A Graph Convolutional Neural Network Protocol Classification Method Based on Spectral Clustering Composition

By applying the graph convolutional neural network (S-GCN) method based on spectral clustering composition in the cloud platform, the protocol data in the cloud platform is efficiently classified, which solves the adaptability and efficiency problems of traditional methods when facing complex protocol data, and achieves high-precision and high-efficiency protocol classification.

CN119179934BActive Publication Date: 2025-06-13STATE GRID ANHUI ELECTRIC POWER CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411682757.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-06-13
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

When traditional fault detection and handling methods face complex environments with large amounts of protocol data and diverse types in cloud platforms, it is difficult to achieve efficient protocol classification and precise processing, and their adaptability to variable protocol interaction characteristics is limited.

Method used

The graph convolutional neural network (S-GCN) protocol classification method based on spectral clustering composition is adopted. By introducing a spectral clustering algorithm, a graph structure model with high clustering characteristics is generated, and combined with the powerful modeling ability of graph convolutional neural network on graph structure data, efficient classification of protocol interactive data is achieved.

Benefits of technology

This method can make full use of the structural characteristics of protocol data, maintain high classification accuracy while significantly improving classification efficiency, and provides strong technical support for fault identification and handling of cloud platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119179934B_ABST
    Figure CN119179934B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for classifying network protocols of a graph convolutional neural network based on spectral clustering graph construction, which relates to the fields of network security and machine learning. The method includes the following steps: screening out key fields from the collected network protocol data; optimizing the traditional spectral clustering graph construction algorithm, clustering the screened data, and processing the data into a graph structure form suitable for a graph neural network; using the graph structure obtained by spectral clustering as the input of the graph convolutional neural network, proposing an S-GCN model, modeling with three randomly initialized GCNs, performing convolution on the third-order neighborhood of nodes, and realizing network protocol classification by aggregating node features in the last layer. Experiments prove that the method of the present invention has a high accuracy rate in the classification result. The quality of the graph structure in S-GCN directly affects the classification result, and at the same time proves the high efficiency of the graph structure of the present invention.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of computer vision and natural language processing, and particularly to a protocol classification method for a graph convolutional neural network based on spectral clustering graph construction. Background Art

[0002] With the rapid development of cloud computing technology, the cloud platform, as the core infrastructure for carrying high-concurrency services and complex computing tasks, is increasingly becoming an important pillar of modern information construction. However, the complexity and dynamic characteristics of the cloud platform often lead to performance bottlenecks and service failures during operation. Especially in a cloud environment with a microservices-based core architecture, services communicate through a large number of network protocols, and the complexity and dynamic changes of these protocol interactions pose higher requirements for system fault identification and rapid response. Traditional fault detection and handling methods mostly adopt a rule-driven mode, analyzing and judging monitoring data based on predefined thresholds or rules. However, the adaptability of such methods to the changing protocol interaction characteristics is limited, and it is difficult to achieve efficient protocol classification and precise processing in the face of problems such as large amounts of protocol data and diverse types in the cloud platform.

[0003] In the actual operating environment of the cloud platform, protocol classification is one of the key technologies for achieving efficient resource management and fault location. The purpose of protocol classification is to accurately classify network data into corresponding protocol types based on the traffic characteristics or interaction behaviors of the protocols. Existing protocol classification methods mainly rely on feature engineering and traditional machine learning models, which highly depend on manually designed features. The performance of the models is limited by the quality and generalization ability of feature extraction, and it is difficult to effectively handle the non-linear characteristics of complex protocol data.

[0004] In recent years, analysis methods based on graph-structured data have gradually attracted attention. Since the protocol interaction data in the cloud platform inherently has the characteristics of networking and relevance, graph modeling can more intuitively depict the relationships and interaction patterns between protocols. However, traditional graph analysis methods have obvious deficiencies in extracting global structural features and processing large-scale data. For this reason, the graph neural network (GNN), as an emerging deep learning technology, has demonstrated excellent graph-structured data processing capabilities by combining node features and graph structure information for modeling. However, when directly applying the graph neural network for protocol classification, the following technical problems still exist: First, how to effectively extract features from complex protocol interaction data and construct a graph structure with significant clustering characteristics; second, how to design an efficient graph neural network model to fully utilize the global and local features of the graph to achieve high-precision protocol classification; finally, how to maintain the efficiency of the algorithm when processing massive protocol data to meet the requirements of real-time fault handling in the cloud platform.

[0005] In view of the above problems, the present invention proposes a protocol classification method for graph convolutional neural networks based on spectral clustering graph construction. By introducing the spectral clustering algorithm to preprocess the protocol data, a graph structure model with high clustering characteristics is generated. Combining the powerful modeling ability of graph convolutional neural networks on graph structure data, efficient classification of protocol interaction data is achieved. This method can make full use of the structural features of protocol data, significantly improve the classification efficiency while maintaining a high classification accuracy, and provides strong technical support for fault identification and handling in cloud platforms. Summary of the Invention

[0006] In view of the problems existing in the above technologies, the purpose of the present invention is to provide a protocol classification method for graph convolutional neural networks based on spectral clustering graph construction.

[0007] In order to achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0008] A protocol classification method for graph convolutional neural networks based on spectral clustering graph construction includes the following steps:

[0009] Step 1: Screen key fields from the collected network protocol data and generate a data set;

[0010] Step 2: Optimize the traditional spectral clustering graph construction algorithm, cluster the screened data, and process the data into a graph structure form suitable for graph neural networks;

[0011] Step 3: Perform graph structure optimization operations on the spectral clustering result graph in Step 2;

[0012] Step 4: Use the graph structure obtained by spectral clustering as the input of the graph convolutional neural network, propose the S-GCN model, perform modeling using three-layer GCN with random initialization, perform convolution on the three-order neighborhood of nodes, and realize network protocol classification by aggregating node features in the last layer.

[0013] In Step 1: In the original data set, the message contains all fields from the physical layer to the application layer. It is necessary to process the data set, screen key fields,

[0014] Step 1-1: Perform traffic segmentation on the data set,

[0015] Step 1-2: Remove redundancy from the traffic of the data set,

[0016] Step 1-3: Select fields for the data set,

[0017] Step 1-4: Unify the length and labels of the data set,

[0018] Step 1-5: Generate a new data set.

[0019] In Step 2: After preprocessing the data, the protocol data is transformed into matrix form, with each row representing a message and each column representing different features of the message, obtaining a data matrix , which is a data matrix composed of data, and each sample has

[0020] Step 2-1: Construct a similarity graph matrix based on the input data matrix ,

[0021] Step 2-2: Construct a Laplacian matrix based on the similarity graph matrix ,

[0022] Step 2-3: Perform eigenvalue decomposition on , extract the eigenvectors corresponding to the first smallest eigenvalues, and construct a spectral representation matrix ,

[0023] Step 2-4: Use K-means clustering to partition the spectral representation and obtain the clustering result ,

[0024] Step 2-5: Analyze and verify the clustering result

[0025] Optimize the spectral clustering graph construction algorithm as follows

[0026] For the original samples and , their similarity is . By means of the transformation matrix , project the original data from the original feature space to the low-dimensional feature subspace. At the same time, the local structure between the samples and in the low-dimensional space remains unchanged, and the mathematical representation is as follows

[0027] (1)

[0028]

[0029] where is the parameter of the Gaussian kernel, and the Bray-Curtis distance is used in calculating the distance. Its formula is as follows

[0030] (2)

[0031] where , are the respective feature components of the vectors , respectively

[0032] The transformation matrix is constrained by an orthogonal constraint term to obtain the objective function of LPP as follows:

[0033] (3)

[0034] where , denotes a diagonal matrix, is the identity matrix, is the orthogonal constraint for generating uncorrelated spectral vectors, and the diagonal elements are equal to the sum of the row vectors of the similarity graph matrix ,

[0035] i.e., . The Laplacian matrix is constructed using a hypergraph, and then the spectral representation is constrained by the hypergraph Laplacian matrix. Formula (3) is rewritten as:

[0036] (4)

[0037] where is a hypergraph Laplacian matrix,

[0038] The attribute selection is embedded into the subspace learning framework

[0039] (5)

[0040] where is a row-sparse matrix, and the non-negative number is a regularization parameter that balances subspace learning and attribute selection during the learning process.

[0041] In the subsequent clustering process, the spectral rotation clustering method is adopted, and the spectral rotation clustering is embedded into the spectral representation learning framework to complete one-step clustering. The objective function is as follows:

[0042]

[0043] (6)

[0044] where is the tuning coefficient.

[0045] To solve the objective function formula (6),

[0046] First, initialize the indicator matrix , the transformation matrix and the identity matrix . Subsequently, enter an iterative loop that will continue to execute until the convergence criterion defined by formula (6) is satisfied.

[0047] During this iterative process, the transformation matrix is updated following these three steps:

[0048] Step (1) Initiate an inner iterative loop that will execute until the update of the transformation matrix satisfies the convergence condition specified by Equation (7),

[0049] Step (2) In the inner loop, first update the transformation matrix according to Equation (11), then the GPI framework updates the matrix , and finally update the matrix according to Equation (13).

[0050] Step (3) These steps will be looped until the update of the transformation matrix reaches the convergence criterion set by Equation (7).

[0051] After the above inner loop is completed, update the matrix according to Equation (15), then update the matrix according to Equation (16). After completing these update steps, return to the outer iterative loop to continue updating the transformation matrix until the convergence criterion defined by Equation (6) is satisfied. The entire iterative process continues until the update of the transformation matrix satisfies the convergence condition of the outer loop,

[0052] For the update of ,

[0053] When updating , it is necessary to fix and , then solving the objective function is equivalent to solving Equation (7),

[0054]

[0055] (7)

[0056] Using the framework of iterative weighted least squares to solve the non-smooth problem of Equation (7), then Equation (7) becomes the following:

[0057]

[0058] (8)

[0059] where is the hypergraph diagonal matrix, whose diagonal elements are ,

[0060] Using the alternating direction multiplicative operator framework, the complex problem is decomposed into multiple sub-problems that are easy to solve. Let Then formula (8) becomes the following formula:

[0061]

[0062] (9)

[0063] After the above transformation, the optimization problem is transformed into three sub-problems to be solved:

[0064] (10)

[0065] For , , update, set the value to 1, and set the derivative of to 0, then the closed-form solution of is obtained:

[0066] (11)

[0067] And the update of is directly achieved through transformation:

[0068]

[0069] (12)

[0070] Where ,

[0071] When and are calculated, the optimization of is obtained through formula (13) optimization:

[0072] (13)

[0073] For the update of ,

[0074] When updating , it is necessary to fix and , then the objective function becomes the following formula:

[0075] (14)

[0076] is an indicator matrix, where the element There are only two values, 0 and 1. is an approximation of , and the solution of formula (14) is as follows:

[0077] (15)

[0078] For the update of

[0079] Update It is necessary to fix and , then the objective function is equivalent to the following formula:

[0080]

[0081] (16)

[0082] Minimize formula (16), and after transformation, it is equivalent to:

[0083]

[0084] (17)

[0085] Let and be the left and right singular matrices of the singular value decomposition with respect to the point respectively, that is:

[0086] (18)

[0087] Replace the non-orthonormal clustering index matrix with a standard orthonormal scaling clustering index matrix to minimize the difference between the two standard orthonormal matrices, and obtain the closed-form solution:

[0088] (19).

[0089] Step 3 Perform graph structure optimization on the spectral clustering result graph in Step 2, specifically as follows:

[0090] For the data set processed in Step 2, define the probability that the -th sample and all data points are connected to a neighbor of , and the probability is determined by the following formula:

[0091] (20)

[0092] Find a linear combination that is closest to the original features of the low-dimensional manifold, as follows:

[0093] (21)

[0094] Agree on a constraint function , where is the number of connected components in the similarity graph matrix . Use the following formula to make fit the initial graph :

[0095] (22)

[0096] where is the updated Laplacian matrix, and the initial graph is the graph obtained in Step 3,

[0097] Use graph learning and sparse learning based on to solve the noise and outlier problems, as shown in the following formula:

[0098] (23)

[0099] where the constraint depends on , is 's th eigenvalue. When it is positive semi-definite, there is and the constraint function represents . Then, obtain from Fanji's theorem:

[0100] (24)

[0101] Formula (23) is solved by the following formula:

[0102]

[0103] (25)

[0104] is a non-negative tuning parameter, represents the characteristics of the feature space after regularization. By solving formula (25), a high-quality graph

[0105] In Step 4, construct a graph convolutional neural network model based on spectral clustering graph construction, and input the optimized graph structure data in Step 3 into the model for network protocol classification,

[0106] Use a hypergraph for semi-supervised classification of nodes. Define an undirected hypergraph , where represents the vertices, represents an edge, and there is also a small set of marked supernodes , and each supernode is associated with a feature vector , where is the number of dimensions,

[0107] The key is the Laplacian operator of the graph. The definition method of the Laplacian operator is as follows,

[0108] The calculation formula is as follows,

[0109] 1) For each hyperedge , let ,

[0110] 2) Add the edge with weight to the vertex to construct a weighted graph , where is the weight of the hyperedge . Then add self-loops to each vertex so that the degree of the vertex in is equal to . Let denote the weighted adjacency matrix of representing ,

[0111] 3) The symmetric normalized hypergraph Laplacian function is:

[0112] (26)

[0113] After obtaining the adjacency matrix and the feature matrix composed of all node features, perform graph convolution operations to transfer and aggregate information between nodes through formula (27). Use a 3-layer GCN with randomly initialized weights to capture the structure of the entire graph. Aggregate the node features in the last layer for classification, and finally use the global attention mechanism for output.

[0114] (27)

[0115] where is the adjacency matrix of the undirected graph with self-connections added, is the identity matrix; is the trainable weight matrix specific to each layer; represents the activation function; is the activation matrix of the th layer, and ,

[0116] Compared with the prior art, the advantages of this application are as follows:

[0117] Based on traditional spectral clustering, this application optimizes the spectral clustering algorithm. Specifically, by combining subspace learning and attribute selection for dimensionality reduction, it can dynamically select inherent important attributes, construct a robust spectral representation in the low-dimensional space, and avoid the influence of redundant attributes and outliers. This application uses a high-quality graph structure to optimize the classification performance of the GCN model. An adaptive graph learning is introduced to capture the intrinsic low-level correlations of the data, and a hypergraph is used to establish the relationships between the data. For the redundant information of the data, this application uses sparse learning and low-rank constraints combined with graph learning, which improves the accuracy of the results and the robustness of the model. Experimental results show that the proposed graph construction method based on spectral clustering and the optimized classification method S-GCN are superior to other comparison methods in protocol classification and recognition effects. Brief Description of the Drawings

[0118] Figure 1 Schematic diagram of protocol data preprocessing;

[0119] Figure 2 Schematic diagram of the S-GCN framework;

[0120] Figure 3 Schematic diagram for comparing the clustering results of the graph construction method;

[0121] Figure 4 Schematic diagram of two-dimensional visualization of protocol classification results;

[0122] Figure 5 Schematic diagram of the convergence curve of the objective function;

[0123] Figure 6 Schematic diagram of the overall process of the present invention. Detailed Description of the Embodiments

[0124] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings so that those skilled in the art can easily implement them. In addition, for clarity, parts unrelated to the description of the exemplary embodiments are omitted in the drawings.

[0125] It should be further noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The present disclosure will be described in detail below with reference to the drawings and in combination with the embodiments.

[0126] Embodiment: Refer to Figures 1 - 6 , a graph convolutional neural network protocol classification method based on spectral clustering graph construction, comprising the following steps:

[0127] Step 1: Screen out key fields from all network protocols from the physical layer to the application layer in the dataset to generate a new dataset;

[0128] Step 2: Optimize the traditional spectral clustering graph construction algorithm by combining subspace learning and attribute selection, and construct a graph using the optimized spectral clustering algorithm for the dataset processed in Step 1.

[0129] Step 3: Perform graph structure optimization operations on the spectral clustering result graph in Step 2.

[0130] Step 4: Construct a graph convolutional neural network model based on spectral clustering graph construction, and input the optimized graph structure data in Step 3 into the model for network protocol classification.

[0131] The data comes from the Internet real-time communication data packets provided by NSFocus Co., Ltd., and the original data format is pcap data packets. It includes 7 industrial protocol messages such as Modbus and Omron, and each message has 2000 - 4000 as the experimental dataset, as shown in Table 1. In the original dataset, the message contains all fields from the physical layer to the application layer, and the dataset needs to be processed to filter out key fields.

[0132] Table 1 Dataset Information Statistics

[0133]

[0134] As Figure 1 shown,

[0135] In Step 1, in the original dataset, the message contains all fields from the physical layer to the application layer, and the dataset needs to be processed to filter out key fields.

[0136] Step 1-1: Perform traffic segmentation on the dataset.

[0137] Step 1-2: Remove redundancy from the traffic of the dataset.

[0138] Step 1-3: Select fields from the dataset.

[0139] Step 1-4: Unify the length and labels of the dataset.

[0140] Step 1-5: Generate a new dataset.

[0141] After preprocessing the data, transform the protocol data into matrix form, with each row representing a message and each column representing different features of the message, obtaining a data matrix , which is a data matrix composed of data, and each sample has

[0142] Step 2-1: Construct a similarity graph matrix based on the input data matrix ,

[0143] Step 2-2: Construct a Laplacian matrix based on the similarity graph matrix ,

[0144] Step 2-3: Perform eigen-decomposition on , extract the eigenvectors corresponding to the first smallest eigenvalues, and construct a spectral representation matrix ,

[0145] Step 2-4: Use K-means clustering to partition the spectral representation and obtain a clustering result ,

[0146] Step 2-5: Analyze and verify the clustering result

[0147] Optimize the spectral clustering graph construction algorithm as follows

[0148] For the original samples and , their similarity is . Project the original data from the original feature space to a low-dimensional feature subspace through a transformation matrix . At the same time, the local structure between the samples and in the low-dimensional space remains unchanged, and the mathematical representation is as follows

[0149] (1)

[0150]

[0151] When calculating the distance, the Bray-Curtis distance is used, and its formula is as follows

[0152] (2) Among them, , are the respective feature components of the vectors , .

[0153] Use an orthogonal constraint term to constrain the transformation matrix , and thus obtain the objective function of LPP as follows

[0154] (3)

[0155] Among them, , represents a diagonal matrix, is the identity matrix, is the orthogonal constraint used to generate uncorrelated spectral vectors, and the diagonal elements are equal to the sum of the row vectors of the similarity graph matrix .

[0156] That is , construct the Laplacian matrix using the hypergraph, and then use the hypergraph Laplacian matrix to constrain the spectral representation. Equation (3) is rewritten as:

[0157] (4)

[0158] where is a hypergraph Laplacian matrix

[0159] Embed the attribute selection into the subspace learning framework

[0160] (5)

[0161] where is a row-sparse matrix, and the non-negative number is a tuning parameter that balances subspace learning and attribute selection during the learning process. In the subsequent clustering process, adopt the spectral rotation clustering method, and embed the spectral rotation clustering into the spectral representation learning framework to complete one-step clustering. The objective function is as follows:

[0162]

[0163] (6)

[0164] where is the tuning coefficient

[0165] Solve the objective function formula (6)

[0166] First, initialize the indicator matrix , transformation matrix and the identity matrix . Subsequently, enter an iterative loop, which will continue to execute until the convergence criterion defined by formula (6) is satisfied

[0167] During this iterative process, the update of the transformation matrix follows the following three steps:

[0168] Step (1) starts an inner iterative loop, which will execute until the update of the transformation matrix satisfies the convergence condition specified by formula (7)

[0169] Step (2) in the inner loop, first update the transformation matrix according to formula (11), then the GPI framework updates the matrix , and finally update the matrix according to formula (13)

[0170] Step (3) These steps will be executed in a loop until the update of the transformation matrix reaches the convergence criterion set by Equation (7).

[0171] After the completion of the above inner loop, the matrix is updated according to Equation (15), and then the matrix is updated according to Equation (16). After completing these update steps, return to the outer iteration loop to continue updating the transformation matrix , until the convergence criterion defined by Equation (6) is satisfied. The entire iteration process continues until the update of the transformation matrix meets the convergence condition of the outer loop.

[0172] For the update of ,

[0173] When updating , it is necessary to fix and . Then, solving the objective function is equivalent to solving Equation (7).

[0174]

[0175] (7)

[0176] Using the framework of iterative weighted least squares to solve the non-smooth problem of Equation (7), Equation (7) becomes the following:

[0177]

[0178] (8)

[0179] where is the hypergraph diagonal matrix, and its diagonal elements are .

[0180] Adopting the alternating direction multiplicative operator framework to decompose the complex problem into multiple sub-problems that are easy to solve. Let Then Equation (8) becomes the following:

[0181]

[0182] (9)

[0183] After the above transformation, the optimization problem is converted into three sub-problems to be solved:

[0184] (10)

[0185] Needle needle , , is updated, set the value to 1, and set the derivative of to 0, then the closed - form solution of

[0186] is obtained:

[0187] while is updated directly through transformation:

[0188]

[0189] (12)

[0190] where ,

[0191] when and are calculated, the optimization of is carried out through formula (13): optimization of

[0192] (13)

[0193] For the update of ,

[0194] when updating , and need to be fixed, then the objective function becomes the following formula:

[0195]

[0196] (14)

[0197] is an indicator matrix, where the element has only two values, 0 and 1, is an approximation of , and the solution of formula (14) is as follows:

[0198] (15)

[0199] For the update of ,

[0200] when updating , and need to be fixed, then the objective function is equivalent to the following formula:

[0201]

[0202] (16)

[0203] Minimizing formula (16), after transformation, it is equivalent to:

[0204]

[0205] (17)

[0206] Then set and to be the left and right singular matrices of the singular value decomposition with respect to points respectively, that is:

[0207] (18)

[0208] Replace the non - orthonormal clustering index matrix with a standard - orthonormal scaling clustering index matrix to minimize the difference between the two standard - orthonormal matrices, obtaining the closed - form solution of :

[0209] (19).

[0210] Step 3 Optimize the graph structure of the spectral clustering result graph in Step 2 as follows:

[0211] For the data set processed in Step 2, define the probability that the th sample is connected to all data points as connected to a neighbor, and the probability is determined by the following formula:

[0212] (20)

[0213] Find a linear combination that is closest to the original features of the low - dimensional manifold, as follows:

[0214] (21)

[0215] Convene a constraint function , where is the number of connected components in the similarity graph matrix , and use the following formula to fit to the initial graph :

[0216] (22)

[0217] where is the updated Laplacian matrix, the initial graph is the graph obtained from step 3,

[0218] Using graph learning and sparse learning based on to solve the noise and outlier problems, as shown in the following equation:

[0219] (23)

[0220] where the constraint depends on , is the th eigenvalue of and when it is positive semi - definite, there is and the constraint function represents

[0221] (24)

[0222] Equation (23) is solved by the following formula:

[0223]

[0224] (25)

[0225] where and are non - negative tuning parameters, represents the characteristics of the feature space after regularization. By solving equation (25), a high - quality graph is obtained.

[0226] In step 4, a graph convolutional neural network model based on spectral clustering graph construction is built, and the optimized graph structure data in step 3 is input into the model for network protocol classification,

[0227] Using a hypergraph for semi - supervised classification of nodes, define an undirected hypergraph , where represents the vertices, represents the edges, and there is also a small set that marks the hyper - nodes, and each hyper - node is associated with a feature vector , where is the number of dimensions,

[0228] The key of is the Laplacian operator of the graph. The definition method of the Laplacian operator is as follows,

[0229] The calculation formula is as follows,

[0230] 1) For each hyper - edge , let ,

[0231] 2) Add the edge with weight to the vertex to construct a weighted graph , where is the weight of the hyperedge . Then add self-loops to each vertex so that the degree of the vertex in is equal to . Let denote the weighted adjacency matrix of .

[0232] 3) The symmetric normalized hypergraph Laplacian function is:

[0233] (26)

[0234] After obtaining the adjacency matrix and the feature matrix composed of all node features, perform graph convolution operations by passing and aggregating information between nodes through formula (27). Use a 3-layer GCN with randomly initialized weights to capture the structure of the entire graph, aggregate the node features in the last layer for classification, and finally use the global attention mechanism for output.

[0235] (27)

[0236] Among them, is the adjacency matrix of the undirected graph with self-connections added, is the identity matrix; is the trainable weight matrix specific to each layer; represents the activation function; is the activation matrix of the -th layer, and .

[0237] Set up simulation comparison experiments for the classification algorithm. Use two different classification methods other than the method: GNN and CNN to classify the same graph structure. Take the average value of the results in 20 iterations and compare the convergence of the objective function. As Figure 2 the process for training. During the training process, use all sample features X to construct the feature matrix. All sample features refer to all features in the graph structure established by the spectral clustering algorithm, and use 10%, 20%, 30%, 40%, and 50% of the labeled samples of three different models to construct and evaluate. In addition, select 10% of the samples as the validation set, and the remaining samples are used for testing.

[0238] The accuracy (ACC) is used as the evaluation metric for the experimental results, and its definition is as follows:

[0239] ,

[0240] where is the total number of samples, is the number of samples that can be correctly classified.

[0241] Table 2 Comparison of different graph construction methods and sample selection results

[0242]

[0243] Table 2 lists the average classification accuracies of three graph construction methods respectively. It can be seen that compared with other algorithms, S-GCN has better performance. When 10%, 20%, and 30% of the samples are selected as the training set on datasets with different graph structures, S-GCN is significantly better than the other three methods. In addition, it is not difficult to see that the accuracies obtained by selecting different sample ratios are different, and their accuracy relationships are as Figure 3 shown. When 30% of the samples are selected as the training set, S-GCN is better than the comparison methods, improving by 3.0% and 4.1% compared with KNN and CLR respectively.

[0244] The t-distributed Stochastic Neighbor Embedding (t-SNE) is used for dimensionality reduction visualization, and the clustering results are reduced to two dimensions for visualization. As Figure 4 shows, the 2D t-SNE visualizations performed by different methods are presented, and different colors are used to identify different classes. It can be seen that in the convolutional layer feature representation of S-GCN, the same classes are closely connected, while different classes are clearly separated.

[0245] As Figure 5 shows the convergence curve of the objective function value. The value of the objective function is monotonically decreasing until the proposed algorithm converges. In addition, the proposed objective function converges within 20 iterations, and the convergence speed is also faster than the other two methods. Therefore, the rapid convergence of the objective function proves the effectiveness of the method.

[0246] It should be noted that the above embodiments are not used to limit the protection scope of the present invention, and equivalent transformations or substitutions made on the basis of the above technical solutions all fall within the protection scope of the claims of the present invention.

Claims

1. A graph convolutional neural network protocol classification method based on spectral clustering composition, characterized in that: The following steps are involved: Step 1: Filter out key fields from all network protocols from the physical layer to the application layer in the data set to generate a new data set; Step 2: Combine subspace learning and attribute selection to optimize the traditional spectral clustering algorithm, and construct the data set processed in step 1 using the optimized spectral clustering algorithm; Step 3: Optimize the graph structure of the spectral clustering result graph in step 2; Step 4: Build a graph convolutional neural network model based on spectral clustering, and input the graph structure data optimized in step 3 into the model for network protocol classification; Among them, step 3 is as follows: The data set X after step 2 is processed as follows: n }, define the probability of the i-th sample and all data points as s ij Connect to x i A neighbor of ij Determined by the following formula: Find a linear combination that is closest to the original features of the low-dimensional manifold, as follows: Agree on a constraint function (L S ) = nc, where c is the number of connected components in the similarity graph matrix S, and the following formula is used to fit S to the initial graph A: Where L S is the updated Laplacian matrix, the initial graph is the graph obtained from step 3, Using graph learning and l-based 2,1 -norm sparse learning can solve the noise and outlier problems, as shown below: The constraint (L S ) = nc depends on S, σ i (L S ) is L S The i-th eigenvalue of is semi-positive definite, with σ i (L S )>0 and the constraint function (L S )=nc means Then from Fan Ji's theorem we get: Formula (23) is solved by the following formula: where τ is a non-negative tuning parameter, W T W=I represents the characteristics of the feature space after reduction. By solving formula (25), a high-quality graph is obtained.

2. According to claim 1, a graph convolutional neural network protocol classification method based on spectral clustering composition is characterized in that: In step 1: In the original data set, the message contains all fields from the physical layer to the application layer. The data set needs to be processed and the key fields need to be filtered. Step 1-1, split the data set into traffic segments. Step 1-2: perform traffic redundancy removal on the data set. Step 1-3, select fields from the data set. Steps 1-4, unify the dataset length and labels, Steps 1-5, generate a new dataset.

3. According to claim 1, a graph convolutional neural network protocol classification method based on spectral clustering composition is characterized in that: In step 2: After preprocessing the data, the protocol data is converted into a matrix form, where each row is a message and each column is a different feature of the message, and the data matrix X∈R is obtained. n×d , a data matrix consisting of n data, each sample has d features, and the spectral clustering composition algorithm is used for composition, as follows: Step 2-1: Construct a similarity graph matrix S based on the input data matrix. Step 2-2: Construct the Laplace matrix L based on the similarity graph matrix. Step 2-3: Perform eigendecomposition on L, extract the eigenvectors corresponding to the first k smallest eigenvalues, and construct the spectral representation matrix F. Step 2-4: Use K-means clustering to divide the spectral representation and obtain clustering results C1, C2, ..., C k , Step 2-5: Analyze and verify the clustering results.

4. According to claim 3, a graph convolutional neural network protocol classification method based on spectral clustering composition is characterized in that: The spectral clustering graph construction algorithm is optimized as follows: For the original sample x i and x j , whose similarity is S i,j , the original data is projected from the original feature space to the low-dimensional feature subspace through the transformation matrix W. At the same time, the sample x in the low-dimensional space l W and x j The local structure between W remains unchanged, which can be expressed as: Among them, σ 2 is the parameter of the Gaussian kernel. Bray-Curtis distance is used to calculate the distance. The formula is as follows: Among them, x i ,y i Divided into the characteristic components of vectors x and y, The orthogonal constraint term is used to constrain the transformation matrix W, and the objective function of the LPP is obtained as follows: in, D represents the diagonal matrix, I is the unit matrix, W T X T XW=I is an orthogonal constraint used to generate uncorrelated spectral vectors, and the diagonal elements are equal to the sum of the row vectors of the similarity graph matrix S. Right now The Laplacian matrix is ​​constructed using a hypergraph, and then the hypergraph Laplacian matrix is ​​used to constrain the spectrum. Formula (3) is rewritten as: Among them, L H is a hypergraph Laplacian matrix, Embedding attribute selection into the subspace learning framework, Among them, ||W|| 2,1 is a row sparse matrix, and the non-negative number β is a tuning parameter that balances subspace learning and attribute selection during the learning process. In the subsequent clustering process, the spectral rotation clustering method is used to embed the spectral rotation clustering into the spectral representation learning framework to complete one-step clustering. The objective function is as follows: Among them, α is the tuning coefficient, Solve the objective function formula (6) First, the indicator matrix Y, the transformation matrix W, and the identity matrix R are initialized. Then, an iterative loop is entered, which will continue to execute until the convergence criterion defined by formula (6) is met. During this iteration, the update of the transformation matrix W follows the following three steps: Step (1) starts an inner iteration loop that will execute until the update of the transformation matrix W satisfies the convergence condition specified by formula (7), In the inner loop of step (2), the transformation matrix W is first updated according to formula (11), then the GPI framework updates the matrix Z, and finally the matrix U is updated according to formula (13). Step (3) These steps will be executed repeatedly until the update of the transformation matrix W reaches the convergence criterion set by formula (7). After the above inner loop is completed, the Y matrix is ​​updated according to formula (15), and then the R matrix is ​​updated according to formula (16). After completing these update steps, return to the outer iteration loop and continue to update the transformation matrix W until the convergence criterion defined by formula (6) is met. The entire iteration process continues until the update of the transformation matrix W meets the convergence condition of the outer loop. Update on W, When updating W, it is necessary to fix Y and R. Then solving the objective function is equivalent to solving formula (7). The non-smooth problem of formula (7) is solved by using the framework of iterative weighted least squares, and then formula (7) becomes the following: Where P is a hypergraph diagonal matrix, whose diagonal elements are The alternating direction multiplication operator framework is used to decompose the complex problem into multiple easily solvable sub-problems. If XW = Z, then formula (8) becomes the following: After the transformation of the above formula, the optimization problem is converted into three sub-problems to be solved: For W (t+1) , Z (t+1) , U (t+1) Update, set the λ value to 1, and set the derivative of W to 0, that is, W (t+1) The closed solution is: W=(βP+X T X) -1 (X T Z+X T U) (11) And Z (t+1) The update is achieved directly through the transformation: Where B = YR + λXW - λU, After calculating W and Z, the optimization of U is obtained, and U is optimized by formula (13): U (t+1) =U (t) +Z (t+1) -XW (t+1) (13) Updates to Y, When updating Y, R and W need to be fixed, and the objective function becomes the following formula: Y is an indicator matrix, where the elements y i,j There are only two values, 0 and 1, and XWR is an approximation of Y. The solution of formula (14) is as follows: Update for R, Updating R requires fixing W and Y, so the objective function is equivalent to the following formula: Minimize formula (16), which is equivalent to: Suppose M and N are respectively T X T The left and right singular matrices of the singular value decomposition of point Y are: W T X T Y=V∑D T (18) The non-orthogonal clustering indicator matrix is ​​replaced by the orthogonal scaling clustering indicator matrix to minimize the difference between the two orthogonal matrices and obtain the closed-form solution of R: R=VD T (19)。 5. According to claim 1, a graph convolutional neural network protocol classification method based on spectral clustering composition is characterized in that: In step 4, a graph convolutional neural network model based on spectral clustering is constructed, and the graph structure data optimized in step 3 is input into the model for network protocol classification. Use hypergraphs for semi-supervised classification of nodes. Define an undirected hypergraph H = (V, E), where V represents vertices, E represents edges, and there is also a small set V of labeled hypernodes. L , each supernode is associated with a feature vector Where p is the number of dimensions, the key to GCN is the graph Laplace operator, the definition of Laplace operator is as follows, The calculation formula is as follows: 1) For each hyperedge e∈E, let (i e , j e ):=argmax i,j∈e |S i -S j |, 2) Set the weight to w({i e , j e ]):=w(e)'s edge {{i e , j e }: e∈E} is added to the vertex V to construct a weighted graph G S , where w(e) is the weight of the hyperedge e, and then add a self-loop on each vertex V so that the vertex in G S The degree in is equal to d v , let A s Represents G S The weighted adjacency matrix of 3) The symmetric normalized hypergraph Laplace function is: After obtaining the adjacency matrix and the feature matrix composed of all node features, the aggregation information is transferred between nodes through formula (27) to perform graph convolution operation. A three-layer GCN with randomly initialized weights is used to capture the structure of the entire graph. In the last layer, the node features are aggregated for classification, and finally a global attention mechanism is used for output. in, is the adjacency matrix of the undirected graph G with self-connection added, I N is the unit matrix; W (l) is a layer-specific trainable weight matrix; σ(·) represents the activation function; is the activation matrix of layer l, and H (0) =X.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the graph convolutional neural network protocol classification method based on spectral clustering composition is implemented as described in any one of claims 1 to 5 above.

7. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instruction is executed by the processor, the graph convolutional neural network protocol classification method based on spectral clustering composition is implemented as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Unknown protocol clustering analysis method and device based on spectral clustering and medium

    CN114118255A