Training method, system and medium for network traffic attack detection model

By using a federated learning framework to perform data augmentation and global parameter aggregation on the client side, the problem of client-side data silos is solved, the accuracy and robustness of network attack detection are improved, and data privacy is protected.

CN119966660BActive Publication Date: 2025-09-23NORTHEASTERN UNIV CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411960753.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-09-23
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

The problem of client-side data silos leads to low attack detection accuracy of server-trained network attack detection models when applied to client applications.

Method used

The federated learning framework is adopted. The client obtains attack traffic data of unidentified attack types, performs data augmentation, and sends the updated model parameters to the central server. The central server generates global model parameters based on aggregated weights and distributes them to each client for updates.

Benefits of technology

It improves the ability of various regulatory nodes to identify unknown network traffic attacks, enhances the accuracy and robustness of network traffic attack detection, and protects data privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966660B_ABST
    Figure CN119966660B_ABST
Patent Text Reader

Abstract

The present invention discloses a training method, system and medium for a network traffic attack detection model, comprising: at least one target client obtains a target attack traffic data set; each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set; a central server calculates an aggregation weight using a preset aggregation function to aggregate at least one first parameter and the second parameters of other clients participating in the training; each client updates the local network traffic attack model based on the received third parameter. Through the above method, each supervisory node can learn the detected new network traffic attack method in a timely manner, greatly improving the network traffic attack detection and defense capabilities of each supervisory node while effectively protecting the data privacy of the supervisory node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a training method, system and medium for a network traffic attack detection model. Background Art

[0002] Currently, network attack detection based on machine learning and deep learning utilizes the powerful data analysis and learning capabilities of intelligent algorithms and is considered to be an effective method for network attack detection. However, due to data privacy considerations, there are data silos between client data, which leads to low attack detection accuracy when the network attack detection model trained on the server is applied on the client. Summary of the Invention

[0003] The present invention provides a training method, system and medium for a network traffic attack detection model to solve the technical problem of low attack detection accuracy when the network attack detection model trained on the server is applied on the client due to the existence of data islands between client data.

[0004] In a first aspect, a method for training a network traffic attack detection model is provided, using a network traffic attack detection system, wherein the network traffic attack detection system includes a central server and multiple clients, the central server being in communication with each client, the method comprising:

[0005] At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified;

[0006] Each target client performs data enhancement on the target attack traffic data set using a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first quantity of the target attack traffic data set to the central server;

[0007] The central server calculates an aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to the multiple clients;

[0008] Each client updates the local network traffic attack model based on the received third parameter.

[0009] In a second aspect, a network traffic attack detection system is provided, comprising a central server; a client processor; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the central server and / or the client processor, and the programs enable the central server and / or the client processor to execute the steps of the above-mentioned training method of the network traffic attack detection model.

[0010] In a third aspect, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, the steps of the training method of the above-mentioned network traffic attack detection model are implemented.

[0011] In the solution implemented by the training method, system, and storage medium of the above-mentioned network traffic attack detection model, attack traffic data of unidentified attack types in any supervisory node is obtained and data enhancement processing is performed on it. Based on the enhanced unknown attack traffic as a sample, the parameters of the local traffic detection model are updated, and the updated model parameters are sent to the central server, so that the central server updates the global traffic detection model based on the received local model parameters. Through the above-mentioned method, network intrusion detection is performed based on the federated learning architecture, so that each supervisory node can simultaneously achieve real-time monitoring of unknown traffic attacks and training and updating of local attack detection local models. In addition, the central server determines the corresponding weights based on the training effect of the local model, aggregates the multiple local model parameters obtained by training according to the weights, and then sends the aggregated model parameters to each supervisory node, so that each supervisory node can learn the detected new network traffic attack methods in a timely manner. This satisfies the migration identification ability of each supervisory node for unknown attack types in network traffic data, greatly improves the network traffic attack detection and defense capabilities of each supervisory node, and effectively protects the data privacy of the supervisory node. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0013] Figure 1 1 is a flow chart of a method for training a network traffic attack detection model according to an embodiment of the present invention;

[0014] Figure 2 1 is a schematic diagram of the function change of the weight aggregation function during the global model parameter update process in one embodiment of the present invention;

[0015] Figure 3 This is a schematic block diagram of a parameter contingency process for unidentified pattern traffic and normal traffic in parameter aggregation in one embodiment of the present invention;

[0016] Figure 4 It is a schematic block diagram of enhancing target attack traffic data in one embodiment of the present invention. DETAILED DESCRIPTION

[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0018] The training method of the network traffic attack detection model provided by the present invention can be applied to malicious traffic detection and network attack traffic detection scenarios in the field of modern network security. Specifically, with the gradual advancement of network technology and the increasing attention paid to data privacy, the level of attention paid to malicious traffic detection and network attack traffic detection technology in the field of modern network security has also increased. In the current network environment, attackers may use a variety of technical means to launch attacks, causing huge losses to enterprises or individuals, such as the leakage of commercial secrets or the collapse of customer trust. With the continuous complexity of network attack patterns, timely detection and processing of malicious traffic has become a key task to protect user privacy and maintain system security. Therefore, establishing an efficient traffic detection mechanism has far-reaching strategic significance for identifying and preventing network traffic attacks.

[0019] Numerous studies have been conducted on malicious traffic detection and network attack traffic detection, including network threat detection (NTA), full-flow threat analysis solutions, and deep learning-based encrypted malicious traffic detection. Network threat detection is an emerging encrypted traffic detection technology that combines rule-based detection with machine learning methods, analyzing encrypted traffic through deep packet inspection (DPI) and deep / dynamic flow inspection (DFI). This approach is often used to detect suspicious behavior within enterprise networks. Full-flow threat analysis solutions rapidly identify potential threats within network traffic by collecting, parsing, and storing full traffic, combined with threat intelligence and machine learning algorithms. This approach can retrospectively analyze historical events, accurately understanding the process and impact of events, and providing effective security protection. Research on encrypted malicious traffic detection based on deep learning suggests that with the increasing amount of encrypted traffic in current network environments and the continuous advancement of existing traffic encryption technologies, traditional traffic detection methods (such as DPI) are no longer suitable. Deep learning, on the other hand, can automatically learn features from raw data and adapt to different network environments, making deep learning-based methods ideally suited for encrypted traffic detection. In practical applications, researchers proposed a system called HyperVision, an unsupervised real-time malicious traffic detection system. It detects unknown malicious encrypted traffic patterns using a compact memory graph based on traffic patterns. However, this compact memory graph no longer focuses on the characteristics of specific known attacks, as in previous research, but instead represents all captured traffic interaction patterns in the form of graph-structured features. After generating the compact memory graph, it analyzes the graph's connectivity, sparsity, and statistical characteristics to detect a variety of encrypted attack traffic without requiring any datasets containing known attacks. The researchers also developed an information-theoretic model to demonstrate that the information preserved by the compact memory graph approaches existing theoretical bounds. Experiments show that HyperVision achieves an AUC of at least 0.92 and an F1 of 0.86 on 92 datasets, a detection throughput of at least 80.6 Gb / s, and an average detection latency of 0.83 seconds. These performance figures significantly outperform existing methods. Furthermore, HyperVision detects over 50% of attacks that evade all existing methods.

[0020] However, while existing research has achieved considerable success in identifying encrypted traffic attacks, rapid detection and knowledge collaboration for unknown malicious traffic remain relatively underdeveloped. Existing methods for detecting malicious encrypted traffic are typically supervised and rely on prior knowledge of known attacks. They can only detect attacks with known traffic patterns, but struggle to detect the broader range of unknown encrypted traffic attacks. Furthermore, after a new encrypted traffic attack emerges, it is often difficult for the victim to respond promptly, even if the attack may have already occurred on nearby endpoints.

[0021] To address the above issues, the present invention provides a method for training a network traffic attack detection model. This method builds a global model and local models based on a federated learning framework. The method uses newly emerging unknown attack traffic from various locations to adjust the training weights of the global model, enabling the global model to promptly learn new network traffic attack methods that have been detected. Ultimately, the distributed training data is aggregated and distributed to each domain after aggregation. This improves the performance of each domain's local model in identifying cross-domain malicious traffic, resolves the data silo problem in each domain, and improves the accuracy and robustness of malicious traffic detection.

[0022] See also Figure 1 As shown, Figure 1 A flowchart of a method for training a network traffic attack detection model provided by an embodiment of the present invention includes the following steps:

[0023] S10: At least one target client obtains a target attack traffic dataset;

[0024] The target client is the client that is attacked, and the target attack traffic data set includes attack traffic data whose attack type is not identified;

[0025] In this step, the target client refers to the client that is detected to be attacked by malicious traffic of unknown attack type; the target attack traffic data refers to the attack traffic data of unidentified attack type.

[0026] It can be understood that the executor of the present invention can be a network traffic attack detection system. Specifically, the system includes a central server and multiple clients. The central server is communicated with each client. A global model of the network traffic attack detection model is pre-constructed on the central server, and a local model of the network traffic attack detection model is constructed on each client. The local model of the client has the same network structure as the global model of the central server.

[0027] In this step, a client of at least one domain attacked by malicious traffic obtains target attack traffic data whose attack type cannot be identified.

[0028] In actual application scenarios, network attacks are usually divided into two types: continuous attacks and discontinuous attacks. Some attackers also combine the characteristics of continuous attacks and discontinuous attacks to launch real-time hybrid attacks. Therefore, when a new type of unknown attack is detected, the target client attacked by malicious traffic can summarize the unknown attack type traffic data within a specified time period to generate a target attack traffic data set.

[0029] In one embodiment of the present application, a specific solution for obtaining target attack traffic data is provided. In S10, at least one target client obtains a target attack traffic data set, which specifically includes the following steps S11-S15:

[0030] S11: For any client, obtain multiple network traffic data of multiple target nodes in the target domain;

[0031] In this step, for any client, the network traffic data flowing through each network node (ie, target node) captured in real time in the target domain corresponding to the client is obtained.

[0032] S12: Using the local network traffic attack detection model corresponding to the client, determine whether the network traffic data of each target node is abnormal traffic data, and proceed to step S13. If not, return to step S11;

[0033] In this step, the local network traffic attack detection model is a local model based on network traffic attack detection constructed by the client by introducing federated learning, which is used to distinguish whether the traffic flowing through each node is normal traffic behavior or abnormal traffic behavior. After capturing the real-time traffic of any network node, it is detected using the local network traffic attack detection model, and based on the detection results, it is determined whether it is normal traffic behavior. If it is normal traffic behavior, continue to capture real-time traffic; if it is abnormal traffic behavior, it is necessary to determine the attack type of the abnormal traffic. In one embodiment of the present application, a specific abnormal traffic data detection scheme is provided. In S12, that is, the local network traffic attack detection model corresponding to the client is used to determine whether the network traffic data of each target node is abnormal traffic data, which specifically includes the following steps S121-S122:

[0034] S121: Extract features from the network traffic data of each target node to obtain traffic features;

[0035] S122: Input the traffic characteristics into the local network traffic attack detection model to determine abnormal traffic data.

[0036] In steps S121-S122, the captured traffic data is parsed to extract key traffic features that can identify malicious behavior (such as traffic time series characteristics, packet size distribution, protocol anomalies, etc.). The extracted traffic features are then input into the local network traffic attack detection model to obtain detection results and determine whether the network traffic data is abnormal.

[0037] In actual application scenarios, by introducing federated learning, a local model based on the network traffic attack detection model is pre-deployed on each node domain. This model should have the ability to quickly learn and adapt to new attack patterns. Considering the complexity of the cross-domain environment and the characteristics of the edge nodes themselves, the local model may be designed with lightweight and easy to update as the focus. Subsequently, multiple rounds of local training are performed based on the existing local attack dataset. After each round of training, the parameters are updated according to the performance of the model on the local data. After the basic training is completed, the model structure is fine-tuned based on the model's performance on the cross-domain malicious traffic identification dataset and the new attack pattern reinforcement dataset. Specific regularization techniques are introduced to prevent overfitting on a small scale, so as to implement additional personalized training steps for the model to better adapt to the network environment and specific attack patterns of the running tasks.

[0038] S13: When it is determined that the network traffic data of any target node is abnormal traffic data, the client is determined to be a target client, and target traffic characteristics of the abnormal traffic data are obtained;

[0039] S14: Based on the target traffic characteristics, determine whether the abnormal traffic data is target attack traffic data.

[0040] For steps S13-S14, when it is determined that the network traffic data of any target node is abnormal traffic data, the client of the node domain is marked as the target client, and the target traffic characteristics of the abnormal traffic data are obtained. Based on the target traffic characteristics, it is determined whether the attack type of the abnormal traffic data is determined to determine whether the abnormal traffic data is target attack traffic data.

[0041] In one embodiment of the present application, a specific target attack traffic data determination solution is provided. In S14, based on the target traffic characteristics, determining whether the abnormal traffic data is the target attack traffic data specifically includes the following steps S141-S142:

[0042] S141: Determine whether the attack type of the abnormal traffic data can be identified based on the target traffic characteristics and a preset attack database;

[0043] The preset attack database is composed of a variety of known attack types and their corresponding traffic characteristics;

[0044] S142: If the attack type of the abnormal traffic data cannot be identified, mark the abnormal traffic data as the target attack traffic data.

[0045] In steps S141-S142, for any abnormal traffic data, the target traffic characteristics of the abnormal traffic data are compared with the preset attack database to determine whether the preset attack database contains the attack type of the abnormal traffic data. If the preset attack database contains the attack type of the abnormal traffic data, it means that the attack traffic flowing through the node is a known attack behavior. At this time, the attack traffic related data is recorded and the process returns to step S11 to continue capturing real-time network traffic. If the attack type of the abnormal traffic data is not found in the preset attack database, it means that the abnormal traffic data is a new type of unknown attack traffic. At this time, the abnormal traffic data is marked as target attack traffic data.

[0046] Optionally, a preset attack database is constructed in advance based on the attack types of malicious traffic data with all current cross-domain characteristics and their corresponding abnormal traffic characteristics, so that the database covers various types of attack modes, such as DDoS, port scanning, malware propagation, etc.

[0047] In one embodiment of the present application, a specific preset database update solution is provided. After S142, that is, after marking the abnormal traffic data as target attack traffic data, the following steps S143-S144 are also included:

[0048] S143: Determine the attack type of the abnormal traffic data based on the traffic characteristics of the abnormal traffic data;

[0049] S144: Based on the traffic characteristics and attack types of the abnormal traffic data, a preset attack database is updated.

[0050] For steps S143-S144: analyze the key features extracted from the abnormal traffic data to confirm the characteristics and behavior patterns of the abnormal traffic data, and use an expert system or knowledge base to infer the attack type based on the characteristics and behavior patterns. In addition, in order to ensure the accuracy of the attack type inference, the inferred attack type can also be manually reviewed. Finally, the preset attack database is updated based on the characteristic data of the abnormal traffic and the inferred attack type to improve the timeliness and accuracy of the preset attack database. S20: Each target client performs data enhancement on the target attack traffic data set through a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and the target attack traffic data set to the central server;

[0051] In this step, for any target client in a node domain that is attacked by an unknown type of malicious traffic, if the unknown type of malicious traffic is detected, it indicates that the attacker may have exploited unknown vulnerabilities or techniques to launch an attack. At this time, it is necessary to use the target attack traffic data to update the parameters of the local model on the target client. However, attackers usually attack through zero-day attacks, sudden abnormal attacks, etc. If the parameters are directly updated using at least one detected target attack traffic data, the sample size is small, which may affect the generalization ability of the model. In order to improve the accuracy of the model parameter update, it is necessary to first perform data enhancement on the data in the target attack traffic dataset to obtain a diverse enhanced attack sample set so that the sample data can cover more attack types and attack methods.

[0052] Specifically, a preset data augmentation model is used to enhance the data in the target attack traffic dataset, generating an enhanced attack sample set. The enhanced attack sample set is then used to update the parameters of the target client's local model, generating updated first parameters. The first parameters and the target attack traffic dataset are then sent to a central server.

[0053] Optionally, based on pre-requirements (focusing on data augmentation for identified new attack patterns), a LoRa model suitable for processing time series data is selected as the pre-set data augmentation model. This model is then customized based on the characteristics of cross-domain malicious traffic. By adjusting the model's depth and width or introducing an attention mechanism, the model can be tailored to capture traffic patterns and adapt to the task of detecting cross-domain malicious traffic. Furthermore, in addition to targeted changes to the model architecture, the LoRa model is pre-trained using an existing database during pre-training and fine-tuning. It should be noted that because the training focuses on the model's generalization ability in cross-domain environments, the pre-training process does not focus on the ultimate optimization of a single performance metric or short-term training results. During fine-tuning, however, special attention is paid to the model's ability to identify new, unknown attacks. Similarly, during model validation and iteration, model performance is tested on an independent validation set, focusing on its accuracy and response time in identifying unknown cross-domain attack traffic.

[0054] Through the above methods, data enhancement technology is used to enrich the diversity of training samples to cope with complex and changeable malicious traffic, which can help the model better capture potential attack features in attack traffic and improve the model's ability to identify unknown attack traffic.

[0055] In one embodiment of the present application, a specific training scheme for a local network traffic attack detection model is provided. In S20, each target client performs data enhancement on a target attack traffic dataset using a pre-trained data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter. The first parameter and the target attack traffic dataset are sent to a central server. The scheme specifically includes the following steps S21-S25:

[0056] S21: For any target client, data in the target attack traffic dataset is enhanced using a preset data enhancement model to obtain an enhanced attack sample set;

[0057] S22: Obtain a historical attack sample set corresponding to the target client;

[0058] S23: Generate a training dataset based on the enhanced attack sample set and the historical attack sample set;

[0059] In steps S21-S23, for any target client, the data in the target attack traffic dataset is enhanced using a preset data enhancement model to obtain an enhanced attack sample set. A historical attack sample set corresponding to the target client is obtained, where the historical attack sample set is an existing attack sample set. The enhanced attack sample set is combined with the existing attack sample set to construct a training dataset.

[0060] Through the above method, the new attack sample set is combined with the existing attack sample set to construct a training data set to enhance the learning ability and adaptability of the model.

[0061] S24: Train a local network traffic attack detection model of the target client based on the training data set to obtain a first parameter.

[0062] In this step, the training data set is used to update the parameters of the local model to obtain the updated first parameters.

[0063] S25: Send the first parameter and the target attack traffic data set to the central server.

[0064] In this step, by introducing federated learning, a global model with the same network structure as the local model is pre-built on the central server. In order to enable other domains to quickly detect new attack behaviors, the updated first parameter and target attack traffic dataset are sent to the central server for update aggregation.

[0065] S30: The central server calculates the aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and the second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to multiple clients.

[0066] In this step, the central server obtains the second number of clients participating in this round of training and each client's historical average contribution. Based on the first number, the second number, and the historical average contribution, the central server dynamically adjusts the training weight of each client using a preset aggregation function. The central server then aggregates the model parameters of all clients based on the calculated weights to generate a new global model. The third parameters of the new global model are then sent to each client.

[0067] In one embodiment of the present application, a specific global parameter contingency aggregation scheme is provided. In S30, the central server calculates an aggregation weight for each client based on a first number, a second number of clients participating in training, and a historical average contribution using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in training based on the aggregation weight to generate a third parameter. The third parameter is sent to multiple clients, specifically including the following steps S31-S35:

[0068] S31: The central server obtains a second number of the plurality of clients participating in the training and a historical average contribution of each client;

[0069] S32: Calculate an aggregation weight corresponding to each client based on the first quantity, the historical average contribution, and the second quantity using a preset aggregation function;

[0070] S33: Obtain at least one second parameter of at least one other client among the multiple clients except the at least one target client;

[0071] S34: Aggregate the at least one first parameter and the at least one second parameter based on the aggregation weight to generate a third parameter of a new global network traffic attack detection model;

[0072] S35: Send the third parameter to each client.

[0073] For steps S31-S35, a second number of the multiple clients participating in the current training round and the historical average contribution of each client in previous training rounds are obtained. Subsequently, the first number, the second number, and the historical average contribution are input into a preset aggregation function to calculate an aggregate weight for each client. Then, at least one second parameter of at least one other client participating in the current training round, excluding the multiple target clients, is obtained. Based on the aggregate weight, the at least one first parameter and the at least one second parameter are aggregated to generate a new global network traffic attack detection model, and the third parameter of the new global model is sent to each client.

[0074] Optionally, the preset aggregation function is:

[0075]

[0076] Wherein, G is the aggregation weight, B is the historical average contribution of each client in updating local model parameters in previous rounds, x is the first number of data in the target attack traffic dataset, and k is the second number of clients participating in training.

[0077] In actual application scenarios, it can react quickly in the initial stage (i.e., the first number of unidentified traffic increases from zero) and quickly increase the weight of the target domain in the parameter aggregation stage. When attacks are frequent (i.e., the first number of unidentified traffic is large), it can ensure that the parameters of other domains will not be swallowed up during aggregation due to the excessive weight of the attacked domain, thereby avoiding the abnormally high weight of the frequently attacked domain during parameter aggregation. Figure 2 Figure 1 shows a schematic diagram of the weight aggregation function's function changes, with the horizontal axis representing the number of iterations and the vertical axis representing the number of clients participating in training. Table 1 shows the numerical changes in the weight aggregation function, demonstrating its excellent ability to adjust the parameters and weights of the second traffic detection model and achieve unknown traffic migration.

[0078] Table 1

[0079]

[0080] Through the above approach, local data augmentation and global parameter contingency aggregation improve the accuracy and response speed of model detection, reducing reliance on centralized data processing. Node augmentation balances the importance of parameters passed in by each device domain participating in training. This not only considers the contribution of nodes in that domain to the training of the network traffic attack detection model during previous training, but also ensures that the impact of emerging network traffic patterns on the training of the overall network traffic attack detection model is considered, thereby enhancing the model's detection and response capabilities for new network traffic attacks, improving detection accuracy and robustness.

[0081] S40: Each client updates the local network traffic attack model based on the received third parameter.

[0082] In this step, each client receives the third parameter sent by the central server and updates its local network traffic attack detection model based on the third parameter. This improves the performance of each client in identifying cross-domain traffic, allowing each domain to promptly detect unknown attack traffic discovered by other domains, significantly enhancing the security of each domain's nodes.

[0083] It can be seen that in the above scheme, attack traffic data of unidentified attack types in any supervisory node is obtained and data enhancement processing is performed on it. Based on the enhanced unknown attack traffic as a sample, the parameters of the local traffic detection model are updated, and the updated model parameters are sent to the central server, so that the central server updates the global traffic detection model based on the received local model parameters. Through the above method, network intrusion detection is performed based on the federated learning architecture, so that each supervisory node can simultaneously realize real-time monitoring of unknown traffic attacks and training and updating of local attack detection local models. In addition, the central server determines the corresponding weights based on the training effect of the local model, aggregates the multiple local model parameters obtained through training according to the weights, and then sends the aggregated model parameters to each supervisory node, so that each supervisory node can learn the detected new network traffic attack methods in a timely manner. It satisfies the migration identification ability of each supervisory node for unknown attack types in network traffic data, greatly improves the network traffic attack detection and defense capabilities of each supervisory node, and effectively protects the data privacy of the supervisory node.

[0084] In one embodiment, a network traffic attack detection system is provided, comprising a central server; a client processor; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the central server and / or the client processor, and the programs cause the central server and / or the client processor to implement the following steps when executing the computer program:

[0085] At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified;

[0086] Each target client performs data enhancement on the target attack traffic data set using a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first quantity of the target attack traffic data set to the central server;

[0087] The central server calculates an aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to the multiple clients;

[0088] Each client updates the local network traffic attack model based on the received third parameter.

[0089] In actual application scenarios, the network traffic attack detection system proposed in this application includes a network traffic attack detection and classification device, a local sample enhancement device for unknown traffic, and a global parameter contingency aggregation device. Among them, the network traffic attack detection and classification device is used to perform attack detection on the network traffic flowing through the edge node based on a preset attack database, and to identify and classify the network traffic attack based on its characteristic manifestations. Figure 3 As shown in FIG, it is a schematic diagram of the parameter contingency process of unidentified pattern traffic (i.e., target attack traffic data) and normal traffic in parameter aggregation. The local sample enhancement device of unknown traffic is used to enhance and generalize the data samples of the identified new network traffic attack mode by using the data sample enhancement method based on the large model locally in each domain node, and the generated data samples are combined with the original classified attack samples to construct the network traffic attack training data set. Figure 4The figure shows a schematic block diagram for enhancing target attack traffic data. A unified unknown traffic input is divided into normal traffic and unknown attack pattern traffic after passing through a network traffic attack detection and classification device. After classification, the unknown traffic is input into a local sample enhancement device for data sample enhancement to generate a comprehensive enhanced dataset. A global parameter contingency aggregation device is used to adjust the model's training weights based on the data set returned by each node, the new attack detection status of each node, and the model's historical training status, so that the entire model can promptly learn the detected new network traffic attack methods. Finally, the distributed training data is finally aggregated and distributed to each domain after aggregation, so that nodes in each domain can promptly learn the detected new network traffic attack methods. In this application, for nodes in any domain, when unknown network traffic flows locally to the node, a capture tool is used to capture the raw traffic. The local client extracts features from the captured raw traffic within a data slice cycle. The feature analysis is performed using a local attack detection model constructed by the local client to quickly identify normal or abnormal traffic. When the traffic is determined to be abnormal, its key features are compared with an existing attack database to identify potential new attacks. The identified new attack traffic is sampled and collected to obtain new attack traffic samples. If the new attack traffic samples are successfully collected, the characteristic information of the identified new attack traffic is stored, a new attack type is generated for it, and this information is promptly fed back to the local sample enhancement device for unknown traffic for subsequent sample generation and model updates. Otherwise, the process proceeds to the next time segment and repeats the above steps. Furthermore, the new attack traffic samples are input into a pre-trained sample enhancement model, and the reinforcement learning method of the large model is used to enhance and generalize the data samples, resulting in an enhanced sample set. The enhanced sample set is combined with the existing attack sample set to construct a training dataset to enhance the model's learning ability and adaptability. At specified time intervals, the training dataset is used to update the parameters of the local attack detection model and the updated local model parameters are fed back to the central server. The central server receives the updated local model parameters from each local client to ensure a comprehensive understanding of the status of each domain. Based on the contribution of each node and the model's historical training, the global model aggregation function G is used to dynamically adjust the training weights to optimize the model's training performance. The training data of all nodes is aggregated to generate updated global model parameters. The parameters of the new global model are distributed to each local client, enabling it to quickly adapt and effectively respond to new attacks. The weight aggregation function G is:

[0090]

[0091] Wherein, G is the aggregation weight, B is the historical average contribution of each client in updating local model parameters in previous rounds, x is the first number of data in the target attack traffic dataset, and k is the second number of clients participating in training.

[0092] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0093] At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified;

[0094] Each target client performs data enhancement on the target attack traffic data set using a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first quantity of the target attack traffic data set to the central server;

[0095] The central server calculates an aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to the multiple clients;

[0096] Each client updates the local network traffic attack model based on the received third parameter.

[0097] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can be found in the relevant descriptions of the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.

[0098] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0099] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0100] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A training method for a network traffic attack detection model, characterized in that: Applied to a network traffic attack detection system, wherein the network traffic attack detection system includes a central server and multiple clients, the central server is in communication with each client, and the method includes: At least one target client obtains a target attack traffic data set, wherein the target client is a client under attack, and the target attack traffic data set includes attack traffic data of which the attack type is not identified; Each target client performs data enhancement on the target attack traffic data set using a preset data enhancement model to obtain an enhanced attack sample set, and updates the parameters of the target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sends the first parameter and a first quantity of the target attack traffic data set to the central server; The central server calculates an aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; and sends the third parameter to the multiple clients; Each client updates the local network traffic attack model based on the received third parameter; The preset aggregation function is: Wherein, G is the aggregation weight, B is the historical average contribution of each client in updating local model parameters in previous rounds, x is the first number of data in the target attack traffic dataset, and k is the second number of clients participating in training.

2. The method according to claim 1, characterized in that The step of at least one target client obtaining a target attack traffic data set specifically includes: For any client, obtain multiple network traffic data of multiple target nodes in the target domain; Use the local network traffic attack detection model corresponding to the client to determine whether the network traffic data of each target node is abnormal traffic data; When it is determined that the network traffic data of any target node is abnormal traffic data, the client is determined to be a target client, and target traffic characteristics of the abnormal traffic data are obtained; Based on the target traffic characteristics, determine whether the abnormal traffic data is target attack traffic data.

3. The method according to claim 2, characterized in that The step of using the local network traffic attack detection model corresponding to the client to determine whether the network traffic data of each target node is abnormal traffic data specifically includes: Performing feature extraction on the network traffic data of each target node to obtain traffic features; The traffic characteristics are input into the local network traffic attack detection model to determine abnormal traffic data.

4. The method according to claim 2, characterized in that The step of determining whether the abnormal traffic data is target attack traffic data based on the target traffic characteristics specifically includes: Determining whether an attack type of the abnormal traffic data can be identified based on the target traffic characteristics and a preset attack database, wherein the preset attack database is composed of multiple known attack types and their corresponding traffic characteristics; If the attack type of the abnormal traffic data cannot be identified, the abnormal traffic data is marked as the target attack traffic data.

5. The method according to claim 4, characterized in that After marking the abnormal traffic data as the target attack traffic data, the method further includes: Determine the attack type of abnormal traffic data based on its traffic characteristics; Based on the traffic characteristics and attack types of abnormal traffic data, the preset attack database is updated.

6. The method according to claim 1, characterized in that The steps of each target client performing data enhancement on a target attack traffic dataset using a pre-trained data enhancement model to obtain an enhanced attack sample set, updating a parameter of a target local network traffic attack detection model based on the enhanced attack sample set to obtain a first parameter, and sending the first parameter and a first quantity of the target attack traffic dataset to a central server specifically include: For any target client, the data in the target attack traffic dataset is enhanced through the preset data enhancement model to obtain an enhanced attack sample set; Obtain the historical attack sample set corresponding to the target client; Generate a training dataset based on the enhanced attack sample set and the historical attack sample set; Training a local network traffic attack detection model of the target client based on the training data set to obtain the first parameter; The first parameter and the target attack traffic data set are sent to the central server.

7. The method according to claim 1, characterized in that The central server calculates an aggregation weight of each client based on the first number, the second number of clients participating in the training, and the historical average contribution using a preset aggregation function, and aggregates at least one first parameter and second parameters of other clients participating in the training based on the aggregation weight to generate a third parameter; The step of sending the third parameter to multiple clients specifically includes: The central server obtains a second number of the plurality of clients participating in the training and a historical average contribution of each client; Calculate the aggregation weight corresponding to each client based on the first quantity, the historical average contribution, and the second quantity using a preset aggregation function; Obtaining at least one second parameter of at least one other client among the plurality of clients except the at least one target client; Aggregating at least one first parameter and at least one second parameter based on the aggregation weight to generate a third parameter of a new global network traffic attack detection model; The third parameter is sent to each client.

8. A network traffic attack detection system, characterized in that: include: Central server; Client processor; Memory; as well as One or more programs, wherein the one or more programs are stored in a memory and configured to be executed by the central server and / or client processor, the programs causing the central server and / or client processor to perform the steps of the method for training a network traffic attack detection model as described in any one of claims 1 to 7.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the training method of the network traffic attack detection model as claimed in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Network attack federal detection method and system under non-uniform Gaussian distribution

    CN117834290A

  • Internet of Things intrusion detection method, system and equipment

    CN118250042A