Distributed new energy station-oriented malicious traffic detection method, system and device, and storage medium

By extracting multi-scale traffic characteristics in distributed new energy stations and combining with the Transformer model's dual-task training strategy, the problem of malicious traffic detection in distributed new energy stations is solved, high-precision and real-time malicious traffic detection is achieved, and the stable operation of new energy stations is ensured.

CN119995982AActive Publication Date: 2025-05-13NARI INFORMATION & COMM TECH +3
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510139565.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-13
Estimated Expiration
2045-02-08

AI Technical Summary

Technical Problem

The surge in data traffic caused by device networking in distributed new energy stations faces serious network security challenges, especially the threat of malicious traffic attacks. The existing technology is difficult to effectively detect and handle, resulting in equipment failure, interruption of energy scheduling and even an energy crisis.

Method used

A malicious traffic detection method for distributed new energy stations is adopted. By obtaining the network traffic data of the device, multi-scale features (byte level, group level, and flow level), combined with the encoder module of the Transformer model, the dual-task training strategy of mask reconstruction and malicious traffic prediction is pre-trained to detect malicious traffic, and the model is fine-tuned using pseudo-label iteration method to detect malicious traffic in real time.

Benefits of technology

It improves the accuracy and real-time nature of malicious traffic detection, adapts to diversified attack modes, effectively deals with various attacks in the complex network environment of distributed new energy stations, and ensures the stable operation of new energy stations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995982A_ABST
    Figure CN119995982A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed new energy station-oriented malicious traffic detection method, system and device, and a storage medium. The method comprises the following steps: acquiring network flow data, performing normal or malicious flow marking on part of data, and identifying different sessions or flows through protocol analysis; according to the identified session or flow, extracting byte-level features and packet-level features based on a first time window, and extracting flow-level features based on a second time window; the method comprises the following steps: constructing a total feature sequence, randomly masking each feature item in the sequence, and pre-training a detection model by using an encoder module of a Transform model through a mask reconstruction and malicious traffic prediction dual-task training strategy; and carrying out fine tuning on the pre-trained detection model by using the pseudo mark data, deploying the fine-tuned detection model to a network of the distributed new energy station, and detecting malicious traffic in real time. According to the method, the feature information in the traffic can be captured at multiple levels, and long-time network attacks or latent malicious activities can be detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of malicious traffic detection, and in particular to a malicious traffic detection method, system, device and storage medium for distributed new energy stations. Background Art

[0002] With the rapid development of distributed new energy technologies, more and more new energy sites and smart devices around the world are connected to the Internet of Things through smart grids, forming a complex distributed energy management network. Wind power, solar energy, energy storage systems and other equipment achieve automated operation and energy dispatch through network communications. However, the surge in data traffic brought about by the networking of devices has also made distributed new energy sites face serious network security challenges, especially the threat of malicious traffic attacks.

[0003] Equipment in distributed new energy stations, such as sensors, inverters, and measurement and control terminals, transmit key data such as equipment status and control instructions through the network. These devices, due to their scattered locations and diverse types, have become targets of network attacks, such as data tampering, DDoS attacks, and traffic poisoning. If these malicious traffic cannot be effectively detected and processed, it may lead to equipment failure, energy scheduling interruption, and even trigger a large-scale energy crisis.

[0004] In order to deal with these threats, in recent years, malicious traffic detection technologies based on machine learning have been gradually introduced into distributed new energy sites. These technologies can automatically analyze traffic characteristics and identify potential malicious traffic patterns. However, current data methods only focus on information in a single time series, and lack information about the overall state, resulting in increased missed detection and false alarm rates, difficulty in identifying advanced persistent threats (APTs), and difficulty in risk assessment and early warning. Summary of the invention

[0005] The purpose of this section is to summarize some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of the present invention to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.

[0006] In view of the problems existing in the above-mentioned prior art, the present invention is proposed. The present invention provides a malicious traffic detection method, system, device and storage medium for distributed new energy stations, which combines the characteristics of different time scales and traffic levels to improve the effect of malicious traffic detection.

[0007] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0008] In a first aspect, a malicious traffic detection method for a distributed new energy station is provided, the method comprising the following steps:

[0009] Obtain network traffic data of various devices in distributed new energy stations under experimental environment, mark some data as normal traffic or malicious traffic according to the experimental environment, and do not mark the rest of the data. Perform protocol analysis on all acquired network traffic data, and identify different sessions or flows based on quintuple information.

[0010] According to the identified session or flow, byte-level features and packet-level features are extracted based on a first time window, and flow-level features are extracted based on a second time window, wherein the second time window is larger than the first time window, prefix tokens are added before the extracted features at each level to identify whether the feature source is byte-level, packet-level or flow-level, a suffix token is added at the end of the flow-level feature to indicate the end of the feature sequence, and the features at each level are combined to form a total feature sequence;

[0011] According to the total feature sequence, position coding is added to each feature item. The total feature sequence and position coding are mapped to a high-dimensional vector space through an embedding layer. The mapped high-dimensional vector is input into the encoder module of the Transformer model. The detection model is pre-trained through the dual-task training strategy of mask reconstruction and malicious traffic prediction.

[0012] The prediction results generated by the detection model on unlabeled data are used as pseudo-labels. The pseudo-labels are iteratively combined with real labeled data to form pseudo-labeled data. The pre-trained detection model is fine-tuned using the pseudo-labeled data. The fine-tuned detection model is deployed in the network of distributed new energy stations to detect malicious traffic in real time.

[0013] According to some embodiments of the first aspect, extracting byte-level features and packet-level features based on the first time window, and extracting stream-level features based on the second time window, includes:

[0014] In the first time window, the first N bytes of each data packet constituting a session or flow are extracted to form a byte-level feature, denoted as S byte =[byte1,byte2,...,byte i ,...,byte N ], where byte i Represents the first N bytes of the i-th data packet;

[0015] The average length avg_length, the maximum length max_length, the average time interval avg_interval1 between data packets and the total number of data packets total_packets1 of the data packets constituting the session in the first time window are counted to form a packet-level feature, which is expressed as: S packet=[avg_length,max_length,avg_interval1,total_packets1];

[0016] In the second time window, the duration of the flow is obtained, and the total number of data packets in the flow, total_packets2, the total number of bytes, the average time interval between data packets, avg_interval2, and the average length of data packets, avg_packet_length, are counted. The transmission direction of the flow, direction, is obtained to form a flow-level feature sequence, which is expressed as:

[0017] S flow =

[0018] [duration,total_packets2,avg_interval2,total_bytes,avg_packet_length,direction].

[0019] According to certain implementations of the first aspect, the dual-task training strategy of mask reconstruction and malicious traffic prediction is specifically as follows:

[0020] by represents the reconstruction output of the detection model for the masked part, where f θ is a model with parameters θ, X masked It is the masked feature, and the reconstruction quality of the model is measured by the mean square error combined with the true value of the feature. rec ;

[0021] Using the labeled dataset D labeled To predict malicious traffic, each sample x∈D labeled It is labeled as y∈{0,1}, where 1 represents malicious traffic and 0 represents normal traffic. The output of the model is the predicted probability of malicious traffic. Among them, f θ (x) is the output of the model for sample x, indicating the probability that the traffic is malicious. Combined with the true label of the sample, the cross entropy loss function is used to calculate the classification loss L for malicious traffic prediction. pred ;

[0022] Combining the losses of the two tasks, we can form a total loss function: L total =αL rec +βL pred , where α and β are weight coefficients used to control the relative importance of tasks. Pre-training is continued based on the total loss function until the stopping condition is met to obtain the pre-trained model.

[0023] According to certain embodiments of the first aspect, in the mask reconstruction task, each feature item in the input sequence is randomly masked, and the masking method is as follows:

[0024] X=[x1,x2,...,x i ,...,x n ] represents the total feature sequence, where x i It is a byte-level, packet-level or stream-level feature. Some features are randomly selected for masking. The masked features are expressed as: masked =M(X), where M is a random mask matrix. According to certain embodiments of the first aspect, in the malicious traffic prediction task, the input features are passed through the Transformer encoder and then use the fully connected layer and the Sigmoid activation function to generate the predicted probability of malicious traffic, and the output is the predicted probability of each sample.

[0025] According to certain embodiments of the first aspect, fine-tuning a trained detection model using pseudo-labeled data comprises:

[0026] The unlabeled dataset is denoted as D unlabeled , use the pre-trained model to train unlabeled samples x l ∈D unlabeled Make predictions and generate predicted probabilities where f θ represents a model with parameters θ;

[0027] Combined with the confidence threshold τ, a pseudo label is generated based on the predicted probability Combining pseudo-labeled data with labeled data combined , using the merged dataset D combined Train the model again and optimize the model parameters: After each round of training, pseudo labels are regenerated, the model is updated and training is repeated.

[0028] According to certain implementations of the first aspect, deploying the fine-tuned detection model to a network of distributed new energy sites includes:

[0029] Lightweight models are deployed on the edge devices of the site to perform real-time traffic detection. The detection results or suspected malicious traffic data are uploaded to the central control platform for comprehensive analysis.

[0030] Edge device deployment: Use edge devices with AI reasoning capabilities to run lightweight model reasoning services on edge devices. Use Flask to provide HTTP interfaces, and pass data streams to the reasoning service in real time through the interfaces.

[0031] Central control platform deployment: The detection results of edge devices are uploaded to the central control platform through a secure protocol. The platform aggregates data from multiple sites for global analysis and alarms.

[0032] According to certain implementations of the first aspect, the method further comprises: collecting new traffic data to periodically evaluate, update and optimize the deployed model, as follows:

[0033] By collecting new traffic data in real time and cleaning and annotating it, the model can be retrained or fine-tuned regularly to adapt it to the latest traffic characteristics;

[0034] Establish an automated update pipeline and rollback mechanism to quickly restore the old version when problems are found;

[0035] Evaluate inference speed, resource utilization, and detection accuracy, focus on false positive rate, false negative rate, and data distribution drift, and adjust the model training strategy based on the evaluation results.

[0036] In a second aspect, a malicious traffic detection system for distributed new energy stations is provided, the system comprising:

[0037] The data collection and preprocessing module is used to obtain the network traffic data of various devices in the distributed new energy station under the experimental environment, mark some data as normal traffic or malicious traffic according to the experimental environment, and leave the rest of the data unmarked. It also performs protocol analysis on all the obtained network traffic data and identifies different sessions or flows based on the five-tuple information;

[0038] A traffic feature extraction module is used to extract byte-level features and packet-level features based on a first time window according to the identified session or flow, extract flow-level features based on a second time window, wherein the second time window is larger than the first time window, add a prefix token before each level of extracted features to identify whether the feature source is byte-level, packet-level or flow-level, add a suffix token at the end of the flow-level feature to indicate the end of the feature sequence, and combine the features at each level to form a total feature sequence;

[0039] The detection model pre-training module is used to add position codes to each feature item according to the total feature sequence, map the total feature sequence and position codes to a high-dimensional vector space through an embedding layer, and input the mapped high-dimensional vector into the encoder module of the Transformer model. The detection model is pre-trained through the dual-task training strategy of mask reconstruction and malicious traffic prediction.

[0040] The model fine-tuning and application module is used to use the prediction results generated by the detection model on unlabeled data as pseudo-labels, combine the pseudo-labels with the real labeled data in an iterative manner to form pseudo-labeled data, use the pseudo-labeled data to fine-tune the pre-trained detection model, and deploy the fine-tuned detection model to the network of distributed new energy stations to detect malicious traffic in real time.

[0041] According to some embodiments of the second aspect, extracting byte-level features and packet-level features based on the first time window, and extracting stream-level features based on the second time window, includes:

[0042] In the first time window, the first N bytes of each data packet constituting a session or flow are extracted to form a byte-level feature, denoted as S byte =[byte1,byte2,...,byte i ,...,byte N ], where byte i Represents the first N bytes of the i-th data packet;

[0043] The average length avg_length, the maximum length max_length, the average time interval avg_interval1 between data packets and the total number of data packets total_packets1 of the data packets constituting the session in the first time window are counted to form a packet-level feature, which is expressed as: S packet =[avg_length,max_length,avg_interval1,total_packets1];

[0044] In the second time window, the duration of the flow is obtained, and the total number of data packets in the flow, total_packets2, the total number of bytes, the average time interval between data packets, avg_interval2, and the average length of data packets, avg_packet_length, are counted to identify the transmission direction of the flow and form a flow-level feature sequence, which is expressed as:

[0045] S flow =

[0046] [duration,total_packets2,avg_interval2,total_bytes,avg_packet_length,direction].

[0047] According to certain embodiments of the second aspect, each feature item in the sequence is randomly masked, comprising:

[0048] Randomly select feature items in the sequence with a specified probability, replace the selected feature items with a given mask with a specified probability, or replace them with other feature items, or keep them unchanged. The mask operation is expressed as follows:

[0049] X=[x1,x2,...,x i ,...,x n ] represents the total feature sequence, where x i It is a byte-level, packet-level or stream-level feature. Some features are randomly selected for masking. The masked features are expressed as: masked =M(X), where M is a random mask matrix.

[0050] According to certain implementations of the second aspect, the dual-task training strategy of mask reconstruction and malicious traffic prediction is as follows:

[0051] by represents the reconstruction output of the detection model for the masked part, where f θ is a model with parameters θ, X masked It is the masked feature, and the reconstruction quality of the model is measured by the mean square error combined with the true value of the feature. rec ;

[0052] Using the labeled dataset D labeled To predict malicious traffic, each sample x∈D labeled It is labeled as y∈{0,1}, where 1 represents malicious traffic and 0 represents normal traffic. The output of the model is the predicted probability of malicious traffic. Among them, f θ (x) is the output of the model for sample x, indicating the probability that the traffic is malicious. The classification loss L for malicious traffic prediction is calculated using the cross entropy loss function combined with the original label. pred ;

[0053] Combining the losses of the two tasks, we can form a total loss function: L total =αL rec +βL pred , where α and β are weight coefficients used to control the relative importance of tasks. Pre-training is continued based on the total loss function until the stopping condition is met to obtain the pre-trained model.

[0054] According to certain embodiments of the second aspect, fine-tuning a trained detection model using pseudo-labeled data comprises:

[0055] The unlabeled dataset is denoted as D unlabeled , use the pre-trained model to train unlabeled samples x i ∈D unlabeled Make predictions and generate predicted probabilities where f θ represents a model with parameters θ;

[0056] Combined with the confidence threshold τ, a pseudo label is generated based on the predicted probability Combining pseudo-labeled data with labeled data combined , using the merged dataset D combined Train the model again and optimize the model parameters: After each round of training, pseudo labels are regenerated, the model is updated and training is repeated.

[0057] According to certain embodiments of the second aspect, the fine-tuned detection model is deployed to the network of distributed new energy stations, wherein the edge devices of the stations deploy lightweight models to perform real-time traffic detection, and the detection results or suspected malicious traffic data are uploaded to the central control platform for comprehensive analysis; the edge devices use edge devices with AI reasoning capabilities, run lightweight model reasoning services, use Flask to provide HTTP interfaces, and data streams are transmitted to the reasoning services in real time through the interfaces; the detection results of the edge devices are uploaded to the central control platform through a security protocol, and the platform aggregates data from multiple stations for global analysis and alarms.

[0058] According to certain embodiments of the second aspect, the system further includes a model maintenance module, which is used to collect new traffic data to regularly evaluate, update and optimize the deployed model, specifically including:

[0059] A regular updating unit is used to regularly retrain or fine-tune the model to adapt it to the latest traffic characteristics by collecting, cleaning, and annotating new traffic data in real time;

[0060] Rollback settings unit, used to establish automated update pipelines and rollback mechanisms, so that old versions can be quickly restored when problems are found;

[0061] The performance evaluation unit is used to evaluate inference speed, resource utilization, and detection accuracy. The detection accuracy focuses on false positive rate, false negative rate, and data distribution drift, and the model training strategy is adjusted according to the evaluation results.

[0062] According to a third aspect, a computer device is provided, comprising one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the malicious traffic detection method for distributed new energy stations as described in the first aspect of the present invention are implemented.

[0063] In a fourth aspect, a computer storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the malicious traffic detection method for distributed new energy stations as described in the first aspect of the present invention are implemented.

[0064] Compared with the prior art, the invention has the following beneficial effects:

[0065] (1) The present invention uses multi-scale fusion technology to comprehensively analyze the traffic characteristics at the byte level, group level (packet level), and flow level in different time windows, and can accurately capture abnormal behaviors from fine-grained to global traffic, thereby improving the accuracy and real-time performance of malicious traffic detection and adapting to diverse attack modes.

[0066] (2) The present invention is particularly suitable for the complex network environment of distributed new energy stations. It makes full use of the diverse traffic data in the stations and combines multi-scale fusion technology for hierarchical analysis. It can effectively respond to various attacks from different devices and regions and ensure the stable operation of new energy stations.

[0067] (3) Aiming at the specific environment of distributed new energy sites, a set of appropriate model deployment and use as well as subsequent maintenance and upgrade solutions are proposed, which can enable distributed sites to maintain a high level of security protection capabilities in an ever-changing network environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 It is the overall flow chart of the method of the present invention;

[0069] Figure 2 This is a model diagram of the pre-trained part in the method of the present invention. DETAILED DESCRIPTION

[0070] The technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings.

[0071] Embodiment 1

[0072] This embodiment provides a malicious traffic detection method for distributed new energy stations. Figure 1 , the method mainly includes the following steps:

[0073] Step S1, collect network traffic data from measurement and control terminals, sensors, inverters and other equipment of distributed new energy stations. Due to the diverse types of equipment in distributed stations, traffic data also covers different communication protocols and data formats. According to the source of traffic, device functions and behaviors, the data is marked as "normal" or "malicious" to provide labeled samples for subsequent model training.

[0074] In this embodiment, during the data collection process, step S1 collects the following types of network traffic data:

[0075] Normal traffic: collects data about normal communication of devices, including traffic from sensors to the control center, status synchronization between devices, data updates, and other traffic.

[0076] Malicious traffic: Capture network traffic under malicious behavior through security testing or attack simulation (such as DoS attack, data tampering, etc.).

[0077] Unlabeled traffic: A large amount of normal traffic and potentially malicious traffic is not labeled. This data will be used in self-supervised pre-training and pseudo-labeling iterations.

[0078] Data labeling is performed by labeling these data through known malicious traffic samples and attack simulation methods. That is, among the collected and captured data, some data are labeled as normal traffic or malicious traffic, and the rest of the data are not labeled.

[0079] Step S2, data preprocessing: preprocess the collected network traffic data, remove redundant data and parse the protocol. Divide the data into different sessions or flows based on information such as source IP, target IP, port number, etc. to ensure the integrity and timing of the data. Ensure that the data structure processed by the model is reasonable and can reflect the actual traffic characteristics.

[0080] In this embodiment, the data preprocessing in step S2 is specifically performed as follows:

[0081] Redundant data removal: Perform preliminary cleaning on captured network traffic to remove invalid data packets, duplicate packets, and empty packets. By comparing key fields such as the source IP, destination IP, port number, protocol type, and timestamp of the data packet, duplicate network packets are identified and deleted to ensure that the data processed subsequently is independent and valid network communication information.

[0082] Protocol parsing: Perform protocol parsing on the cleaned traffic data. According to different network transmission protocols (such as TCP, UDP, HTTP, etc.), parse the protocol header information and payload content of the data packet.

[0083] Data packets (packets) are the basic building blocks of sessions or flows. Sessions or flows are logical units that aggregate packets together through certain rules (such as five-tuples: source IP, destination IP, source port, destination port, and protocol type). A session usually represents a complete process of two-way communication, while a flow usually represents one-way continuous data transmission. Within a specified time window, the packets in the traffic are divided according to the rules of sessions or flows. Specifically, the set of all packets belonging to the same session or flow is determined based on the five-tuple information. For the division of sessions and flows: The first division of network traffic is based on the five-tuple (source IP, destination IP, source port, destination port, and protocol type). The packets in the same session have the same five-tuple information to ensure that they belong to the same communication link. The second division based on time: For long-term sessions, they are further divided into multiple traffic segments based on a given time window to capture traffic changes in the time dimension.

[0084] Step S3, construct a multi-level sequence: organically combine the features of different levels to form a multi-level sequence. By combining the byte level (protocol header information, specific byte sequence), packet level (also called packet level, which is the overall feature of each data packet), and flow level (global communication behavior) features, a comprehensive sequence representation is constructed. This multi-level structure can reflect the complex communication mode of equipment in distributed new energy stations and adapt to data transmission behaviors in various network environments.

[0085] In this embodiment, the step S3 constructs a multi-level sequence, specifically including:

[0086] Define the time window:

[0087] The first time window (applicable to byte level and packet level): usually used to capture burst traffic characteristics within a short period of time, suitable for detecting short-term attack behaviors such as fast scanning, data packet replay, etc., also known as a short time window, such as 1 second or several hundred milliseconds.

[0088] The second time window (applicable to flow level): used to detect long-term, continuous traffic behaviors, such as DDoS attacks, continuous data leakage, etc., also known as a long time window, such as 5 minutes, 10 minutes, or longer.

[0089] Byte-level feature extraction: Within the set first time window (e.g., 1 second or several hundred milliseconds), the first N bytes (e.g., the first 40 bytes) of each data packet are extracted, and the N bytes extracted each time are represented by bytes to form a byte-level feature sequence:

[0090] S byte =[byte1,byte2,...,byte i ,...,byte N ]

[0091] Where byte i Represents the first N bytes of the i-th data packet, and the subscript i represents the i-th data packet.

[0092] Packet-level feature extraction: Also in the first time window, packet-level features are extracted. By extracting statistics, the model can more efficiently process traffic behaviors in different time windows. In this embodiment, statistical information about the length, number, and interval of packets is extracted to form a packet-level feature sequence:

[0093] S packet =[avg_length,max_length,avg_interval1,total_packets1]

[0094] Where avg_length represents the average packet length in the time window. max_length represents the maximum packet length in the time window. avg_interval1 represents the average time interval between packets. total_packets1 represents the total number of packets in the time window.

[0095] Flow-level data processing: Extract flow-level features in the second time window (e.g., 5 minutes, 10 minutes, or longer) to describe the global communication pattern over a period of time. Flow-level features are used to capture long-term traffic behaviors, such as persistent data leaks or botnet behaviors.

[0096] In this embodiment, the global features of each flow are extracted, such as flow duration, total number of packets, total number of bytes, average inter-packet time, etc., to form a flow-level feature sequence:

[0097] S flow =[duration,total_packets2,avg_interval2,total_bytes,avg_packet_length,direction]

[0098] Among them, duration represents the duration of the flow. total_packets2 represents the total number of packets in the flow. total_bytes represents the total number of bytes in the flow. avg_interval2 represents the average time interval between packets. direction represents the transmission direction of the flow (inbound or outbound). It should be understood that in packet-level features, total_packets1 refers to the total number of data packets in a certain time window. In flow-level features, total_packets2 represents the number of all data packets in the flow. Their meanings are the same, but the granularity is different: packet-level features focus on the number of packets in a short time window, while flow-level features focus on the number of packets in the entire flow. Similarly, avg_interval1 represents the average time interval between data packets in a short time window, and avg_interval2 represents the average time interval between data packets in the flow.

[0099] As an example, suppose there is a network traffic dataset containing multiple packets. Each packet has related information such as timestamp, length, packet content, etc., as shown in Table 1.

[0100] Assume that the time windows are: short time window 1 second and long time window 5 minutes.

[0101] Table 1 Network traffic data packet information

[0102]

[0103] Extract the first 40 bytes from all packets within second 1. Assume that the first 40 bytes of the first packet are Header_1, the first 40 bytes of the second packet are Header_2, and so on.

[0104] In the 1 second time window, we extract the statistical features of all packets. Calculate the average length (avg_length), maximum length (max_length), average time interval between packets (avg_interval), and total number of packets (total_packets) per second. Assume that there are 3 packets in the time window from 0.1 seconds to 1 second.

[0105] avg_length = (1500 + 2000 + 1200) / 3 = 1666.67 bytes

[0106] max_length = max(1500,2000,1200) = 2000 bytes

[0107] avg_interval=(0.4+0.2) / 2=0.3 seconds

[0108] total_packets = 3 packets

[0109] We extract global features for each flow in a 5-minute time window. Suppose there is a flow in a 5-minute time window, which contains packets 4 to 6. Calculate the total number of packets (total_packets), total number of bytes (total_bytes), duration of the flow (duration), average time interval between packets (avg_interval), and direction of the flow (direction).

[0110] duration = 5 minutes = 300 seconds

[0111] total_packets = 3 packets (packet 4 to packet 6)

[0112] total_bytes = 1400 + 2200 + 1800 = 5400 bytes

[0113] avg_interval=(0.5+0.5) / 2=0.5 seconds

[0114] direction = inbound

[0115] In step S4, the token embedding method is used to embed byte-level, packet-level, and flow-level features into a multi-level sequence, so that the Transformer model can simultaneously process multi-granularity network traffic features and enhance its traffic analysis capabilities in the complex environment of distributed new energy stations.

[0116] In this embodiment, the token embedding method in step S4 specifically includes:

[0117] (1) Design corresponding tokens for each level of features:

[0118] [BYTE]: Identifier representing a byte-level feature.

[0119] [PACKET]: Identifier representing a packet-level feature.

[0120] [FLOW]: Identifier representing flow-level features.

[0121] Then add tokens to the features. Before the feature vector of each level, add the corresponding token as a prefix to identify the source of the feature, and add the token [PAD] after the stream-level sequence to indicate the end of the entire sequence.

[0122] Byte-level sequence: [BYTE,byte1,byte2,...,byte N ]

[0123] Packet level sequence: [PACKET,avg_length,max_length,,avg_interval,total_packets]

[0124] Flow level sequence: [FLOW,duration,total_packets,total_bytes,avg_interval,direction,PAD]

[0125] It should be noted that multiple signature sequences are generated in each time window, and the specific number depends on the number of packets processed in the time window and its duration.

[0126] (2) Embedding layer processing: Map discrete input features (such as [BYTE], [PACKET], [FLOW] and specific eigenvalues) to a high-dimensional vector space. The mapping is completed by looking up the embedding matrix to generate each input feature x i The corresponding high-dimensional vector generates an embedding matrix of shape (N, D).

[0127]

[0128] The embedding vector of the i-th feature.

[0129] E: embedding matrix, V is the vocabulary size, and D is the embedding dimension.

[0130] (3) Add position coding: Add position coding to each feature to retain the timing information.

[0131] Introduce position information for each feature in the sequence and assign an embedding vector to each position. Generate position encoding based on sine and cosine functions. Output a matrix with the same shape as the embedding matrix, providing position information.

[0132] 1. Learnable Position Embeddings:

[0133]

[0134] P: Learnable position embedding matrix.

[0135] 2. Fixed position encoding (based on sine and cosine functions):

[0136]

[0137] pos: sequence position.

[0138] i: The index of the embedding dimension.

[0139] (4) Combine the feature value and position information to generate the final embedding representation. Add the feature embedding and position encoding matrices element by element. The matrix of shape (N, D) is used to input the Transformer encoder. Embed the token z i and position code p i Add them together to get the final embedding vector:

[0140]

[0141] h i : The high-dimensional vector of the i-th feature, combining feature content and position information.

[0142] Combine the embedding vectors of all sequence positions into a matrix H:

[0143]

[0144] H: The output of the embedding layer, which represents the high-dimensional representation of the entire sequence.

[0145] The embedded feature sequence will be input into the Transformer encoder to generate hidden representations.

[0146] Step S5, self-supervised pre-training: In order to enable the model to be effectively pre-trained on unlabeled data and enhance its ability to identify malicious traffic, a dual-task training strategy is adopted. Figure 2 ,Mask reconstruction task: randomly mask part of the traffic features, the model reconstructs the masked data based on the unmasked part, and learns the basic pattern of the traffic. ,Malicious traffic prediction task: classify traffic based on partial labeled data, train the model to distinguish normal traffic from malicious traffic, and improve its malicious traffic identification ability.

[0147] In this embodiment, the step S5 specifically includes:

[0148] (1) For the mask reconstruction task:

[0149] Randomly select 15% of the tokens from all the tokens in the input sequence for masking. For the selected token, replace it with [MASK] with 80% probability, or select a random token to replace it, or keep it unchanged with 10% probability. Let the model predict the masked tokens through contextual information, thereby learning the internal relationship of the sequence.

[0150] For the input traffic feature sequence X=[x1,x2,...,x n ], where x i It can be byte-level, packet-level or stream-level features, and some features are randomly selected for masking. Let M represent the masking operation, then the input after masking is: X masked=M(X), where M is a random mask matrix that replaces part of the input features with the mask marker [MASK].

[0151] The model learns and reconstructs the masked part through the unmasked features. The reconstruction output of the model is: Among them, f θ is a model with parameters θ, It is the reconstructed output of the model for the masked part.

[0152] The mean square error (MSE) is used to measure the reconstruction quality of the model. The mean square error loss function is:

[0153]

[0154] Among them, Ω is the set of masked feature indices, is the reconstructed value of the model, x i is the true value.

[0155] (2) For malicious traffic prediction tasks:

[0156] After the Transformer encoder, the predicted probability of malicious traffic is generated using the fully connected layer and the Sigmoid activation function, and the output is the predicted probability of each sample.

[0157] Using label data D labeled For malicious traffic prediction. Each sample x∈D labeled is labeled as y∈{0,1}, where 1 indicates malicious traffic and 0 indicates normal traffic, and y is the true label of the sample. The output of the model is the predicted probability of malicious traffic Among them, f θ (x) is the output of the model, which indicates the probability that the traffic is malicious.

[0158] The classification loss for malicious traffic prediction is calculated using the cross entropy loss function:

[0159]

[0160] This loss is used to optimize the classification ability of the model, making it better at distinguishing malicious traffic from normal traffic.

[0161] In order to optimize the model’s mask reconstruction ability and malicious traffic detection ability simultaneously, a joint loss function is adopted to combine the losses of the mask reconstruction task and the malicious traffic prediction task.

[0162] Combine the losses of the two tasks to form a total loss function. Use weight coefficients α and β to balance the losses of the two tasks:

[0163] Ltotal =αL rec +βL pred

[0164] Where L rec is the loss of mask reconstruction, L pred is the loss of malicious traffic prediction. α and β are weight coefficients used to control the relative importance of each task. The mask reconstruction task helps the model learn the internal relationship and global pattern of sequence features. The malicious traffic prediction task strengthens the classification ability of the model and focuses on distinguishing malicious and normal traffic. When the total loss converges or reaches the set training target, the pre-training phase ends and a model with comprehensive capabilities is obtained, which provides a basis for subsequent tasks.

[0165] Step S6, fine-tuning: Based on the pre-trained model, the unlabeled data is further trained through the pseudo-label mechanism. The prediction results generated by the model on the unlabeled data are used as pseudo-labels, and these pseudo-labels are combined with the real labeled data to expand the data set. By introducing the pseudo-label iteration mechanism, the model gradually generates more pseudo-labeled data, and uses this data to periodically retrain the model to ensure that it has good adaptability when facing unknown or new malicious traffic.

[0166] In this embodiment, step S6 specifically includes:

[0167] In the fine-tuning stage, the pseudo-label mechanism and the classification model retraining mechanism are combined to use data without malicious traffic labels to further enhance the generalization ability of the model, as follows:

[0168] The labeled dataset is denoted as D labeled ={(x i ,y i )}, where y i ∈{0,1}, represents sample x i is malicious traffic (1). The unlabeled dataset is denoted as D unlabeled ={x i}, used to generate pseudo labels.

[0169] Loading a self-supervised pre-trained model The model has mastered the ability to represent basic traffic patterns. Initialize model parameters θ = θ pretrained , which is the weight obtained through self-supervised learning training.

[0170] Use the pre-trained model to train unlabeled data D unlabeled Make predictions and generate pseudo labels. Specifically, for unlabeled samples x i ∈D unlabeled Make predictions and generate predicted probabilities

[0171] Then, based on the set confidence threshold τ, a pseudo label is generated according to the predicted probability

[0172] The pseudo-labeled data is then combined with the labeled data to form a merged dataset (i.e., pseudo-labeled data):

[0173] Use the merged dataset D combined Pass it into the model again for training and optimize the model parameters:

[0174] After each round of training, pseudo labels are regenerated, the model is updated and training is repeated.

[0175] Further, for classification model retraining: use the extended dataset D combined Training model. For each sample (x i ,y i ), calculate the model output The classification loss.

[0176] Calculate the classification loss function (cross entropy loss): Update the model parameters θ via back-propagation.

[0177] As the number of iterations increases, the model is trained using the updated pseudo-label data until the model performance reaches the expected target. After each round of iteration, the model performance is evaluated using the validation set, and the pseudo-label generation threshold τ and the number of iterations are dynamically adjusted.

[0178] After fine-tuning is complete, save the final model for use in malicious traffic detection in production environments.

[0179] Step S7, after sufficient self-supervised pre-training and fine-tuning, the model is deployed in the network environment of distributed new energy stations to perform real-time malicious traffic detection. Using the fused multi-scale features, the model can quickly and accurately identify various network attacks, including DDoS attacks, data tampering, scanning and data leakage, to ensure the safe operation of the distributed station network.

[0180] In this embodiment, step S7 specifically includes:

[0181] The trained model is deployed in the network of distributed new energy stations. Due to the characteristics of distributed stations, each station operates independently, and the stations are interconnected through the network. The stations may contain different types of network equipment and computing resources. It is necessary to monitor the traffic of each station at the same time to detect malicious behavior in a timely manner. The deployment of this scenario is optimized, using the edge detection + central analysis architecture: lightweight models are deployed on the edge devices of the station (such as routers, firewalls, or local servers) to perform real-time traffic detection. The detection results or suspected malicious traffic data are uploaded to the central control platform (cloud or main station server) for comprehensive analysis.

[0182] Edge device deployment: Use edge devices with AI reasoning capabilities (such as NVIDIA Jetson, Intel NUC). Run lightweight model reasoning services on edge devices. Use Flask to provide HTTP interfaces, and data streams are transmitted to the reasoning service in real time through the interfaces.

[0183] Central control platform deployment: The detection results of edge devices are uploaded to the central control platform through secure protocols (such as MQTT or HTTPS). The platform aggregates data from multiple sites for global analysis and alarm.

[0184] Step S8: To ensure the continued effectiveness of the model, the model is regularly evaluated on the validation set to assess the detection accuracy, recall rate, and false alarm rate of the model. The performance of the model is judged by the results of the validation set, and retraining and updating are performed when necessary to ensure that the model can effectively respond to new malicious traffic threats in distributed new energy sites.

[0185] In this embodiment, the step S8 specifically includes:

[0186] In distributed renewable energy sites, the deployment and subsequent maintenance of malicious traffic detection models is key to ensuring the long-term stability, accuracy, and adaptability of the system. The models are regularly evaluated by collecting new data.

[0187] The main evaluation indicators include: Accuracy: the correct rate of detecting malicious traffic. Recall: the ability to identify malicious traffic. F1 score: a comprehensive evaluation of the accuracy and recall of the model.

[0188] When the detection recall rate is low, the training data can be expanded by collecting more real malicious traffic samples or synthetic traffic samples to improve the robustness of the model to missed reports. If the traffic environment of the distributed new energy station changes significantly (such as the access of new equipment or the emergence of new traffic patterns), the validation set needs to be replaced or merged with new data to ensure the authenticity and representativeness of the evaluation results.

[0189] By collecting new traffic data in real time and cleaning and labeling it, the model can be retrained or fine-tuned regularly to ensure that it adapts to the latest traffic characteristics. At the same time, an automated update pipeline and rollback mechanism are established to quickly restore the old version when problems are found, and an integrated automated pipeline for data collection, cleaning, labeling, training and deployment is established. The CI / CD (continuous integration / continuous delivery) mechanism is adopted to achieve rapid launch of the model. Secondly, performance monitoring needs to cover inference speed (monitoring the real-time performance of the model in processing traffic to ensure that the delay meets system requirements), resource utilization and detection accuracy, focusing on false alarm rate, missed alarm rate and data distribution drift. By monitoring the changes in the statistical characteristics of the input data (such as distribution, mean and variance), it is determined whether the data deviates from the distribution during model training. For sudden abnormal traffic or detection errors, the system should have the ability to respond and troubleshoot quickly.

[0190] In the environment of distributed new energy stations, network traffic has a complex multi-level structure, from fine-grained information at the byte level to transmission characteristics at the packet level, and then to the global communication mode at the flow level. Traditional single feature analysis methods are often difficult to capture these different levels of feature changes. The present invention uses multi-scale fusion technology to extract features at different time windows and traffic levels, and fuses these multi-dimensional features together, which can more comprehensively capture abnormal behavior of traffic. Combining features at different time scales and traffic levels can improve the detection effect of malicious traffic, because this can comprehensively capture complex attack patterns, reduce false alarms and missed detections, and enhance the adaptability and robustness of the detection system.

[0191] Embodiment 2

[0192] This embodiment provides a malicious traffic detection system for distributed new energy stations, the system comprising:

[0193] The data collection and preprocessing module is used to obtain the network traffic data of various devices in the distributed new energy station under the experimental environment, mark some data as normal traffic or malicious traffic according to the experimental environment, and leave the rest of the data unmarked. It also performs protocol analysis on all the obtained network traffic data and identifies different sessions or flows based on the five-tuple information;

[0194] A traffic feature extraction module is used to extract byte-level features and packet-level features based on a first time window according to the identified session or flow, extract flow-level features based on a second time window, wherein the second time window is larger than the first time window, add a prefix token before each level of extracted features to identify whether the feature source is byte-level, packet-level or flow-level, add a suffix token at the end of the flow-level feature to indicate the end of the feature sequence, and combine the features at each level to form a total feature sequence;

[0195] The detection model pre-training module is used to add position codes to each feature item according to the total feature sequence, map the total feature sequence and position codes to a high-dimensional vector space through an embedding layer, and input the mapped high-dimensional vector into the encoder module of the Transformer model. The detection model is pre-trained through the dual-task training strategy of mask reconstruction and malicious traffic prediction.

[0196] The model fine-tuning and application module is used to use the prediction results generated by the detection model on unlabeled data as pseudo-labels, combine the pseudo-labels with the real labeled data in an iterative manner to form pseudo-labeled data, use the pseudo-labeled data to fine-tune the pre-trained detection model, and deploy the fine-tuned detection model to the network of distributed new energy stations to detect malicious traffic in real time.

[0197] It should be understood that the malicious traffic detection system for distributed new energy stations in the embodiment of the present invention can implement all the technical solutions in the above-mentioned method embodiment, and the functions of its various functional modules can be specifically implemented according to the methods in the above-mentioned method embodiments. Please refer to the relevant description in the above-mentioned embodiments, which will not be repeated here.

[0198] Embodiment 3

[0199] This embodiment provides a computer device, which includes one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the malicious traffic detection method for distributed new energy stations as described above are implemented.

[0200] Embodiment 4

[0201] This embodiment provides a computer storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the malicious traffic detection method for distributed new energy stations as described above are implemented.

[0202] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, devices (systems), computer equipment or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0203] The present invention is described with reference to a flowchart of a method according to an embodiment of the present invention. It should be understood that each process in the flowchart and a combination of processes in the flowchart can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process in the flowchart. Figure 1 A device that specifies functions in a process or multiple processes.

[0204] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A function specified in a process or multiple processes.

[0205] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 The steps of a specified function in a process or multiple processes.

Claims

1. A malicious traffic detection method for distributed new energy stations, characterized in that: The method comprises the following steps: Obtain network traffic data of various devices in distributed new energy stations under experimental environment, mark some data as normal traffic or malicious traffic according to the experimental environment, and do not mark the rest of the data. Perform protocol analysis on all acquired network traffic data, and identify different sessions or flows based on quintuple information. According to the identified session or flow, byte-level features and packet-level features are extracted based on a first time window, and flow-level features are extracted based on a second time window, wherein the second time window is larger than the first time window, prefix tokens are added before the extracted features at each level to identify whether the feature source is byte-level, packet-level or flow-level, a suffix token is added at the end of the flow-level feature to indicate the end of the feature sequence, and the features at each level are combined to form a total feature sequence; According to the total feature sequence, position coding is added to each feature item. The total feature sequence and position coding are mapped to a high-dimensional vector space through an embedding layer. The mapped high-dimensional vector is input into the encoder module of the Transformer model. The detection model is pre-trained through the dual-task training strategy of mask reconstruction and malicious traffic prediction. The prediction results generated by the detection model on unlabeled data are used as pseudo-labels. The pseudo-labels are iteratively combined with real labeled data to form pseudo-labeled data. The pre-trained detection model is fine-tuned using the pseudo-labeled data. The fine-tuned detection model is deployed in the network of distributed new energy stations to detect malicious traffic in real time.

2. The method according to claim 1, characterized in that Extracting byte-level features and packet-level features based on the first time window, and extracting stream-level features based on the second time window, including: In the first time window, the first N bytes of each data packet constituting a session or flow are extracted to form a byte-level feature, denoted as S byte =[byte1,byte2,...,byte i ,...,byte N ], where byte i Represents the first N bytes of the i-th data packet; The average length avg_length, the maximum length max_length, the average time interval avg_interval1 between data packets and the total number of data packets total_packets1 of the data packets constituting the session in the first time window are counted to form a packet-level feature, which is expressed as: S packet =[avg_length,max_length,avg_interval1,total_packets1]; In the second time window, the duration of the flow is obtained, and the total number of data packets in the flow, total_packets2, the total number of bytes, the average time interval between data packets, avg_interval2, and the average length of data packets, avg_packet_length, are counted. The transmission direction of the flow, direction, is obtained to form a flow-level feature sequence, which is expressed as: S flow = [duration,total_packets2,avg_interval2,total_bytes,avg_packet_length,direction].

3. The method according to claim 1, characterized in that The dual-task training strategy of mask reconstruction and malicious traffic prediction is as follows: by represents the reconstruction output of the detection model for the masked part, where f θ is a model with parameters θ, X masked It is the masked feature, and the reconstruction quality of the model is measured by the mean square error combined with the true value of the feature. rec ; Using the labeled dataset D labeled To predict malicious traffic, each sample x∈D labeled It is labeled as y∈{0,1}, where 1 represents malicious traffic and 0 represents normal traffic. The output of the model is the predicted probability of malicious traffic. Among them, f θ (x) is the output of the model for sample x, indicating the probability that the traffic is malicious. Combined with the true label of the sample, the cross entropy loss function is used to calculate the classification loss L for malicious traffic prediction. pred ; Combining the losses of the two tasks, we can form a total loss function: L total =αL rec +βL pred , where α and β are weight coefficients used to control the relative importance of tasks. Pre-training is continued based on the total loss function until the stopping condition is met to obtain the pre-trained model.

4. The method according to claim 3, characterized in that In the mask reconstruction task, each feature item in the input sequence is randomly masked in the following way: X=[x1,x2,...,x i ,...,x n ] represents the total feature sequence, where x i It is a byte-level, packet-level or stream-level feature. Some features are randomly selected for masking. The masked features are expressed as: masked =M(X), where M is a random mask matrix.

5. The method according to claim 4, characterized in that In the malicious traffic prediction task, the input features are passed through the Transformer encoder and then use the fully connected layer and Sigmoid activation function to generate the predicted probability of malicious traffic. The output is the predicted probability of each sample.

6. The method according to claim 1, characterized in that Fine-tune the trained detection model using pseudo-labeled data, including: The unlabeled dataset is denoted as D unlabeled , use the pre-trained model to train unlabeled samples x i ∈D unlabeled Make predictions and generate predicted probabilities where f θ represents a model with parameters θ; Combined with the confidence threshold τ, a pseudo label is generated based on the predicted probability Combining pseudo-labeled data with labeled data combined , using the merged dataset D combined Train the model again and optimize the model parameters: After each round of training, pseudo labels are regenerated, the model is updated and training is repeated.

7. The method according to claim 1, characterized in that Deploy the fine-tuned detection model to the network of distributed new energy stations, including: Lightweight models are deployed on the edge devices of the site to perform real-time traffic detection. The detection results or suspected malicious traffic data are uploaded to the central control platform for comprehensive analysis. Edge device deployment: Use edge devices with AI reasoning capabilities to run lightweight model reasoning services on edge devices. Use Flask to provide HTTP interfaces, and pass data streams to the reasoning service in real time through the interfaces. Central control platform deployment: The detection results of edge devices are uploaded to the central control platform through a secure protocol. The platform aggregates data from multiple sites for global analysis and alarms.

8. The method according to claim 1, characterized in that Also includes: Collect new traffic data to regularly evaluate, update, and optimize the deployed model as follows: By collecting new traffic data in real time and cleaning and annotating it, the model can be retrained or fine-tuned regularly to adapt it to the latest traffic characteristics; Establish an automated update pipeline and rollback mechanism to quickly restore the old version when problems are found; The inference speed, resource utilization, and detection accuracy are evaluated. The detection accuracy focuses on the false alarm rate, missed alarm rate, and data distribution drift. The model training strategy is adjusted according to the evaluation results.

9. A malicious traffic detection system for distributed new energy stations, characterized in that: The system comprises: The data collection and preprocessing module is used to obtain the network traffic data of various devices in the distributed new energy station under the experimental environment, mark some data as normal traffic or malicious traffic according to the experimental environment, and leave the rest of the data unmarked. It also performs protocol analysis on all the obtained network traffic data and identifies different sessions or flows based on the five-tuple information; A traffic feature extraction module is used to extract byte-level features and packet-level features based on a first time window according to the identified session or flow, extract flow-level features based on a second time window, wherein the second time window is larger than the first time window, add a prefix token before each level of extracted features to identify whether the feature source is byte-level, packet-level or flow-level, add a suffix token at the end of the flow-level feature to indicate the end of the feature sequence, and combine the features at each level to form a total feature sequence; The detection model pre-training module is used to add position codes to each feature item according to the total feature sequence, map the total feature sequence and position codes to a high-dimensional vector space through an embedding layer, and input the mapped high-dimensional vector into the encoder module of the Transformer model. The detection model is pre-trained through the dual-task training strategy of mask reconstruction and malicious traffic prediction. The model fine-tuning and application module is used to use the prediction results generated by the detection model on unlabeled data as pseudo-labels, combine the pseudo-labels with the real labeled data in an iterative manner to form pseudo-labeled data, use the pseudo-labeled data to fine-tune the pre-trained detection model, and deploy the fine-tuned detection model to the network of distributed new energy stations to detect malicious traffic in real time.

10. The system according to claim 9, characterized in that Extracting byte-level features and packet-level features based on the first time window, and extracting stream-level features based on the second time window, including: In the first time window, the first N bytes of each data packet constituting a session or flow are extracted to form a byte-level feature, denoted as S byte =[byte1,byte2,...,byte i ,...,byte N ], where byte i Represents the first N bytes of the i-th data packet; The average length avg_length, the maximum length max_length, the average time interval avg_interval1 between data packets and the total number of data packets total_packets1 of the data packets constituting the session in the first time window are counted to form a packet-level feature, which is expressed as: S packet =[avg_length,max_length,avg_interval1,total_packets1]; In the second time window, the duration of the flow is obtained, and the total number of data packets in the flow, total_packets2, the total number of bytes, the average time interval between data packets, avg_interval2, and the average length of data packets, avg_packet_length, are counted. The transmission direction of the flow, direction, is obtained to form a flow-level feature sequence, which is expressed as: S flow = [duration,total_packets2,avg_interval2,total_bytes,avg_packet_length,direction].

11. The system according to claim 9, characterized in that The dual-task training strategy of mask reconstruction and malicious traffic prediction is as follows: by represents the reconstruction output of the detection model for the masked part, where f θ is a model with parameters θ, X masked It is the masked feature, and the reconstruction quality of the model is measured by the mean square error combined with the true value of the feature. rec ; Using the labeled dataset D labeled To predict malicious traffic, each sample x∈D labeled It is labeled as y∈{0,1}, where 1 represents malicious traffic and 0 represents normal traffic. The output of the model is the predicted probability of malicious traffic. Among them, f θ (x) is the output of the model for sample x, indicating the probability that the traffic is malicious. The classification loss L for malicious traffic prediction is calculated using the cross entropy loss function combined with the original label. pred ; Combining the losses of the two tasks, we can form a total loss function: L total =αL rec +βL pred , where α and β are weight coefficients used to control the relative importance of tasks. Pre-training is continued based on the total loss function until the stopping condition is met to obtain the pre-trained model.

12. The system according to claim 11, characterized in that In the mask reconstruction task, each feature item in the input sequence is randomly masked in the following way: X=[x1,x2,...,x i ,...,x n ] represents the total feature sequence, where x i It is a byte-level, packet-level or stream-level feature. Some features are randomly selected for masking. The masked features are expressed as: masked =M(X), where M is a random mask matrix.

13. The system according to claim 9, characterized in that Fine-tune the trained detection model using pseudo-labeled data, including: The unlabeled dataset is denoted as D unlabeled , use the pre-trained model to train unlabeled samples x i ∈D unlabeled Make predictions and generate predicted probabilities where f θ represents a model with parameters θ; Combined with the confidence threshold τ, a pseudo label is generated based on the predicted probability Combining pseudo-labeled data with labeled data combined , using the merged dataset D combined Train the model again and optimize the model parameters: After each round of training, pseudo labels are regenerated, the model is updated and training is repeated.

14. The system according to claim 9, characterized in that The fine-tuned detection model is deployed to the network of distributed new energy stations, where the edge devices of the stations deploy lightweight models to perform real-time traffic detection, and the detection results or suspected malicious traffic data are uploaded to the central control platform for comprehensive analysis; the edge devices use edge devices with AI reasoning capabilities to run lightweight model reasoning services, and use Flask to provide HTTP interfaces. The data stream is transmitted to the reasoning service in real time through the interface; the detection results of the edge devices are uploaded to the central control platform through a security protocol, and the platform aggregates data from multiple stations for global analysis and alarms.

15. The system according to claim 9, characterized in that It also includes a model maintenance module, which is used to collect new traffic data to regularly evaluate, update, and optimize the deployed models, including: A regular updating unit is used to regularly retrain or fine-tune the model to adapt it to the latest traffic characteristics by collecting, cleaning, and annotating new traffic data in real time; Rollback settings unit, used to establish automated update pipelines and rollback mechanisms, so that old versions can be quickly restored when problems are found; The performance evaluation unit is used to evaluate inference speed, resource utilization, and detection accuracy. The detection accuracy focuses on false positive rate, false negative rate, and data distribution drift, and the model training strategy is adjusted according to the evaluation results.

16. A computer device, characterized in that: The device includes one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the malicious traffic detection method for distributed new energy stations as described in any one of claims 1-8 are implemented.

17. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the malicious traffic detection method for distributed new energy stations as described in any one of claims 1-8 are implemented.

Citation Information

Patent Citations

  • Malicious traffic classification method and equipment based on unreliable pseudo label semi-supervised learning

    CN116527399A

  • Malicious traffic detection method based on mask automatic encoder pre-training

    CN118400195A

  • Malicious network traffic detection method based on multistage feature fusion and adaptive balance

    CN118821037A

  • Device, method, and system for supporting botnet traffic detection

    US20240080337A1