High-performance detection analysis method for network security
By encoding network security data into a two-dimensional grayscale graph and combining convolutional neural networks and adversarial generation networks, the problem of data representation in the prior art is not suitable for deep learning processing and category imbalance, and the accuracy and robustness of network security detection are improved.
Patent Information
- Application Number
- CN202510105181.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing cybersecurity detection methods perform poorly when processing high-dimensional nonlinear data, difficult to identify new or variant attacks, and rule-based methods lack flexibility and adaptability to unknown attack patterns.
A high-performance detection and analysis method for network security is proposed. By encoding network security data into a two-dimensional grayscale graph, using convolutional neural networks for classification, and using adversarial generation networks to learn and generate attack data with fewer categories, it is added to the original training set, and combined with ET-RFE and ET-Boruta feature selection methods, the feature subset is optimized.
The detection accuracy of a few categories of attack traffic is improved, the robustness and generalization capabilities of the model are enhanced, and the problem of data representation is not suitable for deep learning processing, category imbalance, and low feature selection efficiency.
Smart Images

Figure CN119945782A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a high-performance detection and analysis method for network security. Background Art
[0002] Current network security detection methods mainly rely on traditional machine learning algorithms and rule-based methods; traditional machine learning algorithms such as support vector machines (SVM) and random forests (RF) usually require manual feature extraction and perform poorly when processing high-dimensional nonlinear data; in addition, these methods have limited ability to identify abnormal behaviors in network traffic, especially when facing new or variant attacks, and are prone to missed detections; on the other hand, although rule-based methods can quickly respond to known threats, they lack flexibility and adaptability to unknown attack patterns; with the increasing complexity of the network environment and the continuous evolution of attack methods, existing intrusion detection systems (IDS) face many challenges and are difficult to meet the needs of modern network security protection.
[0003] In recent years, deep learning technology has been introduced into the field of network security, especially convolutional neural network (CNN) has attracted widespread attention due to its powerful automatic feature extraction ability and good processing effect on image data; however, there are several problems when it is directly applied to network security traffic detection: first, the original network traffic is not in image form, so it is necessary to find an effective way to convert the traffic data into a form suitable for CNN processing; second, network attack data often has the problem of class imbalance, that is, normal traffic is far more than attack traffic, which will cause the model training to be biased towards the majority class, thereby affecting the detection accuracy of the minority class; third, how to select the most representative feature subset from massive features to improve model efficiency is also a problem to be solved urgently, so we propose a high-performance detection and analysis method for network security. Summary of the invention
[0004] 1. Technical issues to be resolved
[0005] In view of the shortcomings of the prior art, the present invention provides a high-performance detection and analysis method for network security, which has the advantages of high efficiency, accuracy and strong robustness, and solves the problems in traditional methods that data representation is not suitable for deep learning processing, small sample attack missed detection due to category imbalance, and low feature selection efficiency.
[0006] (II) Technical solution
[0007] In order to achieve the above-mentioned purpose of high efficiency, accuracy and strong robustness, the present invention provides the following technical solution: a high-performance detection and analysis method for network security, comprising the following steps:
[0008] S1, encoding network security data into a two-dimensional grayscale image;
[0009] S2. Classifying the two-dimensional grayscale image using a convolutional neural network (CNN);
[0010] S3. Use the Generative Adversarial Network (GAN) to learn attack data with fewer categories and generate new data that conforms to the distribution of attack data, add it to the original training set and then train the deep learning model; the Generative Adversarial Network consists of a generator (G) and a discriminator (D), and the generator and the discriminator are trained in a game-like manner to optimize the maximum and minimum objective function. The specific formula is:
[0011]
[0012] Preferably, the step S1 further includes a feature processing step, which specifically includes:
[0013] Step 1: The original network traffic data is processed by using the extreme tree recursive elimination (ET-RFE) method. The importance index of each network traffic feature is calculated using the extreme tree algorithm, and the features are sorted according to the mean reduced impurity (MDI) method. The features with low importance scores are recursively removed to screen out the feature subset with high correlation with the objective function.
[0014] Step 2: Use the full-correlation feature selection method based on ET-Boruta to create a hybrid shadow feature set, compare the importance between the original features and the shadow features, select the features that have a global significant contribution to network traffic anomalies, and further optimize the feature set.
[0015] Preferably, when encoding the network security data into a two-dimensional grayscale image, it should be performed in the following manner:
[0016] Step 1: For numerical features, use the min-max normalization method to map them to the [0,1] interval;
[0017] Step 2: Use the unique hot encoding technology to convert categorical features;
[0018] Step 3: According to the statistical characteristics and distribution laws of the data, the encoding parameters are adaptively adjusted to ensure that the encoded two-dimensional grayscale image can retain the key information of the original data to the greatest extent and is suitable for convolutional neural network processing.
[0019] Preferably, the step S3 further includes a data balance verification step, specifically:
[0020] Step 1: Use the All-KNN-based sampling algorithm to verify the balance of the network security data after the expanded training set, and calculate the Gini coefficient to evaluate the degree of data imbalance;
[0021] Step 2: Determine whether to retain or remove the central flow data based on the number of types of neighbor samples of the data. If the data is still unbalanced, readjust the generation parameters of the adversarial generative network or sample the data again until the data reaches a certain balance standard.
[0022] Preferably, the adversarial generative network adopts a Deep Convolutional GAN (DCGAN) structure, the generator accepts category labels and random vectors as input to ensure that the generated new data maintains the consistency of category information; the discriminator receives real samples and generated samples as input, outputs the probability that the sample belongs to the real data, and uses the cross entropy loss function to guide the generator to improve the quality of the generated samples.
[0023] Preferably, the generator comprises a plurality of fractional strided convolutional layers, which gradually transform the low-dimensional random vector into a high-dimensional image representation; each fractional strided convolutional layer is followed by a ReLU activation function and a batch normalization layer.
[0024] Preferably, the discriminator is composed of a series of convolutional layers, and ReLU or Leaky ReLU is used as the activation function between each layer; the last layer adopts the Sigmoid activation function and outputs a probability value between 0 and 1.
[0025] Preferably, the training process of the generative adversarial network adopts the Adam optimization algorithm, the initial learning rate is 0.0002, β1=0.5, β2=0.999, and the L2 regularization term is added. The training of the generative adversarial network is divided into multiple stages. In the initial stage, a higher learning rate is used to quickly approach the optimal solution, and then the learning rate is gradually reduced to refine the parameters. The training stage is automatically switched according to the error change trend on the verification set. The generator and discriminator of the generative adversarial network promote each other through game-style training. The generator tries to deceive the discriminator so that it misclassifies the generated samples as real samples, while the discriminator strives to distinguish between real samples and generated samples, thereby jointly optimizing the maximum minimization objective function.
[0026] Preferably, the convolutional neural network comprises at least one convolutional layer, a pooling layer, an activation layer and a fully connected layer, the convolution kernel size and the step size of the convolutional layer are adjusted according to the input image size, the convolutional layer uses a ReLU activation function, the pooling layer uses a maximum pooling operation, and the normalization layer uses batch normalization, wherein:
[0027] The convolution layer uses a sliding window mechanism, and the step size of each sliding window movement is set to 1 or 2; the pooling layer uses one of the two methods: maximum pooling or average pooling;
[0028] The fully connected layer is located at the end of the network and is responsible for integrating the features extracted by the previous layers. Finally, the Softmax function is used to obtain the probability that the input data belongs to each category.
[0029] The convolutional neural network training process adopts the gradient descent method, calculates the gradient of the loss function relative to the model parameters by back propagation, and then updates the parameter θ according to the gradient value. The update rule is:
[0030]
[0031] Where η is the learning rate;
[0032] In the convolutional neural network, a multi-head attention mechanism is introduced, specifically:
[0033] The feature vector of network security data after encoding and feature selection is input into the multi-head attention layer. Each attention head independently calculates a set of weights and performs weighted summation on the output of the hidden layer.
[0034] The number of attention heads, dimensions, and related learning rates can be adjusted to optimize the model's ability to extract features and classify network security data.
[0035] Preferably, a visual analysis system is also included, including:
[0036] Model selection module: This module should have the functions of displaying the network structure view of the model, clustering neurons using clustering algorithms and displaying the clustering results, providing t-SNE and convolution kernel views to display the convolution kernel activation value heat map, t-SNE projection map and convolution kernel activation value view on t-SNE projection map, and convolution feature map view to display the feature maps obtained by different convolution kernels on the input data;
[0037] Feature analysis module: This module should be able to calculate feature significance values, approximate model weights of the LI ME method, display confusion matrices and t-SNE projection views to assist users in selecting instances where the model makes incorrect judgments and different instance categories that the model has difficulty distinguishing, and analyze the reasons why the model cannot make correct classifications;
[0038] Visual analysis system: Provides a user-friendly interactive interface that allows users to quickly locate important instances for analysis and explain the model's decision-making process for the selected instance.
[0039] (III) Beneficial effects
[0040] Compared with the prior art, the present invention provides a high-performance detection and analysis method for network security, which has the following beneficial effects:
[0041] 1. This high-performance detection and analysis method for network security introduces a generative adversarial network, which consists of a generator and a discriminator. The generator learns and generates new data that conforms to the distribution of real attack data based on a small number of attack samples. These new data are added to the original training set to expand the number of samples in the minority category. Subsequently, the All-KNN algorithm is used to evaluate the data balance, and the generation parameters of the GAN are adjusted or resampled as needed until the data balance standard is reached. This mechanism improves the detection accuracy of minority category attack traffic and enhances the robustness and generalization ability of the model.
[0042] 2. This high-performance detection and analysis method for network security encodes the original network security data into a two-dimensional grayscale image. Specifically, the Min-Max normalization method is used to map numerical features to the [0,1] interval; the categorical features are converted using the one-hot encoding technology. This process ensures that the original traffic data can be properly represented in an image format suitable for convolutional neural network processing, allowing CNN to effectively extract features and perform classification, solving the problem of direct application of deep learning models to non-image data. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 A schematic diagram of a high-performance network security detection and analysis method of the present invention;
[0044] Figure 2 It is a schematic diagram of the process of recursively eliminating RFE flow of network traffic characteristics of the present invention;
[0045] Figure 3 A schematic diagram of a ten-fold cross validation for recursive elimination of network traffic features of the present invention;
[0046] Figure 4 It is the flow chart of the network traffic ET-RFECV algorithm of the present invention;
[0047] Figure 5 This is a flow chart of ET-Boruta feature selection of the present invention;
[0048] Figure 6 It is a schematic diagram of the structure of the generator of the present invention. DETAILED DESCRIPTION
[0049] The following will be combined with the embodiments of the present invention and the accompanying drawings to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0050] See also Figure 1-6, a high-performance detection and analysis method for network security, comprising the following steps:
[0051] S1, encoding network security data into a two-dimensional grayscale image;
[0052] S2. Classifying the two-dimensional grayscale image using a convolutional neural network (CNN);
[0053] S3. Use the Generative Adversarial Network (GAN) to learn attack data with fewer categories and generate new data that conforms to the distribution of attack data, add it to the original training set and then train the deep learning model; the Generative Adversarial Network consists of a generator (G) and a discriminator (D), and the generator and the discriminator are trained in a game-like manner to optimize the maximum and minimum objective function. The specific formula is:
[0054]
[0055] Embodiment 1:
[0056] Aiming at the problem that redundant features of network traffic affect the complexity and accuracy of detection and analysis models, the present invention proposes a network traffic multi-dimensional feature redundancy elimination method ET-RFECV based on extreme tree recursive elimination. According to the minimum optimal strategy, the extreme tree algorithm is used as the base model of RFE, and it screens and eliminates features in an iterative process. Aiming at the problem that traditional network traffic feature selection methods cannot cover global significant features, a full-correlation significant feature selection method based on ET-Boruta is proposed. According to the full-correlation strategy, the method screens the optimal feature set that is significantly correlated with network abnormal behavior, thereby reducing the complexity of network traffic analysis and the purpose of dimensionality reduction, and providing input conditions for subsequent network abnormal traffic detection and analysis.
[0057] 1. Network Traffic Features Recursive Elimination RFECV Algorithm
[0058] RFECV is used for feature selection of network traffic data to reduce the dimension of the dataset and select the features most relevant to abnormal traffic detection; by iteratively removing features with low importance scores, RFECV can help identify the most important features, thereby improving the performance and effectiveness of abnormal traffic detection.
[0059] The RFECV algorithm consists of two stages: the RFE stage and the CV stage. The role of the RFE stage is to rate the importance of traffic features for recursive feature elimination. The role of the CV stage is to select the traffic feature set with the best cross-validation score through cross-validation after the RFE stage, but both the RFE stage and the CV stage must be repeated cyclically. RFECV optimizes the RFE algorithm by adding a cross-validation module. The purpose of cross-validation is to select an optimal number of traffic feature spaces. When the algorithm is running, once it is determined that reducing features will cause performance loss, features will no longer be eliminated.
[0060] This paper designs a modeling of the extreme tree algorithm through multiple and large-scale repetitions to obtain the feature importance value corresponding to each traffic feature. After each iteration, the worst traffic feature is cleared, and then when the iteration is executed again, the next algorithm model is built by using the traffic features that were not screened in the last modeling stage. All traffic features are traversed once as the termination condition to end the loop; then, it will sort the traffic features according to the order standard of retaining or eliminating features according to its own algorithm, and finally select an optimal traffic feature subset space; therefore, RFE is to build the algorithm model in a loop, and obtain the final ranking result of the importance of each traffic feature by traversing all its traffic features; RFE is used to determine the minimum number of factors that can be used to obtain satisfactory results; The RFE feature selection algorithm is as follows.
[0061] Input: training set Q = {(a1,b1),(a2,b2),…(a n ,b n )}, feature set X = (x1, x2, … x m );
[0062] Output: Feature importance ranking:
[0063] (1) Initialize the original feature set X―(x1,x2,…x m ), feature sorting set R = [];
[0064] (2) for X ≠ NULL do;
[0065] (3) Training the ET model;
[0066] (4) Calculate the importance score of each feature;
[0067] (5) Sort feature importance scores New rank ―sort(Rank);
[0068] (6) Update the feature sort list Update(R) = R + X(New ronk );
[0069] (7) Delete the features with small contribution Update(X) = X - X (New rank );
[0070] (8)End for.
[0071] like Figure 2 As shown, in the RFE-based feature selection algorithm, line 1 initializes all original traffic features and takes all traffic features as input. The UNSW-NB15 dataset has 42 traffic features, where m=42. Lines 3 and 4 establish the ET model through the formula:
[0072]
[0073] Calculate the importance of all traffic features, that is, {F1, F2…F m}, line 5 arranges all traffic features in descending order of importance; lines 6 and 7 remove the traffic feature with the smallest feature importance value to form a new feature set until all the original traffic is traversed.
[0074] RFECV divides the network traffic data training set into N small subsets. In each iteration, N-1 subsets are used for training and the remaining 1 subset is used for testing. N cross-validations are completed during the iteration process, which is called the N-fold cross-validation method. This can avoid the overfitting problem caused by only one operation.
[0075] The present invention adopts a ten-fold cross validation method to perform recursive elimination, such as Figure 3 As shown; the advantage of this method is that by repeatedly using randomly generated sub-samples for training and verification, a stable and reliable model can be obtained.
[0076] 2. Feature Redundancy Elimination Algorithm Based on ET-RFECV
[0077] The ET-RFECVRFECV algorithm process is as follows Figure 4As shown, the present invention combines the extreme tree algorithm and the RFECV algorithm, and uses the RFECV algorithm to perform iterative feature selection on all standardized network abnormal traffic feature sets; uses all features for training and evaluation, and gradually eliminates features from the initial traffic feature set to find the feature subset that contributes most to abnormal traffic detection; in each iteration, the extreme tree algorithm is used as the evaluator in the RFE stage, and the ExtraTrees model is used to fit the training data, and the importance of each feature is evaluated by building multiple decision trees; according to the results of the ET model, the importance score of each traffic feature is calculated; and in the CV stage, according to the feature importance determined in the RFE stage, different numbers of features are selected in turn, and the selected feature subsets are cross-validated to determine the feature set with the highest score, and select the optimal traffic feature subset.
[0078] The combined feature selection algorithm based on RFECVET-RFECVRFECV is as follows:
[0079] Input: network traffic training set train, traffic feature variable set F;
[0080] Output: Optimal flow feature set S t , the highest cross-validation score Score top , the final model M;
[0081] (1) [N, M] = Size (train);
[0082] (2) Preprocess the train tes,dataset;
[0083] (3) Sampling and selecting the flow characteristic variable set F;
[0084] (4) Using the extreme tree algorithm as an evaluator;
[0085] (5) for each variable subset F_{i} in F, i = 1, 2, ... n;
[0086] (6) Extract the front F i The most important traffic characteristic variables;
[0087] (7) Using the extracted traffic characteristic variables as new data sets to train the model;
[0088] (8) Recalculate the importance of each traffic characteristic variable and rank them;
[0089] (9) Split the training set into a new training set and a validation set;
[0090] (10) Use the new training set and all feature variables to train the model;
[0091] (11) Use the validation set to evaluate the model;
[0092] (12) For each flow variable subset F_{i}, calculate the performance curve of F_{i};
[0093] (13) Obtain the cross-validation score Score{i} of the current traffic feature variable subset F_{i};
[0094] (14) End for;
[0095] (15) Select the highest cross-validation score Score from Score{i} top ;
[0096] (16) Select Score top The highest traffic feature variable subset F_{i} is taken as the optimal traffic feature set S t ;
[0097] (17) The model with the optimal flow characteristic variable set is selected as the final model M.
[0098] In the combined feature selection algorithm based on ET-RFECV, the first line is N, which represents the total number of training network traffic data sets, and M, which represents the number of columns in the training network traffic data sets, that is, the number of traffic features; the second line performs numerical and normalization operations on the scalar features in the network traffic data; the third line uses ET through the formula:
[0099]
[0100] Calculate the importance of each network traffic feature; Lines 4-7 use RFE to sort the traffic features through the combined feature selection algorithm based on ET-RFECV. In each cycle, reduce the feature with the smallest importance score to form a feature subset; Lines 8-14 calculate the cross-validation score based on different feature sets, and Line 15 obtains the highest cross-validation score; Line 16 determines the optimal number of features.
[0101] 3. ET-Boruta Full Correlation Significant Feature Selection Method
[0102] The present invention designs the ET-Boruta feature selection method for network abnormal flow detection in order to traverse all characteristic network flow features carrying key information for prediction; the ET-Boruta algorithm can obtain the importance of all flow features of the attack type in the data set, and compare the importance of the original flow features with their random flow feature copies, taking into account the inherent correlation of the features, and evaluating the importance of the features in a randomized context, iteratively deleting unimportant flow feature variables, and retaining important flow features; the steps of the full correlation feature selection algorithm for network abnormal flow based on ETBoruta are as follows:
[0103] (1) All traffic feature variables are copied by taking the values of each feature of the traffic feature matrix X in a shuffled order, and the copied traffic features are concatenated with the original traffic features to form a traffic feature matrix with twice the number of features (2*N);
[0104] (2) Randomly shuffle the order of the added traffic features and rearrange them to eliminate the correlation between various traffic features and abnormal traffic types;
[0105] (3) Run the extreme tree algorithm on the expanded traffic feature matrix, use the new traffic feature matrix as input, and train a model that can output the importance of traffic features;
[0106] (4) Calculate the Z_Score of the original traffic feature and the shadow traffic feature, as shown in the following formula:
[0107]
[0108] Where Z_score is the Z score; is the average value of the Gini index; μ Gini is the standard deviation of the Gini index; the importance score in the Boruta algorithm is defined based on the reduction of the Gini index of the ET model;
[0109] (5) Find the maximum shadow feature matrix: Z_Score is S_max, and S_max is used as the screening criterion;
[0110] (6) The original features with Z_score higher than S_max are retained, and the original features with Z_score lower than S_max are permanently deleted from the feature set;
[0111] (7) Repeat this process for 100 iterations until all features are assigned importance.
[0112] The ET-Boruta algorithm can be used to select a set of features related to the dependent variable to obtain the most useful and informative features. The ET-Boruta feature selection method process is as follows: Figure 5 shown.
[0113] Embodiment 2:
[0114] Compared with traditional machine learning methods, the convolutional neural network of the present invention does not require a large amount of feature engineering on the data. By training the model on massive data, the convolutional neural network can learn how to extract useful features from the data to classify the data.
[0115] The training set of the convolutional neural network of the present invention contains seven weeks of network connection records, and the test set contains two weeks of connection records. The test set contains attack types that have never appeared in the training set to simulate the real situation; the original data is a binary TCP data packet, and the data from the source IP address to the destination IP address within a certain period of time is defined as a network connection record. The original data is organized into network connection records and the features of each connection record are extracted, and finally 41 features are obtained for each connection.
[0116] The convolutional neural network of the present invention comprises two convolutional layers, two fully connected layers, and a softmax output layer, which outputs the probability that the data belongs to each category; a pooling layer is used after each convolutional layer to reduce the amount of calculation; a batch normalization layer is added after the first convolutional layer, and a dropout layer is added after the second convolutional layer and the first fully connected layer to avoid overfitting and accelerate the convergence speed during network training.
[0117] Training of basic convolutional neural network model:
[0118] In the training process of the convolutional neural network, the present invention uses the Adam optimization algorithm to update the parameters. The following are the parameter settings used for the training of each task:
[0119] Second category:
[0120] epoch=4
[0121] batch s size=64
[0122] learning rate = 0.001
[0123] Multiple categories:
[0124] epoch=10
[0125] batch s size=128
[0126] learning rate = 0.001
[0127] Training of convolutional neural networks with DCGAN generated data:
[0128] Multi-classification:
[0129] epoch=15
[0130] batch s size=128
[0131] learning rate = 0.001
[0132] Embodiment three:
[0133] Existing research on using generative adversarial networks for data enhancement mainly targets data such as natural images or medical images; the present invention uses generative adversarial networks to generate data of some attack categories with a small amount of data to expand the data set, thereby improving the performance of the model in supervised learning.
[0134] Specifically, the present invention uses the DCGAN model to generate data of two categories, U2R and R2L, and adds the generated data to the training set to solve the problem of data imbalance.
[0135] For the two categories of data, U2R and R2L, two independent adversarial generative networks are trained respectively. After the training is completed, the generator can be used to generate the required amount of data. First, the connection data of the U2R and R2L categories in the training set are encoded, and the encoded two-dimensional image data is used as the training data of DCGAN. A 100-dimensional latent vector is used as the input of the generator, and the latent vector conforms to the uniform distribution. Figure 6 is a schematic diagram of the generator structure, and Table 3-3 is its specific structure. First, the latent vector is projected into 128 3×3 feature maps, and then two UpSampling and convolution layers gradually convert the feature maps into 12×12 images; the structure of the discriminator is shown in Table 3-4, which accepts a 12×12 grayscale image as input, and finally converts it into a one-dimensional probability output through the convolution layer, the MaxPooling layer and the final fully connected layer to determine whether the image is real or generated.
[0136] Training of adversarial generative networks:
[0137] When training the adversarial generative network, the adversarial generative networks used to generate U2R category and R2L category data are trained separately, using stochastic gradient descent with Nesterov momentum, and the momentum value is set to 0.9.
[0138] Generate adversarial network for U2R category data:
[0139] epoch = 1000
[0140] batch s size=52
[0141] learning rate = 0.0005
[0142] Learning rate of the discriminator = 0.0005
[0143] After the training is completed, 1000 U2R attack data are generated.
[0144] Generate adversarial networks for R2L category data:
[0145] The amount of data in the R2L training set is larger, and more epochs are required for training:
[0146] epoch = 2000
[0147] batch s size=128
[0148] learning rate = 0.0005
[0149] Learning rate of the discriminator = 0.0005
[0150] After training is completed, 1000 R2L attack data are generated.
[0151] Embodiment 4:
[0152] The visual analysis system adopts the front-end and back-end architecture of Web applications. The back-end is responsible for data processing and model calculations, and the front-end is responsible for realizing the visualization interface and interaction with users.
[0153] The front-end uses the Vue framework 1 , implemented using HTML, CSS, JavaScript, and d3 2 Binding data to the DOM using jQuery 3 Assists in manipulating the DOM.
[0154] Vue is a progressive JavaScript framework. In Vue, certain syntax can be used to declaratively render data into the DOM. After rendering, both the data and the DOM become responsive. Specifically, when the data changes, the DOM will responsively change, and when the DOM changes, the data will also change accordingly. At the same time, the data can be bound to the DOM structure, and DOM elements can be added, removed or modified according to the data. This feature of Vue enables users to filter and update different visual elements.
[0155] When building views, use Vue's component concept to build different views into independent reusable components, which constitute the entire system.
[0156] Use vuex for state management, it can centrally store and manage the status of all components. Any component can obtain the centrally stored status or trigger behavior on the status. When the user filters the system, vuex can be used to achieve linkage between different views.
[0157] At the same time, the front end executes a POST request to the back end through axios to obtain data, and then updates the visual interface.
[0158] The backend uses the Django framework 4 , following the MVC (Model, View, Controller) design pattern; when the front-end initiates a data request, the back-end matches it according to the URL, calls the corresponding view function, and returns the data to the front-end as an HttpResponse object; the construction and calculation of the deep model on the back-end are implemented through Keras.
[0159] In summary, this high-performance detection and analysis method for network security introduces a generative adversarial network, which consists of a generator and a discriminator; the generator learns based on a small number of attack samples and generates new data that conforms to the distribution of real attack data, and these new data are added to the original training set to expand the number of samples in the minority category; then, the All-KNN algorithm is used to evaluate the data balance, and the generation parameters of the GAN are adjusted or resampled as needed until the data balance standard is reached; this mechanism improves the detection accuracy of minority category attack traffic and enhances the robustness and generalization ability of the model.
[0160] This high-performance detection and analysis method for network security encodes the original network security data into a two-dimensional grayscale image. Specifically, the Min-Max normalization method is used to map numerical features to the [0,1] interval; the categorical features are converted using the one-hot encoding technology. This process ensures that the original traffic data can be properly represented in an image format suitable for convolutional neural network processing, allowing CNN to effectively extract features and classify them, solving the problem of direct application of deep learning models to non-image data, and solving the problems in traditional methods such as data representation not being suitable for deep learning processing, small sample attack missed detection due to category imbalance, and inefficient feature selection.
[0161] The relevant modules involved in this system are all hardware system modules or functional modules that combine computer software programs or protocols with hardware in the prior art. The computer software programs or protocols involved in the functional modules are themselves technologies that are well known to those skilled in the art and are not improvements of this system. The improvements of this system are the interaction or connection relationships between the modules, that is, improvements to the overall structure of the system to solve the corresponding technical problems to be solved by this system.
[0162] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A high-performance detection and analysis method for network security, characterized in that: The following steps are involved: S1, encoding network security data into a two-dimensional grayscale image; S2. Classifying the two-dimensional grayscale image using a convolutional neural network (CNN); S3. Use the Generative Adversarial Network (GAN) to learn attack data with fewer categories and generate new data that conforms to the distribution of attack data, add it to the original training set and then train the deep learning model; the Generative Adversarial Network consists of a generator (G) and a discriminator (D), and the generator and the discriminator are trained in a game-like manner to optimize the maximum and minimum objective function. The specific formula is:
2. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The step S1 also includes a feature processing step, which specifically includes: Step 1: The original network traffic data is processed by using the extreme tree recursive elimination (ET-RFE) method. The importance index of each network traffic feature is calculated using the extreme tree algorithm, and the features are sorted according to the mean reduced impurity (MDI) method. The features with low importance scores are recursively removed to screen out the feature subset with high correlation with the objective function. Step 2: Use the full-correlation feature selection method based on ET-Boruta to create a hybrid shadow feature set, compare the importance between the original features and the shadow features, select the features that have a global significant contribution to network traffic anomalies, and further optimize the feature set.
3. A high-performance detection and analysis method for network security according to claim 1, characterized in that: When encoding the network security data into a two-dimensional grayscale image, the following method should be used: Step 1: For numerical features, use the min-max normalization method to map them to the [0,1] interval; Step 2: Use the unique hot encoding technology to convert categorical features; Step 3: According to the statistical characteristics and distribution laws of the data, the encoding parameters are adaptively adjusted to ensure that the encoded two-dimensional grayscale image can retain the key information of the original data to the greatest extent and is suitable for convolutional neural network processing.
4. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The step S3 also includes a data balance verification step, which is specifically: Step 1: Use the All-KNN-based sampling algorithm to verify the balance of the network security data after the expanded training set, and calculate the Gini coefficient to evaluate the degree of data imbalance; Step 2: Determine whether to retain or remove the central flow data based on the number of types of neighbor samples of the data. If the data is still unbalanced, readjust the generation parameters of the adversarial generative network or sample the data again until the data reaches a certain balance standard.
5. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The adversarial generative network adopts the Deep Convolutional GAN (DCGAN) structure, and the generator accepts category labels and random vectors as input to ensure that the generated new data maintains the consistency of category information; The discriminator receives real samples and generated samples as input, outputs the probability that the sample belongs to the real data, and uses the cross entropy loss function to guide the generator to improve the quality of the generated samples.
6. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The generator includes multiple fractional strided convolutional layers, which gradually transform low-dimensional random vectors into high-dimensional image representations; each fractional strided convolutional layer is followed by a ReLU activation function and a batch normalization layer.
7. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The discriminator is composed of a series of convolutional layers, and ReLU or Leaky ReLU is used as the activation function between each layer; the last layer adopts the Sigmoid activation function and outputs a probability value between 0 and 1.
8. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The training process of the generative adversarial network adopts the Adam optimization algorithm, with an initial learning rate of 0.0002, β1=0.5, β2=0.999, and an L2 regularization term is added. The training of the generative adversarial network is divided into multiple stages. In the early stage, a higher learning rate is used to quickly approach the optimal solution, and then the learning rate is gradually reduced to fine-tune the parameters. The training stage is automatically switched according to the error change trend on the verification set. The generator and discriminator of the generative adversarial network promote each other through game-based training. The generator tries to deceive the discriminator so that it misclassifies the generated samples as real samples, while the discriminator strives to distinguish between real samples and generated samples, thereby jointly optimizing the maximum and minimum objective functions.
9. A high-performance detection and analysis method for network security according to claim 1, characterized in that: The convolutional neural network includes at least one convolutional layer, a pooling layer, an activation layer and a fully connected layer. The convolution kernel size and step size of the convolutional layer are adjusted according to the input image size. The convolutional layer uses the ReLU activation function, the pooling layer uses the maximum pooling operation, and the standardization layer uses batch normalization, where: The convolution layer uses a sliding window mechanism, and the step size of each sliding window movement is set to 1 or 2; the pooling layer uses one of the two methods: maximum pooling or average pooling; The fully connected layer is located at the end of the network and is responsible for integrating the features extracted by the previous layers. Finally, the Softmax function is used to obtain the probability that the input data belongs to each category. The convolutional neural network training process adopts the gradient descent method, calculates the gradient of the loss function relative to the model parameters by back propagation, and then updates the parameter θ according to the gradient value. The update rule is: Where η is the learning rate; In the convolutional neural network, a multi-head attention mechanism is introduced, specifically: The feature vector of network security data after encoding and feature selection is input into the multi-head attention layer. Each attention head independently calculates a set of weights and performs weighted summation on the output of the hidden layer. The number of attention heads, dimensions, and related learning rate parameters can be adjusted to optimize the model's ability to extract features and classify network security data.
10. A high-performance detection and analysis method for network security according to claim 1, characterized in that: Also included is a visual analytics system, including: Model selection module: This module should have the functions of displaying the network structure view of the model, clustering neurons using clustering algorithms and displaying the clustering results, providing t-SNE and convolution kernel views to display the convolution kernel activation value heat map, t-SNE projection map and convolution kernel activation value view on t-SNE projection map, and convolution feature map view to display the feature maps obtained by different convolution kernels on the input data; Feature analysis module: This module should be able to calculate feature significance values, approximate model weights of the LIME method, and display confusion matrices and t-SNE projection views to assist users in selecting instances where the model makes incorrect judgments and different instance categories that the model has difficulty distinguishing, and analyze the reasons why the model cannot make correct classifications; Visual Analysis System: Provides a user-friendly interactive interface that allows users to quickly locate important instances for analysis and explain the model's decision-making process for the selected instance.
Citation Information
Cited By
Grayscale value dynamic adjustment and risk assessment method in power system network security
CN121098547A