Wireless Communication Network Intrusion Detection Method and Device for Adversarial Example Defense

By integrating MLP and CNN to extract the spatiotemporal characteristics of network traffic, and combining GAN discriminator, DPI and decision tree models for comprehensive detection, the problem of adversarial sample defense is solved and the detection accuracy and security of network traffic is improved.

CN119653369BActive Publication Date: 2025-06-13WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP) +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510157512.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-06-13
Estimated Expiration
2045-02-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify and defend against adversarial samples generated by Generative Adversarial Network (GAN) technology, making it difficult for security detection systems to correctly identify real threats, and may even be bypassed.

Method used

By integrating multi-layer perceptron (MLP) and convolutional neural network (CNN), the spatiotemporal characteristics of network traffic data are extracted and inputted to the pre-trained discriminator of the generative adversarial network for detection. Combining deep packet detection (DPI) and rule-based anomaly behavior analysis, a decision tree model is used to comprehensively detect the final detection results of network traffic and trigger corresponding response decisions.

Benefits of technology

It improves the ability to identify and classify complex network traffic and behavior patterns, enhances the detection accuracy of malicious activities, can effectively combat the latest network attack strategies, and ensures the sustainability of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119653369B_ABST
    Figure CN119653369B_ABST
Patent Text Reader

Abstract

The present invention provides a method and device for intrusion detection in a wireless communication network for adversarial sample defense, belonging to the technical field of communication network security. The method includes: extracting features from the traffic data to be measured to obtain the spatio-temporal features of the traffic data to be measured; inputting the spatio-temporal features into the discriminator of a pre-trained generative adversarial network to obtain a first detection result of the traffic data to be measured; performing deep packet inspection on the traffic data to be measured, and performing abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain a second detection result; inputting decision information into a pre-trained decision tree model to determine the final detection result of the traffic data to be measured. The present invention can not only accurately detect and classify abnormal patterns in network traffic, but also deeply analyze encrypted communication, thereby significantly improving the security protection ability of wireless communication networks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication network security, and particularly to a wireless communication network intrusion detection method and device for adversarial sample defense. Background Art

[0002] In the modern wireless communication network environment, with the rapid development of technology and the popularization of global network applications, the threats faced by network security are increasing day by day, and the forms are becoming more and more diverse and complex. Traditional network attacks such as viruses, Trojans, and phishing attacks are already well-known, while more complex network attack means, such as advanced persistent threat (APT), control and steal network resources through long-term latency and chronic penetration, which pose a severe challenge to network security. The development of dark web technology, especially the use of anonymous networks such as Tor, enables malicious users to communicate and exchange data almost untraceably. The increase in such encrypted traffic has greatly increased the difficulty of traditional network monitoring and intrusion detection technologies.

[0003] In this context, the wide application of machine learning technology has played a significant role in improving the automation and intelligence level of network security. However, the introduction of this technology has also brought new challenges. Especially the emergence of generative adversarial network (GAN) technology enables attackers to create more and more sophisticated adversarial samples. These adversarial samples can deceive security detection systems based on machine learning models by introducing subtle and ingenious perturbations into normal network traffic (actual network traffic), making it difficult for them to correctly identify real threats and even possibly bypass security protection measures completely.

[0004] The rapid growth of Internet of Things (IoT) devices and the popularization of smart devices in daily life have significantly increased the security attack surface of the edge part of wireless communication networks. These devices usually lack sufficient security protection measures and become easy targets for attackers. Network security systems need to be able to not only identify traditional threats but also effectively monitor and defend against potential risks from these emerging devices. Summary of the Invention

[0005] The present invention provides a wireless communication network intrusion detection method and device for adversarial sample defense to solve at least one defect existing in the prior art.

[0006] In a first aspect, the present invention provides a method for intrusion detection in a wireless communication network for adversarial sample defense, including: extracting features from the traffic data to be measured to obtain the spatio-temporal features of the traffic data to be measured; inputting the spatio-temporal features into the discriminator of a pre-trained generative adversarial network to obtain a first detection result of the traffic data to be measured; performing deep packet inspection on the traffic data to be measured, and performing abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain a second detection result; inputting decision information into a pre-trained decision tree model to determine the final detection result of the traffic data to be measured; the decision information includes key parameters of the traffic data to be measured, the first detection result, and the second detection result.

[0007] According to the method for intrusion detection in a wireless communication network for adversarial sample defense provided by the present invention, after determining the final detection result of the traffic data to be measured, it further includes: in the case where it is determined that the traffic data to be measured is malicious data according to the final detection result, triggering a response decision for the final detection result.

[0008] According to the method for intrusion detection in a wireless communication network for adversarial sample defense provided by the present invention, extracting features from the traffic data to be measured to obtain the spatio-temporal features of the traffic data to be measured includes: extracting key parameters of the traffic data to be measured; inputting the key parameters into a multi-layer perceptron to extract high-dimensional vector features of the traffic data to be measured; inputting the high-dimensional vector features into a convolutional neural network to obtain the spatio-temporal features of the traffic data to be measured.

[0009] According to the method for intrusion detection in a wireless communication network for adversarial sample defense provided by the present invention, the generative adversarial network includes a discriminator and a generator; the generator is used to generate feature data of adversarial samples using random noise signals; the adversarial samples are malicious data that mimics actual traffic data; the discriminator is used to identify actual traffic data and adversarial samples based on the feature data of adversarial samples and actual traffic data.

[0010] According to the method for intrusion detection in a wireless communication network for adversarial sample defense provided by the present invention, performing deep packet inspection on the traffic data to be measured includes: determining whether malicious information is carried by analyzing the header information and payload content of the traffic data to be measured.

[0011] A wireless communication network intrusion detection method for adversarial sample defense provided by the present invention performs abnormal behavior analysis on the to-be-tested traffic data based on the spatio-temporal features, including: comparing and analyzing the abnormal behavior of the to-be-tested traffic data based on the spatio-temporal features of the to-be-tested traffic data and various types of preset standard spatio-temporal features; wherein, the various types of standard spatio-temporal features include the spatio-temporal features of the actual traffic standard data and the spatio-temporal features of various malicious traffic standard data; when it is determined that the spatio-temporal features of the to-be-tested traffic data match the spatio-temporal features of any malicious traffic standard data, a corresponding response decision is triggered.

[0012] A wireless communication network intrusion detection method for adversarial sample defense provided by the present invention inputs the decision information into a pre-trained decision tree model to determine the final detection result of the to-be-tested traffic data, including: presetting multiple decision nodes of the decision tree model according to the key parameters, the first detection result and the second detection result of the to-be-tested traffic data; setting the classification rules for each decision node; starting from the root node, gradually refining the classification result based on the set classification rules until reaching the leaf node; the leaf node outputs the final classification result to determine whether the to-be-tested traffic data is malicious traffic data.

[0013] A wireless communication network intrusion detection method for adversarial sample defense provided by the present invention, before performing feature extraction on the to-be-tested traffic data, further includes: deploying traffic monitoring devices at each key access point of the wireless communication network; using the traffic monitoring devices to capture the passing data packets and perform data cleaning on the captured data packets; performing data standardization processing on the data after data cleaning to obtain the to-be-tested traffic data.

[0014] In a second aspect, the present invention also provides a wireless communication network intrusion detection device for adversarial sample defense, including:

[0015] A first processing module, configured to perform feature extraction on the to-be-tested traffic data to obtain the spatio-temporal features of the to-be-tested traffic data;

[0016] A second processing module, configured to input the spatio-temporal features into a discriminator of a pre-trained generative adversarial network to obtain a first detection result of the to-be-tested traffic data;

[0017] A third processing module, configured to perform deep packet detection on the to-be-tested traffic data and perform abnormal behavior analysis on the to-be-tested traffic data based on the spatio-temporal features to obtain a second detection result;

[0018] A fourth processing module, configured to input the decision information into a pre-trained decision tree model to determine the final detection result of the to-be-tested traffic data; the decision information includes the key parameters, the first detection result and the second detection result of the to-be-tested traffic data.

[0019] In a third aspect, the present invention provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the wireless communication network intrusion detection method for adversarial sample defense as described in any one of the above are implemented.

[0020] In a fourth aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the wireless communication network intrusion detection method for adversarial sample defense as described in any one of the above are implemented.

[0021] The wireless communication network intrusion detection method and device for adversarial sample defense provided by the present invention have the following beneficial effects compared with the prior art:

[0022] (1) By integrating a multi-layer perceptron (MLP) and a convolutional neural network (CNN), the present invention can effectively identify and classify complex network traffic and behavior patterns, improving the detection accuracy of malicious activities.

[0023] (2) The present invention performs specific optimization on the generative adversarial network (GAN), adding an adaptive adversarial sample generation mechanism. This mechanism introduces an attack strategy model that can be updated in real time into the generator, enabling the generator to generate corresponding adversarial samples according to the latest network attack means. This enables the model to be updated in real time and effectively counter the latest and more complex network attack strategies.

[0024] (3) By combining deep packet inspection (DPI) and rule-based behavior analysis, the present invention can not only accurately identify traditional security threats but also conduct in-depth analysis of encrypted communications, enhancing the monitoring ability of covert communications.

[0025] (4) By implementing automated response measures and combining a continuous feedback mechanism, the present invention can adapt to changes in the network environment, timely adjust the defense strategy, and ensure continuous network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0027] Figure 1 is a schematic flowchart of the wireless communication network intrusion detection method for adversarial sample defense provided by the present invention;

[0028] Figure 2 It is a schematic flowchart of the anomaly detection method using a generative adversarial network provided by the present invention;

[0029] Figure 3 It is a schematic flowchart of the decision-making, response and feedback mechanism provided by the present invention;

[0030] Figure 4 It is a schematic structural diagram of the wireless communication network intrusion detection device for adversarial sample defense provided by the present invention;

[0031] Figure 5 It is a schematic structural diagram of the electronic device provided by the present invention. Specific embodiments

[0032] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.

[0033] It should be noted that in the description of the embodiments of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, an element defined by the phrase "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.

[0034] The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order different from those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same category and do not limit the number of objects. For example, the first object can be one or multiple. In addition, "and / or" means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0035] The following will be combined with Figures 1-5 Describe the wireless communication network intrusion detection method and device for adversarial sample defense provided by the embodiments of the present invention.

[0036] Figure 1It is a schematic flowchart of the wireless communication network intrusion detection method for adversarial example defense provided by the present invention. As Figure 1 shown, it includes but is not limited to the following steps:

[0037] Step 101: Extract features from the traffic data to be measured, and obtain the spatio-temporal features of the traffic data to be measured.

[0038] Optionally, before performing feature processing, it also includes a data preprocessing process, including but not limited to data cleaning and data standardization processes.

[0039] Step 102: Input the spatio-temporal features into the discriminator of the pre-trained generative adversarial network to obtain the first detection result of the traffic data to be measured.

[0040] The generative adversarial network includes a discriminator and a generator; the generator is used to generate feature data of adversarial examples using random noise signals; the adversarial examples are malicious data that mimics actual traffic data; the discriminator is used to identify actual traffic data and adversarial examples based on the feature data of adversarial examples and actual traffic data.

[0041] Among them, the first detection result is to judge whether the traffic data to be measured is actual traffic data (which can be understood as normal traffic data) or an adversarial example (malicious traffic data that mimics actual traffic data).

[0042] Step 103: Perform deep packet inspection on the traffic data to be measured, and perform abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain the second detection result.

[0043] Perform a deeper analysis on the suspected abnormal traffic, not limited to surface feature matching, but deep into the content level of the data packet to check for any behavior patterns that violate the norm. This process helps to detect complex attacks that cannot be identified by simple feature changes.

[0044] Among them, the second detection result includes whether the traffic data to be measured belongs to malicious data and which specific type of malicious data it belongs to.

[0045] Step 104: Input the decision-making information into the pre-trained decision tree model to determine the final detection result of the traffic data to be measured.

[0046] Among them, the decision-making information includes but is not limited to the key parameters of the traffic data to be measured, the first detection result, and the second detection result, and may also include the spatio-temporal features of the traffic data to be measured. And the key parameters include but are not limited to the data packet size, communication frequency, and timestamp.

[0047] A decision tree is a supervised learning algorithm that classifies data through a series of rules or conditional tests and is very suitable for situations where multiple factors need to be considered for making judgments.

[0048] Optionally, after determining the final detection result of the traffic data to be measured, it further includes: when it is determined according to the final detection result that the traffic data to be measured is malicious data, triggering a response decision for the final detection result.

[0049] The technical solution of the present invention will be described below in conjunction with a specific embodiment:

[0050] Step 1: Data collection and preprocessing

[0051] The present invention automatically captures all inbound and outbound traffic data from a wireless communication network. This process is achieved through traffic monitoring devices deployed at key network access points to ensure comprehensive monitoring of the network data stream. In the data collection stage, the present invention uses high-precision synchronization technology to record the timestamp and source / destination address of each data packet to ensure the integrity and traceability of the data. In the data preprocessing link, the present invention automatically performs data cleaning to remove network noise and non-target data streams, including all redundant information irrelevant to security analysis. Subsequently, the present invention standardizes the data, unifies the data format to JSON, and adopts the UTF-8 encoding format to meet the requirements of subsequent deep learning processing.

[0052] The specific operations are as follows:

[0053] Step 1.1 Device deployment and data capture

[0054] Traffic monitoring devices are deployed at each key access point of the wireless communication network, including gateways, routers, and core switches. These devices are configured to capture all passing data packets, including data at the IP layer and detailed information at the transport layer. The devices use the Network Time Protocol (NTP) to ensure that the timestamp of each data packet is accurate to milliseconds.

[0055] Step 1.2 Data cleaning

[0056] After the data is captured, the present invention immediately conducts a preliminary analysis to identify and remove irrelevant data. This includes using predefined white and blacklists of IP addresses, as well as content-based filtering, such as data related to advertisements and data streams generated by obvious legitimate applications. At the same time, the present invention detects and removes error packets and duplicate packets in data transmission to ensure that the data for subsequent processing has high quality and relevance.

[0057] Step 1.3 Data standardization

[0058] After completing data cleaning, the present invention converts all data into a unified JSON format to form the flow data to be tested. This operation involves mapping the data fields of various network protocols (such as TCP / UDP port number, protocol type, packet length, etc.) to the key-value pairs of JSON. All text data is uniformly encoded in UTF-8. Data standardization ensures that data from different sources and formats can be uniformly managed and queried in subsequent processing.

[0059] Step 2: Feature extraction

[0060] Extracting features from the flow data to be measured to obtain the spatiotemporal features of the flow data to be measured includes: extracting key parameters of the flow data to be measured; inputting the key parameters into a multi-layer perceptron to extract high-dimensional vector features of the flow data to be measured; and inputting the high-dimensional vector features into a convolutional neural network to obtain the spatiotemporal features of the flow data to be measured. The following is a detailed description.

[0061] Based on step one, the feature extraction stage is entered. The feature extraction in the present invention can be performed jointly by a multi-layer perceptron (MLP) and a convolutional neural network (CNN). First, key parameters are directly obtained from the preprocessed data, including data packet size, communication frequency, and timestamp. These key parameters serve as initial data and provide a basis for pattern recognition and anomaly detection. Subsequently, the MLP further processes these directly obtained key parameters and extracts deeper feature representations through nonlinear mapping and feature combination. The convolutional neural network (CNN) continues to process the data, using its stacked convolutional layers and pooling layers to extract spatial and temporal features (i.e., spatiotemporal features) from the data. CNN is able to identify complex patterns in data packet sequences, including periodic behaviors, emergencies, and continuous trends. Through multi-level feature extraction and encoding, the present invention has enhanced its responsiveness to dynamic changes in network traffic. Its specific operations are as follows:

[0062] Step 2.1 Feature extraction via Multi-layer Perceptron (MLP)

[0063] After the data preprocessing is completed, the multi-layer perceptron (MLP) starts to work. The structure of the multi-layer perceptron can be set as needed to extract high-dimensional vector features.

[0064] Take the three-layer multilayer perceptron as an example. The multilayer perceptron consists of three fully connected layers, each equipped with a ReLU activation function to ensure effective processing of linear and nonlinear data relationships. The first layer directly receives and parses the key parameters of the traffic data to be measured, such as size, communication frequency, and timestamp. The second layer further nonlinearly maps and combines the features extracted by the first layer to explore potential complex relationships and patterns. The third layer integrates the outputs of the first two layers into a high-dimensional vector feature. This high-dimensional vector feature is not just the key parameter itself, but a high-dimensional feature representation obtained after MLP processing based on the key parameters, which provides a richer foundation for subsequent advanced pattern recognition.

[0065] Step 2.2 Feature extraction via convolutional neural network (CNN)

[0066] Following the processing of the MLP, the convolutional neural network (CNN) takes over to further extract and identify complex spatial and temporal features (spatiotemporal features). The first convolution layer of the CNN is equipped with 16 filters, focusing on the extraction of local spatial patterns and processing the comprehensive feature vectors passed from the MLP; the first pooling layer that follows is used to reduce the data dimension and enhance the generalization ability of the pattern. The second convolution layer has 32 filters, which is used to deeply analyze the data and mine more complex temporal dynamics and spatial structures; the second pooling layer reduces the feature dimension again to prepare for the final abnormal behavior identification.

[0067] Step 3: Adversarial Sample Detection

[0068] After receiving the spatiotemporal features extracted in step 2, the present invention inputs the spatiotemporal features into the discriminator of a specifically optimized generative adversarial network (GAN) to discriminate the traffic data to be detected. Both the generator and the discriminator of the GAN are carefully designed to improve the defense effect against complex network attacks.

[0069] Figure 2 is a flow chart of anomaly detection using a generative adversarial network provided by the present invention, such as Figure 2 As shown, the generator is used to generate feature data of adversarial samples using random noise signals; the adversarial samples are malicious data that imitate actual traffic data (normal traffic data); the discriminator is used to identify actual traffic data and adversarial samples based on feature data of adversarial samples and actual traffic data. By discriminating spatiotemporal features, the present invention can more accurately identify adversarial samples and enhance the detection capability of adversarial attacks.

[0070] Step 3.1 Generator configuration and operation optimization

[0071] The generator uses advanced Neural Architecture Search (NAS) technology to automatically design the neural network architecture to ensure optimal performance and efficiency. It receives a random noise signal as input and processes it through a dynamically adjusted multi-layer fully connected network. The number of network layers and the number of neurons in each layer are dynamically adjusted according to real-time data, and the LeakyReLU activation function is used to enhance the non-linear processing ability. Subsequently, an attention mechanism is introduced to enable the generator to more accurately simulate key network traffic characteristics. What the generator generates are the features of adversarial samples, rather than the direct adversarial sample data. By simulating and perturbing these key features, the generator can create more deceptive adversarial sample features, making them highly similar to the features of actual traffic data in the feature space.

[0072] Step 3.2 Configuration and Operation Optimization of the Discriminator

[0073] The discriminator combines traditional fully connected layers and modern convolutional layers to improve its sensitivity to details, especially when analyzing the packet structure. After each convolutional layer, batch normalization and ReLU activation functions are equipped to ensure the normalization of input data and effective gradient flow. Before the output layer, the discriminator uses adaptive pooling technology to adjust the size of the feature map, optimizing memory usage and computational speed. Finally, the sigmoid function is used to output the judgment result, and a hybrid model combining Support Vector Machine (SVM) and Convolutional Neural Network (CNN) is used to improve the ability to distinguish adversarial samples from real samples.

[0074] Step Four: Deep Packet Inspection (DPI) and Abnormal Behavior Analysis

[0075] After the detection of adversarial samples in Step Three is completed, the present invention then deploys Deep Packet Inspection (DPI) technology to further strengthen security protection. The DPI technology carefully analyzes the headers and payload contents of each packet, reviews the packets using pre-set security criteria, and identifies packets containing malicious payloads and abnormal signatures. And a rule-based abnormal behavior analysis method is adopted, which is directly based on the spatio-temporal features extracted in Step Two. These rules are formulated by security experts based on common network attack patterns and historical security data. The present invention monitors network behavior and compares it with these rules to identify abnormal behaviors that deviate from normal network activities in real time. When the detected behavior matches the predefined abnormal pattern, corresponding response decisions (such as security alerts) are triggered in a timely manner. The specific steps are as follows:

[0076] Step 4.1 Deep Packet Inspection (DPI)

[0077] After the detection of adversarial examples is completed, the present invention deploys Deep Packet Inspection (DPI) technology to further enhance network security protection. The DPI module carefully analyzes the header information and payload content of each data packet. This analysis includes checking the protocol type, port number, destination address, and payload data in the data packet to ensure that the data packet does not carry the signature of malware or viruses. The DPI technology also examines whether the data packet complies with the organization's internal network usage policies and external compliance requirements, thereby identifying and intercepting non-compliant communications.

[0078] Step 4.2 Rule-based Anomaly Behavior Analysis

[0079] Based on the spatio-temporal characteristics of the traffic data to be measured and various types of pre-set standard spatio-temporal characteristics, the anomaly behavior of the traffic data to be measured is compared and analyzed; among them, various types of standard spatio-temporal characteristics include the spatio-temporal characteristics of actual traffic standard data and the spatio-temporal characteristics of various malicious traffic standard data; when it is determined that the spatio-temporal characteristics of the traffic data to be measured match the spatio-temporal characteristics of any malicious traffic standard data, the corresponding response decision is triggered.

[0080] Specifically, based on the Deep Packet Inspection (DPI) analysis, the present invention uses a rule-based anomaly behavior analysis method to further enhance security monitoring. Security experts define a set of behavior rules based on known attack patterns and historical security data, which describe in detail the characteristics of normal and abnormal network activities. The present invention monitors the spatio-temporal characteristics output by the neural network in step two in real time and compares the real-time data with these rules.

[0081] For example, when the present invention detects that the spatio-temporal feature vector of a certain IP address deviates significantly from the normal mode within a short period of time, such as the change of the feature vector exceeds the preset threshold, this may indicate the sign of a Distributed Denial of Service (DDoS) attack, and the present invention will immediately mark it as abnormal. In addition, if the spatio-temporal characteristics of a certain connection show an abnormal communication pattern, for example, the timing and size characteristics of the data packet match the known data leakage or protocol abuse behavior, the present invention will also identify it as abnormal behavior.

[0082] Any behavior that deviates from the normal spatio-temporal feature pattern, such as the above abnormal traffic characteristics or unauthorized access attempts, will be marked as abnormal. When the network behavior matches the preset abnormal feature pattern, the present invention automatically triggers an alarm and sends a notification to the network administrator so that corresponding countermeasures can be taken in time.

[0083] Step Five: Decision-making, Response and Feedback

[0084] Figure 3 is a schematic diagram of the process of the decision-making, response and feedback mechanism provided by the present invention. The following is further described with reference to Figure 3 as followsFigure 3 As shown in Figure 3 , the decision-making, response, and feedback mechanism of the present invention classifies network traffic using a decision tree algorithm by integrating the analysis results of steps two to four, and determines whether it is malicious.

[0085] Traffic identified as malicious will trigger an alarm and activate automatic response measures, including blocking the traffic, isolating the affected communication system, and notifying the network administrator. The present invention then enters the feedback stage, collecting operation results and user feedback to evaluate the response effect. These data will be used to optimize the detection algorithm and adjust the response strategy to adapt to new threats and ensure the continuous security of the network. The specific steps are as follows:

[0086] Step 5.1 Application of the decision tree algorithm

[0087] The present invention classifies the traffic data to be measured using a pre-trained supervised decision tree algorithm by integrating the content from steps two to four.

[0088] In step two, the present invention can directly utilize key parameters such as the size and communication frequency of data packets and / or spatio-temporal features. Step three identifies whether there are adversarial samples that mimic normal traffic (actual traffic data) through a generative adversarial network (GAN). Step four applies rule-based abnormal behavior analysis to determine whether the traffic shows behavior consistent with known attack patterns.

[0089] The decision tree algorithm evaluates the nature of each data stream based on the integrated analysis results of steps two to four.

[0090] Optionally, input the decision information into a pre-trained decision tree model to determine the final detection result of the traffic data to be measured, including: presetting multiple decision nodes of the decision tree model according to the key parameters, the first detection result, and the second detection result of the traffic data to be measured; setting the classification rules for each decision node; starting from the root node, gradually refining the classification result based on the set classification rules until reaching the leaf node; the leaf node outputs the final classification result to determine whether the traffic data to be measured is malicious traffic data.

[0091] The following takes key parameters as an example to illustrate part of the classification process of the decision tree model:

[0092] The first decision node of the decision tree can set a threshold checkpoint based on the average size of the data packet: if the average size of the data packet exceeds the preset threshold, the algorithm will direct the traffic to the left child node, indicating that there may be abnormal traffic; otherwise, it will be directed to the right child node, indicating normal traffic. Then, in the left child node, the second decision node checks whether the number of data packet transmissions within a specific time period is abnormally increased based on the communication frequency. If the communication frequency is higher than the normal range, the traffic will be further classified as high-risk, which may indicate abnormal behaviors such as distributed denial of service (DDoS) attacks; if it is not higher than the normal range, it may be a short-term network fluctuation and is classified as medium-risk.

[0093] Referring to the above method, the decision tree algorithm can perform inspections of specific attributes at each decision node according to the key parameters, the first detection result, and the second detection result of the traffic data to be measured, and conduct a fine classification of the traffic data to be measured, so as to finally determine the nature of the traffic. This feature-based decision tree design improves the accuracy and efficiency of abnormal traffic detection.

[0094] Step 5.2 Execution of Response Measures

[0095] Once the traffic is classified as malicious, the present invention immediately triggers an alarm and automatically activates response measures. This includes blocking in real time the traffic identified as malicious, isolating the affected part of the present invention to prevent further intrusion, and automatically notifying the network administrator for further emergency handling. The preset security policy of the present invention determines the specific content of the response actions, and each measure is designed to quickly mitigate the potential damage caused by the threat.

[0096] Step 5.3 Feedback Collection and Algorithm Optimization

[0097] After the response event is processed, the present invention enters the feedback collection stage. In this stage, the present invention records and analyzes the processing effect of each event and user feedback, and evaluates the effect of the existing security measures and the accuracy of the detection algorithm. The collected data is used to adjust the parameters and structure of the decision tree algorithm to optimize the classification accuracy. The present invention regularly updates the decision rules to adapt to newly emerging threat types and attack means, ensuring the continuous effectiveness and advancement of the detection and response mechanism.

[0098] In summary, the present invention provides a composite deep learning framework integrating a multi-layer perceptron (MLP) and a convolutional neural network (CNN). This framework uses optimized generative adversarial network (GAN) technology to improve the robustness of the model and effectively enhance the defense ability against malicious adversarial samples. By combining deep packet inspection (DPI) with abnormal behavior analysis, this technology can not only accurately detect and classify abnormal patterns in network traffic, but also conduct in-depth analysis of encrypted communications, thereby significantly improving the security protection ability of wireless communication networks. Specifically, it is reflected in the following aspects:

[0099] (1) Comprehensive deep learning framework: By integrating multi-layer perceptrons (MLPs) and convolutional neural networks (CNNs), this technology can effectively identify and classify complex network traffic and behavior patterns, improving the detection accuracy of malicious activities.

[0100] (2) Enhanced generative adversarial network: The present invention makes specific optimizations to the generative adversarial network (GAN), adding an adaptive adversarial sample generation mechanism. This mechanism introduces an attack strategy model that can be updated in real time into the generator, enabling the generator to generate corresponding adversarial samples according to the latest network attack methods. This allows the model to be updated in real time and effectively counter the latest and more complex network attack strategies. The enhanced GAN module also improves the model's defense capabilities when facing advanced persistent threats (APTs) and other complex attack strategies by sharing features between different network layers.

[0101] (3) Deep packet inspection and behavior analysis: By combining deep packet inspection (DPI) and rule-based behavior analysis, the present invention can not only accurately identify traditional security threats but also conduct in-depth analysis of encrypted communications, enhancing the monitoring ability of covert communications.

[0102] (4) Dynamic response and feedback adjustment: By implementing automated response measures and combining a continuous feedback mechanism, the system can adapt to changes in the network environment, timely adjust defense strategies, and ensure continuous network security.

[0103] Figure 4 It is a schematic structural diagram of a wireless communication network intrusion detection device for adversarial sample defense provided by the present invention. As Figure 4 shown, the device includes:

[0104] A first processing module 410, configured to extract features from the traffic data to be measured and obtain the spatio-temporal features of the traffic data to be measured;

[0105] A second processing module 420, configured to input the spatio-temporal features into the discriminator of the pre-trained generative adversarial network to obtain a first detection result of the traffic data to be measured;

[0106] A third processing module 430, configured to perform deep packet inspection on the traffic data to be measured and perform abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain a second detection result;

[0107] A fourth processing module 440, configured to input decision information into a pre-trained decision tree model to determine a final detection result of the traffic data to be measured; the decision information includes key parameters, a first detection result, and a second detection result of the traffic data to be measured.

[0108] It should be noted that the wireless communication network intrusion detection device for adversarial example defense provided in the embodiments of the present invention can, during specific operation, execute the wireless communication network intrusion detection method for adversarial example defense described in any of the above embodiments, which will not be elaborated in this embodiment.

[0109] Figure 5 is a schematic structural diagram of an electronic device provided by the present invention. As Figure 5 shown, the electronic device may include: a processor 510, a communications interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communications interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logical instructions in the memory 530 to execute the wireless communication network intrusion detection method for adversarial example defense. The method includes: extracting features from the traffic data to be measured to obtain the spatio-temporal features of the traffic data to be measured; inputting the spatio-temporal features into the discriminator of the pre-trained generative adversarial network to obtain the first detection result of the traffic data to be measured; performing deep packet detection on the traffic data to be measured, and performing abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain a second detection result; inputting the decision information into the pre-trained decision tree model to determine the final detection result of the traffic data to be measured.

[0110] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the wireless communication network intrusion detection method for adversarial example defense provided in the above embodiments. The method includes: extracting features from the traffic data to be measured to obtain the spatio-temporal features of the traffic data to be measured; inputting the spatio-temporal features into the discriminator of the pre-trained generative adversarial network to obtain the first detection result of the traffic data to be measured; performing deep packet detection on the traffic data to be measured, and performing abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain a second detection result; inputting the decision information into the pre-trained decision tree model to determine the final detection result of the traffic data to be measured.

[0111] On the other hand, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the wireless communication network intrusion detection method for adversarial sample defense provided in the above embodiments. The method includes: extracting features from the traffic data to be measured to obtain the spatio-temporal features of the traffic data to be measured; inputting the spatio-temporal features into the discriminator of the pre-trained generative adversarial network to obtain a first detection result of the traffic data to be measured; performing deep packet inspection on the traffic data to be measured, and performing abnormal behavior analysis on the traffic data to be measured based on the spatio-temporal features to obtain a second detection result; inputting the decision information into the pre-trained decision tree model to determine the final detection result of the traffic data to be measured.

[0112] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A wireless communication network intrusion detection method for adversarial sample defense, characterized in that: include: Extract features from the flow data to be measured to obtain the spatiotemporal features of the flow data to be measured; The spatiotemporal features are input into the discriminator of a pre-trained generative adversarial network to obtain a first detection result of the traffic data to be tested; wherein the generative adversarial network includes a discriminator and a generator, and the generator of the generative adversarial network is used to generate feature data of adversarial samples using random noise signals; the adversarial samples are malicious data that imitate actual traffic data; wherein the generator uses neural architecture search technology to design a neural network architecture, and introduces an attention mechanism to enable the generator to simulate network traffic features; the discriminator is used to identify actual traffic data and adversarial samples based on feature data of adversarial samples and actual traffic data; Performing deep packet inspection on the flow data to be measured, and performing abnormal behavior analysis on the flow data to be measured based on the spatiotemporal characteristics to obtain a second detection result; wherein, performing abnormal behavior analysis on the flow data to be measured based on the spatiotemporal characteristics includes: performing comparative analysis on abnormal behavior of the flow data to be measured based on the spatiotemporal characteristics of the flow data to be measured and a plurality of pre-set standard spatiotemporal characteristics; wherein the plurality of types of standard spatiotemporal characteristics include spatiotemporal characteristics of actual flow standard data and spatiotemporal characteristics of various malicious flow standard data; wherein the second detection result includes whether the flow data to be measured is malicious data and which specific type of malicious data it belongs to; The decision information is input into a pre-trained decision tree model to determine the final detection result of the flow data to be tested; specifically, the following steps are performed: setting classification rules for each decision node; starting from the root node, based on the set classification rules, the classification results are gradually refined until a leaf node is reached; the leaf node outputs the final classification result to determine whether the flow data to be tested is malicious flow data; the decision information includes key parameters of the flow data to be tested, a first detection result, and a second detection result.

2. The wireless communication network intrusion detection method for adversarial sample defense according to claim 1, characterized in that: After determining the final detection result of the flow data to be measured, the method further includes: When it is determined according to the final detection result that the flow data to be tested is malicious data, a response decision for the final detection result is triggered.

3. The wireless communication network intrusion detection method for adversarial sample defense according to claim 1, characterized in that: Extract features from the flow data to be measured and obtain the spatiotemporal features of the flow data to be measured, including: Extracting key parameters of the flow data to be measured; Inputting the key parameters into a multi-layer perceptron to extract high-dimensional vector features of the flow data to be measured; The high-dimensional vector features are input into a convolutional neural network to obtain the spatiotemporal features of the flow data to be measured.

4. The wireless communication network intrusion detection method for adversarial sample defense according to claim 1, characterized in that: Perform deep packet inspection on the traffic data to be tested, including: By analyzing the header information and payload content of the traffic data to be tested, it is determined whether it carries malicious information.

5. The wireless communication network intrusion detection method for adversarial sample defense according to claim 1, characterized in that: Also includes: When it is determined that the spatiotemporal characteristics of the traffic data to be tested match the spatiotemporal characteristics of any malicious traffic standard data, a corresponding response decision is triggered.

6. The wireless communication network intrusion detection method for adversarial sample defense according to claim 1, characterized in that: Before extracting features from the measured traffic data, it also includes: Deploy traffic monitoring equipment at key access points of wireless communication networks; Use traffic monitoring equipment to capture the passing data packets and perform data cleaning on the captured data packets; The cleaned data is subjected to data standardization to obtain the flow data to be measured.

7. A wireless communication network intrusion detection device for adversarial sample defense, characterized in that: include: The first processing module is used to extract features of the flow data to be measured and obtain the spatiotemporal features of the flow data to be measured; The second processing module is used to input the spatiotemporal features into the discriminator of the pre-trained generative adversarial network to obtain the first detection result of the traffic data to be tested; wherein the generative adversarial network includes a discriminator and a generator; the generator is used to generate feature data of adversarial samples using random noise signals; the adversarial samples are malicious data that imitate actual traffic data; wherein the generator uses neural architecture search technology to design the neural network architecture, and introduces an attention mechanism to enable the generator to simulate network traffic features; the discriminator is used to identify actual traffic data and adversarial samples based on the feature data of adversarial samples and actual traffic data; A third processing module is used to perform deep packet inspection on the flow data to be measured, and to perform abnormal behavior analysis on the flow data to be measured based on the spatiotemporal characteristics to obtain a second detection result; wherein, the abnormal behavior analysis of the flow data to be measured based on the spatiotemporal characteristics includes: based on the spatiotemporal characteristics of the flow data to be measured and a plurality of pre-set standard spatiotemporal characteristics, a comparative analysis of the abnormal behavior of the flow data to be measured is performed; wherein the plurality of types of standard spatiotemporal characteristics include the spatiotemporal characteristics of the actual flow standard data and the spatiotemporal characteristics of various malicious flow standard data; wherein the second detection result includes whether the flow data to be measured is malicious data and which specific type of malicious data it belongs to; The fourth processing module is used to input the decision information into the pre-trained decision tree model to determine the final detection result of the flow data to be tested; specifically including: setting the classification rules for each decision node; starting from the root node, based on the set classification rules, gradually refining the classification results until reaching the leaf node; the leaf node outputs the final classification result to determine whether the flow data to be tested is malicious flow data; the decision information includes the key parameters of the flow data to be tested, the first detection result and the second detection result.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the wireless communication network intrusion detection method for adversarial sample defense as described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Intrusion behavior detection method, system and device based on multiple decision trees and medium

    CN117081858A

  • Intelligent network equipment service host security management system based on deep learning

    CN117424740A