Convolutional Trans-based symmetric encryption intrusion detection method and system
Patent Information
- Application Number
- CN202510162211.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing network intrusion detection systems have problems with low data leakage and detection efficiency, making it difficult to improve detection accuracy while ensuring data privacy.
The symmetric encryption intrusion detection method based on convolutional Trans is adopted, and the training data set is encrypted, the features are extracted using convolutional neural network (CNN), and combined with the self-attention mechanism of the Transformer model, efficient classification and detection of intrusion behavior is achieved.
Effectively avoid information leakage, improve detection efficiency, improve the accuracy of network intrusion detection, and protect data privacy. It is suitable for a variety of complex IoT scenarios.
Smart Images

Figure CN120034369A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of nuclear fusion safety technology, and in particular relates to a symmetric encryption intrusion detection method and system based on convolution Trans. Background Art
[0002] The field of nuclear fusion is a highly complex and critical field, and its security is of great significance for the use of future ultimate energy and national security. With the continuous increase of network attacks and abnormal behaviors, the field of nuclear fusion faces more and more security threats. Network intrusion detection is an efficient network security technology that can detect and block abnormal behaviors in the network in time to ensure the safety of personnel and data in the nuclear fusion system. In the field of nuclear fusion, intrusion detection can effectively ensure the security of the system, prevent network attacks and abnormal behaviors from affecting the ultimate clean energy of nuclear fusion, protect and prevent abnormal behaviors and attacks in the system, and ensure the safety of the nuclear fusion system.
[0003] Currently, many network intrusion detection systems face problems such as data leakage and low detection efficiency. Existing intrusion detection methods usually rely on simple data feature analysis and are easily disguised and bypassed by attackers. Therefore, how to improve the accuracy of detection while ensuring data privacy has become an urgent problem to be solved. Summary of the invention
[0004] In order to solve the problems in the prior art, the present invention proposes a symmetric encryption intrusion detection method and system based on convolutional Trans, which has simple steps, reasonable design, and effectively improves the accuracy of intrusion detection. By encrypting the training data set and using convolutional neural network (CNN) to extract features, combined with the self-attention mechanism of the Transformer model, this method can effectively avoid information leakage and improve detection efficiency.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] A symmetric encryption intrusion detection method based on convolutional Trans, the method comprising the following steps:
[0007] Step 1: Obtain a data set and encrypt it to obtain a preliminary training data set;
[0008] Step 2: Establish a CNN network model to perform feature learning on the preliminary training data set to obtain the final training data set;
[0009] Step 3: Establish a Transformer network model, input the final training data set into the Transformer network model for processing, and output and save the intrusion detection model corresponding to each training data set in the final training data set;
[0010] Step 4: Based on the saved intrusion detection model, the acquired flow data of the network system to be tested is monitored and matched.
[0011] On the other hand, the present invention provides a symmetric encryption intrusion detection system based on convolution Trans, the system comprising:
[0012] A data set acquisition unit, used to acquire and encrypt a data set to obtain a preliminary training data set;
[0013] A feature learning unit is used to establish a CNN network model to perform feature learning on the preliminary training data set to obtain a final training data set;
[0014] A detection model acquisition unit is used to establish a Transformer network model, input the final training data set into the Transformer network model for processing, and output and save an intrusion detection model corresponding to each training data set in the final training data set;
[0015] The monitoring unit is used to monitor and match the acquired flow data of the network system to be tested based on the saved intrusion detection model.
[0016] In a third aspect, the present invention provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the aforementioned symmetric encryption intrusion detection method based on convolutional Trans.
[0017] In a fourth aspect, the present invention provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, enables the processor to implement the aforementioned symmetric encryption intrusion detection method based on convolutional Trans.
[0018] The beneficial effects of the present invention are:
[0019] The method of the present invention has simple steps and reasonable design, solves the current problems of information leakage caused by simple information and low detection efficiency caused by model aging, and improves the accuracy of network intrusion detection.
[0020] The present invention establishes a Transformer model and adopts an attention architecture to learn features more efficiently. The encrypted data is more convenient for natural language processing. Transformer has a natural advantage in processing natural language, and has the ability to handle long-term dependent relationships and improve parallel processing capabilities, which has a good effect on improving intrusion detection capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 This is a flow chart of a symmetric encryption intrusion detection method based on convolutional Trans in the present invention. DETAILED DESCRIPTION
[0022] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0023] like Figure 1 As shown, the present invention is based on a symmetric encryption intrusion detection method based on convolution Trans, comprising the following steps:
[0024] Step 1: Obtain a data set and encrypt it to obtain a preliminary training data set;
[0025] Step 101: Perform a symmetric encryption algorithm on the NSL_KDD data set. There are two types of data in the data set: one is a stable point representing fixed information, and the other is an unstable point responsible for monitoring and identifying malicious access. For such a situation, the stable point communicates with a group of IoT systems;
[0026] Specifically, we extract stable points representing fixed information from the NSL_KDD dataset and use these stable points to perform encrypted communication with the IoT platform. ; N stands for the IoT platform, and N represents the total number of stable points. By adjusting the communication method and controller, data can be shared and updated:
[0027] ,
[0028] ,
[0029] ,
[0030] In the formula, On behalf of the IoT platform, the controller is modified by modifying the communication method so that data can be shared and updated ,N represents the total number of stable points. By adjusting the communication method and controller, we ensure that data can be shared and updated. MA represents the number of malicious accesses in the system. represents the number of controller modifications within a unit time T, P represents the malicious access count indicator, AES represents the symmetric encryption algorithm, and the variable Represents the response rate and prediction failure in the system, constraints and It is used to map malicious access under the system. Through such algorithm encryption, the acquired data set is encrypted, and the fields that need to be encrypted are analyzed, including protocol indicators, IP addresses, timestamps, etc. The selected encrypted fields are encrypted by encryption algorithm and key generation to ensure that each field uses the same encryption algorithm and key. Finally, the encrypted data set is saved.
[0031] Step 102: divide the encrypted data set, i.e., the preliminary training data set, into normal network traffic and abnormal network traffic as a training data set and a test data set; 70% is used as a training data set, 10% is used as a verification data set, and 20% is used as a test data set; wherein the number of training data sets is M, the number of test data sets is Q, and M is greater than Q; the network traffic data in the above data set contains four network anomalies, namely, Probe, Dos, U2R, and R2L;
[0032] Different types of network traffic data in the training data set M are labeled, where the types are 1, 2, 3, 4, and 5, representing Normal, Probe, Dos, U2R, and R2L, respectively.
[0033] Step 2: Establish a CNN network model to perform feature learning on the preliminary training data set to obtain the final training data set;
[0034] Step 201, establishing a CNN network model;
[0035] Step 202: input the M preliminary training data into the CNN model for feature learning to obtain M training data after feature extraction;
[0036] Step 203: normalize the training data after the M features are extracted to obtain a final training data set;
[0037] In step 201, the CNN network model includes an input layer, a first convolutional layer, a first pooling layer, a second convolutional layer, a second pooling layer, a third convolutional layer, a third pooling layer, a fully connected layer and an output layer; the input layer is 41×1, the number of convolution kernels in the first layer is 32, the size of the convolution kernel in the second layer is 3×3, and the sliding step is 1; the first pooling kernel is 2×1, and the sliding step is 2; the number of convolutions in the second convolutional layer is 64, the size of the convolution kernel is 3×3, and the sliding step is 1; the size of the pooling kernel in the second pooling layer is 2×1, and the sliding step is 2; the number of convolutions in the third convolutional layer is 128, the size of the convolution kernel is 3×3, and the sliding step is 1; the size of the pooling kernel in the second pooling layer is 2×1, and the sliding step is 2; the output layer has five nodes.
[0038] Step 3: Establish a Transformer network model, input the final training data set into the Transformer network model for processing, and output and save the intrusion detection model corresponding to each training data set in the final training data set;
[0039] The Transformer model includes an encoder, a decoder, and a Softmax classification layer connected in series in sequence. The encoder includes a self-attention mechanism, a residual link, and a normalization layer. The decoder includes a corresponding self-attention mechanism, a residual link, and a normalization layer. The Softmax classification layer includes five neural units.
[0040] The activation functions of the Transformer network model are Sigmiod function, Relu function and Than function, and the hidden nodes are 5-100.
[0041] The M normalized data, i.e., the final training data set, are processed by the established Transformer network model to obtain the probability distribution corresponding to the M normalized data, which can also be called the training weight, and the weight (probability distribution) is saved; wherein the probability corresponding to each training data set is from S1...S5, which respectively corresponds to the probability distribution of different network states, and the different network states correspond to different intrusion detection models.
[0042] Step 4: Based on the saved intrusion detection model, the acquired flow data of the network system to be tested is monitored and matched.
[0043] The network traffic data of the system under test is detected in real time, and the obtained network traffic of the system under test is processed according to steps 1 and 2 and then input into the Transformer network model. The obtained probability distribution is matched with different intrusion detection models to obtain the intrusion status of the network.
[0044] Furthermore, the convolution kernel and pooling kernel are all 3 rows × 3 columns.
[0045] Furthermore, M is 6000 and N is 4000.
[0046] Furthermore, Normal means normal network traffic data; DoS means denial of service, i.e., a dos attack sends a large amount of traffic or information to the target server, making it impossible to access the target normally. R2L means remote intrusion, i.e., a remote user attacks by exploiting security vulnerabilities and performing illegal operations by remotely logging into the computer. Probe means probing attacks, i.e., collecting information by scanning the network; U2R means obtaining permissions, i.e., obtaining root permissions by illegal means;
[0047] Furthermore, in actual use, the test data set in step 101 is tested according to the methods of steps 1 to 3 to ensure that the trained Transformer network model meets the requirements.
[0048] In summary, the present invention uses a symmetric encryption algorithm (such as AES) to encrypt and protect the data in the IoT system, and extracts the local features of the encrypted data through a convolutional neural network (CNN), and then inputs it into the Transformer network. Transformer uses a self-attention mechanism to capture the temporal correlation and global dependency of traffic features to achieve efficient classification and detection of intrusion behaviors. This method completes the classification output through a fully connected layer, combined with an online update mechanism, continuously optimizes the model performance, ensures high accuracy of intrusion detection, and protects data privacy at the same time, and is suitable for a variety of complex IoT scenarios.
[0049] On the other hand, the present invention provides a symmetric encryption intrusion detection system based on convolution Trans, wherein each unit included in the system can implement each step of the aforementioned method. Specifically, the system includes:
[0050] A data set acquisition unit, used to acquire and encrypt a data set to obtain a preliminary training data set;
[0051] A feature learning unit is used to establish a CNN network model to perform feature learning on the preliminary training data set to obtain a final training data set;
[0052] A detection model acquisition unit is used to establish a Transformer network model, input the final training data set into the Transformer network model for processing, and output and save an intrusion detection model corresponding to each training data set in the final training data set;
[0053] The monitoring unit is used to monitor and match the acquired flow data of the network system to be tested based on the saved intrusion detection model.
[0054] In a third aspect, the present invention provides an electronic device, comprising: one or more processors; a memory for storing one or more programs; wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the aforementioned symmetric encryption intrusion detection method based on convolutional Trans.
[0055] In a fourth aspect, the present invention provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, enables the processor to implement the aforementioned symmetric encryption intrusion detection method based on convolutional Trans.
[0056] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A symmetric encryption intrusion detection method based on convolutional Trans, characterized in that: The method comprises the following steps: Step 1: Obtain a data set and encrypt it to obtain a preliminary training data set; Step 2: Establish a CNN network model to perform feature learning on the preliminary training data set to obtain the final training data set; Step 3: Establish a Transformer network model, input the final training data set into the Transformer network model for processing, and output and save the intrusion detection model corresponding to each training data set in the final training data set; Step 4: Based on the saved intrusion detection model, the acquired flow data of the network system to be tested is monitored and matched.
2. According to claim 1, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: The step 1 comprises: Step 101: Extract stable points representing fixed information from the NSL_KDD data set, and use the stable points to perform encrypted communication with the IoT platform ; N stands for the IoT platform, and N represents the total number of stable points. By adjusting the communication method and controller, data can be shared and updated: , , , Among them, MA represents the number of malicious accesses in the IoT system. represents the number of controller modifications within a unit time T, P represents the malicious access count indicator, AES represents the symmetric encryption algorithm, Represents the response rate and prediction failure times in the IoT system, constraints and Used for mapping system; the mapped data is integrated to form an encrypted data set, i.e., a preliminary training data set; Step 102: divide the preliminary training data set into normal network traffic and abnormal network traffic, and use 70% as the training data set, 10% as the verification data set, and 20% as the test data set respectively; the number of training data sets is M, the number of test data sets is Q, and M is greater than Q.
3. According to claim 2, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: The step 2 comprises: Step 201, establishing a CNN network model; Step 202: input the M preliminary training data sets into the CNN network model for feature learning, and obtain M training data sets after feature extraction; Step 203: normalize the training data set after the M features are extracted to obtain a final training data set.
4. According to claim 3, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: In step 201, the CNN network model includes an input layer, a first convolutional layer, a first pooling layer, a second convolutional layer, a second pooling layer, a third convolutional layer, a third pooling layer, a fully connected layer and an output layer which are sequentially connected; the input layer size is 41×1, the number of convolution kernels in the first convolutional layer is 32, the convolution kernel size is 3×3, and the sliding step is 1; the pooling kernel size of the first pooling layer is 2×1, and the sliding step is 2; the number of convolution kernels in the second convolutional layer is 64, the convolution kernel size is 3×3, and the sliding step is 1; the pooling kernel size in the second pooling layer is 2×1, and the sliding step is 2; the number of convolution kernels in the third convolutional layer is 128, the convolution kernel size is 3×3, and the sliding step is 1; the pooling kernel size in the third pooling layer is 2×1, and the sliding step is 2; and the output layer has five nodes.
5. According to claim 1, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: In step 3, the Transformer model includes an encoder, a decoder, and a Softmax classification layer connected in series in sequence, the encoder includes a self-attention mechanism, a residual link, and a normalization layer, the decoder includes a corresponding self-attention mechanism, a residual link, and a normalization layer, and the Softmax classification layer includes five neural units.
6. According to claim 5, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: The activation functions of the Transformer network model are Sigmiod function, Relu function and Than function, and the number of hidden nodes is 5-100.
7. According to claim 1, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: In step 3, the valid training data set is input into the Transformer network model for processing, and the intrusion detection model corresponding to each training data set in the final training data set is output and saved, including inputting M final training data sets into the Transformer network model for processing to obtain the probability distribution of different network states corresponding to the M final training data sets, and the different network states correspond to different intrusion detection models.
8. According to claim 1, a symmetric encryption intrusion detection method based on convolutional Trans is characterized in that: The step 4 includes processing the acquired flow data of the network system to be tested according to the steps 1 and 2 and inputting the data into the Transformer network model, matching the obtained probability distribution with different intrusion detection models, and obtaining the intrusion status of the network.
9. A symmetric encryption intrusion detection system based on convolutional Trans, characterized in that: The system comprises: A data set acquisition unit, used to acquire and encrypt a data set to obtain a preliminary training data set; A feature learning unit is used to establish a CNN network model to perform feature learning on the preliminary training data set to obtain a final training data set; A detection model acquisition unit is used to establish a Transformer network model, input the final training data set into the Transformer network model for processing, and output and save an intrusion detection model corresponding to each training data set in the final training data set; The monitoring unit is used to monitor and match the acquired flow data of the network system to be tested based on the saved intrusion detection model.
10. An electronic device, characterized in that: include: one or more processors; A memory for storing one or more programs; Wherein, when one or more programs are executed by the one or more processors, the one or more processors implement a symmetric encryption intrusion detection method based on convolutional Trans as described in any one of claims 1-8.
11. A computer-readable storage medium, characterized in that: Executable instructions are stored thereon, and when the instructions are executed by the processor, the processor can implement the symmetric encryption intrusion detection method based on convolution Trans as described in any one of claims 1-8.
Citation Information
Patent Citations
Drilling spill risk identification method, system and device based on convolutional neural network
CN110443488A
Model training method, reasoning method, device, system, equipment and storage medium
CN116011552A
Network intrusion detection method based on GAN-CNN-BiLSTM
CN116582309A
Network intrusion detection method based on convolutional neural network and ensemble learning algorithm
CN117354056A
Power consumption side channel reinforcement learning model vulnerability detection method based on Integrating-Transform
CN118487819A