Network intrusion detection method and device based on hybrid model, and storage medium
The features of network intrusion detection are extracted and enhanced by convolutional neural networks and feature enhancement, and the decision tree is used for classification, which solves the problems of insufficient measurement of high-dimensional feature importance and poor processing of small sample data in the prior art, achieving higher feature accuracy and model stability.
Patent Information
- Application Number
- CN202510328570.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-20
AI Technical Summary
In the detection of network intrusion, existing hybrid models lack effective measurement of the importance of high-dimensional features, are prone to ignore key information, and the classifier is not robust enough when small sample data and unbalanced data sets.
Convolutional neural network is used for feature extraction, combined with feature enhancement network for feature enhancement, and finally classification is used for decision trees. This method shortens the feature sequence length through feature enhancement networks and introduces a decision tree to improve the accuracy of classification results and the execution efficiency of the model.
The accuracy of the features is improved by retaining key features and removing redundant information. At the same time, the introduction of decision trees improves the performance of the model in complex tasks and enhances the adaptability and stability to small samples and imbalanced datasets.
Smart Images

Figure CN120185879A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and more particularly to a network intrusion detection method, device and storage medium based on a hybrid model in the field of network security technology. Background Art
[0002] With the rapid development of artificial intelligence and deep learning technologies, the applications of convolutional neural networks (CNNs) and Transformer models in the fields of computer vision and natural language processing have been widely recognized.
[0003] In recent years, methods combining CNNs and Transformers have gradually attracted the attention of researchers. By combining the local feature extraction ability of CNNs with the global feature modeling ability of Transformers, such methods form a hybrid architecture that can take into account both local details and global semantics in various tasks. In fields such as image classification and object detection, this combined method has shown higher feature extraction efficiency and classification accuracy.
[0004] However, in the model output stage of existing hybrid methods, although CNNs and Transformers can generate rich feature representations, when the fully connected layer classifier processes high-dimensional features, it lacks an effective measure of feature importance and is prone to ignoring some key information, thereby affecting the classification performance. At the same time, when dealing with small sample data and imbalanced data sets, the robustness of the classifier is still insufficient. Summary of the Invention
[0005] The purpose of the present invention is to provide a network intrusion detection method and device based on a hybrid model, and the specific technical solutions adopted are as follows:
[0006] In a first aspect, an embodiment of the present invention provides a network intrusion detection method based on a hybrid model. The hybrid model includes: a convolutional neural network, a feature enhancement network, and a decision tree. The method includes:
[0007] Obtain target data to be detected;
[0008] Use the convolutional neural network to extract features from the target data to be detected to obtain a target feature map;
[0009] Use the feature enhancement network to enhance the features of the target feature map to obtain enhanced features;
[0010] Use the decision tree in the hybrid model to classify the enhanced features to obtain a classification result;
[0011] Based on the classification result, determine whether there is a network intrusion in the target data to be detected.
[0012] In a second aspect, an embodiment of the present invention provides a network intrusion detection device based on a hybrid model. The hybrid model includes: a convolutional neural network, a feature enhancement network, and a decision tree. The network intrusion detection device based on the hybrid model includes:
[0013] An acquisition module, configured to acquire target data to be detected;
[0014] An extraction module, configured to use the convolutional neural network to extract features from the target data to be detected to obtain a target feature map;
[0015] An enhancement module, configured to use the feature enhancement network to enhance the features of the target feature map to obtain enhanced features;
[0016] A classification module, configured to use the decision tree in the hybrid model to classify the enhanced features to obtain a classification result;
[0017] A determination module, configured to determine whether there is a network intrusion in the target data to be detected based on the classification result.
[0018] In a third aspect, a computer program product is provided. The computer program product includes: computer program code, which when running on a computer, causes the computer to execute the method in the first aspect above.
[0019] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores computer program code, which when running on a computer, causes the computer to execute the method in the first aspect above.
[0020] The present invention has the following beneficial effects: After obtaining the target data to be detected, the convolutional neural network is used to extract features from the target data to be detected, and a target feature map is obtained; then, the feature enhancement network is used to enhance the features of the target feature map to obtain enhanced features, which can retain the key features in the target feature map and remove redundant information, making the enhanced features more accurate. Then, the decision tree in the hybrid model is used to classify the enhanced features to obtain a classification result; and based on the classification result, it is determined whether there is a network intrusion in the target data to be detected. In this way, by combining a convolutional neural network, a feature enhancement network, and a decision tree to form a hybrid model, the feature fusion mechanism of the convolutional neural network and the feature enhancement network shortens the sequence length of the feature enhancement network; at the same time, the introduction of the decision tree can not only improve the accuracy of the classification result to more accurately judge whether there is a network intrusion in the target data to be detected, but also reduce the dependence on computing resources and improve the execution efficiency of the model. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0022] Figure 1 is a schematic flowchart of the implementation of a network intrusion detection method based on a hybrid model provided by an embodiment of the present invention;
[0023] Figure 2 is a schematic diagram of the implementation framework of a network intrusion detection method based on a hybrid model provided by an embodiment of the present invention;
[0024] Figure 3 is another schematic flowchart of the implementation of a network intrusion detection method based on a hybrid model provided by an embodiment of the present invention;
[0025] Figure 4 is a schematic diagram of the composition structure of a network intrusion detection device based on a hybrid model provided by an embodiment of the present invention;
[0026] Figure 5 is a schematic diagram of the structure of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details a network intrusion detection method based on a hybrid model according to the present invention, including its specific implementation manner, structure, features, and effects, as follows. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments may be combined in any suitable form.
[0028] Among them, in the description of the embodiments of the present invention, unless otherwise specified, " / " means "or". For example, A / B may represent A or B. The "and / or" in the text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present invention, "a plurality" means two or more than two.
[0029] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.
[0030] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.
[0031] In some embodiments, CNN has become a core technology in image processing tasks with its powerful local feature extraction ability, while Transformer effectively captures global context information through the multi-head attention mechanism and demonstrates excellent performance in processing temporal and sequential data. However, these methods also have certain limitations when dealing with complex tasks.
[0032] Although CNN has advantages in processing spatial features, its ability to capture long-range dependencies and global features is relatively limited. In addition, in the case of insufficient data volume or high noise, CNN is prone to overfitting, resulting in a decline in the generalization ability of the model. On the other hand, although Transformer can demonstrate excellent performance in sequence feature modeling, its computational complexity increases exponentially with the increase in the length of the input sequence, limiting its application in the case of limited computing resources.
[0033] In the related art, in the model output stage, although CNN and Transformer can generate rich feature representations, the choice of classifier has an important impact on the final performance. When dealing with high-dimensional features, traditional fully-connected layer classifiers often lack an effective measure of feature importance, easily ignore some key information, and thus affect the classification performance. At the same time, when existing models deal with small-sample data and imbalanced data sets, the robustness of the classifier is insufficient.
[0034] Based on this, the embodiments of the present invention combine the feature extraction capabilities of CNN and Transformer with the accurate classification capabilities of decision trees as a potential solution. Decision trees have good interpretability, can optimize the decision-making path according to feature importance, and show high stability when dealing with high-dimensional features and small-sample data. By introducing a decision tree as the classifier of the hybrid model, the performance of the model in complex tasks can be further improved, and at the same time, the interpretability of the model and the ability to mine key features can be enhanced.
[0035] Therefore, the hybrid model combining CNN, Transformer and decision tree can not only effectively improve the overall performance of the model, but also show higher adaptability and stability in scenarios such as small samples and imbalanced data sets, thus having broad application prospects in the fields of image processing, network security detection and time series prediction.
[0036] In the related art, CNN and Transformer as feature extraction modules can generate rich feature representations, but these features are often directly classified through fully-connected layers or other simple classifiers. Since the fully-connected layer lacks the ability to judge feature importance, it may ignore some key features, resulting in a decline in classification performance, especially in imbalanced data or small-sample data sets. In the embodiments of the present invention, a decision tree is used instead of the traditional classifier, and the high-dimensional features extracted by CNN and Transformer are input into the decision tree for classification. The decision tree can generate a decision-making path based on feature importance, not only improving the accuracy of classification, but also providing good interpretability.
[0037] In the related art, Transformer usually outputs high-dimensional features, but there is redundant information in these features, which increases the model complexity and affects the performance of the classifier at the same time. The prior art lacks an effective screening and dimensionality reduction mechanism for high-dimensional features. In the embodiments of the present invention, a feature dimensionality reduction module is used to perform dimensionality reduction processing between Transformer and the decision tree, retain key features, remove redundant information, significantly reduce the model complexity and enhance the robustness of the classifier.
[0038] In the related art, deep learning models need to rely on large-scale labeled data for training. In small-sample or imbalanced datasets, the classifiers in the existing technologies are vulnerable to the influence of data distribution, resulting in poor recognition effects for minority classes or long-tail categories. The decision tree classifier in the embodiments of the present invention is applicable to small-sample data and can quickly learn effective decision rules with limited samples. In addition, the decision tree can generate split nodes based on the importance of features, avoiding overlearning of majority-class features, thereby improving the recognition ability for minority-class features.
[0039] In the related art, most deep learning-based hybrid models operate as "black boxes" and it is difficult to explain the classification basis of the model for input data, which limits their applications in sensitive fields (such as medical diagnosis, financial risk control, etc.). The decision tree classifier used in the embodiments of the present invention can generate clear rule paths and feature importance rankings, thereby providing an intuitive interpretability for the model and facilitating users to understand and analyze the classification basis.
[0040] In the related art, when Transformer processes long-sequence data, the computational complexity of its multi-head attention mechanism is relatively high, and it has a large demand for hardware resources, especially there are performance bottlenecks in practical applications. The embodiments of the present invention optimize the feature fusion mechanism of CNN and Transformer to shorten the sequence length of Transformer. At the same time, a dimensionality reduction function and a decision tree are introduced to reduce the dependence on computing resources and improve the execution efficiency of the hybrid model.
[0041] The following specifically describes the specific solution of a network intrusion detection method based on a hybrid model provided by the present invention with reference to the accompanying drawings. Please refer to Figure 1 , which shows a schematic implementation flowchart of a network intrusion detection method based on a hybrid model provided by an embodiment of the present invention. The method includes:
[0042] 101. Obtain target data to be detected.
[0043] Here, the hybrid model includes: a convolutional neural network, a feature enhancement network, and a decision tree; the convolutional neural network, the feature enhancement network, and the decision tree are concatenated to obtain the hybrid model. As shown in Figure 2 , the input dataset 201 is input into the convolutional neural network 202 of the hybrid model. After feature extraction through this network, the feature map is input into the Transformer module 203, and finally the processed features are input into the decision tree 204. After the decision tree makes a decision, it outputs a classification result 205 to determine whether there is a network intrusion.
[0044] The target data to be detected is network intrusion data, for example, data obtained after preprocessing the initial detection data.
[0045] In some possible implementation manners, the above step 101 may be implemented through Figure 3 the steps shown as follows:
[0046] 301. Obtain initial detection data.
[0047] 302. Adjust the initial detection data according to a preset input shape to obtain intermediate detection data.
[0048] Here, the preset input shape is the Tensor format of PyTorch. For example, by storing input data in the Tensor format of PyTorch and organizing these data into a specified input shape, the intermediate detection data can be obtained.
[0049] 303. Normalize the intermediate detection data to obtain the target data to be detected.
[0050] Here, by normalizing the intermediate detection data, the format of the obtained target data to be detected can be unified, which is convenient for processing. Among them, the initial detection data may be data in a network intrusion dataset; this dataset may be the original dataset CICIDS2017. This dataset is a publicly available network intrusion detection benchmark dataset and has the following characteristics:
[0051] (1) This dataset contains network traffic records from a real network environment, and these records are labeled as normal traffic or suffering from different types of network attacks. The dataset covers various types of attacks, including: DoS attack (Denial of Service attack), DDoS attack (Distributed Denial of Service attack), Brute Force, Heartbleed, Port Scan, Infiltration, etc. Each attack type is clearly labeled and used to train and test a network intrusion detection model.
[0052] (2) The characteristics of this dataset include: a. Large scale: The original dataset contains approximately 2.5 million traffic records and more than 80 features, generated in a real-world network environment and having high-dimensional features, which is suitable for training deep learning and traditional machine learning models. b. Diversity: The dataset not only contains normal network traffic (such as Web browsing, FTP transfer, SSH connection, etc.), but also includes various complex attack patterns. Each attack type is carefully designed to simulate different attack means in an actual network environment.
[0053] (3) The format of this dataset includes: The dataset is usually provided in CSV format. Each record contains multiple feature fields, usually including 41 feature attributes and 1 label (Class). These feature fields can be traffic data, timestamps, protocol types, packet lengths, source IP addresses, destination IP addresses, etc. The label field indicates the category of the current record, specifically including "normal traffic" and multiple attack categories (such as DoS, DDoS, Brute Force, etc.).
[0054] (4) The feature types of this dataset include: The features in the dataset include continuous and discrete data, covering multiple network levels, specifically as follows: (1) Continuous features: Such as the size of traffic data (e.g., number of bytes), duration, number of packets transmitted, etc. These data are usually numerical. (2) Discrete features: Such as protocol types (TCP / UDP / ICMP), connection status, service type, etc., which are usually categorical variables. (3) Network layer and application layer features: The features involved include network protocol types (HTTP, HTTPS, FTP, etc.), duration of network sessions, transmission rate of data packets, etc., covering the traffic patterns from the network layer to the application layer, which helps to compare the feature differences of different traffic behaviors.
[0055] 102. Use the convolutional neural network to extract features from the target data to be detected, and obtain a target feature map.
[0056] Here, the convolutional layer, pooling layer, and activation function in the convolutional neural network are used to extract features from the target data to be detected, thereby obtaining a target feature map. According to the features of the input target data, the input data is flattened to form a state space S. The state space is a representation of the current feature map and provides the input required by the CNN and Transformer. Image features are extracted through the convolutional neural network, and the feature map is flattened into a two-dimensional tensor to form a state space, which serves as the basis for subsequent feature processing. Preliminary features are extracted through operations such as multi-layer convolution, batch normalization, activation function, and pooling. The input data is processed through multiple convolutional layers and pooling layers. After each convolutional layer, the ReLU activation function and max pooling operation are applied to extract features at different levels. After each convolutional layer, the Dropout operation is also used to reduce the risk of overfitting.
[0057] In some possible implementation manners, the above step 102 can be implemented through the following steps 121 to 126 (not shown in the figure):
[0058] 121. Use the first convolutional layer in the convolutional neural network to extract features from the target data to be detected, and obtain a first feature map.
[0059] Here, the convolutional neural network is a two-dimensional convolutional neural network, where the number of output channels of the convolutional layers is 64, 128, and 256 in sequence. Each convolutional layer uses a 3×3 convolutional kernel and has a padding of 1. After each convolutional layer, there is a two-dimensional batch normalization (BatchNorm2D) layer, a ReLU activation function, a 2×2 max pooling layer, and a regularization (Dropout) layer, where the Dropout rate is 0.3. For example, the number of channels of the first convolutional layer is 64.
[0060] 122. Perform feature processing on the first feature map to obtain a first candidate feature map.
[0061] Here, the first feature map is processed by a batch normalization layer, a pooling layer, an activation function, and a regularization layer to obtain a first candidate feature map.
[0062] 123. Use the second convolutional layer in the convolutional neural network to perform feature extraction on the first candidate feature map to obtain a second feature map.
[0063] Here, the number of channels of the second convolutional layer is 128; the features of the first candidate feature map are extracted through this second convolutional layer to obtain a second feature map.
[0064] 124. Perform feature processing on the second feature map to obtain a second candidate feature map.
[0065] Here, the second feature map is processed by a batch normalization layer, a pooling layer, an activation function, and a regularization layer to obtain a second candidate feature map.
[0066] 125. Use the third convolutional layer in the convolutional neural network to perform feature extraction on the third candidate feature map to obtain a third feature map.
[0067] Here, the number of channels of the first convolutional layer, the second convolutional layer, and the third convolutional layer are different. The number of channels of the third convolutional layer is 256.
[0068] 126. Perform feature processing on the third feature map to obtain the target feature map.
[0069] Here, the third feature map is processed by a batch normalization layer, a pooling layer, an activation function, and a regularization layer to obtain the target feature map. In this way, by performing feature processing such as regularization on the feature maps extracted by the convolutional layers, the obtained target feature map can be made more accurate.
[0070] In some possible implementation manners, the input data is first fed into the first convolutional layer to generate 64 feature maps. After being processed by BatchNorm2D normalization and the ReLU activation function, downsampling is performed through a 2×2 max pooling layer, and regularization is performed using Dropout. Then, the obtained feature maps are input into the second convolutional layer to generate 128 feature maps, and the same BatchNorm2D, ReLU, max pooling, and Dropout processing are performed. Finally, the input is fed into the third convolutional layer to generate 256 feature maps and the same processing is carried out. The specific structure is shown in Table 1. The processed feature maps are reshaped and transposed into a sequence form, mapped to the input dimension of the Transformer through a linear mapping layer, and a fixed-dimensional feature vector is obtained through multiple Transformer encoders and a feature dimensionality reduction layer. The specific structure is shown in Table 2. This feature vector is used as the input of a decision tree classifier for classification prediction.
[0071] Table 1 CNN Structure Table
[0072]
[0073] Table 2 Structures of Each Encoder Layer of the Transformer
[0074]
[0075] 103. The target feature map is enhanced by using the feature enhancement network to obtain the enhanced feature.
[0076] Here, the feature enhancement network can be a Transformer network. After the convolutional neural network outputs the target feature map, through form conversion processing on the target feature map, a converted feature map that meets the preset sequence form is obtained. Then, the feature enhancement network is used to enhance the converted feature map to obtain the enhanced feature. Among them, the features extracted by the CNN are converted into a sequence form that can be processed by the Transformer through a mapping layer. By reshaping and transposing the converted feature map, a feature map that meets the feature enhancement network is obtained, so as to facilitate the feature enhancement network to enhance this feature map to obtain the enhanced feature.
[0077] In some possible implementation manners, first, reshape the target feature map to obtain the reshaped feature map; then, transpose the reshaped feature map in the preset sequence form to obtain the transformed feature map. Here, the features extracted by the CNN are converted into a sequence form that can be processed by the Transformer through a mapping layer. After reshaping and transposing, the features extracted by the CNN are converted into a sequence, and a linear mapping is used to adjust the transformed feature map to the input dimension of the Transformer. The output of the Transformer undergoes global average pooling and feature dimensionality reduction to obtain a feature vector with a fixed dimension.
[0078] In some possible implementation manners, perform a linear mapping on the transformed feature map through the input dimension corresponding to the feature enhancement network to obtain the mapped feature; and use the feature enhancement network to enhance the mapped feature to obtain the enhanced feature. For example, input the features extracted by the CNN into the Transformer to further extract global features. The Transformer is used to enhance the model's ability to model complex dependencies between features. The features extracted by the CNN are mapped to the dimension of the Transformer input through a linear transformation and converted into a suitable format. The Transformer uses the self-attention mechanism to further encode these features and extract global information to enhance the expressive power of the features.
[0079] In some possible implementation manners, use the encoder of the feature enhancement network to encode the mapped feature to obtain encoded data; and reduce the dimension of the encoded data to a preset dimension through the feature dimensionality reduction layer of the feature enhancement network to obtain the enhanced feature. For example, adopt a Transformer encoder structure with 8 heads of attention: 3 encoder layers, each layer containing multi-head self-attention and a feed-forward network. The input features are scaled by sqrt(d_model) to stabilize the training, and the intermediate expansion dimension of the feed-forward network (256 -> 1024 -> 256) is used to enhance the model's expressive power. In this way, the feature dimension output by the Transformer is reduced by the feature dimensionality reduction module to prepare for subsequent classification. The features output by the Transformer undergo dimensionality reduction through a fully connected layer and are processed using the ReLU activation function to output the final feature vector, so as to use these features as the input of the decision tree classifier.
[0080] 104, use the decision tree in the hybrid model to classify the enhanced feature to obtain a classification result.
[0081] Here, a feature vector with a fixed dimension is used as the input of the decision tree, and the complexity of the tree is controlled by max_depth = 5, providing feature importance analysis and decision tree visualization functions. The extracted features are classified by the decision tree classifier to generate classification results. The decision tree classifies the samples based on the features obtained from training and outputs the classification results. The decision tree is used to train and predict the extracted features. The features of the training samples are input into the decision tree, and the classifier outputs the corresponding predicted labels. The features extracted by CNN and Transformer are trained using the decision tree. In the training phase, the decision tree is trained by using the extracted features and the true labels. After the training is completed, the decision tree classifier obtains the optimal parameters. The enhanced features are classified by the decision tree with the optimal parameters to obtain the classification results.
[0082] 105. Based on the classification result, determine whether there is a network intrusion in the target data to be detected.
[0083] Here, after obtaining the classification result, since there is a mapping relationship between the classification result and whether there is a network intrusion in the target data to be detected, the classification result can be used to determine whether there is a network intrusion in the target data to be detected.
[0084] In some possible implementation manners, after the decision tree outputs the classification result, based on the classification result, determine the gradient loss of the hybrid model; and update the network parameters of the convolutional neural network and the feature enhancement network based on the gradient loss to obtain the updated neural network and the updated feature enhancement network; finally, update the hybrid model based on the updated neural network and the updated feature enhancement network.
[0085] Here, the parameters of the CNN and Transformer are updated through backpropagation to calculate the loss of the model. During training, the cross-entropy loss is used to calculate the error between the outputs of the CNN and Transformer and the true labels. The parameters of the CNN and Transformer networks are updated through gradient descent methods (such as the Adam optimizer) to minimize the loss function. During training, the accuracy of the classifier is calculated and checked for improvement. At the end of each training epoch, the current classification accuracy is compared with the historical best accuracy. If the current accuracy improves, the optimal model parameters are recorded; if not, the early stopping count is incremented, and if the count reaches the set threshold, the training is stopped early. The optimal model weights obtained during the training phase are used to classify and predict the test set, and performance metrics (such as accuracy, recall, and F1-score) are calculated. During the test phase, the optimal parameters of the trained CNN and Transformer networks are used to extract the features of the test set. The test set features are input into the trained decision tree classifier to obtain the classification results. The classification performance metrics on the test set, such as accuracy, precision, recall, and F1-score, are calculated.
[0086] In an embodiment of the present invention, a convolutional neural network is used to extract features from the target data to be detected to obtain a target feature map; then, a feature enhancement network is used to enhance the features of the target feature map to obtain enhanced features, which can retain the key features in the target feature map and remove redundant information, making the enhanced features more accurate. Then, a decision tree in the hybrid model is used to classify the enhanced features to obtain a classification result; and based on the classification result, it is determined whether there is a network intrusion in the target data to be detected. In this way, by combining a convolutional neural network, a feature enhancement network, and a decision tree to form a hybrid model, the feature fusion mechanism of the convolutional neural network and the feature enhancement network shortens the sequence length of the feature enhancement network; at the same time, the introduction of the decision tree can not only improve the accuracy of the classification result to more accurately determine whether there is a network intrusion in the target data to be detected, but also reduce the dependence on computing resources and improve the execution efficiency of the model.
[0087] An embodiment of the present invention provides a network intrusion detection device based on a hybrid model. Please refer to Figure 4 , which shows a schematic structural diagram of a network intrusion detection device based on a hybrid model provided by an embodiment of the present invention. The device 400 includes:
[0088] An acquisition module 401, configured to acquire target data to be detected;
[0089] An extraction module 402, configured to use the convolutional neural network to extract features from the target data to be detected to obtain a target feature map;
[0090] An enhancement module 403, configured to enhance the target feature map by using the feature enhancement network to obtain enhanced features;
[0091] A classification module 404, configured to classify the enhanced features by using a decision tree in the hybrid model to obtain a classification result;
[0092] A determination module 405, configured to determine whether there is a network intrusion in the target data to be detected based on the classification result.
[0093] In some possible implementation manners, the enhancement module 403 is further configured to perform a form conversion process on the target feature map to obtain a converted feature map that meets a preset sequence form; enhance the converted feature map by using the feature enhancement network to obtain the enhanced features.
[0094] In some possible implementation manners, the enhancement module 403 is further configured to reshape the target feature map to obtain a reshaped feature map; transpose the reshaped feature map according to the preset sequence form to obtain the converted feature map.
[0095] In some possible implementation manners, the enhancement module 403 is further configured to perform a linear mapping on the converted feature map based on the input dimension corresponding to the feature enhancement network to obtain mapped features;
[0096] Enhance the mapped features by using the feature enhancement network to obtain the enhanced features.
[0097] In some possible implementation manners, the enhancement module 403 is further configured to encode the mapped features by using an encoder of the feature enhancement network to obtain encoded data;
[0098] Reduce the dimension of the encoded data to a preset dimension based on a feature dimension reduction layer of the feature enhancement network to obtain the enhanced features.
[0099] In some possible implementation manners, the extraction module 402 is further configured to perform feature extraction on the target data to be detected by using a first convolutional layer in the convolutional neural network to obtain a first feature map; perform feature processing on the first feature map to obtain a first candidate feature map; perform feature extraction on the first candidate feature map by using a second convolutional layer in the convolutional neural network to obtain a second feature map; perform feature processing on the second feature map to obtain a second candidate feature map; perform feature extraction on the third candidate feature map by using a third convolutional layer in the convolutional neural network to obtain a third feature map; wherein, the number of channels of the first convolutional layer, the second convolutional layer, and the third convolutional layer are different; perform feature processing on the third feature map to obtain the target feature map.
[0100] In some possible implementation manners, after determining whether there is a network intrusion in the target data to be detected based on the classification result, the determination module 405 is further configured to determine the gradient loss of the hybrid model based on the classification result; update the network parameters of the convolutional neural network and the feature enhancement network based on the gradient loss to obtain an updated neural network and an updated feature enhancement network; update the hybrid model based on the updated neural network and the updated feature enhancement network.
[0101] In some possible implementation manners, the acquisition module 401 is further configured to acquire initial detection data; adjust the initial detection data according to a preset input shape to obtain intermediate detection data; perform normalization processing on the intermediate detection data to obtain the target data to be detected.
[0102] Optionally, the transmission medium may be a wired link (such as, but not limited to, coaxial cable, optical fiber, and Digital Subscriber Line (DSL), etc.) or a wireless link (such as, but not limited to, Wireless Fidelity (WIFI), Bluetooth, and mobile device network, etc.). It should be noted that: the device provided in the above embodiments is only illustrated by dividing the above functional modules. In practical applications, the above functions may be assigned to different functional modules according to needs, that is, the internal structure of the computer device is divided into different functional modules to complete all or part of the functions described above. In addition, the method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process thereof can be found in the method embodiments, which will not be elaborated here.
[0103] Figure 5 is a schematic structural diagram of a computer device provided by an embodiment of the present invention. Exemplarily, as Figure 5As shown in the figure, the computer device 500 includes: a memory 501, a processor 502, and a computer program 503 stored in the memory 501 and running on the processor 502. When the processor 502 executes the computer program 503, the computer device can execute any one of the above-described network intrusion detection methods based on a hybrid model.
[0104] In addition, an embodiment of the present invention also protects a system, which may include a memory and a processor. Among them, an executable program code is stored in the memory, and the processor is used to call and execute the executable program code to execute a network intrusion detection method based on a hybrid model provided by an embodiment of the present invention. In this embodiment, the system can be divided into functional modules according to the above method examples. For example, it can correspond to each functional module, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there may be other division methods in actual implementation. It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be repeated here.
[0105] It should be understood that the device provided in this embodiment is used to execute the above network intrusion detection method based on a hybrid model, so the same effect as the above implementation method can be achieved. In the case of using an integrated unit, the device may include a processing module and a storage module. Among them, when the device is applied to a device, the processing module can be used to control and manage the actions of the device. The storage module can be used to support the device to execute mutual program codes, etc. Among them, the processing module can be a processor or a controller, which can implement or execute various exemplary logical blocks, modules, and circuits described in combination with the disclosure of the present invention. The processor can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processing (DSP) and a microprocessor, etc. The storage module can be a memory.
[0106] In addition, the device provided by the embodiment of the present invention can specifically be a chip, a component, or a module. The chip may include a processor and a memory connected thereto; among them, the memory is used to store instructions, and when the processor calls and executes the instructions, the chip can execute a network intrusion detection method based on a hybrid model provided by the above embodiment. This embodiment also provides a computer-readable storage medium, in which computer program code is stored. When the computer program code runs on a computer, the computer is enabled to execute the above relevant method steps to implement a network intrusion detection method based on a hybrid model provided by the above embodiment.
[0107] This embodiment also provides a computer program product. When the computer program product runs on a computer, it causes the computer to execute the above-related steps to implement a network intrusion detection method based on a hybrid model provided by the above embodiment. Among them, the device, computer-readable storage medium, computer program product, or chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Through the description of the above embodiments, those skilled in the art can understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In the embodiments provided by the present invention, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0108] It should be noted that: the above sequence of the embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous. Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. The above content is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention.
Claims
1. A network intrusion detection method based on a hybrid model, characterized in that: The hybrid model includes: a convolutional neural network, a feature enhancement network and a decision tree. The network intrusion detection method based on the hybrid model includes: Acquire target data to be detected; Using the convolutional neural network to extract features of the target data to be detected to obtain a target feature map; Using the feature enhancement network to perform feature enhancement on the target feature map to obtain enhanced features; Using the decision tree in the hybrid model to classify the enhanced features to obtain a classification result; Based on the classification result, it is determined whether the target data to be detected has network intrusion.
2. A network intrusion detection method based on a hybrid model according to claim 1, characterized in that: The step of using the feature enhancement network to perform feature enhancement on the target feature map to obtain enhanced features includes: Performing a form conversion process on the target feature graph to obtain a converted feature graph that satisfies a preset sequence form; The feature enhancement network is used to perform feature enhancement on the converted feature map to obtain the enhanced feature.
3. A network intrusion detection method based on a hybrid model according to claim 2, characterized in that: The step of converting the target feature graph to obtain a converted feature graph that satisfies a preset sequence format includes: Reshaping the target feature map to obtain a reshaped feature map; The reshaped feature map is transposed according to the preset sequence form to obtain the transformed feature map.
4. A network intrusion detection method based on a hybrid model according to claim 2, characterized in that: The step of using the feature enhancement network to perform feature enhancement on the converted feature map to obtain the enhanced feature includes: Based on the input dimension corresponding to the feature enhancement network, linearly map the converted feature map to obtain mapped features; The feature enhancement network is used to perform feature enhancement on the mapped features to obtain the enhanced features.
5. A network intrusion detection method based on a hybrid model according to claim 4, characterized in that: The step of using the feature enhancement network to enhance the mapped features to obtain the enhanced features includes: Encoding the mapped features using an encoder of the feature enhancement network to obtain encoded data; The coded data is reduced to a preset dimension based on the feature dimension reduction layer of the feature enhancement network to obtain the enhanced features.
6. A network intrusion detection method based on a hybrid model according to claim 1, characterized in that: The method of using the convolutional neural network to extract features of the target data to be detected to obtain a target feature map includes: Using the first convolution layer in the convolutional neural network to extract features of the target data to be detected, to obtain a first feature map; Performing feature processing on the first feature map to obtain a first candidate feature map; Using the second convolutional layer in the convolutional neural network to perform feature extraction on the first candidate feature map to obtain a second feature map; Performing feature processing on the second feature map to obtain a second candidate feature map; Using the third convolutional layer in the convolutional neural network to perform feature extraction on the third candidate feature map to obtain a third feature map; wherein the number of channels of the first convolutional layer, the second convolutional layer and the third convolutional layer are different; Perform feature processing on the third feature map to obtain the target feature map.
7. A network intrusion detection method based on a hybrid model according to claim 1, characterized in that: After determining whether the target data to be detected has network intrusion based on the classification result, the method further includes: Based on the classification result, determining the gradient loss of the hybrid model; Update the network parameters of the convolutional neural network and the feature enhancement network based on the gradient loss to obtain an updated neural network and an updated feature enhancement network; The hybrid model is updated based on the updated neural network and the updated feature enhancement network.
8. A network intrusion detection method based on a hybrid model according to claim 1, characterized in that: The step of obtaining target data to be detected includes: Obtaining initial detection data; Adjusting the initial detection data according to a preset input shape to obtain intermediate detection data; The intermediate detection data is normalized to obtain the target data to be detected.
9. A network intrusion detection device based on a hybrid model, characterized in that: The hybrid model includes: a convolutional neural network, a feature enhancement network and a decision tree. The network intrusion detection device based on the hybrid model includes: An acquisition module, used to acquire target data to be detected; An extraction module, used to extract features of the target data to be detected using the convolutional neural network to obtain a target feature map; An enhancement module, used to perform feature enhancement on the target feature map using the feature enhancement network to obtain enhanced features; A classification module, used for classifying the enhanced features using the decision tree in the hybrid model to obtain a classification result; A determination module is used to determine whether the target data to be detected has network intrusion based on the classification result.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program code, and when the computer program code runs on a computer, the computer is enabled to execute the network intrusion detection method based on a hybrid model according to any one of claims 1 to 8.