Encrypted malicious traffic detection method based on deep learning

By combining deep learning technologies such as LSTM, BERT and GraphSAGE, the timing and semantic features of network traffic are extracted and aggregated, and the problem of difficulty in detecting and distinguishing encrypted malicious traffic in the existing technology is solved, and higher detection accuracy and robustness are achieved.

CN120017304AActive Publication Date: 2025-05-16NANJING UNIV OF SCI & TECH

Patent Information

Application Number
CN202411952188.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-16
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

Existing encrypted malicious traffic detection methods based on deep learning ignore the correlation between traffic samples, making it difficult to effectively detect and distinguish encrypted traffic with similar characteristics but belong to different categories.

Method used

The LSTM model is used to extract the timing characteristics of network traffic data, and the semantic features are further extracted through the BERT model to form a comprehensive feature representation. Then, the DBSCAN algorithm is used to cluster the comprehensive features, build a graph structure, and apply the GraphSAGE graph neural network model to perform malicious traffic detection.

Benefits of technology

By capturing and aggregating the characteristics between traffic samples, the accuracy and robustness of malicious traffic detection is significantly improved, and potential attack behaviors in encrypted traffic can be more effectively identified and distinguished.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017304A_ABST
    Figure CN120017304A_ABST
Patent Text Reader

Abstract

The invention discloses an encrypted malicious traffic detection method based on deep learning, and the method comprises the steps: extracting time sequence features of network traffic data through an LSTM model, further extracting semantic features of the traffic data through a BERT model, and finally forming comprehensive feature representation; clustering the comprehensive feature representation by using a DBSCAN algorithm; optimizing sample labels in each cluster according to a defined naming rule, and classifying traffic types with similar attack characteristics into uniform labels; constructing a graph structure, performing edge connection on the optimized traffic sample labels and the comprehensive feature representation thereof, and establishing edge connection among different clusters according to cosine similarity; and constructing a GraphSAGE graph neural network model, performing information aggregation on nodes of a graph structure and neighbor nodes thereof to obtain an updated feature vector of each node, performing classification processing by using updated node features, and identifying whether the traffic is malicious encrypted traffic. According to the invention, the detection precision and robustness are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cyberspace security technology, and specifically is an encrypted malicious traffic detection method based on deep learning. Background Art

[0002] In recent years, with the rapid development of the Internet and the continuous improvement of network security technology, attackers have gradually turned to using encrypted traffic to carry out malicious activities. Encrypted traffic refers to network traffic transmitted through encryption protocols (such as HTTPS, TLS, etc.), and its main purpose is to protect user privacy and data security. However, attackers can also use encrypted traffic to hide their malicious activities, making it difficult for traditional network security protection measures based on plaintext analysis to effectively detect and prevent these attacks. Malicious encrypted traffic may be used to implement a variety of attack types, such as data theft, distributed denial of service (DDoS) attacks, and malware propagation. In addition, with the popularization of encryption technology, the proportion of encrypted traffic in Internet traffic continues to increase, further increasing the challenges to network security monitoring and analysis.

[0003] Traditional malicious traffic detection methods are gradually becoming ineffective in the face of encrypted transmission. The main reason is that they often rely on plaintext feature extraction and rule matching. When data traffic is encrypted by protocols such as HTTPS or TLS, the valid information that could have been directly parsed is hidden, making it difficult for detection methods based on specific keywords or traffic signatures to work. At the same time, simple statistical feature analysis cannot fully express the complex behavior patterns underlying encrypted traffic. Malicious actors can use disguised obfuscation methods to make the distribution characteristics of normal traffic very similar, thereby increasing the difficulty of detection. In addition, traditional methods lack the fusion of cross-temporal and semantic features, and cannot characterize the inherent correlation and potential semantic information of traffic from multiple angles. It is difficult to effectively identify hidden attack behaviors in massive, dynamic, and high-dimensional encrypted traffic. Unlike traditional detection methods based on manual feature extraction, deep learning models can automatically mine the implicit temporal, semantic, and spatial correlation characteristics in high-dimensional data, and have stronger feature modeling capabilities. In the feature modeling of encrypted traffic, deep learning not only shows higher adaptability and flexibility, but also can strengthen the similarity relationship between samples through multi-level representation learning, thereby improving the generalization ability and robustness of unknown malicious encrypted traffic with complex structure and variable types. However, the existing encrypted malicious traffic detection methods based on deep learning still face the following problems: First, the existing methods often ignore the implicit correlation between traffic samples and cannot fully utilize the spatial and temporal characteristics of traffic samples; second, the existing methods have certain limitations in the classification of encrypted traffic, especially when faced with encrypted traffic with similar characteristics but belonging to different categories, it is difficult to distinguish these minor differences. Summary of the invention

[0004] The purpose of the present invention is to propose a malicious encrypted traffic detection method based on deep learning to detect encrypted malicious traffic.

[0005] The technical solution to implement the present invention is: a method for detecting encrypted malicious traffic based on deep learning, comprising the following steps:

[0006] Step 1: Use the LSTM model to extract the temporal features of network traffic data, and use the BERT model to further extract the semantic features of the traffic data, and finally form a comprehensive feature representation;

[0007] Step 2: Cluster the comprehensive feature representation using the DBSCAN algorithm to divide the network traffic data samples into different clusters based on feature similarity, where each cluster represents a potential encrypted traffic type.

[0008] Step 3: Optimize the sample labels in each cluster according to the defined naming rules to achieve fuzzy classification of traffic labels and classify traffic types with similar attack characteristics into a unified label;

[0009] Step 4: Build a graph structure, connect the optimized traffic sample labels and their comprehensive feature representations, and establish edge connections between different clusters based on cosine similarity to form a complete graph model;

[0010] Step 5: Build a GraphSAGE graph neural network model, aggregate information on the nodes of the graph structure and their neighboring nodes to obtain an updated feature vector for each node, and use the updated node features to perform classification processing to identify whether it is malicious encrypted traffic;

[0011] Step 6: Train the GraphSAGE graph neural network model and classifier through back propagation and optimization algorithms, and perform malicious traffic detection on new network traffic samples.

[0012] Furthermore, in step 1, the LSTM model is used to extract the temporal features of the network traffic data, and the BERT model is used to further extract the semantic features of the traffic data, and finally a comprehensive feature representation is formed. The specific method is as follows:

[0013] Step 1-1: First, collect raw network traffic data from network monitoring devices, log systems or other data sources, including protocol type, packet size, latency, source IP address, destination IP address and transmission port, and pre-process the collected traffic data, including removing noise, filling missing values ​​and standardizing operations;

[0014] Step 1-2: Arrange the preprocessed network traffic data in chronological order to form time series data, and use the LSTM model to process these time series data to extract the key time series features in the traffic data;

[0015] Step 1-3: Input the time series feature vector extracted by the LSTM model into the BERT model, and use its self-attention mechanism to analyze the contextual semantic information of the traffic data and further extract the semantic features of the traffic;

[0016] Step 1-4: Use the feature concatenation method to fuse the temporal features extracted by LSTM with the semantic features extracted by BERT to form a comprehensive feature representation vector.

[0017] Furthermore, in step 2, the DBSCAN algorithm is used to cluster the comprehensive feature representation, and the network traffic data samples are divided into different clusters according to feature similarity. Each cluster represents a potential encrypted traffic type. The specific method is as follows:

[0018] Step 2-1: Use the DBSCAN algorithm to calculate the neighborhood density of each traffic sample, identify the area with higher density as the core point, determine the density connection samples around the core point according to the preset neighborhood radius and density threshold, and use these density connection samples to classify traffic samples with similar characteristics into the same category;

[0019] Step 2-2: Assign a unique cluster label to each cluster, representing the potential encrypted traffic type;

[0020] Step 2-3: Record the cluster label of each traffic sample and generate a data set containing traffic samples and their corresponding cluster labels.

[0021] Furthermore, in step 3, the sample labels in each cluster are optimized according to the defined naming rules to achieve fuzzy classification of traffic labels and classify traffic types with similar attack characteristics into unified labels. The specific method is as follows:

[0022] Step 3-1: Develop a unified naming convention, including:

[0023] Denial of Service Attacks: including DoS and DDoS.

[0024] Data Exfiltration: including DNS tunneling and HTTP tunneling.

[0025] Malware Traffic: includes RAT traffic and virus transmission traffic.

[0026] Network Scanning: Includes port scanning and network reconnaissance traffic.

[0027] Phishing Attacks: includes phishing emails and phishing website traffic.

[0028] Unknown: used to identify unclassified noise points or traffic samples of unknown types.

[0029] Step 3-2: Map each cluster label to the corresponding unified label according to the defined naming rules.

[0030] Furthermore, in step 4, a graph structure is constructed to connect the optimized traffic sample labels and their comprehensive feature representations, and to establish edge connections between different clusters based on cosine similarity to form a complete graph model. The specific method is as follows:

[0031] Step 4-1: Aggregate the edge information within and across clusters to build a complete graph model. The nodes in the graph represent network traffic samples, and the edges represent the similarity relationship between samples.

[0032] Step 4-2: For each cluster, establish edges between samples in the cluster based on cosine similarity. The specific steps are as follows:

[0033] Traverse each cluster and obtain the feature vectors of all samples in the cluster, including protocol type, packet size, and latency. Calculate the cosine similarity between any two samples in the cluster. If the cosine similarity of two samples is greater than the preset threshold θ, an edge is established between the two nodes, indicating that they have a high feature similarity. Otherwise, no edge is established.

[0034] Step 4-3: Establish edges between different clusters. The specific operations are as follows:

[0035] Traverse the sample pairs between different clusters and calculate the cosine similarity between them. If the cosine similarity between samples of two different clusters is greater than the threshold θ, an edge is established between the two nodes, otherwise no edge is established.

[0036] Furthermore, in step 5, a GraphSAGE graph neural network model is constructed to aggregate information of the nodes of the graph structure and their neighboring nodes to obtain an updated feature vector of each node, and the updated node features are used for classification processing to identify whether it is malicious encrypted traffic. The specific method is as follows:

[0037] Step 5-1: Construct a GraphSAGE graph neural network model, which is composed of multiple GraphSAGE layers connected in series. Each GraphSAGE layer includes a neighbor sampling module, a feature aggregation module, and a feature transformation module, wherein:

[0038] Neighbor sampling module: for each target node v, randomly samples a fixed number of neighbor nodes from its neighbor node set N(v) to generate a sampled neighbor feature subset Output the sampled neighbor feature set N(X k-1), the sampled neighbor feature N(X k-1 ) Enter the feature aggregation module;

[0039] The feature aggregation module contains three submodules: mean aggregation, maximum aggregation and LSTM aggregation. The mean aggregation module averages the feature vectors of the sampled neighbors element by element to generate the mean aggregation feature f mean ; The maximum aggregation module extracts the maximum value of the neighbor features element by element and generates the maximum aggregation feature f max ; LSTM aggregation module converts neighbor feature sequence Input into the LSTM network for sequence processing, and output the fixed-dimensional LSTM aggregation feature f LSTM The output of the feature aggregation module is the comprehensive aggregated feature vector [f mean ,f max ,f LSTM ], the comprehensive aggregate feature vector [f mean ,f max ,f LSTM ] is passed to the feature transformation module;

[0040] In the feature transformation module, the aggregated features are transformed by the linear transformation matrix W k Perform linear transformation and process it through ReLU activation function σ to generate new node feature representation The specific update formula is:

[0041]

[0042] Where AGGREGATE represents the selected aggregation operation, σ selects the ReLU activation function, Represents the feature representation of node v at layer k;

[0043] Output of the feature transformation module Will be used as input X for the next GraphSAGE layer k , continue the process of neighbor sampling and feature aggregation, through layer-by-layer stacking, the node features gradually merge the information from a larger range of neighbors to generate the final node feature matrix X n ;

[0044] Step 5-2: The classifier consists of a fully connected layer that receives X n And through a series of linear transformations, the classification output Y is generated to determine whether each node is malicious encrypted traffic.

[0045] Furthermore, in step 6, the GraphSAGE graph neural network model and classifier are trained through back propagation and optimization algorithms to detect malicious traffic on new network traffic samples. The specific method is as follows:

[0046] The labeled training data is used to optimize the parameters of the GraphSAGE model and classifier through the back-propagation mechanism and the Adam optimizer. During the optimization process, the learning rates of the generator and the discriminator are set to 0.001, the momentum parameters β1 and β2 are set to 0.9 and 0.999 respectively, and the batch size is set to 8.

[0047] A deep learning-based encrypted malicious traffic detection system implements the deep learning-based encrypted malicious traffic detection method to achieve deep learning-based encrypted malicious traffic detection, and is divided into six modules to respectively execute steps 1 to 6.

[0048] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for detecting encrypted malicious traffic based on deep learning is implemented to achieve detection of encrypted malicious traffic based on deep learning.

[0049] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the method for detecting encrypted malicious traffic based on deep learning is implemented to achieve encrypted malicious traffic detection based on deep learning.

[0050] Compared with the prior art, the present invention has the significant advantage that by constructing a graph structure between traffic samples, the features of neighboring samples can be effectively captured and aggregated, thereby strengthening the mining of similar relationships between traffic flows and improving the detection accuracy and robustness of malicious traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 The flowchart of the encrypted malicious traffic detection method based on deep learning is shown in FIG.

[0052] Figure 2 Schematic diagram of extracting comprehensive features for LSTM and BERT

[0053] Figure 3 Schematic diagram of fuzzy classification

[0054] Figure 4 Constructing a schematic for a graph

[0055] Figure 5 GraphSAGE structure diagram DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0057] like Figure 1 As shown, a method for detecting encrypted malicious traffic based on deep learning includes the following steps:

[0058] Step 1: Collect network traffic data. First, use the LSTM model to extract time series features. Then use the time series features as input to further extract the semantic features of the traffic data through the BERT model, and finally form a comprehensive feature representation.

[0059] Step 1-1: First, collect raw network traffic data from network monitoring devices, log systems or other data sources. This data usually contains a variety of information, such as protocol type, packet size, latency, source IP address, destination IP address, transmission port, etc. In order to ensure the comprehensiveness and accuracy of the data, the collected traffic data needs to be preprocessed, including noise removal, missing value filling and standardization.

[0060] Step 1-2: If Figure 2 As shown in the figure, the preprocessed network traffic data is arranged in chronological order to form time series data. Then, the LSTM (Long Short-Term Memory Network) model is used to process these time series data. LSTM can effectively capture the time series dynamic features in the data and identify the patterns and trends of traffic changes. Specifically, the LSTM model can remember the data dependencies over a long time span through its memory units, thereby extracting the key time series features in the traffic data. These feature vectors will be used as input for the next step of semantic feature extraction.

[0061] Step 1-3: Input the time series feature vector extracted by the LSTM model into the BERT (Bidirectional Encoder Representation Transformer) model. The BERT model can analyze the contextual semantic information of the traffic data through its self-attention mechanism and further extract the semantic features of the traffic. This process not only enhances the expressive power of the features, but also enables the model to understand the implicit semantic relationships in the traffic data. These semantic feature vectors are combined with the time series feature vectors to form a comprehensive feature representation.

[0062] Step 1-4: Finally, the temporal features extracted by LSTM are fused with the semantic features extracted by BERT to form a comprehensive feature representation vector. The specific fusion method adopts the feature splicing method. The comprehensive feature representation vector will be used as the input for subsequent clustering analysis, providing a rich feature basis for malicious traffic detection.

[0063] Step 2: Use the DBSCAN algorithm to perform cluster analysis on the above comprehensive features, divide the samples into different clusters according to feature similarity, and output the cluster label to which each sample belongs.

[0064] Step 2-1: Use the DBSCAN algorithm to perform cluster analysis on the comprehensive feature representation vector. DBSCAN can effectively identify traffic clusters with different feature patterns by evaluating the density similarity between samples. First, set the parameters of the DBSCAN algorithm, including the neighborhood radius (eps) and the minimum number of samples (min_samples). Then, the algorithm scans each sample to determine whether its neighborhood contains at least min_samples samples, thereby identifying core points, boundary points, and noise points.

[0065] Step 2-2: Divide samples with similar characteristics into the same cluster and assign a unique label to each cluster (e.g. 1, 2, 3...). For samples identified as noise points, a special label (e.g. -1) is assigned to indicate that these samples do not belong to any cluster. In this way, cluster analysis not only achieves the grouping of traffic samples, but also lays the foundation for subsequent label optimization and graph structure construction.

[0066] Step 2-3: Match the clustering results with the original traffic samples to form a cluster label mapping relationship. The specific operation includes recording the cluster label of each traffic sample and generating a data set containing traffic samples and their corresponding cluster labels. This step ensures that the clustering information of each sample is accurately recorded, which facilitates subsequent label optimization and graph structure construction.

[0067] Step 3: Optimize the sample labels in each cluster according to the defined naming rules, so as to achieve fuzzy classification of traffic labels, that is, classify similar traffic samples into similar labels.

[0068] Step 3-1: Establish unified classification and naming rules, such as Figure 3 As shown in the figure, traffic types with similar attack characteristics are classified into a unified label. The specific rules include:

[0069] 1) Denial of Service Attacks: including DoS (denial of service attack) and DDoS (distributed denial of service attack).

[0070] 2) Data Exfiltration: including DNS tunneling and HTTP tunneling.

[0071] 3) Malware Traffic: includes RAT (Remote Access Trojan) traffic and virus transmission traffic.

[0072] 4) Network Scanning: includes port scanning and network reconnaissance traffic.

[0073] 5) Phishing Attacks: includes phishing emails and phishing website traffic.

[0074] 6) Unknown: used to identify unclassified noise points or traffic samples of unknown types.

[0075] Step 3-2: Map each cluster label to the corresponding unified label according to the defined naming rules. The specific steps are as follows:

[0076] 1) Traverse each cluster label and map it to a predefined unified label based on the attack characteristics it represents. 2) For example, if cluster label 0 represents DoS and DDoS attacks, map cluster label 0 to "Denial of Service Attacks".

[0077] Step 3-3: For the noise points marked as -1 in the DBSCAN algorithm, assign the label "Unknown", indicating that these samples cannot be classified into any defined attack type. This ensures that all traffic samples have corresponding labels, which is convenient for subsequent detection and analysis.

[0078] Step 4: Build the graph structure, such as Figure 4 As shown in the figure, the optimized traffic sample labels and their comprehensive feature representations are edge-connected, and edge connections are established between different clusters based on cosine similarity, thus forming a complete graph model.

[0079] Step 4-1: Aggregate the edge information within and across clusters to build a complete graph model. The nodes in the graph represent network traffic samples, and the edges represent the similarity relationship between samples.

[0080] Step 4-2: For each cluster, establish edges between samples in the cluster based on cosine similarity. The specific steps are as follows:

[0081] 1) Traverse each cluster and obtain the feature vectors of all samples in the cluster.

[0082] 2) Calculate the cosine similarity between any two samples in the cluster.

[0083] 3) If the cosine similarity of two samples is greater than the preset threshold θ, an edge is established between the two nodes.

[0084] It means they have high feature similarity.

[0085] Step 4-3: In order to further enhance the expressiveness of the graph structure, edges are also established between different clusters.

[0086] The specific operations are as follows:

[0087] 1) Traverse the sample pairs between different clusters and calculate the cosine similarity between them.

[0088] 2) If the cosine similarity between samples from two different clusters is greater than the threshold θ, an edge is established between the two nodes.

[0089] Step 5: Apply the GraphSAGE graph neural network model. The GraphSAGE graph neural network model is composed of multiple GraphSAGE layers connected in series. Each GraphSAGE layer includes a neighbor sampling module, a feature aggregation module (including mean aggregation, maximum aggregation and LSTM aggregation) and a feature transformation module, such as Figure 5 shown.

[0090] First, the initial node feature vector After the sample label optimization in step 3, a new feature matrix X is formed k-1 , passed to the neighbor sampling module. This module randomly samples a fixed number of neighbor nodes from its neighbor node set N(v) for each target node v, and generates a sampled neighbor feature subset Output the sampled neighbor feature set N(X k-1 ).

[0091] Next, the sampled neighbor feature N(X k-1 ) Enter the feature aggregation module. This module contains three submodules: mean aggregation, maximum aggregation and LSTM aggregation. The mean aggregation module averages the feature vectors of the sampled neighbors element by element to generate the mean aggregation feature f mean ; The maximum aggregation module extracts the maximum value of the neighbor features element by element and generates the maximum aggregation feature f max ; LSTM aggregation module converts neighbor feature sequence Input into the LSTM network for sequence processing, and output the fixed-dimensional LSTM aggregation feature f LSTM The output of the feature aggregation module is a comprehensive aggregated feature vector [f mean ,f max ,f LSTM ].

[0092] Then, the comprehensive aggregate feature vector [f mean ,f max ,f LSTM ] is passed to the feature transformation module. In the feature transformation module, the aggregated features are transformed by the linear transformation matrix W k Perform linear transformation and process it through ReLU activation function σ to generate new node feature representation The specific update formula is: Where AGGREGATE represents the selected aggregation operation, σ selects the ReLU activation function, Represents the feature representation of node v at the kth layer. Output of the feature transformation module Will be used as input X for the next GraphSAGE layer k , continue the process of neighbor sampling and feature aggregation. Through layer-by-layer stacking, node features gradually merge information from a wider range of neighbors to generate the final node feature matrix X n .

[0093] Finally, the node feature matrix X n is passed to the classification module. The classification module consists of a fully connected layer that receives X n A series of linear transformations are used to generate the classification output Y, which is used to determine whether each node is malicious encrypted traffic. During the model training process, the labeled training data is used to optimize the parameters of the GraphSAGE model and classifier through the back-propagation mechanism and the Adam optimizer. During the optimization process, the learning rates of the generator and the discriminator are set to 0.001, the momentum parameters β1 and β2 are set to 0.9 and 0.999 respectively, and the batch size is set to 8.

[0094] The present invention also proposes an encrypted malicious traffic detection system based on deep learning, implements the encrypted malicious traffic detection method based on deep learning, realizes encrypted malicious traffic detection based on deep learning, and executes steps 1 to 6 respectively in six modules.

[0095] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for detecting encrypted malicious traffic based on deep learning is implemented to achieve detection of encrypted malicious traffic based on deep learning.

[0096] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the method for detecting encrypted malicious traffic based on deep learning is implemented to achieve encrypted malicious traffic detection based on deep learning.

[0097] Example

[0098] Combination Figure 1 This embodiment performs malicious encrypted traffic detection based on the deep learning-based encrypted malicious traffic detection method proposed by the present invention, and the steps are as follows:

[0099] 1. Dataset selection: This example uses the CIC-IDS2017 dataset as the experimental object. The CIC-IDS2017 dataset contains various types of network traffic, including normal traffic and various known malicious traffic (such as DoS attacks, DDoS attacks, data leakage, malware propagation, etc.). This dataset is widely used in network security research, has high authenticity and diversity, and is suitable as an evaluation benchmark for malicious traffic detection methods.

[0100] 2. Data preprocessing: Network traffic records are extracted from the CIC-IDS2017 dataset, including features such as protocol type, packet size, latency, source IP address, destination IP address, and transmission port. Outliers and duplicate records are removed, missing values ​​are filled by the mean imputation method, and numerical features are standardized using Z-score standardization.

[0101] 3. Feature extraction and fusion: First, the preprocessed traffic data is arranged in chronological order to form time series data. Next, a model containing two layers of LSTM units is constructed to extract the time series features of each time step and generate a time series feature vector. Then, the time series feature vector extracted by LSTM is used as input to the pre-trained BERT model to further extract semantic features. Finally, the feature splicing method is used to fuse the time series features extracted by LSTM with the semantic features extracted by BERT to form a comprehensive feature representation vector.

[0102] 4. Cluster analysis: Set the neighborhood radius (eps) of DBSCAN to 0.5 and the minimum number of samples (min_samples) to 10. Apply the DBSCAN algorithm to cluster the comprehensive feature representation vector, divide the traffic samples into different clusters, and assign a -1 label to the noise points. According to the predefined naming rules, map each cluster label to a unified attack category label (such as "Denial of Service Attacks", "Data Exfiltration", etc.), and mark the noise points as "Unknown".

[0103] 5. Graph construction based on cosine similarity: Each network traffic sample is taken as a node in the graph. The cosine similarity between samples in each cluster is calculated. If the similarity is greater than the threshold θ (set to 0.8), an edge is established between the corresponding nodes. Similarly, the cosine similarity of samples between different clusters is calculated. If the similarity is greater than θ, an edge is established between these nodes. Finally, a graph structure containing nodes and edges is formed. The edges between nodes reflect the feature similarity between traffic samples.

[0104] 6. Application of GraphSAGE model: Build a graph neural network model with two layers of GraphSAGE, using mean aggregation as the feature aggregation function. Each layer of GraphSAGE model samples a fixed number of neighbor nodes from the neighbors of each node, aggregates the feature information of the neighbor nodes through the GraphSAGE layer, and updates the feature representation of the node. A fully connected layer is connected to the output layer of GraphSAGE to output the classification result of each node (malicious traffic or normal traffic). The Adam optimizer is used, the learning rate is set to 0.001, and the cross entropy loss function is minimized through back propagation. The GraphSAGE model is trained using labeled training data and iterated for 50 epochs.

[0105] 7. Experimental setting: The CIC-IDS2017 dataset is divided into a training set (70%) and a test set (30%). Accuracy, precision, recall and F1-score are used as the main evaluation indicators.

[0106] 8. Experimental results: This embodiment is verified by systematic experiments, as shown in Table 1, which demonstrates the excellent performance of the encrypted malicious traffic detection method based on deep learning in practical applications. Compared with traditional single feature extraction or traditional machine learning methods, the method proposed in this paper achieves significant performance improvement through multi-level feature fusion, effective clustering analysis and the application of graph neural networks.

[0107] Table 1 Experimental results

[0108]

[0109] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0110] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for detecting encrypted malicious traffic based on deep learning, characterized in that: The following steps are involved: Step 1: Use the LSTM model to extract the temporal features of network traffic data, and use the BERT model to further extract the semantic features of the traffic data, and finally form a comprehensive feature representation; Step 2: Cluster the comprehensive feature representation using the DBSCAN algorithm to divide the network traffic data samples into different clusters based on feature similarity, where each cluster represents a potential encrypted traffic type. Step 3: Optimize the sample labels in each cluster according to the defined naming rules to achieve fuzzy classification of traffic labels and classify traffic types with similar attack characteristics into a unified label; Step 4: Build a graph structure, connect the optimized traffic sample labels and their comprehensive feature representations, and establish edge connections between different clusters based on cosine similarity to form a complete graph model; Step 5: Build a GraphSAGE graph neural network model, aggregate information on the nodes of the graph structure and their neighboring nodes to obtain an updated feature vector for each node, and use the updated node features to perform classification processing to identify whether it is malicious encrypted traffic; Step 6: Train the GraphSAGE graph neural network model and classifier through back propagation and optimization algorithms, and perform malicious traffic detection on new network traffic samples.

2. According to the method for detecting encrypted malicious traffic based on deep learning in claim 1, it is characterized in that: Step 1: Use the LSTM model to extract the temporal features of network traffic data, and use the BERT model to further extract the semantic features of the traffic data, and finally form a comprehensive feature representation. The specific method is as follows: Step 1-1: First, collect raw network traffic data from network monitoring devices, log systems or other data sources, including protocol type, packet size, latency, source IP address, destination IP address and transmission port, and pre-process the collected traffic data, including removing noise, filling missing values ​​and standardizing operations; Step 1-2: Arrange the preprocessed network traffic data in chronological order to form time series data, and use the LSTM model to process these time series data to extract the key time series features in the traffic data; Step 1-3: Input the time series feature vector extracted by the LSTM model into the BERT model, and use its self-attention mechanism to analyze the contextual semantic information of the traffic data and further extract the semantic features of the traffic; Step 1-4: Use the feature concatenation method to fuse the temporal features extracted by LSTM with the semantic features extracted by BERT to form a comprehensive feature representation vector.

3. The method for detecting encrypted malicious traffic based on deep learning according to claim 1 is characterized in that: Step 2: Cluster the comprehensive feature representation using the DBSCAN algorithm to divide the network traffic data samples into different clusters based on feature similarity. Each cluster represents a potential encrypted traffic type. The specific method is as follows: Step 2-1: Use the DBSCAN algorithm to calculate the neighborhood density of each traffic sample, identify the area with higher density as the core point, determine the density connection samples around the core point according to the preset neighborhood radius and density threshold, and use these density connection samples to classify traffic samples with similar characteristics into the same category; Step 2-2: Assign a unique cluster label to each cluster, representing the potential encrypted traffic type; Step 2-3: Record the cluster label of each traffic sample and generate a data set containing traffic samples and their corresponding cluster labels.

4. The method for detecting encrypted malicious traffic based on deep learning according to claim 1 is characterized in that: Step 3: Optimize the sample labels in each cluster according to the defined naming rules to achieve fuzzy classification of traffic labels and classify traffic types with similar attack characteristics into unified labels. The specific method is as follows: Step 3-1: Develop a unified naming convention, including: Denial of Service Attacks: including DoS and DDoS. Data Exfiltration: including DNS tunneling and HTTP tunneling. Malware Traffic: includes RAT traffic and virus transmission traffic. Network Scanning: Includes port scanning and network reconnaissance traffic. Phishing Attacks: includes phishing emails and phishing website traffic. Unknown: used to identify unclassified noise points or traffic samples of unknown types. Step 3-2: Map each cluster label to the corresponding unified label according to the defined naming rules.

5. The method for detecting encrypted malicious traffic based on deep learning according to claim 1 is characterized in that: Step 4: Build a graph structure, connect the optimized traffic sample labels and their comprehensive feature representations, and establish edge connections between different clusters based on cosine similarity to form a complete graph model. The specific method is as follows: Step 4-1: Aggregate the edge information within and across clusters to build a complete graph model. The nodes in the graph represent network traffic samples, and the edges represent the similarity relationship between samples. Step 4-2: For each cluster, establish edges between samples in the cluster based on cosine similarity. The specific steps are as follows: Traverse each cluster and obtain the feature vectors of all samples in the cluster, including protocol type, packet size, and latency. Calculate the cosine similarity between any two samples in the cluster. If the cosine similarity of two samples is greater than the preset threshold θ, an edge is established between the two nodes, indicating that they have a high feature similarity. Otherwise, no edge is established. Step 4-3: Establish edges between different clusters. The specific operations are as follows: Traverse the sample pairs between different clusters and calculate the cosine similarity between them. If the cosine similarity between samples of two different clusters is greater than the threshold θ, an edge is established between the two nodes, otherwise no edge is established.

6. The method for detecting encrypted malicious traffic based on deep learning according to claim 1, characterized in that: Step 5: Build a GraphSAGE graph neural network model, aggregate information on the nodes of the graph structure and their neighboring nodes to obtain an updated feature vector for each node, and use the updated node features for classification processing to identify whether it is malicious encrypted traffic. The specific method is as follows: Step 5-1: Construct a GraphSAGE graph neural network model, which is composed of multiple GraphSAGE layers connected in series. Each GraphSAGE layer includes a neighbor sampling module, a feature aggregation module, and a feature transformation module, wherein: Neighbor sampling module: for each target node v, randomly samples a fixed number of neighbor nodes from its neighbor node set N(v) to generate a sampled neighbor feature subset Output the sampled neighbor feature set N(X k-1 ), the sampled neighbor feature N(X k-1 ) Enter the feature aggregation module; The feature aggregation module contains three submodules: mean aggregation, maximum aggregation and LSTM aggregation. The mean aggregation module averages the feature vectors of the sampled neighbors element by element to generate the mean aggregation feature f mean ; The maximum aggregation module extracts the maximum value of the neighbor features element by element and generates the maximum aggregation feature f max ; LSTM aggregation module converts neighbor feature sequence Input into the LSTM network for sequence processing, and output the fixed-dimensional LSTM aggregation feature f LSTM The output of the feature aggregation module is the comprehensive aggregated feature vector [f mean , f max , f LSTM ], the comprehensive aggregate feature vector [f mean , f max , f LSTM ] is passed to the feature transformation module; In the feature transformation module, the aggregated features are transformed by the linear transformation matrix W k Perform linear transformation and process it through ReLU activation function σ to generate new node feature representation The specific update formula is: Where AGGREGATE represents the selected aggregation operation, σ selects the ReLU activation function, Represents the feature representation of node v at layer k; Output of the feature transformation module Will be used as input X for the next GraphSAGE layer k , continue the process of neighbor sampling and feature aggregation, through layer-by-layer stacking, the node features gradually merge the information from a larger range of neighbors to generate the final node feature matrix X n ; Step 5-2: The classifier consists of a fully connected layer that receives X n And through a series of linear transformations, the classification output Y is generated to determine whether each node is malicious encrypted traffic.

7. The method for detecting encrypted malicious traffic based on deep learning according to claim 1, characterized in that: Step 6: Train the GraphSAGE graph neural network model and classifier through back propagation and optimization algorithms, and perform malicious traffic detection on new network traffic samples. The specific method is as follows: The labeled training data is used to optimize the parameters of the GraphSAGE model and classifier through the back-propagation mechanism and the Adam optimizer. During the optimization process, the learning rates of the generator and the discriminator are set to 0.001, the momentum parameters β1 and β2 are set to 0.9 and 0.999 respectively, and the batch size is set to 8.

8. A deep learning-based encrypted malicious traffic detection system, characterized in that: Implement the deep learning-based encrypted malicious traffic detection method described in any one of claims 1-7 to realize deep learning-based encrypted malicious traffic detection, and perform steps 1 to 6 in six modules respectively.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the deep learning-based encrypted malicious traffic detection method according to any one of claims 1 to 7 is implemented to realize deep learning-based encrypted malicious traffic detection.

10. A computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for detecting encrypted malicious traffic based on deep learning according to any one of claims 1 to 7 is implemented to realize encrypted malicious traffic detection based on deep learning.

Citation Information

Patent Citations

  • System and method for controllable machine text generation architecture

    CA3081242A1

  • An encrypted Trojan horse detection method for an HTTPS hidden tunnel

    CN109698835A

  • Malicious encrypted traffic detection method based on graph analysis

    CN113691537A

  • Malicious software detection method based on API call sequence behavior multi-view fusion

    CN115982706A

  • Encrypted traffic network intrusion detection method based on ensemble learning

    CN116155572A

Cited By

  • Encrypted traffic analysis method based on interaction spatio-temporal characteristics

    CN120378219A

  • Industrial control system intrusion detection method based on category enhancement graph learning

    CN121309072A

  • Session-level malicious traffic detection method and system based on dynamic similarity graph

    CN121396673A