A malicious traffic classification method based on feature fusion
By introducing channel fusion module, multi-layer feature fusion module and downsampling fusion module into the malicious traffic classification model, the problem of insufficient feature selection and extraction in the existing technology is solved, and more efficient malicious traffic classification performance is achieved.
Patent Information
- Application Number
- CN202411303794.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2024-05-31
- Filing Date
- 2024-09-19
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-09-19
AI Technical Summary
The existing malicious traffic classification methods have shortcomings in feature selection and extraction, especially when traditional convolutional neural networks process traffic images, they will lead to loss of feature information and insufficient channel feature information.
A malicious traffic classification method based on feature fusion is proposed. By building a malicious traffic classification model including channel fusion module, multi-layer feature fusion module and downsampling fusion module, multiple features of traffic images are effectively extracted and fused.
This method enhances the capture and fusion of feature information through a multi-layer feature fusion module and a downsampling fusion module, improves the performance and stability of malicious traffic classification, and reduces the complexity of the model.
Smart Images

Figure CN119273969B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a traffic classification method in the field of data recognition, and particularly to a malicious traffic classification method based on feature fusion. Background Art
[0002] The rapid growth of Internet of Things (IoT) devices has expanded the network attack surface, making them vulnerable to various attacks in the network. Once an IoT device is attacked, it will not only cause economic losses but also endanger the security and privacy of user data. Therefore, detecting attack behaviors in the IoT is crucial for the security of the IoT. Usually, a malicious traffic classification model detects attack behaviors in the network by analyzing whether network traffic is benign or malicious. Therefore, detecting malicious traffic in the network is an urgent problem to be solved in the IoT currently.
[0003] Currently, the mainstream malicious traffic classification methods include traditional machine learning methods and deep learning methods. Although traditional machine learning methods can effectively detect malicious traffic, feature selection is time-consuming and highly dependent on expert experience. Compared with traditional machine learning, deep learning can automatically extract features from raw data instead of using manual feature selection. Currently, converting network traffic into images and classifying them using traditional convolutional neural networks is an advanced method. However, this method still has some deficiencies. For example, traffic images are usually small, and the downsampling operation of traditional networks will cause loss of feature information. In addition, traffic images are single-channel images, and the channel feature information is less than that of three-channel images, making it difficult for traditional deep learning neural networks to extract sufficient feature information. Summary of the Invention
[0004] To solve the above technical deficiencies, in view of the characteristics of traffic images, the present invention proposes a malicious traffic classification method based on feature fusion.
[0005] The present invention is implemented by the following technical solutions:
[0006] A malicious traffic classification method based on feature fusion, characterized in that the classification method includes the following steps:
[0007] Step 1, preprocess the pcap traffic packets containing malicious traffic packets and benign traffic packets;
[0008] Step 2, convert the preprocessed pcap traffic packets into grayscale images;
[0009] Step 3, build a malicious traffic classification model, where the malicious traffic classification model includes a channel fusion module, a multi-layer feature fusion module, a downsampling fusion module, a global average pooling layer, a fully connected layer, and a Softmax activation function layer;
[0010] Step 4: Input the grayscale image obtained in Step 2 into the malicious traffic classification model to obtain a classification result.
[0011] Further, Step 4 includes the following steps:
[0012] Step 4.1: Input the grayscale image into the channel fusion module of the malicious traffic classification model to obtain an output feature map A 1 ;
[0013] Step 4.2: Input the feature map A 1 into the multi-layer feature fusion module of the malicious traffic classification model to obtain an output feature map B 1 ;
[0014] Step 4.3: Input the feature map B 1 into the downsampling fusion module of the malicious traffic classification model to obtain an output feature map C 1 ;
[0015] Step 4.4: Input the feature map C 1 into the multi-layer feature fusion module of the malicious traffic classification model to obtain an output feature map D 1 ;
[0016] Step 4.5: Input the feature map D 1 into the downsampling fusion module of the malicious traffic classification model to obtain an output feature map E 1 ;
[0017] Step 4.6: Input the feature map E 1 sequentially into the global average pooling layer, fully connected layer, and Softmax activation function layer of the malicious traffic classification model to obtain a classification result.
[0018] Further, the channel fusion module consists of an initial feature extraction module, a parallel channel expansion module, and a channel contraction module. The initial feature extraction module is sequentially composed of a convolutional layer, a BN layer, and a Relu layer. The parallel channel expansion module consists of Branch 1 and Branch 2. Branch 1 is sequentially composed of a convolutional layer, a BN layer, and a Relu layer. Branch 2 is sequentially composed of a convolutional layer, a BN layer, and a Relu layer. The channel contraction module is sequentially composed of a depthwise convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, and a Relu layer connected adjacently.
[0019] Further, the multi-layer feature fusion module is composed of a position feature extraction module and a multi-scale feature extraction module. The position feature extraction module is successively adjacent composed of a convolutional layer, a BN layer, a Relu layer, a convolutional layer, a BN layer, a Relu layer, and a CA attention module. The multi-scale feature extraction module is composed of Branch 1, Branch 2, and Branch 3. Branch 1 is successively adjacent composed of a depthwise convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, and a Relu layer. Branch 2 is successively adjacent composed of a depthwise convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, a Relu layer, a depthwise convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, and a Relu layer. Branch 3 is successively adjacent composed of a pooling layer, a convolutional layer, a BN layer, and a Relu layer.
[0020] Further, the downsampling fusion module is composed of Branch 1, Branch 2, and Branch 3. Branch 1 is successively composed of a convolutional layer, a BN layer, a Relu layer, and an average pooling layer. Branch 2 is successively composed of a convolutional layer, a BN layer, a Relu layer, and a max pooling layer. Branch 3 is successively adjacent composed of a depthwise convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, and a Relu layer.
[0021] Further, Step 4.1 includes the following steps:
[0022] Step 4.1.1, input the grayscale image into the initial feature extraction module to obtain the output feature map A1 1 ;
[0023] Step 4.1.2, input A1 1 into Branch 1 of the parallel channel expansion module to obtain the output feature map A2 1 , input A1 1 into Branch 2 of the parallel channel expansion module to obtain the output feature map A3 1 , perform a concatenation operation on the feature map A2 1 and the feature map A3 1 to obtain the feature map A4 1 ;
[0024] Step 4.1.3, input the feature map A4 1 into the channel contraction module to obtain the output feature map A 1 .
[0025] Further, Step 4.2 includes the following steps:
[0026] Step 4.2.1, input the feature map A 1 into the position feature extraction module to obtain the output feature map A1 2 ;
[0027] Step 4.2.2, input the feature map A12 The branch 1 of the input multi-scale feature extraction module obtains the output feature map A2 2 , and the feature map A1 2 is input into the branch 2 of the multi-scale feature extraction module to obtain the output feature map A3 2 , and the feature map A1 2 is input into the branch 3 of the multi-scale feature extraction module to obtain the output feature map A4 2 , and the feature map A2 2 , A3 2 and A4 2 are subjected to a splicing operation to obtain the feature map A5 2 ;
[0028] Step 4.2.3, the feature maps A 1 , A1 2 and A5 2 are subjected to an addition operation to obtain the feature map B 1 .
[0029] Furthermore, step 4.3 includes the following steps:
[0030] Step 4.3.1, the feature map B 1 is input into the branch 1 of the downsampling fusion module to obtain the output feature map B1 1 , and the feature map B 1 is input into the branch 2 of the downsampling fusion module to obtain the output feature map B2 1 , and the feature map B 1 is input into the branch 3 of the downsampling fusion module to obtain the output feature map B3 1 , and the feature maps B1 1 , B2 1 and B3 1 are subjected to an addition operation to obtain the feature map C 1 .
[0031] Furthermore, step 4.4 includes the following steps:
[0032] Step 4.4.1, the feature map C 1 is input into the position feature extraction module to obtain the output feature map C1 1 ;
[0033] Step 4.4.2, the feature map C1 1 is input into the branch 1 of the multi-scale feature extraction module to obtain the output feature map C2 1 , and the feature map C1 1 is input into the branch 2 of the multi-scale feature extraction module to obtain the output feature map C3 1 , and the feature map C1 1 is input into the branch 3 of the multi-scale feature extraction module to obtain the output feature map C41 , the feature maps C2 1 , C3 1 and C4 1 are concatenated to obtain the feature map C5 1 ;
[0034] Step 4.4.3, the feature maps C 1 , C1 1 and C5 1 are added to obtain the feature map D 1 .
[0035] Furthermore, Step 4.5 includes the following steps:
[0036] Step 4.5.1, the feature map D 1 is input into branch 1 of the downsampling fusion module to obtain the output feature map D1 1 , the feature map D 1 is input into branch 2 of the downsampling fusion module to obtain the output feature map D2 1 , the feature map D 1 is input into branch 3 of the downsampling fusion module to obtain the output feature map D3 1 , the feature maps D1 1 , D2 1 and D3 1 are added to obtain the feature map E 1 .
[0037] The beneficial effects of the present invention are as follows: In view of the characteristics of traffic images, the present invention proposes a malicious traffic classification method based on feature fusion. The malicious traffic classification model proposed by this method includes a channel fusion module, a multi-layer feature fusion module, and a downsampling fusion module. The channel fusion module is composed of an initial feature extraction module, a parallel channel expansion module, and a channel contraction module. The initial feature extraction module uses a convolutional layer to extract shallow features. The parallel channel expansion module can increase the number of channels of the feature map, increasing the feature information. The channel contraction module uses depth convolution to extract feature information and reduces the number of feature maps through convolution, improving the stability and detection performance of the model while reducing the model complexity. The multi-layer feature fusion module is composed of a position feature extraction module and a multi-scale feature extraction module. The position feature extraction module can extract the texture features of traffic images and suppress noise. The multi-scale feature extraction module can extract features of different scales simultaneously at the same level, increasing the receptive field, thereby capturing image information more comprehensively. Depth convolution and convolution with a size of 1 can reduce the computational amount of the model. In addition, the multi-layer feature fusion module adds and fuses features from multiple different layers, improving the expression ability and performance of the model. The downsampling fusion module doubles the number of feature maps, preventing the loss of useful feature information. In addition, this module can fuse features obtained by various pooling operations, enriching the feature information and improving the model's understanding ability of traffic images. Through the combination of each module, the malicious traffic classification method based on feature fusion can effectively extract and fuse various features of traffic images, improving the performance of malicious traffic classification. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 is a flowchart of the steps of the classification method of the present invention;
[0039] Figure 2 is a structural diagram of the channel fusion module in the present invention;
[0040] Figure 3 is a structural diagram of the multi-layer feature fusion module in the present invention;
[0041] Figure 4 is a structural diagram of the downsampling fusion module in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0043] A malicious traffic classification method based on feature fusion, characterized in that the classification method comprises the following steps:
[0044] Step 1, preprocess the pcap traffic packets containing malicious traffic packets and benign traffic packets. Among them, the steps of preprocessing the pcap traffic packets are as follows: The pcap traffic packets are segmented into multiple session data according to the source IP, source port, destination IP, destination port, and transport layer protocol. Duplicate data and blank data in the session data are deleted, and information that may affect the traffic classification result (such as the mac address) is also deleted to obtain traffic data.
[0045] Step 2, convert the preprocessed pcap traffic packets into grayscale images. Among them, after the pcap traffic packets are preprocessed, traffic data is obtained. The traffic data is intercepted at a fixed length of 1024 bytes. Each byte of the intercepted traffic data is converted into a decimal number. Then, the 1024 converted decimal numbers are converted into a two-dimensional array. Finally, the two-dimensional array is converted into the grayscale image. Therefore, the size of the grayscale image is 32×32, and the number of channels is 1.
[0046] Step 3, build a malicious traffic classification model. The malicious traffic classification model includes a channel fusion module, a multi-layer feature fusion module, a downsampling fusion module, a global average pooling layer, a fully connected layer, and a Softmax activation function layer.
[0047] Step 4, input the grayscale image in Step 2 into the malicious traffic classification model to obtain a classification result.
[0048] Step 4 includes the following steps:
[0049] Step 4.1, input the grayscale image into the channel fusion module of the malicious traffic classification model to obtain the output feature map A 1 ;
[0050] Step 4.2, input the feature map A 1 into the multi-layer feature fusion module of the malicious traffic classification model to obtain the output feature map B 1 ;
[0051] Step 4.3, input the feature map B 1 into the downsampling fusion module of the malicious traffic classification model to obtain the output feature map C 1 ;
[0052] Step 4.4, input the feature map C 1 into the multi-layer feature fusion module of the malicious traffic classification model to obtain the output feature map D 1 ;
[0053] Step 4.5, input the feature map D 1In the downsampling fusion module of the malicious traffic classification model, the output feature map E is obtained. 1 ;
[0054] Step 4.6, input the feature map E 1 into the global average pooling layer, fully connected layer, and Softmax activation function layer of the malicious traffic classification model in sequence to obtain the classification result.
[0055] Step 4.1 includes the following steps:
[0056] Step 4.1.1, the channel fusion module of the malicious traffic classification model consists of an initial feature extraction module, a parallel channel expansion module, and a channel contraction module;
[0057] Step 4.1.2, the initial feature extraction module consists of a convolutional layer, a BN layer, and a Relu layer in sequence with a convolutional kernel size of 3, a stride of 2, a padding of 1, and 32 channels. Input the grayscale image into the initial feature extraction module to obtain the output feature map A1 with a size of 32×16×16 1 ;
[0058] Step 4.1.3, the parallel channel expansion module consists of branch 1 and branch 2. Branch 1 consists of a convolutional layer, a BN layer, and a Relu layer in sequence with a convolutional kernel size of 1, a stride of 1, no padding, and 96 channels. Input A1 1 into branch 1 to obtain the output feature map A2 with a size of 96×16×16 1 , branch 2 consists of a convolutional layer, a BN layer, and a Relu layer in sequence with a convolutional kernel size of 1, a stride of 1, no padding, and 96 channels. Input A1 1 into branch 2 to obtain the output feature map A3 with a size of 96×16×16 1 , perform a concatenation operation on the feature map A2 1 and the feature map A3 1 to obtain the feature map A4 with a size of 192×16×16 1 ;
[0059] Step 4.1.4, the channel contraction module consists of a depthwise convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, and a Relu layer in sequence with a convolutional kernel size of 3, a stride of 1, a padding of 1, and 192 channels, and a convolutional kernel size of 1, a stride of 1, no padding, and 32 channels. Input the feature map A4 1 into the channel contraction module to obtain the output feature map A with a size of 32×16×16 1 .
[0060] Step 4.2 includes the following steps:
[0061] Step 4.2.1, The multi-layer feature fusion module of the malicious traffic classification model consists of a location feature extraction module and a multi-scale feature extraction module;
[0062] Step 4.2.2, The location feature extraction module is successively composed of a convolutional layer with a kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, a Relu layer, and a CA attention module adjacent to each other. The feature map A 1 is input into the location feature extraction module to obtain an output feature map A1 with a size of 32×16×16 2 ;
[0063] Step 4.2.3, The multi-scale feature extraction module consists of Branch 1, Branch 2, and Branch 3. Branch 1 is successively composed of a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 12 channels, a BN layer, and a Relu layer adjacent to each other. The feature map A1 2 is input into Branch 1 to obtain an output feature map A2 with a size of 12×16×16 2 , Branch 2 is successively composed of a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 32 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 12 channels, a BN layer, a Relu layer, a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 1, a padding of 1, and 12 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 12 channels, a BN layer, and a Relu layer adjacent to each other. The feature map A1 2 is input into Branch 2 to obtain an output feature map A3 with a size of 12×16×16 2 , Branch 3 is successively composed of a pooling layer with a pooling window of 2, a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 8 channels, a BN layer, and a Relu layer. The feature map A1 2 is input into Branch 3 to obtain an output feature map A4 with a size of 8×16×16 2 , The feature maps A2 2 , A3 2 and A4 2 are concatenated to obtain a feature map A5 with a size of 32×16×16 2 ;
[0064] Step 4.2.4, The feature maps A 1 , A1 2 and A5 2Perform an addition operation to obtain the feature map B with a size of 32×16×16 1 .
[0065] Step 4.3 includes the following steps:
[0066] 4.3.1, The downsampling and fusion module of the malicious traffic classification model consists of Branch 1, Branch 2, and Branch 3. Branch 1 is sequentially composed of a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, a Relu layer, and an average pooling layer with a pooling window of 2. Input the feature map B 1 into Branch 1 to obtain the output feature map B1 with a size of 64×8×8 1 , Branch 2 is sequentially composed of a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, a Relu layer, and a max pooling layer with a pooling window of 2. Input the feature map B 1 into Branch 2 to obtain the output feature map B2 with a size of 64×8×8 1 , Branch 3 is sequentially composed of a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 2, padding of 1, and 32 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 64 channels, a BN layer, and a Relu layer adjacent to each other. Input the feature map B 1 into Branch 3 to obtain the output feature map B3 with a size of 64×8×8 1 , Add the feature map B1 1 , B2 1 and B3 1 to perform an addition operation to obtain the feature map C with a size of 64×8×8 1 .
[0067] Step 4.4 includes the following steps:
[0068] Step 4.4.1, The multi-layer feature fusion module of the malicious traffic classification model consists of a position feature extraction module and a multi-scale feature extraction module;
[0069] Step 4.4.2, The position feature extraction module is sequentially composed of a convolutional layer with a kernel size of 3, a stride of 1, padding of 1, and 64 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 3, a stride of 1, padding of 1, and 64 channels, a BN layer, a Relu layer, and a CA attention module adjacent to each other. Input the feature map A 1 into the position feature extraction module to obtain the output feature map C1 with a size of 64×8×8 1 ;
[0070] Step 4.4.3, The multi-scale feature extraction module consists of Branch 1, Branch 2, and Branch 3. Branch 1 is successively composed of a depthwise convolution layer DWConv with a convolution kernel size of 3, a stride of 1, a padding of 1, and 64 channels, a BN layer, a Relu layer, a convolution layer with a convolution kernel size of 1, a stride of 1, no padding, and 24 channels, a BN layer, and a Relu layer. The feature map C1 1 is input into Branch 1 to obtain an output feature map C2 with a size of 24×8×8 1 , Branch 2 is successively composed of a depthwise convolution layer DWConv with a convolution kernel size of 3, a stride of 1, a padding of 1, and 64 channels, a BN layer, a Relu layer, a convolution layer with a convolution kernel size of 1, a stride of 1, no padding, and 24 channels, a BN layer, a Relu layer, a depthwise convolution layer DWConv with a convolution kernel size of 3, a stride of 1, a padding of 1, and 24 channels, a BN layer, a Relu layer, a convolution layer with a convolution kernel size of 1, a stride of 1, no padding, and 24 channels, a BN layer, and a Relu layer. The feature map C1 1 is input into Branch 2 to obtain an output feature map C3 with a size of 24×8×8 1 , Branch 3 is successively composed of a pooling layer with a pooling window of 2, a convolution layer with a convolution kernel size of 1, a stride of 1, no padding, and 16 channels, a BN layer, and a Relu layer. The feature map C1 1 is input into Branch 3 to obtain an output feature map C4 with a size of 16×8×8 1 , The feature maps C2 1 , C3 1 and C4 1 are concatenated to obtain a feature map C5 with a size of 64×8×8 1 ;
[0071] Step 4.4.4, The feature maps C 1 , C1 1 and C5 1 are added together to obtain a feature map D with a size of 64×8×8 1 .
[0072] Step 4.5 includes the following steps:
[0073] 4.5.1, The downsampling and fusion module of the malicious traffic classification model consists of Branch 1, Branch 2, and Branch 3. Branch 1 is successively composed of a convolution layer with a convolution kernel size of 1, a stride of 1, no padding, and 128 channels, a BN layer, a Relu layer, and an average pooling layer with a pooling window of 2. The feature map D 1 is input into Branch 1 to obtain an output feature map D1 with a size of 128×4×4 1, Branch 2 is successively composed of a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 128 channels, a BN layer, a Relu layer, and a max-pooling layer with a pooling window of 2, and the feature map D 1 is input into Branch 2 to obtain an output feature map D2 with a size of 128×4×4 1 , Branch 3 is successively composed of a depthwise convolutional layer DWConv with a kernel size of 3, a stride of 2, a padding of 1, and 64 channels, a BN layer, a Relu layer, a convolutional layer with a kernel size of 1, a stride of 1, no padding, and 128 channels, a BN layer, and a Relu layer adjacent to each other, and the feature map D 1 is input into Branch 3 to obtain an output feature map D3 with a size of 128×4×4 1 , the feature map D1 1 , D2 1 and D3 1 are added together to obtain a feature map E with a size of 128×4×4 1 .
[0074] Step 4.6 includes the following steps:
[0075] The feature map E 1 is input into the global average pooling layer of the malicious traffic classification model to obtain a global feature map with a size of 128×1×1;
[0076] Global average pooling layer, the global average pooling layer performs an average operation on each channel of the feature map E 1 to generate a one-dimensional vector with the same number as the number of feature channels. This operation has no parameters to be optimized, so it helps to prevent overfitting;
[0077] The global feature map is input into the fully connected layer;
[0078] Fully connected layer, the fully connected layer receives the output from the global average pooling layer and combines it with the class discrimination information. The fully connected layer contains two neurons, and each neuron corresponds to a benign / malicious traffic class respectively.
[0079] The output of the fully connected layer is input into the Softmax activation function layer to be mapped into probability values of two classes, and the one with the largest probability value is taken as the final classification result.
[0080] The above-described embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.
Claims
1. A malicious traffic classification method based on feature fusion, characterized in that: The classification method includes the following steps: Step 1, pre-processing the pcap traffic packets containing malicious traffic packets and benign traffic packets; Step 2, convert the preprocessed pcap traffic packet into a grayscale image; Step 3, building a malicious traffic classification model, the malicious traffic classification model includes a channel fusion module, a multi-layer feature fusion module, a downsampling fusion module, a global average pooling layer, a fully connected layer and a Softmax activation function layer; Step 4, input the grayscale image of step 2 into the malicious traffic classification model to obtain the classification result; Wherein, step 4 comprises: Step 4.1: Input the grayscale image into the channel fusion module of the malicious traffic classification model to obtain the output feature map A. 1 ; Step 4.2: transform feature map A 1 Input the multi-layer feature fusion module of the malicious traffic classification model to obtain the output feature map B 1 ; Step 4.3, feature map B 1 Input the downsampling fusion module of the malicious traffic classification model to obtain the output feature map C 1 ; Step 4.4, the feature map C 1 Input the multi-layer feature fusion module of the malicious traffic classification model to obtain the output feature map D 1 ; Step 4.5: transform the feature map D 1 Input the downsampling fusion module of the malicious traffic classification model to obtain the output feature map E 1 ; Step 4.6, the feature map E 1 The global average pooling layer, fully connected layer, and Softmax activation function layer of the malicious traffic classification model are input in sequence to obtain the classification result.
2. The malicious traffic classification method based on feature fusion as claimed in claim 1 is characterized in that: The channel fusion module is composed of an initial feature extraction module, a parallel channel expansion module and a channel contraction module. The initial feature extraction module is composed of a convolutional layer, a BN layer and a Relu layer in sequence. The parallel channel expansion module is composed of branch 1 and branch 2. Branch 1 is composed of a convolutional layer, a BN layer and a Relu layer in sequence. Branch 2 is composed of a convolutional layer, a BN layer and a Relu layer in sequence. The channel contraction module is composed of a deep convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer and a Relu layer in sequence.
3. The malicious traffic classification method based on feature fusion as claimed in claim 1 is characterized in that: The multi-layer feature fusion module is composed of a position feature extraction module and a multi-scale feature extraction module. The position feature extraction module is composed of a convolutional layer, a BN layer, a Relu layer, a convolutional layer, a BN layer, a Relu layer and a CA attention module in sequence. The multi-scale feature extraction module is composed of branch 1, branch 2 and branch 3. Branch 1 is composed of a deep convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer and a Relu layer in sequence. Branch 2 is composed of a deep convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, a Relu layer, a deep convolutional layer DWConv, a BN layer, a Relu layer, a convolutional layer, a BN layer, and a Relu layer in sequence. Branch 3 is composed of a pooling layer, a convolutional layer, a BN layer and a Relu layer in sequence.
4. The malicious traffic classification method based on feature fusion as claimed in claim 1 is characterized in that: The downsampling fusion module consists of branch 1, branch 2 and branch 3. Branch 1 consists of convolutional layer, BN layer, Relu layer and average pooling layer in sequence. Branch 2 consists of convolutional layer, BN layer, Relu layer and maximum pooling layer in sequence. Branch 3 consists of deep convolutional layer DWConv, BN layer, Relu layer, convolutional layer, BN layer and Relu layer in sequence.
5. The malicious traffic classification method based on feature fusion as claimed in claim 1 is characterized in that: Step 4.1 includes the following steps: Step 4.1.1, input the grayscale image into the initial feature extraction module to obtain the output feature map A1 1 ; Step 4.1.2, A1 1 Input parallel channel expansion module branch 1 to get output feature map A2 1 , A1 1 Input parallel channel expansion module branch 2 to get output feature map A3 1 , the feature map A2 1 And feature map A3 1 Perform the splicing operation to obtain feature map A4 1 ; Step 4.1.3, feature map A4 1 In the input channel contraction module, the output feature map A is obtained 1 .
6. The malicious traffic classification method based on feature fusion as claimed in claim 3 is characterized in that: Step 4.2 includes the following steps: Step 4.2.1: transform feature map A 1 Input position feature extraction module, get output feature map A1 2 ; Step 4.2.2, feature map A1 2 Input branch 1 of the multi-scale feature extraction module to obtain the output feature map A2 2 , the feature map A1 2 Input branch 2 of the multi-scale feature extraction module to obtain the output feature map A3 2 , the feature map A1 2 Input branch 3 of the multi-scale feature extraction module to obtain the output feature map A4 2 , the feature map A2 2 、A3 2 and A4 2 Perform the splicing operation to obtain feature map A5 2 ; Step 4.2.3, feature map A 1 、A1 2 and A5 2 Perform the addition operation to obtain the feature map B 1 .
7. The method for classifying malicious traffic based on feature fusion as claimed in claim 4, characterized in that: Step 4.3 includes the following steps: Step 4.3.1, feature map B 1 Input branch 1 of the downsampling fusion module to obtain the output feature map B1 1 , the feature map B 1 Input branch 2 of the downsampling fusion module to obtain the output feature map B2 1 , the feature map B 1 Input branch 3 of the downsampling fusion module to obtain the output feature map B3 1 , the feature map B1 1 、B2 1 and B3 1 Perform the addition operation to obtain the feature map C 1 .
8. The malicious traffic classification method based on feature fusion as claimed in claim 3 is characterized in that: Step 4.4 includes the following steps: Step 4.4.1, transform the feature map C 1 Input position feature extraction module, get output feature map C1 1 ; Step 4.4.2, feature map C1 1 Input branch 1 of the multi-scale feature extraction module to obtain the output feature map C2 1 , the feature map C1 1 Input branch 2 of the multi-scale feature extraction module to obtain the output feature map C3 1 , the feature map C1 1 Input branch 3 of the multi-scale feature extraction module to obtain the output feature map C4 1 , the feature map C2 1 、C3 1 and C4 1 Perform the splicing operation to obtain the feature map C5 1 ; Step 4.4.3, transform the feature map C 1 、C1 1 and C5 1 Perform the addition operation to obtain the feature map D 1 .
9. The malicious traffic classification method based on feature fusion as claimed in claim 4 is characterized in that: Step 4.5 includes the following steps: Step 4.5.1: transform the feature map D 1 Input branch 1 of the downsampling fusion module to obtain the output feature map D1 1 , the feature map D 1 Input branch 2 of the downsampling fusion module to obtain the output feature map D2 1 , the feature map D 1 Input branch 3 of the downsampling fusion module to obtain the output feature map D3 1 , the feature map D1 1 、D2 1 and D3 1 Perform the addition operation to obtain the feature map E 1 .
Citation Information
Patent Citations
Remote sensing image classification method and device based on local and global feature fusion
CN115937594A
Lightweight malicious traffic classification method based on deep learning
CN117336057A