Training method and system of network traffic attack detection model, and medium

By performing data augmentation and model parameter updates on the client, and using the central server's aggregate weight mechanism, the problem of low accuracy of the network attack detection model when applied to the client is solved, achieving more efficient malicious traffic detection and defense capabilities.

CN119966660AActive Publication Date: 2025-05-09NORTHEASTERN UNIV CHINA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411960753.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-09
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

Due to the data silos between the client's data, the attack detection accuracy of attack detection models trained by the server is low when the attack detection model is applied to the client.

Method used

By obtaining the target attack traffic data set on the target client, data enhancement is performed, local network traffic attack detection model parameters are updated, and the updated parameters are sent to the central server. Based on the received parameters, the central server calculates the aggregate weight of each client, aggregates the model parameters of multiple clients, generates global model parameters, and issues them to each client.

Benefits of technology

Through the federated learning architecture, the performance of local models of each regulatory node in identifying cross-domain malicious traffic is realized, the data silo problem is solved, and the accuracy and robustness of malicious traffic detection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966660A_ABST
    Figure CN119966660A_ABST
Patent Text Reader

Abstract

The invention discloses a training method and system of a network traffic attack detection model and a medium. The training method comprises the steps that at least one target client obtains a target attack traffic data set; each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model, and updates parameters of a target local network traffic attack detection model based on an enhanced attack sample set; the central server calculates an aggregation weight by using a preset aggregation function so as to aggregate the at least one first parameter and second parameters of other clients participating in training; and each client updates the local network traffic attack model based on the received third parameter. Through the above mode, each supervision node can learn the detected novel network traffic attack mode in time, the network traffic attack detection and defense capability of each supervision node is greatly improved, and the data privacy of the supervision node is effectively protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a training method, system and medium for a network traffic attack detection model. Background Art

[0002] At present, network attack detection based on machine learning and network attack detection based on deep learning utilize the powerful data analysis and learning capabilities of intelligent algorithms and are considered to be effective methods of network attack detection. However, due to data privacy protection considerations, there are data silos between client data, which leads to low attack detection accuracy when the network attack detection model trained on the server is applied on the client. Summary of the invention

[0003] The present invention provides a training method, system and medium for a network traffic attack detection model to solve the technical problem that the network attack detection model trained on the server has low attack detection accuracy when applied on the client due to the existence of data islands between client data.

[0004] In a first aspect, a training method for a network traffic attack detection model is provided, wherein a network traffic attack detection system is applied, wherein the network traffic attack detection system includes a central server and a plurality of clients, and the central server is in communication connection with each client, and the method includes:

[0005] At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified;

[0006] Each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first number of the target attack traffic data set to the central server;

[0007] The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution by using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients;

[0008] Each client updates the local network traffic attack model based on the received third parameter.

[0009] In a second aspect, a network traffic attack detection system is provided, comprising a central server; a client processor; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the central server and / or the client processor, and the programs enable the computer to execute the steps of the training method of the above-mentioned network traffic attack detection model.

[0010] In a third aspect, a computer-readable storage medium is provided, which stores a computer program, and when the computer program is executed by a processor, the steps of the training method of the above-mentioned network traffic attack detection model are implemented.

[0011] In the solution implemented by the training method, system and storage medium of the above-mentioned network traffic attack detection model, the attack traffic data of any unidentified attack type in any supervisory node is obtained, and data enhancement processing is performed on it. Based on the enhanced unknown attack traffic as a sample, the parameters of the local local traffic detection model are updated, and the updated model parameters are sent to the central server, so that the central server updates the global traffic detection model based on the received local model parameters. Through the above-mentioned method, network intrusion detection is performed based on the federated learning architecture, so that each supervisory node can simultaneously realize real-time monitoring of unknown traffic attacks and training updates of local attack detection local models. In addition, the central server determines the corresponding weights according to the training effect of the local model, aggregates the multiple local model parameters obtained by training according to the weights, and sends the aggregated model parameters to each supervisory node, so that each supervisory node can learn the detected new network traffic attack mode in time. Satisfy the migration identification ability of each supervisory node for unknown attack types in network traffic data, greatly improve the ability of each supervisory node to detect and defend network traffic attacks, and effectively protect the data privacy of the supervisory node. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative labor.

[0013] Figure 1 It is a flow chart of a training method of a network traffic attack detection model in one embodiment of the present invention;

[0014] Figure 2 Schematic diagram of the function change of the weight aggregation function during the global model parameter update process in one embodiment of the present invention;

[0015] Figure 3It is a schematic block diagram of a parameter contingency process of unidentified mode traffic and normal traffic in parameter aggregation in one embodiment of the present invention;

[0016] Figure 4 It is a schematic block diagram of strengthening target attack traffic data in one embodiment of the present invention. DETAILED DESCRIPTION

[0017] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0018] The training method of the network traffic attack detection model provided by the present invention can be applied to malicious traffic detection and network attack traffic detection scenarios in the field of modern network security. Specifically, with the gradual advancement of network technology and the increasing attention paid to data privacy, malicious traffic detection and network attack traffic detection technology have received increasing attention in the field of modern network security. In the current network environment, attackers may use a variety of technical means to launch attacks, causing huge losses to enterprises or individuals, such as the leakage of commercial secrets or the collapse of customer trust. With the continuous complexity of network attack patterns, timely detection and processing of malicious traffic has become a key task to protect user privacy and maintain system security. Therefore, establishing an efficient traffic detection mechanism is of far-reaching significance for identifying and preventing network traffic attacks.

[0019] In the related technologies, there have been many studies on malicious traffic detection and network attack traffic detection, such as network threat detection technology (NTA), full-flow threat analysis solutions, and encrypted malicious traffic detection research based on deep learning. Network threat detection technology is an emerging encrypted traffic detection technology that combines rule-based detection and machine learning methods to analyze encrypted traffic through deep packet inspection (DPI) and deep / dynamic flow inspection (DFI). This method is often used to detect suspicious behaviors in enterprise networks. The full-flow threat analysis solution is a method that quickly discovers potential threats in network traffic through full-flow collection, parsing and storage, combined with threat intelligence and machine learning algorithms. This method can trace back historical events, so as to accurately grasp the process and impact of events, and provide effective security protection. However, encrypted malicious traffic detection research based on deep learning believes that: with the continuous increase of encrypted traffic in the current network environment and the continuous advancement of existing traffic encryption technology, traditional traffic detection methods (such as DPI) are no longer applicable. However, deep learning technology can automatically learn features from raw data and adapt to different types of network environments, so deep learning-based methods are very suitable for encrypted traffic detection. In practical applications, the researchers proposed a system called HyperVision, which is an unsupervised real-time detection system for malicious traffic. It can detect malicious encrypted traffic of unknown patterns through a compact memory graph based on traffic patterns. However, its compact memory graph is no longer limited to the characteristics of specific known attacks in previous studies, but represents all traffic interaction patterns captured by it in the form of graph structure features. After generating a compact memory graph, it can detect various encrypted attack traffic without any known attack data set by analyzing the connectivity, sparsity and statistical characteristics of the graph. The researchers also established an information theory model to prove that the information retained by the compact memory graph in this study is close to the existing theoretical limit. Through actual experiments, HyperVision's performance on 92 data sets showed at least 0.92 AUC and 0.86 F1, achieved at least 80.6Gb / s detection throughput, and an average detection delay of 0.83 seconds. These data are significantly better than existing methods, and more than 50% of the attacks in the experiment can evade all existing methods, but can be recognized by HyperVision.

[0020] However, even though existing research has achieved considerable results in the field of identifying encrypted traffic attacks, there is still less attention paid to the rapid detection and knowledge collaboration of unknown malicious traffic. In existing research, encrypted malicious traffic detection methods are usually supervised and rely on prior knowledge of known attacks. They can only detect attacks with known traffic patterns, but it is difficult to detect more widespread encrypted traffic attacks with unknown patterns. Moreover, after a new encrypted traffic attack occurs, it is often difficult for the attacked party to take corresponding countermeasures in a timely manner, even if the attack may have occurred on neighboring terminals.

[0021] Based on the above problems, the embodiment of the present application provides a training method for a network traffic attack detection model, which builds a global model and a local model based on a federated learning framework, and uses the newly emerged unknown attack traffic in various places to focus on adjusting the training weights of the global model, so that the global model can learn the detected new network traffic attack methods in a timely manner. Finally, the distributed training data is aggregated and sent to each domain after aggregation, realizing the performance of the local model of each domain in identifying cross-domain malicious traffic, solving the problem of data islands in each domain, and improving the accuracy and robustness of malicious traffic detection.

[0022] See also Figure 1 As shown, Figure 1 A flowchart of a method for training a network traffic attack detection model provided by an embodiment of the present invention includes the following steps:

[0023] S10: At least one target client obtains a target attack traffic data set;

[0024] The target client is the client that is attacked, and the target attack traffic data set includes attack traffic data whose attack type is not identified;

[0025] In this step, the target client refers to the client that is detected to be attacked by malicious traffic of unknown attack type; the target attack traffic data refers to the attack traffic data of unidentified attack type.

[0026] It can be understood that the executor of the present invention can be a network traffic attack detection system. Specifically, the system includes a central server and multiple clients. The central server is communicated with each client. A global model of the network traffic attack detection model is pre-constructed in the central server, and a local model of the network traffic attack detection model is constructed in each client. The local model of the client has the same network structure as the global model of the central server.

[0027] In this step, at least one client in a domain attacked by malicious traffic obtains target attack traffic data whose attack type cannot be identified.

[0028] In actual application scenarios, network attacks are usually divided into two types: continuous attacks and discontinuous attacks. Some attackers also combine the characteristics of continuous attacks and discontinuous attacks to launch real-time mixed attacks. Therefore, when a new type of unknown attack is detected, the target client attacked by malicious traffic can summarize the unknown attack type traffic data within a specified time period to generate a target attack traffic data set.

[0029] In one embodiment of the present application, a specific solution for obtaining target attack traffic data is provided. In S10, at least one target client obtains a target attack traffic data set, which specifically includes the following steps S11-S15:

[0030] S11: For any client, obtain multiple network traffic data of multiple target nodes in the target domain;

[0031] In this step, for any client, the network traffic data flowing through each network node (ie, target node) captured in real time in the target domain corresponding to the client is obtained.

[0032] S12: using the local network traffic attack detection model corresponding to the client, determine whether the network traffic data of each target node is abnormal traffic data, and proceed to step S13; if not, return to step S11;

[0033] In this step, the local network traffic attack detection model is a local model based on network traffic attack detection constructed by the client by introducing federated learning, which is used to distinguish whether the traffic flowing through each node is normal traffic behavior or abnormal traffic behavior. After the real-time traffic of any network node is captured, it is detected using the local network traffic attack detection model, and based on the detection result, it is determined whether it is normal traffic behavior. If it is normal traffic behavior, continue to capture real-time traffic; if it is abnormal traffic behavior, it is necessary to determine the attack type of the abnormal traffic. In one embodiment of the present application, a specific abnormal traffic data detection scheme is provided. In S12, that is, the local network traffic attack detection model corresponding to the client is used to determine whether the network traffic data of each target node is abnormal traffic data, which specifically includes the following steps S121-S122:

[0034] S121: extracting features from the network traffic data of each target node to obtain traffic features;

[0035] S122: Input the traffic characteristics into the local network traffic attack detection model to determine abnormal traffic data.

[0036] For steps S121-S122, the captured traffic data is parsed to extract key traffic features that can identify malicious behavior (such as time series features of traffic, data packet size distribution, protocol anomalies, etc.). Thereafter, the extracted traffic features are input into the local network traffic attack detection model to obtain the detection results and determine whether the network traffic data is abnormal traffic data.

[0037] In actual application scenarios, by introducing federated learning, a local model based on the network traffic attack detection model is pre-deployed on each node domain. The model should have the ability to quickly learn and adapt to new attack patterns. Considering the complexity of the cross-domain environment and the characteristics of the edge nodes themselves, the local model may consider lightweight and easy to update as the design focus. Subsequently, multiple rounds of local training are performed based on the existing local attack data set, and the parameters are updated according to the performance of the model on the local data after each round of training. After the basic training is completed, the model structure is fine-tuned based on the performance of the model on the cross-domain malicious traffic identification data set and the new attack pattern reinforcement data set, and specific regularization techniques are introduced to prevent overfitting in a small scale, so as to implement additional personalized training steps for the model, so that it can better adapt to the network environment and specific attack patterns of the running tasks.

[0038] S13: When it is determined that the network traffic data of any target node is abnormal traffic data, the client is determined to be a target client, and a target traffic feature of the abnormal traffic data is obtained;

[0039] S14: Based on the target traffic characteristics, determine whether the abnormal traffic data is target attack traffic data.

[0040] For steps S13-S14, when it is determined that the network traffic data of any target node is abnormal traffic data, the client of the node domain is marked as the target client, and the target traffic characteristics of the abnormal traffic data are obtained. Based on the target traffic characteristics, it is determined whether the attack type of the abnormal traffic data is determined to determine whether the abnormal traffic data is target attack traffic data.

[0041] In one embodiment of the present application, a specific target attack traffic data determination scheme is provided. In S14, that is, based on the target traffic characteristics, determining whether the abnormal traffic data is the target attack traffic data specifically includes the following steps S141-S142:

[0042] S141: Based on the target traffic characteristics and a preset attack database, determining whether the attack type of the abnormal traffic data can be identified;

[0043] The preset attack database is composed of a plurality of known attack types and their corresponding traffic characteristics;

[0044] S142: If the attack type of the abnormal traffic data cannot be identified, mark the abnormal traffic data as the target attack traffic data.

[0045] For steps S141-S142, for any abnormal traffic data, the target traffic characteristics of the abnormal traffic data are compared in the preset attack database to determine whether the preset attack database contains the attack type of the abnormal traffic data. If the preset attack database contains the attack type of the abnormal traffic, it means that the attack traffic flowing through the node is a known attack behavior. At this time, the attack traffic related data is recorded, and the process returns to step S11 to continue capturing real-time network traffic; if the preset attack database does not contain the attack type of the abnormal traffic data, it means that the abnormal traffic data is a new type of unknown attack traffic, and the abnormal traffic data is marked as target attack traffic data.

[0046] Optionally, a preset attack database is constructed in advance based on the attack types of malicious traffic data with all current cross-domain characteristics and their corresponding abnormal traffic characteristics, so that the database covers various types of attack modes, such as DDoS, port scanning, malware propagation, etc.

[0047] In one embodiment of the present application, a specific preset database update solution is provided. After S142, that is, after marking the abnormal traffic data as target attack traffic data, the following steps S143-S144 are also included:

[0048] S143: Determine the attack type of the abnormal traffic data based on the traffic characteristics of the abnormal traffic data;

[0049] S144: Based on the traffic characteristics and attack types of the abnormal traffic data, a preset attack database is updated.

[0050] For steps S143-S144: analyze the key features extracted from the abnormal traffic data to confirm the characteristics and behavior patterns of the abnormal traffic data, and use an expert system or knowledge base to infer the attack type based on the characteristics and behavior patterns. In addition, in order to ensure the accuracy of the attack type inference, the inferred attack type can also be manually reviewed. Finally, the preset attack database is updated based on the characteristic data of the abnormal traffic and the inferred attack type to improve the timeliness and accuracy of the preset attack database. S20: Each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and the target attack traffic data set to the central server;

[0051] In this step, for any target client in the node domain that is attacked by an unknown type of malicious traffic, when an unknown type of malicious traffic is detected, it means that the attacker may have exploited unknown vulnerabilities and technologies to attack. At this time, the target attack traffic data needs to be used to update the parameters of the local model on the target client. However, attackers usually attack in the form of zero-day attacks, sudden abnormal attacks, etc. If the parameters are directly updated using at least one detected target attack traffic data, the sample size is small, which may affect the generalization ability of the model. In order to improve the accuracy of the model parameter update, it is necessary to first enhance the data in the target attack traffic data set to obtain a diversified enhanced attack sample set so that the sample data can cover more attack types and attack methods.

[0052] Specifically, the data in the target attack traffic data set is enhanced using a preset data enhancement model to obtain an enhanced attack sample set. Subsequently, the local model of the target client is updated with the enhanced attack sample set to obtain an updated first parameter. The first parameter and the target attack traffic data set are sent to the central server.

[0053] Optionally, according to the needs (focusing on data enhancement of the identified new attack patterns), a LoRa model suitable for processing time series data is selected as a preset data enhancement model, and customized according to the characteristics of cross-domain malicious traffic, by adjusting the depth and width of the model or introducing an attention mechanism to capture the traffic pattern in a customized way to adapt to the task of cross-domain malicious traffic detection. In addition, in addition to the directional changes in the model architecture, the LoRa model is pre-trained using an existing database during pre-training and tuning. It should be noted that since the training focuses on the generalization ability of the model in a cross-domain environment, the extreme optimization of a single performance indicator or the short-term training effect will not be overly focused on during the pre-training process. During the tuning process, special attention will be paid to the model's ability to identify new unknown attacks. Similarly, during the model verification and iteration process, the model performance will be tested on an independent verification set, focusing on its accuracy and response time in identifying unknown cross-domain attack traffic.

[0054] Through the above method, data enhancement technology is used to enrich the diversity of training samples to cope with complex and changeable malicious traffic, which can help the model better capture potential attack features in attack traffic and improve the model's ability to identify unknown attack traffic.

[0055] In one embodiment of the present application, a specific training scheme for a local network traffic attack detection model is provided. In S20, each target client performs data enhancement on a target attack traffic data set through a pre-trained data enhancement large model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and the target attack traffic data set to a central server, specifically including the following steps S21-S25:

[0056] S21: For any target client, data in the target attack data set is enhanced by using a preset data enhancement model to obtain an enhanced attack sample set;

[0057] S22: Obtain a historical attack sample set corresponding to the target client;

[0058] S23: Generate a training data set based on the enhanced attack sample set and the historical attack sample set;

[0059] For steps S21-S23, for any target client, the data in the target attack data set is enhanced using a preset data enhancement model to obtain an enhanced attack sample set. A historical attack sample set corresponding to the target client is obtained, wherein the historical attack sample set is an existing attack sample set, and the enhanced enhanced attack sample set is combined with the existing attack sample set to construct a training data set.

[0060] Through the above method, the new attack sample set is combined with the existing attack sample set to construct a training data set to enhance the learning ability and adaptability of the model.

[0061] S24: Train a local network traffic attack detection model of the target client based on the training data set to obtain a first parameter.

[0062] In this step, the training data set is used to update the parameters of the local model to obtain updated first parameters.

[0063] S25: Send the first parameter and the target attack traffic data set to the central server.

[0064] In this step, by introducing federated learning, a global model with the same network structure as the local model is pre-built on the central server. In order to enable other domains to quickly detect new attack behaviors, the updated first parameter and the target attack traffic data set are sent to the central server for update aggregation.

[0065] S30: The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and the second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients.

[0066] In this step, the central server obtains the second number of clients participating in the training in this round and the historical average contribution of each client, and dynamically adjusts the training weight of each client based on the first number, the second number and the historical average contribution using a preset aggregation function. Afterwards, the model parameters of all clients are aggregated based on the calculated weights to generate a new global model, and the third parameters of the new global model are sent to each client.

[0067] In one embodiment of the present application, a specific global parameter contingency aggregation scheme is provided. In S30, that is, the central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution, using a preset aggregation function, and aggregates at least one first parameter and the second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients, specifically including the following steps S31-S35:

[0068] S31: The central server obtains a second number of the plurality of clients participating in the training and a historical average contribution of each client;

[0069] S32: Calculate an aggregation weight corresponding to each client based on the first quantity, the historical average contribution, and the second quantity through a preset aggregation function;

[0070] S33: Acquire at least one second parameter of at least one other client among the multiple clients except the at least one target client;

[0071] S34: Aggregate at least one first parameter and at least one second parameter based on the aggregation weight to generate a third parameter of a new global network traffic attack detection model;

[0072] S35: Send the third parameter to each client.

[0073] For steps S31-S35, obtain the second number of multiple clients participating in the training in this round and the historical average contribution of each client in the historical training rounds. Thereafter, input the first number, the second number and the historical average contribution into a preset aggregation function to calculate the aggregated weight of each client. Then, obtain at least one second parameter of at least one other client other than the multiple target clients participating in the training in this round. Based on the aggregated weight, aggregate at least one first parameter and at least one second parameter to generate a new global network traffic attack detection model, and send the third parameter of the new global model to each client.

[0074] Optionally, the preset aggregation function is:

[0075]

[0076] Among them, the above G is the aggregation weight, the above B is the historical average contribution of each client in updating the local model parameters in previous rounds; the above x is the first number of data in the target attack traffic data set; and the above k is the second number of clients participating in the training.

[0077] In actual application scenarios, it can respond quickly in the initial stage (i.e., the first number of unidentified traffic increases from zero) and quickly increase the weight of the target domain in the parameter aggregation stage. When attacks are frequent (i.e., the first number of unidentified traffic is large), it can ensure that the parameters of other domains will not be swallowed up during aggregation due to the excessive weight of the attacked domain, thereby avoiding the abnormally high weight of the frequently attacked domain during parameter aggregation. Figure 2 As shown in Figure 1, it is a schematic diagram of the function change of the weight aggregation function, where the horizontal axis is the number of iterations and the vertical axis is the number of clients participating in the training. The numerical change of the weight aggregation function is shown in Table 1, and its numerical change reflects that the weight aggregation function can very well adjust the parameters and weights of the second traffic detection model and achieve the purpose of unknown traffic migration.

[0078] Table 1

[0079]

[0080] In the above way, through local data enhancement and global parameter contingency aggregation, the accuracy and response speed of model detection are improved, and the dependence on centralized data processing is reduced. Through node enhancement, the importance of the parameters passed in by each device domain participating in the training is weighed. It is achieved that not only the contribution of the domain node to the training of the network traffic attack detection model in the previous training process is considered, but also the impact of the emerging network traffic pattern on the training of the overall network traffic attack detection model is taken into account to enhance the model's detection and response capabilities for new network traffic attacks, and improve the accuracy and robustness of detection.

[0081] S40: Each client updates the local network traffic attack model based on the received third parameter.

[0082] In this step, each client receives the third parameter sent by the central server and updates the local network traffic attack detection model based on the third parameter. This achieves the performance of each client in identifying cross-domain traffic, so that each domain can also detect unknown attack traffic discovered by other domains in a timely manner, greatly enhancing the security of each domain node.

[0083] It can be seen that in the above scheme, the attack traffic data of any unidentified attack type in any supervisory node is obtained, and data enhancement processing is performed on it. Based on the enhanced unknown attack traffic as a sample, the parameters of the local local traffic detection model are updated, and the updated model parameters are sent to the central server, so that the central server updates the global traffic detection model based on the received local model parameters. Through the above method, network intrusion detection is performed based on the federated learning architecture, so that each supervisory node can simultaneously realize real-time monitoring of unknown traffic attacks and training updates of local attack detection local models. In addition, the central server determines the corresponding weights according to the training effect of the local model, aggregates the multiple local model parameters obtained by training according to the weights, and sends the aggregated model parameters to each supervisory node, so that each supervisory node can learn the detected new network traffic attack mode in time. Satisfy the migration identification ability of each supervisory node for unknown attack types in network traffic data, greatly improve the ability of each supervisory node to detect and defend network traffic attacks, and effectively protect the data privacy of the supervisory node.

[0084] In one embodiment, a network traffic attack detection system is provided, comprising a central server; a client processor; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the central server and / or the client processor, and the program enables a computer to implement the following steps when executing the computer program:

[0085] At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified;

[0086] Each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first number of the target attack traffic data set to the central server;

[0087] The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution by using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients;

[0088] Each client updates the local network traffic attack model based on the received third parameter.

[0089] In actual application scenarios, the network traffic attack detection system proposed in this application includes a network traffic attack detection and classification device, a local sample enhancement device for unknown traffic, and a global parameter contingency aggregation device. Among them, the network traffic attack detection and classification device is used to perform attack detection on the network traffic flowing through the edge node based on a preset attack database, and to identify and classify the network traffic attack based on its characteristic manifestations. Figure 3 As shown in FIG. 1 , it is a schematic diagram of the parameter contingency process of unidentified pattern traffic (i.e., target attack traffic data) and normal traffic in parameter aggregation. The local sample enhancement device for unknown traffic is used to enhance and generalize the data samples of the identified new network traffic attack mode by using the data sample enhancement method based on the large model locally in each domain node, and combine the generated data samples with the original classified attack samples to construct the network traffic attack training data set. Figure 4As shown, it is a schematic block diagram for strengthening the target attack traffic data, wherein the unified unknown traffic input is divided into normal traffic and unknown attack mode traffic after it flows through the network traffic attack detection and classification device, and the local sample enhancement device of the unknown traffic is input after classification to perform data sample enhancement to generate a comprehensive enhanced data set. The global parameter contingency aggregation device is used to focus on adjusting the training weight of the model in combination with the data set returned by each node, the new attack detection situation of each node and the historical training situation of the model, so that the model as a whole can learn the detected new network traffic attack mode in time. Finally, the distributed training data is finally aggregated and sent to each domain after aggregation, so that the nodes in each domain can learn the detected new network traffic attack mode in time. In this application, for the nodes of any domain, in the process of unknown network traffic flow to the local node, the capture tool is used to capture the original traffic, and the local client extracts the features of the captured original traffic within a data slice cycle, and uses the local attack detection model constructed by the local client to perform feature analysis to quickly identify normal traffic or abnormal traffic. When it is determined that the flow is abnormal traffic, its key features are compared with the existing attack database to identify potential new attacks. The identified new attack traffic is sampled and collected to obtain new attack traffic samples. If the above new attack traffic samples are successfully collected, the characteristic information of the identified new attack traffic is stored, a new attack type is generated for it, and it is promptly fed back to the local sample enhancement device of the unknown traffic for subsequent sample generation and model update, otherwise it enters the next time segment cycle and repeats the above steps. Further, the new attack traffic samples are input into the pre-trained sample enhancement large model, and the reinforcement learning method of the large model is used to enhance and generalize the data samples to obtain an enhanced sample set. The enhanced sample set is combined with the existing attack sample set to construct a training data set to enhance the learning ability and adaptability of the model. For the specified time interval, the training data set is used to update the parameters of the local attack detection model, and the updated local model parameters are fed back to the central server. The central server receives the updated local model parameters sent back by each local client to ensure that the status of each domain is fully mastered. According to the contribution of each node and the historical training of the model, the global model aggregation function G is used to dynamically adjust the training weight to optimize the training effect of the model. The training data of all nodes are aggregated to generate updated global model parameters. The parameters of the new global model are sent to each local client so that it can quickly adapt and effectively respond to new attacks. The weight aggregation function G is:

[0090]

[0091] Among them, the above G is the aggregation weight, the above B is the historical average contribution of each client in updating the local model parameters in previous rounds; the above x is the first number of data in the target attack traffic data set; and the above k is the second number of clients participating in the training.

[0092] In one embodiment, a computer readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:

[0093] At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified;

[0094] Each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first number of the target attack traffic data set to the central server;

[0095] The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution by using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients;

[0096] Each client updates the local network traffic attack model based on the received third parameter.

[0097] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can refer to the relevant descriptions on the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.

[0098] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0099] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0100] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A training method for a network traffic attack detection model, characterized in that: Applied to a network traffic attack detection system, wherein the network traffic attack detection system includes a central server and multiple clients, the central server is in communication connection with each client, and the method includes: At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified; Each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first number of the target attack traffic data set to the central server; The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution by using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients; Each client updates the local network traffic attack model based on the received second parameter.

2. The method according to claim 1, characterized in that: The step of at least one target client obtaining a target attack traffic data set specifically includes: For any client, obtain multiple network traffic data of multiple target nodes in the target domain; Using the local network traffic attack detection model corresponding to the client, determine whether the network traffic data of each target node is abnormal traffic data; When it is determined that the network traffic data of any target node is abnormal traffic data, the client is determined to be a target client, and target traffic characteristics of the abnormal traffic data are obtained; Based on the target traffic characteristics, determine whether the abnormal traffic data is target attack traffic data.

3. The method according to claim 2, characterized in that The step of using the local network traffic attack detection model corresponding to the client to determine whether the network traffic data of each target node is abnormal traffic data specifically includes: Extracting features from the network traffic data of each target node to obtain traffic features; The traffic characteristics are input into the local network traffic attack detection model to determine abnormal traffic data.

4. The method according to claim 2, characterized in that: The step of determining whether the abnormal traffic data is target attack traffic data based on the target traffic characteristics specifically includes: Based on the target traffic characteristics and a preset attack database, determining whether the attack type of the abnormal traffic data can be identified, wherein the preset attack database is composed of a plurality of known attack types and their corresponding traffic characteristics; If the attack type of the abnormal traffic data cannot be identified, the abnormal traffic data is marked as the target attack traffic data.

5. The method according to claim 4, characterized in that After marking the abnormal traffic data as the target attack traffic data, the method further includes: Based on the traffic characteristics of the abnormal traffic data, determine the attack type of the abnormal traffic data; Based on the traffic characteristics and attack types of abnormal traffic data, the preset attack database is updated.

6. The method according to claim 1, characterized in that The step of each target client performing data enhancement on a target attack traffic data set through a pre-trained data enhancement large model to obtain an enhanced attack sample set, and updating a parameter of a target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sending the first parameter and a first quantity of the target attack traffic data set to a central server specifically includes: For any target client, the data in the target attack dataset is enhanced through the preset data enhancement model to obtain an enhanced attack sample set; Obtain the historical attack sample set corresponding to the target client; Generate a training data set based on the enhanced attack sample set and the historical attack sample set; Training a local network traffic attack detection model of the target client based on the training data set to obtain the first parameter; The first parameter and the target attack traffic data set are sent to the central server.

7. The method according to claim 1, characterized in that The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution by using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; The step of sending the third parameter to multiple clients specifically includes: The central server obtains a second number of the plurality of clients participating in the training and a historical average contribution of each client; Based on the first quantity, the historical average contribution, and the second quantity, an aggregation weight corresponding to each client is calculated by a preset aggregation function; Acquire at least one second parameter of at least one other client among the plurality of clients except the at least one target client; Aggregating at least one first parameter and at least one second parameter based on the aggregation weight to generate a third parameter of a new global network traffic attack detection model; The third parameter is sent to each client.

8. The method according to any one of claims 1 to 7, characterized in that The preset aggregation function is: Among them, the above G is the aggregation weight, the above B is the historical average contribution of each client in updating the local model parameters in previous rounds; the above x is the first number of data in the target attack traffic data set; and the above k is the second number of clients participating in the training.

9. A network traffic attack detection system, characterized in that: include: Central server; Client processor; Memory; as well as One or more programs, wherein the one or more programs are stored in a memory and are configured to be executed by the central server and / or client processor, the programs causing the computer to execute the steps of the training method of the network traffic attack detection model as described in any one of claims 1 to 8.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the training method of the network traffic attack detection model as described in any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Network intrusion detection method based on data enhancement and self-supervised feature enhancement

    CN114978613A

  • Network attack federal detection method and system under non-uniform Gaussian distribution

    CN117834290A

  • Internet of Things intrusion detection method, system and equipment

    CN118250042A

  • Method and device for identifying unknown traffic data based dynamic network environment

    US11658989B1