Network Security Defense Method Based on Adversarial Examples against Invasion Attacks
By introducing spoofing nodes and adversarial generation networks with perturbing fingerprint information into the network, optimizing model parameters and selecting cluster head nodes to implement defense strategies, the problem of adversarial attacks in deep learning models is solved, and the accuracy of network intrusion detection and the effectiveness of defense strategies are improved.
Patent Information
- Application Number
- CN202411720030.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-11-28
AI Technical Summary
The existing deep learning models are not robust to adversarial attacks in network intrusion detection, resulting in insufficient detection accuracy and generalization capabilities, making it difficult to deploy widely.
By adding new spoofed nodes with perturbing fingerprint information, a confrontation generation network is built, model parameters are optimized, and the defense strategy is implemented by selecting cluster head nodes in the region to improve the accuracy of network node intrusion detection and the effectiveness of defense strategy.
It improves the accuracy of network node intrusion detection and the effectiveness of defense strategies, enhances the defense capabilities against samples, and improves the overall performance of network security defense.
Smart Images

Figure CN119603026B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security defense, and particularly to a network security defense method based on intrusion attack countermeasure samples. Background Art
[0002] In recent years, attackers have used more concealed methods to bypass traditional network security defense means, resulting in an increasing number of security incidents. To improve the detection accuracy and generalization ability of network intrusion detection systems (NIDS), more and more systems have begun to adopt machine learning (ML) and deep learning (DL) technologies. These technologies can learn and model normal network behaviors, thereby effectively identifying abnormal activities and potential threats. With the increasing popularity of deep learning in the field of intrusion detection, it has attracted the attention of attackers, and counterattacks against deep learning models have been explored. More and more applications and related platforms have started to carry deep neural network models. However, the non-robustness of deep neural network models to adversarial attacks makes the models unable to be widely deployed in various security fields. Summary of the Invention
[0003] The purpose of the present invention is to meet the requirements of countermeasure sample defense, improve network node intrusion detection through perturbation design and model parameter optimization, and adopt effective defense strategies to provide a network security defense method based on intrusion attack countermeasure samples.
[0004] To achieve the above-mentioned invention purpose, the embodiments of the present invention provide the following technical solutions:
[0005] A network security defense method based on intrusion attack countermeasure samples includes the following steps:
[0006] Step 1, according to the fingerprint information of each real node in the target network, add spoofing nodes with perturbed fingerprint information;
[0007] Step 2, obtain the network traffic time series data of all nodes in the target network, use the network traffic time series data of real nodes as original samples, use the network traffic time series data of spoofing nodes as countermeasure samples, and construct the objective function of the adversarial generation network;
[0008] Step 3, divide the spoofing nodes in the target network into regions according to their perturbation types, randomly add at least one real node to each region, and select any real node from each region as the cluster head node;
[0009] Step 4, the cluster head node selects a defense strategy to resist attacks on any node in this region.
[0010] The network security defense based on intrusion attack countermeasure samples includes:
[0011] An adversarial example generation module, which is used to add spoofing nodes with perturbed fingerprint information and obtain the network traffic time series data of real nodes and spoofing nodes;
[0012] A target function construction module, which is used to construct the target function of the GAN model based on the network traffic time series data;
[0013] A model parameter optimization module, which is used to optimize the parameters of the GAN model;
[0014] A region division module, which is used to divide regions according to the perturbation types of spoofing nodes, randomly add at least one real node to each region, and select any real node from each region as the cluster head node;
[0015] A defense strategy selection module, which is used to select a defense strategy to defend the cluster head node against the attack on any node in this region by the attacker.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention meets the requirements of adversarial example defense. Through perturbation design and model parameter optimization, it improves the intrusion detection of network nodes and adopts effective defense strategies. It improves the accuracy of intrusion detection through the revenue mechanism and improves the effectiveness of defense strategy selection. Description of the Drawings
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0018] Figure 1 It is the flowchart of the method of the present invention;
[0019] Figure 2 It is the system block diagram of the present invention;
[0020] Figure 3 It is the schematic diagram of the target network of the invention. Detailed Embodiments
[0021] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0022] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present invention, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance, or implying any such actual relationship or order between these entities or operations. In addition, terms such as "connected" and "coupled" can be directly connected between components or indirectly connected through other components.
[0023] The present invention is implemented through the following technical solutions. As Figure 1 shown, a network security defense method based on intrusion attack countermeasure samples includes the following steps:
[0024] Step 1, according to the fingerprint information of each real node in the target network, add spoofing nodes with perturbed fingerprint information.
[0025] The fingerprint information of the nodes in the target network is used to represent the identity of a host node. The fingerprint information can include multiple information such as Mac address, open port numbers, running services, operating system, DNS settings, network protocols, and abnormal behavior detection. Assume that there are n1 real nodes in the original target network. In this solution, n2 spoofing nodes are generated in the target network. The fingerprint information of the spoofing nodes also includes Mac address, open port numbers, running services, operating system, etc., which are the same as those of the real nodes.
[0026] Different from real nodes, the fingerprint information of spoofing nodes is perturbed to form perturbed fingerprint information. As an implementable approach, the perturbation added to spoofing nodes is a network attack, which can include denial-of-service attacks (DoS / DDoS), backdoor attacks (BDAI), vulnerability attacks (VAI), phishing (PI), man-in-the-middle attacks (MitM), SQL injection attacks, cross-site scripting attacks (XSS), malware attacks, credential theft attacks, supply chain attacks, etc. For the fingerprint information of a spoofing node, at least one of the above attacks can be added, enabling the spoofing node to have the ability to confuse attackers. As another implementable approach, the perturbation added to spoofing nodes is random noise following a normal distribution. As yet another implementable approach, the perturbation added to spoofing nodes is environmental changes and human error operations. For example, environmental changes can include environmental factors such as temperature changes, humidity changes, and electromagnetic interference that can affect the performance of network nodes, and human error operations can be that administrators input incorrect parameters or perform incorrect operations when configuring network nodes. And this solution is not limited to the way of adding perturbations and the type of perturbations. The ultimate goal is to make the fingerprint information of spoofing nodes different from that of real nodes and be able to deceive or confuse the attackers' perception.
[0027] Spoofing nodes are special hosts designed by defenders to deceive attackers, and the spoofing nodes contain images of all real nodes in the target network and can disguise as any real node in the target network at any time. Spoofing nodes can be implemented by virtualized cloud platforms or by high-performance physical machines. Therefore, after designing n2 spoofing nodes, there are a total of n nodes in the target network, where n = n1 + n2. As Figure 3 shown, the solid circles in the target network represent real nodes, and the dashed circles represent spoofing nodes.
[0028] Step 2: Obtain the network traffic time series data of all nodes in the target network. Use the network traffic time series data of real nodes as the original samples and the network traffic time series data of spoofing nodes as the adversarial samples to construct the objective function of the adversarial generative network.
[0029] The obtained network traffic time series data of real nodes is The network traffic time series data of spoofing nodes is where τ ∈ T, T represents the sampling time, and m τ represents the length of the τ-th sampling data.
[0030] Take n1 as the original samples and n2 as the adversarial samples to construct the objective function of the adversarial generative network:
[0031]
[0032] The adversarial generative network is modeled based on the GAN model. The generator G attempts to minimize the gap between the original samples and the adversarial samples, while the discriminator D greatly improves its ability to distinguish between the original samples and the adversarial samples. The generator G learns the true distribution P ) of the original samples x (i.e., n1 , as well as the adversarial distribution P of the adversarial samples (i.e., ). The discriminator D determines whether the input sample n2 comes from the original samples or the adversarial samples. V(D, G) represents the adversarial function of the generator G and the discriminator D.
[0033] Furthermore, this solution optimizes the parameters of the adversarial generative network, enabling the GAN model to improve the accuracy of the discriminator D in outputting correct results. The predicted probability of any node i being perturbed in the GAN model output is:
[0034] q i (t) = (1 - β t ) · q i (t - 1) + β t · e i (t - 1);
[0035] where q i (t) represents the predicted probability of node i being perturbed in the t-th iteration of the GAN model output; q i (t - 1) represents the predicted probability of node i being perturbed in the (t - 1)-th iteration of the GAN model output; e i (t - 1) represents the true value of node i being perturbed in the (t - 1)-th iteration. Since node i is either perturbed or not perturbed, the true value e i (t - 1) is a binary classification problem. If node i is not perturbed, then e i (t - 1) = 1; if node i is perturbed, then e i (t - 1) = 0; β t represents the perturbation factor in the t-th iteration. When e i (t - 1) = 0, β t · e i (t - 1) = 0. At this time, only (1 - β t ) · q i (t - 1) is relied on to improve the accuracy of q i (t). Therefore, β t is designed as:
[0036]
[0037] where β t-1 denotes the perturbation factor at the (t - 1)-th iteration; ε denotes the learning rate; ρ is a constant to avoid the denominator being zero, and ρ = 10 can be taken -8 ; μ t is the gradient function at the t-th iteration, and there is This formula represents the gradient of the adversarial function V(D, G) with respect to the parameter θ of the discriminator D at the t-th iteration D The purpose is to make the adversarial function V(D, G) converge faster and more accurately.
[0038] If the predicted probability q i (t) is closer to 1, it indicates a higher possibility that node i is perturbed. If q i (t) is closer to 0, it indicates a higher possibility that node i is not perturbed. A threshold can be set according to the actual situation to determine whether node i is perturbed. This solution does not limit how to set the threshold.
[0039] If the output result of the GAN model is incorrect, the given benefit is 0. If the output result of the GAN model is correct, the benefit is given as follows:
[0040]
[0041] where V i represents the benefit obtained from the GAN model's output prediction result for node i; γ i represents the benefit offset for node i; t represents the current iteration number; t max represents the maximum number of iterations for the time series data of the network traffic of node i; represents the benefit weight; δ represents the learning rate.
[0042] Step 3: Divide the spoofing nodes in the target network into regions according to their perturbation types, randomly add at least one real node to each region, and select any real node from each region as the cluster head node.
[0043] For example, when the perturbation added to the spoofing nodes is a network attack, the n2 spoofing nodes can be divided into M regions according to the type of network attack, and then the n1 real nodes are randomly assigned to the M regions, and there is at least 1 real node in each region. Generally, the number n2 of spoofing nodes is less than the number n1 of real nodes, so the number M of regions is also less than the number n1 of real nodes, which can ensure that each region can be assigned at least 1 real node. As a preferred solution, the number of real nodes in each region is as close as possible, but not necessarily exactly the same.
[0044] Then, select one real node from each area as the cluster head node, which is used to implement attack defense on the nodes in the entire area subsequently. When selecting the cluster head node, first obtain the network traffic time series data of the real nodes, convert the network traffic time series data into traffic features, and construct a traffic adjacency matrix G:
[0045]
[0046] Among them, g ij represents the traffic consumed by the i-th node in this area when transmitting data to the j-th node; m represents the number of real nodes in this area, i = 1, 2,... m, j = 1, 2,..., m; g ii represents the traffic consumed by the i-th node when processing data.
[0047] Calculate the fitness value of node i:
[0048]
[0049] Among them, E i represents the fitness value of node i; α1, α2, and α3 are all weights; g i represents the current traffic of node i, g i0 represents the initial traffic of node i; D i_base represents the distance from node i to the base station; D max_base represents the maximum distance from the nodes in this area to the base station; g max represents the maximum element in the traffic adjacency matrix G.
[0050] Select the node with the largest fitness value in this area as the cluster head node.
[0051] Step 4, the cluster head node selects a defense strategy to resist the attack of the attacker on any node in this area.
[0052] At time t`, the probability that the cluster head node selects the defense strategy s k is:
[0053]
[0054] Among them, represents the probability that the cluster head node selects the defense strategy s k at time t`; represents the weight that the cluster head node selects the defense strategy s k at time t`; represents the weight that the cluster head node selects the defense strategy s k at time t` - 1; σ represents the full weight influence factor; represents the expected probability that the cluster head node selects the defense strategy s k ; sk Denote the k-th defense strategy, where k = 1, 2, ..., K, and K represents the total number of defense strategies.
[0055] The defense benefit is:
[0056]
[0057] Among them, R A represents the defense benefit; represents the probability that the cluster head node selects the defense strategy s k ; f l represents the l-th attack method, where l = 1, 2, ..., L, and L represents the total number of attack methods; r(f l , s k ) represents the benefit obtained when the cluster head node selects the defense strategy s k to resist the attack method f l ; Z defense (s k ) represents the cost of selecting the defense strategy s k . To meet the reduction of the available cost resources of the defense means, the following constraints are imposed on the defense side:
[0058]
[0059] Among them, ω d represents the minimum cost utilization rate, and ω d < 1; represents the defense strategy vector; y i represents the degree of the cluster head node i; γ d represents the node degree coefficient; Z all (s k ) represents the total cost of selecting the defense strategy s k when all real nodes in this area are used as cluster head nodes; θ d represents the cost constraint coefficient; i represents the i-th node in this area as the cluster head node, where i = 1, 2, ..., m, and m is the number of real nodes in this area.
[0060] As Figure 2 shown, this solution also proposes network security defense based on adversarial samples of intrusion attacks, including:
[0061] An adversarial sample generation module, which is used to add spoofing nodes with perturbed fingerprint information and obtain the network traffic time series data of real nodes and spoofing nodes;
[0062] A target function construction module, which is used to construct the target function of the GAN model based on the network traffic time series data;
[0063] A model parameter optimization module, which is used to optimize the parameters of the GAN model;
[0064] The region division module is used to divide regions according to the perturbation types of spoofing nodes, randomly add at least one real node to each region, and select any real node from each region as the cluster head node;
[0065] The defense strategy selection module is used to select a defense strategy to protect the cluster head node from the attack of the attacker on any node in this region.
[0066] As mentioned above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A network security defense method based on adversarial samples for intrusion attacks, characterized in that: It includes the following steps: Step 1: According to the fingerprint information of each real node in the target network, add spoofing nodes with perturbed fingerprint information; Step 2: Obtain the network traffic time-series data of all nodes in the target network. Use the network traffic time-series data of real nodes as the original samples and the network traffic time-series data of spoofing nodes as the adversarial samples to construct the objective function of the adversarial generative network; The adversarial generative network is modeled based on the GAN model. The predicted probability of any node i being perturbed output by the GAN model is: Among them, q i (t) represents the predicted probability of node i being perturbed in the t-th iteration output by the GAN model; q i (t - 1) represents the predicted probability of node i being perturbed in the (t - 1)-th iteration output by the GAN model; e i (t - 1) represents the true value of node i being perturbed in the (t - 1)-th iteration. If node i is not perturbed, then e i (t - 1) = 1. If node i is perturbed, then e i (t - 1) = 0; represents the perturbation factor in the t-th iteration; Step 3: Divide the spoofing nodes in the target network into regions according to their perturbation types, randomly add at least one real node to each region, and select any real node in each region as the cluster head node; Step 4: The cluster head node selects a defense strategy to resist attacks on any node in this region by the attacker.
2. The network security defense method based on adversarial samples for intrusion attacks according to claim 1, wherein: In the above Step 1, the fingerprint information includes Mac address, open port numbers, running services, operating system, DNS settings, network protocols, and abnormal behavior detection; The perturbed fingerprint information refers to adding perturbations to the fingerprint information of the spoofing node. The perturbations include network attacks, random noise, environmental changes, and human error operations.
3. The network security defense method based on adversarial samples against intrusion attacks according to claim 1, wherein: The specific steps in the above Step 2 include the following steps: The obtained network traffic time series data of the real nodes is , and the network traffic time series data of the spoofing nodes is , where , T represents the sampling time, represents the th length of the sampling data; Take n1 as the original samples, and take n2 as the adversarial samples, where n1 is the number of real nodes and n2 is the number of spoofing nodes, and construct the objective function of the adversarial generative network: The generator G attempts to minimize the gap between the original samples and the adversarial samples, while the discriminator D greatly improves its ability to distinguish between the original samples and the adversarial samples; the generator G learns from the original samples x, that is the true distribution P n1 , and the adversarial samples , that is the adversarial distribution P n2 . The discriminator D determines whether the input sample comes from the original samples or the adversarial samples; V(D, G) represents the adversarial function of the generator G and the discriminator D.
4. The network security defense method based on intrusion attack countermeasure samples according to claim 1, characterized in that: In the said step 2, It is: Among them, represents the perturbation factor of the (t - 1)-th iteration; represents the learning rate; is a constant to avoid the denominator being zero, and it can be taken as ; is the gradient function of the t-th iteration, and there is , which represents the gradient of the adversarial function V(D, G) with respect to the parameters of the discriminator D at the t-th iteration.
5. The network security defense method based on intrusion attack countermeasure samples according to claim 1, characterized in that: In the above Step 3, the step of selecting any real node in each region as the cluster head node includes: Obtain the network traffic time-series data of the real node, convert the network traffic time-series data into traffic features, and construct the traffic adjacency matrix G: Among them, g ij represents the traffic consumed by the i-th node transmitting data to the j-th node in this area; m represents the number of real nodes in this area, i = 1, 2,... m, j = 1, 2,..., m; g ii represents the traffic consumed by the i-th node processing data; Calculate the fitness value of node i: Among them, E i represents the adaptation degree value of node i; are all weights; g i represents the current traffic of node i, g i0 represents the initial traffic of node i; D i_base represents the distance from node i to the base station; D max_base represents the maximum distance from the nodes in this area to the base station; g max represents the maximum element in the traffic adjacency matrix G; Select the node with the largest fitness value in this region as the cluster head node.
6. The network security defense method based on adversarial samples for intrusion attacks according to claim 5, characterized in that: The specific steps in the above Step 4 include the following steps: At time t`, the probability that the cluster head node selects the defense strategy s k is as follows: Among them, represents the probability that the cluster head node selects the defense strategy s k at time t'; represents the weight that the cluster head node selects the defense strategy s k at time t'; represents the weight that the cluster head node selects the defense strategy s k at time t'-1; represents the full weight influence factor; represents the expected probability that the cluster head node selects the defense strategy s k ; s k represents the k-th defense strategy, where k = 1, 2,..., K, and K represents the total number of defense strategies.
7. The network security defense method based on intrusion attack countermeasure samples according to claim 6, characterized in that: The above Step 4 also includes the following steps: The defense benefit is: Among them, R A represents the defense benefit; represents the probability of the cluster head node selecting the defense strategy s k ; f l represents the l-th attack method, where l = 1, 2,..., L, and L represents the total number of attack methods; r(f l , s k ) represents the benefit obtained by the cluster head node selecting the defense strategy s k to resist the attack method f l ; Z defense (s k ) represents the cost of selecting the defense strategy s k ; Select the defense strategy with the highest defense benefit value to resist attacks on any node in this region by the attacker.
Citation Information
Patent Citations
Method for generating malicious samples against industrial control system based on adversarial learning
US20210319113A1
Ai-driven defensive penetration test analysis and recommendation system
US20220201042A1