Traffic fingerprint identification method and system based on electric power communication network
By extracting and processing the traffic data of the power communication network, and building a traffic fingerprint database using sparse algorithms and graph theory algorithms, the problem of insufficient accuracy in traditional recognition methods is solved, and accurate identification and security guarantee of the traffic of the power communication network is achieved.
Patent Information
- Application Number
- CN202510534822.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-04-27
AI Technical Summary
In the prior art, traditional traffic fingerprint recognition relies on rules summarized by manual experience, resulting in the inability to accurately traffic fingerprint recognition, which in turn puts the power communication system at security risks.
By extracting the sample traffic data of the target communication network feature, using sparse algorithm and topological structure built on graph theory algorithm, the traffic feature signal is processed, and the characteristic representation of the reconstructed feature signal and graph structure is obtained. After the fusion, the traffic fingerprint database is built and intelligent analysis is performed to generate traffic fingerprint recognition results.
By combining the spatiotemporal correlation characteristics of the Grauplaplas matrix, the accurate identification of traffic data of the power communication network is achieved, the accuracy of traffic fingerprint recognition is improved, and the safe development of the power communication network is ensured.
Smart Images

Figure CN120086801A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network traffic analysis, and in particular to a traffic fingerprint recognition method and system based on a power communication network. Background Art
[0002] With the deep integration of smart grid and energy Internet technologies, the power communication network is developing towards high reliability, high real-time, and high security. Among them, the recognition technology based on traffic fingerprints can effectively identify the behavioral characteristics of power communication devices and detect abnormal traffic or potential attacks.
[0003] In the prior art, traditional traffic fingerprint recognition relies on rules summarized from manual experience, and then identifies traffic according to this rule, which may lead to inaccurate traffic fingerprint recognition and further cause the power communication system to face security risks.
[0004] Therefore, how to improve the accuracy of traffic fingerprint recognition and ensure the safe development of the power communication network has become a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention
[0005] The present invention provides a traffic fingerprint recognition method and system based on a power communication network to improve the accuracy of traffic fingerprint recognition and achieve the effect of ensuring the safe development of the power communication network.
[0006] To solve the above technical problems, an embodiment of the present invention provides a traffic fingerprint recognition method based on a power communication network, including: Performing feature extraction on the acquired sample traffic data of the target communication network to obtain traffic feature data; Processing the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal; Processing the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix; Solving the traffic expression to obtain a feature representation of the graph structure; Fusing the reconstructed feature signal with the feature representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result; Based on the traffic fingerprint database, performing intelligent analysis on the traffic data to be recognized obtained from the target communication network, and generating a matching traffic fingerprint recognition result based on the analysis result.
[0007] As a preferred solution, before performing feature extraction on the acquired sample traffic data of the target communication network, the traffic fingerprint recognition method based on a power communication network further includes: Obtain traffic data with the same application type in the target communication network; Convert the traffic data into a multivariate time series, and perform a dimension difference elimination process on the multivariate time series to obtain sample traffic data with the same dimension.
[0008] As one of the preferred solutions, the process of using a sparse algorithm to process the traffic feature data to obtain a reconstructed feature signal includes: Input the traffic feature data into the encoding end of an autoencoder constructed based on a sparse algorithm for training to obtain a traffic feature signal; Use a sparse representation layer to process the traffic feature signal to obtain a linear sparse representation of the traffic feature signal; Input the linear sparse representation into a sparse autoencoder decoder to obtain the reconstructed feature signal.
[0009] As one of the preferred solutions, before using a topological structure constructed based on a graph theory algorithm to process the traffic feature signal obtained from the traffic feature data to obtain a traffic expression corresponding to a graph Laplacian matrix, the traffic fingerprint recognition method based on a power communication network further includes: Construct an adjacency matrix based on the traffic feature data; Use the Pearson correlation coefficient to calculate the degree of each traffic feature node in the adjacency matrix, and construct a degree matrix based on the degree; Based on the adjacency matrix and the degree matrix, obtain the graph Laplacian matrix.
[0010] As one of the preferred solutions, the process of solving the traffic expression to obtain a feature representation of the graph structure includes: Perform range classification on the traffic expression to obtain a first traffic expression and a second traffic expression; Perform eigenvalue decomposition on the first traffic expression to obtain a first feature representation; Use an iterative method to solve the second traffic expression to obtain a second feature representation; Perform sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure.
[0011] As one of the preferred solutions, before fusing the reconstructed feature signal and the feature representation of the graph structure, the traffic fingerprint recognition method based on a power communication network further includes: Perform mapping processing on the reconstructed feature signal and the feature representation of the graph structure through linear transformation to obtain the reconstructed feature signal and the feature representation of the graph structure with the same dimension.
[0012] As one of the preferred solutions, the process of fusing the reconstructed feature signal with the feature representation of the graph structure includes: Using the entropy weight method to calculate the weight coefficients of the reconstructed feature signal and the feature representation of the graph structure respectively; Based on the weight coefficients, fuse the reconstructed feature signal and the feature representation of the graph structure.
[0013] As one of the preferred solutions, the intelligent analysis of the traffic data to be identified obtained from the target communication network based on the traffic fingerprint database, and generating a matching traffic fingerprint recognition result based on the analysis result includes: Construct a traffic feature matrix according to the sample traffic data; Based on the traffic feature matrix and the graph Laplacian matrix obtained from the traffic fingerprint database, obtain the first spatio-temporal correlation value; Construct a traffic feature matrix to be identified according to the traffic data to be identified; Based on the traffic feature matrix to be identified and the graph Laplacian matrix obtained from the traffic fingerprint database, obtain the second spatio-temporal correlation value; Generate a traffic fingerprint recognition result based on the similarity ratio of the first spatio-temporal correlation value and the second spatio-temporal correlation value.
[0014] As one of the preferred solutions, after generating a matching traffic fingerprint recognition result based on the analysis result, the traffic fingerprint recognition method based on the power communication network further includes: Send the traffic fingerprint recognition result to the network security terminal; Use the preset processing library in the network security terminal to judge the traffic fingerprint recognition result and determine abnormal traffic.
[0015] Another embodiment of the present invention provides a traffic fingerprint recognition system based on a power communication network, including: An extraction module for extracting features from the sample traffic data of the target communication network obtained to obtain traffic feature data; A reconstruction module for processing the traffic feature data using a sparse algorithm to obtain a reconstructed feature signal; A processing module for processing the traffic feature signal obtained from the traffic feature data using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix; A solving module for solving the traffic expression to obtain a feature representation of the graph structure; A fusion module for fusing the reconstructed feature signal with the feature representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result; A matching module, configured to perform intelligent analysis on the traffic data to be recognized obtained from the target communication network based on the traffic fingerprint database, and generate a matching traffic fingerprint recognition result based on the analysis result.
[0016] Compared with the prior art, the beneficial effects of the embodiments of the present invention are at least one of the following: Extract feature data from the sample traffic data of the target communication network obtained; process the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal; process the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix; solve the traffic expression to obtain a feature representation of the graph structure; fuse the reconstructed feature signal and the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result; perform intelligent analysis on the traffic data to be recognized obtained from the target communication network based on the traffic fingerprint database, and generate a matching traffic fingerprint recognition result based on the analysis result. Compared with the prior art, the present invention constructs a traffic fingerprint by combining the spatio-temporal correlation characteristics of the graph Laplacian matrix with the feature signal reconstructed by the sparse algorithm, and then constructs a traffic fingerprint database, and performs traffic fingerprint recognition based on the traffic fingerprint database. By depicting the spatio-temporal coupling relationship of the traffic data in the power service scenario, accurate traffic fingerprint recognition is performed, thereby ensuring the safe development of the power communication network. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a schematic flowchart of a traffic fingerprint recognition method based on a power communication network in one embodiment of the present invention; Figure 2 is a schematic structural diagram of a traffic fingerprint recognition system based on a power communication network in one embodiment of the present invention.
[0018] REFERENCE SIGNS: Among them, 11, an extraction module; 12, a reconstruction module; 13, a processing module; 14, a solving module; 15, a fusion module; 16, a matching module. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0020] In the description of this application, the terms "first", "second", "third", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", "third", etc. may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise stated, the meaning of "a plurality" is two or more.
[0021] In the description of this application, it should be noted that unless otherwise clearly specified and defined, the terms "installed", "connected", "coupled" shall be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two components. The terms "vertical", "horizontal", "left", "right", "up", "down" and similar expressions used herein are only for the purpose of illustration and do not indicate or imply that the indicated device or element must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be understood as a limitation of the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0022] In the description of this application, it should be noted that unless otherwise defined, all technical and scientific terms used in this invention have the same meanings as those commonly understood by those skilled in the technical field to which this invention belongs. The terms used in the specification of this invention are only for the purpose of describing specific embodiments and are not intended to limit this invention. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0023] With the deep integration of smart grid and energy Internet technologies, power communication networks are developing towards the direction of high reliability, high real-time, and high security. For an artificial intelligence-enabled power communication system to achieve accurate network situation perception and active defense, it urgently needs to rely on fine-grained and multi-dimensional traffic recognition capabilities. Among them, the recognition technology based on traffic fingerprints can effectively identify the behavioral characteristics of power communication devices and detect abnormal traffic or potential attacks.
[0024] Flow fingerprint recognition needs to extract device behavior characteristics from a large amount of real-time traffic data to accurately identify abnormal traffic and potential attacks. However, the power communication network has multi-protocol heterogeneity (such as the coexistence of IEC 61850, DNP3, and TCP / IP), strong business timing constraints (interweaving of periodic telemetry and burst control instructions), and the characteristics of dynamic interaction between virtual and physical networks, resulting in the existing methods relying on rules summarized by manual experience in traffic recognition and then identifying traffic according to these rules, which will lead to inaccurate flow fingerprint recognition and further cause the power communication system to face security risks.
[0025] In view of this, an embodiment of the present invention provides a flow fingerprint recognition method based on a power communication network. Specifically, please refer to Figure 1 , Figure 1 which shows a schematic flow diagram of the flow fingerprint recognition method based on a power communication network in one embodiment of the present invention. The method includes: S1: Extract features from the sample traffic data of the target communication network to obtain traffic feature data.
[0026] Based on the target communication network, simulate and generate packets of various normal traffic and malicious traffic, and simulate the transmission process of the packets in the power communication network. At each network element node, according to the preset data collection time interval and collection time window length, obtain the traffic data of the network to be processed in the current collection period. The traffic data includes traffic time series data and event type data; among them, the traffic time series data of the deterministic network to be processed includes the time series data that can reflect the traffic characteristics of each communication node, such as the measured reported values of voltage and current; the event type data includes the power system event data used for exchange or reporting during the communication process, such as the device switch status value; the preset collection time interval can be understood as the shortest reporting period of the packets in the communication network in actual applications, and in principle, it can be set in units of milliseconds, seconds, minutes, etc. according to application requirements; the preset collection time window length is set according to actual needs, generally dozens to hundreds of times the collection time interval.
[0027] Specifically, in the power communication network, the values of various traffic data, including measurement data, usually do not follow a Gaussian distribution. Especially for event type packet data, the event status information it contains takes a small number of discrete values such as 0 and 1, which is quite different from the Gaussian distribution. In view of this, it is selected to perform a dimensional difference elimination process on this type of data, that is, scale all the indicators corresponding to the events to the range of [0,1], and convert the data to the same dimension to eliminate the influence between different dimensions.
[0028] For the time series x corresponding to the traffic data, the process of eliminating the dimensional difference is as follows: Among them, The sample traffic data has the same dimension.
[0029] Feature extraction is performed on the obtained sample traffic data of the target communication network to obtain traffic feature data, which specifically includes at least protocol, timing, statistical, and behavior pattern features.
[0030] The protocol layer features include protocol type identifiers, the mixed usage pattern of power-specific protocols (IEC 61850, DNP3, Modbus) and general protocols (TCP / IP, HTTP); source and destination address information; specific protocol fields (such as the ASDU structure of IEC 61850, the function code of DNP3); control message flag bits (such as the triggering rules of TCP SYN / FIN / RST, the UDP broadcast frequency); protocol nesting features: the protocol stack depth and interaction logic in the multi-protocol encapsulation scenario (such as the nesting relationship between TLS and power protocols in encrypted services), etc.
[0031] The timing and statistical features include time dimension features, such as the fixed reporting period of measurement traffic (such as second-level / minute-level data acquisition), the burst transmission interval of control instruction flows (such as the instantaneous burst of fault protection signals), the timing dependence relationship of multi-device collaborative operations (such as the timing matching between circuit breaker operations and relay protection), the packet size distribution (such as the mixture of short messages for control instructions and long messages for telemetry data), the traffic throughput fluctuation pattern (such as the mutation of renewable energy monitoring traffic caused by new energy access), the traffic directionality (such as the asymmetry between the downstream control flow from the master station to the sub-station and the upstream status flow from the sub-station to the master station), etc.
[0032] The behavior pattern features include device interaction patterns, such as the request-response pattern (such as the regular polling and event-triggered response of smart meters), broadcast / multicast behaviors (such as the network-wide broadcast characteristics of fault recording data), the communication behavior baselines of device types (such as the high-frequency synchronous sampling data stream of PMUs), and the relevance of business scenarios (such as the linkage characteristics between load control instructions and real-time electricity price signals), etc.
[0033] S2: Process the traffic feature data using a sparse algorithm to obtain a reconstructed feature signal.
[0034] Specifically, input the traffic feature data into the encoding end of an autoencoder constructed based on a sparse algorithm for training to obtain a traffic feature signal, process the traffic feature signal using a sparse representation layer to obtain a linear sparse representation of the traffic feature signal, and input the linear sparse representation into the decoder of the sparse autoencoder to obtain a reconstructed feature signal.
[0035] In this embodiment, let and represent training data and test data respectively, where , m and n represent the data dimensions after feature extraction, the sampling length of the training data, and the sampling length of the test data respectively. represents the union of the current training set and the test set, As the feature signal after the encoding end of the autoencoder constructed based on the sparse algorithm, then, in the inserted sparse representation layer in the middle, the following optimization problem is used to find In The sparse representation on: where represents the sparse representation matrix, is a regularization parameter greater than 0.
[0036] After completing the above optimization process, a linear sparse representation of the feature signal Z is obtained.
[0037] Next, use this linear sparse representation as the input to the decoder of the autoencoder.
[0038] The output of the sparse representation can be expressed as: where, represents the identity matrix, , respectively represent the estimation of the feature signal of the training data and the feature signal of the test data. Therefore, the input to the decoder can be expressed as: where , and where, represents the extension of the sparse representation matrix A. Therefore, integrating the autoencoder and the sparse representation layer, its end-to-end training objective can be expressed as where represents the set of all training parameters, including the parameters of the encoder, decoder, and ; , represent sparse regularization parameters greater than 0, and F represents the Frobenius norm, which is used to measure the matrix difference. Among them, the parameters of the encoder and decoder can be set according to specific scenarios to integrate multiple convolutional / deconvolutional layers to achieve performance optimization.
[0039] In the actual network, we do not make specific restrictions on the encoder and decoder. When implementing, multiple convolutional / deconvolutional layers can be integrated to achieve performance optimization.
[0040] After the training of the codec and the sparse representation layer is completed, the parameters of each layer of the codec can be fixed. At this time, the output of the sparse autoencoder is the reconstructed feature signal.
[0041] This feature signal is not sufficient to show the spatio-temporal correlation between traffic data of the same application type. In order to accurately characterize the spatio-temporal coupling relationship of traffic data in the power service scenario and perform accurate traffic fingerprint recognition, it is also necessary to use the spatio-temporal correlation characteristics based on the graph Laplacian matrix for fusion to construct a traffic fingerprint database.
[0042] S3: Process the traffic feature signal obtained from the traffic feature data by using the topological structure constructed based on the graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix.
[0043] Before processing the traffic feature signal obtained from the traffic feature data by using the topological structure constructed based on the graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix, calculate the graph Laplacian matrix. The graph Laplacian matrix is a matrix representation of a graph, which can effectively reflect the topological structure of the graph and the relationship between nodes. In the power communication network, nodes (such as devices, sensors, etc.) are connected to each other through traffic feature data, forming a complex network structure with spatio-temporal correlation characteristics. The graph Laplacian matrix can capture this structural information and provide a basis for subsequent traffic fingerprint recognition.
[0044] Specifically, the calculation process is as follows: Construct an adjacency matrix based on the traffic feature data; calculate the degree of each traffic feature node in the adjacency matrix by using the Pearson correlation coefficient, and construct a degree matrix based on the degree; obtain the graph Laplacian matrix based on the adjacency matrix and the degree matrix.
[0045] For a large and complex network such as the power communication network, it may be very difficult to directly process the relationship between nodes and edges. The graph Laplacian matrix, as a compact matrix representation form, can conveniently process the relationship between nodes and edges in a large-scale network, improving the computational efficiency and scalability of the algorithm.
[0046] Map the traffic feature signal to the nodes or edges of the graph by using the graph theory algorithm, which can be achieved by taking the signal value as the attribute of the node or edge. Use the graph Laplacian matrix and the mapped traffic feature signal to construct a traffic expression corresponding to the graph Laplacian matrix.
[0047] S4: Solve the traffic expression to obtain the feature representation of the graph structure.
[0048] In step S4, the solution process includes: Classify the range of the flow expression to obtain a first flow expression and a second flow expression; Perform eigenvalue decomposition on the first flow expression to obtain a first feature representation; Use the iterative method to solve the second flow expression to obtain a second feature representation; Perform sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure.
[0049] Among them, the flow expression corresponds to the graph Laplacian matrix. According to the scale of the graph Laplacian matrix, a first flow expression corresponding to a small scale and a second flow expression corresponding to a large scale are obtained respectively.
[0050] Perform eigenvalue decomposition on the first flow expression to obtain a first feature representation; use the iterative method (such as the Lanczos algorithm) to solve the second flow expression to obtain a second feature representation, and perform sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure, that is, the eigenvalues and eigenvectors of the graph Laplacian matrix.
[0051] It should also be noted that the sparse matrix optimization can not only process the first feature representation and the second feature representation to obtain the feature representation of the graph structure, but also optimize the calculation efficiency of the eigenvalue decomposition.
[0052] S5: Fuse the reconstructed feature signal with the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result.
[0053] Specifically, the fusion process includes calculating the weight coefficients of the reconstructed feature signal and the feature representation of the graph structure respectively by using the entropy weight method; based on the weight coefficients, fuse the reconstructed feature signal and the feature representation of the graph structure.
[0054] Based on the fusion result, jointly form a traffic fingerprint, and store the fingerprint indexed by the application type to form a traffic fingerprint database for a specific power communication network.
[0055] It should also be noted that before fusing the reconstructed feature signal with the feature representation of the graph structure, it is necessary to perform mapping processing on the reconstructed feature signal and the feature representation of the graph structure, that is, perform mapping processing on the reconstructed feature signal and the feature representation of the graph structure through linear transformation to obtain the reconstructed feature signal and the feature representation of the graph structure with the same dimension.
[0056] S6: Based on the traffic fingerprint database, perform intelligent analysis on the traffic data to be recognized obtained from the target communication network, and generate a matching traffic fingerprint recognition result based on the analysis result.
[0057] Specifically, a traffic feature matrix is constructed based on the sample traffic data, and a first spatio-temporal correlation value is obtained based on the traffic feature matrix and the Laplacian matrix obtained from the traffic fingerprint database, that is A traffic feature matrix to be recognized is constructed according to the traffic data to be recognized, and a second spatio-temporal correlation value is obtained based on the traffic feature matrix to be recognized and the Laplacian matrix obtained from the traffic fingerprint database, that is Wherein, L represents the Laplacian matrix.
[0058] Based on the similarity ratio of the first spatio-temporal correlation value and the second spatio-temporal correlation value, when the ratio is greater than a specific value, it indicates that the current traffic data is unlikely to conform to the inherent spatio-temporal correlation characteristics of the current traffic, and it is determined that the current traffic is abnormal or malicious traffic. When the ratio is less than the specific value, it indicates that the current traffic data is likely to conform to the inherent spatio-temporal correlation characteristics of the current traffic, and it is determined that the current traffic is normal traffic. A traffic fingerprint recognition result is generated based on the malicious traffic result and the normal traffic result.
[0059] Specifically, after generating a matching traffic fingerprint recognition result based on the analysis result, the traffic fingerprint recognition result is sent to the network security terminal; the traffic fingerprint recognition result is judged by using a preset processing library in the network security terminal to determine abnormal traffic.
[0060] According to the determined abnormal traffic, it is saved to the recording terminal in the traffic fingerprint database.
[0061] An embodiment of the present invention provides a traffic fingerprint recognition system based on a power communication network. Specifically, please refer to Figure 2 , Figure 2 which shows a structural schematic diagram of traffic fingerprint recognition in one of the embodiments of the present invention. The system includes: An extraction module 11, configured to extract features from the obtained sample traffic data of the target communication network to obtain traffic feature data; A reconstruction module 12, configured to process the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal; A processing module 13, configured to process the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the Laplacian matrix; A solving module 14, configured to solve the traffic expression to obtain a feature representation of the graph structure; A fusion module 15, configured to fuse the reconstructed feature signal and the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result; A matching module 16, configured to perform intelligent analysis on the to-be-identified traffic data obtained from the target communication network based on the traffic fingerprint database, and generate a matching traffic fingerprint recognition result based on the analysis result.
[0062] Compared with the prior art, the beneficial effects of the embodiments of the present invention are at least one of the following: Extract feature data of traffic from the obtained sample traffic data of the target communication network to obtain traffic feature data; process the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal; process the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to a graph Laplacian matrix; solve the traffic expression to obtain a feature representation of the graph structure; fuse the reconstructed feature signal and the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result; perform intelligent analysis on the to-be-identified traffic data obtained from the target communication network based on the traffic fingerprint database, and generate a matching traffic fingerprint recognition result based on the analysis result. Compared with the prior art, the present invention constructs a traffic fingerprint by combining the spatio-temporal correlation characteristics of the graph Laplacian matrix and the feature signal reconstructed by the sparse algorithm, and further constructs a traffic fingerprint database, and performs traffic fingerprint recognition based on the traffic fingerprint database. By depicting the spatio-temporal coupling relationship of traffic data in the power service scenario, accurate traffic fingerprint recognition is performed, thereby ensuring the safe development of the power communication network.
[0063] The above embodiments merely represent several implementation manners of the present invention, and the description thereof is relatively specific and detailed, but should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the appended claims.
Claims
1. A flow fingerprint recognition method based on power communication network, characterized in that: include: Extracting features from the sample traffic data of the acquired target communication network to obtain traffic feature data; Processing the flow characteristic data using a sparse algorithm to obtain a reconstructed characteristic signal; Processing the flow characteristic signal obtained from the flow characteristic data using a topological structure constructed based on a graph theory algorithm to obtain a flow expression corresponding to a graph Laplacian matrix; Solving the flow expression to obtain a characteristic representation of the graph structure; Fusing the reconstructed characteristic signal with the characteristic representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result; Based on the traffic fingerprint database, intelligent analysis is performed on the traffic data to be identified obtained from the target communication network, and a matching traffic fingerprint identification result is generated based on the analysis result.
2. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: Before extracting features from the sample traffic data of the acquired target communication network, the traffic fingerprint recognition method based on the power communication network further includes: Acquiring traffic data of the same application type in the target communication network; The flow data is converted into a multivariate time series, and dimension difference elimination processing is performed on the multivariate time series to obtain sample flow data with the same dimension.
3. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: The flow characteristic data is processed by using a sparse algorithm to obtain a reconstructed characteristic signal, and the processing process includes: The flow characteristic data is input into an autoencoder encoding end constructed based on a sparse algorithm for training to obtain a flow characteristic signal; Processing the flow characteristic signal by using a sparse representation layer to obtain a linear sparse representation of the flow characteristic signal; The linear sparse representation is input into a sparse autoencoder decoder to obtain the reconstructed feature signal.
4. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: Before processing the flow characteristic signal obtained from the flow characteristic data by using the topological structure constructed based on the graph theory algorithm to obtain the flow expression corresponding to the graph Laplacian matrix, the flow fingerprint recognition method based on the power communication network also includes: Constructing an adjacency matrix based on the traffic characteristic data; Calculating the degree of each traffic feature node in the adjacency matrix using the Pearson correlation coefficient, and constructing a degree matrix based on the degree; The graph Laplacian matrix is obtained based on the adjacency matrix and the degree matrix.
5. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: The step of solving the flow expression to obtain a characteristic representation of a graph structure includes: Performing range classification on the flow expression to obtain a first flow expression and a second flow expression; Performing eigenvalue decomposition on the first flow expression to obtain a first characteristic representation; Solving the second flow expression by using an iterative method to obtain a second characteristic representation; Sparse matrix optimization is performed on the first feature representation and the second feature representation to obtain a feature representation of the graph structure.
6. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: Before fusing the reconstructed characteristic signal with the characteristic representation of the graph structure, the flow fingerprint recognition method based on the power communication network further includes: The reconstructed feature signal and the feature representation of the graph structure are mapped to each other through linear transformation to obtain the reconstructed feature signal and the feature representation of the graph structure having the same dimension.
7. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: The reconstructed feature signal is fused with the feature representation of the graph structure, and the fusion process includes: Calculating weight coefficients of the reconstructed feature signal and the feature representation of the graph structure respectively using an entropy weight method; Based on the weight coefficient, the reconstructed feature signal is fused with the feature representation of the graph structure.
8. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: Based on the traffic fingerprint database, intelligently analyzing the traffic data to be identified obtained from the target communication network, and generating a matching traffic fingerprint identification result based on the analysis result, includes: Constructing a flow characteristic matrix according to the sample flow data; Obtaining a first spatiotemporal correlation value based on the traffic feature matrix and a graph Laplacian matrix obtained from the traffic fingerprint database; Constructing a traffic feature matrix to be identified according to the traffic data to be identified; Obtaining a second spatiotemporal correlation value based on the traffic feature matrix to be identified and the graph Laplacian matrix obtained from the traffic fingerprint database; A traffic fingerprint recognition result is generated based on a similarity ratio between the first spatiotemporal correlation value and the second spatiotemporal correlation value.
9. The flow fingerprint identification method based on the power communication network according to claim 1 is characterized in that: After generating a matching traffic fingerprint recognition result based on the analysis result, the traffic fingerprint recognition method based on the power communication network further includes: Sending the traffic fingerprint identification result to the network security terminal; The traffic fingerprint recognition result is judged by using a processing library preset in the network security terminal to determine abnormal traffic.
10. A flow fingerprint recognition system based on power communication network, characterized in that: include: An extraction module is used to extract features from the sample traffic data of the target communication network to obtain traffic feature data; A reconstruction module, used for processing the flow characteristic data using a sparse algorithm to obtain a reconstructed characteristic signal; A processing module, used to process the flow characteristic signal obtained from the flow characteristic data using a topological structure constructed based on a graph theory algorithm to obtain a flow expression corresponding to a graph Laplacian matrix; A solution module, used for solving the flow expression to obtain a characteristic representation of a graph structure; A fusion module, used to fuse the reconstructed characteristic signal with the characteristic representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result; The matching module is used to perform intelligent analysis on the traffic data to be identified obtained from the target communication network based on the traffic fingerprint database, and generate a matching traffic fingerprint identification result based on the analysis result.
Citation Information
Patent Citations
A communication fingerprint identification method integrating multi-layer sparse learning and multi-view-angle learning
CN109829352A
Abnormal traffic detection method and system, and computer storage medium
CN115606162A
Power Internet of Things anomaly detection method and system based on hypergraph fusion
CN119337326A
Network access anomaly detection via graph embedding
WO2023014497A1