Malicious traffic identification method and device based on space-time attention mechanism

By introducing a spatiotemporal attention mechanism in malicious traffic recognition, the weight of neighbor nodes closer to the current node is calculated, and the problem of difficulty in capturing topological time-varying and strong homogeneous network spatiotemporal correlation in the existing technology is solved, and a more efficient malicious traffic recognition effect is achieved.

CN120128431AActive Publication Date: 2025-06-10TSINGHUA UNIVERSITY +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510608514.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-06-10
Estimated Expiration
2045-05-13

AI Technical Summary

Technical Problem

Existing malicious traffic recognition methods based on graphs are difficult to effectively capture the spatiotemporal correlation between topology changes over time and strong homogeneous networks, resulting in poor recognition results.

Method used

A malicious traffic recognition method based on the spatiotemporal attention mechanism is proposed. Through the graph convolutional neural network model combined with the attention mechanism, the aggregation coefficients of each neighbor node are calculated, and the neighbor nodes that are closer to the time and spatial characteristics of the current node are given greater weight, thereby more accurately depicting the spatiotemporal correlation in topological time-varying and strong homogeneous networks.

Benefits of technology

Through the application of the spatiotemporal attention mechanism, the accuracy and robustness of malicious traffic recognition are significantly improved, and the semantic correlation between flows can be captured more effectively, making the characteristics of malicious traffic and normal traffic more separate in the feature space.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128431A_ABST
    Figure CN120128431A_ABST
Patent Text Reader

Abstract

The invention discloses a malicious traffic identification method and device based on a space-time attention mechanism. The method comprises the following steps: calculating space-time characteristics of each stream in a stream training data set; obtaining a spatial-temporal feature combination of source and target neighbor streams of each stream in the stream training data set, and calculating neighbor embedding of each stream; inputting the spatial-temporal characteristics and the neighbor embedding into a discriminator to calculate a malicious degree score; calculating a difference value between the malicious degree score and a flow label, calculating gradients of parameters of an encoder, an attention network and a discriminator relative to the difference value, updating network parameters, and recording a threshold value which enables a flow training data set to reach the balance of an optimal recall rate and a false positive rate; and calculating a malicious degree score of the to-be-detected stream by using the trained discriminator, and comparing the malicious degree score with a threshold value to identify whether the to-be-detected stream is a malicious stream. According to the method, the problem of insufficient utilization of space-time correlation between streams in graph-based malicious traffic identification is solved, so that accurate hidden malicious traffic identification is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of next-generation Internet application security, cyberspace security, and artificial intelligence technology, and is a technology mainly used for identifying hidden malicious traffic. In particular, it relates to a malicious traffic identification method and device based on a spatio-temporal attention mechanism. Background Art

[0002] In recent years, graph-based malicious traffic identification methods have emerged. These methods represent traffic as a network topology graph with addresses as nodes and flows as edges, and use a graph convolutional neural network model for malicious traffic identification. A graph is a data structure composed of a set of nodes and a set of edges representing the connection relationships between nodes. Two nodes connected by an edge are neighbor nodes to each other. The graph convolutional neural network analogizes the definition of convolution in the field of image recognition and defines the convolution operation on the graph as the aggregation of the features of neighbor nodes, so that the model comprehensively learns the node features and the spatial features of the topology graph to achieve a better learning effect.

[0003] In the graph convolutional neural network, there are multiple calculation models for the aggregation coefficient of aggregating the features of neighbor nodes. The traditional graph convolutional neural network model believes that the more nodes a node is associated with, the less influence it has on each neighbor, and the less influence each neighbor has on it. Therefore, under this model, the aggregation coefficient is calculated according to the degrees of the two associated nodes, and the larger the degree, the smaller the aggregation coefficient. In the relational graph convolutional neural network model, the aggregation coefficient is assigned according to the type of the associated edge. The rarer the type of the edge associated with the current node, the larger the aggregation coefficient.

[0004] These existing models mainly infer the influence of neighbor nodes on the current node based on the static graph topology structure, and have limited ability to depict scenarios where the topology changes over time. In addition, there is an isomorphism phenomenon in many real networks, that is, similar nodes are more closely associated. For example, in a traffic interaction network, neighbor (same-source or same-destination address) flows that are close in appearance time and similar in traffic pattern to the current flow often come from the same session and serve the same target. When identifying the type of the current flow, these similar neighbor flows provide more valuable information than other neighbor flows, while the existing graph convolutional neural network models are difficult to capture this semantic correlation. Summary of the Invention

[0005] The present invention aims to solve at least one of the technical problems in the related art to some extent.

[0006] The present invention proposes a malicious traffic recognition method based on a spatio-temporal attention mechanism, which uses a spatio-temporal attention-based graph convolutional neural network model to aggregate the features of neighbor nodes, and applies the attention mechanism to calculate the aggregation coefficients of each neighbor node, assigning greater weights to neighbor nodes that are closer to the current node in terms of time and space features, thereby more accurately characterizing the spatio-temporal correlation between nodes in a topology time-varying and strongly homogeneous network and achieving a more excellent learning effect.

[0007] Another object of the present invention is to propose a malicious traffic recognition device based on a spatio-temporal attention mechanism.

[0008] To achieve the above object, on the one hand, the present invention proposes a malicious traffic recognition method based on a spatio-temporal attention mechanism, including: Calculating the spatio-temporal features of each flow in the flow training dataset by using an initialized encoder; Obtaining the spatio-temporal feature combinations of the source and destination neighbor flows of each flow in the flow training dataset, and calculating the neighbor embeddings of each flow by using an attention network; Inputting the spatio-temporal features and the neighbor embeddings into a discriminator to calculate the malicious degree score; Calculating the difference between the malicious degree score and the flow label, and calculating the gradients of the parameters of the encoder, the attention network, and the discriminator with respect to the difference, updating the network parameters to obtain a trained neural network model, and recording the threshold that enables the flow training dataset to achieve the best balance of recall rate and false positive rate; Calculating the malicious degree score of the flow to be detected by using the trained discriminator, and comparing it with the threshold to identify whether the flow to be detected is a malicious flow according to the result of the numerical comparison.

[0009] The malicious traffic recognition method based on the spatio-temporal attention mechanism in the embodiments of the present invention may further have the following additional technical features: In an embodiment of the present invention, calculating the spatio-temporal features of each flow in the flow training dataset by using an initialized encoder includes: Initializing the encoder, where the encoder includes a time encoder and a traffic pattern encoder , and the encoder adopts a first neural network model; Constructing a flow training dataset; Presetting the timestamp of the th flow in the flow training dataset as , and the statistical feature as , inputting the flow timestamp and the statistical feature into the time encoder and the traffic pattern encoder respectively to obtain the time encoding and the traffic pattern encoding , and taking the time encoding And flow pattern encoding Combine to obtain the spatio-temporal characteristics of the flow , where Indicates that two vectors are concatenated end to end to form a single vector.

[0010] In one embodiment of the present invention, obtaining the spatio-temporal feature combinations of the source and destination neighbor flows of each flow in the flow training dataset, and calculating the neighbor embedding of each flow using an attention network, includes: Preset the source address of the th flow in the flow training dataset as , and the destination address as , then the source neighbor of the th flow is the index set of all flows with the source address , and the destination neighbor is the index set of all flows with the destination address ; Initialize the attention network, the attention network adopts a second neural network model, and the query vector of the attention network is the spatio-temporal feature of the th flow, and the key vector and value vector are both the spatio-temporal feature combinations of the source and destination neighbor flows of the th flow:

[0011] Among them, indicates randomly selecting elements from the set , and the output of the attention network is the aggregated neighbor embedding ; Calculate the neighbor embedding of the th flow in the flow training dataset as:

[0012] Among them, is the neighbor embedding of the th flow.

[0013] In one embodiment of the present invention, inputting the spatio-temporal features and the neighbor embeddings into a discriminator to calculate the maliciousness score, includes: Initialize the discriminator ; The discriminator adopts a third neural network model; Input the spatio-temporal features of the th flow and the neighbor embedding Input to the discriminator The output is the maliciousness score of the th flow in the flow training dataset.

[0014] In one embodiment of the present invention, the calculation formula of the threshold is:

[0015] Where and are the recall rate and false positive rate of the model under a series of thresholds, respectively.

[0016] To achieve the above object, on the other hand, the present invention proposes a malicious traffic recognition device based on a spatio-temporal attention mechanism, including: A spatio-temporal feature calculation module, configured to calculate the spatio-temporal features of each flow in the flow training dataset by using the initialized encoder; A neighbor embedding calculation module, configured to obtain the spatio-temporal feature combinations of the source and destination neighbor flows of each flow in the flow training dataset, and calculate the neighbor embedding of each flow by using an attention network; A maliciousness score calculation module, configured to input the spatio-temporal features and the neighbor embedding into the discriminator to calculate the maliciousness score; A threshold calculation module, configured to calculate the difference between the maliciousness score and the flow label, and calculate the gradients of the parameters of the encoder, the attention network, and the discriminator with respect to the difference, update the network parameters to obtain a trained neural network model, and record the threshold that enables the flow training dataset to achieve the best balance between the recall rate and the false positive rate; A flow detection module, configured to calculate the maliciousness score of the flow to be detected by using the trained discriminator, and compare the size with the threshold, so as to identify whether the flow to be detected is a malicious flow according to the numerical comparison result.

[0017] The malicious traffic recognition method and device based on the spatio-temporal attention mechanism in the embodiments of the present invention apply multiple neural network models to the task of identifying hidden malicious traffic, encode the timestamp and traffic pattern of the flow as its spatio-temporal features, use the attention mechanism to aggregate the information of the current flow and its neighbor flows according to the spatio-temporal feature similarity as the neighbor embedding of the current flow, and then combine the spatio-temporal features of the current flow to identify malicious traffic, thereby improving the malicious traffic recognition effect.

[0018] The additional aspects and advantages of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present invention. Description of the Drawings

[0019] The above and / or additional aspects and advantages of the present invention will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where: Figure 1It is a flowchart of a malicious traffic recognition method based on a spatio-temporal attention mechanism according to an embodiment of the present invention; Figure 2 It is a structural diagram of a malicious traffic recognition device based on a spatio-temporal attention mechanism according to an embodiment of the present invention. Detailed implementation manners

[0020] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.

[0021] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0022] The malicious traffic recognition method and device based on a spatio-temporal attention mechanism according to an embodiment of the present invention will be described below with reference to the drawings.

[0023] Figure 1 It is a flowchart of a malicious traffic recognition method based on a spatio-temporal attention mechanism according to an embodiment of the present invention, as Figure 1 shown, the method includes: S1, calculating the spatio-temporal features of each flow in the flow training dataset by using the initialized encoder.

[0024] First, initialize the encoder. The encoder consists of a time encoder and a traffic pattern encoder which are both composed of two parts. Both parts use the first neural network model. The input of the time encoder is the flow timestamp with a dimension of 1, and the output dimension is ; the input of the traffic pattern encoder is dimensional statistical features, and the output dimension is . The specific network and activation function type depend on the specific application scenario. The neural network parameters are initialized by using the following random initialization method: for the parameter matrix of the th layer ( ), its elements follow a Gaussian distribution with a mean of 0 and a variance of , where is the number of neurons in the th layer; the parameters of the first layer are initialized as a random real number matrix following a standard normal distribution.

[0025] Secondly, use a% of the data in the flow training dataset as the training set, and the rest as the test set, ensuring that there is no intersection between the training set and the test set. For example, the first a% of the data in the dataset can be used as the training set, and the rest as the test set.

[0026] Then, calculate the spatio-temporal features of the flows in the flow training dataset. Assume the timestamp of the th flow is , and the statistical feature is . Input the flow timestamp and the statistical feature into the time encoder and the traffic pattern encoder respectively to obtain the time encoding and the traffic pattern encoding . Combine the time encoding and the traffic pattern encoding to obtain the spatio-temporal feature of the flow, where

[0027] means concatenating the two vectors end to end to form a single vector.

[0027] S2. Obtain the spatio-temporal feature combinations of the source and destination neighbor flows of each flow in the flow training dataset, and use the attention network to calculate the neighbor embedding of each flow.

[0028] First, find the set of neighbor flows for each flow in the flow training dataset. Assume the source address of the th flow is , and the destination address is . Then the source neighbor of the th flow is the index set of all flows with the source address , and the destination neighbor is the index set of all flows with the destination address .

[0029] Secondly, initialize the attention network. The query vector of the attention network is the spatio-temporal feature of the th flow, and the key vector and the value vector are both the spatio-temporal feature combinations of its source and destination neighbor flows:

[0030] where means randomly selecting elements from the set . The output of the attention network is the aggregated neighbor embedding , with the dimension . The number of attention heads, the network, and the type of activation function depend on the specific application scenario. The attention network adopts a second neural network model, and the neural network parameters are initialized using the following random initialization method: For the layer parameter matrix ( ), its elements follow a Gaussian distribution with a mean of 0 and a variance of , where is the number of neurons in the layer; the parameters of the first layer are initialized as a random real number matrix following a standard normal distribution.

[0031] Then, calculate the neighbor embeddings for the flows in the flow training dataset. The neighbor embedding of the th flow is:

[0032] where is the value of the key vector and the value vector of the attention network parameters.

[0033] S3, input the spatio-temporal features and neighbor embeddings into the discriminator to calculate the maliciousness score.

[0034] S4, calculate the difference between the maliciousness score and the flow label, and calculate the gradients of the encoder, attention network, and discriminator parameters with respect to the difference, update the network parameters to obtain a trained neural network model, and record the threshold that makes the flow training dataset achieve the best balance between recall rate and false positive rate.

[0035] First, initialize the discriminator. The discriminator adopts a third neural network model, and the input is the spatio-temporal features of the th flow and the neighbor embedding , with a dimension of , and the output is the maliciousness score of the flow, with a dimension of 1 and a value range of . The specific network and activation function type depend on the specific application scenario. The neural network parameters are initialized using the following random initialization method: For the layer parameter matrix ( ), its elements follow a Gaussian distribution with a mean of 0 and a variance of , where is the number of neurons in the layer; the parameters of the first layer are initialized as a random real number matrix following a standard normal distribution.

[0036] Secondly, calculate the maliciousness score for the flows in the flow training dataset:

[0037] Then, for each flow in the streaming training dataset, calculate the difference between the maliciousness score and the flow label (the malicious flow label is 1 and the benign flow label is 0), and then calculate the gradients of the difference with respect to the parameters of the encoder, attention network, and discriminator, perform backpropagation to update the network parameters, and repeat for multiple rounds until the neural network model converges. Record the threshold that achieves the best balance between recall rate and false positive rate for the streaming training dataset. The calculation method is as follows:

[0038] where, and are the recall rate and false positive rate of the model at a series of thresholds, respectively.

[0039] S5. Use the trained discriminator to calculate the maliciousness score of the flow to be detected, and compare it with the threshold to identify whether the flow to be detected is a malicious flow according to the result of the numerical comparison.

[0040] Specifically, deploy the trained first neural network model, second neural network model, and third neural network model to the defense system of the network environment for malicious traffic identification.

[0041] First, in the detection phase, use the trained time encoder and traffic pattern encoder to calculate the spatio-temporal feature of the th flow to be detected.

[0042] Second, find the source neighbor and destination neighbor of the th flow to be detected in the training set, and use the trained attention network to calculate its neighbor embedding .

[0043] Then, use the trained discriminator to calculate the maliciousness score of the flow to be detected. If the maliciousness score output by the model is higher than the threshold obtained during model training, then determine that the flow is a malicious flow and send an alarm message to the network administrator in a timely manner; otherwise, consider the flow to be a normal flow.

[0044] In summary, the present invention proposes to use a spatio-temporal attention mechanism to aggregate neighbor flow information. Different from the traditional graph neural network that calculates the aggregation coefficient based on the static topological features of nodes, the spatio-temporal attention graph neural network simultaneously considers the time and traffic pattern similarities of neighbor flows, assigns a higher aggregation coefficient to neighbors more similar to the current flow, and thereby improves the information contribution degree of similar neighbors to the current flow. In terms of the process, the present invention includes two stages: training and detection. In the training stage, first, the timestamps and traffic patterns of each flow in the training set are input into the encoder to calculate the spatio-temporal features of the flow; then, according to the relationship of the same source or the same destination address between flows, the neighbor flow set of each flow is found; furthermore, the spatio-temporal features of the current flow and the spatio-temporal features of neighbor flows are combined and input into the attention neural network to obtain the neighbor embedding of the current flow; finally, the spatio-temporal features of the current flow and the neighbor embedding are combined and input into the discriminator to obtain the malicious degree score of the current flow, and the encoder, discriminator, and attention network are trained in combination with the flow label (i.e., whether the current flow is malicious). In the detection stage, the spatio-temporal features of the flow to be detected are calculated using the encoder, the adjacent flows in the training set are found, the neighbor embedding is calculated using the attention neural network, and then combined with its spatio-temporal features, and the discriminator is used to determine whether the flow is a malicious flow. The core of the present invention lies in fusing the time and space features of the flow and using the attention mechanism to allocate the aggregation weight, so as to capture the semantic correlation in the traffic interaction network, improve the graph learning effect, and achieve more accurate and efficient malicious traffic identification.

[0045] According to the malicious traffic identification method based on the spatio-temporal attention mechanism in an embodiment of the present invention, the problem of insufficient utilization of the spatio-temporal correlation between flows in graph-based malicious traffic identification is solved, thereby improving the identification effect of covert malicious traffic. The spatio-temporal attention mechanism simultaneously considers the time and traffic pattern similarities of neighbor flows, assigns a higher aggregation coefficient to neighbor flows more similar to the current flow, and thereby improves the information contribution degree of similar neighbors to the current flow, enabling the model to better capture the semantic correlation between flows on a traffic interaction network with time-varying topology and strong homogeneity, enabling the graph convolutional neural network to more effectively aggregate neighbor information, separating the features of malicious traffic and normal traffic more in the feature space, and thereby improving the identification accuracy and robustness of the model.

[0046] To implement the above embodiment, as Figure 2 shown, the present embodiment also provides a malicious traffic identification device 10 based on the spatio-temporal attention mechanism, including: A spatio-temporal feature calculation module 100, configured to calculate the spatio-temporal features of each flow in the flow training dataset by using the initialized encoder; A neighbor embedding calculation module 200, configured to obtain the spatio-temporal feature combination of the source and destination neighbor flows of each flow in the flow training dataset, and calculate the neighbor embedding of each flow by using the attention network; The maliciousness degree scoring module 300 is used to input the spatio-temporal features and the neighbor embeddings into a discriminator to calculate the maliciousness degree score; The threshold calculation module 400 is used to calculate the difference between the maliciousness degree score and the flow label, calculate the gradients of the parameters of the encoder, the attention network, and the discriminator with respect to the difference, update the network parameters to obtain a trained neural network model, and record the threshold that enables the flow training dataset to achieve the best balance between recall rate and false positive rate; The flow detection module 500 is used to calculate the maliciousness degree score of the flow to be detected by using the trained discriminator, and compare it with the threshold to identify whether the flow to be detected is a malicious flow according to the result of the numerical comparison.

[0047] Further, the spatio-temporal feature calculation module 100 is further used for: Initializing an encoder, where the encoder includes a time encoder and a traffic pattern encoder , and the encoder adopts a first neural network model; Constructing a flow training dataset; Presetting that the time stamp of the th flow in the flow training dataset is , the statistical feature is , inputting the flow time stamp and the statistical feature into the time encoder and the traffic pattern encoder respectively to obtain a time encoding and a traffic pattern encoding , and merging the time encoding and the traffic pattern encoding to obtain the spatio-temporal feature of the flow , where means concatenating two vectors end to end to form a vector.

[0048] Further, the neighbor embedding calculation module 200 is further used for: Presetting that the source address of the th flow in the flow training dataset is , the destination address is , then the source neighbor of the th flow is the index set of all flows with the source address , and the destination neighbor is the index set of all flows with the destination address ; Initializing an attention network, where the attention network adopts a second neural network model, and the query vector of the attention network is the spatio-temporal feature of the th flow, and the key vector​ Sum vector Both are The spatio-temporal feature combination of the source and destination neighbor flows of the

[0049] Among them, Indicates randomly selecting from the set elements, and the output of the attention network is the aggregated neighbor embedding ; Calculating the neighbor embedding of the th flow in the flow training dataset is:

[0050] Among them, is the neighbor embedding of the th flow.

[0051] Furthermore, the maliciousness score calculation module 300 is further configured to: Initialize the discriminator ; The discriminator Adopts the third neural network model; Input the spatio-temporal features of the th flow and the neighbor embedding into the discriminator The output is the maliciousness score of the th flow in the flow training dataset.

[0052] Furthermore, the calculation formula of the threshold is:

[0053] Among them, and are the recall rate and false positive rate of the model under a series of thresholds respectively.

[0054] According to the malicious traffic recognition device based on the spatio-temporal attention mechanism of the embodiment of the present invention, the problem of insufficient utilization of the spatio-temporal correlation between flows in graph-based malicious traffic recognition is solved, thereby improving the recognition effect of concealed malicious traffic. The spatio-temporal attention mechanism simultaneously considers the time and traffic pattern similarities of neighbor flows, assigns a higher aggregation coefficient to neighbor flows more similar to the current flow, thereby improving the information contribution degree of similar neighbors to the current flow, enabling the model to better capture the semantic correlation between flows on a traffic interaction network with time-varying topology and strong homogeneity, enabling the graph convolutional neural network to more effectively aggregate neighbor information, separating the features of malicious traffic and normal traffic more in the feature space, thereby improving the recognition accuracy and robustness of the model.

[0055] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0056] In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically and clearly defined.

Claims

1. A malicious traffic identification method based on spatiotemporal attention mechanism, characterized in that: include: Use the initialized encoder to calculate the spatiotemporal features of each stream in the stream training dataset; Obtain the spatiotemporal feature combination of the source and destination neighbor flows of each flow in the flow training dataset, and use the attention network to calculate the neighbor embedding of each flow; Inputting the spatiotemporal features and the neighbor embedding into a discriminator to calculate a maliciousness score; Calculate the difference between the maliciousness score and the flow label, and calculate the gradient of the encoder, attention network and discriminator parameters relative to the difference, update the network parameters to obtain the trained neural network model, and record the threshold that makes the flow training dataset achieve the best recall rate and false positive rate balance; The trained discriminator is used to calculate the maliciousness score of the flow to be detected, and the score is compared with the threshold to identify whether the flow to be detected is a malicious flow based on the numerical comparison result.

2. The method according to claim 1, characterized in that The initialized encoder is used to calculate the spatiotemporal features of each stream in the stream training dataset, including: Initialize the encoder, including the time encoder and flow pattern encoder , the encoder adopts a first neural network model; Build a streaming training dataset; The preset stream training data set The timestamp of the stream is , the statistical characteristics are , the stream timestamp and statistical characteristics Input the time encoder and traffic mode encoder respectively to get the time code and traffic pattern encoding , encode the time and traffic pattern encoding Merge to obtain the spatiotemporal characteristics of the flow ,in It means to concatenate two vectors end to end into one vector.

3. The method according to claim 2, characterized in that Get the spatiotemporal feature combination of the source and destination neighbor flows of each flow in the flow training dataset, and use the attention network to calculate the neighbor embedding of each flow, including: The preset stream training data set The source address of the stream is , the destination address is , then Source neighbors of a stream For all source addresses The index set of the flow, the destination neighbor For all destination addresses The index collection of the stream; Initialize the attention network, the attention network uses the second neural network model, the attention network The query vector It is Spatial and temporal characteristics of streams , the key vector Sum value vector All are The combination of spatiotemporal features of the source and destination neighbor streams of a stream: in, Represents from the set Randomly select elements, and the output of the attention network is the aggregated neighbor embedding ; Calculate the number of The neighbor embedding of a stream is: in, For the Neighbor embeddings for streams.

4. The method according to claim 3, characterized in that The spatiotemporal features and the neighbor embedding are input into the discriminator to calculate the maliciousness score, including: Initialize the discriminator ; Discriminator Using the third neural network model; The first Spatial and temporal characteristics of streams and neighbor embedding Input to the discriminator The output is the first The maliciousness score of the stream.

5. The method according to claim 1, characterized in that The calculation formula of the threshold is: in, and are the recall and false positive rate of the model under a range of thresholds, respectively.

6. A malicious traffic identification device based on spatiotemporal attention mechanism, characterized in that: include: A spatiotemporal feature calculation module, used to calculate the spatiotemporal features of each stream in the stream training data set using the initialized encoder; The neighbor embedding calculation module is used to obtain the spatiotemporal feature combination of the source and destination neighbor flows of each flow in the flow training dataset, and calculate the neighbor embedding of each flow using the attention network; A maliciousness score calculation module, used for inputting the spatiotemporal features and the neighbor embedding into a discriminator to calculate a maliciousness score; The threshold calculation module is used to calculate the difference between the maliciousness score and the flow label, and calculate the gradient of the encoder, attention network and discriminator parameters relative to the difference, update the network parameters to obtain the trained neural network model, and record the threshold that makes the flow training data set achieve the best recall rate and false positive rate balance; The flow detection module is used to calculate the maliciousness score of the flow to be detected by using the trained discriminator, and compare the size with the threshold to identify whether the flow to be detected is a malicious flow based on the numerical comparison result.

7. The device according to claim 6, characterized in that The spatiotemporal feature calculation module is also used for: Initialize the encoder, including the time encoder and flow pattern encoder , the encoder adopts a first neural network model; Build a streaming training dataset; The preset stream training data set The timestamp of the stream is , the statistical characteristics are , the stream timestamp and statistical characteristics Input the time encoder and traffic mode encoder respectively to get the time code and traffic pattern encoding , encode the time and traffic pattern encoding Merge to obtain the spatiotemporal characteristics of the flow ,in It means to concatenate two vectors end to end into one vector.

8. The device according to claim 7, characterized in that The neighbor embedding calculation module is also used for: The preset stream training data set The source address of the stream is , the destination address is , then Source neighbors of a stream For all source addresses The index set of the flow, the destination neighbor For all destination addresses The index collection of the stream; Initialize the attention network, the attention network uses the second neural network model, the attention network The query vector It is Spatial and temporal characteristics of streams , the key vector Sum value vector All are The combination of spatiotemporal features of the source and destination neighbor streams of a stream: in, Represents from the set Randomly select elements, and the output of the attention network is the aggregated neighbor embedding ; Calculate the number of The neighbor embedding of a stream is: in, For the Neighbor embeddings for streams.

9. The device according to claim 8, characterized in that The maliciousness score calculation module is also used to: Initialize the discriminator ; Discriminator Using the third neural network model; The first Spatial and temporal characteristics of streams and neighbor embedding Input to the discriminator The output is the first The maliciousness score of the stream.

10. The device according to claim 6, characterized in that The calculation formula of the threshold is: in, and are the recall and false positive rate of the model under a range of thresholds, respectively.

Citation Information

Patent Citations

  • Encrypted malicious flow identification method and device based on spatial-temporal characteristics and attention mechanism

    CN116094792A

  • Malicious traffic detection method based on integral space-time diagram convolutional neural network fused with space-time attention

    CN117579290A

  • Industrial Internet of Things anomaly detection method based on time-space gated map attention network

    CN118018258A

  • Hidden malicious traffic identification method and device based on flipped graph

    CN119743332A