A network attack detection method and system based on multi-modal feature fusion
By extracting multimodal features of network data and fusion, combined with a fully connected network, the detection accuracy problem of traditional neural networks in complex network environments is solved, and higher detection accuracy and robustness of network attacks are achieved.
Patent Information
- Application Number
- CN202411802800.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Modern cyber attack methods are becoming increasingly complex. The traditional neural network structure is single, and it is impossible to fully utilize the rich information contained in network data traffic, making it difficult to maintain good network attack detection accuracy in complex network environments.
A network attack detection method based on multimodal feature fusion is adopted, and a network attack detection is performed by extracting traffic characteristics, load characteristics and timing characteristics of network data, and a multiple attention mechanism is introduced to perform feature fusion, and a full-connected network is used for network attack detection.
It improves the accuracy of network attack detection, reduces the occurrence of false alarms and underreports, can capture complex attack patterns, and enhances the system's ability to respond in complex network environments.
Smart Images

Figure CN119696859B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a network attack detection method and system based on multi-modal feature fusion. Background Art
[0002] With the gradual complexity of the network environment, network security issues have received increasing attention. The digital transformation of modern society has made enterprises, organizations, and individuals rely on various network services and data transmissions in their daily operations. However, with the popularization of the Internet and the diversification of application scenarios, network attack means have become increasingly complex and concealed.
[0003] Detecting network attacks is an effective preventive measure. By real-time monitoring of network traffic and user behavior, abnormal activities can be quickly identified, such as unusual login attempts, abnormal data transmissions, or the spread of malware. This rapid response ability enables organizations to take measures at the initial stage of an attack and reduce potential losses.
[0004] With the rapid development of technologies such as pattern recognition, machine vision, and deep learning, and the urgent need for network attack detection, more and more modern technologies have been applied to network attack detection. Neural networks have become a popular network attack detection solution.
[0005] However, modern network attack techniques are becoming increasingly complex. In the face of the increasingly complex network environment, due to the single structure of traditional neural networks, it is impossible to fully utilize the rich information contained in network data traffic, and it is difficult to maintain a good network attack detection accuracy rate in a complex network environment. Summary of the Invention
[0006] In order to solve the technical problem that modern network attack techniques are becoming increasingly complex, in the face of the increasingly complex network environment, due to the single structure of traditional neural networks, it is impossible to fully utilize the rich information contained in network data traffic, and it is difficult to maintain a good network attack detection accuracy rate in a complex network environment, the present invention provides a network attack detection method and system based on multi-modal feature fusion.
[0007] The technical solutions provided by the embodiments of the present invention are as follows:
[0008] First Aspect
[0009] A network attack detection method based on multi-modal feature fusion provided by an embodiment of the present invention includes:
[0010] S1: Obtain network data;
[0011] S2: Extract traffic features of the network data according to the statistical information and metadata of the network data;
[0012] S3: Extract the load characteristics of the network data according to the load of the network data;
[0013] S4: Calculate the anomaly factor of the network data through a statistical method according to the traffic characteristics and load characteristics of the network data;
[0014] S5: Determine whether there is an anomaly in the network data according to the anomaly factor of the network data; if so, enter S6; otherwise, return to S1 to continue detection;
[0015] S6: Extract the temporal characteristics of the network data through a long short-term memory neural network;
[0016] S7: Perform multi-modal feature fusion on the traffic characteristics, load characteristics, and temporal characteristics based on a multi-attention mechanism;
[0017] S8: Perform network attack detection through a fully connected network according to the fused features, and determine whether the system is under a network attack; if so, output the specific type of network attack and issue an alarm; otherwise, return to S1 to continue detection.
[0018] Second aspect
[0019] A network attack detection system based on multi-modal feature fusion provided by an embodiment of the present invention includes:
[0020] A processor;
[0021] A memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, the network attack detection method based on multi-modal feature fusion as described in the first aspect is implemented.
[0022] Third aspect
[0023] A computer-readable storage medium provided by an embodiment of the present invention, on which a computer program is stored, and when the program is executed by a processor, the network attack detection method based on multi-modal feature fusion as described in the first aspect is implemented.
[0024] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:
[0025] In the present invention, by extracting the traffic characteristics, load characteristics, and temporal characteristics of network data, the rich information contained therein is fully mined, and a multi-attention mechanism is introduced to dynamically identify the importance of each feature, improve the expression ability of the features, be able to capture complex attack patterns, improve the accuracy of network attack detection, and reduce the occurrence of false positives and false negatives. Description of the drawings
[0026] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0027] Figure 1 It is a schematic flow chart of a network attack detection method based on multi-modal feature fusion provided by an embodiment of the present invention;
[0028] Figure 2 It is a schematic structural diagram of a network attack detection method based on multi-modal feature fusion provided by an embodiment of the present invention;
[0029] Figure 3 It is a schematic structural diagram of a network attack detection system based on multi-modal feature fusion provided by an embodiment of the present invention. Specific embodiments
[0030] The following will describe the technical solutions in the present invention in conjunction with the accompanying drawings.
[0031] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to give examples, illustrations or explanations. Any embodiment or design solution described as "example" in the present invention should not be construed as more preferred or more advantageous than other embodiments or design solutions. Exactly, the use of the word "example" is intended to present concepts in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.
[0032] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meaning they express is the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meaning they express is the same.
[0033] In the embodiments of the present invention, sometimes subscripts such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.
[0034] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail in conjunction with the accompanying drawings and specific embodiments.
[0035] Referring to the attached specification Figure 1 , it shows a schematic flow chart of a network attack detection method based on multi-modal feature fusion provided by an embodiment of the present invention.
[0036] Refer to the attached instruction manual Figure 2 , which shows a schematic structural diagram of a network attack detection method provided by an embodiment of the present invention based on multi-modal feature fusion.
[0037] An embodiment of the present invention provides a network attack detection method based on multi-modal feature fusion. This method can be implemented by a network attack detection device based on multi-modal feature fusion. The network attack detection device based on multi-modal feature fusion can be a terminal or a server. The processing flow of the network attack detection method based on multi-modal feature fusion may include the following steps:
[0038] S1: Obtain network data.
[0039] S2: Extract traffic features of the network data according to the statistical information and metadata of the network data.
[0040] Optionally, the traffic features specifically include: traffic start time, traffic duration, source byte count, target byte count, source packet count, and target packet count.
[0041] Among them, the traffic start time refers to the timestamp when the first packet of a data stream or connection is sent. This feature can help analyze the time pattern of network traffic, identify peak periods and potential abnormal activities. For example, by analyzing the traffic start time, it can be found whether there is abnormal traffic during non-working hours, which may indicate potential attack behavior.
[0042] Among them, the traffic duration refers to the time interval from the start to the end of a data stream, usually in seconds. This feature is used to evaluate the persistence of a connection. An abnormally long connection time may indicate potential malicious activities, such as certain types of scans or data penetration attacks. By monitoring the traffic duration, persistent abnormal behaviors can be effectively identified.
[0043] Among them, the source byte count refers to the total number of data bytes sent from the source address to the target address. This feature reflects the sending intensity and data volume of the traffic. Abnormal source byte counts (e.g., suddenly sending a large amount of data) may indicate data leakage or denial-of-service attacks. By analyzing the source byte count, abnormal patterns in the traffic can be identified.
[0044] Among them, the target byte count refers to the total number of data bytes received from the source address for the target address. The target byte count can help analyze the intensity of data reception. Abnormal target byte counts (e.g., an abnormally increased reception volume) may indicate that an attacker has sent a large amount of data to the target, which may be used for penetration or attack. Monitoring the target byte count helps identify potential attack targets.
[0045] Among them, the number of source data packets refers to the total number of data packets sent from the source address to the destination address. This feature can help identify the frequency and pattern of traffic. An abnormal number of source data packets (such as a large number of small data packets) may indicate network scanning, DDoS attacks, or other forms of abuse. By monitoring the number of source data packets, the security system can quickly identify potential attack behaviors.
[0046] Among them, the number of destination data packets refers to the total number of data packets received from the source address for the destination address. This feature is used to analyze the traffic intensity received by the destination. An abnormal number of destination data packets (for example, a sudden increase in the received amount) may indicate that the destination is under attack or is experiencing abnormal traffic. This feature helps the security team evaluate the impact and scope of the attack.
[0047] S3: Extract the load characteristics of the network data according to the load of the network data.
[0048] Among them, the payload is the actual data content contained in the data packet, usually the data at the application layer, such as web page requests, file transfers, email contents, etc. The payload contains the information that the user wants to transmit, rather than just the control information required by the network protocol (such as the IP header and TCP header).
[0049] Optionally, the load characteristic is specifically: the first 32 bytes of the load content. The first 32 bytes of the load usually contain key information, such as the method, URL, user agent, cookie, etc. in the HTTP request. These information help to identify user behaviors and request types, and are beneficial to detecting common attack patterns, such as SQL injection, cross-site scripting (XSS), etc. Analyzing the entire load directly may result in high computing and storage costs. Selecting the first 32 bytes can effectively reduce the complexity of data processing, while still retaining enough information for feature extraction and analysis.
[0050] S4: Calculate the anomaly factor of the network data through statistical methods according to the traffic characteristics and load characteristics of the network data.
[0051] In a possible implementation manner, S4 specifically includes sub-steps S401 to S403:
[0052] S401: Concatenate the traffic characteristics and load characteristics of the network data at the current moment to form a feature vector.
[0053] It should be noted that concatenating the traffic characteristics and load characteristics can effectively integrate information from different sources. Such a comprehensive feature vector can provide a more comprehensive perspective and help identify complex attack patterns.
[0054] S402: Calculate the standard score of each feature in the feature vector:
[0055]
[0056] Among them, Z tk represents the standard score of the k-th feature at time t, X tk represents the eigenvalue of the k-th feature at time t, μ k represents the mean value of the k-th feature, σ k represents the standard deviation of the k-th feature.
[0057] S403: Calculate the anomaly factor of the network data at the current moment according to the standard scores of each feature:
[0058]
[0059] Among them, Z t represents the anomaly factor of the network data at time t, β k represents the contribution degree of the k-th feature to network attack detection, and K represents the total number of features.
[0060] It should be noted that the anomaly factor quantifies the deviation degree of each data point from the normal behavior, and judges the anomaly through the set threshold, which can effectively identify potential network attacks and abnormal behaviors.
[0061] In the present invention, by using the standard score to calculate the anomaly factor, the anomaly degree of each feature can be quantified. Combining the contribution degree of the features, it is possible to more accurately identify which features have a greater impact on the detection result, thereby improving the overall detection accuracy.
[0062] S5: Judge whether there is an anomaly in the network data according to the anomaly factor of the network data. If so, enter S6. Otherwise, return to S1 to continue the detection.
[0063] In a possible implementation manner, S5 is specifically: judge whether the anomaly factor of the network data is greater than the anomaly threshold. If so, determine that there is an anomaly in the network data and enter S6. Otherwise, determine that there is no anomaly in the network data and return to S1 to continue the detection.
[0064] Among them, those skilled in the art can set the size of the anomaly threshold according to the actual situation, and the present invention does not make any limitations.
[0065] In the present invention, performing preliminary anomaly detection before the complex model can quickly screen out the obviously abnormal network data based on statistical principles, thereby avoiding unnecessary waste of computing resources. A complex neural network model usually requires a long training and inference time. By performing anomaly factor detection first, most of the normal traffic can be directly filtered out, and only the potentially abnormal data is deeply analyzed, thereby reducing the computational burden of the model.
[0066] S6: Extract the temporal features of network data through a long short-term memory neural network.
[0067] Among them, the long short-term memory neural network (LSTM, Long Short-Term Memory) is a special type of recurrent neural network (RNN). With its unique gating mechanism and cell state design, it can effectively solve the problem of long-term dependence.
[0068] Specifically, extracting the temporal features of network data through a long short-term memory neural network is specifically as follows:
[0069] I t = Sigmoid(W XI X t + W HI h t-1 + b I )
[0070] F t = Sigmoid(W XF X t + W HF h t-1 + b F )
[0071] O t = Sigmoid(W XO X t + W HO h t-1 + b O )
[0072]
[0073] h t = O t · tanh(C t )
[0074] Among them, X t represents the network data sequence at time t, I t represents the activation output vector of the input gate at time t, Sigmoid() represents the Sigmoid activation function, W XI represents the weight matrix between the token sequence and the input gate, W HI represents the weight matrix between the hidden state and the input gate, b I represents the bias term of the input gate, F t represents the activation output vector of the forget gate at time t, W XF represents the weight matrix between the token sequence and the forget gate, W HF represents the weight matrix between the hidden state and the forget gate, b F represents the bias term of the forget gate, Ot Denote the activation output vector of the output gate at time t, W XO Denote the weight matrix between the word segmentation sequence and the output gate, W HO Denote the weight matrix between the hidden state and the output gate, b O Denote the bias term of the output gate, C t Denote the activation output vector of the cell storage unit at time t, Denote the temporary cell state of the cell storage unit at time t, C t-1 Denote the activation output vector of the cell storage unit at time t-1, tanh() represents the tanh activation function, W XC Denote the weight matrix between the word segmentation sequence and the cell storage unit, W HC Denote the weight matrix between the hidden state and the cell storage unit, b C Denote the bias term of the cell storage unit, h t Denote the hidden state at time t, h t-1 Denote the hidden state at time t-1, t represents time.
[0075] It should be noted that the hidden states at the above-mentioned respective times are the temporal features to be extracted.
[0076] In the present invention, by using LSTM to extract the temporal features of network data, it is not only possible to effectively process and analyze complex temporal information, but also to enhance the accuracy and robustness of the model. This method provides a more powerful and flexible feature basis for network attack detection, which helps to timely identify and respond to potential network threats.
[0077] S7: Based on the multi-attention mechanism, perform multi-modal feature fusion on the traffic features, load features, and temporal features.
[0078] In a possible implementation manner, S7 specifically includes sub-steps S701 to S704:
[0079] S701: Concatenate the traffic features, load features, and temporal features to form a concatenated feature vector.
[0080] S702: For each feature in the concatenated feature vector, calculate the spatial self-attention in the spatial dimension.
[0081] Optionally, S702 specifically includes:
[0082] S7021: Based on the spatial window self-attention mechanism in the spatial dimension, generate the query matrix, key matrix, and value matrix of each original feature in the concatenated feature vector:
[0083] Q = XW Q
[0084] K = XW K
[0085] V = XW V
[0086] Among them, Q represents the query matrix, K represents the key matrix, V represents the value matrix, X represents the original feature, and W Q represents the query linear projection matrix, and W K represents the key linear projection matrix, and W V represents the value linear projection matrix.
[0087] S7022: Divide the query matrix, key matrix, and value matrix into non-overlapping windows respectively, and flatten the windows.
[0088] S7023: According to the flattened windows, divide the query matrix, key matrix, and value matrix into multiple attention heads respectively:
[0089]
[0090] Among them, Q s represents the query matrix of the s-th window, represents the query matrix of the i-th attention head in the s-th window, h represents the total number of attention heads, K s represents the key matrix of the s-th window, represents
[0091] the key matrix of the i-th attention head in the s-th window, V s represents the value matrix of the s-th window, represents the value matrix of the i-th attention head in the s-th window, Y s i represents the output of the i-th attention head in the s-th window, Softmax represents the activation function, T represents the matrix transpose, d represents the size of the attention head, d = C / h, C represents the dimension of the feature vector, and B represents the relative position encoding.
[0092] S7024: Concatenate the outputs of each attention head to obtain the spatial self-attention:
[0093]
[0094] Among them, Y s represents the spatial self-attention, and Concat represents the concatenation function.
[0095] It should be noted that by implementing the spatial self-attention mechanism, especially in the context of window division and multi-head processing, the model's ability to capture complex patterns in network traffic and processing efficiency can be significantly improved.
[0096] S703: For each feature in the spliced feature vector, calculate the channel self-attention of the channel dimension.
[0097] Optionally, S703 specifically includes:
[0098] S7031: Based on the channel window self-attention mechanism of the channel dimension, generate the query matrix, key matrix, and value matrix of each original feature in the spliced feature vector:
[0099] Q = XW Q
[0100] K = XW K
[0101] V = XW V
[0102] Among them, Q represents the query matrix, K represents the key matrix, V represents the value matrix, X represents the original feature, and W Q represents the query linear projection matrix, and W K represents the key linear projection matrix, and W V represents the value linear projection matrix.
[0103] S7032: Reshape the query matrix, key matrix, and value matrix into matrices of the same size.
[0104] S7033: Divide the reshaped query matrix, key matrix, and value matrix into multiple attention heads respectively:
[0105]
[0106] Among them, Q c represents the reshaped query matrix, represents the query matrix of the i-th attention head in the reshaped query matrix, h represents the total number of attention heads, K c represents the reshaped key matrix, represents the key matrix of the i-th attention head in the reshaped key matrix, V c represents the reshaped value matrix, represents the value matrix of the i-th attention head in the reshaped value matrix, Y c i represents the output of the i-th attention head, Softmax represents the activation function, T represents the matrix transpose, and α represents the learnable temperature parameter.
[0107] S7034: Concatenate the outputs of each attention head to obtain the channel self-attention:
[0108]
[0109] Among them, Y cIt represents channel self-attention, and Concat represents the concatenation function.
[0110] It should be noted that the channel self-attention mechanism enables the model to dynamically focus on the important parts in the input features, strengthens the representation of important features by calculating attention weights, and reduces the influence of unimportant features.
[0111] S704: According to the spatial self-attention and channel self-attention, perform multi-modal feature fusion on the traffic feature, load feature, and time series feature to obtain a fused feature vector:
[0112]
[0113] Among them, F m represents the fused feature vector, Y s represents the spatial self-attention, Y c represents the channel self-attention, F s represents the concatenated feature vector, represents the concatenation operation.
[0114] In the present invention, the multiple attention mechanisms enable the model to analyze and integrate features from different perspectives, capture the complex relationships between features, and enhance the model's ability to understand multi-modal data. It not only improves the model's expressiveness and accuracy but also enhances the system's response ability in complex network environments. This comprehensive method provides a more comprehensive and flexible solution for network security and can effectively cope with various network attacks.
[0115] S8: According to the fused feature, through a fully connected network, perform network attack detection to determine whether the system is under a network attack. If so, output the specific type of network attack and issue an alarm. Otherwise, return to S1 to continue detection.
[0116] In a possible implementation manner, S8 specifically includes sub-steps S801 to S802:
[0117] S801: According to the fused feature, through a fully connected network, determine the class prediction probability of the network data:
[0118] P = Softmax(WF m +b)
[0119] Among them, P represents the class prediction probability, Softmax represents the activation function, W represents the network attack detection weight matrix, F m represents the fused feature vector, and b represents the network attack detection bias term.
[0120] S802: Use the category with the largest probability value in the category prediction probability as the result of this network attack detection, and determine whether the system is under a network attack. If so, output the specific type of network attack and issue an alarm. Otherwise, return to S1 to continue the detection.
[0121] For the training of the neural network, the Adam optimizer can be used to optimize the network parameters of the neural network:
[0122]
[0123] m t = β1m t-1 + (1 - β1)g t
[0124] where θ t represents the long short-term memory neural network parameters at the t-th iteration, θ t-1 represents the long short-term memory neural network parameters at the (t - 1)-th iteration, γ represents the base learning rate, represents the estimated value of the second moment after correcting the bias at the t-th iteration, ε represents the hyperparameter for numerical stability, represents the estimated value of the first moment after correcting the bias at the t-th iteration, v t represents the estimated value of the second moment at the t-th iteration, β2 represents the decay coefficient of the second moment estimate, v t-1 represents the estimated value of the second moment at the (t - 1)-th iteration, g t represents the gradient at the t-th iteration, represents the gradient operation, L represents the loss function, represents the gradient operation of the loss function with respect to the convolutional neural network parameters at the t-th iteration, m t represents the estimated value of the first moment at the t-th iteration, β1 represents the decay coefficient of the first moment estimate, m t-1 represents the estimated value of the first moment at the (t - 1)-th iteration.
[0125] In the present invention, the Adam optimizer introduces an adaptive learning rate, designs an independent learning rate for each parameter, and dynamically adjusts the learning rate according to the estimated values of the first moment (average) and the second moment (variance) of the gradient. This adaptive mechanism can ensure that the learning rate can be automatically adjusted under different parameters or different time steps, avoiding the problems of oscillation caused by too large a learning rate or slow convergence caused by too small a learning rate.
[0126] Furthermore, Adam combines the momentum mechanism. By taking the weighted average of past gradients (i.e., the first moment estimate), it can reduce the oscillation in gradient updates, especially smoothing the parameter updates in a steep loss surface.
[0127] At the same time, the Adam optimizer corrects the bias of the first and second moments, that is, in the initial stage of iteration, it corrects the moment estimation to offset the initial bias. Through this correction, Adam can more accurately evaluate the gradient during the early iteration and avoid inaccurate optimization caused by estimation bias.
[0128] In the present invention, a fully connected network is used to detect network attacks based on the fused features, which not only improves the accuracy and efficiency of classification, but also enhances the real-time response ability and scalability of the system. This method provides strong support for network security, helps to quickly identify and respond to various network attacks, and ensures information security.
[0129] The beneficial effects brought by the technical solution provided by the embodiments of the present invention at least include:
[0130] In the present invention, by extracting the traffic features, load features, and temporal features of network data, the rich information contained therein is fully mined, and a multiple attention mechanism is introduced to dynamically identify the importance of each feature, improve the expression ability of the features, be able to capture complex attack patterns, improve the accuracy rate of network attack detection, and reduce the occurrence of false positives and false negatives.
[0131] Refer to the attached Figure 3 illustrates a schematic structural diagram of a network attack detection system based on multi-modal feature fusion provided by the present invention.
[0132] The present invention also provides a network attack detection system 20 based on multi-modal feature fusion, which is applied to the above-mentioned network attack detection method based on multi-modal feature fusion, and includes:
[0133] A processor 201.
[0134] A memory 202, on which computer-readable instructions are stored. When the computer-readable instructions are executed by the processor 201, the network attack detection method based on multi-modal feature fusion as in the method embodiment is implemented.
[0135] The network attack detection system 20 provided by the present invention can execute the above-mentioned network attack detection method based on multi-modal feature fusion and achieve the same or similar technical effects. To avoid repetition, the present invention will not elaborate.
[0136] The beneficial effects brought by the technical solution provided by the embodiments of the present invention at least include:
[0137] In the present invention, by extracting the traffic characteristics, load characteristics, and temporal characteristics of network data, the rich information contained therein is fully mined, and a multiple attention mechanism is introduced to dynamically identify the importance of each feature, improve the expression ability of the features, capture complex attack patterns, enhance the accuracy of network attack detection, and reduce the occurrence of false positives and false negatives.
[0138] It should be understood that the processor in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0139] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0140] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0141] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context.
[0142] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or plural.
[0143] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0144] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0145] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described devices, apparatuses, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0146] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0147] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0148] In addition, the functional units in various embodiments of the present invention can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0149] When the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0150] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the network attack detection method based on multi-modal feature fusion as described in the method embodiment.
[0151] The computer-readable storage medium provided by the present invention can implement the steps and effects of the network attack detection method based on multi-modal feature fusion in the above method embodiment. To avoid repetition, the present invention will not elaborate further.
[0152] The beneficial effects brought by the technical solution provided by the embodiments of the present invention at least include:
[0153] In the present invention, by extracting the traffic characteristics, load characteristics, and time series characteristics of network data, the rich information contained therein is fully explored, and a multiple attention mechanism is introduced to dynamically identify the importance of each feature, improve the expression ability of the features, be able to capture complex attack patterns, improve the accuracy of network attack detection, and reduce the occurrence of false positives and false negatives.
[0154] As mentioned above, the above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
[0155] The following points need to be explained:
[0156] (1) The drawings of the embodiments of the present invention only relate to the structures involved in the embodiments of the present invention, and other structures can refer to the general design.
[0157] (2) For clarity, in the drawings used to describe the embodiments of the present invention, the thickness of layers or regions is enlarged or reduced, that is, these drawings are not drawn to actual scale. It can be understood that when an element such as a layer, film, region, or substrate is referred to as being "on" or "under" another element, the element can be "directly" on or under the other element or there can be intervening elements.
[0158] (3) Without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other to obtain new embodiments.
[0159] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. The protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A network attack detection method based on multimodal feature fusion, characterized in that: include: S1: Get network data; S2: extracting traffic characteristics of the network data according to the statistical information and metadata of the network data; S3: extracting a load feature of the network data according to the load of the network data; S4: Calculating the abnormality factor of the network data by statistical method according to the traffic characteristics and load characteristics of the network data; S5: judging whether the network data is abnormal according to the abnormal factor of the network data; if so, proceeding to S6; otherwise, returning to S1 to continue detection; S6: extracting the temporal features of the network data through a long short-term memory neural network; S7: Based on a multiple attention mechanism, multi-modal feature fusion is performed on the traffic feature, the load feature, and the timing feature; S8: Based on the fusion features, network attack detection is performed through the fully connected network to determine whether the system is under network attack; If so, output the specific network attack type and issue an alarm; Otherwise, return to S1 to continue testing; Wherein, the S7 specifically includes: S701: Concatenate the traffic feature, the load feature, and the timing feature to form a concatenated feature vector; S702: For each feature in the concatenated feature vector, calculate the spatial self-attention of the spatial dimension; S703: For each feature in the concatenated feature vector, calculate the channel self-attention of the channel dimension; S704: According to the spatial self-attention and the channel self-attention, multimodal feature fusion is performed on the flow feature, the load feature and the time series feature to obtain a fused feature vector: Among them, F m represents the fused feature vector, Y s represents spatial self-attention, Y c represents channel self-attention, F s represents the concatenated feature vector, Represents a concatenation operation.
2. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The traffic characteristics specifically include: traffic start time, traffic duration, source byte number, target byte number, source data packet number and target data packet number.
3. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The payload characteristics are specifically: the first 32 bytes of the payload content.
4. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The S4 specifically includes: S401: concatenate the flow characteristics and load characteristics of the current network data to form a feature vector; S402: Calculate the standard score of each feature in the feature vector: Among them, Z tk represents the standard score of the kth feature at time t, X tk represents the eigenvalue of the kth feature at time t, μ k represents the mean of the kth feature, σ k represents the standard deviation of the kth feature; S403: Calculate the abnormal factor of the current network data based on the standard score of each feature: Among them, Z t represents the abnormal factor of network data at time t, β k It represents the contribution of the kth feature to network attack detection, and K represents the total number of features.
5. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The S5 is specifically: Determine whether the abnormal factor of the network data is greater than the abnormal threshold; if so, determine that the network data is abnormal and enter S6; otherwise, determine that the network data is not abnormal and return to S1 to continue detection.
6. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The S702 specifically includes: S7021: Generate query matrix, key matrix and value matrix of each original feature in the concatenated feature vector based on the spatial window self-attention mechanism in the spatial dimension; S7022: Divide the query matrix, the key matrix, and the value matrix into non-overlapping windows respectively, and flatten the windows; S7023: Divide the query matrix, the key matrix, and the value matrix into a plurality of attention heads according to the flattened window; S7024: Concatenate the outputs of each attention head to obtain spatial self-attention.
7. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The S703 specifically includes: S7031: Generate query matrix, key matrix and value matrix of each original feature in the concatenated feature vector based on the channel window self-attention mechanism of the channel dimension; S7032: reshape the query matrix, the key matrix, and the value matrix into matrices of the same size; S7033: Divide the reshaped query matrix, key matrix and value matrix into multiple attention heads respectively; S7034: Concatenate the outputs of each attention head to obtain channel self-attention.
8. The network attack detection method based on multimodal feature fusion according to claim 1 is characterized in that: The S8 specifically includes: S801: Determine the category prediction probability of network data through a fully connected network based on the fusion features: P=Softmax(WF m +b) Among them, P represents the category prediction probability, Softmax represents the activation function, W represents the network attack detection weight matrix, and F m represents the fused feature vector, b represents the bias term for network attack detection; S802: The category with the largest probability value among the category prediction probabilities is taken as the network attack detection result of this time to determine whether the system is under network attack; if so, output the specific network attack type and issue an alarm; otherwise, return to S1 to continue detection.
9. A network attack detection system based on multimodal feature fusion, characterized in that: include: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the network attack detection method based on multimodal feature fusion as described in any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Attack identification method adopting multi-modal data fusion
CN118509255A
Network security situation awareness method, computer equipment and storage medium
CN118590885A