Network security threat intelligent identification and defense method based on artificial intelligence
By applying the superentropy differential evolution algorithm and the variational Bayesian inference model in the network security system, combined with the adaptive defense strategy, the zero-day attack identification and defense problems are solved, and the stability and response capabilities of the network security system are improved.
Patent Information
- Application Number
- CN202510391806.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-03-31
AI Technical Summary
Existing network security systems are difficult to identify and block attacks in a timely manner when facing zero-day attacks, and traditional detection algorithms have problems with high false alarm rates and weak response capabilities.
Using an intelligent identification and defense method of network security threats based on artificial intelligence, network features are optimized through the transentropy differential evolution algorithm, a network traffic anomaly detection probability model based on variational Bayesian inference is constructed, and an adaptive defense strategy is generated.
It improves the overall stability and defense capabilities of the network security system, can accurately identify zero-day attacks in complex network environments, dynamically adjust defense measures, and reduce false alarm rates and response times.
Smart Images

Figure CN120017411A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an artificial intelligence-based network security threat intelligent identification and defense method. Background Art
[0002] With the continuous evolution of network attack technology, network security is facing increasingly severe challenges, especially zero-day attacks, that is, attacks launched by attackers using software vulnerabilities that have not yet been made public or fixed. Since traditional security defense mechanisms mainly rely on known attack feature libraries for detection, in the face of the suddenness and unknown nature of zero-day attacks, existing security systems often find it difficult to identify and block attacks in a timely and effective manner.
[0003] At present, the mainstream network attack detection technologies mainly include intrusion detection systems based on feature matching and intrusion detection systems based on abnormal behavior analysis. The intrusion detection system based on feature matching detects attacks by building an attack feature library and comparing traffic features with known malicious behavior patterns. However, this method relies on the timely update of the attack signature library and is difficult to discover new attack patterns, especially when dealing with zero-day attacks. There is a serious lag. The intrusion detection system based on abnormal behavior analysis uses machine learning or statistical analysis methods to identify abnormal traffic. However, due to the complex network environment and the changeable normal traffic patterns, traditional anomaly detection algorithms often face the problem of high false alarm rates, which affects the system's availability and detection accuracy.
[0004] In addition, the existing security defense mechanisms have weak response capabilities when facing zero-day attacks. Most defense systems rely on predefined static strategies and it is difficult to dynamically adjust defense measures for different types of attacks. For example, blacklist-based traffic blocking strategies are effective in dealing with known attacks, but in zero-day attack scenarios, the blacklist mechanism is difficult to play an effective role due to the unknown characteristics of attack traffic. At the same time, rule-based access control strategies also have problems such as long adjustment cycles and insufficient flexibility, making it difficult to adapt to complex attack environments.
[0005] In recent years, with the development of artificial intelligence and optimization algorithms, intelligent optimization technology has gradually been introduced into the field of network security. For example, differential evolution algorithm, as a global optimization method, can be used for feature selection and detection model parameter optimization to improve the adaptability of the detection system. However, traditional differential evolution algorithm is prone to fall into local optimality when facing high-dimensional and complex network data, which affects the effectiveness of feature selection. In addition, traditional Bayesian reasoning method can be used for probabilistic modeling of network attack detection, but due to its high computational complexity, it is difficult to meet the needs of real-time detection. At the same time, when processing dynamically changing attack traffic, the parameter update speed of traditional Bayesian reasoning model is slow, which limits its application in zero-day attack detection.
[0006] Therefore, there is an urgent need for a zero-day attack detection and defense method that combines intelligent optimization and probabilistic reasoning to improve the accuracy of detection, enhance the dynamic adjustment capability of defense, and build an intelligent collaborative mechanism for the entire process from detection to defense to address the limitations of existing technologies. Summary of the invention
[0007] One purpose of the present invention is to propose an artificial intelligence-based network security threat intelligent identification and defense method, which improves the overall stability and defense capability of the network security system.
[0008] According to an embodiment of the present invention, a network security threat intelligent identification and defense method based on artificial intelligence includes the following steps:
[0009] S1. Collect network traffic data, user behavior data and system log data from the network security system, and perform data cleaning, normalization, feature extraction and dimensionality reduction on the collected network data sets, and output the final converged network feature data set;
[0010] S2. Apply the hyperentropy differential evolution algorithm to the network feature data set for global optimization search, dynamically adjust the population evolution parameters by introducing the hyperentropy mechanism, realize the optimal subset selection and dimensionality reduction optimization of the network features, and generate the network feature data optimized by the hyperentropy differential evolution;
[0011] S3. Use the network feature data optimized by hyperentropy differential evolution to build a network traffic anomaly detection probability model based on variational Bayesian reasoning, and use the variational reasoning method to approximate the potential probability distribution of the network feature data;
[0012] S4. Input the network feature data set into the network traffic anomaly detection probability model, use the network traffic anomaly detection probability model to perform real-time inference and abnormal behavior analysis on the network data, identify the abnormal data pattern with zero-day attack risk, and evaluate the risk probability of abnormal behavior;
[0013] S5. Generate an adaptive defense strategy based on the detection results, the adaptive defense strategy includes automatic blocking of abnormal traffic, restriction of suspicious ports, dynamic isolation of infected nodes, and real-time alerts to network security administrators, and form defense strategy data.
[0014] Optionally, the step S1 includes:
[0015] S11. Collect network traffic data, user behavior data and system log data to build network data set D:
[0016] D=D f ∪D u ∪D s ;
[0017] Among them, D f is a network traffic data set, including the traffic size, flow rate and communication protocol characteristics of network data packets, D u is a user behavior data set, including user login records, access frequency and interaction mode characteristics, D s It is a collection of system log data, including server logs, error logs and audit records;
[0018] S12. Perform data cleaning on the network data set D, remove duplicate data, missing data and abnormal data, use interpolation method to complete the missing data, and perform consistency check on the time series data to form a cleaned network data set;
[0019] S13. Normalize the cleaned network data set, use the minimum-maximum normalization method to map all eigenvalues to the interval [0,1], extract eigenvectors from the normalized network data set, obtain the feature matrix, reduce the dimension of the feature matrix, and finally form the network feature data set D o .
[0020] Optionally, step S2 includes:
[0021] S21. Construct the initial differential evolution population P0, the initial differential evolution population represents the feature selection strategy for the network zero-day attack detection task, the network feature data set D o Contains M features, each candidate feature subset p i Encoded in the form of a continuous vector;
[0022] S22. Define the network risk information entropy function H net (p i ), which is used to measure the ability of each candidate feature subset to reveal information about potential zero-day attack risks in the network:
[0023]
[0024] Among them, α i,j represents the selection weight of the jth feature in the candidate feature subset, w j To select weights, which reflect the contribution of features to zero-day attack risk in revealing abnormal network behavior;
[0025] The average network risk information entropy of the differential evolution population in the tth generation is:
[0026]
[0027] Among them, represents the total number of individuals in the population;
[0028] The average network risk information entropy is used to comprehensively evaluate the overall performance of the current feature selection strategy in revealing network attack risk information;
[0029] S23. Based on the average network risk information entropy H(P t ), set the adaptive variation factor F net (H(P t )) to dynamically adjust the variation range:
[0030]
[0031] Among them, F min and F max are the lower and upper limits of the mutation factor, respectively, which determine the minimum and maximum exploration amplitudes for searching for unknown attack features in the network environment. λ is the attenuation coefficient, which is used to control the sensitivity of the mutation factor to the change of network risk information entropy. max It is the maximum network risk information entropy that can be achieved in theory, representing the upper limit of all features fully displaying network risk information in extreme cases;
[0032] Generate mutant individuals v according to the adaptive mutation factor i :
[0033]
[0034] in, and is the differential evolution population P from the current t Randomly selected non-repeated individuals;
[0035] S24. In the variant individual v i Based on this, a crossover operation is performed to generate offspring individuals u i , set the adaptive crossover rate CR net (H(P t ));
[0036]
[0037] Among them, CR min With CR max are the lower and upper limits of the crossover rate, respectively reflecting the lowest and highest ratios of feature combinations retained in network anomaly detection;
[0038] Each component of the offspring individuals is obtained by the binomial crossover rule:
[0039]
[0040] Among them, u i,j Represents the specific characteristic value of the newly generated individual, rand i,jis a random number uniformly distributed in [0,1], j rand To ensure that at least one dimension of random indexing must be crossed;
[0041] S25. Define the network zero-day attack detection performance fitness function f net (p i )Evaluate the performance of each candidate feature subset in actual detection:
[0042]
[0043] Among them, Acc net (p i ) represents the candidate feature subset p i The accuracy of the constructed detection model in identifying zero-day attacks. ω and δ are weight coefficients for balancing the detection accuracy and the network risk information revealed by feature selection.
[0044] According to the fitness comparison of the network zero-day attack detection performance fitness function, the selection rule is used to update the differential evolution population:
[0045]
[0046] S26. Set the average fitness difference of two consecutive generations of differential evolution populations:
[0047]
[0048] When Δf is satisfied net <∈ or t≥T max When , the candidate feature subset is considered to have reached a stable state, where ∈ is the preset convergence accuracy threshold, T max is the maximum number of iterations; otherwise, return to step S22 to continue iterative updating;
[0049] S27. Output the final converged network feature data set P * :
[0050]
[0051] Among them, P * It is a collection of network feature data.
[0052] Optionally, step S3 includes:
[0053] S31. Using the network feature data set P optimized by super entropy differential evolution * Construct a network traffic anomaly detection probability model, assuming that the optimized network feature data set is X, where Represents N network traffic feature samples, each sample x i It consists of M eigenvectors;
[0054] S32. For the task of network traffic anomaly detection, assume that the attack category Z obeys a discrete distribution, and the prior distribution is p(Z|θ). At the same time, the conditional distribution of network traffic data obeys a Gaussian mixture model, which is p(X|Z,θ).
[0055] S33. Use variational Bayesian inference method for approximate inference, define variational distribution q(Z) to approximate the true posterior distribution, and iteratively update variational parameter φ through variational inference i , obtain the optimal network traffic anomaly detection probability model after convergence;
[0056] S34. Calculate each sample x i Posterior probabilities of belonging to different attack categories:
[0057]
[0058] Among them, p(z i |x i ,θ) is used to evaluate the sample x i Whether it belongs to a certain attack type, realize the classification detection of unknown zero-day attacks, and use the expectation maximization algorithm to optimize the parameters Compute the update rule:
[0059]
[0060] in, Indicates the attack category z i The prior probability after the t+1th iteration is, Indicates the attack category z i The mean vector after the t+1th iteration, Indicates the attack category z i At t+
[0061] The covariance matrix after 1 iteration, p(z i |x i ,θ t ) means that at the tth iteration, the sample x i
[0062] Belongs to attack category z i The posterior probability, x i
[0063] represents the i-th network traffic sample, and t represents the current iteration step number;
[0064] S35. Define the convergence judgment of the network traffic anomaly detection probability model as:
[0065]
[0066] When Δθ<∈ or t≥T max When , the network traffic anomaly detection probability model is determined to have converged, where ∈ is the preset convergence accuracy threshold, T max is the maximum number of iterations; otherwise, return to step S34 to continue optimizing the network traffic anomaly detection probability model parameters;
[0067] S36. Output the optimized network traffic anomaly detection probability model, the posterior probability p(z i |x i ,θ) is used to evaluate whether there is an unknown attack in the current network traffic.
[0068] Optionally, step S4 includes:
[0069] S41. The network feature data set P * Input to the network traffic anomaly detection probability model;
[0070] S42. Use the network traffic anomaly detection probability model to infer the standardized network feature data set X′ and calculate each network traffic sample x′ i The posterior probability of the attack category;
[0071] S43. Calculate the abnormality score S of each network traffic sample anom (x′ i ), the abnormality score is defined as the expected negative log-likelihood of each attack category, which is used to identify potential zero-day attack samples;
[0072] S44. Set the abnormality score S anom (x′ i ) threshold T anom , calculate the sample x′ i The risk probability of being judged as a zero-day attack. If the risk probability is close to 1, it means that the sample x′ i The probability belongs to zero-day attack;
[0073] S45. Classify network traffic using risk probability, and classify traffic with risk probability higher than a preset threshold value T risk The samples are classified as zero-day attacks, forming a zero-day attack detection result set;
[0074] S46. Calculate the current performance indicators of the network traffic anomaly detection probability model, including precision, recall and F1 score, and adaptively adjust the mechanism to optimize the parameters of the network traffic anomaly detection probability model based on the detection performance indicators.
[0075] Optionally, step S5 includes:
[0076] S51. Take the zero-day attack detection result set as the input of defense decision, and calculate the attack category posterior probability and abnormality score S according to the network traffic anomaly detection probability model. anom and the risk probability p risk , classify the detected abnormal traffic, the classification includes:
[0077] High-risk attack traffic: When the attack category posterior probability of a network traffic sample is higher than the set threshold, and the abnormality score exceeds the high-risk threshold, it is determined to be high-risk attack traffic;
[0078] Continuous attack behavior: When a certain IP address or port is identified as high-risk attack traffic multiple times in a short period of time, and the attack behavior persists, it is considered a continuous attack behavior;
[0079] Low-risk suspicious traffic: When the attack category posterior probability of a network traffic sample is in the suspicious range, but the abnormality score does not reach the high-risk threshold, it is judged as low-risk suspicious traffic and monitoring measures are taken;
[0080] S52. Based on the posterior probability calculated by the network traffic anomaly detection probability model and the feature data optimized by super entropy differential evolution, the triggering conditions of the adaptive defense strategy are dynamically set:
[0081] When the amount of high-risk attack traffic exceeds the set threshold and the attack sources are relatively concentrated, the automatic blocking strategy is triggered;
[0082] When continuous attack behavior is detected and the attack targets involve multiple victim nodes, the infected node isolation strategy is triggered;
[0083] When low-risk suspicious traffic is detected to continue to increase but has not yet posed a direct threat to the network system, the traffic monitoring strategy is triggered and defense measures are dynamically adjusted;
[0084] S53. Use the optimized feature subset to construct a dynamically adjusted defense parameter set so that the defense strategy can adaptively adjust the defense rules. The defense parameters include:
[0085] Variation trend of attack behavior: Calculate the variation of attack patterns based on the optimized feature subset and optimize the sensitivity of defense strategies;
[0086] Attack source feature distribution: Optimize feature data to dynamically update the distribution of attack source IP, attack time period, and attack protocol type;
[0087] Dynamic adjustment of port risk level: Calculate the attack probability of the port by combining optimized feature data, and enhance or relax the defense strategy of specific ports;
[0088] S54. Execute the adaptive defense strategy according to the set defense strategy triggering conditions:
[0089] Traffic blocking: When high-risk attack traffic is detected, the attack source is automatically blocked and its communication with the victim is prevented; Port restriction: When a port is attacked multiple times in a short period of time and the posterior probability of the attack gradually increases, the access rights of the port are automatically restricted and the port opening policy is adjusted;
[0090] Isolation of infected nodes: When the same victim node is under continuous attack or a zero-day attack is confirmed, the node will be automatically isolated and its communication with other network devices will be blocked;
[0091] Traffic monitoring and tracing: Real-time monitoring of low-risk suspicious traffic, collection of attack source characteristics, and analysis of attacker behavior patterns, so as to take precise defense measures later;
[0092] Real-time security alerts: When a defense strategy is triggered, real-time alert information is automatically sent to the network security administrator, and the attack category, attack source, affected target, and recommended defense measures are provided;
[0093] S55. The executed defense strategy is stored in the defense strategy database, and the defense strategy is dynamically optimized based on the detection performance evaluation method:
[0094] If high-risk attack traffic still exists after traffic is blocked, adjust the blocking rules to improve the defense response speed;
[0095] If normal services are affected by port restrictions, optimize the port access control policy to reduce the probability of false blocking;
[0096] If the infected node continues to be attacked after being isolated, expand the isolation range and analyze the attack path;
[0097] If the false alarm rate is too high, resulting in an abnormal increase in the number of alarms, the detection algorithm is optimized based on the network traffic anomaly detection probability model to optimize the attack determination accuracy;
[0098] S56. Finally, an adaptive defense strategy set is formed, and the optimized defense strategy is applied to the network security system to achieve dynamic response and real-time defense against zero-day attacks.
[0099] The beneficial effects of the present invention are:
[0100] (1) The present invention proposes a network traffic feature optimization method combined with a hyperentropy differential evolution algorithm. By introducing a hyperentropy control mechanism and dynamically adjusting the feature search range, the detection model can accurately extract key features that can distinguish zero-day attacks in a complex network environment. A population dynamic adjustment strategy based on network risk information entropy is adopted to enable the feature selection process to adaptively adjust between global exploration and local development. The optimized feature subset can more effectively describe the zero-day attack pattern and has higher adaptability and detection stability in complex high-dimensional network data.
[0101] (2) The present invention adopts variational Bayesian reasoning to construct a network traffic anomaly detection probability model, and dynamically approximates the potential probability distribution of network data through variational inference methods, so that the detection system can quickly identify abnormal attack patterns in a real-time environment. The variational Bayesian reasoning model can dynamically update model parameters using new data to ensure that the detection model is adaptively adjusted as the network environment changes, thereby improving the detection capability of new zero-day attacks and the recognition capability of detecting new variant attacks.
[0102] (3) The present invention proposes an adaptive defense strategy driven by detection results. Through the detection results, the defense strategy is dynamically adjusted based on the posterior probability of the attack category, the abnormality score and the risk probability. The dynamic learning mechanism of the attack pattern based on the optimized feature data can adaptively optimize the defense parameters after discovering new attack behaviors, and dynamically adjust the defense measures such as traffic blocking, port restriction and infected node isolation, thereby improving the overall stability and defense capability of the network security system. BRIEF DESCRIPTION OF THE DRAWINGS
[0103] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0104] Figure 1 This is a flow chart of an artificial intelligence-based network security threat intelligent identification and defense method proposed by the present invention. DETAILED DESCRIPTION
[0105] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.
[0106] refer to Figure 1 , an artificial intelligence-based network security threat intelligent identification and defense method, comprising the following steps:
[0107] S1. Collect network traffic data, user behavior data and system log data from the network security system, and perform data cleaning, normalization, feature extraction and dimensionality reduction on the collected network data sets, and output the final converged network feature data set;
[0108] S2. Apply the hyperentropy differential evolution algorithm to the network feature data set for global optimization search, dynamically adjust the population evolution parameters by introducing the hyperentropy mechanism, realize the optimal subset selection and dimensionality reduction optimization of network features, and generate network feature data optimized by hyperentropy differential evolution;
[0109] S3. Use the network feature data optimized by hyperentropy differential evolution to build a network traffic anomaly detection probability model based on variational Bayesian reasoning, and use the variational reasoning method to approximate the potential probability distribution of the network feature data;
[0110] S4. Input the network feature data set into the network traffic anomaly detection probability model, use the network traffic anomaly detection probability model to perform real-time inference and abnormal behavior analysis on the network data, identify the abnormal data pattern with zero-day attack risk, and evaluate the risk probability of abnormal behavior;
[0111] S5. Generate an adaptive defense strategy based on the detection results. The adaptive defense strategy includes automatic blocking of abnormal traffic, restriction of suspicious ports, dynamic isolation of infected nodes, and real-time alerts to network security administrators, and form defense strategy data.
[0112] In this implementation, step S1 includes:
[0113] S11. Collect network traffic data, user behavior data and system log data to build network data set D:
[0114] D=D f ∪D u ∪D s ;
[0115] Among them, D f is a network traffic data set, including the traffic size, flow rate and communication protocol characteristics of network data packets, D u is a user behavior data set, including user login records, access frequency and interaction mode characteristics, D s It is a collection of system log data, including server logs, error logs and audit records;
[0116] S12. Perform data cleaning on the network data set D, remove duplicate data, missing data and abnormal data, use interpolation method to complete the missing data, and perform consistency check on the time series data to form a cleaned network data set;
[0117] S13. Normalize the cleaned network data set, use the minimum-maximum normalization method to map all eigenvalues to the interval [0,1], extract eigenvectors from the normalized network data set, obtain the feature matrix, reduce the dimension of the feature matrix, and finally form the network feature data set D o .
[0118] In this implementation, step S2 includes:
[0119] S21. Construct the initial differential evolution population P0, the initial differential evolution population represents the feature selection strategy for the network zero-day attack detection task, the network feature data set D o Contains M features, each candidate feature subset p i Encoded in the form of a continuous vector;
[0120] S22. Define the network risk information entropy function H net (p i ), which is used to measure the ability of each candidate feature subset to reveal information about potential zero-day attack risks in the network:
[0121]
[0122] Among them, α i,j represents the selection weight of the jth feature in the candidate feature subset, w j To select weights, which reflect the contribution of features to zero-day attack risk in revealing abnormal network behavior;
[0123] The average network risk information entropy of the differential evolution population in the tth generation is:
[0124]
[0125] Among them, represents the total number of individuals in the population;
[0126] The average network risk information entropy is used to comprehensively evaluate the overall performance of the current feature selection strategy in revealing network attack risk information;
[0127] S23. Based on the average network risk information entropy H(P t ), set the adaptive variation factor F net (H(P t )) to dynamically adjust the variation range:
[0128]
[0129] Among them, F min and F maxare the lower and upper limits of the mutation factor, respectively, which determine the minimum and maximum exploration amplitudes for searching for unknown attack features in the network environment. λ is the attenuation coefficient, which is used to control the sensitivity of the mutation factor to the change of network risk information entropy. max It is the maximum network risk information entropy that can be achieved in theory, representing the upper limit of all features fully displaying network risk information in extreme cases;
[0130] Generate mutant individuals v according to the adaptive mutation factor i :
[0131]
[0132] in, and is the differential evolution population P from the current t Randomly selected non-repeated individuals;
[0133] S24. In the variant individual v i Based on this, a crossover operation is performed to generate offspring individuals u i , set the adaptive crossover rate CR net (H(P t ));
[0134]
[0135] Among them, CR min With CR max are the lower and upper limits of the crossover rate, respectively reflecting the lowest and highest ratios of feature combinations retained in network anomaly detection;
[0136] Each component of the offspring individuals is obtained by the binomial crossover rule:
[0137]
[0138] Among them, u i,j Represents the specific characteristic value of the newly generated individual, rand i,j is a random number uniformly distributed in [0,1], j rand To ensure that at least one dimension of random indexing must be crossed;
[0139] S25. Define the network zero-day attack detection performance fitness function f net (p i )Evaluate the performance of each candidate feature subset in actual detection:
[0140]
[0141] Among them, Acc net (p i ) represents the candidate feature subset pi The accuracy of the constructed detection model in identifying zero-day attacks. ω and δ are weight coefficients for balancing the detection accuracy and the network risk information revealed by feature selection.
[0142] According to the fitness comparison of the network zero-day attack detection performance fitness function, the selection rule is used to update the differential evolution population:
[0143]
[0144] S26. Set the average fitness difference of two consecutive generations of differential evolution populations:
[0145]
[0146] When Δf is satisfied net <∈ or t≥T max When , the candidate feature subset is considered to have reached a stable state, where ∈ is the preset convergence accuracy threshold, T max is the maximum number of iterations; otherwise, return to step S22 to continue iterative updating;
[0147] S27. Output the final converged network feature data set P * :
[0148]
[0149] Among them, P * It is a collection of network feature data.
[0150] In this implementation, step S3 includes:
[0151] S31. Using the network feature data set P optimized by super entropy differential evolution * Construct a network traffic anomaly detection probability model, assuming that the optimized network feature data set is X, where Represents N network traffic feature samples, each sample x i It consists of M eigenvectors;
[0152] S32. For the task of network traffic anomaly detection, assume that the attack category Z obeys a discrete distribution, and the prior distribution is p(Z|θ). At the same time, the conditional distribution of network traffic data obeys a Gaussian mixture model, which is p(X|Z,θ).
[0153] S33. Use variational Bayesian inference method for approximate inference, define variational distribution q(Z) to approximate the true posterior distribution, and iteratively update variational parameter φ through variational inference i , obtain the optimal network traffic anomaly detection probability model after convergence;
[0154] S34. Calculate each sample x iPosterior probabilities of belonging to different attack categories:
[0155]
[0156] Among them, p(z i |x i ,θ) is used to evaluate the sample x i Whether it belongs to a certain attack type, realize the classification detection of unknown zero-day attacks, and use the expectation maximization algorithm to optimize the parameters Compute the update rule:
[0157]
[0158] in, Indicates the attack category z i The prior probability after the t+1th iteration is, Indicates the attack category z i The mean vector after the t+1th iteration, Indicates the attack category z i At t+
[0159] The covariance matrix after 1 iteration, p(z i |x i ,θ t ) means that at the tth iteration, the sample x i
[0160] Belongs to attack category z i The posterior probability, x i
[0161] represents the i-th network traffic sample, and t represents the current iteration step number;
[0162] S35. Define the convergence judgment of the network traffic anomaly detection probability model as:
[0163]
[0164] When Δθ<∈ or t≥T max When , the network traffic anomaly detection probability model is determined to have converged, where ∈ is the preset convergence accuracy threshold, T max is the maximum number of iterations; otherwise, return to step S34 to continue optimizing the network traffic anomaly detection probability model parameters;
[0165] S36. Output the optimized network traffic anomaly detection probability model, the posterior probability p(z i |x i ,θ) is used to evaluate whether there is an unknown attack in the current network traffic.
[0166] In this implementation, step S4 includes:
[0167] S41. The network feature data set P * Input to the network traffic anomaly detection probability model;
[0168] S42. Use the network traffic anomaly detection probability model to infer the standardized network feature data set X′ and calculate each network traffic sample x′ i The posterior probability of the attack category;
[0169] S43. Calculate the abnormality score S of each network traffic sample anom (x′ i ), the abnormality score is defined as the expected negative log-likelihood of each attack category, which is used to identify potential zero-day attack samples;
[0170] S44. Set the abnormality score S anom (x′ i ) threshold T anom , calculate the sample x′ i The risk probability of being judged as a zero-day attack. If the risk probability is close to 1, it means that the sample x′ i The probability belongs to zero-day attack;
[0171] S45. Classify network traffic using risk probability, and classify traffic with risk probability higher than a preset threshold value T risk The samples are classified as zero-day attacks, forming a zero-day attack detection result set;
[0172] S46. Calculate the current performance indicators of the network traffic anomaly detection probability model, including precision, recall and F1 score, and adaptively adjust the mechanism to optimize the parameters of the network traffic anomaly detection probability model based on the detection performance indicators.
[0173] In this implementation, step S5 includes:
[0174] S51. Take the zero-day attack detection result set as the input of defense decision, and calculate the attack category posterior probability and abnormality score S according to the network traffic anomaly detection probability model. anom and the risk probability p risk , classify the detected abnormal traffic, the classification includes:
[0175] High-risk attack traffic: When the attack category posterior probability of a network traffic sample is higher than the set threshold, and the abnormality score exceeds the high-risk threshold, it is determined to be high-risk attack traffic;
[0176] Continuous attack behavior: When a certain IP address or port is identified as high-risk attack traffic multiple times in a short period of time, and the attack behavior persists, it is considered a continuous attack behavior;
[0177] Low-risk suspicious traffic: When the attack category posterior probability of a network traffic sample is in the suspicious range, but the abnormality score does not reach the high-risk threshold, it is judged as low-risk suspicious traffic and monitoring measures are taken;
[0178] S52. Based on the posterior probability calculated by the network traffic anomaly detection probability model and the feature data optimized by super entropy differential evolution, the triggering conditions of the adaptive defense strategy are dynamically set:
[0179] When the amount of high-risk attack traffic exceeds the set threshold and the attack sources are relatively concentrated, the automatic blocking strategy is triggered;
[0180] When continuous attack behavior is detected and the attack targets involve multiple victim nodes, the infected node isolation strategy is triggered;
[0181] When low-risk suspicious traffic is detected to continue to increase but has not yet posed a direct threat to the network system, the traffic monitoring strategy is triggered and defense measures are dynamically adjusted;
[0182] S53. Use the optimized feature subset to construct a dynamically adjusted defense parameter set so that the defense strategy can adaptively adjust the defense rules. The defense parameters include:
[0183] Variation trend of attack behavior: Calculate the variation of attack patterns based on the optimized feature subset and optimize the sensitivity of defense strategies;
[0184] Attack source feature distribution: Optimize feature data to dynamically update the distribution of attack source IP, attack time period, and attack protocol type;
[0185] Dynamic adjustment of port risk level: Calculate the attack probability of the port by combining optimized feature data, and enhance or relax the defense strategy of specific ports;
[0186] S54. Execute the adaptive defense strategy according to the set defense strategy triggering conditions:
[0187] Traffic blocking: When high-risk attack traffic is detected, the attack source is automatically blocked and its communication with the victim is prevented; Port restriction: When a port is attacked multiple times in a short period of time and the posterior probability of the attack gradually increases, the access rights of the port are automatically restricted and the port opening policy is adjusted;
[0188] Isolation of infected nodes: When the same victim node is under continuous attack or a zero-day attack is confirmed, the node will be automatically isolated and its communication with other network devices will be blocked;
[0189] Traffic monitoring and tracing: Real-time monitoring of low-risk suspicious traffic, collection of attack source characteristics, and analysis of attacker behavior patterns, so as to take precise defense measures later;
[0190] Real-time security alerts: When a defense strategy is triggered, real-time alert information is automatically sent to the network security administrator, and the attack category, attack source, affected target, and recommended defense measures are provided;
[0191] S55. The executed defense strategy is stored in the defense strategy database, and the defense strategy is dynamically optimized based on the detection performance evaluation method:
[0192] If high-risk attack traffic still exists after traffic is blocked, adjust the blocking rules to improve the defense response speed;
[0193] If normal services are affected by port restrictions, optimize the port access control policy to reduce the probability of false blocking;
[0194] If the infected node continues to be attacked after being isolated, expand the isolation range and analyze the attack path;
[0195] If the false alarm rate is too high, resulting in an abnormal increase in the number of alarms, the detection algorithm is optimized based on the network traffic anomaly detection probability model to optimize the attack determination accuracy;
[0196] S56. Finally, an adaptive defense strategy set is formed, and the optimized defense strategy is applied to the network security system to achieve dynamic response and real-time defense against zero-day attacks.
[0197] Embodiment 1:
[0198] On March 5, 2024, the network security team of a financial institution discovered abnormal network traffic in the core server cluster during routine monitoring. The system log showed that some servers experienced a large number of abnormal SSH access attempts between 2:14 and 2:26 in the morning, among which the traffic characteristics of the source IP address "192.168.1.100" were highly abnormal. In just 12 minutes, this IP address sent more than 7,500 login requests to servers "10.0.0.15" and "10.0.0.22" and used a variety of different SSH keys for attempts. Since this behavior was not recognized by the traditional intrusion detection system, the security team decided to enable the method of the present invention for further analysis.
[0199] The method of the present invention first cleans and normalizes the network traffic data of the past 48 hours, extracts network traffic data packet features, user login behavior features, and system log event features. Subsequently, the system uses a hyperentropy differential evolution algorithm to optimize the feature data and automatically selects the key feature set that best characterizes abnormal behavior. The optimized features show that the traffic behavior of the IP address has the following significant anomalies:
[0200] 1. Abnormal source port change frequency: The source port of 192.168.1.100 keeps changing in a short period of time, changing the port more than 40 times per second on average, while normal users' SSH access usually maintains a fixed source port.
[0201] 2. Abnormal access frequency of destination ports: The IP address accessed 22 different servers within 10 minutes, of which 80% accessed target ports 22 (SSH), 3389 (Remote Desktop), and 5432 (Database), which are common attack target ports.
[0202] 3. Abnormal data packet size distribution: The data packet size of a normal user SSH session is usually stable at 800-1500 bytes, while the SSH data packet size of 192.168.1.100 varies randomly within the range of 500-2000 bytes, which conforms to the typical pattern of SSH brute force cracking + covert data penetration attack.
[0203] The detection model inputs the optimized feature data into the variational Bayesian inference model for inference, and calculates the posterior probability of the attack category and the abnormality score of the IP.
[0204] Posterior probability of attack category: The model calculation found that the posterior probability of this IP address belonging to SSH brute force attack is 93.6%, the posterior probability of belonging to remote desktop attack is 4.1%, and the posterior probability of belonging to normal user behavior is only 2.3%.
[0205] Abnormality score: The SSH traffic abnormality score of this IP is 8.73 (the average score of normal users is about 3.12, and the threshold is 6.5), indicating that this traffic pattern is very likely to be a malicious attack behavior.
[0206] The system finally determined that 192.168.1.100 was very likely to be conducting an SSH brute force attack and might try to further expand the scope of the attack. The system then automatically generated an attack event report, recording the following:
[0207] Attack time: 02:14–02:26, March 5, 2024;
[0208] Attack source IP: 192.168.1.100;
[0209] Victim servers: 10.0.0.15, 10.0.0.22, 10.0.0.30;
[0210] Attack type: SSH brute force cracking + port scanning + hidden data penetration;
[0211] Attack characteristics: random changes in source ports, frequent access to destination ports, and unstable data packet sizes;
[0212] Attack posterior probability: 93.6%;
[0213] Abnormality score: 8.73;
[0214] After detecting an attack, the system automatically executes an adaptive defense strategy and takes the following measures:
[0215] 1. Traffic blocking: Automatically block all outbound traffic from 192.168.1.100 and record it in the firewall log.
[0216] 2. Port restriction: Limit SSH ports 10.0.0.15, 10.0.0.22, and 10.0.0.30 to only allow trusted IP addresses to access, and increase the threshold for failed login attempts.
[0217] 3. Isolation of infected nodes: Since 10.0.0.15 is suspected to have been successfully hacked, the system automatically isolates it from the core network and initiates a security review procedure.
[0218] 4. Real-time security alerts: The system sends high-priority security alerts to the security operation and maintenance team, including attack source information, attack behavior analysis, and recommended defense measures.
[0219] The comparison results show that the method of the present invention can detect attacks faster than traditional IDS (recognition time is reduced from 213 seconds to 2.1 seconds), while reducing false alarms and improving the automated response speed of the defense strategy (defense response time is shortened from 110 seconds to 4.2 seconds).
[0220] Within two hours after the incident, the system used historical data to conduct further attack source tracing analysis and found that the attack source 192.168.1.100 had scanned network ports at a low frequency many times in the past two days, but had not previously triggered the alarm rules of the traditional IDS. The method of the present invention discovered these low-frequency attack precursors through the feature subset optimized by hyper-entropy differential evolution, and in future defense strategy optimization, similar behaviors will be included in the potential threat monitoring list to enable earlier detection of attacker activities.
[0221] Over the next two weeks, the financial institution’s overall cybersecurity defense capabilities were significantly improved, the system’s detection efficiency for potential zero-day attacks increased by 67.2%, and two similar SSH brute force attacks were successfully blocked.
[0222] This example demonstrates the practical application effect of the method of the present invention in the network security protection of financial institutions. Experimental data show that the method of the present invention can accurately detect zero-day attacks and quickly prevent the spread of attacks through adaptive defense strategies. Compared with traditional IDS, the detection speed is increased by 100 times and the defense response time is shortened by 26 times, effectively improving the intelligent level of network security.
[0223] The present invention proposes a network traffic feature optimization method combined with a hyper-entropy differential evolution algorithm. By introducing a hyper-entropy control mechanism and dynamically adjusting the feature search range, the detection model can accurately extract key features that can distinguish zero-day attacks in a complex network environment. A population dynamic adjustment strategy based on network risk information entropy is adopted to enable the feature selection process to adaptively adjust between global exploration and local development. The optimized feature subset can more effectively describe the zero-day attack mode and has higher adaptability and detection stability in complex high-dimensional network data.
[0224] The present invention adopts variational Bayesian reasoning to construct a network traffic anomaly detection probability model, and dynamically approximates the potential probability distribution of network data through variational inference methods, so that the detection system can quickly identify abnormal attack patterns in a real-time environment. The variational Bayesian reasoning model can dynamically update model parameters using new data to ensure that the detection model is adaptively adjusted as the network environment changes, thereby improving the detection capability of new zero-day attacks and the recognition capability of detecting new variant attacks.
[0225] The present invention proposes an adaptive defense strategy driven by detection results. Through the detection results, the defense strategy is dynamically adjusted based on the posterior probability of the attack category, the abnormality score and the risk probability. The dynamic learning mechanism of the attack pattern based on the optimized feature data can adaptively optimize the defense parameters after discovering new attack behaviors, dynamically adjust the defense measures of traffic blocking, port restriction and infected node isolation, and improve the overall stability and defense capability of the network security system.
[0226] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. An artificial intelligence-based network security threat intelligent identification and defense method, characterized in that: The steps include: S1. Collect network traffic data, user behavior data and system log data from the network security system, and perform data cleaning, normalization, feature extraction and dimensionality reduction on the collected network data sets, and output the final converged network feature data set; S2. Apply the hyperentropy differential evolution algorithm to the network feature data set for global optimization search, dynamically adjust the population evolution parameters by introducing the hyperentropy mechanism, realize the optimal subset selection and dimensionality reduction optimization of network features, and generate network feature data optimized by hyperentropy differential evolution; S3. Use the network feature data optimized by hyperentropy differential evolution to build a network traffic anomaly detection probability model based on variational Bayesian reasoning, and use the variational reasoning method to approximate the potential probability distribution of the network feature data; S4. Input the network feature data set into the network traffic anomaly detection probability model, use the network traffic anomaly detection probability model to perform real-time inference and abnormal behavior analysis on the network data, identify the abnormal data patterns with zero-day attack risks, and evaluate the risk probability of abnormal behavior; S5. Generate an adaptive defense strategy based on the detection results, the adaptive defense strategy includes automatic blocking of abnormal traffic, restriction of suspicious ports, dynamic isolation of infected nodes, and real-time alerts to network security administrators, and form defense strategy data.
2. The method for intelligent identification and defense of network security threats based on artificial intelligence according to claim 1 is characterized in that: The step S1 comprises: S11. Collect network traffic data, user behavior data and system log data to build network data set D: D=D f ∪D u ∪D s ; Among them, D f is a network traffic data set, including the traffic size, flow rate and communication protocol characteristics of network data packets, D u is a user behavior data set, including user login records, access frequency and interaction mode characteristics, D s It is a collection of system log data, including server logs, error logs and audit records; S12. Perform data cleaning on the network data set D, remove duplicate data, missing data and abnormal data, use interpolation method to complete the missing data, and perform consistency check on the time series data to form a cleaned network data set; S13. Normalize the cleaned network data set, use the minimum-maximum normalization method to map all eigenvalues to the interval [0,1], extract eigenvectors from the normalized network data set, obtain the feature matrix, reduce the dimension of the feature matrix, and finally form the network feature data set D o .
3. The method for intelligent identification and defense of network security threats based on artificial intelligence according to claim 1 is characterized in that: The step S2 comprises: S21. Construct the initial differential evolution population P0, the initial differential evolution population represents the feature selection strategy for the network zero-day attack detection task, the network feature data set D o Contains M features, each candidate feature subset p i Encoded in the form of a continuous vector; S22. Define the network risk information entropy function H net (p i ), which is used to measure the ability of each candidate feature subset to reveal information about potential zero-day attack risks in the network: Among them, α i,j represents the selection weight of the jth feature in the candidate feature subset, w j To select weights, which reflect the contribution of features to zero-day attack risk in revealing abnormal network behavior; The average network risk information entropy of the differential evolution population in the tth generation is: Among them, represents the total number of individuals in the population; The average network risk information entropy is used to comprehensively evaluate the overall performance of the current feature selection strategy in revealing network attack risk information; S23. Based on the average network risk information entropy H(P t ), set the adaptive variation factor F net (H(P t )) to dynamically adjust the variation range: Among them, F min and F max are the lower and upper limits of the mutation factor, respectively, which determine the minimum and maximum exploration amplitudes for searching for unknown attack features in the network environment. λ is the attenuation coefficient, which is used to control the sensitivity of the mutation factor to the change of network risk information entropy. max It is the maximum network risk information entropy that can be achieved in theory, representing the upper limit of all features fully displaying network risk information in extreme cases; Generate mutant individuals v according to the adaptive mutation factor i : Among them, p r1 、p r2 and p r3 is the differential evolution population P from the current t Randomly selected non-repeated individuals; S24. In the variant individual v i Based on this, a crossover operation is performed to generate offspring individuals u i , set the adaptive crossover rate CR net (H(P t )); Among them, CR min With CR max are the lower and upper limits of the crossover rate, respectively reflecting the lowest and highest ratios of feature combinations retained in network anomaly detection; Each component of the offspring individuals is obtained by the binomial crossover rule: Among them, u i,j Represents the specific characteristic value of the newly generated individual, rand i,j is a random number uniformly distributed in [0,1], j rand To ensure that at least one dimension of random indexing must be crossed; S25. Define the network zero-day attack detection performance fitness function f net (p i )Evaluate the performance of each candidate feature subset in actual detection: Among them, Acc net (p i ) represents the candidate feature subset p i The accuracy of the constructed detection model in identifying zero-day attacks. ω and δ are weight coefficients for balancing the detection accuracy and the network risk information revealed by feature selection. According to the fitness comparison of the network zero-day attack detection performance fitness function, the selection rule is used to update the differential evolution population: S26. Set the average fitness difference of two consecutive generations of differential evolution populations: When Δf is satisfied net <∈ or t≥T max When , the candidate feature subset is considered to have reached a stable state, where ∈ is the preset convergence accuracy threshold, T max is the maximum number of iterations; otherwise, return to step S22 to continue iterative updating; S27. Output the final converged network feature data set P * : Among them, P * It is a collection of network feature data.
4. The method for intelligent identification and defense of network security threats based on artificial intelligence according to claim 1 is characterized in that: The step S3 comprises: S31. Using the network feature data set P optimized by super entropy differential evolution * Construct a network traffic anomaly detection probability model, assuming that the optimized network feature data set is X, where Represents N network traffic feature samples, each sample x i It consists of M eigenvectors; S32. For the task of network traffic anomaly detection, assume that the attack category Z obeys a discrete distribution, and the prior distribution is p(Z|θ). At the same time, the conditional distribution of network traffic data obeys a Gaussian mixture model, which is p(X|Z,θ). S33. Use variational Bayesian inference method for approximate inference, define variational distribution q(Z) to approximate the true posterior distribution, and iteratively update variational parameter φ through variational inference i , obtain the optimal network traffic anomaly detection probability model after convergence; S34. Calculate each sample x i Posterior probabilities of belonging to different attack categories: Among them, p(z i |x i ,θ) is used to evaluate the sample x i Whether it belongs to a certain attack type, realize the classification detection of unknown zero-day attacks, and use the expectation maximization algorithm to optimize the parameters Compute the update rule: in, Indicates the attack category z i The prior probability after the t+1th iteration is, Indicates the attack category z i The mean vector after the t+1th iteration, Indicates the attack category z i The covariance matrix after the t+1th iteration, p(z i |x i ,θ t ) means that at the tth iteration, the sample x i Belongs to attack category z i The posterior probability, x i represents the i-th network traffic sample, and t represents the current iteration step number; S35. Define the convergence judgment of the network traffic anomaly detection probability model as: When Δθ<∈ or t≥T max When , the network traffic anomaly detection probability model is determined to have converged, where ∈ is the preset convergence accuracy threshold, T max is the maximum number of iterations; otherwise, return to step S34 to continue optimizing the network traffic anomaly detection probability model parameters; S36. Output the optimized network traffic anomaly detection probability model, the posterior probability p(z i |x i ,θ) is used to evaluate whether there is an unknown attack in the current network traffic.
5. The method for intelligent identification and defense of network security threats based on artificial intelligence according to claim 1 is characterized in that: The step S4 comprises: S41. The network feature data set P * Input to the network traffic anomaly detection probability model; S42. Use the network traffic anomaly detection probability model to infer the standardized network feature data set X′ and calculate each network traffic sample x′ i The posterior probability of the attack category; S43. Calculate the abnormality score S of each network traffic sample anom (x′ i ), the abnormality score is defined as the expected negative log-likelihood of each attack category, which is used to identify potential zero-day attack samples; S44. Set the abnormality score S anom (x′ i ) threshold T anom , calculate the sample x′ i The risk probability of being judged as a zero-day attack. If the risk probability is close to 1, it means that the sample x′ i The probability belongs to zero-day attack; S45. Classify network traffic using risk probability, and classify traffic with risk probability higher than a preset threshold value T risk The samples are classified as zero-day attacks, forming a zero-day attack detection result set; S46. Calculate the current performance indicators of the network traffic anomaly detection probability model, including precision, recall and F1 score, and adaptively adjust the mechanism to optimize the parameters of the network traffic anomaly detection probability model based on the detection performance indicators.
6. The method for intelligent identification and defense of network security threats based on artificial intelligence according to claim 1 is characterized in that: The step S5 comprises: S51. Take the zero-day attack detection result set as the input of defense decision, and calculate the attack category posterior probability and abnormality score S according to the network traffic anomaly detection probability model. anom and the risk probability p risk , classify the detected abnormal traffic, the classification includes: High-risk attack traffic: When the attack category posterior probability of a network traffic sample is higher than the set threshold, and the abnormality score exceeds the high-risk threshold, it is determined to be high-risk attack traffic; Continuous attack behavior: When a certain IP address or port is identified as high-risk attack traffic multiple times in a short period of time, and the attack behavior persists, it is considered a continuous attack behavior; Low-risk suspicious traffic: When the attack category posterior probability of a network traffic sample is in the suspicious range, but the abnormality score does not reach the high-risk threshold, it is judged as low-risk suspicious traffic and monitoring measures are taken; S52. Based on the posterior probability calculated by the network traffic anomaly detection probability model and the feature data optimized by super entropy differential evolution, the triggering conditions of the adaptive defense strategy are dynamically set: When the amount of high-risk attack traffic exceeds the set threshold and the attack sources are relatively concentrated, the automatic blocking strategy is triggered; When continuous attack behavior is detected and the attack targets involve multiple victim nodes, the infected node isolation strategy is triggered; When low-risk suspicious traffic is detected to continue to increase but has not yet posed a direct threat to the network system, the traffic monitoring strategy is triggered and defense measures are dynamically adjusted; S53. Use the optimized feature subset to construct a dynamically adjusted defense parameter set so that the defense strategy can adaptively adjust the defense rules. The defense parameters include: Variation trend of attack behavior: Calculate the variation of attack patterns based on the optimized feature subset and optimize the sensitivity of defense strategies; Attack source feature distribution: Optimize feature data to dynamically update the distribution of attack source IP, attack time period, and attack protocol type; Dynamic adjustment of port risk level: Calculate the attack probability of the port by combining optimized feature data, and enhance or relax the defense strategy of specific ports; S54. Execute the adaptive defense strategy according to the set defense strategy triggering conditions: Traffic blocking: When high-risk attack traffic is detected, the attack source is automatically blocked and its communication with the victim is prevented; Port restriction: When a port is attacked multiple times in a short period of time and the posterior probability of the attack gradually increases, the access rights of the port are automatically restricted and the port opening policy is adjusted; Isolation of infected nodes: When the same victim node is under continuous attack or a zero-day attack is confirmed, the node will be automatically isolated and its communication with other network devices will be blocked; Traffic monitoring and tracing: Real-time monitoring of low-risk suspicious traffic, collection of attack source characteristics, and analysis of attacker behavior patterns, so as to take precise defense measures later; Real-time security alerts: When a defense strategy is triggered, real-time alert information is automatically sent to the network security administrator, and the attack category, attack source, affected target, and recommended defense measures are provided; S55. The executed defense strategy is stored in the defense strategy database, and the defense strategy is dynamically optimized based on the detection performance evaluation method: If high-risk attack traffic still exists after traffic is blocked, adjust the blocking rules to improve the defense response speed; If normal services are affected by port restrictions, optimize the port access control policy to reduce the probability of false blocking; If the infected node continues to be attacked after being isolated, expand the isolation range and analyze the attack path; If the false alarm rate is too high, resulting in an abnormal increase in the number of alarms, the detection algorithm is optimized based on the network traffic anomaly detection probability model to optimize the attack determination accuracy; S56. Finally, an adaptive defense strategy set is formed, and the optimized defense strategy is applied to the network security system to achieve dynamic response and real-time defense against zero-day attacks.
Citation Information
Patent Citations
Low-speed denial of service attack detection method based on cloud model
CN109450957A
DDoS attack situation evaluation method and device
CN110445766A
Information network security self-defense method and system based on trusted computing
CN119254489A
Cited By
Network security management method and system based on artificial intelligence
CN120498808A
An artificial intelligence-based network security management method and system
CN120498808B
Self-adaptive dynamic network security policy intelligent regulation and control method
CN120582836A
Risk defense method and device based on network cloud security detection and medium
CN120639440A
Abnormal traffic detection and attack identification method and system based on deep learning
CN120880794A