Deep Learning-Based Encrypted Traffic Threat Detection Method and System

Through the deep learning-based encrypted traffic threat detection method, time series analysis and LSTM networks are used to identify abnormal behaviors in encrypted traffic, solving the problem of insufficient recognition capabilities for unknown threats and zero-day attacks in the prior art, and achieving efficient and accurate encrypted traffic threat detection.

CN119363412BActive Publication Date: 2025-06-24BEIJING RONGHENG TECHNOLOGY DEVELOPMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411459816.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-18
Publication Date
2025-06-24
Estimated Expiration
2044-10-18

AI Technical Summary

Technical Problem

When handling encrypted traffic, it is difficult to accurately identify unknown threats and zero-day attacks, resulting in limited real-time and accuracy, which cannot meet the security needs of modern network environments.

Method used

The encrypted traffic threat detection method based on deep learning is adopted to extract traffic behavior characteristics through time series analysis, train LSTM network matching behavior pattern changes, and optimize the detection configuration using anomaly score algorithm and genetic algorithm to achieve real-time threat detection of encrypted traffic.

Benefits of technology

It improves the ability of encrypted traffic threat detection, can identify abnormal behavior without decrypting data, reduce false alarm rates, improve the degree of automation of data processing, and enhances dynamic monitoring capabilities, improves the efficiency and accuracy of threat detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363412B_ABST
    Figure CN119363412B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of threat detection, specifically a method and system for encrypted traffic threat detection based on deep learning, including the following steps: Based on encrypted traffic data, perform time series analysis on the data stream, extract traffic behavior characteristics, use the characteristics to train an LSTM network, match changes in behavior patterns, and perform predictive analysis on future data to obtain a behavior pattern data set. In the present invention, through the long short-term memory network, the ability of encrypted traffic threat detection is improved. It can extract traffic behavior characteristics through time series analysis without decrypting the data, allowing the system to capture small changes in behavior patterns, thereby effectively identifying abnormal behaviors hidden in encrypted traffic. The abnormal score algorithm automatically adjusts the abnormal threshold, reduces the false alarm rate, and improves the automation degree of data processing. The genetic algorithm enables the LSTM network structure to automatically adapt to changes in the network environment, enhances the dynamic monitoring ability, and improves the efficiency and accuracy of threat detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of threat detection, and particularly to an encrypted traffic threat detection method and system based on deep learning. Background Art

[0002] Threat detection is a core area of network security technology, aiming to identify, evaluate, and respond to various forms of network threats, such as malware, viruses, phishing attacks, and zero-day vulnerabilities. This field integrates a variety of technologies and methods, including signature-based detection, behavior analysis, anomaly detection, and automated detection techniques. Threat detection usually requires the ability to analyze large amounts of data in real time and quickly and accurately identify potential security threats. With the complexity of the network environment and the increase in encrypted traffic, it is also necessary to adapt to the parsing of encrypted data in order to effectively identify malicious activities hidden in encrypted communications.

[0003] Among them, the encrypted traffic threat detection method is a technology for identifying and responding to security threats in encrypted network traffic. In the modern network environment, the vast majority of data transmissions use encryption technology to protect data privacy, but this also poses difficulties to traditional threat detection methods because encrypted communications can easily hide malicious content. The encrypted traffic threat detection method analyzes information such as the metadata, traffic patterns, and time series of encrypted data in order to detect potential malicious activities without decrypting the content. Its main purpose is to improve the level of network security protection, reduce the exploitation of security vulnerabilities, and protect the data of individuals and enterprises from network attackers.

[0004] The existing technologies mainly rely on signature-based detection and behavior analysis, and have deficiencies in dealing with encrypted traffic, especially limited ability to identify unknown threats and zero-day attacks. Existing methods are difficult to accurately evaluate the behavior patterns in encrypted data without decrypting the communication content, resulting in limited real-time performance and accuracy when dealing with large amounts of encrypted data, and making it difficult for the network security protection level to meet the requirements of the modern network environment. It is easy to cause data leakage or system intrusion due to untimely response or inaccurate identification, bringing serious risks to security protection. Summary of the Invention

[0005] The purpose of the present invention is to solve the deficiencies existing in the prior art, and to propose an encrypted traffic threat detection method and system based on deep learning.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions: An encrypted traffic threat detection method based on deep learning, including the following steps,

[0007] S1: Based on the encrypted traffic data, perform time series analysis on the data stream, extract traffic behavior features, use the features to train an LSTM network, match changes in behavior patterns, and perform predictive analysis on future data to obtain a behavior pattern dataset;

[0008] S2: Based on the behavior pattern dataset, calculate the anomaly score for each data packet through the anomaly score algorithm, automatically set and adjust the anomaly threshold, and perform anomaly data screening and marking to obtain anomaly-marked data packets;

[0009] S3: Based on the anomaly-marked data packets, perform in-depth feature analysis on the data packets, extract key features, use the genetic algorithm to optimize the LSTM network structure, refine the anomaly detection ability, and obtain an optimized detection configuration;

[0010] S4: Based on the optimized detection configuration, use the encrypted traffic data to test the threat detection ability of the LSTM network, compare the performance data with the performance standard, and adjust the LSTM network parameters according to the test results to obtain an adjusted detection model.

[0011] The improvement of the present invention is that the extraction steps of the traffic behavior features are specifically as follows:

[0012] S111: Based on the encrypted traffic data, use the autocorrelation function to perform time series analysis on the encrypted traffic data and perform windowing processing, using the formula:

[0013]

[0014] to obtain a window feature vector, where μ is the weighted average autocorrelation coefficient in the window, r j is the autocorrelation coefficient of the j-th data point in the window, w is the window size, and β j is the weight of the j-th data point in the window;

[0015] S112: Based on the window feature vector, calculate the skewness and kurtosis of each window, using the formula:

[0016]

[0017] and

[0018]

[0019] to obtain key statistical features, where S represents the skewness calculated from the window, K represents the kurtosis calculated from the window, and σ is the standard deviation of the data in the window.

[0020] The improvement of the present invention is that the acquisition steps of the behavior pattern dataset are specifically as follows:

[0021] S121: Train the LSTM network using the said features, where the features include mean, standard deviation, skewness, and kurtosis, and adopt the formula:

[0022]

[0023] Obtain the trained LSTM network model, where y i is the target output, V i is the i-th input feature vector, N is the total number of samples, and E is the average error during the training process;

[0024] S122: Use the trained LSTM network model to predict the feature vectors of the new dataset, and adopt the formula:

[0025]

[0026] Obtain the predicted behavior pattern where V new is the feature vector in the new dataset, and M is the trained LSTM network model.

[0027] The improvement of the present invention is that the step of calculating the anomaly score is specifically as follows:

[0028] S211: Based on the behavior pattern dataset, extract the key features of the data packet, including the traffic size and duration, and calculate the anomaly score of the data packet, using the formula:

[0029]

[0030] Obtain the anomaly score SE i of the i-th data packet, where βQ k is the weight of feature k, is the average value of feature k in the training data, is the k-th feature value in data packet i, and K E is the total number of features;

[0031] S212: Conduct statistical analysis on the anomaly scores to determine the distribution characteristics of the anomaly scores, using the formula:

[0032]

[0033] and

[0034]

[0035] Obtain the average value of the anomaly scores and the standard deviation where N E is the total number of data packets, and SE iis the anomaly score of the i-th data packet.

[0036] The improvement of the present invention is that the step of obtaining the anomaly-marked data packet is specifically as follows:

[0037] S221: Using the calculated anomaly score, automatically set the anomaly threshold, using the formula:

[0038]

[0039] Get the anomaly threshold T a , where is the average value of the anomaly scores, is the standard deviation of the anomaly scores, k a is the standard deviation multiplier;

[0040] S222: Based on the anomaly threshold, screen and mark each data packet, compare the anomaly score of the data packet with the anomaly threshold, using the formula:

[0041]

[0042] Get the anomaly-marked data packet, where is the anomaly mark of data packet i, SE i is the anomaly score of data packet i, T a is the anomaly threshold.

[0043] The improvement of the present invention is that the step of performing in-depth feature analysis is specifically as follows:

[0044] S311: Based on the anomaly-marked data packet, extract preliminary features, including communication size, duration, and protocol type, calculate the feature index for each data packet, using the formula:

[0045]

[0046] Get the feature index FD, where and are feature weights, assigned according to the data packet features, and are the communication size, duration, and protocol type of the i-th data packet respectively, n D is the total number of data packets;

[0047] S312: Based on the feature index, perform in-depth feature analysis to identify anomaly patterns, using the formula:

[0048]

[0049] Obtain a deep analysis result FD′ for identifying data packets deviating from the normal state, where FD i is the characteristic index of data packet i, is the average value of the characteristic indices, and n D is the total number of data packets;

[0050] S313: Based on the deep analysis result, select the characteristics including those above or below the average level to determine the key characteristics.

[0051] The improvement of the present invention is that the obtaining step of the optimized detection configuration is specifically as follows:

[0052] S321: Use the genetic algorithm to adjust the LSTM network structure, and adopt the formula:

[0053] LH new = K H ·θ H

[0054] Obtain new network parameters LH new , where K H represents the numerical value of the key feature set, and θ H is the parameter vector;

[0055] S322: Based on the new network parameters, verify the performance of the optimized model, and adopt the formula:

[0056]

[0057] Obtain the performance index PH in the model verification stage, where yh i is the current label value of the i-th data point, is the label value predicted by the model for the i-th data point, and n H is the total number of samples in the data set;

[0058] S323: Based on the performance index in the model verification stage, refine the anomaly detection ability of the LSTM network model to obtain an optimized detection configuration.

[0059] The improvement of the present invention is that the obtaining step of the adjusted detection model is specifically as follows:

[0060] S411: Based on the optimized detection configuration, use encrypted traffic data to test the threat detection ability of the LSTM network, and judge whether the model before adjustment meets the performance standard, and adopt the judgment formula:

[0061] CB = (SB t ≤ ∈ b )

[0062] Obtain the performance comparison result CB, where SB t is the average error in the test phase, ∈ b is the performance threshold;

[0063] S412: Based on the performance comparison result, adjust the model parameters. Using the gradient descent method, adopt the formula:

[0064]

[0065] Obtain the adjusted model parameters where, are the model parameters before adjustment, η B is the learning rate, is the gradient of the loss function J with respect to the parameter θ.

[0066] A deep learning-based encrypted traffic threat detection system, the system includes:

[0067] The feature extraction module performs time series analysis on the data stream based on the encrypted traffic data, extracts traffic behavior features, trains a long short-term memory network, matches changes in the behavior pattern, and generates a behavior pattern data set;

[0068] The anomaly detection module calculates the anomaly score of each data packet through the anomaly score algorithm based on the behavior pattern data set, automatically sets and adjusts the anomaly threshold, and performs anomaly screening and marking of the data packets to generate anomaly-marked data packets;

[0069] The network optimization module performs in-depth feature analysis on the data packets based on the anomaly-marked data packets, optimizes the LSTM network structure using the genetic algorithm, refines the anomaly detection performance, and generates an optimized detection configuration;

[0070] The performance evaluation module tests the threat detection performance of the long short-term memory network using the encrypted traffic data based on the optimized detection configuration, compares the results with the performance standard, matches the current threat environment, and generates an adjusted detection model;

[0071] The configuration and deployment module evaluates the model effectiveness based on the adjusted detection model according to the key performance indicators, including network traffic and error rate, and determines the parameter settings before deploying the detection model to generate the detection model deployment result.

[0072] Compared with the prior art, the advantages and positive effects of the present invention are:

[0073] In the present invention, through the long short-term memory network, the ability of encrypted traffic threat detection is improved. It can extract traffic behavior features through time series analysis without decrypting the data, allowing the system to capture subtle changes in behavior patterns, thereby effectively identifying abnormal behaviors hidden in encrypted traffic. The abnormal score algorithm automatically adjusts the abnormal threshold to reduce the false alarm rate and improve the automation level of data processing. The genetic algorithm enables the LSTM network structure to automatically adapt to changes in the network environment, enhancing the dynamic monitoring ability and improving the efficiency and accuracy of threat detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0074] Figure 1 is a flowchart of the method for detecting encrypted traffic threats based on deep learning proposed by the present invention;

[0075] Figure 2 is a flowchart for extracting traffic behavior features in the present invention;

[0076] Figure 3 is a flowchart for obtaining the behavior pattern data set in the present invention;

[0077] Figure 4 is a flowchart for calculating the abnormal score in the present invention;

[0078] Figure 5 is a flowchart for obtaining abnormal marked data packets in the present invention;

[0079] Figure 6 is a flowchart for performing deep feature analysis in the present invention;

[0080] Figure 7 is a flowchart for obtaining the optimized detection configuration in the present invention;

[0081] Figure 8 is a flowchart for obtaining the adjusted detection model in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0082] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0083] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation on the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more unless otherwise specifically defined.

[0084] Embodiment

[0085] Please refer to Figure 1 , the present invention provides a technical solution: an encryption traffic threat detection method based on deep learning, including the following steps:

[0086] S1: Based on the encrypted traffic data, perform time series analysis on the data stream, extract traffic behavior characteristics, use the characteristics to train the LSTM network, match the changes in behavior patterns, and perform predictive analysis on future data to obtain a behavior pattern data set;

[0087] S2: Based on the behavior pattern data set, calculate the anomaly score for each data packet through the anomaly score algorithm, automatically set and adjust the anomaly threshold, and perform anomaly data screening and marking to obtain anomaly-marked data packets;

[0088] S3: Based on the anomaly-marked data packets, perform in-depth feature analysis on the data packets, extract key features, use the genetic algorithm to optimize the LSTM network structure, refine the anomaly detection ability, and obtain an optimized detection configuration;

[0089] S4: Based on the optimized detection configuration, use the encrypted traffic data to test the threat detection ability of the LSTM network, compare the performance data with the performance standard, and adjust the LSTM network parameters according to the test results to obtain an adjusted detection model.

[0090] The behavior pattern data set includes the pattern change trend, abnormal activity time, and behavior consistency measure. The anomaly-marked data packets include the marked timestamp, marked priority, and correlation scoring result. The optimized detection configuration includes the hierarchical adjustment result, parameter adjustment record, and performance improvement point.

[0091] Please refer to Figure 2 , the specific steps for extracting traffic behavior characteristics are as follows:

[0092] S111: Based on the encrypted traffic data, use the autocorrelation function to perform time series analysis on the encrypted traffic data and perform windowing processing, using the formula:

[0093]

[0094] Obtain the window feature vector, where μ is the weighted average autocorrelation coefficient in the window, r j is the autocorrelation coefficient of the j-th data point in the window, w is the window size, i.e., the number of consecutive data points, and β j is the weight of the j-th data point in the window;

[0095] S112: Based on the window feature vector, calculate the skewness and kurtosis of each window using the formulas:

[0096]

[0097] and

[0098]

[0099] Obtain the key statistical features, where S represents the skewness calculated from the window, K represents the kurtosis calculated from the window, and σ is the standard deviation of the data in the window.

[0100] β j is defined as

[0101] The obtained autocorrelation coefficient array is:

[0102] {-0.2485, 0.1902, -0.0534, 0.3001, -0.1163}

[0103] Select the window size w = 3 and set γ = 0.5;

[0104] The process of calculating the weighted average μ with the window center at r2 is as follows:

[0105] Calculate β j :

[0106]

[0107] β2 = 1 (center point)

[0108] β3 = 0.8889 (symmetric weight)

[0109] Calculate μ:

[0110] μ = β1 × r1 + β2 × r2 + β3 × r3

[0111] μ = 0.8 × (-0.2485) + 1 × 0.1902 + 0.8 × (-0.0534)

[0112] μ = -0.1988 + 0.1902 - 0.04272 ≈ -0.05132

[0113] The average autocorrelation coefficient μ in the window is -0.0781, indicating that within this window, the correlation of the time series tends to be negatively correlated, but the effect is relatively slight. This indicator can help identify the local characteristics of data behavior.

[0114] The calculation method of σ is

[0115] Using the above data and, the process of calculating the skewness S and kurtosis K is as follows:

[0116] Calculate σ:

[0117] σ 2 = β1 × (r1 - μ) 2 + β2 × (r2 - μ) 2 + β3 × (r3 - μ) 2

[0118] σ 2 = 0.8 × (-0.2485 + 0.0781) 2 + 1 × (0.1902 + 0.0781) 2

[0119] + 0.8 × (-0.0534 + 0.0781) 2

[0120] σ 2 = 0.8 × 0.0290 2 + 1 × 0.2683 2 + 0.8 × 0.0247 2

[0121] σ 2 = 0.8 × 0.000841 + 0.072019 + 0.8 × 0.000610 ≈ 0.073

[0122]

[0123] Calculate S and K:

[0124]

[0125] The results show that the skewness S ≈ 0.7803 and the kurtosis K ≈ -2.306, indicating that within the selected window, the distribution of the autocorrelation coefficient is slightly biased towards negative values, the distribution is relatively flat and has slight peaks, which helps to identify abnormal behaviors or prominent features in the data.

[0126] Please refer to Figure 3 , the specific steps for obtaining the behavior pattern dataset are:

[0127] S121: Train the LSTM network using features, which include mean, standard deviation, skewness, and kurtosis, with the formula:

[0128]

[0129] Obtain the trained LSTM network model, where y i is the target output, V i is the i-th input feature vector, N is the total number of samples, and E is the average error during the training process;

[0130] S122: Use the trained LSTM network model to predict the feature vectors of the new dataset, with the formula:

[0131]

[0132] Obtain the predicted behavior pattern where V new is the feature vector in the new dataset, and M is the trained LSTM network model.

[0133] There are observations of 5 data points:

[0134] y = {2, 4, 5, 6, 7}

[0135] and the corresponding predicted values:

[0136]

[0137] The process of calculating the average error is as follows:

[0138] Calculate the squared error for each data point:

[0139] (2 - 2.1) 2 = 0.01

[0140] (4 - 3.9) 2 = 0.01

[0141] (5 - 4.8) 2 = 0.04

[0142] (6 - 6.1) 2 = 0.01

[0143] (7 - 7.2) 2 = 0.04

[0144] Sum up the squared errors:

[0145] 0.01 + 0.01 + 0.04 + 0.01 + 0.04 = 0.11

[0146] Calculate the average error E:

[0147]

[0148] The result shows that the average error of the LSTM model on the dataset is 0.022, indicating that the model can fit the actual data well with a small error.

[0149] Collect the feature vector V of the new data new ={3.5, 2.5, 0.5, 1.0};

[0150] Use this vector to make predictions on the trained LSTM model:

[0151]

[0152] According to the current data features, the output of the model predicting future behavior is 5.5, representing a quantitative evaluation of a specific behavior pattern or trend.

[0153] Please refer to Figure 4 , and the steps for calculating the anomaly score are specifically as follows:

[0154] S211: Based on the behavior pattern dataset, extract the key features of the data packet, including the traffic size and duration, and calculate the anomaly score for the data packet using the formula:

[0155]

[0156] Obtain the anomaly score SE of the i-th data packet i , where βQ k is the weight of feature k, is the average value of feature k in the training data, is the k-th feature value in data packet i, and K E is the total number of features;

[0157] S212: Conduct statistical analysis on the anomaly scores to determine the distribution characteristics of the anomaly scores using the formula:

[0158]

[0159] and

[0160]

[0161] Obtain the average value and the standard deviation where N E is the total number of data packets, and SE i is the anomaly score of the i-th data packet.

[0162] Three features are collected: packet size, duration, and signal strength, with corresponding weights βQ k being 0.5, 0.3, and 0.2 respectively;

[0163] The weights are based on data analysis. Among them, the variability of packet size is the largest, so the weight is the highest, and the historical average of each feature is 100 bytes, 50 ms, and -70 dBm respectively;

[0164] There is currently a data packet i with its feature values being 110 bytes, 45 ms, and -75 dBm respectively.

[0165] Calculation of the fraction of packet size:

[0166]

[0167] Calculation of the fraction of duration:

[0168]

[0169] Calculation of the fraction of signal strength:

[0170]

[0171] The total score SE i is:

[0172] SE i = 50 + 7.5 + 5 = 62.5

[0173] The calculated result SE i = 62.5 indicates the degree of deviation of data packet i from normal behavior. A high anomaly score indicates that the data packet may be abnormal and requires further review or measures.

[0174] βQ3 is the weight of the signal strength feature and is 0.2;

[0175] is the signal strength feature value of the current data packet and is -75 dBm;

[0176] is the average value of signal strength in historical data and is -70 dBm.

[0177] Calculate the deviation between the signal strength of the current data packet and the historical average:

[0178]

[0179] It means that the signal strength of the current data packet is 5 dBm lower than the average value.

[0180] Square the deviation value to eliminate the negative sign and amplify the difference:

[0181] (-5) 2 =25

[0182] The squared value is 25, representing the quantification of the deviation, regardless of the direction of the deviation (positive or negative).

[0183] Multiply the calculated squared deviation by the weight of the signal strength to obtain the weighted anomaly score for this feature:

[0184] βQ3·25=0.2·25=5

[0185] The result of multiplying the weight by the squared deviation is 5, the contribution value to the overall anomaly score;

[0186] The obtained partial anomaly score value of 5 indicates that this data packet has a significant deviation from the historical average in terms of signal strength.

[0187] Please refer to Figure 5 , the specific steps for obtaining the anomaly - marked data packets are as follows:

[0188] S221: Use the calculated anomaly score to automatically set the anomaly threshold, using the formula:

[0189]

[0190] to obtain the anomaly threshold T a , where is the average value of the anomaly scores, is the standard deviation of the anomaly scores, and k a is the standard - deviation multiplier;

[0191] S222: Based on the anomaly threshold, screen and mark each data packet, comparing the anomaly score of the data packet and the anomaly threshold, using the formula:

[0192]

[0193] to obtain the anomaly - marked data packet, where is the anomaly mark of data packet i, SE i is the anomaly score of data packet i, and T a is the anomaly threshold.

[0194] The anomaly scores obtained from 100 data packets are as follows (a total of 100 values):

[0195] SE i ={20,22,19,18,30,...}

[0196] Calculate the average value

[0197]

[0198] Assume the calculation result is

[0199] Calculate the standard deviation

[0200]

[0201] Assume the calculation result is

[0202] Set the threshold T a :

[0203] T a = 25 + 3·5 = 40

[0204] Select k a = 3 to ensure that the threshold is high enough to reduce false positives.

[0205] T a = 40 indicates that any data packet with an anomaly score higher than 40 will be considered an anomaly;

[0206] Since the threshold is 40, the collected anomaly scores are (42, 35, 45, 25, 50):

[0207] Data packet score 42: 42 ≥ 40 = 1, is an anomaly;

[0208] Data packet score 35: 35 ≥ 40 = 0, is normal;

[0209] Data packet score 45: 45 ≥ 40 = 1, is an anomaly;

[0210] Data packet score 25: 25 ≥ 40 = 0, is normal;

[0211] Data packet score 50: 50 ≥ 40 = 1, is an anomaly;

[0212] This process marks which data packets are anomalies, providing a basis for further analysis.

[0213] Please refer to Figure 6 , the steps for in-depth feature analysis are specifically as follows:

[0214] S311: Based on the anomaly-marked data packets, extract preliminary features, including communication size, duration, and protocol type, calculate the feature index for each data packet, using the formula:

[0215]

[0216] Obtain the feature index FD, where, and are feature weights, which are assigned according to the data packet features, and are the communication size, duration, and protocol type of the i-th data packet respectively, where n D is the total number of data packets;

[0217] S312: Based on the feature index, perform in-depth feature analysis to identify abnormal patterns, using the formula:

[0218]

[0219] Obtain the in-depth analysis result FD′ for identifying data packets that deviate from the normal state, where FD i is the feature index of data packet i, is the average value of the feature index, and n D is the total number of data packets;

[0220] S313: Based on the in-depth analysis result, select features that are above or below the average level to determine the key features.

[0221] The information of three data packets is monitored as follows:

[0222] Data packet 1:

[0223]

[0224] Data packet 2:

[0225]

[0226] Data packet 3:

[0227]

[0228] The weight is set to

[0229] Calculate FD:

[0230] FD = (0.5×1500 + 1.5×0.2 + 1×1) + (0.5×1000 + 1.5×0.1 + 1×2)

[0231] + (0.5×1200 + 1.5×0.3 + 1×1)

[0232] FD = (750 + 0.3 + 1) + (500 + 0.15 + 2) + (600 + 0.45 + 1)

[0233] FD = 751.3 + 502.15 + 601.45

[0234] FD = 1854.9

[0235] FD = 1854.9 represents the weighted sum of the characteristics of three data packets, representing the characteristic strength of the overall data packet.

[0236] Use the aforementioned combination and the data of 3 data packets;

[0237] Calculate the average value

[0238]

[0239] Calculate the variance:

[0240]

[0241] The result shows that the degree of dispersion of the eigenvalue is quite high, indicating some abnormal activities or behaviors in the data packet. In network security and monitoring systems, characteristic data with high variance may indicate network attacks, data leaks, or other security threats.

[0242] Please refer to Figure 7 , the specific steps for obtaining the optimized detection configuration are as follows:

[0243] S321: Use the genetic algorithm to adjust the LSTM network structure, using the formula:

[0244] LH new = K H ·θ H

[0245] Obtain the new network parameter LH new , where K H represents the numerical value of the key feature set, and θ H is the parameter vector;

[0246] S322: Based on the new network parameters, verify the performance of the optimized model, using the formula:

[0247]

[0248] Obtain the performance index PH in the model verification stage, where yh i is the current label value of the i-th data point, is the label value predicted by the model for the i-th data point, and n H is the total number of samples in the dataset;

[0249] S323: Based on the performance index in the model verification stage, refine the anomaly detection ability of the LSTM network model to obtain the optimized detection configuration.

[0250] Let K Hand θ H The dimensions match, and the dot product operation can be directly performed. The specific values are as follows:

[0251] K H =[1.5, 2.0, 0.5]

[0252] represents the importance score of the key features extracted from the abnormal data packets;

[0253] θ H =[0.5, 1.5, 0.75]

[0254] represents the optimized parameters obtained by the genetic algorithm, and the parameters correspond to the adjustment weights of different features respectively

[0255] Perform the dot product operation, and multiply the adjustment weight of each feature by its importance score respectively:

[0256] LH new =[1.5×0.5, 2.0×1.5, 0.5×0.75]=[0.75, 3.0, 0.375]

[0257] The calculation result [0.75, 3.0, 0.375] shows the weights of each feature in the optimized model, which will directly affect the model's parsing and prediction effects on the data.

[0258] The dataset for model validation contains 100 data points;

[0259] The actual labels and predicted labels of the data points are as follows:

[0260] The value of the current label yh is [1, 0, 1, 1, 0, 1, 0, 1, 1, 0,..., 1];

[0261] Model prediction The value of is [1, 1, 1, 1, 0, 0, 1, 0, 1, 0, 1,..., 1];

[0262] Assume that the differences between the model prediction values and the current values are as follows (the first 10):

[0263] Difference The value of:

[0264] [0, -1, 0, 1, 0, 0, 0, 0, 1, -1,..., 0]

[0265] Calculate the sum of squared errors:

[0266]

[0267] Substitute this value into the formula to calculate the performance metric PH:

[0268]

[0269] A lower pH value indicates that the prediction error of the model is relatively small, indicating that the model has good prediction ability.

[0270] Please refer to Figure 8 , and the steps for obtaining the adjusted detection model are specifically as follows:

[0271] S411: Based on the optimized detection configuration, use the encrypted traffic data to test the threat detection ability of the LSTM network, and judge whether the model before adjustment meets the performance standard. The judgment formula is:

[0272] CB = (SB t ≤∈ b )

[0273] Obtain the performance comparison result CB, where SB t is the average error in the test phase, and ∈ b is the performance threshold;

[0274] S412: Based on the performance comparison result, adjust the model parameters. Use the gradient descent method with the formula:

[0275]

[0276] Obtain the adjusted model parameters where, is the model parameter before adjustment, η B is the learning rate, is the gradient of the loss function J with respect to the parameter θ.

[0277] In the actual test, the prediction results of the model on 100 samples were compared with the actual data, and the specific values are as follows:

[0278] SB t = 0.15

[0279] ∈ b = 0.1

[0280] Judgment process:

[0281] CB = (0.15 ≤ 0.1)

[0282] CB = False

[0283] The comparison result is false, which means that the performance of the model does not meet the predetermined standard. Therefore, further parameter adjustment is required to optimize the model.

[0284] Obtained from the model configuration or previous optimization iterations;

[0285] ηB Determined through the debugging phase of the model to achieve fast and stable convergence;

[0286] Calculated during the model training process through the backpropagation algorithm;

[0287] The following data was collected:

[0288]

[0289] η B = 0.01;

[0290]

[0291] Calculation process:

[0292]

[0293] The new parameter values represent the model parameters after fine-tuning, which helps to improve the prediction performance of the model and ensure the effectiveness and reliability of the detection model in practical applications.

[0294] A deep learning-based encrypted traffic threat detection system, the system includes:

[0295] The feature extraction module is based on encrypted traffic data, performs time series analysis on the data stream, extracts traffic behavior features, trains a long short-term memory network, matches changes in behavior patterns, and generates a behavior pattern data set;

[0296] The anomaly detection module is based on the behavior pattern data set, calculates the anomaly score of each data packet through the anomaly score algorithm, automatically sets and adjusts the anomaly threshold, and performs anomaly screening and marking of the data packets to generate anomaly-marked data packets;

[0297] The network optimization module is based on the anomaly-marked data packets, performs in-depth feature analysis on the data packets, optimizes the LSTM network structure using the genetic algorithm, refines the anomaly detection performance, and generates an optimized detection configuration;

[0298] The performance evaluation module is based on the optimized detection configuration, uses encrypted traffic data, tests the threat detection performance of the long short-term memory network, compares the results with the performance standard, matches the current threat environment, and generates an adjusted detection model;

[0299] The configuration and deployment module is based on the adjusted detection model, evaluates the model effectiveness according to key performance indicators, including network traffic and error rate, and determines the parameter settings before the detection model is deployed, generating the detection model deployment result.

[0300] The above are only the preferred embodiments of the present invention, and do not impose other forms of limitation on the present invention. Any person skilled in the relevant art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. The encrypted traffic threat detection method based on deep learning is characterized by: The following steps are involved: Based on encrypted traffic data, we conduct time series analysis on the data stream, extract traffic behavior features, use the features to train the LSTM network, match the behavior pattern changes, and perform predictive analysis on future data to obtain a behavior pattern data set. Based on the behavior pattern data set, an anomaly score algorithm is used to calculate an anomaly score for each data packet, an anomaly threshold is automatically set and adjusted, and anomaly data is screened and marked to obtain an anomaly marked data packet; The steps of obtaining the abnormal marking data packet are specifically as follows: Using the calculated anomaly score, the anomaly threshold is automatically set using the formula: Get the abnormal threshold T a ,in, is the average of the anomaly scores, is the standard deviation of the anomaly score, k a is the standard deviation multiplier; Based on the anomaly threshold, each data packet is screened and marked, and the anomaly score of the data packet is compared with the anomaly threshold, using the formula: Get the abnormal marked data packet, where is the abnormal flag of packet i, SE i is the anomaly score of packet i, T a is the abnormal threshold; Based on the abnormal marked data packets, deep feature analysis is performed on the data packets to extract key features, and the LSTM network structure is optimized using a genetic algorithm to refine the abnormal detection capability and obtain an optimized detection configuration; Based on the optimized detection configuration, the threat detection capability of the LSTM network is tested using encrypted traffic data, the performance data is compared with the performance standard, and the LSTM network parameters are adjusted according to the test results to obtain an adjusted detection model.

2. The encrypted traffic threat detection method based on deep learning according to claim 1 is characterized in that: The steps of extracting the traffic behavior features are specifically as follows: Based on the encrypted traffic data, the autocorrelation function is used to perform time series analysis on the encrypted traffic data and perform window processing using the formula: Get the window feature vector, where μ is the weighted average autocorrelation coefficient in the window, r j is the autocorrelation coefficient of the jth data point in the window, w is the window size, β j is the weight of the jth data point in the window; Based on the window feature vector, the skewness and kurtosis of each window are calculated using the formula: and The key statistical features are obtained, where S represents the skewness calculated from the window, K represents the kurtosis calculated from the window, and σ is the standard deviation of the data in the window.

3. The encrypted traffic threat detection method based on deep learning according to claim 1 is characterized in that: The steps for obtaining the behavior pattern data set are specifically as follows: The LSTM network is trained using the features, including mean, standard deviation, skewness and kurtosis, using the formula: Get the trained LSTM network model, where y i is the target output, V i is the i-th input feature vector, N is the total number of samples, and E is the average error during training; Using the trained LSTM network model, the feature vector of the new data set is predicted using the formula: Get predicted behavior patterns Among them, V new is the feature vector in the new data set, and M is the trained LSTM network model.

4. The encrypted traffic threat detection method based on deep learning according to claim 1 is characterized in that: The steps of calculating the anomaly score are specifically as follows: Based on the behavior pattern dataset, the key features of the data packet, including the traffic size and duration, are extracted, and the anomaly score of the data packet is calculated using the formula: Get the abnormal score SE of the i-th data packet i , where βQ k is the weight of feature k, is the average value of feature k in the training data, is the kth eigenvalue in data packet i, K E is the total number of features; The anomaly scores are statistically analyzed to determine the distribution characteristics of the anomaly scores, using the formula: and Get the average of the anomaly scores and standard deviation Among them, N E is the total number of packets, SE i is the anomaly score of the ith packet.

5. The encrypted traffic threat detection method based on deep learning according to claim 1 is characterized in that: The steps of performing deep feature analysis are specifically as follows: Based on the abnormally marked data packets, preliminary features are extracted, including communication size, duration and protocol type, and the feature index of each data packet is calculated using the formula: The characteristic index FD is obtained, where and is the feature weight, which is assigned according to the characteristics of the data packet. and are the communication size, duration and protocol type of the ith data packet, n D is the total number of packets; Based on the characteristic index, deep feature analysis is performed to identify abnormal patterns using the formula: The deep analysis result FD′ is obtained to identify packets that deviate from the normal state, where FD i is the characteristic index of packet i, is the average value of the characteristic index, n D is the total number of packets; Based on the in-depth analysis results, features that are above or below average are selected to determine key features.

6. The encrypted traffic threat detection method based on deep learning according to claim 1 is characterized in that: The steps for obtaining the optimized detection configuration are specifically as follows: Using the genetic algorithm, the LSTM network structure is adjusted using the formula: LH new =K H ·i H Get the new network parameters LH new , where K H Represents the value of the key feature set, θ H is the parameter vector; Based on the new network parameters, the performance of the optimized model is verified using the formula: The performance index PH of the model verification phase is obtained, where yh i is the current label value of the ith data point, is the label value predicted by the model for the i-th data point, n H is the total number of samples in the dataset; Based on the performance indicators of the model verification phase, the anomaly detection capability of the LSTM network model is refined to obtain an optimized detection configuration.

7. The encrypted traffic threat detection method based on deep learning according to claim 1 is characterized in that: The steps for obtaining the adjusted detection model are specifically as follows: Based on the optimized detection configuration, the threat detection capability of the LSTM network is tested using encrypted traffic data to determine whether the model before adjustment meets the performance standards. The judgment formula is: CB=(SB t ≤∈ b ) The performance comparison result CB is obtained, where SB t is the average error in the test phase, ∈ b is the performance threshold; Based on the performance comparison results, the model parameters are adjusted using the gradient descent method using the formula: Get the adjusted model parameters in, is the model parameter before adjustment, η B is the learning rate, is the gradient of the loss function J with respect to the parameter θ.

8. The encrypted traffic threat detection system based on deep learning is characterized by: According to the method for detecting encrypted traffic threats based on deep learning according to any one of claims 1 to 7, the system comprises: The feature extraction module performs time series analysis on the data stream based on encrypted traffic data, extracts traffic behavior features, trains long-term and short-term memory networks, matches behavior pattern changes, and generates behavior pattern data sets; The anomaly detection module calculates the anomaly score of each data packet based on the behavior pattern data set through an anomaly score algorithm, automatically sets and adjusts the anomaly threshold, and performs anomaly screening and marking of the data packet to generate an anomaly marked data packet; The network optimization module performs in-depth feature analysis on the data packets based on the abnormally marked data packets, optimizes the LSTM network structure using a genetic algorithm, refines the abnormality detection performance, and generates an optimized detection configuration; The performance evaluation module uses encrypted traffic data based on the optimized detection configuration to test the threat detection performance of the long short-term memory network, compares the results with the performance standards, matches the current threat environment, and generates an adjusted detection model; the configuration and deployment module uses the adjusted detection model according to key performance indicators, including network traffic and error rate. Conduct model performance evaluation, determine parameter settings before detection model deployment, and generate detection model deployment results.

Citation Information

Patent Citations

  • GRU parallel network flow anomaly detection method based on GA optimization

    CN111726349A

  • Encrypted malicious traffic detection and attack identification method based on deep learning

    CN115589314A