Wireless Communication Data Security Management Method and System
By splitting wireless communication data according to communication nodes and session cycles, feature transformation and event representation is performed, and timing characteristics are captured using deep learning models, the problem of security risk identification in wireless communication networks is solved, and the accurate identification and prediction of risk communication events is achieved, which improves the generalization ability and computing efficiency of the model.
Patent Information
- Application Number
- CN202411901032.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-12-23
AI Technical Summary
The prior art is difficult to effectively manage and analyze communication events in wireless communication networks and identify potential security risks. In the security management of wireless communication data, deep learning models face difficulties in feature extraction and timing dependency capture, model generalization capabilities and low computing efficiency.
By splitting wireless communication data into event sets according to communication nodes and session cycles, feature transformation and event representation are performed, and event representation information is used to mine networks and risk communication event detection networks, capture the timing characteristics and risks of communication events, and improve the generalization and prediction stability of the model.
It realizes accurate identification and prediction of risk communication events in wireless communication networks, improves the generalization ability and computing efficiency of the model, and ensures the effectiveness and reliability of security management.
Smart Images

Figure CN119996999B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and in particular, to a method and system for wireless communication data security management. Background Art
[0002] With the rapid development and wide application of wireless communication technologies, wireless communication networks have become an indispensable part of modern society. However, the security issues of wireless communication data have become increasingly prominent and have become one of the key factors restricting its further development. In wireless communication networks, data is frequently exchanged between communication nodes. These communication events are not only large in number but also diverse in type, containing rich temporal characteristics and event attributes. How to effectively manage and analyze these communication events and timely identify and prevent potential security risks has become an urgent problem to be solved in the field of wireless communication data security management.
[0003] In recent years, the rise of machine learning, especially deep learning technologies, has provided new ideas and methods for wireless communication data security management. Deep learning models have powerful feature extraction and pattern recognition capabilities and can learn useful knowledge and rules from a large amount of complex data. However, applying deep learning technologies to the field of wireless communication data security management still faces many challenges. For example, how to effectively represent communication events to capture their key features and temporal dependencies; how to build a suitable deep learning model to achieve accurate identification and prediction of risk communication events; how to improve the generalization ability and computational efficiency of the model while ensuring its performance, etc. Summary of the Invention
[0004] In view of this, this application provides a method and system for wireless communication data security management.
[0005] The technical solution of this application is implemented as follows:
[0006] On the one hand, the present application provides a method for wireless communication data security management. The method includes: splitting the wireless communication data source information according to communication nodes and communication session periods to obtain one or more communication event sets, where each communication event set includes a set number of communication events triggered by the same communication node in one communication session period. For each communication event set, the following steps are respectively performed: for each communication event covered by the communication event set, feature transformation is respectively performed according to the corresponding event feature to obtain a transformed feature set; through a pre-tuned event characterization information mining network, the event characterization vectors of each set data unit covered by the transformed feature set are respectively mined, where each event characterization vector is obtained based on the vectorized feature after transformation of the corresponding set data unit and the event characterization vector of its previous set data unit; the obtained event characterization vectors are integrated into a set integrated characterization vector and loaded into a pre-tuned risk communication event detection network to obtain an event risk identification result, and the event risk identification result is used to indicate the confidence level of the corresponding communication node having a risk communication event in the corresponding communication session period.
[0007] On the other hand, the present application provides a computer system, including a memory and a processor. The memory stores a computer program that can run on the processor, and when the processor executes the program, the steps in any one of the above methods are implemented.
[0008] In the embodiments of the present application, the communication events of each communication node are decomposed into one or more communication event sets according to the communication session period. The communication events of the same communication node can be classified into the communication event sets corresponding to one or more periods. Based on this, these communication events are characterized by event features to obtain a transformed feature set covering temporal features and event attributes. The present application maps through various event features, and communication events with different features correspond to different mapping values, ensuring that the network can learn the features of different communication events during the process of processing diverse communication events, and increasing the generalization of the network.
[0009] Then, in combination with the temporal relationship, the event characterization vectors corresponding to each set data unit in the transformed feature set are mined, and each obtained event characterization vector integrates the association information of the previous communication event, enabling more accurate learning of the event change features. Based on this, the event characterization vectors are integrated into a set integrated characterization vector to predict risk communication events, complete accurate learning of the communication event features, improve the prediction stability and generalization, and accurately identify risk communication events.
[0010] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the technical solution of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The accompanying drawings here are incorporated into the specification and form a part of this specification. These drawings illustrate embodiments consistent with the present application and, together with the specification, are used to explain the technical solutions of the present application.
[0012] Figure 1 It is a schematic diagram of the implementation process of a wireless communication data security management method provided by an embodiment of the present application.
[0013] Figure 2 It is a schematic diagram of the hardware entity of a computer system provided by an embodiment of the present application. Detailed implementation manners
[0014] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.
[0015] An embodiment of the present application provides a wireless communication data security management method, which can be executed by a processor of a computer system. Among them, the computer system may refer to devices with data processing capabilities such as servers, laptops, tablets, desktop computers, mobile devices, etc.
[0016] Figure 1 It is a schematic diagram of the implementation process of a wireless communication data security management method provided by an embodiment of the present application, as Figure 1 shown, the method includes:
[0017] Step S100: Split the wireless communication data source information according to communication nodes and communication session cycles to obtain one or more communication event sets, and each communication event set includes a set number of communication events triggered by the same communication node in one communication session cycle.
[0018] In a wireless communication environment, the data source information contains a large number of communication events, which are triggered by different communication nodes at different time points and involve various types of data transmission and interaction. To effectively manage this data and identify potential security risks, the computer system first preprocesses this raw data.
[0019] Specifically, the computer system identifies and extracts all communication events from the wireless communication data source. These events may include the sending and receiving of data packets, login attempts, file transfers, voice calls, etc. Each communication event contains a series of attributes or characteristics, such as event type, occurrence time, transmission volume, source address, destination address, protocol type, port number, etc. These characteristics jointly describe all aspects of the communication event, providing a basis for subsequent analysis and processing. Next, the computer system groups these events according to communication nodes. In a wireless communication network, each communication node (such as a mobile phone, base station, server, etc.) is an independent entity that can initiate or receive communication events. Therefore, grouping events with the same communication node identifier together helps the computer system better understand the behavior patterns and data flow of each node. After the grouping is completed, the computer system further splits the events according to the communication session cycle. The communication session cycle refers to a period of continuous interaction between communication nodes, which reflects the communication frequency and duration between nodes. In practical applications, the communication session cycle can be defined according to specific requirements, such as in hours, days, or weeks. The computer system assigns each communication event to the corresponding communication session cycle by identifying its timestamp.
[0020] During the splitting process, the computer system generates one or more sets of communication events. Each set of communication events contains a set number of communication events triggered by the same communication node within a specific communication session cycle. Here, the "set number" is an adjustable parameter that determines the number of events contained in each set. The selection of the set number takes into account multiple factors, such as the efficiency of data processing, the complexity of the model, and the accuracy of risk identification. Generally speaking, the set number should not be too large or too small: too large a set number may result in an overly large set, increasing the difficulty of subsequent processing; while too small a set number may not be able to fully capture the behavior characteristics of the communication node, affecting the effect of risk identification.
[0021] For example, suppose there is a wireless communication network that contains three communication nodes A, B, and C. During a day, multiple communication events occur between these nodes. The computer system first extracts all the attributes of these events, including event type, occurrence time, transmission volume, source address, destination address, etc. Then, according to the communication nodes, these events are divided into three groups, corresponding to the events of nodes A, B, and C respectively.
[0022] Next, the computer system defines the communication session period in hours and assigns the events of each node to the corresponding periods. For example, Node A triggered 5 communication events between 8 am and 9 am, and these events were assigned to a set of communication events; similarly, Node B triggered 7 events between 2 pm and 3 pm and was also assigned to a set. For Node C, if it did not trigger any events within a certain hour, no corresponding set of communication events would be generated during that period.
[0023] Suppose the set number is 5, that is, each set of communication events can contain at most 5 events. In the above example, the 5 events of Node A between 8 am and 9 am exactly form a complete set; while the 7 events of Node B between 2 pm and 3 pm are split into two sets: the first set contains the first 5 events, and the second set contains the remaining 2 events.
[0024] Through these steps, the computer system has successfully split the wireless communication data source information into multiple sets of communication events. Each set contains the communication events of the same communication node in a specific communication session period, and the number of events conforms to the limit of the set number. These sets will then be used in subsequent steps such as feature extraction, event representation, and risk identification, providing strong support for the security management of wireless communication data.
[0025] For each set of communication events, the following steps are performed respectively:
[0026] Step S200: For each communication event covered by the set of communication events, perform feature transformation according to the corresponding event features respectively to obtain a set of transformed features.
[0027] In a wireless communication environment, each communication event contains a series of attributes or features that describe various aspects of the event, such as event type, occurrence time, transmission volume, source address, destination address, protocol type, port number, etc. Although these features are rich and diverse, when directly used for processing by a machine learning model, some problems may be faced, such as high feature dimensionality, uneven distribution of feature values, correlation between features, etc. Therefore, in step S200, the computer system transforms these original features to generate a set of transformed features that are more suitable for model processing. Specifically, the computer system traverses each communication event set and extracts each communication event and its corresponding event features. These event features may exist in various forms, such as strings, numbers, timestamps, etc. For unified processing, the computer system may convert these features into a unified data type or format. For example, it may convert the timestamp into a time difference relative to a certain reference time and encode the string as a numerical identifier. Next, the computer system selects an appropriate feature transformation method for encoding according to the type and meaning of the event features. The selection of the feature transformation method depends on the specific application scenario and model requirements. Common transformation methods include numerical encoding, one-hot encoding, normalization, standardization, etc. Taking numerical encoding as an example, assume there is a communication event set that contains a login attempt event. The event features of this event include event type (login attempt), occurrence time (2023-04-01 10:00), transmission volume (1KB), source address (IP1), destination address (server IP), protocol type (TCP), port number (80). For the event type feature, the computer system can encode it as a numerical identifier. For example, it can encode "login attempt" as 1, and other event types as different numerical values. For the occurrence time feature, the computer system can convert it into the number of seconds since a certain reference time (such as January 1, 1970) to obtain a numerical timestamp. For the transmission volume feature, since it is already numerical data, it can be directly used or normalized. For the source address and destination address features, since they are strings in the form of IP addresses, the computer system can encode them as numerical identifiers. For example, it can use a hash function to map the IP address to a unique numerical value. For the protocol type and port number features, since their value ranges are limited and relatively fixed, the one-hot encoding method can be used to convert them into binary vectors.
[0028] After the above feature transformation, the computer system converts the event features of each communication event into a set of transformed features. This set contains a series of numerical or vector data corresponding to the original event features, and these data are more suitable for the processing and analysis of machine learning models.
[0029] Taking the application of a machine learning model as an example, assume that after step S200, the computer system inputs the generated set of transformed features into an event representation information mining network. This network may be a deep neural network that extracts high-level representations of events by learning the complex relationships between the transformed features. During this process, each layer in the network performs non-linear transformations and feature extractions on the input data to generate more expressive and discriminative feature representations. If the feature transformation process in step S200 can fully capture the important information in the original event features and remove redundancy and noise, then this will help the network better learn and understand the data, thereby improving the accuracy and effectiveness of event representation.
[0030] Furthermore, if the output of the event representation information mining network is used as the input to a risk communication event detection network, then the feature transformation process in step S200 will also have an important impact on the final risk identification result. The risk communication event detection network may be a classifier or a regressor that determines whether there is a security risk in a communication event based on the event representation. If the set of transformed features can accurately reflect the essential features and potential risks of the communication event, then this will help the network make more accurate judgments and predictions.
[0031] Step S300: Through the pre-debugged event representation information mining network, respectively mine the event representation vectors of each set data unit covered by the set of transformed features, where each event representation vector is obtained based on the vectorized features after transformation of the corresponding set data unit and the event representation vector of its previous set data unit.
[0032] In step S300, through the pre-debugged event representation information mining network, each set data unit in the set of transformed features is deeply mined to generate its respective event representation vector. This step is an important link connecting feature transformation and risk identification. It uses deep learning techniques, especially the characteristics of recurrent neural networks (such as long short-term memory networks LSTM), to capture the temporal dependence relationships and potential patterns between communication events, thereby providing strong support for subsequent risk communication event detection.
[0033] Before step S300, the computer system has completed the splitting (step S100) and feature transformation (step S200) of the wireless communication data source information, obtaining one or more communication event sets. Each set contains a set number of communication events triggered by the same communication node during a communication session period, and each event has been converted into a set data unit in the set of transformed features. These set data units contain the encoded and transformed event features, providing input data for the event representation information mining network.
[0034] The event representation information mining network is a pre-trained deep learning model that may contain multiple levels of neural network structures, among which the most important is the recurrent neural network layer. Recurrent neural networks are particularly suitable for processing sequential data because they can capture the temporal dependencies between elements in a sequence. In step S300, the computer system will utilize this feature to sequentially process each set data unit in the transformed feature set to generate corresponding event representation vectors.
[0035] Specifically, for the first set data unit in the transformed feature set, the computer system inputs it into the event representation information mining network. The network first converts the set data unit into vectorized features through a vectorization module (which may be a fully connected layer or an embedding layer). Then, these vectorized features are fed into the recurrent neural network layer (such as an LSTM layer) for processing. Since this is the first element in the sequence and there is no previous event representation vector for reference, the recurrent neural network layer may use an initial state vector or a zero vector as input. During the processing, the network learns how to map the vectorized features of the set data unit to a point in a high-dimensional space, and this point is the event representation vector of the set data unit.
[0036] For subsequent set data units in the transformed feature set, the computer system adopts a similar processing flow, but there is a key difference: when processing each set data unit, the network not only considers its own vectorized features but also the event representation vector of the previous set data unit. This is achieved through the internal state mechanism of the recurrent neural network layer. In an LSTM, each cell has an internal state vector that stores all the input information up to the current moment. When processing new input (i.e., the vectorized features of the next set data unit), the LSTM cell combines the current input and the internal state vector to update its internal state and generate a new output vector (i.e., the event representation vector of the current set data unit). In this way, each event representation vector contains the feature information of its corresponding set data unit and the historical information of all previous set data units, thus achieving the capture of the temporal dependencies of communication events.
[0037] For example, suppose there is a communication event set that contains three set data units corresponding to three consecutive communication events. Each set data unit has undergone feature transformation to obtain a vectorized representation containing features such as event type, occurrence time, transmission volume, etc. The computer system sequentially inputs these vectorized representations into the event representation information mining network.
[0038] For the first set of data units, the network converts it into a vectorized feature through a vectorization module and processes it through an LSTM layer to obtain an initial event representation vector. This vector may contain some information about the first event itself, but since there is no information about the previous event for reference, it may be relatively isolated.
[0039] For the second set of data units, the network also converts it into a vectorized feature first. However, this time when processing, the LSTM layer will consider the first event representation vector as part of the input. This means that when the LSTM unit updates its internal state and generates a new event representation vector, it will comprehensively consider the current features of the second event and the historical information of the first event. Therefore, the second event representation vector not only contains information about the second event itself but also implicitly contains the influence of the first event on the second event.
[0040] Similarly, for the third set of data units, the network will consider the previous two event representation vectors as part of the input when processing. In this way, the third event representation vector will contain information about the third event itself and the cumulative influence of the previous two events on it.
[0041] In this way, the computer system can generate an event representation vector containing rich temporal information and potential patterns for each set of data units in the transformed feature set. These vectors can then be used as the input of the risk communication event detection network for further risk identification and prediction.
[0042] It can be understood that although LSTM is used as the implementation method of the recurrent neural network layer in the above example, in fact, there are other types of recurrent neural networks (such as GRU) or more advanced sequence processing models (such as Transformer) that can also be used to construct the event representation information mining network. The choice of which model depends on factors such as specific application scenarios, data characteristics, and computing resources. Regardless of which model is adopted, the core goal of step S300 is to generate high-quality event representation vectors by deeply mining the temporal dependencies and potential patterns of communication events, thereby providing a solid foundation for subsequent risk identification.
[0043] Step S400: Integrate the obtained event representation vectors into a set integration representation vector and load it into the pre-debugged risk communication event detection network to obtain an event risk identification result, which is used to indicate the confidence level of the corresponding communication node having a risk communication event in the corresponding communication session cycle.
[0044] Before step S400, the computer system has completed the splitting of wireless communication data source information (step S100), feature transformation (step S200), and generation of event representation vectors (step S300). These steps together provide the necessary input data for step S400, namely, multiple event representation vectors corresponding to each communication event set. These vectors capture the key features and temporal dependencies of communication events and are the basis for subsequent risk identification.
[0045] In step S400, the computer system integrates these event representation vectors into a set integration representation vector. This integration process may involve various techniques, such as average pooling, max pooling, attention mechanism, etc. The specific choice depends on the application scenario and model design. The purpose of integration is to extract useful information from multiple event representation vectors and fuse them into a high-dimensional vector that can represent the entire communication event set. This vector should be able to retain the key features of each event in the set while reflecting the temporal relationship and potential pattern between them.
[0046] Taking average pooling as an example, the computer system can simply take the average value of all event representation vectors in the corresponding dimension to obtain a set integration representation vector. This method is simple and easy to implement, but it may not fully utilize the temporal information and potential associations between event representation vectors. Therefore, in practical applications, more complex integration methods are often adopted.
[0047] Another integration method is to use the attention mechanism. The computer system can construct an attention layer that receives all event representation vectors as input and outputs a weighted set integration representation vector. Each element of this vector is the result of weighted summation of the original event representation vectors, and the weights are dynamically calculated by the attention mechanism according to the importance and relevance of the events. Regardless of which integration method is adopted, the computer system will ultimately obtain a set integration representation vector. This vector is then loaded into a pre-debugged risk communication event detection network. The risk communication event detection network is a specially trained deep learning model that can extract information related to the security risk of communication events from the set integration representation vector and output an event risk identification result. This result is a probability value or confidence score, which is used to indicate the possibility that the corresponding communication node has a risk communication event in the corresponding communication session period.
[0048] The specific implementation of the risk communication event detection network may vary depending on the application scenario, but it includes a neural network structure with multiple layers, such as convolutional layers, fully connected layers, Transformer layers, etc. These layers extract high-level features and make predictions by combining and transforming the input data. During the training process, the network learns how to map the set integration representation vectors to the risk identification results and continuously optimizes its internal parameters through the backpropagation algorithm to improve the prediction accuracy.
[0049] For example, assume there is a communication event set that contains five communication events, corresponding to five event representation vectors respectively. These vectors have been generated through step S300 and capture the key features and temporal dependencies of each event. The computer system integrates these vectors into a set integration representation vector.
[0050] In this example, the computer system uses the attention mechanism for integration. It first constructs an attention layer, which receives the five event representation vectors as input and calculates the attention weights corresponding to each vector. These weights reflect the importance and relevance of the vectors in the set. Then, the system performs a weighted sum of the event representation vectors according to these weights to obtain a weighted set integration representation vector.
[0051] Next, the computer system inputs this vector into the risk communication event detection network. Through multiple levels of transformation and calculation, the network finally outputs an event risk identification result, such as a probability value between 0 and 1. This value represents the confidence level of the corresponding communication node having a risk communication event during the corresponding communication session period. If the probability value is high (such as close to 1), it indicates a high security risk; if the probability value is low (such as close to 0), it indicates a low security risk.
[0052] As an implementation manner, in step S200, for each communication event covered by the communication event set, feature transformation is respectively performed according to the corresponding event features to obtain a transformed feature set, including:
[0053] Step S210: For each communication event covered by the communication event set, based on the event features of the communication event, the communication event is converted into an event identifier in a preset event identifier set, where the event identifiers corresponding to communication events with different features are different;
[0054] Step S220: The set composed of the obtained event identifiers is used as the transformed feature set, where each event identifier is a set data unit in the transformed feature set.
[0055] In step S210, the computer system traverses each communication event in the communication event set and converts it into an event identifier in a preset event identifier set according to its event characteristics (such as event type, occurrence time, transmission volume, source address, destination address, protocol type, port number, etc.). This conversion process is based on the uniqueness and distinctiveness of the event characteristics to ensure that communication events with different characteristics correspond to different event identifiers.
[0056] For example, suppose there is a communication event set that contains three communication events, namely:
[0057] 1. An HTTP request event that occurred at 10:00 am on April 1, 2023, with a transmission volume of 1 KB, a source address of IP1, a destination address of the server IP, a protocol type of TCP, and a port number of 80.
[0058] 2. An FTP upload event that occurred at 10:15 am on April 1, 2023, with a transmission volume of 5 MB, a source address of IP2, a destination address of the server IP, a protocol type of FTP, and a port number of 21.
[0059] 3. An SSH login attempt event that occurred at 10:30 am on April 1, 2023, with a transmission volume of 0 KB (because the login attempt does not transmit data), a source address of IP3, a destination address of the server IP, a protocol type of SSH, and a port number of 22.
[0060] The computer system converts these communication events into event identifiers. Suppose the preset event identifier set is defined according to the event type and some key characteristics (such as protocol type, port number), then the conversion process is as follows:
[0061] 1. For the first HTTP request event, since its event type is HTTP, protocol type is TCP, and port number is 80, it may be converted into the event identifier "HTTP_TCP_80".
[0062] 2. For the second FTP upload event, since its event type is FTP, protocol type is FTP, and port number is 21, it may be converted into the event identifier "FTP_FTP_21".
[0063] 3. For the third SSH login attempt event, since its event type is SSH, protocol type is SSH, and port number is 22, it may be converted into the event identifier "SSH_SSH_22".
[0064] In practical applications, the generation of event identifiers may be more complex and may involve more feature combinations and coding rules. In addition, the set of event identifiers may also be customized according to specific application scenarios and data characteristics to ensure that the key information and distinctiveness of communication events can be fully expressed.
[0065] In step S220, the computer system collects all the event identifiers generated in step S210 to form a set, that is, the transformation feature set. Each element in this set is an event identifier corresponding to a communication event in the communication event set. The transformation feature set provides structured input data for subsequent event characterization and risk identification.
[0066] Continuing with the above example, assume that three communication events have been converted into event identifiers "HTTP_TCP_80", "FTP_FTP_21", and "SSH_SSH_22". The computer system combines these event identifiers into a transformation feature set, that is, {"HTTP_TCP_80", "FTP_FTP_21", "SSH_SSH_22"}. This set is the output result of step S220 and will be used as the input data for subsequent steps.
[0067] The event identifiers in the transformation feature set not only represent the key features of communication events but also imply the temporal relationship and potential patterns between them. This is because the generation of event identifiers is based on the timestamps and event features of communication events, so they naturally retain the time order and feature information of the original events. This provides rich context information for subsequent event characterization and risk identification. In addition, the construction process of the transformation feature set does not involve complex calculations or the training of machine learning models. It more relies on the understanding of data structures and the design of processing logics. However, the output result of this step is crucial for the input and training of machine learning models in subsequent steps. Therefore, when executing step S220, the computer system ensures the accuracy and integrity of the data, avoiding introducing any errors or omissions to ensure the effectiveness and reliability of the entire security management method.
[0068] As an implementation, the event characterization information mining network includes a vectorization module and a long short-term memory network module. The number of network layers of the long short-term memory network module is equal to the number of features in the transformation feature set, and each long short-term memory network layer corresponds to a set data unit in the transformation feature set.
[0069] Step S300, through the pre-debugged event characterization information mining network, respectively mines the event characterization vectors of each set data unit covered by the transformation feature set, including:
[0070] For each set data unit in the transformed feature set, the following steps are performed separately:
[0071] Step S310: Through the vectorization module, perform vectorization conversion on the set data unit to obtain the vectorized features of the set data unit;
[0072] Step S320: Through the corresponding long short-term memory network layer, after integrating the vectorized features of the set data unit and the event representation vector of its previous set data unit, mine the event representation vector of the set data unit.
[0073] The event representation information mining network is mainly composed of two modules: the vectorization module and the long short-term memory network module. These two modules work together to jointly complete the mining of the event representation vector of each set data unit in the transformed feature set.
[0074] The main function of the vectorization module is to convert the set data unit (i.e., each element in the transformed feature set) into vectorized features. Vectorization refers to converting discrete data (such as text, class labels, etc.) into continuous numerical vectors for mathematical operations and model training. In the vectorization module, techniques such as the Embedding Layer or the Fully Connected Layer may be used to achieve vectorization conversion. Through the processing of the vectorization module, each set data unit is converted into a vector of a fixed length, and this vector contains the key feature information of the data unit.
[0075] The long short-term memory network module is a variant of the recurrent neural network (RNN). In wireless communication data security management, communication events occur in chronological order, forming a natural sequence. The long short-term memory network can capture the long-term dependencies in the sequence, that is, the mutual influence between events that are far apart. The number of network layers of this module is equal to the number of features in the transformed feature set (or the number of set data units), and each network layer corresponds to a set data unit. Through layer-by-layer processing, the long short-term memory network can gradually accumulate and transmit the information in the sequence, and finally generate the event representation vector of each set data unit.
[0076] In step S310, the computer system inputs each set data unit in the transformed feature set into the vectorization module for vectorization conversion. Suppose the first set data unit in the transformed feature set is an event identifier "HTTP_TCP_80" representing an HTTP request event. The vectorization module will look up the corresponding vectorized representation in the pre-trained embedding table or fully connected layer according to this event identifier. This vectorized representation may be a vector containing multiple numerical values, and each numerical value corresponds to the embedding of a character or substring in the event identifier. Through this process, the event identifier "HTTP_TCP_80" is converted into a fixed-length vectorized feature, such as [0.1, 0.3, -0.2, ..., 0.4].
[0077] Similarly, other set data units in the transformed feature set will also undergo vectorization conversion to obtain their respective vectorized features. These feature vectors are then input into the long short-term memory network module for further processing.
[0078] In step S320, the computer system inputs the vectorized features generated in step S310 into the corresponding long short-term memory network layer for processing. Each long short-term memory network layer corresponds to a set data unit in the transformed feature set, so the processing process is carried out step by step in the order of the set data units.
[0079] Taking the first set data unit as an example, its vectorized feature is input into the first long short-term memory network layer. Since this is the first element in the sequence and there is no previous event representation vector for reference, the network layer may use an initial state vector or a zero vector as part of the input. During the processing, the long short-term memory network layer combines the current input (i.e., the vectorized feature) and the internal state (which may contain information processed previously) to update its internal state and generate a new output vector (i.e., the event representation vector of the current set data unit). This vector not only contains the feature information of the current set data unit but also implicitly contains the influence of previous events in the sequence.
[0080] For subsequent set data units in the sequence, the processing process of the long short-term memory network layer is similar, but there is a key difference: when processing each set data unit, the network layer will consider both its own vectorized feature and the event representation vector of the previous set data unit. This is achieved through the internal mechanism of the long short-term memory network, which allows the network layer to consider previous information when updating the internal state and generating the output vector. In this way, each event representation vector contains the feature information of its corresponding set data unit and the historical information of all previous set data units, thus realizing the capture of the temporal dependence relationship of communication events.
[0081] As an implementation manner, in step S320, after integrating the vectorized features of the set data unit and the event representation vector of its previous set data unit through the corresponding long short-term memory network layer, mining the event representation vector of the set data unit includes:
[0082] Step S321: Load the vectorized features of the set data unit and the event representation vector of its previous set data unit into the long short-term memory network layer corresponding to the set data unit respectively;
[0083] Step S322: Sum the corresponding units in the vectorized features and the event representation vector bit by bit to obtain the feature integration result;
[0084] Step S323: Extract features from the feature integration result through the long short-term memory network layer to obtain the event representation vector of the set data unit.
[0085] In step S321, the computer system loads the vectorized features of the current set data unit (denoted as ) and the event representation vector of its previous set data unit (denoted as ) into the corresponding long short-term memory network layer respectively. The long short-term memory network layer here is part of the event representation information mining network, and it is specifically responsible for processing the current set data unit and its historical information.
[0086] The vectorized features are the output results of step S310. It is a vector with a fixed length and contains the key feature information of the current set data unit. The event representation vector is the event representation result of the previously processed set data unit. It is also a vector, but contains the historical information of all previous set data units. By loading these two vectors into the long short-term memory network layer, the system is ready for subsequent integration and feature extraction.
[0087] It should be noted that when the long short-term memory network layer processes the input, it will combine its internal state (denoted as ) and the gating mechanism (including the forget gate, input gate, and output gate) to update its internal state and generate the output. However, in step S321, the focus is mainly on the loading process of the input vector, and the update of the gating mechanism and internal state will be introduced in detail in the subsequent steps.
[0088] Step S322 integrates the vectorized features and the event representation vector together by bit-by-bit summation to obtain the feature integration result (denoted as ). This process realizes the fusion of the features of the current set data unit and the historical information, providing rich context information for subsequent feature extraction.
[0089] Element-wise summation is a vector operation that adds the elements at corresponding positions in two vectors. Suppose the vectorized feature and the event representation vector are both vectors of length n. Then the calculation formula for element-wise summation can be expressed as:
[0090] ;
[0091] where respectively represent the elements at the i-th position in the vectors .
[0092] The advantage of element-wise summation is that it retains the information of each element in the vector and achieves feature fusion by addition. This fusion method is both simple and effective, and can capture the potential correlation between the vectorized feature and the event representation vector. However, element-wise summation may also introduce some noise or redundant information because not all elements at each position contribute significantly to the final event representation vector. To solve this problem, the long short-term memory network layer will further screen and refine the useful information in the subsequent feature extraction process.
[0093] In step S323, the computer system performs feature extraction on the feature integration result through the long short-term memory network layer, and finally obtains the event representation vector of the current set data unit (denoted as ). This process realizes the high-level abstraction and representation of the integrated features, providing strong support for subsequent risk identification.
[0094] When performing feature extraction, the long short-term memory network layer will generate an output vector by combining its internal state, gating mechanism, and activation function. Specifically, it will first determine which historical information is retained and which is forgotten through the forget gate; then determine which new information is added to the internal state through the input gate; and finally generate the output vector (i.e., the event representation vector) at the current moment through the output gate and activation function.
[0095] Suppose the internal state update formula of the long short-term memory network layer is:
[0096] ;
[0097] where are the outputs of the forget gate and the input gate respectively, represents element-wise multiplication, are the learnable weight and bias parameters, and tanh is the activation function.
[0098] The formula for generating the output vector is: ;
[0099] Among them, o t is the output of the output gate.
[0100] Through the above formula, the long short-term memory network layer can capture the feature information of the current set of data units and the historical information of all previous sets of data units, and fuse this information into a high-dimensional vector . This vector not only contains rich feature information but also reflects the temporal dependence relationship and potential patterns between communication events. Therefore, it can be used as an effective input for subsequent risk identification steps to help the computer system more accurately identify and evaluate the security risks of communication events.
[0101] In summary, through the collaborative work of sub-steps S321, S322, and S323, step S320 integrates the vectorized features of the set of data units with the event representation vector of its previous set of data units and extracts the event representation vector of the current set of data units. This process not only captures the key feature information of communication events but also reflects the temporal dependence relationship and potential patterns between them, providing strong support for subsequent risk identification.
[0102] As an implementation, in step S310, through a vectorization module, the set of data units is vectorized and transformed to obtain the vectorized features of the set of data units, including:
[0103] Step S311: For each set of data units, according to the vectorized feature mapping relationship obtained from the pre-debugging of the vectorization module, the set of data units is transformed into a vectorized feature, and the vectorized feature mapping relationship contains the vectorized features corresponding to each set of data units.
[0104] In sub-step S311, the computer system traverses each set of data units in the transformed feature set and, according to the pre-debugged vectorized feature mapping relationship, transforms it into a vectorized feature with a fixed length. This mapping relationship is obtained in the pre-debugging (i.e., pre-training) stage of the vectorization module, which establishes a mapping from the set of data units to the vectorized features.
[0105] The vectorized feature mapping relationship can be a table or other data structure that contains the vectorized features corresponding to each set of data units. These vectorized features are obtained through training and optimization, which can maximize the retention of the key information of the set of data units and facilitate the processing of subsequent machine learning models. In the vectorized feature mapping relationship, each set of data units has a unique identifier (such as an event identifier or index), and the corresponding is a vector with a fixed length, which contains the vectorized features of the set of data units.
[0106] For example, assume there is a set of transformation features that contains three set data units, namely: "HTTP_TCP_80", "FTP_FTP_21", and "SSH_SSH_22". These set data units are generated through steps S210 and S220 and represent different types of communication events.
[0107] In the pre-debugging stage of the vectorization module, a vectorization feature mapping relationship has been trained. This mapping relationship is a table that contains the vectorization features corresponding to each set data unit. For example, the content of the table may be as follows:
[0108] Aggregate data unit Vectorized feature HTTP_TCP_80 [0.1, 0.3, -0.2, 0.4, ...] FTP_FTP_21 [-0.1, 0.2, 0.5, -0.3, ...] SSH_SSH_22 [0.2, -0.1, 0.3, 0.1, ...]
[0109] Table 1 Vectorization Feature Mapping Relationship Table
[0110] In this Table 1, each set data unit corresponds to a vector of a fixed length (for example, a vector of length 5). Each element of the vector is a numerical value representing the value of the set data unit in a certain feature dimension. These numerical values are obtained through the training process of the vectorization module and can reflect the key features and attributes of the set data unit.
[0111] Enter the execution stage of sub-step S311. The computer system traverses each set data unit in the set of transformation features and converts it into the corresponding vectorization feature according to the vectorization feature mapping relationship table. For example, for the set data unit "HTTP_TCP_80", the computer system looks up its corresponding vectorization feature in the table and obtains the vector [0.1, 0.3, -0.2, 0.4,...]. Similarly, for the set data units "FTP_FTP_21" and "SSH_SSH_22", the computer system will also obtain their corresponding vectorization feature vectors [-0.1, 0.2, 0.5, -0.3,...] and [0.2, -0.1, 0.3, 0.1,...] respectively.
[0112] In this way, sub-step S311 successfully converts each set data unit in the set of transformation features into vectorization features. These vectorization features not only retain the key information of the set data unit but also facilitate the processing and analysis of subsequent machine learning models. In the event representation information mining network, these vectorization features will be used as the input of the long short-term memory network layer and further used to mine the event representation vector and risk identification result.
[0113] As an implementation, the risk communication event detection network includes a Transformer module and a dense connection module; in step S400, the obtained event representation vectors are integrated into a set integrated representation vector and loaded into the pre-debugged risk communication event detection network to obtain an event risk recognition result, including:
[0114] Step S410: Integrate the obtained event representation vectors into a set integrated representation vector;
[0115] Step S420: Perform weighted focus integration processing on the set integrated representation vector through the Transformer module to obtain a weighted focus integration vector;
[0116] Step S430: Perform projection prediction on the weighted focus integration vector through the dense connection module to obtain an event risk recognition result.
[0117] In step S410, the computer system integrates the event representation vectors generated in step S300 into a set integrated representation vector. This integration process is a process of combining multiple event representation vectors into a single vector, which aims to retain the key information in the original event representation vectors and provide structured input data for subsequent risk recognition.
[0118] Suppose there are three event representation vectors, denoted as , which represent the event representations of three consecutive communication events respectively. These vectors may have the same dimension, for example, each vector is a column vector of length n. In step S410, the computer system can adopt various methods to integrate these vectors, such as average pooling, max pooling, concatenation, etc. However, here it is assumed to adopt a more general method, that is, to perform linear transformation and integration through a learnable weight matrix W and a bias vector b:
[0119] ;
[0120] ;
[0121] where H is a matrix whose column vectors are the original event representation vectors; W is a learnable weight matrix with a dimension of (m×3n), where m is the dimension of the integrated vector; b is a bias vector with a dimension of m; z is the integrated set integrated representation vector with a dimension of m.
[0122] Through this method, the computer system can integrate multiple event representation vectors into a set integrated representation vector, which contains the key information in the original event representation vectors and provides structured input for subsequent risk recognition.
[0123] In step S420, the computer system inputs the set integration representation vector generated in step S410 into the Transformer module for weighted focus integration processing. This processing aims to assign different weights to different parts of the set integration representation vector through techniques such as the attention mechanism, so as to highlight important information and suppress noise.
[0124] The Transformer module is a deep learning model based on the self-attention mechanism, which can capture long-range dependencies in the input data without relying on the sequence order. In step S420, the Transformer module will first perform self-attention processing on the set integration representation vector to generate a series of attention weights, and then perform weighted summation on different parts of the vector according to these weights to obtain the weighted focus integration vector.
[0125] Specifically, assuming that the set integration representation vector is z, the Transformer module inputs it into a multi-head attention layer. This layer will calculate the query vector (Query), key vector (Key), and value vector (Value), and then calculate the attention weights through the dot-product attention mechanism and perform weighted summation on the value vector. This process can be expressed as:
[0126] ;
[0127] where are the matrix representations of the query vector, key vector, and value vector respectively, d k is the dimension of the key vector, and the softmax function is used to normalize the attention weights.
[0128] In the multi-head attention layer, this process will be performed multiple times in parallel (i.e., "multi-head"), and each time different linear transformations are used to generate the query vector, key vector, and value vector. Then, the outputs of these attention heads will be concatenated and passed through an additional linear transformation to obtain the final output.
[0129] After the processing of the multi-head attention layer, the Transformer module will generate a weighted focus integration vector, and each element in this vector is the weighted sum of the corresponding element in the original set integration representation vector. This weighted focus integration vector not only retains the key information in the original vector, but also highlights the important parts and suppresses noise through the attention mechanism.
[0130] In step S430, the computer system inputs the weighted focus integration vector generated in step S420 into the densely connected module for projection prediction to obtain the event risk identification result.
[0131] The dense connection module (also known as the fully connected layer or the feedforward neural network) is a simple neural network layer that maps an input vector to an output vector through a linear transformation and a non - linear activation function. In step S430, the dense connection module first maps the weight - focused integration vector to a higher - dimensional space through a linear transformation, then activates it through a non - linear activation function (such as ReLU, sigmoid, etc.), and finally maps the output to the dimension of the risk identification result through another linear transformation.
[0132] Specifically, assuming the weight - focused integration vector is a, the first linear transformation in the dense connection module can be expressed as: ; where, is the learnable weight matrix, is the bias vector, and h' is the vector after the linear transformation.
[0133] Then, the non - linear activation function activates h' to obtain the activated vector h''. This activation process can be expressed as: h'' = ((h'); where, is the non - linear activation function.
[0134] Finally, the second linear transformation maps the activated vector to the dimension of the risk identification result to obtain the final event risk identification result y: y = W2h''+b2; where, W2 is the learnable weight matrix, b2 is the bias vector, and y is the event risk identification result vector.
[0135] In the wireless communication data security management method, the event risk identification result is a probability value or a confidence score, which is used to indicate the possibility that the corresponding communication node has a risk communication event in the corresponding communication session period. For example, if y is a vector of length 1 and its value is greater than a certain threshold (such as 0.5), the computer system may consider that there is a risk communication event for the communication node in the current communication session period.
[0136] In summary, step S400 realizes the intelligent identification and evaluation of communication event security risks by integrating the event representation vector, performing weight - focused integration processing, and projection prediction. This process not only fully utilizes the key information in the event representation vector but also improves the accuracy and robustness of risk identification through the collaborative work of the Transformer module and the dense connection module.
[0137] As an implementation, the method further includes:
[0138] Step S500: Among the obtained event risk identification results, determine the event risk identification results greater than the risk reference value as the target event risk identification results;
[0139] Step S600: Determine the security management mechanism for the corresponding communication node based on the determined risk identification results of each target event; and perform communication management based on the security management mechanism.
[0140] In step S500, those communication events with potential security risks are screened out from all event risk identification results. The execution entity of this step is the computer system, which determines which event risk identification results are to be focused on by setting a risk reference value (also known as a threshold). Assume that in step S400, the computer system has generated a series of event risk identification results through the risk communication event detection network. Each result corresponds to a communication event and gives the confidence level or probability value that the event is a risk communication event. These probability values range from 0 to 1, where 0 indicates no risk at all and 1 indicates extremely high risk. To screen out events with potential security risks, the computer system sets a risk reference value, which is determined according to the actual application scenario and security requirements.
[0141] For example, assume the risk reference value is set to 0.7, which means the computer system believes that any event risk identification result with a probability value greater than 0.7 indicates a communication event with potential security risks. During the screening process, the computer will traverse all event risk identification results and compare them with the risk reference value. If the probability value of a certain result is greater than 0.7, it is marked as a target event risk identification result, indicating that the communication event is further concerned and managed.
[0142] Based on the target event risk identification results determined in step S500, step S600 formulates a security management mechanism for the corresponding communication node and implements corresponding communication management measures. The execution entity of this step is also the computer system, which realizes the effective monitoring and management of communication nodes in an automated and intelligent manner.
[0143] When determining the security management mechanism, the computer system considers multiple factors, including but not limited to the risk level of communication events, the historical behavior patterns of communication nodes, the security status of the network communication environment, etc. Based on these factors, the system can formulate personalized security management strategies for each communication node, such as restricting specific types of communication, increasing the monitoring intensity, triggering security alerts, etc. For example, assume that in step S500, the computer system determines that there is a high-risk communication event in a specific communication session period for a communication node. To address this risk, the system may take the following security management measures:
[0144] 1. Restrict communication types: The system may restrict the node to only perform low-risk communication activities in the next period of time, such as prohibiting file transfer or restricting the data transfer volume.
[0145] 2. Increase monitoring intensity: The system may enhance the monitoring and logging of this node to promptly detect and address potential security threats.
[0146] 3. Trigger security alerts: The system may send alert notifications to security administrators, reminding them to pay attention to the abnormal behavior of this node and take further investigation and handling measures.
[0147] 4. Dynamically adjust policies: The system may dynamically adjust security management policies according to the real-time behavior of communication nodes and changes in the network environment to ensure the effectiveness and flexibility of security management.
[0148] When implementing communication management measures, the computer system relies on a series of automated tools and platforms to monitor and manage communication nodes. These tools may include network monitoring systems, log analysis systems, security alert systems, etc. They can collect and analyze communication data in real time and automatically execute corresponding operations according to predefined security management policies.
[0149] As an implementation method, the training process of the event characterization information mining network and the risk communication event detection network includes:
[0150] Step S10: Obtain multiple debugging learning examples, where each debugging learning example is a set composed of a set number of communication events triggered by the same sample communication node in a sample communication session cycle;
[0151] Step S20: For each debugging learning example, for each communication event covered by the debugging learning example, perform feature transformation respectively according to the corresponding event characteristics to obtain a transformed feature set; through the event characterization information mining network to be debugged, respectively mine the event characterization vectors of each set data unit covered by the transformed feature set. Each event characterization vector is obtained by combining the vectorized features after transformation of the corresponding set data unit and the event characterization vector of its previous set data unit; integrate the obtained event characterization vectors into a set integrated characterization vector, load it into the risk communication event detection network to be debugged, and obtain a target event risk recognition result, which is used to indicate the confidence level of the corresponding sample communication node having a risk communication event in the corresponding sample communication session cycle;
[0152] Step S30: Optimize the network parameters of the event characterization information mining network and the risk communication event detection network based on the obtained target event risk recognition results and the corresponding prior risk labels.
[0153] Step S10 obtains multiple debugging learning examples from actual wireless communication data. These examples are sample data for training machine learning models, and they should be able to fully reflect the diversity and complexity of communication events in the wireless communication network.
[0154] Specifically, each debugging learning example contains a set of communication events triggered by a sample communication node during a sample communication session cycle. These sets of communication events are arranged in chronological order, and each event contains characteristics such as event type, occurrence time, transmission volume, source address, destination address, protocol type, port number, etc. For example, a debugging learning example may contain all the communication events triggered by a smartphone user in a day, including text message sending, phone calls, Internet browsing, etc.
[0155] To ensure the effectiveness and generalization ability of the training process, the computer system collects a sufficient number of debugging learning examples and ensures that these examples cover various communication scenarios and event types that may occur in the wireless communication network. In addition, to simulate the uncertainties in the real world, the computer system can also perform appropriate preprocessing and enhancement on the debugging learning examples, such as adding noise, adjusting the event order, etc.
[0156] Step S20 performs feature transformation on the communication events in the debugging learning example and mines the event representation vector through the event representation information mining network to be debugged.
[0157] For the communication events in each debugging learning example, the computer system performs feature transformation according to their event characteristics to obtain a set of transformed features. This step involves encoding the event characteristics into numerical or vector data for subsequent processing. For example, the event type can be converted into a binary vector through one-hot encoding, and the occurrence time can be obtained as a numerical representation through timestamp conversion or normalization processing.
[0158] Next, the computer system inputs the set of transformed features into the event representation information mining network to be debugged. This network is a deep neural network that includes a vectorization module and a long short-term memory network module. The vectorization module is responsible for converting the transformed features into vectorized features, and the long short-term memory network module is responsible for capturing the temporal dependence relationships between communication events.
[0159] During the process of mining the event representation vector, the long short-term memory network module will gradually process each set data unit in the set of transformed features (i.e., the vectorized features of each communication event). For each set data unit, the network will combine its own vectorized features and the event representation vector of the previous set data unit to generate the event representation vector of the current set data unit. This process is recursive until all set data units are processed.
[0160] Finally, the computer system integrates all event representation vectors into a set integration representation vector and inputs it into the risk communication event detection network to be debugged. This network is a classifier or a regressor, which is responsible for generating the target event risk identification result based on the set integration representation vector. The target event risk identification result is a numerical value or a probability value, which represents the confidence level of the corresponding sample communication node having a risk communication event in the corresponding sample communication session cycle.
[0161] Step S30 optimizes the network parameter variables based on the target event risk identification result and the prior risk label.
[0162] During the training process, each debugging learning sample is attached with a prior risk label, which is a numerical value or a label, representing the actual risk level or the existence of a risk communication event of the sample communication node in the sample communication session cycle. The prior risk label is obtained through manual annotation or expert judgment.
[0163] To evaluate the performance of the network to be debugged and optimize its parameter variables, the computer system compares the target event risk identification result with the prior risk label. This comparison process involves calculating a loss function (such as cross-entropy loss, mean squared error, etc.), which measures the difference between the network prediction result and the actual situation.
[0164] Based on the calculation result of the loss function, the computer system uses optimization techniques such as backpropagation algorithm and gradient descent to adjust the parameter variables of the event representation information mining network and the risk communication event detection network. This process is iterative until the loss function converges to an acceptable range. In each iteration, the computer system updates the values of the parameter variables according to the gradient information of the current parameter variables, aiming to reduce the prediction error and improve the generalization ability of the model in the next iteration.
[0165] It should be noted that the optimization of network parameter variables is a complex and time-consuming process. To accelerate the training process and improve the model performance, the computer system can adopt various strategies, such as batch processing, learning rate adjustment, regularization, etc. In addition, to avoid overfitting, the computer system can also adopt techniques such as data augmentation, early stopping, dropout, etc. to enhance the robustness and generalization ability of the model.
[0166] As an implementation manner, the event representation information mining network includes a first densely connected module; the method further includes:
[0167] Step S40: For each debugging and learning example, project and predict the event representation vector of the last set data unit in the corresponding transformed feature set through the first dense connection module to obtain a predicted event risk recognition result, which is used to indicate the confidence level of a risk communication event for the corresponding example communication node in the corresponding example communication session period;
[0168] Step S30, based on the obtained target event risk recognition results and the corresponding prior risk labels, optimize the network parameter variables of the event representation information mining network and the risk communication event detection network, including:
[0169] Step S31: Based on the obtained target event risk recognition results, predicted event risk recognition results and the corresponding prior risk labels, optimize the network parameter variables of the event representation information mining network and the risk communication event detection network.
[0170] Step S40 is an additional prediction step introduced during network training. Its purpose is to use the first dense connection module in the event representation information mining network to project and predict the event representation vector of the last set data unit in the transformed feature set, thereby obtaining a predicted event risk recognition result. The introduction of this step provides an additional supervision signal for network training, which helps to improve the network's ability to recognize communication event risks.
[0171] Specifically, during training, for each debugging and learning example, the computer system first, as described in step S20, mines the event representation vectors of each set data unit in the transformed feature set through the event representation information mining network. When processing the last set data unit in the transformed feature set, in addition to integrating its event representation vector into the set integration representation vector for subsequent risk communication event detection, the computer system also inputs this event representation vector into the first dense connection module.
[0172] The first dense connection module is a fully connected layer (also known as a linear layer or a feedforward neural network layer). It receives the event representation vector as input and maps it to an output space through a series of linear transformations and non-linear activation functions. In this output space, each dimension corresponds to a specific risk recognition result or category. For the wireless communication data security management task, this output space is a one-dimensional space, representing the confidence level or probability value of a communication event being a risk communication event.
[0173] Assume the event representation vector is h T (where T represents the total number of set data units in the transformed feature set and is also the index of the last set data unit), the linear transformation of the first dense connection module can be expressed as:
[0174] ;
[0175] Among them, is a learnable weight matrix, b d is a bias vector, and z is the vector after linear transformation.
[0176] Next, the non-linear activation function activates z to obtain the final predicted event risk identification result . Commonly used non-linear activation functions include the sigmoid function (for binary classification tasks) and the softmax function (for multi-classification tasks). In this scenario, since we are concerned about whether a communication event has risks, the sigmoid function can be used:
[0177] ;
[0178] Among them, is the sigmoid function, is the predicted event risk identification result, and its value ranges between 0 and 1, indicating the confidence level of the communication event having risks.
[0179] Through step S40, the computer system can generate a predicted event risk identification result for each debugging learning example, and this result will be used together with the subsequent target event risk identification result for the optimization of network parameters.
[0180] Step S30 is an optimization step in the network training process. Its purpose is to optimize the network parameters of the event characterization information mining network and the risk communication event detection network based on the obtained target event risk identification result, the predicted event risk identification result, and the corresponding prior risk labels. And step S31 is one of the specific implementation methods of this optimization process, which emphasizes the importance of considering both the predicted event risk identification result and the target event risk identification result simultaneously.
[0181] In step S31, the computer system calculates the error or loss between the predicted event risk identification result and the target event risk identification result y and the prior risk label . For binary classification tasks, commonly used loss functions include the cross-entropy loss function and the mean squared error loss function. In this scenario, since we are concerned about the difference between probability values, the cross-entropy loss function can be used:
[0182] ;
[0183] ;
[0184] where is the loss of the prediction event risk identification result, is the loss of the target event risk identification result, is the prior risk label (0 or 1), is the prediction event risk identification result, and y is the target event risk identification result.
[0185] Then, the computer system performs a weighted sum of these two loss functions to obtain the total loss function:
[0186] ;
[0187] where, is a hyperparameter used to balance the importance of the prediction event risk identification result and the target event risk identification result in the optimization process.
[0188] Finally, the computer system is based on the total loss function , and uses optimization techniques such as backpropagation algorithm and gradient descent to adjust the parameter variables of the event representation information mining network and the risk communication event detection network. This process is iterative until the loss function converges to an acceptable range. In each iteration, the computer system updates the values of the parameter variables according to the gradient information of the current parameter variables, in order to reduce the prediction error and improve the generalization ability of the model in the next iteration.
[0189] Through the optimization process of step S31, the computer system can simultaneously consider the information of the prediction event risk identification result and the target event risk identification result, so as to more comprehensively evaluate the performance of the model and adjust the parameter variables. This not only helps to improve the accuracy of the model in identifying communication event risks, but also enhances the robustness and generalization ability of the model, enabling it to better adapt to different communication scenarios and data distributions.
[0190] As an implementation, in step S31, based on the obtained target event risk identification results, prediction event risk identification results and the corresponding prior risk labels, the network parameter variables of the event representation information mining network and the risk communication event detection network are optimized, including:
[0191] Step S311: In the first debugging session, based on the error between the obtained prediction event risk identification results and the corresponding prior risk labels, determine the first training cost; based on the first training cost, optimize the network parameter variables of the event representation information mining network;
[0192] Step S312: In the second debugging phase, based on the error between each obtained target event risk identification result and the corresponding prior risk label, determine the second training cost; based on the second training cost, optimize the network parameter variables of the risk communication event detection network.
[0193] Step S311 focuses on optimizing the parameter variables of the event characterization information mining network. This step determines the training cost of the event characterization information mining network by evaluating the error between the predicted event risk identification result and the prior risk label, and accordingly adjusts the parameter variables of the network to improve its accuracy in characterizing communication events.
[0194] Specifically, in the first debugging phase, the computer system first calculates the predicted event risk identification result of each debugging learning example and the corresponding prior risk label The error between them. This error can be measured by various loss functions, such as cross-entropy loss, mean squared error, etc.
[0195] Based on the calculated loss value, the computer system can determine the first training cost, which reflects the performance of the event characterization information mining network under the current parameter configuration. Subsequently, the computer system uses optimization techniques such as backpropagation algorithm and gradient descent to adjust the parameter variables of the event characterization information mining network according to the first training cost. This process is iterative, and each iteration updates the value of the parameter variables according to the gradient information of the current parameter variables, with the expectation of reducing the prediction error and improving the accuracy of the model in the next iteration.
[0196] Step S312 is different from Step S311. The optimization goal of Step S312 is to improve the accuracy of the risk communication event detection network for the target event risk identification result.
[0197] In the second debugging phase, the computer system first calculates the error between the target event risk identification result y of each debugging learning example and the corresponding prior risk label The error can be measured by the cross-entropy loss function as follows:
[0198] ;
[0199] where represents the loss of the target event risk identification result, and y is the target event risk identification result (a probability value between 0 and 1).
[0200] Based on the calculated loss value, the computer system can determine the second training cost, which reflects the performance of the risk communication event detection network under the current parameter configuration. Subsequently, the computer system uses the same optimization technique as in step S311 to adjust the parameters of the risk communication event detection network according to the second training cost. This process is also iterative, aiming to improve the accuracy of the model by continuously reducing the error of the target event risk recognition result.
[0201] Compared with step S311, the optimization process of step S312 is more directly related to the final risk recognition output. Since the target event risk recognition result is the direct judgment of whether a communication event has a risk by the risk communication event detection network, optimizing the parameters of the risk communication event detection network is crucial for improving the performance of the entire security management method.
[0202] As an implementation, step S30, based on the obtained risk recognition results of each target event and the corresponding prior risk tags, optimizes the network parameters of the event characterization information mining network and the risk communication event detection network, including:
[0203] Step S301: Determine the second training cost based on the error between the obtained risk recognition results of each target event and the corresponding prior risk tags;
[0204] Step S302: Based on the second training cost, synchronously optimize the network parameters of the event characterization information mining network and the risk communication event detection network.
[0205] The task of step S301 is to calculate the error between the target event risk recognition result and the prior risk tag, and determine the second training cost accordingly. This step is the basis of the optimization process, which provides a clear goal and direction for subsequent parameter adjustment.
[0206] Specifically, during the training process, for each debugging learning example, the computer system will obtain a target event risk recognition result y through the processing of the event characterization information mining network and the risk communication event detection network. At the same time, each example is accompanied by a prior risk tag, which represents the actual risk level or the existence of a risk communication event of the example communication node in the corresponding communication session cycle. To evaluate the prediction performance of the model, the computer system calculates the error between the target event risk recognition result and the prior risk tag.
[0207] This error can be measured by various loss functions, such as cross-entropy loss, mean squared error, etc. For all the debugging learning examples, the computer system calculates their loss values respectively, and averages or sums these loss values to obtain the second training cost. The second training cost reflects the overall performance of the event representation information mining network and the risk communication event detection network under the current parameter configuration. If the second training cost is high, it indicates that the prediction performance of the model is poor, and the parameters need to be adjusted to improve; conversely, if the second training cost is low, it indicates that the prediction performance of the model is good, but it is still possible to improve it by further adjusting the parameters.
[0208] The task of step S302 is to synchronously optimize the parameters of the event representation information mining network and the risk communication event detection network based on the second training cost. This step is the core of the optimization process. It reduces the prediction error and improves the performance of the model by adjusting the parameters of the network.
[0209] During the synchronous optimization process, the computer system uses optimization techniques such as backpropagation algorithm and gradient descent. These techniques determine the adjustment direction and step size of the parameters by calculating the gradients of the loss function with respect to the network parameters. Specifically, for each parameter, its gradient (i.e., the partial derivative of the loss function with respect to this parameter) is calculated, and then the value of the parameter is updated according to the direction and magnitude of the gradient. This process is iterative. Each iteration updates the value of the parameter based on the current gradient information, with the expectation of reducing the value of the loss function in the next iteration. It should be noted that during the synchronous optimization process, the parameters of the event representation information mining network and the risk communication event detection network are adjusted simultaneously. This is because these two networks are interrelated. The output of the event representation information mining network is the input of the risk communication event detection network, so their performances affect each other. By synchronously optimizing the parameters of these two networks, it can be ensured that they remain coordinated during the training process and jointly improve the prediction performance of the model.
[0210] In practical applications, the synchronous optimization process may involve a large amount of computation and resource consumption. To accelerate the training process and improve the optimization efficiency, the computer system can adopt various strategies, such as batch processing, learning rate adjustment, regularization, etc. In addition, to avoid overfitting, the computer system can also adopt techniques such as data augmentation, early stopping, dropout, etc. to enhance the generalization ability of the model.
[0211] Through the collaborative work of steps S301 and S302, the computer system can efficiently optimize the parameters of the event representation information mining network and the risk communication event detection network based on the error between the target event risk identification result and the prior risk marker. This process not only improves the prediction performance of the model but also enhances the robustness and generalization ability of the model, enabling it to better adapt to different communication scenarios and data distributions. At the same time, the synchronous optimization strategy also ensures that the event representation information mining network and the risk communication event detection network remain coordinated during the training process, jointly providing strong support for the security management of wireless communication data.
[0212] As an implementation, in step S20, for each communication event covered by the debugging learning example, feature transformation is performed respectively according to the corresponding event features to obtain a set of transformed features, including:
[0213] Step S21: For each communication event covered by the debugging learning example, based on the event features of the communication event, the communication event is converted into an event identifier in a preset set of event identifiers, where the event identifiers corresponding to communication events with different features are different;
[0214] Step S22: The set composed of the obtained event identifiers is used as the set of transformed features, where each event identifier is a set data unit in the set of transformed features.
[0215] Step S21 converts each communication event in the debugging learning example into an event identifier in a preset set of event identifiers. This conversion process is based on the event features of the communication event, and communication events with different features will be converted into different event identifiers.
[0216] Specifically, during the training process, the computer system traverses each communication event in the debugging learning example and extracts its event features. These event features may include event type, occurrence time, transmission volume, source address, destination address, protocol type, port number, etc. To convert these event features into event identifiers, the computer system pre-defines a set of event identifiers, which contains all possible event identifiers and their corresponding feature combinations.
[0217] For example, assume there is a set of event identifiers that contains the following event identifiers and their corresponding feature combinations:
[0218] "HTTP_GET_80": Represents an HTTP GET request, using the TCP protocol, and the target port is 80.
[0219] "FTP_UPLOAD_21": Represents an FTP upload operation, using the TCP protocol, and the target port is 21.
[0220] "SSH_LOGIN_22": Represents an SSH login attempt using the TCP protocol with a destination port of 22.
[0221] Suppose a communication event in the debugging learning example has the following characteristics: the event type is HTTP GET, using the TCP protocol, and the destination port is 80. Based on these characteristics, the computer system looks up the matching event identifier in the set of event identifiers and assigns it to this communication event. In this example, the communication event will be converted into the event identifier "HTTP_GET_80".
[0222] The task of step S22 is to collect all the event identifiers generated in step S21 and construct a transformed feature set. Each element in this set is an event identifier, which corresponds to a communication event in the debugging learning example. The transformed feature set provides structured input data for the subsequent event characterization information mining network.
[0223] Specifically, in step S22, the computer system traverses all the communication events in the debugging learning example and adds the event identifier corresponding to each event to the transformed feature set. This process is sequential and preserves the original order of the communication events in the debugging learning example. Therefore, the transformed feature set not only contains the key feature information of the communication events but also implies the temporal relationship and potential patterns among them.
[0224] Continuing with the above example, assume that the debugging learning example contains three communication events, which are respectively converted into the event identifiers "HTTP_GET_80", "FTP_UPLOAD_21", and "SSH_LOGIN_22". In step S22, the computer system collects these three event identifiers in the order they appear in the debugging learning example and constructs a transformed feature set: {"HTTP_GET_80", "FTP_UPLOAD_21", "SSH_LOGIN_22"}.
[0225] In addition, in practical applications, other factors may also be considered in the construction process of the transformed feature set, such as the encoding method of the event identifier, the size limit of the set, etc. For example, to handle a large number of communication events or improve computational efficiency, the computer system may encode or compress the event identifiers; at the same time, to avoid excessive consumption of computing resources caused by an overly large transformed feature set, the computer system may also set an upper limit on the size of the set and truncate or partition the set when the limit is reached.
[0226] Through the collaborative work of steps S21 and S22, the computer system can convert the communication events in the debugging learning samples into a set of transformed features, providing structured input data for the subsequent event characterization information mining network. This process not only simplifies the representation of communication events but also preserves the key features and temporal relationships between them, providing strong support for subsequent risk identification.
[0227] As an implementation, the event characterization information mining network includes a vectorization module and a long short-term memory network module. The number of network layers of the long short-term memory network module is equal to the number of features in the set of transformed features, and each long short-term memory network layer corresponds to a set data unit in the set of transformed features.
[0228] In step S20, through the event characterization information mining network to be debugged, the event characterization vectors of each set data unit covered by the set of transformed features are mined respectively, including:
[0229] For each set data unit in the set of transformed features, the following steps are performed respectively:
[0230] Step S23: Through the vectorization module, the set data unit is vectorized to obtain the vectorized features of the set data unit.
[0231] Step S24: Through the corresponding long short-term memory network layer, after integrating the vectorized features of the set data unit with the event characterization vector of its previous set data unit, the event characterization vector of the set data unit is extracted.
[0232] During the network training process of the wireless communication data security management method, the event characterization information mining network is responsible for extracting the event characterization vectors of each set data unit (i.e., communication events) from the set of transformed features. These vectors can capture the key features of communication events and the temporal dependencies between them. To achieve this goal, the event characterization information mining network is designed to consist of two parts: a vectorization module and a long short-term memory network module. Among them, the vectorization module is responsible for converting the set data unit into vectorized features, and the long short-term memory network module is responsible for further extracting the event characterization vectors.
[0233] Step S23 vectorizes the set data unit to obtain its vectorized features. This process is completed by the vectorization module, which can convert the set data unit (here it is the event identifier or simply encoded event features) into a fixed-length vector representation.
[0234] During the vectorization conversion process, the vectorization module adopts a mapping mechanism to map each set data unit into a high-dimensional vector space. This vector space is a continuous real number space, and its dimension may be much higher than that of the original set data unit. Through this mapping, the vectorization module can capture the potential relationships and similarities between set data units, facilitating subsequent processing and analysis.
[0235] For example, assume that a set data unit in the transformed feature set is the event identifier "HTTP_GET_80", which represents a communication event of accessing port 80 using the HTTP GET method. During the vectorization conversion process, the vectorization module may map this event identifier to a vector of length 100, such as [0.1, 0.2, -0.3, ..., 0.5]. Each element in this vector represents a value on a feature dimension, and together they constitute the vectorized feature of the event identifier.
[0236] The specific implementation method of vectorization conversion may vary depending on the application scenario and data characteristics. In practical applications, the vectorization module may adopt a pre-trained embedding layer, a fully connected layer, or other complex neural network structures to implement vectorization conversion. In addition, to enhance the expressive power of vectorized features, the vectorization module may also introduce some additional processing steps, such as feature scaling, normalization, or non-linear transformation, etc.
[0237] Step S24 further extracts the event representation vector through the long short-term memory network module. This process is carried out on the basis of vectorization conversion, and it takes into account the temporal dependence relationship between set data units.
[0238] In step S24, the vectorized features of each set data unit are input into the corresponding long short-term memory network layer for processing. The long short-term memory network is a special type of recurrent neural network that can effectively capture the long-term dependence relationship in sequence data. In the event representation information mining network, each long short-term memory network layer corresponds to a set data unit, and they are processed in sequence according to the order of set data units in the transformed feature set.
[0239] For each set data unit, the long short-term memory network layer combines its vectorized features and the event representation vector of the previous set data unit to generate the event representation vector of the current set data unit. This process is achieved through the internal mechanism of the long short-term memory network, which involves the collaborative work of components such as the forget gate, input gate, and output gate. Specifically, the long short-term memory network layer determines how much information of the event representation vector of the previous set data unit to retain according to the forget gate, determines how much information of the vectorized features of the current set data unit to introduce according to the input gate, and generates the final event representation vector according to the output gate.
[0240] Continuing with the above example, assume that the vectorized features of the event identifier "HTTP_GET_80" have been obtained as [0.1, 0.2, -0.3, ..., 0.5], and the event representation vector of the previous set data unit is [0.6, -0.1, 0.4, ..., 0.2]. In step S24, the long short-term memory network layer combines these two vectors to generate the event representation vector of "HTTP_GET_80". This process may involve a series of complex mathematical operations and parameter adjustments, but the final result is a new vector that contains the key features of the "HTTP_GET_80" event and the temporal dependence relationship between it and the previous event.
[0241] The processing of the long short-term memory network layer is not isolated. In the event representation information mining network, each long short-term memory network layer is affected by the subsequent layers, and their outputs are further processed by the subsequent layers. This layer-by-layer processing method enables the event representation information mining network to gradually extract higher-level event representation vectors, thereby more accurately capturing the features and temporal dependence relationships of communication events.
[0242] Through the collaborative work of steps S23 and S24, the event representation information mining network can extract the event representation vectors of each set data unit from the transformed feature set. These vectors not only contain the key feature information of communication events but also reflect the temporal dependence relationships between them. These event representation vectors will be used as the input data for the subsequent risk communication event detection network for further risk identification and assessment.
[0243] As an implementation, in step S23, through the vectorization module, the set data unit is vectorized and transformed to obtain the vectorized features of the set data unit, including:
[0244] Step S231: Through the vectorization module, the set data unit is randomly vectorized and transformed to obtain the corresponding vectorized features of the set data unit;
[0245] When optimizing the network parameters of the event representation information mining network, the method further includes:
[0246] Step S3111: Jointly optimize the vectorized features obtained by randomly vectorizing each set data unit, and after the debugging is completed, form a vectorized feature mapping relationship for the vectorized features corresponding to each potential set data unit, so as to determine the vectorized features of each set data unit based on the vectorized feature mapping relationship during the network inference stage.
[0247] Step S231 is one of the specific implementation manners of step S23. It performs random vector transformation on the set data unit through the vectorization module to obtain its corresponding vectorized feature. This transformation process is based on randomness, aiming to generate a unique vector representation for each set data unit while maintaining the relative relationships between vectors.
[0248] During the random vector transformation process, the vectorization module first initializes a random seed or a random number generator. Then, for each set data unit, the module generates a vector with a fixed length according to this random seed or generator. The length of this vector (i.e., the dimension of the vector) is predefined, which determines the expression ability and computational complexity of the vectorized feature. Each element of the vector is a random number, and these random numbers together constitute the vectorized feature of the set data unit.
[0249] It should be noted that the random vector transformation is not a simple random selection or random permutation. On the contrary, it involves a series of complex mathematical operations and parameter adjustments to ensure that the generated vectorized features can accurately reflect the features and potential relationships of the set data units. For example, the vectorization module may adopt a specific distribution (such as normal distribution, uniform distribution, etc.) to generate random numbers, or perform weighted processing according to the features of the set data units.
[0250] Suppose there is a set data unit that represents a communication event of accessing a specific port using the HTTP GET method. During the vectorization transformation process, the vectorization module may generate a vector with a length of 100 as the vectorized feature of this event. Each element in this vector is a random number, and they together constitute the representation of this event in the vector space. Although these random numbers seem random, they are actually generated through specific algorithms and parameters, so they can maintain the relative relationships between vectors and the consistency of features.
[0251] Step S3111 is a derivative step introduced when optimizing the network parameters of the event characterization information mining network. Its main purpose is to jointly optimize the vectorized features obtained by each set data unit through random vector transformation and construct a vectorized feature mapping relationship after the debugging is completed. This mapping relationship will be used to quickly determine the vectorized features of each set data unit during the network inference stage.
[0252] During the joint optimization process, the computer system optimizes the parameters of the event representation information mining network together with the generation process of the vectorized features. This means that while the vectorization module generates vectorized features, the event representation information mining network is also learning how to better utilize these features to extract event representation vectors. Through optimization techniques such as backpropagation algorithm and gradient descent, the computer system continuously adjusts the parameters of the vectorization module and the parameters of the event representation information mining network to minimize the prediction error and improve the performance of the model.
[0253] After the debugging is completed, the computer system constructs a vectorized feature mapping relationship based on the vectorized features obtained during the optimization process. This mapping relationship is a lookup table or a mapping function that maps each set data unit to its corresponding vectorized feature. When constructing the mapping relationship, the computer system considers all the set data units that appeared during the training process and their corresponding vectorized features. In this way, during the network inference stage, when the computer system receives a new set data unit, it can directly look up the corresponding vectorized feature in the mapping relationship without having to perform random vector conversion again.
[0254] The construction of the vectorized feature mapping relationship not only improves the efficiency of network inference but also enhances the stability and interpretability of the model. Because each vectorized feature in the mapping relationship has been optimized and verified, they can more accurately reflect the features and potential relationships of the set data units. In addition, the existence of the mapping relationship also makes the model easier to debug and modify because the computer system can directly view and adjust the vectorized features in the mapping relationship.
[0255] Steps S231 and S3111 together constitute the core link of vectorization conversion in the event representation information mining network. By combining random vector conversion with joint optimization and mapping relationship construction, the computer system can efficiently generate and utilize vectorized features to extract event representation vectors, thereby improving the accuracy and efficiency of the wireless communication data security management method.
[0256] As an implementation, the risk communication event detection network includes a Transformer module and a second dense connection module; in step S20, the obtained event representation vectors are integrated into a set integrated representation vector and loaded into the risk communication event detection network to be debugged to obtain a target event risk identification result, including:
[0257] Step S25: Integrate the obtained event representation vectors into a set integrated representation vector;
[0258] Step S26: Perform weight focusing integration processing on the set integrated representation vector through the Transformer module to obtain a weight focusing integration vector;
[0259] Step S27: Project and predict the weight - focused integration vector through the second dense connection module to obtain the target event risk identification result.
[0260] In step S25, the computer system integrates each event representation vector generated by the event representation information mining network into a set - integrated representation vector. This process is the basis for subsequent processing steps, ensuring that the information in all event representation vectors can be effectively integrated and utilized.
[0261] Specifically, in step S25, the computer system collects all event representation vectors output by the event representation information mining network. These vectors have the same dimension, and each vector represents the key features and temporal dependencies of the corresponding communication event. To integrate these vectors into a set - integrated representation vector, the computer system can adopt various methods, such as average pooling, max pooling, concatenation, etc. However, here it is assumed that a more general method is used, that is, linear transformation and integration are performed through a learnable weight matrix and a bias vector.
[0262] Suppose there are N event representation vectors, denoted as , and the dimension of each vector is D. In step S25, the computer system will concatenate these vectors into a matrix H, where . Then, the computer system performs a linear transformation through a learnable weight matrix W and a bias vector b to obtain the set - integrated representation vector z:
[0263] ;
[0264] where the dimension of W is (M×ND), M is the dimension of the set - integrated representation vector, and the dimension of b is M. Through this process, the computer system successfully integrates multiple event representation vectors into a set - integrated representation vector containing richer information.
[0265] In step S26, the Transformer module is used to perform weight - focused integration processing on the set - integrated representation vector to obtain the weight - focused integration vector. This process aims to assign different weights to different parts of the set - integrated representation vector through techniques such as the attention mechanism, so as to highlight important information and suppress noise.
[0266] Specifically, in step S26, the Transformer module first receives the set integration representation vector z as input. Then, the module uses the self-attention mechanism to calculate the query vector, key vector, and value vector, and calculates the attention weights through the dot-product attention mechanism. These attention weights reflect the correlations between different parts of the set integration representation vector, and they will be used to perform weighted summation on the value vector to generate the weight-focused integration vector.
[0267] Assume that the self-attention layer in the Transformer module has H attention heads, and each attention head will independently perform the above calculation process. For each attention head, the query vector, key vector, and value vector can be respectively expressed as (where i = 1, 2, …, H). These vectors are obtained from the set integration representation vector z through linear transformation. Then, the attention weights can be calculated by the following formula:
[0268] ;
[0269] where, is the dimension of the key vector, and the softmax function is used to normalize the attention weights. Finally, the outputs of all attention heads will be concatenated and passed through an additional linear transformation to obtain the final weight-focused integration vector a.
[0270] Through this process, the Transformer module successfully performs weight-focused integration processing on the set integration representation vector, generating a weight-focused integration vector that highlights important information more prominently.
[0271] Step S27 uses the second dense connection module to project and predict the weight-focused integration vector to obtain the target event risk identification result. This process is a key step in mapping the high-dimensional weight-focused integration vector to the low-dimensional target space.
[0272] Specifically, in step S27, the second dense connection module receives the weight-focused integration vector a as input and maps it to the target space through a series of linear transformations and non-linear activation functions., this target space is a one-dimensional space, which represents the confidence or probability value of the communication event being a risky communication event.
[0273] Assume that the second dense connection module contains two fully connected layers. The first fully connected layer maps the weight-focused integration vector a to an intermediate representation h', and the second fully connected layer then maps the intermediate representation h' to the target event risk identification result y in the target space. The calculation processes of these two fully connected layers can be respectively expressed as:
[0274] ;
[0275] ;
[0276] Among them, is a learnable weight matrix, is a bias vector, is a non-linear activation function (such as the sigmoid function). Through this process, the second densely connected module successfully maps the weight-focused integration vector to a scalar value representing the risk confidence of communication events.
[0277] Figure 2 is a schematic diagram of the hardware entity of a computer system provided by an embodiment of the present application. As Figure 2 shown, the hardware entity of the computer system 1000 includes: a processor 1001 and a memory 1002. Among them, the memory 1002 stores a computer program that can run on the processor 1001, and when the processor 1001 executes the program, it implements the steps in the method of any of the above embodiments.
[0278] The memory 1002 stores a computer program that can run on the processor. The memory 1002 is configured to store instructions and applications executable by the processor 1001, and can also cache data to be processed or already processed by the processor 1001 and each module in the computer system 1000 (for example, image data, audio data, voice communication data, and video communication data), and can be implemented by flash memory (FLASH) or random access memory (Random Access Memory, RAM).
[0279] When the processor 1001 executes the program, it implements the steps of the wireless communication data security management method of any of the above. The processor 1001 generally controls the overall operation of the computer system 1000.
[0280] As described above, only the embodiments of the present application are provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application.
Claims
1. A method for wireless communication data security management, characterized in that, The method includes: Splitting the wireless communication data source information according to communication nodes and communication session cycles to obtain one or more communication event sets, where each communication event set includes a set number of communication events triggered by the same communication node in one communication session cycle; For each communication event set, the following steps are respectively carried out: For each communication event covered by the communication event set, feature transformation is respectively carried out according to the corresponding event features to obtain a transformed feature set; Through a pre-debugged event representation information mining network, the event representation vectors of each set data unit covered by the transformed feature set are respectively mined, where each event representation vector is obtained based on the vectorized features after transformation of the corresponding set data unit and the event representation vector of its previous set data unit; among them, the event representation information mining network is a pre-trained deep learning model, including a vectorization module and a long short-term memory network module, the number of network layers of the long short-term memory network module is equal to the number of features in the transformed feature set, and each long short-term memory network layer corresponds to a set data unit in the transformed feature set; the step of respectively mining the event representation vectors of each set data unit covered by the transformed feature set through the pre-debugged event representation information mining network includes: for each set data unit in the transformed feature set, the following steps are respectively carried out: through the vectorization module, the set data unit is subjected to vectorization conversion to obtain the vectorized features of the set data unit; through the corresponding long short-term memory network layer, after integrating the vectorized features of the set data unit and the event representation vector of its previous set data unit, the event representation vector of the set data unit is mined; Integrating the obtained event representation vectors into a set integrated representation vector and loading it into a pre-debugged risk communication event detection network to obtain an event risk identification result, where the event risk identification result is used to indicate the confidence level of the corresponding communication node having a risk communication event in the corresponding communication session cycle, and the risk communication event detection network is a trained deep learning model, including a Transformer module and a dense connection module; the step of integrating the obtained event representation vectors into a set integrated representation vector and loading it into a pre-debugged risk communication event detection network to obtain an event risk identification result includes: integrating the obtained event representation vectors into a set integrated representation vector; through the Transformer module, weight focusing integration processing is carried out on the set integrated representation vector to obtain a weight focusing integration vector; through the dense connection module, projection prediction is carried out on the weight focusing integration vector to obtain the event risk identification result.
2. The method according to claim 1, wherein The step of for each communication event covered by the communication event set, respectively carrying out feature transformation according to the corresponding event features to obtain a transformed feature set includes: For each communication event covered by the set of communication events, based on the event characteristics of the communication event, convert the communication event into an event identifier in a preset set of event identifiers, where the event identifiers corresponding to communication events with different characteristics are different; Use the set composed of the obtained event identifiers as the transformation feature set, where each event identifier is a set data unit in the transformation feature set.
3. The method according to claim 2, wherein The process of mining the event representation vector of the set data unit by integrating the vectorized feature of the set data unit and the event representation vector of its previous set data unit through the corresponding long short-term memory network layer includes: Load the vectorized feature of the set data unit and the event representation vector of its previous set data unit into the long short-term memory network layer corresponding to the set data unit respectively; Sum the corresponding units in the vectorized feature and the event representation vector to obtain a feature integration result; Extract features from the feature integration result through the long short-term memory network layer to obtain the event representation vector of the set data unit; The process of obtaining the vectorized feature of the set data unit by vectorizing and transforming the set data unit through the vectorization module includes: For each set data unit, convert the set data unit into a vectorized feature according to the vectorized feature mapping relationship obtained by pre-debugging the vectorization module. The vectorized feature mapping relationship includes the vectorized feature corresponding to each set data unit, where pre-debugging is the process of pre-training.
4. The method according to claim 1, wherein The method further includes: Among the obtained event risk recognition results, determine the event risk recognition results greater than the risk reference value as the target event risk recognition results; Based on the determined target event risk recognition results, determine the security management mechanism of the corresponding communication node; and perform communication management based on the security management mechanism.
5. The method according to any one of claims 1 to 4, characterized in that, The training process of the event representation information mining network and the risk communication event detection network includes: Obtain a plurality of debugging learning examples, where each debugging learning example is a set composed of a set number of communication events triggered by the same example communication node in an example communication session period; For each debugging learning example, for each communication event covered by the debugging learning example, perform feature transformation according to the corresponding event characteristics respectively to obtain a transformation feature set; through the event representation information mining network to be debugged, mine the event representation vectors of each set data unit covered by the transformation feature set respectively. Each event representation vector is obtained by combining the vectorized feature after transformation of the corresponding set data unit and the event representation vector of its previous set data unit; integrate the obtained event representation vectors into a set integration representation vector, and load it into the risk communication event detection network to be debugged to obtain a target event risk recognition result, where the target event risk recognition result is used to indicate the confidence level of the corresponding example communication node having a risk communication event in the corresponding example communication session period; Based on the obtained target event risk identification results and corresponding prior risk markers, optimize the network parameter variables of the event characterization information mining network and the risk communication event detection network.
6. The method according to claim 5, wherein The event characterization information mining network includes a first dense connection module; The method further includes: For each debugging learning example, project and predict the event characterization vector of the last set data unit in the corresponding transformed feature set through the first dense connection module to obtain a predicted event risk identification result, where the predicted event risk identification result is used to indicate the confidence level of the corresponding example communication node having a risk communication event in the corresponding example communication session period; The optimizing the network parameter variables of the event characterization information mining network and the risk communication event detection network based on the obtained target event risk identification results and corresponding prior risk markers includes: Based on the obtained target event risk identification results, predicted event risk identification results and corresponding prior risk markers, optimize the network parameter variables of the event characterization information mining network and the risk communication event detection network.
7. The method according to claim 6, wherein The optimizing the network parameter variables of the event characterization information mining network and the risk communication event detection network based on the obtained target event risk identification results, predicted event risk identification results and corresponding prior risk markers includes: In the first debugging session, determine a first training cost based on the error between the obtained predicted event risk identification results and the corresponding prior risk markers; based on the first training cost, optimize the network parameter variables of the event characterization information mining network; where the first training cost reflects the performance of the event characterization information mining network under the current parameter configuration; In the second debugging session, determine a second training cost based on the error between the obtained target event risk identification results and the corresponding prior risk markers; based on the second training cost, optimize the network parameter variables of the risk communication event detection network; where the second training cost reflects the performance of the risk communication event detection network under the current parameter configuration; The optimizing the network parameter variables of the event characterization information mining network and the risk communication event detection network based on the obtained target event risk identification results and corresponding prior risk markers includes: Determine a second training cost based on the error between the obtained target event risk identification results and the corresponding prior risk markers; Based on the second training cost, synchronously optimize the network parameter variables of the event characterization information mining network and the risk communication event detection network.
8. The method according to claim 7, wherein The obtaining the transformed feature set by respectively performing feature transformation on each communication event covered by the debugging learning example according to the corresponding event feature includes: For each communication event covered by the debugging learning example, based on the event feature of the communication event, convert the communication event into an event identifier in a preset event identifier set, where the event identifiers corresponding to communication events with different features are different; The set composed of the obtained event identifiers is used as the transformation feature set, where each event identifier is a set data unit in the transformation feature set; The event characterization information mining network includes a vectorization module and a long short-term memory network module. The number of network layers of the long short-term memory network module is equal to the number of features in the transformation feature set, and each long short-term memory network layer corresponds to a set data unit in the transformation feature set; Mining the event characterization vectors of each set data unit covered by the transformation feature set respectively through the event characterization information mining network to be debugged, including: For each set data unit in the transformation feature set, the following steps are respectively performed: Through the vectorization module, perform vectorization conversion on the set data unit to obtain the vectorization feature of the set data unit; Through the corresponding long short-term memory network layer, after integrating the vectorization feature of the set data unit with the event characterization vector of its previous set data unit, extract the event characterization vector of the set data unit; Among them, performing vectorization conversion on the set data unit through the vectorization module to obtain the vectorization feature of the set data unit includes: Through the vectorization module, perform random vector conversion on the set data unit to obtain the corresponding vectorization feature of the set data unit; When optimizing the network parameters of the event characterization information mining network, the method further includes: Jointly optimize the vectorization features obtained by performing random vector conversion on each set data unit respectively, and after the debugging is completed, form a vectorization feature mapping relationship with the vectorization features corresponding to each potential set data unit, so as to determine the vectorization feature of each set data unit according to the vectorization feature mapping relationship during the network inference stage; The risk communication event detection network includes a Transformer module and a second dense connection module; integrating the obtained event characterization vectors into a set integration characterization vector and loading it into the risk communication event detection network to be debugged to obtain the target event risk recognition result, including: Integrate the obtained event characterization vectors into a set integration characterization vector; Perform weight focusing integration processing on the set integration characterization vector through the Transformer module to obtain a weight focusing integration vector; Perform projection prediction on the weight focusing integration vector through the second dense connection module to obtain the target event risk recognition result.
9. A computer system, comprising a memory and a processor, the memory storing a computer program that can run on the processor, characterized in that, When the processor executes the program, it implements the steps in the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Time series data risk prediction method and system based on knowledge guidance, and application thereof
CN111370122A
Risk prediction method and system for time series data
CN111382930A