Network anomaly detection method and system based on AI and IPS joint detection

By combining AI and IPS detection methods in network abnormality detection, the problems of low detection efficiency and difficulty in detecting unknown threats in the prior art are solved, more efficient and accurate malicious traffic detection is achieved, and network security defense capabilities are improved.

CN120151074APending Publication Date: 2025-06-13NANJING XIAOZHUANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510431810.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing network anomaly detection methods are inefficient in detection, difficult to detect unknown threats in a timely manner, and feature-based detection methods are difficult to cope with complex and dynamic network environments.

Method used

The combined detection method based on AI and IPS is adopted to conduct preliminary detection of message data through the AI ​​detection model. If the detection result is uncertain, it will be sent to the IPS detection engine for further detection, improving detection efficiency and accuracy.

Benefits of technology

It realizes more accurate and efficient detection of malicious traffic, improves the security defense capabilities of the firewall, and can better deal with complex and dynamic network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151074A_ABST
    Figure CN120151074A_ABST
Patent Text Reader

Abstract

The invention discloses a network anomaly detection method and system based on AI and IPS joint detection. The method comprises the following steps: obtaining message data to be detected; performing abnormal message detection on to-be-detected message data based on the trained AI detection model to obtain a corresponding AI detection result; performing blocking processing in response to the fact that the AI detection result is an abnormal message; if the AI detection result is a safe message, passing processing is carried out; and if the AI detection result is a to-be-processed message, further detecting based on a preset IPS detection engine to obtain a corresponding detection result, and performing response processing. Through the joint strategy of the AI detection model and the IPS detection engine, the malicious traffic can be detected more accurately and efficiently by means of the strong AI anomaly detection capability instead of purely depending on a set signature feature library, and the complex and dynamic network environment can be better coped with. And a great value is provided for constructing a next-generation AI firewall.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a network anomaly detection method and system based on the joint detection of AI and IPS, and belongs to the technical field of network anomaly detection. Background Art

[0002] As a network device between the internal network and the external network, the firewall is mainly used to perform security detection on the user's Internet traffic to prevent intrusion behavior. Currently, intrusion detection systems are mainly divided into signature-based detection and anomaly-based detection. As a signature-based detection method, IPS / IDS is the core component of the current firewall, providing an active and real-time protection, accurately analyzing and judging deep network attack behaviors, and blocking malicious traffic of vulnerability attacks. Its working principle is to capture and analyze known network threats and attacks on the network, and then construct detection rules. Typical rules include Snort, Suricata, Zeek, etc. When a packet can match the rule, it is blocked, otherwise it is allowed to pass. However, the current network attack traffic is increasing day by day. With the continuous expansion of the signature scale, signature matching poses challenges to the detection performance. In addition, the existing protection strategies are all based on known threat rules for detection, which is a passive defense method and difficult to cope with the emerging security problems. Currently, the AI-driven network data plane provides a new solution to solve network security problems. By constructing an AI model to identify anomalies in real-time packets, however, its accuracy cannot be guaranteed. Summary of the Invention

[0003] The purpose of the present invention is to overcome the deficiencies in the prior art, and provide a network anomaly detection method and system based on the joint detection of AI and IPS, which solves the problems of low detection efficiency and inability to detect unknown threats in the existing solutions. Through the joint strategy of the AI detection model and the IPS detection engine, malicious traffic can be detected more accurately and efficiently, and it can better cope with complex and dynamic network environments. The packet data first enters the AI detection model to automatically identify abnormal packets that deviate from the normal mode. If it is not certain, it is then sent to the signature-based IPS detection engine for further determination. Most of the normal traffic and significantly abnormal traffic are selected through AI anomaly detection, and the traffic entering the IPS detection engine is greatly reduced, greatly improving the detection efficiency and comprehensively enhancing the security defense ability of the firewall.

[0004] To achieve the above purpose, the present invention is implemented by the following technical solutions: On the one hand, the present invention discloses a network anomaly detection method based on the joint detection of AI and IPS, including the following steps: Obtain the packet data to be detected; Perform anomaly message detection on the message data to be detected based on the trained AI detection model, determine whether it deviates from the normal mode behavior, and obtain the corresponding AI detection result; In response to the AI detection result being an anomaly message, perform blocking processing; In response to the AI detection result being a secure message, perform passing processing; In response to the AI detection result being a message to be processed, perform further detection based on a preset IPS detection engine, obtain the corresponding detection result, and perform response processing.

[0005] Furthermore, the training steps of the AI detection model include: Obtain the historical message data of the secure network device; According to the historical message data, perform data cleaning, normalization, and feature extraction to obtain a data set; divide the data set into a training set, a validation set, and a test set; Use the training set to train a pre-constructed AI detection model based on a random forest to obtain a preliminary AI detection model; Use the validation set to perform performance evaluation on the preliminary AI detection model, calculate the accuracy, recall rate, and F1 score of the preliminary AI detection model on the validation set, and adjust the model parameters according to the accuracy, recall rate, and F1 score to obtain an optimized AI detection model; Use the test set to perform a final evaluation on the optimized AI detection model to obtain the trained AI detection model; Among them, the AI detection model is iteratively updated and trained based on a preset time threshold.

[0006] Furthermore, the steps of the data cleaning include: According to the historical message data, perform data cleaning and label acquisition, delete the historical messages that have not been detected by the IPS detection engine, and retain the historical messages with IPS detection results to obtain the cleaned data; Among them, the IPS detection result is used as the label of the historical message, including anomaly messages or secure messages.

[0007] Furthermore, the steps of the feature extraction include: According to the cleaned data, perform a decoding operation to obtain the decoded data; According to the decoded data, perform a character generalization operation to obtain the generalized data; According to the generalized data, perform event matching and keyword matching to obtain the matched data; According to the matched data, perform feature vector conversion to obtain feature data to construct a training set.

[0008] Further, the feature data includes the source IP address, destination IP address, port information, protocol type, payload content, traffic pattern, behavior pattern, and IPS detection result of the historical message data.

[0009] Further, the steps of event matching and keyword matching include: Generalize the events of the same type in the generalized data into corresponding event character combinations; Generalize the keywords of the same type in the generalized data into corresponding keyword character combinations; Obtain the matched data according to the event character combination and keyword character combination.

[0010] Further, the step of further detecting based on a preset IPS detection engine includes: Match the to-be-processed message based on a preset IPS detection engine and a preset rule set; In response to the existence of a corresponding matching rule for the to-be-processed message, determine that the to-be-processed message is an abnormal message, perform blocking processing based on the operation defined in the matching rule, and issue an ACL blocking flow table; In response to the non-existence of a corresponding matching rule for the to-be-processed message, determine that the to-be-processed message is a secure message and perform passing processing.

[0011] On the other hand, the present invention discloses a detection system according to the above network anomaly detection method based on joint detection of AI and IPS, including: A data acquisition module for acquiring message data to be detected; An AI detection module for performing abnormal message detection on the message data to be detected based on a trained AI detection model, determining whether it deviates from normal mode behavior, and obtaining a corresponding AI detection result; A data blocking module for performing blocking processing in response to the AI detection result being an abnormal message; A data passing module for performing passing processing in response to the AI detection result being a secure message; An IPS detection module for, in response to the AI detection result being a to-be-processed message, further detecting based on a preset IPS detection engine, obtaining a corresponding detection result, and performing response processing.

[0012] Compared with the prior art, the beneficial effects achieved by the present invention: The network anomaly detection method and system based on the joint detection of AI and IPS of the present invention can more accurately and efficiently detect malicious traffic through the joint strategy of the AI detection model and the IPS detection engine, and better cope with complex and dynamic network environments. It helps to improve the overall performance of the network, enhance security, and provide a better service experience for users. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is a flowchart of the network anomaly detection method based on the joint detection of AI and IPS provided in Embodiment 1; Figure 2 is a schematic diagram of the operation logic of the network anomaly detection method based on the joint detection of AI and IPS provided in Embodiment 1; Figure 3 is a schematic diagram of data acquisition provided in Embodiment 1; Figure 4 is a schematic diagram of the overall architecture logic provided in Embodiment 1; Figure 5 is a schematic diagram of the deployment environment provided in Embodiment 1; Figure 6 is a schematic diagram of the structure of the network anomaly detection system based on the joint detection of AI and IPS provided in Embodiment 2. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0014] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention and cannot be used to limit the protection scope of the present invention.

[0015] Embodiment 1: Embodiment 1 of the present invention provides a network anomaly detection method based on the joint detection of AI and IPS, as Figure 1 shown, including the following steps: Obtain the packet data to be detected; Based on the trained AI detection model, perform anomaly packet detection on the packet data to be detected, determine whether it deviates from the normal mode behavior, and obtain the corresponding AI detection result; In response to the AI detection result being an abnormal packet, perform a blocking process; In response to the AI detection result being a safe packet, perform a passing process; In response to the AI detection result being a packet to be processed, perform further detection based on the preset IPS detection engine, obtain the corresponding detection result, and perform a response process.

[0016] The technical concept of the present invention is as follows: Through the combined detection of an AI detection model and an IPS detection engine, the advantages of both can be fully utilized to detect malicious traffic more accurately and efficiently, and better cope with complex and dynamic network environments. This helps to improve the overall performance of the network, enhance security, and provide a better service experience for users.

[0017] To facilitate the understanding of this application, some terms related to this application are introduced as follows: ‌AI: Artificial Intelligence, artificial intelligence.

[0018] IPS: Intrusion Prevention System, an intrusion prevention system, which is a network security device used to detect and prevent network attacks. An IPS can monitor network traffic in real time, identify and block malicious traffic and attacks to protect network security. Compared with traditional firewalls, an IPS can inspect packets and applications more deeply, thus providing more comprehensive security protection. The main advantages of this method are high detection efficiency, low false alarm rate, and low detection cost. However, because this method relies on an accumulated feature library, and the signatures in the feature library are feature descriptions for known threats and have limited capacity, for unknown and variant attack methods and means, rule-based detection is prone to false negatives. This detection method that lags behind the occurrence of threats results in a high false alarm rate for threat detection and untimely threat response.

[0019] It should be noted that as Figure 5 shown, this method is deployed on the firewall between the internal network and the external network to control the packet data entering and leaving the network, and only allows packet data that conforms to the security policy to pass through, thereby preventing unauthorized access and protecting computer systems and networks from external malicious attacks and intrusions. By checking information such as the source address, destination address, and port number of the packet data, the firewall can decide whether to allow this packet data to enter or leave the network. The security defense devices commonly used in the industry generally use rule-based detection, such as Snort\Suricata, etc. Taking Snort as an example, it uses a set of preset rules to analyze each packet. These rules are usually based on pattern matching or detection logic based on abnormal behavior. If the characteristics of the packet match a certain rule, the system will issue a warning or make a corresponding response. This patent adds AI-based anomaly detection on the basis of the original firewall system, which is deployed in front of the IPS detection to form a combined detection mechanism.

[0020] As Figure 2 shown, the specific steps are as follows: Step 1: Obtain the packet data to be detected.

[0021] Specifically, it includes the following steps: Get all raw data flowing in or out.

[0022] The original data is decoded by protocol to obtain the message data to be detected, so that the subsequent AI detection model can identify various protocol types in the message data.

[0023] Step 2: Perform abnormal message detection on the message data to be detected based on the trained AI detection model to determine whether it deviates from the normal mode behavior and obtain the corresponding AI detection result.

[0024] 2.1. Training of AI detection model.

[0025] The training steps of the AI ​​detection model include: 2.1.1. Obtain historical message data of security network devices, specifically historical message data of firewalls.

[0026] Specifically, Figure 3 As shown in the figure, the pcap file generated by large-scale network traffic is used to replay traffic for accurate collection of historical message data. Based on the Telemetry mechanism, collection tasks are issued and measurement data is regularly received from the data plane, and then historical message data related to security events and threats is extracted.

[0027] In addition, the historical message data enters the IPS detection engine for message detection. If the message has no threat, it is marked with 0, and if it has a threat, it is marked with 1. Based on this, the data labeling task is completed. Collecting appropriate IPS labels is crucial for training machine learning models. First, a data set containing features and hit labels of various types of intrusion attacks and normal network traffic is collected. Then, during data preprocessing, the data needs to be cleaned and features extracted. Obtain black and white traffic data in the existing network by time period and store them separately.

[0028] The data acquisition content table is as follows:

[0029] 2.1.2. Based on the historical message data, data cleaning and feature extraction are performed to obtain the training set.

[0030] According to the historical message data, data cleaning and label acquisition are performed, and the messages that are not detected based on the IPS detection engine IPS engine detection results are deleted, and the historical messages with IPS detection results are retained to obtain the cleaned data; The IPS detection result is used as a label of the historical message, including abnormal messages or safe messages.

[0031] The steps of feature extraction include: Perform decoding operations on the cleaned data to obtain the decoded data. Specifically, the decoding operations include recursive URL decoding, Base64 decoding, and decimal hexadecimal decoding.

[0032] Perform character generalization operations on the decoded data to obtain the generalized data. Specifically, character generalization operations, such as generalizing the data uniformly to "0", converting uppercase letters to lowercase, etc.

[0033] Perform event matching and keyword matching on the generalized data to obtain the matched data; among them, the steps of event matching and keyword matching include: generalizing the same type of events in the generalized data into corresponding event character combinations; generalizing the same type of keywords in the generalized data into corresponding keyword character combinations; obtaining the matched data based on the event character combinations and keyword character combinations.

[0034] Perform feature vector conversion on the matched data to obtain features, obtain the dataset D, and construct the training set. Specifically, feature vector conversion refers to operations such as generalizing the data uniformly to "0" or converting uppercase letters to lowercase.

[0035] The purpose of feature extraction is to extract features useful for model training from the original data to improve the performance and accuracy of the model. It generally includes the following information: Statistical features: Extract some statistical features from the message, such as message length, occurrence frequency, etc.

[0036] Text features: If the message is in text format, some text features can be extracted, such as word frequency, part of speech, keywords, etc.

[0037] Network flow features: According to the network flow information of the message, some network flow features can be extracted, such as source / destination IP addresses, port numbers, protocol types, etc.

[0038] Time features: Consider the time information of the message, such as timestamp, sending frequency, etc.

[0039] In the development process of the AI detection model, it is hoped that the trained AI detection model can perform well on new and unseen data. To simulate new and unseen data, the available data is split, so that the dataset D is divided into an 80% training set S, a 10% validation set Y, and a 10% test set T, and the data distributions of the training set S, the validation set Y, and the test set T are consistent. It should be noted that this data split is only performed once.

[0040] 2.1.3. Use the training set to train the pre-constructed AI detection model based on random forest to obtain a preliminary AI detection model; Use the validation set to evaluate the performance of the preliminary AI detection model, calculate the accuracy, recall rate, and F1 score of the preliminary AI detection model on the validation set, and adjust the model parameters according to the accuracy, recall rate, and F1 score to obtain an optimized AI detection model; Use the test set to conduct a final evaluation of the optimized AI detection model to obtain a trained AI detection model.

[0041] Among them, the AI detection model is iteratively updated and trained based on a preset time threshold. The update frequency set in this embodiment is to update the model once a week. It can be basically regarded as training based on the real-time data reported on the Internet, with the ability of self-learning and self-adaptation. It can automatically adjust the detection strategy and parameters according to the real-time changes in the network environment, which can bring a more efficient and reliable network solution, provide the generalization of the model to adapt to new network environments and attack methods. The accuracy of the model is very high. In addition, users can conveniently view the training situation of the model and the performance indicators of the model for optimization and improvement.

[0042] This method can use a variety of machine learning algorithms to train the AI detection model, such as: support vector machine, decision tree, random forest, etc. In this embodiment, the random forest is taken as an example, which adopts the idea of Bagging: (1) Each time, n training samples are taken from the training set with replacement to form a new training set; (2) Use the new training set to train and obtain M sub-models; (3) For classification problems, use the voting method, and the classification category of the sub-model with the most votes is the final AI detection model.

[0043] 2.3. Application of the AI detection model.

[0044] Input the message data to be detected into the trained AI detection model for abnormal message detection to obtain the corresponding AI detection result.

[0045] In response to the AI detection result of the message data to be detected being an abnormal message, transfer to Step Three.

[0046] In response to the AI detection result of the message data to be detected being a secure message, transfer to Step Four.

[0047] In response to the AI detection result of the message data to be detected being a message to be processed, transfer to Step Five.

[0048] It should be emphasized that as Figure 3 and Figure 4As shown in the figure, the AI detection model of this embodiment is deployed to the programmable data plane and can be applied to fields such as delay guarantee, throughput optimization, security attack prevention, and reliability enhancement, solving the problems of high overhead and insufficient information in the deployment of traditional controller AI models.

[0049] The programmable data plane is a new type of network programming language that allows network administrators and developers to write custom data plane processing logic on network devices. By using the programmable data plane, network devices can dynamically adjust their data plane behavior according to the specific attributes and requirements of network traffic. The main advantages of the programmable data plane lie in its programmability and flexibility. Traditional network devices usually use hardware-specific chips to process data packets, and the functions of these chips are fixed and cannot be customized. However, by using the programmable data plane, network administrators and developers can write their own data plane logic to meet specific network requirements and application scenarios.

[0050] As Figure 4 shown in the figure, this method adopts a collaborative strategy based on the management plane, control plane, and data plane. Their close cooperation enables self-learning and self-adaptation capabilities, and can automatically adjust detection strategies and parameters according to the real-time changes in the network environment, bringing a more efficient and reliable network solution and providing the generalization ability of the model to adapt to new network environments and attack methods. The following is an overview of the work of several planes: Management plane: Responsible for the training of the model. It uses the feature data uploaded by the control plane for large model training, all of which are based on the real-time data reported on the live network, so the accuracy of the model is very high; in addition, users can conveniently view the training situation of the model and the performance indicators of the model for optimization and improvement. Based on the continuous reporting of the data plane, the model can automatically update the detection strategy by continuously learning new data and attack patterns, improving the accuracy and adaptability of detection.

[0051] Control plane: Responsible for model data collection and model management. During the model training process, the control plane will collect training data and store it in the data warehouse for model training. At the same time, the control plane is also responsible for tasks such as model upgrade, model deployment, and model monitoring.

[0052] Data plane: Deploying the AI anomaly detection algorithm to the programmable data plane reduces data transmission latency and enables more efficient traffic analysis, anomaly detection, and real-time decision-making, solving the problems of high overhead, decision lag, and insufficient information in the deployment of traditional controller AI models.

[0053] Based on the coordinated operation of the above hierarchical model, the AI model can be continuously upgraded, continuously supply threat intelligence, identify and prevent known and unknown malicious attacks, and provide security protection. By learning the normal / abnormal behavior of the network, the intelligent system can more accurately distinguish normal traffic from malicious activities, thereby reducing false positives and false negatives.

[0054] By calling the measurement subscription interface of Telemetry in the control plane to the data plane; the data plane pushes real-time network packet data to the control plane, and the control plane extracts features after parsing the packets; in addition, the packets are distinguished between black and white traffic based on the rule matching detection results of Snort\Suricata to distinguish whether this packet is a threat as label data. This method first performs anomaly detection on packet data based on the AI detection model, identifies the packet data of network attacks for blocking or even discarding, and directly passes the packet data without threat, quickly filtering out a large part of white traffic. For the data that cannot be identified, it enters the IPS detection engine for further detection as follows: Step 3: In response to the AI detection result being an abnormal packet, perform a blocking process.

[0055] Once any threat is detected, this method will take blocking measures, such as blocking packet transmission or sending an alarm to the administrator, or even discarding.

[0056] Step 4: In response to the AI detection result being a secure packet, perform a pass process.

[0057] Step 5: In response to the AI detection result being a packet to be processed, perform further detection based on a preset IPS detection engine, obtain the corresponding detection result, and perform a response process.

[0058] For the packets that cannot be identified in the AI detection model, perform in-depth detection through a preset IPS detection engine to detect whether there are any security vulnerabilities or malicious codes. And take corresponding response measures for the detection results, such as alarm, isolation, blocking, etc., to prevent or mitigate the impact of network attacks. By using this collaborative strategy, it is more intelligent and adaptive, and can better cope with complex and dynamic network environments. It helps to improve the overall performance of the network, enhance security, and provide a better service experience for users.

[0059] Specifically, the steps of performing further detection based on a preset IPS detection engine include: Based on the packet to be processed, match the preset IPS detection engine with a preset rule set; In response to the packet to be processed having a corresponding matching rule, determine the packet to be processed as an abnormal packet, perform a blocking process based on the operation defined in the matching rule, and issue an ACL blocking flow table; In response to the absence of a corresponding matching rule for the message to be processed, it is determined that the message to be processed is a secure message and is processed for passing.

[0060] Embodiment 2: Embodiment 2 provides a network anomaly detection system based on joint detection of AI and IPS, as Figure 6 shown, including: A data acquisition module for acquiring message data to be detected; An AI detection module for performing anomaly message detection on the message data to be detected based on a trained AI detection model, determining whether it deviates from normal mode behavior, and obtaining a corresponding AI detection result; A data blocking module for performing blocking processing in response to the AI detection result being an anomaly message; A data passing module for performing passing processing in response to the AI detection result being a secure message; An IPS detection module for performing further detection based on a preset IPS detection engine in response to the AI detection result being a message to be processed, obtaining a corresponding detection result, and performing response processing.

[0061] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0062] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0063] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions in the process Figure 1One process or multiple processes and / or boxes Figure 1 The functions specified in one box or multiple boxes.

[0064] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 One process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one box or multiple boxes.

[0065] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A network anomaly detection method based on joint detection of AI and IPS, characterized by: The steps include: Obtain the message data to be detected; Based on the trained AI detection model, abnormal message detection is performed on the message data to be detected to determine whether it deviates from the normal mode behavior, and the corresponding AI detection result is obtained; In response to the AI ​​detection result being an abnormal message, blocking processing is performed; In response to the AI ​​detection result being a safe message, performing a pass process; In response to the AI ​​detection result being a message to be processed, further detection is performed based on a preset IPS detection engine to obtain a corresponding detection result and perform response processing.

2. The network anomaly detection method based on joint detection of AI and IPS according to claim 1 is characterized in that: The training steps of the AI ​​detection model include: Obtain historical message data of security network devices; According to the historical message data, data cleaning, normalization and feature extraction are performed to obtain a data set; the data set is divided into a training set, a verification set and a test set; Using the training set to train a pre-built random forest-based AI detection model to obtain a preliminary AI detection model; Using the validation set to perform performance evaluation on the preliminary AI detection model, calculating the accuracy, recall, and F1 score of the preliminary AI detection model on the validation set, and adjusting model parameters according to the accuracy, recall, and F1 score to obtain an optimized AI detection model; Using the test set to perform a final evaluation on the optimized AI detection model to obtain a trained AI detection model; The AI ​​detection model is iteratively updated and trained based on a preset time threshold.

3. The network anomaly detection method based on AI and IPS joint detection according to claim 2 is characterized in that: The data cleaning steps include: According to the historical message data, data cleaning and label acquisition are performed, historical messages that have not been detected based on the IPS detection engine are deleted, and historical messages with IPS detection results are retained to obtain cleaned data; The IPS detection result is used as a label of the historical message, including an abnormal message or a safe message.

4. The network anomaly detection method based on AI and IPS joint detection according to claim 3 is characterized in that: The feature extraction step comprises: Performing a decoding operation on the cleaned data to obtain decoded data; Performing a character generalization operation according to the decoded data to obtain generalized data; Perform event matching and keyword matching according to the generalized data to obtain matched data; According to the matched data, feature vector conversion is performed to obtain feature data to construct a training set.

5. The network anomaly detection method based on AI and IPS joint detection according to claim 4 is characterized in that: The characteristic data includes the source IP address, destination IP address, port information, protocol type, load content, traffic pattern, behavior pattern and IPS detection result of historical message data.

6. The network anomaly detection method based on AI and IPS joint detection according to claim 5 is characterized in that: The steps of event matching and keyword matching include: According to the same type of events in the generalized data, generalize into corresponding event character combinations; Generalizing keywords of the same type in the generalized data into corresponding keyword character combinations; According to the event character combination and the keyword character combination, matched data is obtained.

7. The network anomaly detection method based on AI and IPS joint detection according to claim 1 is characterized in that: The step of performing further detection based on the preset IPS detection engine includes: According to the message to be processed, matching is performed based on a preset IPS detection engine and a preset rule set; In response to the existence of a corresponding matching rule for the message to be processed, the message to be processed is determined to be an abnormal message, a blocking process is performed based on the operation defined in the matching rule, and an ACL blocking flow table is issued; In response to the fact that there is no corresponding matching rule for the message to be processed, the message to be processed is determined to be a safe message and is processed through.

8. The detection system of the network anomaly detection method based on AI and IPS joint detection according to any one of claims 1 to 7, characterized in that: include: A data acquisition module, used to acquire message data to be detected; An AI detection module is used to perform abnormal message detection on the message data to be detected based on a trained AI detection model, determine whether it deviates from the normal mode behavior, and obtain the corresponding AI detection result; A data blocking module, configured to perform blocking processing in response to the AI ​​detection result being an abnormal message; A data passing module, for performing passing processing in response to the AI ​​detection result being a safe message; The IPS detection module is used to respond to the AI ​​detection result as a message to be processed, then perform further detection based on a preset IPS detection engine, obtain a corresponding detection result and perform response processing.