Multi-modal data fusion network attack detection method
Through multi-dimensional attribute analysis of network traffic data and multi-source data fusion, a multi-modal attack detection model is built, which solves the problem of insufficient detection based on a single data source in the existing technology, and achieves higher detection accuracy and flexibility.
Patent Information
- Application Number
- CN202510047765.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing cyber attack detection methods are mainly based on a single data source, resulting in incomplete feature extraction and information loss, low detection accuracy, high false alarm rate, and insufficient model generalization capabilities, making it impossible to accurately identify new attacks.
By obtaining and analyzing the multi-dimensional attributes of network traffic data in real time, including time attributes, spatial attributes and network traffic eigen-attributes, and combining attack path maps, terminal device log data and threat intelligence data, cross-modal interactive learning is carried out to build a multi-modal attack detection model.
This method breaks the limitations of traditional single data source detection, makes full use of the correlation and complementarity of multi-source data, improves the accuracy and flexibility of network attack detection, and can more effectively identify complex and changeable network attack behaviors, and reduces the rate of missed and false alarms.
Smart Images

Figure CN119995947A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network security, and in particular to a network attack detection method based on multi-modal data fusion. Background Art
[0002] With the continuous expansion of information systems and IoT devices and their increasingly widespread application in various fields, the frequent occurrence of cyber attacks has become a serious problem, posing a major threat to the information security of countries and enterprises. How to predict and effectively prevent cyber attacks before they occur has become a topic of great concern and urgent resolution.
[0003] The invention patent with announcement number CN116844213A discloses a multimodal face presentation attack detection method based on a spatiotemporal decomposition encoder, including: 1. Obtain samples from a multimodal video dataset and generate feature representations; 2. Construct a feature converter to generate a spatial embedding representation, construct a spatiotemporal decomposition encoder to extract unimodal features, construct a fusion encoder to fuse multimodal features, and input the final classification result into a classifier; 3. Construct a concentrated contrast loss and a binary cross entropy loss, use an optimizer to train and update model parameters; 4. Input the video to be tested to test the model to ensure that the model can effectively distinguish between real faces and presented attack faces. This method can improve the accuracy and robustness of face presentation attack detection, thereby ensuring the security of the face recognition system. However, the existing attack detection and recognition methods are mainly based on a single data source, such as the temporal attributes or spatial attributes of network traffic, which leads to incomplete feature extraction and information loss, and there are problems such as low detection accuracy and high false alarm rate. Due to the diversity and variability of network attacks, the lack of training data may lead to insufficient generalization ability of the model and inability to accurately identify new attacks. Summary of the invention
[0004] In view of the deficiencies of the prior art, the present invention provides a network attack detection method of multimodal data fusion to solve the existing problems.
[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: a network attack detection method based on multimodal data fusion, comprising the following steps:
[0006] Step 1: Acquire network traffic data in real time, and analyze attribute information of the network traffic data, including time attributes, space attributes, intrinsic attributes of the network traffic, firewall related information, and network attack rules;
[0007] Step 2: Analyze the time attributes to extract time series features; analyze the space attributes to extract spatial distribution features; analyze the network traffic intrinsic attributes to extract intrinsic features, and generate an attack path diagram based on network attack rules and network models;
[0008] Step 3: splicing and fusing the time series features, the spatial distribution features, and the intrinsic features, and performing cross-modal interactive learning on the features of the attack path map, terminal device log data, and threat intelligence data to form a multimodal evidence chain database, and construct a multimodal attack detection model;
[0009] Step 4: Activate the multimodal attack detection model and use the activated multimodal attack detection model to provide a weight score for each potential attack route;
[0010] Step 5: Receive the current user's real-time data, and input the current user's real-time data into the multimodal attack detection model to determine whether there is a network attack.
[0011] Preferably, the time attributes include data packet arrival time, sending time, duration, interval time, arrival order, sending frequency, time distribution pattern, time correlation, and time window statistical characteristics;
[0012] The spatial attributes include the source IP address, destination IP address, source port number, and destination port number of the data packet;
[0013] The network traffic intrinsic attributes include data packet length, transmission protocol, TCP flag, and IP protocol version.
[0014] Preferably, the firewall related information and network attack rules include:
[0015] The connection matrix L of all nodes in the network is determined by the following formula, and L is used to represent the network connectivity:
[0016]
[0017] Where n represents the total number of hosts in the network. When nodes i and j are reachable, l ij The value of is 1. When nodes i and j are unreachable, l ij The value of is 0, i∈[1,n], j∈[1,n];
[0018] The network security attribute A is determined by the following formula:
[0019]
[0020] Among them, W is the vulnerability set, I is the intention set, W includes the CVE number of the vulnerability, I includes the name and action point of the network attack intention, S is the node network state set, S = {S0, S1, S2, ..., S n},S i ∈S,S i represents the network status of the i-th node, S0 represents the node where the attack starts, S t represents the node where the attack ends, t∈[0,n], E represents all possible attack methods between nodes, R represents the network attack rule, the network vulnerability label is mun, the minimum weight required for the attacker to attack the initiating host before the intrusion attack is lege, and the minimum weight required for the attacker to attack the target host before the intrusion attack is privilege;
[0021] The following formula is used to determine the total authority state p of the attacker in the entire network after losing control of node i, where pi represents the attacker's authority state on node i:
[0022]
[0023] The following formula is used to describe the attacker's expected attack effect on node i:
[0024]
[0025] Among them, Z(ε) represents the host attribute, k(s) represents the attack behavior in the network, and θ(s) represents each attack on all paths in the network attack graph.
[0026] Preferably, analyzing the time attribute specifically includes:
[0027] Sorting the network traffic data in chronological order; extracting data within the time window using a sliding window;
[0028] Perform numerical statistical analysis of the mean value and variance on the data within the time window.
[0029] Preferably, analyzing the spatial attributes specifically includes:
[0030] Grouping the network traffic data according to source IP address, destination IP address, source port number, and destination port number;
[0031] Perform cluster analysis on each IP address group or port number, including calculating traffic size and number of connections.
[0032] Preferably, analyzing the intrinsic attributes of the network traffic specifically includes:
[0033] The analysis of the length of the data packet includes calculating the length distribution of the data packet by calculating the statistical indicators of the average length, the maximum length and the minimum length;
[0034] According to the transmission protocols of the data packets, including TCP, UDP, and ICMP, the traffic ratios of different protocols are counted, and the usage of the protocols is analyzed to realize the analysis of the transmission protocols;
[0035] For TCP protocol data packets, analyze the usage of TCP flag bits, including SYN, ACK, and FIN, and detect the establishment and termination of TCP connections to analyze the TCP flag bits;
[0036] The IP protocol version analysis is to count the traffic proportions of different IP protocol versions including IPv4 and IPv6, and analyze the usage of IP protocol versions.
[0037] Preferably, in step three, the time series features, the spatial distribution features, and the intrinsic features are spliced and fused using a feature fusion algorithm, which specifically includes:
[0038] The time series features are standardized to have the same scale and range; the spatial distribution features are one-hot encoded to convert them into binary features; the intrinsic features are normalized;
[0039] The processed time series features, spatial distribution features and intrinsic features are concatenated to form a multi-dimensional feature vector;
[0040] The multi-dimensional feature vector is reduced in dimension using a principal component analysis algorithm.
[0041] Preferably, in step 3, Word2Vec is used to convert the text in the attack path graph into a dense vector representation to capture the semantic relationship between words;
[0042] Use one-hot encoding to convert categorical variables into binary vectors to represent different vulnerability categories. Vulnerability severity scores are used directly as features, and finally different feature arrays are spliced horizontally;
[0043] Use Fluentd to automatically extract and convert terminal device log data to obtain log text, and then use Word2Vec to convert the log text into a dense vector representation;
[0044] Word2Vec is used to extract text data of threat intelligence data, and the key information in the extracted text data is converted into feature vectors. After processing by the temporal layer and the fully connected layer, the introduction of the cross-modal attention module and the final feature fusion, a multimodal model is constructed.
[0045] The present invention provides a network attack detection method using multimodal data fusion. Compared with the prior art, it has the following beneficial effects:
[0046] 1. This multimodal data fusion network attack detection method, through detailed analysis of the multi-dimensional attributes of network traffic data (covering time attributes, spatial attributes, network traffic intrinsic attributes, etc.), comprehensively mines the potential feature information in the data, further integrates multi-source information such as attack path diagrams, terminal device log data, and threat intelligence data, and conducts cross-modal interactive learning to build a multimodal attack detection model, breaking the limitations of traditional single data source detection, and making full use of the correlation and complementarity between various data, so that the model can comprehensively consider various clues to judge the network attack situation.
[0047] 2. In terms of data processing, the multimodal data fusion network attack detection method adopts an adaptive processing method for different types of features. For text or classified data such as attack path diagrams, terminal device log data, and threat intelligence data, appropriate methods such as Word2Vec and one-hot encoding are also used to convert them into feature vector forms that are convenient for model processing, thereby achieving efficient integration and utilization of multimodal data. In terms of model application, the constructed multimodal attack detection model has good flexibility and adaptability, and can prioritize potential attacks of different threat levels according to the scores, making it convenient for network security managers to take targeted countermeasures. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a schematic diagram of the method flow of the present invention;
[0049] Figure 2 The figure is a schematic diagram of the model construction process of the present invention. DETAILED DESCRIPTION
[0050] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0051] See also Figure 1-2 The present invention provides a network attack detection method based on multi-modal data fusion, comprising the following steps:
[0052] Step 1: Obtain network traffic data in real time and analyze the attribute information of network traffic data, including time attributes, spatial attributes, intrinsic attributes of network traffic, firewall related information and network attack rules;
[0053] Time attributes include packet arrival time, sending time, duration, interval time, arrival order, sending frequency, time distribution pattern, time correlation, and time window statistical characteristics;
[0054] The spatial attributes include the source IP address, destination IP address, source port number, and destination port number of the data packet;
[0055] The intrinsic attributes of network traffic include packet length, transmission protocol, TCP flag, and IP protocol version.
[0056] Firewall-related information and network attack rules include:
[0057] The connection matrix L of all nodes in the network is determined by the following formula, and L is used to represent the network connectivity:
[0058]
[0059] Where n represents the total number of hosts in the network. When nodes i and j are reachable, l ij The value of is 1. When nodes i and j are unreachable, l ij The value of is 0, i∈[1,n], j∈[1,n];
[0060] The network security attribute A is determined by the following formula:
[0061]
[0062]
[0063] Among them, W is the vulnerability set, I is the intention set, W includes the CVE number of the vulnerability, I includes the name and action point of the network attack intention, S is the node network state set, S = {S0, S1, S2, ..., S n},S i ∈S,S i represents the network status of the i-th node, S0 represents the node where the attack starts, S t represents the node where the attack ends, t∈[0,n], E represents all possible attack methods between nodes, R represents the network attack rule, the network vulnerability label is mun, the minimum weight required for the attacker to attack the initiating host before the intrusion attack is lege, and the minimum weight required for the attacker to attack the target host before the intrusion attack is privilege;
[0064] The following formula is used to determine the total authority state p of the attacker in the entire network after losing control of node i, where pi represents the attacker's authority state on node i:
[0065]
[0066] The following formula is used to describe the attacker's expected attack effect on node i:
[0067]
[0068] Among them, Z(ε) represents the host attribute, k(s) represents the attack behavior in the network, and θ(s) represents each attack on all paths in the network attack graph.
[0069] Step 2: Analyze the time attributes and extract the time series features; analyze the space attributes and extract the spatial distribution features; analyze the intrinsic attributes of network traffic and extract the intrinsic features, and generate the attack path diagram according to the network attack rules and network model;
[0070] Step 3: Splice and fuse the time series features, spatial distribution features, and intrinsic features, and conduct cross-modal interactive learning on the features of the attack path map, terminal device log data, and threat intelligence data to form a multimodal evidence chain database and build a multimodal attack detection model;
[0071] The analysis of time attributes specifically includes:
[0072] Sort network traffic data in chronological order; use sliding windows to extract data within the time window;
[0073] Perform numerical statistical analysis of the mean and variance of the data within the time window.
[0074] The analysis of spatial attributes specifically includes:
[0075] Group network traffic data by source IP address, destination IP address, source port number, and destination port number;
[0076] Perform cluster analysis on each IP address group or port number, including calculating traffic size and number of connections.
[0077] The analysis of the intrinsic properties of network traffic specifically includes:
[0078] The analysis of the packet length includes calculating the length distribution of the statistical data packets by calculating the statistical indicators of average length, maximum length and minimum length;
[0079] According to the transmission protocols of data packets including TCP, UDP, and ICMP, statistics are made on the traffic proportions of different protocols, and the usage of the protocols is analyzed to analyze the transmission protocols;
[0080] For TCP protocol data packets, analyze the use of TCP flags, including SYN, ACK, and FIN, and detect the establishment and termination of TCP connections to analyze TCP flags.
[0081] IP protocol version analysis is to count the traffic proportions of different IP protocol versions, including IPv4 and IPv6, and analyze the usage of IP protocol versions.
[0082] Use feature fusion algorithm to combine time series features, spatial distribution features, and intrinsic features, including:
[0083] Standardize the time series features to make them have the same scale and range; perform one-hot encoding on the spatial distribution features and convert them into binary features; normalize the intrinsic features;
[0084] The processed time series features, spatial distribution features and intrinsic features are concatenated to form a multi-dimensional feature vector;
[0085] The principal component analysis algorithm is used to reduce the dimensionality of multidimensional feature vectors.
[0086] Use Word2Vec to convert the text in the attack path graph into a dense vector representation to capture the semantic relationship between words;
[0087] Use one-hot encoding to convert categorical variables into binary vectors to represent different vulnerability categories. Vulnerability severity scores are used directly as features, and finally different feature arrays are spliced horizontally;
[0088] Use Fluentd to automatically extract and convert terminal device log data to obtain log text, and then use Word2Vec to convert the log text into a dense vector representation;
[0089] Word2Vec is used to extract text data of threat intelligence data, and the key information in the extracted text data is converted into feature vectors. After processing by the temporal layer and the fully connected layer, the introduction of the cross-modal attention module and the final feature fusion, a multimodal model is constructed.
[0090] Step 4: Activate the multimodal attack detection model and use the activated multimodal attack detection model to provide a weight score for each potential attack route.
[0091] When activating the multimodal attack detection model, you first need to load the pre-trained model parameters and related model structure configuration information. These parameters are trained on a large amount of historical network data and simulated attack data through complex machine learning algorithms (such as neural network training algorithms in deep learning). They contain multiple mode characteristics of network traffic under normal and abnormal conditions and typical data feature combination rules corresponding to different attack types.
[0092] During the activation process, each functional module within the model will be initialized, including the data processing layer, feature extraction layer, modal fusion layer, and the final prediction and scoring layer. Among them, the data processing layer is responsible for preprocessing operations such as cleaning, formatting, and data standardization of the input data to ensure the quality and consistency of the data for subsequent feature extraction and model analysis. The feature extraction layer re-extracts and optimizes the time series features, spatial distribution features, intrinsic features, and features extracted from the attack path map, terminal device log data, and threat intelligence data based on the feature extraction method determined when the model was built before, further highlighting the key information and abnormal features in the data. The modal fusion layer will deeply fuse the features of different modalities according to the pre-set fusion strategy (such as weighted summation, feature splicing followed by nonlinear transformation, etc.), so that the information between the modalities can complement and enhance each other, forming a more representative and discriminative comprehensive feature representation.
[0093] When the activated multimodal attack detection model receives information about potential attack routes, it will analyze and evaluate it based on the fused multimodal features using an internal complex algorithm model. For each potential attack route, the model will comprehensively consider its abnormal behavior patterns in the time dimension (such as the outbreak of a large amount of abnormal traffic in a short period of time, the law of traffic fluctuations within a specific time interval, etc.), the source and destination distribution characteristics in the spatial dimension (such as the concentration of traffic from a specific malicious IP address segment pointing to the key server area, etc.), the abnormal performance of the intrinsic properties of network traffic (such as abnormal packet size, abnormal protocol usage, etc.), and the degree of matching with the known attack path map, abnormal terminal device log records, and related attack patterns in threat intelligence. Through quantitative analysis and comprehensive evaluation of these factors, a weight score is calculated for each potential attack route. This weight score represents the degree of danger and possibility of the attack route. The higher the score, the more likely it is that the attack route is a real network attack path, thus providing an important basis for subsequent attack judgment and response decisions.
[0094] Step 5: Receive the current user's real-time data and input the current user's real-time data into the multimodal attack detection model to determine whether there is a network attack.
[0095] Receiving real-time data from current users is a continuous and dynamic process. The data sources cover various key nodes and devices in the network, including network traffic data generated by routers, switches, servers, and end-user devices. These data will be collected in real time and transmitted to the input end of the multimodal attack detection model. During the data transmission process, efficient data transmission protocols and encryption technologies will be used to ensure the integrity, accuracy, and security of the data and prevent the data from being tampered with or stolen during transmission.
[0096] When real-time data reaches the model input, it will first be preprocessed according to the same data processing flow as in the activation process, converting it into a format and feature representation that the model can understand and process. Then, the processed real-time data is input into the activated and built multimodal attack detection model. The model will quickly start the internal feature extraction, modal fusion, and attack judgment mechanism, and perform in-depth analysis of the real-time data according to the previous method based on multimodal feature analysis.
[0097] When judging whether there is a network attack, the model will compare and match the multimodal features generated by the current user's real-time data with the normal network behavior patterns and various known attack patterns learned by the model during the training process. If the characteristics of the real-time data deviate greatly from the normal pattern and have a high degree of similarity or matching with one or more known attack patterns, the model will determine whether there is a network attack based on the pre-set attack judgment threshold. For example, if the weight score of the potential attack route corresponding to a certain real-time data exceeds the set threshold, the model will determine that there is a corresponding network attack on the current network and immediately trigger the alarm mechanism to send detailed attack alarm information to the network administrator or related security monitoring system, including the type of attack, possible source, affected devices and network areas, etc. At the same time, the model can also provide some preliminary response suggestions based on the severity and characteristics of the attack, such as whether it is necessary to immediately cut off specific network connections, activate specific protection rules of the firewall, isolate the affected devices or back up data, etc., so as to quickly respond to and handle network attack events and minimize the damage and impact of the attack on the network system. In addition, the model will continue to monitor and analyze subsequent real-time data to track the development of attacks and evaluate the effectiveness of response measures to ensure that network security is effectively protected.
[0098] The present invention comprehensively mines the potential characteristic information in the data through detailed analysis of the multi-dimensional attributes of network traffic data (covering time attributes, spatial attributes, network traffic intrinsic attributes, etc.). For example, when analyzing time attributes, not only conventional elements such as the arrival and sending time of the data packet are considered, but also complex features such as time distribution pattern and time correlation are deeply explored to accurately capture traffic anomalies from the perspective of time series; spatial attribute analysis focuses on the source and destination IP addresses and port numbers of the data packet, and can clearly present the distribution characteristics of the traffic in the network space through grouping and clustering analysis; for the intrinsic attributes of network traffic, it is detailed to the analysis of data packet length, transmission protocol, TCP flag bit and other aspects to accurately grasp the inherent characteristics of the traffic.
[0099] Moreover, it further integrates multi-source information such as attack path diagrams, terminal device log data, and threat intelligence data, and conducts cross-modal interactive learning to build a multi-modal attack detection model. This multi-modal fusion method breaks the limitations of traditional single data source detection, and makes full use of the correlation and complementarity between various data, so that the model can comprehensively consider multiple clues to judge the network attack situation. For example, the attack path diagram can provide a logical link of the attack behavior, the terminal device log reflects the abnormal operation of the local device, and the threat intelligence warns of potential attack methods from a more macro perspective. The combination of multiple modes can more accurately identify complex and changeable network attack behaviors, whether it is a known common attack or a new variant of the attack mode, with a higher detection accuracy, effectively reducing the missed and false alarm rates, and comprehensively ensuring network security.
[0100] Meanwhile, the contents not described in detail in this specification belong to the prior art known to those skilled in the art, and the model parameters of each electrical appliance are not specifically limited, and conventional equipment can be used.
[0101] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.
[0102] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A network attack detection method based on multimodal data fusion, characterized in that: The following steps are involved: Step 1: Acquire network traffic data in real time, and analyze attribute information of the network traffic data, including time attributes, space attributes, intrinsic attributes of the network traffic, firewall related information, and network attack rules; Step 2: Analyze the time attributes and extract time series features; Analyzing the spatial attributes to extract spatial distribution characteristics; Analyze the intrinsic properties of the network traffic, extract the intrinsic features, and generate an attack path diagram according to network attack rules and network models; Step 3: splicing and fusing the time series features, the spatial distribution features, and the intrinsic features, and performing cross-modal interactive learning on the features of the attack path map, terminal device log data, and threat intelligence data to form a multimodal evidence chain database, and construct a multimodal attack detection model; Step 4: Activate the multimodal attack detection model and use the activated multimodal attack detection model to provide a weight score for each potential attack route; Step 5: Receive the current user's real-time data, and input the current user's real-time data into the multimodal attack detection model to determine whether there is a network attack.
2. The network attack detection method based on multimodal data fusion according to claim 1 is characterized by: The time attributes include data packet arrival time, sending time, duration, interval time, arrival order, sending frequency, time distribution pattern, time correlation, and time window statistical characteristics; The spatial attributes include the source IP address, destination IP address, source port number, and destination port number of the data packet; The network traffic intrinsic attributes include data packet length, transmission protocol, TCP flag, and IP protocol version.
3. The network attack detection method based on multimodal data fusion according to claim 1 is characterized in that: The firewall related information and network attack rules include: The connection matrix L of all nodes in the network is determined by the following formula, and L is used to represent the network connectivity: Where n represents the total number of hosts in the network. When nodes i and j are reachable, l ij The value of is 1. When nodes i and j are unreachable, l ij The value of is 0, i∈[1,n], j∈[1,n]; The network security attribute A is determined by the following formula: Where W is the vulnerability set, I is the intention set, W includes the CVE number of the vulnerability, I includes the name and action point of the network attack intention, S is the node network state set, S = {S0, S1, S2, ..., S n },S i ∈S,S i represents the network status of the i-th node, S0 represents the node where the attack starts, S t represents the node where the attack ends, t∈[0,n], E represents all possible attack methods between nodes, R represents the network attack rule, the network vulnerability label is mun, the minimum weight required for the attacker to attack the initiating host before the intrusion attack is lege, and the minimum weight required for the attacker to attack the target host before the intrusion attack is privilege; The following formula is used to determine the total authority state p of the attacker in the entire network after losing control of node i, where pi represents the attacker's authority state on node i: The following formula is used to describe the attacker's expected attack effect on node i: Among them, Z(ε) represents the host attribute, k(s) represents the attack behavior in the network, and θ(s) represents each attack on all paths in the network attack graph.
4. The network attack detection method based on multimodal data fusion according to claim 1 is characterized in that: Analyzing the time attribute specifically includes: Sorting the network traffic data in chronological order; extracting data within the time window using a sliding window; Perform numerical statistical analysis of the mean value and variance on the data within the time window.
5. The network attack detection method based on multimodal data fusion according to claim 1 is characterized in that: The analysis of the spatial attributes specifically includes: Grouping the network traffic data according to source IP address, destination IP address, source port number, and destination port number; Perform cluster analysis on each IP address group or port number, including calculating traffic size and number of connections.
6. The network attack detection method based on multimodal data fusion according to claim 1 is characterized by: The analysis of the intrinsic properties of the network traffic specifically includes: The analysis of the length of the data packet includes calculating the length distribution of the data packet by calculating the statistical indicators of the average length, the maximum length and the minimum length; According to the transmission protocols of the data packets, including TCP, UDP, and ICMP, the traffic ratios of different protocols are counted, and the usage of the protocols is analyzed to realize the analysis of the transmission protocols; For TCP protocol data packets, analyze the usage of TCP flag bits, including SYN, ACK, and FIN, and detect the establishment and termination of TCP connections to analyze the TCP flag bits; The IP protocol version analysis is to count the traffic proportions of different IP protocol versions including IPv4 and IPv6, and analyze the usage of IP protocol versions.
7. The network attack detection method based on multimodal data fusion according to claim 1 is characterized by: In step 3, the time series features, the spatial distribution features, and the intrinsic features are spliced and fused using a feature fusion algorithm, specifically including: The time series features are standardized to have the same scale and range; the spatial distribution features are one-hot encoded to convert them into binary features; the intrinsic features are normalized; The processed time series features, spatial distribution features and intrinsic features are concatenated to form a multi-dimensional feature vector; The multi-dimensional feature vector is reduced in dimension using a principal component analysis algorithm.
8. The network attack detection method based on multimodal data fusion according to claim 1 is characterized by: In the step 3, Word2Vec is used to convert the text in the attack path graph into a dense vector representation to capture the semantic relationship between words; Use one-hot encoding to convert categorical variables into binary vectors to represent different vulnerability categories. Vulnerability severity scores are used directly as features, and finally different feature arrays are spliced horizontally; Use Fluentd to automatically extract and convert terminal device log data to obtain log text, and then use Word2Vec to convert the log text into a dense vector representation; Word2Vec is used to extract text data of threat intelligence data, and the key information in the extracted text data is converted into feature vectors. After processing by the temporal layer and the fully connected layer, the introduction of the cross-modal attention module and the final feature fusion, a multimodal model is constructed.
Citation Information
Patent Citations
Multi-modal face presentation attack detection method based on space-time decomposition encoder
CN116844213A
Cited By
Detection method fusing depth feature extraction and attack recognition
CN120455178A
Visual early warning method and system for network security event
CN120474836A
Communication protection method based on big data analysis and cloud computing
CN120547070A
Communication protection methods based on big data analytics and cloud computing
CN120547070B
Network security threat detection method and system based on multi-modal artificial intelligence
CN120658466A