An intelligent network security detection system and method based on big data analysis
By dynamically adjusting weights and updating model parameters, balancing the accuracy and robustness of the network security detection model, the problem of insufficient detection capabilities of existing systems when facing confrontational samples and traditional network attacks is solved, and better detection results are achieved.
Patent Information
- Application Number
- CN202510338429.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-03-21
AI Technical Summary
When facing adversarial samples, existing intelligent network security detection systems are difficult to balance the robustness and accuracy of the model, and they lack the ability to detect traditional network attacks.
By obtaining dynamic adjustment weights, updating model parameters, balancing the accuracy and robustness of the network security detection model. Specific methods include generating adversarial data, dynamically adjusting adversarial training objective functions, combining traditional cyberattack data and adversarial perturbations for training, and optimizing the network security detection model.
The network security detection model is realized better detection capabilities when facing confronting samples and traditional network attacks, balances the robustness and accuracy of the model, and adapts to changes in the network environment.
Smart Images

Figure CN119854052B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly relates to an intelligent network security detection system and method based on big data analysis. Background Art
[0002] The so-called intelligent network security detection usually uses technologies such as artificial intelligence, machine learning, and big data analysis to automatically identify, analyze, and respond to network attacks as an active defense means. If an attacker uses adversarial samples (such as perturbed traffic) to deceive the model and bypass the model, it is necessary to enhance the robustness of the model.
[0003] The robustness of the model to adversarial samples can be enhanced through adversarial training, that is, adversarial samples are actively generated during the training process and added to the training set, forcing the model to learn the decision boundary under adversarial perturbations. However, adversarial training will reduce the accuracy of normal data detection.
[0004] In addition, in real-world deployments, there is also the problem of whether the model after adversarial training can normally cope with traditional network attacks and maintain the detection rate of traditional network attacks. Summary of the Invention
[0005] In the present invention, by obtaining dynamically adjusted weights and updating the parameters of the model according to the adjusted dynamically adjusted weights, the accuracy and robustness of the network security detection model are balanced.
[0006] The technical solution proposed by the present invention is: an intelligent network security detection system and method based on big data analysis, and the method includes:
[0007] Obtain historical network data to form a historical network data set; the historical network data includes historical network log data, traffic data, and network behavior data;
[0008] Generate adversarial data through the historical network data set, train the network security detection model with the adversarial data, and dynamically adjust the adversarial training objective function during the training, so that the network security detection model can balance the normal loss and the adversarial loss, and balance the robustness and accuracy of the network security detection model; the network security detection model includes a feature extraction module, a dynamic task head, and an adversarial training module;
[0009] Obtain real-time network traffic data stream, analyze the network traffic data stream through a machine learning model, output network status indicators, and optimize the network security detection model according to the output network status indicators to improve the detection ability of the network security detection model for adversarial attacks;
[0010] Extract traditional network attack data from the historical network dataset, combine the traditional network attack data with the adversarial perturbations generated through adversarial training, and train the network security detection model so that the network security detection model can detect traditional network attacks simultaneously.
[0011] Preferably, during the training, dynamically adjust the adversarial training objective function so that the network security detection model can balance the normal loss and the adversarial loss. Balancing the robustness and accuracy of the network security detection model includes:
[0012] Define a dynamic weighted loss function, decompose the total loss into a weighted sum of the normal sample loss and the adversarial sample loss, and dynamically adjust the dynamic weight according to the model performance, specifically including:
[0013] Let the dynamic weighted loss function be: , where, represents the cross-entropy loss of the normal samples, represents the cross-entropy loss of the adversarial samples; represents the dynamic weight, ;
[0014] By monitoring and ratio, adjust so that the network security detection model automatically balances and during the training, specifically including:
[0015] Let the adjusted dynamic weight be ;
[0016] ; where, is the smoothing coefficient, is the perturbation coefficient;
[0017] Perform model training, and the training process includes the following steps:
[0018] Step 2.1, set the initial dynamic weight , generate adversarial samples through the PGD attack method ;
[0019] Step 2.2, perform forward propagation calculation and :
[0020] and ;
[0021] Step 2.3, substitute , obtain ;
[0022] Step 2.4. Calculate the total loss and backpropagate:
[0023] , and use the calculated to update the model parameters , that is ; where represents the learning rate;
[0024] Step 2.5. Repeat Steps 2.1 to 2.4 until the model converges;
[0025] The performance of the model includes: during the training process, the normal accuracy of the network security detection model on the validation set increases or decreases, or the adversarial accuracy increases or decreases;
[0026] The normal accuracy is the accuracy of the network security detection model for detecting normal network data, and the adversarial accuracy is the accuracy of the network security detection model for detecting adversarial data.
[0027] Preferably, dynamically adjusting the adversarial training objective function during training to enable the network security detection model to balance the normal loss and the adversarial loss, and balance the robustness and accuracy of the network security detection model, further includes:
[0028] Construct a dynamic defense strategy by combining the graph neural network GNN and the causal inference algorithm, specifically including the following steps:
[0029] Construct an attack chain graph, which includes nodes, edges, node features, and edge features;
[0030] The GNN encodes the attack chain, specifically: using the graph attention network GAT to aggregate neighbor information to generate node embedding representations; capturing the propagation patterns of attack behaviors in multiple paths, including lateral movement and privilege escalation;
[0031] Based on the causal discovery algorithm, identify the causal dependencies in the attack chain, and use counterfactual analysis to locate the key nodes;
[0032] Adjust the adversarial sample generation and loss function according to the causal importance weights, and combine the graph structure of the GNN to optimize the robustness and accuracy of the network security detection model;
[0033] The nodes include users, devices, IPs, and processes; the edges are the interaction behaviors between nodes, including logins, API calls, and data flows; the node features include login time and privilege level, and the edge features include traffic size and protocol type.
[0034] Preferably, the use of the graph attention network GAT to aggregate neighbor information to generate node embedding representations includes:
[0035] Calculate the nodes using the graph attention mechanism and its neighbors 's attention coefficients: ; where, where, represents the activation function;
[0036] Node embedding update:
[0037] ;
[0038] where, represents the input feature vector of node ; represents the learnable weight matrix for feature transformation; represents the parameter vector of the attention mechanism, represents the activation function; represents the set of nodes.
[0039] Preferably, the causal discovery algorithm is used to identify the causal dependencies in the attack chain, including:
[0040] Calculate the causal effect, that is, measure the impact of the attack node on the detection result :
[0041] ;
[0042] where, represents forcing the state of node to be ; represents that node is a key causal node in the attack chain, where ; The multiple key causal nodes form the key attack node set .
[0043] Preferably, the graph structure optimization of the network security detection model in combination with GNN improves the robustness and accuracy, including:
[0044] Combining GNN embeddings, causal effects, and adversarial samples to construct a new dynamic weighted loss function: , where, represents the GNN embedding vector of node ; represents the causal regularization weight for controlling the influence intensity of the causal effect; represents the causal regularization; is used to describe the accuracy of the network security detection model, is used to describe the robustness of the network security detection model;
[0045] Generate adversarial examples, and preferentially perturb nodes with high causal effects:
[0046] , where represents the perturbation component for node ; represents the causal perturbation weight, which is used to enhance the adversarial attack on key causal nodes.
[0047] Preferably, for obtaining the real-time network traffic data stream, analyzing the network traffic data stream through a machine learning model, outputting network status metrics, and optimizing the network security detection model according to the output network status metrics to improve the detection ability of the network security detection model against adversarial attacks, the method includes the following steps:
[0048] Obtain real-time network traffic data stream information, and extract multiple network data features to form a network data stream information set , where the network data features include the size of the data packet, the protocol type, the IP of the data source and the data target;
[0049] Calculate the attack density and traffic anomaly degree according to the network data features in the network data stream information set, and then synthesize network status metrics;
[0050] Use the synthesized network status metrics and the current model performance, that is, the normal accuracy and the adversarial accuracy, as input variables and input them into the machine learning model to output dynamic weights based on the synthesized network status metrics;
[0051] Substitute the output dynamic weights into the loss function to obtain , and use to update the model parameters ; the model parameters are the trainable parameters obtained through data learning in the network security detection model, specifically including the classification head, the weights and biases of the attention mechanism;
[0052] Deploy the updated network security detection model to the detection node.
[0053] Preferably, combining traditional network attack data and adversarial perturbations generated through adversarial training to train the network security detection model, so that the network security detection model can detect traditional network attacks simultaneously, including:
[0054] Construct a mixed training data set, specifically:
[0055] Add adversarial perturbations to normal samples to generate simulated adversarial attack samples, and add adversarial perturbations to the traditional attack data set to generate adversarial samples;
[0056] Combine the simulated adversarial attack samples and the adversarial samples into a mixed training set;
[0057] Define the hybrid loss function ; where represents the traditional network attack detection loss, is the adversarial loss, represents the prediction entropy regularization term, which is used to prevent overfitting of model perturbations; represents the entropy regularization coefficient, which is used to constrain the model confidence;
[0058] Adaptively update the dynamic weight, and the adjusted dynamic weight , where represents the accuracy difference sensitivity, represents the network state influence factor, represents the detection accuracy of traditional attack samples, represents the detection accuracy of adversarial samples; represents the network state index.
[0059] Substitute the adjusted dynamic weight into the hybrid loss function to obtain , and use to update the model parameters ; then deploy the updated network security detection model to the detection node to cope with adversarial attacks and traditional attacks on the node.
[0060] An intelligent network security detection system based on big data analysis, comprising:
[0061] A big data analysis module for calculating network state indexes in real time, where the network state indexes include attack density and traffic anomaly degree;
[0062] A dynamic parameter adjustment module for adjusting the dynamic weight according to the network state indexes output by the big data analysis module;
[0063] An adaptive adversarial training module for optimizing the network security detection model using the dynamic weight.
[0064] A computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the above-mentioned intelligent network security detection system and method based on big data analysis.
[0065] Advantages of the present invention:
[0066] In the present invention, by analyzing data in real time and dynamically adjusting the dynamic weight (balancing normal and adversarial samples), the network security detection model can better adapt to changes in the network environment. At the same time, by combining the adversarial perturbations generated by adversarial training and the enhancement of traditional attack features, the detection ability of the network security detection model for traditional attacks is improved. Description of the drawings
[0067] Figure 1 This is a flowchart of an intelligent network security detection method based on big data analysis according to the present invention. Specific implementation manners
[0068] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious deformations. The basic principles defined in the following description of the present invention can be applied to other implementation manners, deformation schemes, improvement schemes, equivalent schemes, and other technical schemes that do not deviate from the spirit and scope of the present invention.
[0069] It can be understood that the term "one" should be understood as "at least one" or "one or more". That is, in one embodiment, the number of one element can be one, while in other embodiments, the number of this element can be multiple. The term "one" cannot be understood as a limitation on the quantity.
[0070] Embodiment 1:
[0071] Refer to Figure 1 , the technical solution provided by the present invention is: an intelligent network security detection system and method based on big data analysis, including the following steps:
[0072] Step 1, obtain historical network data to form a historical network data set, where the historical network data includes historical network log data, traffic data, and network behavior data;
[0073] Step 2, generate adversarial data through the historical network data set, train a network security detection model with the adversarial data, and dynamically adjust the adversarial training objective function during training so that the network security detection model can balance the normal loss and the adversarial loss, and balance the robustness and accuracy of the network security detection model; including the following steps:
[0074] Define a dynamic weighted loss function, decompose the total loss into a weighted sum of the normal sample loss and the adversarial sample loss, and dynamically adjust the dynamic weight according to the model performance, specifically including:
[0075] Let the dynamic weighted loss function be: , where, represents the cross-entropy loss of normal samples, represents the cross-entropy loss of adversarial samples; represents the dynamic weight, ;
[0076] By monitoring and ratio, adjust , so that the network security detection model automatically balances and , specifically including:
[0077] Let the adjusted dynamic weight be , ; where is the smoothing coefficient, is the perturbation coefficient;
[0078] Perform model training, and the training process includes the following steps:
[0079] Step 2.1, Set the initial dynamic weight , and generate adversarial samples through the PGD attack method ;
[0080] Step 2.2, Forward propagation calculation and :
[0081] and ;
[0082] Step 2.3, Substitute , and obtain ;
[0083] Step 2.4, Calculate the total loss and backpropagate:
[0084] , and use the calculated to update the model parameters , that is ; where represents the learning rate;
[0085] Step 2.5, Repeat steps 2.1 to 2.4 until the model converges;
[0086] The model parameters mentioned in this embodiment can represent the convolution and weights for processing time-series traffic data (such as packet sequences), the aggregation weights for modeling network entity relationships in the graph neural network GNN, the self-attention weights for analyzing protocol fields or log texts in the Transformer encoder, the adversarial attack detection head parameters, etc.
[0087] During the training process it is updated through the backpropagation algorithm, and the goal is to minimize the loss function, such as the mentioned above.
[0088] The performance of the model includes: during the training process, the normal accuracy of the network security detection model on the validation set increases or decreases, or the adversarial accuracy increases or decreases;
[0089] The normal accuracy rate is the accuracy rate of the network security detection model for detecting normal network data, and the adversarial accuracy rate is the accuracy rate of the network security detection model for detecting adversarial data.
[0090] The network security detection model includes a feature extraction module, a dynamic task head, and an adversarial training module;
[0091] Among them, the feature extraction module is used to extract network traffic features from network traffic data. For structured data (such as traffic statistical features), a multi-layer perceptron (MLP) or a Transformer encoder can be used; for sequence data (such as packet payload byte streams), 1D convolution (CNN) or bidirectional LSTM or GRU can be used.
[0092] Among them, the dynamic task head includes a traditional attack classification head, an adversarial attack detection head, and a shared attention module.
[0093] The traditional attack classification head includes a fully connected layer and a Softmax function, and outputs traditional attack types (such as DDos, SQL injection, etc.);
[0094] The adversarial attack detection head includes a fully connected layer and a Sigmoid function, and outputs the confidence of the adversarial sample (the confidence is 0 or 1, which is used to indicate whether it is adversarial perturbation traffic);
[0095] The attention module (such as Transformer) dynamically weights the importance of different features.
[0096] Among them, the adversarial training module generates adversarial samples based on PGD and injects them into the training process.
[0097] Step 3: Obtain the real-time network traffic data stream, analyze the network traffic data stream through a machine learning model, output network state metrics, and optimize the network security detection model according to the output network state metrics to improve the detection ability of the network security detection model for adversarial attacks; including the following steps:
[0098] Obtain the network traffic data stream information in real time, and extract multiple network data features to form a network data stream information set , where the network data features include the size of the data packet, the protocol type, the IP of the data source and the data target;
[0099] Calculate the attack density and traffic anomaly degree based on the network data features in the network data stream information set, and then synthesize the network state metrics;
[0100] Attack density ;
[0101] Use the Isolation Forest (IForest) algorithm to calculate the traffic anomaly degree ;
[0102] Synthesize network status indicators, ; represent the weights of attack density and traffic anomaly degree;
[0103] Take the synthesized network status indicators and the current model performance (i.e., normal accuracy and adversarial accuracy) as input variables and input them into the machine learning model to output the dynamic weights based on the synthesized network status indicators; specifically:
[0104] Input the synthesized network status indicators , the current normal accuracy and the current adversarial accuracy ;
[0105] Output the dynamic weights based on the synthesized network status indicators:
[0106] ;
[0107] That is, when the normal accuracy decreases or the network risk is low ( is 0), increase to pay attention to normal samples;
[0108] Substitute the output dynamic weights into the loss function to obtain , and use to update the model parameters ; The model parameters are the trainable parameters obtained through data learning in the network security detection model, specifically including the classification head, the weights and biases of the attention mechanism;
[0109] Deploy the updated network security detection model to the detection node.
[0110] Step 4: Extract traditional network attack data from the historical network dataset, combine the traditional network attack data with the adversarial perturbations generated through adversarial training, and train the network security detection model so that the network security detection model can detect traditional network attacks simultaneously, including the following steps:
[0111] Construct a mixed training dataset, specifically:
[0112] Add adversarial perturbations to normal samples to generate simulated adversarial attack samples, and add adversarial perturbations to the traditional attack dataset to generate adversarial samples;
[0113] Combine the simulated adversarial attack samples and the adversarial samples into a mixed training set;
[0114] Define the mixed loss function ; Among them, represents the traditional network attack detection loss, is the adversarial loss, represents the predicted entropy regularization term, which is used to prevent overfitting of model perturbations; represents the entropy regularization coefficient, which is used to constrain the model confidence;
[0115] Adaptive update of the dynamic weight, the adjusted dynamic weight , where represents the accuracy difference sensitivity, represents the network state impact factor, represents the detection accuracy of traditional attack samples, represents the detection accuracy of adversarial samples;
[0116] Substitute the adjusted dynamic weight into the hybrid loss function to obtain , and use to update the model parameters ; then deploy the updated network security detection model to the detection node to cope with adversarial attacks and traditional attacks on the node.
[0117] For example, when detecting DDoS attack traffic, the characteristics of traditional attacks include high-frequency requests, abnormal source IP distribution, etc.;
[0118] The generation process of adversarial samples is as follows: add tiny perturbations to the DDoS attack traffic to make it difficult for the model to recognize;
[0119] The following training process can be adopted:
[0120] Set the initial dynamic weight in the initial stage, focusing on traditional network attack detection;
[0121] When the accuracy of detecting adversarial attacks (such as adversarial evasion attacks) drops, reduce the dynamic weight to 0.6 to enhance robustness and ensure the detection of adversarial attacks;
[0122] During the network quiet period, that is, when there is no attack density and traffic anomaly, restore the dynamic weight to 0.7 to balance accuracy and robustness.
[0123] The present invention also provides an intelligent network security detection system based on big data analysis, including:
[0124] A big data analysis module for calculating network state metrics in real time, where the network state metrics include attack density and traffic anomaly;
[0125] A dynamic parameter adjustment module for adjusting the dynamic weight according to the network state metrics output by the big data analysis module;
[0126] An adaptive adversarial training module for optimizing the network security detection model using the dynamic weight.
[0127] Example 2:
[0128] The difference between this embodiment and Embodiment 1 lies in that by combining a graph neural network and causal reasoning, the complex dependency relationships of the attack chain are modeled, and the key causal paths are identified, thereby dynamically optimizing the detection and defense capabilities of the network security detection model against attacks. The specific steps are as follows:
[0129] Construct a dynamic defense strategy by combining the graph neural network GNN and the causal reasoning algorithm. The specific steps are as follows:
[0130] Construct an attack chain graph, which includes nodes, edges, node features, and edge features; specifically: input network logs at the input nodes, network behavior data at the nodes, and threat intelligence; output a dynamic graph , where represent node features and edge features respectively, represent the node information set and the edge information set respectively;
[0131] The GNN encodes the attack chain. Specifically: use the graph attention network GAT to aggregate neighbor information and generate node embedding representations; capture the propagation patterns of attack behaviors in multiple paths, including lateral movement and privilege escalation; this step includes the following sub-steps:
[0132] Use the graph attention mechanism to calculate the attention coefficient of node and its neighbor : ; where represents the activation function;
[0133] Node embedding update: ; where represents the input feature vector of node ; represents the learnable weight matrix for feature transformation; represents the parameter vector of the attention mechanism, represents the activation function; represents the set of nodes.
[0134] Based on the causal discovery algorithm, identify the causal dependency relationships in the attack chain, and use counterfactual analysis to locate the key nodes; this step includes the following sub-steps:
[0135] Calculate the causal effect, that is, measure the impact of the attack node on the detection result :
[0136] ;
[0137] The causal effect in this embodiment The calculation process is based on the Randomized Controlled Trial (RCT) algorithm, i.e.:
[0138] ;
[0139] ;
[0140] Among them, the intervention group: forced (in the attacked state), the control group: maintained (in the normal state);
[0141] indicates that the state of the forced setting node is ; indicates that the node is a key causal node in the attack chain, where ; Multiple key causal nodes form a key attack node set .
[0142] Combine GNN embedding, causal effect, and adversarial samples to construct a new dynamic weighted loss function , where represents the GNN embedding vector of the node ; represents the causal regularization weight, which is used to control the influence intensity of the causal effect; represents causal regularization; is used to describe the accuracy of the network security detection model, is used to describe the robustness of the network security detection model;
[0143] Generate adversarial samples and preferentially perturb nodes with high causal effects:
[0144] , where represents the perturbation component for the node ; represents the causal perturbation weight, which is used to enhance the adversarial attack on key causal nodes.
[0145] Adjust the adversarial sample generation and loss function according to the causal importance weight, and combine the graph structure of GNN to optimize the robustness and accuracy of the network security detection model;
[0146] The nodes include users, devices, IPs, and processes; the edges are the interaction behaviors between nodes, including logins, API calls, and data flows; the node features include login time and permission level, and the edge features include traffic size and protocol type.
[0147] For example, an attacker infiltrates user A through a phishing email, uses A's permissions to move laterally to server B, and steals data;
[0148] At this time, the node users are A, the server is B, the mail client, and the database; the edges are A logging in to the mail client, A accessing B, and B accessing the database;
[0149] The GAT layer of the GNN discovers the abnormal path of "user A - server B - database" and calculates (user A) and (user B), and determines that user A is the attack entry point. During adversarial training, the perturbation of the features of this node (user A) is enhanced to improve the sensitivity to abnormal behaviors;
[0150] The causal regularization weight of user A is added to the loss function , and by adjusting this weight, the robustness of high-risk nodes is specifically improved.
[0151] The present invention also provides an intelligent network security detection system based on big data analysis, including:
[0152] A big data analysis module for calculating network status metrics in real time, where the network status metrics include attack density and traffic anomaly degree;
[0153] A dynamic parameter adjustment module for adjusting dynamic weights according to the network status metrics output by the big data analysis module;
[0154] An adaptive adversarial training module for optimizing the network security detection model using dynamic weights.
[0155] In addition, in some preferred embodiments, by introducing non-linear interactions and matrix constraints into the loss function, the complex relationships between different loss terms can be effectively captured.
[0156] For example, let the loss function be ; where represents the loss correlation coefficient, . represents the dynamic weight matrix, and the diagonal elements are respectively used to control the normal and adversarial losses, and the non-diagonal elements are used to capture the cross-influence. By expanding the loss function into a two-dimensional co-optimization problem, the correlation between the normal and adversarial losses is reflected.
[0157] By setting the dynamic weight matrix, it is applicable to multi-task security detection, such as simultaneously identifying malware and abnormal logins.
[0158] The present invention also provides a computer-readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the above-mentioned intelligent network security detection method based on big data analysis.
[0159] Embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. Embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication part, and / or installed from a removable medium. When the computer program is executed by a central processing unit (CPU), the above functions defined in the methods of the present application are executed. It should be noted that the computer-readable medium in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. A computer-readable storage medium can, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wire segments, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program codes are carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or combined with an instruction execution system, apparatus, or device. The program codes contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: a wireless segment, a wire segment, an optical cable, RF, etc., or any suitable combination of the above.
[0160] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0161] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the accompanying drawings are only examples and do not limit the present invention. The objectives of the present invention have been fully and effectively achieved. The functions and structural principles of the present invention have been demonstrated and explained in the embodiments. Without departing from the said principles, any changes or modifications can be made to the embodiments of the present invention.
Claims
1. An intelligent network security detection method based on big data analysis, characterized in that: The method comprises: Acquire historical network data to form a historical network data set; the historical network data includes historical network log data, traffic data, and network behavior data; Generate adversarial data through historical network data sets, train a network security detection model through adversarial data, and dynamically adjust the adversarial training objective function during training so that the network security detection model can balance normal loss and adversarial loss, and balance the robustness and accuracy of the network security detection model; the network security detection model includes a feature extraction module, a dynamic task head and an adversarial training module; Obtain real-time network traffic data streams, analyze network traffic data streams through machine learning models, output network status indicators, optimize network security detection models based on the output network status indicators, and improve the network security detection model's ability to detect adversarial attacks; specifically, including: calculating attack density and traffic anomaly based on network data features in the network data stream information set, and then synthesizing network status indicators; The synthetic network state indicator and the current model performance, i.e., normal accuracy and adversarial accuracy, are used as input variables to input into the machine learning model, and the dynamic weight based on the synthetic network state indicator is output; Substitute the output dynamic weight into the loss function to obtain ,use Update model parameters ; The model parameters are trainable parameters obtained through data learning in the network security detection model, specifically including the classification head, the weight and bias of the attention mechanism; Deploy the updated network security detection model to the detection node; Extract traditional network attack data from historical network data sets, combine traditional network attack data with adversarial perturbations generated through adversarial training, and train network security detection models so that network security detection models can detect traditional network attacks at the same time. The adversarial training objective function is dynamically adjusted during training so that the network security detection model can balance normal loss and adversarial loss, and balance the robustness and accuracy of the network security detection model, including: Define a dynamic weighted loss function, decompose the total loss into the weighted sum of normal sample loss and adversarial sample loss, and dynamically adjust the dynamic weight according to the model performance, including: Assume the dynamic weighted loss function is: ,in, represents the cross entropy loss of normal samples, represents the cross entropy loss of adversarial samples; represents the dynamic weight, ; Through monitoring and proportion, adjust , so that network security detection models are automatically balanced during training and , specifically including: Assume the adjusted dynamic weight is , ;in, is the smoothing coefficient, is the disturbance coefficient; Perform model training. The training process includes the following steps: Step 2.1: Set initial dynamic weights , generate adversarial samples through PGD attack method ; Step 2.2: Forward propagation calculation and : and ; Step 2.3, Substitute ,get ; Step 2.4, calculate the total loss and back propagate: , using the calculated Update model parameters: ;in, represents the learning rate; Step 2.5: Repeat steps 2.1 to 2.4 until the model converges; The model performance includes: during the training process, the normal accuracy of the network security detection model on the validation set increases or decreases or the adversarial accuracy increases or decreases; The normal accuracy rate is the accuracy rate of the network security detection model for detecting normal network data, and the adversarial accuracy rate is the accuracy rate of the network security detection model for detecting adversarial data.
2. According to claim 1, an intelligent network security detection method based on big data analysis is characterized in that: The method of dynamically adjusting the adversarial training objective function during training so that the network security detection model can balance the normal loss and the adversarial loss, and balance the robustness and accuracy of the network security detection model, further includes: Combining graph neural network GNN and causal reasoning algorithm to build a dynamic defense strategy, which includes the following steps: Constructing an attack chain graph, wherein the attack chain graph includes nodes, edges, node features, and edge features; GNN encodes the attack chain, specifically: using the graph attention network GAT to aggregate neighbor information and generate node embedding representations; capturing the propagation pattern of attack behaviors in multiple paths, including lateral movement and privilege escalation; Identify causal dependencies in the attack chain based on causal discovery algorithms and locate key nodes using counterfactual analysis; The adversarial sample generation and loss function are adjusted according to the causal importance weights, and the robustness and accuracy of the network security detection model are optimized by combining the GNN graph structure; The nodes include users, devices, IPs and processes; the edges are interactive behaviors between nodes, including logins, API calls and data flows; the node features include login time and permission level, and the edge features include traffic size and protocol type.
3. According to claim 2, an intelligent network security detection method based on big data analysis is characterized in that: The use of the graph attention network GAT to aggregate neighbor information and generate node embedding representations includes: Calculate nodes using graph attention mechanism With its neighbors The attention coefficient: ;in, represents the activation function; Node embedding updates: ; in, Representation Node The input feature vector of Represents a learnable weight matrix for feature transformation; represents the attention mechanism parameter vector, represents the activation function; Represents a collection of nodes.
4. According to claim 3, an intelligent network security detection method based on big data analysis is characterized in that: The causal dependency relationship in the attack chain is identified based on the causal discovery algorithm, including: Calculate causal effects, i.e. measure the attack nodes Test results Impact: ; in, Indicates mandatory setting of nodes The status is ; Representation Node is the key causal node of the attack chain, where ; Multiple key causal nodes constitute a key attack node set .
5. The intelligent network security detection method based on big data analysis according to claim 4 is characterized in that: The graph structure combined with GNN optimizes the robustness and accuracy of the network security detection model, including: Combining GNN embedding, causal effects and adversarial samples to construct a new dynamic weighted loss function: ,in, Representation Node The GNN embedding vector, represents the causal regularization weight, which is used to control the strength of the causal effect; represents causal regularization; Used to describe the accuracy of network security detection models, Used to describe the robustness of network security detection models; Generate adversarial samples, and prioritize perturbing nodes with high causal effects: ,in, Indicates that for the node The disturbance component of represents the causal perturbation weight, which is used to enhance adversarial attacks on key causal nodes.
6. The intelligent network security detection method based on big data analysis according to claim 5 is characterized in that: The method of obtaining a real-time network traffic data stream, analyzing the network traffic data stream through a machine learning model, outputting a network status indicator, and optimizing a network security detection model according to the output network status indicator to improve the detection capability of the network security detection model against adversarial attacks includes the following steps: Obtain network traffic data flow information in real time, extract multiple network data features to form a network data flow information set ,The network data characteristics include the size of the data packet, the protocol type, the IP of the data source and the data target.
7. The intelligent network security detection method based on big data analysis according to claim 6 is characterized in that: The method combines traditional network attack data with adversarial perturbations generated by adversarial training to train a network security detection model, so that the network security detection model can simultaneously detect traditional network attacks, including: Construct a mixed training data set, specifically: Add adversarial perturbations to normal samples to generate simulated adversarial attack samples, and add adversarial perturbations to traditional attack datasets to generate adversarial samples; Combine simulated adversarial attack samples and adversarial samples into a mixed training set; Defining the mixed loss function ;in, Represents the traditional network attack detection loss, To combat losses, represents the prediction entropy regularization term, which is used to prevent overfitting of model perturbations; Represents the entropy regularization coefficient, which is used to constrain the model confidence; Adaptively update dynamic weights, adjusted dynamic weights ,in, represents the sensitivity of accuracy difference, represents the network status influencing factor, represents the detection accuracy of traditional attack samples, represents the accuracy of adversarial sample detection, Indicates network status indicators; Substitute the adjusted dynamic weights into the hybrid loss function to obtain ,use Update model parameters ; Then the updated network security detection model is deployed to the detection nodes to deal with adversarial attacks and traditional attacks on the nodes.
8. An intelligent network security detection system based on big data analysis, the system is used to execute the intelligent network security detection method based on big data analysis according to any one of claims 1 to 7, characterized in that: include: A big data analysis module, used to calculate network status indicators in real time, including attack density and traffic anomaly; A dynamic parameter adjustment module is used to adjust the dynamic weight according to the network status indicators output by the big data analysis module; Adaptive adversarial training module for optimizing network security detection models using dynamic weights.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement an intelligent network security detection method based on big data analysis as described in any one of claims 1 to 7.
Citation Information
Patent Citations
CNN-LSTM network anomaly detection method based on adversarial training
CN116980208A
Pedestrian target-oriented multi-view adaptive weight balance adversarial attack method
CN118397431A