Industrial control system intrusion detection method and device of Mamba model, and medium

By integrating Fourier transform and LSTM modules into the intrusion detection method of the Mamba model industrial control system, the time-frequency domain characteristic data of the industrial control system is extracted, and the problem of limited detection capabilities in the face of variant attacks and hidden attacks is solved, and more efficient and accurate intrusion detection is achieved.

CN120165984APending Publication Date: 2025-06-17JIEYANG VOCATIONAL & TECH COLLEGE
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510638392.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing Mamba model industrial control system intrusion detection methods have limited detection capabilities when facing variant attacks and hidden attacks, making it difficult to effectively identify new attack modes.

Method used

By integrating the advantages of Fourier transform in frequency domain analysis and the capabilities of Mamba model in multimodal data processing, the time-frequency domain feature data of the industrial control system is extracted, the long and short-term feature data are extracted using the LSTM module, and the intrusion detection results are output through the full-connection layer network.

Benefits of technology

It improves the accuracy and efficiency of intrusion detection of industrial control systems, can more effectively identify new attack modes such as periodic attacks and frequency abnormal attacks, and enhances the system's security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165984A_ABST
    Figure CN120165984A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial control system intrusion detection, in particular to an industrial control system intrusion detection method and device of a Mama model and a medium. The method comprises the steps that frequency domain features are extracted based on Fourier transform, industrial control system data can be converted from a time domain to a frequency domain, the features of the data on the frequency domain are extracted, an attack mode hidden in a time domain signal can be revealed through frequency domain analysis, a Mamba model can process multi-modal data, and the attack mode hidden in the time domain signal can be revealed. According to the method, the joint features of the data in the time domain and the frequency domain are extracted, the multi-modal data processing capability enables the model to more comprehensively understand the operation state of the industrial control system, and a richer feature space can be constructed by fusing the frequency domain features of Fourier transform and the multi-modal features of the Mamba model, so that the operation state of the industrial control system is more comprehensively understood. And the accuracy and efficiency of intrusion detection of the industrial control system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial control system intrusion detection, and specifically to an industrial control system intrusion detection method, device and medium based on the Mamba model. Background Technique

[0002] With the wide application of industrial control systems and the continuous improvement of the intelligent level, industrial control systems are facing increasingly severe security threats. As an important means to ensure the security of industrial control systems, the accuracy and efficiency of intrusion detection are directly related to the stable operation of the system. However, there are still many challenges and deficiencies in the existing industrial control system intrusion detection methods based on the Mamba model.

[0003] Traditional intrusion detection methods, such as rule-based detection and statistic-based detection, often rely on known attack features and patterns, and have limited detection capabilities for variant attacks and stealth attacks. With the continuous development of attack technologies, attackers continuously update functions or modify attack features to create more variant attacks, resulting in the failure of traditional detection means.

[0004] Therefore, there is an urgent need for an industrial control system intrusion detection method, device and medium based on the Mamba model to solve the above problems. Summary of the Invention

[0005] The purpose of the present invention is to provide an industrial control system intrusion detection method, device and medium based on the Mamba model: aiming to fuse the advantages of Fourier transform in frequency domain analysis and the ability of the Mamba model in multi-modal data processing to achieve accurate detection of intrusion behaviors in industrial control systems and improve the accuracy and efficiency of intrusion detection.

[0006] The purpose of the present invention can be achieved through the following technical solutions: On the one hand, an industrial control system intrusion detection method based on the Mamba model, the method includes: Obtain the communication data of the industrial measurement and control system and preprocess the communication data, extract the basic feature vectors and derived feature vectors from the communication data, and use the attention mechanism to weight and fuse the basic feature vectors and derived feature vectors to obtain the time-domain input feature data; Analyze the time-domain input feature data by the Mamba module to obtain the frequency-domain features, and fuse them with the time-domain input feature data to be recorded as the time-frequency domain feature data, and extract the long-term and short-term feature data from the time-frequency domain feature data through the LSTM module; The long-term and short-term feature data is processed by the fully connected layer network, and the intrusion detection result is output.

[0007] Further, extract the basic feature vectors and derived feature vectors from the communication data, and use the attention mechanism to weight and fuse the basic feature vectors and derived feature vectors to obtain the time-domain input feature data, which specifically includes the following processes: Extract the basic feature vectors from the communication data. Among them, the basic feature vectors include the source IP, destination IP, port number, data length, function code, and timestamp. Construct derived features within the sliding window Win to obtain the derived feature vectors. Among them, the derived feature vectors include the communication frequency feature vector, period feature vector, and statistical feature vector. Use the attention mechanism to weight and fuse the basic feature vectors and derived feature vectors to obtain the time-domain input feature data.

[0008] Further, the process of extracting the basic feature vectors from the communication data specifically includes the following: For the communication data, use the Z-score method to calculate the standard deviation deviation value of each data point, and set the threshold of the standard deviation deviation value of the data point. Determine whether the standard deviation deviation value of the data point is greater than the threshold of the standard deviation deviation value of the data point. If so, regard this data point as an outlier and perform outlier removal. If not, regard it as a normal value. Apply the Z-score method to extract features from the normal values to obtain the basic feature vector b including the source IP, destination IP, port number, data length, function code, and timestamp.

[0009] Further, the process of constructing derived features within the sliding window Win to obtain the derived feature vectors specifically includes the following: Set the sliding window as Win, and form the communication pair (src, dst) with the source address src and the destination address dst. Calculate the communication frequency f(src, dst) based on the M data packets sent by the communication pair (src, dst) within the time interval [t, t + Δt]. The calculation formula for the communication frequency is f(src, dst)=M / Δt. Form the communication frequency feature vector f with the communication frequencies of all communication pairs. Obtain the packet arrival time series of the communication pair (src, dst) within the sliding window Win as T = {t1, t2,..., t M}, and the adjacent packet interval time series P = { , ,..., ,..., }, where and 0 ≤ i ≤ M - 1; calculate the packet period mean : ; calculate the packet periodic variance σ 2 , ; Fuse the period mean and the periodic variance into a period feature vector p; Calculate the mean value of the data packets within the sliding window Win , the standard deviation σ k and the kurtosis K u , where the kurtosis K of the data packets u The formula is ; Combine and fuse the statistical metrics of the mean value, standard deviation, maximum value, minimum value, and kurtosis of the data packets within Win into a statistical feature vector s.

[0010] Furthermore, the attention mechanism is used to weight and fuse the basic feature vector and the derived feature vector to obtain the time-domain input feature data, which specifically includes the following process: Form the feature vector A by combining the basic feature vector b, the communication frequency feature vector f, the period feature vector p, and the statistical feature vector s t ={b, f, p, s}; The feature vector A t Is weighted and fused through the attention mechanism to obtain the time-domain input feature data, and the attention size is set to 32: Calculate the attention scores of each feature vector A t where the attention scores , where the attention scores The calculation formula is ; where Is the hidden state, W and V are the weight matrices of A t , T represents the transpose symbol, and b represents the bias; Calculate the weighted fusion of all features to obtain the time-domain input feature data A fusion , where the calculation of the time-domain input feature data A fusion The formula is: ; where Is the attention weight.

[0011] Furthermore, the Mamba module analyzes the time-domain input feature data to obtain the frequency-domain features, which specifically includes the following process: The Mamba module consists of two branches: the Mamba model and the FFT feature extraction module; The time-domain input feature data is respectively processed by the Mamba model and the Fourier transform feature extraction to obtain the state space feature data and the frequency-domain feature data; Fuse and extract the state space feature data, the frequency-domain feature data, and the time-domain input feature data to obtain the time-frequency domain feature data.

[0012] Furthermore, the working process of the FFT feature extraction module specifically includes the following: Regard the time-domain input feature data as a data set; Let the time-domain input feature data be \(x' \in \mathbb{R}\). B×L×D , where \(B\), \(L\), and \(D\) are the batch size, length, and dimension of the detection data sequence respectively; Perform Fourier transform on the time-domain input feature data to obtain the frequency-domain representation \(X\). k , where the frequency-domain representation \(X\). k The formula is where \(0 \leq k \leq N - 1\), and \(N\) is the length of the time-domain input feature data; Perform one-dimensional convolution on the fused \(Re(X k )\) and \(Im(X k )\) to extract the feature \(x c '\), and the formula for the feature \(x c '\) is ; where \(Re(X k )\) and \(Im(X k )\) are the real part and imaginary part of \(X k \) respectively, and \(conv1d(\cdot)\), \(cat(\cdot)\) are one-dimensional convolution and concatenation operations; Split the feature \(x c '\) into two parts in the channel dimension and denote them as \(x R '\) and \(x I '\), and construct the frequency-domain representation \(X k '\) of the convolutional feature. The formula for the frequency-domain representation \(X k '\) of the convolutional feature is \(X k ' = x R ' + jx I '; Perform inverse Fourier transform on the frequency-domain representation \(X k '\) of the convolutional feature to obtain the frequency-domain feature data \(y' \in \mathbb{R}\). B×L×D , and the formula for the frequency-domain feature data \(y'\) is where \(0 \leq n \leq N - 1\).

[0013] Furthermore, the long-short-term feature data is obtained by extracting the time-frequency domain feature data through the LSTM module, which specifically includes the following process: Let the output dimension of the LSTM hidden layer be 64; Extract the long-short-term feature data \(x t+f \) from the time-frequency domain feature data \(x lstm \) through the LSTM module. The formula for the long-short-term feature data \(x lstm \) is \(x lstm = x t+f + Dropout(LSTM(LayerNorm(x t+f ))); where \(LayerNorm(\cdot)\) is layer normalization, \(Dropout(\cdot)\) is the dropout layer, and \(LSTM(\cdot)\) is the LSTM model.

[0014] On the other hand, the Mamba model industrial control system intrusion detection device includes: The detection data preprocessing module includes an outlier detection subunit, a feature extraction subunit, a data slicing subunit and a feature fusion subunit, which are used to preprocess the collected communication data of the industrial measurement and control system: the outlier detection submodule: uses the Z-score method to remove abnormal data; the feature extraction subunit: extracts the communication frequency feature vector, period feature vector and statistical feature vector from the communication data; the data slicing subunit uses a sliding window to construct a fixed-length sequence input and normalizes the extracted numerical features; the feature fusion submodule uses the attention weight weighted fusion algorithm to fuse the basic features and derived features to obtain the time domain input feature data; The intrusion detection analysis module is used to analyze the time domain input feature data to obtain time-frequency domain feature data and long-term and short-term feature data; The deep feature analysis module includes the Mamba module and the LSTM module. The Mamba module consists of two branches: the Mamba model and the FFT feature extraction module. They extract state space feature data and frequency domain feature data respectively, and fuse the time domain input feature data. After layer normalization and linear layer, the time and frequency domain feature data is obtained. The LSTM module consists of layer normalization, LSTM model, and discard layer to extract and generate long-term and short-term feature data. The detection fusion output module is used to output the intrusion detection results from the long-term and short-term feature data. The detection fusion output module includes a linear layer and an activation function.

[0015] Finally, a medium stores computer instructions, wherein the computer instructions enable a computer to execute the industrial control system intrusion detection method based on the Mamba model.

[0016] Compared with the existing solutions, the present invention achieves the following beneficial effects: The present invention can convert industrial control system data from time domain to frequency domain based on Fourier transform to extract frequency domain features, and extract features of data in frequency domain. These features are very effective for identifying certain specific types of attacks such as periodic attacks, frequency anomaly attacks, etc. Through frequency domain analysis, attack patterns hidden in time domain signals can be revealed. The Mamba model can process multimodal data and extract joint features of data in time domain and frequency domain. This multimodal data processing capability enables the model to understand the operating status of the industrial control system more comprehensively. By fusing the frequency domain features of Fourier transform and the multimodal features of the Mamba model, a richer feature space can be constructed to further improve the accuracy of detection.

[0017] Furthermore, based on the Fourier transform and the good parallel processing ability of the Mamba model, the feature extraction and model inference processes are accelerated. In large-scale industrial control systems, this parallel processing ability can significantly improve the detection efficiency and reduce the detection latency. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0019] Figure 1 is a flowchart of the first industrial control system intrusion detection method of the Mamba model according to an embodiment of the present invention; Figure 2 is a flowchart of the second industrial control system intrusion detection method of the Mamba model according to an embodiment of the present invention; Figure 3 is a flowchart of the third industrial control system intrusion detection method of the Mamba model according to an embodiment of the present invention; Figure 4 is a structural block diagram of an industrial control system intrusion detection device of a Mamba model according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0021] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more exemplary embodiments. In the following description, many specific details are provided to give a full understanding of the exemplary embodiments of the present disclosure. However, those skilled in the art will realize that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, steps, etc. can be used. In other cases, well-known structures, methods, implementations, or operations are not shown or described in detail to avoid obscuring the various aspects of the present disclosure.

[0022] This embodiment provides an industrial control system intrusion detection method of the Mamba model, Figure 1 is a flowchart of the first industrial control system intrusion detection method of the Mamba model according to an embodiment of the present invention, as Figure 1As shown in the figure, the method includes the following steps: Step S101: Obtain the communication data of the industrial measurement and control system and preprocess the communication data. Extract the basic feature vectors and derived feature vectors from the communication data, and use the attention mechanism to weight and fuse the basic feature vectors and derived feature vectors to obtain the time-domain input feature data; Step S102: Analyze the time-domain input feature data through the Mamba module to obtain the frequency-domain features, and fuse them with the time-domain input feature data to obtain the time-frequency domain feature data. Extract the long-term and short-term feature data from the time-frequency domain feature data through the LSTM module; Step S103: Process the long-term and short-term feature data through the fully connected layer network and output the intrusion detection result.

[0023] Specifically, the core function: Map the long-term and short-term feature data to the probability space of the intrusion detection result, and automatically mine the non-linear relationship between the features and the intrusion behavior through weight learning.

[0024] Typical structure: Input layer: Receive the concatenated long-term and short-term feature vectors; Hidden layer: 1-3 layers of fully connected layers, each layer contains 128-512 neurons, and the activation function is usually ReLU; Output layer: Use the Softmax or Sigmoid function to output the intrusion probability or classification result.

[0025] In summary, the present invention extracts the frequency-domain features based on the Fourier transform, which can convert the industrial control system data from the time domain to the frequency domain, extract the features of the data in the frequency domain, and through the frequency-domain analysis, the attack patterns hidden in the time-domain signal can be revealed. The Mamba model can process multi-modal data and extract the joint features of the data in the time domain and the frequency domain. This multi-modal data processing ability enables the model to more comprehensively understand the operating state of the industrial control system. By fusing the frequency-domain features of the Fourier transform and the multi-modal features of the Mamba model, a richer feature space can be constructed, further improving the accuracy and efficiency of industrial control system intrusion detection.

[0026] In some embodiments, Figure 2 is the flowchart of the second Mamba model-based industrial control system intrusion detection method of the present invention. As Figure 2 shown, extracting the basic feature vectors and derived feature vectors from the communication data, and using the attention mechanism to weight and fuse the basic feature vectors and derived feature vectors to obtain the time-domain input feature data includes the following steps: Step S201: Extract the basic feature vectors from the communication data. Among them, the basic feature vectors include the source IP, target IP, port number, data length, function code, and timestamp; Step S202: Construct derivative features within the sliding window Win to obtain a derivative feature vector, where the derivative feature vector includes a communication frequency feature vector, a period feature vector, and a statistical feature vector; Step S203: Use the attention mechanism to weight and fuse the basic feature vector and the derivative feature vector to obtain the time-domain input feature data.

[0027] Furthermore, the process of extracting basic feature vectors from communication data specifically includes the following steps: For communication data, use the Z-score method to calculate the standard deviation deviation value of each data point, and set the threshold of the standard deviation deviation value of the data point. Determine whether the standard deviation deviation value of the data point is greater than the threshold of the standard deviation deviation value of the data point. If so, regard the data point as an outlier and perform outlier removal. If not, regard it as a normal value; apply the Z-score method to extract features from the normal values to obtain a basic feature vector b including the source IP, destination IP, port number, data length, function code, and timestamp.

[0028] The process of constructing derivative features within the sliding window Win to obtain a derivative feature vector specifically includes the following steps: Let the sliding window be Win, and form a communication pair (src, dst) with the source address src and the destination address dst; Based on the M data packets sent within the time interval [t, t + Δt] by the communication pair (src, dst), calculate the communication frequency f(src, dst). The calculation formula for the communication frequency is f(src, dst)=M / Δt; form a communication frequency feature vector f from the communication frequencies of all communication pairs; Obtain the packet arrival time series of the communication pair (src, dst) within the sliding window Win as T={t1, t2,..., t M}, and the adjacent packet interval time series P={ , ,..., ,..., }, where and 0 ≤ i ≤ M - 1; calculate the average packet period : ; calculate the packet periodic variance σ 2 , ; fuse the average period and the periodic variance into a period feature vector p; Calculate the average value , standard deviation σ k and kurtosis K u of the data packets within the sliding window Win, where the formula for the packet kurtosis K u is ;The mean, standard deviation, maximum value, minimum value, and kurtosis statistical indicators of the data packets in Windows are combined into a statistical feature vector s.

[0029] The attention mechanism is used to weight and fuse the basic feature vector and the derived feature vector to obtain the time-domain input feature data, which specifically includes the following process: The basic feature vector b, the communication frequency feature vector f, the period feature vector p, and the statistical feature vector s are combined into a feature vector A t ={b, f, p, s}; The feature vector A t is weighted and fused by the attention mechanism to obtain the time-domain input feature data, and the attention size is set to 32: Calculate the attention scores of each feature vector A t where the attention score , and the attention score The calculation formula is ; where is the hidden state, W and V are the weight matrices of A t , T represents the transpose symbol, and b represents the bias; Calculate the weighted fusion of all features to obtain the time-domain input feature data A fusion , where the calculation formula for the time-domain input feature data A fusion is: ; where is the attention weight.

[0030] In some embodiments, Figure 3 is the flowchart of the third Mamba model-based industrial control system intrusion detection method in the embodiments of the present invention. As Figure 3 shown, the Mamba module analyzes the time-domain input feature data to obtain the frequency-domain features, which specifically includes the following process: Step S301: The Mamba module is composed of two branches: the Mamba model and the FFT feature extraction module; It should be noted that FFT (Fast Fourier Transform) converts the time-domain signal into a frequency-domain signal, thereby revealing the features of the signal in the frequency domain; the Mamba model is an innovative deep learning architecture developed based on the structured state space sequence model (SSM), aiming to efficiently capture the complex dependencies in sequence data.

[0031] Step S302: The time-domain input feature data is respectively subjected to the Mamba model and the Fourier transform feature extraction to obtain the state space feature data and the frequency-domain feature data; Step S303: Fuse and extract the state space feature data, frequency domain feature data, and time domain input feature data to obtain time-frequency domain feature data.

[0032] Furthermore, the working process of the FFT feature extraction module specifically includes the following: Regard the time domain input feature data as a data set; Let the time domain input feature data be x´ ∈ R B×L×D , where B, L, and D are the batch size, length, and dimension of the detection data sequence respectively; Perform Fourier transform on the time domain input feature data to obtain the frequency domain representation X k , where the frequency domain representation X k The formula is where 0 ≤ k ≤ N - 1, and N is the length of the time domain input feature data; Perform one-dimensional convolution on the fused Re(X k ) and Im(X k ) to extract the feature x c ´, and the formula for the feature x c ´ is ; where Re(X k ) and Im(X k ) are the real part and imaginary part of X k respectively, and conv1d(·) and cat(·) are one-dimensional convolution and concatenation operations; Split the feature x c ´ into two parts in the channel dimension and denote them as x R ´ and x I ´, and construct the convolutional feature frequency domain representation X k ´. The formula for the convolutional feature frequency domain representation X k ´ is X k ´ = x R ´ + jx I ´; Perform inverse Fourier transform on the convolutional feature frequency domain representation X k ´ to obtain the frequency domain feature data y´ ∈ R B×L×D , and the formula for the frequency domain feature data y´ is where 0 ≤ n ≤ N - 1.

[0033] The process of obtaining the state space feature data from the time domain input feature data through the Mamba model specifically includes the following: Input the preprocessed time domain input feature data into the input layer of the Mamba model.

[0034] Encoding layer (pre-trained encoder): The pre-trained encoder performs preliminary processing on the input data and maps it into a high-dimensional latent representation space. This process may include operations such as linear transformation and non-linear activation functions to capture complex patterns in the input data.

[0035] State Space Module (LSS Module): The core of the Mamba model is the Local-enhanced State Space (LSS) module, which is responsible for capturing long-range dependencies and local information in sequence data at multiple scales.

[0036] The LSS module captures the dynamic changes in the sequence by recursively scanning the input sequence and updating the state representation in the state space.

[0037] Decoding Layer (Mamba Decoder): The decoding layer converts the state representation output by the state space module back to the original feature space or a higher-level feature space. This process may include operations such as linear transformation and deconvolution to generate the final state space feature data.

[0038] Generation of State Space Feature Data Feature Fusion: After the decoding layer, the Mamba model may fuse features at different scales and levels to generate more comprehensive and richer state space feature data.

[0039] Output: The Mamba model outputs state space feature data, which reflect the representation and dynamic changes of the input sequence in the state space.

[0040] The process of extracting long-term and short-term feature data from the time-frequency domain feature data by the LSTM module specifically includes the following steps: Let the output dimension of the LSTM hidden layer be 64; For the time-frequency domain feature data x t+f Extract the long-term and short-term feature data x through the LSTM module lstm , where the long-term and short-term feature data x lstm The formula is x lstm =x t+f +Dropout(LSTM(LayerNorm(x t+f ))); where, LayerNorm(·) is layer normalization, Dropout(·) is the dropout layer, and LSTM(·) is the LSTM model.

[0041] The process of fusing and extracting the time-frequency domain feature data specifically includes the following steps: Obtain the time-domain input feature data, state-space feature data, and frequency-domain feature data of each detected data packet, perform addition fusion, and after layer normalization and a linear layer, form time-frequency domain feature data.

[0042] On the other hand, Figure 4 is a structural block diagram of an industrial control system intrusion detection device of a Mamba model according to an embodiment of the present invention, as Figure 4 shown. The device includes: A detection data preprocessing module, including an outlier detection sub-unit, a feature extraction sub-unit, a data slicing sub-unit, and a feature fusion sub-unit, for preprocessing the communication data of the industrial measurement and control system collected: Outlier detection sub-module: Use the Z-score method to remove abnormal data; Feature extraction sub-unit: Extract communication frequency feature vectors, period feature vectors, and statistical feature vectors from the communication data; Data slicing sub-unit, use a sliding window to construct a fixed-length sequence input and normalize the extracted numerical features; Feature fusion sub-module, use the attention weight weighted fusion algorithm to fuse the basic features and derived features to obtain time-domain input feature data; An intrusion detection analysis module for analyzing the time-domain input feature data to obtain time-frequency domain feature data and long-term and short-term feature data; A deep feature analysis module, including a Mamba module and an LSTM module; The Mamba module consists of two branches, a Mamba model and an FFT feature extraction module, which respectively extract state-space feature data and frequency-domain feature data, and fuse the time-domain input feature data. After layer normalization and a linear layer, time-frequency domain feature data is obtained; The LSTM module consists of layer normalization, an LSTM model, and a dropout layer, and extracts and generates long-term and short-term feature data; A detection fusion output module for outputting an intrusion detection result from the long-term and short-term feature data. The detection fusion output module includes a linear layer and an activation function.

[0043] Finally, the present invention also provides a medium that stores computer instructions, and the computer instructions cause the computer to execute the above-mentioned industrial control system intrusion detection method of the Mamba model.

[0044] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable medium or transmitted from one computer-readable medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable medium can be any available medium that the computer can access or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0045] Those of ordinary skill in the art will appreciate that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.

[0046] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.

[0047] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only for some logical function divisions, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed with each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0048] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0049] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. Mamba model industrial control system intrusion detection method, characterized in that the method include: Acquire the communication data of the industrial measurement and control system and preprocess the communication data, extract the basic feature vector and the derived feature vector from the communication data, and use the attention mechanism to weightedly fuse the basic feature vector and the derived feature vector to obtain the time domain input feature data; The Mamba module analyzes the time domain input feature data to obtain frequency domain features, which are fused with the time domain input feature data to be recorded as time-frequency domain feature data. The LSTM module extracts the time-frequency domain feature data to obtain long-term and short-term feature data. The long-term and short-term feature data are processed by the fully connected layer network and the intrusion detection results are output.

2. The industrial control system intrusion detection method of the Mamba model according to claim 1 is characterized in that: Extracting basic feature vectors and derived feature vectors from communication data, and using the attention mechanism to weightedly fuse the basic feature vectors and derived feature vectors to obtain time domain input feature data specifically includes the following processes: Extract features from the communication data to obtain a basic feature vector, where the basic feature vector includes source IP, target IP, port number, data length, function code and timestamp; Constructing derived features in the sliding window Win to obtain a derived feature vector, wherein the derived feature vector includes a communication frequency feature vector, a period feature vector and a statistical feature vector; The attention mechanism is used to weightedly fuse the basic feature vector and the derived feature vector to obtain the time domain input feature data.

3. The industrial control system intrusion detection method of the Mamba model according to claim 2 is characterized in that: The process of extracting features from communication data to obtain basic feature vectors specifically includes the following steps: For communication data, the Z-score method is used to calculate the standard deviation deviation value of each data point, and a data point standard deviation deviation value threshold is set to determine whether the data point standard deviation deviation value is greater than the data point standard deviation deviation value threshold. If so, the data point is regarded as an outlier and removed. Otherwise, it is regarded as a normal value. The Z-score method is used to extract features of normal values ​​to obtain a basic feature vector b containing source IP, target IP, port number, data length, function code and timestamp.

4. The industrial control system intrusion detection method of the Mamba model according to claim 2 is characterized in that: Constructing derived features in the sliding window Win to obtain derived feature vectors specifically includes the following processes: Let the sliding window be Win, and let the source address be src and the destination address be dst to form a communication pair (src, dst); The communication frequency f(src,dst) is calculated based on the M data packets sent by the communication pair (src,dst) in the time interval [t,t+Δt]. The calculation formula of the communication frequency is f(src,dst)=M / Δt; the communication frequencies of all communication pairs are used to form a communication frequency feature vector f; The arrival time series of the data packets of the communication pair (src, dst) in the sliding window Win are T={t1,t2,...,t M }, the time series of adjacent data packets interval P = { , , ..., , ..., },in, And 0≤i≤M-1; calculate the mean value of the data packet cycle : ; Calculate the periodic variance σ of the data packet 2 , ; Merge the periodic mean and periodic variance into the periodic feature vector p; Calculate the mean of the data packets in the sliding window Win , standard deviation σ k and kurtosis K u , where the packet kurtosis K u The formula is ; The mean, standard deviation, maximum, minimum and kurtosis statistical indicators of the data packets in Win are integrated into the statistical feature vector s.

5. The industrial control system intrusion detection method of the Mamba model according to claim 2 is characterized in that: The attention mechanism is used to weight the fusion of the basic feature vector and the derived feature vector to obtain the time domain input feature data, which specifically includes the following process: The basic feature vector b, the communication frequency feature vector f, the period feature vector p, and the statistical feature vector s are combined into a feature vector A t ={b,f,p,s}; The feature vector A t The time domain input feature data is obtained by weighted fusion of the attention mechanism, and the attention size is set to 32: Calculate each eigenvector A t Attention score , where the attention score The calculation formula is ;in, is the hidden state, W and V are A t The weight matrix of , T represents the transposed sign, and b represents the bias; Calculate the weighted fusion of all features to obtain the time domain input feature data A fusion , where the time domain input feature data A is calculated fusion The formula is: ; in, is the attention weight.

6. The industrial control system intrusion detection method of the Mamba model according to claim 1 is characterized in that: The Mamba module analyzes the time domain input feature data to obtain the frequency domain feature details. The process includes: The Mamba module consists of two branches: the Mamba model and the FFT feature extraction module; The time domain input feature data is extracted through Mamba model and Fourier transform to obtain state space feature data and frequency domain feature data; The state space feature data, frequency domain feature data and time domain input feature data are fused and extracted to obtain the time-frequency domain feature data.

7. The industrial control system intrusion detection method of the Mamba model according to claim 6 is characterized in that: The workflow of the FFT feature extraction module specifically includes: the following: The time domain input feature data is taken as a data set; Assume that the time domain input feature data is x´∈R B×L×D , B, L, and D are the batch size, length, and dimension of the detection data sequence, respectively; Perform Fourier transform on the time domain input feature data to obtain the frequency domain representation X k , where the frequency domain represents X k The formula is Where 0≤k≤N-1, N is the length of the time domain input feature data; For Re(X k )、Im(X k ) After fusion, one-dimensional convolution is performed to extract features x c ´, feature x c The formula is ; where Re(X k )、Im(X k ) are X k The real and imaginary parts of , conv1d(·) and cat(·) are one-dimensional convolution and concatenation operations; The feature x c ´Split into two parts in the channel dimension and record them as x R ´、x I ´And construct the convolution feature frequency domain representation X k ´, the convolution feature frequency domain representation X k ´The formula is X k ´=x R ´+jx I ´; Represent the convolution feature in frequency domain X k ´Perform inverse Fourier transform to obtain frequency domain feature data y´∈R B×L×D , the frequency domain characteristic data y´ formula is Among them, 0≤n≤N-1.

8. The industrial control system intrusion detection method of the Mamba model according to claim 1 is characterized in that: The LSTM module extracts the time-frequency domain feature data to obtain long-term and short-term feature data, which specifically includes the following processes: Assume that the output dimension of the LSTM hidden layer is 64; For the time-frequency domain feature data x t+f Extract long-term and short-term feature data x through the LSTM module lstm , where the long-term and short-term characteristic data x lstm The formula is x lstm =x t+f +Dropout(LSTM(LayerNorm(x t+f ))); LayerNorm(·) is layer normalization, Dropout(·) is the dropout layer, and LSTM(·) is the LSTM model.

9. The industrial control system intrusion detection device based on the Mamba model is characterized by: An industrial control system intrusion detection method applicable to the Mamba model described in any one of claims 1 to 8, the device comprising: The detection data preprocessing module includes an outlier detection subunit, a feature extraction subunit, a data slicing subunit and a feature fusion subunit, which are used to preprocess the collected communication data of the industrial measurement and control system: the outlier detection submodule: uses the Z-score method to remove abnormal data; the feature extraction subunit: extracts the communication frequency feature vector, period feature vector and statistical feature vector from the communication data; the data slicing subunit uses a sliding window to construct a fixed-length sequence input and normalizes the extracted numerical features; the feature fusion submodule uses the attention weight weighted fusion algorithm to fuse the basic features and derived features to obtain the time domain input feature data; The intrusion detection analysis module is used to analyze the time domain input feature data to obtain time-frequency domain feature data and long-term and short-term feature data; The deep feature analysis module includes the Mamba module and the LSTM module. The Mamba module consists of two branches: the Mamba model and the FFT feature extraction module. They extract state space feature data and frequency domain feature data respectively, and fuse the time domain input feature data. After layer normalization and linear layer, the time and frequency domain feature data is obtained. The LSTM module consists of layer normalization, LSTM model, and discard layer to extract and generate long-term and short-term feature data. The detection fusion output module is used to output the intrusion detection results from the long-term and short-term feature data. The detection fusion output module includes a linear layer and an activation function.

10. A medium, characterized in that The medium stores computer instructions, and the computer instructions enable a computer to execute the industrial control system intrusion detection method of the Mamba model as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Smart home detection and management method and device and computer equipment

    CN118918535A

  • Network anomaly monitoring method and system of switch

    CN119071052A

  • Tunnel construction collapse early warning method and system

    CN119435131A

  • Industrial control system intrusion detection method and system based on Mama model

    CN119848749A

  • Transitive and commutative multimodal models and uses

    WO2024223621A1