Attack detection method and system based on chaotic mapping and transformation of credential
By applying chaotic mapping and transformation technology based on information and innovation in network attack detection, feature transformation and Lyapunov index judgment are performed on network traffic data, combined with neural network model to identify attack types, the problem of false alarms and missed reports by traditional detection methods in the face of complex attacks is solved, and higher detection accuracy and adaptability are achieved.
Patent Information
- Application Number
- CN202411951447.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-13
AI Technical Summary
When traditional cyberattack detection methods face complex and changeable cyberattacks, they have high false alarm rates and missed alarm rates, making it difficult to effectively detect new or unknown attacks.
The attack detection method based on chaotic mapping and transformation is adopted, and multiple chaotic mapping and feature combinations are performed on network traffic data, the Lyapunov index is calculated to judge the attack traffic, and the attack type is identified using the pre-trained neural network model.
It improves the accuracy and adaptability of attack detection, reduces the false alarm rate and missed alarm rate, enhances the detection ability of unknown attacks, and maintains high detection accuracy and real-time performance in complex network environments.
Smart Images

Figure CN119995932A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network attack detection, and specifically to an attack detection method and system based on chaotic mapping and transformation of information creation. Background Art
[0002] With the continuous development of the information society and the widespread application of Internet technology, network security issues are becoming increasingly severe, especially the continuous evolution of various forms of network attacks against enterprises and individual users, which poses a huge threat to the network environment. From the initial viruses and Trojans to today's DDoS attacks, malware, APT attacks (advanced persistent threats), etc., the attack methods have become more complex and diverse. These attacks are usually hidden, widespread, and destructive. Traditional attack detection methods based on feature matching or rule bases face great challenges. When detecting new or unknown attacks, traditional methods often have high false alarm rates and missed rates. However, in the face of complex network attacks, how to improve detection accuracy, reduce false alarm rates, and be able to cope with the challenges of unknown attacks is still the focus of research in the current field of network security. Chaotic systems have the characteristics of high randomness, nonlinearity, and unpredictability. These characteristics enable chaotic mapping to effectively increase the complexity of data when simulating and detecting the behavior of network attacks, thereby improving the robustness and accuracy of attack detection.
[0003] Existing attack detection technologies based on chaos theory mainly focus on using chaotic mapping to generate pseudo-random sequences, perturbing or transforming network traffic data to enhance the distinguishability of traffic features, thereby improving the accuracy of attack detection. These technologies usually introduce the complexity of chaotic mapping to make the characteristic distribution difference between attack behavior and normal traffic more significant. Some existing technical solutions combine chaotic mapping sequences with traditional machine learning algorithms to introduce chaotic perturbations in the feature extraction and classification process to improve the accuracy and stability of classification. For example, the traffic features are perturbed using a random sequence generated by chaotic mapping, and then the traffic is distinguished between normal traffic and attack traffic by a classifier. These methods have improved the detection capability of unknown attack patterns to a certain extent, but there are still some problems, such as the high computational complexity and poor real-time performance caused by the nonlinear problems of chaotic mapping and feature transformation processes. Therefore, the present invention proposes an attack detection algorithm based on chaotic mapping and transformation of Xinchuang, which further improves the adaptability and real-time performance of the algorithm by optimizing chaotic mapping parameters to adapt to changes in network attack patterns, thereby better coping with variable network attack scenarios. Summary of the invention
[0004] In response to the technical problems in the prior art, the present application proposes an attack detection method and system based on chaotic mapping and transformation of information technology.
[0005] According to one aspect of the present invention, a method for attack detection based on chaotic mapping and transformation is proposed, the method comprising:
[0006] S1, collecting various characteristic data of network traffic data, and preprocessing the characteristic data;
[0007] S2, performing multiple chaotic mappings on the processed feature data to obtain a chaotic sequence, and combining the chaotic sequences of the feature data to obtain the chaotic features of the network traffic data;
[0008] S3, judging whether the network traffic data is attack traffic data based on the calculated Lyapunov exponent of the chaotic feature;
[0009] S4, when it is determined that the network traffic data is attack traffic data, the chaotic features are input into a pre-trained first neural network model for identification and classification to determine the traffic attack type.
[0010] Preferably, the various characteristic data of the network traffic data specifically include: the number of bytes of the data packet, the timestamp of the data packet arrival, the IP addresses of the source IP address and the target IP address of the data packet, the protocol type, and the interval time of sending the data packet.
[0011] Preferably, the characteristic data is preprocessed, specifically including normalizing each characteristic data of the network traffic data by x′=[x-min(x)] / [max(x)-min(x)], wherein x′ represents each characteristic data after processing, x represents each characteristic data of the network traffic data, min(x) represents the minimum value of each characteristic data of the network traffic data, and max(x) represents the maximum value of each characteristic data of the network traffic data.
[0012] Preferably, the processed characteristic data is subjected to multiple chaotic mappings to obtain a chaotic sequence, which specifically includes: setting a control parameter r, and the processed characteristic data is mapped by a Logistic mapping formula x n+1 = r·x n ·(1-x n ) is iterated multiple times, and the state value obtained in each iteration constitutes the chaotic sequence, where x n It represents the nth state value obtained by bringing the processed feature data into the Logistic mapping formula, x n+1Indicates the n+1th state value obtained by bringing the processed feature data into the Logistic mapping formula. By introducing chaotic mapping into the transformation process of network traffic features, the complexity and unpredictability of traffic data can be effectively increased. The nonlinear chaotic mapping enhances the difference between attack traffic and normal traffic, making the attack behavior more prominent in the data, thereby improving the accuracy of detection. When facing unknown attacks or variant attacks, the feature transformation introduced by chaotic mapping makes it difficult to hide traditional attack patterns, enhancing the algorithm's ability to identify new attacks.
[0013] Further preferably, judging whether the network traffic data is attack traffic data based on calculating the Lyapunov exponent of the chaotic feature specifically includes: Calculate the Lyapunov exponent of the chaotic sequence, where: When the obtained Lyapunov exponent λ is greater than 0, it is determined that the network traffic data is attack traffic data.
[0014] Further preferably, the types of traffic attacks judged by the first neural network model include DDoS attacks, port scanning attacks, and SQL injection attacks. Traditional network attack detection algorithms often rely on static attack features, which can easily lead to false positives and false negatives, especially when facing variable network traffic. Through the dynamic perturbation of network traffic features by chaotic mapping, the present invention can make the characteristics of attack traffic and normal traffic more distinct, avoiding the difficulty of traditional methods in identifying in complex traffic environments. Most existing attack detection systems rely on known attack features for identification, while new attacks and variant attacks are often difficult to detect by traditional feature matching methods. By using the nonlinear characteristics of chaotic mapping, the present invention can generate more unpredictable traffic features, enhance the expressiveness of attack data, and help machine learning models better identify attack patterns that are difficult to detect by traditional methods. When dealing with zero-day attacks or unrecognized complex attacks, the system can effectively identify features enhanced by chaotic mapping, thereby improving the ability to detect unknown attacks.
[0015] More preferably, the control parameter r is 3.56-4.
[0016] According to one aspect of the present invention, an attack detection system based on chaotic mapping and transformation is proposed, comprising the following modules:
[0017] Feature data processing module: collects various feature data of network traffic data, and pre-processes the feature data;
[0018] Chaotic feature acquisition module: performs multiple chaotic mappings on the processed feature data to obtain a chaotic sequence, and combines the chaotic sequences of the feature data to obtain the chaotic features of the network traffic data;
[0019] Attack traffic judgment module: judging whether the network traffic data is attack traffic data based on the Lyapunov exponent calculated from the chaotic feature;
[0020] Attack type judgment module: When the network traffic data is judged to be attack traffic data, the chaotic features are input into a pre-trained first neural network model for identification and classification to judge the traffic attack type.
[0021] According to one aspect of the present invention, a computer program product is provided, on which a computer program is stored. When the computer program is executed by a processor, the method according to any one of the first aspects is implemented.
[0022] According to one aspect of the present invention, a computing system is provided, comprising a processor and a memory, wherein the processor is configured to execute the method as described in any one of the first aspects.
[0023] The present invention is beneficial in that:
[0024] Provided is an attack detection algorithm based on chaotic mapping and transformation of Xinchuang, which improves the intelligence, adaptability and accuracy of the attack detection system by integrating chaos theory and network security detection technology; by dynamically adjusting the parameters of the chaotic mapping, the feature transformation process is optimized according to the real-time network traffic and environmental changes, so that the detection system can flexibly adapt to various network environments and traffic pattern changes. This adaptability enhances the stability and effectiveness of the system in a complex and changeable network environment; by using the nonlinear characteristics of the chaotic mapping, the present invention can generate more unpredictable traffic features, enhance the expressiveness of the attack data, and help the machine learning model better identify the attack mode that is difficult to detect by traditional methods. When dealing with zero-day attacks or unrecognized complex attacks, the system can effectively identify the features strengthened by the chaotic mapping, thereby improving the detection capability of unknown attacks; by dynamically disturbing the network traffic features through the chaotic mapping, the present invention can make the features of the attack traffic and the normal traffic more distinct, avoiding the difficulty of identification of the traditional method in a complex traffic environment. Therefore, while improving the accuracy of attack identification, the present invention significantly reduces the false alarm rate and the missed alarm rate, thereby improving the reliability of the network security system. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated into and constitute a part of this specification. The accompanying drawings illustrate the embodiments and are used together with the description to explain the principles of the present invention. It will be easy to recognize other embodiments and many expected advantages of the embodiments because they become better understood by reference to the following detailed description. The elements of the drawings are not necessarily to scale with each other. The same reference numerals refer to corresponding similar parts.
[0026] Figure 1 A schematic flow chart of an attack detection method based on chaotic mapping and transformation of information creation according to the present invention is shown;
[0027] Figure 2 A structural schematic diagram of an attack detection system based on chaotic mapping and transformation according to the present invention is shown;
[0028] Figure 3 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown. DETAILED DESCRIPTION
[0029] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It should also be noted that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.
[0030] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0031] like Figure 1 As shown, the present application proposes an attack detection method based on chaotic mapping and transformation of information creation, the method comprising:
[0032] S1, collecting various characteristic data of network traffic data, and preprocessing the characteristic data;
[0033] S2, performing multiple chaotic mappings on the processed feature data to obtain a chaotic sequence, and combining the chaotic sequences of the feature data to obtain the chaotic features of the network traffic data;
[0034] S3, judging whether the network traffic data is attack traffic data based on the calculated Lyapunov exponent of the chaotic feature;
[0035] S4, when it is determined that the network traffic data is attack traffic data, the chaotic features are input into a pre-trained first neural network model for identification and classification to determine the traffic attack type.
[0036] Preferably, the various characteristic data of the network traffic data specifically include: the number of bytes of the data packet, the timestamp of the data packet arrival, the IP addresses of the source IP address and the target IP address of the data packet, the protocol type, and the interval time of sending the data packet.
[0037] Among them, character-type traffic features such as protocol type and IP address are first converted into numerical data and then normalized.
[0038] Preferably, the characteristic data is preprocessed, specifically including normalizing each characteristic data of the network traffic data by x′=[x-min(x)] / [max(x)-min(x)], wherein x′ represents each characteristic data after processing, x represents each characteristic data of the network traffic data, min(x) represents the minimum value of each characteristic data of the network traffic data, and max(x) represents the maximum value of each characteristic data of the network traffic data.
[0039] The algorithm can optimize the mapping process in real time according to the changes in traffic characteristics and attack patterns in different network environments. The innovation of this mechanism lies in its dynamic adaptability, which can ensure that high detection accuracy and low false alarm rate can be maintained in various network environments.
[0040] This ensures that the input data fits the chaotic system and avoids values that are too large or too small. For example, the packet size range is [20, 1500] bytes, which can be normalized to a value between [0, 1] through a linear mapping.
[0041] For data with a packet size range of [20,1500] bytes, it can be normalized to a value between [0,1] using the above formula. The steps are as follows:
[0042] 1. Calculate the minimum and maximum packet sizes in the dataset.
[0043] 2. Apply the above formula to convert the size of each packet into a value in the [0,1] interval.
[0044] The processed feature data is subjected to multiple chaotic mappings to obtain a chaotic sequence, which specifically includes: setting the control parameter r, and the processed feature data is mapped by the Logistic mapping formula x n+1 = r·x n ·(1-x n ) is iterated multiple times, and the state value obtained in each iteration constitutes the chaotic sequence, where x n It represents the nth state value obtained by bringing the processed feature data into the Logistic mapping formula, x n+1 The n+1th state value obtained by bringing the processed feature data into the Logistic mapping formula. Determining whether the network traffic data is attack traffic data based on the calculation of the Lyapunov exponent of the chaotic feature specifically includes: Calculate the Lyapunov exponent of the chaotic sequence, where: When the obtained Lyapunov exponent λ is greater than 0, it is determined that the network traffic data is attack traffic data.
[0045] The nonlinear and highly complex characteristics of chaotic mapping are combined with network traffic feature transformation to achieve network attack detection. By applying chaotic mapping to the feature extraction and transformation process of network traffic, the unpredictability and complexity of traffic data can be significantly enhanced, making the difference between network attack patterns and normal traffic patterns more prominent. Chaotic mapping can bring a powerful dynamic disturbance effect to traditional detection methods and enhance the detection ability of the system in complex network environments.
[0046] By transforming the feature space of traffic data, the distinguishability between attack traffic and normal traffic is further improved. The feature transformation based on the chaotic mapping of Xinchuang can effectively avoid the noise interference that traditional methods are susceptible to, making the patterns of attack traffic and normal traffic clearer, thereby improving the stability and accuracy of the algorithm in complex network environments.
[0047] Assuming that the normalized initial value of a data packet size is x0=0.5 and the control parameter r=3.7, an iterative calculation is performed according to the Logistic mapping formula to obtain a series of state values:
[0048] x1=3.7·0.5·(1-0.5)=0.925
[0049] x2=3.7·0.925·(1-0.925)=0.256875
[0050] x3=3.7·0.256875·(1-0.256875)=0.70822265625…
[0051] And so on, until enough state values are obtained. And so on, after 100 iterations, a chaotic sequence is obtained: x1 x2 x3...x 100 .
[0052] Since there are multiple traffic features, each feature generates a sequence through chaotic mapping, and these sequences can be combined into a high-dimensional chaotic sequence as a chaotic feature. If there are 5 features, each feature generates 100 state values, then the final high-dimensional chaotic sequence will be a 100x5 matrix.
[0053] Then based on the logarithm of the absolute value of the derivative calculated at each iteration step:
[0054] log|r-2rx1|=log|3.7-2·3.7·0.925|
[0055] log|r-2rx2|=log|3.7-2·3.7·0.256875|
[0056] log|r-2rx3|=log|3.7-2·3.7·0.70822265625|
[0057] …
[0058] Sum these values and divide them by the number of iterations n to get the approximate value of the Lyapunov exponent. If the calculated Lyapunov exponent λ is greater than 0, it means that the system is chaotic, that is, it is very sensitive to the initial conditions. It may be attacked by DDoS, port scanning, or SQL injection.
[0059] Use chaos mapping to map the normalized data to the state space of the chaotic system. By iterating the chaotic mapping function, each output can be used as a point in the state space. As the number of iterations increases, the chaotic system will show sensitivity and complex nonlinear behavior, thereby revealing small changes in network traffic and potential attack patterns. By iterating the Logistic mapping formula multiple times, the network traffic feature sequence is gradually displayed in the state space of the chaotic system. As the number of iterations increases, the chaotic system exhibits more complex behavior, and any small traffic change will produce obvious fluctuations in the state space.
[0060] By observing the evolution trajectory of the state space in the chaotic system, the difference between normal traffic and abnormal traffic can be captured. Attack behaviors (such as DDoS attacks, port scanning, etc.) usually cause sudden changes in traffic patterns, and the mapped state space trajectory shows abnormal distribution or bifurcation, so that potential attacks can be detected. For example, DDoS attacks usually manifest as a large amount of burst traffic, which leads to significant changes in the state space trajectory in the chaotic system, manifested as a sharp deviation of the trajectory from the normal trajectory. This deviation can be used as a signal for anomaly detection. The chaotic features corresponding to various attack types are input into the first network model, and the algorithm can identify the attack mode based on the changing trend of the features and their comparison with historical data. If attack traffic is detected, the system will immediately issue an alarm and initiate a predetermined response mechanism, such as blocking attack traffic, adjusting firewall policies, or notifying security administrators.
[0061] Lyapunov exponent - used to quantify the degree of chaos in a system and predict the long-term behavior of the system. In the present invention, the Lyapunov exponent is positive, indicating that small changes in the system can lead to huge differences in long-term behavior. Different attack modes may show different characteristics in the Lyapunov exponent. Certain attacks may cause the positive and negative changes of the Lyapunov exponent to be unstable, etc. The Lyapunov exponent indicator in chaos theory is used to analyze high-dimensional chaotic sequences. For example, during a DDoS attack, network traffic will increase dramatically, resulting in significant changes in the value of the Lyapunov exponent, and the values of various indicators will fluctuate abnormally, which is significantly higher than the value of normal traffic. Further analysis and judgment of the chaotic characteristics are performed to distinguish normal traffic from attack traffic.
[0062] The control parameter r is 3.7, which is an empirical value and a commonly used value. It does not have to be equal to 3.7. The normal value of r is between 3.56 and 4. In this range, chaotic behavior can be exhibited.
[0063] Further preferably, the types of traffic attacks judged by the first neural network model include DDoS attacks, port scan attacks, and SQL injection attacks. The method of combining the features after chaos mapping with the machine learning model, especially the application in the feature preprocessing and model training process. The nonlinear features generated by the chaotic mapping enable the machine learning model to obtain more diverse and complex input data, thereby enhancing its ability to detect network attacks, and can still maintain efficient performance in the face of large amounts of complex network traffic, especially in the scenario of real-time detection and response to network attacks, providing strong support.
[0064] Once the system identifies abnormal traffic and determines the corresponding attack type, it will automatically defend based on the classification results.
[0065] In order to further verify the effectiveness of the present invention, multiple experiments were conducted. Some experimental data are shown in Table 1:
[0066] Table 1
[0067]
[0068] The recall rate is also called sensitivity, which indicates the proportion of positive samples correctly detected by the model to all actual positive samples. The recall rate measures how many real attacks are correctly identified. Recall rate = attack samples correctly identified by the model / all samples.
[0069] The F1 value is the harmonic mean of precision and recall. Precision indicates the proportion of samples predicted by the model as attacks that are actually attacks. Among them, F1 value = precision * recall / (precision + recall).
[0070] Judging from the experimental data, the attack detection algorithm based on chaotic mapping and transformation can achieve high detection accuracy in a variety of attack scenarios, while having low missed alarm rate and false alarm rate, showing good real-time and high efficiency.
[0071] It is worth noting that, in theory, the method proposed in the present invention can identify a variety of different attack types, including brute force cracking, domain name hijacking attacks, etc. The above identification results should not be improperly understood as limiting the scope of protection and application of the present invention.
[0072] Although the chaotic mapping process increases the complexity of the data, the above experimental structure proves that the present invention reduces redundant calculations and unnecessary processing steps by optimizing the calculation process of chaotic mapping, and effectively improves the calculation efficiency of the algorithm. In a large-scale network environment, the algorithm of the present invention can maintain a high real-time performance and respond to attack behaviors in the network in a timely manner. This is crucial for real-time monitoring and defense against attacks, especially in a high-traffic environment, which can ensure that the system can identify and respond to network attacks in real time without affecting performance.
[0073] The network environment and traffic patterns are dynamically changing. Traditional attack detection systems usually rely on fixed feature libraries and rules, which makes them less adaptable. In contrast, the present invention dynamically adjusts the parameters of the chaotic map and optimizes the feature transformation process according to real-time network traffic and environmental changes, so that the detection system can flexibly adapt to various network environments and traffic pattern changes. This adaptability enhances the stability and effectiveness of the system in complex and changing network environments.
[0074] According to one aspect of the present invention, an attack detection system based on chaotic mapping and transformation is proposed, comprising the following modules:
[0075] Feature data processing module 201: collects various feature data of network traffic data, and pre-processes the feature data;
[0076] Chaotic feature acquisition module 202: performing multiple chaotic mappings on the processed feature data to obtain a chaotic sequence, and combining the chaotic sequences of the feature data to obtain the chaotic features of the network traffic data;
[0077] Attack traffic judgment module 203: judging whether the network traffic data is attack traffic data based on the calculated Lyapunov exponent of the chaotic feature;
[0078] Attack type determination module 204: When it is determined that the network traffic data is attack traffic data, the chaotic features are input into a pre-trained first neural network model for identification and classification to determine the traffic attack type.
[0079] Reference below Figure 3 , which shows a schematic diagram of the structure of a computer system 300 suitable for implementing an electronic device of an embodiment of the present application. Figure 3 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0080] like Figure 3 As shown, the computer system 300 includes a central processing unit (CPU) 301, which performs various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage part 309 into a random access memory (RAM) 304. In the RAM 304, various programs and data required for the operation of the system 300 are also stored. The CPU 301, the ROM 302, the ROM 303, and the RAM 304 are connected to each other through a bus 305. An input / output (I / O) interface 306 is also connected to the bus 305.
[0081] The following components are connected to the I / O interface 306: an input section 307 including a keyboard, a mouse, etc.; an output section 308 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 309 including a hard disk, etc.; and a communication section 310 including a network interface card such as a LAN card, a modem, etc. The communication section 310 performs communication processing via a network such as the Internet. A drive 311 is also connected to the I / O interface 306 as needed. A removable medium 312, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 311 as needed so that a computer program read therefrom is installed into the storage section 309 as needed.
[0082] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart is implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program is downloaded and installed from the network through the communication part 310, and / or installed from the removable medium 312. When the computer program is executed by the central processing unit (CPU) 301, the above-mentioned functions defined in the method of the present application are executed.
[0083] It should be noted that the computer-readable storage medium of the present application is a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium is, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium is any tangible medium containing or storing a program that is used by or in combination with an instruction execution system, device or device. In the present application, a computer-readable signal medium includes a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal takes a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium is any computer-readable storage medium other than a computer-readable storage medium that sends, propagates or transmits a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer-readable storage medium is transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0084] Computer program code for performing the operations of the present application is written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code is executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer is connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or is connected to an external computer (e.g., via the Internet using an Internet service provider).
[0085] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram represents a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the box also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession are actually executed substantially in parallel, and they are sometimes also executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart, are implemented by a dedicated hardware-based system that performs the specified function or operation, or are implemented by a combination of dedicated hardware and computer instructions.
[0086] The modules involved in the embodiments of the present application are implemented by software and hardware.
[0087] As another aspect, the present application also provides a computer-readable storage medium, which is included in the electronic device described in the above embodiment; it also exists independently and is not assembled into the electronic device. The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device: S1, collects various feature data of network traffic data, and the feature data is preprocessed; S2, performs multiple chaotic mapping on the processed feature data to obtain a chaotic sequence, and combines the chaotic sequences of the various feature data to obtain the chaotic features of the network traffic data; S3, based on the calculation of the Lyapunov exponent of the chaotic feature, determines whether the network traffic data is attack traffic data; S4, when the network traffic data is determined to be attack traffic data, the chaotic feature is input into the pre-trained first neural network model for identification and classification to determine the type of traffic attack.
[0088] The above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other to form a technical solution.
Claims
1. An attack detection method based on chaotic mapping and transformation of information creation, characterized in that: The following steps are involved: S1, collecting various characteristic data of network traffic data, and preprocessing the characteristic data; S2, performing multiple chaotic mappings on the processed feature data to obtain a chaotic sequence, and combining the chaotic sequences of the feature data to obtain the chaotic features of the network traffic data; S3, judging whether the network traffic data is attack traffic data based on the calculated Lyapunov exponent of the chaotic feature; S4, when it is determined that the network traffic data is attack traffic data, the chaotic features are input into a pre-trained first neural network model for identification and classification to determine the traffic attack type.
2. According to claim 1, a method for detecting attacks based on chaotic mapping and transformation of information creation, characterized in that: The characteristic data of the network traffic data specifically include: the number of bytes of the data packet, the timestamp of the data packet arrival, the IP address of the source IP address and the destination IP address of the data packet, the protocol type, and the interval time of sending the data packet.
3. According to claim 1, a method for attack detection based on chaotic mapping and transformation of information creation, characterized in that: The characteristic data is preprocessed, specifically including normalizing the various characteristic data of the network traffic data through x′=[x-min(x)] / [max(x)-min(x)], wherein x′ represents the processed characteristic data, x represents the various characteristic data of the network traffic data, min(x) represents the minimum value of the various characteristic data of the network traffic data, and max(x) represents the maximum value of the various characteristic data of the network traffic data.
4. According to claim 1, a method for detecting attacks based on chaotic mapping and transformation of information creation, characterized in that: The processed feature data is subjected to multiple chaotic mappings to obtain a chaotic sequence, which specifically includes: setting the control parameter r, and the processed feature data is mapped by the Logistic mapping formula x n+1 = r·x n ·(1-x n ) is iterated multiple times, and the state value obtained in each iteration constitutes the chaotic sequence, where x n It represents the nth state value obtained by bringing the processed feature data into the Logistic mapping formula, x n+1 It represents the n+1th state value obtained by bringing the processed feature data into the Logistic mapping formula.
5. According to claim 4, a method for detecting attacks based on chaotic mapping and transformation of information creation, characterized in that: Determining whether the network traffic data is attack traffic data based on calculating the Lyapunov exponent of the chaotic feature specifically includes: Calculate the Lyapunov exponent of the chaotic sequence, where: When the obtained Lyapunov exponent λ is greater than 0, it is determined that the network traffic data is attack traffic data.
6. According to claim 4, the attack detection method based on chaotic mapping and transformation of information creation is characterized in that: The traffic attack types judged by the first neural network model include DDoS attacks, port scanning attacks, and SQL injection attacks.
7. The attack detection method based on chaotic mapping and transformation of information creation according to claim 4 or 5 is characterized in that: The control parameter r is 3.56~4.
8. An attack detection system based on chaotic mapping and transformation of information creation, characterized in that: Includes the following modules: Feature data processing module: collects various feature data of network traffic data, and pre-processes the feature data; Chaotic feature acquisition module: performs multiple chaotic mappings on the processed feature data to obtain a chaotic sequence, and combines the chaotic sequences of the feature data to obtain the chaotic features of the network traffic data; Attack traffic judgment module: judging whether the network traffic data is attack traffic data based on the Lyapunov exponent calculated from the chaotic feature; Attack type judgment module: When the network traffic data is judged to be attack traffic data, the chaotic features are input into a pre-trained first neural network model for identification and classification to judge the traffic attack type.
9. A computer program product having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 7.
10. A computing system comprising a processor and a memory, wherein the processor is configured to execute the method according to any one of claims 1 to 7.
Citation Information
Cited By
Chaotic watermark-based network attack event traceability processing method and device, and medium
CN120811802A