5G Mobile Network Intrusion Detection Method, System and Storage Medium Based on Transformer Model
The Transformer model-based method for 5G mobile network intrusion detection addresses high error rates and human resource costs by automating alert classification and clustering, enhancing accuracy and reducing analyst workload.
Patent Information
- Application Number
- CN202510108598.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The existing 5G mobile network intrusion detection methods rely on manual analysis, with high false alarm rates and high labor costs, and low-quality alarms affect detection performance.
The intrusion detection method based on the Transformer model is adopted to detect alarm associations adaptively, and the automatic characterization and classification of attack activities is realized, combined with the sequence similarity aggregation method, and the manual verification workload is reduced.
Improves the robustness and accuracy of detection, reduces the workload of the security operation center, and reduces the workload of manual verification.
Smart Images

Figure CN119922551B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network intrusion detection, and particularly to a 5G mobile network intrusion detection method, system and storage medium based on a Transformer model. Background Art
[0002] With the rapid development of the Internet, network security issues have become increasingly severe. How to protect the integrity of network information and reduce the losses caused by network attacks has become an urgent problem to be solved. An intrusion detection system is a network or host system that can identify insecure events and issue alarms. Typical 5G mobile network intrusion detection methods are as Figure 1 shown. A Network Intrusion Detection System (NIDS) is deployed bypassing the edge network, bearer network, and core network user plane. This device detects potential attack behaviors existing in network traffic according to predefined rules and sends them to the security event analysis center. The security event analysis center uses tools to de-duplicate and filter the alarms and aggregates them based on IP addresses. Since the alarms generated by NIDS generally have a high error rate, it is necessary to rely on manual verification of the alarms. By correlating the alarms generated by the same attack activity, a complete attack scenario is constructed, and based on this, the type of attack activity is determined according to rules and manual analysis.
[0003] Such mobile network intrusion detection methods rely heavily on manual analysis, requiring manual verification of alarms, alarm correlation analysis, and determination of attack activities. The workload is mainly reflected in two points: 1) The intrusion detection devices deployed at the network boundary rely on predefined rules, which results in a high alarm error rate. There are a large number of false alarms and missed alarms in the generated alarm sequence, and a large amount of human cost is required to achieve alarm verification; 2) Relying on manual determination of the type of attack activity, the human cost is high, and it highly depends on manual experience. The analysis of attack activities lacks objectivity and accuracy. Considering the increasing scale of attacks and the increasing complexity of attack activities, the mobile network intrusion detection method relying on manual labor faces huge human cost expenditures.
[0004] Later, with the development of artificial intelligence, many researchers have tried to use AI intelligence to complete intrusion detection. Empowering mobile network attack detection with artificial intelligence is an effective method to reduce the manual analysis load of attack activities. Based on the type of input data, the mobile network detection method based on Artificial Intelligence (AI) can be divided into 2 categories.
[0005] Determining the alarm type according to the network traffic characteristics, such as Figure 2As shown, such methods collect network traffic, extract network features, and use deep learning models such as Convolution Neural Network (CNN) and Recurrent Neural Network (RNN) to detect the types of alarms. The advantage of such methods is that they reduce the overhead of manually maintaining alarm rules, but still rely on manual verification, correlation analysis, and determination of attack activities for alarms.
[0006] Determine the type of attack activity based on the alarm sequence, such as Figure 3 As shown, such methods collect the alarms generated by NIDS; generate alarm vectors by encoding the alarms or using natural language processing (NLP) text embedding methods; then, according to the timestamp, regard the alarms in a fixed time window as an alarm sequence associated with the same attack activity, and input it into a time series model to determine the type of attack activity. There are also attack activity determination methods based on alarm sequences that use the Hidden Markov Model (HMM) to solve the problem of attack activity determination. This method first generates templates of known attack activities and stores them in a template library; for the captured attack activities, determine the type of attack activity by comparing the similarity between this activity and the templates of known attack activities in the template library.
[0007] The AI - empowered mobile network attack detection method inputs the alarm sequence and outputs the classification result of the attack activity. Its detection accuracy depends to a large extent on the quality of the alarms. The artificial intelligence community generally believes that data quality is crucial for the accuracy of artificial intelligence methods, so - called "garbage in, garbage out". However, the poor quality of alarm sequences is a common problem, mainly reflected in two aspects:
[0008] 1) The rigid attack sequence slicing mechanism leads to noise pollution in the alarm sequence. Before inputting the alarm sequence into the AI model, it is first necessary to slice the alarms, that is, to split the alarm sequence to determine which alarms belong to the same attack activity. The general method is to slice the alarm sequence based on the time window and the timestamp of the alarms. That is, the alarms within the same window are considered to be of the same attack activity, and the alarms of the same attack activity are input into the AI model for training and prediction. However, the alarms of other attack activities may be mixed within a time window, and these irrelevant alarms are called "noise alarms", and these noise alarms will affect the detection performance of the AI model;
[0009] 2) Low-quality alarms. Ideally, each alarm should correspond to an attack behavior. However, in practice, due to factors such as rule aging and the evolution of network attack techniques, the NIDS generates a large number of false positive (FP) and false negative (FN) alarms, resulting in a decline in alarm quality. False positives introduce error information and hinder the extraction of effective features, while FN alarms lead to the loss of key attack features. These low-quality alarms significantly increase the difficulty of extracting effective attack patterns for the classifier, thereby reducing the detection performance. Summary of the Invention
[0010] Aiming at the problem of poor detection performance of traditional attack detection schemes in the scenario of low-quality alarms, the present invention provides a 5G mobile network intrusion detection method, system and storage medium based on the Transformer model. This method adaptively discovers the correlation relationships between alarms, and based on this, realizes the automatic characterization of attack activities and supports automatic classification. At the same time, aiming at the problem of the large workload of analysts manually verifying the classification results of attack activities, a clustering method based on sequence similarity is proposed, so as to reduce the workload of the staff in the Security Operation Center (SOC).
[0011] To achieve the above object, the technical solution of the present invention is as follows:
[0012] In a first aspect, the present invention provides a 5G mobile network intrusion detection method based on the Transformer model, including:
[0013] S1. Collect the network intrusion detection data stream, generate the original alarms, and preprocess the original alarms to form an alarm sequence;
[0014] S2. Perform alarm embedding on the alarm sequence and output the embedding representation of each alarm;
[0015] S3. Based on the Transformer encoder, input the embedding representation of each alarm and output the attack activity feature vector; specifically including:
[0016] S301. The Transformer encoder extracts important alarm vectors to form an important alarm vector sequence;
[0017] S302. Use the Transformer encoder to learn the correlation relationships between the important alarms and each alarm and generate an attention score vector;
[0018] S303. Based on the attention score vector, realize the vector representation of the attack activity;
[0019] S4. Classify the input attack activity feature vector and output the attack activity type.
[0020] Further, in step S1, preprocess the original alarms, including: filtering the original alarms to delete duplicate alarms; then performing importance evaluation to classify the threat levels of the alarms; and segmenting the classified alarms to form alarm sequences.
[0021] Even further, in step S302, use the Transformer encoder to learn the correlation between the important alarms and each alarm, and generate an attention score vector; specifically including:
[0022] Set the important alarm vector sequence as , and the complete alarm vector sequence as , where the important alarm vector sequence is a vector sequence composed of the important alarm vectors marked after classifying the alarms by threat level; the complete alarm vector sequence is a vector sequence composed of all the alarms embedded within a set time period;
[0023] The Transformer encoder has a self-attention mechanism, which consists of three neural networks, namely the query neural network, the key neural network, and the value neural network;
[0024] Input the important alarm vector sequence into the query neural network to obtain the query vector ;
[0025] Input the complete alarm vector sequence into the key neural network and the value neural network to obtain the key vector and the value vector ; Obtain the attention score matrix;
[0026] Normalize all the attention scores in the attention score matrix to obtain the attention score vector.
[0027] Even further, use the Softmax function to normalize all the attention scores.
[0028] Even further, the Transformer encoder has at least one self-attention mechanism, and all the self-attention mechanisms learn the correlation between the important alarms and each alarm in parallel and independently.
[0029] Even further, in step S303, based on the attention score vector, implement the attack activity vector representation, and the specific method is:
[0030]
[0031] In the above formula, where represents the dimension, i takes values from 1 to h, and h represents the number of self-attention mechanisms in the Transformer encoder.
[0032] Furthermore, filter the original alarms, specifically including: deleting duplicate alarms from the original alarms using the five-tuple information, where the five-tuple information is the source IP, destination IP, source port, destination port, and transport layer protocol.
[0033] Furthermore, perform sequence segmentation, specifically including: counting the expectation and variance of the posterior alarms of each type of alarm. If the time difference between the current alarm and the alarms of the same type that appear subsequently
[0034] Further, the 5G mobile network intrusion detection method further includes:
[0035] S5. Cluster the attack activity feature vectors to obtain multiple clusters;
[0036] S6. Manually verify the multiple clusters.
[0037] Furthermore, in step S5, clustering the attack activity feature vectors to obtain multiple clusters specifically includes: using the DBSCAN clustering method to aggregate the attack activity feature vectors to obtain multiple clusters, and each cluster represents multiple alarm sequences with similar features.
[0038] In a second aspect, the present invention provides a 5G mobile network intrusion detection system based on a Transformer model for implementing the above-mentioned 5G mobile network intrusion detection method based on a Transformer model. The 5G mobile network intrusion detection system includes:
[0039] An alarm preprocessing module for collecting network intrusion detection data streams, generating original alarms, and preprocessing the original alarms to form alarm sequences;
[0040] An attack activity classification module, where the attack activity classification module includes an embedder, an encoder, and a classifier;
[0041] The embedder is used to perform alarm embedding on the alarm sequences and output the embedded representations of each alarm;
[0042] The encoder is a Transformer encoder. Input the embedded representations of each alarm into the encoder, and the encoder outputs attack activity feature vectors;
[0043] The classifier is used to classify the input attack activity feature vectors and output the types of attack activities.
[0044] Furthermore, the 5G mobile network intrusion detection system further includes:
[0045] An attack activity aggregation module, configured to perform clustering processing on the attack activity feature vectors to obtain multiple clusters.
[0046] In a third aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned 5G mobile network intrusion detection method based on the Transformer model is implemented.
[0047] Compared with the prior art, the present invention has the following beneficial effects:
[0048] The 5G mobile network intrusion detection method provided by the present invention evaluates the importance of alarms, and uses the multi-head attention mechanism to extract the correlation between important alarms and the remaining alarms, so that the model pays more attention to the alarms related to important alarms and ignores noise alarms or false alarms, thereby improving the robustness and accuracy of the model.
[0049] The present invention intelligently learns the feature representation of attack activities according to the alarm sequence through the encoder of the Transformer model, and based on this feature representation, performs intelligent classification and aggregation. During subsequent manual verification, it is only necessary to verify the cluster centers of multiple clusters or randomly sample in the cluster for verification, which greatly reduces the workload of SOC staff. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 It is a schematic diagram of a typical 5G mobile network intrusion detection method in the prior art.
[0051] Figure 2 It is a schematic flowchart of determining the alarm type according to the network traffic characteristics in the prior art.
[0052] Figure 3 It is a schematic flowchart of determining the type of attack activity according to the alarm sequence in the prior art.
[0053] Figure 4 It is a schematic flowchart of the method of the present invention.
[0054] Figure 5 It is a schematic flowchart of the alarm embedding, encoding and classification performed by the attack activity classification module in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] The technical solution of the present invention will be clearly described below in conjunction with the accompanying drawings. Obviously, the described embodiments are not all embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0056] It should be noted that unless otherwise specifically stated, the relative arrangements of components and steps described in these embodiments and numerical expressions should not be construed as limiting the scope of the present invention.
[0057] The following description of the exemplary embodiments is merely illustrative and in no sense limits the present invention or its application or use. Technologies, methods, and devices known to those of ordinary skill in the relevant fields may not be discussed in detail here, but when applicable, these technologies, methods, and devices should be regarded as part of this specification.
[0058] Embodiment 1
[0059] This embodiment provides a 5G mobile network intrusion detection method based on the Transformer model, as Figure 4 shown, including:
[0060] S1. Collect network intrusion detection data streams, generate original alarms, and preprocess the original alarms to form alarm sequences; the preprocessing includes three processes:
[0061] Alarm deduplication: Use five-tuple information to delete duplicate alarms from a large amount of original data sets, thereby reducing the scale of data to be analyzed, where the five-tuple information refers to source IP, destination IP, source port, destination port, and transport layer protocol;
[0062] Alarm importance assessment: An intrusion detection device generates a large number of alarms, and different alarms have different contributions to the classification of attack activities. For example, there are often a large number of precursor alarms at the beginning stage of an attack, such as detection and scanning. Since an attacker often probes a large number of ports / vulnerabilities, the number of such precursor alarms is often large. However, since such alarms exist in the vast majority of attack activities and do not have particularity, their characteristics have limited contribution to the improvement of classification performance. During the analysis of attack activities, attention should be focused on events that may have a substantial impact on the victim. Such events are more representative and contribute more to the identification of attack types. Therefore, in this embodiment, according to the ATT&CK framework, attack activities are divided into different stages according to the attack target and attack method. The degree of harm caused to the system by each stage of an attack is different, so the threat levels of alarms can be classified, and the classification principle is shown in Table 1.
[0063] Table 1 Alarm importance classification principle
[0064]
[0065] Alarm sequence segmentation: Within the same time period, a victim device may be subject to multiple attack activities. The goal of alarm sequence segmentation is to split the set of alarms suffered by the victim into multiple alarm sequences, and these alarm sequences will be input into a classifier to determine the type of attack activity. Traditional segmentation schemes are relatively coarse-grained because such schemes only segment the set of alarms associated with the victim device based on a time window. For example, the alarm set is divided with a granularity of 1 hour, that is, the alarms within the first hour are one attack activity, and the alarms within the second hour are the second attack activity. However, there are two problems with this. On the one hand, it cannot handle the situation where there are multiple attack activities within one time window. On the other hand, there may be a large number of noisy alarms in the alarm sequences generated according to the time window, which affects the learning of the classifier.
[0066] In this embodiment, the expectation of the posterior alarms of each type of alarm is statistically calculated and variance , if the time difference between the current alarm and the alarms of the same type that appear later, then it is determined that the current alarm and the alarms of the same type that appear later belong to different alarm sequences.
[0067] For example, "port 555 scan" is used in all 10 attack activities. The present invention statistically calculates the time difference between the appearance of "port 555 scan" and the posterior alarms in these 10 attack activities, and obtains the expectation and variance. When the time difference between "port 555 scan" and the alarms that appear later is greater than, it is considered that this is a new attack activity, that is, "port 555 scan" and the alarms that appear later should belong to 2 different alarm sequences.
[0068] S2. Perform alarm embedding on the alarm sequences and output the embedding representation of each alarm;
[0069] The input of the embedder is the summary information (usually the "msg" field of the alarm) of each alarm in the alarm sequence, and the output is the embedding representation of this summary information, where the embedding representation can represent the semantic features of this alarm.
[0070] The specific embedding method is as follows:
[0071] First, extract the summary information of the alarms. The summary information of each alarm is actually a piece of text. For example, "GlibcGhost Attack - Buffer Overflow Attempt (EHLO)". The Doc2Vec paragraph vector method is an unsupervised algorithm that can learn fixed-length feature representations from variable-length texts (such as sentences, paragraphs, and documents). In this embodiment, Doc2Vec is used to encode the summary information of each alarm to capture the potential structural and semantic relationships in the sentences, thereby improving the accuracy of alarm representation. The Distributed Bag of Words (DBOW) model is a Doc2Vec encoding algorithm. Compared with other Doc2Vec schemes, this scheme is more efficient. Therefore, in this embodiment, a robust encoding model is pre-trained using the DBOW model, and then the pre-trained model is used to complete the alarm embedding. The text embedding process is as follows:
[0072]
[0073] In the above formula, represents the alarm sequence, represents the text vector generation function learned by Doc2Vec .
[0074] In the alarm sequence, the alarm type at the previous moment will affect the alarm type at the next moment, and the order of appearance in a sequence is also important feature information for attack activity detection. To represent the position information of the alarms in the sequence, this embodiment uses the position encoding matrix of the Transformer to extract the alarm position information. represents the feature dimension of the alarm vector. For an attack activity, the position embedding is calculated as follows:
[0075]
[0076]
[0077] where represents the position of the current alarm in the sequence, is used to determine the parity of the current sequence. For elements at odd positions, formula (3) is used for position embedding, and for elements at even positions, formula (2) is used for position embedding. In formula (2) and formula (3), the position encodings of all alarms are within interval, and formula (2) and formula (3) can well reflect the distances between different alarm vectors. Finally, by adding the text encoding and the position encoding, the input embedding vector is obtained, denoted as .
[0078]
[0079] S3. Based on the Transformer encoder, input the embedded representation of each alarm and output the attack activity feature vector;
[0080] The role of the encoder is to learn the vector encoding of the attack activity from the alarm vector sequence. The input is the embedded representation of the alarm sequence, and the output is the attack activity feature vector. Since in the live network scenario, the collected attack sequence may contain interference information. For example, in an alarm sequence, there may be a large number of false alarms and noise alarms. Therefore, the encoder needs to have the ability to learn the alarm correlation relationship, that is, to focus on the alarms highly correlated with the attack activity and ignore the interference information. Since the multi-head attention mechanism of Transformer can well extract the correlation relationship between different inputs, the encoder of the Transformer model is adopted in this embodiment to extract the features of the alarm sequence.
[0081] Transformer is a deep learning model that adopts the attention mechanism. This mechanism can assign different weights according to the different importance of each part of the input data. Its core is the multi-head attention mechanism (Multi-Head Attention). The multi-head attention mechanism is composed of multiple self-attention mechanisms. The self-attention mechanism (SelfAttention) can well assign different attention scores according to the different correlations between the elements in the input sequence, so that the model can pay more attention to and thus amplify the influence of the important elements in the input sequence and reduce the influence of the unimportant elements. And the multi-head attention mechanism, this mechanism obtains the correlation relationship between the elements at a specific position and the elements at different positions by running multiple independent self-attention mechanisms in parallel, so as to more comprehensively capture the potential correlation relationships in the sequence. As Figure 5 shown, the specific processing process is as follows:
[0082] S301. The Transformer encoder extracts important alarm vectors to form an important alarm vector sequence;
[0083] S302. Use the Transformer encoder to learn the correlation relationship between the important alarms and each alarm, and generate an attention score vector;
[0084] Define as the number of self-attention mechanisms in the Transformer encoder, the important alarm vector sequence is and the complete alarm vector sequence is , the important alert sequence here refers to the vector sequence composed of important alert vectors marked according to the ATT&CK framework, while the complete alert vector sequence refers to the sequence formed after embedding all alerts during this time period. Each self-attention mechanism consists of three neural networks, namely, the query neural network, the key neural network, and the value neural network, and their model parameters are respectively represented as , and . In this embodiment, the important alert vector sequence is input into the query neural network to obtain the query vector ; the complete alert vector sequence is input into the key neural network and the value neural network to obtain the key vector and the value vector .
[0085]
[0086]
[0087]
[0088] This embodiment is different from the implementation method of the general Transformer encoder. The input vectors of the query vector, key vector, and value vector of the general Transformer encoder are all the complete input sequences, and rely on the multi-head self-attention mechanism of the Transformer to discover the correlation relationships among the elements in the input sequence. The initial input of the query network in this embodiment is different from the initial inputs of the value network and the key network. That is, the initial input of the query network is the important alert vector sequence, and the initial inputs of the value network and the key network are the complete alert vector sequences. This processing is to simulate the process of manual attack activity analysis. That is, during the attack activity analysis process, SOC staff will first extract important alerts, and then search for ordinary alerts associated with the important alerts in the full set of alert sequences to form the alert sequence of the attack activity.
[0089] In this embodiment, the correlation relationship between each alert in the Transformer model and the important alert vector is obtained, that is, the attention score matrix in the Transformer model. The attention score matrix indicates the correlation between each alert vector in the complete alert vector sequence and the important alert vector sequence, and can also reflect the importance of this alert to the entire attack.
[0090] After that, the present invention uses the Softmax function to normalize all attention scores, and then the attention score vector can be obtained. The Softmax function can normalize the model output values to the range and use them as the probabilities of the samples, which has good interpretability.
[0091] S303. Based on the attention score vector, implement the representation of the attack activity vector;
[0092] Multiply the attention score matrix by the value vector and then divide by , and the representation of the attack activity vector for this attention head can be obtained. Note that dividing by is because this can shrink the attention scores to an appropriate range, making the calculation of the softmax function more stable and easier to converge.
[0093]
[0094] In the above formula, represents the dimension of.
[0095] Finally, in order to comprehensively consider all attention mechanisms, that is, to integrate the correlation information extracted by all attention mechanisms, the present invention splices the outputs of multiple self-attention mechanisms and then inputs them into a neural network to form the final output. The model parameters of this neural network are denoted as , specifically:
[0096]
[0097] Among them,
[0098]
[0099] After using the multi-head attention mechanism to extract vector correlations, the encoder structure also includes a feed-forward neural network (FFN) and a layer of Add&Norm layer. The feed-forward neural network enables the model to learn complex features in the input data, thereby increasing the expressive power of the model. Add in the Add&Norm mechanism refers to the Residule Block, and the core of the Residule Block is the Residule Connection. The Residule Connection allows the output of the shallow neurons to bypass one or more layers and be directly spliced into the output of the subsequent layers, which can effectively alleviate the problems of gradient disappearance and gradient explosion during the training process, accelerate the convergence of the model, and avoid overfitting. Norm in the Add&Norm mechanism refers to the Normalization module. The Transformer uses the Layer Normalization method to improve the training stability and accelerate the convergence.
[0100] S4. Classify the input attack activity feature vector and output the attack activity type.
[0101] The role of the classifier is to classify attack activities. The input of the classifier is the feature vector representation of the attack activities, and the output is the classification result, that is, which type of attack this alarm sequence belongs to, such as Mirai, etc.
[0102] S5. Cluster the feature vectors of the attack activities to obtain multiple clusters;
[0103] For the attack activity types obtained in step S4, manual verification is still required to ensure the credibility of the classification results. Considering the huge scale of alarms, manually verifying all alarm sequences one by one incurs a huge human cost. Since the alarms caused by different types of attacks exhibit similar characteristics, in this embodiment, an attack activity aggregation module is designed. The input of this module is the feature representation of the alarm sequence, and the output is the aggregated cluster, so as to reduce the load of manual verification and improve the verification efficiency. This module adopts a clustering method based on DBSCAN (Density-Based Spatial Clustering of Applications with Noise), which is a density-based clustering algorithm. This method can find clusters of any shape and intelligently detect outliers, thus effectively avoiding the influence of outliers on the clustering results. The attack activity aggregation module aggregates the feature vectors of the attack activities output by the encoder to obtain multiple clusters, and each cluster represents an alarm sequence with similar characteristics. When analysts perform manual verification of attack activities, they only need to verify the cluster center of each cluster or randomly sample in the cluster for verification, thus greatly reducing the workload of manual verification.
[0104] S6. Manually verify multiple clusters.
[0105] Embodiment 2
[0106] This embodiment provides a 5G mobile network intrusion detection system based on the Transformer model, which is used to implement the 5G mobile network intrusion detection method based on the Transformer model provided in Embodiment 1. The 5G mobile network intrusion detection system includes:
[0107] An alarm preprocessing module, which is used to collect network intrusion detection data streams, generate original alarms, and preprocess the original alarms to form alarm sequences;
[0108] An attack activity classification module, and the attack activity classification module includes an embedder, an encoder, and a classifier;
[0109] The embedder is used to perform alarm embedding on the alarm sequence and output the embedding representation of each alarm;
[0110] The role of the embedder is to map the alarm sequence into a vector space. The input of the embedder is the alarm sequence, and the output is the embedded representation of these alarm sequences, that is, the alarm vector sequence. In this embodiment, Doc2Vec is used to embed the text description of each alarm, and combined with the position information of each alarm in the sequence, the vector representation of each alarm is generated. The vector representations of each alarm in the alarm sequence are concatenated to form the embedded representation of the alarm sequence. The vector representation of the alarm sequence will be used for the encoding of alarm activities.
[0111] The encoder is a Transformer encoder. The embedded representation of each alarm is input into the encoder, and the encoder outputs the attack activity feature vector;
[0112] The classifier is used to classify the input attack activity feature vector and output the attack activity type.
[0113] The classifier consists of a fully connected neural network layer. This neural network layer can comprehensively extract the output of the encoding layer and use the Softmax activation function to achieve fine-grained classification of attack activity types.
[0114] The attack activity aggregation module is used to perform clustering processing on the attack activity feature vectors to obtain multiple clusters. This module adopts a clustering method based on DBSCAN (Density-Based Spatial Clustering of Applications with Noise), which is a density-based clustering algorithm. This method can find clusters of arbitrary shapes and intelligently discover outliers, thus effectively avoiding the influence of outliers on the clustering results.
[0115] Embodiment III
[0116] This embodiment provides a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the 5G mobile network intrusion detection method based on the Transformer model provided in Embodiment I.
[0117] The above specific embodiments are only used to illustrate the technical solutions of the present invention and are not restrictive. Although the present invention has been described in detail with reference to the examples, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A 5G mobile network intrusion detection method based on the Transformer model, characterized in that Including: S1. Collect network intrusion detection data streams, generate original alerts, preprocess the original alerts, and form an alert sequence. S2. Perform alert embedding on the alert sequence and output the embedded representation of each alert. S3. Based on the Transformer encoder, input the embedded representation of each alert and output an attack activity feature vector. Specifically, it includes: S301. The Transformer encoder extracts important alert vectors to form an important alert vector sequence. S302. Use the Transformer encoder to learn the correlation between important alerts and each alert and generate an attention score vector. S303. Based on the attention score vector, achieve the vector representation of the attack activity. S4. Classify the input attack activity feature vector and output the attack activity type.
2. The 5G mobile network intrusion detection method according to claim 1, wherein In step S1, the preprocessing of the original alerts includes: filtering the original alerts to delete duplicate alerts; then conducting importance assessment to classify the threat levels of the alerts; and performing sequence segmentation on the classified alerts to form an alert sequence.
3. The 5G mobile network intrusion detection method according to claim 2, wherein In step S302, use the Transformer encoder to learn the correlation between important alerts and each alert and generate an attention score vector. Specifically, it includes: Set the important alarm vector sequence as , and the complete alarm vector sequence is , where the important alarm vector sequence is a vector sequence composed of important alarm vectors marked after classifying alarms by threat level; the complete alarm vector sequence is a vector sequence formed after embedding all alarms within the set time period; The Transformer encoder has a self-attention mechanism, which consists of three neural networks, namely the query neural network, the key neural network, and the value neural network. Input the important alarm vector sequence into the query neural network to obtain the query vector ; Input the complete alarm vector sequence into the key neural network and the value neural network to obtain the key vector and the value vector ; obtain the attention score matrix; Normalize all the attention scores in the attention score matrix to obtain an attention score vector.
4. The 5G mobile network intrusion detection method according to claim 3, characterized in that, Use the Softmax function to normalize all the attention scores.
5. The 5G mobile network intrusion detection method according to claim 4, characterized in that, The Transformer encoder has at least one self-attention mechanism, and all the self-attention mechanisms learn the correlation between important alerts and each alert in parallel and independently.
6. The 5G mobile network intrusion detection method according to claim 5, characterized in that, In step S303, based on the attention score vector, achieve the vector representation of the attack activity. The specific method is: In the above formula, where denotes 's dimension, i takes values from 1 to h, and h represents the number of self-attention mechanisms in the Transformer encoder.
7. The 5G mobile network intrusion detection method according to claim 2, characterized in that, Filter the original alerts, specifically including: deleting duplicate alerts from the original alerts using quintuple information, where the quintuple information is the source IP, destination IP, source port, destination port, and transport layer protocol.
8. The 5G mobile network intrusion detection method according to claim 2, characterized in that, Perform sequence segmentation, specifically including: calculating the expectation of the posterior alarms for each type of alarm and variance , if the time difference between the current alarm and the subsequent alarms of the same type is, then it is determined that the current alarm and the subsequent alarms of the same type belong to different alarm sequences.
9. The 5G mobile network intrusion detection method according to claim 1, characterized in that The network intrusion detection method further includes: S5. Perform clustering processing on the attack activity feature vector to obtain multiple clusters. S6. Conduct manual verification on the multiple clusters.
10. The 5G mobile network intrusion detection method according to claim 9, characterized in that, In step S5, perform clustering processing on the attack activity feature vector to obtain multiple clusters. Specifically, it includes: using the DBSCAN clustering method to aggregate the attack activity feature vector to obtain multiple clusters, and each cluster represents multiple alert sequences with similar features.
11. A 5G mobile network intrusion detection system based on the Transformer model, which is used to implement the 5G mobile network intrusion detection method based on the Transformer model according to any one of claims 1-10, characterized in that, The 5G mobile network intrusion detection system includes: An alert preprocessing module, which is used to collect network intrusion detection data streams, generate original alerts, preprocess the original alerts, and form an alert sequence. An attack activity classification module, and the attack activity classification module includes an embedder, an encoder, and a classifier. The embedder is used to perform alert embedding on the alert sequence and output the embedded representation of each alert. The encoder is a Transformer encoder. The embedded representation of each alarm is input into the encoder, and the encoder outputs an attack activity feature vector; The classifier is used to classify the input attack activity feature vector and output the type of attack activity.
12. The 5G mobile network intrusion detection system according to claim 11, characterized in that, It further includes: An attack activity aggregation module, which is used to perform clustering processing on the attack activity feature vector to obtain multiple clusters.
13. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the 5G mobile network intrusion detection method based on the Transformer model according to any one of claims 1-10.
Citation Information
Patent Citations
CNN (Convolutional Neural Network) and Transform-based DDoS (Distributed Denial of Service) attack detection method
CN117097498A
Data processing method and related device
US20220383078A1