Intrusion detection method based on similarity measurement and graph convolution
By using graph convolutional networks and similarity metric models in intrusion detection, the non-European distance characteristics of high-dimensional network intrusion detection data are extracted, and the problems of dimensional disasters and insufficient samples in traditional methods are solved, and efficient and robust intrusion detection effects are achieved.
Patent Information
- Application Number
- CN202411829601.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-05-13
AI Technical Summary
Traditional intrusion detection methods face dimensional disasters, insufficient samples and difficult to extract non-European distance features when processing high-dimensional network intrusion detection data, resulting in a degradation of detection performance.
The intrusion detection method based on similarity metrics and graph convolution is adopted to extract non-European distance characteristics of high-dimensional data through graph convolution networks, and distance measurement and classification are used using the similarity metric model.
It effectively alleviates the problem of dimensional disasters, improves the generalization ability and detection performance of the model, can obtain good intrusion detection effects in small samples, and effectively detects unknown attack types, improving the accuracy and robustness of detection.
Smart Images

Figure CN119995918A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network security, and in particular to an intrusion detection method based on similarity measurement and graph convolution. Background Art
[0002] With the increasing awareness of security, network intrusion detection has attracted more and more attention. Traditional intrusion detection methods face many challenges in dealing with current network security threats. First, intrusion detection data usually has high-dimensional characteristics, such as protocol features in network traffic, time-based network traffic features, and host-based network traffic features, which can easily lead to "dimensionality disaster" and reduce the generalization ability of the model. Secondly, intrusion detection tasks often face the problem of insufficient samples. Due to the scarcity and diversity of malicious traffic, it is extremely challenging to obtain sufficient labeled data, which makes it difficult for traditional supervised learning-based methods to work effectively. In addition, the effective extraction and representation of data features are the core issues in intrusion detection. The distance between high-dimensional data is not a simple Euclidean distance, and it is difficult for traditional convolutional neural networks to extract effective features. To this end, there is an urgent need for a new intrusion detection method that can make full use of the feature relationship in high-dimensional data, solve the dilemma of insufficient samples, and improve the detection performance through an efficient feature extraction mechanism to cope with complex security threats in modern network environments.
[0003] The Chinese invention patent document with the announcement number CN 116743473 B discloses an intrusion detection method based on parallel metric learning, which belongs to the field of intrusion detection technology. An intrusion detection method based on parallel metric learning consists of an embedding module, a metric module and a classifier to form a model; the embedding module is used to receive five-tuple data, the metric module is used to obtain the prediction similarity, and the classifier is used to obtain the prediction category; the specific implementation process is: S1. training model; S2. inputting network traffic into the model, the model outputs the recognition result, if the network traffic is non-intrusion traffic, the output result is 0, otherwise, the output result is 1. This scheme aims to solve the technical problems of low recognition efficiency and poor real-time performance of the model in the prior art; the present invention only needs to use the embedding module to extract features of the network traffic, and then input the extracted features into the classifier to obtain the final recognition result, without having to compare one by one with the samples in the support set, which can greatly improve the recognition efficiency and recognition accuracy. This scheme only proposes an intrusion detection method based on parallel metric learning, and does not focus on solving the problems of dimensional disaster, insufficient samples and difficulty in extracting non-Euclidean distance features in intrusion detection data.
[0004] According to literature survey, most of the current intrusion detection methods do not pay attention to the problems of intrusion detection in data dimension, insufficient samples and difficulty in extracting non-Euclidean distance features. In order to solve the above problems, the present invention proposes an intrusion detection method based on similarity measurement and graph convolution.
[0005] After searching, the application publication number CN112861913A, a method for associating intrusion alarm messages based on graph convolutional networks, belongs to the field of network security technology. The association method encodes the alarm message, constructs the feature vector of the alarm message, and constructs the alarm message graph according to the alarm message. The feature vector and the alarm message graph are simultaneously input into the graph convolutional neural network. The present invention models the association of the alarm message as a node classification problem on the alarm message graph. By training the graph convolutional neural network, the label and the predicted probability value of the attack category of the alarm message are compared using the cross entropy loss function. When the cross entropy loss function converges, the training of the graph convolutional neural network is completed; the alarm message fed back by the intrusion detection is collected again and input into the trained graph convolutional neural network, and the probability value of the attack category of the alarm message is output. Compared with the traditional alarm association method based on similarity, the association method applied by the present invention has a higher accuracy rate. The patent application focuses on the association of alarm messages after intrusion detection rather than the intrusion detection method studied by the present invention; the invention uses graph convolution for classification, which is different from the use of graph convolution in the present invention to extract non-Euclidean distance features of intrusion detection data. Summary of the invention
[0006] The present invention aims to solve the above problems of the prior art. An intrusion detection method based on similarity measurement and graph convolution is proposed. The technical solution of the present invention is as follows:
[0007] An intrusion detection method based on similarity measurement and graph convolution comprises the following steps:
[0008] a) Data preprocessing, including data cleaning, one-hot encoding, normalization, graph structure construction, and data set partitioning;
[0009] b) Construct a graph convolutional network to extract features from graph structure data;
[0010] c) Construct a similarity measurement model and perform distance measurement based on the feature output of the graph convolutional network;
[0011] d) Train the model and save the optimal model;
[0012] e) By calculating the similarity between the test data and the training samples, the data is classified as normal data or a certain type of intrusion.
[0013] Furthermore, the step a) of preprocessing data specifically includes the following contents:
[0014] Perform data cleaning on intrusion detection data, including missing value processing and outlier processing;
[0015] Perform one-hot encoding on the cleaned data to convert non-numerical information into numerical features;
[0016] Normalize the one-hot encoded data;
[0017] Use the self-attention mechanism to extract similarity features between high-dimensional intrusion detection data and use it as an adjacency matrix to construct graph structure data;
[0018] The data is divided into training set, validation set and test set according to a certain ratio, which are used for model training, cross-validation and effect testing respectively.
[0019] Furthermore, the step b) of graph convolutional network design includes determining the number of convolutional layers, input layer data shape, activation function and output layer data shape to adapt to non-Euclidean distance feature extraction of intrusion detection data.
[0020] Furthermore, the step c) constructs a similarity measurement model and performs distance measurement based on the feature output of the graph convolutional network, specifically including:
[0021] Step 1: Set the distance metric of similarity measurement, such as Euclidean distance, Manhattan distance, and Chebyshev distance, to calculate the distance between feature vectors;
[0022] Step 2: Set the overall model training parameters, including batch size batch_size, model training epochs, model learning rate lr, and optimizer Optimizer.
[0023] Furthermore, in the model training and optimal model saving steps, validation set data is used for cross-validation to ensure the generalization performance of the model, and the model parameters with the best performance on the validation set are saved for subsequent intrusion detection.
[0024] Furthermore, the step e) classifies the test data into normal data or a certain intrusion type by calculating the similarity between the test data and the training samples, specifically including:
[0025] In the similarity detection and intrusion detection steps, by calculating the average similarity between the test sample and multiple labeled samples, when the similarity between the test sample and all labeled samples is lower than the set threshold, it is classified as an unknown intrusion type to improve the recognition compatibility of zero-day attacks.
[0026] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the intrusion detection method based on similarity measurement and graph convolution as described in any one of the items is implemented.
[0027] A non-transitory computer-readable storage medium stores a computer program thereon, wherein the computer program, when executed by a processor, implements an intrusion detection method based on similarity measurement and graph convolution as described in any one of the items.
[0028] A computer program product comprises a computer program, wherein when the computer program is executed by a processor, the intrusion detection method based on similarity measurement and graph convolution as described in any one of the items is implemented.
[0029] The advantages and beneficial effects of the present invention are as follows:
[0030] The present invention utilizes a similarity measurement model to convert high-dimensional data into a low-dimensional feature vector, thereby effectively alleviating the dimensionality curse of intrusion detection data; the intrusion detection of the present invention determines the intrusion type of the test sample by comparing the similarity between the test sample and the labeled sample, and the model training does not directly depend on the amount of labeled data, thereby being able to obtain a better intrusion detection effect in a small sample; the present invention extracts non-Euclidean distance features of high-dimensional intrusion detection data through a self-attention mechanism and a graph convolutional network, thereby effectively improving the feature extraction capability of the similarity measurement model; the present invention can effectively detect unknown attack types other than labeled data through similarity measurement and threshold setting, thereby effectively improving the accuracy and robustness of intrusion detection.
[0031] Innovation: Using Graph Convolutional Networks (GCN) to process high-dimensional intrusion detection data
[0032] -Beneficial effects: Graph convolutional networks can effectively extract features from data in non-Euclidean space (such as graph structure data), which is particularly applicable to high-dimensional network intrusion data, can alleviate the problem of "dimensionality disaster", and improve the generalization ability of the model. Since data is difficult to process in high-dimensional space, using GCN through its inherent graph structure analysis ability can more accurately capture the correlation between data, thereby improving the stability and accuracy of the detection effect.
[0033] -Unpredictable reasons: Traditional intrusion detection methods mostly use linear models or shallow neural networks, which often do not work well when processing high-dimensional data. GCN targets graph-structured data, and although network intrusion data is inherently high-dimensional, it is not intuitive to directly convert it into a graph structure, which requires some innovative thinking and a deep understanding of the data to achieve.
[0034] 2. Innovation: Building a graph structure by combining the self-attention mechanism
[0035] -Beneficial effects: The self-attention mechanism can capture long-distance dependencies within the data, which is crucial for building a graph structure that reflects network intrusion characteristics. It not only enhances the feature extraction capability of GCN, but also helps the model to more accurately judge the similarity between nodes when processing complex data, thereby improving the robustness of intrusion detection.
[0036] - Reasons for being hard to think of: The self-attention mechanism is relatively common in the field of natural language processing. Applying it to network intrusion detection requires the integration and innovation of cross-domain knowledge. In addition, how to effectively combine the self-attention mechanism with graph structure data to adapt to intrusion detection tasks requires in-depth understanding and experimental verification, which is not intuitive or easy to think of.
[0037] 3. Innovation: Using similarity measurement instead of direct classification
[0038] -Beneficial effects: Through the similarity measurement model, the present invention can identify unknown attack types instead of relying solely on existing attack labels for classification. This strategy is particularly effective in the face of zero-day attacks and can significantly improve the coverage and security of detection.
[0039] -Unpredictable reasons: Traditional intrusion detection methods often classify attacks based on known attack features, while similarity measurement requires the model to have more advanced pattern recognition capabilities and be able to determine the correlation between data points. This change in thinking requires a deep understanding of the diversity and complexity of network attacks and the design of appropriate similarity measurement methods, which is not easy to achieve without sufficient prior knowledge.
[0040] 4. Innovation: Identifying unknown attacks through threshold setting
[0041] -Beneficial effects: In intrusion detection, the identification of unknown attacks is extremely important. By setting a similarity threshold, the present invention can identify data points that are not similar to all known attack types as unknown intrusions, thereby enhancing the security of the detection system and avoiding misjudgment of unknown attacks.
[0042] - Unpredictable reasons: Threshold setting requires accurate understanding and control of the model's output, which usually requires a lot of experiments to find a suitable threshold. When dealing with unknown attacks, it is a challenge to determine a threshold that can effectively distinguish between normal traffic and unknown attacks. In addition, this method requires the model to maintain high detection performance even with low data volume, which is often not easy to achieve in practice.
[0043] In summary, the innovation of the present invention is that it combines the deep feature extraction capability of graph convolutional networks, the long-distance dependency capture capability of self-attention mechanisms, and the flexibility of similarity metrics to form an efficient, robust, and adaptable intrusion detection system. These innovations can not only significantly improve the accuracy of detection, but also cover a wider range of attack types, especially when dealing with unknown or zero-day attacks. Since these innovations require cross-domain knowledge fusion, a deep understanding of data characteristics, and complex model design, these ideas are not easy to think of without sufficient research and experimental verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a framework diagram of an intrusion detection model proposed in a preferred embodiment of the present invention;
[0045] Figure 2 Provide a flow chart of an intrusion detection system of a preferred embodiment of the present invention;
[0046] Figure 3 Construct a graph for the graph structure described in the present invention. DETAILED DESCRIPTION
[0047] The following will describe the technical solutions in the embodiments of the present invention in detail in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only part of the embodiments of the present invention.
[0048] The technical solution of the present invention to solve the above technical problems is:
[0049] This embodiment provides an intrusion detection method based on similarity measurement and graph convolution. Figure 2 As shown in the figure, it includes five steps: data preprocessing, graph convolution network construction, similarity measurement model construction, model training and optimal model preservation, and similarity detection and intrusion detection:
[0050] (1) Data preprocessing, including the following:
[0051] Step 1: Clean the intrusion detection data, mainly for missing value processing and outlier processing, check the integrity of the data, and remove the data with missing data and detected outliers;
[0052] Step 2: Perform one-hot encoding on the cleaned data to convert non-numerical information into numerical features. For example, protocol_type TCP, UDP, and ICMP are three-dimensional numbers 001, 010, and 100 respectively after one-hot encoding.
[0053] Step 3: Use minimum and maximum value normalization to map the one-hot encoded data in equal proportion to avoid the influence of feature values that are too large or too small on the model training effect. The calculation formula of minimum and maximum value normalization is:
[0054]
[0055] Step 4: Use the self-attention mechanism to extract similarity features between high-dimensional intrusion detection data and use it as an adjacency matrix to construct graph structure data. The graph structure is constructed as follows: Figure 3 As shown;
[0056]
[0057] The data of a single sample is represented as I represents the dimension of the data. Taking the KDD-cup dataset as an example, after the data is one-hot encoded, I=122, d=1 is the depth of the data, where Q and K represent query and key, which can be respectively represented by the learnable parameters in the self-attention mechanism.
[0058] E Q and E K It is calculated by linear projection. In intrusion detection, Softmax is an activation function that scales the data to between (0,1) according to the probability. The adjacency matrix, referred to as a graph G, represents the connections between high-dimensional data for intrusion detection.
[0059] Step 5: Divide the original data into training set, validation set and test set according to 70%, 20% and 10% respectively, which are used for model training, cross-validation and effect testing respectively.
[0060] (2) Graph convolutional network construction,The graph convolutional network structure is designed according to the graph structure characteristics of intrusion detection data,including 2 convolutional layers, input layer data shape (1,122), activation function of activation layer is SELU and output layer data shape (1,122),which is then mapped to (1,16) by two fully connected layers.
[0061] The embodiment of the present invention adopts a spectrum-based graph convolutional neural network from the perspective of signal processing, converting the graph structure time domain signal to the frequency domain for further analysis. Fourier transform is the most common spectral decomposition method in signal processing, which decomposes the signal into sines and cosines of different frequencies as basis. In the graph structure, the Laplace matrix can be regarded as a regularized form of the adjacency matrix of the graph, so the task of constructing the orthogonal basis of the graph can be converted into the Laplace matrix eigenvalue decomposition.
[0062] Regularized graph Laplacian matrix is the identity matrix, E is the adjacency matrix of the graph, and D is a diagonal matrix whose diagonal values represent the number of edges connected to each node. Since the regularized graph Laplacian matrix has real symmetric semi-positive definiteness, the regularized Laplacian matrix can be decomposed into L sym =UΛU T ,U=[u0,u1,…,u n-1 ], So for a graph node vector X, the graph Fourier decomposition is defined as Inverse Graph Fourier Decomposition Graph convolution can be expressed as Gcov(X)=GF -1 (GF(X)⊙GF(g)), where g is the defined convolution kernel.
[0063] (3) Construction of similarity measurement model: Based on the characteristics of graph structure data and graph convolutional network, a similarity measurement model is designed, including the following:
[0064] Step 1: Set the distance metric of the similarity metric to calculate the 2-norm between feature vectors, and the loss function formula is expressed as:
[0065]
[0066] D W =||G w (X1)-G w (X2)||2
[0067] Among them G w (X1) and G w (X2) are low-dimensional feature vectors output by the similarity measurement model. When X1 and X2 belong to the same class, Y = 0, and the model training reduces the distance between the same classes. When they are different classes, Y = 1, and the model training increases the distance between classes. m is a constant margin, which can be set to 1 in KDD-cup data.
[0068] Step 2: Set the batch size batch_size = 32, the number of model training epochs = 150, the model learning rate lr = 0.01, and the optimizer Optimizer uses the adaptive moment estimate Adam.
[0069] (4) Model training and optimal model preservation: Use contrast loss function to optimize model parameters, cross-validate model effects through validation set data, and save the model parameters with the best performance on the validation set;
[0070] (5) Similarity detection and intrusion detection, such as Figure 1 As shown, the similarity is estimated by calculating the loss function of the test data and the known training samples. The greater the similarity, the smaller the loss function, and vice versa. By setting a threshold, such as α=0.12, if the average loss function between the test sample and multiple labeled data is lower than the threshold, the test sample is considered to be similar to the labeled data, and the test sample is regarded as an intrusion type of the labeled class. When the test sample is not similar to all labeled data, the test data is considered to be an unknown intrusion type.
[0071] The following are two specific embodiments:
[0072] Specific Example 1: Intrusion Detection on KDD Cup 99 Dataset
[0073] In this embodiment, we use the KDD Cup 99 dataset as the original data source for intrusion detection. This dataset was generated from a network attack experiment at MIT Lincoln Laboratory in 1998 and contains a large number of different types of network attacks, including DOS, U2R, R2L, Probe, etc., as well as normal network traffic.
[0074] Detailed implementation steps:
[0075] 1. Data preprocessing:
[0076] -Step 1: Clean the KDD Cup 99 dataset, remove records with missing values, and detect and process outliers.
[0077] -Step 2: One-hot encode the cleaned data and convert non-numeric features (such as protocol type, service type, flag, etc.) into numerical features to suit model training.
[0078] -Step 3: Perform minimum and maximum normalization on the one-hot encoded data to ensure that the features are on a uniform scale and avoid the dominant influence of features with large values on model training.
[0079] -Step 4: Use the self-attention mechanism to calculate the similarity between each data sample and other samples as the adjacency matrix of the graph structure, with special attention to the mutual relationships in high-dimensional data.
[0080] -Step5: Divide the dataset into 70% training set, 20% validation set and 10% test set.
[0081] 2. Graph convolutional network construction:
[0082] -Determine that the number of convolutional layers of the graph convolutional network is 2, the input layer data shape is (1,122), the activation layer uses the SELU activation function, and the output layer data shape is also set to (1,122).
[0083] -Use a double-layer fully connected layer to map the output to a low-dimensional feature space of (1,16). This step aims to reduce the dimensionality of the data and improve the computational efficiency and generalization ability of the model.
[0084] 3. Similarity measurement model construction:
[0085] -Step 1: The distance metric is set to 2-norm, and the loss function uses contrastive loss, where the margin parameter is set to 1 to ensure that the distance between the feature vectors of similar samples is small enough and the distance between heterogeneous samples is large enough.
[0086] -Step 2: The overall model training parameters are set to batch size batch_size of 32, model training epochs of 150, model learning rate lr of 0.01, and optimizer Adam to ensure that the model can converge stably and efficiently.
[0087] 4. Model training and optimal model preservation:
[0088] -Use the contrastive loss function for model training and perform cross-validation with the validation set data to evaluate the performance of the model on unseen data.
[0089] -Save the model parameters that perform best on the validation set to provide the most reliable model foundation for subsequent intrusion detection tasks.
[0090] 5. Similarity detection and intrusion detection:
[0091] - Calculate the similarity between the test data and the training samples, and classify them according to the set threshold. When the average distance between the test sample and all known intrusion types exceeds the threshold, it will be marked as an unknown intrusion type, improving the ability to identify zero-day attacks.
[0092] Extensions:
[0093] - Enhance model robustness: By introducing data enhancement techniques such as random rotation, translation, scaling and other operations, the model's ability to identify unknown attacks is further improved.
[0094] -Ensemble learning: Combining the decisions of multiple similarity measurement models, such as using ensemble learning techniques, to improve the stability and accuracy of the model.
[0095] - Real-time detection: Deploy the model in a streaming framework such as Apache Kafka or Apache Storm to implement intrusion detection on real-time network traffic.
[0096] Specific Example 2: Intrusion Detection on CICIDS2017 Dataset
[0097] In this example, we use the CICIDS2017 dataset as the raw data for intrusion detection. This dataset was released by the Canadian Innovation Center (CIC) in Kampelos, Ontario, Canada in 2017 and covers the latest network attack types such as Botnet, Brute Force, DDoS, etc.
[0098] Detailed implementation steps:
[0099] 1. Data preprocessing:
[0100] -Step 1: Clean the CICIDS2017 dataset and process outliers to ensure data quality.
[0101] -Step 2: Perform one-hot encoding to convert non-numerical features into numerical features for easy model processing.
[0102] -Step 3: Perform minimum and maximum normalization to ensure consistent feature scales.
[0103] -Step 4: Use the self-attention mechanism to establish the graph structure relationship between the data and form an adjacency matrix.
[0104] -Step 5: Divide the dataset into training set, validation set and test set in proportion.
[0105] 2. Graph convolutional network construction:
[0106] - Considering the complexity of the CICIDS2017 dataset, a deeper graph convolutional network is designed, such as setting the number of convolutional layers to 3 and adjusting the input and output layer data shapes according to the characteristics of the dataset.
[0107] - You can try various activation functions, such as ReLU, tanh, etc., to find the function that best suits the characteristics of the data.
[0108] 3. Similarity measurement model construction:
[0109] -Set the distance metric, such as using cosine similarity instead of 2-norm, to adapt to the feature distribution in the CICIDS2017 dataset.
[0110] - Adjust model training parameters such as batch_size, epoch, lr and optimizer. Depending on the size and characteristics of the dataset, you may need to adjust batch_size = 64, epoch = 200, lr = 0.001.
[0111] 4. Model training and optimal model preservation:
[0112] -During the training process, periodic cross-validation is used to ensure the performance of the model on the validation set to preserve the optimal model parameters.
[0113] 5. Similarity detection and intrusion detection:
[0114] -After similarity calculation, combined with the characteristics of the CICIDS2017 dataset, a stricter threshold is set for classification to improve the accuracy of intrusion detection.
[0115] Extensions:
[0116] - Deep Graph Networks: Consider using more complex graph neural network architectures such as GraphSAGE or GAT (Graph Attention Network) to adapt to the high dimensionality and complexity of the CICIDS2017 dataset.
[0117] -Semi-supervised learning: Since the CICIDS2017 dataset may contain a small amount of labeled data, a semi-supervised learning strategy can be adopted to enhance the learning ability of the model using unlabeled data.
[0118] -Multi-model fusion: By fusing multiple models based on different architectures (such as LSTM, CNN), the diversity of the model and the overall detection performance can be improved.
[0119] These two specific examples demonstrate the applicability and flexibility of the intrusion detection method based on similarity measurement and graph convolution on different data sets. By adjusting the model parameters and architecture, it can be optimized for specific intrusion detection scenarios, thereby improving the detection efficiency and accuracy of the model.
[0120] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions.
[0121] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0122] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0123] The above embodiments should be understood to be only used to illustrate the present invention and not to limit the protection scope of the present invention. After reading the contents of the present invention, technicians can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. An intrusion detection method based on similarity measurement and graph convolution, characterized in that: The following steps are involved: a) Data preprocessing, including data cleaning, one-hot encoding, normalization, graph structure construction, and data set partitioning; b) Construct a graph convolutional network to extract features from graph structure data; c) Construct a similarity measurement model and perform distance measurement based on the feature output of the graph convolutional network; d) Train the model and save the optimal model; e) By calculating the similarity between the test data and the training samples, the data is classified as normal data or a certain intrusion type.
2. The intrusion detection method according to claim 1, characterized in that: The step a) of data preprocessing specifically includes the following contents: Perform data cleaning on intrusion detection data, including missing value processing and outlier processing; Perform one-hot encoding on the cleaned data to convert non-numerical information into numerical features; Normalize the one-hot encoded data; Use the self-attention mechanism to extract similarity features between high-dimensional intrusion detection data and use it as an adjacency matrix to construct graph structure data; The data is divided into training set, validation set and test set according to a certain ratio, which are used for model training, cross-validation and effect testing respectively.
3. The intrusion detection method according to claim 1, characterized in that: The step b) of graph convolutional network design includes determining the number of convolutional layers, input layer data shape, activation function and output layer data shape to adapt to non-Euclidean distance feature extraction of intrusion detection data.
4. The intrusion detection method according to claim 1, characterized in that: The step c) constructs a similarity measurement model and performs distance measurement based on the feature output of the graph convolutional network, specifically including: Step 1: Set the distance measurement method of similarity measurement including Euclidean distance, Manhattan distance and Chebyshev distance to calculate the distance between feature vectors; Step 2: Set the overall model training parameters, including batch size batch_size, model training epochs, model learning rate lr, and optimizer Optimizer.
5. The intrusion detection method according to claim 1, characterized in that: In the model training and optimal model saving steps, validation set data is used for cross-validation to ensure the generalization performance of the model, and the model parameters with the best performance on the validation set are saved for subsequent intrusion detection.
6. The intrusion detection method according to claim 1, characterized in that: The step e) classifies the test data into normal data or a certain intrusion type by calculating the similarity between the test data and the training samples, specifically including: In the similarity detection and intrusion detection steps, by calculating the average similarity between the test sample and multiple labeled samples, when the similarity between the test sample and all labeled samples is lower than the set threshold, it is classified as an unknown intrusion type to improve the recognition compatibility of zero-day attacks.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the intrusion detection method based on similarity measurement and graph convolution as described in any one of claims 1 to 6 is implemented.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the intrusion detection method based on similarity measurement and graph convolution as claimed in any one of claims 1 to 6 is implemented.
9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the intrusion detection method based on similarity measurement and graph convolution as claimed in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Intrusion alarm message association method based on graph convolutional network
CN112861913A
An intrusion detection method, electronic device and storage medium based on parallel metric learning
CN116743473B