Cloud MES illegal intrusion predictive security defense method and system

By building a cloud MES illegal intrusion prediction model and using the log data feature vector set for prediction, the problem of the inability to predict illegal intrusion in advance in the existing technology is solved, the time and location prediction of illegal intrusion events are realized, and security defense capabilities are improved.

CN120200776APending Publication Date: 2025-06-24YANCHENG TEACHERS UNIV +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411981278.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively predict possible illegal intrusions in cloud MES in advance, resulting in delayed response to defense measures and inability to prevent irreparable losses in a timely manner.

Method used

By constructing a cloud MES illegal intrusion behavior log data feature vector set, an illegal intrusion prediction model is established, including an illegal intrusion behavior identification model, a sequence generation module and a prediction model based on long and short-term memory networks, the prediction time and location of illegal intrusion behavior are achieved.

Benefits of technology

It has achieved the time and location prediction of possible illegal intrusions in the future, transformed passive defense into active defense, improved security defense capabilities, and enhanced security guarantees in cyberspace.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200776A_ABST
    Figure CN120200776A_ABST
Patent Text Reader

Abstract

The invention provides a cloud MES illegal intrusion predictive security defense method and system, and the method comprises the steps: obtaining the log data of various types of cloud MES illegal intrusion behaviors, constructing a cloud MES illegal intrusion behavior log data feature vector set, carrying out the class labeling of the illegal intrusion behaviors, obtaining labeled data, and obtaining a training data set; a cloud MES illegal intrusion prediction model is constructed, the cloud MES illegal intrusion prediction model comprises an illegal intrusion behavior recognition model, a sequence generation module and an illegal intrusion behavior prediction model based on a long and short-term memory network, and the trained cloud MES illegal intrusion prediction model is obtained; the prediction time and the prediction position of the illegal intrusion behavior are obtained; cloud MES illegal intrusion predictive security defense is realized; according to the method, possible illegal intrusion can be effectively predicted in advance, passive defense in an event and after the event is changed into active defense in advance, the security defense capability can be improved, and the security of a network space can be further guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and system for predictive security defense against illegal intrusion in cloud MES, belonging to the technical field of cybersecurity defense in cyberspace. Background Art

[0002] In the cyberspace of cloud manufacturing execution system, i.e., cloud MES, there are various security threats, including malware, cyberattacks, and illegal intrusions. In particular, network intrusion behaviors against enterprises and organizations may lead to serious consequences such as data leakage, service interruption, and property loss, posing a severe challenge to information security and economic development. The cybersecurity defense system can detect cyberattacks in real time and respond promptly, and has become an essential important security line of defense.

[0003] Regarding the above problems, the main current methods for cybersecurity defense in cyberspace are as follows: One is the intrusion detection method. For example, a method, system, device, and medium for active defense and attack based on end sensing disclosed in Chinese Patent Publication No. CN 118018328 A monitors the access port to obtain device information of the access device, inputs the device information into a support vector machine model for device classification and identification, and determines whether the classification and identification result is an illegally intruding device, realizing effective defense against illegal intrusion. At the same time, through intelligent monitoring, identification, feedback, and dynamic adjustment of strategies, the security of the host port facilities is ensured. Another example is a method and system for intrusion tracking detection and interception and removal for industrial Internet of Things disclosed in Chinese Patent Application Publication No. CN117938453 A. It performs attack data stream identification processing on the device terminal where an illegal intrusion event occurs, identifies the device terminal in a hijacked state from it, determines the attack source inside the industrial Internet of Things, and isolates the device terminal in a hijacked state, improving the timeliness and initiative of intrusion detection in the industrial Internet of Things.

[0004] Second, there are security defense methods. For example, a network security defense system based on cloud computing disclosed in Chinese Patent Application Publication No. CN 116980185 A. When detecting the access of network IPs in the malicious IP library, it uses a data isolation module to isolate the internal data information of the computer and generate an alarm instruction to prompt that the internal data information of the computer has been illegally invaded. Through the data monitoring module and the IP verification module, security management is carried out simultaneously from both the inside and outside of the computer, which can prevent the leakage of important information in the internal data of the computer and achieve double protection. Another example is a network security intrusion prevention system disclosed in Chinese Patent Application Publication No. CN 116471031 A. It determines and intercepts intrusion information, and at the same time can perform reverse tracking and positioning based on the intrusion path of the intrusion information, and send alarm information to the staff terminal, so that the staff can take protective measures in a timely and effective manner and control the intruder, improving network security.

[0005] However, the above-mentioned network space security defense methods are all defenses against currently occurring illegal intrusion events and do not effectively predict illegal intrusions. At this time, the illegal intrusion events have already occurred or are occurring. Once the identification or defense fails, serious irreparable consequences will occur. Therefore, there is an urgent need for a predictive cloud MES security defense method and system to effectively predict in advance possible illegal intrusion events and predict the time and location of their occurrence, realizing predictive security defense against illegal intrusions. Summary of the Invention

[0006] The purpose of the present invention is to provide a cloud MES illegal intrusion predictive security defense method and system to solve the problems existing in the prior art of how to effectively predict in advance possible illegal intrusions and the need to improve security defense capabilities.

[0007] The technical solution of the present invention is as follows: A cloud MES illegal intrusion predictive security defense method includes the following steps: S1. Obtain log data of various types of cloud MES illegal intrusion behaviors, construct a feature vector set of cloud MES illegal intrusion behavior log data, and after performing illegal intrusion behavior category annotation, obtain annotated data and a training data set; S2. Build a cloud MES illegal intrusion prediction model. The cloud MES illegal intrusion prediction model includes an illegal intrusion behavior recognition model, a sequence generation module, and an illegal intrusion behavior prediction model based on a long short-term memory network. Input the feature vector set of cloud MES illegal intrusion behavior log data into the illegal intrusion behavior recognition model, and then output the recognized illegal intrusion behavior categories. The sequence generation module constructs the time-space sequence of illegal intrusion behaviors based on the log data feature vectors corresponding to the recognized illegal intrusion behavior categories, and outputs it to the illegal intrusion behavior prediction model based on the long short-term memory network. The prediction results obtained by the illegal intrusion behavior prediction model based on the long short-term memory network include the predicted time and predicted location of the occurrence of cloud MES illegal intrusion behaviors. S3. After training the cloud MES illegal intrusion prediction model with the training data set obtained in step S1, obtain the trained cloud MES illegal intrusion prediction model. S4. From the log data of the cloud MES illegal intrusion behavior to be predicted, obtain the feature vector set of the cloud MES illegal intrusion behavior log data to be predicted, and obtain the predicted time and predicted location of the occurrence of the illegal intrusion behavior through the trained cloud MES illegal intrusion prediction model. S5. According to the predicted time and predicted location of the occurrence of the illegal intrusion behavior obtained in step S4, and the corresponding feature vector set of the cloud MES illegal intrusion behavior log data, call the cloud security defense mechanism to achieve predictive security defense against cloud MES illegal intrusion.

[0008] Further, in step S2, the illegal intrusion behavior recognition model adopts a recognition model based on the II-BRes2Net network. The recognition model based on the II-BRes2Net network includes a first input layer, a multi-scale backbone network Res2Net, a pyramid feature network FPN, a region proposal network RPN, a region of interest alignment layer RoIAlign, a first fully connected layer, and a first output layer. First input layer: used to input the feature vector set of cloud MES illegal intrusion behavior log data into the multi-scale backbone network Res2Net. Multi-scale backbone network Res2Net: conduct preliminary recognition on the input feature vector set of cloud MES illegal intrusion behavior log data to obtain preliminary cloud MES illegal intrusion behavior features. Pyramid feature network FPN: map the preliminary cloud MES illegal intrusion behavior features to the cloud MES illegal intrusion behavior log data, take the center point of this data area as the anchor point to obtain the regional anchor reference box anchor, and apply the predicted offset to the reference box anchor to obtain the predicted candidate object localization box. At the same time, obtain the intersection over union IoU threshold. Region proposal network RPN: adjust the predicted candidate object localization box and then output it to the region of interest alignment layer RoIAlign. Region of Interest Alignment Layer RoIAlign: After combining the Intersection over Union (IoU) threshold and performing normalization to obtain the normalized cloud MES illegal intrusion behavior feature localization box, it is output to the fully connected layer; First Fully Connected Layer: Classifies and identifies the cloud MES illegal intrusion behavior features to obtain the cloud MES illegal intrusion behavior; First Output Layer: Used to output the cloud MES illegal intrusion behavior categories obtained by the fully connected layer.

[0009] Furthermore, in step S2, in the sequence generation module, a spatio-temporal sequence {T j , P j | B i} of illegal intrusion behaviors is constructed, where T j represents the duration since the previous occurrence when the i-th type of illegal intrusion behavior Bi appears for the j-th time, and Pj represents the location (i.e., the IP address value) where the i-th type of illegal intrusion behavior Bi appears for the j-th time.

[0010] Furthermore, in step S2, the illegal intrusion behavior prediction model based on the Long Short-Term Memory (LSTM) network includes a second input layer, a first hidden layer, a second hidden layer, a second fully connected layer, and a second output layer. Second Input Layer: Used to input the spatio-temporal sequence of illegal intrusion behaviors into the first hidden layer; First Hidden Layer: Used to perform a preliminary prediction on the input cloud MES illegal intrusion behavior log data feature vector set to obtain the preliminary predicted time and predicted location of the cloud MES illegal intrusion behavior occurrence at each node; Second Hidden Layer: The second hidden layer has the same network structure as the first hidden layer and is used to optimize and fine-tune the preliminary predicted time and location of the cloud MES illegal intrusion behavior occurrence at each node to obtain the predicted time and predicted location of the cloud MES illegal intrusion behavior occurrence at each node; Second Fully Connected Layer: Combines the predicted time and predicted location of the cloud MES illegal intrusion behavior occurrence at each node to obtain the final predicted time and predicted location of the cloud MES illegal intrusion behavior occurrence; Second Output Layer: Used to output the prediction result, that is, the final predicted time and predicted location of the cloud MES illegal intrusion behavior occurrence obtained by the fully connected layer.

[0011] Further, in step S1, the cloud MES illegal intrusion behavior log data feature vector set Bi = {network protocol type vector npType, network connection feature vector NCFV, network connection traffic feature vector NCTFV, network dynamic behavior feature vector NDBFV, network connection traffic host feature vector hNCTFV, attacker behavior pattern feature vector BMTraitV, illegal intrusion behavior category feature vector BTTraitV, binary feature vector BiTraitV, service feature vector SerTraitV}.

[0012] A cloud MES illegal intrusion predictive security defense system adopting the method described in any one of the above, including a data annotation module, a model construction module, a model training module, a prediction module, and a security defense module. Data annotation module: Obtain log data of various types of cloud MES illegal intrusion behaviors, construct a cloud MES illegal intrusion behavior log data feature vector set, and after performing illegal intrusion behavior category annotation, obtain annotated data and a training data set. Model construction module: Construct a cloud MES illegal intrusion prediction model. The cloud MES illegal intrusion prediction model includes an illegal intrusion behavior recognition model, a sequence generation module, and an illegal intrusion behavior prediction model based on a long short-term memory network. After inputting the cloud MES illegal intrusion behavior log data feature vector set into the illegal intrusion behavior recognition model, the recognized illegal intrusion behavior category is output. The sequence generation module respectively constructs the time-space sequence of this category of illegal intrusion behavior based on the log data feature vectors corresponding to the recognized illegal intrusion behavior category and outputs it to the illegal intrusion behavior prediction model based on the long short-term memory network. The prediction results obtained by the illegal intrusion behavior prediction model based on the long short-term memory network include the predicted time and predicted location of the occurrence of the cloud MES illegal intrusion behavior. Model training module: After training the cloud MES illegal intrusion prediction model with the obtained training data set, obtain the trained cloud MES illegal intrusion prediction model. Prediction module: From the log data of the cloud MES illegal intrusion behavior to be predicted, obtain the cloud MES illegal intrusion behavior log data feature vector set to be predicted, and obtain the predicted time and predicted location of the occurrence of the illegal intrusion behavior through the trained cloud MES illegal intrusion prediction model. Security defense module: According to the obtained predicted time and predicted location of the occurrence of the illegal intrusion behavior, as well as the corresponding cloud MES illegal intrusion behavior log data feature vector set, call the cloud security defense mechanism to achieve cloud MES illegal intrusion predictive security defense.

[0013] The beneficial effects of the present invention are as follows: Compared with the existing illegal intrusion security defense methods, the cloud MES illegal intrusion predictive security defense method and system of the present invention can effectively predict possible illegal intrusions in advance, can predict the time and location of various possible future illegal intrusions, change the passive defense during and after the event into active defense before the event, can improve the security defense ability, and can further ensure the security of the cyberspace. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 is a schematic flow chart of the cloud MES illegal intrusion predictive security defense method according to an embodiment of the present invention; Figure 2 is a schematic explanatory diagram for labeling the illegal intrusion behavior category of the MES illegal intrusion log data feature vector data set in the embodiment; Figure 3 is a schematic explanatory diagram of the cloud MES illegal intrusion prediction model in the embodiment; Figure 4 is a schematic explanatory diagram of the recognition model of the II-BRes2Net network in the embodiment; Figure 5 is a schematic explanatory diagram of the illegal intrusion behavior prediction model based on the long short-term memory network in the embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0015] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0016] The embodiment provides a cloud MES illegal intrusion predictive security defense method, as Figure 1 , including the following steps, S1. Obtain the log data of various types of cloud MES illegal intrusion behaviors, construct a cloud MES illegal intrusion behavior log data feature vector set, and after performing illegal intrusion behavior category labeling, obtain labeled data.

[0017] In step S1, the cloud MES illegal intrusion behavior log data feature vector set B i = {network protocol type vector npType, network connection feature vector NCFV, network connection traffic feature vector NCTFV, network dynamic behavior feature vector NDBFV, network connection traffic host feature vector hNCTFV, attacker behavior mode feature vector BMTraitV, illegal intrusion behavior category feature vector BTTraitV, binary feature vector BiTraitV, service feature vector SerTraitV}, where: The network protocol type vector npType (Transmission Control Protocol TCP, User Datagram Protocol UDP, Internet Control Message Protocol ICMP); Network Connection Feature Vector NCFV(source IP address sIPAddress, destination IP address dIPAddress, source port sPort, destination port dPort, protocol type pType); Network Connection Traffic Feature Vector NCTFV(connection duration Duration, connection start time Start_time, connection end time End_time, number of packets sent sNum_pkts, number of packets transmitted tNum_pkts, number of packets with the source address as the starting point Start_Num_pkts, number of packets with the destination address as the ending point End_Num_pkts, number of bytes sent sNum_bytes, number of bytes received rNum_bytes, error status eState); Network Dynamic Behavior Feature Vector NDBFV(number of logins L_nTimes, number of connections of the same type nConect, number of successful logins sL_nTimes, number of failed logins fL_nTimes, number of host changes Hchange_nTimes); Network Connection Traffic Host Feature Vector hNCTFV(number of hosts hCount, number of different destination hosts hSrv_count, different service quantity sDiff_srv_rate, number of connections with the same host before hSame_srv_rate, number of connections on the same service before hSrv_serror_rate, number of connections with a REJ error, i.e., the number of connections with a rejection error dst_host_srv_rerror_rate); Attacker Behavior Pattern Feature Vector BMTraitV(Denial of Service attack DOS, Probe, Remote to Local attack R2L, User to Root attack U2R); Illegally invaded behavior category feature vector BTTraitV (Normal (non - attack), Buffer_overflow attack, loadmodule attack to create root privilege, Perl script attack, Neptune development board file reading vulnerability attack, Smurf attack to exhaust bandwidth by sending a large number of IP packets, guess_passwd attack to guess passwords, Pod attack to send a large number of malformed ping packets, Teardrop attack to send a large number of oversized and misaligned IP fragments, Portsweep attack for port scanning, Ipsweep attack for IP scanning, Land attack with spoofed data packets having the same source and destination addresses, ftp_write attack for anonymous ftp, Back attack for reverse denial of service, imap port privilege attack, Satan attack for network probing, Phf attack for CGI script web server attack, Nmap attack for TCP connection SYN packet attack, Multihop attack for multi - step activities, Warezmaster attack for anonymous ftp upload, Warezclient attack for anonymous ftp publishing, Spy attack for multi - day scenarios, Rootkit attack for hidden trojans); Binary feature vector BiTraitV (TCP flag TCP_Flag); Service feature vector SerTraitV (Connected service type csType).

[0018] A specific example of illegally invaded behavior in cloud MES: The feature vector B1 of an attack behavior = {npType, NCFV, NCTFV, NDBFV, hNCTFV, BMTraitV, BTTraitV, BiTraitV, SerTraitV}, and the values are: npType = {TCP}, NCFV = {210.28.176.7, 10.255.21.208, 80, 9000, TCP}, NCTFV = {6790s, 2024 - 12 - 12 04:47:20, 2024 - 12 - 12 06:40:30, 2100876, 2000876, 2100876, 5100876, 38912 bytes, 58912 bytes, 1}, NDBFV = {20, 50, 2, 18, 9}, hNCTFV = {10, 5, 50, 1000, 100, 5}, BMTraitV = {DOS}, BTTraitV = {Neptune, Smurf, guess_passwd}, BiTraitV = {PSH}, SerTraitV = {TCP}.

[0019] Some labeled data such as Figure 2As shown in the figure. When annotating, the <input, output> tag pair is <{npType, NCFV, NCTFV, NDBFV, hNCTFV, BMTraitV, BiTraitV, SerTraitV}, {BTTraitV}>. All the annotated datasets constitute the training dataset for model training.

[0020] S2. Construct a cloud MES illegal intrusion prediction model, as Figure 3 shown. The cloud MES illegal intrusion prediction model includes an illegal intrusion behavior recognition model, a sequence generation module, and an illegal intrusion behavior prediction model based on a long short-term memory network. After inputting the cloud MES illegal intrusion behavior log data feature vector set into the illegal intrusion behavior recognition model, the recognized illegal intrusion behavior categories are output. The sequence generation module constructs the time-space sequence of the illegal intrusion behavior based on the log data feature vectors corresponding to the recognized illegal intrusion behavior categories and outputs it to the illegal intrusion behavior prediction model based on the long short-term memory network. The prediction results obtained by the illegal intrusion behavior prediction model based on the long short-term memory network include the predicted time and predicted location of the occurrence of the cloud MES illegal intrusion behavior.

[0021] In step S2, the illegal intrusion behavior recognition model adopts a recognition model based on the II-BRes2Net network. The recognition model based on the II-BRes2Net network includes a first input layer, a multi-scale backbone network Res2Net, a pyramid feature network FPN, a region proposal network RPN, a region of interest alignment layer RoIAlign, a first fully connected layer, and a first output layer, as Figure 4 : First input layer: Used to input the cloud MES illegal intrusion behavior log data feature vector set into the multi-scale backbone network Res2Net; Multi-scale backbone network Res2Net: Conducts preliminary recognition on the input cloud MES illegal intrusion behavior log data feature vector set to obtain preliminary cloud MES illegal intrusion behavior characteristics; Pyramid feature network FPN: Maps the preliminary cloud MES illegal intrusion behavior characteristics to the cloud MES illegal intrusion behavior log data, takes the center point of this data area as the anchor point to obtain the regional anchor reference box anchor, and applies the predicted offset to the reference box anchor to obtain the predicted candidate object localization box. At the same time, the intersection over union IoU threshold is obtained; Region proposal network RPN: After adjusting the predicted candidate object localization box, outputs it to the region of interest alignment layer RoIAlign; Region of interest alignment layer RoIAlign: Combines the intersection over union IoU threshold for normalization. After obtaining the normalized cloud MES illegal intrusion behavior feature localization box, it outputs to the fully connected layer; The first fully connected layer: classifies and identifies the characteristics of illegal intrusion behaviors in cloud MES to obtain illegal intrusion behaviors in cloud MES; The first output layer: is used to output the categories of illegal intrusion behaviors in cloud MES obtained by the fully connected layer.

[0022] In the illegal intrusion behavior recognition model, for illegal intrusion behaviors, an identification model of the residual deep learning network of illegal intrusion behaviors, namely the II-BRes2Net network, is constructed; and based on the labeled data of the feature vectors of the log data of different illegal intrusion behaviors, the identification model based on the II-BRes2Net network is trained. In the identification model based on the II-BRes2Net network, considering the heterogeneous characteristics of the log data of illegal intrusion behaviors in cloud MES, the multi-scale backbone network Res2Net is used as the backbone network; then the Pyramid Feature Network FPN and the Region Proposal Network RPN are used to improve the ability to detect heterogeneous behavior data; furthermore, combined with different IoU (Intersection over Union) thresholds, the Region of Interest Align layer RoIAlign is used for normalization; finally, classification is completed by the fully connected layer FC, and the Soft NMS (Non-Maximum Suppression algorithm) is adopted at the backend of the fully connected layer FC to improve the recognition accuracy of illegal intrusion behavior categories. In a specific example of the embodiment, the category of this illegal intrusion behavior is the Denial of Service attack DOS.

[0023] In step S2, in the sequence generation module, a time-space sequence {T j , P j |B i} of this category of illegal intrusion behavior is constructed, where T jDenote the duration since the last occurrence when the \(i\)-th type of illegal intrusion behavior \(B_i\) appears for the \(j\)-th time as \(T_j\), and \(P_j\) represents the location where the \(i\)-th type of illegal intrusion behavior \(B_i\) appears for the \(j\)-th time, that is, the IP address value. In a specific example of the embodiment, \(T_1 = 6790s\), \(P_1 = 10.255.21.208\), \(B_1=\{npType, NCFV, NCTFV, NDBFV, hNCTFV, BMTraitV, BTTraitV, BiTraitV, SerTraitV\}\), where \(npType = \{TCP\}\), \(NCFV=\{210.28.176.7, 10.255.21.208, 80, 9000, TCP\}\), \(NCTFV=\{6790s, 2024 - 12 - 12\ 04:47:20, 2024 - 12 - 12\ 06:40:30, 2100876, 2000876, 2100876、5100876、38912\ bytes, 58912\ bytes, 1\}\), \(NDBFV=\{20, 50, 2, 18, 9\}\), \(hNCTFV=\{10, 5, 50, 1000, 100, 5\}\), \(BMTraitV = \{DOS\}\), \(BTTraitV=\{Neptune, Smurf, guess\_passwd\}\), \(BiTraitV=\{PSH\}\), \(SerTraitV=\{TCP\}\).

[0024] In step S2, the illegal intrusion behavior prediction model based on the long short - term memory network includes a second input layer, a first hidden layer, a second hidden layer, a second fully - connected layer, and a second output layer, as Figure 5 : Second input layer: used to input the time - space sequence of illegal intrusion behaviors into the first hidden layer; First hidden layer: used to make a preliminary prediction on the input feature vector set of cloud MES illegal intrusion behavior logs, and obtain the preliminary prediction time and prediction location of the occurrence of cloud MES illegal intrusion behaviors at each node; Second hidden layer: The second hidden layer has the same network structure as the first hidden layer, and is used to optimize and fine - tune the preliminary prediction time and location of the occurrence of cloud MES illegal intrusion behaviors at each node, and obtain the prediction time and prediction location of the occurrence of cloud MES illegal intrusion behaviors at each node; Second fully - connected layer: merge the prediction time and prediction location of the occurrence of cloud MES illegal intrusion behaviors at each node to obtain the final prediction time and prediction location of the occurrence of cloud MES illegal intrusion behaviors; Second output layer: used to output the prediction result, that is, the final prediction time and prediction location of the occurrence of cloud MES illegal intrusion behaviors obtained by the fully - connected layer.

[0025] In the illegal intrusion behavior prediction model based on the long short-term memory network, considering the characteristics of the unstable appearance time and location of the illegal intrusion behavior in cloud MES, a network hidden layer structure is adopted to improve the prediction accuracy of the appearance time and location of the illegal intrusion behavior.

[0026] S3. After training the cloud MES illegal intrusion prediction model with the training data set obtained in step S1, a trained cloud MES illegal intrusion prediction model is obtained.

[0027] S4. From the log data of the cloud MES illegal intrusion behavior to be predicted, a feature vector set of the log data of the cloud MES illegal intrusion behavior to be predicted is obtained, and the predicted time and predicted location of the occurrence of the illegal intrusion behavior are obtained through the trained cloud MES illegal intrusion prediction model.

[0028] In step S4, in the specific example of the embodiment, the predicted output result data: <10.114.232.40; 2024-12-12 08:53:45,7995s>, the predicted duration of the next occurrence is 7995s, that is, the next illegal intrusion behavior time is 2024-12-12 08:53:45, and the location where the next illegal intrusion behavior occurs is 10.114.232.40.

[0029] S5. According to the predicted time and predicted location of the occurrence of the illegal intrusion behavior obtained in step S4, and the corresponding feature vector set of the log data of the cloud MES illegal intrusion behavior, the cloud security defense mechanism is called to implement predictive security defense against cloud MES illegal intrusion.

[0030] In step S5, from the possible occurrence time (duration) and location (IP address) of the i-th type of illegal intrusion behavior Bi at the (j + 1)-th time, and the feature vector of the i-th type of illegal intrusion behavior Bi, the prediction result is connected to the existing security defense system to implement predictive security defense against cloud MES illegal intrusion. In the specific example of the embodiment, on the cloud MES platform, the existing security defense system selects the 360 security protection system to implement predictive security defense against cloud MES illegal intrusion.

[0031] Compared with the existing illegal intrusion security defense methods, this cloud MES illegal intrusion predictive security defense method and system can effectively predict possible illegal intrusions in advance, can predict the time and location of various possible future illegal intrusions, change the passive defense during and after the event into active defense before the event, can improve the security defense ability, and can further ensure the security of the cyber space.

[0032] The embodiment also provides a cloud MES illegal intrusion predictive security defense system adopting the method described in any one of the above, including a data annotation module, a model construction module, a model training module, a prediction module, and a security defense module. Data annotation module: Obtain log data of various types of cloud MES illegal intrusion behaviors, construct a feature vector set of cloud MES illegal intrusion behavior log data, and after performing illegal intrusion behavior category annotation, obtain annotated data and a training data set. Model construction module: Construct a cloud MES illegal intrusion prediction model. The cloud MES illegal intrusion prediction model includes an illegal intrusion behavior recognition model, a sequence generation module, and an illegal intrusion behavior prediction model based on a long short-term memory network. After inputting the feature vector set of cloud MES illegal intrusion behavior log data into the illegal intrusion behavior recognition model, the recognized illegal intrusion behavior category is output. The sequence generation module constructs a time-space sequence of the illegal intrusion behavior of this category based on the log data feature vectors corresponding to the recognized illegal intrusion behavior category and outputs it to the illegal intrusion behavior prediction model based on the long short-term memory network. The prediction result obtained by the illegal intrusion behavior prediction model based on the long short-term memory network includes the predicted time and predicted location of the occurrence of the cloud MES illegal intrusion behavior. Model training module: After training the cloud MES illegal intrusion prediction model with the obtained training data set, obtain the trained cloud MES illegal intrusion prediction model. Prediction module: From the log data of the cloud MES illegal intrusion behavior to be predicted, obtain the feature vector set of the cloud MES illegal intrusion behavior log data to be predicted, and obtain the predicted time and predicted location of the occurrence of the illegal intrusion behavior through the trained cloud MES illegal intrusion prediction model. Security defense module: According to the obtained predicted time and predicted location of the occurrence of the illegal intrusion behavior, and the feature vector set of the cloud MES illegal intrusion behavior log data, call the cloud security defense mechanism to implement cloud MES illegal intrusion predictive security defense.

[0033] The predictive security defense method and system for illegal intrusion of cloud MES obtain the log data of illegal intrusion behavior of cloud MES, determine the illegal intrusion behavior, and obtain the labeled data of the log data feature vectors of various types of illegal intrusion behaviors. For each type of illegal intrusion behavior, an identification model of the II-BRes2Net network is constructed; a long short-term memory B_LSTM network prediction model is constructed; the log data of the illegal intrusion behavior to be identified is input into the identification model of the II-BRes2Net network to obtain the identified illegal intrusion behavior; the identified illegal intrusion behavior data is input into the B_LSTM network prediction model to obtain the predicted time and location of the occurrence of the illegal intrusion behavior; the predicted intrusion behavior characteristics, time and location are connected to the security protection system in the cloud MES to realize the predictive security defense against illegal intrusion of the cloud MES. The present invention adopts proactive defense in advance, can effectively predict the time and location of various possible future illegal intrusions, and can more effectively ensure the security of the cloud MES system.

[0034] The detailed description of the embodiments is only a specific description of the feasible implementation manners of the present invention, and is not intended to limit the protection scope of the present invention. Any equivalent implementation manners or changes made without departing from the technical spirit of the present invention should be included in the protection scope of the present invention.

Claims

1. A cloud MES illegal intrusion predictive security defense method, characterized by: The following steps are included: S1. Obtain log data of various categories of illegal intrusion behaviors of cloud MES, construct a feature vector set of illegal intrusion behavior log data of cloud MES, label the illegal intrusion behavior categories, obtain labeled data, and obtain a training data set; S2. Construct a cloud MES illegal intrusion prediction model. The cloud MES illegal intrusion prediction model includes an illegal intrusion behavior recognition model, a sequence generation module, and an illegal intrusion behavior prediction model based on a long short-term memory network. After the cloud MES illegal intrusion behavior log data feature vector set is input into the illegal intrusion behavior recognition model, the identified illegal intrusion behavior category is output. The sequence generation module constructs a time-space sequence of illegal intrusion behavior based on the log data feature vector corresponding to the identified illegal intrusion behavior category, and outputs it to the illegal intrusion behavior prediction model based on the long short-term memory network. The illegal intrusion behavior prediction model based on the long short-term memory network obtains a prediction result including the predicted time and predicted location of the cloud MES illegal intrusion behavior. S3, after training the cloud MES illegal intrusion prediction model with the training data set obtained in step S1, a trained cloud MES illegal intrusion prediction model is obtained; S4. Obtain a feature vector set of the cloud MES illegal intrusion behavior log data to be predicted from the log data of the cloud MES illegal intrusion behavior to be predicted, and obtain the predicted time and predicted location of the illegal intrusion behavior through the trained cloud MES illegal intrusion prediction model; S5. Based on the predicted time and predicted location of the illegal intrusion behavior obtained in step S4, and the corresponding cloud MES illegal intrusion behavior log data feature vector set, call the cloud security defense mechanism to implement cloud MES illegal intrusion predictive security defense.

2. The cloud MES illegal intrusion predictive security defense method according to claim 1, characterized in that: In step S2, the illegal intrusion behavior recognition model adopts a recognition model based on the II-BRes2Net network. The recognition model based on the II-BRes2Net network includes a first input layer, a multi-scale backbone network Res2Net, a pyramid feature network FPN, a region candidate network RPN, a region of interest alignment layer RoIAlign, a first fully connected layer and a first output layer. The first input layer: used to input the feature vector set of cloud MES illegal intrusion behavior log data into the multi-scale backbone network Res2Net; Multi-scale backbone network Res2Net: performs preliminary recognition on the input cloud MES illegal intrusion behavior log data feature vector set to obtain preliminary cloud MES illegal intrusion behavior features; Pyramid feature network FPN: Map the preliminary cloud MES illegal intrusion behavior features to the cloud MES illegal intrusion behavior log data, take the center point of the cloud MES illegal intrusion behavior log data area as the anchor point, obtain the regional anchor reference frame anchor, and apply the predicted offset to the reference frame anchor to obtain the predicted candidate object positioning frame, and at the same time obtain the intersection over union (IoU) threshold; Region Proposal Network (RPN): After adjusting the predicted candidate object positioning box, it is output to the region of interest alignment layer (RoIAlign). Region of Interest Alignment Layer RoIAlign: Combined with the intersection over union (IoU) threshold, normalization is performed to obtain the normalized cloud MES illegal intrusion behavior feature positioning frame, which is then output to the fully connected layer; The first fully connected layer: classifies and identifies the characteristics of illegal intrusion behavior of cloud MES, and obtains illegal intrusion behavior of cloud MES; The first output layer is used to output the cloud MES illegal intrusion behavior category obtained by the fully connected layer.

3. The cloud MES illegal intrusion predictive security defense method according to claim 1, characterized in that: In step S2, in the sequence generation module, the time-space sequence { T j , P j |B i }, where T j It represents the time between the jth occurrence of the i-th illegal intrusion behavior Bi and the last occurrence, and Pj represents the location where the i-th illegal intrusion behavior Bi appears the jth time, that is, the IP address value.

4. The cloud MES illegal intrusion predictive security defense method according to any one of claims 1 to 3, characterized in that: In step S6, the illegal intrusion behavior prediction model based on the long short-term memory network includes a second input layer, a first hidden layer, a second hidden layer, a second fully connected layer and a second output layer. The second input layer is used to input the time-space sequence of illegal intrusion behavior into the first hidden layer; The first hidden layer is used to make a preliminary prediction of the input cloud MES illegal intrusion behavior log data feature vector set, and obtain the preliminary predicted time and predicted location of the cloud MES illegal intrusion behavior of each node; Second hidden layer: The second hidden layer has the same network structure as the first hidden layer, and is used to optimize and fine-tune the initial predicted time and location of the cloud MES illegal intrusion behavior of each node, and obtain the predicted time and predicted location of the cloud MES illegal intrusion behavior of each node; The second fully connected layer: merges the predicted time and predicted location of the illegal intrusion behavior of each node cloud MES to obtain the final predicted time and predicted location of the illegal intrusion behavior of the cloud MES; The second output layer is used to output the prediction results, that is, the predicted time and predicted location of the final cloud MES illegal intrusion behavior obtained by the fully connected layer.

5. The cloud MES illegal intrusion predictive security defense method according to any one of claims 1 to 3, characterized in that: In step S1, the cloud MES illegal intrusion behavior log data feature vector set B i ={network protocol type vector npType, network connection feature vector NCFV, network connection traffic feature vector NCTFV, network dynamic behavior feature vector NDBFV, network connection traffic host feature vector hNCTFV, attacker behavior mode feature vector BMTraitV, illegal intrusion behavior category feature vector BTTraitV, binary feature vector BiTraitV, service feature vector SerTraitV}.

6. A cloud MES illegal intrusion predictive security defense system using the method described in any one of claims 1 to 4, characterized in that: It includes data annotation module, model building module, model training module, prediction module and security defense module. Data labeling module: obtains log data of various categories of cloud MES illegal intrusion behaviors, constructs a feature vector set of cloud MES illegal intrusion behavior log data, labels illegal intrusion behavior categories, obtains labeled data, and obtains a training data set; Model construction module: constructs a cloud MES illegal intrusion prediction model, which includes an illegal intrusion behavior recognition model, a sequence generation module, and an illegal intrusion behavior prediction model based on a long short-term memory network. After the cloud MES illegal intrusion behavior log data feature vector set is input into the illegal intrusion behavior recognition model, the identified illegal intrusion behavior category is output. The sequence generation module constructs the time-space sequence of the illegal intrusion behavior of the category according to the log data feature vector corresponding to the identified illegal intrusion behavior category, and outputs it to the illegal intrusion behavior prediction model based on the long short-term memory network. The illegal intrusion behavior prediction model based on the long short-term memory network obtains the prediction results including the predicted time and predicted location of the cloud MES illegal intrusion behavior. Model training module: After training the cloud MES illegal intrusion prediction model with the obtained training data set, a trained cloud MES illegal intrusion prediction model is obtained; Prediction module: obtains the log data feature vector set of the cloud MES illegal intrusion behavior to be predicted from the log data of the cloud MES illegal intrusion behavior to be predicted, and obtains the predicted time and predicted location of the illegal intrusion behavior through the trained cloud MES illegal intrusion prediction model; Security defense module: Based on the predicted time and location of illegal intrusion behavior and the corresponding cloud MES illegal intrusion behavior log data feature vector set, the cloud security defense mechanism is called to implement predictive security defense of cloud MES illegal intrusion.

Citation Information

Patent Citations

  • Network security intrusion prevention system

    CN116471031A

  • Network security defense system based on cloud computing

    CN116980185A

  • Intrusion tracking detection and interception clearing method and system for industrial Internet of Things

    CN117938453A

  • Active defense and attack method, system and equipment based on port sensing and medium

    CN118018328A