Network intrusion detection method for distributed environment

By combining graph neural network and Transformer model, the spatial relationship and time series characteristics between nodes in the network are captured, and the problem that the existing technology is difficult to adapt to network changes is solved, and more accurate and effective network intrusion detection is achieved.

CN120110702APending Publication Date: 2025-06-06GUANGDONG POWER GRID CO LTD INFORMATION CENT +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311672095.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing network intrusion detection technology is difficult to adapt to changes in the network environment and cannot effectively capture the spatial relationship and time series characteristics between nodes, resulting in unsatisfactory detection results.

Method used

Using the combination of graph neural network (GNN) and Transformer model, GNN is used to capture the spatial relationship between nodes, and Transformer is used to capture time series features to perform network intrusion detection.

Benefits of technology

Modeling the relationship between nodes in a global scope can better capture the global information of the graph, identify complex patterns and exceptions in the network, and improve the accuracy and effectiveness of intrusion detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110702A_ABST
    Figure CN120110702A_ABST
Patent Text Reader

Abstract

The invention relates to a network intrusion detection method oriented to a distributed environment. According to the method, network intrusion detection is carried out by adopting a mode of fusing the GNN and the Transform model. GNN is used for capturing a spatial relationship, and Transform is used for capturing a time relationship. Wherein the GNN focuses on learning local features of each node, and captures a relationship between the node and a neighbor thereof. Through combination with Transform, the model can model the relationship between nodes in a global range, so that global information of a graph is better captured, and more complex modes and anomalies in a network can be identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the field of network intrusion detection, in particular to a network intrusion detection method oriented to a distributed environment. Background Art

[0002] With the development of the Internet, network security issues have also become prominent. The network security threats brought about by the external openness of the network are becoming more and more common in daily life. Specifically, criminals can use loopholes in the network to conduct illegal activities on the system, such as modifying system permissions, tampering with system data, etc. These activities may cause economic losses, privacy leaks, system paralysis, and even threaten national interests. As a security defense technology that protects the network from attacks, network intrusion detection plays a vital role in the security of computer systems and networks.

[0003] Existing technical solutions are divided into network intrusion detection based on machine learning and network intrusion detection based on deep learning. Most commonly used machine learning algorithms belong to supervised learning. Supervised learning means that the training set must have labeled data during the training process, and the algorithm learns under the supervision of the labeled data, such as the support vector machine algorithm. [1] et al. used the support vector machine algorithm to perform network intrusion detection on the KDD Cup99 dataset, normalized the data and other preprocessing. After classifying the data, the support vector machine algorithm can effectively perform network intrusion detection. Although machine learning has achieved good results in intrusion detection, such models require that the dataset has certain conditions before they can be used. However, the network environment is constantly changing, and the machine learning algorithm cannot adapt to such changes, so the detection effect is not ideal.

[0004] With the development of deep learning and artificial intelligence, many network security researchers have begun to apply deep learning algorithms to intrusion detection. For example, convolutional neural networks, recurrent neural networks and their variant models, long short-term memory networks, have achieved good results in intrusion detection. [2] Convolutional Neural Network (CNN) has outstanding performance in image processing and natural language processing. LeNet-5 proposed by Yann LeCun et al. [3] The network model achieved a low false positive rate on the MNIST dataset. Based on this model, Wang Yong et al. proposed 6 different convolutional neural network structures for network intrusion detection, which improved the overall classification accuracy. [4] .

[0005] These experimental investigations are all based on graphical data sets and do not fully consider the spatial characteristics of the data. However, the spatial relationship between nodes (hosts, devices, etc.) in the network is crucial for identifying abnormal behaviors and intrusion events. Summary of the invention

[0006] In view of the defects in the prior art, the purpose of the present invention is to provide a network intrusion detection method for a distributed environment. The method adopts a method of integrating a graph neural network (GNN) and a transformer model to perform network intrusion detection. GNN is used to capture spatial relationships, and Transformer is used to capture temporal relationships. Among them, GNN focuses on learning the local features of each node and capturing the relationship between the node and its neighbors.

[0007] Among them, GNN is a class of deep learning models specially designed to process graph-structured data. They have achieved remarkable success in various fields, such as social network analysis, chemical molecule representation, recommendation systems, and network intrusion detection. Graph-structured data consists of nodes and edges. Each element in the graph is called a node, which can represent an entity, such as a host in network intrusion detection, which is a vector that captures the characteristic information of a node and its neighbors; an edge represents the relationship or connection between nodes. In network intrusion detection, an edge can represent the communication relationship between two hosts. GNN can learn feature representations on nodes and edges while taking into account the topological structure between nodes. This helps to discover abnormal patterns, such as the movement path of an attacker in the network or abnormal node behavior.

[0008] The Transformer attention mechanism was first introduced in the 2017 paper “Attention Is All You Need”. [5] The Transformer model has achieved remarkable success in the field of natural language processing, but its attention mechanism is also applicable to other sequence data. In network intrusion detection, time series data can be regarded as a sequence, where each time step represents an observation point. This enables it to effectively capture long-distance dependencies in the sequence and helps detect abnormal patterns in the network.

[0009] In order to achieve the above purpose, the technical solution adopted by the present invention is:

[0010] A network intrusion detection method for a distributed environment, characterized in that it comprises the following steps:

[0011] Step 1: preprocess the network traffic data, that is, standardize and label encode the network traffic data;

[0012] Step 2: Convert the network data preprocessed in step 1 into a graph representation. Each node in the graph represents a network connection. The relationship between nodes includes IP address, port number, protocol type, packet size, source and destination MAC addresses. Edges represent the relationship between connections.

[0013] Step 3, use GCN to process the network data in the graphical representation obtained in step 2 to extract network structure and traffic pattern features;

[0014] Step 4: Use the traffic data obtained in step 3 to perform detection and classification recognition training on the Transformer model;

[0015] Step 5: Input the test data set into the model trained in step 4 to predict the intrusion data label.

[0016] Based on the above solution, step 3 is as follows:

[0017] When GCN processes the network data in the form of a graph obtained in step 2, it performs supervised learning with the label of network intrusion detection;

[0018] The learning process of node representation is as follows: by iterating multiple graph convolutional layers, the node representation is gradually updated so that each node captures local and global graph structure information;

[0019] The update formula of the node representation is as follows:

[0020]

[0021] In the above formula, v and u represent two nodes respectively, h v (l) and h v (l+1) are the representation of node v at the lth and l+1th layers, N(v) represents the set of neighbor nodes of node v, and d v and d u are the degrees of nodes v and u, respectively, and W (l) is the weight matrix and σ is the activation function.

[0022] Based on the above solution, step 4 is as follows:

[0023] Step 4-1, linearly project the node representation generated by GNN and input it into the Transformer model;

[0024] Step 4-2, embed the time series position information of the data processed in step 4-1, and then send it to the model encoder to obtain the predicted label through forward propagation;

[0025] The embedding formula of position information is as follows:

[0026]

[0027]

[0028] In the above two formulas, pos is the position index in the input sequence, i is the index of the embedding dimension, and the value range is [0, d / 2), where d is the embedding dimension;

[0029] Step 4-3, use the loss function to calculate the difference between the predicted label and the correct label, and perform back propagation based on the loss value to update the Transformer model parameters; the above loss function can be the cross entropy loss function

[0030] Step 4-4, concatenate the output of the multi-head attention layer of the encoder module with the output of the feedforward neural network layer, and obtain the output matrix of the encoder after normalization, as shown in the following formula:

[0031]

[0032] Z = MHA(Q, K, V) = concat(Z 1 ,Z 2 , ..., Z i )

[0033] In the above two equations, d k Represents the dimension of the input matrix, Z i is the output of a single attention function, Z is the output of the multi-head attention layer; T is the transpose icon, indicating the transpose of the matrix.

[0034] In the above two formulas, the calculation formulas of Q, K, and V matrices are as follows:

[0035] Q=X·W Q

[0036] K=X·W k

[0037] V=X·W v

[0038] Among them, X is the model input after the position information is embedded, W Q , W k , W v To learn the matrix.

[0039] The network intrusion detection method for a distributed environment described in the present invention has the following beneficial effects:

[0040] The present invention can model the relationship between nodes on a global scale, better capture the global information of the graph, and help identify complex patterns and anomalies in the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The present invention has the following accompanying drawings:

[0042] Figure 1 This is a structural diagram of the fusion model described in the present invention;

[0043] Figure 2 This is the intrusion detection flow chart of the present invention;

[0044] Figure 3 This is the confusion matrix and overall detection effect diagram of the present invention. DETAILED DESCRIPTION

[0045] The present invention is further described in detail below in conjunction with the accompanying drawings.

[0046] The specific process of fusing GNN and Transformer models to achieve network intrusion detection can be divided into several key steps. Figure 1 This is the structural diagram of the model, which mainly includes the GNN feature extraction module and the Transformer encoder module. The GNN feature extraction module learns the spatial features of the intrusion data through the Graph Convolutional Network (GCN), and the Transformer encoder module completes the detection of the intrusion data in combination with the temporal features. Figure 2 Flowchart of intrusion detection.

[0047] 1. Data preprocessing: Load network traffic data from the CIC-IDS2018 dataset and perform necessary preprocessing, including data standardization, label encoding, etc.

[0048] 2. Graph representation construction: Use the adjacency matrix of the graph to represent the connection relationship between nodes and convert the network traffic data into a graph representation. Each network node represents a network connection. The node relationship includes IP address, port number, protocol type, packet size, source and destination MAC addresses, etc., while the edge represents the relationship between the connections.

[0049] 3. GNN model training: GCN is used to process the network data represented by the graph and extract the features of the network structure and traffic pattern. During the training process, the network intrusion detection labels are used for supervised learning to ensure that the model learns spatial features that are helpful for detecting intrusions. GCN learns the complex interactions between nodes through neighbor aggregation and feature propagation mechanisms, making the representation of node features more locally consistent, which helps to better capture the relationships and patterns in the graph structure, thereby improving the performance of subsequent node classification. The learning process of node representation and the update formula are as follows.

[0050] Learning process of node representation: By iterating multiple graph convolutional layers, the node representation is gradually updated so that each node can capture more local and global graph structure information, thereby improving the representation ability of graph data. The update formula of node representation is as follows:

[0051]

[0052] Among them, v and u represent two nodes respectively, h v (l) and h v (l+1) are the representation of node v at the lth and l+1th layers, N(v) represents the set of neighbor nodes of node v, and d v and d u are the degrees of nodes v and u, respectively, and W (l) is the weight matrix, and σ is the activation function (the nonlinear activation function ReLU is used in the model).

[0053] 4. Transformer model is trained for traffic data detection and classification recognition: Since the data output by GNN is in the form of a graph, the node representation generated by GNN must be linearly projected before it can be input into the Transformer model. After the processed data is embedded with the time series position information, the data will be sent to the model encoder, and the predicted label will be obtained through forward propagation. The loss function calculates the difference between the predicted label and the correct label, and backpropagates according to the loss value to update the model parameters. In this process, Transformer uses the self-attention mechanism to capture long-term dependencies in the time series for modeling global information.

[0054] The formula for embedding position information is as follows:

[0055]

[0056]

[0057] Here, pos is the position index in the input sequence, and i is the index of the embedding dimension, ranging from [0, d / 2), where d is the embedding dimension.

[0058] The calculation formulas for the Q, K, and V matrices are as follows:

[0059] Q=X·W Q

[0060] K=X·W k

[0061] V=X·W v

[0062] Among them, X is the model input after the position information is embedded, W Q , W k , W v To learn the matrix, it is randomly initialized at the beginning and continuously updated during the learning process.

[0063] Afterwards, the output of the multi-head attention layer of the encoder module is concatenated with the output of the feedforward neural network layer and normalized to obtain the output matrix of the encoder.

[0064]

[0065] Z = MHA(Q, K, V) = concat(Z 1 ,Z 2 , ..., Z i )

[0066] Among them, d k Represents the dimension of the input matrix, Z i is the output of a single attention function, and Z is the output of the multi-head attention layer.

[0067] 5. The model predicts the intrusion data label: The output of the Transformer encoder is converted into the final required dimension by the weight matrix of the linear layer, and is normalized by the SoftMax function to obtain the predicted value of the label.

[0068] The contents not described in detail in this specification belong to the prior art known to professional and technical personnel in this field.

[0069] The detection effect of the model is as follows. After the preprocessing of the data set and the model training, the final output of the model prediction stage is the confusion matrix of the label detection, the overall detection effect including the accuracy, recall and other indicators, and the detection accuracy of each attack data. The results show that the model can better detect the intrusion data. The confusion matrix and the overall detection effect are as follows: Figure 3 The detection results of each attack are shown in the following table:

[0070]

[0071] References:

[0072] [1] Jiang Feng, Wang Chunping, Zeng Huifen. Decision tree algorithm based on relative decision entropy and its application in intrusion detection [J]. Computer Science, 2012, 39(4): 223-226.

[0073] [2] Wang Yinqiu, Yu Wei, Chen Junpeng. Research on automatic question answering in Chinese medical question answering community based on knowledge graph[J]. Data Analysis and Knowledge Discovery, 2023, 7(03): 97-109.

[0074] [3]Y.LeCun, L.Bottou, Y.Bengio, et al.Gradient-based learning applied todocument recognition[J].Proceedings of the IEEE, 1998, 86(11): 2278-2324.

[0075] [4]H.Zhou, Y.Wang, X.Lei, et al.A method of improved CNN traffic classification[C] / / 2017 13th International Conference on Computational Intelligence and Security.IEEE, 2017: 177-181.

[0076] [5] A. Vaswani, N. Shazeer, N. Parmar, et al. Attention is all you need. arxiv2017[J]. arxiv preprint arxiv: 1706.03762, 2017: 2999-3007.

Claims

1. A network intrusion detection method for distributed environments, It is characterized in that The steps include: Step 1: preprocess the network traffic data, that is, standardize and label encode the network traffic data; Step 2: Convert the network data preprocessed in step 1 into a graph representation. Each node in the graph represents a network connection. The relationship between nodes includes IP address, port number, protocol type, packet size, source and destination MAC addresses. Edges represent the relationship between connections. Step 3, use GCN to process the network data in the graphical representation obtained in step 2 to extract network structure and traffic pattern features; Step 4: Use the traffic data obtained in step 3 to perform detection and classification recognition training on the Transformer model; Step 5: Input the test data set into the model trained in step 4 to predict the intrusion data label.

2. A distributed network intrusion detection method according to claim 1, It is characterized in that Step 3 is as follows: When GCN processes the network data in the form of a graph obtained in step 2, it performs supervised learning with the label of network intrusion detection; The learning process of node representation is as follows: by iterating multiple graph convolutional layers, the node representation is gradually updated so that each node captures local and global graph structure information; The update formula of the node representation is as follows: In the above formula, v and u represent two nodes respectively, h v (l) and h v (l+1) are the representation of node v at the lth and l+1th layers, N(v) represents the set of neighbor nodes of node v, and d v and d u are the degrees of nodes v and u, respectively, and W (l) is the weight matrix and σ is the activation function.

3. A distributed network intrusion detection method according to claim 1, It is characterized in that Step 4 is as follows: Step 4-1, linearly project the node representation generated by GNN and input it into the Transformer model; Step 4-2, embed the time series position information of the data processed in step 4-1, and then send it to the model encoder to obtain the predicted label through forward propagation; The embedding formula of position information is as follows: In the above two formulas, pos is the position index in the input sequence, i is the index of the embedding dimension, and the value range is [0, d / 2), where d is the embedding dimension; Step 4-3, use the loss function to calculate the difference between the predicted label and the correct label, and perform backpropagation based on the loss value to update the Transformer model parameters; Step 4-4, concatenate the output of the multi-head attention layer of the encoder module with the output of the feedforward neural network layer, and obtain the output matrix of the encoder after normalization, as shown in the following formula: Z=MHA(Q,K,V)=concat(Z 1 ,Z 2 ,...,Z i ) In the above two equations, d k Represents the dimension of the input matrix, Z i is the output of a single attention function, and Z is the output of the multi-head attention layer; In the above two formulas, the calculation formulas of Q, K, and V matrices are as follows: Q=X·W Q K=X·W k V=X·W v Among them, X is the model input after the position information is embedded, W Q , W k , W v To learn the matrix.