Gigabit Ethernet Device Fingerprint Classification Method Based on Generalized Extreme Value Distribution Compensation
Through the generalized extreme value distribution compensation method, combined with SMOTE and SVM, the accuracy and efficiency problems of Ethernet fingerprint technology under environmental changes are solved, and the fast and accurate classification of gigabit Ethernet devices is achieved.
Patent Information
- Application Number
- CN202411745553.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-02
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-12-02
AI Technical Summary
When faced with environmental changes, especially the influence of factors such as temperature, humidity and power supply fluctuations, existing Ethernet fingerprint technology leads to deviations in fingerprint characteristics, affecting the accuracy and efficiency of authentication, and the data acquisition process is complex, and time delay affects real-time.
The method based on generalized extreme value distribution compensation is adopted, and data enhancement and undersampling are performed through the SMOTE algorithm. The fingerprint classifier is trained in combination with the SVM support vector machine, and iterative compensation is used to use historical and current data to correct fingerprint distribution deviations and improve the robustness of the classifier.
It improves the accuracy and speed of fingerprint classification of Gigabit Ethernet devices, reduces data acquisition time, enhances the training efficiency of classification models, adapts to changes in physical characteristics of network devices, and resists environmental influences.
Smart Images

Figure CN119229482B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of wireless positioning, and particularly to a method for classifying fingerprints of gigabit Ethernet devices based on generalized extreme value distribution compensation. Background Art
[0002] The popularization of Ethernet communication technology has made the network one of the infrastructures of modern society. With the rapid development of the Internet of Things (IoT), more and more devices are connected to the network, and the security authentication issues of these devices have become particularly important. Although traditional authentication mechanisms based on MAC (Media Access Control Address) addresses and digital certificates provide security guarantees to a certain extent, they have obvious security flaws. MAC addresses are easily copied or forged by malicious users through technical means, and digital certificates may also be subject to man-in-the-middle attacks, resulting in the failure of identity authentication.
[0003] To address these security threats, new device authentication technologies have been explored in the prior art. As an emerging authentication method, Ethernet fingerprint technology realizes identity authentication by analyzing the physical layer characteristics of network devices. Existing research shows that the fingerprints composed of physical layer features are unique in different network cards. Even for communication devices of the same model, the same manufacturer, and the same series, there are slight differences in fingerprints. The fingerprints of 10M rate negotiation signals in 100M Ethernet can be extracted by correlating the symbol differential trajectory diagram and the signal amplitude distribution histogram, and the fingerprints can be identified using the naive Bayes algorithm, SVM, and deep learning methods respectively, or the fingerprints of 1000M Ethernet signals can be extracted using the Adjacent Constellation Trance Figure (ACTF) method and identified using a convolutional neural network, achieving recognition rates of 96.29% and 99.49% respectively at signal-to-noise ratios of 10dB and 30dB.
[0004] Existing research shows that Ethernet fingerprint technology is affected by time factors, and its accuracy will decrease over time. This is because the physical characteristics of network devices may change due to factors such as temperature, humidity, and power fluctuations, resulting in deviations in fingerprint features. It is necessary to design robust algorithms and models to resist the impact of environmental changes on fingerprints. In addition, the process of collecting Ethernet fingerprints is relatively complex and requires a long time to collect enough data to train the classification model. In a rapidly changing network environment, this time delay may affect the real-time performance and efficiency of authentication. To improve the speed of fingerprint collection and the training efficiency of the classification model, it is necessary to design lightweight algorithms and models to reduce the pressure of collecting data. Summary of the Invention
[0005] Technical objective: Aiming at the defects in the prior art, the present invention discloses a gigabit Ethernet device fingerprint classification method based on generalized extreme value distribution compensation. The compensation method based on the generalized extreme value distribution can adapt to the physical characteristic changes of network devices caused by factors such as time and power fluctuations, thereby resisting the influence of environmental changes on fingerprints.
[0006] Technical solution: To achieve the above technical objective, the present invention adopts the following technical solutions.
[0007] A gigabit Ethernet device fingerprint classification method based on generalized extreme value distribution compensation, the method includes:
[0008] Obtain the historical data basic fingerprints of several gigabit Ethernet devices from the historical database; several historical data of gigabit Ethernet devices are stored in the historical database, and the several historical data constitute a historical data basic data set. Fingerprint extraction is performed on the historical data basic data set to obtain historical data basic fingerprints;
[0009] Collect several current data of the gigabit Ethernet device, and process the current data through the acquisition method of the historical data basic fingerprint to obtain the current data basic fingerprint;
[0010] Use the SMOTE algorithm to synthesize the minority oversampling technique to enhance the data of the current data basic fingerprint;
[0011] After randomly sampling and undersampling the historical data basic fingerprints, add the current data basic fingerprints to obtain a new and old data mixed fingerprint library;
[0012] Based on the new and old data mixed fingerprint library after fitting with the generalized extreme value distribution, use the SVM support vector machine method to train the fingerprint classifier to obtain a robust fingerprint classifier for subsequent fingerprint classification.
[0013] Beneficial effects:
[0014] 1. The robust gigabit Ethernet device classification method designed by the present invention, based on the compensation method of the generalized extreme value distribution, can adapt to the physical characteristic changes of network devices caused by factors such as time and power fluctuations, thereby resisting the influence of environmental changes on fingerprints. This method compensates the fingerprint distribution through multiple iterations, corrects the deviation of the Ethernet fingerprint over time, and improves the accuracy of fingerprint classification.
[0015] 2. Improving the time for training the gigabit Ethernet device classifier based on data augmentation methods: By combining old data with new data to train the classifier simultaneously and using the SMOTE oversampling method to expand the fingerprint dataset, the fingerprint acquisition time is reduced. At the same time, lightweight algorithms and models reduce the pressure of collecting data, improve the fingerprint acquisition speed and the training efficiency of the classification model, thereby improving the overall processing speed.
[0016] 3. Based on the DPC algorithm, combining the clustering density of sub-clusters for fitting the mixed-class undersampling distribution, while retaining the intra-class aggregation characteristics, quickly fitting the distribution characteristics of the old distribution, improving the iterative speed of distribution compensation, and reducing the generation time of the generated mixed training set. Brief Description of the Drawings
[0017] Figure 1 Schematic diagram of the structure of the gigabit Ethernet device signal acquisition system of the present invention;
[0018] Figure 2 Flowchart of the method of the present invention. Detailed Embodiments
[0019] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0020] As shown in the attached Figure 2 As shown, a method for classifying fingerprints of gigabit Ethernet devices based on generalized extreme value distribution compensation in this embodiment includes the following steps:
[0021] S1. Obtain the historical data basic fingerprints of several gigabit Ethernet devices from the historical database; the historical database stores several historical data of gigabit Ethernet devices, and the several historical data constitute the historical data basic dataset. Extract fingerprints from the historical data basic dataset to obtain the historical data basic fingerprints; after preprocessing, feature extraction, and LDA dimensionality reduction of the historical data basic dataset, obtain the historical data basic fingerprints;
[0022] For the historical data of each gigabit Ethernet device in the historical data basic dataset, intercept it into several signal sequences according to a preset length, and perform preprocessing, feature extraction, and LDA dimensionality reduction on all signal sequences to obtain several device fingerprints as the historical data basic fingerprints; that is to say, for each gigabit Ethernet device, fingerprint information at different time periods can be obtained.
[0023] Among them, preprocessing is performed on all signal sequences, including: successively performing DC removal processing and power normalization processing on all signal sequences. Among them, the DC removal processing includes: subtracting the average value of the signal sequence from the signal sequence to obtain the signal sequence after DC removal; the power normalization processing includes: dividing the signal sequence after DC removal by its standard deviation to obtain the signal sequence after power normalization, and finally realizing the standardization of all signal sequences.
[0024] In this embodiment, a number of historical data of the Gigabit Ethernet device are obtained by constructing a Gigabit Ethernet device signal acquisition system, as Figure 1 shown. The Gigabit Ethernet device signal acquisition system includes three external access terminals, multiple Gigabit Ethernet network cards, a Gigabit Ethernet switch, an Ethernet signal transfer board, and three SMA interfaces. The three external access terminals can be desktop computers, laptops, etc.; the multiple Gigabit Ethernet network cards serve as the fingerprint sources of the Gigabit Ethernet device. Multiple Gigabit Ethernet network cards can be plugged into the Gigabit Ethernet device, and each Gigabit Ethernet network card has its own device fingerprint; the Gigabit Ethernet network card is a PCIE or USB network card; a Gigabit Ethernet switch, as a unified terminal device and also a Gigabit Ethernet classification system, is used to classify the received device fingerprint information. The Ethernet signal transfer board is connected to the Gigabit Ethernet device with two RJ45 interfaces, and the three SMA interfaces are used as outputs and connected to an oscilloscope to collect the Gigabit Ethernet signals of the Gigabit Ethernet network cards in the Gigabit Ethernet device. When a user uses the Gigabit Ethernet device, the signal passes through the transfer board and is collected by the oscilloscope. The oscilloscope inputs the collected signal into the processor, extracts the signal fingerprint, and collects the terminal device fingerprint library. After the fingerprint library is generated, the processor controls the oscilloscope to regularly collect the Gigabit Ethernet device signals, extracts the fingerprints, and determines the identity of the Gigabit Ethernet device through the switch. For an unknown device, the communication link of the device is disconnected by controlling the switch port.
[0025] Using the Gigabit Ethernet signal acquisition system, the transmission signals of multiple Gigabit Ethernet network cards are collected; the historical database in this embodiment stores 4 days of historical data to form a historical data basic data set. The historical data of each Gigabit Ethernet device are intercepted into several signal sequences according to a preset length. The following elaborates on the processing process of a signal sequence of a Gigabit Ethernet device:
[0026] Define a signal sequence of a Gigabit Ethernet device as , is the th signal in the signal sequence , , represents the length of the signal sequence,
[0027] When performing signal acquisition, problems such as DC offset and power differences among different devices are often encountered. The DC offset is not part of the signal characteristics and may interfere with subsequent processing. To eliminate this interference, it is necessary to perform DC removal on the signal sequence That is, subtract its average value from the signal. The calculation method for DC removal is as follows:
[0028] ,
[0029] where, is the signal sequence after DC removal, is the th signal in;
[0030] At the same time, the power differences among different devices will also affect the effect of signal processing. To solve this problem, power normalization technology can be adopted, that is, divide each value of the signal by its standard deviation to achieve signal standardization. The calculation method for power normalization is:
[0031] ,
[0032] where, is the signal sequence after power normalization. Through these steps, the accuracy and consistency of signal processing can be ensured, and the power-normalized signal sequence can improve the quality of signal processing.
[0033] The power-normalized signal sequence is time-series data. For the truncated average spectrum of the power-normalized signal sequence , as a relatively stable random signal of the device fingerprint, analyze the relationship between its correlation function and power spectrum for spectral analysis, and perform feature extraction by calculating its power spectrum. The process of feature extraction includes:
[0034] Within a finite time interval , consider a truncated signal of the stationary power-normalized signal sequence , and its discrete Fourier transform is:
[0035] ,
[0036] where, is the discrete sequence obtained by the discrete Fourier transform of the truncated signal , is the index of frequency, is the length of the discrete sequence ;
[0037] Determine the time interval length T according to the length of the signal sequence after power normalization. For each signal sequence after power normalization , divide it into Z signal groups, and each signal group includes L truncated signals ; finally, calculate all discrete sequences and their average power spectra to obtain the device power spectrum set. In one embodiment, Z is 100 and L is 50. Correspondingly, the discrete sequence 's power spectrum is defined as:
[0038] ,
[0039] Since the random signal has multiple possible implementation forms, after taking the absolute value of the square of and dividing by 2T, take one signal group , where L is the number of truncated signals in the signal group, and calculate the average power spectrum of the signal group :
[0040] ,
[0041] where, represents the average value calculation; by this method, obtain the device power spectrum fingerprint set , where, is the average power spectrum calculated for the Z-th signal group; is 's matrix representation form, and Z is the number of signal groups.
[0042] Use Linear Discriminant Analysis (LDA) to reduce the dimension of the obtained power spectrum fingerprints. The specific steps are as follows:
[0043] For each device category, calculate the scatter matrix of its fingerprint samples, where the samples refer to each average power spectrum. The scatter matrix measures the differences between samples within the same category. For a gigabit Ethernet fingerprint data set with Ethernet device categories, the within-class scatter matrix and the between-class scatter matrix of the -th category are respectively defined as:
[0044] ,
[0045] where, is the device power spectrum fingerprint set of the -th category, , is the number of Ethernet device categories; is the The sample mean of the device power spectrum fingerprints of each category, is the number of samples in the set of device power spectrum fingerprints of the ith category; the sample mean of the set of device power spectrum fingerprints of all categories;
[0046] To find the optimal dimensionality reduction direction, the following generalized eigenvalue problem needs to be solved:
[0047] ,
[0048] where, is the eigenvector, is the between-class scatter matrix corresponding eigenvalue;
[0049] Solving this formula gives a series of eigenvalues and corresponding eigenvectors. In the order of eigenvalues from largest to smallest, select the eigenvectors corresponding to the first d largest eigenvalues. These eigenvectors form a matrix V. Project the original data onto the selected eigenvectors, that is, the eigenvectors corresponding to the first d largest eigenvalues, to achieve dimensionality reduction; for the original data set, that is, each fingerprint sample in the set of device power spectrum fingerprints , its representation after dimensionality reduction is , which can be calculated by the following formula:
[0050] ,
[0051] where, is the transpose matrix of the selected eigenvector. In this way, the representation of the gigabit Ethernet signal fingerprint after dimensionality reduction is obtained, and further the set of device power spectrum fingerprints after dimensionality reduction is obtained.
[0052] S2. Collect several pieces of current data of gigabit Ethernet devices, and process the current data through the method of obtaining historical data base fingerprints to obtain current data base fingerprints. Perform the same method of preprocessing, feature extraction, and LDA dimensionality reduction on the current data to obtain current data base fingerprints;
[0053] S3. Use the SMOTE algorithm to synthesize the minority oversampling technique to enhance the current data base fingerprints and generate new samples to solve the problem of insufficient number of samples in the minority class of data;
[0054] Since the number of newly collected fingerprints is small, the ratio of the current data base fingerprints to the historical data base fingerprints is 1:9; the Synthetic Minority Over-sampling Technique (SMOTE) algorithm is used to perform data augmentation on the newly collected fingerprints. SMOTE is an unsupervised learning algorithm for dealing with class imbalance problems in datasets. It achieves sample balance by generating new sample points between minority class samples. The specific steps are as follows:
[0055] (1)Determine the neighborhood of each newly collected sample in the current data base fingerprints: For each sample in the current data base fingerprints , use the K-nearest neighbor algorithm to determine its M nearest neighbor samples;
[0056] (2)Calculate the imbalance degree of the sample set: According to the ratio q of the newly collected samples to the old data, randomly select q neighborhood samples from the M nearest neighbor samples of each newly collected sample;
[0057] (3)Generate new sample points: For each newly collected sample, based on the selected q neighborhood samples, generate new samples through linear interpolation. If an original newly collected sample is , and a randomly selected neighborhood sample is , then the generation formula for the new sample is: , where is a number randomly selected from the interval [0, 1]. Thus, the augmented set of device power spectrum fingerprints is obtained, where R is the number of augmented power spectrum fingerprints.
[0058] S4. After randomly undersampling the historical data base fingerprints and adding them to the current data base fingerprints, a mixed fingerprint database of old and new data is obtained. To compensate for the offset caused by the time change of the new data, the distribution of the old data and the mixed distribution of the old and new data are calculated based on the generalized extreme value distribution. Based on the difference between the old data distribution and the mixed distribution of the old and new data, a method of multiple random sampling is adopted to compensate for the distribution, so that the old data fingerprint distribution is successfully fitted to the new data fingerprint distribution. The undersampling process is as follows:
[0059] Let be a sequence of independent and identically distributed samples in the current data base fingerprints that follow the distribution F, , if there exists a sequence of constants such that:
[0060] holds, then follows the following distribution:
[0061] ,
[0062] Among them, is a location parameter, is a scale parameter, is a scale parameter, is a location parameter, is called the extreme value index. Based on the maximum likelihood estimation method, the maximum likelihood estimation is performed on the generalized extreme value distribution eigenvalues of the old data fingerprints to obtain the location parameter of the generalized distribution, the scale parameter and the extreme value index ;
[0063] S41. Perform undersampling on the old data; assume that the old data samples are divided into F sub-clusters ; Based on the DPC algorithm, that is, the density peak clustering algorithm, quickly find the clustering density of each sub-cluster, aiming to strengthen the local region features of each sub-cluster and remove noise points. The local region feature of the i-th sub-cluster is calculated as follows:
[0064] ,
[0065] Among them, is the distance between samples , , is the truncation distance, that is, the search radius of the neighborhood. The function is defined as ; It is easy to obtain that the local density , that is, the number of sample points whose distance from the sample is less than or equal to .
[0066] The density and the sampling weight of each sub-cluster are defined as:
[0067] ,
[0068] Among them, is the number of Ethernet device categories; Use the sampling weight to perform undersampling on the sub-clusters to obtain the undersampled sub-cluster The expression is:
[0069] ,
[0070] S42. Mix the undersampled fingerprint data with the new fingerprint data, and calculate the generalized extreme value distribution eigenvalues of the mixed fingerprint data, including the location parameter of the generalized distribution, the scale parameter , extreme value index ; Define the difference function to measure the difference between the new and old data:
[0071] ,
[0072] wherein, , are the extreme value index of the new data and the extreme value index of the old data respectively, , are the scale parameter of the new data and the scale parameter of the old data respectively, are the location parameters of the new data and the old data respectively;
[0073] S43. Given a threshold , if , it is considered that there is no significant difference in the distribution characteristics between the new data and the old data; if the difference is greater than or equal to the threshold , randomly sample the mixed data to obtain a new subset; randomly draw samples of the compensation parameter from the target distribution:
[0074] ,
[0075] wherein, p is abstracted as the random sampling process. In one embodiment, according to the ratio of the old data to the new data, the sampling ratio is set to 90%, are the extreme value index, scale parameter, and location parameter of the distribution after random sampling respectively;
[0076] For each sampling, calculate the new difference function , if the threshold condition is not met, divide the sample set into GROUP1 and GROUP2, and calculate and , which are the difference functions calculated from the sample set GROUP1, the sample set GROUP2 and the old data respectively; select and the smaller one of them as the new distribution ,
[0077] S44. Calculate the generalized extreme value distribution characteristic value again, and repeat the above steps, that is, S42 to S44, until is satisfied.
[0078] S5. Based on the mixed fingerprint database of the new and old data after fitting with the generalized extreme value distribution, use the SVM support vector machine method to train the fingerprint classifier to obtain a robust fingerprint classifier for subsequent fingerprint classification.
[0079] The robust gigabit Ethernet device classification method designed by the present invention, a compensation method based on the generalized extreme value distribution, can adapt to the physical characteristic changes of network devices caused by factors such as time and power fluctuations, thereby resisting the impact of environmental changes on fingerprints. This method compensates the fingerprint distribution through multiple iterations, corrects the deviation of Ethernet fingerprints over time, and improves the accuracy of fingerprint classification.
[0080] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for classifying gigabit Ethernet device fingerprints based on generalized extreme value distribution compensation, characterized in that The method includes: Obtaining historical data basic fingerprints of several Gigabit Ethernet devices from a historical database; the historical database stores several historical data of Gigabit Ethernet devices, and the several historical data constitute a historical data basic dataset. Fingerprint extraction is performed on the historical data basic dataset to obtain historical data basic fingerprints; Collecting several current data of Gigabit Ethernet devices, and processing the current data through the obtaining method of historical data basic fingerprints to obtain current data basic fingerprints; Using the SMOTE algorithm (Synthetic Minority Over-sampling Technique) to perform data enhancement on the current data basic fingerprints; The processing process of the SMOTE algorithm includes: Determine the neighborhood of each newly collected sample in the current data base fingerprint: For each sample in the current data base fingerprint , use the K-nearest neighbor algorithm to determine its M nearest neighbor samples; Calculating the imbalance degree of the sample set: According to the ratio q of the newly collected samples to the old data, randomly select q neighborhood samples from the M nearest neighbor samples of each newly collected sample; For each newly collected sample, based on the selected q neighborhood samples, generate new samples through linear interpolation; After randomly extracting and under-sampling the historical data basic fingerprints, add the current data basic fingerprints to obtain a new and old data mixed fingerprint database; Based on the new and old data mixed fingerprint database after fitting with the generalized extreme value distribution, use the SVM (Support Vector Machine) method to train a fingerprint classifier to obtain a robust fingerprint classifier for subsequent fingerprint classification.
2. The fingerprint classification method for gigabit Ethernet devices based on generalized extreme value distribution compensation according to claim 1, wherein: The fingerprint extraction process includes: preprocessing the dataset, feature extraction, and LDA (Linear Discriminant Analysis) dimensionality reduction to obtain device fingerprints. The dataset contains several data of several Gigabit Ethernet devices. The several data of each Gigabit Ethernet device in the dataset are intercepted into several signal sequences according to a preset length. For each signal sequence, preprocessing, feature extraction, and LDA dimensionality reduction are performed to obtain several device fingerprints of several devices.
3. A method for classifying fingerprints of gigabit Ethernet devices based on generalized extreme value distribution compensation according to claim 2, characterized in that, The preprocessing process includes: A signal sequence for a Gigabit Ethernet device is , is the th signal in the signal sequence . , represents the length of the signal sequence. The signal sequence is processed to remove DC. The calculation formula includes: , Among them, is the signal sequence after removing the DC component, is the th signal in Performing power normalization calculation on the signal sequence after removing the direct current. The calculation formula includes: , Among them, is the signal sequence after power normalization.
4. A method for classifying gigabit Ethernet device fingerprints based on generalized extreme value distribution compensation according to claim 2, characterized in that, The process of feature extraction includes: for each preprocessed signal sequence , determining the time interval length T, dividing it into Z signal groups, and each signal group includes L truncated signals , and finally calculating all discrete sequences and their average power spectra to obtain the device power spectrum set; The calculation formula for the discrete sequence is: , wherein, is a discrete sequence obtained by performing a discrete Fourier transform on a truncated signal , is the index of frequency is the length of the discrete sequence , represents the length of the signal sequence, and the power spectrum of the discrete sequence is calculated by the formula: , Take a signal group , where L is the number of truncated signals in the signal group, and calculate the average power spectrum of the signal group : , Among them, represents the average value calculation; by this method, the device power spectrum fingerprint set is obtained , where is the average power spectrum calculated for the Z-th signal group; is the matrix representation form of.
5. A method for classifying fingerprints of gigabit Ethernet devices based on generalized extreme value distribution compensation according to claim 2, characterized in that, The LDA dimensionality reduction process includes: For a gigabit Ethernet fingerprint dataset with Ethernet device categories, the within-class scatter matrix and between-class scatter matrix of the th category are respectively defined as: , Among them, is the set of device power spectrum fingerprints of the th category, , where is the number of Ethernet device categories; is the sample mean of the device power spectrum fingerprints of the th category device, is the sample size of the set of device power spectrum fingerprints of the th category, and is the sample mean of the set of device power spectrum fingerprints of all categories; The calculation formulas for eigenvalues and eigenvectors include: , Among them, is the eigenvector, is the between-class scatter matrix corresponding eigenvalue; Solving this formula yields a series of eigenvalues and corresponding eigenvectors. In the order of eigenvalues from largest to smallest, select the eigenvectors corresponding to the top d largest eigenvalues. These eigenvectors form a matrix V. Project the original data onto the selected eigenvectors, that is, the eigenvectors corresponding to the top d largest eigenvalues, to achieve dimensionality reduction; for each fingerprint sample in the device power spectrum fingerprint set , its representation after dimensionality reduction is , and the calculation formula is: , Among them, is the transpose matrix of the selected eigenvector, obtaining the set of device power spectrum fingerprints after dimensionality reduction .
Citation Information
Patent Citations
Network intrusion detection method and system based on mixed sampling
CN111314353A