Multi-stage interpretation and analysis method for network communication behavior abnormity

Through a multi-stage interpretation analysis method for abnormal network communication behavior, the problem of lack of interpretability and incomplete feature extraction in the prior art is solved, and higher detection accuracy and user trust are achieved.

CN120074916AInactive Publication Date: 2025-05-30HARBIN INST OF TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510217790.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art has problems such as lack of interpretability, difficulty in building abnormal data sets, incomplete feature extraction, and insufficient accuracy and comprehensiveness of interpretation methods in the detection of network communication behavior.

Method used

A multi-stage interpretation and analysis method for network communication behavior abnormalities is adopted, including building an abnormal data set based on four dimensions, feature extraction of network traffic features, multi-stage interpretability analysis (Ante-hoc and Post-hoc interpretation), and combining large models to interpret and optimize the feature contribution results.

Benefits of technology

Through multi-dimensional data set construction and comprehensive feature extraction, the accuracy and generalization capabilities of detection are improved; through multi-stage interpretability analysis and large-scale model optimization, the interpretability and transparency of detection results are improved, and the trust of users is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074916A_ABST
    Figure CN120074916A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-stage interpretation and analysis method for network communication behavior abnormity, relates to the technical field of data security, and aims to solve the technical problems of lack of interpretability, difficulty in abnormal data set construction, incomplete feature extraction and insufficient accuracy of an interpretation method in the prior art. The invention provides the following scheme: S1, constructing an abnormal data set based on four dimensions; s2, performing feature extraction on the abnormal data set to obtain network traffic features; s3, performing multi-stage interpretability analysis on the network flow characteristics to obtain a comprehensive characteristic contribution result; the multi-stage interpretability analysis comprises the following steps: Ante-hoc interpretation and Post-hoc interpretation; and S4, explaining and optimizing the integrated feature contribution result by combining a large model. The method is of great significance in improving the network security protection capability and reducing the network threat risk.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a multi-stage interpretation and analysis method for abnormal network communication behaviors Background Art

[0002] With the rapid development of the Internet and information technology, data transmission plays a crucial role in various network applications. However, with the surge in data transmission volume, network security issues have become increasingly prominent, especially the anomaly detection in data transmission behaviors has become an important link in ensuring network security. The purpose of anomaly detection is to identify abnormal behaviors that are significantly different from normal transmission behaviors to prevent potential network attacks, data leaks, or faults

[0003] The popularity of encrypted traffic has brought challenges to the anomaly detection of data transmission behaviors, prompting methods based on traffic characteristics to become the mainstream; deep learning technology has improved the accuracy of anomaly detection, but its "black box" nature limits the understanding and trust of the results; in the field of security, interpretability is crucial for understanding the detection basis, improving transparency, and optimizing the model. Existing methods such as SHAP, LIME, and IG have advantages but are difficult to comprehensively reflect feature contributions when used independently

[0004] In the prior art, most schemes for data transmission anomaly detection adopt a combination of a deep learning model and a single interpretability method. For example, some studies use a DNN model for encrypted traffic anomaly detection and use the SHAP method to interpret the detection results. These schemes have partially improved the transparency of the model and the user's understanding ability by introducing interpretability methods. However, these methods have the following main technical problems

[0005] Lack of interpretability: Most existing anomaly detection methods rely on black box deep learning models such as neural networks. Although these models perform well in detection accuracy, their decision-making processes and results lack transparency, making it difficult for users to understand the basis of the detection results and reducing their credibility and usability

[0006] Difficulty in constructing abnormal datasets: The diversity and complexity of network traffic make it particularly difficult to construct high-quality abnormal datasets. Existing methods usually rely on abnormal samples in a single dimension and cannot comprehensively cover various possible abnormal behaviors, resulting in insufficient generalization ability of the detection model and being vulnerable to unseen abnormal patterns

[0007] Incomplete feature extraction: Current methods often focus on single or a few features in feature extraction and fail to fully utilize multi-dimensional feature information. This limits the model's ability to capture complex abnormal behavior patterns and affects the accuracy and reliability of detection

[0008] Insufficient accuracy and comprehensiveness of the interpretation method: Existing interpretability methods, such as SHAP, LIME, and Integrated Gradients (IG), are often used independently and lack an effective integration mechanism. This results in the possibility that the interpretation results may be biased or inconsistent, unable to comprehensively reflect the contribution of each feature to the detection result, and affecting the accuracy and practicality of the interpretation. Summary of the Invention

[0009] To solve the technical problems existing in the prior art, such as lack of interpretability, difficulty in constructing abnormal data sets, incomplete feature extraction, and insufficient accuracy of the interpretation method, the present invention provides a multi-stage interpretation and analysis method for network communication behavior anomalies, including:

[0010] S1. Construct an abnormal data set based on four major dimensions;

[0011] S2. Extract features from the abnormal data set to obtain network traffic features;

[0012] S3. Perform multi-stage interpretability analysis on the network traffic features to obtain a comprehensive feature contribution result; the multi-stage interpretability analysis includes: Ante-hoc interpretation and Post-hoc interpretation;

[0013] S4. Combine a large model to interpret and optimize the comprehensive feature contribution result.

[0014] Further, in S1, the four major dimensions include: traffic volume anomaly, connection number anomaly, traffic frequency anomaly, and time period traffic distribution anomaly;

[0015] The traffic volume anomaly is to identify the situation where the amount of data transmitted in the same TCP flow increases significantly;

[0016] The connection number anomaly is to detect an abnormal number of TCP connections between the same source IP and destination IP within a short period of time;

[0017] The traffic frequency anomaly is to monitor the abnormal change in the number of TCP flows within a specific time period;

[0018] The time period traffic distribution anomaly is the deviation of the network traffic distribution from the normal mode in different time periods.

[0019] Further, in S2, the network traffic features include: raw data features, time features, time statistical features, and spatial statistical features.

[0020] Further, in S3, the Ante-hoc interpretation is used for the machine learning model, specifically: directly using the feature importance method to analyze the global contribution of features to the model decision-making.

[0021] Further, in S3, the Post-hoc explanation is used for deep learning, specifically: comprehensively applying the SHAP explanation method, the LIME explanation method, and the integrated gradient explanation method, and combining information entropy and Bayesian optimization through a multi-stage analysis mechanism to obtain the feature contribution results.

[0022] Further, the information entropy is used to calculate the initial weights of the SHAP explanation method, the LIME explanation method, and the integrated gradient explanation method. The information entropy is obtained through:

[0023]

[0024] where Pi is the normalized distribution of the contribution value of the explanation method R method to feature i.

[0025] Further, the Bayesian optimization is used to adjust the initial weights, and its objective function is:

[0026]

[0027] where α is the weight of the SHAP explanation method, β is the weight of the LIME explanation method, γ is the weight of the integrated gradient explanation method, is the comprehensive feature contribution, is the benchmark feature contribution provided by domain knowledge or labeled data.

[0028] Further, in S4, combining the large model to interpret and optimize the comprehensive feature contribution results specifically means: inputting the comprehensive feature contribution results into the large language model through prompt engineering, and the large language model further analyzes the feature contribution according to the context and generates an explanation report that can be understood by users.

[0029] The beneficial effects of the present invention are as follows:

[0030] 1. In terms of dataset construction: The present invention constructs a multi-dimensional anomaly dataset, solving the problem of insufficient representativeness of the dataset in the prior art. This ensures that the detection model can identify various complex abnormal behavior patterns, thus significantly improving the detection accuracy and generalization ability.

[0031] 2. In terms of feature extraction: The present invention adopts a comprehensive feature extraction mechanism, covering multiple aspects of data transmission behavior. This enhances the model's ability to identify complex abnormal patterns and makes up for the deficiency of incomplete feature extraction in existing methods.

[0032] 3. In terms of interpretability analysis: The present invention integrates multiple interpretability methods for multi-stage analysis. This not only improves the interpretability of the detection results, but also ensures the accuracy and comprehensiveness of the interpretation results through the comprehensive application of multiple methods, enhancing transparency and user trust.

[0033] 4. In terms of result accuracy evaluation and optimization: The present invention evaluates and optimizes the accuracy of the interpretation result, further ensuring the reliability of the interpretation process. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 is the overall flowchart of the multi-stage interpretation analysis method for abnormal network communication behaviors;

[0035] Figure 2 is the schematic diagram of the multi-stage interpretability analysis method. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] In order to make the technical solutions and advantages in the embodiments of the present invention clearer and more understandable, the exemplary embodiments of the present invention are further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than an exhaustive list of all embodiments. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0037] Embodiment 1: Refer to Figure 1 To illustrate this embodiment, the present invention provides a multi-stage interpretation analysis method for abnormal network communication behaviors, including:

[0038] S1. Construct an abnormal data set based on four major dimensions;

[0039] S2. Extract features from the abnormal data set to obtain network traffic features;

[0040] S3. Perform multi-stage interpretability analysis on the network traffic features to obtain the comprehensive feature contribution result; the multi-stage interpretability analysis includes: Ante-hoc interpretation and Post-hoc interpretation;

[0041] S4. Combine the large model to interpret and optimize the comprehensive feature contribution result.

[0042] In S1, the four major dimensions include: traffic volume anomaly, connection number anomaly, traffic frequency anomaly, and time period traffic distribution anomaly;

[0043] The traffic volume anomaly is to identify the situation where the amount of data transmitted in the same TCP flow significantly increases;

[0044] The connection number anomaly is to detect the abnormal number of TCP connections between the same source IP and destination IP within a short period of time;

[0045] The traffic frequency anomaly is to monitor the abnormal change in the number of TCP flows within a specific time period;

[0046] The abnormal distribution of traffic volume during the period refers to the deviation of the network traffic distribution in different time periods from the normal mode.

[0047] In S2, the network traffic characteristics include: raw data characteristics, time characteristics, time statistical characteristics, and spatial statistical characteristics.

[0048] Specifically, the extracted characteristics can be seen from Table 1.

[0049] Table 1 Descriptive Interpretability Features

[0050]

[0051]

[0052] In S3, the Ante-hoc explanation is used for machine learning models, specifically: directly using the feature importance method to analyze the global contribution of features to model decisions.

[0053] In S3, the Post-hoc explanation is used for deep learning, specifically: comprehensively applying the SHAP explanation method, the LIME explanation method, and the integrated gradient explanation method, and through a multi-stage analysis mechanism combining information entropy and Bayesian optimization, the feature contribution results are obtained.

[0054] Specifically, the SHAP explanation method is: based on the Shapley value principle, calculate the contribution of each feature to the model output, and provide global and local feature importance evaluations.

[0055] The LIME explanation method is: generate local perturbation data near the model decision point, and explain individual prediction results through linear regression analysis.

[0056] The integrated gradient (IG) explanation method is: calculate the integral of the gradient along the path from the baseline input to the current input, quantify the cumulative contribution of each feature, and provide a sensitivity analysis of the input feature changes.

[0057] The information entropy is used to calculate the initial weights of the SHAP explanation method, the LIME explanation method, and the integrated gradient explanation method. The information entropy is obtained through:

[0058]

[0059] obtained, where Pi is the normalized distribution of the contribution value of the explanation method R method to feature i.

[0060] Specifically, calculating the initial weights of each method according to the entropy value is specifically through:

[0061]

[0062] Wtotal = w SHAP + w LIME + w IG

[0063]

[0064] is achieved, where w method is the initial weight of the explanation method method, and W total is 1, and w SHAP is the initial weight of the SHAP method, and w LIME is the initial weight of the LIME method, and w IG is the initial weight of the IG method.

[0065] The Bayesian optimization is used to adjust the initial weight, and its objective function is:

[0066]

[0067] where α is the weight of the SHAP explanation method, β is the weight of the LIME explanation method, γ is the weight of the integrated gradient explanation method, is the comprehensive feature contribution, is the benchmark feature contribution provided by domain knowledge or labeled data.

[0068] Specifically, the Bayesian optimization process is as follows:

[0069] First, define the initial weights {α 0 , β 0 , γ 0};

[0070] Second, use the Gaussian process to fit the objective function in the weight space;

[0071] Then, find the optimal solution of the objective function in the weight space:

[0072]

[0073] where {α * , β * , γ *} are the optimized and adjusted weights.

[0074] Finally, the comprehensive explanation formula:

[0075]

[0076] where is the feature contribution of the SHAP explanation method, is the feature contribution of the LIME explanation method, is the feature contribution of the integrated gradient explanation method.

[0077] In S4, the specific process of interpreting and optimizing the combined feature contribution results with the large model is as follows: Input the combined feature contribution results into the large language model through prompt engineering. The large language model further analyzes the feature contributions based on the context and generates an explanation report that can be understood by users.

[0078] Specifically, the large language models are ChatGPT-4.0 and Qwen-plus. The following is an example prompt:

[0079] A cybersecurity analyst now needs to explain the following abnormal data. Analyze the reasons for the abnormal data based on the provided feature descriptions, anomaly classifications, SHAP values, LIME values, IG values, and comprehensive interpretation results.

[0080] Project background:

[0081] Network traffic anomaly detection is in progress. Anomaly detection is performed using a deep learning model, and interpretability methods are used to explain the detection results. The following are the feature fields of the project and their meanings: {Feature description}

[0082] Anomaly classification: {Anomaly classification definition}

[0083] The following are the features of a certain abnormal data, its SHAP value, LIME value, IG value, and comprehensive interpretation result:

[0084] SHAP value: {shap_values}

[0085] LIME value: {lime_values}

[0086] IG value: {ig_values}

[0087] Comprehensive interpretation result: {final_values}

[0088] Please analyze which features in the anomaly classification led to the anomaly of this data and provide a comprehensive interpretation from multiple perspectives and dimensions.

[0089] The powerful language understanding ability of the large model can help users transform the abstract feature contribution results into intuitive and easy-to-understand analysis conclusions, providing guidance for subsequent anomaly repair and optimization. The specific process is as Figure 2 shown.

[0090] Although the present invention has been described in terms of a limited number of embodiments, those skilled in the art, having the benefit of the foregoing description, will appreciate that other embodiments can be devised within the scope of the invention as thus described. Additionally, it should be noted that the language used in this specification has been principally selected for readability and instructional purposes and not to limit or circumscribe the inventive subject matter. Accordingly, many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the appended claims. For the scope of the present invention, the disclosure herein is illustrative and not restrictive, and the scope of the invention is defined by the appended claims.

Claims

1. A multi-stage interpretation and analysis method for abnormal network communication behavior, characterized by: The method comprises: S1. Construct anomaly dataset based on four dimensions; S2. Extract features from the abnormal data set to obtain network traffic features; S3. Perform a multi-stage interpretability analysis on the network traffic features to obtain a comprehensive feature contribution result; the multi-stage interpretability analysis includes: Ante-hoc interpretation and Post-hoc interpretation; S4. Explain and optimize the integrated feature contribution results in combination with the large model.

2. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 1 is characterized in that: In S1, the four dimensions include: abnormal communication volume, abnormal number of connections, abnormal traffic frequency, and abnormal traffic distribution during a period; The traffic anomaly is to identify a significant increase in the amount of data transmitted in the same TCP stream; The abnormal number of connections is to detect an abnormal number of TCP connections between the same source IP and target IP in a short period of time; The traffic frequency anomaly is to monitor the abnormal changes in the number of TCP flows within a specific time period; The time period traffic distribution anomaly is the deviation of network traffic distribution in different time periods from the normal mode.

3. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 2 is characterized in that: In S2, the network traffic characteristics include: original data characteristics, time characteristics, time statistical characteristics and space statistical characteristics.

4. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 3 is characterized in that: In S3, the Ante-hoc explanation is used for machine learning models, specifically: directly using the feature importance method to analyze the global contribution of features to model decisions.

5. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 4 is characterized in that: In S3, the Post-hoc explanation is used for deep learning, specifically: comprehensively applying the SHAP explanation method, the LIME explanation method and the integral gradient explanation method, and obtaining the feature contribution results through a multi-stage analysis mechanism combined with information entropy and Bayesian optimization.

6. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 5 is characterized in that: The information entropy is used to calculate the initial weights of the SHAP interpretation method, the LIME interpretation method, and the integrated gradient interpretation method. The information entropy is obtained by: Obtained, where Pi is the interpretation method R method Normalized distribution of contributions to feature i.

7. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 6 is characterized in that: The Bayesian optimization is used to adjust the initial weights, and its objective function is: Among them, α is the weight of the SHAP explanation method, β is the weight of the LIME explanation method, and γ is the weight of the integrated gradient explanation method. is the comprehensive feature contribution, It is the baseline feature contribution provided by domain knowledge or labeled data.

8. The multi-stage interpretation and analysis method for abnormal network communication behavior according to claim 7 is characterized in that: In S4, the integrated feature contribution result is interpreted and optimized in combination with the large model. Specifically, the integrated feature contribution result is input into the large language model through the prompt project. The large language model further analyzes the feature contribution according to the context analysis and generates an explanation report that the user can understand.

Citation Information

Patent Citations

  • Network intrusion analysis method based on interpretable artificial intelligence technology

    CN117997624A

  • Multi-interpretation fusion algorithm for intrusion detection feature analysis

    CN118885966A

  • Abnormal network traffic analysis method and system based on deep learning

    CN118984250A

  • Explainable neural network for anomaly detection

    US20240378423A1