Inter-Domain Routing Anomaly Detection Method and System Based on Transformer Model
Through the inter-domain routing anomaly detection method based on the Transformer model, a dynamic BGP network topology is constructed and combined with Simhash and GCN frameworks, the existing BGP anomaly detection methods in real-time and accuracy are solved, and efficient abnormal detection and traceability analysis of the BGP network is realized.
Patent Information
- Application Number
- CN202411758137.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-12-03
AI Technical Summary
The existing BGP anomaly detection methods are insufficient in terms of real-time and accuracy, and cannot effectively deal with the bias and incompleteness of observed data, dynamic changes in BGP routing behavior, and the challenges of large-scale BGP networks.
The inter-domain routing anomaly detection method based on the Transformer model is adopted. By constructing a dynamic BGP network topology, the AS node feature information is extracted, the fingerprint information of the graph model is calculated using Simhash, and the abnormal detection model is constructed in combination with Transformer and GCN framework to perform inter-domain routing anomaly detection.
It improves the accuracy and real-time nature of abnormal detection, can accurately capture the behavioral information of AS in dynamic BGP network, reduces complexity and improves the processing ability of incomplete information, and enhances the accuracy of abnormal detection and traceability.
Smart Images

Figure CN119254533B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of inter-domain anomaly detection in inter-domain routing security, and particularly relates to an inter-domain routing anomaly detection method based on a Transformer model. Background Art
[0002] The Border Gateway Protocol (BGP) is a routing protocol for autonomous systems running on TCP. BGP anomaly detection detects anomalies by actively and passively obtaining routing data, and further locates suspicious routing information (prefixes, ASes, etc.), enabling operation and maintenance personnel to quickly trace and mitigate anomalies. Such methods usually use a large amount of BGP historical routing data, analyze historical BGP routing behavior rules and patterns as prior knowledge, detect BGP routing messages sent by ASes, and effectively identify and trace BGP anomalies.
[0003] However, there is still much room for improvement in the real-time performance, accuracy, and intelligence of existing anomaly detection methods. Facing many challenges such as the bias and incompleteness of observed data, the dynamic changes of BGP routing behavior, and large-scale BGP networks, existing methods cannot achieve both real-time performance and accuracy. Therefore, it is necessary to conduct research on BGP anomaly detection and tracing mechanisms, monitor the global BGP operation status in real time, and conduct tracing analysis to ensure the security of the national inter-domain network. Summary of the Invention
[0004] The present invention addresses the challenges faced by existing anomaly detection methods, including the bias and incompleteness of the collected data; the dynamic changes of BGP routing behavior; and the fact that the BGP network is a distributed system with a large scale.
[0005] An object of the present invention is to provide an inter-domain routing anomaly detection method based on a Transformer model, aiming to solve at least one of the technical problems to a certain extent.
[0006] Another object of the present invention is to provide an inter-domain routing anomaly detection system based on a Transformer model.
[0007] To achieve the above object, on the one hand, the present invention provides an inter-domain routing anomaly detection method based on a Transformer model, including:
[0008] Collecting BGP routing data based on collection points to construct a dynamic BGP network topology;
[0009] Extracting subgraphs of each AS node in the BGP network topology and extracting relevant feature information to obtain a graph model;
[0010] Based on the graph model with relevant feature information, calculate the fingerprint information of the graph model based on Simhash;
[0011] According to the fingerprint information obtained at the previous and current moments, use the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection.
[0012] A further preferred technical solution of the present invention is that the BGP routing data is collected based on the collection points to construct a dynamic BGP network topology; specifically:
[0013] Collect BGP routing data based on global collection points, including BGP routing table data and BGP routing update data;
[0014] Construct a global routing topology according to the BGP routing table data;
[0015] Then, according to the BGP routing update data at the current moment, update the global routing topology to obtain the BGP network topology at the current moment.
[0016] Preferably, extract the subgraphs of each AS node in the BGP network topology and extract relevant feature information to obtain a graph model; specifically:
[0017] Traverse each AS node in the BGP network topology and extract its first-order Ego subgraph;
[0018] Calculate the relevant feature information of the AS node, including edge features, local topology features, global topology features, and path-related features.
[0019] Preferably, calculate the fingerprint information of the graph model based on Simhash according to the graph model with relevant feature information; specifically:
[0020] Use cyclic redundancy coding to perform hash calculation on m AS nodes and n edge names in the BGP network topology to form a b-bit binary number, and the expression is:
[0021]
[0022] In the formula, and respectively represent the node and connection edge sets at the current moment t;
[0023] Normalize the AS node features to obtain the feature vector at time t , and perform positive and negative inversion according to the obtained hash value, and then sum by row to obtain the fingerprint information of the i-th AS node , which is expressed as:
[0024]
[0025] In the formula, represents a function for obtaining fingerprint information; represents the j-th bit of the i-th AS node; is the j-th feature of the i-th AS node at the current t moment, and b is the number of binary digits output by the hash function;
[0026] Then, take 0 for the negative value positions and 1 for the positive value positions of the fingerprint information of each AS node to obtain the fingerprint vector of each AS node, forming a global fingerprint matrix, which is expressed as:
[0027]
[0028] Among them, .
[0029] Preferably, according to the fingerprint information obtained at the previous and current moments, an anomaly detection model is constructed using the Transformer and GCN frameworks for inter-domain routing anomaly detection; specifically:
[0030] First, perform an exclusive OR operation on the global fingerprint matrix obtained at this moment and the previous moment, and input the fingerprint information after the exclusive OR operation into the Transformer module to output an attention vector matrix. The specific calculation formula is:
[0031]
[0032]
[0033]
[0034]
[0035] Among them, represents the normalized query tensor, represents the key-value tensor, represents the value tensor, N represents the number of nodes in the BGP network topology, represents an N-dimensional all-1 column vector; represents the input of the first layer of the attention network, that is, the fingerprint data, is a hyperparameter representing the proportion of residual connections;
[0036] , and respectively represent linear transformation functions, represents the function of taking the diagonal elements of the matrix, represents the Frobenius norm;
[0037] Meanwhile, the adjacency information of the BGP network topology and the fingerprint information after the XOR operation are input into the GCN network for pooling operation, and the GCN representation tensor is output, which is expressed as:
[0038]
[0039] In the formula, represents the l-th layer structure of the GCN, represents the degree matrix of the AS graph, represents the adjacency matrix of the AS graph, represents the GCN output matrix of the l-th layer, represents the learning matrix of the l-th layer of the GCN, represents the vector dimension of the hidden layer, represents the non-linear activation function, and the RELU activation function is adopted;
[0040] The obtained attention vector matrix is concatenated with the GCN representation tensor, and the result is input into the multi-layer perceptron to obtain the output at the current time t , and the gradient variable is updated by calculating the binary cross-entropy loss , which is expressed as:
[0041]
[0042]
[0043] In the formula, represents the output matrix of the GCN network at time t, represents the global fingerprint matrix, represents the output of the attention network at time t; represents the number of abnormal categories, represents the label of the i-th sample in the c-th category, represents the output score for the i-th sample in the c-th category; in addition, represents the concatenation operation of matrices;
[0044] According to this detection model, inter-domain routing anomaly detection is performed.
[0045] Preferably, according to the constructed anomaly detection model, a traceability analysis model is constructed through the reconstruction loss , which is expressed as:
[0046]
[0047] In the formula, , respectively represent the deviation loss function and the classification loss function; is the label of the i-th sample.
[0048] On the other hand, the present invention provides an inter-domain routing anomaly detection system based on the Transformer model, including:
[0049] A data collection and topology construction module, which is used to collect BGP routing data based on collection points and construct a dynamic BGP network topology;
[0050] A feature extraction module, which is used to extract each AS node in the BGP network topology, extract relevant feature information, and obtain a graph model;
[0051] A fingerprint information calculation module, which is used to calculate the fingerprint information of the graph model based on Simhash according to the graph model with relevant feature information;
[0052] An anomaly detection model construction module, which is used to construct an anomaly detection model for inter-domain routing anomaly detection by using the Transformer and GCN frameworks according to the fingerprint information obtained at the previous and current moments.
[0053] On another aspect, the present invention provides a non-transitory computer-readable storage medium, on which computer instructions are stored, and the computer instructions cause the computer to execute the above-mentioned inter-domain routing anomaly detection method based on the Transformer model.
[0054] On another aspect, the present invention provides an electronic device, including: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus, and the processor calls the logical instructions in the memory to execute the above-mentioned inter-domain routing anomaly detection method based on the Transformer model.
[0055] On yet another aspect, the present invention provides a computer program product, the computer program product includes a computer program, the computer program is stored on a non-transitory computer-readable storage medium, and when the computer program is executed by a processor, the computer executes the above-mentioned inter-domain routing anomaly detection method based on the Transformer model.
[0056] Advantageous effects: The inter-domain routing anomaly detection method based on the Transformer model of the present invention accurately captures the behavior information of AS in the dynamic BGP network by sampling the subgraphs of the global BGP network and calculating Simhash to obtain rich fingerprint information for each AS, which includes the edge information and node information of the subgraph;
[0057] The inter-domain routing anomaly detection method based on the Transformer model of the present invention performs parallel tensor processing on the fingerprint information of global ASes through calculating the linear attention mechanism, reducing the complexity, and thus being able to calculate the vector representations of global ASes simultaneously, avoiding the problem of memory overflow in the original method;
[0058] In order to overcome the local incomplete information of collection points, the present invention proposes to use a combination of local information extracted by graph convolution and global information extracted by the attention mechanism to accurately make up for the incomplete information, thereby improving the accuracy of anomaly detection and traceability. Brief Description of the Drawings
[0059] Figure 1 It is a flowchart of the inter-domain routing anomaly detection method based on the Transformer model in Embodiment 1 of the present invention.
[0060] Figure 2 It is a flowchart of detecting and tracing BGP anomalies based on the linear attention mechanism in Embodiment 1 of the present invention.
[0061] Figure 3 It is a comparison chart of performance indicators of the method in Embodiment 1 of the present invention under different partial observability degrees. Detailed Embodiments
[0062] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below in conjunction with the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention, and they should not be construed as limitations to the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention. In the description of the present invention, it should be understood that the terms used are only for the purpose of description and cannot be construed as indicating or implying relative importance.
[0063] The following will be combined with Figures 1 - 3 Describe the inter-domain routing anomaly detection method and system based on the Transformer model provided by the present invention.
[0064] Before specifically describing the embodiments of the present invention, some terms involved in the present invention will be explained first.
[0065] BGP, the full name is Border Gateway Protocol, and the corresponding Chinese is Border Gateway Protocol. BGP is a core decentralized autonomous routing protocol on the Internet.
[0066] AS, (Autonomous System), is a collection of Internet Protocol (IP) routing prefixes connected under the control of one or more network operators on behalf of a single administrative entity or domain. It provides a common and well-defined routing policy to the Internet. An AS is a collection of multiple routers identified by a unique autonomous system number under a single technical management system; it is a large network or network group with (the same or multiple) routing protocol policies. Usually, each AS is operated by a single large organization (such as an Internet Service Provider (ISP), a large enterprise technology company, a university, or a government agency); among them, each ISP can manage multiple ASs.
[0067] Simhash is a text similarity algorithm. Its main idea is dimensionality reduction, which maps high-dimensional feature vectors into low-dimensional feature vectors, and determines whether articles are repeated or highly similar through the Hamming Distance between two vectors.
[0068] GCN, (Graph Convolutional Network), is a graph convolutional network and a widely used graph neural network. It is a convolutional neural network that can directly act on a graph and utilize its structural information.
[0069] Embodiment 1: This embodiment provides an inter-domain routing anomaly detection method based on the Transformer model.
[0070] Facing the increasing routing scale and the dynamically changing global AS connection topology, it poses a huge challenge to accurately perceive the BGP anomaly situation. To address the above technical challenges, this embodiment proposes an inter-domain routing anomaly detection method based on the Transformer model, thereby overcoming the characteristics of BGP's dynamic changes, complex and large-scale BGP network.
[0071] In this embodiment, first, a global BGP network topology is constructed based on the routing table (RIB table) and the routing update table and dynamically updated; then, graph-related features and statistical-related features are extracted from the constructed BGP network topology, including edge features, local topology features, global topology features, and path-related features; the fingerprint information of the entire graph is calculated using Simhash based on the extracted features, thereby embedding the information into the Hamming space; to overcome the challenge of the large-scale BGP network resulting in a large amount of calculation for global AS features, a linear attention mechanism is used to process the fingerprint information of ASs. Specifically, the inter-domain routing anomaly detection method based on the Transformer model in this embodiment, as Figure 1 shown, includes the following steps:
[0072] S1. Collect BGP routing data based on globally collected points, including BGP routing table data and BGP routing update data.
[0073] S2. Construct a dynamic BGP routing topology, specifically:
[0074] S21. Construct a global routing topology according to the BGP routing table data R t-1 ; then update the global routing topology according to the BGP routing update data U
[0075] at the current moment to obtain the BGP network topology R t at the current moment. t .
[0076] S3. Extract each AS node subgraph in the BGP network topology and extract relevant feature information to obtain a graph model; specifically:
[0077] S31. Traverse each AS node in the BGP network topology and extract its first-order Ego subgraph.
[0078] S32. Calculate the relevant feature information of the AS node, including the out-degree, in-degree, and Pagerank value of the node, and calculate the edge information of the topology, that is, the number of prefixes flowing through the AS.
[0079] S4. Calculate the fingerprint information of the graph model based on Simhash according to the graph model with relevant feature information; specifically:
[0080] S41. Use cyclic redundancy coding to perform hash calculation on m AS nodes and n edge names in the BGP network topology to form a b-bit binary number, and the expression is:
[0081]
[0082] where and respectively represent the node and connection edge sets at the current moment t;
[0083] S42. Normalize the AS node features to obtain the feature vector at time t, and perform positive and negative inversion according to the obtained hash value, and then sum by row to obtain the fingerprint information of the i-th AS node, which is expressed as:
[0084]
[0085] where represents the function for obtaining fingerprint information; represents the j-th bit of the i-th AS node; is the j-th feature of the i-th AS node at the current t moment, and b is the number of bits of the binary output of the hash function;
[0086] S43. Then, take 0 at the negative value positions and 1 at the positive value positions of the fingerprint information of each AS node to obtain the fingerprint vector of each AS node, forming the global fingerprint matrix, which is expressed as:
[0087]
[0088] Among them, .
[0089] S5. According to the fingerprint information obtained at the previous and current moments, use the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection; as Figure 2 shown, specifically:
[0090] S51. First, perform an exclusive OR operation on the global fingerprint matrix obtained at this moment and the previous moment, and input the fingerprint information after the exclusive OR operation into the Transformer module to output the attention vector matrix. The specific calculation formula is:
[0091]
[0092]
[0093]
[0094]
[0095] Among them, represents the normalized query tensor, represents the key-value tensor, represents the value tensor, N represents the number of nodes in the BGP network topology, represents an N-dimensional all-1 column vector; represents the input of the first layer of the attention network, that is, the fingerprint data, is a hyperparameter representing the proportion of the residual connection;
[0096] , and respectively represent the linear transformation function, represents the function of taking the diagonal elements of the matrix, represents the Frobenius norm;
[0097] S52. At the same time, input the adjacency information of the BGP network topology and the fingerprint information after the exclusive OR operation into the GCN network for pooling operation, and output the GCN representation tensor, which is expressed as:
[0098]
[0099] In the formula, represents the l-th layer structure of the GCN, represents the degree matrix of the AS graph, represents the adjacency matrix of the AS graph, represents the GCN output matrix of the l-th layer, represents the learning matrix of the l-th layer of the GCN, represents the vector dimension of the hidden layer, represents the vector dimension of the hidden layer, represents the non-linear activation function, and the RELU activation function is adopted;
[0100] S53. Connect the obtained attention vector matrix with the GCN representation tensor, and input the result into the multi-layer perceptron to obtain the output at the current time t , update the gradient variable by calculating the binary cross-entropy loss , construct an anomaly model, and construct a traceability analysis model through the reconstruction loss It is expressed as:
[0101]
[0102]
[0103]
[0104] In the formula, represents the output matrix of the GCN network at time t, represents the global fingerprint matrix, represents the output at time t of the attention network; represents the number of anomaly categories, represents the label of the i-th sample in the c-th category, represents the output score for the i-th sample in the c-th category; in addition, represents the concatenation operation of matrices;
[0105] , represent the bias loss function and the classification loss function respectively; is the label of the i-th sample.
[0106] To detect the effect of the inter-domain routing anomaly detection method based on the Transformer model in this embodiment under global real data, the present invention uses RIPENCC and RouteView global public collection points to collect BGP routing data. In the constructed dataset, based on the grid search results, a 1-minute time window is used to construct data samples. Then, the data is labeled according to the occurrence time of the actually occurring abnormal events and the reported abnormal routing information. The simulation experiment platform is the Python 3.10 software under the Linux system (the analysis results of the present invention are not affected by the operating system and the Python software version). In addition, the geographical location and ranking information of the AS are obtained from the official authoritative data of Caida.
[0107] As can be seen Figure 3 from the specific performance metrics of the method of Example 1 and the comparison methods (BGPViewer and MSLSTM methods) under different partial observability conditions. Compared with the comparison methods, the method of Example 1 can overcome the negative impact brought by partial observation, has higher accuracy and F1 score, as well as lower false alarm rate and missed alarm rate. It shows that the method of Example 1 has higher robustness than the comparison methods as the missing information increases.
[0108] From the above experimental results, it can be seen that the inter-domain routing anomaly detection method based on the Transformer model proposed by the present invention can more accurately detect BGP anomalies and perform traceability analysis.
[0109] Example 2: This embodiment provides an inter-domain routing anomaly detection system based on the Transformer model, including:
[0110] A data collection and topology construction module, configured to collect BGP routing data based on collection points and construct a dynamic BGP network topology;
[0111] A feature extraction module, configured to extract each AS node in the BGP network topology and extract relevant feature information to obtain a graph model;
[0112] A fingerprint information calculation module, configured to calculate the fingerprint information of the graph model based on the Simhash according to the graph model with relevant feature information;
[0113] An anomaly detection model construction module, configured to construct an anomaly detection model for inter-domain routing anomaly detection by using the Transformer and GCN frameworks according to the fingerprint information obtained at the previous and subsequent moments.
[0114] Example 3: This example provides a non-transitory computer-readable storage medium, on which computer instructions are stored. The computer instructions cause the computer to execute an inter-domain routing anomaly detection method based on the Transformer model. The method includes the following steps:
[0115] Based on the collection points, collect BGP routing data and construct a dynamic BGP network topology;
[0116] Extract each AS node in the BGP network topology and extract relevant feature information to obtain a graph model;
[0117] According to the graph model with relevant feature information, calculate the fingerprint information of the graph model based on Simhash;
[0118] According to the fingerprint information obtained at the previous and current moments, use the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection.
[0119] Example 4: This example provides an electronic device, which may include: a processor, a communications interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus. The processor can call the logical instructions in the memory to execute an inter-domain routing anomaly detection method based on the Transformer model. The method includes the following steps:
[0120] Based on the collection points, collect BGP routing data and construct a dynamic BGP network topology;
[0121] Extract each AS node in the BGP network topology and extract relevant feature information to obtain a graph model;
[0122] According to the graph model with relevant feature information, calculate the fingerprint information of the graph model based on Simhash;
[0123] According to the fingerprint information obtained at the previous and current moments, use the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection.
[0124] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0125] Embodiment 5: The present embodiment provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute an inter-domain routing anomaly detection method based on the Transformer model. The method includes the following steps:
[0126] Based on the collection points to collect BGP routing data, construct a dynamic BGP network topology;
[0127] Extract each AS node in the BGP network topology and extract relevant feature information to obtain a graph model;
[0128] According to the graph model with relevant feature information, calculate the fingerprint information of the graph model based on Simhash;
[0129] According to the fingerprint information obtained at the previous and current moments, use the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection.
[0130] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.
[0131] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An inter-domain routing anomaly detection method based on the Transformer model, characterized in that, including: Collecting BGP routing data based on collection points to construct a dynamic BGP network topology; Extracting subgraphs of each AS node in the BGP network topology and extracting relevant feature information to obtain a graph model; Calculating the fingerprint information of the graph model based on Simhash according to the graph model with relevant feature information; Specifically: Use cyclic redundancy coding to perform hash calculation on m AS nodes and n edge names in the BGP network topology, forming a b -bit binary number. The expression is as follows: m AS nodes and n edge names to form b bit binary numbers, with the expression: ; wherein, and respectively represent the set of nodes and connecting edges at the current moment t ; Normalize the AS node features to obtain t the time feature vector , and perform positive and negative inversion according to the obtained hash value, and then sum by row to obtain the i fingerprint information of the AS node , expressed as: ; In the formula, represents the function for obtaining fingerprint information; represents the i th bit of the j th AS node; is the t th feature of the i th AS node at the current j time, b is the number of binary digits output by the hash function; Then, for the fingerprint information of each AS node, set the negative positions to 0 and the positive positions to 1 to obtain the fingerprint vectors of each AS node, forming a global fingerprint matrix, expressed as: ; Among them, ; According to the fingerprint information obtained at previous and current times, using the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection.
2. The inter-domain routing anomaly detection method based on the Transformer model according to claim 1, characterized in that The collecting BGP routing data based on collection points to construct a dynamic BGP network topology; specifically: Collecting BGP routing data based on global collection points, which includes BGP routing table data and BGP routing update data; Constructing a global routing topology according to the BGP routing table data; Then, according to the BGP routing update data at the current time, updating the global routing topology to obtain the BGP network topology at the current time.
3. The inter-domain routing anomaly detection method based on the Transformer model according to claim 1, wherein, The extracting subgraphs of each AS node in the BGP network topology and extracting relevant feature information to obtain a graph model; specifically: Traversing each AS node in the BGP network topology to extract its first-order Ego subgraph; Calculating the relevant feature information of the AS node, including edge features, local topology features, global topology features, and path-related features.
4. The method for inter-domain routing anomaly detection based on the Transformer model according to claim 1, wherein According to the fingerprint information obtained at previous and current times, using the Transformer and GCN frameworks to construct an anomaly detection model for inter-domain routing anomaly detection; specifically: First, perform an exclusive OR operation on the global fingerprint matrix obtained at this time and the previous time, and input the fingerprint information after the exclusive OR operation into the Transformer module to output an attention vector matrix. The specific calculation formula is: ; ; ; ; Among them, represents the normalized query tensor, represents the key-value tensor, represents the value tensor, N represents the number of nodes in the BGP network topology, represents a N dimensional all-ones column vector; represents the first-layer input of the attention network, that is, the fingerprint data, is a hyperparameter representing the proportion of residual connections; , and respectively represent linear transformation functions, represents the function of taking the diagonal elements of a matrix, represents the Frobenius norm; At the same time, input the adjacency information of the BGP network topology and the fingerprint information after the exclusive OR operation into the GCN network for pooling operation to output a GCN representation tensor, expressed as: ; In the formula, represents the -th layer structure of the GCN, represents the degree matrix of the AS graph, represents the adjacency matrix of the AS graph, represents the GCN output matrix of the -th layer, represents the learning matrix of the -th layer of the GCN, represents the vector dimension of the hidden layer, represents the non-linear activation function, and the RELU activation function is adopted; The obtained attention vector matrix is concatenated with the GCN representation tensor, and the result is input into a multi-layer perceptron to obtain the output at the current t moment , and the binary cross-entropy loss is calculated to update the gradient variable, expressed as: ; ; In the formula, Represents the GCN network The output matrix at time instant, represents the global fingerprint matrix, Represents the attention network Output at the moment; Indicates the number of abnormal categories, Indicates i Sample No. c The identification of the categories, Indicates that for i Sample No. c Output scores for each category; in addition, Represents the concatenation operation of the matrix; According to this detection model, perform inter-domain routing anomaly detection.
5. The inter-domain routing anomaly detection method based on the Transformer model according to claim 4, wherein According to the constructed anomaly detection model, through the reconstruction loss Construct a traceability analysis model, expressed as: ; Wherein, , respectively represent the deviation loss function and the classification loss function; is the label of the i th sample.
6. An inter-domain routing anomaly detection system based on the Transformer model, characterized in that, including: A data collection and topology construction module for collecting BGP routing data based on collection points to construct a dynamic BGP network topology; A feature extraction module for extracting each AS node in the BGP network topology and extracting relevant feature information to obtain a graph model; A fingerprint information calculation module for calculating the fingerprint information of the graph model based on Simhash according to the graph model with relevant feature information; Specifically: Use cyclic redundancy coding to perform hash calculations on m AS nodes and n edge names in the BGP network topology, forming b bit binary numbers, with the expression: ; In the formula, and respectively represent the set of nodes and connection edges at the current moment t ; Normalize the AS node features to obtain t the time feature vector , and perform positive and negative inversion according to the obtained hash value, then sum by row to obtain the i fingerprint information of the nth AS node , expressed as: ; In the formula, represents the function for obtaining fingerprint information; represents the i -th bit of the j -th AS node; is the t -th feature of the i -th AS node at the current j time, b is the number of bits in the binary output of the hash function; Then, for the fingerprint information of each AS node, set the negative positions to 0 and the positive positions to 1 to obtain the fingerprint vectors of each AS node, forming a global fingerprint matrix, expressed as: ; Among them, ; An anomaly detection model construction module for constructing an anomaly detection model for inter-domain routing anomaly detection according to the fingerprint information obtained at previous and current times using the Transformer and GCN frameworks.
7. A non-transitory computer-readable storage medium, characterized in that, It stores computer instructions, and these computer instructions cause the computer to execute the inter-domain routing anomaly detection method based on the Transformer model described in any one of claims 1-5.
8. An electronic device, characterized in that, including: A processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete mutual communication through the communication bus, and the processor calls the logical instructions in the memory to execute the inter-domain routing anomaly detection method based on the Transformer model according to any one of claims 1-5.
9. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer executes the inter-domain routing anomaly detection method based on the Transformer model according to any one of claims 1-5.
Citation Information
Patent Citations
BGP anomaly detection method and system based on graph attention network
CN114221790A
Chemical process dynamic prediction method based on dynamic space-time diagram
CN117151275A