DDoS detection method for optimizing convolutional neural network based on particle swarm optimization
By using particle swarm algorithm to optimize convolutional neural networks in DDoS detection, the problems of poor real-time detection, low accuracy and high resource consumption in the existing technology are solved, and more efficient and accurate DDoS attack detection is achieved, which is suitable for complex network environments.
Patent Information
- Application Number
- CN202510157574.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-16
AI Technical Summary
When facing complex and changing network environments and new attack methods, the existing DDoS detection methods have poor real-time detection, low accuracy, high resource consumption and insufficient model adaptability, resulting in frequent false alarms and missed reports, affecting the normal operation of network services.
The DDoS detection method based on particle swarm algorithm is adopted to optimize convolutional neural networks. The network traffic data is converted into two-dimensional representation through data preprocessing technology, and the hyperparameters of the CNN model are optimized in combination with particle swarm optimization algorithm to improve the real-time and accuracy of detection and reduce resource consumption.
It significantly improves the real-timeness of detection, can respond quickly in the early stage of an attack, reduces resource consumption, improves the accuracy and efficiency of detection, is more adaptable, and reduces false alarms and underreports.
Smart Images

Figure CN120017361A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network services, and in particular to a DDoS detection method based on particle swarm algorithm optimized convolutional neural network. Background Art
[0002] With the rapid development of Internet technology, the application of network services is becoming more and more extensive. However, the security threats they face are also becoming increasingly severe. Among them, DDoS (distributed denial of service) attacks are one of the most common and extremely destructive forms of attack.
[0003] Traditional DDoS detection methods have many drawbacks when dealing with complex and changing network environments and increasingly sophisticated attack methods, such as:
[0004] ① Rule-based detection method: It requires manual pre-setting of a large number of complex rules, which is difficult to adapt to new attack modes. In addition, in a high-traffic network environment, the rule matching process consumes a lot of computing resources, resulting in low detection efficiency.
[0005] ② Traffic threshold detection method: Although this method is simple and direct, it is difficult to accurately set the threshold due to the dynamic nature of network traffic itself. It is prone to false positives and false negatives and cannot meet the actual needs of network security.
[0006] Convolutional neural networks (CNNs) have achieved remarkable results in image recognition, speech processing and other fields. Their powerful feature extraction capabilities provide new ideas for DDoS detection. In order to take advantage of the CNN solution, the existing technology has designed the following ideas to overcome the shortcomings of many problems in DDoS detection methods, such as:
[0007] LUCID - A DDoS attack detection system based on Convolutional Neural Network (CNN):
[0008] It aims to achieve efficient detection in an online resource-constrained environment, including: network traffic preprocessing, CNN layer, maximum pooling layer, and classification layer. The learning process adopts supervised learning, uses binary cross entropy as the cost function, and minimizes the cost function by iteratively updating the weights and biases of the model. During training, the data set is balanced to have an equal number of malicious and benign traffic to reduce learning bias; hyperparameter adjustment: using a grid search strategy, with the F1 score as the performance indicator, the maximum number of packets (n), time window (t), convolution filter height (h) and number (k) and other hyperparameters are adjusted, and finally the model configuration with the highest F1 score on the validation set is selected.
[0009] Although the above technical solution integrates the advantages of CNN, it cannot respond quickly in the early stage of DDoS attacks, causing the server to be hit by a large amount of attack traffic in a short period of time, seriously affecting the normal operation of network services, and lacking real-time detection capabilities; the complex network traffic environment makes it difficult for traditional detection methods to accurately distinguish normal traffic from attack traffic, and frequent false positives and missed positives greatly reduce the reliability of detection;
[0010] Although it uses a complex model and uses CNN to improve the detection accuracy, it greatly increases the overall resource consumption, and it is difficult to balance resource consumption and detection accuracy.
[0011] In summary, when facing DDoS attacks, traditional methods are unable to respond quickly in the early stages of the attack, causing the server to be hit by a large amount of attack traffic in a short period of time, seriously affecting the normal operation of network services; the complex network traffic environment makes it difficult for traditional detection methods to accurately distinguish between normal traffic and attack traffic, and frequent false alarms and missed alarms greatly reduce the reliability of detection; at the same time, the high resource cost required to process large-scale network traffic data and the lack of adaptability of existing models in new network environments and attack modes have become important obstacles to ensuring network security. Summary of the invention
[0012] In order to solve the above technical problems, the present invention provides a DDoS detection method based on particle swarm algorithm to optimize convolutional neural network, which solves the technical problems of existing DDoS detection methods such as poor detection real-time performance, low accuracy, high resource consumption and weak model adaptability.
[0013] In a first aspect, the present application shows a DDoS detection method based on particle swarm algorithm optimized convolutional neural network, comprising:
[0014] Step 1: Data preprocessing;
[0015] Since the DDoS attack traffic suffered by network services usually consists of thousands of data request packets requesting services in the same period of time, real-time collection of traffic data and pre-processing of the data consumes a lot of computing resources;
[0016] To this end, a data preprocessing method is proposed here. After accessing the network traffic data, the collection window is divided according to the time sequence and the data traffic size, and preprocessing is performed based on the data traffic characteristics in the collection window. By setting the time sequence and the collection window size, as many data traffic characteristics as possible are captured with as little data as possible, thereby reducing processing time and cost and improving detection efficiency.
[0017] As an example, the specific scheme of data preprocessing includes:
[0018] ① When converting the concentrated network traffic data into an array-like data structure, the continuous network traffic data is divided into sub-flows according to the time interval by setting the timing;
[0019] ②Through the above operations, the original network traffic data is converted into a two-dimensional representation, one dimension representing time and the other representing traffic;
[0020] This two-dimensional representation of the data structure can more intuitively understand and analyze the patterns and characteristics of network traffic data, and also allow CNN to adapt convolutional filters to learn the characteristics of DDoS attack traffic and normal traffic.
[0021] As an example, the timing setting means: starting from time t0, the network flow data is grouped according to the time interval t, and each time window can contain at most n data packets; each flow is divided into multiple groups; in the grouping process, the identification feature used is to extract a series of flow attributes from the data packet;
[0022] The advantage of this method is that by properly setting the t value and n value, potential attack traffic in local traffic can be quickly detected without waiting for the data set to accumulate to a large enough size before training and detection; this real-time feature extraction method greatly reduces the time cost and resource consumption of detection, while improving the overall detection efficiency while ensuring the detection accuracy;
[0023] Moreover, by setting the t value of appropriate size, the model can quickly capture possible abnormal traffic in a short time, and the setting of the n value can control the number of data packets contained in each time window, thereby balancing the detection sensitivity and resource consumption; this flexible parameter adjustment enables the entire model to be optimized for different scenarios, thereby better adapting to changes in the actual network environment.
[0024] As an example, the attributes of the series of flows include characteristic attributes such as initiation time, data packet length, IP flag fragmentation identifier, and TCP length.
[0025] Step 2: Input the data flow characteristics after data preprocessing into the initialized PSO model and the initialized CNN model;
[0026] Step 3: Obtain the global optimal hyperparameter weight value and calculate the accuracy and other evaluation values of the detection method;
[0027] As an example, the global optimal hyperparameter weight value is obtained, and its initial value is customized by the user when CNN is actually used.
[0028] Step 4: using the accuracy of the calculation detection method as the fitness value;
[0029] As an example, the fitness value is: the accuracy obtained when the PSO algorithm is used to train the initialized CNN model is used as the fitness value.
[0030] Step 5: Calculate the local and global particle positions and velocity matrices; obtain the optimal values of the local and global particle and velocity matrices based on the fitness values;
[0031] Step 6: According to the optimal values of the local and global particle and velocity matrices, the current local and global particle positions and velocities are updated;
[0032] Step 7: Determine whether the number of iterations has been reached;
[0033] ① If the current particle position and speed have not reached the number of iterations specified by the PSO algorithm, the global optimal hyperparameter weight value is updated to the current PSO global optimal hyperparameter combination, and then the process returns to step 3 to continue running;
[0034] ② If the current particle position and velocity reach the number of iterations specified by the PSO algorithm, then the hyperparameter combination obtained by running the PSO algorithm at this moment is the final result;
[0035] Step 8: Output the final result as the optimal particle set, and then use the final optimized CNN model to perform DDoS detection.
[0036] In a second aspect, the present application shows an electronic device, which includes: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to execute the method described in any of the above aspects.
[0037] In a third aspect, the present application shows a non-temporary computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method described in any of the above aspects.
[0038] In a fourth aspect, the present application illustrates a computer program product. When instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to execute the method described in any of the above aspects.
[0039] Beneficial effects of the present invention:
[0040] 1. The present invention greatly improves the real-time detection: Traditional DDoS detection methods respond slowly in the early stages of an attack, causing the server to be impacted by a large amount of attack traffic, seriously affecting the normal operation of network services. The present invention, with the help of a dynamic time window strategy, can perceive changes in network traffic in real time and respond quickly in the early stages of an attack, thereby buying valuable time for network security protection and significantly improving the real-time detection.
[0041] 2. The present invention is based on a lightweight detection model to reduce resource consumption: Traditional methods require a lot of computing resources to process large-scale network traffic data. The lightweight CNN model adopted by the present invention is combined with the particle swarm optimization algorithm (PSO) to deeply optimize hyperparameters. While ensuring detection accuracy, it greatly reduces computing resource consumption and training time, which is more in line with online real-time detection needs, and is particularly suitable for network environments with limited resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 The figure is a schematic diagram of the process architecture of the DDoS detection method based on particle swarm algorithm optimization of convolutional neural network in the present invention.
[0043] Figure 2 This is a design block diagram of an electronic device for a DDoS detection method based on particle swarm algorithm optimized convolutional neural network in the present invention.
[0044] Figure 3 This is a design block diagram of another electronic device of the DDoS detection method based on particle swarm algorithm optimized convolutional neural network of the present invention. DETAILED DESCRIPTION
[0045] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work belong to the scope of protection of the present application, and reference is made to the accompanying drawings in the embodiments of the present application. Figures 1 to 3 As shown,
[0046] In a first aspect, the present application shows a DDoS detection method based on particle swarm algorithm optimized convolutional neural network, comprising:
[0047] Step 1: Data preprocessing;
[0048] Since the DDoS attack traffic suffered by network services usually consists of thousands of data request packets requesting services in the same period of time, real-time collection of traffic data and pre-processing of the data consumes a lot of computing resources;
[0049] To this end, a data preprocessing method is proposed here. After accessing the network traffic data, the collection window is divided according to the time sequence and the data traffic size, and preprocessing is performed based on the data traffic characteristics in the collection window. By setting the time sequence and the collection window size, as many data traffic characteristics as possible are captured with as little data as possible, thereby reducing processing time and cost and improving detection efficiency.
[0050] As an example, the specific scheme of data preprocessing includes:
[0051] ① When converting the concentrated network traffic data into an array-like data structure, the continuous network traffic data is divided into sub-flows according to the time interval by setting the timing;
[0052] ②Through the above operations, the original network traffic data is converted into a two-dimensional representation, one dimension representing time and the other representing traffic;
[0053] This two-dimensional representation of the data structure can more intuitively understand and analyze the patterns and characteristics of network traffic data, and also allow CNN to adapt convolutional filters to learn the characteristics of DDoS attack traffic and normal traffic.
[0054] As an example, the timing setting means: starting from time t0, the network flow data is grouped according to the time interval t, and each time window can contain at most n data packets; each flow is divided into multiple groups; in the grouping process, the identification feature used is to extract a series of flow attributes from the data packet;
[0055] The advantage of this method is that by properly setting the t value and n value, potential attack traffic in local traffic can be quickly detected without waiting for the data set to accumulate to a large enough size before training and detection; this real-time feature extraction method greatly reduces the time cost and resource consumption of detection, while improving the overall detection efficiency while ensuring the detection accuracy;
[0056] Moreover, by setting the t value of appropriate size, the model can quickly capture possible abnormal traffic in a short time, and the setting of the n value can control the number of data packets contained in each time window, thereby balancing the detection sensitivity and resource consumption; this flexible parameter adjustment enables the entire model to be optimized for different scenarios, thereby better adapting to changes in the actual network environment.
[0057] As an example, the attributes of the series of flows include characteristic attributes such as initiation time, data packet length, IP flag fragmentation identifier, and TCP length.
[0058] Step 2: Input the data flow characteristics after data preprocessing into the initialized PSO model and the initialized CNN model;
[0059] Step 3: Obtain the global optimal hyperparameter weight value and calculate the accuracy and other evaluation values of the detection method;
[0060] As an example, the global optimal hyperparameter weight value is obtained, and its initial value is customized by the user when CNN is actually used.
[0061] Step 4: using the accuracy of the calculation detection method as the fitness value;
[0062] As an example, the fitness value is: the accuracy obtained when the PSO algorithm is used to train the initialized CNN model is used as the fitness value.
[0063] Step 5: Calculate the local and global particle positions and velocity matrices; obtain the optimal values of the local and global particle and velocity matrices based on the fitness values;
[0064] As an example, the PSO algorithm, i.e., the particle swarm optimization algorithm, performs hyperparameter optimization on the initialized convolutional neural network (CNN) model (attack detection model) to improve the performance and detection capability of the model; the PSO algorithm simulates the foraging behavior of the particle swarm, continuously iteratively updates the position of particles (parameters), and guides them to move towards the global optimal value.
[0065] Step 6: According to the optimal values of the local and global particle and velocity matrices, the current local and global particle positions and velocities are updated;
[0066] Step 7: Determine whether the number of iterations has been reached;
[0067] ① If the current particle position and speed have not reached the number of iterations specified by the PSO algorithm, the global optimal hyperparameter weight value is updated to the current PSO global optimal hyperparameter combination, and then the process returns to step 3 to continue running;
[0068] ② If the current particle position and velocity reach the number of iterations specified by the PSO algorithm, then the hyperparameter combination obtained by running the PSO algorithm at this moment is the final result;
[0069] Step 8: Output the final result as the optimal particle set, and then use the final optimized CNN model to perform DDoS detection.
[0070] In a second aspect, the present application shows an electronic device, which includes: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to execute the method described in any of the above aspects.
[0071] In a third aspect, the present application shows a non-temporary computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method described in any of the above aspects.
[0072] In a fourth aspect, the present application illustrates a computer program product. When instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to execute the method described in any of the above aspects.
[0073] In order to better illustrate the design concept of the present invention, a detailed explanation of the principle is now provided through the framework concept of the present invention:
[0074] First, a convolutional neural network (CNN) is used to extract and detect features of DDoS attacks. With its excellent feature learning ability and strong adaptability, CNN can efficiently capture multi-dimensional and scaled information in the data set, and can automatically complete classification and regression operations, which is of great help in significantly improving the accuracy of detection. However, due to the complexity of the neural network's own structure and the high requirements for training depth, the training process of the model consumes considerable resources and time. In view of this, in the detection algorithm proposed in this application, the traffic is segmented into time windows in the data preprocessing stage, and it is disassembled into sub-traffic, thereby realizing the lightweight of CNN to ensure that the best detection effect can be achieved under resource-constrained conditions.
[0075] Secondly, when building a CNN model, it is usually necessary to manually adjust parameters, which will undoubtedly bring extremely high labor costs; in view of this, the particle swarm optimization (PSO) algorithm is introduced to optimize the convolutional neural network (CNN); the PSO algorithm has excellent global search capabilities by simulating the movement of particles in the search space and information sharing; when optimizing the hyperparameters of CNN, the PSO algorithm can efficiently search the parameter space and accurately find the global optimal solution or a solution close to the optimal solution; at the same time, the PSO algorithm also has a faster convergence speed and can obtain a more ideal solution in a relatively short time.
[0076] Finally, optimizing the hyperparameters of CNN is crucial because the hyperparameter space of CNN is often extremely large, and traditional grid search or random search methods may take a lot of time to find the optimal solution; the PSO algorithm has a certain degree of adaptability and can flexibly adjust the search direction and speed of particles according to the dynamic situation during the search process; when optimizing the hyperparameters of CNN, PSO can adjust the direction and speed of parameter search in real time according to the current search status, so as to better fit different optimization goals and problem characteristics.
[0077] Figure 2 800 is a block diagram of an electronic device 800 shown in the present application. For example, the electronic device 800 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
[0078] Reference Figure 2 , the electronic device 800 may include one or more of the following components: a processing component 802 , a memory 804 , a power component 806 , a multimedia component 808 , an audio component 810 , an input / output (I / O) interface 812 , a sensor component 814 , and a communication component 816 .
[0079] The processing component 802 generally controls the overall operation of the electronic device 800, such as operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the above method. In addition, the processing component 802 may include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 may include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.
[0080] The memory 804 is configured to store various types of data to support operations on the device 800; examples of such data include instructions for any application or method operating on the electronic device 800, contact data, phone book data, messages, images, videos, etc. The memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0081] The power supply component 806 provides power to the various components of the electronic device 800. The power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 800.
[0082] The multimedia component 808 includes a screen that provides an output interface between the electronic device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each front camera and the rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.
[0083] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC), and when the electronic device 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive an external audio signal. The received audio signal can be further stored in the memory 804 or sent via the communication component 816. In some embodiments, the audio component 810 also includes a speaker for outputting audio signals.
[0084] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include but are not limited to: home button, volume button, start button, and lock button.
[0085] The sensor assembly 814 includes one or more sensors for providing various aspects of status assessment for the electronic device 800. For example, the sensor assembly 814 can detect the open / closed state of the device 800, the relative positioning of components, such as the display and keypad of the electronic device 800, and the sensor assembly 814 can also detect the position change of the electronic device 800 or a component of the electronic device 800, the presence or absence of contact between the user and the electronic device 800, the orientation or acceleration / deceleration of the electronic device 800, and the temperature change of the electronic device 800. The sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 814 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 814 may also include an accelerometer, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0086] The communication component 816 is configured to facilitate wired or wireless communication between the electronic device 800 and other devices. The electronic device 800 can access a wireless network based on a communication standard, such as WiFi, a carrier network (such as 2G, 3G, 4G or 5G), or a combination thereof. In an exemplary embodiment, the communication component 816 receives a broadcast signal or broadcast operation information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 816 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0087] In an exemplary embodiment, the electronic device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above methods.
[0088] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, and the instructions can be executed by a processor 820 of an electronic device 800 to perform the above method. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0089] Figure 31 is a block diagram of an electronic device 1900 shown in the present application. For example, the electronic device 1900 may be provided as a server.
[0090] Reference Figure 3 As shown, the electronic device 1900 includes a processing component 1922, which further includes one or more processors, and a memory resource represented by a memory 1932 for storing instructions that can be executed by the processing component 1922, such as an application. The application stored in the memory 1932 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 1922 is configured to execute instructions to perform the above method.
[0091] The electronic device 1900 may also include a power supply component 1926 configured to perform power management of the electronic device 1900, a wired or wireless network interface 1950 configured to connect the electronic device 1900 to a network, and an input / output (I / O) interface 1958. The electronic device 1900 may operate based on an operating system stored in the memory 1932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™ or the like.
[0092] Furthermore, the design of the PSO algorithm is further described in the following structure:
[0093] The particle swarm optimization algorithm is used to simulate the group foraging behavior of a flock of birds. In a multidimensional search space, each particle represents a possible solution, that is, a set of CNN hyperparameter settings; each particle has its own position and speed, and can remember the optimal position (individual extreme value) searched by itself, while the entire particle swarm can also know the global optimal position (global extreme value); during the search process, the particles continuously adjust their flight direction and speed according to the information of individual extreme values and global extreme values and the specific speed and position update formula to find the optimal solution.
[0094] In the PSO-CNN algorithm, PSO is responsible for optimizing the hyperparameters of CNN.
[0095] First, a group of particles are initialized, and the position of each particle corresponds to different hyperparameter settings of CNN;
[0096] Then, in each iteration, the particle adjusts its position according to the established speed and position update formula, that is, tries different hyperparameter combinations; the CNN model under each hyperparameter combination will be trained on the training data, and its performance on the validation set, such as accuracy, loss value, etc., will be calculated as the particle's fitness value; the higher the fitness value, the better the performance of the CNN model under the hyperparameter combination corresponding to the particle.
[0097] As the iterations proceed, the particles continue to move closer to a better combination of hyperparameters, and eventually find a set of hyperparameters that can achieve the best performance of the CNN model;
[0098] Compared with traditional CNN, the PSO-CNN algorithm effectively avoids the blindness and inefficiency of manual parameter adjustment through intelligent optimization of hyperparameters by PSO, and can find hyperparameters close to the global optimal one more quickly, thereby improving the performance of the CNN model.
[0099] In the PSO-CNN traffic classification technique, the main task of PSO is to find the optimal hyperparameter combination for CNN;
[0100] First, a group of particles are randomly initialized, and the position of each particle is assigned a different CNN hyperparameter initial value; in each subsequent iteration, the particle adjusts its own speed according to the speed update formula:
[0101] v i (t+1)=wv i (t)+c1r1(p i (t)-x i (t))+c2r2(p g (t)-x i (t));
[0102] Among them, v i (t+1) is the velocity of particle i at the t+1th iteration, v i (t) is the current speed, w is the inertia weight, which controls the degree to which the particle inherits the previous speed; c1 and c2 are learning factors, which respectively represent the degree to which the particle learns from the individual extreme value and the global extreme value; r1 and r2 are random numbers in the interval [0, 1], which introduce a certain degree of randomness into the particle search process to avoid falling into the local optimum; p i (t) is the individual extreme position of particle i, x i (t) is the current position of particle i, p g (t) is the global extremum position.
[0103] Then, according to the updated velocity, the particle adjusts its position through the position update formula, that is, trying different hyperparameter combinations:
[0104] x i (t+1)=x i (t)+v i (t+1)
[0105] The CNN model corresponding to each set of hyperparameter combinations will be trained on the training data set. After the training is completed, the performance of the model is evaluated on the validation data set. Common evaluation indicators include accuracy, recall, F1 value, etc. These evaluation indicators are used as the fitness value of the particle to measure the quality of the hyperparameter combination represented by the particle. The higher the fitness value, the higher the accuracy of the CNN model under the hyperparameter combination in traffic classification.
[0106] Finally, as the iterations continue, the particles continue to approach a better hyperparameter combination until the preset termination conditions are met (such as reaching the maximum number of iterations, fitness value convergence, etc.). At this time, the hyperparameter combination corresponding to the global optimal position is the optimal hyperparameter found by PSO for CNN. Applying this set of optimal hyperparameters to the CNN model can accurately classify network traffic.
[0107] CNN hyperparameters planned to be optimized using PSO:
[0108] kernels size: convolution kernel size;
[0109] kernel rows: the number of rows of the convolution kernel;
[0110] epoch: the update frequency in the model;
[0111] Batch size: the number of times the algorithm traverses the entire training set;
[0112] learning rate: learning rate;
[0113] Dropout rate: the probability of failure of a neuron during training to prevent overfitting;
[0114] L1 regularization: Add weight parameters to the loss function to prevent overfitting.
[0115] The above are only preferred embodiments of the present invention. It should be understood that the description of the above embodiments is only used to help understand the method and core ideas of the present invention, and is not used to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, etc. made within the ideas and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A DDoS detection method based on particle swarm algorithm optimized convolutional neural network, characterized in that: include: Step 1: Data preprocessing; After accessing the network traffic data, the collection window is divided according to the timing and data traffic size, and preprocessing is performed based on the data traffic characteristics within the collection window. By setting the timing and collection window size, as many data traffic characteristics as possible are captured with as little data as possible, thereby reducing processing time and cost and improving detection efficiency; Step 2: Input the data flow characteristics after data preprocessing into the initialized PSO model and the initialized CNN model; Step 3: Obtain the global optimal hyperparameter weight value and calculate the accuracy of the detection method; Step 4: using the accuracy of the calculation detection method as the fitness value; Step 5: Calculate the local and global particle positions and velocity matrices; obtain the optimal values of the local and global particle and velocity matrices based on the fitness values; Step 6: According to the optimal values of the local and global particle and velocity matrices, the current local and global particle positions and velocities are updated; Step 7: Determine whether the number of iterations has been reached; ① If the current particle position and speed have not reached the number of iterations specified by the PSO algorithm, the global optimal hyperparameter weight value is updated to the current PSO global optimal hyperparameter combination, and then the process returns to step 3 to continue running; ② If the current particle position and velocity reach the number of iterations specified by the PSO algorithm, then the hyperparameter combination obtained by running the PSO algorithm at this moment is the final result; Step 8: Output the final result as the optimal particle set, and then use the final optimized CNN model to perform DDoS detection.
2. The DDoS detection method based on particle swarm algorithm optimized convolutional neural network according to claim 1 is characterized in that: The specific scheme of the data preprocessing includes: ① When converting the concentrated network traffic data into an array-like data structure, the continuous network traffic data is divided into sub-flows according to the time interval by setting the timing; ②Through the above operations, the original network traffic data is converted into a two-dimensional representation, one dimension representing time and the other representing traffic; This two-dimensional representation of the data structure can more intuitively understand and analyze the patterns and characteristics of network traffic data, and also allow CNN to adapt convolutional filters to learn the characteristics of DDoS attack traffic and normal traffic.
3. The DDoS detection method based on particle swarm algorithm optimized convolutional neural network according to claim 2 is characterized in that: The timing setting means: starting from time t0, the network flow data is grouped according to the time interval t, and each time window can accommodate at most n data packets; each flow will be divided into multiple groups; During the grouping process, the identification features used are a series of flow attributes extracted from the data packets.
4. The DDoS detection method based on particle swarm algorithm optimized convolutional neural network according to claim 3 is characterized in that: The attributes of the series of flows include: initiation time, data packet length, IP flag fragmentation identifier and TCP length.
5. The DDoS detection method based on particle swarm algorithm optimized convolutional neural network according to claim 1, characterized in that: The global optimal hyperparameter weight value is obtained, and its initial value is customized by the user when CNN is actually used.
6. The DDoS detection method based on particle swarm algorithm optimized convolutional neural network according to claim 1, characterized in that: The fitness value is: the accuracy obtained when the PSO algorithm is used to train the initialized CNN model is used as the fitness value.
7. An electronic device, characterized in that: include: A processor, and a memory for storing processor executable instructions; wherein the processor is configured to execute the method of any one of claims 1-6.
8. A non-transitory computer-readable storage medium, characterized in that: When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method according to any one of claims 1 to 6.
9. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to perform the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
SDN network DDoS attack detection method based on optimized BP neural network
CN109120630A
A DDoS attack detection method
CN109274651A
Station terminal load prediction method and prediction device
CN112700060A
Network intrusion detection method, system and equipment based on comparative learning, and medium
CN117914618A
DDoS attack detection method based on deep learning
CN118573396A