A BGP Anomaly Detection and Tracing Method Based on BGP Graph

Through the abnormal detection and traceability method based on BGP graph, the problem of insufficient real-time, accuracy and intelligence of BGP abnormal detection in the prior art is solved, and more efficient abnormal detection and traceability is achieved, and the monitoring and protection capabilities of inter-domain routing security are enhanced.

CN119854106BActive Publication Date: 2025-06-24NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510322393.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-24
Estimated Expiration
2045-03-19

AI Technical Summary

Technical Problem

The existing BGP anomaly detection methods have room for improvement in real-time, accuracy and intelligence, mainly due to the bias and incompleteness of data collection, the dynamic changes in BGP routing behavior, and the distributed and huge characteristics of the BGP network.

Method used

The BGP graph-based anomaly detection and traceability method is adopted to realize real-time and accurate abnormal detection and traceability through data acquisition and initial topology construction, incremental update mechanism, topological feature extraction and construction of BGP embedded graphs, graph convolution anomaly detection and auto-encoder traceability models.

Benefits of technology

It improves the real-time and accuracy of BGP anomaly detection, can capture the abnormal behavior of AS more accurately, and position the abnormal AS collection through feature space compression and expansion, enhancing the monitoring and protection capabilities of inter-domain routing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119854106B_ABST
    Figure CN119854106B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for BGP anomaly detection and traceability based on BGP graphs, including data collection and initial topology construction. BGP routing data is collected based on global collection points, including BGP routing table data and BGP routing update data; an initial global BGP network topology is constructed according to the collected routing data; an incremental update mechanism is proposed, and according to different situations of BGP messages, including explicit announcements, explicit withdrawals, and implicit withdrawals, three graph update mechanisms are respectively adopted to dynamically update the BGP network topology; topology feature extraction and construction of a BGP embedding graph; finally, the BGP embedding graph is input into a graph convolutional neural network model, and through the method of multi-order neighborhood aggregation, combined with node attributes, edge attributes, and adjacency relationships, anomaly detection is carried out; if the detection result is abnormal, anomaly traceability is performed, and the abnormal AS set is located through feature space compression and expansion. The method proposed by the present invention can more accurately detect BGP anomalies and perform traceability analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of inter-domain anomaly detection in inter-domain routing security, and specifically provides a BGP anomaly detection and traceability method based on a BGP graph. Background Art

[0002] The Border Gateway Protocol (BGP) is the fundamental guarantee for the interconnection of global autonomous systems. However, due to the lack of a security authentication mechanism in its initial design, BGP anomalies occur frequently. Among them, large-scale BGP anomalies are characterized by fast propagation speed and wide influence range, posing a huge threat to global inter-domain routing security. BGP anomaly detection is to detect anomalies through actively and passively obtained routing data, and further locate suspicious routing information. The routing information includes prefixes and autonomous systems (ASs), etc., enabling operation and maintenance personnel to quickly trace and mitigate anomalies. However, in the face of an AS network topology with a huge scale and a large number of connections, accurate anomaly detection and location cannot be achieved only by existing methods. Therefore, it is necessary to carry out research on BGP anomaly detection and traceability mechanisms based on the topology constructed by connections between ASs, monitor the global BGP operation status in real time, and conduct traceability analysis to ensure national inter-domain network security.

[0003] Such methods usually use a large amount of BGP historical routing data, analyze historical BGP routing behavior rules and patterns as prior knowledge, detect BGP routing messages sent by ASs, effectively identify BGP anomalies and conduct traceability. However, there is still much room for improvement in the real-time performance, accuracy, and intelligence of existing anomaly detection methods. Fundamentally, there are mainly the following three problems:

[0004] 1) The collected data is biased and incomplete;

[0005] 2) The dynamic changes in BGP routing behavior;

[0006] 3) The BGP network is a distributed system and has a huge scale. Summary of the Invention

[0007] Aiming at the deficiencies of the prior art, the present invention discloses a BGP anomaly detection and traceability method based on a BGP graph to solve the problems raised in the above background art.

[0008] To achieve the above object, the present invention provides the following technical solution: A BGP anomaly detection and traceability method based on a BGP graph, characterized by including the following steps:

[0009] Step 1, data collection and initial topology construction, including:

[0010] S11. Collect BGP routing data based on global collection points, including BGP routing table (RIB table) data and BGP routing update data;

[0011] S12. Construct an initial global BGP network topology based on the collected routing data;

[0012] Step 2. Propose an incremental update mechanism. According to different situations of BGP messages, including explicit announcement, explicit revocation, and implicit revocation, adopt three graph update mechanisms to dynamically update the BGP network topology to ensure the real-time and accuracy of the topology;

[0013] Step 3. Topology feature extraction and construction of the BGP embedding graph, including:

[0014] S31. Calculate the node information of the topology, including the out-degree, in-degree, and Pagerank value of the node;

[0015] S32. Calculate the edge information of the topology, including the number of prefixes flowing through the AS;

[0016] S33. Based on the node information and edge information, extract graph-related features, including edge features, local topology features, global topology features, and path-related features;

[0017] S34. Based on the extracted features, construct the BGP embedding graph;

[0018] Step 4. Anomaly detection and tracing, including:

[0019] Input the BGP embedding graph into the Graph Convolutional Network (GCN) model, and through the multi-order neighborhood aggregation method, combine node attributes, edge attributes, and adjacency relationships to perform anomaly detection;

[0020] If the detection result is abnormal, then perform anomaly tracing, and locate the abnormal AS set through feature space compression and expansion.

[0021] Preferably, in step 2, the specific steps include:

[0022] S21. First, construct an initial global routing topology according to the BGP routing table R t-1 ; ;

[0023] S22. Then, update the global routing topology according to the routing update message at this moment to obtain the routing topology at this moment ;

[0024] Among them, when the topology is updated, it is divided into three categories, including: explicit announcement, explicit revocation, and implicit revocation; for each given routing update message at a given moment t of the i th :

[0025] 1) Explicit revocation means that the operation attribute in the routing update message is revocation W operation, and at the same time, the prefix R exists in the routing table p . It is formulated as:

[0026]

[0027] Among them, represents the route corresponding to the prefix t in the routing table R t at the moment p . R t represents the routing table at time t; in this case, the AS connection in G ( t-1 ) is deleted, and ( G - t - 1 ) represents the BGP network topology graph at time t - 1;

[0028] 2) Explicit announcement means that there is a routing update message whose operation attribute is announcement A . Among them, A represents the adjacency matrix of the BGP graph; at the same time, t the routing table of the prefix p at the moment is empty. It is formulated as:

[0029]

[0030] Among them, in the case of explicit announcement, the AS connection in G ( t-1 ) is added;

[0031] 3) Implicit revocation means that the routing update message is an announcement message, and at the same time is not empty. In addition, the routing attribute in the routing update message does not belong to t the routing set of the prefix p at the moment . It is formulated as:

[0032]

[0033] Among them, in the case of implicit revocation, for in the AS connection in is added, and at the same time, the AS connection in the routing table in

[0034] is deleted.

[0035] Preferably, in step 4, anomaly detection and traceability specifically include the following steps:

[0036]

[0037]

[0038] Among them, F (l+1) represents the output of the l +1-th layer of the graph convolutional neural network, which is a matrix with a dimension of R N×H where N represents the number of nodes in the graph, H represents the dimension of the features of this layer, that is, the number of features possessed by each node, D represents the degree matrix, A represents the adjacency matrix of the BGP graph, F (l) represents the output of the l -th layer of the graph convolutional neural network, σ represents the activation function, represents the l -th layer of learnable parameter matrix, represents the connection matrix with weighted self-loops;

[0039] Among them, is defined as:

[0040] When the edge e ij = 1, that is, when there is a connection between node i and node j , Here w ij represents the weight of the edge e ij ;

[0041] When the edge e ij = 0, that is, when there is no connection between node i and node j , ;

[0042] S42. Perform a pooling operation on the output result obtained by graph convolution and aggregate the multi-order neighborhoods, which is formulated as follows:

[0043]

[0044]

[0045]

[0046] where and represent the average pooling and max pooling operations respectively, F ih in i represents the F th i row of the node attribute matrix

[0047] Finally, what is obtained is which represents the superposition of the two pooling operations of the g layer with respect to the BGP graph l ;

[0048] S43. The graph convolutional neural network has hierarchical local learning ability. To fuse multi-neighborhood knowledge, local and global information are fused, and the knowledge of multi-level graph convolution learning is fused to finally obtain the output representation:

[0049] ;

[0050] S44. Input F g into a multi-layer perceptron for softmax operation to obtain the predictable probability p :

[0051]

[0052] During the iterative backpropagation process, the cross-entropy loss is used to optimize the model parameters.

[0053] Preferably, in step 4, if the detection result is abnormal, the auto-encoder model framework is used for anomaly tracing and positioning. The encoder is used to compress the data into the feature space, the decoder is used for the expansion of the feature space, and the mean squared error loss l b is used to optimize the parameters of the tracing model, which is formulated as follows:

[0054]

[0055]

[0056] Among them, represents the reconstructed feature output of the decoder in the autoencoder for the n th sample, represents the original feature representing the n th sample, V represents the set of nodes in the BGP graph;

[0057] And in the process of tracing and positioning, the normalized deviation is used to obtain:

[0058]

[0059] Among them, is the normalized deviation of the n th sample, and respectively represent the median and the interquartile range of the estimated value b i ;

[0060] It is calculated through the abnormal AS set V a :

[0061]

[0062] Among them, { v n} is the element representation form of the set V a where v n represents the n th abnormal AS in the set; k is a preset hyperparameter used to determine the number of abnormal ASs to be selected.

[0063] Compared with the prior art, the beneficial effects of the present invention:

[0064] 1. In the present invention, the BGP topology is abstracted into a graph model, and an incremental update mechanism for the BGP graph is proposed according to the BGP routing information. This mechanism can overcome the disadvantage that the BGP graph cannot be updated in time, so as to update the BGP graph accurately and in real time. This kind of BGP graph incremental update mechanism, based on different situations of BGP messages, namely explicit announcement, explicit revocation and implicit revocation, respectively adopts three graph update mechanisms, namely adding and deleting AS connection relationships, so as to accurately update the BGP graph model, construct a real-time BGP dynamic graph based on the graph update mechanism, and select the optimal node attributes and edge attributes to form a BGP graph embedding model.

[0065] 2. The present invention proposes a BGP anomaly detection method based on graph convolution. Node attributes and edge attributes are embedded into the graph model, where a multi-order neighborhood aggregation method is used to combine the changes of multiple neighbors to perceive the occurrence of BGP anomaly behaviors as much as possible. In the graph convolution model, not only node attributes and the adjacency matrix are input, but also edge attributes are input, so that the model can more accurately capture the anomaly behaviors of ASs.

[0066] 3. In the present invention, an auto-encoder architecture is adopted to construct an anomaly tracing model. The detection model is used as the pre-training model of the encoder to reduce the training time. In addition, a node-level deviation loss is designed to be combined with the structure loss, so as to trace the abnormal AS when an anomaly occurs. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention.

[0068] In the drawings:

[0069] Figure 1 is a flowchart of the BGP anomaly detection and tracing method based on the BGP graph of the present invention;

[0070] Figure 2 is a flowchart of calculating the BGP anomaly detection of the present invention;

[0071] Figure 3 is a flowchart of anomaly tracing based on the auto-encoder of the present invention;

[0072] Figure 4 is a schematic diagram of the specific performance indicators of the method of the present invention and the comparison method under the real dataset and the balanced dataset, where the upper figure represents the real dataset and the lower figure represents the balanced dataset. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0073] The following describes the preferred embodiments of the present invention with reference to the drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0074] Embodiment: As Figure 1 shown, a BGP anomaly detection and tracing method based on a BGP graph, characterized by comprising the following steps:

[0075] Step 1. Data collection and initial topology construction, including:

[0076] S11. Collect BGP routing data based on global collection points, including BGP routing table (RIB table) data and BGP routing update data;

[0077] S12. Construct an initial global BGP network topology based on the collected routing data.

[0078] Step 2. Propose an incremental update mechanism. According to different situations of BGP messages, including explicit announcement, explicit revocation, and implicit revocation, adopt three graph update mechanisms respectively to dynamically update the BGP network topology and ensure the real-time and accuracy of the topology.

[0079] Step 3. Topology feature extraction and construction of the BGP embedding graph, including:

[0080] S31. Calculate the node information of the topology, including the out-degree, in-degree, and Pagerank value of the node;

[0081] S32. Calculate the edge information of the topology, including the number of prefixes flowing through the AS;

[0082] S33. Based on the node information and edge information, extract graph-related features, including edge features, local topology features, global topology features, and path-related features;

[0083] S34. Based on the extracted features, construct the BGP embedding graph.

[0084] Step 4. Anomaly detection and tracing, including:

[0085] Input the BGP embedding graph into a Graph Convolutional Network (GCN) model, and through the method of multi-order neighborhood aggregation, combine node attributes, edge attributes, and adjacency relationships to perform anomaly detection;

[0086] If the detection result is abnormal, perform anomaly tracing, and locate the abnormal AS set through feature space compression and expansion.

[0087] Furthermore, in Step 2, the specific steps include:

[0088] S21. First, construct an initial global routing topology according to the BGP routing table R t-1 ; ;

[0089] S22. Then, update the global routing topology according to the routing update message at this moment to obtain the routing topology at this moment ;

[0090] Among them, when updating the topology, it is divided into three categories of situations, including: explicit announcement, explicit revocation, and implicit revocation; for each given routing update message at a given moment t of the i th :

[0091] 1) Explicit revocation is an operation attribute in the routing update message as revocation W operation, and at the same time in the routing table R the prefix p exists, which is formulated as:

[0092]

[0093] Among them, represents the routing table at t time R t the prefix p corresponding route, R t represents the routing table at time t; in this case, for G ( t-1 ) in the AS connection is deleted, G ( t - 1 ) represents the BGP network topology at time t t - 1.

[0094] 2) Explicit announcement means that there is a routing update message whose operation attribute is announcement A , among which, A represents the adjacency matrix of the BGP graph; at the same time t the prefix at time p the routing table is empty, which is formulated as:

[0095]

[0096] Among them, in the case of explicit announcement, for G ( t-1 ) in the AS connection in is added.

[0097] 3) Implicit revocation means that the routing update message is an announcement message, and at the same time is not empty, and in addition, the routing attribute in the routing update message does not belong to t the routing set of the prefix at time p in , which is formulated as:

[0098]

[0099] Among them, in the case of implicit revocation, for in the AS connection in is added, and at the same time for the routing table Delete the AS connection in

[0100] Furthermore, as Figure 2 shown, in step 4, anomaly detection and tracing specifically include the following steps:

[0101] S41. Input the node attributes, edge attributes, and topological adjacency relationships into the graph convolutional neural network, which is formulated as:

[0102]

[0103]

[0104] Among them, F (l+1) represents the output of the l +1-th layer of the graph convolutional neural network, which is a matrix with a dimension of R N×H . Among them, N represents the number of nodes in the graph, H represents the dimension of the features of this layer, that is, the number of features each node has, D represents the degree matrix, A represents the adjacency matrix of the BGP graph, F (l) represents the output of the l -th layer of the graph convolutional neural network, σ represents the activation function, represents the l -th layer of learnable parameter matrix, represents the connection matrix with weighted self-loops;

[0105] Among them, is defined as:

[0106] When the edge e ij =1, that is, there is a connection between node i and node j , . Here, w ij represents the weight of the edge e ij ;

[0107] When the edge e ij =0, that is, there is no connection between node i and node j , .

[0108] S42. Perform a pooling operation on the output result obtained by graph convolution and aggregate multi-order neighborhoods, which is formulated as:

[0109]

[0110]

[0111]

[0112] Among them, and represent average pooling and max pooling operations respectively, F ih in i represents the F th i row of the node attribute matrix

[0113] Finally obtained is which represents the superposition of two pooling operations for the g th l layer of the BGP graph;

[0114] S43. The graph convolutional neural network has hierarchical local learning ability. To fuse multi-neighborhood knowledge, local and global information is fused, and multi-level graph convolutional learning knowledge is fused. Finally, the output representation is obtained:

[0115] ;

[0116] S44. Input F g into a multi-layer perceptron for softmax operation to obtain the predictable probability p :

[0117]

[0118] During the iterative backpropagation process, the cross-entropy loss is used to optimize the model parameters.

[0119] Furthermore, as Figure 3 shown, in step 4, if the detection result is abnormal, then the auto-encoder model framework is used for anomaly tracing and localization. The encoder is used to compress the data into the feature space, and the decoder is used for the expansion of the feature space. Finally, it is expected that the input and output are as close as possible, and the mean squared error loss l b is used to optimize the tracing model parameters, which is formulated as follows:

[0120]

[0121]

[0122] Among them, denotes the reconstructed feature output of the decoder in the auto - encoder for the n th sample, denotes the original feature representing the n th sample, V denotes the set of nodes in the BGP graph;

[0123] And in the process of traceability positioning, the normalized deviation is used to obtain:

[0124]

[0125] where, is the normalized deviation of the n th sample, and respectively represent the median and the inter - quartile range of the estimated value b i ;

[0126] And the formula for the normalized deviation b n is as follows:

[0127]

[0128] where, x n represents the feature value of the n th sample; median( x ) represents the median of all sample feature values; IQR( x ) represents the inter - quartile range (Interquartile Range) of all sample feature values, that is, the difference between the upper quartile (Q3) and the lower quartile (Q1), and the calculation formula is:

[0129]

[0130] And it is calculated through the abnormal AS set V a to obtain:

[0131]

[0132] where, { v n} is the element representation form of the set V a , where v n represents the n th abnormal AS in the set; k is a preset hyper - parameter used to determine the number of abnormal ASs to be selected.

[0133] The simulation results are as follows:

[0134] To detect the effect of the proposed anomaly detection and tracing method based on the BGP graph in the global real data, the present invention uses the RIPENCC and RouteView global public collection points to collect BGP routing data. In the constructed dataset, based on the grid search results, 1 minute is used as the time window to construct data samples. Then, the data is labeled according to the occurrence time of the actually occurred anomaly events and the reported abnormal routing information. The simulation experiment platform is the Python 3.10 software under the Linux system (the analysis results of the present invention are not affected by the operating system and the Python software version). In addition, the geographical location and ranking information of AS are obtained from the official authoritative data of Caida.

[0135] From Figure 4 it can be seen the specific performance metrics of the proposed method and the comparison methods in the real dataset and the balanced dataset. In Figure 4 the above figure, compared with other methods, the proposed method has higher accuracy and F1 score, as well as lower false positive rate and false negative rate in the real dataset; in Figure 4 the following figure, compared with other methods, the proposed method also has higher accuracy and F1 score, as well as lower false positive rate and false negative rate in the balanced dataset. It shows that the proposed method has higher robustness in anomaly detection compared with other methods.

[0136] From the above experimental results, it can be seen that the anomaly detection and tracing method based on the BGP graph proposed by the present invention can more accurately detect BGP anomalies and trace analysis.

[0137] Finally, it should be noted that the above are only the preferred examples of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A BGP anomaly detection and tracing method based on a BGP graph, characterized in that: The following steps are involved: Step 1: Data collection and initial topology construction, including: S11. Collect BGP routing data based on global collection points, including BGP routing table data and BGP routing update data; S12, constructing an initial global BGP network topology based on the collected routing data; Step 2: An incremental update mechanism is proposed. According to different situations of BGP messages, including explicit announcement, explicit withdrawal and implicit withdrawal, three graph update mechanisms are adopted to dynamically update the BGP network topology. Step 3: Extract topological features and construct BGP embedding graph, including: S31, calculate the node information of the topology, including the node's out-degree, in-degree and Pagerank value; S32, calculate the edge information of the topology, including the number of prefixes flowing through the AS; S33, extracting graph-related features based on node information and edge information, including edge features, local topology features, global topology features, and path-related features; S34, constructing a BGP embedding graph based on the extracted features; Step 4: Anomaly detection and tracing, including: The BGP embedding graph is input into the graph convolutional neural network model, and anomaly detection is performed by combining node attributes, edge attributes and adjacency relationships through multi-order neighborhood aggregation. If the detection result is abnormal, the abnormality is traced and the abnormal AS set is located through feature space compression and expansion.

2. The BGP anomaly detection and tracing method based on BGP graph according to claim 1, characterized in that: In step 2, the specific steps include: S21. First, construct an initial global routing topology G(0) based on the BGP routing table; S22, then, according to the routing update message U at time t t Update the global routing topology to obtain the routing topology G(t) at time t.

3. The BGP anomaly detection and tracing method based on BGP graph according to claim 2, characterized in that: When the topology is updated, there are three cases, including explicit announcement, explicit withdrawal and implicit withdrawal; for each given i-th route update message at a given time t 4. The BGP anomaly detection and tracing method based on BGP graph according to claim 3 is characterized in that: The explicit revocation operation attribute in the routing update message is to revoke the W operation, and the prefix p exists in the routing table R, which is formally expressed as: in, Represents the routing table R at time t t The route corresponding to prefix p in R t represents the routing table at time t; in this case, for G(t-1) The AS connection is deleted, and G(t-1) represents the BGP network topology at time t-1.

5. The BGP anomaly detection and tracing method based on BGP graph according to claim 3 is characterized in that: Explicit announcement of the existence of routing update messages The operational attribute of is to declare A, where A represents the adjacency matrix of the BGP graph; at the same time, the routing table of prefix p at time t Is empty, the formula is expressed as: Among them, in the case of display declaration, Add the AS connection in.

6. The BGP anomaly detection and tracing method based on BGP graph according to claim 3, characterized in that: Implicit revocation is a routing update message for an announcement message, and Not empty, and the route attribute in the route update message does not belong to the route set of prefix p at time t In the formula, it is expressed as: Among them, in the case of implicit revocation, Add the AS connection in the routing table and Delete the AS connection in the system.

7. The BGP anomaly detection and tracing method based on BGP graph according to claim 1, characterized in that: In step 4, anomaly detection and tracing includes the following steps: S41. Input the node attributes, edge attributes and topological adjacency relationships into the graph convolutional neural network, which can be expressed as: Among them, F (l+1) Represents the output of the l+1th layer of the graph convolutional neural network, which is a dimension R N×H where N represents the number of nodes in the graph, H represents the dimension of the layer feature, that is, the number of features each node has, D represents the degree matrix, A represents the adjacency matrix of the BGP graph, and F represents the (l) represents the output of the lth layer of the graph convolutional neural network, σ represents the activation function, and θ (l) represents the learnable parameter matrix of layer l, Represents a connection matrix with weighted self-loops; in, is defined as: When the side ij =1, that is, when there is a connection between node i and node j, Here ij Represents edge e ij The weight of When the side ij = 0, that is, there is no connection between node i and node j, S42. Pool the output result obtained by graph convolution and aggregate multi-order neighborhoods, which can be expressed as follows: Among them, F mean and F max Represents average pooling and maximum pooling operations respectively, and F ih The i in represents the i-th row of the node attribute matrix F; The final result is It represents the superposition of two pooling operations on layer l of the BGP graph g; S43, integrate the multi-level graph convolution learning knowledge and finally get the output representation: S44, F g Input into the multi-layer perceptron for softmax operation to obtain a predictable probability p: p=softmax(MLP(F g )) During the iterative back-propagation process, the model parameters are optimized using cross-entropy loss.

8. The BGP anomaly detection and tracing method based on BGP graph according to claim 1, characterized in that: In step 4, if the detection result is abnormal, the auto-encoder model framework is used to trace and locate the abnormality, the encoder is used to compress the data in the feature space, the decoder is used to expand the feature space, and the mean square error loss l is used. b Optimize the traceability model parameters and formulate them as follows: in, It represents the reconstructed feature output of the decoder in the autoencoder for the nth sample, f n t represents the original features of the nth sample, V represents the set of nodes in the BGP graph; And in the process of tracing and locating, the normalized deviation is used get: in, is the normalized deviation of the nth sample, and Represent the estimated value b n The median and interquartile range; By exception AS set V a The calculation results are: Among them, {v n } is the set V a Element representation of , where v n Represents the nth abnormal AS in the set; k is a pre-set hyperparameter used to determine the number of abnormal ASs to be selected.

Citation Information

Patent Citations

  • Method, equipment and system for realizing BGP (Border Gateway Protocol) anomaly detection

    CN113271286A

  • Transform model-based inter-domain routing anomaly detection method and system

    CN119254533A