Network abnormal flow detection method and device based on PU-MIL
By introducing PU-MIL technology and a two-component loss function automatic encoder model in network abnormal traffic detection, the existing methods depend on comprehensive annotation data and imbalance of positive and negative samples is solved, and efficient and accurate abnormal traffic detection is achieved.
Patent Information
- Application Number
- CN202510449733.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing anomaly traffic detection methods rely on comprehensive annotation data and the positive and negative samples are unbalanced, resulting in increased difficulty in model training and weakened the ability to identify abnormal traffic.
The abnormal flow detection technology (PU-MIL) based on a combination of positive sample, unlabeled sample learning and multi-example learning is adopted to optimize the performance of the automatic encoder model by building a two-component loss function, combining sample-level reconstruction errors and packet-level labels.
With only a small number of known exception samples and a large number of unlabeled data, the abnormal traffic in the network is efficiently and accurately identified, effectively improving the detection ability of a few types of abnormal events.
Smart Images

Figure CN119996076A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a method and device for detecting abnormal network traffic based on PU-MIL. Background Art
[0002] In current network traffic monitoring, traditional abnormal traffic detection methods rely on each data sample having a clear label (normal or abnormal). However, in practical applications, it is extremely difficult to obtain comprehensive and accurate label information due to the high cost and time-consuming labeling process. In addition, traditional abnormal traffic detection methods usually assume that positive and negative samples are balanced, but in reality, abnormal traffic only accounts for a small part of the total traffic, resulting in a serious imbalance between positive and negative samples in the training set. This imbalance not only increases the difficulty of model training, but may also cause the model to be biased towards the majority class, i.e., normal traffic, thereby weakening the ability to identify the minority class, i.e., abnormal traffic.
[0003] Therefore, how to provide a technology that can both efficiently process and fully utilize limited anomaly data stream information is crucial to improving the accuracy and efficiency of anomaly detection. Summary of the invention
[0004] In view of the above defects or deficiencies in the prior art, the present invention provides a network abnormal traffic detection method and device based on PU-MIL, aiming to solve the challenges of the existing abnormal traffic detection methods in terms of heavy reliance on fully labeled data and imbalance of positive and negative samples. By introducing an abnormal traffic detection technology based on the combination of positive sample, unlabeled sample learning and multi-instance learning (referred to as PU-MIL in the present invention), it is possible to efficiently and accurately identify abnormal traffic in the network with only a small number of known abnormal samples and a large amount of unlabeled data.
[0005] In one aspect of the present invention, a method for detecting abnormal network traffic based on PU-MIL is provided, comprising: dividing a network data flow containing multiple data packets into positive packets containing multiple examples and unlabeled packets; wherein each example corresponds to a data packet, the positive packet is a data flow with at least one abnormal data packet, and the unlabeled packet is a data flow without any category label; constructing an automatic encoder model with a two-component loss function; wherein the two-component loss function includes a first component loss function and a second component loss function, the first component loss function is used to calculate the loss value of all unlabeled packets, and the second component loss function is used to calculate the loss value of all positive packets; Through deep learning back-propagation training, the minimum value of the two-component loss function is iteratively solved to obtain a data stream level classifier and a data packet level classifier; the data stream level classifier is used to distinguish abnormal data streams, and the data packet level classifier is used to detect abnormal data packets.
[0006] Furthermore, the loss value of all unlabeled packages is calculated by the following formula: ; ,in ; in, represents the first component loss function, represents the packet-level reconstruction error in multi-instance learning, Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Indicates the number of all data streams. Represents the set of all data streams.
[0007] Furthermore, the loss value of all positive packets is calculated by the following formula: ; ; ; in, represents the second component loss function, represents a data stream level classifier, represents the packet level classifier, express The weight of Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Represents a collection of abnormal data flows, Represents a normal data flow set, Take the constant, and Represents the parameters to be learned by the autoencoder.
[0008] Further, the packet type, packet length, packet payload length and packet character statistics are taken as example features of each example.
[0009] Furthermore, the abnormal data flow set and the normal data flow set The number of data streams is the same.
[0010] On the other hand, the present invention also provides a network abnormal traffic detection device based on PU-MIL, including: a first module, configured to divide a network data flow containing multiple data packets into positive packets containing multiple examples and unlabeled packets; wherein each example corresponds to a data packet, the positive packet is a data flow with at least one abnormal data packet, and the unlabeled packet is a data flow without any category label; a second module, configured to construct an automatic encoder model with a two-component loss function; wherein the two-component loss function includes a first component loss function and a second component loss function, the first component loss function is used to calculate the loss value of all unlabeled packets, and the second component loss function is used to calculate the loss value of all positive packets; a third module, configured to iteratively solve the minimum value of the two-component loss function through deep learning back-propagation training to obtain a data stream level classifier and a data packet level classifier; a fourth module, configured to use a data stream level classifier to distinguish abnormal data flows, and use a data packet level classifier to detect abnormal data packets.
[0011] Furthermore, the loss value of all unlabeled packages is calculated by the following formula: ; ,in ; in, represents the first component loss function, represents the packet-level reconstruction error in multi-instance learning, Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Indicates the number of all data streams. Represents the set of all data streams.
[0012] Furthermore, the loss value of all positive packets is calculated by the following formula: ; ; ; in, represents the second component loss function, represents a data stream level classifier, represents the packet level classifier, express The weight of Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Represents a collection of abnormal data flows, Represents a normal data flow set, Take the constant, and Represents the parameters to be learned by the autoencoder.
[0013] Further, the packet type, packet length, packet payload length and packet character statistics are taken as example features of each example.
[0014] Furthermore, the abnormal data flow set and the normal data flow set The number of data streams is the same.
[0015] The present invention provides a PU-MIL-based network abnormal traffic detection method and device, introduces an abnormal traffic detection technology that combines positive sample, unlabeled sample learning (PU learning) and multi-instance learning (MIL learning), proposes a new loss function of the autoencoder model, introduces Pratt scaling technology to reconstruct errors to adapt to the PU-MIL learning algorithm, and combines example-level reconstruction errors with packet-level labels to optimize the performance of the autoencoder model, so that in the case of only a small number of known abnormal samples and a large amount of unlabeled data, the abnormal traffic in the network can be efficiently and accurately identified, effectively improving the detection capability of a small number of abnormal events, and providing a more practical and effective solution for network security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings: Figure 1 is a flow chart of a method for detecting abnormal network traffic based on PU-MIL provided by an embodiment of the present application; Figure 2 It is a structural diagram of a network abnormal traffic detection device based on PU-MIL provided by an embodiment of the present application; Figure 3 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0017] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0018] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention are also intended to include plural forms, unless the context clearly indicates other meanings.
[0019] It should be understood that although the terms first, second, third, etc. may be used to describe the acquisition modules in the embodiments of the present invention, the acquisition modules should not be limited to these terms. These terms are only used to distinguish the acquisition modules from each other.
[0020] The word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.
[0021] It should be noted that the directional words such as "upper", "lower", "left", and "right" described in the embodiments of the present invention are described at the angles shown in the drawings and should not be understood as limiting the embodiments of the present invention. In addition, in the context, it should also be understood that when it is mentioned that an element is formed "on" or "under" another element, it can not only be formed directly "on" or "under" another element, but also be formed "on" or "under" another element indirectly through an intermediate element.
[0022] An embodiment of the present application provides a network abnormal traffic detection method based on PU-MIL (a combination of positive sample, unlabeled sample learning and multi-instance learning). The method adopts an autoencoder as the underlying anomaly detector and introduces a new loss function for PU-MIL learning. It can achieve effective learning in the case of only partial positive packets and unlabeled packets, solving the problem of traditional methods' dependence on fully labeled data.
[0023] In order to facilitate understanding of the technical solution of the present invention, some technical terms are explained below: Packet - In network communication, a data packet is the basic unit of TCP / IP protocol transmission. It improves the reliability and efficiency of the network by dividing the data into multiple small packets for transmission. Each data packet is transmitted independently and reassembled into the original data at the destination.
[0024] Data stream: A collection of data that is transmitted continuously from a source to a destination over a period of time. A data stream contains several data packets.
[0025] Bag - Bag and data packet are two completely different concepts. Bag is a special term in multi-instance learning, which means a collection of multiple sample examples. Bag has category labels, while sample examples do not have category labels. When a bag is labeled negatively, it means that all samples in the bag are labeled negatively; when a bag is labeled positively, it means that at least one sample in the bag is labeled positively.
[0026] The following is a detailed description of the network abnormal traffic detection method based on PU-MIL in this embodiment. Figure 1 , the method comprises the following steps: Step S101, divide the network data flow containing multiple data packets into positive packets containing multiple examples and unlabeled packets; wherein each example corresponds to a data packet, the positive packet is a data flow with at least one abnormal data packet, and the unlabeled packet is a data flow without any category label.
[0027] Specifically, the network traffic includes several data streams in different time periods, and each data stream contains multiple data packets. Abnormal data streams are usually less than normal data streams. Therefore, this embodiment regards abnormal data streams as positive bags in PU multi-instance learning. Unmarked packets in PU multi-instance learning contain both normal business data streams and unknown data streams that may contain malicious attacks. Data packets are regarded as examples of each packet in PU multi-instance learning. If there is an abnormal data packet (i.e., a positive example) in a data stream, the data stream is considered to be an abnormal data stream (i.e., a positive packet). Among them, the data packet type, packet length, payload length, character statistical features, etc. extracted from each data packet are used as example features of each example.
[0028] Step S102, constructing an autoencoder model with a two-component loss function; wherein the two-component loss function includes a first component loss function and a second component loss function, the first component loss function is used to calculate the loss values of all unlabeled packages, and the second component loss function is used to calculate the loss values of all positive packages.
[0029] This step designs a new loss function for the autoencoder model to achieve the effect of identifying both abnormal data flows and abnormal data packets.
[0030] Specifically, we train an autoencoder with a two-component loss function, which can be expressed as: Among them, the first component loss function It is used to calculate the loss value of all unlabeled packets, that is, to use unlabeled packets to simulate the distribution of the examples seen. In other words, it is to use unlabeled data streams (data streams to be judged) to learn the distribution characteristics of each data packet in each data stream. The second component loss function It is used to calculate the loss value of all positive packets, that is, to use positive packets (data flows marked as abnormal) to learn to distinguish positive packets from negative packets (that is, abnormal data flows and normal data flows).
[0031] Furthermore, the loss value of all unlabeled packages is calculated by the following formula: ; ,in ; in, represents the first component loss function, represents the packet-level reconstruction error in multi-instance learning, Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Indicates the number of all data streams. Represents the set of all data streams.
[0032] The above calculation process obtains the packet-level reconstruction error through the example-level reconstruction error, and then obtains the loss value of all unlabeled packets through the packet-level reconstruction error.
[0033] Furthermore, the loss value of all positive packets is calculated by the following formula: ; ; ; in, represents the second component loss function, represents a data stream level classifier, represents the packet level classifier, express The weight of Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Represents a collection of abnormal data flows, Represents a normal data flow set, Take a constant and preferably set it to 0.01, and Represents the parameters to be learned by the autoencoder.
[0034] The calculation process of the above loss value is firstly introduced by Platt scaling , the autoencoder's example anomaly score ranges from [0,+ ]Convert to probability value , in order to unify the proportion of different abnormal data streams; secondly, since only learning the information of abnormal data streams will cause the autoencoder model to overfit and cause imbalance problems, in this step, the abnormal data stream set is collected The same number of normal data flows constitutes a normal data flow set , thus converting the problem into a classification task with balanced classes; finally, the negative value of the log-likelihood of the abnormal data stream and the normal data stream is used as the loss function, and the parameter to alleviate overfitting.
[0035] After completing the calculation of the above two parts of the loss function, the two parts are added together to obtain the two-component loss function = , which is the network abnormal data flow detection model based on PU-MIL.
[0036] Step S103, through deep learning back propagation training, iteratively solve the minimum value of the two-component loss function to obtain a data stream level classifier and a data packet level classifier.
[0037] Specifically, the two-component loss function is iteratively solved through the back propagation training technique in deep learning The minimum value of can be used to obtain the data stream level classifier and packet-level classifiers .
[0038] Step S104, using a data stream level classifier to identify abnormal data streams, and using a data packet level classifier to detect abnormal data packets.
[0039] The network abnormal traffic detection method based on PU-MIL provided in this embodiment introduces an abnormal traffic detection technology that combines positive sample, unlabeled sample learning and multi-instance learning, proposes a new loss function of the autoencoder model, introduces Pratt scaling technology to reconstruct the error to adapt to the PU-MIL learning algorithm, and combines the example-level reconstruction error with the packet-level label to optimize the performance of the autoencoder model, so as to efficiently and accurately identify abnormal traffic in the network with only a small number of known abnormal samples and a large amount of unlabeled data, thereby effectively improving the detection capability of a small number of abnormal events.
[0040] See also Figure 2Another embodiment of the present invention further provides a PU-MIL-based network abnormal traffic detection device 200, including a first module 201, a second module 202, a third module 203 and a fourth module 204. The device 200 can execute the network abnormal traffic detection method in the method embodiment.
[0041] Specifically, the network abnormal traffic detection device 200 based on PU-MIL includes: The first module 201 is configured to divide a network data flow containing multiple data packets into positive packets containing multiple examples and unlabeled packets; wherein each example corresponds to a data packet, the positive packet is a data flow containing at least one abnormal data packet, and the unlabeled packet is a data flow without any category label; The second module 202 is configured to construct an autoencoder model with a two-component loss function; wherein the two-component loss function includes a first component loss function and a second component loss function, wherein the first component loss function is used to calculate the loss value of all unlabeled packages, and the second component loss function is used to calculate the loss value of all positive packages; The third module 203 is configured to iteratively solve the minimum value of the two-component loss function through deep learning back-propagation training to obtain a data stream level classifier and a data packet level classifier; The fourth module 204 is configured to use a data stream level classifier to identify abnormal data streams, and use a data packet level classifier to detect abnormal data packets.
[0042] Furthermore, the loss value of all unlabeled packages is calculated by the following formula: ; ,in ; in, represents the first component loss function, represents the packet-level reconstruction error in multi-instance learning, Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Indicates the number of all data streams. Represents the set of all data streams.
[0043] Furthermore, the loss value of all positive packets is calculated by the following formula: ; ; ; in, represents the second component loss function, represents a data stream level classifier, represents the packet level classifier, express The weight of Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Represents a collection of abnormal data flows, Represents a normal data flow set, Take the constant, and Represents the parameters to be learned by the autoencoder.
[0044] Further, the packet type, packet length, packet payload length and packet character statistics are taken as example features of each example.
[0045] Furthermore, the abnormal data flow set and the normal data flow set The number of data streams is the same.
[0046] It should be noted that the PU-MIL-based network abnormal traffic detection device 200 provided in this embodiment corresponds to a technical solution that can be used to execute various method embodiments, and its implementation principle and technical effects are similar to the method, which will not be repeated here.
[0047] See also Figure 3 Another embodiment of the present invention provides a schematic diagram of the structure of an electronic device 300, which is used to implement the PU-MIL-based network abnormal traffic detection method in the method embodiment. The electronic device 300 in the embodiment of the present invention may include but is not limited to a PC, a server, a smart phone, a tablet computer, and a PDA. Figure 3 The electronic device 300 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.
[0048] like Figure 3As shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 to a random access memory (RAM) 303 to implement the method of the embodiment of the present invention. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the ROM 302, and the RAM 303 are connected to each other via a bus 305. An input / output (I / O) interface 304 is also connected to the bus 305.
[0049] Typically, the following devices may be connected to the I / O interface 304: an input device 306 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead.
[0050] The above description is only a preferred embodiment of the present invention. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solution formed by a specific combination of the above technical features, but also should cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present invention (but not limited to) to form a technical solution.
Claims
1. A method for detecting abnormal network traffic based on PU-MIL, characterized in that: The steps include: Divide a network data flow containing multiple data packets into positive packets containing multiple examples and unlabeled packets; wherein each example corresponds to a data packet, the positive packet is a data flow with at least one abnormal data packet, and the unlabeled packet is a data flow without any category label; Constructing an autoencoder model with a two-component loss function; wherein the two-component loss function includes a first component loss function and a second component loss function, wherein the first component loss function is used to calculate the loss value of all unlabeled packages, and the second component loss function is used to calculate the loss value of all positive packages; Through deep learning back propagation training, the minimum value of the two-component loss function is iteratively solved to obtain a data stream level classifier and a data packet level classifier; A data stream level classifier is used to identify abnormal data streams, and a packet level classifier is used to detect abnormal packets.
2. According to the PU-MIL-based network abnormal traffic detection method of claim 1, it is characterized in that: The loss value of all unlabeled packages is calculated by the following formula: ; ,in ; in, represents the first component loss function, represents the packet-level reconstruction error in multi-instance learning, Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Indicates the number of all data streams. Represents the set of all data streams.
3. The method for detecting abnormal network traffic based on PU-MIL according to claim 2, characterized in that: The loss value of all positive packets is calculated by the following formula: ; ; ; in, represents the second component loss function, represents a data stream level classifier, represents the packet level classifier, express The weight of Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Represents a collection of abnormal data flows, Represents a normal data flow set, Take the constant, and Represents the parameters to be learned by the autoencoder.
4. The method for detecting abnormal network traffic based on PU-MIL according to claim 1, characterized in that: Packet type, packet length, packet payload length, and packet character statistics features are used as example features for each sample.
5. The method for detecting abnormal network traffic based on PU-MIL according to claim 3, characterized in that: The abnormal data flow set and the normal data flow set The number of data streams is the same.
6. A network abnormal traffic detection device based on PU-MIL, characterized in that: include: The first module is configured to divide a network data flow containing multiple data packets into positive packets containing multiple examples and unlabeled packets; wherein each example corresponds to a data packet, the positive packet is a data flow containing at least one abnormal data packet, and the unlabeled packet is a data flow without any category label; The second module is configured to construct an autoencoder model with a two-component loss function; wherein the two-component loss function includes a first component loss function and a second component loss function, the first component loss function is used to calculate the loss value of all unlabeled packages, and the second component loss function is used to calculate the loss value of all positive packages; The third module is configured to iteratively solve the minimum value of the two-component loss function through deep learning back-propagation training to obtain a data stream level classifier and a data packet level classifier; The fourth module is configured to use a data stream level classifier to identify abnormal data streams and use a data packet level classifier to detect abnormal data packets.
7. The network abnormal traffic detection device based on PU-MIL according to claim 6 is characterized in that: The loss value of all unlabeled packages is calculated by the following formula: ; ,in ; in, represents the first component loss function, represents the packet-level reconstruction error in multi-instance learning, Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Indicates the number of all data streams. Represents the set of all data streams.
8. The PU-MIL-based network abnormal traffic detection device according to claim 7, characterized in that: The loss value of all positive packets is calculated by the following formula: ; ; ; in, represents the second component loss function, represents a data stream level classifier, represents the packet level classifier, express The weight of Indicates that it contains Packets A data stream of represents the instance-level reconstruction error in multi-instance learning, Represents a collection of abnormal data flows, Represents a normal data flow set, Take the constant, and Represents the parameters to be learned by the autoencoder.
9. The PU-MIL-based network abnormal traffic detection device according to claim 6, characterized in that: Packet type, packet length, packet payload length, and packet character statistics features are used as example features for each sample.
10. The PU-MIL-based network abnormal traffic detection device according to claim 8, characterized in that: The abnormal data flow set and the normal data flow set The number of data streams is the same.
Citation Information
Patent Citations
Network traffic anomaly detection method based on small amount of annotation data
CN111585997A
Network anomaly detection method and device, electronic equipment and storage medium
CN113554094A
Weak supervision detection method and system for encrypting malicious traffic
CN114826776A
Autoencoder-based anomaly detection method, apparatus and device, and storage medium
WO2021139236A1