Intrusion detection method and device

By performing two-dimensional processing of target messages and time-series high-frequency feature extraction, combining feature extraction models, abnormal detection models and attack type discrimination models, the problems of large amount of data and high computing resources consumption of traditional intrusion detection systems are solved, and more efficient intrusion detection is achieved.

CN120128404APending Publication Date: 2025-06-10NEW H3C TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510348701.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Traditional machine learning-based intrusion detection systems have large amounts of data, high computing resources, and low effective information, resulting in low detection accuracy.

Method used

By performing two-dimensional data processing on the target message, high-frequency features of timing are extracted, and intrusion detection is used using feature extraction models, abnormality detection models and attack type discrimination models, and attack type discrimination models are used to determine attack type only when the detection result is abnormal.

Benefits of technology

It reduces the amount of data involved in the calculation during intrusion detection, saves system computing resources, and improves the accuracy and speed of intrusion detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128404A_ABST
    Figure CN120128404A_ABST
Patent Text Reader

Abstract

The invention provides an intrusion detection method and device. The method comprises the following steps: performing data two-dimensional processing on a target message, and inputting a two-dimensional processing result into a feature extraction model to obtain a time sequence high-frequency feature; inputting the time sequence high-frequency features into an anomaly detection model to obtain an anomaly detection result; and when the anomaly detection result is abnormal, inputting the two-dimensional processing result and the time sequence high-frequency feature into an attack type discrimination model to obtain the attack type of the target message. According to the method, a feature extraction model used for extracting time sequence high-frequency features of a message and an anomaly detection model used for carrying out anomaly judgment according to the time sequence high-frequency features of the message are added in front of a traditional intrusion detection system; therefore, according to the method, the amount of data participating in calculation in the intrusion detection process is reduced, and the accuracy and speed of intrusion detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to an intrusion detection method and apparatus. Background Art

[0002] With the rapid development of network-based computing services and applications, the Internet is subject to more and more security threats. As an important part of the network security deep defense system, the Intrusion Detection System (IDS) is particularly important.

[0003] An intrusion detection system discovers and identifies intrusion behaviors in a system by detecting and analyzing network traffic or host behaviors. In order to detect abnormal behaviors under large-scale data traffic, the intrusion detection system based on machine learning has become the focus. However, the traditional intrusion detection system based on machine learning requires a large amount of data, consumes more computing resources, has less effective information, and has low detection accuracy. How to overcome the above defects is the key research objective in this field. Summary of the Invention

[0004] To overcome the problems existing in the related technologies, this application provides an intrusion detection method and apparatus.

[0005] According to the first aspect of the embodiments of this application, an intrusion detection method is provided. The method includes:

[0006] Performing data two-dimensionalization processing on a target packet, and inputting the two-dimensionalization processing result of the target packet into a feature extraction model to obtain the time-series high-frequency features of the target packet;

[0007] Inputting the time-series high-frequency features of the target packet into an anomaly detection model to obtain the anomaly detection result of the target packet;

[0008] When the anomaly detection result of the target packet is abnormal, inputting the two-dimensionalization processing result of the target packet and the time-series high-frequency features of the target packet into an attack type discrimination model to obtain the attack type of the target packet.

[0009] According to the second aspect of the embodiments of this application, an intrusion detection apparatus is provided. The apparatus includes:

[0010] A feature extraction module, configured to perform data two-dimensionalization processing on a target packet, and input the two-dimensionalization processing result of the target packet into a feature extraction model to obtain the time-series high-frequency features of the target packet;

[0011] An anomaly detection module, configured to input the time-series high-frequency features of the target packet into an anomaly detection model to obtain the anomaly detection result of the target packet;

[0012] A type discrimination module, configured to, when the anomaly detection result of the target message is an anomaly, input the two-dimensional processing result of the target message and the time-series high-frequency features of the target message into an attack type discrimination model to obtain the attack type of the target message.

[0013] According to a third aspect of the embodiments of the present application, there is provided an electronic device, including:

[0014] A memory and one or more processors; the memory is coupled to the processor; wherein, computer program code is stored in the memory, and the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described above.

[0015] According to a fourth aspect of the embodiments of the present application, there is provided a computer-readable storage medium, including computer instructions, and when the computer instructions run on an electronic device, the electronic device is caused to execute the method as described above.

[0016] According to a fifth aspect of the embodiments of the present application, there is provided a computer program product, and when the computer program product runs on a computer, the computer is caused to execute the method as described above.

[0017] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:

[0018] The embodiments of the present application draw on the thinking of graphics processing algorithms to convert message data into two-dimensional pictures. Compared with other machine learning-based intrusion detection solutions, the embodiments of the present application add a feature extraction model for extracting the time-series high-frequency features of messages and an anomaly detection model for performing anomaly judgment based on the time-series high-frequency features of messages before the traditional intrusion detection system. Only when the anomaly detection model determines that a message is abnormal, the attack type discrimination model is used to determine the attack type of the message. It can be seen that the embodiments of the present application specifically propose to perform message anomaly detection based on the time-series high-frequency features of messages, reduce the amount of data involved in the calculation during the intrusion detection process, save system computing resources, and improve the accuracy and speed of intrusion detection.

[0019] It should be understood that the above general description and subsequent detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings herein are incorporated into the specification and constitute a part of this application, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0021] Figure 1 It is a schematic flowchart of an intrusion detection method provided by an embodiment of the present application;

[0022] Figure 2 Schematic diagram of the implementation process of an intrusion detection method provided by an embodiment of the present application;

[0023] Figure 3 Schematic diagram of the structure of an intrusion detection device provided by an embodiment of the present application;

[0024] Figure 4 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0025] The following describes the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to limit the present application.

[0026] It should be noted that "at least one" in the present application means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The terms "first", "second", "third", etc. (if any) in the description and claims of the present application and the accompanying drawings are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0027] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.

[0028] The intrusion detection system based on machine learning mainly extracts features from a large amount of data through machine learning technology, and establishes a classification model for the labeled data set to realize the classification of network traffic or host behavior. It can not only detect known attacks, but also detect new or unknown attacks. However, the traditional intrusion detection system based on machine learning still has the following problems:

[0029] First, in the face of a variety of attack types that change over time, a single machine learning detection model often cannot guarantee the detection accuracy;

[0030] Second, machine learning models often ignore the extraction of time-domain information and can only focus on real-time information, and it is not easy to detect latent and long-term attacks; and the information extraction efficiency is low, and a large amount of computing resources are required;

[0031] Third, the false alarm rate and the missed alarm rate are relatively high, resulting in low detection accuracy or denial of service.

[0032] In view of the above problems, the present application provides an intrusion detection method and device.

[0033] Next, the embodiments of the present application will be described in detail.

[0034] The embodiment of the present application provides an intrusion detection method, as Figure 1 shown, the method may include the following steps:

[0035] Step 110: Perform two-dimensional data processing on the target packet, and input the two-dimensional processing result of the target packet into the feature extraction model to obtain the time-series high-frequency features of the target packet;

[0036] Step 120: Input the time-series high-frequency features of the target packet into the anomaly detection model to obtain the anomaly detection result of the target packet;

[0037] Step 130: When the anomaly detection result of the target packet is abnormal, input the two-dimensional processing result of the target packet and the time-series high-frequency features of the target packet into the attack type discrimination model to obtain the attack type of the target packet.

[0038] The embodiment of the present application performs intrusion detection on packets based on machine learning technology. For the convenience of implementation, the embodiment of the present application first performs two-dimensional data processing on the target packet (the specific form may be binary captured packet data). Specifically, the packet data is converted into a two-dimensional picture format data according to the corresponding protocol standard to obtain the two-dimensional processing result of the target packet.

[0039] To extract the features of the target packet, the embodiment of the present application pre-constructs and trains a feature extraction model based on machine learning technology. This model is used to output the time-series high-frequency features of the packet according to the two-dimensional processing result of the packet.

[0040] It is worth mentioning that the time-series high-frequency features mentioned in the embodiment of the present application refer to the feature data in the packet data that changes greatly in the time dimension and the degree of this change is highly correlated with the abnormal state of the packet (that is, whether the packet is related to a network attack). Therefore, by monitoring the time-series high-frequency features of the packet, the abnormal state of the packet can be inferred with a high probability.

[0041] In an actual business scenario, in this embodiment, a feature extraction model is used to extract time-series high-frequency features from a message. Next, the feature extraction model will be introduced. In the embodiment of the present application, a first machine learning model is first constructed, which takes the two-dimensional processing result of the message as the input and the time-series high-frequency features of the message as the output. Specifically, the first machine learning model can be constructed based on the Deformable Convolutional Networks (DCN). Then, the two-dimensional processing result of the historical message and the time-series high-frequency features of the historical message are used to train the first machine learning model until a preset first training termination condition is reached, and a feature extraction model is obtained for the intrusion detection system in the real-time scenario.

[0042] It can be understood that the two-dimensional processing result of the above historical message and the time-series high-frequency features of the historical message are essentially training samples. Regarding the generation method of the training samples, the specific details are as follows: For the two-dimensional processing result, the same two-dimensional processing as the above target message can be performed on the historical message to obtain the two-dimensional processing result of the historical message; for the time-series high-frequency features, as a specific implementation, the time-series high-frequency features of the historical message can be calculated according to the target formula. The target formula is specifically as follows:

[0043]

[0044] where I i is the two-dimensional processing result of the historical message, I edge is the time-series high-frequency feature of the historical message, n is the number of messages in the historical message sequence, 1 / (1 + 2 + 3 + 4 + …… n) = 1 / {n(n - 1) / 2} = 2 / n(n - 1).

[0045] It can be seen from the above target formula that for the time-series high-frequency features of the historical messages in the training samples, in the embodiment of the present application, the time-series high-frequency features are actually calculated not based on a single message, that is, the above historical message, but based on a series of messages (including but not limited to the above historical messages), that is, the above historical message sequence.

[0046] In an actual intrusion detection system, after obtaining the time-series high-frequency features of the target message, in the embodiment of the present application, an anomaly detection model is further used to determine whether the target message is abnormal. Specifically, the time-series high-frequency features of the target message are input into the anomaly detection model to obtain the anomaly detection result of the target message. The anomaly detection result includes normal and abnormal. The above anomaly detection model is also pre-constructed and trained based on machine learning techniques in the embodiment of the present application.

[0047] The construction and training process of the anomaly detection model will be introduced below. Specifically, historical packets with anomaly detection labels are obtained, and the anomaly detection labels include normal and abnormal; then, a second machine learning model is constructed with the time-series high-frequency features of the packets as the input and the anomaly detection results of the packets as the output; finally, the second machine learning model is trained using the time-series high-frequency features of the historical packets and the anomaly detection labels of the historical packets until a preset second training termination condition is reached, and an anomaly detection model is obtained.

[0048] As Figure 2 shown, in an actual intrusion detection system, if the anomaly detection result of the target packet is normal, the target packet is allowed to pass and the current process is exited; if the anomaly detection result of the target packet is abnormal, the attack type of the target packet is further determined through an attack type discrimination model. The above attack type discrimination model is also pre-constructed and trained based on machine learning technology in the embodiments of this application.

[0049] The construction and training process of the attack type discrimination model will be introduced below. Historical packets with attack type labels (such as port scanning attack, denial of service attack, session hijacking attack, etc.) are obtained; a third machine learning model is constructed with the two-dimensional processing result of the packets and the time-series high-frequency features of the packets as the input and the abnormal attack type of the packets as the output. Specifically, the third machine learning model can be constructed based on a Residual Network (ResNet); the third machine learning model is trained using the two-dimensional processing result of the historical packets, the time-series high-frequency features of the historical packets, and the attack type labels of the historical packets to obtain an attack type discrimination model.

[0050] It is worth mentioning that a model with the fusion features of the packets as the input and the abnormal attack type of the packets as the output can also be constructed as the third machine learning model. Correspondingly, the third machine learning model is trained using the fusion features of the historical packets and the attack type labels of the historical packets to obtain an attack type discrimination model. The above-mentioned fusion features of the packets refer to the features obtained by performing a feature fusion operation on the two-dimensional processing result of the packets and the time-series high-frequency features of the packets. The specific feature fusion method is not limited in this embodiment.

[0051] Finally, the embodiments of this application can also generate an alarm log according to the attack type of the target packet and the time-series high-frequency features of the target packet. Specifically, the alarm log can also include the following information: timestamp, source and destination IP addresses, port numbers, transport protocols, attack features, abnormal behavior descriptions, etc.

[0052] As can be seen from the above technical solutions, in view of the characteristics of large amount of data and less effective information required by traditional machine learning-based intrusion detection solutions, compared with other machine learning-based intrusion detection solutions, the embodiments of the present application draw on the thinking of graphics processing algorithms to picture the packet data, and add a feature extraction model for extracting the time-series high-frequency features of the packets and an anomaly detection model for judging anomalies according to the time-series high-frequency features of the packets before the traditional intrusion detection system. Only when the anomaly detection model determines that the packet is abnormal, the attack type discrimination model is used to determine the attack type of the packet.

[0053] It can be seen that the embodiments of the present application specifically propose to perform packet anomaly detection according to the time-series high-frequency features of the packets, reduce the amount of data involved in the calculation during the intrusion detection process, save the system computing resources, and improve the accuracy and speed of intrusion detection.

[0054] Based on the same inventive concept, the present application also provides an intrusion detection device, the structural schematic diagram of which is as Figure 3 shown, specifically including:

[0055] A feature extraction module 310, configured to perform two-dimensional data processing on a target packet, input the two-dimensional processing result of the target packet into a feature extraction model, and obtain the time-series high-frequency features of the target packet;

[0056] An anomaly detection module 320, configured to input the time-series high-frequency features of the target packet into an anomaly detection model, and obtain the anomaly detection result of the target packet;

[0057] A type discrimination module 330, configured to, when the anomaly detection result of the target packet is abnormal, input the two-dimensional processing result of the target packet and the time-series high-frequency features of the target packet into an attack type discrimination model, and obtain the attack type of the target packet.

[0058] As a specific implementation manner, the device further includes:

[0059] A first construction module 410, configured to construct a first machine learning model with the two-dimensional processing result of the packet as the input and the time-series high-frequency features of the packet as the output;

[0060] A first training module 420, configured to train the first machine learning model by using the two-dimensional processing result of the historical packet and the time-series high-frequency features of the historical packet, and obtain a feature extraction model.

[0061] As a specific implementation manner, the device further includes:

[0062] An anomaly acquisition module 510, configured to acquire historical packets with anomaly detection labels;

[0063] A second construction module 520, configured to construct a second machine learning model that takes the time-series high-frequency features of a message as input and the anomaly detection result of the message as output;

[0064] A second training module 530, configured to train the second machine learning model by using the time-series high-frequency features of the historical messages and the anomaly detection labels of the historical messages to obtain an anomaly detection model.

[0065] As a specific implementation manner, the apparatus further includes:

[0066] A type acquisition module 610, configured to acquire historical messages with attack type labels;

[0067] A third construction module 620, configured to construct a third machine learning model that takes the two-dimensional processing result of a message and the time-series high-frequency features of the message as input and the different attack types of the message as output;

[0068] A third training module 630, configured to train the third machine learning model by using the two-dimensional processing result of the historical messages, the time-series high-frequency features of the historical messages, and the attack type labels of the historical messages to obtain an attack type discrimination model.

[0069] As a specific implementation manner, the apparatus further includes:

[0070] A calculation module 710, configured to calculate the time-series high-frequency features of historical messages according to a target formula based on the two-dimensional processing result of a historical message sequence, where the target formula is as follows:

[0071]

[0072] where, I i is the two-dimensional processing result of the historical message, I edge is the time-series high-frequency feature of the historical message, and n is the number of messages in the historical message sequence.

[0073] As a specific implementation manner, the apparatus further includes:

[0074] An alarm module 810, configured to generate an alarm log according to the attack type of the target message and the time-series high-frequency features of the target message.

[0075] As a specific implementation manner, the apparatus further includes:

[0076] A release module 910, configured to release the target message when the anomaly detection result of the target message is normal.

[0077] An embodiment of the present application provides an electronic device, which may include: a memory and one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the electronic device can perform each function or step of the above method embodiment.

[0078] The structure of the electronic device may refer to Figure 4 the structure of the electronic device 100 shown.

[0079] The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0080] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions run on an electronic device, the electronic device is enabled to perform each function or step of the above method embodiment.

[0081] The above-mentioned computer-readable storage medium includes, but is not limited to, any one of the following: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc., which are various media that can store program code.

[0082] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, the computer is enabled to perform each function or step of the above method embodiment.

[0083] Among them, the electronic device, the computer-readable storage medium, and the computer program product provided by the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.

[0084] From the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0085] In several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the modules or units can be in electrical, mechanical or other forms.

[0086] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0087] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An intrusion detection method, characterized in that: The method comprises: Performing two-dimensional data processing on the target message, inputting the two-dimensional processing result of the target message into a feature extraction model to obtain the time series high-frequency features of the target message; Inputting the temporal high-frequency features of the target message into an anomaly detection model to obtain an anomaly detection result of the target message; When the abnormality detection result of the target message is abnormal, the two-dimensional processing result of the target message and the temporal high-frequency feature of the target message are input into the attack type discrimination model to obtain the attack type of the target message.

2. The method according to claim 1, characterized in that The method further comprises: Constructing a first machine learning model that takes the two-dimensional processing result of the message as input and the temporal high-frequency features of the message as output; The first machine learning model is trained using the two-dimensional processing results of historical messages and the time series high-frequency features of historical messages to obtain a feature extraction model.

3. The method according to claim 1, characterized in that The method further comprises: Obtain historical messages with anomaly detection tags; Construct a second machine learning model that uses the high-frequency temporal features of the message as input and the anomaly detection results of the message as output; The second machine learning model is trained using the time series high-frequency features of the historical messages and the anomaly detection labels of the historical messages to obtain an anomaly detection model.

4. The method according to claim 1, characterized in that The method further comprises: Get historical messages with attack type tags; Construct a third machine learning model that takes the two-dimensional processing results of the message and the high-frequency temporal features of the message as input and the abnormal attack type of the message as output; The third machine learning model is trained using the two-dimensional processing results of the historical messages, the time series high-frequency features of the historical messages, and the attack type labels of the historical messages to obtain an attack type discrimination model.

5. The method according to any one of claims 2 to 4, characterized in that: The method further comprises: According to the target formula, based on the two-dimensional processing results of the historical message sequence, the time series high-frequency features of the historical message are calculated. The target formula is as follows: Among them, I i is the two-dimensional processing result of historical messages, I edge is the temporal high-frequency feature of the historical message, and n is the number of messages in the historical message sequence.

6. The method according to claim 1, characterized in that The method further comprises: An alarm log is generated according to the attack type of the target message and the time series high-frequency characteristics of the target message.

7. The method according to claim 1, characterized in that The method further comprises: When the abnormality detection result of the target message is normal, the target message is released.

8. An intrusion detection device, characterized in that: The device comprises: A feature extraction module is used to perform two-dimensional data processing on the target message, input the two-dimensional processing result of the target message into a feature extraction model, and obtain the temporal high-frequency features of the target message; An anomaly detection module, used to input the temporal high-frequency features of the target message into an anomaly detection model to obtain an anomaly detection result of the target message; The type discrimination module is used to input the two-dimensional processing result of the target message and the temporal high-frequency characteristics of the target message into the attack type discrimination model when the abnormal detection result of the target message is abnormal, so as to obtain the attack type of the target message.

9. The device according to claim 8, characterized in that The device also includes: A first construction module is used to construct a first machine learning model that takes the two-dimensional processing result of the message as input and takes the time series high-frequency features of the message as output; The first training module is used to train the first machine learning model using the two-dimensional processing results of historical messages and the time series high-frequency features of historical messages to obtain a feature extraction model.

10. The device according to claim 8, characterized in that The device also includes: Anomaly acquisition module, used to obtain historical messages with anomaly detection tags; A second construction module is used to construct a second machine learning model that takes the time series high-frequency features of the message as input and takes the anomaly detection result of the message as output; The second training module is used to train the second machine learning model by using the time series high-frequency features of the historical messages and the anomaly detection labels of the historical messages to obtain an anomaly detection model.

11. The device according to claim 8, characterized in that The device also includes: Type acquisition module, used to obtain historical messages with attack type labels; A third construction module is used to construct a third machine learning model that takes the two-dimensional processing result of the message and the time series high-frequency features of the message as input and takes the abnormal attack type of the message as output; The third training module is used to train the third machine learning model by using the two-dimensional processing results of the historical messages, the time series high-frequency features of the historical messages, and the attack type labels of the historical messages to obtain an attack type discrimination model.

12. An electronic device, characterized in that: include: A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described in any one of claims 1-7.

13. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 7.

14. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network abnormal flow detection method, device and equipment

    CN111935170A

  • Network encrypted traffic identification method and device based on deep learning

    CN112003870A

  • Message anomaly detection method and device, equipment and medium

    CN114338129A

  • Automatic modulation classification method based on wavelet transform and multi-modal feature fusion

    CN116738278A

  • Unmanned aerial vehicle anomaly detection method based on memory enhanced auto-encoder integrated structure

    CN117235549A