A traffic fingerprint recognition method and system based on a power communication network
By performing feature extraction, sparse algorithm processing and graph theory algorithm construction on the traffic data of the power communication network, the traffic expression of the graph Laplace matrix is generated, which solves the problem of inaccurate traffic fingerprint recognition in the traditional method and realizes the security guarantee of the power communication network.
Patent Information
- Application Number
- CN202510534822.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-27
AI Technical Summary
In the prior art, traditional traffic fingerprint recognition relies on rules summarized by manual experience, resulting in inaccurate traffic fingerprint recognition of power communication networks and poses security risks.
By extracting the sample traffic data of the power communication network feature, using sparse algorithm and graph theory algorithm to build a topological structure, generating traffic expressions of the graph Laplace matrix, and performing feature representation fusion, building a traffic fingerprint database, and performing intelligent analysis to generate matching traffic fingerprint recognition results.
It improves the accuracy of traffic fingerprint recognition, ensures the security of the power communication network, and realizes effective detection of abnormal traffic and potential attacks.
Smart Images

Figure CN120086801B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network traffic analysis, and in particular to a traffic fingerprint recognition method and system based on a power communication network. Background Art
[0002] With the deep integration of smart grid and energy Internet technologies, the power communication network is developing towards high reliability, high real-time, and high security. Among them, the recognition technology based on traffic fingerprints can effectively identify the behavioral characteristics of power communication devices and detect abnormal traffic or potential attacks.
[0003] In the prior art, traditional traffic fingerprint recognition relies on rules summarized by manual experience, and then identifies traffic according to this rule, which will lead to inaccurate traffic fingerprint recognition, and further cause the power communication system to face security risks.
[0004] Therefore, how to improve the accuracy of traffic fingerprint recognition and ensure the safe development of the power communication network has become a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention
[0005] The present invention provides a traffic fingerprint recognition method and system based on a power communication network to improve the accuracy of traffic fingerprint recognition and achieve the effect of ensuring the safe development of the power communication network.
[0006] To solve the above technical problem, an embodiment of the present invention provides a traffic fingerprint recognition method based on a power communication network, including:
[0007] Performing feature extraction on the acquired sample traffic data of the target communication network to obtain traffic feature data;
[0008] Processing the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal;
[0009] Processing the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to a graph Laplacian matrix;
[0010] Solving the traffic expression to obtain a feature representation of the graph structure;
[0011] Fusing the reconstructed feature signal and the feature representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result;
[0012] Based on the traffic fingerprint database, performing intelligent analysis on the traffic data to be recognized obtained from the target communication network, and generating a matching traffic fingerprint recognition result based on the analysis result.
[0013] As one of the preferred solutions, before extracting features from the sampled traffic data of the target communication network, the traffic fingerprint recognition method based on the power communication network further includes:
[0014] Obtain the traffic data with the same application type in the target communication network;
[0015] Convert the traffic data into a multivariate time series, and perform a dimension difference elimination process on the multivariate time series to obtain the sampled traffic data with the same dimension.
[0016] As one of the preferred solutions, the process of using the sparse algorithm to process the traffic feature data to obtain the reconstructed feature signal includes:
[0017] Input the traffic feature data into the encoding end of the autoencoder constructed based on the sparse algorithm for training to obtain the traffic feature signal;
[0018] Use the sparse representation layer to process the traffic feature signal to obtain the linear sparse representation of the traffic feature signal;
[0019] Input the linear sparse representation into the decoder of the sparse autoencoder to obtain the reconstructed feature signal.
[0020] As one of the preferred solutions, before using the topological structure constructed based on the graph theory algorithm to process the traffic feature signal obtained from the traffic feature data to obtain the traffic expression corresponding to the graph Laplacian matrix, the traffic fingerprint recognition method based on the power communication network further includes:
[0021] Construct an adjacency matrix based on the traffic feature data;
[0022] Use the Pearson correlation coefficient to calculate the degree of each traffic feature node in the adjacency matrix, and construct a degree matrix based on the degree;
[0023] Based on the adjacency matrix and the degree matrix, obtain the graph Laplacian matrix.
[0024] As one of the preferred solutions, the process of solving the traffic expression to obtain the feature representation of the graph structure includes:
[0025] Perform range classification on the traffic expression to obtain a first traffic expression and a second traffic expression;
[0026] Perform eigenvalue decomposition on the first traffic expression to obtain a first feature representation;
[0027] Use the iterative method to solve the second traffic expression to obtain a second feature representation;
[0028] Perform sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure.
[0029] As one of the preferred solutions, before fusing the reconstructed feature signal with the feature representation of the graph structure, the traffic fingerprint recognition method based on the power communication network further includes:
[0030] Perform mapping processing on the reconstructed feature signal and the feature representation of the graph structure through linear transformation to obtain the reconstructed feature signal and the feature representation of the graph structure with the same dimension.
[0031] As one of the preferred solutions, the process of fusing the reconstructed feature signal with the feature representation of the graph structure includes:
[0032] Use the entropy weight method to calculate the weight coefficients of the reconstructed feature signal and the feature representation of the graph structure respectively;
[0033] Based on the weight coefficients, fuse the reconstructed feature signal and the feature representation of the graph structure.
[0034] As one of the preferred solutions, the intelligent analysis of the traffic data to be recognized obtained from the target communication network based on the traffic fingerprint database and the generation of a matching traffic fingerprint recognition result based on the analysis result include:
[0035] Construct a traffic feature matrix according to the sample traffic data;
[0036] Based on the traffic feature matrix and the graph Laplacian matrix obtained from the traffic fingerprint database, obtain the first spatio-temporal correlation value;
[0037] Construct a traffic feature matrix to be recognized according to the traffic data to be recognized;
[0038] Based on the traffic feature matrix to be recognized and the graph Laplacian matrix obtained from the traffic fingerprint database, obtain the second spatio-temporal correlation value;
[0039] Generate a traffic fingerprint recognition result based on the similarity ratio of the first spatio-temporal correlation value and the second spatio-temporal correlation value.
[0040] As one of the preferred solutions, after generating a matching traffic fingerprint recognition result based on the analysis result, the traffic fingerprint recognition method based on the power communication network further includes:
[0041] Send the traffic fingerprint recognition result to the network security terminal;
[0042] Use the preset processing library in the network security terminal to judge the traffic fingerprint recognition result and determine abnormal traffic.
[0043] Another embodiment of the present invention provides a traffic fingerprint recognition system based on a power communication network, including:
[0044] An extraction module for extracting features from the acquired sample traffic data of the target communication network to obtain traffic feature data;
[0045] A reconstruction module for processing the traffic feature data using a sparse algorithm to obtain a reconstructed feature signal;
[0046] A processing module for processing the traffic feature signal obtained from the traffic feature data using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix;
[0047] A solution module for solving the traffic expression to obtain a feature representation of the graph structure;
[0048] A fusion module for fusing the reconstructed feature signal and the feature representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result;
[0049] A matching module for intelligently analyzing the traffic data to be recognized obtained from the target communication network based on the traffic fingerprint database, and generating a matching traffic fingerprint recognition result based on the analysis result.
[0050] Compared with the prior art, the beneficial effects of the embodiments of the present invention are at least one of the following:
[0051] Extract features from the sampled traffic data of the target communication network to obtain traffic feature data; process the traffic feature data using a sparse algorithm to obtain a reconstructed feature signal; process the traffic feature signal obtained from the traffic feature data using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix; solve the traffic expression to obtain a feature representation of the graph structure; fuse the reconstructed feature signal and the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result; based on the traffic fingerprint database, perform intelligent analysis on the traffic data to be recognized obtained from the target communication network, and generate a matching traffic fingerprint recognition result based on the analysis result. Compared with the prior art, the present invention constructs a traffic fingerprint by combining the spatio-temporal correlation characteristics of the graph Laplacian matrix and the feature signal reconstructed by the sparse algorithm, and then constructs a traffic fingerprint database, and performs traffic fingerprint recognition based on the traffic fingerprint database. By characterizing the spatio-temporal coupling relationship of traffic data in the power service scenario, accurate traffic fingerprint recognition is performed, thereby ensuring the safe development of the power communication network. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 is a schematic flowchart of a traffic fingerprint recognition method based on a power communication network in one embodiment of the present invention;
[0053] Figure 2 is a schematic structural diagram of a traffic fingerprint recognition system based on a power communication network in one embodiment of the present invention.
[0054] Reference Signs:
[0055] Among them, 11, extraction module; 12, reconstruction module; 13, processing module; 14, solution module; 15, fusion module; 16, matching module. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0056] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.
[0057] In the description of this application, the terms "first", "second", "third", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", "third", etc. may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise specified, the meaning of "a plurality" is two or more.
[0058] In the description of this application, it should be noted that, unless otherwise clearly specified and defined, the terms "installed", "connected", "coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two elements. The terms "vertical", "horizontal", "left", "right", "up", "down" and similar expressions used herein are only for illustrative purposes and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be construed as a limitation on the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0059] In the description of this application, it should be noted that, unless otherwise defined, all technical and scientific terms used in this invention have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs. The terms used in the specification of this invention are only for the purpose of describing specific embodiments and are not intended to limit this invention. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0060] With the deep integration of smart grid and energy Internet technologies, power communication networks are developing towards the direction of high reliability, high real-time, and high security. For an artificial intelligence-enabled power communication system to achieve accurate network situation perception and active defense, it urgently needs to rely on fine-grained and multi-dimensional traffic recognition capabilities. Among them, the recognition technology based on traffic fingerprints can effectively identify the behavior characteristics of power communication devices and detect abnormal traffic or potential attacks.
[0061] Flow fingerprint recognition needs to extract device behavior characteristics from a large amount of real-time traffic data to accurately identify abnormal traffic and potential attacks. However, the power communication network has multi-protocol heterogeneity (such as the coexistence of IEC 61850, DNP3, and TCP / IP), strong business timing constraints (the interweaving of periodic telemetry and burst control instructions), and the dynamic interaction characteristics of virtual and physical networks, resulting in the existing methods relying on rules summarized by manual experience in traffic recognition and then identifying traffic according to this rule, which will lead to inaccurate flow fingerprint recognition and further cause the power communication system to face security risks.
[0062] In view of this, an embodiment of the present invention provides a flow fingerprint recognition method based on a power communication network. Specifically, please refer to Figure 1 , Figure 1 which shows a schematic flow diagram of the flow fingerprint recognition method based on a power communication network in one embodiment of the present invention. The method includes:
[0063] S1: Extract features from the sample traffic data of the target communication network to obtain traffic feature data.
[0064] Based on the target communication network, simulate and generate packets of various normal traffic and malicious traffic, and simulate the transmission process of the packets in the power communication network. At each network element node, according to the preset data collection time interval and collection time window length, obtain the traffic data of the network to be processed in the current collection period. The traffic data includes traffic time series data and event class data; among them, the traffic time series data of the deterministic network to be processed includes the time series data that can reflect the traffic characteristics of each communication node, such as the measured reported values of voltage and current; the event class data includes the power system event data used for exchange or reporting during the communication process, such as the device switch state value; the preset collection time interval can be understood as the shortest reporting period of the packets in the communication network in actual applications, and in principle, it can be set in units of milliseconds, seconds, minutes, etc. according to application requirements; the preset collection time window length is set according to actual needs, generally dozens to hundreds of times the collection time interval.
[0065] Specifically, in the power communication network, the values of various traffic data, including measurement data, usually do not follow a Gaussian distribution. Especially for event class packet data, the event status information it contains takes a small number of discrete values such as 0 and 1, which is quite different from the Gaussian distribution. In view of this, it is selected to perform a dimensional difference elimination process on this type of data, that is, scale all the indicators corresponding to the events to the range of [0,1] and convert the data to the same dimension to eliminate the influence between different dimensions.
[0066] For the time series x corresponding to the traffic data, the process of eliminating the dimensional difference is as follows:
[0067]
[0068] in, are sample flow data with the same dimension.
[0069] Feature extraction is performed on the sample traffic data of the acquired target communication network to obtain traffic feature data, which specifically includes at least protocol, timing, statistics and behavior pattern features.
[0070] The protocol layer features include protocol type identification, mixed use mode of power-specific protocols (IEC 61850, DNP3, Modbus) and general protocols (TCP / IP, HTTP); source and destination address information; specific protocol fields (such as the ASDU structure of IEC 61850 and the function code of DNP3); control message flags (such as the triggering rules of TCP SYN / FIN / RST and the frequency of UDP broadcasts); protocol nesting features: protocol stack depth and interaction logic in multi-protocol encapsulation scenarios (such as the nested relationship between TLS and power protocols in encryption services), etc.
[0071] Timing and statistical characteristics include time dimension characteristics, such as fixed reporting period of measurement traffic (such as second / minute data collection), burst transmission interval of control instruction flow (such as instantaneous burst of fault protection signal), timing dependency of multi-device collaborative operation (such as timing matching of circuit breaker action and relay protection), data packet size distribution (such as a mixture of short messages of control instructions and long messages of telemetry data), traffic throughput fluctuation pattern (such as sudden change of renewable energy monitoring traffic caused by new energy access), traffic directionality (such as asymmetry between the downlink control flow from master station to slave station and the uplink status flow from slave station to master station), etc.
[0072] Behavioral pattern characteristics include device interaction patterns, such as request-response patterns (such as periodic polling and event-triggered responses of smart meters), broadcast / multicast behaviors (such as the network-wide broadcast characteristics of fault recording data), communication behavior baselines of device types (such as RTU, IED, PMU) (such as the high-frequency synchronous sampling data stream of PMU), and business scenario relevance (such as the linkage characteristics of load control instructions and real-time electricity price signals).
[0073] S2: Process the traffic characteristic data using a sparse algorithm to obtain a reconstructed characteristic signal.
[0074] Specifically, the traffic feature data is input into the encoder end of the autoencoder built based on the sparse algorithm for training to obtain the traffic feature signal, the traffic feature signal is processed by the sparse representation layer to obtain the linear sparse representation of the traffic feature signal, and the linear sparse representation is input into the sparse autoencoder decoder to obtain the reconstructed feature signal.
[0075] In this embodiment, let and represent training data and test data respectively, where , m, and n represent the dimensionality of the data after feature extraction, the sampling length of the training data, and the sampling length of the test data respectively. Let represent the union of the current training set and the test set, as the feature signal after passing through the encoding end of the autoencoder constructed based on the sparse algorithm. Then, in the inserted sparse representation layer in the middle, the following optimization problem is used to find the sparse representation of :
[0076]
[0077] where represents the sparse representation matrix, is a regularization parameter greater than 0.
[0078] After completing the above optimization process, the linear sparse representation of the feature signal Z is obtained.
[0079] Next, use this linear sparse representation as the input to the decoder of the autoencoder.
[0080] The output of the sparse representation can be expressed as:
[0081]
[0082] where, represents the identity matrix, , represent the estimates of the feature signals of the training data and the feature signals of the test data respectively. Therefore, the input to the decoder can be expressed as:
[0083]
[0084] where , and
[0085]
[0086] where, represents the extension of the sparse representation matrix A. Therefore, integrating the autoencoder and the sparse representation layer, its end-to-end training objective can be expressed as
[0087]
[0088] where represents the set of all training parameters, including the parameters of the encoder, decoder, and ; , represents a sparse regularization parameter greater than 0, and F represents the Frobenius norm, which is used to measure the matrix difference. Among them, the parameters of the encoder and decoder can be set according to specific scenarios to integrate multiple convolutional / deconvolutional layers, so as to achieve performance optimization.
[0089] In the actual network, we do not make specific restrictions on the encoder-decoder. When implementing, multiple convolutional / deconvolutional layers can be integrated to achieve performance optimization.
[0090] After the training of the encoder-decoder and the sparse representation layer is completed, the parameters of each layer of the encoder-decoder can be fixed. At this time, the output of the sparse autoencoder is the reconstructed feature signal.
[0091] This feature signal is not sufficient to show the spatio-temporal correlation between traffic data of the same application type. In order to accurately depict the spatio-temporal coupling relationship of traffic data in the power service scenario and perform accurate traffic fingerprint recognition, it is also necessary to use the spatio-temporal correlation characteristics based on the graph Laplacian matrix to fuse and construct a traffic fingerprint database.
[0092] S3: Process the traffic feature signal obtained from the traffic feature data by using the topological structure constructed based on the graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix.
[0093] Before processing the traffic feature signal obtained from the traffic feature data by using the topological structure constructed based on the graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix, calculate the graph Laplacian matrix. The graph Laplacian matrix is a matrix representation of a graph, which can effectively reflect the topological structure of the graph and the relationship between nodes. In the power communication network, nodes (such as devices, sensors, etc.) are connected to each other through traffic feature data, forming a complex network structure with spatio-temporal correlation characteristics. The graph Laplacian matrix can capture this structural information and provide a basis for subsequent traffic fingerprint recognition.
[0094] Specifically, the calculation process is as follows:
[0095] Construct an adjacency matrix based on the traffic feature data; calculate the degree of each traffic feature node in the adjacency matrix by using the Pearson correlation coefficient, and construct a degree matrix based on the degree; obtain the graph Laplacian matrix based on the adjacency matrix and the degree matrix.
[0096] For a large and complex network such as a power communication network, it may be very difficult to directly process the relationship between nodes and edges. The graph Laplacian matrix, as a compact matrix representation form, can conveniently process the relationship between nodes and edges in a large-scale network, improving the computational efficiency and scalability of the algorithm.
[0097] The traffic feature signal is mapped to the nodes or edges of a graph using graph theory algorithms, which can be achieved by taking the signal values as the attributes of the nodes or edges. Using the graph Laplacian matrix and the mapped traffic feature signal, a traffic expression corresponding to the graph Laplacian matrix is constructed.
[0098] S4: Solve the traffic expression to obtain the feature representation of the graph structure.
[0099] In step S4, the solution process includes:
[0100] Classify the range of the traffic expression to obtain a first traffic expression and a second traffic expression;
[0101] Perform eigenvalue decomposition on the first traffic expression to obtain a first feature representation;
[0102] Use an iterative method to solve the second traffic expression to obtain a second feature representation;
[0103] Perform sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure.
[0104] Among them, the traffic expression corresponds to the graph Laplacian matrix. According to the scale of the graph Laplacian matrix, a first traffic expression corresponding to a small scale and a second traffic expression corresponding to a large scale are obtained respectively.
[0105] Perform eigenvalue decomposition on the first traffic expression to obtain a first feature representation; use an iterative method (such as the Lanczos algorithm) to solve the second traffic expression to obtain a second feature representation, and perform sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure, that is, the eigenvalues and eigenvectors of the graph Laplacian matrix.
[0106] It should also be noted that sparse matrix optimization can not only process the first feature representation and the second feature representation to obtain the feature representation of the graph structure, but also optimize the computational efficiency of eigenvalue decomposition.
[0107] S5: Fuse the reconstructed feature signal with the feature representation of the graph structure, and construct the traffic fingerprint database of the target communication network based on the fusion result.
[0108] Specifically, the fusion process includes calculating the weight coefficients of the reconstructed feature signal and the feature representation of the graph structure respectively using the entropy weight method; based on the weight coefficients, fuse the reconstructed feature signal and the feature representation of the graph structure.
[0109] Based on the fusion results, they jointly constitute a traffic fingerprint, and this fingerprint is stored with the application type as the index to form a traffic fingerprint database for a specific power communication network.
[0110] It should also be noted that before fusing the reconstructed feature signal and the feature representation of the graph structure, a mapping process needs to be performed on the reconstructed feature signal and the feature representation of the graph structure, that is, the reconstructed feature signal and the feature representation of the graph structure are mapped through a linear transformation to obtain the reconstructed feature signal and the feature representation of the graph structure with the same dimension.
[0111] S6: Based on the traffic fingerprint database, perform intelligent analysis on the traffic data to be recognized obtained from the target communication network, and generate a matching traffic fingerprint recognition result based on the analysis result.
[0112] Specifically, construct a traffic feature matrix according to the sample traffic data, and based on the traffic feature matrix and the graph Laplacian matrix obtained from the traffic fingerprint database, obtain the first spatio-temporal correlation value, that is
[0113]
[0114] Construct a traffic feature matrix to be recognized according to the traffic data to be recognized, and based on the traffic feature matrix to be recognized and the graph Laplacian matrix obtained from the traffic fingerprint database, obtain the second spatio-temporal correlation value, that is
[0115]
[0116] Among them, L represents the graph Laplacian matrix.
[0117] Based on the similarity ratio of the first spatio-temporal correlation value and the second spatio-temporal correlation value, when the ratio is greater than a specific value, it indicates that the current traffic data is likely to not conform to the inherent spatio-temporal correlation characteristics of the current traffic, and it is determined that the current traffic is abnormal or malicious traffic. When the ratio is less than a specific value, it indicates that the current traffic data is likely to conform to the inherent spatio-temporal correlation characteristics of the current traffic, and it is determined that the current traffic is normal traffic. Generate a traffic fingerprint recognition result based on the malicious traffic result and the normal traffic result.
[0118] Specifically, after generating a matching traffic fingerprint recognition result based on the analysis result, send the traffic fingerprint recognition result to the network security terminal; use the preset processing library in the network security terminal to judge the traffic fingerprint recognition result to determine abnormal traffic.
[0119] According to the determined abnormal traffic, save it to the record terminal in the traffic fingerprint database.
[0120] An embodiment of the present invention provides a traffic fingerprint recognition system based on a power communication network. Specifically, please refer to Figure 2 , Figure 2 which shows a schematic structural diagram of traffic fingerprint recognition in one of the embodiments of the present invention. The system includes:
[0121] An extraction module 11, configured to extract features from the acquired sample traffic data of the target communication network to obtain traffic feature data;
[0122] A reconstruction module 12, configured to process the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal;
[0123] A processing module 13, configured to process the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to a graph Laplacian matrix;
[0124] A solving module 14, configured to solve the traffic expression to obtain a feature representation of the graph structure;
[0125] A fusion module 15, configured to fuse the reconstructed feature signal and the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result;
[0126] A matching module 16, configured to perform intelligent analysis on the traffic data to be recognized obtained from the target communication network based on the traffic fingerprint database, and generate a matching traffic fingerprint recognition result based on the analysis result.
[0127] Compared with the prior art, the beneficial effects of the embodiment of the present invention are at least one of the following:
[0128] Extract features from the sample traffic data of the target communication network to obtain traffic feature data; use a sparse algorithm to process the traffic feature data to obtain a reconstructed feature signal; use the topological structure constructed based on the graph theory algorithm to process the traffic feature signal obtained from the traffic feature data to obtain a traffic expression corresponding to the graph Laplacian matrix; solve the traffic expression to obtain a feature representation of the graph structure; fuse the reconstructed feature signal with the feature representation of the graph structure, and construct a traffic fingerprint database of the target communication network based on the fusion result; based on the traffic fingerprint database, perform intelligent analysis on the traffic data to be recognized obtained from the target communication network, and generate a matching traffic fingerprint recognition result based on the analysis result. Compared with the prior art, the present invention constructs a traffic fingerprint by combining the spatio-temporal correlation characteristics of the graph Laplacian matrix with the feature signal reconstructed by the sparse algorithm, and then constructs a traffic fingerprint database, and performs traffic fingerprint recognition based on the traffic fingerprint database. By depicting the spatio-temporal coupling relationship of traffic data in the power service scenario, accurate traffic fingerprint recognition is performed, thereby ensuring the safe development of the power communication network.
[0129] The above embodiments only represent several implementation manners of the present invention, and the description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the invention patent of the present invention shall be subject to the appended claims.
Claims
1. A traffic fingerprint recognition method based on a power communication network, characterized in that Including: Performing feature extraction on the sampled traffic data of the target communication network to obtain traffic feature data; Processing the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal; Processing the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to a graph Laplacian matrix; Solving the traffic expression to obtain a feature representation of the graph structure, including: classifying the range of the traffic expression to obtain a first traffic expression and a second traffic expression; Performing eigenvalue decomposition on the first traffic expression to obtain a first feature representation; Solving the second traffic expression by using an iterative method to obtain a second feature representation; Performing sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure; Fusing the reconstructed feature signal and the feature representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result; Based on the traffic fingerprint database, performing intelligent analysis on the traffic data to be identified obtained from the target communication network, and generating a matching traffic fingerprint recognition result based on the analysis result, including: constructing a traffic feature matrix according to the sampled traffic data; Obtaining a first spatio-temporal correlation value based on the traffic feature matrix and the graph Laplacian matrix obtained from the traffic fingerprint database; Constructing a traffic feature matrix to be identified according to the traffic data to be identified; Obtaining a second spatio-temporal correlation value based on the traffic feature matrix to be identified and the graph Laplacian matrix obtained from the traffic fingerprint database; Generating a traffic fingerprint recognition result based on the similarity ratio of the first spatio-temporal correlation value and the second spatio-temporal correlation value.
2. The traffic fingerprint recognition method based on a power communication network according to claim 1, wherein Before performing feature extraction on the sampled traffic data of the target communication network, the traffic fingerprint recognition method based on a power communication network further includes: Obtaining traffic data with the same application type in the target communication network; Converting the traffic data into a multivariate time series, and performing dimension difference elimination processing on the multivariate time series to obtain sampled traffic data with the same dimension.
3. The traffic fingerprint recognition method based on a power communication network according to claim 1, characterized in that The process of processing the traffic feature data by using a sparse algorithm to obtain a reconstructed feature signal includes: Inputting the traffic feature data into an encoder end of an autoencoder constructed based on a sparse algorithm for training to obtain a traffic feature signal; Processing the traffic feature signal by using a sparse representation layer to obtain a linear sparse representation of the traffic feature signal; Inputting the linear sparse representation into a decoder of a sparse autoencoder to obtain the reconstructed feature signal.
4. The traffic fingerprint recognition method based on a power communication network according to claim 1, wherein Before processing the traffic feature signal obtained from the traffic feature data by using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to a graph Laplacian matrix, the traffic fingerprint recognition method based on a power communication network further includes: Constructing an adjacency matrix based on the traffic feature data; Calculating the degree of each traffic feature node in the adjacency matrix by using a Pearson correlation coefficient, and constructing a degree matrix based on the degree; Based on the adjacency matrix and the degree matrix, the graph Laplacian matrix is obtained.
5. The traffic fingerprint recognition method based on a power communication network according to claim 1, wherein Before fusing the reconstructed feature signal and the feature representation of the graph structure, the traffic fingerprint recognition method based on the power communication network further includes: The reconstructed feature signal and the feature representation of the graph structure are subjected to a mapping process through a linear transformation to obtain the reconstructed feature signal and the feature representation of the graph structure with the same dimension.
6. The traffic fingerprint recognition method based on a power communication network according to claim 1, characterized in that The process of fusing the reconstructed feature signal and the feature representation of the graph structure includes: Using the entropy weight method to calculate the weight coefficients of the reconstructed feature signal and the feature representation of the graph structure respectively; Based on the weight coefficients, the reconstructed feature signal and the feature representation of the graph structure are fused.
7. The traffic fingerprint recognition method based on a power communication network according to claim 1, characterized in that, After generating a matching traffic fingerprint recognition result based on the analysis result, the traffic fingerprint recognition method based on the power communication network further includes: Sending the traffic fingerprint recognition result to the network security terminal; Using the preset processing library in the network security terminal to judge the traffic fingerprint recognition result to determine abnormal traffic.
8. A traffic fingerprint recognition system based on a power communication network, characterized in that, Including: An extraction module for extracting features from the acquired sample traffic data of the target communication network to obtain traffic feature data; A reconstruction module for processing the traffic feature data using a sparse algorithm to obtain a reconstructed feature signal; A processing module for processing the traffic feature signal obtained from the traffic feature data using a topological structure constructed based on a graph theory algorithm to obtain a traffic expression corresponding to the graph Laplacian matrix; A solution module for solving the traffic expression to obtain the feature representation of the graph structure, including: classifying the range of the traffic expression to obtain a first traffic expression and a second traffic expression; performing eigenvalue decomposition on the first traffic expression to obtain a first feature representation; using an iterative method to solve the second traffic expression to obtain a second feature representation; performing sparse matrix optimization on the first feature representation and the second feature representation to obtain the feature representation of the graph structure; A fusion module for fusing the reconstructed feature signal and the feature representation of the graph structure, and constructing a traffic fingerprint database of the target communication network based on the fusion result; A matching module for performing intelligent analysis on the traffic data to be recognized obtained from the target communication network based on the traffic fingerprint database, and generating a matching traffic fingerprint recognition result based on the analysis result, including: constructing a traffic feature matrix according to the sample traffic data; Based on the traffic feature matrix and the graph Laplacian matrix obtained from the traffic fingerprint database, a first spatio-temporal correlation value is obtained; Constructing a traffic feature matrix to be recognized according to the traffic data to be recognized; Based on the traffic feature matrix to be recognized and the graph Laplacian matrix obtained from the traffic fingerprint database, a second spatio-temporal correlation value is obtained; Based on the similarity ratio of the first spatio-temporal correlation value and the second spatio-temporal correlation value, a traffic fingerprint recognition result is generated.
Citation Information
Patent Citations
A communication fingerprint identification method integrating multi-layer sparse learning and multi-view-angle learning
CN109829352A
Abnormal traffic detection method and system, and computer storage medium
CN115606162A