DDos attack defense method and device based on flow feature multi-dimensional collaborative interception
Through the multi-dimensional collaborative interception method based on traffic features, the problem of insufficient sample data during the new DDoS attack is solved, and effective identification and interception of small sample attacks is achieved, and the adaptability and robustness of the system are improved.
Patent Information
- Application Number
- CN202411992477.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-30
AI Technical Summary
When the existing technology faces new DDoS attacks, it lacks sufficient sample data, which makes it difficult to effectively intercept emerging few-sample attacks.
The multi-dimensional collaborative interception method based on traffic features is adopted, data preprocessing is performed through the rolling time window, a multi-head attention mechanism is introduced for traffic feature extraction, and the DDos intrusion detection model is updated using the adaptive architecture of transfer learning.
It improves the system's identification performance of attack methods with few samples, reduces false alarms and missed alarm rates, and improves the system's adaptability and robustness.
Smart Images

Figure CN120074858A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of DDoS attack defense, and particularly to a DDoS attack defense method and device based on multi-dimensional collaborative interception of traffic characteristics. Background Art
[0002] DDoS attacks, namely distributed denial of service attacks, are a major threat to global network organizations. These attacks have the potential to paralyze the network, making it inaccessible to legitimate users and seriously damaging the availability and integrity of services. Therefore, the ability to detect and mitigate DDoS attacks is crucial for ensuring the security of critical network facilities. From the perspective of the core technologies used, DDoS intrusion detection systems can be classified into the following three categories:
[0003] 1. Signature-based intrusion detection systems: Signature-based intrusion detection systems are a common intrusion detection technology that identifies known attack behaviors through predefined attack feature patterns. First, the system collects a large number of known attack behavior characteristics and builds an attack feature library. When the system monitors network traffic or system behaviors, it compares them with the patterns in the feature library. If a matching attack feature is found, an alarm will be triggered to prompt the system administrator to take corresponding defense measures. The advantage of this type of system is high detection efficiency, which can quickly identify known attack behaviors. However, writing signatures requires in-depth security expertise and has poor scalability.
[0004] 2. Statistical anomaly-based intrusion detection systems: Statistical anomaly-based intrusion detection systems are an intrusion detection method that uses statistical analysis techniques to identify network abnormal behaviors. Different from traditional signature-based detection systems, this method focuses on discovering abnormal patterns in network activities rather than predefined attack features. First, the system collects a large amount of data on normal network activities and constructs a distribution model for normal behaviors, considering statistical metrics such as the median, mean, mode, and standard deviation of data packets. When new network activities are monitored, the system detects low-probability events based on the distribution model and marks them as potential intrusions. This type of system can learn adaptively and continuously optimize the detection model over time to improve detection accuracy. However, it relies on a large amount of historical data, and the detection results are limited by the detection threshold, making it prone to false positives and false negatives.
[0005] 3. Machine learning-based intrusion detection systems: To address the limitations of the above solutions, many studies have explored using machine learning techniques to build network intrusion detection systems. Among them, deep learning systems can derive more complex feature representations from the fine-grained features of data packets and have been proven to be effective in distinguishing normal traffic from DDoS attack traffic. This type of system does not require manual feature extraction, has strong generalization ability, and higher accuracy.
[0006] In recent years, due to the emergence of various attack methods, DDoS attacks have become more difficult to detect. For example, attackers use multiple devices and a combination of various attack methods to carry out DDoS attacks. In this scenario, existing DDoS intrusion detection systems still face some challenges:
[0007] First, in actual applications, the system needs to quickly respond to and detect attacks, and cannot wait to collect all packet features and then let the model calculate. Second, there is insufficient mining of feature information. The arrival sequence and arrival time of packets are important features for distinguishing DDoS attack traffic from normal traffic. Finally, DDoS attack methods continue to evolve. Whenever a new attack method appears, due to the lack of sufficient sample data, effectively intercepting these emerging few-sample attacks has become a very challenging task.
[0008] In summary, for the intrusion detection system of DDoS attacks, existing methods have defects and need further research. Summary of the Invention
[0009] To solve the technical problem in the prior art that when a new attack method appears, there is a lack of sufficient sample data to effectively intercept these emerging few-sample attacks, an embodiment of the present invention provides a DDoS attack defense method and device based on multi-dimensional collaborative interception of traffic characteristics. The technical solution is as follows:
[0010] On the one hand, a DDoS attack defense method based on multi-dimensional collaborative interception of traffic characteristics is provided, which is characterized in that the method includes:
[0011] S1. Based on a rolling time window, obtain traffic packets, preprocess the traffic packets, and construct a feature matrix of the traffic packets;
[0012] S2. Introduce a multi-head attention mechanism for traffic feature extraction and construct a DDoS intrusion detection binary classification model;
[0013] S3. Train the DDoS intrusion detection binary classification model to obtain a DDoS intrusion detection model;
[0014] S4. Obtain target data in an actual application scenario, update the DDoS intrusion detection model based on the adaptive architecture of transfer learning, input the target data into the updated DDoS intrusion detection model, and complete the DDoS attack defense based on multi-dimensional collaborative interception of traffic characteristics.
[0015] Optionally, in S1, based on a rolling time window, obtain traffic packets, preprocess the traffic packets, and construct a feature matrix of the traffic packets, including:
[0016] Given a two-way traffic and a predefined time window of length \(t\) seconds;
[0017] Capture all packets within the time window of \([t 0 , t 0 +t]\), and delete the attributes of all packets that are not conducive to model generalization;
[0018] Arrange the attributes of traffic packets belonging to the same two-way traffic in chronological order to form a feature matrix of traffic packets with the shape of \([n, f]\); where \(n\) is the maximum number of packets collected for each two-way traffic within a single predefined time window, and \(f\) is the number of remaining attributes after deleting the attributes that are not conducive to model generalization; the attributes that are not conducive to model generalization include: IP address, TCP / UDP port, link layer encapsulation type, and application layer type.
[0019] Based on the above process, traverse and capture all packets within the time window of \((t 0 +t, t 0 +2t]\) to \((t 0 +nt, t 0 +(n + 1)t]\), delete the attributes that are not conducive to model generalization, and arrange the attributes of traffic packets belonging to the same two-way traffic in chronological order; obtain the feature matrices of \(n\) traffic packets.
[0020] The feature matrix of traffic collected every certain time \(t\) is sent to the intrusion detection model.
[0021] Optionally, S1 also includes:
[0022] When the number of packets within a single time window is greater than \(n\), the extra data stream is truncated; while for shorter data streams, normalization operations are performed on each attribute value, mapping the attribute values to \([0, 1]\), and zero-padding the samples to make the packet length of each \(t\) time window fixed at \(n\).
[0023] Among them, the packets captured within the time window of \([t 0 , t 0 +t]\) are denoted as \(E pack (t 0 , t 0 +t)\);
[0024] When traversing the time window, label the preprocessed packets; for DDoS attack traffic, each packet sequence \(E pack captured on this traffic within each time window is marked as 1, while each \(E pack captured on normal traffic is marked as 0.
[0025] Optionally, in S2, a multi-head attention mechanism is introduced for traffic feature extraction, and a binary classification model for DDoS intrusion detection is constructed, including:
[0026] Introduce a multi-head attention mechanism; among them, the multi-head attention mechanism is a self-attention mechanism with multiple channels; among them, the self-attention mechanism includes: Query, Key, Value; the input of the first multi-head attention mechanism is E input ;
[0027] In the hyperparameter optimization process, multiple multi-head attention mechanisms are stacked. When multiple multi-head attention mechanisms are stacked, the input of each multi-head attention mechanism is the output of the previous multi-head attention mechanism; the self-attention mechanism calculates and weights Query, Key, and Value to generate the Attention value of the target vector;
[0028] Based on the multi-head attention mechanism, connect a lightweight convolutional neural network for feature extraction to capture the feature information and multi-scale dependency relationships of the packet sequence; perform binary classification on the traffic data according to the feature information extracted by the multi-head attention mechanism.
[0029] Optionally, calculating and weighting Query, Key, and Value through the self-attention mechanism to generate the Attention value of the target vector includes:
[0030] Calculate the similarity between Query and Key, quantify their correlation through dot product operation, and weight Value to generate the Attention value of the target vector:
[0031]
[0032] where d k represents the dimension of the hidden layer.
[0033] Optionally, based on the multi-head attention mechanism, connect a lightweight convolutional neural network for feature extraction to capture the feature information and multi-scale dependency relationships of the packet sequence; perform binary classification on the traffic data according to the feature information extracted by the multi-head attention mechanism, including:
[0034] Take the output of the multi-head attention mechanism module as the input of the convolutional neural network:
[0035] F = {f 1 ,f 2 ,…,f n}
[0036] where f iRepresents the i-th row in the feature matrix, that is, the feature information of the i-th data packet extracted after considering the dependencies between data packets; the dimension of the feature matrix F is the same as that of the matrix obtained by preprocessing, that is, [n, f];
[0037] Adopt k convolutional kernels of size h×f, and extract and learn local features containing useful information on the feature matrix F with a stride of 1 to detect DDoS traffic and normal traffic. Each convolutional kernel will generate an activation map a of size (n - h + 1);
[0038] Stack all the activation maps a to obtain an activation matrix A of size (n - h + 1)×k;
[0039] Use the max pooling layer to downsample along the first dimension of the activation matrix A, and use the Sigmoid function to construct the classification layer.
[0040] Optionally, in S3, training the DDoS intrusion detection binary classification model includes:
[0041] When training the model, use the binary cross-entropy loss function:
[0042]
[0043] where N represents the number of samples in this batch, y i represents the true label of the sample, and p i represents the prediction result of the intrusion detection model.
[0044] Optionally, in S4, obtaining the target data of the actual application scenario and updating the DDoS intrusion detection model based on the adaptive architecture of transfer learning includes:
[0045] Mark the source domain data as S;
[0046] Train the DDoS intrusion detection model with the source domain data S so that the DDoS intrusion detection model learns the general features and rules of DDoS attacks; obtain the optimal parameters on the source domain data S and use as the initial parameters for subsequent fine-tuning.
[0047] On the other hand, a DDoS attack defense device based on multi-dimensional collaborative interception of traffic features is provided. This device is applied to the DDoS attack defense method based on multi-dimensional collaborative interception of traffic features. This device includes:
[0048] A data processing module, which is used to obtain traffic data packets based on a rolling time window, preprocess the traffic data packets, and construct a feature matrix of the traffic data packets;
[0049] A model construction module, which is used to introduce a multi-head attention mechanism for traffic feature extraction and construct a DDos intrusion detection binary classification model;
[0050] A model preliminary training module, which is used to train the DDos intrusion detection binary classification model to obtain a DDos intrusion detection model;
[0051] An attack defense module, which is used to obtain target data in the actual application scenario, update the DDos intrusion detection model based on the adaptive architecture of transfer learning, input the target data into the updated DDos intrusion detection model, and complete the DDos attack defense based on multi-dimensional collaborative interception of traffic features.
[0052] On the other hand, a DDos attack defense device based on multi-dimensional collaborative interception of traffic features is provided. The DDos attack defense device based on multi-dimensional collaborative interception of traffic features includes: a processor; a memory, on which computer-readable instructions are stored. When the computer-readable instructions are executed by the processor, any one of the methods in the above-mentioned DDos attack defense method based on multi-dimensional collaborative interception of traffic features is implemented.
[0053] On the other hand, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the at least one instruction is loaded and executed by a processor to implement any one of the methods in the above-mentioned DDos attack defense method based on multi-dimensional collaborative interception of traffic features.
[0054] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention at least include:
[0055] In the embodiments of the present invention, data preprocessing of traffic is performed based on the rolling time window method, providing data support for the subsequently constructed DDos attack defense model; secondly, a multi-head attention mechanism is introduced in the process of traffic feature extraction to capture the feature information of the packet sequence in the traffic and the multi-scale dependence relationship; finally, a DDos attack defense method in a transformed scenario is designed based on the adaptive architecture of transfer learning, improving the adaptability and robustness of the system. Description of the Drawings
[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0057] Figure 1 It is a flowchart of the DDos attack defense method based on multi-dimensional collaborative interception of traffic features provided by the embodiments of the present invention;
[0058] Figure 2 Schematic process diagram of DDos attack defense based on multi-dimensional collaborative interception of traffic characteristics provided by an embodiment of the present invention;
[0059] Figure 3 Block diagram of a DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics provided by an embodiment of the present invention;
[0060] Figure 4 Schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0061] The technical solutions in the present invention will be described below with reference to the accompanying drawings.
[0062] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.
[0063] In the embodiments of the present invention, sometimes subscripts such as W 1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning to be expressed is the same.
[0064] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.
[0065] The embodiments of the present invention provide a DDos attack defense method based on multi-dimensional collaborative interception of traffic characteristics. This method can be implemented by a DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics. The DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics can be a terminal or a server. As Figure 1 shown in the flowchart of the DDos attack defense method based on multi-dimensional collaborative interception of traffic characteristics, Figure 2 the specific process of the method of the present invention is described. Figure 2 Shows a schematic process diagram of the DDos attack defense method based on multi-dimensional collaborative interception of traffic characteristics according to an embodiment of the present invention. As Figure 1 and Figure 2 shown, the DDos attack defense method based on multi-dimensional collaborative interception of traffic characteristics proposed by the present invention mainly includes three parts: data preprocessing based on a rolling time window, a DDos intrusion detection model introducing a multi-head attention mechanism, and a DDos attack defense method based on an adaptive architecture design for transforming scenarios based on transfer learning; the processing flow of this method can include the following steps:
[0066] S1. Based on a rolling time window, obtain traffic data packets, preprocess the traffic data packets, and construct a feature matrix of the traffic data packets.
[0067] In a feasible implementation manner, S1 of the present invention preprocesses the received traffic to provide data support for subsequent construction of a DDos attack defense model.
[0068] In a feasible implementation manner, in S1, based on a rolling time window, obtain traffic data packets, preprocess the traffic data packets, and construct a feature matrix of the traffic data packets, including:
[0069] Given a two-way traffic and a predefined time window with a length of t seconds;
[0070] Capture all data packets within the time window of [t 0 , t 0 +t], and delete the attributes of all data packets that are not conducive to model generalization; the attributes that are not conducive to model generalization include: IP address, TCP / UDP port, link layer encapsulation type, and application layer type (such as HTTP), etc.;
[0071] Arrange the attributes of the traffic data packets belonging to the same two-way traffic in chronological order to form a feature matrix of the traffic data packets with a shape of [n, f]; where n is the maximum number of data packets collected for each two-way traffic within a single predefined time window, and f is the number of remaining attributes after deleting the attributes that are not conducive to model generalization;
[0072] Based on the above process, traverse and capture all data packets within the time window of (t 0 +t, t 0 +2t] to (t 0 +nt, t 0 +(n + 1)t], delete the attributes that are not conducive to model generalization, and arrange the attributes of the traffic data packets belonging to the same two-way traffic in chronological order; obtain n feature matrices of the traffic data packets;
[0073] The feature matrix of the traffic collected every certain time t is sent to the intrusion detection model.
[0074] In a feasible implementation manner, S1 further includes:
[0075] When the number of data packets within a single time window is greater than n, the excess data stream is truncated; while for shorter data streams, normalization operations are performed on each attribute value to map the attribute value to [0, 1], and zero-padding is performed on the samples to make the data packet length of each t time window fixed at n;
[0076] Among them, [t0 , t 0 The data packets captured within the time window [t, t + t] are denoted as E pack (t 0 , t 0 + t);
[0077] When traversing the time window, the pre - processed data packets are tagged; among them, the data of each time window includes a feature matrix and a pair of tags. For DDoS attack traffic, the data packet sequence E pack captured for each time window on this traffic is marked as 1, while each E pack captured on normal traffic is marked as 0; where 0 and 1 represent the tags of the data packets within each time window, used to distinguish whether the traffic is normal traffic or DDoS attack traffic.
[0078] In a feasible implementation, the feature matrix of the traffic collected every certain time t is sent to the intrusion detection model, which ensures that the model can make decisions based on real - time traffic without the need to capture the entire life cycle of bidirectional traffic.
[0079] In a feasible implementation, network traffic consists of end - to - end data streams. Due to the sharing nature of communication links, data packets of different data streams will be multiplexed, resulting in the separation of data packets of the same data stream during transmission. This means that processing the traffic received in a real - time system is completely different from processing a static data set containing complete traffic. Therefore, this application pre - processes network traffic based on a tumbling time window, converts the traffic extracted within each time window into a matrix, and represents the traffic within the window from multiple feature dimensions such as time, space, etc. This approach can capture traffic information in real - time and unify the input dimensions for training the DDoS intrusion detection model.
[0080] In a feasible implementation, the premise of the data pre - processing method of the present invention is to assume that the DDoS intrusion detection model can detect attack traffic within a time window of length t. When t and n are relatively small, the computational overhead of the model becomes smaller and the real - time performance becomes better, but the false alarm and missed alarm rates will correspondingly become higher. On the contrary, higher values of t and n can provide more feature information about the traffic for the detection model, thereby improving the detection accuracy, but they will also bring a larger computational overhead, which will affect the real - time performance of the detection model. Consider t and n as part of the hyperparameters of the detection model.
[0081] S2. Introduce a multi - head attention mechanism for traffic feature extraction and construct a DDoS intrusion detection binary classification model.
[0082] In a feasible implementation manner, the second step of the present invention mainly performs traffic feature extraction based on the multi-head attention mechanism to capture the feature information of the data packet sequence in the traffic and the dependencies of different scales and types between multiple data packets, so as to more accurately identify abnormal patterns in network traffic.
[0083] In a feasible implementation manner, the input of the feature extraction part consists of E pack and positional encoding, which can effectively capture the specific content information in the data packet sequence and ensure that the model understands the relative positions of each data packet in its sequence, which is crucial for identifying specific patterns or abnormal behaviors related to the sequence:
[0084] E input = E pack + E pos
[0085] wherein, E pos can be expressed as:
[0086]
[0087] In a feasible implementation manner, in S2, a multi-head attention mechanism is introduced for traffic feature extraction, and a binary classification model for DDoS intrusion detection is constructed, including:
[0088] Introduce a multi-head attention mechanism; wherein, the multi-head attention mechanism is a self-attention mechanism with multiple channels, and each self-attention mechanism can independently focus on different aspects of the input sequence, thereby enhancing the model's ability to understand complex patterns; wherein, the self-attention mechanism includes: Query, Key, Value, and its calculation process involves three intermediate weight matrices, which are used to calculate the values of Query, Key, Value respectively:
[0089] Q = XW Q , K = XW K , V = XW V
[0090] wherein, X represents the input of the multi-head attention mechanism; the input of the first multi-head attention mechanism is E input ;
[0091] During the hyperparameter optimization process, multiple multi-head attention mechanisms are stacked to balance the complexity and generalization of the model. When multiple multi-head attention mechanisms are stacked, the input of each multi-head attention mechanism is the output of the previous multi-head attention mechanism; the Query, Key, and Value are calculated and weighted through the self-attention mechanism to generate the Attention value of the target vector.
[0092] Feature extraction is performed by connecting a lightweight convolutional neural network based on the multi-head attention mechanism to capture the feature information and multi-scale dependency relationships of the packet sequence; binary classification of the traffic data is performed based on the feature information extracted by the multi-head attention mechanism.
[0093] In a feasible implementation, the Query, Key, and Value are calculated and weighted through the self-attention mechanism to generate the Attention value of the target vector, including:
[0094] Calculate the similarity between the Query and the Key, quantify their correlation through dot product operation, and weight the Value to generate the Attention value of the target vector:
[0095]
[0096] where d k represents the dimension of the hidden layer.
[0097] The multi-head attention mechanism consists of multi-channel self-attention mechanisms, that is:
[0098] Multi-Head(Q,K,V)=Concat(h 1 , h 2 ,..., h n )W o
[0099] h i =Attention(Q i , K i , V i )
[0100] where Concat() represents the matrix concatenation operation, and W o is a mapping matrix used to ensure that the input and output matrices of the module have the same dimension.
[0101] After each multi-head attention mechanism, an Add&Norm layer is usually added, that is, the residual and normalization layer, to alleviate the vanishing gradient and exploding gradient problems in the deep network and accelerate the training process of the model.
[0102] In a feasible implementation, feature extraction is performed by connecting a lightweight convolutional neural network based on the multi-head attention mechanism to capture the feature information and multi-scale dependency relationships of the packet sequence; binary classification of the traffic data is performed based on the feature information extracted by the multi-head attention mechanism, including:
[0103] Take the output of the multi-head attention mechanism module as the input of the convolutional neural network:
[0104] F={f 1 , f2 , …, f n}
[0105] Among them, f i represents the i-th row in the feature matrix, that is, the feature information of the i-th data packet extracted after considering the dependency relationship between data packets; the dimension of the feature matrix F is the same as the dimension of the matrix obtained by preprocessing, that is, [n, f];
[0106] Adopt k convolutional kernels with a size of h×f, and extract and learn local features containing useful information on the feature matrix F with a step size of 1 to detect DDos traffic and normal traffic. Each convolutional kernel will generate an activation map a with a size of (n - h + 1):
[0107] a = ReLU(Conv(F)W k , b k )
[0108] Among them, W k and b k are the weight matrix and bias of the k-th convolutional kernel. In order to introduce non-linearity into the convolutional kernel, the activation function ReLU(x) = max{0, x} is used;
[0109] Stack all the activation maps a to obtain an activation matrix A with a size of (n - h + 1)×k;
[0110] Use the max pooling layer to downsample along the first dimension of the activation matrix A. In this way, the model will ignore those less useful information with smaller activation degrees and instead focus on larger activation degrees. This also means that this application will ignore the position information of the activation.
[0111] Finally, use the Sigmoid function to construct the classification layer:
[0112] p = Sigmoid(x)
[0113] Among them, x represents the output of the pooling layer. When p > 0.5, it is determined that the traffic is DDos traffic, otherwise it is normal traffic.
[0114] In a feasible implementation manner, S2 of the present invention takes the output of S1 as the input of the DDos intrusion detection model. First, perform positional encoding on the preprocessed data packets to add positional information to the data, and then use the multi-head attention mechanism module to extract the sequence feature information and dependency relationship of the data packets. Then use the convolutional kernel to transform the dimension of the data, and the width of the convolutional kernel is the same as the number of data packet features. The last part of the model is a pooling and fully connected layer, which is used to screen the most important information in the feature information and classify the traffic into two categories accordingly to determine whether the traffic is DDos attack traffic or normal traffic.
[0115] In addition, during the training of the model, hyperparameter optimization is also required. By adjusting the learning rate and the sample batch size, the efficient convergence of the model is ensured. The number of multi-head attention mechanism modules is adjusted to find the best balance between model complexity and generalization ability.
[0116] S3. Train the DDos intrusion detection binary classification model to obtain the DDos intrusion detection model.
[0117] In a feasible implementation, in S3, training the DDos intrusion detection binary classification model includes:
[0118] When training the model, the binary cross-entropy loss function is adopted:
[0119]
[0120] where N represents the number of samples in this batch, y i represents the true label of the sample, and p i represents the prediction result of the intrusion detection model.
[0121] In a feasible implementation, during the model training, hyperparameter optimization is required to enable the model to achieve the best effect. In this model, the parameters that need to be optimized include the window length t, the maximum number of data packets n, the learning rate, the sample batch size, the number of layers of the multi-head attention mechanism, and the width h of the convolutional kernel. First, define the search space of the hyperparameters, and then perform grid search on the hyperparameters to select the optimal parameters.
[0122] S4. Obtain the target data of the actual application scenario, update the DDos intrusion detection model based on the adaptive architecture of transfer learning, and input the target data into the updated DDos intrusion detection model to complete the DDos attack defense based on multi-dimensional collaborative interception of traffic characteristics.
[0123] In a feasible implementation, during actual application, it is necessary to retrain or update the DDos intrusion detection model according to different scenarios. However, due to the continuous change of DDos attack methods, when new attack methods emerge, there are not enough sample numbers to train the model to converge. Considering the feature correlation between various DDos attack methods, an adaptive architecture of transfer learning is adopted to solve this problem, that is, first train on the DDos attack data with a large number of samples, and then migrate to a specific attack domain for fine-tuning, thereby improving the performance of the model.
[0124] In a feasible implementation, in S4, obtaining the target data of the actual application scenario and updating the DDos intrusion detection model based on the adaptive architecture of transfer learning includes:
[0125] Label the source domain data (i.e., DDos attack data containing a large number of samples) as S; the target domain data (few-sample DDos attack data) as T;
[0126] Train a DDos intrusion detection model with the source domain data S so that the DDos intrusion detection model learns the general characteristics and rules of DDos attacks; obtain the optimal parameters on the source domain data S And use As the initial parameters for subsequent fine-tuning.
[0127] In a feasible implementation, train a DDos intrusion detection model on S, aiming to enable the model to learn the general characteristics and rules of DDos attacks from a large amount of labeled data. The parameters after training can be expressed as:
[0128]
[0129] Where M s Represents the source model, and θ s Is the parameter of the source model. This process describes the iterative update of the parameter θ s Of the source model M s To minimize the loss function Loss of the source domain data S. At the end of this training stage, the optimal parameters on the source domain data S can be obtained And use As the initial parameters for subsequent fine-tuning. This method ensures that the feature information learned by the source model on DDos attack samples will not be discarded to adapt to the target domain data T, which helps to improve the adaptability and detection accuracy of the model in new environments or few-sample scenarios. The update from the source domain model to the target domain model involves parameter initialization and fine-tuning, that is:
[0130]
[0131] In the above process, the model parameters are initially set to And then fine-tuned to adapt to the target domain data T. This method is particularly effective for the case where the source dataset and the target dataset are related but different, such as domain adaptation tasks.
[0132] In the embodiments of the present invention, the DDos attack defense method based on the adaptive architecture design transformation scenario in S3. The system designed based on such a method can learn the feature correlation between multiple DDoS attack methods, improve the recognition performance of the system for few-sample attack methods, and thus enhance the adaptability and robustness of the system.
[0133] First, train the model on the DDoS attack data (i.e., source data) with a large number of attack samples and diverse attack methods, and then apply the model to the DDoS attack data with fewer samples and possibly more specific types (i.e., target data). Specifically, first find the optimal parameters of the model on the source data to minimize the cross-entropy loss. Then, use the parameters of the source model as the initial parameters and fine-tune on the target data to find the parameters that minimize the cross-entropy loss again. This method uses the pre-trained state to accelerate and improve the learning process of few-shot data, thereby improving learning efficiency and performance.
[0134] In the embodiments of the present invention, based on the adaptive architecture of transfer learning, the present application can design a DDoS attack defense method in a transformed scenario. Specifically, the core of this method is to utilize the knowledge learned from the source domain data with rich resources to quickly adapt to the new target domain environment that may have only a small number of samples. First, the data preprocessing module shown in step one sends the preprocessed data packets to the intrusion detection model every time interval t, ensuring that the model can obtain the latest network traffic information in a timely manner and make judgments. The intrusion detection model extracts and mines the complete feature information of the data packets and the dependencies between the data packets to determine whether the traffic belongs to a DDoS attack. If the judgment result is an attack, the traffic is immediately intercepted. When facing new application scenarios, especially those with specific and few-shot new attack methods, there is no need to train a completely new model from scratch. Instead, the pre-trained intrusion detection model can be fine-tuned to address these challenges. During the fine-tuning process, the model adjusts its parameters according to the data in the target domain, which not only greatly reduces the training time and computing resources required, but more importantly, enables the model to quickly learn the correlation between the new attack method and other DDoS attacks, effectively identify and respond to new attack patterns. This method significantly improves the adaptability and robustness of the model, enabling it to operate efficiently in a constantly changing network threat environment.
[0135] In the embodiments of the present invention, a data preprocessing method based on a rolling time window is adopted to ensure the real-time performance of the intrusion detection system. The data packets in different bidirectional traffic are preprocessed and represented from multiple feature dimensions such as time, space, etc., achieving efficient and real-time traffic capture and providing data support for building a real-time DDoS attack defense model.
[0136] In the present invention, a multi-head attention mechanism is introduced in the traffic feature extraction process, significantly enhancing the ability to capture the sequence feature information of the data packets in the traffic and the multi-scale dependencies. The multi-head attention mechanism can simultaneously focus on different scales and types of dependencies between multiple data packets in the traffic, thereby more accurately identifying abnormal patterns in network traffic, especially performing more excellently in dealing with complex and changing network environments.
[0137] The present invention designs a method for defending against DDos attacks in a transformed scenario by using an adaptive architecture of transfer learning. By capturing the feature correlations among various DDoS attack methods in a continuously changing scenario, the recognition performance of few-shot attack methods is improved, the false alarm rate and missed alarm rate are reduced, and the adaptability and robustness of the system are enhanced.
[0138] Figure 3 FIG. 390 is a block diagram of a DDos attack defense device 300 based on multi-dimensional collaborative interception of traffic characteristics shown according to an exemplary embodiment. The device 300 is used for a method of defending against DDos attacks based on multi-dimensional collaborative interception of traffic characteristics. Referring to Figure 3 FIG. 391, the device includes a data processing module 310, a model construction module 320, a model preliminary training module 330, and an attack defense module 340. Among them:
[0139] The data processing module 310 is configured to obtain traffic data packets based on a rolling time window, preprocess the traffic data packets, and construct a feature matrix of the traffic data packets;
[0140] The model construction module 320 is configured to introduce a multi-head attention mechanism for traffic feature extraction and construct a DDos intrusion detection binary classification model;
[0141] The model preliminary training module 330 is configured to train the DDos intrusion detection binary classification model to obtain a DDos intrusion detection model;
[0142] The attack defense module 340 is configured to obtain target data of an actual application scenario, update the DDos intrusion detection model based on the adaptive architecture of transfer learning, input the target data into the updated DDos intrusion detection model, and complete the DDos attack defense based on multi-dimensional collaborative interception of traffic characteristics.
[0143] Optionally, the data processing module 310 is configured to give a two-way traffic and a predefined time window with a length of t seconds;
[0144] Capture all data packets within the time window of [t 0 t 0 +t], and delete the attributes of all data packets that are not conducive to model generalization;
[0145] Arrange the attributes of the traffic data packets belonging to the same two-way traffic in chronological order to form a feature matrix of the traffic data packets with a shape of [n, f]; where n is the maximum number of data packets collected for each two-way traffic within a single time window set in advance, and f is the number of remaining attributes after deleting the attributes that are not conducive to model generalization; the attributes that are not conducive to model generalization include: IP address, TCP / UDP port, link layer encapsulation type, and application layer type;
[0146] Traversing based on the above process for the time window of (t 0 +t, t 0 +2t] to all data packets within the time window of (t 0 +nt, t 0 +(n + 1)t], perform capture, delete attributes that are not conducive to model generalization, and arrange the attribute of traffic data packets belonging to the same two-way traffic in chronological order; obtain the feature matrix of n traffic data packets;
[0147] The feature matrix of the traffic collected every certain time t is sent to the intrusion detection model.
[0148] Optionally, the data processing module 310 is further configured to:
[0149] When the number of data packets within a single time window is greater than n, the excess data stream is truncated; while for shorter data streams, perform normalization operations on each attribute value, map the attribute value to [0, 1], and perform zero-padding on the samples to make the data packet length of each t time window fixed to n;
[0150] wherein, the data packets captured within the time window of [t 0 , t 0 +t] are represented as E pack (t 0 , t 0 +t);
[0151] When traversing the time window, label the preprocessed data packets; for DDoS attack traffic, the data packet sequence E pack captured in each time window on this traffic is marked as 1, while each E pack captured on normal traffic is marked as 0.
[0152] Optionally, the model construction module 320 is used to introduce a multi-head attention mechanism; wherein, the multi-head attention mechanism is a self-attention mechanism with multiple channels; wherein, the self-attention mechanism includes: Query, key, Value; the input of the first multi-head attention mechanism is Einput;
[0153] During the hyperparameter optimization process, stack multiple multi-head attention mechanisms. When multiple multi-head attention mechanisms are stacked, the input of each multi-head attention mechanism is the output of the previous multi-head attention mechanism; calculate and weight Query, Key, and Value through the self-attention mechanism to generate the Attention value of the target vector;
[0154] Feature extraction is performed by connecting a lightweight convolutional neural network based on the multi-head attention mechanism to capture the feature information and multi-scale dependency relationships of the packet sequence; binary classification is performed on the traffic data based on the feature information extracted by the multi-head attention mechanism.
[0155] Optionally, calculate and weight Query, Key, and Value through the self-attention mechanism to generate the Attention value of the target vector, including:
[0156] Calculate the similarity between Query and Key, quantify their correlation through dot product operation, and weight Value to generate the Attention value of the target vector:
[0157]
[0158] where d k represents the dimension of the hidden layer.
[0159] Optionally, feature extraction is performed by connecting a lightweight convolutional neural network based on the multi-head attention mechanism to capture the feature information and multi-scale dependency relationships of the packet sequence; binary classification is performed on the traffic data based on the feature information extracted by the multi-head attention mechanism, including:
[0160] Take the output of the multi-head attention mechanism module as the input of the convolutional neural network:
[0161] F = {f 1 , f 2 , …, f n}
[0162] where f i represents the i-th row in the feature matrix, that is, the feature information of the i-th packet extracted after considering the dependency relationship between packets; the dimension of the feature matrix F is the same as the dimension of the matrix obtained by preprocessing, that is, [n, f];
[0163] Adopt k convolutional kernels of size h×f, extract and learn local features containing useful information on the feature matrix F with a stride of 1, detect DDos traffic and normal traffic, and each convolutional kernel will generate an activation map a of size (n - h + 1);
[0164] Stack all the activation maps a to obtain an activation matrix A of size (n - h + 1)×k;
[0165] Use the max pooling layer to downsample along the first dimension of the activation matrix A, and use the Sigmoid function to construct the classification layer.
[0166] Optionally, the model preliminary training module 330 is used to adopt the binary cross-entropy loss function when training the model:
[0167]
[0168] Among them, N represents the number of samples in this batch, and y i represents the true label of the sample, and p i represents the prediction result of the intrusion detection model.
[0169] Optionally, the attack defense module 340 is used to label the source domain data as S;
[0170] Train the DDos intrusion detection model with the source domain data S, so that the DDos intrusion detection model learns the general characteristics and rules of DDos attacks; obtain the optimal parameters on the source domain data S and use as the initial parameters for subsequent fine-tuning.
[0171] In the embodiment of the present invention, data preprocessing is performed on the traffic based on the rolling time window method, providing data support for the subsequently constructed DDos attack defense model; secondly, a multi-head attention mechanism is introduced in the traffic feature extraction process to capture the packet sequence feature information and multi-scale dependency relationships in the traffic; finally, a DDos attack defense method in a transformed scenario is designed based on the adaptive architecture of transfer learning, improving the adaptability and robustness of the system.
[0172] Figure 4 is a schematic structural diagram of a DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics, as Figure 4 shown, the DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics may include the above-mentioned Figure 3 shown DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics. Optionally, the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics may include a first processor 2001.
[0173] Optionally, the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics may further include a memory 2002 and a transceiver 2003.
[0174] Among them, the first processor 2001 is connected to the memory 2002 and the transceiver 2003, such as through a communication bus.
[0175] Next, in combination with Figure 4 specific introductions will be made to the respective components of the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics:
[0176] Among them, the first processor 2001 is the control center of the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics, which can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention. For example: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0177] Optionally, the first processor 2001 can execute various functions of the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.
[0178] In a specific implementation, as an embodiment, the first processor 2001 may include one or more CPUs, such as Figure 4 CPU0 and CPU1 shown in
[0179] In a specific implementation, as an embodiment, the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics may also include multiple processors, such as Figure 4 the first processor 2001 and the second processor 2004 shown in. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0180] Among them, the memory 2002 is used to store software programs for implementing the solution of the present invention and is controlled by the first processor 2001 for execution. The specific implementation method can refer to the above method embodiments and will not be elaborated here.
[0181] Optionally, the memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or may exist independently and is coupled to the first processor 2001 through an interface circuit ( Figure 4 not shown) of the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics. The embodiments of the present invention do not make specific limitations on this.
[0182] The transceiver 2003 is used to communicate with a network device or with a terminal device.
[0183] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 4 not shown separately). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.
[0184] Optionally, the transceiver 2003 may be integrated with the first processor 2001 or may exist independently and is coupled to the first processor 2001 through an interface circuit ( Figure 4 not shown) of the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics. The embodiments of the present invention do not make specific limitations on this.
[0185] It should be noted that Figure 4 the structure of the DDos attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics shown in does not constitute a limitation on the router. The actual knowledge structure recognition device may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.
[0186] In addition, for the technical effects of the DDoS attack defense device 410 based on multi-dimensional collaborative interception of traffic characteristics, reference may be made to the technical effects of the DDoS attack defense method based on multi-dimensional collaborative interception of traffic characteristics described in the foregoing method embodiments, which will not be elaborated herein.
[0187] It should be understood that the first processor 2001 in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0188] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0189] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable sensors. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0190] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context before and after.
[0191] It should be understood that in various embodiments of the present invention, the sequence numbers of the above processes do not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0192] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0193] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0194] In addition, in each embodiment of the present invention, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0195] If the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention.
[0196] As mentioned above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A DDos attack defense method based on multi-dimensional collaborative interception of traffic characteristics, characterized in that: The method comprises: S1. Based on the rolling time window, obtain a traffic data packet, pre-process the traffic data packet, and construct a feature matrix of the traffic data packet; S2, introduce the multi-head attention mechanism to extract traffic features and build a DDos intrusion detection binary classification model; S3, training the DDos intrusion detection binary classification model to obtain a DDos intrusion detection model; S4. Obtain target data of actual application scenarios, update the DDos intrusion detection model based on the adaptive architecture of transfer learning, input the target data into the updated DDos intrusion detection model, and complete DDos attack defense based on multi-dimensional collaborative interception of traffic characteristics.
2. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 1 is characterized in that: In S1, based on the rolling time window, a traffic data packet is obtained, the traffic data packet is preprocessed, and a feature matrix of the traffic data packet is constructed, including: Given a bidirectional flow and a predefined time window of length t seconds; capture For all data packets within the time window, delete the attributes of all data packets that are not conducive to model generalization; Arrange the traffic data packet attributes belonging to the same bidirectional traffic in chronological order to form a shape of The characteristic matrix of the traffic data packet; where is the maximum number of packets collected for each bidirectional flow in a single pre-set time window, is the number of attributes remaining after deleting attributes that are not conducive to model generalization; the attributes that are not conducive to model generalization include: IP address, TCP / UDP port, link layer encapsulation type, and application layer type; Based on the above process, Time window to All data packets within the time window are captured, attributes that are not conducive to model generalization are deleted, and the attributes of traffic data packets belonging to the same bidirectional traffic are arranged in chronological order; the feature matrix of n traffic data packets is obtained; The feature matrix of traffic collected every certain time t is sent to the intrusion detection model.
3. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 2 is characterized in that: The S1 also includes: When the number of packets in a single time window is greater than When , the redundant data stream will be truncated; the shorter data stream will be normalized for each attribute value, mapping the attribute value to , and fill the samples with zeros so that each The packet length of the time window is fixed to ; in, The packets captured within the time window are represented as ; When traversing the time window, the pre-processed data packets are labeled; for DDos attack traffic, the data packet sequence of each time window captured on the traffic are marked as 1, and each captured on normal traffic is marked as 0.
4. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 3 is characterized in that: In S2, a multi-head attention mechanism is introduced to extract traffic features and construct a DDos intrusion detection binary classification model, including: A multi-head attention mechanism is introduced; wherein the multi-head attention mechanism is a self-attention mechanism with multiple channels; wherein the self-attention mechanism includes: , , ; The input of the first multi-head attention mechanism is ; In the process of hyperparameter optimization, multiple multi-head attention mechanisms are superimposed. When multiple multi-head attention mechanisms are superimposed, the input of each multi-head attention mechanism is the output of the previous multi-head attention mechanism. , , Calculate and weight to generate the target vector value; Based on the multi-head attention mechanism, a lightweight convolutional neural network is connected to perform feature extraction to capture the feature information and multi-scale dependencies of the data packet sequence; the traffic data is classified into two categories based on the feature information extracted by the multi-head attention mechanism.
5. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 4 is characterized in that: The self-attention mechanism , , Calculate and weight to generate the target vector Values, including: calculate and The similarity between them is quantified by the dot product operation, and the Weighted to generate the target vector value: ; in, Represents the dimension of the hidden layer.
6. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 5 is characterized in that: The multi-head attention mechanism is used to connect a lightweight convolutional neural network to extract features, capture feature information and multi-scale dependencies of data packet sequences; and the traffic data is classified into two categories according to the feature information extracted by the multi-head attention mechanism, including: The output of the multi-head attention mechanism module is used as the input of the convolutional neural network: ; in, Represents the first The first row is extracted after considering the dependencies between data packets. Feature information of a data packet; feature matrix The dimension of is the same as the matrix dimension obtained by preprocessing, that is, ; use The size is The convolution kernel of The local features containing useful information are extracted and learned with a step size of 1 to detect DDos traffic and normal traffic. Each convolution kernel generates a Activation map of ; All activation maps Stacked up, we get The activation matrix ; Using the maximum pooling layer, along the activation matrix The first dimension of is downsampled and the Sigmoid function is used to construct the classification layer.
7. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 6 is characterized in that: In S3, the DDos intrusion detection binary classification model is trained, including: When training the model, the binary cross entropy loss function is used: ; in, represents the number of samples in this batch, represents the true label of the sample, Represents the prediction results of the intrusion detection model.
8. The DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics according to claim 7 is characterized in that: In S4, target data of the actual application scenario is obtained, and the DDos intrusion detection model is updated based on the adaptive architecture of transfer learning, including: Mark the source domain data as ; Through source domain data Train the DDos intrusion detection model so that the DDos intrusion detection model can learn the general characteristics and rules of DDos attacks; obtain source domain data The optimal parameters , and As the initial parameters for subsequent fine-tuning.
9. A DDos attack defense device based on multi-dimensional coordinated interception of traffic characteristics, the DDos attack defense device based on multi-dimensional coordinated interception of traffic characteristics is used to implement the DDos attack defense method based on multi-dimensional coordinated interception of traffic characteristics as claimed in any one of claims 1 to 8, characterized in that: The device comprises: A data processing module, used to obtain traffic data packets based on a rolling time window, pre-process the traffic data packets, and construct a feature matrix of the traffic data packets; Model building module, used to introduce multi-head attention mechanism to extract traffic features and build a binary classification model for DDos intrusion detection; A model preliminary training module is used to train the DDos intrusion detection binary classification model to obtain a DDos intrusion detection model; The attack defense module is used to obtain target data of actual application scenarios, update the DDos intrusion detection model based on the adaptive architecture of transfer learning, input the target data into the updated DDos intrusion detection model, and complete the DDos attack defense based on multi-dimensional collaborative interception of traffic characteristics.
10. A DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics, characterized in that: The DDos attack defense device based on multi-dimensional collaborative interception of traffic characteristics includes: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the method according to any one of claims 1 to 8 is implemented.