DDOS Attack Monitoring System Based on Hybrid Neural Network

Through the DDOS attack monitoring system of hybrid neural networks, combined with convolutional neural networks and nonlinear dynamics models, the existing system's low detection rate and untimely response to complex and zero-day attacks is solved, and real-time recognition and accurate response to complex DDOS attacks are achieved.

CN119740181BActive Publication Date: 2025-07-04ANHUI PROPERTY RIGHTS TRADING CENT CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510259010.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-04
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

The existing DDOS attack monitoring system is difficult to deal with highly dynamic and complex attack modes. The traditional detection method based on static rules cannot handle nonlinear features in traffic, resulting in low detection rate, lack of adaptability, and inability to detect new attacks in time, resulting in untimely response or inaccurate defense strategies.

Method used

The DDOS attack monitoring system based on hybrid neural networks is adopted, including feature extraction fusion unit, zero-day attack detection unit, traffic resource balance unit and policy feedback execution unit. High-order deep features of network traffic data are extracted through convolutional neural networks, and attack response strategy construction is carried out in combination with neural networks and nonlinear dynamic models, and adaptive resource balance and policy feedback adjustment are carried out.

Benefits of technology

Real-time identification and accurate response to complex and mutated attack patterns is achieved, the system's adaptability is improved, and the mutated attack types and zero-day attacks that are difficult to capture by traditional methods are improved, and the real-time and defense effect of network protection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119740181B_ABST
    Figure CN119740181B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology. Specifically, it relates to a DDOS attack monitoring system based on a hybrid neural network. It includes: a feature extraction and fusion unit for obtaining network traffic data, extracting network basic features in the network traffic data, using a convolutional neural network to extract high-order depth features in the network traffic data, and fusing them to obtain network comprehensive features; a zero-day attack detection unit using a neural network combined with nonlinear dynamics to monitor the network traffic state vector, and using a neural network combined with a Q-value function to construct an attack response strategy; a traffic resource balancing unit for adaptively balancing system resources and optimizing the attack response strategy according to the real-time state of system resources; a policy feedback and execution unit for executing the attack response strategy and feedback-adjusting the defense strategy. This DDOS attack monitoring system based on a hybrid neural network improves the recognition ability for complex and mutated attack patterns by combining deep adaptive learning and nonlinear time series modeling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology. Specifically, it relates to a DDOS attack monitoring system based on a hybrid neural network. Background Art

[0002] The DDOS attack monitoring system based on a hybrid neural network aims to improve the detection accuracy of complex and zero-day attacks and optimize the adaptive ability of attack response strategies. By combining a nonlinear dynamics model with a recurrent neural network for real-time traffic analysis and anomaly detection, it controls the state evolution of network traffic and the detection and response of attack patterns, realizes the rapid identification of unknown attacks, and adjusts defense measures based on the real-time traffic state.

[0003] Existing DDOS attack monitoring systems usually have difficulty coping with highly dynamic and complex attack patterns. Moreover, since traditional static rule-based detection methods cannot handle the nonlinear features in traffic, the detection rate of the system for zero-day attacks and mutated attack patterns is relatively low, new attacks cannot be discovered in a timely manner, and there is a lack of sufficient adaptive ability, resulting in the network protection being unable to make real-time adjustments according to changes in traffic characteristics, leading to problems such as untimely response or inaccurate defense strategies when the system is under attack. Therefore, a DDOS attack monitoring system based on a hybrid neural network is designed. Summary of the Invention

[0004] The purpose of the present invention is to provide a DDOS attack monitoring system based on a hybrid neural network to solve the problems raised in the above background art, that is, since traditional static rule-based detection methods cannot handle the nonlinear features in traffic, the detection rate of the system for zero-day attacks and mutated attack patterns is relatively low, new attacks cannot be discovered in a timely manner, and there is a lack of sufficient adaptive ability, resulting in the network protection being unable to make real-time adjustments according to changes in traffic characteristics, leading to problems such as untimely response or inaccurate defense strategies when the system is under attack.

[0005] To achieve the above object, the present invention aims to provide a DDOS attack monitoring system based on a hybrid neural network, including: a feature extraction and fusion unit, which is used to obtain network traffic data, extract network basic features from the network traffic data, use a convolutional neural network to extract high-order depth features from the network traffic data, and fuse the network basic features and high-order depth features to obtain network comprehensive features;

[0006] It further includes a zero-day attack detection unit, which, based on the network comprehensive features, uses a neural network combined with nonlinear dynamics to monitor the network traffic state vector, and uses a neural network combined with a Q-value function to construct an attack response strategy;

[0007] It further includes a traffic resource balancing unit, which is used to adaptively balance system resources according to the real-time changes of network traffic and device health status, and optimize the attack response strategy according to the real-time status of system resources;

[0008] It further includes a policy feedback execution unit, which is used to execute the attack response strategy and feedback to adjust the defense strategy.

[0009] As a further improvement of this technical solution, the feature extraction and fusion unit includes a feature extraction module and a feature fusion module;

[0010] Among them, the feature extraction module is used to obtain network traffic data, extract network basic features from the network traffic data, and use a convolutional neural network to extract high-order depth features from the network traffic data;

[0011] The feature fusion module is used to fuse the network basic features and high-order depth features to obtain network comprehensive features.

[0012] As a further improvement of this technical solution, the feature extraction module is used to obtain network traffic data, extract network basic features from the network traffic data, and use a convolutional neural network to extract high-order depth features from the network traffic data, specifically as follows:

[0013] S1.1.1. Collect raw network traffic data from the network monitoring system:

[0014] ;

[0015] Among them, is the network traffic data collection; is the network traffic data; is the network traffic data label; is the total number of network traffic data;

[0016] Extract network basic features from the network traffic data:

[0017] ;

[0018] Among them, is the network basic feature collection; is the network basic feature; is the network basic feature label; is the total number of network basic features;

[0019] S1.1.2. Use a convolutional neural network to extract high-order depth features from the raw network traffic data:

[0020] ;

[0021] Among them, is the high-order depth feature; is the convolutional neural network operation; is the convolutional neural network parameter;

[0022] The feature fusion module is used to fuse the network basic feature and the high-order depth feature to obtain the network comprehensive feature, specifically as follows:

[0023] S1.2.1. Fuse the network basic feature and the high-order depth feature with weights to obtain the network comprehensive feature:

[0024] ;

[0025] Among them, is the weight of the network basic feature; is the weight of the high-order depth feature; is the network comprehensive feature.

[0026] As a further improvement of this technical solution, the zero-day attack detection unit includes a behavior pattern detection module and a zero-day attack response module;

[0027] Among them, the behavior pattern detection module is based on the network comprehensive feature, uses a neural network combined with nonlinear dynamics to predict the network traffic state vector, and uses a recurrent neural network combined with LSTM to perform anomaly detection on the network traffic state vector;

[0028] The zero-day attack response module uses a neural network combined with a Q-value function to construct an optimized attack response strategy.

[0029] As a further improvement of this technical solution, the behavior pattern detection module is based on the network comprehensive feature, uses a neural network combined with nonlinear dynamics to predict the network traffic state vector, and uses a recurrent neural network combined with LSTM to perform anomaly detection on the network traffic state vector. The specific method steps are as follows:

[0030] S2.1.1. Based on the network comprehensive feature, use a neural network model to predict the network traffic state vector:

[0031] ;

[0032] Among them, is the predicted network traffic state vector at time t; is the neural network model; is the neural network parameter; is the network comprehensive feature at time t; is the time;

[0033] S2.1.2. Based on the predicted network traffic state vector, a network traffic state vector update equation is constructed by combining nonlinear dynamics:

[0034] Network traffic state vector update equation:

[0035] ;

[0036] Wherein, is the actual network traffic state vector at time t; is the system state transition matrix; is the system input influence matrix; is the noise influence matrix; is the external interference matrix; is the predicted network traffic state vector at time t;

[0037] S2.1.3. Based on the actual network traffic state vector at time t, a recurrent neural network combined with LSTM is used to predict the network traffic state vector at the next moment and perform anomaly detection:

[0038] ;

[0039] ;

[0040] Wherein, is the predicted network traffic state vector at time t-1; is the actual network traffic state vector at time t-1; is the LSTM operation; is the LSTM parameter; is the network traffic anomaly degree at time t; is the network traffic anomaly degree at time t+1;

[0041] S2.1.4. Set the network traffic anomaly degree threshold , and determine whether there is an anomaly in the network traffic at time t:

[0042] If , then there is an anomaly in the network traffic at time t;

[0043] If , then the network traffic at time t is normal.

[0044] As a further improvement of this technical solution, the zero-day attack response module uses a neural network combined with a Q-value function to construct an optimized attack response strategy. The specific method is as follows:

[0045] S2.2.1. Define the state space and action space;

[0046] Among them, the state space includes the network traffic anomaly degree, the health status of network devices, the attack source information, and the node load status; the action space includes network isolation, adjusting firewall rules, restricting network traffic, and starting an emergency response program;

[0047] S2.2.2. Construct a Q-value function based on the state space and the action space, and generate the Bellman equation:

[0048] Bellman equation:

[0049] ;

[0050] Among them, is the Q-value of taking the action space under the state space at time t; is the reward function at time t; is the discount factor; is the state space at time t; is the action space at time t; is the state space at time t + 1; is the action space at time t + 1;

[0051] S2.2.3. Construct a deep Q-network based on the Bellman equation:

[0052] Deep Q-network:

[0053] ;

[0054] Among them, are the neural network parameters; is the output of the neural network for the state space at time t;

[0055] S2.2.4. Design a reward function:

[0056] ;

[0057] S2.2.5. Train the deep Q-network constructed based on the Bellman equation to finally obtain an attack response strategy.

[0058] As a further improvement of this technical solution, the traffic resource balance unit includes an adaptive dynamic balance module and a feedback adjustment and optimization module;

[0059] Among them, the adaptive dynamic balance module is used to adaptively balance system resources according to the real-time changes in network traffic and device health status;

[0060] The feedback adjustment and optimization module is used to optimize the attack response strategy described in S2.2.5 according to the real-time state of system resources.

[0061] As a further improvement of this technical solution, the adaptive dynamic balancing module is used to adaptively balance system resources according to the real-time changes in network traffic and device health status. The specific method steps are as follows:

[0062] S3.1.1. Define the load balancing factor as :

[0063] ;

[0064] Wherein, is the load balancing factor; is the system load at time t; is the maximum load that the system can bear at time t;

[0065] S3.1.2. Based on the load balancing factor, the actual network traffic status vector, and the network comprehensive characteristics, construct a load-traffic balance model:

[0066] Load-traffic balance model:

[0067] ;

[0068] Wherein, is the state transition matrix; is the network feature influence matrix; is the load balancing influence matrix; is the load adjustment function;

[0069] S3.1.3. Solve the load-traffic balance model to obtain the self-balancing of network traffic and system resources.

[0070] As a further improvement of this technical solution, the feedback adjustment and optimization module is used to optimize the attack response strategy described in S2.2.5 according to the real-time state of system resources. The specific method steps are as follows:

[0071] S3.2.1. According to the actual network traffic status vector and the load balancing factor, construct a loss function:

[0072] Loss function:

[0073] ;

[0074] Wherein, is the loss function; is the target network traffic status vector; is the target load balancing factor; is the network traffic status weight; is the load balancing factor weight;

[0075] S3.2.2. Minimize and solve the loss function using the backpropagation algorithm based on the loss function, and adjust the attack response strategy:

[0076] ;

[0077] wherein, is the optimal attack response strategy after adjustment.

[0078] As a further improvement of this technical solution, the policy feedback execution unit is used to execute the attack response strategy and feedback to adjust the defense strategy, specifically as follows:

[0079] S4.1. Obtain the network traffic state vector, state space, and optimal attack response strategy from the zero-day attack detection unit and the traffic resource balance unit, and execute the optimal attack response strategy;

[0080] S4.2. After executing the optimal attack response strategy, feedback the effectiveness of the current strategy, and feedback the real-time network traffic state vector to the zero-day attack detection unit to re-analyze and adjust the attack response strategy.

[0081] Compared with the prior art, the beneficial effects of the present invention are:

[0082] 1. In this DDOS attack monitoring system based on a hybrid neural network, based on deep adaptive learning and non-linear time series modeling, it can capture and analyze complex dynamic patterns in traffic in real time. By using a recurrent neural network to model the traffic time series, the system can identify mutant attack types that are difficult to capture by traditional detection methods, as well as unknown features for zero-day attacks;

[0083] 2. In this DDOS attack monitoring system based on a hybrid neural network, by combining a convolutional neural network and a long short-term memory network, it can detect static feature attacks and accurately identify attack patterns that evolve over time, improving the system's response ability and protection effect against complex DDOS attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] Figure 1 is the overall flow block diagram of the present invention;

[0085] The meanings of the various labels in the figure are as follows:

[0086] 1. Feature extraction and fusion unit; 11. Feature extraction module; 12. Feature fusion module; 2. Zero-day attack detection unit; 21. Behavior pattern detection module; 22. Zero-day attack response module; 3. Traffic resource balance unit; 31. Adaptive dynamic balance module; 32. Feedback adjustment and optimization module; 4. Policy feedback execution unit. DETAILED DESCRIPTION OF THE INVENTION

[0087] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0088] Please refer to Figure 1 As shown, a DDOS attack monitoring system based on a hybrid neural network is provided, including: a feature extraction and fusion unit 1, where the feature extraction and fusion unit 1 is used to obtain network traffic data, extract network basic features from the network traffic data, use a convolutional neural network to extract high-order depth features from the network traffic data, and fuse the network basic features and the high-order depth features to obtain network comprehensive features;

[0089] In this embodiment, the feature extraction and fusion unit 1 includes a feature extraction module 11 and a feature fusion module 12;

[0090] Among them, the feature extraction module 11 is used to obtain network traffic data, extract network basic features from the network traffic data, and use a convolutional neural network to extract high-order depth features from the network traffic data;

[0091] The feature fusion module 12 is used to fuse the network basic features and the high-order depth features to obtain network comprehensive features.

[0092] In this embodiment, the feature extraction module 11 is used to obtain network traffic data, extract network basic features from the network traffic data, and use a convolutional neural network to extract high-order depth features from the network traffic data, specifically as follows:

[0093] S1.1.1. Collect the original network traffic data from the network monitoring system:

[0094] ;

[0095] Among them, is the network traffic data collection; is the network traffic data; is the network traffic data label; is the total number of network traffic data;

[0096] Extract network basic features from the network traffic data:

[0097] ;

[0098] Among them, is the network basic feature collection; is the network basic feature; Label for network basic features; Total number of network basic features;

[0099] In this embodiment, network traffic data includes source IP, destination IP, traffic rate, number of sessions, etc.; Label for network traffic data Labeled in the order of acquisition time;

[0100] S1.1.2. Extract high-order depth features from the original network traffic data using a convolutional neural network:

[0101] ;

[0102] Among them, Is the high-order depth feature; Is the convolutional neural network operation; Is the convolutional neural network parameter;

[0103] In this embodiment, the feature fusion module 12 is used to fuse network basic features and high-order depth features to obtain network comprehensive features, specifically as follows:

[0104] S1.2.1. Fuse network basic features and high-order depth features with weights to obtain network comprehensive features:

[0105] ;

[0106] Among them, Is the weight of network basic features; Is the weight of high-order depth features; Is the network comprehensive feature.

[0107] It also includes a zero-day attack detection unit 2. The zero-day attack detection unit 2 is based on the network comprehensive feature, uses a neural network combined with nonlinear dynamics to monitor the network traffic state vector, and uses a neural network combined with the Q-value function to construct an attack response strategy;

[0108] In this embodiment, the zero-day attack detection unit 2 includes a behavior pattern detection module 21 and a zero-day attack response module 22;

[0109] Among them, the behavior pattern detection module 21 is based on the network comprehensive feature, uses a neural network combined with nonlinear dynamics to predict the network traffic state vector, and uses a recurrent neural network combined with LSTM to perform anomaly detection on the network traffic state vector;

[0110] The zero-day attack response module 22 uses a neural network combined with the Q-value function to construct an optimized attack response strategy.

[0111] In this embodiment, the behavior pattern detection module 21 predicts the network traffic state vector based on the network comprehensive features, uses a neural network combined with nonlinear dynamics, and uses a recurrent neural network combined with LSTM to perform anomaly detection on the network traffic state vector. The specific method steps are as follows:

[0112] S2.1.1. Predict the network traffic state vector based on the network comprehensive features using a neural network model:

[0113] ;

[0114] Among them, is the predicted network traffic state vector at time t; is the neural network model; is the neural network parameter; is the network comprehensive feature at time t; is the time;

[0115] S2.1.2. Based on the predicted network traffic state vector, construct a network traffic state vector update equation in combination with nonlinear dynamics:

[0116] Network traffic state vector update equation:

[0117] ;

[0118] Among them, is the actual network traffic state vector at time t; is the system state transition matrix; is the system input influence matrix; is the noise influence matrix; is the external interference matrix; is the predicted network traffic state vector at time t;

[0119] S2.1.3. Based on the actual network traffic state vector at time t, use a recurrent neural network combined with LSTM to predict the network traffic state vector at the next moment and perform anomaly detection:

[0120] ;

[0121] ;

[0122] Among them, is the predicted network traffic state vector at time t-1; is the actual network traffic state vector at time t-1; is the LSTM operation; is the LSTM parameter; is the network traffic anomaly degree at time t; is the network traffic anomaly degree at time t+1;

[0123] S2.1.4. Set the network traffic anomaly degree threshold , and determine whether there is an anomaly in the network traffic at time t:

[0124] If , then there is an anomaly in the network traffic at time t;

[0125] If , then the network traffic at time t is normal.

[0126] In this embodiment, the zero-day attack response module 22 uses a neural network combined with a Q-value function to construct an optimized attack response strategy. The specific method is as follows:

[0127] S2.2.1. Define the state space and the action space;

[0128] Among them, the state space includes the network traffic anomaly degree, the health status of network devices, the attack source information, and the node load status; the action space includes network isolation, adjusting firewall rules, restricting network traffic, and starting an emergency response program;

[0129] S2.2.2. Based on the state space and the action space, construct a Q-value function and generate the Bellman equation:

[0130] Bellman equation:

[0131] ;

[0132] Among them, is the Q-value of taking the action space under the state space at time t; is the reward function at time t; is the discount factor; is the state space at time t; is the action space at time t; is the state space at time t+1; is the action space at time t+1;

[0133] S2.2.3. Based on the Bellman equation, construct a deep Q network:

[0134] Deep Q network:

[0135] ;

[0136] Among them, are the neural network parameters; is the output of the neural network for the state space at time t;

[0137] S2.2.4. Design the reward function:

[0138] ;

[0139] S2.2.5. Train the deep Q-network constructed based on the Bellman equation to finally obtain the attack response strategy.

[0140] In this embodiment, for S2.2.5, training the deep Q-network constructed based on the Bellman equation to finally obtain the attack response strategy is specifically as follows:

[0141] By interacting with the environment, continuously update the Q-value and the strategy, and finally converge to an optimal strategy;

[0142] According to the state space, use the deep Q-network to evaluate the Q-value of each possible action and select the action with the largest Q-value as the attack response measure;

[0143] The final attack response strategy can be used to perform real-time response to zero-day attacks in the actual environment, and the specific response actions are selected according to the current state and the Q-value.

[0144] It further includes a traffic resource balancing unit 3, and the traffic resource balancing unit 3 is used to adaptively balance the system resources according to the real-time changes of the network traffic and the device health status, and optimize the attack response strategy according to the real-time state of the system resources;

[0145] In this embodiment, the traffic resource balancing unit 3 includes an adaptive dynamic balancing module 31 and a feedback adjustment and optimization module 32;

[0146] Among them, the adaptive dynamic balancing module 31 is used to adaptively balance the system resources according to the real-time changes of the network traffic and the device health status;

[0147] The feedback adjustment and optimization module 32 is used to optimize the attack response strategy described in S2.2.5 according to the real-time state of the system resources.

[0148] In this embodiment, the adaptive dynamic balancing module 31 is used to adaptively balance the system resources according to the real-time changes of the network traffic and the device health status, and the specific method steps are as follows:

[0149] S3.1.1. Define the load balancing factor as :

[0150] ;

[0151] Among them, is the load balancing factor; is the system load at time t; is the maximum load that the system can withstand at time t;

[0152] S3.1.2. Build a load - traffic balance model based on the load - balance factor, the actual network - traffic status vector, and the network comprehensive characteristics:

[0153] Load - traffic balance model:

[0154] ;

[0155] Wherein, is the state - transition matrix; is the network - characteristic influence matrix; is the load - balance influence matrix; is the load - adjustment function;

[0156] S3.1.3. Solve the load - traffic balance model to obtain the self - balance of network traffic and system resources.

[0157] In this embodiment, the feedback - adjustment optimization module 32 is used to optimize the attack - response strategy described in S2.2.5 according to the real - time status of system resources. The specific method steps are as follows:

[0158] S3.2.1. Build a loss function according to the actual network - traffic status vector and the load - balance factor:

[0159] Loss function:

[0160] ;

[0161] Wherein, is the loss function; is the target network - traffic status vector; is the target load - balance factor; is the network - traffic status weight; is the load - balance factor weight;

[0162] S3.2.2. Based on the loss function, use the back - propagation algorithm to minimize and solve the loss function, and adjust the attack - response strategy:

[0163] ;

[0164] Wherein, is the adjusted optimal attack - response strategy.

[0165] It further includes a policy - feedback execution unit 4. The policy - feedback execution unit 4 is used to execute the attack - response strategy and feedback - adjust the defense strategy, specifically as follows:

[0166] S4.1. Obtain the network traffic state vector, state space, and optimal attack response strategy from the zero-day attack detection unit 2 and the traffic resource balancing unit 3, and execute the optimal attack response strategy;

[0167] S4.2. After executing the optimal attack response strategy, feedback the effectiveness of the current strategy, and feedback the real-time network traffic state vector to the zero-day attack detection unit 2 to re-analyze and adjust the attack response strategy.

[0168] In this embodiment, after the attack response strategy is executed, the system will evaluate the effectiveness of the current strategy through a feedback mechanism, and adjust and optimize the strategy in real time according to changes in network traffic and device status to adapt to changes in the attack pattern, and calculate the following metrics:

[0169] Attack success rate: Monitor whether the zero-day attack is successfully identified and defended;

[0170] Network performance: Evaluate whether the network performance is affected, such as latency, throughput, and packet loss rate, etc.;

[0171] Device health status: Monitor the health status of the device during the execution of the defense strategy.

[0172] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed.

Claims

1. A DDOS attack monitoring system based on a hybrid neural network, characterized in that, Including: A feature extraction and fusion unit (1), which is used to obtain network traffic data, extract network basic features from the network traffic data, use a convolutional neural network to extract high-order depth features from the network traffic data, and fuse the network basic features and the high-order depth features to obtain network comprehensive features; A zero-day attack detection unit (2), which is based on the network comprehensive features, uses a neural network combined with nonlinear dynamics to monitor the network traffic state vector, and uses a neural network combined with a Q-value function to construct an attack response strategy; A traffic resource balancing unit (3), which is used to adaptively balance the system resources according to the real-time changes of the network traffic and the device health status, and optimize the attack response strategy according to the real-time state of the system resources; A policy feedback execution unit (4), which is used to execute the attack response strategy and feedback to adjust the defense strategy; The zero-day attack detection unit (2) includes a behavior pattern detection module (21) and a zero-day attack response module (22); The specific method steps of the behavior pattern detection module (21) are as follows: S2.1.1: Based on the network comprehensive features, use a neural network model to predict the network traffic state vector; S2.1.2: Based on the predicted network traffic state vector, combine nonlinear dynamics to construct a network traffic state vector update equation; S2.1.3: Based on the actual network traffic state vector at time t, use a recurrent neural network combined with LSTM to predict the network traffic state vector at the next moment and perform anomaly detection; S2.1.

4. Set the threshold for network traffic anomaly degree , and judge whether there is any anomaly in the network traffic at the moment: If , there is an abnormality in the network traffic at time t; If , the network traffic is normal at time t; The specific method of the zero-day attack response module (22) is as follows: S2.2.1: Define the state space and the action space; S2.2.2: Based on the state space and the action space, construct a Q-value function and generate a Bellman equation; S2.2.3: Based on the Bellman equation, construct a deep Q network; S2.2.4: Design a reward function; S2.2.5: Train the deep Q network constructed based on the Bellman equation to finally obtain an attack response strategy.

2. The DDOS attack monitoring system based on a hybrid neural network according to claim 1, characterized in that: The feature extraction and fusion unit (1) includes a feature extraction module (11) and a feature fusion module (12); Among them, the feature extraction module (11) is used to obtain network traffic data, extract network basic features from the network traffic data, and use a convolutional neural network to extract high-order depth features from the network traffic data; The feature fusion module (12) is used to fuse the network basic features and the high-order depth features to obtain network comprehensive features.

3. The DDOS attack monitoring system based on a hybrid neural network according to claim 2, characterized in that: The feature extraction module (11) is used to obtain network traffic data, extract network basic features from the network traffic data, and use a convolutional neural network to extract high-order depth features from the network traffic data, specifically as follows: S1.1.1: Collect the original network traffic data from the network monitoring system: ; Among them, is a collection of network traffic data; is network traffic data; is the label of network traffic data; is the total number of network traffic data; Extract network basic features from the network traffic data: ; Among them, is the collection of network basic features; is the network basic feature; is the label of the network basic feature; is the total number of network basic features; S1.1.2: Use a convolutional neural network to extract high-order depth features from the original network traffic data: ; Among them, is the high-order depth feature; is the convolutional neural network operation; is the convolutional neural network parameter; The feature fusion module (12) is used to fuse the network basic features and the high-order depth features to obtain network comprehensive features, specifically as follows: S1.2.

1. The basic features and high - order depth features of the weighted fusion network are fused to obtain the comprehensive network features: ; Among them, is the weight of network basic features; is the weight of high-order depth features; is the comprehensive network feature.

4. The DDOS attack monitoring system based on a hybrid neural network according to claim 3, wherein: Based on the comprehensive network features, the behavior pattern detection module (21) uses a neural network combined with nonlinear dynamics to predict the network traffic state vector, and uses a recurrent neural network combined with LSTM to perform anomaly detection on the network traffic state vector; The zero - day attack response module (22) uses a neural network combined with a Q - value function to construct an optimized attack response strategy.

5. The DDOS attack monitoring system based on a hybrid neural network according to claim 4, wherein: In S2.1.1, a neural network model is used to predict the network traffic state vector: ; Among them, is the predicted network traffic state vector at time t; is the neural network model; are the neural network parameters; is the comprehensive network feature at time t; is the time; The network traffic state vector update equation in S2.1.2: ; Among them, is the actual network traffic state vector at time t; is the system state transition matrix; is the system input influence matrix; is the noise influence matrix; is the external interference matrix; is the predicted network traffic state vector at time t; Anomaly detection is performed in S2.1.3: ; ; Among them, is the predicted network traffic state vector at time t-1; is the actual network traffic state vector at time t-1; is the LSTM operation; are the LSTM parameters; is the network traffic anomaly degree at time t+1; If in S2.1.4 , there is an abnormality in the network traffic at time t; if , the network traffic at time t is normal.

6. The DDOS attack monitoring system based on a hybrid neural network according to claim 5, characterized in that: The state space in S2.2.1 includes network traffic anomaly degree, network device health status, attack source information, and node load status; the action space includes network isolation, adjusting firewall rules, restricting network traffic, and starting an emergency response program; The Bellman equation in S2.2.2: ; wherein, is the Q-value of the action space adopted at the state space at time t; is the reward function at time t; is the discount factor; is the state space at time t; is the action space at time t; is the state space at time t+1; is the action space at time t+1; The deep Q - network in S2.2.3: ; Among them, are neural network parameters; is the output of the neural network for the state space at time t; Designing the reward function in S2.2.4: ; S2.2.

5. Train the deep Q - network constructed based on the Bellman equation to finally obtain the attack response strategy.

7. The DDOS attack monitoring system based on a hybrid neural network according to claim 6, characterized in that: The traffic resource balance unit (3) includes an adaptive dynamic balance module (31) and a feedback adjustment and optimization module (32); Among them, the adaptive dynamic balance module (31) is used to adaptively balance the system resources according to the real - time changes of network traffic and device health status; The feedback adjustment and optimization module (32) is used to optimize the attack response strategy described in S2.2.5 according to the real - time state of the system resources.

8. The DDOS attack monitoring system based on a hybrid neural network according to claim 7, characterized in that: The adaptive dynamic balance module (31) is used to adaptively balance the system resources according to the real - time changes of network traffic and device health status. The specific method steps are as follows: S3.1.

1. Define the load balancing factor as :[[]] ; wherein, is the load balancing factor; is the system load at time t; is the maximum load that the system can withstand at time t; S3.1.

2. Based on the load - balancing factor, the actual network traffic state vector, and the comprehensive network features, construct a load - traffic balance model: Load - traffic balance model: ; Among them, is the state transition matrix; is the network feature influence matrix; is the load balancing influence matrix; is the load adjustment function; S3.1.

3. Solve the load - traffic balance model to obtain the self - balance of network traffic and system resources.

9. The DDOS attack monitoring system based on a hybrid neural network according to claim 8, characterized in that: The feedback adjustment and optimization module (32) is used to optimize the attack response strategy described in S2.2.5 according to the real - time state of the system resources. The specific method steps are as follows: S3.2.

1. According to the actual network traffic state vector and the load - balancing factor, construct a loss function: Loss function: ; wherein, is the loss function; is the target network traffic state vector; is the target load balancing factor; is the network traffic state weight; is the load balancing factor weight; S3.2.

2. Based on the loss function, use the backpropagation algorithm to minimize and solve the loss function to adjust the attack response strategy: ; Among them, is the optimal attack response strategy after adjustment.

10. The DDOS attack monitoring system based on a hybrid neural network according to claim 1, characterized in that: The policy feedback execution unit (4) is used to execute the attack response strategy and feedback - adjust the defense strategy, specifically as follows: S4.

1. Obtain the network traffic state vector, state space, and optimal attack response strategy from the zero - day attack detection unit (2) and the traffic resource balance unit (3), and execute the optimal attack response strategy; S4.

2. After executing the optimal attack response strategy, feedback the effectiveness of the current strategy, and feedback the real - time network traffic state vector to the zero - day attack detection unit (2) to re - analyze and adjust the attack response strategy.

Citation Information

Patent Citations

  • Nonlinear network adaptive fuzzy control system under multiple network attacks

    CN118011814A

  • DDoS attack identification method and system based on multi-modal fusion analysis

    CN119210903A

  • Network anomaly detection method and system, terminal and storage medium

    WO2022011977A1