An Encrypted Malicious Traffic Detection Method and System for Cloud-edge Computing Environment

By adopting multimodal deep learning model and feature fusion technology in the cloud environment and combining cloud service entity knowledge, the problem of poor encryption malicious traffic detection in the cloud environment is solved, and more efficient and accurate detection is achieved.

CN119382984BActive Publication Date: 2025-06-03WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411528639.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-06-03
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

Encrypted malicious traffic detection in the cloud environment is difficult to adapt to complex network traffic data and diversified cloud service links, resulting in poor detection results.

Method used

Multimodal technology and deep learning models are used to build an encrypted malicious traffic identification network in the cloud environment, integrate global features through self-attention mechanism, extract time features in combination with BiLSTM, and use cross-attention mechanism to perform feature fusion to mine the knowledge of inter-cloud service entities to assist detection.

Benefits of technology

It improves the efficiency and accuracy of encrypted malicious traffic detection in the cloud environment, and can more effectively handle complex network traffic data and diversified cloud service links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382984B_ABST
    Figure CN119382984B_ABST
Patent Text Reader

Abstract

The present invention discloses an encrypted malicious traffic detection method and system for an inter-cloud computing environment. The method mainly includes the following steps: preprocessing encrypted traffic; using a deep learning model to extract the spatial features and temporal features of the preprocessed encrypted traffic, and after feature extraction, adopting a feature fusion technology based on a cross-attention mechanism to fuse the two features; mining the inter-cloud service entity knowledge in the inter-cloud environment to assist the model in detecting encrypted malicious traffic in the inter-cloud environment; the model fuses the spatio-temporal features of encrypted traffic and the inter-cloud service entity knowledge to detect encrypted malicious traffic in the inter-cloud environment. Based on a deep learning model, the present invention simultaneously utilizes multi-modal technology and external knowledge of the inter-cloud environment, and can effectively solve the problem of detecting encrypted malicious traffic in the inter-cloud environment and maintain the network security of the inter-cloud environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network security, and particularly to an encrypted malicious traffic detection method and system for an inter-cloud computing environment. Background Art

[0002] Inter-cloud computing is based on the open cooperation among multiple cloud service entities. Through the deep integration of multi-party cloud resources, it enables developers to customize cloud services and create cloud value in a "software-defined" manner, and can realize cross-cloud collaboration and integrated network service customization, which is a new generation of cloud computing paradigm. Inter-cloud computing can achieve interconnection between clouds, enabling high-level collaborative cooperation among entities such as clouds, edges, and terminals. It is the underlying support technology for the Internet of Everything scenario, with many advantages such as high performance, large capacity, and high availability.

[0003] Compared with the traditional cloud environment, in the inter-cloud environment, the number of cloud service providers and cloud service consumers is huge and the sources are numerous. Large-scale diverse data interaction and data collaboration have become the norm, and cross-cloud and cross-organization data collaboration is an important collaboration method in the inter-cloud computing environment. However, the complexity and diversity of the inter-cloud environment also pose greater security challenges. There are many interconnected entities and various complex cloud service links in the inter-cloud environment. There are a large number of collaborative work and resource sharing behaviors among various entities, and these behaviors are all realized through the interaction of network traffic. The frequent circulation of network traffic also makes the inter-cloud environment face a huge risk of being attacked by malicious traffic. Among them, encrypted malicious traffic can encrypt communication content through various encryption algorithms and protocols to avoid detection and interception. Its existence brings great hidden dangers to the ecosystem of the inter-cloud environment. Therefore, it is very necessary to study the detection of encrypted malicious traffic in the inter-cloud environment. Traditional encrypted malicious traffic detection mainly includes three categories: rule-based detection algorithms, machine learning or deep learning detection algorithms based on manual feature extraction, and deep learning detection algorithms based on feature self-learning. Rule-based detection algorithms have low recognition efficiency; machine learning or deep learning detection algorithms based on manual feature extraction are complex and laborious; deep learning detection algorithms based on feature self-learning have excellent performance in traditional network environments due to their good non-linear modeling ability. These traditional encrypted malicious traffic detection algorithms have good performance in conventional network environments. However, due to the characteristics of large data interaction volume, many service entities, and complex collaboration links in the inter-cloud environment, traditional detection methods are difficult to apply to the inter-cloud environment.

[0004] Compared with the research on encrypted malicious traffic detection in traditional network environments, encrypted malicious traffic detection in the inter-cloud environment faces the following challenges: (1) Different from conventional network environments and cloud environments, network traffic data in the inter-cloud environment is often much larger and contains a lot of redundant information, and encrypted malicious traffic detection research needs to process more complex data; (2) There are a large number of entities in the inter-cloud environment, the cloud service process is complex, and complex behaviors such as resource sharing and collaborative work among entities give encrypted malicious traffic a larger flow space, making the efficiency and accuracy of detection unable to meet the requirements; (3) Currently, the methods for encrypted malicious traffic detection in traditional network environments are difficult to cope with the complex inter-cloud environment.

[0005] It can be seen that the problem of encrypted malicious traffic detection research in the inter-cloud environment urgently needs to be solved. Summary of the Invention

[0006] In view of the above defects or improvement requirements of the existing technology, the present invention provides an encrypted malicious traffic detection method for the inter-cloud computing environment, thereby solving the technical problem of poor detection effect of the existing method and filling the gap in the research of encrypted malicious traffic detection in the inter-cloud environment.

[0007] To achieve the above object, the technical solution adopted by the present invention is as follows:

[0008] In a first aspect, an encrypted malicious traffic detection method for the inter-cloud computing environment is provided, including:

[0009] Preprocess the original encrypted traffic data to obtain an encrypted traffic graph;

[0010] Use an encrypted traffic recognition network constructed based on the BoTNet model to integrate global features through a self-attention mechanism and extract the spatial features of the encrypted traffic image;

[0011] Use the BiLSTM model to extract the temporal features containing forward and backward temporal information in the encrypted traffic image;

[0012] Use a feature fusion technology based on a cross-attention mechanism to fuse the extracted spatial features and temporal features;

[0013] Mine the knowledge of inter-cloud service entities in the inter-cloud environment;

[0014] Detect the encrypted malicious traffic existing in the inter-cloud environment according to the fused features and the mined knowledge of inter-cloud service entities.

[0015] In one implementation, preprocessing the original encrypted traffic data to obtain an encrypted traffic graph includes:

[0016] The original encrypted traffic data is subjected to traffic segmentation, traffic cleaning, and the length of the data packets is unified. Finally, each data packet is converted into a grayscale image.

[0017] In one implementation, the encrypted traffic recognition network based on the BoTNet model builds the backbone network based on the BoTNet model, which consists of 4 stages. The first 3 stages are composed of Bottlenecks, and are internally connected by residual networks. The 4th stage is a BoT module containing a multi-head self-attention mechanism.

[0018] In one implementation, the encrypted traffic recognition network based on the BoTNet model integrates global features through the self-attention mechanism to extract the spatial features of the encrypted traffic image, including:

[0019] Using Bottleneck to extract features from the encrypted traffic map:

[0020] Y = ReLU(W 3 * ReLU(W 2 * ReLU(W 1 * x neck )) + x neck )

[0021] where Y represents the output of each Bottleneck, and x neck represents the feature input of the Bottleneck, and W 1 , W 2 , W 3 represent the weight matrices of three convolutions in sequence, * represents the convolution operation, and ReLU is the activation function;

[0022] Using the BoT module to aggregate the feature information captured by the convolutional network through the global self-attention mechanism:

[0023] F S = ReLU(W 3 * MHSA(ReLU(W 1 * x BoT )) + x BoT )

[0024] where x BoT represents the feature input of the BoT module, and W 1 , W 3 represent the weight matrices of two convolutions in sequence, MHSA represents the multi-head self-attention mechanism, * represents the convolution operation, ReLU is the activation function, and the output feature map F S serves as the spatial feature of the encrypted traffic.

[0025] In one implementation, the extracted spatial features and temporal features are fused using a feature fusion technique based on cross-attention mechanism, including:

[0026] Based on the cross-attention mechanism, two independent embedding sequences of the same dimension are combined in an asymmetric manner on the input. Among them, the cross-attention mechanism uses two input sequences, one as the query input and the other as the key and value inputs. The query input corresponds to the spatial features of the encrypted traffic, and the key and value inputs correspond to the temporal features of the encrypted traffic.

[0027] In one implementation, mining the knowledge of inter-cloud service entities in the inter-cloud environment includes:

[0028] Mining the degree of association between the entities participating in the inter-cloud service, and generating a detection weight corresponding to each entity.

[0029] In one implementation, mining the degree of association between the entities participating in the inter-cloud service and generating a detection weight corresponding to each entity includes:

[0030] Determining the influencing factors of the degree of association;

[0031] Assigning different weights to the determined influencing factors to reflect the importance of each influencing factor to the degree of association of the host. For two inter-cloud service entities A and B in the inter-cloud environment, the degree of association calculation formula is:

[0032]

[0033] where R(A, B) represents the degree of association between A and B, S(A, B) represents the resource sharing frequency between A and B, C(A, B) represents the number of collaborative tasks between A and B, T(A, B) represents the network topology distance between A and B, and α 1 、α 2 and α 3 represent the weights corresponding to different influencing factors;

[0034] Normalizing the degree of association:

[0035]

[0036] where max(R) is the maximum value among all degrees of association, and mmin(R) is the minimum value among all degrees of association;

[0037] Establishing an association degree matrix to represent the entity association in the entire inter-cloud environment. The association degree matrix is:

[0038]

[0039] where n represents the number of entities, and R(A i , A j ) represents the degree of association between entity i and entity j. If i = j, then R(A i , A j ) = 1;

[0040] Generate the detection weight corresponding to each entity according to the association degree matrix. The detection weight of the i-th entity is:

[0041] W i = R(A i , A 1 ) + R(A i , A 2 ) + … + R(A i , A n )

[0042] Normalize the detection weights:

[0043]

[0044] where max(W) is the maximum value among all detection weights, min(W) is the minimum value among all detection weights, W i is the detection weight of the i-th entity, and W′ i is the normalized detection weight of the i-th entity.

[0045] Based on the same inventive concept, a second aspect of the present invention provides an encrypted malicious traffic detection system for a cloud-edge computing environment, including:

[0046] An encrypted traffic preprocessing module for preprocessing the original encrypted traffic data to obtain an encrypted traffic graph;

[0047] An encrypted traffic feature extraction module for integrating global features through a self-attention mechanism using an encrypted traffic recognition network constructed based on the BoTNet model to extract the spatial features of the encrypted traffic image;

[0048] And using the BiLSTM model to extract the temporal features containing forward and backward temporal information in the encrypted traffic image;

[0049] A cloud-edge service entity knowledge mining module for fusing the extracted spatial features and temporal features using a feature fusion technology based on a cross-attention mechanism;

[0050] A cloud-edge service entity knowledge mining module for mining cloud-edge service entity knowledge in the cloud-edge environment;

[0051] The cloud-edge encryption malicious traffic detection module is used to detect encrypted malicious traffic existing in the cloud-edge environment according to the fused features and the mined cloud-edge service entity knowledge.

[0052] Based on the same inventive concept, the third aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the encrypted malicious traffic detection method for the cloud-edge computing environment described in the first aspect.

[0053] Based on the same inventive concept, the fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the encrypted malicious traffic detection method for the cloud-edge computing environment described in the first aspect.

[0054] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:

[0055] (1) The present invention adopts multi-modal technology and deep learning models to construct an encrypted malicious traffic recognition network in the cloud-edge environment, and improves the model's ability to process complex network traffic data in the cloud-edge environment by fusing features of different modalities.

[0056] (2) The present invention proposes a method for mining cloud-edge service entity knowledge, which is used to mine the degree of association between each entity participating in the cloud-edge service, generate detection weights for each entity, and assist the entire model in detecting cloud-edge encrypted malicious traffic with this, effectively improving the detection effect of the model in the cloud-edge environment.

[0057] (3) The present invention converts encrypted network traffic data into an encrypted traffic graph, uses the model to capture the global and local features of the encrypted traffic, fuses all features in a way based on the attention mechanism, and effectively combines the cloud-edge service entity knowledge into the specific detection link, providing a new solution for the research on encrypted malicious traffic detection in the cloud-edge environment. Description of the Drawings

[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0059] Figure 1 It is the overall flowchart of the encrypted malicious traffic detection method for the cloud-edge computing environment in the embodiment of the present invention.

[0060] Figure 2Schematic flowchart of encrypted traffic preprocessing provided by an embodiment of the present invention;

[0061] Figure 3 Schematic diagram of the structure of an encrypted traffic recognition network constructed based on the BoTNet model in an embodiment of the present invention. Detailed implementation manners

[0062] The present invention discloses an encrypted malicious traffic detection method for an inter-cloud computing environment. The method mainly includes the following steps: preprocessing encrypted traffic; extracting spatial features and temporal features of the preprocessed encrypted traffic by using a deep learning model, and performing feature fusion on the two features by using a feature fusion technology based on a cross-attention mechanism after feature extraction; mining inter-cloud service entity knowledge in the inter-cloud environment to assist the model in detecting encrypted malicious traffic in the inter-cloud environment; and fusing the spatio-temporal features and inter-cloud service entity knowledge of the encrypted traffic to detect encrypted malicious traffic in the inter-cloud environment. Based on a deep learning model, the present invention simultaneously utilizes multi-modal technology and external knowledge of the inter-cloud environment, and can effectively solve the problem of detecting encrypted malicious traffic in the inter-cloud environment and maintain the network security of the inter-cloud environment.

[0063] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0064] Embodiment 1

[0065] The present invention discloses an encrypted malicious traffic detection method for an inter-cloud computing environment, including:

[0066] S1: Preprocessing the original encrypted traffic data to obtain an encrypted traffic graph;

[0067] S2: Integrating global features through a self-attention mechanism by using an encrypted traffic recognition network constructed based on the BoTNet model to extract spatial features of the encrypted traffic image;

[0068] S3: Using a BiLSTM model to extract temporal features containing forward and backward timing information in the encrypted traffic image;

[0069] S4: Using a feature fusion technology based on a cross-attention mechanism to fuse the extracted spatial features and temporal features;

[0070] S5: Mining inter-cloud service entity knowledge in the inter-cloud environment;

[0071] S6: Detect the encrypted malicious traffic existing in the cloud-edge environment based on the fused features and the mined cloud-edge service entity knowledge.

[0072] Specifically, the BoTNet model, namely the BottleneckTransformer model, is a deep learning model proposed by Google that combines the advantages of Transformer and ResNet and is applicable to computer vision tasks. The BiLSTM (Bidirectional Long Short-Term Memory) model is a neural network model that combines forward LSTM and backward LSTM.

[0073] In one implementation, preprocess the original encrypted traffic data to obtain an encrypted traffic graph, including:

[0074] Perform traffic segmentation, traffic cleaning on the original encrypted traffic data, unify the length of data packets, and finally convert each data packet into a grayscale image.

[0075] In the specific implementation process, the specific steps of encrypted traffic preprocessing are as follows:

[0076] A1. Traffic segmentation: Since the original encrypted traffic is encrypted during communication, the encryption algorithm encrypts the application layer data, but there are still visible fields in the data packets. Split the pcap file of network traffic data into smaller files according to the session standard, and split the traffic into the form of two-way communication flows plus all protocols.

[0077] A2. Traffic cleaning: Delete duplicate data packets and data packets without payloads to reduce redundant information in the traffic.

[0078] A3. Unify the data length: Since the length of each sample data packet and the number of data packets are different, they cannot be directly input into the neural network, so it is necessary to unify the data length. Here, the method based on retaining the complete data packet is adopted. The UDP header of the data packet is filled to 20 bytes, and the first 784 bytes of each traffic data packet are intercepted. If the data packet length is less than 784 bytes, it is filled with 0.

[0079] A4. Convert the data packet into an image: Divide each session into data packets, and then further convert each data packet into a grayscale image. The specific image size is 28×28.

[0080] In one implementation, the encrypted traffic recognition network based on the BoTNet model builds a backbone network based on the BoTNet model, which consists of 4 stages in total. The first 3 stages are composed of Bottlenecks and are internally connected by residual networks. The 4th stage is a BoT module containing a multi-head self-attention mechanism.

[0081] In one embodiment, an encrypted traffic recognition network constructed based on the BoTNet model integrates global features through a self-attention mechanism to extract the spatial features of encrypted traffic images, including:

[0082] Use Bottleneck to extract features from the encrypted traffic map:

[0083] Y = ReLU(W 3 * ReLU(W 2 * ReLU(W 1 * x neck )) + x neck )

[0084] where Y represents the output of each Bottleneck, and x neck represents the feature input of the Bottleneck, and W 1 , W 2 , W 3 represent the weight matrices of three convolutions in sequence, * represents the convolution operation, and ReLU is the activation function;

[0085] Use the BoT module to aggregate the feature information captured by the convolutional network through the global self-attention mechanism:

[0086] F S = ReLU(W' 3 * MHSA(ReLU(W' 1 * x BoT )) + x BoT )

[0087] where x BoT represents the feature input of the BoT module, and W' 1 , W' 3 represent the weight matrices of two convolutions in sequence, MHSA represents the multi-head self-attention mechanism, * represents the convolution operation, ReLU is the activation function, and the output feature map F S is used as the spatial feature of the encrypted traffic.

[0088] Specifically, the feature extraction of the present invention is divided into two parts: encrypted traffic spatial feature extraction and encrypted traffic temporal feature extraction. The encrypted traffic spatial feature extraction builds a backbone network based on the BoTNet model. The BoTNet multi-layer residual blocks gradually extract the encrypted traffic feature maps with low resolution, and then use the BoT block to integrate the global spatial feature information.

[0089] Please refer to Figure 3, the encrypted traffic recognition network constructed based on the BoTNet model consists of 4 stages. The first 3 stages are composed of Bottlenecks, and the 4th stage integrates global encrypted traffic features through the BoT module containing the multi-head self-attention mechanism. Compared with Bottleneck, the BoT module only replaces its 3×3 convolution with the multi-head self-attention mechanism. The BoT module can aggregate the feature information captured by the convolutional network through the global self-attention mechanism, which not only retains the local feature extraction ability but also has the global information capture ability.

[0090] The process of spatial feature extraction is as follows:

[0091] The original encrypted traffic map is used as the input and fed into the Bottleneck module. Through multiple Bottleneck modules, layer-by-layer feature extraction is carried out (the original encrypted traffic map is used as the input of the first Bottleneck module, the features extracted by the first Bottleneck module are used as the input of the second Bottleneck module, and the output of the second Bottleneck module is used as the input of the third Bottleneck module). The extracted features then enter the BoT module for the last feature extraction, and finally F is obtained. S . The encrypted traffic time feature extraction builds the backbone network based on the BiLSTM model, which is parallel to the encrypted traffic spatial feature extraction part. BiLSTM extracts the time feature information containing forward and backward time features in the original traffic. The LSTM contains multiple layers of LSTM networks, and each layer uses 32 hidden units.

[0092] In one implementation, the extracted spatial features and time features are fused using the feature fusion technology based on the cross-attention mechanism, including:

[0093] Based on the cross-attention mechanism, two independent embedding sequences of the same dimension are combined in an asymmetric manner on the input. Among them, the cross-attention mechanism uses two input sequences, one as the query input and the other as the key and value inputs.

[0094] Specifically, the specific calculation formula of the cross-attention is as follows:

[0095] Q = X 1 W Q

[0096] K = V = X 2 W K

[0097]

[0098] where X 1is the input spatial feature, X 2 is the input temporal feature, Q is the query vector, K is the key vector, V is the value vector, W Q is the query weight matrix, W K is the key weight matrix, d 2 is the dimension of the key vector, Softmax is the normalization function.

[0099] In one implementation, mining the knowledge of inter-cloud service entities in the inter-cloud environment includes:

[0100] Mining the degree of association between each entity participating in the inter-cloud service, and generating a detection weight corresponding to each entity.

[0101] Specifically, since the strength of the association between service entities in the inter-cloud environment also affects the trend of encrypted malicious traffic. For example, multiple cloud service providers sharing the same type of resources are more likely to be attacked by malicious behavior. Based on this, this implementation proposes a method for mining the knowledge of inter-cloud service entities, which is used to mine the degree of association between each entity participating in the inter-cloud service, generate a detection weight for each entity, and assist the entire model in detecting inter-cloud encrypted malicious traffic;

[0102] In the specific implementation process, when mining the degree of association between each entity participating in the inter-cloud service, first extract the factors affecting the association between each entity, including: resource sharing frequency, resource integration degree, task collaboration times, data exchange volume, network topology distance. Assign different weights to the above factors to reflect their importance to the entity association degree. Set the measurement formula for each factor, and then comprehensively calculate to obtain the final association degree. Normalize all the association degrees and generate the detection weight corresponding to each entity.

[0103] In one implementation, mining the degree of association between each entity participating in the inter-cloud service, and generating a detection weight corresponding to each entity, includes:

[0104] B1. Determine the influencing factors of the degree of association;

[0105] B2. Assign different weights to the determined influencing factors to reflect the importance of each influencing factor to the host association degree. For two inter-cloud service entities A and B in the inter-cloud environment, the degree of association calculation formula is:

[0106]

[0107] where R(A, B) represents the degree of association between A and B, S(A, B) represents the resource sharing frequency between A and B, C(A, B) represents the number of collaborative tasks between A and B, T(A, B) represents the network topology distance between A and B, α 1 、α2 and α 3 represent the weights corresponding to different influencing factors;

[0108] B3. Normalize the degree of association:

[0109]

[0110] where max(R) is the maximum value among all degrees of association, and min(R) is the minimum value among all degrees of association;

[0111] B4. Establish an association degree matrix to represent the entity association in the entire cloud environment. The association degree matrix is:

[0112]

[0113] where n represents the number of entities, and R(A i , A j ) represents the degree of association between entity i and entity j. If i = j, then R(A i , A j ) = 1;

[0114] B5. Generate the detection weight corresponding to each entity according to the association degree matrix. The detection weight of the i-th entity is:

[0115] W i = R(A i , A 1 ) + R(A i , A 2 ) + … + R(A i , A n )

[0116] B6. Normalize the detection weights:

[0117]

[0118] where max(W) is the maximum value among all detection weights, min(W) is the minimum value among all detection weights, W i is the detection weight of the i-th entity, and W′ i is the normalized detection weight of the i-th entity.

[0119] Specifically, the influencing factors of the correlation degree determined in B1 include: resource sharing frequency, task collaboration times, and network topology distance. To ensure the comparability of the correlation degrees between different entities, each index is normalized through B3. The specific method is to scale the maximum and minimum values of each index. When there are n entities, the correlation degree matrix in B4 is an n×n matrix. B5 obtains the detection weights of the corresponding entities by calculating the sum of each row of the matrix.

[0120] Embodiment 2

[0121] Based on the same inventive concept, this embodiment discloses an encrypted malicious traffic detection system for an inter-cloud computing environment, including:

[0122] An encrypted traffic preprocessing module for preprocessing the original encrypted traffic data to obtain an encrypted traffic graph;

[0123] An encrypted traffic feature extraction module for using an encrypted traffic recognition network constructed based on the BoTNet model to integrate global features through a self-attention mechanism to extract the spatial features of the encrypted traffic image;

[0124] And using the BiLSTM model to extract the temporal features containing forward and backward temporal information in the encrypted traffic image;

[0125] An inter-cloud service entity knowledge mining module for using a feature fusion technology based on a cross-attention mechanism to fuse the extracted spatial features and temporal features;

[0126] An inter-cloud service entity knowledge mining module for mining the knowledge of inter-cloud service entities in the inter-cloud environment;

[0127] An inter-cloud encrypted malicious traffic detection module for detecting the encrypted malicious traffic existing in the inter-cloud environment according to the fused features and the mined knowledge of inter-cloud service entities.

[0128] Specifically, the inter-cloud encrypted malicious traffic detection module provided by the present invention is used to integrate the information provided by the feature fusion module and the inter-cloud entity knowledge mining module, and use the trained classifier to identify the encrypted malicious traffic in the inter-cloud environment. The input of the inter-cloud encrypted malicious traffic module consists of the spatio-temporal feature information provided by the feature fusion module and the inter-cloud entity detection weights provided by the inter-cloud entity knowledge mining module, and its output is the detection result of the encrypted traffic. The inter-cloud encrypted malicious traffic detection module pays attention to the whole, and assigns different detection weights to different entities in the inter-cloud environment according to the information provided by the inter-cloud service entity knowledge mining module, so as to improve the overall detection ability of the model for encrypted malicious traffic in the inter-cloud environment.

[0129] In the specific implementation process, during the inference stage of the model, the detection threshold is adjusted according to the detection weights to control the detection sensitivity of different entities. Each entity has an independent detection threshold. For entities with higher weights, the threshold can be reduced to make the model more sensitive to the traffic of this entity (i.e., it is easier to determine the traffic as malicious); for entities with lower weights, the threshold can be increased to reduce false alarms. Calculate the personalized threshold for each entity:

[0130] Threshold i = BaseThreshold × (1 - t B × W′ i )

[0131] where BaseThreshold is the default detection threshold of the model, t B is the balance coefficient of the detection weight, and W′ i is the normalized weight of entity i. When the probability detected by the model is higher than the threshold Threshold i , the model determines it as encrypted malicious traffic and outputs the result.

[0132] Since the system introduced in the second embodiment of the present invention is the system adopted for the encrypted malicious traffic detection method in the first embodiment of the present invention for the cloud-edge computing environment, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of this system, so it will not be elaborated here. Any system adopted by the method in the first embodiment of the present invention belongs to the scope protected by the present invention.

[0133] Embodiment 3

[0134] Based on the same inventive concept, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method described in Embodiment 1.

[0135] Since the computer-readable storage medium introduced in the third embodiment of the present invention is the computer-readable storage medium adopted for the encrypted malicious traffic detection method in the first embodiment of the present invention for the cloud-edge computing environment, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of this computer-readable storage medium, so it will not be elaborated here. Any computer-readable storage medium adopted by the method in the first embodiment of the present invention belongs to the scope protected by the present invention.

[0136] Embodiment 4

[0137] The present invention also provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method described in Embodiment 1.

[0138] Since the computer device introduced in the fourth embodiment of the present invention is the computer device used for implementing the encrypted malicious traffic detection method for the cloud-edge computing environment in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of this computer device, so it will not be elaborated here. Any computer device adopted by the method in the first embodiment of the present invention falls within the scope of protection of the present invention.

[0139] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0140] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0141] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the present invention. Obviously, those skilled in the art can make various changes and variations to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and variations.

Claims

1. A method for detecting encrypted malicious traffic in a cloud computing environment, characterized in that: include: Preprocess the original encrypted traffic data to obtain an encrypted traffic graph; The encrypted traffic recognition network built based on the BoTNet model is used to integrate global features through the self-attention mechanism to extract the spatial features of the encrypted traffic image; The BiLSTM model is used to extract the temporal features containing forward and backward time series information in the encrypted traffic image; The extracted spatial features and temporal features are fused using feature fusion technology based on cross-attention mechanism; Mining cloud service entity knowledge in cloud environments; Detect encrypted malicious traffic in the cloud environment based on the fused features and mined cloud service entity knowledge; Mining cloud service entity knowledge in cloud environments, including: Mining the correlation between entities involved in cloud services and generating detection weights corresponding to each entity; Among them, the correlation between the entities participating in the cloud service is mined to generate the detection weight corresponding to each entity, including: Determine the factors that influence the degree of association; Different weights are assigned to the determined influencing factors to reflect the importance of each influencing factor to the degree of association of the host. For two cloud service entities A and B in the cloud environment, the degree of association calculation formula is: Where R(A,B) represents the degree of association between A and B, S(A,B) represents the resource sharing frequency between A and B, C(A,B) represents the number of collaborative tasks between A and B, T(A,B) represents the network topological distance between A and B, and α1, α2 and α3 represent the weights corresponding to different influencing factors; Normalize the degree of association: Among them, max(R) is the maximum value among all association degrees, and min(R) is the minimum value among all association degrees; A correlation matrix is ​​established to represent the entity correlation in the entire cloud environment. The correlation matrix is: Where n represents the number of entities, R(A i ,A j ) represents the association between entity i and entity j. If i = j, then R(A i ,A j )=1; The detection weight corresponding to each entity is generated according to the association degree matrix. The detection weight of the i-th entity is: W i =R(A i ,A1)+R(A i ,A2)+…+R(A i ,A n ) Normalize the detection weights: Where max(W) is the maximum value of all detection weights, min(W) is the minimum value of all detection weights, and W i is the detection weight of the i-th entity, W′ i is the normalized detection weight of the i-th entity.

2. The method for detecting encrypted malicious traffic in a cloud computing environment as claimed in claim 1, characterized in that: The original encrypted traffic data is preprocessed to obtain the encrypted traffic graph, including: The original encrypted traffic data is segmented and cleaned, and the length of the data packets is unified. Finally, each data packet is converted into a grayscale image.

3. The method for detecting encrypted malicious traffic in a cloud computing environment as claimed in claim 1, characterized in that: The encrypted traffic identification network built based on the BoTNet model builds a backbone network based on the BoTNet model, which includes 4 stages. The first 3 stages are composed of Bottleneck, which are internally connected by a residual network. The fourth stage is a BoT module that includes a multi-head self-attention mechanism.

4. The method for detecting encrypted malicious traffic in a cloud computing environment as claimed in claim 3, characterized in that: The encrypted traffic identification network built based on the BoTNet model is used to integrate global features through the self-attention mechanism to extract the spatial features of the encrypted traffic image, including: Use Bottleneck to extract features from encrypted traffic graphs: Y=ReLU(W3*ReLU(W2*ReLU(W1*x neck ))+x neck ) Where Y represents the output of each Bottleneck, x neck represents the feature input of Bottleneck, W1, W2, W3 represent the weight matrices of three convolutions respectively, * represents the convolution operation, and ReLU is the activation function; The BoT module is used to aggregate the feature information captured by the convolutional network through a global self-attention mechanism: F S =ReLU(W′3*MHSA(ReLU(W′1*x BoT ))+x BoT ) where x BoT represents the feature input of the BoT module, W′1 and W′3 represent the weight matrices of two convolutions respectively, MHSA represents the multi-head self-attention mechanism, * represents the convolution operation, ReLU is the activation function, and the output feature map F S As spatial characteristics of encrypted traffic.

5. The method for detecting encrypted malicious traffic in a cloud computing environment as claimed in claim 1, characterized in that: The extracted spatial features and temporal features are fused using feature fusion technology based on cross-attention mechanism, including: Based on the cross-attention mechanism, two independent embedding sequences of the same dimension are combined together in an asymmetric way on the input. The cross-attention mechanism uses two input sequences, one as the query input and the other as the key and value input. The query input corresponds to the spatial features of the encrypted traffic, and the key and value inputs correspond to the temporal features of the encrypted traffic.

6. An encrypted malicious traffic detection system for cloud computing environment, characterized in that: include: The encrypted traffic preprocessing module is used to preprocess the original encrypted traffic data to obtain an encrypted traffic graph; The encrypted traffic feature extraction module is used to extract the spatial features of the encrypted traffic image by integrating global features through the self-attention mechanism using the encrypted traffic identification network built based on the BoTNet model; And use the BiLSTM model to extract the time features containing forward and backward time series information in the encrypted traffic image; The cloud service entity knowledge mining module is used to fuse the extracted spatial features and temporal features using feature fusion technology based on the cross-attention mechanism; The cloud service entity knowledge mining module is used to mine the cloud service entity knowledge in the cloud environment; The cloud-based encrypted malicious traffic detection module is used to detect the encrypted malicious traffic in the cloud environment based on the fused features and mined cloud service entity knowledge; The cloud service entity knowledge mining module is specifically used for: Mining the correlation between entities involved in cloud services and generating detection weights corresponding to each entity; Among them, the correlation between the entities participating in the cloud service is mined to generate the detection weight corresponding to each entity, including: Determine the factors that influence the degree of association; Different weights are assigned to the determined influencing factors to reflect the importance of each influencing factor to the degree of association of the host. For two cloud service entities A and B in the cloud environment, the degree of association calculation formula is: Where R(A,B) represents the degree of association between A and B, S(A,B) represents the resource sharing frequency between A and B, C(A,B) represents the number of collaborative tasks between A and B, T(A,B) represents the network topological distance between A and B, and α1, α2 and α3 represent the weights corresponding to different influencing factors; Normalize the degree of association: Among them, max(R) is the maximum value among all association degrees, and min(R) is the minimum value among all association degrees; A correlation matrix is ​​established to represent the entity correlation in the entire cloud environment. The correlation matrix is: Where n represents the number of entities, R(A i ,A j ) represents the association between entity i and entity j. If i = j, then R(A i ,A j )=1; The detection weight corresponding to each entity is generated according to the association degree matrix. The detection weight of the i-th entity is: W i =R(A i ,A1)+R(A i ,A2)+…+R(A i ,A n ) Normalize the detection weights: Where max(W) is the maximum value of all detection weights, min(W) is the minimum value of all detection weights, and W i is the detection weight of the i-th entity, W′ i is the normalized detection weight of the i-th entity.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, it implements the encrypted malicious traffic detection method for a cloud computing environment as described in any one of claims 1 to 5.

8. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the encrypted malicious traffic detection method for a cloud computing environment is implemented as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Potential affected group positioning method based on heterogeneous information network

    CN115242438A

  • Encrypted traffic identification method based on BoTNet fused spatial-temporal characteristics

    CN117240488A