feature information as input and outputs the initial network access behavior feature fusion information. For example, the initial fusion network can be a DenseNet convolutional network, a ResNet deep residual network, or a CBP (Compact Bilinear Pooling) network.
[0081] 6. Input the aforementioned initial network access behavior feature fusion information into the initial access behavior detection network included in the initial abnormal network access behavior detection model to obtain the initial access behavior detection result. The aforementioned initial access behavior detection network can be a neural network model that takes the initial network access behavior feature fusion information as input and the initial access behavior detection result as output. For example, the initial access behavior detection network can be a support vector machine (SVM) model.
[0082] 7. Based on a preset access behavior loss function, determine the difference between the initial access behavior detection result and the corresponding abnormal network access label. The preset loss function can be, but is not limited to: mean squared error loss function (MSE), hinge loss function (SVM), cross-entropy loss function, 0-1 loss function, absolute value loss function, etc.
[0083] 8. In response to determining that the above difference value is less than or equal to the preset loss value, the initial abnormal network access behavior detection model is determined as the trained abnormal network access behavior detection model.
[0084] Therefore, an initial classification network can be trained to classify initial access behavior information, initial domain information, and initial access account information. Then, a feature extraction network, including embedding layers, convolutional layers, and fully connected layers, can be trained to accurately extract features from these three information sets. Thus, by fusing these initial network access behavior features, a more accurate access behavior detection result can be identified to determine whether abnormal access behavior exists.
[0085] The fourth step is to select target network traffic request training samples from the above network traffic request training sample set, and train the above initial virus traffic detection model based on the target network traffic request training samples to obtain the trained virus traffic detection model.
[0086] The initial virus traffic detection model can include: an initial virus traffic convolutional network, an initial virus traffic attack prediction network, and an initial virus traffic detection network. Here, the initial virus traffic convolutional network can be a diffusing convolutional recurrent neural network model that takes sample network traffic request information as input and outputs initial network traffic request convolutional information. The initial virus traffic attack prediction network can be a neural network model that takes initial network traffic request convolutional information as input and outputs initial virus traffic prediction information. For example, the initial virus traffic attack prediction network can be an optimized GRU (Gated Recurrent Unit) model. The initial virus traffic detection network can be a neural network model that takes initial virus traffic prediction information as input and outputs the initial virus traffic detection result. For example, the initial virus traffic detection network can be a Support Vector Machine (SVM) model.
[0087] The training of the initial virus traffic detection model can include the following sub-steps:
[0088] The first step is to input the sample network traffic request information, which includes the target network traffic request training samples, into the initial virus traffic convolutional network to obtain the initial network traffic request convolutional information.
[0089] The second step involves inputting the initial network traffic request convolution information into the initial virus traffic attack prediction network to generate initial virus traffic prediction information.
[0090] The third step is to input the initial virus traffic prediction information into the initial virus traffic detection network to obtain the initial virus traffic detection results.
[0091] The fourth step involves determining the predicted difference between the initial virus traffic detection result and the corresponding network traffic virus detection label based on a preset loss function. The preset loss function can be, but is not limited to, mean squared error (MSE), hinge loss function (SVM), cross-entropy, etc.
[0092] The fifth step is to determine the initial virus traffic detection model as the trained virus traffic detection model in response to the determination that the predicted difference value is less than or equal to the preset difference value.
[0093] The sixth step is to merge the above-mentioned abnormal network access behavior detection model with the above-mentioned virus traffic detection model into an escape anti-virus traffic detection model.
[0094] Therefore, by training an initial virus traffic detection model that includes an initial virus traffic convolutional network, an initial virus traffic attack prediction network, and an initial virus traffic detection network, a robust virus traffic detection model can be trained. This trained virus traffic detection model can detect virus attacks on various types of network traffic, thereby improving the efficiency of network virus attack prevention and enhancing network security.
[0095] Step 107: In response to determining that the above network traffic virus detection results meet the virus traffic detection conditions, the above access terminal is blocked, and an alarm message is sent to the associated virus traffic defense terminal.
[0096] In some embodiments, the execution entity may, in response to determining that the network traffic virus detection result meets the virus traffic detection conditions, block the access terminal and send alarm information to the associated virus traffic defense terminal. The virus traffic detection conditions may be: the network traffic virus detection result indicates the presence of a network traffic virus. The virus traffic defense terminal may be a defense terminal used to eliminate network traffic viruses in applications. The alarm information may refer to information indicating that the access terminal is an abnormal terminal.
[0097] This application also provides a computer device 200. For example... Figure 2 As shown, the computer device 200 includes a bus 201, a processor 202, a memory 203, and a communication interface 204. The processor 202, the memory 203, and the communication interface 204 communicate with each other via the bus 201. The computer device 200 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computer device 200.
[0098] Bus 201 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 2 The bus 201 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 201 may include a path for transmitting information between various components of the computer device 200 (e.g., processor 202, memory 203, communication interface 204).
[0099] Processor 202 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0100] Memory 203 may include volatile memory, such as random access memory (RAM). Memory 203 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0101] The memory 203 stores executable program code, and the processor 202 executes this executable program code to implement the functions of the aforementioned acquisition module, sampling module, determination module, and mixing module, thereby realizing the aforementioned virus traffic detection method based on the escape adversarial model. That is, the memory 203 stores instructions for executing the aforementioned virus traffic detection method based on the escape adversarial model.
[0102] The communication interface 204 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computer device 200 and other devices or communication networks.
[0103] This application also provides a chip, which includes a processor and a data interface. The processor reads instructions stored in the memory through the data interface to execute the above-described virus traffic detection method based on the escape adversarial model.
[0104] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium capable of being stored by a computing device, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the aforementioned virus traffic detection method based on an escape-based adversarial model.
[0105] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0106] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.
Claims
1. A virus traffic detection method based on an escape adversarial model, comprising: In response to detecting a network traffic request sent by an access terminal, the network traffic request is intercepted; Based on the preset network traffic monitoring configuration information, it is determined whether the network traffic request is a target network traffic request. The network traffic monitoring configuration information is information used to configure the target network traffic data and network traffic monitoring strategy to be monitored. In response to determining that the network traffic request is a target network traffic request, the network traffic request is traffic-tagged to obtain a traffic-tagged network traffic request, and the traffic-tagged network traffic request is sent to the server through the corresponding transmission interface; Based on the network traffic monitoring strategy in the network traffic monitoring configuration information, the data of the network traffic request is subjected to initial virus traffic detection processing to obtain the initial virus traffic detection result. In response to determining that the initial virus traffic detection result meets the initial abnormal conditions, the network traffic request information sequence of the access terminal within a preset time period is read. The network traffic request information sequence is input into a pre-trained anti-virus traffic detection model to obtain network traffic virus detection results; In response to determining that the network traffic virus detection result meets the virus traffic detection conditions, the access terminal is blocked, and an alarm message is sent to the associated virus traffic defense terminal. The method further includes, before determining whether the network traffic request is a target network traffic request based on preset network traffic monitoring configuration information: In response to the detection of a configuration operation on network traffic monitoring information, determine whether the content of the currently configured network traffic monitoring configuration information has changed; In response to the determination that the content has changed, the configured network traffic monitoring configuration information is used as the new network traffic monitoring configuration information, and the current time is used as the file name of the new network traffic monitoring configuration information; The new network traffic monitoring configuration information will be synchronously updated to the preset storage location and the corresponding gateway.
2. The virus traffic detection method based on the escape adversarial model according to claim 1, wherein, The step of determining whether the network traffic request is a target network traffic request based on preset network traffic monitoring configuration information includes: Determine whether the transmission interface connecting the access terminal to the server is consistent with the transmission interface set in the network traffic monitoring configuration information; The response confirms that the configured transmission interface is consistent, and determines that the network traffic request is the target network traffic request. Determine whether the user identifier of the access terminal is consistent with the user identifier set in the network traffic monitoring configuration information; In response to the determination that the user identifier matches the one set in the network traffic monitoring configuration information, the network traffic request is determined to be the target network traffic request.
3. The virus traffic detection method based on the escape adversarial model according to claim 1, wherein, The method further includes: In response to receiving traffic request response data corresponding to the network traffic request sent by the server, the traffic request response data is intercepted; Determine whether a tag field for traffic marking exists in the traffic request response data; In response to the determination that a tag field exists, the system determines whether the tag field in the traffic request response data is consistent with the filename of the locally cached network traffic monitoring configuration information, based on the network traffic monitoring policy in the network traffic monitoring configuration information. In response to the determination that the file name is inconsistent, new traffic monitoring configuration information that matches the tag field in the traffic request response data is obtained from a preset storage location, and the traffic request response data is replaced according to the new traffic monitoring configuration information.
4. The virus traffic detection method based on the escape adversarial model according to claim 3, wherein, Before determining whether the network traffic request is a target network traffic request based on preset network traffic monitoring configuration information, the method further includes: In response to detecting a change in network traffic monitoring configuration information, the new network traffic monitoring configuration information is retrieved from the preset storage location; The data and time in the target network traffic request sent by the transmission interface are determined and cached. The target field in the target network traffic request sent by the transmission interface is validated according to preset rules; Cache the data and time in the traffic request response data of the received target network traffic request; Replace the value of the target field in the traffic request response data of the received target network traffic request; According to the set rules, the set fields in the traffic request response data of the received target network traffic request are validated. In response to determining that the network traffic request is a target network traffic request, the operation behavior of the access terminal is globally monitored, and the operation data and operation time are cached. In response to the determination of a data verification error, the cached data is reported and processed.
5. A computer device, wherein, The computer device includes a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein the computer program, when executed by the processor, implements the steps of the method as described in any one of claims 1-4.
6. A computer-readable storage medium, wherein, The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1-4.
Citation Information
Patent Citations
Network traffic access control method and device, storage medium and electronic equipment
CN117792681A
Container escape detection method and detection system
CN118540137A