Method and device for generating antagonistic malicious traffic
By combining the generative adversarial network and reinforcement learning mechanism, the traffic characteristics are extracted and processed, and the adversarial malicious traffic characteristics of evasion detection systems are solved, and the problem of difficulty in identifying adversarial malicious activities in encrypted traffic is achieved in the existing technology, and the robustness of efficient malicious traffic generation and detection models is achieved.
Patent Information
- Application Number
- CN202510327660.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-19
AI Technical Summary
The prior art is difficult to effectively identify and detect adversarial malicious activities hidden in encrypted traffic, especially in the face of complex encrypted traffic and polymorphic hybrid attacks.
Combining the generative adversarial network, heuristic mutation technology and reinforcement learning mechanism, traffic features are extracted and preprocessed to generate adversarial malicious traffic feature vectors, and through adversarial training, it avoids the recognition of the intrusion detection system.
It improves the concealment and deceptiveness of adversarial malicious traffic, makes it more difficult for traditional network intrusion detection systems to effectively detect these mutated traffic, and builds a highly robust detection model to deal with complex encrypted malicious traffic.
Smart Images

Figure CN120151045A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a method and a device for generating antagonistic malicious traffic, belonging to the technical field of network security. Background Art
[0002] In the current network environment, the detection and identification of encrypted traffic has become one of the core challenges in building an effective network protection system. As attackers increasingly use encryption technology to hide malicious behavior, traditional port- or load-based detection methods face huge challenges in processing complex encrypted traffic and find it difficult to effectively identify malicious activities hidden in encrypted traffic. In addition, the widespread application of advanced technologies such as deep learning and generative adversarial networks (GANs) enables attackers to generate adversarial samples to further circumvent existing detection methods, making adversarial encrypted traffic an important issue that needs to be urgently addressed in network security. Therefore, how to improve the robust detection capability of adversarial encrypted traffic while improving the performance of the detection system has become an important issue in the field of network security.
[0003] In terms of encrypted traffic detection, researchers at home and abroad have gradually turned to machine learning and deep learning methods to automatically extract features from encrypted traffic and improve the ability to identify potential malicious behaviors. For example, models such as convolutional neural networks (CNN) and long short-term memory networks (LSTM) have been widely used to capture potential malicious features in network traffic, and reduce redundant information through feature selection and dimensionality reduction techniques (such as principal component analysis PCA) to improve the computational efficiency of detection models. However, these traditional encrypted traffic detection systems still have significant limitations when facing adversarial samples, because the load part of encrypted traffic is often unstructured data that is difficult to directly represent as variables. In contrast, non-load features are more suitable for detecting attacks that rely on traffic behavior, such as DoS / DDoS, scanning, brute force cracking, and botnet attacks, while it is difficult to effectively deal with attacks involving specific content (such as SQL injection). In addition, polymorphic hybrid attacks have been able to bypass load-based anomaly detection, and attackers can also add adversarial perturbations to malicious traffic, making it difficult for existing detection models to effectively identify these new adversarial samples, thereby evading detection. Therefore, how to deal with these complex disturbances during the detection process and improve the robustness of the model has become an important challenge in current research.
[0004] In response to the above challenges, researchers first attempted to build detection systems using technologies such as machine learning. Compared with traditional methods, machine learning technologies have lower false positive and false negative rates, but their robustness against adversarial attacks has not been fully considered and verified. The core challenge of such research is that attackers may make appropriate changes to the traffic while maintaining communication functions and malicious features, making it difficult to be recognized by detection models. For example, researchers have gradually attempted to use generative models such as generative adversarial networks (GANs) to generate adversarial encrypted traffic. By making specific modifications to traffic features, it can evade the recognition of existing detection systems. The core challenge of such research is how to make appropriate modifications to the traffic while maintaining communication functions and malicious features, making it difficult to be recognized by detection models. Some adversarial attack methods mostly rely on the attacker's comprehensive understanding of the target detection system, and this assumption is often difficult to meet in practical applications.
[0005] Meanwhile, some research has also explored enhancing the anti-interference ability of detection models against adversarial attacks by introducing adversarial training and robust optimization. For example, through multi-modal feature fusion technology, traffic features from the time domain, space, and protocol behavior are combined to build a more robust detection model; in addition, by introducing adversarial training, the model shows higher robustness when facing adversarial samples. To further improve the robustness of the detection system, researchers have also used ensemble learning technology to combine the advantages of multiple detection models to build a more effective detection mechanism. By integrating multiple learning models, such as random forests, gradient boosting decision trees, etc., and combining with deep learning models, a multi-level detection framework is established to effectively deal with malicious behaviors in encrypted traffic. In addition, for low-knowledge attack scenarios that may exist in practical applications, researchers are also exploring the development of more lightweight and efficient feature extraction and matching methods to enhance the protection ability of the detection system under knowledge-limited conditions. Therefore, future research needs to develop a more flexible and robust malicious traffic generation mechanism under low-knowledge conditions, and also needs to propose targeted detection strategies to deal with the complex strategies of attackers and improve the adaptability and robustness of the detection system. Summary of the Invention
[0006] In view of this, the present invention proposes an adversarial malicious traffic generation method and device, which realizes the diversification and concealment processing of encrypted malicious traffic by combining generative adversarial networks, heuristic mutation technology, and reinforcement learning mechanisms.
[0007] The technical solution of the present invention is implemented as follows:
[0008] In the first aspect, an adversarial malicious traffic generation method of the present invention has the following specific process:
[0009] First, extract features from the traffic through the feature extraction and preprocessing steps, convert the traffic data packets into reversible high-dimensional metadata feature vectors, generate malicious traffic feature vectors and benign traffic feature vectors, and add noise to the malicious traffic feature vectors;
[0010] Secondly, input the malicious traffic features with added noise into the generator. The pre-trained generator generates adversarial malicious traffic feature vectors and mutates the malicious traffic feature vectors to generate mutated malicious traffic feature vectors;
[0011] Thirdly, input the mutated malicious traffic feature vectors and the benign traffic feature vectors into the intrusion detection system NIDS, and input the prediction results of NIDS into the discriminator;
[0012] Finally, the discriminator classifies the prediction results of NIDS to output probability values, and uses them as rewards for the generator to create new adversarial mutated malicious traffic features;
[0013] Through the adversarial training between the generator and the discriminator, the generator generates adversarial malicious traffic feature vectors that can evade the intrusion detection system NIDS.
[0014] Optionally, before the adversarial training between the generator and the discriminator of the present invention, the generator is pre-trained with a large number of benign traffic feature vectors.
[0015] Optionally, the loss function of the adversarial training between the generator and the discriminator of the present invention includes adversarial loss and reconstruction loss l G ,
[0016]
[0017] where f is the malicious traffic feature vector, z represents Gaussian distribution noise, F mal represents the set of malicious traffic feature vectors, D represents the discriminator, G(f,z) represents the output of the generator, L(f,G(f,z)) represents the error between the input and output of the generator, and D(G(f,z)) represents the output of the discriminator;
[0018] The generator updates its parameters by maximizing the reward function J(θ):
[0019]
[0020] where D(x) is the probability output by the discriminator for the generated sample x (i.e., the adversarial malicious traffic feature vector output by the generator), and π θ is the parameterized generation strategy of the generator.
[0021] Optionally, the loss function of the discriminator of the present invention is:
[0022]
[0023] Among them, is a benign traffic feature vector, is an adversarial malicious traffic feature vector, λ is a hyperparameter that controls the gradient penalty intensity, D(f) represents the discrimination probability of the discriminator for the input feature f, and represents the probability that the discriminator believes that f belongs to the true benign traffic. represents a random interpolation point between the true benign feature and the adversarial malicious traffic feature, represents the expected value, represents the interpolation point gradient of, represents the discriminator's determination probability for the interpolation point , ∥∥ 2 represents the L2 norm.
[0024] Optionally, the random interpolation point between the true benign feature and the adversarial malicious traffic feature in the present invention is:
[0025]
[0026] Optionally, the objective function for optimizing the generator using the PPO algorithm in the present invention is:
[0027]
[0028] Among them, π θ (a t |s t ) represents the probability that the generator with parameter θ takes action a t under state s t , A t is the advantage function estimate, represents the probability that the generator takes action a t under state s t before the parameter is updated to θ, and ∈ is a hyperparameter used to control the policy update range.
[0029] Optionally, the present invention uses the RFPMPSO traffic mutation and optimization algorithm to mutate the malicious traffic feature vector. The RMPFPSO traffic mutation and optimization algorithm is a particle swarm optimization algorithm with random mutation and dynamic perception factor, which automatically identifies the best traffic mutation sample from the generated adversarial traffic samples.
[0030] Optionally, the specific process of mutating using the RFPMPSO traffic mutation and optimization algorithm in the present invention is:
[0031] First step, for the adversarial malicious traffic feature vector, from position xn Reconstruct the variant traffic. After directly retrieving the original traffic, replace it with the timestamp in x mal to obtain a variant feature vector; for the variant feature vector, refer to the protocol layer number that determines the protocol type;
[0032] Second, use an extractor to extract features from the variant feature vector;
[0033] Third, calculate the distance between the extracted features and the input adversarial features to determine the mutation effect.
[0034] Optionally, the present invention further includes training an intrusion detection system NIDS using the adversarial malicious traffic feature vectors generated by the generator, specifically: training in an adaptive and iterative adversarial data augmentation manner.
[0035] In a second aspect, the present invention provides an adversarial malicious traffic generation device, including: a processor, a generator, a discriminator, and a data mutation module;
[0036] The processor is configured to extract features from the traffic and perform preprocessing, convert the traffic data packet into a reversible high-dimensional metadata feature vector, generate malicious traffic feature vectors and benign traffic feature vectors, and add noise to the malicious traffic feature vectors;
[0037] The generator is configured to receive the malicious traffic features with added noise and generate adversarial malicious traffic feature vectors;
[0038] The data mutation module is configured to mutate the malicious traffic feature vectors to generate mutated malicious traffic feature vectors;
[0039] The discriminator is configured to receive the prediction results of the intrusion detection system NIDS for the input mutated malicious traffic feature vectors and benign traffic feature vectors, output the prediction results for classification and output probability values, and use them as rewards for the generator to create new adversarial mutated malicious traffic features;
[0040] Through the adversarial training between the generator and the discriminator, the generator generates adversarial malicious traffic feature vectors that evade the intrusion detection system NIDS.
[0041] Beneficial effects:
[0042] First, the generator continuously optimizes the generation strategy through a reinforcement learning process to improve the concealment and deception of adversarial traffic, making it more difficult for traditional network intrusion detection systems (NIDS) to effectively detect these mutated traffic.
[0043] Second, the present invention also proposes a highly robust detection model constructed based on an adaptive and iterative adversarial data augmentation method, forming a complete network security solution to systematically improve the detection performance against adversarial encrypted malicious traffic. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0045] Figure 1 is the adversarial encrypted malicious traffic attack framework;
[0046] Figure 2 is the flowchart of the attack framework;
[0047] Figure 3 is the flowchart of the AADA method. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] The following will describe the embodiments of the present invention in detail with reference to the drawings.
[0049] It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other; and, based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present disclosure.
[0050] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is only illustrative. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement a device and / or practice a method. Additionally, this device and / or method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.
[0051] The present invention first designs an attack framework for generating adversarial encrypted malicious traffic, aiming to generate adversarial malicious traffic samples that can evade existing network intrusion detection systems (NIDS). The attack framework design is as Figure 1 shown, which details the entire workflow and components of the system.
[0052] This attack framework includes several key modules:
[0053] (1) Generator: Based on the malicious traffic characteristics with added noise, generate adversarial malicious traffic feature vectors;
[0054] (2) Discriminator: Classify benign traffic and malicious traffic, and use the classification result as a reward for the generator to create new adversarial mutated malicious traffic characteristics, and feedback it to the generator;
[0055] (3) RMPFPSO algorithm module: RMPFPSO is a particle swarm optimization algorithm with random mutation and dynamic perception factor, aiming to automatically identify the best traffic mutation samples from the generated adversarial traffic samples.
[0056] A method for generating adversarial malicious traffic in this embodiment is as Figure 2 shown, and the specific process is as follows:
[0057] First, extract features from the traffic through the feature extraction and preprocessing links, convert the traffic data packets into reversible high-dimensional metadata feature vectors, generate malicious traffic feature vectors and benign traffic feature vectors, and add noise to the malicious traffic feature vectors;
[0058] Second, input the malicious traffic features with added noise into the generator. The pre-trained generator generates adversarial malicious traffic feature vectors, and mutate the malicious traffic feature vectors to generate mutated malicious traffic feature vectors;
[0059] Third, input the mutated malicious traffic feature vectors and benign traffic feature vectors into the intrusion detection system NIDS, and input the prediction result of NIDS into the discriminator;
[0060] Finally, the discriminator classifies the prediction result of NIDS to output a probability value, and uses it as a reward for the generator to create new adversarial mutated malicious traffic characteristics;
[0061] Through the adversarial training between the generator and the discriminator, the generator generates adversarial malicious traffic feature vectors that can avoid the intrusion detection system NIDS.
[0062] In the specific implementation of this embodiment, the generator is pre-trained on the reversible high-dimensional metadata feature vectors of benign traffic data packets to generate adversarial malicious traffic feature vectors, and the RFPMPSO algorithm is used to mutate the malicious traffic feature vectors to create mutated malicious traffic feature vectors. The generated malicious samples and benign samples are simultaneously input into the intrusion detection system (NIDS) to simulate gray-box attacks and black-box attacks, and the prediction results of the NIDS are then input into the discriminator. The discriminator is implemented through a neural network classifier and outputs a probability value as the reward for the generator to create new adversarial mutated malicious traffic features. Through the adversarial training between the generator and the discriminator, malicious adversarial samples that can evade the network intrusion detection system (NIDS) are generated, and these adversarial samples are used to construct a robust classifier.
[0063] In this embodiment, the generator and the discriminator are trained in a joint adversarial manner:
[0064] (1) Generator
[0065] The generator uses a Transformer-based model to be pre-trained on large-scale benign traffic data, and the self-attention mechanism is used to enhance the feature representation ability. The model includes an input layer, an embedding layer, a self-attention mechanism, and a feed-forward neural network. Through the multi-head self-attention mechanism, the model can calculate the associations between the feature vectors in the input sequence to generate new feature representations. The feed-forward neural network further performs non-linear transformations on these features to improve the complexity and accuracy of the feature representations. The pre-training uses benign traffic, and then malicious feature vectors are input for adversarial training, making the mutated feature vectors of malicious traffic become adversarial mutated feature vectors that can be regarded as benign traffic by the detection model.
[0066] During the adversarial training process of the generator, the generator receives the malicious feature vector f and the noise vector from the Gaussian distribution p z (z) as inputs and outputs the generated feature vector G(f,z). To train the generator, this embodiment defines a loss function l G that combines the adversarial loss and the reconstruction loss, and is extended by additionally calculating the construction error L between the input and the output, as shown specifically below:
[0067]
[0068] Among them, F mal represents the original malicious feature set, D is the discriminator, the weight of l G should be minimized, L(f,G(f,z)) represents the error between the generator input and output, adversarial: logD(G(f,z) is maximized (deceiving the discriminator); fidelity: L(f,G(f,z)) is minimized (retaining maliciousness).
[0069] (2) Discriminator
[0070] The discriminator, as an alternative classifier (i.e., C(·)), is trained to distinguish between generated malicious features and benign features. It is also a feed-forward neural network. The input includes the benign feature vector Fben and the malicious feature vector Fgen generated by the generator. The output is the probability that the input vector is generated (i.e., malicious). This probability serves as the reward for the generator to update its parameters. The generator updates its parameters by maximizing the following reward function J(θ):
[0071]
[0072] where D(x) is the probability output by the discriminator for the generated sample x, and π θ is the parameterized generation strategy of the generator, indicating how the generator generates adversarial samples G(f, z) based on the input (malicious feature f and noise z).
[0073] The discriminator is trained to maximize the output for the generated input vector while minimizing the output for the benign input vector. To enhance the training stability of the discriminator and the diversity of the generated features, this embodiment introduces a gradient penalty mechanism. The gradient penalty helps ensure that the decision boundary of the discriminator is smooth and prevents the generator from generating overly extreme features. The loss function of the discriminator is:[[]]
[0074]
[0075] where is the feature set extracted from the benign traffic collected from the attacker-controlled network, is the feature set generated by the generator, λ is the hyperparameter that controls the intensity of the gradient penalty, D(f) represents the determination probability of the discriminator for the input feature f, indicating the probability that the discriminator believes f belongs to the true benign sample.[[]] represents the random interpolation point between the true benign feature and the generated feature, represents the expected value, indicating the mean operation on the data distribution, represents the interpolation point of the gradient, represents the determination probability of the discriminator for the interpolation point , and ∥∥ 2 represents the L2 norm, which is used to measure the gradient intensity; the gradient penalty term ensures that the gradient of the discriminator remains consistent near the interpolation point.[[]]
[0076]
[0077] The training process is an iterative optimization between the generator and the discriminator until convergence. The features generated by the generator can be used as adversarial features.[[]]
[0078] The present invention adopts a heuristic-based data packet construction algorithm to generate mutated malicious traffic with reversible metadata characteristics. While maintaining the original malicious characteristics, these mutated samples are transformed in terms of traffic characteristics to evade the recognition of existing detection systems.
[0079] In this embodiment, in order to further optimize the performance of the generator, the PPO algorithm is used. PPO is a policy optimization algorithm for reinforcement learning. Its main goal is to optimize the agent's policy so that it can obtain higher cumulative rewards in a specific environment, solve the problem of "too fast policy update" in reinforcement learning, and improve stability by restricting the amplitude of each update, thereby optimizing the performance of the generator in generating adversarial feature vectors.
[0080] The objective function for optimizing the generator using the PPO algorithm is:
[0081]
[0082] where π θ (a t ∣s t ) represents the probability that the generator takes action a t under state s t , A t is the advantage function estimate, and ∈ is a hyperparameter used to control the policy update range. Through the PPO algorithm, the performance of the generator in generating adversarial feature vectors can be optimized. represents the probability that, before the policy update, i.e., for the generator with parameters θ old , it takes action a t under state s t . The policy update is achieved by comparing the old and new policies (i.e., the policies before and after the update).
[0083] The specific processing process of the RFPMPSO traffic mutation optimization algorithm in this embodiment is as follows:
[0084] To automatically and efficiently select the best traffic mutation samples from the adversarial traffic generated by the system, the present invention designs an algorithm based on RMPFPSO (Particle Swarm Optimization with Random Mutation and Dynamic Awareness Factor). Each particle in this algorithm framework represents a potential traffic mutation and has a position and a velocity vector. Each position vector in the swarm represents a meta-information vector x n (where the range of n is from 1 to N swarm , and N swarm represents the total number of particles), the velocity vector is denoted as v n , and its structure is the same as that of x n . The algorithm using RMPFPSO will be described in detail below.
[0085] Initialization: Initially, to ensure that the initial particles are evenly distributed in the search space, the fields within x cat [] and x mal are randomly initialized within their valid ranges. For the timestamp in x mal , the maximum arrival time between consecutive original data packets (related to L t ) is divided into m equal parts, and a timestamp is randomly selected from these segments. Additionally, v n is initially set to zero.
[0086] Effect evaluation: In each iteration, the proximity of the particle to the target is evaluated based on the particle's position x n (where n ∈ {1, 2, …, N swarm}). The effect is defined by Equation (5):
[0087]
[0088] where, represents the set of malicious traffic characteristics (or feature library), which contains multiple "malicious feature vectors" predefined or extracted from historical malicious samples. R(x n ) represents the specific traffic mutation sample generated after reconstructing or decoding the particle position vector x n . The position x n of each particle in the search space represents a set of meta-information. After being transformed by the function R, a simulated network traffic data instance is obtained, which can be used for subsequent feature extraction and evaluation. ε′ is a feature evaluation (or extraction) function. This function extracts the feature vectors for comparison from the traffic samples generated by R(x n ) and may perform some form of enhancement or normalization on these features. In this way, the obtained feature vectors can be compared with the preset malicious feature vectors for differences.
[0089] By calculating the difference between the generated traffic sample (reconstructed by R(x n ) and the preset malicious feature vector f (extracted from or compared with the malicious feature set ), the effectiveness of the sample (i.e., the similarity to the target malicious feature) is measured. This design provides an objective function for the particle swarm optimization algorithm, enabling the algorithm to automatically optimize the traffic mutation sample during the search process to make it closer to or imitate the characteristics of the target malicious traffic.
[0090] This process can be divided into three steps: First, for the adversarial malicious traffic feature vectors, reconstruct the mutated traffic (denoted as R) from the position x n . After directly retrieving the original traffic, use x malReplace the timestamp in it to obtain a mutated feature vector; for the mutated feature vector, after randomly determining its protocol type, refer to the protocol layer number in x craft [i]. In the second step, use an alternative extractor to extract features (denoted as ε) from the mutated feature vector. In the third step, calculate the distance between the extracted features and the input adversarial features according to formula (5) to determine the effect.
[0091] In this embodiment, by ensuring that the mutated traffic is legal in protocol structure and conforms to the actual network specifications through the protocol template library, the common protocol structure error problems (such as missing transport layer headers and illegal field values) in traditional traffic mutation methods are solved, thereby significantly improving the concealment and attack success rate of adversarial traffic.
[0092] Update: After evaluating the effect of x n , record the position where it achieves the best effect as the individual best position, denoted as b n , and the best position in the group is called the global best position, denoted as g.
[0093] Subsequently, each particle updates its velocity v n according to the following formula:
[0094] v nd = ω 1 v nd + r 1 c 1 (b nd - x nd ) + r 2 c 2 (g d - x nd ) + ω 2 r 3 (p if - x nd ) (6)
[0095] Among them, the subscript d represents the d - th component of the particle in the multi - dimensional search space. That is to say, when the position, velocity, and best position of the particle are all vectors, d is used to indicate the value of a specific dimension in these vectors.
[0096] The first term represents the "inertia" part of the particle, indicating its tendency to maintain the previous velocity; the second and third terms represent the "cognitive" and "social" parts of the particle, indicating its tendency to move towards its own historical best position and the group historical best position. The fourth term is the random mutation part, indicating that the particle explores its local space, enhances the driving force of the particle, and enriches the diversity of the group. r 1 , r 2 , and r 3is a random number in the range of [0, 1]. To simplify the complexity of the algorithm and enhance the mining ability in the later stage, ω 1 and ω 2 are set to be equal and both adopt the non-linear decreasing weight strategy. p if represents the randomly mutated particle, which is obtained by simplifying the complex method. Then, when updating the particle position x n , combined with the perception factor, the particle can dynamically and adaptively control the spatial distance between itself and other particles in the same dimension:
[0097]
[0098] where, represents the average distance between particles, d k represents the distance between particles in a specific dimension, ω 3 is the inertia weight coefficient.
[0099] Iteration is completed: The above two steps (evaluation and update) are repeated for a fixed number of iterations, denoted as N iter , and the traffic reconstructed from the current global best position g is identified as the best evasive mutation.
[0100] An embodiment of the present application provides an adversarial malicious traffic generation device, including a processor, a generator, a discriminator, and a data mutation module;
[0101] The processor is used to extract features from the traffic and perform preprocessing, convert the traffic data packet into a reversible high-dimensional metadata feature vector, generate a malicious traffic feature vector and a benign traffic feature vector, and add noise to the malicious traffic feature vector;
[0102] The generator is used to receive the malicious traffic feature with added noise and generate an adversarial malicious traffic feature vector;
[0103] The data mutation module is used to mutate the malicious traffic feature vector to generate a mutated malicious traffic feature vector;
[0104] The discriminator is used to receive the prediction results of the intrusion detection system NIDS for the input mutated malicious traffic feature vector and benign traffic feature vector, output the classification output probability value of the prediction results, and use it as the reward for the generator to create a new adversarial mutated malicious traffic feature;
[0105] Through the adversarial training between the generator and the discriminator, the generator generates an adversarial malicious traffic feature vector that evades the intrusion detection system NIDS.
[0106] Furthermore, the detection model NIDS for adversarial encrypted malicious traffic is trained to achieve adaptive and iterative adversarial data augmentation.
[0107] To address the challenges posed by adversarial encrypted malicious traffic to detection systems, the embodiments of this application propose a highly robust encrypted traffic defense strategy, Adaptive and Iterative Adversarial Data Augmentation (AADA): This strategy dynamically adjusts the defense capabilities of the model by continuously generating new adversarial samples and incorporating them into the training set. This method combines an automated testing and retraining framework to gradually enhance the robustness of the NIDS.
[0108] The core idea of AADA is to identify and exploit potential weaknesses in the NIDS to generate samples that can enhance the defense capabilities, thereby improving the adaptability and accuracy of the detection system when facing complex encrypted traffic attacks. The strategy design is as Figure 3 shown and includes the following processes:
[0109] 1. Identify potential weaknesses and target attack patterns
[0110] During the training process, the NIDS analyzes different categories of encrypted traffic and classifies them based on the statistical characteristics and patterns of the traffic. However, due to the concealment of encrypted traffic, these models often have some weaknesses that have not been fully learned, especially when facing adversarial encrypted traffic. These weaknesses may manifest as certain specific traffic characteristics or patterns that are easily deceived by malicious traffic through minor perturbations.
[0111] The first step of AADA is to identify these weaknesses through continuous training and testing. For example, if the NIDS detection model has a high misjudgment rate for a certain category of encrypted traffic, AADA will generate highly deceptive adversarial samples for this misjudgment situation. The generation of these adversarial samples is not a simple "optimization", but by dynamically adjusting the generation strategy to ensure that each generated adversarial sample can effectively "approach" the defense limit of the detection system, break the original robustness of the model, continuously analyze these weaknesses through iterative learning, and generate appropriate adversarial samples according to the analysis results. The generated samples can not only strengthen the defense capabilities of the model but also ensure that the characteristics of the traffic remain concealed during the encryption process and are not easily recognized by the detection model.
[0112] 2. Application of deep generative models
[0113] AADA employs deep generative models (such as generative adversarial networks, GANs) to generate adversarial samples.
[0114] Based on the original traffic generation adversarial framework architecture, the task of the generator is to generate "forged" data, while the discriminator (i.e., the classifier) is responsible for determining whether this data belongs to the true data category.
[0115] In AADA's defense strategy, the generator's task is to generate samples that can confuse NIDS and ensure that these samples are similar to the original encrypted traffic. The samples must also be slightly perturbed to generate adversarial traffic samples that can deceive NIDS.
[0116] Unlike traditional adversarial sample generation methods, the generator used by AADA does not only focus on the size of the perturbation or the impact on model classification, but pays more attention to the naturalness and concealment of the generated samples. The generated adversarial samples must not only be able to mislead the detection model, but also must be similar to the original encrypted traffic, so as to avoid obvious distortion of traffic characteristics due to excessive interference.
[0117] 3. Combination of adversarial loss and feature loss
[0118] Another important aspect of the AADA method is its strategy of combining adversarial loss and feature loss. This strategy ensures that the generated adversarial samples can not only effectively confuse the detection model, but also maintain the naturalness of the traffic and avoid excessive perturbations that lead to distortion of traffic features.
[0119] Adversarial Loss: This loss aims to maximize the misleading effect of the generated samples on the detection model. Its core goal is to optimize the generator so that the generated adversarial samples can cause the target model to make incorrect predictions. Similar to traditional adversarial training, the goal of generating samples is to make the labels output by the model as different from the true labels as possible, or to predict a target label (i.e., targeted attack).
[0120] Feature Loss: Different from traditional adversarial loss, the purpose of feature loss is to ensure that the generated adversarial samples have similar characteristics to the original encrypted traffic. This is especially important for encrypted traffic, because excessive perturbations may cause significant changes in traffic characteristics, resulting in large statistical differences between the generated adversarial samples and the real traffic, which can be identified by the detection system. Therefore, AADA uses feature loss to ensure that the generated samples are structurally consistent with the original traffic, while effectively avoiding abnormal changes in traffic.
[0121] 4. Dynamic adjustment and iterative optimization
[0122] The generation process of AADA is not completed in one go, but a dynamic optimization process. After each adversarial sample is generated, the model will provide feedback on its performance, and the generator and discriminator will adjust according to the effect of the current generated sample. Specifically, in each round of training, AADA will dynamically adjust the generation strategy according to the attack success rate of the current model and the fidelity of the traffic characteristics to approach the defense limit of the detection system.
[0123] Each generation of adversarial samples is fine-tuned according to the misjudgment pattern of the target model. Suppose the generated adversarial samples fail to successfully deceive the detection model in some cases. AADA will identify the potential deficiencies of the generated samples and adjust the generation strategy to improve the effectiveness of the samples. For example, if some generated samples fail to effectively deceive the detection system, AADA will ensure that the generated adversarial samples are more effective in the next round of training and can gradually increase the attack success rate to enhance the system's robustness against different adversarial samples by adjusting parameters such as the network structure of the generator, the weight of the adversarial loss, or the perturbation size. This dynamic optimization method ensures that the defense system can continuously improve its adaptability and robustness as the attack pattern evolves. By adjusting parameters such as the network structure of the generator, the weight of the adversarial loss, or the perturbation size, AADA ensures that the generated adversarial samples are more effective in the next round of training and can gradually increase the attack success rate of the system.
[0124] 5. Preservation and Concealment of Encrypted Traffic Features
[0125] A key feature of encrypted traffic is that it is difficult to directly analyze from the outside, which makes it an ideal carrier for malicious attacks. In encrypted traffic, malicious activities can only be identified by decrypting or analyzing specific statistical features. Therefore, AADA pays special attention to the concealment of the generated adversarial samples in encrypted traffic. The generated adversarial samples not only need to deceive the detection model but also must remain concealed in the overall features of the encrypted traffic without triggering an alarm from the detection system.
[0126] To achieve this, AADA introduces a perturbation size control mechanism to ensure that the perturbation of each generated adversarial sample is within an acceptable range, thus avoiding excessive interference that may cause abnormal fluctuations in the traffic and ensuring that the generated adversarial samples are consistent with the original traffic in terms of statistical features of the encrypted traffic, thereby effectively enhancing the defense ability of the detection system and preventing malicious traffic from being easily identified.
[0127] 6. Continuous Iteration and Enhancement of Model Defense Ability
[0128] The AADA (Adaptive Adversarial Sample Generation) method continuously strengthens the defense ability of the Network Intrusion Detection System (NIDS) through continuous iterative training. Different from traditional single-training methods, the core of AADA is to dynamically add each generated adversarial sample to the training set so that the detection model can maintain high detection ability when facing new types of adversarial encrypted traffic.
[0129] In each iteration, the NIDS will be retrained using new adversarial samples to improve its ability to recognize new attack patterns by optimizing the model parameters. This retraining process enables the detection model to learn from new samples and update its internal parameters, gradually enhancing the robustness against adversarial encrypted traffic. With the continuously increasing training data of adversarial samples, the NIDS can gradually improve its sensitivity to encrypted malicious traffic, reduce the probability of false positives and false negatives, and ultimately enhance its ability to handle various complex attacks in a real environment.
[0130] This iterative training mechanism not only improves the ability of the detection system to handle new types of adversarial attacks but also enables the NIDS to continuously adapt to the evolution of attack patterns. With each round of training and the update of adversarial samples, AADA enables the system to handle increasingly complex adversarial encrypted traffic, ensuring stable and efficient detection performance under strong attack pressure.
[0131] Through this continuously optimized training strategy, AADA provides the NIDS with strong adaptive capabilities, enabling the detection system to always maintain a high degree of accuracy and robustness when facing continuously changing and increasingly complex encrypted malicious traffic, preventing malicious traffic from bypassing the detection system through continuously changing adversarial strategies.
[0132] In summary, the above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for generating adversarial malicious traffic, characterized in that: The specific process is: First, features are extracted from traffic through feature extraction and preprocessing, and traffic packets are converted into reversible high-dimensional metadata feature vectors. Malicious traffic feature vectors and benign traffic feature vectors are generated, and noise is added to the malicious traffic feature vectors. Secondly, the malicious traffic features with added noise are input into the generator, the pre-trained generator generates an adversarial malicious traffic feature vector, and the malicious traffic feature vector is mutated to generate a mutated malicious traffic feature vector; Thirdly, the mutated malicious traffic feature vector and the benign traffic feature vector are input into the intrusion detection system NIDS, and the prediction result of NIDS is input into the discriminator; Finally, the discriminator classifies the prediction results of NIDS and outputs a probability value, which is used as a reward for the generator to create new adversarial variant malicious traffic features; Through adversarial training between the generator and the discriminator, the generator generates adversarial malicious traffic feature vectors that evade the intrusion detection system NIDS.
2. The method for generating antagonistic malicious traffic according to claim 1, characterized in that: The specific process is: Before the adversarial training is formed between the generator and the discriminator, a large-scale benign traffic feature vector is used to pre-train the generator.
3. The method for generating antagonistic malicious traffic according to claim 2, characterized in that: The loss function of the adversarial training between the generator and the discriminator includes adversarial loss and reconstruction loss l G , Among them, f is the malicious traffic feature vector, z represents Gaussian distribution noise, and F mal represents the malicious traffic feature vector set, D represents the discriminator, G(f,z) represents the output of the generator, L(f,G(f,z)) represents the error between the input and output of the generator, and D(G(f,z)) represents the output of the discriminator; The generator updates its parameters by maximizing the reward function J(θ): Among them, D(x) is the probability of the discriminator outputting the sample x generated by the generator, π θ is the parameterized generation strategy of the generator.
4. The method for generating antagonistic malicious traffic according to claim 3, characterized in that: The loss function of the discriminator is: in, is the benign traffic feature vector, is the adversarial malicious traffic feature vector, λ is a hyperparameter that controls the intensity of the gradient penalty, D(f) represents the probability of the discriminator’s decision on the input feature f, and represents the probability that the discriminator believes that f belongs to real benign traffic. represents the random interpolation points between the real benign features and the adversarial malicious traffic features, represents the expected value, Indicates interpolation points The gradient of Denotes the discriminator for the interpolation point The judgment probability of , ∥∥2 represents the L2 norm.
5. The method for generating antagonistic malicious traffic according to claim 4, characterized in that: Random interpolation points between the true benign features and the adversarial malicious traffic features for:
6. The method for generating antagonistic malicious traffic according to any one of claims 1 to 5, characterized in that: The objective function of the generator optimized using the PPO algorithm is: Among them, π θ (a t ∣s t ) indicates that the generator with parameter θ is in state s t Take action a t The probability of A t is the advantage function estimate, It means that before the parameter is updated to θ, the generator is in state s t Take action a t The probability of ,∈ is a hyperparameter used to control the scope of policy updates.
7. The method for generating antagonistic malicious traffic according to claim 1, characterized in that: The RFPMPSO traffic variation optimization algorithm is used to mutate the malicious traffic feature vector. The RMPFPSO traffic variation optimization algorithm is a particle swarm optimization algorithm with random mutation and dynamic perception factors, which automatically identifies the best traffic variation sample from the generated adversarial traffic samples.
8. The method for generating antagonistic malicious traffic according to claim 7, characterized in that: The specific process of the RFPMPSO flow variation optimization algorithm for variation is as follows: The first step is to target the adversarial malicious traffic feature vector from position x n Reconstruct the variant traffic, retrieve the original traffic directly, and use x mal The timestamp in is replaced to obtain a mutated feature vector; for the mutated feature vector, the number of protocol layers of the protocol type is determined by reference; In the second step, the extractor is used to extract features from the mutated feature vector; In the third step, the distance between the extracted features and the input adversarial features is calculated to determine the mutation effect.
9. The method for generating adversarial malicious traffic according to claim 1, characterized in that: It also includes using the adversarial malicious traffic feature vectors generated by the generator to train the intrusion detection system NIDS, specifically: training using an adaptive and iterative adversarial data enhancement method.
10. A device for generating counteractive malicious traffic, characterized in that: Includes processor, generator, discriminator, and data mutation modules; A processor, used for extracting features from traffic and performing preprocessing, converting traffic data packets into reversible high-dimensional metadata feature vectors, generating malicious traffic feature vectors and benign traffic feature vectors, and adding noise to the malicious traffic feature vectors; A generator, used for receiving malicious traffic features with added noise and generating adversarial malicious traffic feature vectors; A data mutation module, used for mutating the malicious traffic feature vector to generate a mutated malicious traffic feature vector; The discriminator is used to receive the prediction results of the intrusion detection system NIDS on the input mutated malicious traffic feature vector and the benign traffic feature vector, and output the prediction results for classification and output probability values, and use them as rewards for the generator to create new countermeasures against the mutated malicious traffic features; Through adversarial training between the generator and the discriminator, the generator generates adversarial malicious traffic feature vectors that evade the intrusion detection system NIDS.
Citation Information
Patent Citations
Method and system for detecting malware in virtual execution
CN110581857A
Classified confrontation network attack detection method and system
CN110598794A
Malicious data flow detection method and system for adversarial network
CN112532562A
Distributed network anti-attack self-training learning method
CN115333869A
Malicious traffic avoidance detection method based on generative adversarial network
CN116707992A
Cited By
Information security transmission method and system of multiplexing data bus
CN121367607A
Information security transmission method and system of multiplex data bus
CN121367607B