Abnormal flow detection method based on multilevel time-frequency decomposition and graph neural network

Through the combination of multi-level time-frequency decomposition and multi-scale graph neural network, the problem of insufficient accuracy and robustness of traditional methods in detecting complex and hidden network attacks is solved, and more efficient network traffic anomaly detection is achieved.

CN120017330AActive Publication Date: 2025-05-16UNIV OF ELECTRONICS SCI & TECH OF CHINA

Patent Information

Application Number
CN202510076543.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-05-16
Estimated Expiration
2045-01-16

AI Technical Summary

Technical Problem

Traditional network traffic anomaly detection methods are difficult to effectively separate and identify complex and hidden network attacks, resulting in insufficient detection accuracy and robustness.

Method used

Multi-level time-frequency decomposition technology is used to decompose network traffic data, combine Fourier transform to extract high-frequency and low-frequency components, and multi-scale graph neural networks are used for feature fusion and abnormal detection.

Benefits of technology

Through the combination of multi-level time-frequency decomposition and multi-scale graph neural network, complex features in network traffic can be captured more clearly, improving the accuracy and robustness of anomaly detection, and is especially suitable for real-time detection and prediction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017330A_ABST
    Figure CN120017330A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of computer information security, provides an abnormal traffic detection method based on multilevel time-frequency decomposition and a graph neural network, and aims to solve the problem that a traditional method is difficult to effectively separate and identify complex and hidden network attack traffic. The method comprises the following steps: collecting and preprocessing network flow data to form a multivariable time sequence; extracting high-frequency and low-frequency components of trend and seasonal components by utilizing seasonal and trend decomposition and combining a Fourier mask function; carrying out stationary processing and linear mapping on the extracted components to generate a new vector representation; and finally, modeling through a multi-scale graph neural network and carrying out anomaly detection. According to the method, the time-frequency decomposition and the graph neural network are combined, the complex space-time dependency relationship of the network flow can be accurately captured, the detection capability of abnormal behaviors with high concealment or time sequence correlation is remarkably improved, the method is suitable for real-time detection and prediction scenes, and efficient early warning and analysis support is provided for network security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer information security technology, and specifically relates to an abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network. Background Art

[0002] Cyber ​​security threats are becoming an important issue in network systems that cannot be ignored. With the rapid development of information technology, the frequency and complexity of network attacks are also increasing, which has posed a serious challenge to various network systems. At present, the means of network attacks against network systems are showing a trend of diversification and complexity, and the concealment of attack behaviors is gradually increasing. These attack behaviors are often mixed with the normal communication behaviors of network devices, making detection significantly more difficult. The traffic generated by such attack behaviors mixed in normal network communications is usually called abnormal network traffic, while the traffic carrying normal communication behaviors is called normal network traffic. Traditional solutions usually use intrusion detection systems, which can effectively detect various forms of network attacks, such as denial of service attacks, malware propagation, and vulnerability exploits, by analyzing network traffic to identify abnormal patterns.

[0003] However, with the continuous evolution of attack methods, existing intrusion detection technologies face many bottlenecks. Therefore, designing a more intelligent, efficient and real-time detection technology has become an important research topic in the field of network security. In recent years, in order to improve the performance of intrusion detection systems, many machine learning-based methods have been proposed, especially using artificial neural networks and other technologies to further improve the accuracy and efficiency of abnormal traffic detection by deeply analyzing massive network traffic features. These methods can not only identify known attacks, but also have certain generalization capabilities and can detect unknown attack patterns. The current network abnormal traffic detection methods are mainly divided into four categories: payload feature-based detection technology, flow feature-based detection methods, statistics-based detection methods, and machine learning-based detection methods. Traditional machine learning methods often rely on manual feature engineering when detecting network abnormal traffic, with weak generalization ability, limited performance when facing new attacks, high false alarm and false negative rates, and difficult to support real-time detection. In contrast, the detection method based on network traffic features has stronger generalization ability and adaptability through automatic feature extraction and deep analysis.

[0004] Abnormal network traffic detection based on network traffic features is a technical method to identify abnormal behavior by extracting and analyzing multidimensional features in network traffic. This method first captures features from network traffic data, such as traffic size, inter-packet time interval, communication frequency, protocol distribution, session duration, etc. These features can reflect the normal behavior patterns of network traffic as well as potential abnormal behaviors. These features can actually constitute multivariate time series data, which can be modeled and analyzed by machine learning or deep learning models to detect possible abnormal behaviors. The features extracted from network traffic data are essentially natural multivariate time series data, which have complex dynamic changes and significant nonlinear characteristics, including multi-level features such as long-term trends, periodic changes, and short-term fluctuations. The effective separation of these features has always been one of the important research directions. To address this problem, we propose a new separation method that efficiently separates different components in the time series through time series decomposition technology. On the basis of realizing component decoupling, each component and its relationship are modeled and analyzed separately, so as to more comprehensively explore the inherent laws of the time series and effectively improve the accuracy and robustness of anomaly detection.

[0005] Dynamic graph neural network is a type of model that specializes in processing graph structure data that changes over time. It can model the dynamic evolution of nodes, edges and overall structures in the graph and capture spatiotemporal dependencies. It combines the spatial feature extraction capabilities of traditional graph neural networks with time series analysis methods to mine deep feature patterns from dynamic changes. It has significant advantages in modeling dynamic complex relationships, extracting high-dimensional spatiotemporal features and improving prediction accuracy. In time series data analysis, dynamic graph neural networks are particularly outstanding. By modeling the dynamic changes of network traffic characteristics, the time evolution laws of nodes, edges and graph structures are embedded in the analysis, complex spatiotemporal dependencies are captured, and abnormal behaviors that are highly hidden or have time series correlation can be identified. Compared with traditional methods, it extracts multiple traffic features more accurately and improves the ability to detect abnormal traffic. It is particularly suitable for real-time detection and prediction application scenarios. Summary of the invention

[0006] The purpose of the present invention is to solve the problem that traditional network traffic anomaly detection methods are difficult to effectively separate and identify abnormal traffic when facing complex and hidden network attacks through multi-level time-frequency decomposition and multi-scale graph neural networks, thereby improving the accuracy and robustness of detection.

[0007] In order to achieve the above purpose, the present invention adopts the following technical solutions:

[0008] The present invention provides an abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network, comprising the following steps:

[0009] Step 1: Collect and preprocess network traffic data to obtain multivariate time series data;

[0010] Step 2: Perform seasonal and trend decomposition on the preprocessed multivariate time series data to obtain the trend component and seasonal component corresponding to the original multivariate time series;

[0011] Step 3, performing Fourier mask function calculation processing on the trend component and seasonal component extracted in step 2 to obtain high-frequency components and low-frequency components of the trend component and high-frequency components and low-frequency components of the seasonal component;

[0012] Step 4, perform stabilization processing on the high and low frequency components extracted in step 3 to obtain a vector after stabilization processing;

[0013] Step 5, embedding the high-frequency component and low-frequency component of the trend component and seasonal component obtained by the stabilization process in step 4 into a linear mapping process to obtain a new vector representation corresponding to the two;

[0014] Step 6: Perform vector embedding on the vector obtained in step 5 to perform graph neural network modeling to obtain a feature vector;

[0015] Step 7: Perform anomaly detection on the feature vector to obtain the final anomaly detection result.

[0016] In the above scheme, step 1 includes:

[0017] Step 1.1: Collect normal network traffic and abnormal network traffic data in the target network through traffic collection tools;

[0018] Step 1.2: pre-process the traffic data packets to remove duplicate, erroneous or incomplete data packets;

[0019] Step 1.3, dividing the collected traffic data into multiple independent flows according to the data packets;

[0020] Step 1.4, extract the timestamp, packet size, and protocol type features of each flow;

[0021] Step 1.5: Preprocess the feature data including data cleaning, formatting, invalidating data, and filling missing values;

[0022] Step 1.6: Arrange the extracted features along the time axis to form multivariate time series data;

[0023] In the above scheme, step 2 includes:

[0024] Step 2.1: The multivariate time series data obtained in step 1 is processed by the sliding average method to obtain the trend component and seasonal component respectively. Given the time series x(t), the trend component column T(t) and the seasonal column R(t) are calculated by the sliding average method, where k is the size of the sliding window:

[0025]

[0026] R(t)=x(t)-T(t)

[0028] In the above scheme, step 3 includes:

[0029] Step 3.1, by dividing the time window, perform Fourier transform on each window to obtain the frequency domain representation under the window, then calculate the amplitude spectrum average of the frequency domain data of all windows, then select the top α frequencies to construct the mask function, and finally obtain the mask function corresponding to the data set;

[0030] Step 3.2, the trend component extracted in step 2 is processed by using the above-mentioned mask function to obtain the high-frequency component and the low-frequency component of the trend component;

[0031] Step 3.3: The seasonal component extracted in step 2 is processed using the above-mentioned mask function to obtain the high-frequency component and the low-frequency component of the seasonal component.

[0032] In the above scheme, the mask function in step 3.1 is calculated by the following formula:

[0033]

[0034] Where X i.k [f] represents the value of the frequency domain signal of the kth time window of the ,th sample at frequency f, Sort(*) represents sorting, TopK(*) represents selecting the first K frequency components with the largest amplitude, represents rounding down, α is a scaling factor 0<α≤1, and K is the total number of frequency components.

[0035] In the above scheme, step 4 includes:

[0036] Step 4.1, perform stabilization processing on the high-frequency component and the low-frequency component of the seasonal component to obtain the stabilized data;

[0037] Step 4.2: Stabilize the high-frequency and low-frequency components of the trend component to obtain stabilized data.

[0038] In the above scheme, step 5 includes:

[0039] Step 5.1, concatenate the vectors of the high-frequency component and the low-frequency component of the stabilized trend component and the original data residual, and concatenate other optional supplementary features, and then map them to a new vector representation through a linear layer;

[0040] Step 5.2, concatenate the vectors of the high-frequency component and the low-frequency component of the stabilized seasonal component and the original data residual, and concatenate other optional supplementary features, and then map them to a new vector representation through a linear layer;

[0041] In the above scheme, step 5 includes:

[0042] Step 6.1: Input the generated high-dimensional feature representation into the graph neural network (GNN) module to start further processing of the features.

[0043] Step 6.2: Group high-dimensional features based on manually set fixed ratio rules.

[0044] Step 6.3: Apply 1D convolution operation to the features of each group, and use convolution kernels of different sizes to extract multi-scale features;

[0045] Step 6.4: Calculate the feature vector of the node through graph learning mechanisms (such as feature aggregation and information propagation).

[0046] In the above scheme, the multi-scale feature extraction in step 6.3 is calculated by the following formula:

[0047]

[0048] Among them, z i is the feature vector of the node, σ is the activation function, h i and h j is the node representation vector, W is the weight matrix, MLP expand (*) is the multi-layer perceptron extension function.

[0049] In the above scheme, step 7 includes:

[0050] Step 7.1, concatenate the feature vectors and input them into the anomaly detection module based on reconstruction error;

[0051] Step 7.2, identifying abnormal traffic through reconstruction error or anomaly scoring mechanism;

[0052] Step 7.3: Output the detection results, including the location, category and characteristics of the abnormal traffic.

[0053] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:

[0054] 1. Combination of multi-level time-frequency decomposition and Fourier transform: Network traffic data is decomposed into trend components and seasonal components through time series decomposition technology, and high-frequency and low-frequency components are extracted in combination with Fourier transform. This combination of technical means effectively solves the problem of separating complex time series features in network traffic data, and can more clearly capture long-term trends, periodic fluctuations and short-term abnormal signals, providing multi-level feature expressions for subsequent anomaly detection.

[0055] 2. Multi-scale graph neural network modeling: The feature vector after time-frequency decomposition is input into the graph neural network (GNN), and feature extraction is performed through multi-scale convolution kernels. This combination of technical means solves the problem that traditional methods are difficult to capture complex spatiotemporal dependencies, can more accurately extract potential patterns in network traffic, and improve the ability to detect abnormal behaviors that are highly concealed or have time-series correlation.

[0056] 3. Dynamic adjacency matrix construction and feature aggregation: Through the dynamic adjacency matrix construction mechanism in the graph neural network, the similarity scores between nodes are automatically learned, and multi-scale convolution kernels are combined for feature aggregation. This combination of technical means solves the limitations of traditional graph learning methods in processing dynamically changing data, can more efficiently capture complex relationships in network traffic data, and enhance the robustness of anomaly detection.

[0057] 4. Feature fusion and linear mapping: The high- and low-frequency components of the trend and seasonal components after time-frequency decomposition are spliced, and high-dimensional feature representation is generated through linear mapping. This combination of technical means solves the problem of information loss when multi-source features are fused, can completely retain the original expression form of the features, avoid introducing additional complexity, and thus generate a unified high-dimensional feature representation, providing richer feature information for subsequent anomaly detection.

[0058] 5. Anomaly detection module and reconstruction error mechanism: Through the anomaly detection module based on reconstruction error, the prediction results are compared with the actual traffic data to identify abnormal traffic. This combination of technical means solves the problem of high false alarm rate and missed alarm rate of traditional methods, and can more accurately identify abnormal traffic, output the location, category and characteristics of abnormal traffic, and provide real-time warning and analysis basis for network security protection.

[0059] 6. Data preprocessing and feature extraction: Collect network traffic data through traffic collection tools, perform data cleaning, formatting and other preprocessing operations, and extract features such as timestamp, packet size, and protocol type. This combination of technical means solves the problems of data noise and incompleteness, and can provide high-quality multivariate time series data for subsequent time-frequency decomposition and graph neural network modeling, thereby improving the accuracy of anomaly detection.

[0060] 7. Sliding average and seasonal decomposition: The time series is decomposed into trend components and seasonal components through the sliding average method, and the frequency domain features are further extracted by combining Fourier transform. This combination of technical means solves the problem of noise interference in time series, can effectively remove noise, highlight the long-term trend and short-term fluctuation characteristics of time series, and provide more accurate basic data for anomaly detection.

[0061] 8. Combination of multi-scale convolution kernels and graph convolutional networks: Based on the graph convolutional network (GCN), convolution kernels of different sizes are used for multi-scale feature extraction. This combination of technical means solves the limitations of traditional convolutional networks in processing multi-scale features, can more comprehensively capture multi-scale features in network traffic data, and improves the ability to detect complex abnormal behaviors.

[0062] 9. Mask function and frequency domain feature extraction: The high-frequency and low-frequency components of the time series are extracted through Fourier transform and mask function. This combination of technical means solves the noise interference problem in frequency domain feature extraction, can more accurately separate the main and secondary components in the time series, and provide richer frequency domain feature information for anomaly detection.

[0063] 10. Combination of real-time detection and dynamic graph neural network: Dynamic graph neural network models the dynamic changes of network traffic characteristics and captures the time evolution of nodes, edges and graph structures. This combination of technical means solves the problem that traditional methods are difficult to support real-time detection. It can more accurately extract multiple traffic features and improve the real-time detection capability of abnormal traffic. It is particularly suitable for real-time detection and prediction application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is a structural schematic diagram of the model proposed by the present invention;

[0065] Figure 2 It is a flow chart of a specific implementation mode of the present invention. DETAILED DESCRIPTION

[0066] The following is a detailed description of the embodiments of the present invention. Although the present invention will be described and illustrated in conjunction with some specific embodiments, it should be noted that the present invention is not limited to these embodiments. On the contrary, modifications or equivalent substitutions made to the present invention should all be included in the scope of the claims of the present invention.

[0067] In addition, in order to better illustrate the present invention, numerous specific details are given in the following specific embodiments. It will be understood by those skilled in the art that the present invention can also be implemented without these specific details.

[0068] In order to solve the problems in the above background, we proposed the MTFGAN (Multi-scale Time-Frequency Graph Neural Network for Anomaly Detection) model. This is a multi-level time-frequency decomposition technology that separates the seasonal and trend components in network traffic data, extracts high-frequency and low-frequency features through Fourier transform, and finally uses multi-scale graph neural network for feature fusion and anomaly detection. This method can accurately characterize the complex characteristics of network traffic data and provide a new solution for anomaly detection.

[0069] First, we collect normal network traffic and abnormal network traffic data in the target network, and divide these traffic data into multiple independent flows according to data packets. On this basis, we extract the features commonly used in the field of network traffic anomaly detection tasks, including timestamp, packet size, protocol type, etc. These features are arranged along the time axis to form multivariate time series data, which becomes the basis for subsequent decomposition and modeling.

[0070] Next, the multivariate time series data is decomposed. First, the time series decomposition method is used to decompose the time series into trend components (representing long-term change trends), seasonal components (representing periodic fluctuations) and random components (capturing irregular fluctuations). This decomposition method can more clearly separate the regular changes and abnormal characteristics in network traffic. Then, each decomposed component is further Fourier transformed to extract its frequency domain features, and the data is decomposed into high-frequency components (short-term fluctuations and abnormal signals) and low-frequency components (long-term trends and stability). This process uses information in the time domain and frequency domain to provide rich and multi-level feature expressions for subsequent modeling. After splicing and fusion of the data after time series decomposition and Fourier decomposition, it is input into a linear layer for feature transformation to generate high-dimensional feature representation. Subsequently, these features are input into the graph neural network (GNN) for anomaly detection. In the graph neural network module, the traditional graph learning method is improved to more efficiently capture the complex relationships and abnormal features in network traffic data. Specifically, based on the graph convolutional network (GCN), the feature processing flow is redesigned to expand the feature representation of each variable to a higher dimension, and the features are divided into multiple groups according to the set grouping rules. In each group, convolutional kernels of different sizes are used to build a convolutional neural network. Finally, anomaly detection results are generated through a mapping layer.

[0071] The present invention provides a method for detecting abnormal network traffic based on a dynamic graph neural network, comprising the following steps:

[0072] Step 1. Data collection and preprocessing: Collect normal network traffic and abnormal network traffic data in the target network, and divide the traffic data into multiple independent flows according to data packets. For these traffic data, extract the common features in network traffic anomaly detection tasks, such as timestamp, packet size, protocol type, etc. The extracted features are arranged according to the time axis to form multivariate time series data, which provides a data basis for subsequent decomposition and modeling.

[0073] Step 2. Time domain decomposition: Decompose the multivariate time series data. First, the time series decomposition method is used to decompose the time series into trend components (representing long-term change trends), seasonal components (representing periodic fluctuations), and residual components of the original data. Further, Fourier transform is applied to these decomposed components to extract frequency domain features, and the trend component and seasonal component data are divided into high-frequency components (capturing short-term fluctuations and abnormal signals) and low-frequency components (reflecting long-term trends and stability). This decomposition method combines the feature expressions of time domain and frequency domain, providing multi-level and rich feature data for subsequent modeling. The trend and seasonal components are decomposed as follows: the trend component is extracted by the sliding average method to capture the overall change trend in the traffic data, and the residual is calculated to separate the seasonality, which contains periodic patterns and short-term abnormal signals. This decomposition process can effectively remove noise interference, highlight the core features of the time series, and provide more accurate and detailed basic data for subsequent feature extraction and anomaly detection. Given a time series x(t), the trend component column T(t) and the seasonal column R(t) are calculated by the sliding average method, where k is the size of the sliding window. The seasonal components are then calculated:

[0074]

[0075] R(t)=x(t)-T(t)

[0076] R(t) is the seasonal component. The decomposition process can effectively remove noise interference and highlight the long-term trend and short-term volatility characteristics of the time series.

[0077] Step 3. Frequency domain decomposition: After obtaining the seasonal components and trend components corresponding to the original time series data in step 2 and the residual input of the original data, the seasonal components and trend components are decomposed based on the frequency domain to obtain the high-frequency and low-frequency components of the two respectively. The original time series data is statistically analyzed in the frequency domain by Fourier decomposition to obtain the main components and secondary components of the time series data. The training time series is divided into multiple time windows for Fourier transform:

[0078] X train ={x1, x2, ..., x m}, x i =xi,k

[0079]

[0080] Where X train represents the multivariate time series data of traffic volume extracted in step 1, x i,k The kth time series subset data in the i-th time window, X i,k [f] represents the time window (x i,k [t]) is the Fourier transform result in the frequency domain, where f represents the frequency component and the corresponding frequency after Fourier transform. Represents the Fourier transform operator. About the formula N represents the length of the time series segment, while n represents the sample point index in the current time series, x i,k [n] represents the value of the nth sample point in the time series segment.

[0081] The frequency of the amplitude spectrum before α is calculated and selected as G α And construct the mask function M(f)

[0082]

[0083] Sort(amplitude f )for allf

[0084]

[0085] amplitude f represents the average amplitude corresponding to frequency f, which is used to measure the importance of frequency f in all time windows, while m represents the total number of time windows, |X i.k [f]| represents the amplitude corresponding to frequency f, and Sort(*) represents the average amplitude of all frequencies f f , sort them and arrange them from large to small according to the amplitude, TopK(*) means selecting the first K frequency components with the largest amplitude. Indicates rounding down, α is a scaling factor 0<α≤1, K is the number of total frequency components, and the most important frequency set is selected, that is, a part of the frequencies ranked at the top according to the amplitude value, so that the main components can be obtained. These components usually correspond to the most significant periodic or trend characteristics in the signal. Therefore, the subscripts of the main frequencies in the frequency band are obtained according to the main frequencies, and we can construct the mask function through these subscripts. M(f) indicates whether the frequency belongs to the selected important frequency set.

[0086] Apply the separated mask function to the seasonal component and trend component extracted in step 2. The high-frequency component and low-frequency component of the two components can be obtained. The formula is shown in the following table. X[f] represents the Fourier transform result of the original signal X[t], which contains all frequency components. M(f) is our mask function, and S[f] is the frequency domain signal obtained after applying the mask function, which indicates that the frequency components of the main components are retained.

[0087] S[f]=M(f)·X[f]

[0088] By decomposing the time series into trend and seasonality and further extracting the principal components and secondary components, this method aims to separate the main structural information (significant trends and periodicity) in the signal from the minor details or noise, thereby improving the interpretability of the data, noise reduction effect and modeling efficiency, and providing a more accurate basis for subsequent time series prediction, feature extraction and classification.

[0089] Step 4. Feature fusion and linear mapping: After completing the time series decomposition and Fourier decomposition and stabilization processing, the high-frequency and low-frequency components of the seasonal component and the high-frequency and low-frequency components of the trend component are respectively vectorized and spliced. This splicing method is intuitive and efficient, and can completely preserve the original expression of the two types of features, avoiding making too many assumptions about the potential information in the feature space or introducing additional complexity in the fusion stage. At the same time, the spliced ​​multi-source features can be fully mined and optimized in the subsequent linear mapping process, thereby generating a unified high-dimensional feature representation.

[0090] Step 5. Perform vector embedding processing on the high-dimensional representation generated above, treat each variable as a node in the graph, and use a multi-layer perceptron network to map the time series of a variable into a representation vector.

[0091] At the same time, the remaining features of the variable are also added to the representation, treating each traffic feature as a node of the graph. A multi-layer perceptron is used to map each time series into a representation vector of fixed length. While generating the node representation vector, other supplementary features (such as protocol type, traffic direction, etc.) are integrated into the representation vector to ensure that the representation vector contains rich feature information. The whole process can be summarized as follows:

[0092] h i =MLP seq (x i )+MLP(F i )

[0093] where F i is the complementary feature vector of node i, MLP seq is a multi-layer perceptron specifically designed for processing time series, h i is the final node representation vector, x iThe time series input of node i, MLP(*) represents a general multi-layer perceptron.

[0094] Step 6. Graph neural network modeling: Input the embedding output from step 4 into the graph neural network (GNN) module. Improve the traditional graph learning method: Based on the graph convolutional network (GCN), expand the feature dimension of each variable, and then group them according to the manually set division ratio. For the features of each group, convolutional kernels of different sizes are used to construct a convolutional neural network to perform multi-scale graph learning. The learning process is as follows: the vector embedding inner product and activation function are used to automatically learn the scores between two nodes as the adjacency matrix. Based on the graph convolutional network, the representation of each variable is first expanded in dimension and then grouped. Convolutional neural networks of different sizes are used in each group to perform graph learning to calculate the inner product between node representation vectors, and the similarity score between nodes is generated through the activation function to construct a dynamic adjacency matrix. The above formula is expressed as follows:

[0095]

[0096] in is the dynamic adjacency matrix weight, MLP expand (h j ) is an extension of the representation to capture more complex relationships, where Indicates h i The transpose of h j Represents the node representation vector of node j.

[0097] Step 7. Finally, an abnormal detection module is used to reconstruct the prediction results to generate the final abnormal detection results. The prediction results are compared with the actual traffic data, and abnormal traffic is identified through the reconstruction error or abnormal scoring mechanism. If the reconstruction error exceeds the threshold or the abnormal score exceeds the set value, the traffic is judged to be abnormal. The final output detection results include the location, category and characteristics of the abnormal traffic, providing real-time warning and analysis basis for network security protection.

[0098] In summary, the present invention decomposes network traffic data into multi-level time domain and frequency domain features by combining time series decomposition and Fourier transform, effectively extracting long-term trends, periodic fluctuations and short-term abnormal signals; combined with the multi-scale graph neural network method, it deeply mines the potential patterns and abnormal characteristics of network traffic. Compared with traditional methods, this model can significantly improve the accuracy of detection, reduce noise interference, and enhance the ability to identify abnormal behaviors with complex time series dependencies, thereby achieving more comprehensive and efficient feature extraction and anomaly detection.

Claims

1. An abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network, characterized in that: The following steps are involved: Step 1: Collect and preprocess network traffic data to obtain multivariate time series data; Step 2: Perform seasonal and trend decomposition on the preprocessed multivariate time series data to obtain the trend component and seasonal component corresponding to the original multivariate time series; Step 3, performing Fourier mask function calculation processing on the trend component and seasonal component extracted in step 2 to obtain high-frequency components and low-frequency components of the trend component and high-frequency components and low-frequency components of the seasonal component; Step 4, perform stabilization processing on the high and low frequency components extracted in step 3 to obtain a vector after stabilization processing; Step 5, embedding the high-frequency component and low-frequency component of the trend component and seasonal component obtained by the stabilization process in step 4 into a linear mapping process to obtain a new vector representation corresponding to the two; Step 6: Perform vector embedding on the vector obtained in step 5 to perform graph neural network modeling to obtain a feature vector; Step 7: Perform anomaly detection on the feature vector to obtain the final anomaly detection result.

2. According to claim 1, the abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network is characterized in that: Step 1 includes: Step 1.1: Collect normal network traffic and abnormal network traffic data in the target network through traffic collection tools; Step 1.2: pre-process the traffic data packets to remove duplicate, erroneous or incomplete data packets; Step 1.3, dividing the collected traffic data into multiple independent flows according to the data packets; Step 1.4, extract the timestamp, packet size, and protocol type features of each flow; Step 1.5: Preprocess the feature data including data cleaning, formatting, invalidating data, and filling missing values; Step 1.6: Arrange the extracted features along the time axis to form multivariate time series data.

3. According to claim 1, the abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network is characterized in that: Step 2 includes: Step 2.1: The multivariate time series data obtained in step 1 is processed by the sliding average method to obtain the trend component and seasonal component respectively. Given the time series x(t), the trend component column T(i) and the seasonal column R(t) are calculated by the sliding average method, where k is the size of the sliding window: R(t)=x(t)-T(t) 4. According to claim 1, the abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network is characterized in that: Step 3 includes: Step 3.1, by dividing the time window, perform Fourier transform on each window to obtain the frequency domain representation under the window, then calculate the amplitude spectrum average of the frequency domain data of all windows, then select the top α frequencies to construct the mask function, and finally obtain the mask function corresponding to the data set; Step 3.2, the trend component extracted in step 2 is processed by using the above-mentioned mask function to obtain the high-frequency component and the low-frequency component of the trend component; Step 3.3: The seasonal component extracted in step 2 is processed using the above-mentioned mask function to obtain the high-frequency component and the low-frequency component of the seasonal component.

5. According to claim 3, the abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network is characterized in that: The mask function in step 3.1 is calculated by the following formula: Where X i,k [f] represents the value of the frequency domain signal of the kth time window of the i-th sample at frequency f, Sort(*) represents sorting, and TopK(*) represents selecting the first K frequency components with the largest amplitude. represents rounding down, α is a scaling factor 0<α≤1, and K is the total number of frequency components.

6. According to claim 1, the abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network is characterized in that: Step 4 includes: Step 4.1, perform stabilization processing on the high-frequency component and the low-frequency component of the seasonal component to obtain the stabilized data; Step 4.2: Stabilize the high-frequency and low-frequency components of the trend component to obtain stabilized data.

7. According to claim 1, the abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network is characterized in that: Step 5 includes: Step 5.1, concatenate the vectors of the high-frequency component and the low-frequency component of the stabilized trend component and the original data residual, and concatenate other optional supplementary features, and then map them to a new vector representation through a linear layer; Step 5.2: Concatenate the vectors of the high-frequency component and the low-frequency component of the stabilized seasonal component and the original data residual, and concatenate other optional supplementary features, and then map them to a new vector representation through a linear layer.

8. The abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network according to claim 1 is characterized in that: Step 5 includes: Step 6.1: Input the generated high-dimensional feature representation into the graph neural network (GNN) module to start further processing of the features. Step 6.2: Group high-dimensional features based on manually set fixed ratio rules. Step 6.3: Apply 1D convolution operation to the features of each group, and use convolution kernels of different sizes to extract multi-scale features; Step 6.4: Calculate the feature vector of the node through graph learning mechanisms (such as feature aggregation and information propagation).

9. The abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network according to claim 8 is characterized in that: The multi-scale feature extraction in step 6.3 is calculated by the following formula: Among them, z i is the feature vector of the node, σ is the activation function, h i and h i is the node representation vector, W is the weight matrix, MLP expand (*) is the multi-layer perceptron extension function.

10. The abnormal traffic detection method based on multi-level time-frequency decomposition and graph neural network according to claim 1 is characterized in that: Step 7 includes: Step 7.1, concatenate the feature vectors and input them into the anomaly detection module based on reconstruction error; Step 7.2, identifying abnormal traffic through reconstruction error or anomaly scoring mechanism; Step 7.3: Output the detection results, including the location, category and characteristics of the abnormal traffic.

Citation Information

Patent Citations

  • Industrial control system flow anomaly detection method based on deep learning

    CN118713855A

  • Control channel isolation with time-series control traffic prediction in programmable network virtualization

    US20240171517A1

Cited By

  • Multi-element time series data prediction method and device based on hierarchical frequency model

    CN120449106A

  • Abnormal traffic auxiliary analysis method based on signal feature multiple selection

    CN121173525A

  • An abnormal traffic auxiliary analysis method based on multiple selection of signal features

    CN121173525B