Network intrusion detection method based on sparrow cluster optimization algorithm

By improving the sparrow search algorithm, the ISSA-RF-LSTM model is constructed, and the RF-LSTM model hyperparameters in network intrusion detection are optimized, which solves the problem of insufficient detection accuracy and easy to fall into local optimal solutions in the existing technology, and achieves more efficient intrusion detection.

CN120074875APending Publication Date: 2025-05-30HARBIN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510102511.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art has insufficient detection accuracy in network intrusion detection, which is prone to falling into local optimal solutions, and has low efficiency in hyperparameter optimization.

Method used

The network intrusion detection method based on sparrow cluster optimization algorithm is adopted, and the sparrow search algorithm is improved through Tent mapping, Tent chaotic perturbation, and Gaussian mutation, and the ISSA-RF-LSTM model is constructed to optimize the hyperparameters of the RF-LSTM model.

Benefits of technology

It improves the detection accuracy of the intrusion detection model, reduces the false positive rate, enhances the global search ability of the algorithm, avoids local optimal solutions, and improves the efficiency of hyperparameter optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074875A_ABST
    Figure CN120074875A_ABST
Patent Text Reader

Abstract

The invention discloses a sparrow cluster optimization algorithm-based network intrusion detection method. The method comprises the steps of preprocessing a network intrusion detection data set; individual positions of a sparrow population are initialized through Tent mapping improved by Tent disturbance and Gaussian variation, and an individual fitness value of the initial population is calculated; determining an optimal sparrow position through individual fitness, outputting a chaos sequence to obtain a hyper-parameter initial value of an SF-LSTM model, and obtaining an RF-LSTM model optimized by a sparrow cluster optimization algorithm; training the model to generate a combined model; and inputting the processed network intrusion detection data set to detect the classification effect of the model on the threat data. Dynamically adjusting the step length control parameters according to the change of the global fitness; and a sparrow cluster optimization algorithm-RF-LSTM combined detection model is constructed and obtained. According to the method for searching the optimal hyper-parameter by optimizing the RF-LSTM neural network by using the sparrow cluster optimization algorithm, the convergence of the model can be accelerated by using the RF-LSTM optimized by using the sparrow cluster, the detection precision of the intrusion detection model is improved, and the false alarm rate is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the intrusion detection direction in the field of network security, and particularly relates to a network intrusion detection method based on a sparrow swarm optimization algorithm. Background Art

[0002] With the wide application of the Internet in many fields such as industry, commerce, social platforms, and government departments, network attack incidents have occurred frequently in recent years, causing immeasurable losses to the property of the people. Therefore, the concept of intrusion detection has been proposed and applied in more and more fields. Intrusion detection is a very important security countermeasure for identifying malicious activities in network traffic. With the continuous development of intrusion detection technology, various intrusion detection systems have been written and deployed in all walks of life.

[0003] Intrusion detection is a typical classification problem, and its purpose is to timely and accurately identify attacks or potential threats hidden in network traffic. Traditional intrusion detection systems use predefined rules and pattern libraries to detect known attack behaviors. These rules identify malicious behaviors through feature matching or regular expressions.

[0004] Common methods for initializing intelligent population optimization algorithms mainly include random initialization, uniform distribution initialization, chaotic mapping initialization, etc. For random initialization and uniform distribution initialization, that is, randomly or uniformly sampling to generate the parameters or positions of each individual in the population, it is easy to implement but does not consider the high-dimensional, discrete, aperiodic, and sensitive characteristics of intrusion detection. Chaotic mapping is a class of nonlinear dynamic systems, which have the characteristic of highly sensitive dependence on initial conditions, and the generated sequences have randomness and complexity.

[0005] At present, some researchers have used swarm optimization algorithms to improve machine learning or deep learning models, and then applied the combined models to the field of intrusion detection. However, these methods have some deficiencies: existing swarm algorithms such as the sparrow search algorithm have limited optimization ability and are prone to falling into local optimal solutions; hyperparameter optimization is not intelligent enough, and manual screening is adopted, resulting in low efficiency.

[0006] In the prior art, there have been some combined application methods of chaotic mapping and sparrow search algorithm. However, limited by the aforementioned characteristics of the intrusion detection field, the combined methods of chaotic mapping and sparrow search algorithm in these inventions cannot be applied in the intrusion detection field.

[0007] Moreover, the detection accuracy of the prior art is insufficient, and it cannot adapt to complex network environments. For the problem of classifying network abnormal traffic, the recognition effect is not good and cannot meet the actual needs. Summary of the Invention

[0008] The purpose of the present invention is to solve the problem of insufficient detection accuracy in the prior art, and at the same time overcome the defects of low accuracy, slow convergence speed and easy to fall into local optimal solutions in the existing detection methods, and provide a network intrusion detection method based on the sparrow swarm optimization algorithm.

[0009] To achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0010] A network intrusion detection method based on the sparrow swarm optimization algorithm, the method comprising the following steps:

[0011] Step 1: Preprocess the intrusion detection data set, perform normalization and One-hot encoding on the data set to obtain the initial data set, and divide the initial data set into a training set and a test set;

[0012] Step 2: Use RF to extract the features of network abnormal traffic, then fuse RF and LSTM to construct an RF-LSTM combined model, train the combined model to obtain the hyperparameters to be improved, namely the learning rate, the number of iterations and the number of hidden layer nodes;

[0013] Step 3: Improve the sparrow search algorithm by means of Tent mapping, Tent chaotic perturbation and Gaussian mutation, and propose the sparrow swarm optimization algorithm (ISSA);

[0014] Step 4: Construct an ISSA-RF-LSTM model, input the training set into the model, initialize the sparrow population, iterate and update the positions of the discoverers, the joiners and the sparrows aware of danger in the sparrow population until the number of iterations reaches the set maximum number of iterations, determine the position of the optimal sparrow, and obtain the optimal solution of the hyperparameters of the model, that is, the optimal solution of the number of hidden layer nodes, the learning rate and the number of training times;

[0015] Step 5: Set the model parameters to the optimal parameters to obtain an intrusion detection model, input the test set into the intrusion detection model and obtain the optimal detection classification result.

[0016] Further, the specific content of Step 1 is: after performing normalization and One-hot encoding, divide the training set and the test set;

[0017] Normalize the data according to the following formula:

[0018]

[0019] In the formula, x * is the normalized data, x is the original data, MIN is the minimum value in the original data, and MAX is the maximum value in the original data;

[0020] For non-numerical features, such as session status, IP address, protocol, etc., One-Hot encoding is used for processing; for each categorical feature to be encoded, all its possible categories are identified, and a new binary feature is created for each category. If a sample belongs to a certain category, the corresponding feature of that category is set to 1, and the remaining features are set to 0.

[0021] Further, in step two, the process of constructing the RF-LSTM model includes the following steps:

[0022] Step two-one: Use the LSTM model to learn the features of abnormal traffic data by training a large amount of network abnormal traffic data;

[0023] Step two-two: Introduce the RF ensemble learning method, and use RF to reorder the learned features from high to low according to importance, and combine RF and LSTM into the RF-LTSM model.

[0024] Further, in step three, the method of improving the sparrow search algorithm with Tent mapping, Tent chaotic perturbation, and Gaussian mutation includes the following steps:

[0025] Step three-one: Randomly generate an initial value z within (0, 1) 0 , where i represents the number of mappings, z i represents the function value of the i-th mapping, and at this time i = 0;

[0026] Step three-two: Iterate according to the following formula to generate the z sequence, and i is incremented by 1;

[0027]

[0028] Among them, z i+1 represents the function value of the (i + 1)-th mapping, z i represents the function value of the i-th mapping, mod1 is taking the modulus of 1, rand(0, 1) is a random number within [0, 1], and N T is the number of particles in the chaotic sequence;

[0029] Step three-three: After the iteration reaches the maximum number of times, save the generated z sequence;

[0030] Step three-four: Generate chaotic variables according to the following formula;

[0031]

[0032] Step three-five: Introduce the chaotic variables into the solution space of the result to be solved according to the following formula;

[0033]

[0034] In the formula, the maximum and minimum values of the d - dimensional variable are respectively denoted as d max and d min ; z i+1 is a chaotic variable generated by using the formulas in Steps 3 and 4;

[0035] Step 3 - 6: Perform chaotic perturbation on the input individual according to the following formula;

[0036] X' new =(X'+X new ) / 2

[0037] In the formula, X' is the input individual, X new is the chaotic perturbation amount, and X' new is the individual after chaotic perturbation;

[0038] Step 3 - 7: According to the following formula, use the random number generated by the standard normal distribution as the improvement parameter to replace the original parameter for mutation operation;

[0039] mutation(x)=x(1 + N(0,1))

[0040] In the formula, x is the original parameter, N(0,1) is the standard normal distribution, and mutation(x) is the mutated value.

[0041] Furthermore, the said Step 4 includes:

[0042] Step 4 - 1: Construct an ISSA - RF - LSTM model and input the training set into the model;

[0043] Step 4 - 2: Initialize the parameters: among them, there are population size N, number of discoverers p, number of joiners N - p, number of perceivers s, upper and lower bounds l b , u b of the initial value, and maximum number of iterations T;

[0044] Step 4 - 3: Initialize the population by Tent chaos, generate N d - dimensional vectors z i , and make the components in the vector z i take values within the value range of the input space variable;

[0045] Step 4 - 4: Calculate the fitness f i of each sparrow, select the current optimal fitness value f g and the worst fitness value f w , and take their corresponding position values x b and x w ;

[0046] Step 45: Arrange the fitness values from the best to the worst according to the fitness, select the top p sparrows with the best fitness as discoverers, and the remaining ones as joiners. Divide the discoverers and joiners, and update the position values of the two types of individuals according to the sparrow algorithm formula;

[0047] Step 46: Randomly select s perceivers from the sparrow population and update their position values according to the sparrow algorithm formula;

[0048] Step 47: After one iteration is completed, recalculate the fitness f of each sparrow i and the average fitness value f of the sparrow population avg ;

[0049] f i is less than f avg , it indicates that there is a certain aggregation at present, and Gaussian mutation is used for processing. If the individual value after mutation is better than the individual value before mutation, the individual value after mutation is adopted; otherwise, the individual value before mutation is adopted; f i is greater than or equal to f avg , it indicates that there is a divergence trend at present, and chaotic perturbation is used for processing. If the individual value after perturbation is better than the individual value before mutation, the individual value after perturbation is adopted; otherwise, the individual value before perturbation is adopted;

[0050] Check the overall state of the sparrow population, and update the optimal fitness value f g and the worst fitness value f w , as well as the corresponding position values x b and x w ;

[0051] Step 48: Judge whether ISSA has reached the maximum number of iterations. If it has reached the maximum number of iterations, output the optimization result; otherwise, jump to Step 44 to optimize again;

[0052] Among them, the sparrow algorithm updates the positions of the discoverers, joiners, and sparrows aware of danger in turn according to the following formula:

[0053]

[0054] In the formula, represents the information of the position update of the i-th sparrow at the j-th dimension in the t-th iteration; t represents the number of iterations; α is a random number belonging to (0, 1); iter max represents the maximum number of iterations, R 2 belongs to [0, 1] and represents the early warning signal threshold; ST belongs to [0.5, 1] and represents the safety early warning signal threshold; Q is a random number and satisfies the normal distribution; L is a 1×d matrix, and the initial value of each element inside the matrix is 1;

[0055]

[0056] In the formula, n is the number of individuals in the sparrow population, is the position of the sparrow with the best and safest position in the current population; similarly, is the position of the sparrow in the most dangerous and worst position in the current population; A represents a 1×d matrix, and the values in the matrix are randomly assigned 1 or -1 and satisfy A + = A T (AA T ) -1 ; if i > n / 2, it means that the i-th predator has low energy, poor position, and is in hunger; if i ≤ n / 2, it means that the current sparrow has a good position and only needs to approach the sparrows in better positions in the future;

[0057]

[0058] In the formula, represents the central position of the current population, that is, the optimal position; β is used as a compensation control parameter and follows a standard normal distribution with a mean of 0 and a variance of 1; K represents the moving step size and is a random value taken from the interval [-1, 1]; f i represents the fitness function value of the i-th sensing sparrow in the sensing sparrow population; f g represents the fitness function value of the sparrow with the highest energy in the current entire sparrow population; on the contrary, f w is the fitness function value of the sparrow with the lowest energy in the sparrow population; ε represents an infinitesimal number to prevent the denominator in the update function from being 0;

[0059] Step forty-nine, obtain the optimal solutions of the hyperparameters, namely the number of hidden layer nodes, the learning rate, and the number of training times.

[0060] Furthermore, the specific content of the said step five is as follows:

[0061] Step fifty-one: Set the hyperparameters of the ISSA-RF-LSTM model to the optimal parameters to obtain an intrusion detection model:

[0062] Step fifty-two: Input the test set into the intrusion detection model;

[0063] Step fifty-three: Obtain the optimal detection and classification effect.

[0064] The beneficial effects of the present invention compared with the prior art are as follows: In order to solve the problem that the existing sparrow search algorithm has limited optimization ability and is prone to falling into local optimal solutions, the present invention improves the sparrow search algorithm by using Tent mapping, Tent chaotic perturbation, and Gaussian mutation methods, and proposes the Improved Sparrow Search Algorithm (ISSA); traditional network abnormal traffic and intrusion detection systems achieve the function of intrusion detection through packet sniffing and rule base matching. The types of perceivable abnormal behaviors are positively correlated with the types and quantities of rules recorded in the rule base. However, the existing models have limited recognition effects on intrusion behaviors and cannot meet the classification requirements for network traffic. To adapt to complex network environments and solve the problem of network abnormal traffic classification, the present invention introduces knowledge related to machine learning and deep learning, combines RF on the basis of LSTM, and proposes a neural network model based on RF-LSTM to screen intrusion behavior features through random forests; to solve the problem of hyperparameter optimization, the present invention uses the ISSA algorithm to optimize the hyperparameters of the RF-LSTM prediction model, namely the number of hidden layer nodes, learning rate, and number of training times, and proposes the ISSA-SF-LSTM model, which is applied to the field of intrusion detection, improving the detection accuracy of the intrusion detection model and reducing the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 It is a flowchart of an intrusion detection method based on the Improved Sparrow Search Algorithm according to an embodiment of the present invention;

[0066] Figure 2 It is a comparison diagram of Tent mapping chaotic sequence distributions according to an embodiment of the present invention;

[0067] Figure 3 It is a comparison diagram of Logistic mapping chaotic sequence distributions according to an embodiment of the present invention;

[0068] Figure 4 It is a comparison histogram of Tent mapping chaos according to an embodiment of the present invention;

[0069] Figure 5 It is a comparison histogram of Logistic mapping chaos according to an embodiment of the present invention;

[0070] Figure 6 It is a comparison diagram for testing the convergence ability of the Improved Sparrow Search Algorithm (ISSA) according to an embodiment of the present invention using a unimodal multi-dimensional function 1, and comparing it with the SSA algorithm, whale algorithm, and grey wolf algorithm;

[0071] Figure 7 It is a comparison diagram for testing the convergence ability of the Improved Sparrow Search Algorithm (ISSA) according to an embodiment of the present invention using a unimodal multi-dimensional function 2, and comparing it with the SSA algorithm, whale algorithm, and grey wolf algorithm;

[0072] Figure 8It is a curve graph of the accuracy change after inputting the preprocessed NSL-KDD dataset into the ISSA-SF-LSTM model;

[0073] Figure 9 It is a curve graph of the loss rate change after inputting the preprocessed NSL-KDD dataset into the ISSA-SF-LSTM model;

[0074] Figure 10 It is a confusion matrix graph after inputting the preprocessed NSL-KDD dataset into the ISSA-SF-LSTM model;

[0075] Figure 11 It is an ROC curve graph after inputting the preprocessed NSL-KDD dataset into the ISSA-SF-LSTM model. Detailed implementation manners

[0076] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the accompanying drawings. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the present invention and should not be construed as a limitation to the present invention.

[0077] The method of the present invention includes: preprocessing the network intrusion detection dataset; initializing the individual positions of the sparrow population through the Tent mapping improved by Tent perturbation and Gaussian mutation, and calculating the fitness values of the initial population individuals; determining the optimal sparrow position through the individual fitness, outputting a chaotic sequence to obtain the initial values of the hyperparameters of the SF-LSTM model, and obtaining the RF-LSTM model optimized by the sparrow swarm optimization algorithm; training the sparrow swarm optimization algorithm-SSA-LSTM model to generate a combined model; inputting the processed network intrusion detection dataset into the combined model to detect the classification effect of the model on threat data. Dynamically adjust the step control parameter according to the change of the global fitness; construct a sparrow swarm optimization algorithm-RF-LSTM combined detection model. The present invention uses the sparrow swarm optimization algorithm to optimize the method of finding the optimal hyperparameters of the RF-LSTM neural network. The RF-LSTM optimized by the sparrow swarm optimization can accelerate the convergence of the model, improve the detection accuracy of the intrusion detection model and reduce the false alarm rate, thereby solving the problem of insufficient detection accuracy in the prior art, and at the same time overcoming the defects of slow convergence speed and easy to fall into local optimal solutions in the existing detection methods.

[0078] Embodiment 1:

[0079] The intrusion detection method based on the sparrow swarm optimization algorithm to optimize RF-LSTM of the present invention first proposes an RF-LSTM intrusion detection model, and then proposes a sparrow swarm optimization algorithm (ISSA) for optimizing the hyperparameters of the network security situation prediction model. The flow of the intrusion detection method based on the sparrow swarm optimization algorithm to optimize RF-LSTM of the present invention is asFigure 1 As shown, the specific steps are as follows:

[0080] Step 1: Preprocess the intrusion detection dataset. After normalization and One-hot encoding, divide it into a training set and a test set. Table 1 shows the distribution of various types of attacks in the dataset.

[0081] Table 1 NSL-KDD Attack Distribution

[0082]

[0083] Normalize the data according to the following formula:

[0084]

[0085] In the formula, x * is the normalized data, x is the original data, MIN is the minimum value in the original data, and MAX is the maximum value in the original data.

[0086] For non-numerical features such as session status, IP address, protocol, etc., use the One-Hot encoding method for processing. For each categorical feature to be encoded, identify all its possible categories, create a new binary feature for each category. If a sample belongs to a certain category, set the corresponding feature of that category to 1, and the remaining features to 0.

[0087] Step 2: Use RF to extract the features of network abnormal traffic, then fuse RF with LSTM to construct an RF-LSTM combined model, train the combined model, and obtain the hyperparameters to be improved, namely the learning rate, the number of iterations, and the number of hidden layer nodes. In this example, the upper and lower limits of the hyperparameters are set. The lower limit of the learning rate is set to 0.001, the upper limit is set to 0.01, the lower limit of the number of iterations is set to 50, the upper limit is set to 200, and the lower limit of the number of hidden layer nodes is set to 64, and the upper limit is set to 512.

[0088] Step 3: Improve the sparrow search algorithm through Tent mapping, Tent chaotic perturbation, and Gaussian mutation methods, and propose an improved sparrow swarm optimization algorithm (ISSA).

[0089] In this embodiment, the method of improving the sparrow search algorithm by Tent mapping, Tent chaotic perturbation, and Gaussian mutation includes the following steps:

[0090] Step 3-1: Randomly generate an initial value z 0 within the range of (0, 1), and at this time i = 0;

[0091] Step 3-2: Iterate according to the following formula to generate a z sequence, and i is incremented by 1;

[0092]

[0093] where rand(0, 1) is a random number with values in the range [0, 1], and N T is the number of particles in the chaotic sequence.

[0094] Step 33: After the iteration reaches the maximum number of times, save the generated z sequence.

[0095] Step 34: Generate chaotic variables according to the following formula;

[0096]

[0097] Step 35: Introduce the chaotic variables into the solution space of the result to be solved according to the following formula;

[0098]

[0099] In the formula, the maximum and minimum values of the d-dimensional variable are represented as d max and d min .

[0100] Step 36: Perform chaotic perturbation on the input individual according to the following formula;

[0101] X' new = (X' + X new ) / 2

[0102] In the formula, X' is the input individual, X new is the chaotic perturbation amount, and X' new is the individual after chaotic perturbation.

[0103] Step 37: According to the following formula, use the random number generated by the standard normal distribution as the improvement parameter to replace the original parameter for mutation operation;

[0104] mutation(x) = x(1 + N(0, 1))

[0105] In the formula, x is the original parameter, N(0, 1) is the standard normal distribution, and mutation(x) is the mutated value.

[0106] The chaotic sequence output by the Tent map has certain small periods and some unstable periodic points. To solve this problem while introducing a random variable The values of the improved Tent mapping are more uniform. Therefore, the algorithm can improve the quality of the initial solution and enhance the global search ability of the algorithm. To solve the problem that the optimization algorithm is prone to falling into local optimum and improve the global search ability and optimization accuracy of the algorithm, this embodiment introduces chaotic perturbation on the basis of the Tent mapping. Gaussian mutation focuses on searching the area around the input individual. By adding a normal distribution to form a Gaussian distribution, the local search ability of the search becomes stronger, and the optimization is more efficient and accurate, improving the robustness of the SSA algorithm. The comparison of the chaotic sequence distribution and the chaotic histogram comparison of the Tent chaotic mapping and the Logistic mapping adopted in this embodiment are referred to Figure 2 and Figure 3 。

[0107] Step Four: Construct the ISSA-RF-LSTM model, input the training set into the model, initialize the sparrow population, and iteratively update the positions of the discoverers, joiners, and sparrows aware of danger in the sparrow population until the number of iterations reaches the set maximum number of iterations, determine the position of the optimal sparrow, and obtain the optimal solution of the hyperparameters of the model, that is, the optimal solutions of the number of hidden layer nodes, learning rate, and number of training times.

[0108] In this embodiment, initializing the sparrow population and iteratively updating the positions of the discoverers, joiners, and sparrows aware of danger in the sparrow population until the number of iterations reaches the set maximum number of iterations and determining the position of the optimal sparrow include the following steps:

[0109] Step Four-One: Initialize the parameters. Among them are: population size N, number of discoverers p, number of joiners N - p, number of perceivers s, upper and lower bounds l b 、u b , and maximum number of iterations T;

[0110] Step Four-Two: Initialize the population with Tent chaos, generate N d-dimensional vectors z i , and make the component values in the vector z i fall within the value range of the input space variables;

[0111] Step Four-Three: Calculate the fitness f i of each sparrow, select the current optimal fitness value f g and the worst fitness value f w , and take the corresponding position values x b and x w ;

[0112] Step Four-Four: Arrange the fitness values from best to worst according to fitness, select the top p sparrows with the best fitness as discoverers, and the rest as joiners. Divide the discoverers and joiners, and update the position values of the two types of individuals according to the sparrow algorithm formula;

[0113] Step 45: Randomly select s perceivers from the sparrow population and update the position values according to the sparrow algorithm formula;

[0114] Step 46: After one iteration is completed, recalculate the fitness value f of each sparrow i and the average fitness value f of the sparrow population avg .

[0115] f i is less than f avg , indicating that there is a certain aggregation at present. Gaussian mutation is used for processing. If the individual value after mutation is better than the individual value before mutation, the individual value after mutation is adopted; otherwise, the individual value before mutation is adopted; f i is greater than or equal to f avg , indicating that there is a divergence trend at present. Chaotic perturbation is used for processing. If the individual value after perturbation is better than the individual value before mutation, the individual value after perturbation is adopted; otherwise, the individual value before perturbation is adopted;

[0116] Step 47: Check the overall state of the sparrow population and update the optimal fitness value f g and the worst fitness value f w of the sparrow population, as well as the corresponding position values x b and x w ;

[0117] Step 48: Determine whether ISSA has reached the maximum number of iterations. If it has reached the maximum number of iterations, output the optimization result; otherwise, jump to Step 44 to optimize again.

[0118] Among them, the sparrow algorithm updates the positions of the discoverer, the joiner, and the sparrow aware of danger in turn according to the following formula:

[0119]

[0120] In the formula, t represents the number of iterations; represents the information of the position updated at the j-th dimension of the i-th sparrow at the t-th iteration; iter max represents the maximum number of iterations; α is a random number belonging to (0, 1); ST belonging to [0.5, 1] represents the safety warning signal threshold; R 2 belonging to [0, 1] represents the warning signal threshold; Q is a random number and satisfies the normal distribution; L is a 1×d matrix, and the initial value of each element inside the matrix is 1.

[0121]

[0122] In the formula, n is the number of individuals in the sparrow population, X p is the position of the sparrow with the best and safest position in the current population; similarly, Xworst is the position of the sparrow with the worst position among the most dangerous positions in the current population; A represents a 1×d matrix, and the values in the matrix are randomly assigned 1 or -1 and satisfy A + = A T (AA T ) -1 ; if i > n / 2, it means that the i-th predator has low energy, poor position, and is hungry. If i ≤ n / 2, it means that the current sparrow position is better, and only needs to approach the sparrows in better positions in the future

[0123]

[0124] In the formula, represents the central position of the current population, that is, the optimal position; β is a compensation control parameter, following the standard normal distribution with a mean of 0 and a variance of 1; K represents the moving step size, which is a random value taken from the interval [-1, 1]; f i represents the fitness function value of the i-th sensing sparrow in the sensing sparrow population; f g represents the fitness function value of the sparrow with the highest energy in the current entire sparrow population; on the contrary, f w is the fitness function value of the sparrow with the lowest energy in the sparrow population; ε represents an infinitesimal number to prevent the denominator in the update function from being 0

[0125] The ISSA algorithm increases the population diversity, improves the search performance and exploration performance of the algorithm, and avoids falling into local optima by introducing Tent chaotic search and Gaussian mutation. The finally found optimal hyperparameter combination is: learning rate 0.0084, number of iterations 68, and number of hidden layer nodes 91

[0126] Step Five: Analyze the sparrow swarm optimization algorithm (ISSA). At the same time, compare it with the SSA algorithm, whale algorithm, and gray wolf algorithm. The results are as Figure 4 .

[0127] In this embodiment, the population size of these algorithms is set to 30, the maximum number of iterations is set to 500, the dimension is set to 30, the discovery rate in the sparrow population is set to 20%, the sensing rate is set to 10%, and each algorithm runs independently 50 times. It can be clearly seen that in the process from 0 iteration to 100 times, the ISSA algorithm converges faster and more stably than the SSA algorithm. In the later stage of the search, the search capabilities of the SSA algorithm, whale algorithm, and gray wolf algorithm are almost stagnant, and the convergence curves tend to be stable, while the convergence curve of the ISSA algorithm is still steep. This proves that the convergence effect of the ISSA algorithm has been greatly improved, and its local development ability is stronger than that of the SSA algorithm, whale algorithm, and gray wolf algorithm

[0128] Step 6: Input the test set into the intrusion detection model and obtain the detection and classification results.

[0129] Input the test set into the model to check the detection effect. The change curves of the accuracy rate and error rate after the NSL-KDD test set is input into the ISSA-SF-LSTM model are referred to Figure 5 . As the number of iteration rounds epoch increases, the loss rate Loss decreases, and the accuracy rate Accuracy continuously increases. When epoch reaches 80 and later, the change curves of the loss rate and accuracy rate tend to be stable.

[0130] To further verify the detection effect of the model, the confusion matrix and ROC curve are used for evaluation. The confusion matrix is referred to Figure 6 , and it can be intuitively seen the classification effect of the model for various types of attacks. The diagonal line shows the number of samples with correct predicted classification by the model. It can be seen that the normal traffic and the four types of abnormal traffic can be relatively clearly classified. The ROC curve is referred to Figure 7 , the closer to 1, the better the classification effect. It can be seen that for the five attack types, the average Auc value is 0.98, and the classification effect is good.

[0131] The specific classification effect is referred to Table 2. It can be seen that the model has the best classification effect for the Dos type threat data, and the precision rate reaches 99%. The classification effects for the Normal and Probe type threat data are also good. The model also has a certain classification effect for the R2l and u2r type data with a small quantity in the dataset.

[0132] Table 2 NSL-KDD Classification Effect

[0133]

[0134]

[0135] To make the detection method proposed in the present invention more persuasive, CNN, LSTM, CNN-LSTM, and improved CNN-BILSTM-ATTENTION are used as comparative experiments. The experimental results are referred to Table 3, which shows that the accuracy rate, precision rate, recall rate, and F1 value of the ISSA-SF-LSTM combined model are significantly higher than those of the single model and other composite models, which verifies the feasibility of the detection method proposed in the present invention in detection and classification.

[0136] Table 3 Comparative Analysis

[0137]

[0138] The above-disclosed is only a preferred embodiment of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Those of ordinary skill in the art can understand all or part of the processes of implementing the above embodiments, and the equivalent changes made according to the claims of the present invention still fall within the scope covered by the invention.

Claims

1. A network intrusion detection method based on sparrow cluster optimization algorithm, characterized in that: The method comprises the following steps: Step 1: Preprocess the intrusion detection data set, normalize and One-hot encode the data set to obtain the initial data set, and divide the initial data set into a training set and a test set; Step 2: Use RF to extract the characteristics of abnormal network traffic, then fuse RF with LSTM to build an RF-LSTM combined model, train the combined model, and obtain the hyperparameters that need to be improved, such as learning rate, number of iterations, and number of hidden layer nodes; Step 3: Improve the sparrow search algorithm through the methods of tent mapping, tent chaos perturbation and Gaussian mutation, and propose the sparrow cluster optimization algorithm (ISSA); Step 4: Build the ISSA-RF-LSTM model, input the training set into the model, initialize the sparrow population, iteratively update the discoverer position, joiner position, and the position of the sparrow that is aware of the danger in the sparrow population until the number of iterations reaches the set maximum number of iterations, determine the position of the optimal sparrow, and obtain the model's hyperparameter values, that is, the optimal solution for the number of hidden layer nodes, learning rate, and number of training times; Step 5: Set the model parameters to the optimal parameters, obtain the intrusion detection model, input the test set into the intrusion detection model and obtain the optimal detection classification result.

2. A network intrusion detection method based on sparrow cluster optimization algorithm according to claim 1, characterized in that: The step 1 specifically includes: performing normalization and one-hot encoding, and then dividing the training set and the test set; The data were normalized according to the following formula: In the formula, x * is the normalized data, x is the original data, MIN is the minimum value in the original data, and MAX is the maximum value in the original data; For non-numeric features, One-Hot encoding is used for processing; for each categorical feature that needs to be encoded, all possible categories are identified, and a new binary feature is created for each category. If a sample belongs to a certain category, the corresponding feature of the category is set to 1, and the remaining features are set to 0.

3. A network intrusion detection method based on sparrow cluster optimization algorithm according to claim 1, characterized in that: In step 2, the process of constructing the RF-LSTM model includes the following steps: Step 21: Use the LSTM model to learn the characteristics of abnormal traffic data by training a large amount of network abnormal traffic data; Step 22: Introduce the RF ensemble learning method, use RF to reorder the learned features from high to low importance, and combine RF with LSTM into the RF-LTSM model.

4. A network intrusion detection method based on sparrow cluster optimization algorithm according to claim 1, characterized in that: In step 3, the method of improving the sparrow search algorithm by using tent mapping, tent chaotic perturbation, and Gaussian mutation includes the following steps: Step 31: Randomly generate an initial value z0 between (0, 1), where i represents the number of mappings, and z i Represents the i-th mapping function value, where i=0; Step 32: Iterate according to the following formula to generate the z sequence, with i increasing by 1; Among them, z i+1 represents the i+1th mapping function value, z i represents the i-th mapping function value, mod1 is modulo 1, rand(0,1) is a random number between [0, 1], N T is the number of particles in the chaotic sequence; Step 33: After the maximum number of iterations is reached, save the generated z sequence; Step 34: Generate chaotic variables according to the following formula; Step 35: Introduce chaotic variables into the solution space of the required solution results according to the following formula; In the formula, the d-th dimension variable The maximum and minimum values ​​of max and d min ; z i+1 is the chaotic variable generated by the formula in steps three and four; Step 36: Perform chaotic perturbation on the input individual according to the following formula; X' new =(X'+X new ) / 2 In the formula, X' is the input individual, X new is the chaotic disturbance, X' new is the individual after the chaotic disturbance; Step 37: According to the following formula, use the random numbers generated by the standard normal distribution as improved parameters to replace the original parameters for mutation operation; mutation(x)=x(1+N(0,1)) In the formula, x is the original parameter, N(0,1) is the standard normal distribution, and mutation(x) is the value after mutation.

5. A network intrusion detection method based on sparrow cluster optimization algorithm according to claim 1, characterized in that: The fourth step comprises: Step 41: Build the ISSA-RF-LSTM model and input the training set into the model; Step 42: Initialize parameters: population size N, number of discoverers p, number of joiners Np, number of perceivers s, upper and lower bounds of initial values ​​l b 、u b , maximum number of iterations T; Step 43: Initialize the population with Tent chaos and generate N d-dimensional vectors z i , so that the vector z i The component values ​​in are within the range of the input spatial variables; Step 44: Calculate the fitness f of each sparrow i , select the current optimal fitness value f g And the worst fitness value f w , take the corresponding position value x b and x w ; Step 4 and 5: Arrange the fitness values ​​from best to worst, select the top p best sparrows as discoverers, and the rest as joiners, divide the discoverers and joiners, and update the values ​​of the two individual positions according to the sparrow algorithm formula; Step 46: randomly select s perceivers from the sparrow population and update the value of their position according to the sparrow algorithm formula; Step 47: After one iteration is completed, recalculate the fitness f of each sparrow i and the average fitness value of the sparrow population f avg ; f i Less than f avg When , it indicates that there is a certain amount of aggregation at present, and Gaussian mutation is used for processing. If the individual value after mutation is better than the individual value before mutation, the individual value after mutation is used, otherwise the individual value before mutation is used; f i Greater than or equal to f avg When , it indicates that there is a divergent trend at present, and chaotic disturbance is used for processing. If the individual value after disturbance is better than the individual value before mutation, the individual value after disturbance is used, otherwise the individual value before disturbance is used; Check the overall status of the sparrow population and update the optimal fitness value f of the sparrow population g And the worst fitness value f w , and the corresponding position value x b and x w ; Step 48, determine whether ISSA has reached the maximum number of iterations. If it has reached the maximum number of iterations, output the optimization result; otherwise, skip to step 44 and search for the optimization again; The sparrow algorithm updates the discoverer's position, the joiner's position, and the position of the sparrow that is aware of the danger in turn according to the following formula: In the formula, It represents the information of the position update of the i-th sparrow in the j-th dimension iteration t; t represents the number of iterations; α is a random number belonging to (0, 1); iter max represents the maximum number of iterations, R2 belongs to [0, 1] to indicate the warning signal threshold; ST belongs to [0.5, 1] ​​to indicate the safety warning signal threshold; Q is a random number and satisfies the normal distribution; L is a 1×d matrix, and the initial value of each element in the matrix is ​​1; Where n is the number of individuals in the sparrow population, is the position of the sparrow with the best and safest position in the current population; similarly, is the position of the sparrow in the most dangerous and worst position in the current population; A represents a 1×d matrix, and the values ​​in the matrix are randomly assigned 1 or -1 and satisfy A + =A T (AA T ) -1 ; If i>n / 2, it means that the i-th predator has low energy, poor position, and is hungry; if i≤n / 2, it means that the current sparrow is in a good position, and it only needs to move closer to the sparrow in a better position; In the formula, represents the current population center position, i.e., the optimal position; β is a compensation control parameter, which follows a standard normal distribution with a mean of 0 and a variance of 1; K represents the moving step length, which is a random value taken from the interval [-1, 1]; f i represents the fitness function value of the i-th perceiving sparrow in the perceiving sparrow population; f g It represents the fitness function value of the sparrow with the highest energy in the entire sparrow population; on the contrary, f w It is the fitness function value of the sparrow with the lowest energy in the sparrow population; ε represents an infinitesimal number to prevent the denominator from being 0 in the update function; Step 49, obtain the optimal solution for the hyperparameters, namely the number of hidden layer nodes, learning rate and number of training times.

6. A network intrusion detection method based on sparrow cluster optimization algorithm according to claim 1, characterized in that: The step five is specifically as follows: Step 51: Set the hyperparameters of the ISSA-RF-LSTM model to the optimal parameters to obtain the intrusion detection model: Step 52: Input the test set into the intrusion detection model; Step 53: Obtain the optimal detection and classification effect.