Illegal attack detection method based on cloud computing platform
By building and optimizing an illegal attack detection model on a cloud computing platform, the problem that weak performance devices cannot effectively identify illegal attacks is solved, and efficient illegal attack detection capabilities are achieved.
Patent Information
- Application Number
- CN202510291594.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, some platforms or devices have weak performance and cannot effectively identify illegal attacks or deploy powerful detection models, especially on cloud computing platforms.
By obtaining the historical network traffic feature sample set, an illegal attack detection model is built, and the model is optimized using an adaptive search algorithm. The optimized model is deployed on the cloud computing platform to detect real-time network traffic.
It effectively improves the accuracy and efficiency of illegal attack detection, so that devices with weak performance or devices without identification software can also achieve illegal attack detection.
Smart Images

Figure CN120200787A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of security technology, and particularly relates to an illegal attack detection method based on a cloud computing platform. Background Art
[0002] An illegal attack refers to an unauthorized act of damaging, stealing, or interfering with a computer system, network, or data through technical means. Common types include DDoS attacks, malware attacks, data breaches, etc. A DDoS attack paralyzes the target server through a large number of invalid requests; a malware attack steals information or controls devices by implanting viruses, Trojans, etc.; a data breach refers to the unauthorized external transmission of data. These attack methods are covert and complex, posing a serious threat to network security, and effective detection and defense measures need to be taken. With the rapid development of cloud computing technology, more and more enterprises and individuals are migrating their data and services to cloud computing platforms. However, cloud computing platforms are also faced with threats of various illegal attacks, such as DDoS attacks, malware attacks, data breaches, etc. With the development of communication technology, there are more and more various networked devices and systems, and some platforms or devices with weak processing performance cannot effectively identify illegal attacks and cannot deploy relatively powerful illegal attack detection models. Summary of the Invention
[0003] The present invention provides an illegal attack detection method based on a cloud computing platform to solve the problem that some platforms or devices in the prior art have weak performance and cannot effectively identify illegal attacks.
[0004] An illegal attack detection method based on a cloud computing platform includes: Obtaining a historical network traffic feature sample set; wherein, the historical network traffic feature sample set includes multiple pairs of historical network traffic features and illegal attack labels corresponding to the historical network traffic features; Constructing an illegal attack detection model, using the historical network traffic features and the illegal attack labels corresponding to the historical network traffic features as data support, and optimizing the illegal attack detection model by using an adaptive search algorithm to obtain an optimized illegal attack detection model; Deploying the optimized illegal attack detection model on the cloud computing platform, and during the data access process, scheduling the illegal attack detection model on the cloud computing platform to detect the real-time network traffic features to determine the illegal attack detection result; Feeding back the illegal attack detection result to the attack detection requester until the reception completion flag transmitted by the attack detection requester is received, and completing the illegal attack detection based on the cloud computing platform.
[0005] Further, the historical network traffic feature sample set is set as the CIC-IDS-2017 / 2018 dataset or the KDDCup-99 dataset.
[0006] Further, an illegal attack detection model is constructed, including: constructing an input layer, a first convolutional layer, a first pooling layer, a second convolutional layer, a second pooling layer, a fully connected layer, and an output layer that are sequentially connected.
[0007] Further, using the historical network traffic features and the corresponding illegal attack labels as data support, an adaptive search algorithm is used to optimize the illegal attack detection model to obtain an optimized illegal attack detection model, including: Initialize the model parameters of the illegal attack detection model and determine multiple different individuals; where each individual includes all the model parameters of the illegal attack detection model; Using the historical network traffic features and the corresponding illegal attack labels as data support, obtain the fitness value corresponding to each individual, and divide the individuals into leaders, developers, and followers according to the fitness value; For the leader, adopt an adaptive neighborhood search strategy to perform neighborhood search on the leader to determine the leader after neighborhood search; For the developer, adopt a collaborative development search strategy based on fitness decision-making to perform joint development search on the developer to determine the developer after joint development search; For the follower, adopt a double-follower strategy to perform a better region search on the follower to determine the follower after better region search; Judge whether the optimization end condition is met. If so, determine the optimal individual according to the leader after neighborhood search, the developer after joint development search, and the follower after better region search, and use the model parameters in the optimal individual as the final parameters of the illegal attack detection model to obtain an optimized illegal attack detection model. Otherwise, return to the fitness value acquisition step.
[0008] Further, using the historical network traffic features and the corresponding illegal attack labels as data support, obtain the fitness value corresponding to each individual, including: For any individual, apply the parameters in the individual to the illegal attack detection model, and then use the historical network traffic features as the input of the illegal attack detection model to obtain the actual output of the illegal attack detection model; Using the illegal attack label corresponding to the historical network traffic feature as the expected output, and determine the cross-entropy loss function value corresponding to the individual according to the actual output and the expected output of the illegal attack detection model; Add the cross-entropy loss function value corresponding to the individual to a preset constant term to obtain a numerical addition term, and take the reciprocal of the numerical addition term to obtain the fitness value corresponding to the individual.
[0009] Further, an adaptive neighborhood search strategy is adopted to perform neighborhood search on the leader to determine the leader after the neighborhood search, including: For any one leader, randomly match a leader with another leader to obtain the matching leader corresponding to the leader; Judge whether the fitness value of the leader is greater than the fitness value of its corresponding matching leader. If so, determine the neighborhood search factor according to the fitness value of the leader. Otherwise, directly determine the neighborhood search factor as 1; According to the neighborhood search factor, perform neighborhood search on the leader to determine that the leader after the neighborhood search is:
[0010]
[0011] Among them, represents the t th l leader in the th optimization process, , l = 1, 2,.., L, where L represents the total number of leaders, represents the neighborhood search factor, represents a random number generated by a Gaussian distribution with a mean of 0 and a variance of , represents the exponential function with the natural constant e as the base, represents the l th fitness value corresponding to the leader, represents the l th fitness value corresponding to the matching leader corresponding to the leader, represents a constant term and is set to 0.001.
[0012] Further, a collaborative development search is performed on the developers by adopting a collaborative development strategy of fitness decision-making to determine the developers after the collaborative development search, including: For any one developer, randomly match a leader with the developer to obtain a social learning individual; Match a developer with another developer with the closest Euclidean distance, and set the constraint condition that the fitness value of the matched other developer is greater than the fitness value of the developer to obtain a collaborative search individual; Determine the influence of the social learning individual on the developer to obtain the first influence factor as:
[0013] Among them, represents the first influence factor, represents the fitness value corresponding to the social learning individual, represents the fitness value corresponding to the optimal individual, that is, the maximum fitness value; represents the fitness value corresponding to the worst individual, that is, the minimum fitness value; e represents the natural constant, represents the Euclidean distance between the developer and its corresponding social learning individual; Determine the influence of the collaborative search individual on the developer, and obtain the second influence factor as:
[0014] Among them, represents the second influence factor, represents the fitness value of the collaborative search individual, represents the Euclidean distance between the developer and its corresponding collaborative search individual; According to the first influence factor, social learning individual, collaborative search individual and the second influence factor, conduct a joint development search for the developer, and determine the developer after the joint development search as:
[0015] Among them, represents the m-th developer in the t-th optimization process, m = 1, 2,.., M, and M represents the total number of developers, represents the developer after the joint development search , represents the first random number between (0, 1), represents the second random number between (0, 1), represents the developer corresponding social learning individual, represents the developer corresponding collaborative search individual.
[0016] Furthermore, adopt a double-following strategy to conduct a better region search for the followers, and determine the followers after the better region search, including: Generate a transfer factor as:
[0017] Among them, represents the transfer factor, represents the exponential function with the natural constant e as the base, and T represents the preset maximum number of optimizations; When the transfer factor TF is less than or equal to 0.5, a better region search is performed on the follower, and the follower after the better region search is determined as:
[0018]
[0019]
[0020]
[0021]
[0022]
[0023] where represents the nth follower in the t th optimization process, represents the follower after the better region search , n = 1, 2,.., N, where N represents the total number of followers, represents the third random number between (0, 1), represents the t +1th optimization process, the search step corresponding to the follower , represents the t +1th optimization process, the control factor corresponding to the follower , represents the developer randomly matched for the follower, represents the first normalized range adjustment factor, represents the second normalized range adjustment factor, represents the t +1th optimization process, the search ability corresponding to the nth developer, represents the t +1th optimization process, the search ability corresponding to the kth developer, represents the t +1th optimization process, the first search ability control factor corresponding to the nth developer, represents the t +1th optimization process, the second search ability control factor corresponding to the nth developer, represents the first search ability control factor corresponding to the random developer, represents the second search ability control factor corresponding to the random developer, represents the fourth random number between (0, 1), represents the tThe first search ability control factor corresponding to the nth developer during the nth optimization process represents t the maximum first search ability control factor during the nth optimization process, represents a fifth random number between (0, 1), represents t the second search ability control factor corresponding to the nth developer during the nth optimization process represents t the maximum second search ability control factor during the nth optimization process, represents a sixth random number between (0, 1); at the initial optimization moment, the first search ability control factor and the second search ability control factor corresponding to each developer are randomly generated between (0, 1); When the transfer factor TF is greater than 0.5, perform a better region search on the follower, and determine the follower after the better region search as:
[0024] wherein represents the optimal individual, represents a direction factor randomly being 1 or -1, represents a seventh random number between (0, 1).
[0025] Further, determine whether the optimization end condition is satisfied, including: determining whether the current optimization times reach the preset maximum optimization times. If so, it is determined that the optimization end condition is satisfied; otherwise, it is determined that the optimization end condition is not satisfied.
[0026] Further, it also includes: When the illegal attack detection result is an abnormal category, generate an illegal attack warning message and feedback the illegal attack warning message to the attack detection requester.
[0027] An illegal attack detection method based on a cloud computing platform provided by the present invention, using the historical network traffic characteristics and the corresponding illegal attack labels of the historical network traffic characteristics as data support, optimizing the illegal attack detection model by using an adaptive search algorithm to obtain an optimized illegal attack detection model, which can effectively improve the accuracy and efficiency of illegal attack detection. After determining the illegal attack detection result, feedback the illegal attack detection result to the attack detection requester until receiving the reception completion flag transmitted by the attack detection requester, and complete the illegal attack detection based on the cloud computing platform, so that devices with weak performance or devices without deployed recognition software can also implement illegal attack detection. Description of the Drawings
[0028] The accompanying drawings here are incorporated into and constitute a part of this specification, showing embodiments consistent with the present invention and, together with the specification, used to explain the principles of the present invention.
[0029] Figure 1 It is a flowchart of an illegal attack detection method based on a cloud computing platform provided for an embodiment of the present invention.
[0030] Through the above accompanying drawings, specific embodiments of the present invention have been shown, and there will be more detailed descriptions hereinafter. These drawings and written descriptions are not intended to limit the scope of the inventive concept in any way, but to illustrate the concept of the present invention to those skilled in the art by referring to specific embodiments. Detailed Embodiments
[0031] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.
[0032] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0033] As Figure 1 shown, an embodiment of the present invention provides an illegal attack detection method based on a cloud computing platform, including: S1. Obtain a historical network traffic feature sample set; wherein, the historical network traffic feature sample set includes multiple pairs of historical network traffic features and illegal attack labels corresponding to the historical network traffic features; In an embodiment of the present invention, the historical network traffic feature sample set is set as the CIC-IDS-2017 / 2018 dataset or the KDDCup-99 dataset.
[0034] However, it is worth noting that the historical network traffic feature sample set can also be set as other existing datasets or directly input by staff to achieve customized tasks.
[0035] S2. Build an illegal attack detection model, and use the historical network traffic features and the illegal attack labels corresponding to the historical network traffic features as data support, and optimize the illegal attack detection model using an adaptive search algorithm to obtain an optimized illegal attack detection model; The illegal attack detection model can be set as deep learning models such as a convolutional neural network, a bidirectional long short-term memory network, a BP neural network, etc. After training these deep learning models, an optimized illegal attack detection model can be obtained.
[0036] In the process of optimizing deep learning models in the prior art, problems such as insufficient training and poor training accuracy are likely to occur, resulting in a weak ability to detect illegal attacks ultimately. Therefore, an embodiment of the present invention provides an adaptive search algorithm to optimize the illegal attack detection model, thereby improving the training effect and the accuracy of illegal attack detection.
[0037] S3. Deploy the optimized illegal attack detection model on the cloud computing platform, and during the data access process, schedule the illegal attack detection model on the cloud computing platform to detect the real-time network traffic characteristics, and determine the illegal attack detection result; The real-time network traffic characteristics here can be the characteristics on some other devices (i.e., the characteristics on the attack detection requester), or the characteristics on the cloud computing platform (i.e., the attack detection requester is the cloud platform itself), so as to utilize the current low-latency communication network to enable various devices or platforms to have the ability to identify illegal attacks.
[0038] S4. Feed back the illegal attack detection result to the attack detection requester until the reception completion flag transmitted by the attack detection requester is received, and complete the illegal attack detection based on the cloud computing platform.
[0039] After the attack detection requester receives the illegal attack detection result, it should return the reception completion flag, thereby ending a cycle of detection and starting the next detection cycle.
[0040] In the embodiment of the present invention, constructing an illegal attack detection model includes: constructing an input layer, a first convolutional layer, a first pooling layer, a second convolutional layer, a second pooling layer, a fully connected layer, and an output layer that are sequentially connected.
[0041] The above illegal attack detection model is only the preferred implementation manner of the embodiment of the present invention, and other deep learning models can also be used to construct the illegal attack detection model. However, it is worth noting that the input forms of different deep learning models may be different, and the input needs to be converted into the corresponding input form.
[0042] In the embodiment of the present invention, using the historical network traffic characteristics and the illegal attack labels corresponding to the historical network traffic characteristics as data support, an adaptive search algorithm is used to optimize the illegal attack detection model, and the optimized illegal attack detection model is obtained, including: Initialize the model parameters of the illegal attack detection model to determine multiple different individuals; among them, each individual contains all the model parameters of the illegal attack detection model; For example, the model parameters of the illegal attack detection model generally have upper and lower limits, and can be randomly initialized within the upper and lower limits, so as to achieve initialization.
[0043] Using the historical network traffic characteristics and the illegal attack labels corresponding to the historical network traffic characteristics as data support, obtain the fitness value corresponding to each individual, and classify the individuals into leaders, developers, and followers according to the fitness value; All individuals can be sorted in descending order of fitness value and divided into leaders, developers, and followers according to a ratio of 1:7:2. The fitness value of any leader is greater than the fitness values of all developers, and the fitness value of any developer is greater than the fitness values of all followers. To ensure integer division, the number of individuals generated initially can be an integer multiple of 10.
[0044] For the leaders, adopt an adaptive neighborhood search strategy to perform neighborhood search on the leaders to determine the leaders after neighborhood search; For the developers, adopt a collaborative development search strategy based on fitness decision-making to perform joint development search on the developers to determine the developers after joint development search; For the followers, adopt a double-follower strategy to perform better region search on the followers to determine the followers after better region search; Judge whether the optimization end condition is met. If so, determine the optimal individual according to the leaders after neighborhood search, the developers after joint development search, and the followers after better region search, and use the model parameters in the optimal individual as the final parameters of the illegal attack detection model to obtain the optimized illegal attack detection model. Otherwise, return to the fitness value acquisition step.
[0045] Optionally, out-of-bounds processing can also be performed on all individuals at the end of each round of optimization to ensure that each parameter is between its corresponding upper and lower limits.
[0046] In the embodiment of the present invention, using the historical network traffic characteristics and the illegal attack labels corresponding to the historical network traffic characteristics as data support, obtaining the fitness value corresponding to each individual includes: For any individual, apply the parameters in the individual to the illegal attack detection model, and then use the historical network traffic characteristics as the input of the illegal attack detection model to obtain the actual output of the illegal attack detection model; Using the illegal attack label corresponding to the historical network traffic characteristics as the expected output, and determining the cross-entropy loss function value corresponding to the individual according to the actual output and the expected output of the illegal attack detection model; Add the cross-entropy loss function value corresponding to the individual to a preset constant term (such as 0.01) to obtain a numerical addition term, and take the reciprocal of the numerical addition term to obtain the fitness value corresponding to the individual.
[0047] In the embodiment of the present invention, an adaptive neighborhood search strategy is adopted to perform neighborhood search on the leader to determine the leader after neighborhood search, including: For any leader, randomly match another leader to the leader to obtain the matching leader corresponding to the leader; Judge whether the fitness value of the leader is greater than the fitness value of its corresponding matching leader. If so, determine the neighborhood search factor according to the fitness value of the leader, otherwise directly determine the neighborhood search factor as 1; According to the neighborhood search factor, perform neighborhood search on the leader, and determine that the leader after neighborhood search is:
[0048]
[0049] Wherein, represents the t th optimization process, the l th leader, represents the leader after neighborhood search , l = 1, 2,.., L, where L represents the total number of leaders, represents the neighborhood search factor, represents a random number generated by a Gaussian distribution with a mean of 0 and a variance of , represents an exponential function with the natural constant e as the base, represents the l th fitness value corresponding to the leader, represents the l th fitness value corresponding to the matching leader corresponding to the leader, represents a constant term and is set to 0.001.
[0050] The adaptive neighborhood search strategy provided by the embodiment of the present invention can enable the leader to search in its respective area, ensure the search efficiency of the algorithm, and at the same time search in a better area, which can also improve the ability to find a better solution.
[0051] In the embodiment of the present invention, a collaborative development strategy based on fitness decision is adopted to perform joint development search on developers to determine the developers after joint development search, including: For any developer, randomly match a leader to the developer to obtain a social learning individual; Match a developer with the other developer with the closest Euclidean distance, and set the constraint condition that the fitness value of the matched other developer is greater than the fitness value of the developer to obtain a collaborative search individual; Determine the influence of social learning individuals on developers, and obtain the first influence factor as:
[0052] wherein, represents the first influence factor, represents the fitness value corresponding to the social learning individual, represents the fitness value corresponding to the optimal individual, that is, the maximum fitness value; represents the fitness value corresponding to the worst individual, that is, the minimum fitness value; e represents the natural constant, represents the Euclidean distance between the developer and its corresponding social learning individual; Determine the influence of collaborative search individuals on developers, and obtain the second influence factor as:
[0053] wherein, represents the second influence factor, represents the fitness value of the collaborative search individual, represents the Euclidean distance between the developer and its corresponding collaborative search individual; According to the first influence factor, social learning individuals, collaborative search individuals, and the second influence factor, perform joint development search on developers, and determine the developer after joint development search as:
[0054] wherein, represents the m-th developer in the t-th optimization process, m = 1, 2,.., M, and M represents the total number of developers, represents the developer after joint development search , represents the first random number between (0, 1), represents the second random number between (0, 1), represents the developer corresponding social learning individual, represents the developer corresponding collaborative search individual.
[0055] The collaborative development strategy for fitness decision provided by the embodiments of the present invention enables developers to perform local area development and collaborative search, and can effectively improve the ability of the algorithm to search for the global optimal solution.
[0056] In the embodiments of the present invention, a double following strategy is adopted to perform a better region search on the followers, and determine the followers after the better region search, including: Generate a transfer factor as:
[0057] Among them, represents the transfer factor, represents the exponential function with the natural constant e as the base, and T represents the preset maximum number of optimizations; When the transfer factor TF is less than or equal to 0.5, a better region search is performed on the follower, and the follower after the better region search is determined as:
[0058]
[0059]
[0060]
[0061]
[0062]
[0063] Among them, represents the t nth follower in the kth optimization process, represents the follower after the better region search , where n = 1, 2,.., N, and N represents the total number of followers, represents the third random number between (0, 1), t represents the search step size corresponding to the follower in the (k + 1)th optimization process, t represents the control factor corresponding to the follower in the (k + 1)th optimization process, represents the developer randomly matched for the follower, represents the first normalized range adjustment factor, represents the second normalized range adjustment factor, t represents the search ability corresponding to the nth developer in the (k + 1)th optimization process, t represents the search ability corresponding to the kth developer in the (k + 1)th optimization process, t represents the first search ability control factor corresponding to the nth developer in the (k + 1)th optimization process, t represents the second search ability control factor corresponding to the nth developer in the (k + 1)th optimization process, Represents the second search ability control factor corresponding to the random developer, Represents the fourth random number between (0, 1), Represents the t First search ability control factor corresponding to the nth developer during the Represents the t Maximum first search ability control factor during the Represents the fifth random number between (0, 1), Represents the t Second search ability control factor corresponding to the nth developer during the Represents the t Maximum second search ability control factor during the Represents the sixth random number between (0, 1); at the initial optimization moment, the first search ability control factor and the second search ability control factor corresponding to each developer are randomly generated between (0, 1); When the transfer factor TF is greater than 0.5, then perform a more optimal region search on the follower, and determine the follower after the more optimal region search as:
[0064] Among them, Represents the optimal individual, Represents the direction factor that is randomly 1 or -1, Represents the seventh random number between (0, 1).
[0065] The dual-follower strategy provided by the embodiments of the present invention can ensure the diversity of the algorithm in the early stage of the algorithm, improve the global search ability, and in the later stage of the algorithm, it is more inclined to search the area near the optimal position, which can effectively improve the convergence accuracy and ensure the convergence of the algorithm.
[0066] The algorithm provided by the embodiments of the present invention can achieve the search of more regions, and can effectively maintain the diversity during the search process, avoid the algorithm falling into local optimality, thereby improving the parameter optimization effect and ultimately improving the illegal attack recognition ability.
[0067] In the embodiments of the present invention, determining whether the optimization end condition is satisfied includes: determining whether the current optimization times reach the preset maximum optimization times. If so, it is determined that the optimization end condition is satisfied; otherwise, it is determined that the optimization end condition is not satisfied.
[0068] In the embodiments of the present invention, it further includes: When the illegal attack detection result is an abnormal category, an illegal attack warning message is generated and the illegal attack warning message is fed back to the attack detection requester.
[0069] An illegal attack detection method based on a cloud computing platform provided by the present invention uses the historical network traffic characteristics and the corresponding illegal attack labels of the historical network traffic characteristics as data support, and optimizes the illegal attack detection model by using an adaptive search algorithm to obtain an optimized illegal attack detection model, which can effectively improve the accuracy and efficiency of illegal attack detection. After determining the illegal attack detection result, the illegal attack detection result is fed back to the attack detection requester until the reception completion flag transmitted by the attack detection requester is received, and the illegal attack detection based on the cloud computing platform is completed, so that devices with weak performance or devices without deployed identification software can also achieve illegal attack detection.
[0070] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present invention. The present invention is intended to cover any variations, uses, or adaptations of the present invention, which follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed by the present invention. It should be understood that the present invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A method for detecting illegal attacks based on a cloud computing platform, characterized in that: include: Obtain a historical network traffic feature sample set; wherein the historical network traffic feature sample set includes multiple pairs of historical network traffic features and illegal attack labels corresponding to the historical network traffic features; An illegal attack detection model is constructed, and the illegal attack labels corresponding to the historical network traffic characteristics and the historical network traffic characteristics are used as data support. The illegal attack detection model is optimized by using an adaptive search algorithm to obtain the optimized illegal attack detection model. The optimized illegal attack detection model is deployed on the cloud computing platform, and during the data access process, the illegal attack detection model on the cloud computing platform is scheduled to detect the real-time network traffic characteristics to determine the illegal attack detection results; The illegal attack detection result is fed back to the attack detection requester until a receiving completion flag transmitted by the attack detection requester is received, thereby completing the illegal attack detection based on the cloud computing platform.
2. The illegal attack detection method based on cloud computing platform according to claim 1 is characterized in that: The historical network traffic feature sample set is set to the CIC-IDS-2017 / 2018 dataset or the KDDCup-99 dataset.
3. The illegal attack detection method based on cloud computing platform according to claim 1 is characterized in that: Constructing an illegal attack detection model, including: constructing a sequentially connected input layer, a first convolutional layer, a first pooling layer, a second convolutional layer, a second pooling layer, a fully connected layer, and an output layer.
4. The illegal attack detection method based on cloud computing platform according to claim 1 is characterized in that: Taking the historical network traffic characteristics and the illegal attack labels corresponding to the historical network traffic characteristics as data support, an adaptive search algorithm is used to optimize the illegal attack detection model to obtain the optimized illegal attack detection model, including: Initialize the model parameters of the illegal attack detection model and determine a plurality of different individuals; wherein each individual includes all the model parameters of the illegal attack detection model; Using historical network traffic characteristics and illegal attack labels corresponding to the historical network traffic characteristics as data support, obtaining the fitness value corresponding to each individual, and dividing the individuals into leaders, developers and followers according to the fitness value; For the leader, an adaptive neighborhood search strategy is used to search the neighborhood of the leader and determine the leader after the neighborhood search; For developers, a collaborative development strategy based on fitness decision is used to conduct joint development search on developers and determine the developers after the joint development search; For followers, a double-following strategy is used to search for followers in a better area, and followers after the better area search are determined; Determine whether the optimization end condition is met. If so, determine the optimal individual based on the leader after the neighborhood search, the developer after the joint development search, and the follower after the better area search, and use the model parameters in the optimal individual as the final parameters of the illegal attack detection model to obtain the optimized illegal attack detection model. Otherwise, return to the fitness value acquisition step.
5. The illegal attack detection method based on cloud computing platform according to claim 4 is characterized in that: Using historical network traffic characteristics and illegal attack labels corresponding to historical network traffic characteristics as data support, obtain the fitness value corresponding to each individual, including: For any individual, apply the parameters in the individual to the illegal attack detection model, and then use the historical network traffic characteristics as the input of the illegal attack detection model to obtain the actual output of the illegal attack detection model; The illegal attack labels corresponding to the historical network traffic characteristics are used as the expected output, and the cross entropy loss function value corresponding to the individual is determined according to the actual output and expected output of the illegal attack detection model; The cross entropy loss function value corresponding to the individual is added to the preset constant term to obtain a numerical addition term, and the reciprocal of the numerical addition term is taken to obtain the fitness value corresponding to the individual.
6. The illegal attack detection method based on cloud computing platform according to claim 5 is characterized in that: Adopting an adaptive neighborhood search strategy to search the neighborhood of the leader, the leader after the neighborhood search is determined, including: For any leader, randomly match another leader for the leader to obtain the matching leader corresponding to the leader; Determine whether the fitness value of the leader is greater than the fitness value of its corresponding matching leader. If so, determine the neighborhood search factor according to the fitness value of the leader, otherwise directly determine the neighborhood search factor to be 1; According to the neighborhood search factor, a neighborhood search is performed on the leader, and the leader after the neighborhood search is determined to be: in, Indicates t During the optimization process l A leader, Indicates the leader after the neighborhood search , l =1,2,..,L, L represents the total number of leaders, represents the neighborhood search factor, means the mean is 0 and the variance is Random numbers generated from a Gaussian distribution, represents an exponential function with the natural constant e as the base, Indicates l The fitness value corresponding to each leader is Indicates l The fitness value corresponding to the matching leader of each leader, represents the constant term and is set to 0.
001.
7. The illegal attack detection method based on cloud computing platform according to claim 6 is characterized in that: A collaborative development strategy based on fitness decision-making is used to conduct a joint development search for developers, and the developers after the joint development search are determined, including: For any developer, a leader is randomly matched to the developer to obtain a social learning individual; Match the developer with another developer with the closest Euclidean distance, and set the constraint condition that the fitness value of the other matched developer is greater than the fitness value of the developer, to obtain a collaborative search individual; Determine the impact of social learning individuals on developers, and get the first impact factor as: in, represents the first impact factor, represents the fitness value corresponding to the social learning individual, Indicates the fitness value corresponding to the optimal individual, that is, the maximum fitness value; represents the fitness value corresponding to the worst individual, that is, the minimum fitness value; e represents the natural constant, represents the Euclidean distance between the developer and its corresponding social learning individual; Determine the impact of collaborative search individuals on developers, and get the second impact factor as: in, represents the second impact factor, represents the fitness value of the collaborative search individual, represents the Euclidean distance between the developer and its corresponding collaborative search individual; According to the first influencing factor, the social learning individual, the collaborative search individual and the second influencing factor, a joint development search is performed on the developer, and the developer after the joint development search is determined to be: in, represents the mth developer in the tth optimization process, m=1,2,..,M, M represents the total number of developers, Indicates the developer after the joint development search , represents the first random number between (0,1), represents the second random number between (0,1), Indicates the developer The corresponding social learning individuals, Indicates the developer The corresponding collaborative search individuals.
8. The illegal attack detection method based on cloud computing platform according to claim 7 is characterized in that: The double follower strategy is used to search for a better area for the follower, and the follower after the better area search is determined, including: The resulting transfer factor is: in, represents the transfer factor, represents an exponential function with the natural constant e as the base, and T represents the preset maximum number of optimizations; When the transfer factor TF is less than or equal to 0.5, a better area search is performed on the follower, and the follower after the better area search is determined to be: in, Indicates t The nth follower in the sub-optimization process, Indicates the follower after the better area search , n=1,2,..,N, N represents the total number of followers, represents the third random number between (0,1), Indicates t +1 follower in the optimization process The corresponding search step size is, Indicates t +1 follower in the optimization process The corresponding control factor is represents a developer who is randomly matched to a follower, represents the first normalized range adjustment factor, represents the second normalized range adjustment factor, Indicates t +1 optimization process corresponding to the search capability of the nth developer, Indicates t +1 optimization process corresponding to the search capability of the kth developer, Indicates t +1 optimization process corresponding to the first search capability control factor of the nth developer, Indicates t +1 optimization process corresponding to the second search capability control factor of the nth developer, represents the first search capability control factor corresponding to the random developer, represents the second search capability control factor corresponding to the random developer, represents the fourth random number between (0,1), Indicates t The first search capability control factor corresponding to the nth developer in the optimization process, Indicates t The maximum first search capability control factor in the sub-optimization process, represents the fifth random number between (0,1), Indicates t The second search capability control factor corresponding to the nth developer in the optimization process, Indicates t The maximum second search capability control factor in the sub-optimization process, Represents the sixth random number between (0, 1); at the initial optimization moment, each developer's corresponding first search capability control factor and second search capability control factor are randomly generated between (0, 1); When the transfer factor TF is greater than 0.5, a better area search is performed on the follower, and the follower after the better area search is determined to be: in, represents the optimal individual, Indicates a random direction factor of 1 or -1. Represents the seventh random number between (0,1).
9. The illegal attack detection method based on cloud computing platform according to claim 8 is characterized in that: Determining whether the optimization end condition is met includes: determining whether the current optimization times reaches a preset maximum optimization times, if so, determining that the optimization end condition is met, otherwise determining that the optimization end condition is not met.
10. The illegal attack detection method based on cloud computing platform according to claim 9 is characterized in that: Also includes: When the illegal attack detection result is an abnormal category, illegal attack warning information is generated and fed back to the attack detection requester.