Replay attack detection method and device, equipment and storage medium
By using pre-trained classification models to perform feature extraction and dimensionality reduction processing on messages in an edge computing environment, identifying and defending against replay attacks, the problem of poor effectiveness of traditional methods in the face of complex attack methods is solved, and the security and stability of the system are improved.
Patent Information
- Application Number
- CN202510312372.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-05-30
AI Technical Summary
In the edge computing environment, message replay attacks have become an important issue in the field of network security. Traditional methods seem to be incompetent when facing complex attack methods.
By using a pre-trained classification model, the target message data is characterized and dimensionally reduced, and the normal message and replay attack message are distinguished, and the defense strategy is determined based on the classification results.
It realizes accurate identification and defense of replay attack messages, improves the security and stability of the edge computing environment, and can dynamically respond to different types of attacks.
Smart Images

Figure CN120074943A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of edge computing technology, and in particular, to a replay attack detection method, apparatus, device, and storage medium. Background Art
[0002] With the rapid development of Internet of Things technology, edge computing has been widely promoted in various industry application scenarios, making the data interaction between edge computing devices and the cloud increasingly frequent. However, along with the rapid development of edge computing technology, data security issues have gradually become an important challenge.
[0003] In the edge computing environment, the replay attack of messages has become an important issue in the field of network security. A replay attack refers to an attacker intercepting and repeatedly sending legitimate messages that have been transmitted, thereby causing system failures or unauthorized operations in the network. In the face of this security threat, traditional methods are becoming increasingly ineffective when dealing with complex attack means. Summary of the Invention
[0004] In view of this, the purpose of this application is to propose a replay attack detection method, apparatus, device, and storage medium.
[0005] As an aspect of this application, a replay attack detection method is provided, including:
[0006] Determine the target message data;
[0007] Input the target message data into a pre-trained classification model to obtain a classification result; wherein, the pre-trained classification model is trained based on training data; the training data is obtained by successively performing feature extraction and dimensionality reduction processing on pre-acquired historical message data;
[0008] In response to the classification result being a replay attack message, determine a defense strategy.
[0009] Optionally, the method further includes obtaining the training data by the following method:
[0010] Calculate the covariance matrix of the historical message data;
[0011] Perform eigen-decomposition on the covariance matrix to obtain the eigenvalues and eigenvectors of the covariance matrix; wherein, the eigenvectors include the timestamps, packet byte counts, sequence numbers, and hash values of the historical message data;
[0012] Arrange the eigenvalues in descending order, determine the eigenvectors whose eigenvalues are greater than a first preset threshold, and obtain a dimensionality reduction matrix;
[0013] Obtain the training data according to the historical message data and the dimensionality reduction matrix.
[0014] Optionally, determining a defense strategy in response to the classification result being a replay attack message includes:
[0015] Determine the attack type and attack frequency of the replay attack message;
[0016] In response to the attack type or attack frequency of the replay attack message reaching a preset condition, determine the defense strategy.
[0017] Optionally, the defense strategy includes at least one of the following: adjusting the valid range of the time stamp, adjusting the valid range of the sequence number, and adjusting the encryption degree of the data packet.
[0018] Optionally, determining the defense strategy in response to the attack type or attack frequency of the replay attack message reaching a preset condition includes:
[0019] In response to the attack frequency being greater than a second preset threshold, narrow the valid range of the time stamp and / or enhance the encryption degree of the data packet;
[0020] In response to the attack type being sequence number repetition or sequence number wrap-around, adjust the valid range of the sequence number.
[0021] Optionally, after determining the defense strategy, it further includes:
[0022] Obtain the real-time error value of the defense strategy; the real-time error value satisfies the following expression:
[0023] e t = θ desired - θ t
[0024] where θ desired is the desired defense strategy; θ t is the current defense strategy; e t is the real-time error value;
[0025] According to the real-time error value and the adaptive control algorithm, obtain the optimized defense strategy; where the optimized defense strategy satisfies the following expression:
[0026]
[0027] where θ t+1 is the optimized defense strategy; K p is the proportionality coefficient; K i is the integral coefficient; K d is the differential coefficient; Δt is the time step.
[0028] Optionally, determine the actual classification result of the target message data;
[0029] Determine a prediction error according to the actual classification result and the classification result;
[0030] Update the classification model based on the prediction error and an incremental learning algorithm.
[0031] As a second aspect of the present application, there is provided a replay attack detection device, including: a determination module and a processing module.
[0032] The determination module is configured to determine target message data;
[0033] The processing module is configured to input the target message data into a pre-trained classification model to obtain a classification result; wherein, the pre-trained classification model is trained based on training data; the training data is obtained by sequentially performing feature extraction and dimensionality reduction processing on pre-acquired historical message data;
[0034] The determination module is further configured to determine a defense strategy in response to the classification result being a replay attack message.
[0035] Optionally, the replay attack detection device further includes a calculation module.
[0036] The calculation module is configured to calculate a covariance matrix of the historical message data;
[0037] The processing module is further configured to perform eigen-decomposition on the covariance matrix to obtain eigenvalues and eigenvectors of the covariance matrix; wherein, the eigenvectors include timestamps, data packet byte counts, sequence numbers, and hash values of the historical message data;
[0038] The determination module is further configured to arrange the eigenvalues in descending order, determine the eigenvectors whose eigenvalues are greater than a first preset threshold, and obtain a dimensionality reduction matrix;
[0039] The processing module is further configured to obtain the training data according to the historical message data and the dimensionality reduction matrix.
[0040] Optionally, the determination module is specifically configured to determine the attack type and attack frequency of the replay attack message;
[0041] In response to the attack type or attack frequency of the replay attack message reaching a preset condition, determine the defense strategy.
[0042] Optionally, the defense strategy includes at least one of the following: adjusting the effective range of the timestamp, adjusting the effective range of the sequence number, and adjusting the encryption degree of the data packet.
[0043] Optionally, the determining module is further specifically configured to, in response to the attack frequency being greater than a second preset threshold, narrow the valid range of the time stamp and / or enhance the encryption degree of the data packet;
[0044] In response to the attack type being the sequence number repetition or the sequence number wrap-around, adjust the valid range of the sequence number.
[0045] Optionally, after determining the defense strategy, the replay attack detection device further includes an acquisition module.
[0046] The acquisition module is configured to acquire a real-time error value of the defense strategy; the real-time error value satisfies the following expression:
[0047] e t = θ desired - θ t
[0048] where θ desired is the desired defense strategy; θ t is the current defense strategy; e t is the real-time error value;
[0049] The processing module is further configured to obtain the optimized defense strategy according to the real-time error value and an adaptive control algorithm; wherein, the optimized defense strategy satisfies the following expression:
[0050]
[0051] where θ t+1 is the optimized defense strategy; K p is the proportionality coefficient; K i is the integral coefficient; K d is the differential coefficient; Δt is the time step.
[0052] Optionally, the replay attack detection device further includes an update module.
[0053] The determining module is further configured to determine an actual classification result of the target message data;
[0054] The determining module is further configured to determine a prediction error according to the actual classification result and the classification result;
[0055] The update module is configured to update the classification model based on the prediction error and an incremental learning algorithm.
[0056] As a third aspect of the present application, an electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the above-mentioned replay attack detection method is implemented.
[0057] As a fourth aspect of the present application, a non-transitory computer-readable storage medium is provided. The non-transitory computer-readable storage medium stores computer instructions for causing the computer to execute the above-mentioned replay attack detection method provided by the present application.
[0058] As can be seen from the above, the replay attack detection method, device, equipment, and storage medium provided by the present application can accurately classify target message data by using a pre-trained classification model, effectively distinguishing normal messages and replay attack messages. The pre-trained classification model has learned the characteristics and patterns of historical message data through a large amount of training data, so it can quickly and accurately judge the message type. Among them, the training data is derived from historical message data and has undergone feature extraction and dimensionality reduction processing. Feature extraction helps to identify key information in historical message data, while dimensionality reduction processing reduces data redundancy and improves the running speed and accuracy of the classification model. This data preprocessing method makes the classification model more efficient and easy to manage. Further, after the classification model detects a replay attack message, corresponding defense strategies are determined and executed in a timely manner to prevent attackers from obtaining illegal access rights or disrupting the normal operation of the system through replay attacks, which helps to improve the security and stability of the edge computing environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0060] Figure 1 It is a schematic flowchart of a replay attack detection method provided by an embodiment of the present application;
[0061] Figure 2 It is a schematic flowchart of another replay attack detection method provided by an embodiment of the present application;
[0062] Figure 3 It is a schematic flowchart of yet another replay attack detection method provided by an embodiment of the present application;
[0063] Figure 4 It is a schematic diagram of the acoustic signal sampling of a substation equipment provided by an embodiment of the present application;
[0064] Figure 5 It is a schematic flowchart of yet another replay attack detection method provided by an embodiment of the present application;
[0065] Figure 6 It is a schematic diagram of the composition of a replay attack detection device provided by an embodiment of the present application;
[0066] Figure 7 It is a schematic diagram of the composition of an electronic device provided by an embodiment of the present application. Specific embodiments
[0067] To make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the following further elaborates on the present application in detail with reference to specific embodiments and the accompanying drawings. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the scope of protection of the present application.
[0068] It should be noted that in the embodiments of the present application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplarily" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner. Unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the ordinary meaning understood by those of ordinary skill in the art to which the present application pertains. Summary of the Invention
[0070] In the related art, in the field of network security, replay attack is a common threat. An attacker deceives the system by intercepting and resending legitimate packets, thereby undermining the security and integrity of the system. Traditional defense methods mainly rely on simple rules such as timestamps and sequence numbers to determine the timeliness and validity of packets. However, these methods have obvious limitations when facing complex attack means and cannot effectively identify and prevent replay attacks.
[0071] The inventors of the present application have found that existing defense methods generally suffer from the problems of lack of adaptability and flexibility. Once most traditional methods are configured, it is difficult to update them in real time according to changes in the network environment or attack behaviors. In a dynamically changing network environment, static defense rules are easily exploited by attackers, and attackers can conduct targeted attacks against the regularity of these rules, resulting in the failure of system protection. The defects of these traditional methods are particularly obvious when facing continuously changing attack methods and cannot respond in a timely manner to new attack patterns.
[0072] To solve the above problems, the present application provides a replay attack detection method. By using a pre-trained classification model, it can accurately classify target packet data and effectively distinguish normal packets from replay attack packets. The pre-trained classification model has learned the characteristics and patterns of historical packet data through a large amount of training data, so it can quickly and accurately determine the packet type. Among them, the training data is derived from historical packet data and has undergone feature extraction and dimensionality reduction processing. Feature extraction helps to identify key information in historical packet data, while dimensionality reduction processing reduces data redundancy and improves the running speed and accuracy of the classification model. This data preprocessing method makes the classification model more efficient and easy to manage. Further, after the classification model detects a replay attack packet, it promptly determines and executes corresponding defense strategies to prevent attackers from obtaining illegal access rights or disrupting the normal operation of the system through replay attacks, which helps to improve the security and stability of the edge computing environment.
[0073] After introducing the basic principle of the present application, the following specifically introduces various non-limiting implementation manners of the present application.
[0074] Figure 1 It is a schematic flowchart of a replay attack detection method provided by an embodiment of the present application. As Figure 1 shown, the replay attack detection method provided by the present application specifically includes the following steps:
[0075] S101. Determine the target packet data.
[0076] In some embodiments, the communication packet data between the edge computing device and the server is collected in real time through a network traffic monitoring system, and the communication packet data is used as the target packet data. Among them, the target packet data includes a timestamp, the number of bytes of the data packet, a sequence number, and a hash value of the data packet content, etc. The timestamp can provide a timeliness basis for subsequent replay attack detection, the number of bytes of the data packet can reflect the validity and integrity of the packet, the sequence number is used to track the order of the packets, and the hash value is used to verify the consistency of the data content to prevent the data from being tampered with during transmission.
[0077] S102. Input the target packet data into the pre-trained classification model to obtain a classification result.
[0078] Among them, the pre-trained classification model is trained based on the training data; the training data is obtained by sequentially performing feature extraction and dimensionality reduction processing on the pre-acquired historical packet data.
[0079] In some embodiments, the training data includes normal communication messages sent by edge computing devices and messages containing replay attacks. The classification model can adopt a Support Vector Machine (SVM) model. SVM is a classification model based on statistical learning theory that can obtain an optimal classification hyperplane by maximizing the margin between classes. That is, the support vector machine model learns the features of the training data, gradually adjusts the parameters, and obtains a trained classification model so that normal messages and attack messages can be effectively separated in the feature space.
[0080] Specifically, the SVM algorithm finds an optimal hyperplane to ensure the maximum margin between positive samples and negative samples (i.e., normal messages and replay attack messages). This makes the model have strong robustness when facing new and unknown data. The goal of SVM is to optimize the following objective function:
[0081]
[0082] When solving the above objective function, certain constraint conditions need to be satisfied, that is, to ensure that all sample points (x i , y i ) satisfy the classification condition:
[0083]
[0084] where: w and b are the parameters of the hyperplane; x i is the input feature vector; y i is the class label corresponding to the sample; and y i ∈ {-1, +1}, representing normal messages and replay attack messages respectively.
[0085] To enhance the classification ability and adaptability of the classification model, different kernel functions can be used during training. Selecting a suitable kernel function can improve the performance of the model. In this embodiment, the linear kernel function and the non-linear kernel function (such as the RBF kernel) are the main choices. By selecting a suitable kernel function, SVM can map the feature space to a higher dimension to achieve effective classification of non-linearly separable data. In addition, the loss function of the classification model needs to be minimized, and the complexity of the model also needs to be considered. In some cases, to prevent overfitting, SVM introduces a regularization term to balance the relationship between the fitting error and the model complexity. The optimization objective is:
[0086]
[0087] where: C is the regularization parameter, which controls the penalty degree for misclassified points; ξ iis a slack variable that allows some sample points to be near the classification boundary without affecting the overall performance of the model. By adjusting the parameter C, the model can find a balance between accuracy and complexity.
[0088] In some embodiments, to ensure the efficiency and accuracy of the model, the training process can incorporate cross - validation techniques. Through cross - validation, the training data is divided into multiple subsets, including a validation set and a training set. The model is trained and validated on different subsets, thus effectively avoiding overfitting and ensuring that the model has good generalization ability when facing practical applications.
[0089] In some embodiments, the training set is the dataset used to train the SVM model, and the SVM model will learn the rules and patterns from this data; the validation set is the dataset used to evaluate the performance of the SVM model during the training process. The validation set does not participate in the training but is used to adjust the parameters of the SVM model and select the best model. The training data is randomly divided proportionally, for example, 70% for training and 30% for validation.
[0090] Exemplarily, first initialize the SVM model and select a suitable kernel function (such as a linear kernel, a polynomial kernel, or a radial basis function kernel). Then, use the training set to train the SVM model. During the training process, the model will learn the relationship between the features of the samples and the corresponding labels, thus finding an optimal decision boundary. Further, adjust the hyperparameters of the SVM model, such as the penalty parameter, kernel function parameter, etc., according to the performance of the validation set to optimize the performance of the model.
[0091] In some embodiments, after the SVM model is trained on the training set, use the validation set to evaluate the model. The evaluation metrics can include accuracy, recall rate, F1 - score, etc. When the performance of the model on the validation set meets the expectations, the trained SVM model can be saved as the final classification model. The classification model can determine in real - time whether the newly received packet data is a replay attack. This process indicates that the system can perform accurate attack detection based on the previously trained model and provide a reliable basis for subsequent incremental learning and dynamic adjustment of defense strategies.
[0092] It should be noted that the training process of SVM also involves kernel tricks, which help the algorithm solve non - linear problems that could not be handled originally. By selecting an appropriate kernel function, the model can be adaptively adjusted according to specific data distribution types. This method enables SVM to maintain high accuracy when dealing with complex data sets. In addition, in order to improve the training efficiency and accuracy of the SVM model, methods for accelerating calculations can be adopted. For example, using the linear kernel function of the support vector machine for relatively simple classification tasks, or using parallel processing in a multi - core computing environment to accelerate the training process of the model and further shorten the training time.
[0093] In some embodiments, in order to reduce the occupancy of hardware resources by the classification model, lightweight models such as a simplified version of the support vector machine or a decision - tree - based classifier can be adopted. These models have lower computational complexity, but can also achieve good results in some simple attack detection tasks. By selecting an appropriate model, it is possible to reduce the consumption of computing resources while ensuring detection accuracy, and adapt to the resource - limited environment on edge computing devices.
[0094] In some embodiments, after receiving the target packet data, it is input into the classification model, and based on the output result of the model, it is determined whether the packet is a normal communication packet or a replay attack packet.
[0095] Specifically, when performing real - time replay attack detection, first, the features of the target packet data are pre - processed. After feature extraction and dimensionality reduction, the target packet data will be converted into a format suitable for model input. Then, the model classifies the input packets according to pre - set rules. Next, the input data x t =(t i , s i , σ i , H i ) is input into the SVM model, and the model will calculate a prediction result This result represents the classifier's judgment on the current packet: if then it means the packet is a normal packet; if then it means the packet is determined to be a replay attack packet. Based on the classification result, it is decided whether to trigger defense measures.
[0096] It should be noted that replay attack detection is not limited to using the SVM model for classification. For some complex scenarios, multiple algorithms can be combined. For example, other machine learning methods such as decision trees, random forests, or neural networks can be combined, and the output results of multiple models can be integrated to further improve the accuracy and robustness of attack recognition. At the same time, in order to improve the detection accuracy and response speed, parallel computing technology can be adopted in this embodiment. Multiple SVM models can process packets from different data sources in parallel, which can speed up the data processing speed and ensure that the system can still operate efficiently under high load. During the processing, the model can automatically adjust the processing strategy according to the characteristics of the packet data to adapt to the changing attack patterns in the network.
[0097] In some embodiments, the data collection module extracts the packet features by analyzing the historical packet data transmitted by the edge computing device. Among them, these packet features can be obtained by directly reading the packet header information or by calculating relevant parameters. Exemplarily, in response to the edge computing device supporting hardware acceleration or a dedicated protocol stack, information such as timestamps, packet byte counts, sequence numbers, and hash values can be obtained in real time through the hardware module, further reducing the computational overhead and improving the efficiency.
[0098] It should be noted that the timestamp t i represents the transmission time of each packet in the historical packet data, the packet byte count s i reflects the number of bytes of the packet, the sequence number σ i is used to identify the position of the packet in the sequence, and the hash value H i is obtained by calculating the packet content through a common hash algorithm (such as SHA-256). The features of each packet will be represented in the form of a vector as:
[0099] x i =(t i ,s i ,σ i ,H i )
[0100] where: i is the packet number; t i is the timestamp of the packet; s i is the packet byte count of the packet; σ i is the sequence number of the packet; H i is the hash value of the packet content. In this way, the features of the packet can be stored in a structured manner and provide reliable data support for subsequent steps.
[0101] In some embodiments, to reduce the computational complexity and extract the most representative features, the Principal Component Analysis (PCA) algorithm is used to reduce the dimensionality of the data. The PCA method calculates the eigenvalues and eigenvectors of the covariance matrix, selects the principal components that can best represent the data variability from them, and maps the data to a low-dimensional space.
[0102] It should be noted that to further improve the robustness of the system, different dimensionality reduction methods can be adopted according to the actual distribution of the data in the feature extraction process. For example, other dimensionality reduction methods such as t-Distributed Stochastic Neighbor Embedding (t-SNE) or Linear Discriminant Analysis (LDA) can be used, and the parameters can also be adjusted according to specific application scenarios.
[0103] In some embodiments, after obtaining the historical message data, in order to extract useful features from it and provide high-quality and low-dimensional input data for subsequent model training, this embodiment further performs feature extraction and dimensionality reduction processing on the historical message data. As Figure 2 shown, the process of obtaining the training data can be implemented as follows S1021 - S1024:
[0104] S1021. Calculate the covariance matrix of the historical message data.
[0105] In some embodiments, the historical message data is represented as X = {x 1 , x 2 ,..., x n}, where each message is used as a sample, and a sample x i = (t i , s i , σ i , H i ) is a high-dimensional vector. First, calculate the covariance matrix C of the sample data set, and this matrix reflects the correlation between the sample features. The calculation formula of the covariance matrix C is:
[0106]
[0107] Where: is the mean vector of the data set X; n is the number of samples; x i is the i-th sample.
[0108] S1022. Perform eigen decomposition on the covariance matrix to obtain the eigenvalues and eigenvectors of the covariance matrix.
[0109] In some embodiments, the eigenvector corresponds to the most important direction in the dataset, and the eigenvalue represents the importance degree of each direction. The eigenvalues and eigenvectors of the covariance matrix C are obtained through eigenvalue decomposition:
[0110] C = VΛV T
[0111] where V is the matrix composed of eigenvectors, Λ is a diagonal matrix, the elements on the diagonal are eigenvalues, and the off-diagonal elements are 0.
[0112] In some embodiments, according to different requirements or processing scenarios, the eigenvector can flexibly include different elements in the historical message data. These elements include timestamp, packet byte count, sequence number, and hash value. Specifically, the eigenvector can include only one or more of these elements, or can include all of these elements.
[0113] S1023. Arrange the eigenvalues in descending order, determine the eigenvectors whose eigenvalues are greater than the first preset threshold, and obtain the dimensionality reduction matrix.
[0114] In some embodiments, when the eigenvalues are arranged in descending order, the larger the eigenvalue, the greater the data variance and the more information in the corresponding eigenvector direction. By selecting the eigenvectors whose eigenvalues are greater than the first preset threshold, the directions corresponding to these eigenvectors are the main change directions of the data, called the principal components. Combine the selected eigenvectors into a matrix to obtain the dimensionality reduction matrix. Exemplarily, by selecting the eigenvector with the largest eigenvalue, the most representative direction in the data is screened out, and these eigenvectors constitute a new feature space.
[0115] S1024. Obtain the training data according to the historical message data and the dimensionality reduction matrix.
[0116] In some embodiments, multiply the historical message data by the dimensionality reduction matrix to obtain the dimensionality-reduced data. This process projects the historical message data onto the selected principal component directions, thereby reducing the dimension of the data. The dimensionality-reduced data is the training data X reduced , which retains the main information of the historical message data, reduces the data complexity at the same time, and is convenient for subsequent machine learning model training and analysis. This processing not only lays a foundation for the detection of replay attacks, but also improves the computational efficiency of the system by reducing the feature dimension, providing a reliable basis for further adjustment of defense strategies.
[0117] It should be understood that in order to further improve the real-time performance and efficiency of the system, the data acquisition module can accelerate the data extraction and dimensionality reduction process through hardware acceleration or a dedicated protocol stack. For example, using a Field-Programmable Gate Array (FPGA for short) for data processing can significantly improve the speed of data acquisition and feature extraction and reduce system latency.
[0118] S103. In response to the classification result indicating a replay attack message, determine a defense strategy.
[0119] Among them, a replay attack is a type of network attack where an attacker intercepts legitimate communication data (such as authentication information, transaction requests, etc.) and then resends (replays) it to deceive the recipient, thereby obtaining unauthorized access or operation permissions.
[0120] In some embodiments, in response to the classification result indicating a replay attack message, automatically activate the defense mechanism and immediately intercept the message. The specific forms of defense measures can include discarding the message, recording logs, or blocking the IP address of the attack source, etc. In addition, in actual operations, the defense strategy can also include dynamically adjusting the timestamp range or sequence number valid range, as well as encrypting data packets, etc., to further enhance the defense ability and perform adaptive optimization in subsequent steps.
[0121] It should be understood that the process of real-time attack detection can also be optimized based on the feedback of historical data. For example, when a certain type of replay attack occurs frequently, the weights of the classification model can be adjusted according to historical records, so that the classification model pays more attention to these attack patterns and improves the efficiency of subsequent detections.
[0122] In some embodiments, as Figure 3 shown, S103 can be specifically implemented as S1031 - S1032 as follows:
[0123] S1031. Determine the attack type and attack frequency of the replay attack message.
[0124] In some embodiments, the attack type refers to the specific form of the replay attack. For example, attacks against authentication, attacks on transaction systems, attempts to access sensitive resources, execution of unauthorized operations, etc. The identification methods include checking whether the sequence number and timestamp in the replay attack message are outside the valid window or reused, and whether protocol-specific features are replayed, etc. The attack frequency refers to the frequency of attacks, such as the number of attack messages per unit time. The higher the attack frequency, the more active the attacker and the greater the threat, to help evaluate the intensity and urgency of the attack.
[0125] S1032. Determine a defense strategy in response to the attack type or attack frequency of the replay attack message reaching a preset condition.
[0126] In some embodiments, the preset condition is used to determine when to activate the defense mechanism. For example, if the attack frequency exceeds a certain threshold, or the attack type belongs to a high-risk category, the defense strategy is triggered. The defense strategy includes adjusting the valid range of timestamps, adjusting the valid range of sequence numbers, adjusting the encryption level of data packets, etc., to further enhance the defense ability.
[0127] In some embodiments, when adjusting the defense strategy, the system first judges the attack type and attack frequency of the replay attack message based on the output result of real-time attack detection. If the system detects a replay attack and the attack has a high frequency or intensity, the system will make a more stringent adjustment to the defense strategy to prevent the success of the attack. At this time, the system will narrow the valid range of timestamps or redefine the valid range of sequence numbers to ensure that only new, non-replayed data packets can pass the verification.
[0128] Exemplarily, in response to the attack frequency being greater than the second preset threshold, first limit the received message time by adjusting the timestamp range [t min , t max . At the same time, dynamically modify this range according to the network environment and security requirements. When the timestamp difference is too large, it indicates that the message comes from an expired session, and it will be regarded as a replay attack and rejected. For example, if the number of repeated messages received per second exceeds 100 times (the threshold can be dynamically adjusted), or the proportion of messages with the same hash value within 1 minute exceeds 30% of the total traffic, the time window will be adjusted from 5 minutes to 1 minute, and only messages with timestamps within the most recent 60 seconds will be accepted.
[0129] Exemplarily, in terms of adjusting the sequence number range, when continuous sequence number repetition or wrapping is detected, automatically adjust the valid range of sequence numbers [σ min , σ max , which helps to prevent replay attacks from entering the system again through repeated sequence numbers, thereby improving the protection ability of the edge computing environment. For example, the original valid range of sequence numbers is from 1 to 1000, and now it is adjusted to 1001 to 2000 to ensure that only new, non-replayed messages can pass the verification.
[0130] In addition, the adjustment of the defense strategy can also be combined with some additional security measures. For example, when the attack intensity is high or multiple attack sources are detected, more stringent defense measures are triggered, such as enhancing the encryption level of data packets, introducing additional authentication steps, etc. These measures can not only strengthen the defense effect but also provide multiple protection mechanisms for the system and improve its anti-attack ability.
[0131] Exemplarily, when it is detected that an attacker bypasses authentication by replaying a plaintext message (such as replaying an HTTP plaintext cookie), the encryption level of the data packet is automatically upgraded. For example, it is upgraded from basic symmetric encryption to a more secure asymmetric encryption or hybrid encryption method, or from the original 128-bit encryption to 256-bit encryption, so as to increase the difficulty for the attacker to crack the content of the data packet.
[0132] It should be noted that in order to make the adjustment of the defense strategy more flexible, the system can introduce an adaptive adjustment mechanism based on real-time attack feedback. Specifically, the system can adjust the defense intensity by setting a dynamic adjustment threshold. When the system detects that the attack intensity exceeds the set threshold, the defense strategy will immediately make a large-scale adjustment to effectively reduce the risk brought by the attack. For example, when the system detects that the frequency of replay attacks reaches a certain value, the effective range of the timestamp will be further reduced to ensure the timeliness and uniqueness of the message. The adjustment of the defense strategy can also be intelligently optimized based on historical data and attack patterns. By analyzing historical attack data, the system can learn which attack patterns are highly destructive and adjust the defense strategy in advance accordingly. This learning-based defense strategy adjustment method can continuously improve the adaptive ability of the system to cope with complex attack behaviors. In the design of the system, the adjustment of the defense strategy should not be limited to a single defense parameter, but can adjust multiple defense dimensions simultaneously, such as adjusting the timestamp range, sequence number range, data packet encryption limit, etc. The combination of these parameters can provide the system with more comprehensive defense capabilities. Through this comprehensive defense strategy, the system can take the most appropriate protection measures when facing various attacks.
[0133] The replay attack detection method provided by this application can accurately classify the target message data by using a pre-trained classification model, effectively distinguishing normal messages and replay attack messages. The pre-trained classification model has learned the characteristics and patterns of historical message data through a large amount of training data, so it can quickly and accurately judge the message type. Among them, the training data is derived from historical message data and has undergone feature extraction and dimensionality reduction processing. Feature extraction helps to identify the key information in historical message data, and dimensionality reduction processing reduces data redundancy, improving the running speed and accuracy of the classification model. This data preprocessing method makes the classification model more efficient and easy to manage. Further, after the classification model detects a replay attack message, it promptly determines and executes the corresponding defense strategy to prevent the attacker from obtaining illegal access rights or disrupting the normal operation of the system through replay attacks, which helps to improve the security and stability of the edge computing environment.
[0134] In some embodiments, the method further introduces an adaptive control mechanism to optimize the defense strategy by using the Proportional-Integral-Derivative (PID) control algorithm. This process automatically adjusts the defense parameters based on real-time feedback and historical performance data to ensure that the replay attack prevention system can dynamically respond to changing attack threats. The adaptive control strategy can continuously adjust the defense strategy according to environmental changes, enhancing the intelligence and automation level of the system. As Figure 4 shown, after S103, the replay attack detection method provided by the embodiments of the present application further includes the following S201-S202:
[0135] S201. Obtain the real-time error value of the defense strategy.
[0136] In some embodiments, the adaptive control adjusts the relevant parameters of the defense strategy by calculating the real-time error value. The goal of the adaptive control is to make reasonable adjustments according to the real-time error to make the adjustment of the defense strategy more accurate. The calculation of the real-time error value is based on the gap between the real-time detection result and the expected defense target.
[0137] Exemplarily, the real-time error value e t satisfies the following expression:
[0138] e t = θ desired - θ t
[0139] where θ desired is the expected defense strategy parameter; θ t is the current defense strategy parameter; e t is the calculated error value. At this time, the error value e t reflects the deviation between the current defense strategy and the expected value.
[0140] S202. Obtain the optimized defense strategy according to the real-time error value and the adaptive control algorithm.
[0141] In some embodiments, the adaptive control optimizes the defense strategy based on the real-time error value through the PID algorithm. The PID algorithm adjusts the control parameters by responding to the proportional, integral, and derivative of the error to make the defense strategy converge to the expected state as soon as possible. The PID control formula is:
[0142]
[0143] where: θ t is the adjustment parameter of the defense strategy; e t is the real-time error; K p ,Ki , K d are the proportional, integral, and derivative coefficients respectively; Δt is the time step. By adjusting these control parameters, the system can dynamically adjust the defense strategy and gradually reduce the error.
[0144] It should be noted that the PID control algorithm is not only applied to the adjustment of a single defense strategy, but can also optimize multiple defense dimensions simultaneously. For example, the system can simultaneously adjust multiple defense parameters such as the valid range of timestamps, the valid range of sequence numbers, and the message size limit. This multi-dimensional control can provide more fine-grained protection in complex attack scenarios, ensuring that the system can still maintain an efficient defense ability when facing different types of replay attacks. To further improve the effect of the PID control algorithm, the control parameters K p , K i , K d can be automatically adjusted according to real-time feedback. This way of dynamically adjusting control parameters can ensure that the system always maintains the best defense state, avoiding overcompensation or overly conservative defense strategies.
[0145] When the system does not detect a replay attack for a period of time, the PID control algorithm can be set to automatically reduce the adjustment intensity and reduce the intervention degree of the system on the defense strategy. This adaptive adjustment strategy can reduce the burden on the system and maintain stable operation in the absence of attacks, thereby improving the utilization efficiency of computing resources.
[0146] At the same time, the introduction of the PID control algorithm greatly improves the defense ability of the system. Through real-time calculation and adjustment, the system can dynamically optimize the defense strategy for different types of attacks and provide more robust protection in a continuous attack environment. Through multi-level adaptive control, the system can not only respond quickly at the initial stage of the attack, but also flexibly adjust the defense strategy when the attack intensity changes, avoiding performance loss caused by over-defense.
[0147] In some embodiments, to ensure that the system can cope with continuously changing attack types, the classification model is dynamically adjusted and updated to enable it to continuously adapt to new attack patterns while ensuring the accuracy and robustness of the classification model. As Figure 5 shown, the replay attack detection method provided by the embodiments of the present application further includes the following S301 - S303:
[0148] S301. Determine the actual classification result of the target message data.
[0149] In some embodiments, a predefined rule or knowledge base is used to determine the actual classification result of the target message data, or the category is determined by analyzing the header information (such as protocol type, IP address, port number, etc.) or payload content of the target message data.
[0150] S302. Determine the prediction error according to the actual classification result and the classification result.
[0151] In some embodiments, whenever the target packet data x t arrives, first, its features are extracted, such as the same timestamp, packet byte count, sequence number, and hash value as in step S102. Then, the extracted features are input into the classification model to obtain the classification result This result represents the classification result of the model for the target packet data. Further, calculate the prediction error of the target packet data:
[0152]
[0153] where y t is the actual classification result, is the label (classification result) predicted by the model.
[0154] S303. Update the classification model based on the prediction error and the incremental learning algorithm.
[0155] In some embodiments, the key to incremental learning is how to update the parameters of the existing model according to new data without destroying the results of the trained model. Incremental learning continuously enhances the adaptability of the model by updating the training data in real-time. When the system receives the target packet data again, the newly received data will be added to the training set and used to update the existing classification model. Different from traditional batch learning, incremental learning can avoid large-scale retraining from scratch every time, but can quickly update the model by incrementally adjusting the model parameters.
[0156] In some embodiments, in response to the prediction error being greater than the first preset threshold, it indicates that the classification model needs to be updated. At this time, based on the error feedback, an incremental learning algorithm, such as the Stochastic Gradient Descent (SGD) algorithm, is used to update the parameters of the model. The incremental learning algorithm uses the previous training data and the current new data to adjust the weights of the model by minimizing the loss function.
[0157] Specifically, SGD is an optimization algorithm that reduces the model error by continuously updating the parameters. Whenever new data x t is received, the SGD algorithm calculates the gradient based on this data and updates the parameters θ t of the model along the gradient direction. The update rule of the SGD algorithm is:
[0158]
[0159] where θ t$\theta$ is the current model parameter, and $\eta$ is the learning rate. $\nabla_{\theta}L(\theta$ t ) is the gradient of the loss function $L(\theta$ t ) with respect to the parameter $\theta$, and $L(\theta$ t ) is the loss function. Usually, the loss function adopted is the classification error function, such as the cross-entropy loss. The learning rate $\eta$ gradually decays as the training progresses, so as to ensure that the model can quickly adapt to new data in the initial stage and converge stably in the later stage. This decay process uses the following formula:
[0160]
[0161] where $\eta$ 0 is the initial learning rate, $\lambda$ is the decay factor, and $t$ is the current number of training steps. In this way, the learning rate gradually decreases over time, enabling the model to make more refined adjustments after convergence.
[0162] It should be understood that the advantage of incremental learning is that it can achieve rapid model updates with less computational overhead without having to retrain all the data each time. This is especially important for devices with limited computing resources in edge computing environments. Incremental learning ensures that the model can be updated in a timely manner when continuously receiving new data and maintains a high classification accuracy. Incremental learning is not limited to using the SGD algorithm. According to different application scenarios, other algorithms (such as the Adam optimization algorithm) can also be applied to the incremental learning process. In addition, as an option, in order to prevent the model from overly relying on the latest data, a certain "memory" mechanism can be introduced during the incremental learning process. That is, the system not only updates the model according to the latest packet data but also periodically reuses a part of the historical data for retraining to enhance the long-term stability and overfitting resistance of the model. This method helps to solve the excessive influence of new data on the model and maintain the generalization ability of the model.
[0163] In some embodiments, the replay attack detection method provided by the embodiments of the present application further includes the following beneficial effects:
[0164] 1. Using a support vector machine model as the basis of the classification model, through the incremental learning technology of real-time update, it can effectively distinguish normal packets and replay attack packets. It achieves the technical effects of improving the accuracy and real-time performance of replay attack detection. Compared with the traditional method that relies on a static model in the prior art, the present application realizes the adaptive update of the classification model through the incremental learning module, solves the problem that the traditional method cannot respond to new attacks in a timely manner, and improves the defense ability of the system.
[0165] 2. Principal component analysis is introduced as a feature extraction means, and dimensionality reduction technology is used to optimize the representation of message features. By reducing redundant features, the technical effects of improving calculation efficiency and processing speed are achieved. Compared with the traditional feature extraction methods used in the prior art, the present invention can extract key features more efficiently and solves the problem of excessive consumption of computing resources when processing large-scale message data.
[0166] 3. The defense strategy parameters are dynamically adjusted through an adaptive control algorithm, and the defense strategy is optimized according to the real-time error, which can automatically adjust the defense intensity according to different attack situations. Compared with the practice of adopting a fixed defense strategy in the prior art, the present invention provides a more flexible and intelligent defense mechanism, which can automatically adapt according to the attack intensity and solves the problem that the traditional fixed defense strategy cannot cope with complex and ever-changing attacks.
[0167] 4. By introducing an incremental learning module and using the SGD algorithm to optimize the classification model parameters, the model can be updated at any time according to new data. The technical effects of improving the system adaptability and response ability are achieved. Different from the traditional batch training method, the incremental learning of the present invention can continuously optimize the model, solves the problems of lagging training data and slow update in the traditional method, and thus ensures that the system can cope with constantly changing attack methods.
[0168] It should be noted that the method of the embodiment of the present application can be executed by a single device, such as a computer or a server, etc. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In such a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiment of the present application, and these multiple devices will interact with each other to complete the described method.
[0169] It should be noted that some embodiments of the present application have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order from that in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0170] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a replay attack detection device.
[0171] Refer to Figure 6 , the replay attack detection device includes: a determination module 601 and a processing module 602.
[0172] The determining module 601 is configured to determine target packet data;
[0173] The processing module 602 is configured to input the target packet data into a pre-trained classification model to obtain a classification result; wherein, the pre-trained classification model is trained based on training data; the training data is obtained by successively performing feature extraction and dimensionality reduction processing on pre-acquired historical packet data;
[0174] The determining module 601 is further configured to determine a defense strategy in response to the classification result being a replay attack packet.
[0175] In some embodiments, the replay attack detection device further includes a calculation module 603.
[0176] The calculation module 603 is configured to calculate the covariance matrix of the historical packet data;
[0177] The processing module 602 is further configured to perform eigenvalue decomposition on the covariance matrix to obtain the eigenvalues and eigenvectors of the covariance matrix; wherein, the eigenvectors include the timestamps, packet byte counts, sequence numbers, and hash values of the historical packet data;
[0178] The determining module 601 is further configured to arrange the eigenvalues in descending order, determine the eigenvectors whose eigenvalues are greater than a first preset threshold, and obtain a dimensionality reduction matrix;
[0179] The processing module 602 is further configured to obtain the training data according to the historical packet data and the dimensionality reduction matrix.
[0180] In some embodiments, the determining module 601 is specifically configured to determine the attack type and attack frequency of the replay attack packet;
[0181] In response to the attack type or attack frequency of the replay attack packet reaching a preset condition, determine the defense strategy.
[0182] In some embodiments, the defense strategy includes at least one of the following: adjusting the effective range of the timestamp, adjusting the effective range of the sequence number, and adjusting the encryption degree of the data packet.
[0183] In some embodiments, the determining module 601 is further specifically configured to, in response to the attack frequency being greater than a second preset threshold, narrow the effective range of the timestamp and / or enhance the encryption degree of the data packet;
[0184] In response to the attack type being sequence number repetition or sequence number wrap-around, adjust the effective range of the sequence number.
[0185] In some embodiments, after determining the defense strategy, the replay attack detection device further includes an acquisition module 604.
[0186] The acquisition module 604 is configured to acquire a real-time error value of the defense strategy; the real-time error value satisfies the following expression:
[0187] e t = θ desired - θ t
[0188] where θ desired is the desired defense strategy; θ t is the current defense strategy; and e t is the real-time error value.
[0189] The processing module 602 is further configured to obtain the optimized defense strategy according to the real-time error value and an adaptive control algorithm; where the optimized defense strategy satisfies the following expression:
[0190]
[0191] where θ t+1 is the optimized defense strategy; K p is the proportionality coefficient; K i is the integral coefficient; K d is the differential coefficient; and Δt is the time step.
[0192] In some embodiments, the replay attack detection device further includes an update module 605.
[0193] The determination module 601 is further configured to determine the actual classification result of the target packet data;
[0194] The determination module 601 is further configured to determine a prediction error according to the actual classification result and the classification result;
[0195] The update module 605 is configured to update the classification model based on the prediction error and an incremental learning algorithm.
[0196] For convenience of description, when describing the above device, various modules are described separately according to their functions. Of course, when implementing the present application, the functions of each module can be implemented in one or more software and / or hardware.
[0197] The device in the above embodiments is used to implement the corresponding replay attack detection method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated herein.
[0198] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the replay attack detection method described in any one of the above embodiments is implemented.
[0199] Figure 7 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1060. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1060.
[0200] The processor 1010 may be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present specification.
[0201] The memory 1020 may be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of the present specification through software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.
[0202] The input / output interface 1030 is used to connect to an input / output module to implement information input and output. The input / output module may be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.
[0203] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module may implement communication in a wired manner (such as USB, network cable, etc.) or in a wireless manner (such as mobile network, WIFI, Bluetooth, etc.).
[0204] The bus 1050 includes a path for transmitting information between various components of the device, such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040.
[0205] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0206] The electronic device of the above embodiment is used to implement the corresponding replay attack detection method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0207] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the replay attack detection method as described in any of the above embodiments.
[0208] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0209] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the replay attack detection method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0210] Based on the same inventive concept, corresponding to the replay attack detection method described in any of the above embodiments, the present disclosure also provides a computer program product, which includes a computer program. In some embodiments, the computer program is executable by one or more processors to cause the processors to execute the replay attack detection method. Corresponding to the execution subjects corresponding to the steps in each embodiment of the replay attack detection method, the processors that execute the corresponding steps may belong to the corresponding execution subjects.
[0211] The computer program product of the above embodiment is used to cause a processor to execute the replay attack detection method described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0212] Those of ordinary skill in the art should understand that: the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the present application (including the claims) is limited to these examples; under the concept of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and they are not provided in detail for the sake of brevity.
[0213] In addition, for simplicity of explanation and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. In addition, the devices may be shown in block diagram form in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (i.e., these details should be completely within the understanding of those skilled in the art). In the case where specific details (such as circuits) are set forth to describe the exemplary embodiments of the present application, it will be apparent to those skilled in the art that the embodiments of the present application can be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0214] Although the present application has been described in conjunction with specific embodiments of the present application, many substitutions, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) can be used in the embodiments discussed.
[0215] Embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application shall be included within the protection scope of the present application.
Claims
1. A replay attack detection method, characterized in that: The method comprises: Determine target message data; Input the target message data into a pre-trained classification model to obtain a classification result; wherein the pre-trained classification model is trained based on training data; the training data is obtained by sequentially performing feature extraction and dimensionality reduction processing on pre-acquired historical message data; In response to the classification result being a replay attack message, a defense strategy is determined.
2. The method according to claim 1, characterized in that The method further comprises obtaining the training data by: Calculating the covariance matrix of the historical message data; Performing eigendecomposition on the covariance matrix to obtain eigenvalues and eigenvectors of the covariance matrix; wherein the eigenvector includes at least one of a timestamp, a number of bytes of a data packet, a sequence number, and a hash value of the historical message data; Arrange the eigenvalues in descending order, determine the eigenvector whose eigenvalue is greater than a first preset threshold, and obtain a reduced dimension matrix; The training data is obtained according to the historical message data and the dimensionality reduction matrix.
3. The method according to claim 1, characterized in that In response to the classification result being a replay attack message, determining a defense strategy includes: Determining the attack type and attack frequency of the replayed attack message; In response to the attack type or attack frequency of the replayed attack message reaching a preset condition, the defense strategy is determined.
4. The method according to claim 3, characterized in that The defense strategy includes at least one of the following: adjusting the valid range of the timestamp, adjusting the valid range of the sequence number, and adjusting the encryption level of the data packet.
5. The method according to claim 4, characterized in that The determining of the defense strategy in response to the attack type or attack frequency of the replayed attack message reaching a preset condition includes: In response to the attack frequency being greater than a second preset threshold, reducing the effective range of the timestamp and / or increasing the encryption level of the data packet; In response to the attack type being the sequence number repetition or the sequence number wrapping, the valid range of the sequence number is adjusted.
6. The method according to claim 1, characterized in that After determining the defense strategy, the method further includes: Obtain a real-time error value of the defense strategy; the real-time error value satisfies the following expression: e t =θ desired -θ t Among them, θ desired is the desired defense strategy; θ t is the current defense strategy; e t is the real-time error value; According to the real-time error value and the adaptive control algorithm, the optimized defense strategy is obtained; wherein the optimized defense strategy satisfies the following expression: Among them, θ t+1 is the optimized defense strategy; K p is the proportionality coefficient; K i is the integral coefficient; K d is the differential coefficient; Δt is the time step.
7. The method according to claim 1, characterized in that The method further comprises: Determining an actual classification result of the target message data; Determining a prediction error based on the actual classification result and the classification result; Based on the prediction error and the incremental learning algorithm, the classification model is updated.
8. A replay attack detection device, characterized in that: The device comprises: a determination module and a processing module; The determination module is used to determine the target message data; The processing module is used to input the target message data into a pre-trained classification model to obtain a classification result; wherein the pre-trained classification model is trained based on training data; the training data is obtained by sequentially extracting features and reducing the dimension of pre-acquired historical message data; The determination module is further configured to determine a defense strategy in response to the classification result being a replay attack message.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 7 when executing the computer program. 10 . A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute the method according to claim 1 .
Citation Information
Cited By
Cross-platform operation and maintenance playback scene intelligent identification method and cross-platform operation and maintenance playback method
CN120744317A
API security detection method and API security detection system
CN121309009A