Distributed boundary network threat flow detection method based on GCN model

By applying the GCN model in the detection of boundary network threat traffic for real-time analysis of the embedding of BGP network topology map and path change difference scores, the problems of difficulty in manually configuring information and poor model interpretability in the existing detection methods are solved, and efficient and accurate boundary network threat detection is achieved.

CN120090832APending Publication Date: 2025-06-03XIDIAN UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510202689.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

The existing boundary network threat traffic detection methods have problems such as difficulty in manually configuring information and poor model interpretability, resulting in a lack of effectiveness and accuracy in detecting boundary network threats.

Method used

A distributed boundary network threat traffic detection method based on GCN model is adopted, and the BGP network topology graph is constructed, and the graph node embedding is used using a two-layer GCN model to analyze the path change difference score in real time, detect the path change pattern with security threats in the traffic, and give an abnormal report.

Benefits of technology

This method can automatically detect boundary cyber threats without manual configuration information, with good interpretability and high accuracy, and can quickly respond to and handle cyber threat events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090832A_ABST
    Figure CN120090832A_ABST
Patent Text Reader

Abstract

The invention particularly relates to a distributed boundary network threat flow detection method based on a GCN model, which comprises the following steps of: constructing a BGP network topological graph according to a business relationship of each autonomous system in a wide area network provided by an existing data set, endowing different weights to corresponding edges in the BGP network topological graph, and initializing node features; according to the acquired BGP network topological graph information, learning a BGP network topological graph by using a GCN model, performing graph node embedding and retaining key graph features; monitoring traffic path changes of a plurality of global routing convergent points, and detecting a path change mode with security threats in traffic by analyzing a path change difference score in real time; and summarizing abnormal traffic, associating the common prefix and the autonomous system, and giving an abnormal report. According to the method, the problems that information configuration is difficult to carry out and the model interpretability is poor during boundary network threat flow detection are solved, and meanwhile, the method has good real-time performance, interpretability and relatively high accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure network communication technology, and in particular to a distributed border network threat traffic detection method based on a GCN model. Background Art

[0002] The Border Gateway Protocol (BGP) is an autonomous system (AS) routing protocol running on TCP that ensures the connectivity of the global Internet. The Border Gateway Protocol establishes Internet-wide routing paths by exchanging routing announcements between different autonomous systems to ensure that data packets can choose the best path between multiple networks to reach their destination. The Border Gateway Protocol is currently the only protocol designed to handle networks as large as the Internet, and is also the only protocol that can properly handle multiple connections between unrelated routing domains.

[0003] However, as the most complex and widely used routing protocol, the Border Gateway Protocol (BGP) assumes mutual trust between BGP neighbors when it was first designed, and does not take any measures to ensure that the communication between BGP neighbors is not attacked. Due to the security vulnerability of the BGP, the Internet routing infrastructure is vulnerable to attacks, which destroys the Internet's network accessibility and causes abnormal traffic paths, which we call border network threat events. Frequent border network threat events have a very bad impact on the majority of Internet users. For example, in 2014, a large-scale routing hijacking occurred in Indonesian operator Indosat, which blocked network connections in Indonesia, Thailand and the United States for three hours; in 2015, a routing leak occurred in Indian operator BHARTIAirtel, which caused more than 2,000 autonomous domain network failures. Therefore, the problem of border network threat traffic detection has received widespread attention.

[0004] The main reason for border network threat incidents is that the Border Gateway Protocol itself does not have a built-in verification mechanism. Therefore, misbehaving autonomous systems can publish arbitrary routes on the Internet through deliberate attacks or misconfigurations. These forged routes pose a serious threat to routing security, namely BGP hijacking and BGP route leakage. BGP hijacking is to force certain traffic to pass through a malicious autonomous system. In BGP hijacking, an attacker can falsely claim ownership of a prefix or publish a fake but higher priority route. BGP route leakage is to redirect traffic through unexpected links, and routes will be propagated to unexpected autonomous systems.

[0005] It can be seen that the research on the problem of detecting border network threat traffic is extremely urgent at present. However, since traditional detection methods require network operators to conduct a large number of manual investigations on routes. Although some conventional machine learning algorithms can automate this process, there are difficulties in manually configuring information for large-scale data, the potential features of data learning and classification are unexplainable, and it provides limited help for network operators to repair anomalies.

[0006] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present invention, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0007] Aiming at the problems of difficult manual configuration of information and poor model interpretability in the existing border network threat traffic detection methods, the present invention provides a distributed border network threat traffic detection method based on the GCN model, which can analyze the path change difference score in real time to detect the path change patterns with security threats in the traffic, summarize abnormal traffic, associate common prefixes and autonomous systems, and give an abnormal report.

[0008] Other features and advantages of the present invention will become apparent through the following detailed description, or will be learned in part through the practice of the present invention.

[0009] According to a first aspect of the present invention, there is provided a distributed border network threat traffic detection method based on the GCN model, the method comprising:

[0010] The method comprises:

[0011] Construct a BGP network topology diagram based on the business relationships of each autonomous system in the wide area network provided by the existing data set, assign different weights to the corresponding edges in the BGP network topology diagram according to the business relationships, and initialize the node features;

[0012] Use the GCN model to learn the BGP network topology diagram and obtain the graph node embedding feature vector by performing graph node embedding;

[0013] Monitor the traffic path changes of multiple global routing convergence points, calculate the path change difference score based on the graph node embedding feature vector, and detect the path change patterns with security threats in the traffic by analyzing the path change difference score in real time; the global routing convergence point is a convergence point for data flow and information exchange between nodes;

[0014] Summarize abnormal traffic, find out the autonomous systems that cause the abnormal traffic, and give an abnormal report.

[0015] In some exemplary embodiments, a BGP network topology graph is constructed based on the business relationships of each autonomous system in the wide area network provided according to the existing dataset, different weights are assigned to the corresponding edges in the BGP network topology graph according to the business relationships, and the node features are initialized; specifically including:

[0016] Obtain the business relationship dataset of each autonomous system in the wide area network, and construct a BGP network topology graph with the autonomous systems as nodes and the business relationships of the autonomous systems as edges;

[0017] Assign different weights to the edges of the BGP network topology graph according to the business relationships between autonomous systems;

[0018] Initialize the node features of the BGP network topology graph according to the degree centrality of the autonomous systems.

[0019] In some exemplary embodiments, the obtaining the business relationship dataset of each autonomous system in the wide area network and constructing a BGP network topology graph with the autonomous systems as nodes and the business relationships of the autonomous systems as edges includes:

[0020] Construct a BGP network topology graph G=(V, E, W) according to the business relationship dataset of each autonomous system in the wide area network, where V represents the node set of the BGP network topology graph, E represents the weighted directed edge set of the BGP network topology graph, and W represents the weight set corresponding to the weighted directed edges of the BGP network topology graph;

[0021] Use the autonomous system number in the business relationship dataset of the autonomous system to represent the autonomous system, add it to the node V set, construct weighted directed edges according to the autonomous system relationships in the business relationship dataset of the autonomous system, and add them to the weighted directed edge E set and the weight set W corresponding to the weighted directed edges.

[0022] In some exemplary embodiments, the GCN model adopts a two-layer GCN model, including:

[0023] The formula for the first-layer GCN model is:

[0024]

[0025] In the formula, X is the input feature matrix, W (0) is the weight matrix of the first layer, is the normalized adjacency matrix, and σ is the ReLU activation function;

[0026] The formula for the second-layer GCN model is:

[0027]

[0028] In the formula, H (1) is the output of the first layer, and W (1) is the weight matrix of the second layer.

[0029] In some exemplary embodiments, learning the BGP network topology graph using the GCN model includes:

[0030] Input the initialized node features, edge indices, and edge weights into the GCN model training sample, and use a convolutional neural network to aggregate features and update the node features until the training converges. The objective function is:

[0031]

[0032] where: z i represents the i-th element in the input tensor z = [z 1 , z 2 , …, z n , z j represents the j-th element in the input tensor z = [z 1 , z 2 , …, z n , and n represents the number of elements in the input tensor z = [z 1 , z 2 , …, z n .

[0033] In some exemplary embodiments, calculating the path change difference score based on the graph node embedding feature vectors, that is, calculating the difference scores of the node pairs in the node pair sequence; the formula used is:

[0034]

[0035] where ||·|| is the norm symbol representing the length of the vector, n is the vector dimension of the node embedding, and v i , v j are the graph node embedding feature vectors.

[0036] In some exemplary embodiments, detecting the path change pattern with security threats in the traffic by real-time analyzing the path change difference score includes:

[0037] Sum the difference scores of all node pairs in the node pair sequence to obtain the difference score of the node pair sequence, and take the minimum difference score of the node pair sequence as the path difference score;

[0038] If the path difference score is greater than the pre-set path difference score threshold, the path change pattern has a security threat.

[0039] According to the second aspect of the present invention, there is provided a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the distributed boundary network threat traffic detection method based on the GCN model described in the first aspect above.

[0040] According to a third aspect of the present invention, there is provided a computer program product having a computer program stored thereon, and when the computer program is executed by a processor, it implements the distributed boundary network threat traffic detection method based on the GCN model described in the first aspect above.

[0041] According to a fourth aspect of the present invention, there is provided an electronic device, comprising:

[0042] a processor; and

[0043] a memory for storing executable instructions of the processor;

[0044] wherein the processor is configured to implement the distributed boundary network threat traffic detection method based on the GCN model described in the first aspect above when executing the executable instructions.

[0045] The distributed boundary network threat traffic detection method provided by the embodiments of the present invention obtains a commercial relationship data set of each autonomous system in the wide area network according to the GCN framework, constructs a BGP network topology graph with autonomous systems as nodes and the commercial relationships of autonomous systems as edges, initializes the node features of the BGP network topology graph according to the degree centrality of autonomous systems, assigns different weights to the edges of the BGP network topology graph according to the commercial relationships between autonomous systems, uses a two-layer GCN model to learn the BGP network topology graph, and performs graph node embedding. Monitor the traffic path changes of multiple global routing aggregation points, detect the path change patterns with security threats in the traffic by real-time analyzing the path change difference scores, summarize abnormal traffic, associate common prefixes and autonomous systems, and give an abnormal report. The present invention solves the problem that it is difficult to configure information for data during boundary network threat traffic detection, and at the same time has good interpretability, high real-time performance and accuracy.

[0046] 1. Construct a BGP network topology graph based on the commercial relationships of each autonomous system in the wide area network provided by the existing data set, use the GCN model to learn the BGP network topology graph, perform graph node embedding and retain key graph features. This method does not require manual configuration of any special information for the data, solves the problem of difficult manual configuration of information for large-scale graph node data in the wide area network, and can learn node embedding based on graph features by simply processing the read autonomous system relationship data.

[0047] 2. Assign weights to the edges of the BGP network topology graph according to the commercial relationships of autonomous systems, initialize the autonomous system features according to the degree centrality of autonomous systems, and use a two-layer GCN model to learn the node embedding of the BGP network topology graph, accurately representing the feature vectors of each autonomous system, having strong model interpretability, and having a high accuracy for boundary network threat traffic detection.

[0048] 3. Monitor the traffic path changes of multiple global route aggregation points, detect the path change patterns with security threats in the traffic by real-time analyzing the path change difference scores. This method quickly calculates the path difference scores through a simple algorithm and determines whether there are threats in the path changes, meeting the needs of real-time detection.

[0049] 4. Induce abnormal traffic, associate common prefixes and autonomous systems, and give an abnormal report, which has good interpretability.

[0050] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. Brief Description of the Drawings

[0051] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0052] Figure 1 A flowchart of a distributed boundary network threat traffic detection method based on the GCN model provided by an embodiment of the present invention;

[0053] Figure 2 An overall framework diagram of a distributed boundary network threat traffic detection method based on the GCN model provided by an embodiment of the present invention;

[0054] Figure 3 A detailed implementation flowchart of a distributed boundary network threat traffic detection method based on the GCN model provided by an embodiment of the present invention;

[0055] Figure 4 A graph showing the accuracy rate of identifying traffic path changes throughout the month of December 2024 by using the method of the present invention through BGP update announcements collected from a small number of wide collectors in the RouteViews dataset. Detailed Embodiments

[0056] Now, the exemplary embodiments will be described more comprehensively with reference to the drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; on the contrary, these embodiments are provided so that the present invention will be more comprehensive and complete, and the concept of the exemplary embodiments will be fully conveyed to those skilled in the art. The features, structures, or characteristics described can be combined in any suitable manner in one or more embodiments.

[0057] In addition, the attached drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the drawings represent the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0058] In the related art, common machine learning methods used for BGP network topology map embedding in distributed threat traffic detection include decision trees, naive Bayes, and support vector machines (SVMs), etc. Machine learning methods are used to classify nodes (autonomous systems) of the input BGP network topology map and calculate path difference scores in combination with path changes. The recent technology Ap2vec is also based on node embedding technology and uses a graph convolutional network (GCN) to embed BGP routing data, thereby realizing the detection of border network threat traffic. The main steps are as follows:

[0059] 1. Select the dataset: BGP routing update data from public data sources such as RouteViews and RIPE NCC is used to load traffic path information in the wide area network.

[0060] 2. Data preprocessing: The original BGP routing update data is cleaned and processed to remove duplicate or invalid data, and the BGP routing information is converted into a graph form. Each BGP routing update record can be regarded as a node in the graph, and the AS path and prefix of the BGP update are represented as edges of the graph.

[0061] 3. Graph construction: Each update message of the BGP routing forms a directed graph with AS (autonomous system) as nodes and AS paths as edges. Each node represents an AS, and the edge represents the connection from one AS to another in the BGP routing update.

[0062] 4. Graph embedding: The Ap2vec method uses a graph convolutional network (GCN) to perform node embedding learning. The GCN is used to learn the low-dimensional embedding representation of each AS from the graph structure, capturing the topological relationship and routing information between AS nodes.

[0063] 5. Unsupervised training: Ap2vec adopts an unsupervised learning method for training. Without explicit annotation, the model learns the embedding representation of AS nodes through the adjacency information of the graph structure. During the training process, anomalies are discovered by analyzing the patterns and topological structures of AS routing updates.

[0064] 6. Create an adjacency matrix: During the training process, the graph convolutional network uses the adjacency matrix to transmit information and gradually updates the node representation through the embedded representations of the neighbor nodes of each node.

[0065] 7. Detect hijacking: After the model training is completed, the author uses the learned embedded representations to determine which AS route updates may be related to the border network threat traffic. By calculating the similarity between the embedded representations, the model can identify abnormal behaviors different from the normal routing patterns. These abnormal behaviors may indicate the occurrence of BGP hijacking events.

[0066] 8. Anomaly detection: Ap2vec can separate normal AS route updates and potential BGP hijacking events through a clustering algorithm based on the embedded representations.

[0067] The above-mentioned distributed border network threat traffic detection scheme has problems such as difficult information configuration for large-scale BGP relationship data and lack of model interpretability. Under the complex network conditions in today's world, the extremely large number of autonomous systems and the complex relationships between autonomous systems in the wide area network, as well as the unclear network traffic threats in the wide area network, make it difficult to configure information for the read autonomous system relationship data and path data. The learning of implicit relationships between autonomous systems and paths by machine learning methods also makes it impossible to effectively explain the learning model, which is not conducive to preventing and controlling border network traffic threats.

[0068] To accurately and quickly detect network threat traffic, in this exemplary embodiment, a distributed border network threat traffic detection method based on the GCN model is provided, which can directly learn the BGP network topology through the business relationships of autonomous systems and has a certain degree of interpretability. Refer to Figure 1 As shown, the distributed border network threat traffic detection method based on the GCN model may specifically include the following steps:

[0069] Step S1, construct a BGP network topology graph according to the business relationships of each autonomous system in the wide area network provided by the existing data set, assign different weights to the corresponding edges in the BGP network topology graph, and initialize the node features;

[0070] Step S2, according to the obtained BGP network topology graph information, use the GCN model to learn the BGP network topology graph, perform graph node embedding and retain key graph features;

[0071] Step S3, monitor the changes in the traffic paths of multiple global route aggregation points, and detect the path change patterns with security threats in the traffic by real-time analyzing the path change difference scores;

[0072] Step S4, summarize abnormal traffic, associate common prefixes and autonomous systems and give an abnormal report.

[0073] After the above steps, the traffic anomalies reported by this method have good real-time performance, interpretability, and high accuracy.

[0074] A distributed boundary network threat traffic detection method based on the GCN model provided by the present invention learns the BGP network topology graph by using the GCN model, performs graph node embedding and retains key graph features, and solves the problem of difficult manual configuration of information for large-scale graph node data in a wide area network. Monitor the traffic path changes of multiple global routing convergence points, detect the path change patterns with security threats in the traffic by real-time analyzing the path change difference scores, summarize the abnormal traffic, associate the common prefixes and autonomous systems, and give an abnormal report, and finally can have good interpretability.

[0075] Next, each step of the distributed boundary network threat traffic detection method based on the GCN model in this exemplary embodiment will be described in more detail in conjunction with the accompanying drawings and embodiments.

[0076] In step S1, a BGP network topology graph is constructed according to the business relationships of each autonomous system in the wide area network provided by the existing data set, different weights are assigned to the corresponding edges in the BGP network topology graph, and the node features are initialized.

[0077] Obtain the business relationship data set of each autonomous system in the wide area network, and construct a BGP network topology graph with autonomous systems as nodes and the business relationships of autonomous systems as edges;

[0078] In this embodiment, the autonomous system relationship data set uses the CAIDA AS relationship data set.

[0079] Furthermore, the node features of the BGP network topology graph are initialized according to the degree centrality of the autonomous system, and the expression is:

[0080]

[0081] In the formula: v represents the node of the BGP network topology graph, deg in (v) represents the in-degree of the node, deg out (v) represents the out-degree of the node, and N represents the sum of the in-degree and out-degree of the node.

[0082] Construct a BGP network topology graph G=(V, E, W) according to the business relationship data set of each autonomous system in the wide area network, where V represents the node set of the BGP network topology graph, E represents the weighted directed edge set of the BGP network topology graph, and W represents the weight set corresponding to the weighted directed edges of the BGP network topology graph.

[0083] Use the autonomous system numbers in the business relationship dataset of the autonomous system to represent the autonomous systems, add them to the set of nodes V, construct weighted directed edges according to the autonomous system relationships in the business relationship dataset of the autonomous system, and add them to the set of weighted directed edges E and the weight set W corresponding to the weighted directed edges;

[0084] Specifically, for any two autonomous systems AS1 and AS2 in the business relationship dataset of the autonomous system, if their business relationship is C2P, two nodes u and v are constructed using the autonomous system codes of AS1 and AS2 respectively, added to the node set V, a directed edge (u, v) is constructed, added to the set of weighted directed edges E, and its weight is assigned as w1 and added to the weight set W corresponding to the weighted directed edge.

[0085] Specifically, for any two autonomous systems AS1 and AS2 in the business relationship dataset of the autonomous system, if their business relationship is P2P, two nodes u and v are constructed using the autonomous system codes of AS1 and AS2 respectively, added to the node set V, directed edges (u, v) and (v, u) are constructed, added to the set of weighted directed edges E, and the weights of both sides are assigned as w2 and added to the weight set W corresponding to the weighted directed edge.

[0086] In this embodiment, w1 is assigned a value of 2 and w2 is assigned a value of 1.

[0087] In step S2, according to the obtained BGP network topology graph information, use the GCN model to learn the BGP network topology graph, perform graph node embedding and retain key graph features.

[0088] Specifically, a two-layer GCN model is adopted. The formula of the first-layer GCN model is:

[0089]

[0090] In the formula: X is the input feature matrix, W (0) is the weight matrix of the first layer, is the normalized adjacency matrix, and σ is the ReLU activation function;

[0091] The formula of the second-layer GCN model is:

[0092]

[0093] In the formula: H (1) is the output of the first layer, W(1) is the weight matrix of the second layer, is the normalized adjacency matrix;

[0094] Input the initialized node features, edge indices, and edge weights into the model training samples, use the convolutional neural network to aggregate features and update the node features until the training converges. The objective function is:

[0095]

[0096] Where: z i represents the i-th element in the input tensor z = [z 1 , z 2 , …, z n , z j represents the j-th element in the input tensor z = [z 1 , z 2 , …, z n , and n represents the number of elements in the input tensor z = [z 1 , z 2 , …, z n .

[0097] In step S3, monitor the traffic path changes of multiple global routing aggregation points, and detect the path change patterns with security threats in the traffic by analyzing the path change difference scores in real time.

[0098] Specifically, for the detected path change, assuming that the path l 1 (a 1 , a 2 , …, a n ) changes to l 2 (a 1 , a 2 , …, a m ), we generate a sequence of all node pairs that meet the algorithm requirements based on the two different paths using the dynamic time warping algorithm;

[0099] Then, for the node pair (v i , v j ) in the node pair sequence, that is, the graph node embedding feature vector. We calculate its difference score, and the formula is:

[0100]

[0101] Where: ||·|| is the norm symbol, usually representing the Euclidean norm, indicating the length of the vector, and n is the vector dimension of the node embedding;

[0102] It should be noted that for calculating the difference scores of the node pair sequence, we sum the difference scores of all node pairs in the node pair sequence to obtain the difference score of the node pair sequence, and we take the minimum difference score of the node pair sequence as the path difference score;

[0103] If the path difference score is greater than the pre-set path difference score threshold, the path change pattern has a security threat.

[0104] In step S4, summarize the abnormal traffic, associate the common prefix and the autonomous system, and give an abnormal report.

[0105] Specifically, abnormal traffic is summarized, and abnormal paths are classified according to the time interval of path changes, the common prefix involved, and the autonomous systems, and an abnormal report is given.

[0106] In the embodiment of the present invention, the path changes provided by the Border Gateway Protocol update messages within a certain time interval are quickly processed according to the above method, the real-time traffic path anomaly score is calculated, and an anomaly report is given.

[0107] In this embodiment, a small number of BGP update announcements from the RouteViews dataset wide collector are used to download and identify traffic path changes for the entire month of December 2024.

[0108] It should be noted that in order to verify the identified unknown alerts and pursue a certain degree of interpretability, we define four forms of abnormal traffic path changes:

[0109] Unauthorized traffic path change: The source autonomous systems before and after the traffic path change belong to different organizations and have different RPKI verification statuses, that is, one is in an invalid state and the other is in a valid state.

[0110] Route leakage: The traffic path before or after the traffic path change violates the valley-free criterion.

[0111] Improper path handling: The routing path before or after the routing change contains reserved autonomous system numbers or adjacent autonomous systems for which there is no record of business relationship between them.

[0112] ROA misconfiguration: The original autonomous systems before and after the change come from the same organization but have different RPKI verification statuses, that is, one is in an invalid path length or invalid autonomous system number state and the other is in a valid state.

[0113] By Figure 4 It can be seen that a high accuracy rate and good interpretability are shown in the task of traffic path change in December 2024 using a small number of BGP update announcements from the RouteViews dataset wide collector.

[0114] Aiming at the problem of difficult manual configuration information in the existing border network threat traffic detection method, the present invention proposes a distributed border network threat traffic detection method based on the GCN model. This method uses a two-layer GCN model to learn the BGP network embedding graph node embedding vectors based on graph features without any manual configuration information. This method learns the graph node embedding vectors based on the explicit features of the BGP network embedding graph and has a simple algorithm, and summarizes the abnormal traffic path to output an abnormal report, obtaining relatively high real-time performance, accuracy rate, and good interpretability.

[0115] It should be noted that, on the other hand, the present application also provides a storage medium, which may be included in an electronic device; or may exist separately without being assembled into the electronic device. The above storage medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the methods described in the following embodiments.

[0116] In one embodiment, the present application provides a computer program product, including a computer program, which when executed by a processor implements the steps in the above method embodiments.

[0117] In one embodiment, the present application provides an electronic device, including: a processor; and a memory for storing executable instructions of the processor; wherein, the processor is configured to implement the above-mentioned distributed boundary network threat traffic detection method based on the GCN model when executing the executable instructions.

[0118] In addition, the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present invention, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes may be executed synchronously or asynchronously in, for example, multiple modules.

[0119] Those skilled in the art will readily think of other embodiments of the present invention after considering the specification and practicing the invention herein. The present application aims to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include the common general knowledge or conventional technical means in the technical field not disclosed by the present invention. The specification and embodiments are only regarded as exemplary, and the true scope and spirit of the present invention are pointed out by the claims.

[0120] It should be understood that the present invention is not limited to the exact structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only defined by the appended claims.

Claims

1. A distributed border network threat traffic detection method based on the GCN model, characterized in that: The method comprises: According to the business relationship of each autonomous system in the wide area network provided by the existing data set, a BGP network topology graph is constructed, different weights are assigned to the corresponding edges in the BGP network topology graph according to the business relationship, and node features are initialized; Use the GCN model to learn the BGP network topology graph, embed the graph nodes and obtain the graph node embedding feature vector; Monitor traffic path changes at multiple global routing convergence points, calculate path change difference scores based on graph node embedding feature vectors, and detect path change patterns with security threats in traffic by real-time analysis of path change difference scores; the global routing convergence point is a convergence point for data flow and information exchange between nodes; Summarize abnormal traffic, find out the autonomous system that causes abnormal traffic and give an abnormal report.

2. The distributed border network threat traffic detection method based on the GCN model according to claim 1 is characterized in that: The BGP network topology diagram is constructed based on the business relationship of each autonomous system in the wide area network provided by the existing data set, different weights are assigned to the corresponding edges in the BGP network topology diagram according to the business relationship, and node features are initialized; Specifically include: Obtain the business relationship data set of each autonomous system in the wide area network, and build a BGP network topology graph with the autonomous system as the node and the business relationship of the autonomous system as the edge; Assign different weights to the edges of the BGP network topology graph based on the business relationships between autonomous systems; Initialize the node characteristics of the BGP network topology graph according to the degree centrality of the autonomous system.

3. The distributed border network threat traffic detection method based on the GCN model according to claim 2 is characterized in that: The step of obtaining a data set of business relationships of each autonomous system in the wide area network and constructing a BGP network topology graph with the autonomous system as a node and the business relationship of the autonomous system as an edge includes: Construct a BGP network topology graph G = (V, E, W) based on the business relationship data set of each autonomous system in the wide area network, where V represents the node set of the BGP network topology graph, E represents the weighted directed edge set of the BGP network topology graph, and W represents the weight set corresponding to the weighted directed edge of the BGP network topology graph; The autonomous system number in the autonomous system's business relationship data set is used to represent the autonomous system, a node V set is added, weighted directed edges are constructed according to the autonomous system relationships in the autonomous system's business relationship data set, and a weighted directed edge set E and a weight set W corresponding to the weighted directed edges are added.

4. The distributed border network threat traffic detection method based on the GCN model according to claim 1 is characterized in that: The GCN model adopts a double-layer GCN model, including: The first layer GCN model formula is: Where X is the input feature matrix, W (0) is the weight matrix of the first layer, is the standardized adjacency matrix, σ is the ReLU activation function; The second layer GCN model formula is: In the formula, H (1) is the output of the first layer, W (1) is the weight matrix of the second layer.

5. The distributed border network threat traffic detection method based on the GCN model according to claim 4 is characterized in that: The use of the GCN model to learn the BGP network topology graph includes: The initialized node features, edge indexes and edge weights are input into the GCN model training sample, and the convolutional neural network is used to aggregate the features and update the node features until the training converges. The objective function is: Where: z i Represents the input tensor z=[z1,z2,…,z n ], the i-th element in z j Represents the input tensor z=[z1,z2,…,z n ], n represents the input tensor z = [z1,z2,…,z n ] is the number of elements.

6. The distributed border network threat traffic detection method based on the GCN model according to claim 1 is characterized in that: The path change difference score is calculated based on the graph node embedding feature vector, that is, the difference score of the node pairs in the node pair sequence is calculated; the formula used is: In the formula, ||·|| is the modulus symbol, which indicates the length of the vector, n is the vector dimension of the node embedding, and υ i 、v j Embedding feature vectors for graph nodes.

7. The distributed border network threat traffic detection method based on the GCN model according to claim 6 is characterized in that: The method of detecting a path change pattern with a security threat in traffic by analyzing the path change difference score in real time includes: The difference scores of all node pairs in the node pair sequence are summed up to obtain the difference score of the node pair sequence, and the smallest node pair sequence difference score is taken as the path difference score; If the path difference score is greater than a preset path difference score threshold, the path change pattern poses a security threat.

8. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the distributed border network threat traffic detection method based on the GCN model as described in any one of claims 1 to 7 is implemented.

9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the distributed border network threat traffic detection method based on the GCN model described in any one of claims 1 to 7 is implemented.

10. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the distributed border network threat traffic detection method based on the GCN model described in any one of claims 1 to 7 by executing the executable instructions.

Citation Information

Cited By

  • BGP anomaly detection method based on embedded vector

    CN120811965A

  • A BGP anomaly detection method based on embedded vectors

    CN120811965B

  • Network automatic topology method and system for safety control of industrial Internet of Things

    CN120956609A