Network intrusion detection method and device, computer equipment and storage medium
Through the comparative Tranceformer neural network model, the network traffic data is serialized and trained, which solves the complexity of network intrusion detection and data imbalance in the cloud computing environment, and realizes high-precision and efficient intrusion detection to adapt to the dynamics of the cloud environment.
Patent Information
- Application Number
- CN202510550798.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-29
AI Technical Summary
The prior art is difficult to efficiently detect network intrusions in cloud computing environments, especially when facing large data traffic, fast changes, and new and unknown attack methods, traditional methods are difficult to adapt, and there are data imbalance problems and inefficiency in handling large-scale and high-noise data.
The comparative Tranceformer neural network model is used to serialize and train network traffic data. Through the comparison learning mechanism, the deep characteristics of network traffic are automatically learned, and the loss value of network traffic data is calculated to judge the intrusion result, and to adapt to the complexity and dynamics of the cloud environment.
It realizes high-precision network intrusion detection, effectively solves the problem of data imbalance, improves the sensitivity and efficiency of detection, adapts to the complexity and dynamics of the cloud environment, and enhances decision-making support for network security management.
Smart Images

Figure CN120074966A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of cloud computing networks, and particularly to a network intrusion detection method, device, computer device, computer-readable storage medium, and computer program product. Background Art
[0002] The rapid development of cloud computing technology has enabled it to be widely used in fields such as artificial intelligence, big data, and the Internet of Things. However, it has also led to an increasingly complex cloud network environment, facing more severe security challenges. As a virtual resource pool, the cloud computing environment, with its distributed characteristics, multi-tenant architecture, and dynamic adjustment of resources, makes network intrusion detection more complex and difficult. With the wide use of cloud computing services, hackers have also started to target the cloud environment, using means such as vulnerability attacks, denial-of-service attacks, and cross-site scripting attacks to illegally invade and damage cloud systems. These attacks may not only lead to data leakage and property losses but also have a serious impact on the entire cloud computing environment.
[0003] Traditional network intrusion detection technologies, such as rule-based detection and statistical anomaly detection, are unable to cope when faced with the complexity and dynamics of the cloud environment. They often struggle to adapt to the characteristics of large and rapidly changing data traffic in the cloud environment and are also unable to effectively deal with new and unknown attack methods. Currently, the existing anomaly traffic intrusion detection methods mainly have the following two problems: First, in real-world scenarios, the number of abnormal samples is often much less than that of normal samples, resulting in extremely unbalanced training data. This imbalance makes the model tend to be biased towards normal samples during training, thereby reducing the detection ability for abnormal samples. When improving the detection sensitivity, the false alarm rate often increases; while when reducing the false alarm rate, the detection sensitivity may be reduced. Second, traditional algorithms may not be as effective as deep learning in scenarios involving processing large-scale data, high-noise data, and applications that require automatic feature learning.
[0004] Therefore, there is an urgent need for a network intrusion detection method, device, computer device, computer-readable storage medium, and computer program product that can efficiently detect network traffic data. Summary of the Invention
[0005] Based on this, it is necessary to provide a network intrusion detection method, device, computer device, computer-readable storage medium, and computer program product that can efficiently detect network traffic data for the above technical problems.
[0006] In a first aspect, this application provides a network intrusion detection method, including:
[0007] Collect network traffic sample data, perform serialization processing on the network traffic sample data to obtain traffic sequence data;
[0008] Use the traffic sequence data to train a comparative Transformer neural network model to obtain a network intrusion detection model;
[0009] Obtain subsequent network traffic data within a preset range of the cloud environment;
[0010] Calculate the loss value of the subsequent network traffic data, and use the network intrusion detection model to determine the network intrusion result according to the loss value.
[0011] In one embodiment, the serializing the network traffic sample data includes:
[0012] Taking the network session topic type as the segmentation basis, segment the collected network traffic sample data to obtain at least one PCAP storage file, and read the link layer frames from each PCAP storage file;
[0013] Remove the header fields from the link layer frames and retain the IP data packets encapsulated in the link layer frames;
[0014] Perform a merging process on the IP data packets with the same traffic characteristics.
[0015] In one embodiment, the training the comparative Transformer neural network model using the traffic sequence data includes:
[0016] Perform positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data, and original sample data respectively;
[0017] Extract the semantic features from the positive sample data, negative sample data, and original sample data;
[0018] Use the semantic features in the positive sample data, negative sample data, and original sample data to train the comparative Transformer neural network model.
[0019] In one embodiment, the training the comparative Transformer neural network model using the semantic features in the positive sample data, negative sample data, and original sample data includes:
[0020] According to the semantic features in the positive sample data, the negative sample data, and the original sample data, use the calculation formula of the loss function to calculate the similarity between different two items in the positive sample data, the negative sample data, and the original sample data respectively;
[0021] When the similarity between the positive sample data and the original sample data reaches the maximum value, and the similarity between the negative sample data and the original sample data reaches the minimum value, it indicates that the loss value of the loss function reaches the minimum, and the comparative Tranceformer neural network model training is completed.
[0022] In one embodiment, the calculation formula of the loss value of the loss function includes:
[0023] ;
[0024] Among them, SimCSE-Loss represents the loss value; represents the original sample data corresponding true label value result; represents the positive sample data corresponding predicted value result; represents the negative sample data corresponding predicted value result; τ represents the similarity adjustment factor; represents the cosine similarity function for calculating any two sample data, and the specific formula is: , represents the dot product of vector A and vector B, represents the norm of vector A, represents the norm of vector B.
[0025] In one embodiment, after obtaining the subsequent network traffic data within the preset range of the cloud environment, it further includes:
[0026] Determine whether the subsequent network traffic data belongs to the preset blacklist traffic list or the preset whitelist traffic list; among them, the preset blacklist traffic list is marked by the cloud resource service provider or the user, and the preset whitelist traffic list is added by the cloud resource service provider or the user according to the preset rules;
[0027] When the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data, and use the network intrusion detection model according to the loss value to determine the network intrusion result.
[0028] In one embodiment, after determining the network intrusion result, it further includes:
[0029] When the network intrusion result indicates that the subsequent network traffic data belongs to abnormal traffic data, add the subsequent network traffic data to the preset blacklist traffic list.
[0030] In a second aspect, the present application also provides a network intrusion detection device, including:
[0031] A data acquisition module, configured to acquire network traffic sample data, perform serialization processing on the network traffic sample data, and obtain traffic sequence data;
[0032] A model training module, configured to use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0033] A data acquisition module, configured to acquire subsequent network traffic data within a preset range of the cloud environment;
[0034] An intrusion detection module, configured to calculate a loss value of the subsequent network traffic data, and use the network intrusion detection model according to the loss value to determine a network intrusion result.
[0035] In a third aspect, the present application also provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0036] Acquire network traffic sample data, perform serialization processing on the network traffic sample data, and obtain traffic sequence data;
[0037] Use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0038] Acquire subsequent network traffic data within a preset range of the cloud environment;
[0039] Calculate a loss value of the subsequent network traffic data, and use the network intrusion detection model according to the loss value to determine a network intrusion result.
[0040] In a fourth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0041] Acquire network traffic sample data, perform serialization processing on the network traffic sample data, and obtain traffic sequence data;
[0042] Use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0043] Acquire subsequent network traffic data within a preset range of the cloud environment;
[0044] Calculate the loss value of the subsequent network traffic data, and based on the loss value, use the network intrusion detection model to determine the network intrusion result.
[0045] In a fifth aspect, the present application also provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0046] Collect network traffic sample data, perform serialization processing on the network traffic sample data to obtain traffic sequence data;
[0047] Use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0048] Obtain subsequent network traffic data within a preset range of the cloud environment;
[0049] Calculate the loss value of the subsequent network traffic data, and based on the loss value, use the network intrusion detection model to determine the network intrusion result.
[0050] The above network intrusion detection method, device, computer device, computer-readable storage medium, and computer program product, by performing serialization processing on the collected network traffic sample data and converting it into unified traffic sequence data, enhance the temporal characteristics and processability of the data, and reduce the data complexity. Using these sequence data to train a comparative Transformer neural network model can give full play to the advantages of the multi-head self-attention mechanism of Transformer, automatically learn complex features and long-distance dependence relationships, thereby achieving high-precision intrusion detection and effectively solving the data imbalance problem. In practical applications, this method realizes real-time monitoring and dynamic detection of network traffic by continuously obtaining subsequent network traffic data within the preset range of the cloud environment, adapting to the complexity and dynamics of the cloud environment. By calculating the loss value of the subsequent network traffic data and combining the trained model to determine the network intrusion result, it can quantify the degree of abnormality, improve the reliability of detection, and at the same time can dynamically adjust the detection threshold according to actual needs to balance the detection sensitivity and false alarm rate, providing strong decision-making support for network security management. Generally speaking, this method has significant technical effects in terms of detection accuracy, efficiency, adaptability, real-time performance, and reliability, and can effectively cope with network security challenges in the cloud computing environment. Description of the Drawings
[0051] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0052] Figure 1 It is an application environment diagram of the network intrusion detection method in an embodiment;
[0053] Figure 2 It is a schematic flowchart of the network intrusion detection method in an embodiment;
[0054] Figure 3 It is a schematic flowchart of the network intrusion detection method in another embodiment;
[0055] Figure 4 It is a structural block diagram of the network intrusion detection device in an embodiment;
[0056] Figure 5 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0057] In order to make the objectives, technical solutions, and advantages of the present application more clear and understandable, the following further details the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0058] The network intrusion detection method provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed in the cloud or other network servers.
[0059] The server 104 controls the terminal 102 to collect network traffic sample data, performs serialization processing on the network traffic sample data to obtain traffic sequence data; the server 104 uses the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model; the server 104 controls the terminal 102 to obtain subsequent network traffic data within a preset range of the cloud environment; the server 104 calculates the loss value of the subsequent network traffic data, and based on the loss value, uses the network intrusion detection model to determine the network intrusion result.
[0060] Among them, the terminal 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server 104 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0061] In an exemplary embodiment, as Figure 2 shown, a network intrusion detection method is provided. Taking the method applied to Figure 1 the server 104 in as an example for description, it includes the following steps S202 to step S208. Among them:
[0062] Step S202, collect network traffic sample data, perform serialization processing on the network traffic sample data, and obtain traffic sequence data.
[0063] Specifically, the network traffic sample data is usually captured from network devices (such as switches, routers) or network monitoring tools. These data contain various information about network communications, such as the source address, destination address, protocol type, packet size, timestamp, etc. of the data packets. The collected sample data should cover normal traffic and abnormal traffic (such as attack traffic). The normal traffic is used for the model to learn the characteristics of normal network behavior, while the abnormal traffic is used to train the model to identify potential intrusion behaviors. The collected data usually exists in the form of original network data packets, for example, saved in the PCAP (Packet Capture) file format. These files contain detailed records of network communications.
[0064] The serialization processing is to convert the network traffic sample data into an ordered sequence format so that the model can better capture the time characteristics and dynamic changes of the data. This is crucial for detecting time-series-based attack behaviors (such as DDoS attacks, scanning attacks, etc.). After the above processing, the network traffic sample data is converted into ordered sequence data. Each sequence data represents a network session or a set of related network interaction processes. The traffic sequence sample data is usually organized in the form of a time series, and the data at each time point may contain multiple features, such as packet size, protocol type, etc. These sequence data can be directly used to train deep learning models, such as the Transformer model.
[0065] Step S204: Use the traffic sequence data to train a comparative Transformer neural network model to obtain a network intrusion detection model.
[0066] Specifically, the traffic sequence data is network traffic data after preprocessing (such as session segmentation, link layer stripping, data aggregation, and enhancement, etc.), which retains the time sequence information and dynamic characteristics of network traffic. This data format is suitable for training deep learning models based on time series because it can reflect the dynamic changes and behavior patterns of network traffic.
[0067] Transformer is a deep learning model based on the self-attention mechanism, initially used for natural language processing tasks such as machine translation. It can capture long-range dependencies in sequence data through the multi-head self-attention mechanism and can process all elements in the sequence in parallel, thereby improving the training efficiency. In the present invention, the Transformer model is used to extract features from network traffic sequence data.
[0068] The comparative Transformer proposed in this embodiment introduces a contrastive learning mechanism on the basis of the traditional Transformer. Contrastive learning is an unsupervised learning method that learns feature representations by comparing the similarities and differences between samples. During the training process, the model not only learns the features of normal traffic and abnormal traffic but also enhances the ability to distinguish different traffic patterns through contrastive learning. The model learns the deep features of network traffic and can distinguish normal traffic from abnormal traffic. The finally obtained network intrusion detection model can be used to detect the network traffic flowing into the cloud environment in real time and determine whether there is an intrusion behavior.
[0069] Step S206: Obtain the subsequent network traffic data within the preset range of the cloud environment.
[0070] Specifically, the "preset range" refers to the network area or key nodes that need to be monitored and predefined in the cloud environment. For example, it can be a specific server, virtual machine, network interface, or specific network service. The setting of the preset range enables the detection system to focus on monitoring important resources and improves the efficiency and pertinence of detection.
[0071] The subsequent network traffic data refers to the network traffic data captured in real time after the model training is completed. These data are the actual inputs for model detection and are used to determine whether the current network traffic is normal.
[0072] Step S208: Calculate the loss value of the subsequent network traffic data, and use the network intrusion detection model to determine the network intrusion result according to the loss value.
[0073] Specifically, in the training phase, the model optimizes the loss function (such as SimCSE-Loss) through contrastive learning, maximizing the similarity between positive samples and the original samples and minimizing the similarity between negative samples and the original samples. For the subsequent network traffic data captured in real time, the model calculates the loss value between it and the normal traffic pattern. The loss value reflects the degree of difference between the current traffic data and the normal traffic pattern.
[0074] According to a preset threshold, if the calculated loss value exceeds the threshold, it indicates that the difference between the current traffic data and the normal traffic pattern is large, and it may be abnormal traffic. The model will judge it as an intrusion behavior. Using the trained network intrusion detection model (such as Comparative Transformer), the subsequent network traffic data is classified and judged. The model will output the probability or confidence level of whether the traffic is normal or abnormal, and finally determine the intrusion result based on these outputs.
[0075] By calculating the loss value, the degree of abnormality of the traffic is quantified into a specific value, making the judgment process more objective and accurate. The model has learned the feature differences between normal traffic and abnormal traffic during the training phase. Through the judgment of the loss value, it can effectively distinguish normal traffic and abnormal traffic and reduce the false alarm rate. According to the changes in the actual network environment, the threshold of the loss value can be dynamically adjusted, so as to balance the detection sensitivity and the false alarm rate. This step can quickly detect and judge the real-time network traffic, discover and respond to potential intrusion behaviors in a timely manner, and enhance the security of the cloud environment.
[0076] In the above network intrusion detection method, by serializing the collected network traffic sample data, it is converted into unified traffic sequence data, enhancing the temporal characteristics and processability of the data and reducing the data complexity. Using these sequence data to train the comparative Transformer neural network model can give full play to the advantages of the multi-head self-attention mechanism of Transformer, automatically learn complex features and long-distance dependencies, so as to achieve high-precision intrusion detection and effectively solve the data imbalance problem. In practical applications, this method realizes the real-time monitoring and dynamic detection of network traffic by continuously obtaining the subsequent network traffic data within the preset range of the cloud environment, adapting to the complexity and dynamics of the cloud environment. By calculating the loss value of the subsequent network traffic data and combining the trained model to determine the network intrusion result, it can quantify the degree of abnormality, improve the reliability of detection, and at the same time, the detection threshold can be dynamically adjusted according to actual needs to balance the detection sensitivity and the false alarm rate, providing strong decision-making support for network security management. Generally speaking, this method has significant technical effects in terms of detection accuracy, efficiency, adaptability, real-time performance and reliability, and can effectively cope with the network security challenges in the cloud computing environment.
[0077] In an exemplary embodiment, such asFigure 3 As shown in the figure, serializing the network traffic sample data includes:
[0078] Step S302: Using the network session topic type as the splitting basis, split the collected network traffic sample data to obtain at least one PCAP storage file, and read the link layer frames from each PCAP storage file;
[0079] Step S304: Remove the header fields from the link layer frames and retain the IP data packets encapsulated in the link layer frames;
[0080] Step S306: Merge the IP data packets with similar traffic characteristics.
[0081] Specifically, a network session refers to a communication connection established between two network nodes, usually defined by a specific protocol (such as TCP, UDP) and port number. The network session topic type can distinguish different sessions based on characteristics such as protocol type, port number, IP address, etc. Based on the network session topic type, a large amount of collected network traffic data is split into multiple small PCAP storage files. Each PCAP storage file contains the traffic data of a specific session. The PCAP (Packet Capture) format storage file is a common network traffic data storage format used to save the detailed information of network data packets.
[0082] The link layer is the second layer in the network protocol stack and is responsible for transmitting data frames between adjacent nodes. The link layer frame contains a frame header and a frame data part. The frame header contains information such as MAC address and protocol type, and the frame data part encapsulates the data of the upper layer protocol (such as IP data packets). Parse the content of the link layer frames from each PCAP storage file for further processing.
[0083] The header fields of the link layer frames contain some link layer-related control information, such as MAC address and protocol type. This information may not be necessary for subsequent traffic analysis, so the header fields can be removed, and only the frame data part is retained. The frame data part usually encapsulates IP data packets, which are the data units of the network layer and contain important information such as source IP address, destination IP address, and protocol type. Retaining the IP data packets is for subsequent analysis of the characteristics of network traffic.
[0084] The characteristics of IP packets can include protocol type, packet size, source IP address, destination IP address, etc. IP packets with similar characteristics may belong to the same type of traffic. For example, HTTP requests from the same client to the same server. Merging IP packets with similar traffic characteristics or the same traffic characteristics into a category or group can reduce data redundancy and improve the efficiency of data processing. The merged data can be used to generate higher-level traffic characteristics, such as session duration, packet transmission rate, etc.
[0085] In this embodiment, by removing the link layer header fields and merging IP packets with the same traffic characteristics, the data redundancy and complexity are reduced, and the efficiency of data processing is improved. The data after the merging process can better reflect the characteristics of network traffic and provide higher-quality input for subsequent model training. By retaining the key information in the IP packets, the model can more accurately identify the characteristic differences between normal traffic and abnormal traffic, thereby improving the accuracy of intrusion detection.
[0086] In an exemplary embodiment, a comparative Transformer neural network model is trained using traffic sequence data, including:
[0087] Performing positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data, and original sample data respectively;
[0088] Extracting semantic features from the positive sample data, negative sample data, and original sample data.
[0089] Using the semantic features in the positive sample data, negative sample data, and original sample data to train the comparative Transformer neural network model.
[0090] Specifically, positive sample data refers to samples of normal network traffic. These samples represent the behavior patterns of the network in a normal operating state. Negative sample data refers to samples of abnormal network traffic, such as traffic under attack or with malicious behavior. These samples represent the behavior patterns of the network when under intrusion. Original sample data refers to the unmodified original traffic sequence data, which is used for contrastive learning with positive and negative samples.
[0091] Positive sample sampling refers to randomly extracting samples from normal traffic to generate positive sample data. Negative sample sampling refers to randomly extracting samples from abnormal traffic to generate negative sample data. Negative samples can also be generated from normal traffic through data augmentation techniques (such as adding noise, random transformation, etc.). Original sample sampling refers to directly selecting samples from the traffic sequence data that have not undergone any processing as original samples.
[0092] Extract the semantic features from the positive sample data, negative sample data, and original sample data. Semantic features refer to, in the context of deep learning, high-level feature representations of data that can reflect the intrinsic meaning and patterns of the data. For network traffic data, semantic features may include the size of data packets, transmission frequency, protocol type, source / destination IP addresses, etc.
[0093] The Transformer model extracts features from the input traffic sequence data through its encoder part. Specifically, the self-attention mechanism of the Transformer model can capture long-range dependencies in the sequence data and transform the input data into abstract semantic feature vectors. The Transformer model can capture complex patterns and long-range dependencies in network traffic data, thereby extracting more meaningful semantic features. Through the self-attention mechanism, the model can automatically learn the important features in the data without manual feature engineering.
[0094] By comparing the similarities and differences between positive samples, negative samples, and original samples, the model can learn more effective feature representations. During the training process, the model uses a specific loss function (such as SimCSE-Loss) to optimize the parameters. The goal of the loss function is to maximize the similarity between positive samples and original samples and minimize the similarity between negative samples and original samples. Input the positive sample data, negative sample data, and original sample data into the Transformer model. The model extracts the semantic features of these samples through the encoder part.
[0095] In this embodiment, through the contrastive learning mechanism, the model's ability to detect abnormal traffic is enhanced. Through positive and negative sample sampling, semantic feature extraction, and loss function optimization, the model can automatically learn the deep features of network traffic and effectively distinguish normal traffic from abnormal traffic. This method not only improves the detection accuracy and efficiency but also enhances the model's generalization ability and adaptability, providing strong technical support for network intrusion detection in the cloud environment.
[0096] In an exemplary embodiment, use the semantic features in the positive sample data, negative sample data, and original sample data to train a comparative Tranceformer neural network model, including:
[0097] According to the semantic features in the positive sample data, negative sample data, and original sample data, use the calculation formula of the loss function to calculate the similarities between different pairs of the positive sample data, negative sample data, and original sample data respectively;
[0098] When the similarity between the positive sample data and the original sample data reaches the maximum value, and the similarity between the negative sample data and the original sample data reaches the minimum value, the loss value representing the loss function reaches the minimum, and the comparative Tranceformer neural network model training is completed.
[0099] Specifically, the calculation formula of the loss function (such as SimCSE-Loss) is used to calculate the similarity between different samples. The similarity is usually measured using cosine similarity, which calculates the cosine value of the angle between two vectors, and the value range is between -1 and 1, and the larger the value, the more similar. The loss function is the objective function used to optimize the parameters during model training. In the comparative Transformer model, the loss function is designed to maximize the similarity between the positive sample and the original sample, and minimize the similarity between the negative sample and the original sample.
[0100] During the training process, the model parameters are continuously adjusted to increase the similarity between the positive sample and the original sample, and decrease the similarity between the negative sample and the original sample. When the similarity between the positive sample and the original sample reaches the maximum value, and the similarity between the negative sample and the original sample reaches the minimum value, the loss value of the loss function reaches the minimum. This indicates that the model has learned the feature representation that can effectively distinguish normal traffic and abnormal traffic. When the loss value reaches the minimum and the performance of the model on the validation set meets the requirements, it can be considered that the model training is completed.
[0101] In this embodiment, through contrastive learning, the model can more accurately distinguish normal traffic and abnormal traffic, thereby improving the accuracy of intrusion detection. The model learns the feature differences between normal and abnormal traffic during the training process, and can effectively reduce the false alarm rate. By learning the similarities and differences between samples, the model can better adapt to new attack patterns and unknown network environments.
[0102] In an exemplary embodiment, the calculation formula of the loss value of the loss function includes:
[0103] ;
[0104] where SimCSE-Loss represents the loss value; represents the original sample data corresponding true label value result; represents the positive sample data corresponding predicted value result; represents the negative sample data corresponding predicted value result; τ represents the similarity adjustment factor; represents the cosine similarity function for calculating any two items of sample data, and the specific formula is: , Denotes the dot product of vector A and vector B, Denotes the norm of vector A, Denotes the norm of vector B.
[0105] In this embodiment, the comparative Transformer model is optimized through the SimCSE-Loss function to improve the accuracy and efficiency of network intrusion detection; through the contrastive learning mechanism, the model's ability to distinguish between normal and abnormal traffic features is strengthened, thereby reducing the false alarm rate and improving the detection sensitivity. SimCSE-Loss is particularly suitable for dealing with unbalanced data sets and can optimize the model performance by maximizing the similarity of positive samples and minimizing the similarity of negative samples; it can adapt to the dynamic changes of network traffic in the cloud environment, realize the rapid identification and response to new attack behaviors, and enhance the generalization ability and real-time detection effect of the model. By automatically learning traffic features, the need for manual feature engineering is reduced, the detection process is simplified, and more effective protection measures are provided for cloud security.
[0106] In an exemplary embodiment, after obtaining the subsequent network traffic data within the preset range of the cloud environment, it further includes:
[0107] Determine whether the subsequent network traffic data belongs to a preset blacklist traffic list or a preset whitelist traffic list; wherein, the preset blacklist traffic list is marked by the cloud resource service provider or the user, and the preset whitelist traffic list is added by the cloud resource service provider or the user according to preset rules;
[0108] In the case where the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data, and use the network intrusion detection model according to the loss value to determine the network intrusion result.
[0109] Specifically, the preset blacklist traffic list refers to a traffic list marked by the cloud resource service provider or the user according to known malicious behaviors or attack patterns. These traffic is considered abnormal and is usually directly intercepted or blocked. The preset whitelist traffic list refers to a traffic list added by the cloud resource service provider or the user according to preset rules (such as known normal business traffic patterns). These traffic is considered trustworthy and is usually directly allowed to pass. The system will first check whether the captured network traffic data matches the entries in the blacklist or whitelist. If it matches the blacklist, it will be directly intercepted and an alarm will be issued; if it matches the whitelist, it will be directly allowed to pass without further detection.
[0110] In the case that the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data. According to the loss value, use the network intrusion detection model to determine that the network intrusion result refers to the traffic that does not belong to the blacklist or the whitelist, which means that for the traffic that belongs to neither the blacklist nor the whitelist, the system needs to further analyze to determine whether it is abnormal traffic.
[0111] Use the trained network intrusion detection model (such as the comparative Transformer model) to calculate the loss value between the current traffic data and the normal traffic pattern. The loss value reflects the degree of difference between the current traffic data and the normal traffic pattern. According to the preset threshold, if the calculated loss value exceeds the threshold, it indicates that the difference between the current traffic data and the normal traffic pattern is large, and it may be abnormal traffic. The model will judge it as an intrusion behavior. Use the probability or confidence level of whether the traffic output by the model is normal or abnormal to finally determine the intrusion result.
[0112] In this embodiment, through the quick screening of the blacklist and the whitelist, the repeated detection of known normal or malicious traffic is reduced, saving computing resources and time. The system can concentrate resources on the detailed analysis of unknown or suspicious traffic, improving the pertinence and efficiency of detection. Blacklist traffic is usually known malicious behavior, and direct interception can reduce false alarms. Whitelist traffic is usually known normal business traffic, and direct release can avoid normal traffic being misjudged as abnormal traffic. The blacklist and the whitelist can be dynamically updated according to actual needs. For example, when a new attack pattern is discovered, it can be added to the blacklist in a timely manner; when the normal business traffic pattern changes, the whitelist can be updated. Cloud resource service providers or users can define blacklist and whitelist rules according to their own needs and experience, enhancing the flexibility and customizability of the system.
[0113] In an exemplary embodiment, after determining the network intrusion result, it further includes:
[0114] In the case that the network intrusion result indicates that the subsequent network traffic data belongs to abnormal traffic data, add the subsequent network traffic data to the preset blacklist traffic list.
[0115] Specifically, after the network intrusion detection model analyzes subsequent network traffic data, it outputs a judgment result indicating whether the current traffic is normal or abnormal. If the model determines that the subsequent network traffic data belongs to abnormal traffic, it means that the traffic may contain malicious behaviors or attack characteristics, such as unauthorized access, data leakage, denial-of-service attack (DDoS), etc. The preset blacklist traffic list is a list containing known malicious traffic characteristics, which is used to quickly identify and intercept potential attack behaviors. The traffic in the blacklist is usually directly blocked or isolated to prevent further damage to the system. When new abnormal traffic is detected, adding these traffic characteristics to the blacklist can expand the coverage of the blacklist and enhance the system's recognition ability for newly emerging attack patterns.
[0116] In this embodiment, by adding the detected abnormal traffic to the blacklist, the system can identify and intercept similar attack behaviors faster, thereby enhancing the defense ability against unknown and new attacks. For traffic patterns that have been identified as abnormal, when they appear again later, they can be directly intercepted through the blacklist without the need for detailed detection and analysis again, saving system resources. Dynamically updating the blacklist can ensure that the system can respond to newly emerging threats in a timely manner and reduce the impact of attacks on the system.
[0117] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps does not have a strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0118] Based on the same inventive concept, the embodiments of the present application also provide a network intrusion detection device for implementing the above-mentioned network intrusion detection method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the network intrusion detection device provided below can refer to the limitations on the network intrusion detection method in the above text, and will not be repeated here.
[0119] In an exemplary embodiment, as Figure 4 shown, a network intrusion detection device is provided, including:
[0120] The data acquisition module 402 is used to acquire network traffic sample data, perform serialization processing on the network traffic sample data, and obtain traffic sequence data;
[0121] The model training module 404 is used to utilize the traffic sequence data to train a comparative Tranceformer neural network model and obtain a network intrusion detection model;
[0122] The data acquisition module 406 is used to acquire subsequent network traffic data within a preset range of the cloud environment;
[0123] The intrusion detection module 408 is used to calculate the loss value of the subsequent network traffic data, and based on the loss value, utilize the network intrusion detection model to determine the network intrusion result.
[0124] In an exemplary embodiment, the model training module 404 is further used to use the network session topic type as a segmentation basis to segment the acquired network traffic sample data, obtain at least one PCAP storage file, read link layer frames from each PCAP storage file; remove the header fields from the link layer frames and retain the IP data packets encapsulated in the link layer frames; perform merging processing on the IP data packets with the same traffic characteristics.
[0125] In an exemplary embodiment, the data acquisition module 402 is further used to perform positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data, and original sample data respectively; extract semantic features from the positive sample data, negative sample data, and original sample data. Utilize the semantic features in the positive sample data, negative sample data, and original sample data to train a comparative Tranceformer neural network model.
[0126] In an exemplary embodiment, the model training module 404 is further used to calculate the similarity between different two items in the positive sample data, negative sample data, and original sample data respectively according to the semantic features in the positive sample data, negative sample data, and original sample data and the calculation formula of the loss function; when the similarity between the positive sample data and the original sample data reaches the maximum value and the similarity between the negative sample data and the original sample data reaches the minimum value, it indicates that the loss value of the loss function reaches the minimum, and the training of the comparative Tranceformer neural network model is completed.
[0127] In an exemplary embodiment, the calculation formula of the loss value of the loss function includes:
[0128] ;
[0129] where SimCSE-Loss represents the loss value; represents the original sample data The corresponding true label value result; Represents positive sample data The corresponding predicted value result; Represents negative sample data The corresponding predicted value result; τ represents the similarity adjustment factor; Represents the cosine similarity function for calculating the cosine similarity between any two sample data, and the specific formula is: , Represents the dot product of vector A and vector B, Represents the norm of vector A, Represents the norm of vector B.
[0130] In an exemplary embodiment, the intrusion detection module 408 is configured to determine whether subsequent network traffic data belongs to a preset blacklist traffic list or a preset whitelist traffic list; wherein, the preset blacklist traffic list is marked by a cloud resource service provider or a user, and the preset whitelist traffic list is added by a cloud resource service provider or a user according to preset rules; in the case where the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data, and according to the loss value, use the network intrusion detection model to determine the network intrusion result.
[0131] In an exemplary embodiment, the intrusion detection module 408 is configured to add the subsequent network traffic data to the preset blacklist traffic list in the case where the network intrusion result indicates that the subsequent network traffic data belongs to abnormal traffic data.
[0132] Each module in the above network intrusion detection device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above respective modules.
[0133] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 5As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store network traffic sample data and subsequent network traffic data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a network intrusion detection method.
[0134] Those skilled in the art can understand that Figure 5 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0135] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0136] Collect network traffic sample data, perform serialization processing on the network traffic sample data to obtain traffic sequence data;
[0137] Use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0138] Obtain subsequent network traffic data within the preset range of the cloud environment;
[0139] Calculate the loss value of the subsequent network traffic data, and use the network intrusion detection model according to the loss value to determine the network intrusion result.
[0140] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0141] Use the network session topic type as the segmentation basis to segment the collected network traffic sample data to obtain at least one PCAP storage file, and read link layer frames from each PCAP storage file;
[0142] Remove the header field from the link layer frame and retain the IP data packet encapsulated in the link layer frame;
[0143] Merge and process IP data packets with the same traffic characteristics.
[0144] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0145] Perform positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data, and original sample data respectively;
[0146] Extract the semantic features from the positive sample data, negative sample data, and original sample data.
[0147] Utilize the semantic features in the positive sample data, negative sample data, and original sample data to train a comparative Tranceformer neural network model.
[0148] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0149] According to the semantic features in the positive sample data, negative sample data, and original sample data, use the calculation formula of the loss function to calculate the similarity between different two items in the positive sample data, negative sample data, and original sample data respectively;
[0150] When the similarity between the positive sample data and the original sample data reaches the maximum value, and the similarity between the negative sample data and the original sample data reaches the minimum value, it indicates that the loss value of the loss function reaches the minimum, and the comparative Tranceformer neural network model is trained.
[0151] In an exemplary embodiment, the calculation formula of the loss value of the loss function includes:
[0152] ;
[0153] Among them, SimCSE-Loss represents the loss value; represents the true label value result corresponding to the original sample data ; represents the predicted value result corresponding to the positive sample data ; represents the predicted value result corresponding to the negative sample data ; τ represents the similarity adjustment factor; represents the cosine similarity function for calculating any two sample data, and the specific formula is: represents the dot product of vector A and vector B, represents the norm of vector A, represents the norm of vector B.
[0154] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0155] Determine whether the subsequent network traffic data belongs to a preset blacklist traffic list or a preset whitelist traffic list; wherein, the preset blacklist traffic list is marked by a cloud resource service provider or a user, and the preset whitelist traffic list is added by a cloud resource service provider or a user according to preset rules;
[0156] In the case where the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data, and according to the loss value, use the network intrusion detection model to determine the network intrusion result.
[0157] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0158] In the case where the network intrusion result indicates that the subsequent network traffic data belongs to abnormal traffic data, add the subsequent network traffic data to the preset blacklist traffic list.
[0159] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0160] Collect network traffic sample data, perform serialization processing on the network traffic sample data to obtain traffic sequence data;
[0161] Use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0162] Obtain subsequent network traffic data within a preset range of the cloud environment;
[0163] Calculate the loss value of the subsequent network traffic data, and according to the loss value, use the network intrusion detection model to determine the network intrusion result.
[0164] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0165] Use the network session topic type as a segmentation basis to segment the collected network traffic sample data to obtain at least one PCAP storage file, and read link layer frames from each PCAP storage file;
[0166] Remove the header fields from the link layer frames and retain the IP data packets encapsulated in the link layer frames;
[0167] Perform merging processing on IP data packets with the same traffic characteristics.
[0168] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0169] Perform positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data, and original sample data respectively;
[0170] Extract the semantic features from the positive sample data, negative sample data, and original sample data.
[0171] Use the semantic features in the positive sample data, negative sample data, and original sample data to train a comparative Transformer neural network model.
[0172] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0173] According to the semantic features in the positive sample data, negative sample data, and original sample data, use the calculation formula of the loss function to calculate the similarity between different two items in the positive sample data, negative sample data, and original sample data respectively;
[0174] When the similarity between the positive sample data and the original sample data reaches the maximum value, and the similarity between the negative sample data and the original sample data reaches the minimum value, it indicates that the loss value of the loss function reaches the minimum, and the training of the comparative Transformer neural network model is completed.
[0175] In an exemplary embodiment, the calculation formula of the loss value of the loss function includes:
[0176] ;
[0177] where SimCSE-Loss represents the loss value; represents the true label value result corresponding to the original sample data ; represents the predicted value result corresponding to the positive sample data ; represents the predicted value result corresponding to the negative sample data ; τ represents the similarity adjustment factor; represents the cosine similarity function for calculating any two sample data, and the specific formula is: represents the dot product of vector A and vector B, represents the norm of vector A, represents the norm of vector B.
[0178] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0179] Determine whether the subsequent network traffic data belongs to a preset blacklist traffic list or a preset whitelist traffic list; wherein, the preset blacklist traffic list is marked by a cloud resource service provider or a user, and the preset whitelist traffic list is added by a cloud resource service provider or a user according to preset rules;
[0180] In the case that the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data, and based on the loss value, use the network intrusion detection model to determine the network intrusion result.
[0181] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0182] In the case that the network intrusion result indicates that the subsequent network traffic data belongs to abnormal traffic data, add the subsequent network traffic data to the preset blacklist traffic list.
[0183] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0184] Collect network traffic sample data, perform serialization processing on the network traffic sample data to obtain traffic sequence data;
[0185] Use the traffic sequence data to train a comparative Tranceformer neural network model to obtain a network intrusion detection model;
[0186] Obtain subsequent network traffic data within a preset range of the cloud environment;
[0187] Calculate the loss value of the subsequent network traffic data, and based on the loss value, use the network intrusion detection model to determine the network intrusion result.
[0188] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0189] Use the network session topic type as the segmentation basis to segment the collected network traffic sample data to obtain at least one PCAP storage file, and read the link layer frames from each PCAP storage file;
[0190] Remove the header fields from the link layer frames and retain the IP data packets encapsulated in the link layer frames;
[0191] Perform merging processing on IP data packets with the same traffic characteristics.
[0192] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0193] Perform positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data, and original sample data respectively;
[0194] Extract the semantic features from the positive sample data, negative sample data, and original sample data.
[0195] Use the semantic features in the positive sample data, negative sample data, and original sample data to train a comparative Transformer neural network model.
[0196] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0197] According to the semantic features in the positive sample data, negative sample data, and original sample data, use the calculation formula of the loss function to calculate the similarity between different two items in the positive sample data, negative sample data, and original sample data respectively;
[0198] When the similarity between the positive sample data and the original sample data reaches the maximum value, and the similarity between the negative sample data and the original sample data reaches the minimum value, it indicates that the loss value of the loss function reaches the minimum, and the training of the comparative Transformer neural network model is completed.
[0199] In an exemplary embodiment, the calculation formula of the loss value of the loss function includes:
[0200] ;
[0201] Where, SimCSE-Loss represents the loss value; represents the true label value result corresponding to the original sample data ; represents the predicted value result corresponding to the positive sample data ; represents the predicted value result corresponding to the negative sample data ; τ represents the similarity adjustment factor; represents the cosine similarity function for calculating any two items of sample data, and the specific formula is: ,[[]]END]] represents the dot product of vector A and vector B, represents the norm of vector A, represents the norm of vector B.
[0202] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0203] Determine whether the subsequent network traffic data belongs to a preset blacklist traffic list or a preset whitelist traffic list; wherein, the preset blacklist traffic list is marked by a cloud resource service provider or a user, and the preset whitelist traffic list is added by a cloud resource service provider or a user according to preset rules;
[0204] In the case that the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, calculate the loss value of the subsequent network traffic data, and use the network intrusion detection model according to the loss value to determine the network intrusion result.
[0205] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0206] In the case that the network intrusion result indicates that the subsequent network traffic data belongs to abnormal traffic data, add the subsequent network traffic data to the preset blacklist traffic list.
[0207] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0208] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0209] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope recorded in this application.
[0210] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A network intrusion detection method, characterized in that: The method comprises: Collecting network traffic sample data, and performing serialization processing on the network traffic sample data to obtain traffic sequence data; Using the traffic sequence data, a comparative Tranceformer neural network model is trained to obtain a network intrusion detection model; Obtain subsequent network traffic data within a preset range of the cloud environment; The loss value of the subsequent network traffic data is calculated, and according to the loss value, the network intrusion detection model is used to determine the network intrusion result.
2. The method according to claim 1, characterized in that The serializing the network traffic sample data includes: The collected network traffic sample data is segmented using the network session topic type as a segmentation basis to obtain at least one PCAP storage file, and a link layer frame is read from each PCAP storage file; Remove the header field from the link layer frame and retain the IP data packet encapsulated in the link layer frame; Merge IP packets with the same traffic characteristics.
3. The method according to claim 1, characterized in that The method of using the traffic sequence data to train a comparative Tranceformer neural network model includes: Performing positive and negative sample sampling on the traffic sequence data to obtain positive sample data, negative sample data and original sample data respectively; Extract semantic features from positive sample data, negative sample data, and original sample data; The comparative Tranceformer neural network model is trained by using the semantic features in the positive sample data, the negative sample data and the original sample data.
4. The method according to claim 3, characterized in that The method of training the comparative Tranceformer neural network model by using the semantic features in the positive sample data, the negative sample data and the original sample data includes: According to the semantic features in the positive sample data, the negative sample data and the original sample data, the similarities between different two items in the positive sample data, the negative sample data and the original sample data are calculated respectively using a calculation formula of a loss function; When the similarity between the positive sample data and the original sample data reaches a maximum value, and the similarity between the negative sample data and the original sample data reaches a minimum value, the loss value representing the loss function reaches a minimum, and the training of the comparative Tranceformer neural network model is completed.
5. The method according to claim 4, characterized in that The calculation formula of the loss value of the loss function includes: ; Among them, SimCSE-Loss represents the loss value; Represents the original sample data The corresponding true label value result; Represents positive sample data The corresponding predicted value results; Represents negative sample data The corresponding predicted value result; τ represents the similarity adjustment factor; Represents the cosine similarity function for calculating any two sample data. The specific formula is: , represents the dot product of vector A and vector B, represents the norm of vector A, Represents the norm of vector B.
6. The method according to claim 1, characterized in that After obtaining the subsequent network traffic data in the preset range of the cloud environment, the method further includes: Determine whether the subsequent network traffic data belongs to a preset blacklist traffic list or a preset whitelist traffic list; wherein the preset blacklist traffic list is marked by the cloud resource service provider or user, and the preset whitelist traffic list is added by the cloud resource service provider or user according to preset rules; When the subsequent network traffic data does not belong to the preset blacklist traffic list or the preset whitelist traffic list, the loss value of the subsequent network traffic data is calculated, and the network intrusion result is determined based on the loss value using the network intrusion detection model.
7. The method according to claim 6, characterized in that After determining the network intrusion result, the method further includes: When the network intrusion result indicates that the subsequent network traffic data is abnormal traffic data, the subsequent network traffic data is added to the preset blacklist traffic list.
8. A network intrusion detection device, characterized in that: The device comprises: A data collection module is used to collect network traffic sample data, and perform serialization processing on the network traffic sample data to obtain traffic sequence data; A model training module, used to train a comparative Tranceformer neural network model using the traffic sequence data to obtain a network intrusion detection model; A data acquisition module, used to acquire subsequent network traffic data within a preset range of the cloud environment; The intrusion detection module is used to calculate the loss value of the subsequent network flow data, and determine the network intrusion result based on the loss value and using the network intrusion detection model.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Masquerade intrusion detection method and device based on deep neural network
CN106951783A
Network intrusion detection method, network intrusion detection model training method, network intrusion detection model training device and server
CN110881037A
Semantic feature generation method and device, model training method and device, equipment and medium
CN112560501A
Intrusion detection method, system and device and readable storage medium
CN113449837A
Malicious network traffic classification method based on sample enhancement and comparative learning
CN117034112A