Network abnormal flow detection method, system, equipment and medium

By applying non-extended entropy feature extraction and incremental learning methods in network traffic detection, dynamically adjusting feature contribution values ​​and adaptively updating parameters, the problem of identifying abnormal traffic in large-scale network environments in the prior art is solved, and more accurate and flexible traffic anomaly detection is achieved.

CN120074904APending Publication Date: 2025-05-30GCI SCI & TECH +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510200866.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing network traffic detection methods are difficult to accurately identify abnormal traffic in large-scale network environments, especially when facing heavy tail distribution and dynamically changing network traffic, they cannot effectively handle low-frequency characteristics and respond to new attacks.

Method used

The feature extraction method based on non-extended entropy is adopted, combined with incremental learning method, the contribution value of the basic attribute characteristics is dynamically adjusted, and the non-extended entropy parameters are adaptively updated, and the traffic characteristics are reconstructed to identify network abnormal traffic.

Benefits of technology

It realizes accurate identification of abnormal traffic in a dynamically changing network environment, can effectively handle low-frequency features and respond to new attacks, and improves the accuracy and flexibility of network security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074904A_ABST
    Figure CN120074904A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a network abnormal flow detection method, system and device and a medium, and the method comprises the steps: collecting basic attribute features of a network flow data packet, and forming a basic attribute feature sequence; performing feature processing on the basic attribute feature sequence based on non-extensive entropy to obtain a non-extensive entropy feature value; wherein the parameters of the non-extensive entropy are adaptively updated according to the change of the network flow; dynamically adjusting contribution values of the basic attribute features according to the new traffic data by using an incremental learning method, and reconstructing traffic features; and identifying network abnormal traffic based on the reconstructed traffic features. End-to-end network traffic characteristic parameter adaptive adjustment is realized by fusing improved non-extensive entropy-based characteristic extraction and an incremental learning method, and new attack behaviors and dynamic traffic changes can be coped with; and meanwhile, dynamic adjustment of the contribution degree of the basic attribute characteristics is realized by adopting new flow data, and dynamic reconstruction of the flow characteristics can be realized according to the basic attribute characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method, system, device, and medium for detecting network abnormal traffic. Background Art

[0002] With the continuous expansion of the scale of the Internet and data centers, the complexity and scale of network traffic have gradually increased. Traditional network traffic monitoring methods are facing more and more challenges, especially in large-scale network environments. To address these challenges, existing traffic anomaly detection methods often rely on data sampling to reduce the pressure of traffic data processing. However, traffic sampling inevitably leads to the loss of important information, resulting in the inability to fully and effectively express traffic characteristics. This information loss seriously affects the accuracy of network security monitoring. Especially in large-scale network environments such as backbone networks, existing traffic detection methods are inadequate.

[0003] Shannon entropy is one of the traditional network anomaly detection methods. It relies on the probability distribution of traffic data for anomaly detection, but this method has significant limitations when facing heavy-tailed distributions in traffic data. Shannon entropy assigns larger weights to frequently occurring features, while the handling of low-frequency or rare features is insufficient. In some non-Gaussian distributed traffic data, especially attack traffic with long-tailed distributions, the effect of Shannon entropy is poor because it cannot accurately capture these features.

[0004] In addition, with the diversification of network attack methods and the continuous change of attack patterns, traditional traffic monitoring technologies are slow to respond to new attacks and are difficult to effectively handle dynamically changing network traffic. Traditional static feature methods cannot adapt to the changes in network traffic in real time, resulting in many new attacks not being identified in a timely manner.

[0005] Therefore, how to achieve accurate and efficient abnormal traffic detection in a constantly changing traffic environment has become a major technical challenge in the field of network security. Most existing technologies cannot effectively solve the problems of information loss, challenges of heavy-tailed distributed traffic, and adaptation to the changing requirements of new attacks. Therefore, a new method is needed that can overcome the deficiencies of existing technologies and achieve more accurate and flexible traffic anomaly detection. Summary of the Invention

[0006] The present invention provides a method, system, device, and medium for detecting network abnormal traffic, which solves the problems of inaccurate identification of abnormal traffic, inability to process low-frequency or rare features, and inability to handle dynamically changing network traffic.

[0007] The present invention provides a method for detecting network abnormal traffic, including:

[0008] Collect the basic attribute features of network traffic data packets to form a basic attribute feature sequence;

[0009] Perform feature processing on the basic attribute feature sequence based on the non-extensive entropy to obtain the non-extensive entropy feature value; among them, the parameter of the non-extensive entropy is adaptively updated according to the change of network traffic;

[0010] Use the incremental learning method to dynamically adjust the contribution value of the basic attribute features according to the new traffic data and reconstruct the traffic features;

[0011] Identify network abnormal traffic based on the reconstructed traffic features.

[0012] Preferably, the basic attribute features of the collected network traffic data packets include:

[0013] Statistically analyze the attribute values in the data packets within the time window of the data stream from the backbone link entropy to construct the basic attribute features of the backbone link data stream.

[0014] Preferably, the statistical attribute values in the data packets include:

[0015] Segment the large-scale network data packets in the backbone link on demand according to a fixed time period, and extract the attribute fields related to network traffic from the data packets.

[0016] Preferably, the feature processing of the basic attribute feature sequence based on the non-extensive entropy includes:

[0017] Perform non-extensive entropy processing on m data packets X = {x 1 , x 2 ,..., x m} in a specific time period, specifically:

[0018]

[0019] Among them, S q (H) is the non-extensive entropy characterization value; p(h ij,t ) represents the occurrence probability that the jth basic attribute feature h i of the data packet x ij takes a certain value; q represents the non-extensive entropy parameter;

[0020]

[0021] Among them, represents the number when the jth basic attribute feature sequence takes a certain value.

[0022] Preferably, the parameter of the non-extensive entropy is adaptively updated according to the change of network traffic, including:

[0023] Randomly select an initial value of the non-extensive entropy parameter, calculate the non-extensive entropy characterization values of each basic attribute feature based on the initial value, reconstruct the traffic of each feature after non-extensive entropy processing, and identify abnormal traffic in the classification model to obtain the loss function. Then, optimize the parameters of the non-extensive entropy according to the gradient descent method and dynamically adjust the learning rate according to the error rate to achieve the adaptive update of the non-extensive entropy parameters.

[0024] Preferably, the step of optimizing the parameters of the non-extensive entropy according to the gradient descent method and dynamically adjusting the learning rate according to the error rate to achieve the adaptive update of the non-extensive entropy parameters includes:

[0025] In each iteration process, according to a randomly sampled data packet x i , calculate the gradient through the following formula to iterate q;

[0026]

[0027] where, represents the error function, and η represents the learning rate;

[0028] Adjust the learning rate of each parameter according to the past gradient, specifically:

[0029]

[0030] where, ε is a random function added for numerical stability; r k represents the gradient cumulative squared gradient, and the specific representation formula is:

[0031]

[0032] Preferably, the step of dynamically adjusting the contribution value of the basic attribute feature according to the new traffic data and reconstructing the traffic feature includes:

[0033] Use elastic weight consolidation to achieve the contribution value of the basic attribute feature, and adopt the loss function minimization objective to ensure the function accuracy, specifically including the following formula:

[0034]

[0035] where, L'(θ) represents the total loss of the new traffic data after the adjustment of the contribution value of the basic attribute feature; L(θ) represents the loss of the new traffic data after using the basic attribute feature value and the basic attribute feature contribution input into the abnormal traffic identification model; represents the loss of the input into the abnormal traffic identification model before and after the adjustment of the contribution value of the basic attribute feature; λ represents the importance degree of the contribution value of the basic attribute feature trained by the original traffic data; θ i represents the contribution of the basic attribute feature trained by the original traffic data; Contribution of basic attribute features trained with new traffic data.

[0036] Preferably, a network abnormal traffic detection system includes:

[0037] A feature acquisition module, configured to acquire basic attribute features of network traffic data packets to form a basic attribute feature sequence;

[0038] A feature processing module, configured to perform feature processing on the basic attribute feature sequence based on the non-extensive entropy to obtain non-extensive entropy feature values; wherein, the parameters of the non-extensive entropy are adaptively updated according to the changes in network traffic;

[0039] A feature reconstruction module, configured to use the incremental learning method to dynamically adjust the contribution value of the basic attribute features according to new traffic data and reconstruct the traffic features;

[0040] An abnormal identification module, configured to identify network abnormal traffic based on the reconstructed traffic features.

[0041] Preferably, a device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the network abnormal traffic detection method described above.

[0042] Preferably, a computer-readable storage medium includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the network abnormal traffic detection method described above.

[0043] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0044] The present invention discloses a network abnormal traffic detection method, system, device, and medium, which integrates feature extraction based on improved non-extensive entropy and incremental learning method to achieve end-to-end adaptive adjustment of network traffic feature parameters, and can cope with new attack behaviors and changes in dynamic traffic; at the same time, new traffic data is used to dynamically adjust the contribution degree of basic attribute features, and traffic features can be dynamically reconstructed according to basic attribute features. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 It is a schematic flowchart of a network abnormal traffic detection method provided by an embodiment of the present invention;

[0046] Figure 2 It is a schematic diagram of modules of a network abnormal traffic detection system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0047] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0048] As Figure 1 shown, the present application provides a method for detecting abnormal network traffic, including:

[0049] S1: Collect the basic attribute features of network traffic data packets to form a basic attribute feature sequence;

[0050] S2: Perform feature processing on the basic attribute feature sequence based on the non-extensive entropy to obtain the non-extensive entropy feature value; wherein, the parameter of the non-extensive entropy is adaptively updated according to the change of network traffic.

[0051] S3: Use the incremental learning method to dynamically adjust the contribution value of the basic attribute features according to the new traffic data and reconstruct the traffic features;

[0052] S4: Identify abnormal network traffic based on the reconstructed traffic features.

[0053] In the above solution, a method is proposed that, based on the basic attribute summary record of network traffic data packets, integrates the feature extraction based on the improved non-extensive entropy and the incremental learning method to find out the influence degree of changing the network traffic feature parameters on the interval distribution of different types of abnormal traffic features; on this basis, reconstructs the traffic features according to the influence degree of different types of abnormal traffic feature interval distributions, adaptively selects the change value of the network traffic feature parameters in combination with the loss function, so as to realize the end-to-end adaptive adjustment of network traffic feature parameters, which can well cope with new attack behaviors and the changes of dynamic traffic; at the same time, uses new traffic data to realize the dynamic adjustment of the contribution degree of basic attribute features and dynamically reconstructs traffic features according to basic attribute features.

[0054] Preferably, in step S1, the collection of the basic attribute features of network traffic data packets includes:

[0055] Statistically analyze the attribute values in the data packets within the time window of the data stream from the backbone link entropy to construct the basic attribute features of the backbone link data stream.

[0056] Preferably, the statistical analysis of the attribute values in the data packets includes:

[0057] Slice the large-scale network data packets in the backbone link according to the fixed time period on demand, and extract the attribute fields related to network traffic from the data packets.

[0058] In the above solution, assume a certain data packet x i Extract the j-th basic attribute feature H = {h ij , h ij ,..., h ij} of the data stream. Extract the features according to the time series to obtain the j-th basic attribute feature sequence as: H t = {h ij,1 , h ij,2 ,..., h ij,T}; Since the number of abnormal data packets on the backbone link is very small, it is difficult to detect multiple attack behaviors by extracting the attribute fields related to network traffic from the network traffic data of a certain time period; it is necessary to amplify some features with the help of non-extensive entropy, so that a small number of abnormal traffic features are highlighted in the high-dimensional space, thereby constructing the non-extensive entropy values between different features and combining multiple values into a one-dimensional vector, representing the overall feature of the network traffic in this time period. By constructing the overall feature, the influence of the attack behavior on the value distribution of the basic attribute values of the traffic data can be reflected in the entropy with finer granularity, so as to quickly identify abnormal traffic.

[0059] Preferably, in step S2, the feature processing of the basic attribute feature sequence based on non-extensive entropy includes:

[0060] Perform non-extensive entropy processing on m data packets X = {x 1 , x 2 ,..., x m} in a specific time period, specifically:

[0061]

[0062] where S q (H) is the non-extensive entropy characterization value; p(h ij,t ) represents the occurrence probability that the j-th basic attribute feature h i of the data packet x ij takes a certain value; q represents the non-extensive entropy parameter;

[0063]

[0064] where represents the number when the j-th basic attribute feature sequence takes a certain value.

[0065] In the above solution, q represents the non-extensive entropy parameter. When q > 1, the greater the probability of the occurrence of the basic attribute characteristics, the greater its influence on the non-extensive entropy parameter, which is equivalent to amplifying the basic attribute characteristics with high probability through the non-extensive entropy parameter; on the contrary, when q < 1, the smaller the probability of the occurrence of the basic attribute characteristics, the smaller its influence on the non-extensive entropy parameter, which is equivalent to amplifying the basic attribute characteristics with low probability.

[0066] Preferably, the parameter of the non-extensive entropy is adaptively updated according to the change of network traffic, including:

[0067] Randomly select an initial value of the non-extensive entropy parameter, calculate the non-extensive entropy characterization values of each basic attribute characteristic based on the initial value, reconstruct the traffic for each characteristic processed by the non-extensive entropy, and identify abnormal traffic in the classification model to obtain the loss function. Then, optimize the parameter of the non-extensive entropy according to the gradient descent method, and dynamically adjust the learning rate according to the error rate to achieve the adaptive update of the non-extensive entropy parameter.

[0068] Preferably, the parameter of the non-extensive entropy is optimized according to the gradient descent method, and the learning rate is dynamically adjusted according to the error rate to achieve the adaptive update of the non-extensive entropy parameter, including:

[0069] In each iteration process, according to a randomly sampled data packet x i , calculate the gradient through the following formula to iterate q;

[0070]

[0071] Among them, represents the error function, and η represents the learning rate;

[0072] Adjust the learning rate of each parameter according to the past gradient, specifically:

[0073]

[0074] Among them, ε is a random function added for numerical stability; r k represents the gradient cumulative square gradient, and the specific representation formula is:

[0075]

[0076] Preferably, in step S3, the contribution value of the basic attribute characteristic is dynamically adjusted according to the new traffic data, and the traffic characteristic is reconstructed, including:

[0077] Use elastic weight consolidation to realize the contribution value of the basic attribute characteristic, and adopt the loss function minimization objective to ensure the function accuracy, specifically including the following formula:

[0078]

[0079] Among them, L'(θ) represents the total loss of the new traffic data after the adjustment of the contribution value of the basic attribute features; L(θ) represents the loss of the new traffic data after inputting the basic attribute feature values and the basic attribute feature contributions into the abnormal traffic recognition model; represents the loss after inputting into the abnormal traffic recognition model before and after the adjustment of the contribution value of the basic attribute features; λ represents the importance degree of the contribution value of the basic attribute features trained by the original traffic data; θ i represents the contribution of the basic attribute features trained by using the original traffic data; the contribution of the basic attribute features trained by using the new traffic data.

[0080] In the above solution, for the original traffic data, non-extensive entropy features can be processed, and appropriate non-extensive entropy parameter q can be found through the loss function to characterize the influence of attack behavior on the value distribution of the basic attribute values of traffic data. However, based on this method, it is impossible to cope with the influence of the increasingly changing network traffic on feature selection. Therefore, this application adopts an incremental learning method to realize the selection based on attribute features.

[0081] The contribution value of the attribute features of the network traffic recognition model is obtained through large-scale offline data learning. Since the data distribution of the new traffic sequence may have a certain difference from the data distribution of the historical traffic sequence, the contribution value of the basic attribute features of the traffic data needs to be adjusted through incremental learning to realize the selection of basic attribute features.

[0082] Preferably, as Figure 2 shown, a network abnormal traffic detection system includes:

[0083] A feature acquisition module, configured to acquire the basic attribute features of network traffic data packets and form a basic attribute feature sequence;

[0084] A feature processing module, configured to perform feature processing on the basic attribute feature sequence based on non-extensive entropy to obtain non-extensive entropy feature values; wherein, the parameters of the non-extensive entropy are adaptively updated according to the change of network traffic;

[0085] A feature reconstruction module, configured to use the incremental learning method to dynamically adjust the contribution value of the basic attribute features according to the new traffic data and reconstruct the traffic features;

[0086] An abnormal recognition module, configured to recognize network abnormal traffic based on the reconstructed traffic features.

[0087] In the above solution, in the feature acquisition module, its purpose is to obtain the basic data that can characterize the network traffic status. Specifically, it extracts the preset basic attribute fields related to the network traffic characteristics from the data packets captured in the network link. These basic attribute fields may include, for example, but are not limited to: source IP address, destination IP address, source port number, destination port number, protocol type, data packet length, timestamp, etc. The attribute fields are extracted from the network traffic data packets within a continuous time window and arranged in a time series, thereby forming the time series of each basic attribute feature. For example, the source IP address sequence, the destination port number sequence, etc. These basic attribute feature sequences constitute the basic data for subsequent feature processing and analysis;

[0088] In the feature processing module, the limitations of the traditional Shannon entropy in processing heavy-tailed distribution traffic data are overcome. Compared with the Shannon entropy, the non-extensive entropy introduces an adjustable parameter q, which can control the sensitivity to different probability distribution characteristics by adjusting the q value; when q > 1, the non-extensive entropy is more sensitive to high-frequency features and plays a role in amplifying high-frequency features; when q < 1, it is more sensitive to low-frequency features and plays a role in amplifying low-frequency features. The key of this module is that the parameter of the non-extensive entropy is adaptively updated according to the change of network traffic, which means that the parameter q of the non-extensive entropy is not statically set, but can be dynamically adjusted according to the real-time monitored network traffic changes. This adaptive update mechanism enables the feature extraction process to better adapt to the dynamically changing network environment and optimize for different types of traffic distributions. For example, when the network traffic distribution changes significantly, such as a new type of attack causes the traffic distribution to deviate from the normal state, the adaptive update mechanism can adjust the q value, so that the non-extensive entropy can more effectively capture the new traffic features. By performing non-extensive entropy processing on the basic attribute feature sequence, the original feature sequence can be transformed into non-extensive entropy feature values that can better characterize the traffic distribution characteristics;

[0089] In the feature reconstruction module, an incremental learning mechanism is introduced to address the challenges brought about by the dynamic changes in network traffic and new attack patterns. The feature distribution of network traffic is not static. Over time and with the emergence of new attacks, the original traffic features may no longer be able to fully and effectively represent the current traffic state. Incremental learning methods allow the model to continuously learn and adapt to new data based on existing knowledge, thus maintaining the effectiveness and accuracy of the model. In this module, the core lies in dynamically adjusting the contribution values of the basic attribute features according to new traffic data. This means that the importance of different basic attribute features in abnormal traffic detection is not fixed. Through incremental learning, the model can evaluate the performance of each basic attribute feature in new traffic data and dynamically adjust its contribution value. Features with high contribution values will be given higher weights in subsequent abnormal traffic identification, while those with low contribution values will have their weights reduced. Reconstructing traffic features means reconstructing the traffic feature representation for abnormal traffic identification on the basis of dynamically adjusting the contribution values of basic attribute features. This reconstruction process can be understood as a weighted combination of the original basic attribute features, where the weights are determined by the contribution values dynamically adjusted by incremental learning. Through the reconstruction of traffic features, the feature representation finally used for abnormal traffic identification can better fit the current network traffic state, thereby improving the accuracy of detection;

[0090] In the abnormal identification module, the aim is to use the traffic features reconstructed in the previous steps to identify network abnormal traffic. Specific identification methods can employ various machine learning or deep learning classification algorithms, such as support vector machines, random forests, neural networks, etc. The input is the traffic features reconstructed in the feature reconstruction module, and the output is the judgment result on whether the network traffic is abnormal. Since the input features are processed by non-extensive entropy and dynamically adjusted and reconstructed by incremental learning, they can more effectively represent the features of network abnormal traffic, thus improving the accuracy and robustness of abnormal traffic identification.

[0091] Preferably, a device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the described automatic detection method for a repeater based on NCO.

[0092] Preferably, a computer-readable storage medium includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the described automatic detection method for a repeater based on NCO.

[0093] Preferably, the computer program may be divided into one or more modules / units (such as computer programs), and the one or more modules / units are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the terminal device.

[0094] The processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor. The processor is the control center of the terminal device and connects various parts of the terminal device through various interfaces and circuits.

[0095] The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc., and the data storage area can store relevant data, etc. In addition, the memory may be a high-speed random access memory, or may also be a non-volatile memory, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc., or the memory may also be other volatile solid-state storage devices.

[0096] It should be noted that the above terminal device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above terminal device is only an example and does not constitute a limitation on the terminal device. It may include more or fewer components, or combine certain components, or different components.

[0097] The above is the preferred embodiment of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A method for detecting abnormal network traffic, characterized in that: include: Collect basic attribute characteristics of network traffic data packets to form a basic attribute characteristic sequence; Based on the non-extensive entropy, the basic attribute feature sequence is processed to obtain the non-extensive entropy feature value; wherein the parameter of the non-extensive entropy is adaptively updated according to the change of network traffic; Using incremental learning methods, the contribution values ​​of basic attribute features are dynamically adjusted according to new traffic data, and traffic features are reconstructed; Based on the reconstructed traffic characteristics, abnormal network traffic is identified.

2. A method for detecting abnormal network traffic according to claim 1, characterized in that: The basic attribute characteristics of the collected network traffic data packets include: The attribute values ​​of the data packets in the time window of the data flow are counted based on the backbone link entropy to construct the basic attribute characteristics of the backbone link data flow.

3. A method for detecting abnormal network traffic according to claim 2, characterized in that: The attribute values ​​in the statistical data package include: The large-scale network data packets in the backbone link are segmented on demand according to fixed time periods, and attribute fields related to network traffic are extracted from the data packets.

4. A method for detecting abnormal network traffic according to claim 3, characterized in that: The feature processing of the basic attribute feature sequence based on the non-extensive entropy includes: For a specific time period, m packets X={x1,x2,...,x m }Perform non-extensive entropy processing, specifically: Among them, S q (H) is the non-extensive entropy representation value; p(h ij,t ) indicates data packet x i The jth basic attribute feature h ij The probability of a value occurring at a certain value; q represents the non-extensive entropy parameter; in, It indicates the number of times the jth basic attribute feature sequence takes a certain value.

5. A method for detecting abnormal network traffic according to claim 4, characterized in that: The parameters of the non-extensive entropy are adaptively updated according to changes in network traffic, including: An initial value of a non-extensive entropy parameter is randomly selected, and the non-extensive entropy representation values ​​of each basic attribute feature are calculated based on the initial value. The traffic is reconstructed for each feature after non-extensive entropy processing, and abnormal traffic is identified in the classification model to obtain the loss function. Then, the non-extensive entropy parameters are optimized according to the gradient descent method, and the learning rate is dynamically adjusted according to the error rate to achieve adaptive update of the non-extensive entropy parameters.

6. A method for detecting abnormal network traffic according to claim 5, characterized in that: The step of optimizing the parameters of the non-extensive entropy according to the gradient descent method and dynamically adjusting the learning rate according to the error rate to achieve the adaptive update of the non-extensive entropy parameters includes: In each iteration, a randomly sampled data packet x i , the gradient is calculated by the following formula To iterate q; in, represents the error function, η represents the learning rate; The learning rate of each parameter is adjusted according to the past gradient, specifically: Among them, ε is a random function added for numerical stability; r k Represents the gradient accumulation square gradient, and the specific formula is:

7. A method for detecting abnormal network traffic according to claim 6, characterized in that: The dynamically adjusting the contribution value of the basic attribute feature according to the new traffic data and reconstructing the traffic feature includes: Elastic weight consolidation is used to realize the contribution value of basic attribute features, and the loss function minimization objective is used to ensure the function accuracy, including the following formula: Among them, L'(θ) represents the total loss of the new traffic data after the basic attribute feature contribution value is adjusted; L(θ) represents the loss of the new traffic data after the basic attribute feature value and the basic attribute feature contribution are input into the abnormal traffic identification model; represents the loss of the basic attribute feature contribution value before and after adjustment after input into the abnormal traffic recognition model; λ represents the importance of the basic attribute feature contribution value of the original traffic data training; θ i Represents the basic attribute feature contribution trained using raw traffic data; Leverage the basic attribute feature contributions trained with new traffic data.

8. A network abnormal traffic detection system, characterized in that: include: A feature collection module is used to collect basic attribute features of network traffic data packets to form a basic attribute feature sequence; A feature processing module is used to perform feature processing on a basic attribute feature sequence based on non-extensive entropy to obtain a non-extensive entropy feature value; wherein the parameter of the non-extensive entropy is adaptively updated according to changes in network traffic; The feature reconstruction module is used to dynamically adjust the contribution value of basic attribute features according to new traffic data and reconstruct traffic features using an incremental learning method; The anomaly identification module is used to identify abnormal network traffic based on the reconstructed traffic characteristics.

9. A device, characterized in that: The invention comprises a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, a method for detecting abnormal network traffic as claimed in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a network abnormal traffic detection method as claimed in any one of claims 1 to 7.

Citation Information

Cited By

  • Abnormal node monitoring method and device, equipment and storage medium

    CN120455246A

  • Methods, devices, equipment, and storage media for monitoring abnormal nodes

    CN120455246B