Self-adaptive momentum gradient target-free attack monitoring system

By designing an adaptive momentum gradient targetless attack monitoring system, using a dual-layer defense architecture and a variety of innovative technologies, the existing system's insufficient recognition capabilities when facing unknown attacks are solved, and efficient and accurate targetless attack detection and response are achieved.

CN120050078APending Publication Date: 2025-05-27SHANDONG INST OF BUSINESS & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510180823.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The existing targetless attack detection system has limited recognition capabilities when facing unknown types of targetless attacks, and traditional methods are difficult to respond in a timely manner without affecting normal services, and lacks the ability to learn new unknown attack modes.

Method used

An adaptive momentum gradient targetless attack monitoring system was designed. Through modules such as data acquisition, preprocessing, annotation, model construction and model training, a targetless attack monitoring model with a two-layer defense architecture was built, and technologies such as random micro-perturbation, differential privacy protection and cumulative update were introduced during the model training process to enhance the noise immunity and generalization capabilities of the model.

Benefits of technology

It significantly improves the detection efficiency and accuracy of targetless attacks, enhances the flexibility and security of the system, and can better capture and respond to new unknown attack modes, ensuring the latest status and best performance of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050078A_ABST
    Figure CN120050078A_ABST
Patent Text Reader

Abstract

The invention discloses a self-adaptive momentum gradient target-free attack monitoring system, and belongs to the technical field of target-free attacks. Comprising a data acquisition module for acquiring group contact data in a hypergraph form; the preprocessing module is used for preprocessing the group contact data; the labeling module is used for establishing a dynamic label for the preprocessed group contact data and labeling the dynamic label to generate a data sample set; the model construction module is used for constructing a target-free attack monitoring model of a double-layer defense architecture; the model training module is used for training a target-free attack monitoring model based on the data sample set; and the capture and response module is used for carrying out target-free attack monitoring through the trained attack monitoring model and carrying out response based on a target-free attack monitoring result. According to the method, the detection efficiency and accuracy of target-free attacks are remarkably improved, meanwhile, the flexibility and safety of the system are enhanced, and a powerful guarantee is provided for modern network safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of untargeted attacks, and more particularly to an adaptive momentum gradient untargeted attack monitoring system. Background Art

[0002] With the rapid development of information technology, the forms of cyber attacks have become increasingly diverse and complex. As a common cyber security threat, untargeted attacks are characterized by the fact that attackers do not target specific targets or systems, but rather use widespread vulnerabilities to conduct large-scale penetration attempts. Such attacks are often difficult to predict and highly concealed, and traditional rule-based security protection measures are difficult to effectively cope with.

[0003] Existing attack detection systems mostly rely on known pattern matching or abnormal behavior analysis, and have limited ability to identify unknown types of untargeted attacks. In addition, due to the high dynamism of the network environment and the diversity of user behaviors, how to accurately capture potential attack signals and respond in a timely manner without affecting normal operations has become an urgent problem to be solved.

[0004] To address the above challenges, solutions combining advanced technologies such as graph convolutional networks (GCN) and hypergraph convolutional networks (HGCN) have been proposed in the prior art. These methods can better model the complex relationships between nodes and improve the sensitivity to abnormal activities. However, they usually require a large amount of labeled data to train the model, and the cost of obtaining high-quality labels is high. At the same time, the model is prone to overfitting and has insufficient generalization ability when facing new types of attacks.

[0005] Therefore, how to provide an adaptive momentum gradient untargeted attack monitoring system that can solve the above problems is an urgent problem for those skilled in the art. Summary of the Invention

[0006] In view of this, the present invention provides an adaptive momentum gradient untargeted attack monitoring system to solve the technical problems existing in the above prior art.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] An adaptive momentum gradient untargeted attack monitoring system, comprising:

[0009] A data acquisition module that acquires group contact data in the form of a hypergraph;

[0010] A preprocessing module that preprocesses the group contact data;

[0011] The annotation module creates dynamic labels for the preprocessed group contact data and performs annotation to generate a data sample set;

[0012] The model construction module constructs a non-target attack monitoring model with a two-layer defense architecture;

[0013] The model training module trains the non-target attack monitoring model based on the data sample set;

[0014] The capture and response module performs non-target attack monitoring through the trained attack monitoring model and makes a response based on the non-target attack monitoring results.

[0015] Furthermore, the preprocessing module includes;

[0016] The data cleaning unit cleans the group contact data, removes noise and irrelevant information, and obtains the original data;

[0017] The data augmentation unit generates synthetic sample data through the generative adversarial network GAN and expands the original data with the synthetic sample data.

[0018] Furthermore, the annotation module includes:

[0019] The self-supervised learning unit minimizes the group contact data between different dimensions using a self-supervised learning loss function;

[0020] The time series analysis unit predicts the dynamic label at the current time based on the historical group contact data;

[0021] The label annotation unit annotates the dynamic label and generates a data sample set.

[0022] Furthermore, the non-target attack monitoring model with a two-layer defense architecture includes: a first-layer classifier and a second-layer classifier;

[0023] Among them, the first-layer classifier is the predicted label, X = [x 1 , x 2 ,..., x n is the data sample set;

[0024] The second-layer classifier C represents the context information.

[0025] Furthermore, a random micro-perturbation is added to the non-target attack monitoring model with a two-layer defense architecture, and the perturbed feature matrix is obtained as:

[0026] X' = X + δ

[0027] In the formula, δ is the random bit perturbation.

[0028] Furthermore, a context awareness mechanism is added based on the perturbation feature matrix.

[0029] Furthermore, the model training module includes:

[0030] A transfer learning unit that uses the pre-trained targetless attack monitoring model as initialization parameters for training;

[0031] A differential privacy protection unit that adds noise during gradient update in the training process;

[0032] An accumulative update unit that calculates the cumulative gradient and uses accumulative update for the gradient information generated during the training process.

[0033] Furthermore, the capture and response module includes:

[0034] A real-time monitoring unit that monitors targetless attacks through the trained attack monitoring model and triggers an alarm when the monitoring result is abnormal;

[0035] A feedback loop optimization unit that adjusts the parameters of the attack monitoring model based on the capture result and newly emerging attack patterns.

[0036] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses an adaptive momentum gradient targetless attack monitoring system, aiming to overcome the deficiencies in the prior art, specifically reflected in the following aspects:

[0037] (1) Introduce a random micro-perturbation mechanism to generate a perturbation feature matrix, enabling the model to maintain high accuracy in the presence of noise. In this way, not only the anti-interference performance of the system is improved, but also the learning ability for new and unknown attack patterns is enhanced;

[0038] (2) The data cleaning unit can effectively remove noise and irrelevant information to ensure the quality of the input data; while the data augmentation unit generates synthetic sample data through a generative adversarial network (GAN), expanding the scale of the training set and further improving the generalization ability and stability of the model.

[0039] (3) The self-supervised learning unit uses a loss function to minimize the group connection data between different dimensions and combines with the time series analysis unit to predict the dynamic label at the current time. This method not only reduces the cost of manual annotation, but also can better fit the changing behavior patterns in the actual application scenario;

[0040] (4) The first-layer classifier focuses on detecting potential attack signals, and the second-layer classifier combines context information to accurately locate and classify the attack types. This hierarchical design not only ensures a wide coverage, but also realizes refined management and improves the monitoring accuracy;

[0041] (5) The differential privacy protection unit ensures the security of user data and prevents the leakage of sensitive information; the cumulative update unit helps to simulate continuous attack scenarios in the real world and makes the model more adaptable to the dynamically changing network environment;

[0042] (6) The real-time monitoring unit can trigger an early warning immediately when abnormal activities are detected, while the feedback loop optimization unit continuously adjusts the model parameters according to the latest attack patterns to ensure the latest state and optimal performance of the system;

[0043] In summary, the adaptive momentum gradient untargeted attack monitoring system proposed by the present invention significantly improves the detection efficiency and accuracy of untargeted attacks through a series of innovative technologies and strategies. At the same time, it also enhances the flexibility and security of the system, providing a strong guarantee for modern network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0045] Figure 1 It is a schematic structural diagram of the system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0046] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0047] See Figure 1 , the embodiments of the present invention disclose an adaptive momentum gradient untargeted attack monitoring system, including:

[0048] A data acquisition module that acquires group contact data in the form of a hypergraph;

[0049] A preprocessing module that preprocesses the group contact data;

[0050] A labeling module that establishes dynamic labels and labels the preprocessed group contact data to generate a data sample set;

[0051] A model construction module that constructs an untargeted attack monitoring model with a two-layer defense architecture;

[0052] A model training module that trains the targetless attack monitoring model based on a data sample set;

[0053] A capture and response module that monitors targetless attacks through the trained attack monitoring model and responds based on the targetless attack monitoring results.

[0054] In a specific embodiment, the preprocessing module includes;

[0055] A data cleaning unit that cleans the group contact data, removes noise and irrelevant information, and obtains the original data to remove noise and irrelevant information.

[0056] A data augmentation unit that generates synthetic sample data through a generative adversarial network (GAN) and augments the original data with the synthetic sample data to improve the generalization ability of the model.

[0057] For example: H = (V, E) is a hypergraph, where V represents the set of nodes and E represents the set of edges (or hyperedges). For each node vi ∈ V, the feature vector where d is the feature dimension. After preprocessing, a feature matrix X = [x 1 , x 2 ,..., x n is obtained.

[0058] In a specific embodiment, the annotation module includes:

[0059] A self-supervised learning unit that uses a self-supervised learning loss function L self-supervised (X, X X ), where X X is the data-augmented version, and minimizes the group contact data between different dimensions;

[0060] Specifically, a self-supervised learning mechanism is used to dynamically construct a hypergraph convolutional network to predict node labels based on the acquired data, rather than static label assignment.

[0061] A time series analysis unit that predicts the dynamic label at the current time based on historical group contact data;

[0062] Specifically, time series analysis is applied, considering that node labels may change over time, thereby enhancing the adaptability of the model to dynamic environments.

[0063] A label annotation unit that annotates the dynamic labels and generates a data sample set.

[0064] In a specific embodiment, the targetless attack monitoring model with a two-layer defense architecture includes: a first-layer classifier and a second-layer classifier;

[0065] Specifically, the first layer is used to detect potential attack signals, and the second layer focuses on precisely locating and classifying the types of attacks;

[0066] Among them, the first-layer classifier is the predicted label, X = [x 1 , x 2 ,..., x n is the data sample set;

[0067] The second-layer classifier C represents context information.

[0068] In a specific embodiment, a context awareness mechanism is added to the perturbed feature matrix, considering the influence of the relationship between nodes and external environmental factors, and the perturbed feature matrix is obtained as:

[0069] X' = X + δ

[0070] In the formula, δ is a random bit perturbation.

[0071] In a specific embodiment, a context awareness mechanism is added to the perturbed feature matrix.

[0072] Specifically, an attention mechanism is incorporated into the hypergraph incidence matrix to more accurately measure the relative importance between different nodes, specifically:

[0073] Applying attention weights to the hypergraph incidence matrix thus obtaining the weighted relationship matrix A′ = A ⊙ W a , where ⊙ is element-wise multiplication.

[0074] In a specific embodiment, the model training module includes:

[0075] The transfer learning unit uses the pre-trained non-target attack monitoring model as the initialization parameter for training, accelerating the convergence process and reducing the risk of overfitting.

[0076] The differential privacy protection unit adds noise during the gradient update in the training process;

[0077] Specifically, applying the differential privacy protection algorithm ensures user privacy is not violated while guaranteeing the model performance.

[0078] The cumulative update unit calculates the cumulative gradient and uses cumulative update for the gradient information generated during the training process. Specifically, let G t be the gradient at the t-th step, then the cumulative gradient is:

[0079]

[0080] Specifically, the gradient information generated during the training process is updated cumulatively instead of being updated instantaneously at a single time point, so as to simulate the continuous attack scenario in the real world.

[0081] In a specific embodiment, the capture and response module includes:

[0082] A real-time monitoring unit that monitors the untargeted attack through the trained attack monitoring model and triggers an alarm when the monitoring result is abnormal;

[0083] A feedback loop optimization unit that adjusts the parameters of the attack monitoring model based on the capture results and newly emerging attack patterns.

[0084] This not only improves the ability to capture untargeted attacks, but also enhances the robustness and privacy protection level of the system.

[0085] Specifically, the overall process of the untargeted attack monitoring model of the double-layer defense architecture of the present invention is as follows:

[0086] The first layer is the potential attack signal detection layer, including: (1) Feature extraction and representation learning part:

[0087] The node feature matrix X and the edge set E obtained from the hypergraph H=(V, E);

[0088] Feature extraction is performed on the nodes to generate a hidden feature representation Z = f(X, A), where A is the adjacency matrix or hypergraph incidence matrix constructed based on E.

[0089] Optionally, data augmentation techniques are introduced in this step to improve the generalization ability of the model.

[0090] (2) Anomaly detection part:

[0091] Apply an autoencoder (Autoencoder), variational autoencoder (VAE) or anomaly detection algorithm (such as Isolation Forest, Local Outlier Factor (LOF), etc.) to identify abnormal patterns.

[0092] Calculate the anomaly score Si of each node vi, which reflects the degree of deviation of the node from the normal behavior.

[0093] Obtain a set of anomaly score vectors S = [S 1 , S 2 ,..., S n for marking the nodes that may be under attack.

[0094] The second layer is the localization layer, including: (1) Context awareness mechanism part:

[0095] Input the anomaly score vector S of the first layer and the original node feature matrix X;

[0096] Introduce context information C, including time series data, user behavior logs, etc., and construct a richer node representation Z′ = g(X, C).

[0097] For each suspected node vi, calculate the comprehensive score Si′ by combining its context information, which helps to distinguish real attack activities from other non-malicious but abnormal behaviors.

[0098] (2) Attention mechanism fusion part:

[0099] Based on the hypergraph adjacency matrix A and the relationship matrix derived from the edge set E, apply the attention mechanism to construct the weighted adjacency matrix A′ = A ⊙ W a , where W a is the weight matrix calculated by the attention function.

[0100] This process enables the model to more accurately measure the relative importance between different nodes and focus on the key nodes most likely to be involved in the attack.

[0101] (3) Classification and decision-making part:

[0102] Use the classifier to finally classify the nodes according to the comprehensive score S′ and the improved adjacency matrix ′A′.

[0103] Set a threshold p to determine whether to trigger an alarm; if the comprehensive score of a certain node exceeds the threshold, it is considered that the node is affected by a non-targeted attack.

[0104] Finally, provide a detailed attack report, including the list of affected nodes, attack type prediction and its confidence, etc.

[0105] Specifically, the hypergraph adjacency matrix A and the relationship matrix derived from the edge set E together constitute the core data basis. The former is mainly used to capture static network structure features, and the latter helps to understand dynamic behavior patterns. The two complement each other and play a bridging role in the whole monitoring process, ensuring that the model can not only widely cover all possible attack paths, but also deeply explore the subtle differences within specific nodes or subnets, and finally achieve efficient and accurate non-targeted attack capture. By constructing and applying these matrices in the above way, not only the detection sensitivity of the present invention to non-targeted attacks is improved, but also the understanding and response ability to complex attack scenarios are enhanced.

[0106] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts among the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description in the method section.

[0107] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An adaptive momentum gradient non-target attack monitoring system, characterized in that: include: A data acquisition module, which acquires group contact data in the form of a hypergraph; A preprocessing module, for preprocessing the group contact data; The annotation module creates dynamic labels and annotates the pre-processed group contact data to generate a data sample set; Model building module, building a non-targeted attack monitoring model with a two-layer defense architecture; A model training module, for training the non-targeted attack monitoring model based on a data sample set; The capture and response module monitors non-targeted attacks through the trained attack monitoring model and responds based on the non-targeted attack monitoring results.

2. The adaptive momentum gradient non-target attack monitoring system according to claim 1 is characterized in that: The preprocessing module comprises: The data cleaning unit cleans the group contact data, removes noise and irrelevant information, and obtains the original data; The data enhancement unit generates synthetic sample data through the generative adversarial network GAN, and expands the original data through the synthetic sample data.

3. The adaptive momentum gradient non-target attack monitoring system according to claim 1 is characterized in that: The marking module comprises: A self-supervised learning unit that uses a self-supervised learning loss function to minimize group contact data between different dimensions; A time series analysis unit that predicts the dynamic label of the current time based on historical group contact data; The label annotation unit annotates the dynamic labels and generates a data sample set.

4. The adaptive momentum gradient non-target attack monitoring system according to claim 1, characterized in that: The non-targeted attack monitoring model of the double-layer defense architecture includes: a first-layer classifier and a second-layer classifier; Among them, the first layer classifier is the predicted label, X = [x1, x2, ..., x n ] is the data sample set; The second layer classifier C represents context information.

5. The adaptive momentum gradient non-target attack monitoring system according to claim 4 is characterized in that: Adding random micro-perturbations to the non-targeted attack monitoring model of the two-layer defense architecture, the perturbation feature matrix is ​​obtained as follows: X=X+δ Where δ is the random bit perturbation.

6. The adaptive momentum gradient non-target attack monitoring system according to claim 4, characterized in that: A context-aware mechanism is added based on the perturbation feature matrix.

7. The adaptive momentum gradient non-target attack monitoring system according to claim 1, characterized in that: The model training module includes: A transfer learning unit, using the pre-trained non-targeted attack monitoring model as an initialization parameter for training; Differential privacy protection unit, which adds noise to the gradient update during training; The cumulative update unit calculates the cumulative gradient and uses cumulative update for the gradient information generated during the training process.

8. The adaptive momentum gradient non-target attack monitoring system according to claim 1, characterized in that: The capture and response module includes: The real-time monitoring unit monitors non-targeted attacks through the trained attack monitoring model and triggers an early warning when the monitoring results are abnormal. Feedback loop optimization unit adjusts attack monitoring model parameters based on capture results and emerging attack patterns.