Flow detection and analysis method and device and flow detection and analysis system
By building and processing network flow collections, training the LSTM model and deploying it to satellites, the problem of inaccurate network traffic anomaly detection in the prior art is solved, accurate identification and interception of abnormal traffic is achieved, and network security is improved.
Patent Information
- Application Number
- CN202510180893.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-09
AI Technical Summary
In the prior art, the detection of network traffic abnormalities is inaccurate, resulting in data leakage and damage to the satellite network.
By building a collection of network flows, performing tensor conversion, training the LSTM neural network model, obtaining anomaly traffic detection model, and deploying it to the satellite's detection module to identify and intercept anomaly traffic.
It improves the accuracy of network traffic anomaly detection, prevents potential network attacks, and enhances the anti-attack and damage resistance capabilities of the integrated aerospace and earth network.
Smart Images

Figure CN119966741A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of satellite network security, and in particular to a flow detection and analysis method, device, computer-readable storage medium, computer program product and flow detection and analysis system. Background Art
[0002] Unlike the traditional Internet, the integrated space-air-ground network has the characteristics of open channels, highly variable topology, and mutually compatible protocols. Because of these characteristics, the security situation it faces is more severe than that of a single-structure network. At the Global Satellite Cybersecurity Summit in November 2019, some experts believed that cyber attacks could paralyze or hijack satellites on a large scale, or even use satellites as attack "amplifiers" to launch larger-scale attacks on the ground. The TCP / IP network structure will be used in the integration of space-air-ground, so it is vulnerable to security threats such as malicious propagation of false information at the application layer; vulnerable to routing tampering, port scanning, DDoS and other attacks at the network layer and transport layer; vulnerable to security threats such as data eavesdropping and interception at the link layer; vulnerable to cosmic noise, lunar eclipses, solar eclipse interruptions, and even malicious destruction by other countries at the physical layer.
[0003] Therefore, it is of great significance to deploy an effective security situation awareness system in the integration of air, space and land. Network traffic anomaly detection, as an extremely important part of the security situation awareness system, plays a role in maintaining the security of the entire network. Therefore, network traffic anomaly detection is selected for research. Network traffic anomaly detection can identify, analyze and understand the traffic data in the network, discover or predict whether the network will be attacked, and then take relevant rescue measures to minimize the losses caused by data leakage, damage and loss caused by the attack, and improve the anti-attack and anti-damage capabilities of air, space and land integration. The existing network traffic anomaly detection methods may not be able to effectively detect network attacks caused by abnormal traffic, which may cause data leakage and damage to the satellite network. Summary of the invention
[0004] The main purpose of the present application is to provide a traffic detection and analysis method, device, computer-readable storage medium, computer program product and traffic detection and analysis system to at least solve the problem of inaccurate detection of network traffic anomalies in the prior art.
[0005] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a traffic detection and analysis method is provided, including: constructing a network flow set, the network flow set including a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data including a normal traffic label and an abnormal traffic label; performing tensor conversion on each of the data packet sequences in the network flow set to obtain a network flow tensor set, the network flow tensor set including a plurality of network flow tensors with the label data, the network flow tensors corresponding one-to-one to the data packet sequences; using the network flow tensor set to train an LSTM neural network model to obtain an abnormal traffic detection model; deploying the abnormal traffic detection model to a detection module of a satellite, and intercepting the abnormal traffic when the satellite detects abnormal traffic to prevent potential network attacks.
[0006] Optionally, constructing a network flow set includes: acquiring all data packets within a historical time period in the network to obtain a data packet set, wherein the data packet includes five-tuple information, a start time and load information, wherein the start time is the time point when the data packet is first recorded during the transmission process, and the load information is the actual data content of the network communication contained in the data packet; dividing all data packets in the data packet set according to a predetermined time interval to obtain data packet subsets corresponding to multiple different time periods; dividing the data packets with the same five-tuple information in each of the data packet subsets into a group to obtain multiple data packet groups; splicing the load information of all the data packets in each of the data packet groups in the chronological order of the start time to obtain the network flow set, wherein the network flow set includes the data packet sequence corresponding to each of the data packet groups, and the data packet sequence corresponds one-to-one to the number of different five-tuple information in the data packet subset.
[0007] Optionally, each of the data packet sequences in the network flow set is converted into a tensor to obtain a network flow tensor set, including: performing length unification processing on the payload information corresponding to each of the data packet sequences in the network flow set to obtain a fixed-length network flow set, wherein the length unification processing is to truncate or fill in zeros on the payload information; and performing tensor quantization processing on each of the data packet sequences in the fixed-length network flow set to obtain the network flow tensor set.
[0008] Optionally, the network flow tensor set is used to train the LSTM neural network model to obtain an abnormal traffic detection model, including: using a one-dimensional convolutional neural network as an encoder of the LSTM neural network model, and constructing a network symmetrical to the one-dimensional convolutional neural network structure as a decoder of the LSTM neural network model; inputting each of the network flow tensors with the normal traffic label in the network flow tensor set into the encoder for data compression to obtain a first encoding vector, and inputting each of the network flow tensors with the abnormal traffic label in the network flow tensor set into the encoder for data compression to obtain a second encoding vector; inputting each of the first encoding vectors into the decoder, and the decoder performs vector reconstruction according to each of the first encoding vectors to obtain a first decoding vector corresponding to each of the first encoding vectors. vector, input each second coding vector into the decoder, the decoder performs vector reconstruction according to each second coding vector to obtain a second decoding vector corresponding to each second coding vector; use each first coding vector and the first decoding vector corresponding to each first coding vector, each second coding vector and the second decoding vector corresponding to each second coding vector to train the LSTM neural network model until the first loss function converges downward and the second loss function converges upward, so as to obtain the abnormal traffic detection model, the first loss function is used to calculate the loss between each first coding vector and each first decoding vector corresponding to each first coding vector, and the second loss function is used to calculate the loss between each second coding vector and each second decoding vector corresponding to each second coding vector.
[0009] Optionally, each of the network flow tensors with the normal traffic label in the network flow tensor set is input into the encoder for data compression to obtain a first encoding vector, and each of the network flow tensors with the abnormal traffic label in the network flow tensor set is input into the encoder for data compression to obtain a second encoding vector, and also includes: performing noise processing on each of the network flow tensors with the normal traffic label and each of the network flow tensors with the abnormal traffic label, and adding each of the noise-processed network flow tensors to the network flow tensor set.
[0010] Optionally, the abnormal traffic detection model is deployed to a detection module of a satellite, and when the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks, including: sending the abnormal traffic detection model to the satellite for model deployment; regularly sampling user traffic received by the abnormal traffic detection model of the satellite, and using the user traffic to optimize and train the abnormal traffic detection model.
[0011] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a traffic detection and analysis device is provided, comprising: a construction unit, used to construct a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal traffic label and an abnormal traffic label; a processing unit, used to perform tensor conversion on each of the data packet sequences in the network flow set to obtain a network flow tensor set, the network flow tensor set comprising a plurality of network flow tensors with the label data, the network flow tensors corresponding one-to-one to the data packet sequences; a training unit, used to train an LSTM neural network model using the network flow tensor set to obtain an abnormal traffic detection model; and a control unit, used to deploy the abnormal traffic detection model to a detection module of a satellite, and intercept the abnormal traffic when the satellite detects abnormal traffic to prevent potential network attacks.
[0012] According to another aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium includes a stored program, wherein when the program is executed, the method described in any one of the devices where the computer-readable storage medium is located is controlled.
[0013] According to another aspect of the present application, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, any one of the methods described above is implemented.
[0014] According to another aspect of the present application, a traffic detection and analysis system is provided, comprising: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include methods for executing any one of the described methods.
[0015] Applying the technical solution of the present application, in the above-mentioned traffic detection and analysis method, it includes: constructing a network flow set, the above-mentioned network flow set includes multiple data packet sequences with label data, the above-mentioned data packet sequence is a sequence composed of data packets with the same five-tuple information arranged in chronological order, the above-mentioned five-tuple information is the source IP address, the destination IP address, the source port number, the destination port number and the transport layer protocol, and the above-mentioned label data includes a normal traffic label and an abnormal traffic label; performing tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, the above-mentioned network flow tensor set includes multiple network flow tensors with the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences; using the above-mentioned network flow tensor set to train an LSTM neural network model to obtain an abnormal traffic detection model; deploying the above-mentioned abnormal traffic detection model to the detection module of the satellite, and when the above-mentioned satellite detects abnormal traffic, intercepting the above-mentioned abnormal traffic to prevent potential network attacks. The present application constructs a network flow set based on multiple data packet sequences with label data, and performs tensor conversion on each data packet sequence in the network flow set to obtain a network flow tensor set, and inputs the network flow tensor set into an LSTM model for training to obtain an abnormal traffic detection model, and deploys it to a satellite to detect abnormal traffic and prevent network attacks. The abnormal traffic detection model is used to identify abnormal traffic data in the network to determine whether the network is under attack, so as to take relevant measures to avoid abnormal traffic attacks, thereby solving the problem of inaccurate network traffic anomaly detection in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 A hardware structure block diagram of a mobile terminal for executing a flow detection and analysis method provided in an embodiment of the present application is shown;
[0017] Figure 2 A flow chart of a flow detection and analysis method provided according to an embodiment of the present application is shown;
[0018] Figure 3 A deployment diagram of an abnormal traffic detection model of a traffic detection and analysis method provided according to an embodiment of the present application is shown;
[0019] Figure 4 A structural block diagram of a flow detection and analysis device provided according to an embodiment of the present application is shown.
[0020] The above drawings include the following reference numerals:
[0021] 102, processor; 104, memory; 106, transmission device; 108, input and output devices. DETAILED DESCRIPTION
[0022] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0023] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0025] As introduced in the background technology, the network traffic anomaly detection method in the prior art may not be able to effectively detect network attacks caused by abnormal traffic, thereby causing data leakage and damage to the satellite network. To solve this technical problem, the embodiments of the present application provide a traffic detection and analysis method, device, computer-readable storage medium, computer program product and traffic detection and analysis system.
[0026] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings in the embodiments of the present invention.
[0027] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 FIG. 1 is a hardware structure block diagram of a mobile terminal of a flow detection and analysis method according to an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.
[0028] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as a computer program corresponding to a flow detection and analysis method in an embodiment of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the mobile terminal via a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof. The transmission device 106 is used to receive or send data via a network. The above-mentioned specific network example may include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0029] In this embodiment, a traffic detection and analysis method running on a mobile terminal, a computer terminal or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0030] Figure 2 FIG. 1 is a flow chart of a flow detection and analysis method according to an embodiment of the present application. Figure 2 As shown, the method comprises the following steps:
[0031] Step S201, constructing a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal flow label and an abnormal flow label;
[0032] Specifically, the process of constructing a network flow set involves organizing multiple sequences of data packets carrying labeled data. These sequences are composed of data packets with the same five-tuple information (source IP address, destination IP address, source port number, destination port number and transport layer protocol) arranged in chronological order. This network flow set not only includes the transmission characteristics of the data packets, but also integrates key label information, that is, each sequence is given a clear label to indicate whether it is normal traffic or abnormal traffic.
[0033] Step S202, performing tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, wherein the above-mentioned network flow tensor set includes a plurality of network flow tensors having the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences;
[0034] Specifically, the process of tensor conversion for each data packet sequence in the network flow set is essentially to unify all original network data formats into a mathematical structure that can be efficiently processed by the deep learning framework. This conversion generates a set of network flow tensors, each of which corresponds to the original data packet sequence and inherits the label data it carries. At the same time, data in tensor form can be directly used by the neural network model.
[0035] Step S203, using the above network flow tensor set to train the LSTM neural network model to obtain an abnormal flow detection model;
[0036] Specifically, the LSTM neural network model is trained using a set of network flow tensors. This process begins with inputting the set of network flow tensors into the model. Through the complex calculation and learning mechanisms within the model, especially the time series analysis capabilities of the LSTM, the detection process is gradually constructed and optimized, and finally an abnormal traffic detection model capable of detecting abnormal traffic is obtained.
[0037] Step S204: deploy the abnormal traffic detection model to the detection module of the satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks.
[0038] Specifically, the abnormal traffic detection model is deployed in the satellite's detection component. When the satellite detects network traffic that matches the abnormal patterns identified in the model training, it will take prompt action to intercept these abnormal traffic to resist possible network attacks and protect the healthy operation of the integrated air-ground-space network.
[0039] Through this embodiment, in the above-mentioned traffic detection and analysis method, a network flow set is constructed, the above-mentioned network flow set includes multiple data packet sequences with label data, the above-mentioned data packet sequence is a sequence composed of data packets with the same five-tuple information arranged in chronological order, the above-mentioned five-tuple information is the source IP address, the destination IP address, the source port number, the destination port number and the transport layer protocol, and the above-mentioned label data includes a normal traffic label and an abnormal traffic label; each of the above-mentioned data packet sequences in the above-mentioned network flow set is tensor-converted to obtain a network flow tensor set, the above-mentioned network flow tensor set includes multiple network flow tensors with the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences; the above-mentioned network flow tensor set is used to train an LSTM neural network model to obtain an abnormal traffic detection model; the above-mentioned abnormal traffic detection model is deployed to the detection module of the satellite, and when the above-mentioned satellite detects abnormal traffic, the above-mentioned abnormal traffic is intercepted to prevent potential network attacks. The present application constructs a network flow set based on multiple data packet sequences with label data, and performs tensor conversion on each data packet sequence in the network flow set to obtain a network flow tensor set, and inputs the network flow tensor set into an LSTM model for training to obtain an abnormal traffic detection model, and deploys it to a satellite to detect abnormal traffic and prevent network attacks. The abnormal traffic detection model is used to identify abnormal traffic data in the network to determine whether the network is under attack, so as to take relevant measures to avoid abnormal traffic attacks, thereby solving the problem of inaccurate network traffic anomaly detection in the prior art.
[0040] In order to construct the network flow set, in an optional implementation, the network flow set is constructed, and the above step S201 includes:
[0041] Step S2011, acquiring all data packets in the historical time period in the network to obtain a data packet set, wherein the data packet includes five-tuple information, a start time, and load information, wherein the start time is the time point when the data packet is first recorded during the transmission process, and the load information is the actual data content of the network communication contained in the data packet;
[0042] Specifically, all data packets circulating in the network within a specific historical period are captured to construct a detailed data packet collection. This collection not only covers the five-tuple information of the data packet (i.e., source IP, destination IP, source port, destination port, and transport layer protocol), but also records the start time of the data packet and its payload information. The payload information is the actual network communication data carried in the data packet. This comprehensive data collection method can provide a basis for better detection of network attacks in the future.
[0043] Step S2012, dividing all the data packets in the above data packet set according to a predetermined time interval to obtain a plurality of data packet subsets corresponding to different time periods;
[0044] Specifically, the acquired data packet set is subdivided according to a pre-set time interval, thereby generating a series of data packet subsets corresponding to different time segments. This process is essentially a time slicing of network communication behavior. It decomposes the continuous network activity flow into segments that are easy to process and analyze. Each segment contains all the data packets circulating in a specific time period, which helps to improve the efficiency of data processing.
[0045] Step S2013, grouping the data packets having the same five-tuple information in each of the data packet subsets into one group to obtain a plurality of data packet groups;
[0046] Specifically, all data packets with the same five-tuple information (i.e., source IP, destination IP, source port number, destination port number and protocol type) in each data packet subset obtained by dividing according to a predetermined time interval are classified into the same group, thereby forming multiple data packet groups.
[0047] Step S2014, splicing the above-mentioned load information of all the above-mentioned data packets in each of the above-mentioned data packet groups in the order of the above-mentioned start time to obtain the above-mentioned network flow set, and the above-mentioned network flow set includes the above-mentioned data packet sequences corresponding to each of the above-mentioned data packet groups, and the above-mentioned data packet sequences correspond one-to-one to the number of different five-tuple information in the above-mentioned data packet subset.
[0048] Specifically, the payload information of all packets in each packet group is spliced according to the chronological order of their start time, thereby constructing a network flow set, and each packet sequence accurately reflects the time sequence of the packet payload content in a specific network session.
[0049] It can be understood that the process of constructing a network flow set is to obtain all data packets in the historical time period in the network and obtain a data packet set Where i = 1, 2, ..., |P|, p i is a single data packet in P, xi For p i The five-tuple information, t i For p i The starting time, b i For p i Load information;
[0050] After that, all data packets are divided into multiple segments according to the time interval τ, and the data packet in the jth segment can be expressed as: p i j =(x i ,t i ,b i ),τ(j-1)≤t i ≤τj, then, P is sorted according to the five-tuple information j The data packets in each group are sorted in the order of the start time to obtain K data packet sequences S, where Then concatenate the payload information of all packets in S, and finally get the network flow set F, where
[0051] In order to obtain the parameter form recognized by the model, in an optional implementation, each of the above-mentioned data packet sequences in the above-mentioned network flow set is converted into a tensor to obtain a network flow tensor set. The above-mentioned step S202 includes:
[0052] Step S2021, performing length unification processing on the payload information corresponding to each of the data packet sequences in the network flow set to obtain a fixed-length network flow set, wherein the length unification processing is to truncate or fill zeros on the payload information;
[0053] Specifically, before the length unification processing, since the data packets have been divided according to the same five-tuple information, the five-tuple information in each data packet is redundant information, so the five-tuple information in each data packet sequence in the network flow set is batch removed. In this step and the subsequent length unification step, the data packets have been processed in the memory, so they are converted into binary code format. After that, a length standardization operation is performed on each data packet sequence in the network flow set, that is, those data packet sequences classified by the same five-tuple information and sorted by start time, so as to generate a fixed-length network flow set. This operation mainly involves adjusting the length of the payload information, specifically including truncating the overly long payload information, or padding the shorter payload information with zeros to achieve a unified length standard.
[0054] Step S2022, performing tensorization processing on each of the above-mentioned data packet sequences in the above-mentioned fixed-length network flow set to obtain the above-mentioned network flow tensor set.
[0055] Specifically, the set of fixed-length network flows that have been processed with unified length, that is, the sequence of data packets whose payload information length is standardized, is tensorized to construct a set of network flow tensors. This conversion process essentially converts the fixed-length network flow set into the tensor format required by the deep learning algorithm. A tensor is a multidimensional array. The order of the network flow tensor in the processed network flow tensor set is 2, which is divided into the number of data packets in the network flow tensor and the payload length carried by a single data packet. The data type is byte, occupying 1 byte of space, that is, every 8 bits of information in the data packet corresponds to a byte tensor.
[0056] In order to obtain an abnormal traffic detection model, in an optional implementation, the above network flow tensor set is used to train an LSTM neural network model to obtain an abnormal traffic detection model. The above step S203 includes:
[0057] Step S2031, using a one-dimensional convolutional neural network as an encoder of the LSTM neural network model, and constructing a network symmetrical to the one-dimensional convolutional neural network structure as a decoder of the LSTM neural network model;
[0058] Specifically, a one-dimensional convolutional neural network is selected as the encoder of the LSTM neural network model, and a network that mirrors its structure is designed to act as the decoder of the LSTM model. The purpose is to build a framework for efficient feature extraction and reconstruction. At the same time, the layers of the encoder and decoder are directly connected through skip-connection, that is, jumping directly from a certain layer of the encoder to the corresponding layer of the decoder without going through all the intermediate layers. Through skip-connection, the decoder does not need to build features from scratch, but can directly use the intermediate results of the encoder, which reduces the learning task of each layer and enables the model to focus more on the extraction and reconstruction of key features.
[0059] Step S2032, inputting each of the network flow tensors with the normal flow label in the network flow tensor set into the encoder for data compression to obtain a first encoding vector, and inputting each of the network flow tensors with the abnormal flow label in the network flow tensor set into the encoder for data compression to obtain a second encoding vector;
[0060] Specifically, the network flow tensor marked as a normal traffic label in the network flow tensor set is input into the encoder for feature compression and encoding, thereby generating a first encoding vector reflecting the characteristics of normal traffic. At the same time, the network flow tensor marked as an abnormal traffic label in the set is also sent to the encoder for feature compression to generate a second encoding vector reflecting the characteristics of abnormal traffic, in preparation for the subsequent LSTM to more accurately identify the difference between normal and abnormal traffic.
[0061] Step S2033, input each of the first coding vectors into the decoder, and the decoder performs vector reconstruction according to each of the first coding vectors to obtain a first decoding vector corresponding to each of the first coding vectors; input each of the second coding vectors into the decoder, and the decoder performs vector reconstruction according to each of the second coding vectors to obtain a second decoding vector corresponding to each of the second coding vectors;
[0062] Specifically, the generated first coding vectors are input into the decoder in sequence, and the decoder decompresses and reconstructs the features according to the content of each first coding vector, thereby obtaining a series of first decoding vectors corresponding to the first coding vectors. Similarly, the second coding vectors are input into the decoder in sequence, and the decoder decompresses and reconstructs the features according to these vectors, thereby generating a series of second decoding vectors corresponding to the second coding vectors.
[0063] Step S2034, using each of the above-mentioned first encoding vectors and the above-mentioned first decoding vectors corresponding to each of the above-mentioned first encoding vectors, and each of the above-mentioned second encoding vectors and the above-mentioned second decoding vectors corresponding to each of the above-mentioned second encoding vectors to train the above-mentioned LSTM neural network model until the first loss function converges downward and the second loss function converges upward, to obtain the above-mentioned abnormal traffic detection model, the above-mentioned first loss function is used to calculate the loss between each of the above-mentioned first encoding vectors and the above-mentioned first decoding vectors corresponding to each of the above-mentioned first encoding vectors, and the above-mentioned second loss function is used to calculate the loss between each of the above-mentioned second encoding vectors and the above-mentioned second decoding vectors corresponding to each of the above-mentioned second encoding vectors.
[0064] Specifically, the LSTM neural network model is continuously trained using the first encoding vector generated by normal traffic and its corresponding first decoding vector reconstructed by the decoder, as well as the second encoding vector generated by abnormal traffic and its corresponding second decoding vector. During the training process, the model simultaneously monitors and optimizes two loss functions: the first loss function quantifies the difference between the first encoding vector and the first decoding vector, that is, the reconstruction error of normal traffic, and its purpose is to minimize the reconstruction error between the first encoding vector and the first decoding vector; the second loss function evaluates the difference between the second encoding vector and the second decoding vector, that is, the reconstruction error of abnormal traffic, and its purpose is to maximize the reconstruction error between the second encoding vector and the second decoding vector. When the two loss functions reach the expected convergence state respectively, that is, the value of the first loss function stabilizes at a lower level and the value of the second loss function rises to a higher point, the model training is completed, and at this time we have obtained an abnormal traffic detection model designed to accurately detect abnormal traffic.
[0065] In order to enable the model to better process noise data, in an optional implementation, each of the network flow tensors with the normal flow label in the network flow tensor set is input into the encoder for data compression to obtain a first encoding vector, and each of the network flow tensors with the abnormal flow label in the network flow tensor set is input into the encoder for data compression to obtain a second encoding vector. The step S2032 further includes:
[0066] Step S20321, performing noise processing on each of the above network flow tensors with the above normal flow label and each of the above network flow tensors with the above abnormal flow label, and adding each of the above network flow tensors after noise processing to the above network flow tensor set.
[0067] Specifically, each network flow tensor is subjected to noise processing, that is, random perturbations are added to these network flow tensors. Subsequently, the noised network flow tensors are reintegrated into the network flow tensor set, and together with the unnoised data constitute the training data set of the model. By adding noise, the model can be exposed to network flow tensors with slight random changes during training, which simulates the interference or variation that the data may be subject to in a real network environment, prompting the model to learn more robust feature representations.
[0068] In order to apply the model, in an optional implementation, the abnormal traffic detection model is deployed to a detection module of a satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks. The step S204 includes:
[0069] Step S2041, sending the abnormal traffic detection model to the satellite for model deployment;
[0070] Specifically, the trained abnormal traffic detection model will be transmitted to the corresponding satellite equipment to implement the model deployment.
[0071] Step S2042: regularly sampling the user traffic received by the abnormal traffic detection model of the satellite, and optimizing and training the abnormal traffic detection model using the user traffic.
[0072] Specifically, the user traffic received by the abnormal traffic detection model deployed on the satellite is sampled and checked periodically, and the abnormal traffic detection model is continuously optimized and retrained using the sampled user traffic data. Specifically, the satellite will regularly collect samples from the passing traffic, and these samples will be securely transmitted back to the gateway station or other ground facilities for further analysis and labeling to determine the normal or abnormal state of the traffic. Subsequently, these labeled traffic data will be used again for model training to update the model's parameters and enhance its ability to identify new or evolving network attacks.
[0073] Figure 3 FIG. 4 shows a deployment diagram of an abnormal traffic detection model of a traffic detection and analysis method provided in an embodiment of the present application, such as Figure 3 As shown, the deployment process includes the following steps:
[0074] S1: The gateway station uses the currently known air-ground integrated network traffic (including normal traffic and abnormal traffic) to train the model and obtain a trained abnormal traffic detection model;
[0075] S2: The gateway station sends the trained abnormal traffic detection model to the high-orbit satellite through the space-based network link. After receiving the model, the high-orbit satellite synchronizes its original abnormal detection model.
[0076] S3: Assume that the attacker and the normal user access the target user at the same time. The normal user sends normal communication traffic, while the attacker sends abnormal attack traffic. Both traffic flows are transmitted through the space-based network and uplinked to the high-orbit satellite at the same time.
[0077] S4: After receiving two flows from users, the high-orbit satellite passes the received flows through the abnormal flow detection model in turn according to the abnormal flow detection algorithm. If the detection result is normal, the flow is released; if the detection result is abnormal, the flow is intercepted, cached and then transmitted back to the gateway station for further analysis and processing;
[0078] S5: High-orbit satellites regularly sample the passing traffic and transmit it back to the gateway station. After professionals proofread and annotate the returned traffic, it is added to the original training set to retrain the abnormal traffic detection model. By continuously correcting the training set, the accuracy of the abnormal traffic detection algorithm is further improved.
[0079] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0080] The embodiment of the present application also provides a flow detection and analysis device. It should be noted that a flow detection and analysis device of the embodiment of the present application can be used to execute a flow detection and analysis method provided in the embodiment of the present application. The device is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0081] The following is an introduction to a flow detection and analysis device provided in an embodiment of the present application.
[0082] Figure 4 is a structural block diagram of a flow detection and analysis device according to an embodiment of the present application. Figure 4 As shown, the device comprises:
[0083] A construction unit 10 is used to construct a network flow set, wherein the network flow set includes a plurality of data packet sequences with label data, wherein the data packet sequence is a sequence of data packets with the same five-tuple information arranged in chronological order, wherein the five-tuple information is a source IP address, a destination IP address, a source port number, a destination port number, and a transport layer protocol, and the label data includes a normal flow label and an abnormal flow label;
[0084] Specifically, the process of constructing a network flow set involves organizing multiple sequences of data packets carrying labeled data. These sequences are composed of data packets with the same five-tuple information (source IP address, destination IP address, source port number, destination port number and transport layer protocol) arranged in chronological order. This network flow set not only includes the transmission characteristics of the data packets, but also integrates key label information, that is, each sequence is given a clear label to indicate whether it is normal traffic or abnormal traffic.
[0085] The processing unit 20 is used to perform tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, wherein the above-mentioned network flow tensor set includes a plurality of network flow tensors having the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences;
[0086] Specifically, the process of tensor conversion for each data packet sequence in the network flow set is essentially to unify all original network data formats into a mathematical structure that can be efficiently processed by the deep learning framework. This conversion generates a set of network flow tensors, each of which corresponds to the original data packet sequence and inherits the label data it carries. At the same time, data in tensor form can be directly used by the neural network model.
[0087] A training unit 30 is used to train an LSTM neural network model using the above network flow tensor set to obtain an abnormal flow detection model;
[0088] Specifically, the LSTM neural network model is trained using a set of network flow tensors. This process begins with inputting the set of network flow tensors into the model. Through the complex calculation and learning mechanisms within the model, especially the time series analysis capabilities of the LSTM, the detection process is gradually constructed and optimized, and finally an abnormal traffic detection model capable of detecting abnormal traffic is obtained.
[0089] The control unit 40 is used to deploy the abnormal traffic detection model to the detection module of the satellite, and intercept the abnormal traffic when the satellite detects abnormal traffic to prevent potential network attacks.
[0090] Specifically, the abnormal traffic detection model is deployed in the satellite's detection component. When the satellite detects network traffic that matches the abnormal patterns identified in the model training, it will take prompt action to intercept these abnormal traffic to resist possible network attacks and protect the healthy operation of the integrated air-ground-space network.
[0091] Through this embodiment, in the above-mentioned traffic detection and analysis device, a construction unit is used to construct a network flow set, the above-mentioned network flow set includes multiple data packet sequences with label data, the above-mentioned data packet sequence is a sequence composed of data packets with the same five-tuple information arranged in chronological order, the above-mentioned five-tuple information is the source IP address, the destination IP address, the source port number, the destination port number and the transport layer protocol, and the above-mentioned label data includes a normal traffic label and an abnormal traffic label; a processing unit is used to perform tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, the above-mentioned network flow tensor set includes multiple network flow tensors with the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequence; a training unit is used to train an LSTM neural network model using the above-mentioned network flow tensor set to obtain an abnormal traffic detection model; a control unit is used to deploy the above-mentioned abnormal traffic detection model to the detection module of the satellite, and when the above-mentioned satellite detects abnormal traffic, the above-mentioned abnormal traffic is intercepted to prevent potential network attacks. The present application constructs a network flow set based on multiple data packet sequences with label data, and performs tensor conversion on each data packet sequence in the network flow set to obtain a network flow tensor set, and inputs the network flow tensor set into an LSTM model for training to obtain an abnormal traffic detection model, and deploys it to a satellite to detect abnormal traffic and prevent network attacks. The abnormal traffic detection model is used to identify abnormal traffic data in the network to determine whether the network is under attack, so as to take relevant measures to avoid abnormal traffic attacks, thereby solving the problem of inaccurate network traffic anomaly detection in the prior art.
[0092] In order to construct the network flow set, in an optional implementation, the network flow set is constructed, and the construction unit includes:
[0093] The first construction module is used to obtain all data packets in the historical time period in the network to obtain a data packet set, wherein the data packet includes five-tuple information, a start time and a load information, wherein the start time is the time point when the data packet is first recorded during the transmission process, and the load information is the actual data content of the network communication contained in the data packet;
[0094] Specifically, all data packets circulating in the network within a specific historical period are captured to construct a detailed data packet collection. This collection not only covers the five-tuple information of the data packet (i.e., source IP, destination IP, source port, destination port, and transport layer protocol), but also records the start time of the data packet and its payload information. The payload information is the actual network communication data carried in the data packet. This comprehensive data collection method can provide a basis for better detection of network attacks in the future.
[0095] A second construction module is used to divide all the data packets in the above data packet set according to a predetermined time interval to obtain a plurality of data packet subsets corresponding to different time periods;
[0096] Specifically, the acquired data packet set is subdivided according to a pre-set time interval, thereby generating a series of data packet subsets corresponding to different time segments. This process is essentially a time slicing of network communication behavior. It decomposes the continuous network activity flow into segments that are easy to process and analyze. Each segment contains all the data packets circulating in a specific time period, which helps to improve the efficiency of data processing.
[0097] A third construction module is used to group the data packets having the same five-tuple information in each of the data packet subsets into one group to obtain a plurality of data packet groups;
[0098] Specifically, all data packets with the same five-tuple information (i.e., source IP, destination IP, source port number, destination port number and protocol type) in each data packet subset obtained by dividing according to a predetermined time interval are classified into the same group, thereby forming multiple data packet groups.
[0099] The fourth construction module is used to splice the above-mentioned payload information of all the above-mentioned data packets in each of the above-mentioned data packet groups in the order of the above-mentioned start time to obtain the above-mentioned network flow set, and the above-mentioned network flow set includes the above-mentioned data packet sequences corresponding to each of the above-mentioned data packet groups, and the above-mentioned data packet sequences correspond one-to-one to the number of different five-tuple information in the above-mentioned data packet subset.
[0100] Specifically, the payload information of all packets in each packet group is spliced according to the chronological order of their start time, thereby constructing a network flow set, and each packet sequence accurately reflects the time sequence of the packet payload content in a specific network session.
[0101] In order to obtain the parameter form recognized by the model, in an optional implementation, each of the above-mentioned data packet sequences in the above-mentioned network flow set is subjected to tensor conversion to obtain a network flow tensor set, and the above-mentioned processing unit includes:
[0102] A first processing module is used to perform length uniform processing on the payload information corresponding to each of the data packet sequences in the network flow set to obtain a fixed-length network flow set, wherein the length uniform processing is to truncate or fill zeros on the payload information;
[0103] Specifically, before the length unification processing, since the data packets have been divided according to the same five-tuple information, the five-tuple information in each data packet is redundant information, so the five-tuple information in each data packet sequence in the network flow set is batch removed. In this step and the subsequent length unification step, the data packets have been processed in the memory, so they are converted into binary code format. After that, a length standardization operation is performed on each data packet sequence in the network flow set, that is, those data packet sequences classified by the same five-tuple information and sorted by start time, so as to generate a fixed-length network flow set. This operation mainly involves adjusting the length of the payload information, specifically including truncating the overly long payload information, or padding the shorter payload information with zeros to achieve a unified length standard.
[0104] The second processing module is used to perform tensorization processing on each of the above-mentioned data packet sequences in the above-mentioned fixed-length network flow set to obtain the above-mentioned network flow tensor set.
[0105] Specifically, the set of fixed-length network flows that have been processed with unified length, that is, the sequence of data packets whose payload information length is standardized, is tensorized to construct a set of network flow tensors. This conversion process essentially converts the fixed-length network flow set into the tensor format required by the deep learning algorithm. A tensor is a multidimensional array. The order of the network flow tensor in the processed network flow tensor set is 2, which is divided into the number of data packets in the network flow tensor and the payload length carried by a single data packet. The data type is byte, occupying 1 byte of space, that is, every 8 bits of information in the data packet corresponds to a byte tensor.
[0106] In order to obtain an abnormal traffic detection model, in an optional implementation, the above network flow tensor set is used to train an LSTM neural network model to obtain an abnormal traffic detection model, and the above training unit includes:
[0107] The first training module is used to use a one-dimensional convolutional neural network as an encoder of the LSTM neural network model, and to construct a network symmetrical to the one-dimensional convolutional neural network structure as a decoder of the LSTM neural network model;
[0108] Specifically, a one-dimensional convolutional neural network is selected as the encoder of the LSTM neural network model, and a network that mirrors its structure is designed to act as the decoder of the LSTM model. The purpose is to build a framework for efficient feature extraction and reconstruction. At the same time, the layers of the encoder and decoder are directly connected through skip-connection, that is, jumping directly from a certain layer of the encoder to the corresponding layer of the decoder without going through all the intermediate layers. Through skip-connection, the decoder does not need to build features from scratch, but can directly use the intermediate results of the encoder, which reduces the learning task of each layer and enables the model to focus more on the extraction and reconstruction of key features.
[0109] A second training module is used to input each of the network flow tensors with the normal flow label in the network flow tensor set into the encoder for data compression to obtain a first encoding vector, and input each of the network flow tensors with the abnormal flow label in the network flow tensor set into the encoder for data compression to obtain a second encoding vector;
[0110] Specifically, the network flow tensor marked as a normal traffic label in the network flow tensor set is input into the encoder for feature compression and encoding, thereby generating a first encoding vector reflecting the characteristics of normal traffic. At the same time, the network flow tensor marked as an abnormal traffic label in the set is also sent to the encoder for feature compression to generate a second encoding vector reflecting the characteristics of abnormal traffic, in preparation for the subsequent LSTM to more accurately identify the difference between normal and abnormal traffic.
[0111] A third training module is used to input each of the first coding vectors into the decoder, and the decoder performs vector reconstruction according to each of the first coding vectors to obtain a first decoding vector corresponding to each of the first coding vectors, and input each of the second coding vectors into the decoder, and the decoder performs vector reconstruction according to each of the second coding vectors to obtain a second decoding vector corresponding to each of the second coding vectors;
[0112] Specifically, the generated first coding vectors are input into the decoder in sequence, and the decoder decompresses and reconstructs the features according to the content of each first coding vector, thereby obtaining a series of first decoding vectors corresponding to the first coding vectors. Similarly, the second coding vectors are input into the decoder in sequence, and the decoder decompresses and reconstructs the features according to these vectors, thereby generating a series of second decoding vectors corresponding to the second coding vectors.
[0113] The fourth training module is used to train the LSTM neural network model by using the first encoding vectors and the first decoding vectors corresponding to the first encoding vectors, and the second encoding vectors and the second decoding vectors corresponding to the second encoding vectors, until the first loss function converges downward and the second loss function converges upward, so as to obtain the abnormal traffic detection model, wherein the first loss function is used to calculate the loss between the first encoding vectors and the first decoding vectors corresponding to the first encoding vectors, and the second loss function is used to calculate the loss between the second encoding vectors and the second decoding vectors corresponding to the second encoding vectors.
[0114] Specifically, the LSTM neural network model is continuously trained using the first encoding vector generated by normal traffic and its corresponding first decoding vector reconstructed by the decoder, as well as the second encoding vector generated by abnormal traffic and its corresponding second decoding vector. During the training process, the model simultaneously monitors and optimizes two loss functions: the first loss function quantifies the difference between the first encoding vector and the first decoding vector, that is, the reconstruction error of normal traffic, and its purpose is to minimize the reconstruction error between the first encoding vector and the first decoding vector; the second loss function evaluates the difference between the second encoding vector and the second decoding vector, that is, the reconstruction error of abnormal traffic, and its purpose is to maximize the reconstruction error between the second encoding vector and the second decoding vector. When the two loss functions reach the expected convergence state respectively, that is, the value of the first loss function stabilizes at a lower level and the value of the second loss function rises to a higher point, the model training is completed, and at this time we have obtained an abnormal traffic detection model designed to accurately detect abnormal traffic.
[0115] In order to enable the model to better process noise data, in an optional implementation, each of the network flow tensors with the normal flow label in the network flow tensor set is input into the encoder for data compression to obtain a first encoding vector, and each of the network flow tensors with the abnormal flow label in the network flow tensor set is input into the encoder for data compression to obtain a second encoding vector. The second training module further includes:
[0116] The second training submodule is used to perform noise processing on each of the above-mentioned network flow tensors with the above-mentioned normal flow labels and each of the above-mentioned network flow tensors with the above-mentioned abnormal flow labels, and add each of the above-mentioned network flow tensors after noise processing to the above-mentioned network flow tensor set.
[0117] Specifically, each network flow tensor is subjected to noise processing, that is, random perturbations are added to these network flow tensors. Subsequently, the noised network flow tensors are reintegrated into the network flow tensor set, and together with the unnoised data constitute the training data set of the model. By adding noise, the model can be exposed to network flow tensors with slight random changes during training, which simulates the interference or variation that the data may be subject to in a real network environment, prompting the model to learn more robust feature representations.
[0118] In order to apply the model, in an optional implementation, the abnormal traffic detection model is deployed to a detection module of a satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks. The control unit includes:
[0119] A first control module, used for sending the abnormal traffic detection model to the satellite for model deployment;
[0120] Specifically, the trained abnormal traffic detection model will be transmitted to the corresponding satellite equipment to implement the model deployment.
[0121] The second control module is used to periodically sample the user traffic received by the abnormal traffic detection model of the satellite, and use the user traffic to optimize and train the abnormal traffic detection model.
[0122] Specifically, the user traffic received by the abnormal traffic detection model deployed on the satellite is sampled and checked periodically, and the abnormal traffic detection model is continuously optimized and retrained using the sampled user traffic data. Specifically, the satellite will regularly collect samples from the passing traffic, and these samples will be securely transmitted back to the gateway station or other ground facilities for further analysis and labeling to determine the normal or abnormal state of the traffic. Subsequently, these labeled traffic data will be used again for model training to update the model's parameters and enhance its ability to identify new or evolving network attacks.
[0123] The above-mentioned flow detection and analysis device includes a processor and a memory. The above-mentioned construction unit, processing unit, training unit and control unit are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize the corresponding functions. The above-mentioned modules are all located in the same processor; or, the above-mentioned modules are located in different processors in any combination.
[0124] The processor includes a kernel, which calls the corresponding program unit from the memory. One or more kernels can be set, and the accuracy of network traffic anomaly detection can be improved by adjusting kernel parameters.
[0125] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0126] An embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned traffic detection and analysis method.
[0127] Specifically, a flow detection and analysis method includes:
[0128] Step S201, constructing a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal flow label and an abnormal flow label;
[0129] Step S202, performing tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, wherein the above-mentioned network flow tensor set includes a plurality of network flow tensors having the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences;
[0130] Step S203, using the above network flow tensor set to train the LSTM neural network model to obtain an abnormal flow detection model;
[0131] Step S204: deploy the abnormal traffic detection model to the detection module of the satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks.
[0132] An embodiment of the present invention provides a processor, and the processor is used to run a program, wherein the program executes the above-mentioned flow detection and analysis method when running.
[0133] Specifically, a flow detection and analysis method includes:
[0134] Step S201, constructing a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal flow label and an abnormal flow label;
[0135] Step S202, performing tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, wherein the above-mentioned network flow tensor set includes a plurality of network flow tensors having the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences;
[0136] Step S203, using the above network flow tensor set to train the LSTM neural network model to obtain an abnormal flow detection model;
[0137] Step S204: deploy the abnormal traffic detection model to the detection module of the satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks.
[0138] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program for initializing at least the following method steps:
[0139] Step S201, constructing a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal flow label and an abnormal flow label;
[0140] Step S202, performing tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, wherein the above-mentioned network flow tensor set includes a plurality of network flow tensors having the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences;
[0141] Step S203, using the above network flow tensor set to train the LSTM neural network model to obtain an abnormal flow detection model;
[0142] Step S204: deploy the abnormal traffic detection model to the detection module of the satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks.
[0143] An embodiment of the present application also provides a traffic detection and analysis system, comprising: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, including executing any one of the above-mentioned traffic detection and analysis methods.
[0144] Specifically, a flow detection and analysis method includes:
[0145] Step S201, constructing a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal flow label and an abnormal flow label;
[0146] Step S202, performing tensor conversion on each of the above-mentioned data packet sequences in the above-mentioned network flow set to obtain a network flow tensor set, wherein the above-mentioned network flow tensor set includes a plurality of network flow tensors having the above-mentioned label data, and the above-mentioned network flow tensors correspond one-to-one to the above-mentioned data packet sequences;
[0147] Step S203, using the above network flow tensor set to train the LSTM neural network model to obtain an abnormal flow detection model;
[0148] Step S204: deploy the abnormal traffic detection model to the detection module of the satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks.
[0149] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order than here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present invention is not limited to any specific combination of hardware and software.
[0150] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0151] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0152] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0153] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0154] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0155] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0156] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0157] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0158] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:
[0159] 1) A traffic detection and analysis method of the present application constructs a network flow set based on multiple data packet sequences with label data, and performs tensor conversion on each data packet sequence in the network flow set to obtain a network flow tensor set, and inputs the network flow tensor set into an LSTM model for training to obtain an abnormal traffic detection model, and deploys it to a satellite to detect abnormal traffic and prevent network attacks. The abnormal traffic detection model is used to identify abnormal traffic data in the network to determine whether the network is under attack, so as to take relevant measures to avoid abnormal traffic attacks, thereby solving the problem of inaccurate detection of network traffic anomalies in the prior art.
[0160] 2) A traffic detection and analysis device of the present application constructs a network flow set based on multiple data packet sequences with label data, and performs tensor conversion on each data packet sequence in the network flow set to obtain a network flow tensor set, and inputs the network flow tensor set into an LSTM model for training to obtain an abnormal traffic detection model, and deploys it to a satellite to detect abnormal traffic and prevent network attacks. The abnormal traffic detection model is used to identify abnormal traffic data in the network to determine whether the network is under attack, so as to take relevant measures to avoid abnormal traffic attacks, thereby solving the problem of inaccurate detection of network traffic anomalies in the prior art.
[0161] The above description is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A flow detection and analysis method, characterized in that: include: Constructing a network flow set, the network flow set comprising a plurality of data packet sequences with label data, the data packet sequence being a sequence of data packets with the same five-tuple information arranged in chronological order, the five-tuple information being a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data comprising a normal flow label and an abnormal flow label; Performing tensor conversion on each of the data packet sequences in the network flow set to obtain a network flow tensor set, wherein the network flow tensor set includes a plurality of network flow tensors having the label data, and the network flow tensors correspond one-to-one to the data packet sequences; The network flow tensor set is used to train the LSTM neural network model to obtain an abnormal flow detection model; The abnormal traffic detection model is deployed to the detection module of the satellite. When the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks.
2. The method according to claim 1, characterized in that: Build a network flow collection, including: Acquire all data packets in a historical time period in the network to obtain a data packet set, wherein the data packet includes five-tuple information, a start time and a load information, wherein the start time is the time point when the data packet is first recorded during the transmission process, and the load information is the actual data content of the network communication contained in the data packet; Dividing all the data packets in the data packet set according to a predetermined time interval to obtain a plurality of data packet subsets corresponding to different time periods; Grouping the data packets having the same five-tuple information in each of the data packet subsets into one group to obtain a plurality of data packet groups; The payload information of all the data packets in each of the data packet groups is spliced in the order of the start time to obtain the network flow set, wherein the network flow set includes the data packet sequence corresponding to each of the data packet groups, and the data packet sequence corresponds one-to-one to the number of different five-tuple information in the data packet subset.
3. The method according to claim 2, characterized in that Performing tensor conversion on each of the data packet sequences in the network flow set to obtain a network flow tensor set, including: Performing length unification processing on the payload information corresponding to each of the data packet sequences in the network flow set to obtain a fixed-length network flow set, wherein the length unification processing is to truncate or fill zeros on the payload information; Each of the data packet sequences in the fixed-length network flow set is subjected to tensorization processing to obtain the network flow tensor set.
4. The method according to claim 1, characterized in that: The network flow tensor set is used to train the LSTM neural network model to obtain an abnormal flow detection model, including: A one-dimensional convolutional neural network is used as an encoder of the LSTM neural network model, and a network symmetrical to the one-dimensional convolutional neural network structure is constructed as a decoder of the LSTM neural network model; Inputting each of the network flow tensors with the normal flow label in the network flow tensor set into the encoder for data compression to obtain a first encoding vector, and inputting each of the network flow tensors with the abnormal flow label in the network flow tensor set into the encoder for data compression to obtain a second encoding vector; Input each of the first coding vectors to the decoder, and the decoder performs vector reconstruction according to each of the first coding vectors to obtain a first decoding vector corresponding to each of the first coding vectors; input each of the second coding vectors to the decoder, and the decoder performs vector reconstruction according to each of the second coding vectors to obtain a second decoding vector corresponding to each of the second coding vectors; The LSTM neural network model is trained using each of the first encoding vectors and the first decoding vectors corresponding to each of the first encoding vectors, and each of the second encoding vectors and the second decoding vectors corresponding to each of the second encoding vectors, until the first loss function converges downward and the second loss function converges upward, to obtain the abnormal traffic detection model, wherein the first loss function is used to calculate the loss between each of the first encoding vectors and the first decoding vectors corresponding to each of the first encoding vectors, and the second loss function is used to calculate the loss between each of the second encoding vectors and the second decoding vectors corresponding to each of the second encoding vectors.
5. The method according to claim 4, characterized in that Inputting each of the network flow tensors with the normal flow label in the network flow tensor set to the encoder for data compression to obtain a first encoding vector, and inputting each of the network flow tensors with the abnormal flow label in the network flow tensor set to the encoder for data compression to obtain a second encoding vector, further comprising: Noise processing is performed on each of the network flow tensors with the normal flow label and each of the network flow tensors with the abnormal flow label, and each of the network flow tensors after the noise processing is added to the network flow tensor set.
6. The method according to claim 1, characterized in that The abnormal traffic detection model is deployed to a detection module of a satellite, and when the satellite detects abnormal traffic, the abnormal traffic is intercepted to prevent potential network attacks, including: Sending the abnormal traffic detection model to the satellite for model deployment; The user traffic received by the abnormal traffic detection model of the satellite is sampled regularly, and the abnormal traffic detection model is optimized and trained using the user traffic.
7. A flow detection and analysis device, characterized in that: include: A construction unit, used to construct a network flow set, the network flow set includes a plurality of data packet sequences with label data, the data packet sequence is a sequence composed of data packets with the same five-tuple information arranged in chronological order, the five-tuple information is a source IP address, a destination IP address, a source port number, a destination port number and a transport layer protocol, the label data includes a normal flow label and an abnormal flow label; A processing unit, configured to perform tensor conversion on each of the data packet sequences in the network flow set to obtain a network flow tensor set, wherein the network flow tensor set includes a plurality of network flow tensors having the label data, and the network flow tensors correspond one to one to the data packet sequences; A training unit, used for training an LSTM neural network model using the network flow tensor set to obtain an abnormal flow detection model; The control unit is used to deploy the abnormal traffic detection model to the detection module of the satellite, and intercept the abnormal traffic when the satellite detects abnormal traffic to prevent potential network attacks.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 6.
9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A flow detection and analysis system, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs include methods for executing any one of claims 1 to 6.