Complex multi-step network attack detection method based on space-time fusion features
Through a deep learning model based on spatial and fusion features, using graph neural networks and time weighting technology, the problem of difficulty in detecting and distinguishing space-time overlapping multi-step network attacks in the existing technology is solved, and accurate detection and step identification of complex multi-step attacks are achieved.
Patent Information
- Application Number
- CN202510230079.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-28
AI Technical Summary
It is difficult for the prior art to effectively detect and distinguish complex multi-step cyber attacks with space-time overlap, especially when multiple attack chains overlap in the same time period and in the same IP environment, traditional methods are difficult to accurately identify and divide attack chain steps.
The deep learning model based on space-time fusion features is adopted, and the space-time characteristics of complex multi-step attacks are comprehensively analyzed through graph neural network, time weights and LSTM technology, and a multi-step attack chain division model and attack step identification model are built to achieve accurate detection of space-time overlapping multi-step attacks.
Effectively capture the complex relationship between and within the multi-step attack chain, improve the detection accuracy and accuracy of space-time overlapping multi-step attacks, and reduce the interference of timing confusing noise on attack chain division.
Smart Images

Figure CN120074929A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a method and system for detecting complex multi-step network attacks in a spatio-temporal overlap scenario. Background Art
[0002] With the rapid development of the Internet and the advancement of digital transformation, the network environment has become increasingly complex, involving multiple organizations, systems, and network levels. Attackers gradually penetrate the system through multi-stage attack strategies, reducing the risk of being discovered and blocked. Such attacks consisting of multiple stages are called multi-step attacks. Due to their high concealment and complexity, they have become one of the main ways of current network attacks. At the same time, attackers are increasingly inclined to launch multiple multi-step attacks simultaneously, and these attacks exhibit obvious spatio-temporal overlap characteristics in the same network environment. Specifically, through the spatio-temporal overlap strategy, attackers execute multiple attack chains in parallel within the same time period and the same IP segment, further increasing the difficulty of detection.
[0003] This kind of spatio-temporal overlapping multi-step attack brings three challenges: First, the difficulty of event description and modeling. Spatio-temporal overlapping multi-step attacks not only need to consider the context relationship and correlation between events, but also need to comprehensively analyze the time sequence, influence scope, and interaction of events. The meaning and impact of each attack event may depend on the occurrence of previous events. Second, the difficulty of distinguishing attack chains. When multiple attack chains overlap in the same time period and the same IP environment, distinguishing the independent steps of each attack chain becomes a challenge. For example, within the same IP and time window, if two different multi-step attack chains execute steps such as scanning, login attempts, and data theft, traditional IP address-based detection systems (such as community discovery algorithms) are difficult to accurately distinguish the steps of different attack chains because they cannot effectively utilize other information except IP addresses. Finally, the difficulty of detecting similar attack steps. During the step detection process of multi-step attacks, attackers may use the same technology or protocol in different stages. Although the purposes of these steps are different, this makes it difficult for existing detection methods to accurately identify. The existing technologies have the following limitations in dealing with this kind of complex multi-step attack: Traditional intrusion detection systems (such as Snort, Suricata) rely on predefined rule libraries to identify attack features, but cannot capture the association between multi-step attack stages. Temporal modeling methods, such as Hidden Markov Model (HMM) and Long Short-Term Memory (LSTM), although they can model the stage sequence, face the problem of temporal confusion. When the time windows of multiple attack chains overlap, LSTM cannot effectively distinguish the step sequence of different attack chains, resulting in misjudgment of stages. In addition, most existing solutions focus on the detection of a single attack chain and lack systematic support for spatio-temporal overlap scenarios. Summary of the Invention
[0004] Aiming at the deficiencies of the above-mentioned existing technologies, the present invention proposes a complex multi-step network attack detection method based on spatio-temporal fusion features, which constructs a deep learning model to effectively divide and accurately classify complex multi-step attacks containing multiple attack chains.
[0005] A complex multi-step network attack detection method based on spatio-temporal fusion features includes a model training stage and a multi-step attack detection stage. The specific process is as follows:
[0006] The model training stage in the steps includes the following steps:
[0007] Step 1): Using a set of marked multi-step attack network traffic data packets as input, preprocess the data packets, extract the header information and payload byte information of each data packet in each flow, so as to obtain a set of flow sequence sets composed of header information and payload byte information.
[0008] Step 2): Using the set of flow sequences of multiple multi-step attacks obtained in Step 1) as input, synthesize a set of spatio-temporally overlapping multi-step attack flow sequences.
[0009] Step 3): Using the set of flow sequences of multiple multi-step attacks in Step 1) and the set of spatio-temporally overlapping flow sequences synthesized in Step 2) as input, extract the payload information of each flow sequence to form a set of node information. According to the association between five-tuples, generate an edge set, and finally obtain multiple corresponding multi-step attack graph structures and a graph structure containing multiple multi-step attacks.
[0010] Step 4): Using a graph structure containing multiple multi-step attacks generated in Step 3) as input, train a model for dividing multi-step attack chains.
[0011] Step 5): Using the multiple corresponding multi-step attack graph structures generated in Step 3) as input, train a model for detecting specific multi-step attack stages.
[0012] The multi-step attack detection stage includes the following steps:
[0013] Step 6): Using a set of unmarked original network traffic data packets as input, process them through the Snort intrusion detection system to generate an alarm set. Match the alarm set with the data packets to obtain a set of attack network traffic data packets, and process the set of traffic data packets into a set of flows in the same way as in Step 1) of the model training stage, and further extract the flow sequence information to obtain an unmarked flow sequence information set composed of header information and payload byte information.
[0014] Step 7) Using the set of unlabeled flow sequence information obtained in step 6) as input, extract the payload information of each flow sequence as the set of node information, and generate an edge set based on the association between the five-tuples, so as to obtain a graph structure containing the set of node information and the edge set.
[0015] Step 8) Using the graph structure obtained in step 7) as input, input it into the model used for dividing multi-step attacks in step 4) of the training stage, calculate the multi-step attack type of each node, and generate a graph structure containing multi-step attack type labels.
[0016] Step 9) Using the graph structure containing multi-step attack type labels obtained in step 8) as input, perform subgraph extraction to obtain the subgraph structure information of each multi-step attack, and correspondingly use the model for detecting specific multi-step attack stages in step 5) to calculate the stage value of each node belonging to a specific multi-step attack and assign it different labels.
[0017] A deep learning multi-step attack detection system based on spatio-temporal feature fusion, including a model training stage for constructing a spatio-temporal feature extraction model and a detection stage for multi-step attack chain division and step recognition, where:
[0018] The model training stage includes three sequential modules: a data preprocessing module, a graph structure generation module, and two model training modules. First, receive the labeled multi-step attack traffic data, perform flow sequence normalization processing through the data preprocessing module, generate fixed-length flow sequences by using five-tuple matching and packet interception, and construct a composite attack scenario with spatio-temporal overlap features through the address replacement and time-axis interleaving strategies; then enter the graph structure generation module, and construct a benchmark graph structure of a single attack chain and a composite graph structure of a mixed attack chain based on node attributes (including protocol type, first packet timestamp, and payload characteristics) and edge generation algorithms respectively; finally, the graph structure of each multi-step attack and the graph structure of the composite attack are input into the two models respectively to obtain the models for attack step recognition and multi-step attack chain division respectively.
[0019] The detection stage of multi-step attack chain division and step recognition includes four sequential modules: a data preprocessing module, a graph structure generation module, a multi-step attack chain division module, and an attack step recognition module. First, it receives an unlabeled set of original network traffic data packets, triggers alerts through an intrusion detection system, performs flow matching operations based on the five-tuple features (source / destination IP, source / destination port, protocol) of the alert information, and standardizes the matched attack flow payload using a predefined interception length to generate a set of flow features containing the payload byte sequence and the payload length sequence. Subsequently, it enters the graph structure generation module, constructs a time adjacency matrix based on the first packet timestamp, with node attributes including protocol type, TTL value, and intercepted payload features, and at the same time uses a self-loop edge compensation mechanism to handle isolated nodes to form a graph structure containing spatio-temporal features. In the multi-step attack chain division module, using the graph structure containing spatio-temporal features as input, it adopts a time-weighting mechanism to strengthen the information aggregation of temporally adjacent nodes and outputs the multi-step attack type labels for each node in the graph. Finally, in the attack step recognition module, using the subgraph segmentation technology to extract the subgraph structure belonging to the same attack chain as input, it classifies the attack steps through an attack step recognition model and outputs a graph structure containing step labels as the detection result.
[0020] The key technical points of the present invention are as follows:
[0021] 1. The present invention proposes a new complex multi-step attack detection method. This method combines graph neural networks, time weights, and LSTM to comprehensively analyze the spatio-temporal features of complex multi-step attacks and effectively capture the complex associations between and within multi-step attack chains.
[0022] 2. Design a graph generation algorithm to construct a traffic graph structure through five-tuple fingerprints, fuse node attributes such as protocol type, timestamp, and payload features, and the designed edge generation algorithm can effectively represent the spatio-temporal association characteristics of multi-step attacks.
[0023] 3. Design an adjacency matrix update algorithm with time decay characteristics to dynamically adjust the information propagation intensity between nodes through a configurable decay factor, effectively suppressing the interference of temporal confusion noise on attack chain division.
[0024] 4. Design a three-layer composite network structure. The first layer GCN extracts spatial features such as protocol type and payload distribution through local neighborhood aggregation, the second layer GCN realizes the extraction of global interaction features of multi-hop neighbors, and the third layer LSTM unit models the temporal evolution law of attack steps, forming a progressive feature learning path of "space-global-time".
[0025] Using the method of the present invention can achieve accurate detection of spatio-temporally overlapping multi-step attacks. Compared with existing detection technologies, it has the following significant advantages:
[0026] 1. The invention designs a graph neural network based on time-weighted aggregation, introduces a time decay function, and dynamically adjusts the node aggregation weights, enabling the model to pay more attention to the associated traffic with similar time, and solves the problem of dividing the spatio-temporal overlapping multi-step attack chain.
[0027] 2. The invention designs a neural network based on multi-layer spatio-temporal feature extraction, and fuses the spatial features of the multi-layer graph convolutional neural network and the temporal features of the LSTM in the step recognition stage, and solves the recognition of similar attack stages in multi-step attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 is the model training flowchart of the complex multi-step network attack detection method based on spatio-temporal fusion features.
[0029] Figure 2 is the detection stage flowchart of multi-step attack chain division and step recognition.
[0030] Figure 3 is the experimental result graph of the multi-step attack chain division model under different decay rates.
[0031] FIG. 4(a) is the experimental result graph of the multi-step attack chain division model in the DARPA2000 (L1+L2) hybrid attack scenario.
[0032] FIG. 4(b) is the experimental result graph of the multi-step attack chain division model in the DARPA2000 (L1+L2)+ISCX2012 hybrid attack scenario.
[0033] FIG. 5(a) is the experimental result graph of the multi-step attack step recognition model on the DARPA2000 test set.
[0034] FIG. 5(b) is the experimental result graph of the multi-step attack step recognition model on the ISCX2012 test set.
[0035] FIG. 6(a) is the confusion matrix graph of the multi-step attack step recognition model on the DARPA2000 test set.
[0036] FIG. 6(b) is the confusion matrix graph of the multi-step attack step recognition model on the ISCX2012 test set. DETAILED DESCRIPTION OF THE INVENTION
[0037] The workflow of the present invention includes a model training stage and a detection stage for multi-step attack chain division and step recognition. In the model training stage, the labeled network traffic is used as input to train the learnable parameters in the neural network, thereby constructing a multi-step attack chain division model and an attack step recognition model. In the detection stage of multi-step attack chain division and step recognition, the unlabeled traffic in the real network environment is used as input, and an alarm is triggered by the intrusion detection system. Through the flow matching and graph generation module, a graph structure with multi-step attack flows as nodes is obtained. Then, the multi-step attack chain division model divides the multi-step attack chain in the graph structure and obtains the multi-step attack type label of each node. Finally, the sub-graph structure of a single multi-step attack is extracted and input into the attack step recognition model to obtain a graph structure containing multi-step attack step labels.
[0038] In the model training stage, the key technical part of the present invention lies in the construction of the multi-step attack division model and the multi-step attack step recognition model. The model construction process is as Figure 1 shown. The input of this stage is a set of labeled multi-step attack network traffic data packets, and the output is the multi-step attack division model and the multi-step attack step recognition model.
[0039] The multi-step attack division model and the multi-step attack step recognition model of the present invention are constructed based on the training method of the deep neural network model. The specific implementation steps are as follows:
[0040] The data preprocessing step takes a set of labeled multi-step attack network traffic data packets as input, preprocesses the data packets in the set, and extracts the header information and payload byte information of each data packet in each flow, thereby obtaining a set of header information and payload byte sequences. The specific implementation steps are as follows:
[0041] First, the set of labeled multi-step attack network traffic data packets is processed into a flow set. Taking the given labeled original network traffic data packets as input, they are assembled into a set according to the five-tuple identifier (y i ∈[1, N] is the multi-step attack type label of flow flow i , N is the total number of known multi-step attack categories, y‘ i ∈[1, N] is the multi-step attack step label of flow flow i , and M is the total number of flows). Among them, the five-tuple refers to the source IP address (ip.src), destination IP address (ip.dst), source port (port.src), destination port (port.dst), and communication protocol (protocol) of the data packet.
[0042] Then, the flow sequence information extraction operation is performed on the flow set D raw to obtain the multi-step attack traffic set Among them, H i flow i Header information, H' i To extract the header information, P i flow i For ease of understanding, in the following steps, we will use a single flow flow i Taking the example of FIG. 1 as an example, the flow sequence information extraction operation in the present invention is introduced, and the specific steps are as follows:
[0043] First, extract the header information and intercept the first L packets of each flow in the flow set. Then, extract the header information of L packets in turn. Since each flow is composed of an ordered sequence of packets, for any flow i We define its packet sequence as in Indicates flow i The jth packet, m represents the flow i Contains m data packets in total. To prevent overfitting in model training, the IP address and MAC address in the header are deleted, and the transport layer protocol type protocol (such as TCP = 6, UDP = 17) and other header information are retained to maintain the traffic behavior characteristics. i For example, intercept the flow i The first L packets of Delete the header information H' after the address i According to the header information in flow' i The order of appearance is obtained to obtain the header information sequence H' i ={H' i1 ,...,H' i2 ,...,H' iL}.
[0044] Then, the payload byte sequence information is extracted, and the first L packets of each flow in the flow set are intercepted. Subsequently, the payload byte information of the L packets is extracted in sequence. i For example, first, extract the payload byte information of each data packet Then, the payload byte information of each packet is sorted according to its appearance in flow' i The order in the sequence is arranged in order to obtain the payload byte sequence in Indicates flow i The payload byte information of the jth packet. Specifically, for flow i The jth data packet of this step intercepts the first P bytes of the packet payload, thereby obtaining the payload byte information where represents the e-th byte of the j-th data packet payload.
[0045] Using a set D of flow sequences of multiple multi-step attacks f as input, a set of multi-step attack flow sequences with spatio-temporal overlap is synthesized. Taking the preprocessed multi-step attack data traffic sets D 1 and D 2 as input, the synthesized spatio-temporal overlap attack data set D merged is output. The specific implementation steps are as follows:
[0046] First, perform time-axis interleaving. Define the time offset Δt and shift the timestamps of all attack steps in D 2 into the time window of D to generate new timestamps 1 where T and T start and T end are the start and end times of D 1 , and is the total duration of D 2 .
[0047] Then, perform IP address replacement. Define the address mapping rule and replace the source / destination IP of the attack in D 2 with an address within the subnet segment of D 1 : Finally, perform attack chain merging. Merge the traffic data of D 1 and D 2 in ascending order of timestamps to generate a mixed data traffic set: where represents the i-th original attack traffic flow from the data set D 1 , and represents the j-th adjusted attack traffic flow from the data set D 2 .
[0048] The input is the mixed data traffic set D merge or the preprocessed multi-step attack data traffic set D f , and the output is a graph structure for graph neural network training, including the generation of nodes and edges: the nodes represent the individual flows in the multi-step attack, and the edges depict the spatial connections between these flows. The specific implementation steps are as follows:
[0049] Node generation. Taking the preprocessed multi-step attack data traffic set as an example as input, the node set V = {v 1 , v 2 ,..., vM}, and the node feature matrix is taken as \(F\in\mathbb{R}\) M×d , for each flow \(s\) i corresponding to a unique node \(v\) i . First, extract the header information \(H\) i The five-tuple in it is the node identifier \(ID(v\) i ), then extract the features of each flow \(s\) i to construct the node attribute vector \(f\) i \(\in\mathbb{R}\) d : \(f\) i =[ \(t\) i , \(TTL\) i , \(OneHot(proto\) i ), \(x\) i , where the timestamp \(t\) i \(\in\mathbb{R}\) is the first packet time of the flow \(s\) i , the \(TTL\) value \(TTL\) i \(\in\mathbb{Z}\) is the maximum value of the packet survival period, the protocol type \(OneHot(proto\) i ) \(\in\{0,1\}\) k is a \(K\)-dimensional one-hot encoding, and the payload feature \(x\) i \(\in\mathbb{R}\) n*m is the header information \(H'\) after preprocessing to delete the address information i and the intercepted payload byte sequence \(P\) i .
[0050] Edge generation. Taking the preprocessed multi-step attack data traffic set as an example as the input, output the set of edges \(E\). The specific operations are as follows: Set the maximum number of edges per node \(max\_edges\), and the attack flow set \(D = \{f\) 1 , \(f\) 2 ,..., \(f\) M \}. First, the generation of candidate edges depends on the determination of five-tuple relevance. For any two flows \(f\) i , \(f\) j \(\in D\), if it satisfies one of the following spatial association conditions, it is marked as a candidate edge:
[0051]
[0052] Then, perform the edge number constraint for each node. For each node \(v\) i , maintain a priority queue \(Q\) i storing candidate edges in ascending order of time difference. Traverse all candidate edges \(e\) ij and \(e\) ji , and insert them into the queue \(Q\) i and \(Q\) j in turn. When the current size of the queue \(Q\) i \(|Q|\) i|≥max_edges, then perform the following operations: If Δt ij <Δt max_current , where Δt max_current is the maximum time difference in the current queue, then replace the edge with the largest time difference in the queue.
[0053] Finally, merge the queues Q of all nodes 1 Q 2 Q M , and generate the final edge set after removing duplicate edges:
[0054] Train the multi-step attack chain partitioning model. The key technologies in the training process lie in the construction of the time-weighted adjacency matrix and the design of the graph convolutional neural network. Input the edge set E, the node set V, the timestamp vector T ∈ R M , the attenuation factor λ, and output the multi-step attack chain partitioning model:
[0055] First, perform the initialization of the adjacency matrix and the calculation of the time decay weight. Define the total number of nodes M = |T|, and initialize the all-zero adjacency matrix: A = 0 M*M . For each edge e ij ∈E, calculate the time difference and fill the symmetric weight: Δt = |T i -T j |, A[i,j] = A[j,i] = w ij . Add self-loop edges to unconnected nodes, A[i,i] = 1.0, if and only if
[0056] Then design the graph convolutional neural network. The updated representation h' i of each node v i is composed of its own feature h i and the set of features of its neighbor nodes {h i |j ∈ N(i)} through time-weighted difference weighted combination. The node features are updated according to h' i = σ(W·h i + Σ i∈N(i) α ij ·W·h j ). Where σ is the ReLU non-linear activation function, W is the learnable weight matrix, and is the weight based on the time difference.
[0057] Where w = e (-decay_rate·|Δt|) is the time weight between nodes, w sum = ∑ k∈N(i) e (-decay_rate·|Δt|) is for the node v iThe cumulative weight of all connected nodes. And to avoid the error that the weight w becomes zero when there are no neighbors for isolated nodes, check the sum of the weights of each node. If the weight w of a certain node is zero, then set it to 1 through sum In sum , decay_rate is a hyperparameter that controls the magnitude of the impact of time difference on the weight, and |Δt| = |t sum - t | is the time difference between nodes.
[0058] In e (-decay_rate·|Δt|) i j - t j | is the time difference between nodes.
[0059] Train the multi-step attack step recognition model. The key technology in the training process lies in the design of a three-layer spatio-temporal feature deep learning model. Input the edge set E of a specific multi-step attack graph structure, and the node feature matrix X ∈ R M*d , and output the multi-step attack step recognition model:
[0060] First, use a two-layer graph convolutional neural network to update the spatial features of the multi-step attack. Use the ReLU function as the activation function after each layer of the graph convolutional neural network. The following are the update formulas for the first and second layers of the graph convolutional neural network:
[0061]
[0062] Among them, d i d j represents the distance between node i and node j, W is a trainable parameter, represents the representation of node v i in the first layer, represents the representation of node v i in the second layer.
[0063] Then, to obtain the time features, transform the output of the second layer of GCN through dimensionality transformation, and then input it into the LSTM layer, initializing the hidden state and cell state: h 0 = 0 2*h , c 0 = 0 2*h , 2 represents a double-layer LSTM. Then input H (2) sorted by timestamp into LSTM: H seq ,(h n , c n ) = LSTM(H (2) ,(h 0 , c 0 ))), where H seq ∈R M*h is the time series feature matrix, and h is the hidden layer dimension.
[0064] Finally, the spatio-temporal features and the gating weights are concatenated through a gating mechanism. The calculation method of the gating value G is as follows:
[0065] G = σ([H (2) ||H seq W g +b g )
[0066] where || represents concatenation by column, W g ∈R 2h*h is the gating parameter, and σ(·) is the Sigmoid activation function. According to the gating control, the fused features can be calculated as follows:
[0067] H fuse = G⊙H (2) +(1 - G)⊙H seq
[0068] where ⊙ represents element-wise multiplication. Then, through the fully connected classification layer, the attack step classification probability matrix P = Softmax(H fuse W c +b c ), and W c is the parameter of the classification layer.
[0069] The workflow of the detection stage for multi-step attack chain division and step recognition is as Figure 2 shown. In this stage, based on the multi-step attack chain division model and the multi-step attack step recognition model constructed in the model training stage, the unlabeled original traffic is subjected to multi-step attack chain division and step recognition, and the multi-step attack chain category and the multi-step attack step category to which the attack traffic belongs are output. The specific process of the detection stage for multi-step attack chain division and step recognition is as follows:
[0070] Step 1: Using the set of unlabeled original network traffic data packets as input, an intrusion detection system generates alerts. Through the same data preprocessing as in step 1 of the training stage by the flow matching mechanism, multi-step attack traffic containing header information and payload information is obtained.
[0071] Step 2: Input the multi-step attack traffic containing header information and payload information into the graph structure generation model to generate a graph structure containing node and edge sets, the same as step 3 of the training stage.
[0072] Step 3: Input the graph structure obtained in step 2 into the multi-step attack chain division model to classify all nodes in the graph, and obtain the label l ∈ [1, N] of all nodes, where N is the number of multi-step attack chain types.
[0073] Step 4: Extract the subgraph of a specific multi-step attack chain through the subgraph algorithm. From the graph structure G = (V, E) with labels obtained in step 3, the node feature matrix X ∈ RM*n , the classification label vector S ∈ {1, 2,..., K} M , the target multi-step attack chain type k. First, filter the nodes, and filter the set of nodes of the target attack type k according to the classification label: V k = {v i ∈ V | S[i] = k}. Then perform edge filtering, and only keep the edges whose both end nodes belong to V k : E k = {(v i , v j ) ∈ E | v i ∈ V k ∧ v j ∈ V k}.
[0074] Step 5, send the corresponding subgraph into the corresponding multi-step attack step recognition model, classify all the nodes in the subgraph, and obtain the labels l' ∈ [1, M] of all the nodes, where M is the number of step categories of this multi-step attack.
[0075] In the verification experiment, the present invention conducts instance verification on the network traffic of two different multi-step attacks in the DARPA2000 (LLDOS 1.0 + LLDSO2.0) dataset and the UNB ISCX2012. The specific network traffic information used in the experiment is shown in Table 1. Two multi-step attacks are used to verify the multi-step attack step recognition model, and two hybrid multi-step attacks are used to verify the multi-step attack chain division model. Stratified sampling is performed on the training set and the test set, and the ratio of the training set to the test set for each step of each multi-step attack type is 7:3.
[0076] Table 1: Application names and network traffic information of each category used in the experimental verification
[0077] Multi-step attack name Number of data packets Number of alerts Number of flows DARPA2000 LLDOS 1.0 6719 5590 4096 ISCX 2012 61456 1329 1050 LLDOS 1.0 + ISCX 2012 68583 6919 5146 LLDOS 1.0 + LLDSO2.0 + ISCX 2012 70685 8719 5202
[0078] To evaluate its classification performance, the following metrics are defined to evaluate the classification performance of the classifier:
[0079]
[0080] For the multi-step attack chain division model, True Positive (TP) means that the predicted attack type is the same as the actual attack type;
[0081] False Positive (FP) refers to the situation where the predicted attack type is different from the actual attack type, that is, misclassifying an attack sample as another type; False Negative (FN) refers to the situation where the actual attack type is inconsistent with the predicted attack type, that is, missing that attack type. For the multi-step attack step recognition model, TP refers to the situation where the predicted attack step is consistent with the actual attack step; FP refers to the situation where the predicted attack step is inconsistent with the actual attack step, that is, wrongly predicting the wrong step;
[0082] FN refers to the situation where the actual attack step does not match the predicted attack step, that is, missing that attack step.
[0083] Figure 3 The variation of the F1 values of the multi-step attack chain division model on the test set of the experimental dataset is plotted when the parameter time decay rate λ takes different values. For different parameter settings, the experiment adopted four different decay rates: 0.001, 0.002, 0.005, and 0.01. By comparison, the model converges faster during training and has better F1 values under different decay rates.
[0084] Figure 4(a) and Figure 4(b) respectively plot the performance of the multi-step attack chain division model in two multi-step attack mixed scenarios: DARPA2000 (L1+L2) and DARPA2000 (L1+L2)+ISCX2012, as well as the performance comparison of five methods for multi-step attack division. As shown in Figure 4(a), in the DARPA2000 (L1+L2) mixed scenario, the F1 score, recall rate, and precision rate of the multi-step attack chain division model are 0.971, 0.944, and 0.999 respectively. As shown in Figure 4(b), in the scenario of three multi-step attack mixtures of DARPA2000 (L1+L2)+ISCX2012, after adding one multi-step attack, the performance metrics of the multi-step attack chain division model are: 0.973, 0.958, and 0.987 respectively.
[0085] Figure 5(a) and Figure 5(b) respectively show the performance of each method of the multi-step attack step recognition model on DARPA2000L1 and ISCX2012 in terms of performance metrics. In DARPA2000L1, the F1 score, recall rate, and precision rate are 0.986, 0.973, and 0.997 respectively; in ISCX2012, the F1 score, recall rate, and precision rate are 0.992, 0.986, and 0.997 respectively. Finally, Figure 6(a) and Figure 6(b) respectively plot the confusion matrices of the multi-step attack step recognition model for each step classification of two multi-step attack types.
Claims
1. A complex multi-step network attack detection method based on spatiotemporal fusion features, characterized in that: It includes the model training phase and the multi-step attack detection phase. The specific process is as follows: The model training phase includes the following steps: Step 1) taking a set of marked multiple multi-step attack network traffic data packets as input, preprocessing the data packets, extracting header information and payload byte information of each data packet of each flow, thereby obtaining multiple flow sequence sets consisting of header information and payload byte information; Step 2) using the multiple multi-step attack flow sequence sets obtained in step 1) as input, synthesizing a multi-step attack flow sequence set with overlapping time and space; Step 3) takes the multiple multi-step attack flow sequence sets of step 1) and the spatiotemporal overlapping flow sequence sets synthesized in step 2) as input, extracts the load information of each flow sequence, and forms a node information set; generates an edge set according to the association between the quintuples, and finally obtains multiple corresponding multi-step attack graph structures and a graph structure containing multiple multi-step attacks; Step 4) using a graph structure containing multiple multi-step attacks generated in step 3) as input, training a model for dividing the multi-step attack chain; Step 5) using the multiple corresponding multi-step attack graph structures generated in step 3) as input, training a model for detecting a specific multi-step attack stage; The multi-step attack detection phase includes the following steps: Step 6) using the set of unlabeled original network traffic data packets as input, and processing them through the Snort intrusion detection system to generate an alarm set; performing data packet matching on the alarm set to obtain an attack network traffic data packet set, and processing the traffic data packet set into a flow set in the same manner as step 1) of the model training phase, further extracting flow sequence information, and obtaining an unlabeled flow sequence information set consisting of header information and payload byte information; Step 7) takes the unlabeled flow sequence information set obtained in step 6) as input, extracts the load information of each flow sequence as a node information set, generates an edge set according to the association between the quintuples, and thus obtains a graph structure including a node information set and an edge set; Step 8) takes the graph structure obtained in step 7) as input and inputs it into the model used to divide the multi-step attacks in step 4) of the training phase, calculates the multi-step attack type of each node, and generates a graph structure containing the multi-step attack type label; Step 9) uses the graph structure containing the multi-step attack type labels obtained in step 8) as input, performs subgraph extraction and obtains the subgraph structure information of each multi-step attack. Correspondingly, the model used in step 5) for detecting a specific multi-step attack stage is used to calculate the stage value of each node belonging to the specific multi-step attack and assign it a different label.
2. A deep learning multi-step attack detection system based on spatiotemporal feature fusion for implementing the method of claim 1, characterized in that: It includes a model training phase for building a spatiotemporal feature extraction model and a detection phase for multi-step attack chain division and step identification, where: The model training phase includes three sequential modules: data preprocessing module, graph structure generation module and two model training modules. First, the labeled multi-step attack traffic data is received, and the flow sequence standardization processing is performed through the data preprocessing module. The fixed-length flow sequence is generated by five-tuple matching and data packet interception, and a composite attack scenario with time-space overlapping characteristics is constructed through address replacement and time axis interleaving strategy. Then, the graph structure generation module is entered, and the baseline graph structure of the single attack chain and the composite graph structure of the mixed attack chain are constructed respectively based on the node attributes including protocol type, first packet timestamp and load characteristics with the edge generation algorithm. Finally, the graph structure of each multi-step attack and the graph structure of the composite attack are input into the two models respectively, and the models for attack step identification and multi-step attack chain division are obtained respectively. The detection phase of multi-step attack chain division and step identification includes four sequential modules: data preprocessing module, graph structure generation module, multi-step attack chain division module and attack step identification module. First, a set of unlabeled original network traffic data packets is received, and an alarm is triggered through the intrusion detection system. A flow matching operation is performed based on the five-tuple features of the alarm information. The five-tuple features include source / destination IP, source / destination port, and protocol. The matched attack flow load is standardized using a predefined interception length to generate a flow feature set containing a load byte sequence and a load length sequence. Then, the graph structure generation module is entered to match the attack flow based on the timestamp of the first packet. A temporal adjacency matrix is constructed, and the node attributes include protocol type, TTL value and intercepted load characteristics. At the same time, a self-loop edge compensation mechanism is used to process isolated nodes, forming a graph structure containing temporal and spatial characteristics. In the multi-step attack chain division module, the graph structure containing temporal and spatial characteristics is used as input, and a time weighting mechanism is used to strengthen the information aggregation of temporal neighboring nodes, and the multi-step attack type label of each node in the graph is output. Finally, in the attack step identification module, the subgraph segmentation technology is used to extract the subgraph structure belonging to the same attack chain as input, and the attack step classification is realized through the attack step identification model, and the graph structure containing the step label is output as the detection result.
3. The deep learning multi-step attack detection system based on spatiotemporal feature fusion according to claim 2 is characterized in that: Data preprocessing takes a set of marked multi-step attack network traffic data packets as input, preprocesses the data packets in the set, extracts the header information and payload byte information of each data packet of each flow, and thus obtains a set of header information and payload byte sequences; the specific implementation steps are as follows: First, the set of marked multiple multi-step attack network traffic packets is processed into a flow set; given the marked original network traffic packets as input, they are assembled into a set according to the five-tuple identifier. y i ∈[1,N] is the flow i The multi-step attack type label, N is the total number of known multi-step attack categories, y' i ∈[1,N] is the flow i The multi-step attack step label of M is the total number of flows; the quintuple refers to the source IP address, destination IP address, source port, destination port, and communication protocol of the data packet; Then, the convection set D raw Perform flow sequence information extraction to obtain a multi-step attack flow set Among them, H i flow i Header information, H' i To extract the back header information, P i flow i The payload byte sequence.
4. The deep learning multi-step attack detection system based on spatiotemporal feature fusion according to claim 3 is characterized in that: Single flow i The specific steps of midstream sequence information extraction operation are as follows: First, extract the header information and intercept the first L packets of each flow in the flow set; then, extract the header information of L packets in turn; since each flow is composed of an ordered sequence of packets, for any flow i Its packet sequence is defined as in Indicates flow i The jth packet, m represents the flow i Contains a total of m data packets; To prevent overfitting in model training, the IP address and MAC address in the header are deleted, and the transport layer protocol type protocol and other header information are retained to maintain the traffic behavior characteristics; flow i , intercept flow i The first L packets of Delete the header information H' after the address i According to the header information in flow' i The order of appearance is obtained to obtain the header information sequence H' i ={H' i1 ,...,H' i2 ,...,H' iL }; Then, the payload byte sequence information is extracted, and the first L packets of each flow in the flow set are intercepted; then, the payload byte information of the L packets is extracted in sequence; flow i First extract the payload byte information of each data packet Then, the payload byte information of each packet is sorted according to its appearance in flow' i The order in the sequence is arranged in order to obtain the payload byte sequence in Indicates flow i The payload byte information of the jth packet; specifically, for flow flow i The jth data packet of the packet is intercepted, and the first P bytes of the packet payload are obtained to obtain the payload byte information. in Represents the e-th byte of the j-th packet payload.
5. According to claim 4, the deep learning multi-step attack detection system based on spatiotemporal feature fusion is characterized in that: The set of flow sequences D with multiple multi-step attacks f As input, a set of multi-step attack flow sequences with spatiotemporal overlap is synthesized; after preprocessing the multi-step attack data flow sets D1 and D2, the synthesized spatiotemporal overlapping attack data set D is output. merged ; The specific implementation steps are as follows: First, the time axis is interleaved, and the time offset Δt is defined, and the timestamps of all attack steps in D2 are Shift to the time window of D1 and generate a new timestamp Where T start and T end are the start and end time of D1, is the total duration of D2; Then, replace the IP address and define the address mapping rules Replace the attack source / target IP in D2 with the address in the subnet segment of D1: Finally, the attack chain is merged, and the traffic data of D1 and D2 are merged in ascending order of timestamps to generate a mixed data traffic set: in represents the i-th original attack traffic flow from dataset D1, represents the jth adjusted attack traffic flow from dataset D2; The input is a mixed data traffic set D merge Or the multi-step attack data flow set D after data preprocessing f , outputs a graph structure that can be used for graph neural network training, including the generation of nodes and edges: nodes represent individual flows in a multi-step attack, while edges depict the spatial connections between these flows; The specific implementation steps are as follows: Node generation; using the pre-processed multi-step attack data flow set As input, the output node set V = {v1, v2, ..., v M } and the node feature matrix is F∈R M×d , each flow s i Corresponding to the only node v i ; First extract the header information H i The five-tuple in is the node identifier ID (v i ), and then extract each stream s i Construct node attribute vector f based on the features i ∈R d :f i =[t i ,TTL i ,OneHot(proto i ),x i ], where the timestamp is t i ∈R is the flow s i First packet time, TTL value TTL i ∈Z is the maximum value of the data packet life cycle, the protocol type OneHot (proto i )∈{0,1} k is a K-dimensional one-hot encoding, with load feature x i ∈R n*m It is the header information H' that is preprocessed to delete the address information i and the intercepted payload byte sequence P i ; Edge generation; The pre-processed multi-step attack data traffic set As input, the output edge set E; the specific operation is as follows: set the maximum number of edges per node max_edges, the attack flow set D = {f1,f2,...,f M }; First, the generation of candidate edges depends on the five-tuple association determination. For any two flows f i ,f j ∈D, if it satisfies one of the following spatial association conditions, it is marked as a candidate edge: Then, the edge number constraint of a single node is performed, and for each node v i , maintain a priority queue Q i Store candidate edges in ascending order of time difference; traverse all candidate edges e ij and e ij , insert into queue Q in sequence i and Q j , when the queue Q i Current size of |Q i |≥max_edges, then do the following: If Δt ij <Δt max_current , where Δt max_current is the maximum time difference in the current queue, then replace the edge with the largest time difference in the queue; Finally, all nodes' queues Q1, Q2, Q M , after removing duplicate edges, the final edge set is generated:
6. The deep learning multi-step attack detection system based on spatiotemporal feature fusion according to claim 5 is characterized in that: Train the multi-step attack chain partitioning model; the key technology in the training process lies in the construction of the time weight adjacency matrix and the design of the graph convolutional neural network, input edge set E, node set V, timestamp vector T∈R M , attenuation factor λ, output multi-step attack chain partition model: First, the adjacency matrix is initialized and the time-decayed weight is calculated; the total number of nodes is defined as M = |T|, and the all-zero adjacency matrix is initialized: A = 0 M*M ; For each edge e ij ∈E, calculate the time difference and fill in the symmetric weight: Δt=|T i -T j |,w ij = A[i,j]=A[j,i]=w ij ; Add a self-loop edge to an unconnected node, A[i,i] = 1.0, if and only if Then the graph convolutional neural network is designed, each node v i The updated representation h' i It is due to its own characteristics h i And the feature set of its neighbor nodes {h i |j∈N(i)} is weighted by time-weighted difference; node features are calculated according to h' i =σ(W·h i +∑ j∈N(i )α ij ·W·h j ) update; where σ is the ReLU nonlinear activation function, W is the learnable weight matrix, and is a weight based on time differences; where w = e (-decay_rate|Δt|) is the time weight of node and, w sum =Σ k∈N(i) e (-decay_rate|Δt|) For node v i The cumulative weight of all connected nodes; And to avoid isolated points without neighbors causing w sum To check the error of zero, check the sum of weights of each node; If a node's w sum If it is zero, then Set it to 1; In e (-decay_rate·|Δt|) In the above example, decay_rate is a hyperparameter that controls the influence of time difference on weight, |Δt| = |t i -t j | is the time difference between nodes; Train the multi-step attack step recognition model; the key technology in the training process lies in the design of a three-layer spatiotemporal feature deep learning model, input a specific multi-step attack graph structure edge set E, node feature matrix X∈R M*d , output multi-step attack step recognition model: First, a two-layer graph convolutional neural network is used to update the spatial features of the multi-step attack. The ReLU function is used as the activation function after each layer of the graph convolutional neural network. The following are the update formulas for the first and second layers of the graph convolutional neural network: Among them, d j 表 represents the distance between node i and node j, W is a trainable parameter, Represents node v i In the first layer, Represents node v i Representation in the second layer; Then, in order to obtain the temporal features, the output of the second layer of GCN is transformed by dimension and then input into the LSTM layer to initialize the hidden state and cell state: h0 = 0 2*h , c0=0 2*h , 2 represents a double-layer LSTM; then H (2) Sort by timestamp and input into LSTM: H seq ,(h n ,c n )=LSTM(H (2) ,(h0,c0)), where H seq ∈R M*h is the time series feature matrix, h is the hidden layer dimension; Finally, the spatiotemporal features and the calculation of the gating weights are spliced through the gating mechanism; the calculation method of the gating value G is as follows: G=σ([H (2) ||H seq ]W g +b g ) Among them, || means column-by-column concatenation, W g ∈R 2h*h is the gate parameter, σ(·) is the Sigmoid activation function; according to the gate control, the fused features can be calculated: H fuse =G⊙H (2) +(1-G)⊙H seq Where ⊙ represents element-by-element multiplication; then the attack step classification probability matrix P = Softmax (H fuse W c +b c ),W c is the classification layer parameter.
Citation Information
Patent Citations
Multi-step attack detection method for network security of power system
CN115459965A
Composite attack chain completion method and system based on multi-modal data model, and medium
CN115883218A
Concealed malicious traffic detection method fusing statistical features and graph structure features
CN116132095A
Internet of Things DDoS attack detection method and device based on space-time hybrid model
CN116886345A
Complex network attack detection method based on cross-host abnormal behavior recognition
WO2024216729A1
Cited By
Communication replay attack detection model training method and system based on deep learning
CN121098633A