Network intrusion detection method and device based on heterogeneous computing
Through the network intrusion detection method based on heterogeneous computing, the spatio-temporal correlation of network target data is extracted, the computing tasks of virtual GPUs are determined, key features are extracted and network intrusion classification is solved, and the problems of large computing resources and poor real-time performance of traditional systems in the face of complex network attacks are achieved, and efficient and accurate network intrusion detection is achieved.
Patent Information
- Application Number
- CN202510411691.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-03-26
- Filing Date
- 2025-04-02
- Publication Date
- 2025-05-13
AI Technical Summary
When traditional network intrusion detection systems face complex and changeable network attack environments, they are difficult to deal with changes in spatial and temporal characteristics, and their computing resources are consumed and their real-time performance is poor.
Using a network intrusion detection method based on heterogeneous computing, a network target data of the physical layer is obtained, and structured data blocks are generated by slicing processing. The calculation tasks of the virtual graphics processor are determined based on space-time correlation, key spatial features and target timing characteristics are extracted, and network intrusion classification is performed.
It improves the accuracy and security of traffic processing, rationally configures virtual GPUs, realizes the end-to-end processing pipeline from intelligent network card to GPU, simplifies data transmission, has strong real-time, flexibility and scalability, saves computing resources and improves the accuracy of network intrusion detection.
Smart Images

Figure CN119996067A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network intrusion detection method and device based on heterogeneous computing in the field of network security technology. Background Art
[0002] With the rapid development of information technology, network security threats have become increasingly complex, and traditional network security protection methods can no longer meet the needs of today's complex and ever-changing network attack environment. As one of the key technologies for protecting computer networks from malicious attacks, intrusion detection systems (IDS) have occupied an important position in the network security defense system. In a dynamic and complex network environment, traditional anomaly detection methods are difficult to cope with changes in spatiotemporal characteristics. As network attack patterns become increasingly diverse, attackers often use temporal and spatial distribution characteristics to launch complex attack behaviors.
[0003] In the past, intrusion detection systems mostly relied on centralized computing architectures, usually analyzing network traffic through a single processing unit. However, with the rapid growth of network traffic and the continuous evolution of intrusion attack techniques, the computing power of a single processing unit often cannot meet the requirements of high load and high throughput. Therefore, in recent years, the introduction of heterogeneous computing platforms has become an important direction for improving the performance of intrusion detection systems, especially multi-core heterogeneous computing based on graphics processing units (GPUs) and central processing units (CPUs), which can significantly improve the processing power of the system. In addition, the characteristics of network traffic usually have spatiotemporal correlation, that is, the spatial characteristics of traffic (such as protocol type, packet length, etc.) and temporal characteristics (such as traffic time series, burst traffic, etc.) are closely related. In order to more accurately identify and detect network intrusion behaviors, researchers have gradually tried to use deep learning methods, such as convolutional neural networks (CNNs) and recurrent neural networks (RNNs), to improve the accuracy and robustness of detection by learning the spatiotemporal patterns of traffic. However, due to the huge scale of network traffic data and the changing attack patterns, these methods often face problems such as high consumption of computing resources and poor real-time performance. Summary of the invention
[0004] The purpose of the present invention is to provide a network intrusion detection method and device based on heterogeneous computing. The technical solution adopted is as follows:
[0005] In a first aspect, an embodiment of the present invention provides a network intrusion detection method based on heterogeneous computing, the method comprising:
[0006] Get network target data of physical layer;
[0007] Slicing the network target data to generate structured data blocks with temporal and spatial correlation;
[0008] Determining a computing task for each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks;
[0009] Based on the computing task, extracting key spatial features and target temporal features in the structured data block;
[0010] Based on the key spatial features and the target temporal features, the network target data is classified into network intrusion categories to obtain a classification result indicating whether the network target data has network intrusion.
[0011] In a second aspect, an embodiment of the present invention provides a network intrusion detection device based on heterogeneous computing, and the network intrusion detection device based on heterogeneous computing includes:
[0012] An acquisition module, used to acquire network target data of the physical layer;
[0013] A generation module, used for slicing the network target data to generate structured data blocks with temporal and spatial correlation;
[0014] A determination module, configured to determine a computing task of each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks;
[0015] An extraction module, configured to extract key spatial features and target temporal features from the structured data block based on the computing task;
[0016] The classification module is used to classify the network target data into network intrusions based on the key spatial features and the target temporal features, and obtain a classification result indicating whether the network target data has network intrusions.
[0017] According to a third aspect, a computer program product is provided. The computer program product includes: a computer program code. When the computer program code is executed on a computer, the computer executes the method according to the first aspect.
[0018] According to a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program code. When the computer program code is executed on a computer, the computer executes the method according to the first aspect.
[0019] The present invention has the following beneficial effects: after obtaining the network target data of the physical layer, the network target data is sliced to generate a structured data block with spatiotemporal correlation, so that the accuracy and security of traffic processing can be enhanced. Afterwards, based on the spatiotemporal correlation of the structured data block, the computing task of each virtual graphics processor is determined; and based on the computing task, the key spatial features and the target timing features are extracted from the structured data block; in this way, the virtual GPU can be reasonably deployed to realize the end-to-end processing pipeline from the smart network card to the GPU, and simplify the transmission mode of data from the smart network card to the CPU and then to the GPU. Finally, based on the key spatial features and the target timing features, the network target data is classified for network intrusion, and a classification result characterizing whether the network target data has network intrusion is obtained. In this way, the target timing features and the key spatial features are combined, and dynamic task scheduling is performed, so that large-scale network traffic can be efficiently processed, with strong real-time, flexibility and scalability, which can not only save computing resources, but also improve the accuracy of network intrusion detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0021] Figure 1 It is a schematic diagram of an implementation flow of a network intrusion detection method based on heterogeneous computing provided by an embodiment of the present invention;
[0022] Figure 2 It is a schematic diagram of an implementation framework of a network intrusion detection method based on heterogeneous computing provided by an embodiment of the present invention;
[0023] Figure 3 It is another implementation flow diagram of a network intrusion detection method based on heterogeneous computing provided by an embodiment of the present invention;
[0024] Figure 4 It is a schematic diagram of the composition structure of a network intrusion detection device based on heterogeneous computing provided by an embodiment of the present invention;
[0025] Figure 5 It is a structural schematic diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0026] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of the network intrusion detection method based on heterogeneous computing proposed by the present invention, its specific implementation method, structure, features and effects, in combination with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form as described.
[0027] Among them, in the description of the embodiments of the present invention, unless otherwise specified, " / " means or, for example, A / B can mean A or B: "and / or" in the text is only a way to describe the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present invention, "multiple" refers to two or more than two.
[0028] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as suggesting or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.
[0029] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0030] The following is a detailed description of a network intrusion detection method based on heterogeneous computing provided by the present invention in conjunction with the accompanying drawings. Figure 1 , which shows a schematic diagram of an implementation flow of a network intrusion detection method based on heterogeneous computing provided by an embodiment of the present invention, the method comprising:
[0031] 101, obtain network target data of the physical layer.
[0032] Here, the network target data of the physical layer is the traffic data of the physical layer captured through the smart network card interface. The network traffic is ingested and the protocol is parsed through hardware, invalid traffic is filtered, and the line speed capture and protocol semantic parsing of the physical layer network traffic are achieved to obtain the network target data.
[0033] In some possible implementations, the above step 101 may be implemented by the following steps 111 and 112 (not shown):
[0034] 111, using hardware to obtain network traffic data at the physical layer.
[0035] 112. Perform protocol semantic analysis on the network traffic data to obtain the network target data.
[0036] like Figure 2 As shown, the network traffic data of the physical layer is captured by the traffic capture submodule in the smart network card data preprocessing module, and the network target data of the physical layer is obtained by the protocol analysis submodule. The traffic capture submodule and the protocol analysis submodule perform physical layer data ingestion and protocol analysis on the network traffic through hardware, and filter invalid traffic to achieve line-speed capture and protocol semantic analysis of the physical layer network traffic, and obtain network target data. In this way, the traffic capture and protocol analysis technology based on the smart network card can achieve line-speed capture and protocol semantic analysis of the physical layer network traffic, significantly improving the efficiency and real-time performance of network traffic analysis.
[0037] In some possible implementations, this can be accomplished by Figure 3 The steps shown are used to obtain network target data:
[0038] 301, using a preset network card physical interface to capture full-duplex Ethernet traffic to obtain the network traffic data.
[0039] like Figure 2 As shown, full-duplex Ethernet traffic is captured through the SmartNIC physical interface.
[0040] 302 , marking the timestamp of each data packet in the network traffic data based on the current timestamp to obtain marked traffic data.
[0041] like Figure 2 As shown, the timestamp of each data network packet is marked based on the timestamp synchronization to ensure timing consistency.
[0042] 303 , decapsulate the Ethernet frame, network address header, and transport layer header of the marked traffic data layer by layer based on the hardware-level protocol parsing pipeline to obtain key metadata.
[0043] Here, if Figure 2 As shown, a hardware-level protocol parsing pipeline is used to decapsulate Ethernet frames, IP headers, and transport layer headers layer by layer, extract key metadata, and build a protocol syntax tree.
[0044] 304 , using a rule matching engine to filter invalid traffic in the key metadata to obtain the network traffic data.
[0045] like Figure 2As shown in the figure, the rule matching engine is used to filter invalid traffic, and real-time abnormal traffic detection is performed based on the statistical characteristics of the traffic to obtain network target data and input it into the painting flow slicing submodule. In this way, the real-time filtering of traffic is achieved through the rule matching engine, and abnormal traffic detection is performed based on the statistical characteristics of traffic, which effectively enhances the accuracy and security of traffic processing.
[0046] 102, slicing the network target data to generate structured data blocks with temporal and spatial correlation.
[0047] Here, through Figure 2 The painting flow slicing submodule and feature encoding submodule shown in the figure slice the network target data to generate structured data blocks with spatiotemporal correlation. The painting flow slicing submodule and feature encoding submodule slice the original traffic using a preset window size or data threshold, perform feature extraction, and finally generate structured data blocks with spatiotemporal correlation.
[0048] In some possible implementations, the above step 102 may be implemented by the following steps 121 and 122 (not shown):
[0049] 121, slice the network target data to obtain sliced data.
[0050] Here, the network target data is sliced by the drawing stream slicing submodule to obtain sliced data. The drawing stream slicing submodule associates data packets according to key metadata, constructs a session stream, and slices using a preset window size or data threshold to obtain sliced data.
[0051] 122, extract features from the sliced data to obtain the structured data block with spatiotemporal correlation.
[0052] In some possible implementations, the above step 122 can be implemented through the following process: first, a preset feature extraction engine is used to calculate the statistical features of the sliced data; second, the data packets corresponding to the statistical features are reorganized into data blocks of a fixed size; for example, the feature encoding submodule uses a lightweight feature extraction engine to calculate statistical features such as payload byte entropy and packet rate variance, and reorganizes the data packets into data blocks of a fixed size.
[0053] Finally, the preset spatiotemporal data is added to the data block to obtain the structured data block.
[0054] Here, if Figure 2As shown in the figure, the feature encoding submodule attaches spatiotemporal data to the data packet, including timestamp sequence, protocol context, and threat weight, and finally outputs it as a three-dimensional vector (number of channels × time step × feature dimension) with a unified computing device architecture (CUDA) memory descriptor, that is, a structured data block is obtained. After that, the three-dimensional vector is stored in the smart network card. In this way, the traffic is sliced and features are extracted using a lightweight feature extraction engine, and a structured data block is constructed by attaching spatiotemporal data, and an innovative three-dimensional vector format that conforms to the CUDA memory model is designed.
[0055] 103 : Determine a computing task of each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks.
[0056] Here, through Figure 2 The CPU dynamic task scheduling module shown determines the computing tasks of each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks. The CPU dynamic task scheduling module runs a real-time task scheduling engine through a multi-core CPU (e.g., I7-12700KF, 20 cores) to dynamically allocate computing tasks according to the spatiotemporal attributes of traffic characteristics.
[0057] In some possible implementations, the above step 103 may be implemented by the following steps 131 and 132 (not shown):
[0058] 131. Determine the traffic type of the structured data block based on the spatiotemporal correlation of the structured data block.
[0059] like Figure 2 As shown, the CPU dynamic task scheduling module classifies data traffic according to its type. There are three specific types of traffic: safe traffic (eg, green safe), suspicious traffic (eg, yellow suspicious), and high-risk traffic (eg, red high-risk).
[0060] 132. Determine a computing task of each virtual graphics processor based on the traffic type and the real-time load of each virtual graphics processor.
[0061] like Figure 2As shown in the figure, high-risk traffic is preferentially allocated to the virtual GPU for processing. The task scheduling engine in the CPU dynamic task scheduling module allocates computing tasks according to each virtual GPU and adjusts the task allocation according to the real-time load of each virtual GPU to ensure that the computing resources of each GPU are used in the best state. In this way, the module based on CPU dynamic task scheduling dynamically allocates computing resources according to traffic type, reasonably deploys virtual GPUs, breaks through the traditional CPU-centric architecture, realizes the end-to-end processing pipeline from smart network card to GPU, and simplifies the transmission method of data from smart network card to CPU and then to GPU.
[0062] 104. Extract key spatial features and target temporal features from the structured data block based on the computing task.
[0063] Here, the key spatial features and target temporal features are extracted from the structured data block by using a multi-virtual GPU parallel inference module. In some possible implementations, first, based on the computing task, a network data packet is read from the structured data block; second, a dynamic residual gated convolutional neural network and a multi-scale dilated convolution are used to extract features from the network data packet to obtain the key spatial features. Figure 2 As shown in the figure, the spatial feature extraction submodule in the multi-virtual GPU parallel inference module receives the tasks assigned by the CPU and directly reads the network packet data blocks from the device memory, and executes the dynamic residual gated convolutional neural network and multi-scale dilated convolution in parallel to extract key spatial features. The spatial feature extraction submodule captures spatial features of different granularities through different expansion rates (for example, the expansion rate is 1, 3, or 5).
[0064] The spatial feature extraction submodule receives the task assigned by the CPU, captures data descriptors in parallel through CUDA streams, uses RDMA or GPU Direct technology to input data blocks directly from the memory to the GPU, enters the convolutional neural network, extracts protocol header features through deep separable convolution, and introduces learnable residual weight coefficients for dynamic addition; then, performs void convolutions of different scales, and each convolution expansion rate is 1, 3, and 5 to capture spatial features of different granularities; among them, the convolution expansion rate is 1: to extract the payload entropy value of the data packet; the convolution expansion rate is 3: to capture the traffic mutation of the data; the convolution expansion rate is 5: to detect the pattern of a long time span) The results of different scales are weighted and fused to obtain the key spatial features.
[0065] Finally, a bidirectional gated recurrent neural network with a time decay factor is used to extract the target temporal features of the key spatial features.
[0066] like Figure 2As shown in the figure, the time series modeling submodule uses a bidirectional gated recurrent neural network with a time decay factor to analyze the long-term dependency of the traffic sequence, and outputs the target time series features extracted from the forward and backward directions in a weighted manner through a multi-head attention mechanism. The time series modeling submodule inputs the results output by the spatial feature extraction submodule into the bidirectional gated recurrent unit with time decay. The forward propagation processes the traffic sequence in chronological order, and the backward propagation analyzes the historical information in reverse order and associates the context information. After that, the time decay factor is introduced to adjust during the training process, and the weight of the influence of outdated information will be reduced. Finally, the bidirectional feature results output by the gated recurrent unit are spliced based on the attention mechanism, and then compressed to a fixed dimension through a fully connected layer to obtain the target time series features. In this way, through the multi-virtual GPU parallel inference module, combined with the dynamic residual gated convolutional neural network and the dilated convolution, the spatial features of the network traffic can be efficiently extracted, and the long-term dependency of the traffic sequence can be analyzed through time series modeling, further improving the accuracy of traffic prediction.
[0067] 105. Based on the key spatial features and the target temporal features, the network target data is classified into network intrusion categories to obtain a classification result indicating whether the network target data has network intrusion.
[0068] Here, a CPU dynamic result fusion module including a dynamic threshold classification and uncertainty quantification submodule and an incremental learning feedback and feature update module submodule is used to classify the network target data for network intrusion based on the key spatial features and the target time series features, and obtain a classification result that characterizes whether the network target data has network intrusion. Figure 2 As shown in the figure, the dynamic threshold classification and uncertainty quantification submodule is mainly responsible for dynamically adjusting the classification threshold according to the statistical characteristics of real-time network traffic and evaluating the credibility of the prediction results. The process of extracting the spatial characteristics of network traffic by the dynamic threshold classification and uncertainty quantification submodule is as follows: First, the CPU receives the detection results of the GPU and analyzes the working status of the current network environment (the network traffic is large during peak hours, and the high traffic judgment standard is relaxed at this time to avoid misjudgment); secondly, the CPU performs a sampling check on the detection results to see whether the judgment results of different GPUs for the same data block are consistent. A large gap means that the model uncertainty is higher. At this time, it will be marked and the corresponding information will be provided for personnel to review. In this way, the dynamic threshold classification and uncertainty quantification module can dynamically adjust the classification threshold according to the real-time network traffic, and improve the reliability of the prediction results through uncertainty evaluation, avoiding misjudgment and missed judgment.
[0069] In some embodiments, first, after classifying network intrusions of network target data through a network model to obtain classification results, candidate samples with confidence levels less than a preset threshold are determined in the network target data based on the classification results; for example, the incremental learning feedback and feature update module submodule analyzes long-term dependencies of traffic sequences, automatically captures candidate samples with higher uncertainty in prediction results, extracts feature information of these candidate samples, retains and compresses the feature information, and transmits it back to the storage area of the network card.
[0070] Secondly, based on the classification result, the classification threshold of the network model corresponding to the classification result is adjusted to obtain an intermediate network model; finally, the intermediate network model is incrementally learned based on the candidate sample to obtain an updated network model. For example, the incremental learning feedback and feature update module submodule regularly inputs the feature information of the network card storage area into the model for training to improve the accuracy of the entire system's prediction of future traffic. In this way, by introducing the incremental learning feedback and feature update mechanism, the model can be continuously optimized through incremental learning and feature update of low-confidence samples, thereby enhancing the system's ability to predict future traffic.
[0071] In an embodiment of the present invention, after obtaining the network target data of the physical layer, the network target data is sliced to generate a structured data block with spatiotemporal correlation, so that the accuracy and security of traffic processing can be enhanced. Afterwards, based on the spatiotemporal correlation of the structured data block, the computing task of each virtual graphics processor is determined; and based on the computing task, the key spatial features and the target timing features are extracted from the structured data block; in this way, the virtual GPU can be reasonably deployed to realize the end-to-end processing pipeline from the smart network card to the GPU, and simplify the transmission method of data from the smart network card to the CPU and then to the GPU. Finally, based on the key spatial features and the target timing features, the network target data is classified for network intrusion, and a classification result is obtained to characterize whether the network target data has network intrusion. In this way, the target timing features and key spatial features are combined, and dynamic task scheduling is performed, so that large-scale network traffic can be efficiently processed, with strong real-time, flexibility and scalability, which can not only save computing resources, but also improve the accuracy of network intrusion detection.
[0072] The embodiment of the present invention provides a network intrusion detection device based on heterogeneous computing, see Figure 4 , which shows a schematic diagram of the composition structure of a network intrusion detection device based on heterogeneous computing provided by an embodiment of the present invention, the device 400 includes:
[0073] An acquisition module 401 is used to acquire network target data of a physical layer;
[0074] A generation module 402 is used to slice the network target data to generate structured data blocks with temporal and spatial correlation;
[0075] A determination module 403, configured to determine a computing task of each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks;
[0076] An extraction module 404, configured to extract key spatial features and target temporal features from the structured data block based on the computing task;
[0077] The classification module 405 is used to classify the network target data for network intrusion based on the key spatial features and the target temporal features, and obtain a classification result indicating whether the network target data has network intrusion.
[0078] In some possible implementations, the acquisition module 401 is further used to acquire network traffic data of the physical layer using hardware; perform protocol semantic analysis on the network traffic data to obtain the network target data.
[0079] In some possible implementations, the acquisition module 401 is also used to capture full-duplex Ethernet traffic using a preset network card physical interface to obtain the network traffic data; mark the timestamp of each data packet in the network traffic data based on the current timestamp to obtain marked traffic data; decapsulate the Ethernet frame, network address packet header and transport layer header of the marked traffic data layer by layer based on the hardware-level protocol parsing pipeline to obtain key metadata; use a rule matching engine to filter invalid traffic in the key metadata to obtain the network target data.
[0080] In some possible implementations, the generation module 402 is further used to slice the network target data to obtain sliced data; and perform feature extraction on the sliced data to obtain the structured data blocks with spatiotemporal correlation.
[0081] In some possible implementations, the generation module 402 is further used to calculate the statistical features of the sliced data using a preset feature extraction engine; reorganize the data packets corresponding to the statistical features into data blocks of a fixed size; and attach preset spatiotemporal data to the data blocks to obtain the structured data blocks.
[0082] In some possible implementations, the determination module 403 is further used to determine the traffic type of the structured data block based on the spatiotemporal correlation of the structured data block; and determine the computing task of each virtual graphics processor based on the traffic type and the real-time load of each virtual graphics processor.
[0083] In some possible implementations, the extraction module 404 is also used to read network data packets from the structured data block based on the computing task; use a dynamic residual gated convolutional neural network and a multi-scale hole convolution to extract features of the network data packets to obtain the key spatial features; and use a bidirectional gated recurrent neural network with a time attenuation factor to extract the target temporal features of the key spatial features.
[0084] In some possible implementations, the extraction module 404 is also used to use the bidirectional gated recurrent neural network to perform timing processing on the forward propagation of the key spatial features, and to perform reverse analysis on the backward propagation of the key spatial features to obtain the historical information and context information of the key spatial features; based on the time attenuation factor, the historical information and the context information, the network parameters of the bidirectional gated recurrent neural network are adjusted to obtain the adjusted bidirectional gated recurrent neural network; based on the attention mechanism, the initial timing features output by the adjusted bidirectional gated recurrent neural network are spliced to obtain the target timing features.
[0085] In some possible implementations, the classification module 405 is also used to determine, based on the classification result, candidate samples whose confidence level is less than a preset threshold in the network target data; based on the classification result, adjust the classification threshold of the network model corresponding to the classification result to obtain an intermediate network model; and perform incremental learning on the intermediate network model based on the candidate samples to obtain an updated network model.
[0086] Optionally, the transmission medium can be a wired link (for example, but not limited to, coaxial cable, optical fiber and digital subscriber line (DSL), etc.) or a wireless link (for example, but not limited to, wireless Fidelity (WIFI), Bluetooth and mobile device network, etc.). It should be noted that: the device provided in the above embodiment is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the computer device is divided into different functional modules to complete all or part of the functions described above. In addition, the method embodiments provided in the above embodiments belong to the same concept. The specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0087] Figure 5 is a schematic diagram of the structure of a computer device provided by an embodiment of the present invention. Figure 5As shown, the computer device 500 includes: a memory 501, a processor 502, and a computer program 503 stored in the memory 501 and running on the processor 502, wherein when the processor 502 executes the computer program 503, the computer device can execute any one of the network intrusion detection methods based on heterogeneous computing introduced above.
[0088] In addition, an embodiment of the present invention also protects a system, which may include a memory and a processor, wherein an executable program code is stored in the memory, and the processor is used to call and execute the executable program code to perform a network intrusion detection method based on heterogeneous computing provided by an embodiment of the present invention. This embodiment can divide the system into functional modules according to the above method example. For example, it can correspond to each functional module, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is schematic, which is only a logical function division, and there may be other division methods in actual implementation. It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, which will not be repeated here.
[0089] It should be understood that the device provided in this embodiment is used to perform the above-mentioned network intrusion detection method based on heterogeneous computing, so the same effect as the above-mentioned implementation method can be achieved. In the case of an integrated unit, the device may include a processing module and a storage module. Among them, when the device is applied to a device, the processing module can be used to control and manage the actions of the device. The storage module can be used to support the device to execute mutual program codes, etc. Among them, the processing module can be a processor or a controller, which can implement or execute various exemplary logical boxes, modules and circuits described in conjunction with the disclosure of the present invention. The processor can also be a combination that implements a computing function, such as a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc., and the storage module can be a memory.
[0090] In addition, the device provided in the embodiment of the present invention may be a chip, a component or a module, and the chip may include a connected processor and a memory; wherein the memory is used to store instructions, and when the processor calls and executes the instructions, the chip may execute a network intrusion detection method based on heterogeneous computing provided in the above embodiment. This embodiment also provides a computer-readable storage medium, in which a computer program code is stored, and when the computer program code is run on a computer, the computer executes the above-mentioned related method steps to implement a network intrusion detection method based on heterogeneous computing provided in the above embodiment.
[0091] This embodiment also provides a computer program product. When the computer program product is run on a computer, the computer executes the above-mentioned related steps to implement a network intrusion detection method based on heterogeneous computing provided in the above embodiment. Among them, the device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be repeated here. Through the description of the above implementation mode, the technicians in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In practical applications, the above-mentioned function allocation can be completed by different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In the embodiments provided by the present invention, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiment described above is only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, which may be electrical, mechanical or other forms.
[0092] It should be noted that the sequence of the above-mentioned embodiments of the present invention is only for description and does not represent the advantages and disadvantages of the embodiments. The process depicted in the accompanying drawings does not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or may be advantageous. The various embodiments in this specification are described in a progressive manner, and the same and similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments. The above content is only a specific implementation method of the present invention, but the protection scope of the present invention is not limited to this. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be covered within the protection scope of the present invention.
Claims
1. A network intrusion detection method based on heterogeneous computing, characterized in that: The network intrusion detection method based on heterogeneous computing includes: Get network target data of physical layer; Slicing the network target data to generate structured data blocks with temporal and spatial correlation; Determining a computing task for each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks; Based on the computing task, extracting key spatial features and target temporal features in the structured data block; Based on the key spatial features and the target temporal features, the network target data is classified into network intrusion categories to obtain a classification result indicating whether the network target data has network intrusion.
2. A network intrusion detection method based on heterogeneous computing according to claim 1, characterized in that: The obtaining of network target data of the physical layer includes: Use hardware to obtain network traffic data at the physical layer; The network traffic data is subjected to protocol semantic parsing to obtain the network target data.
3. A network intrusion detection method based on heterogeneous computing according to claim 2, characterized in that: The method of using hardware to obtain network traffic data of the physical layer includes: Using a preset network card physical interface to capture full-duplex Ethernet traffic to obtain the network traffic data; Correspondingly, performing protocol semantic parsing on the network traffic data to obtain the network target data includes: Marking the timestamp of each data packet in the network traffic data based on the current timestamp to obtain marked traffic data; Decapsulating the Ethernet frame, network address header and transport layer header of the marked traffic data layer by layer based on the hardware-level protocol parsing pipeline to obtain key metadata; A rule matching engine is used to filter invalid traffic in the key metadata to obtain the network target data.
4. A network intrusion detection method based on heterogeneous computing according to claim 1, characterized in that: The slicing process of the network target data to generate structured data blocks with temporal and spatial correlation includes: Slicing the network target data to obtain sliced data; Feature extraction is performed on the sliced data to obtain the structured data block with spatiotemporal correlation.
5. A network intrusion detection method based on heterogeneous computing according to claim 4, characterized in that: The step of extracting features from the sliced data to obtain the structured data block with spatiotemporal correlation includes: Calculating statistical features of the sliced data using a preset feature extraction engine; Reorganize the data packets corresponding to the statistical features into data blocks of fixed size; The preset spatiotemporal data is appended to the data block to obtain the structured data block.
6. A network intrusion detection method based on heterogeneous computing according to claim 1, characterized in that: The step of determining the computing task of each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks includes: Determining a traffic type of the structured data block based on the spatiotemporal correlation of the structured data block; Based on the traffic type and the real-time load of each virtual graphics processor, a computing task of each virtual graphics processor is determined.
7. A network intrusion detection method based on heterogeneous computing according to claim 1, characterized in that: The step of extracting key spatial features and target temporal features from the structured data block based on the computing task includes: Based on the computing task, reading a network data packet from the structured data block; Using a dynamic residual gated convolutional neural network and a multi-scale dilated convolution to extract features from the network data packet to obtain the key spatial features; A bidirectional gated recurrent neural network with a time decay factor is used to extract target temporal features of the key spatial features.
8. A network intrusion detection method based on heterogeneous computing according to claim 7, characterized in that: The method of using a bidirectional gated recurrent neural network with a time decay factor to extract the target temporal features of the key spatial features includes: The bidirectional gated recurrent neural network is used to perform time sequence processing on the forward propagation of the key spatial features, and reverse analysis is performed on the backward propagation of the key spatial features to obtain historical information and context information of the key spatial features; Based on the time decay factor, the historical information and the context information, adjusting the network parameters of the bidirectional gated recurrent neural network to obtain an adjusted bidirectional gated recurrent neural network; The initial time series features output by the adjusted bidirectional gated recurrent neural network are concatenated based on the attention mechanism to obtain the target time series features.
9. A network intrusion detection method based on heterogeneous computing according to claim 1, characterized in that: The method further comprises: Based on the classification result, determining candidate samples whose confidence level is less than a preset threshold in the network target data; Based on the classification result, adjusting the classification threshold of the network model corresponding to the classification result to obtain an intermediate network model; Incremental learning is performed on the intermediate network model based on the candidate samples to obtain an updated network model.
10. A network intrusion detection device based on heterogeneous computing, characterized in that: The network intrusion detection device based on heterogeneous computing includes: An acquisition module, used to acquire network target data of the physical layer; A generation module, used for slicing the network target data to generate structured data blocks with temporal and spatial correlation; A determination module, configured to determine a computing task of each virtual graphics processor based on the spatiotemporal correlation of the structured data blocks; An extraction module, configured to extract key spatial features and target temporal features from the structured data block based on the computing task; The classification module is used to classify the network target data into network intrusions based on the key spatial features and the target temporal features, and obtain a classification result indicating whether the network target data has network intrusions.