Firewall threat detection method, device and equipment based on deep learning model
By performing hyperparameter optimization on deep learning models of different structures, combined with optimization algorithms to minimize detection error and duration, the problem of poor detection accuracy and speed in the prior art is solved, and the applicability of firewall threat detection is improved.
Patent Information
- Application Number
- CN202510303422.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-27
AI Technical Summary
The existing deep learning-based firewall threat detection scheme fails to take into account both detection accuracy and detection speed, resulting in the need to improve its applicability on the firewall side.
By collecting normal and abnormal HTTP request messages, extracting feature data, obtaining deep learning models of different structures, and using optimization algorithms to optimize the model hyperparameters to minimize output errors and calculation time objective functions.
It realizes the need for computing power required for detection while ensuring detection accuracy, improves the applicability of the detection model on the firewall side, and facilitates practical application and promotion.
Smart Images

Figure CN120223373A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of artificial intelligence, and particularly relates to a firewall threat detection method, device and equipment based on a deep learning model. Background Art
[0002] With the rapid development of computers and the Internet, modern information technology has played a crucial role in human society, promoting social scientific and technological progress and the development of civilization. However, at the same time, the openness and popularity of information networks have also brought a series of security challenges, including threats such as hacker attacks, worm viruses and malicious codes. To address these risks, various defense means have been adopted in the field of network security, among which the firewall is a key technology. As the first line of defense for network security, the firewall aims to monitor, filter and control the traffic entering and leaving the network to protect the network from potential threats.
[0003] The existing patent "CN111669354A, Threat Intelligence Industrial Firewall Based on Machine Learning" discloses a threat intelligence industrial firewall based on machine learning, including the following steps: Step 1, access recognition: perform identity recognition through Modbus protocol access control to restrict the access of access subjects to objects in the industrial control system; Step 2, data acquisition and transmission: the process of data acquisition and transmission through the OPC (Object Linking and Embedding for Process Control) protocol; Step 3, feature extraction and screening: first perform dimensionality reduction on the data using the linear discriminant analysis LDA (Linear Discriminant Analysis) technology; Step 4, training: in machine learning, use the support vector machine SVM (Support Vector Machine) algorithm; Step 5, testing: obtain a test set by independently and identically distributed sampling on the previous training set, and enable the leave one out detection method. Although the foregoing firewall combines protocol recognition, dimensionality reduction processing and machine learning algorithms, these algorithms perform feature statistical analysis on modeling data, etc., and then establish a model for anomaly detection, which belongs to a shallow feature representation method and cannot accurately describe the relationship between features.
[0004] Regarding the technical problems of the above patent, the existing patent "CN117857157A, A Firewall Threat Detection Method and System Based on Deep Learning" provides a firewall threat detection solution based on deep learning, including: crawling http request information to obtain the original http request information; preprocessing the original http request information to obtain the preprocessed http request information; obtaining a bidirectional LSTM (Long Short-Term Memory) model injected with a self-attention mechanism; training the bidirectional LSTM model injected with the self-attention mechanism based on the preprocessed http request information to obtain a firewall threat detection model. Although the foregoing solution can extract deep features, learn abstract information in the request information, and record abnormal behaviors through the attention mechanism, a more effective firewall threat detection model can be obtained, and the accuracy of web-side anomaly detection can be improved. However, there are more than just the bidirectional LSTM model injected with the self-attention mechanism among deep learning models that have the ability to extract deep features and learn abstract information in the request information. Therefore, it is necessary to select the model with the most accurate detection ability from multiple deep learning models with different structures for firewall threat detection. In addition, considering that the computing resources on the firewall side, such as the web side, are limited and it is necessary to detect and identify firewall threats in a timely manner to intercept requests or allow requests to pass in a timely manner to ensure the user experience, it is also necessary to minimize the computing time required for the final obtained firewall threat detection model.
[0005] In summary, when performing firewall threat detection based on deep learning, how to select a firewall threat detection model that can balance detection accuracy and detection speed from multiple deep learning models with different structures for firewall threat detection is an urgent research topic for those skilled in the art. Summary of the Invention
[0006] The object of the present invention is to provide a firewall threat detection method, device, computer device, computer-readable storage medium and computer program product based on a deep learning model to solve the problem that the existing firewall threat detection solution based on deep learning has limited applicability on the firewall side due to the lack of consideration of detection accuracy and detection speed.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] In a first aspect, a firewall threat detection method based on a deep learning model is provided, including:
[0009] Collecting a plurality of normal HTTP request messages and a plurality of abnormal HTTP request messages;
[0010] Perform feature extraction processing on the multiple normal HTTP request messages respectively to obtain multiple firewall threat negative sample data corresponding one-to-one to the multiple normal HTTP request messages, and perform the feature extraction processing on the multiple abnormal HTTP request messages respectively to obtain multiple firewall threat positive sample data corresponding one-to-one to the multiple abnormal HTTP request messages;
[0011] Obtain multiple deep learning models with different structures;
[0012] For each deep learning model among the multiple deep learning models, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data, and optimize the hyperparameters of the corresponding model based on an optimization algorithm to obtain an optimal search result corresponding to the hyperparameters and used to minimize the objective function F, where the calculation formula of the objective function F is as follows:
[0013] F = d E × d T
[0014] In the formula, d E represents the output error situation index value of the deep learning model, and d T represents the calculation required duration index value of the deep learning model;
[0015] Select a certain deep learning model with the smallest objective function F from the multiple deep learning models;
[0016] Import the optimal search result of the hyperparameters of the certain deep learning model and the model parameters obtained during the optimization process and corresponding to the optimal search result into the certain deep learning model to obtain a firewall threat detection model;
[0017] Deploy the firewall threat detection model to the firewall side, so that when the firewall side receives a new HTTP request message, first perform the feature extraction processing on the new HTTP request message, then import the feature extraction result into the firewall threat detection model, output a firewall threat detection result corresponding to the new HTTP request message, and finally execute a corresponding preset security policy according to the firewall threat detection result.
[0018] Based on the above inventive concept, a new firewall threat detection solution based on a deep learning model that can balance detection accuracy and detection speed is provided. First, based on multiple normal and abnormal HTTP request messages, multiple positive and negative firewall threat sample data are preprocessed. Then, for each model among multiple deep learning models, the positive and negative firewall threat sample data are applied, and the hyperparameters of the corresponding model are optimized based on an optimization algorithm to obtain the optimal search results corresponding to the hyperparameters and used to minimize the objective function that is the product of the output error situation index value and the calculation required duration index value. Then, a certain model with the minimum objective function is selected from multiple models, and the optimal search results of the corresponding hyperparameters and the corresponding model parameters are imported to obtain a firewall threat detection model. Finally, the firewall threat detection model is deployed to the firewall side to perform firewall threat detection. In this way, by selecting a firewall threat detection model that can balance detection accuracy and detection speed from multiple deep learning models with different structures for firewall threat detection, the demand for computing power required for detection can be reduced while ensuring detection accuracy, improving the applicability of the detection model on the firewall side, and facilitating practical application and promotion.
[0019] In a possible design, feature extraction processing is respectively performed on the multiple normal HTTP request messages to obtain multiple negative firewall threat sample data corresponding one-to-one to the multiple normal HTTP request messages, including:
[0020] For a certain HTTP request message among the multiple normal HTTP request messages, an HTTP parsing tool is used to parse the corresponding message to obtain an HTTP parsing result;
[0021] Key information extraction processing is performed on the HTTP parsing result to obtain original key information;
[0022] URL processing and text processing are performed on the original key information to obtain new key information;
[0023] Numerical conversion processing is performed on the new key information to obtain key numerical values;
[0024] Missing value filling processing is performed on the key numerical values to obtain new key numerical values;
[0025] Standardization processing is performed on the new key numerical values to obtain multiple negative firewall threat sample data corresponding to the certain HTTP request message.
[0026] In a possible design, the multiple deep learning models include a perceptron, a multi-layer perceptron, a recurrent neural network, a long short-term memory network, an autoencoder, and / or a variational autoencoder.
[0027] In a possible design, the optimization algorithm adopts a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a grey wolf optimization algorithm, a whale optimization algorithm, or a tuna school optimization algorithm.
[0028] In a possible design, for each deep learning model among the multiple deep learning models, the multiple firewall threat negative sample data and the multiple firewall threat positive sample data are applied, and the hyperparameters of the corresponding model are optimized based on the optimization algorithm to obtain an optimal search result corresponding to the hyperparameters and used to minimize the objective function F, including the following steps S401 to S416:
[0029] S401. For any one of the multiple deep learning models, initialize the optimization algorithm parameters corresponding to and including the number of search individuals I in the search population, the maximum number of iterations T, the first learning factor α1, the second learning factor α2, the third learning factor α3, the fourth learning factor α4, the fifth learning factor α5, and the sixth learning factor α6, and randomly generate the initial positions of each search individual in the search population, and then execute step S402, where the initial positions of each search individual are randomly generated based on the following formula:
[0030]
[0031] In the formula, i′ represents a positive integer less than or equal to I, d′ represents a positive integer less than or equal to D′, D′ represents the dimension number of the parameter vector to be optimized, and the parameter vector to be optimized includes all hyperparameters of the any deep learning model. represents the component of the initial position of the i′-th search individual in the search population on the d′-th dimension of the parameter vector to be optimized, u c,d′ represents the upper limit of the parameter search space on the d′-th dimension, l c,d′ represents the lower limit of the parameter search space on the d′-th dimension, and rand(0, 1) represents a pure decimal random generation function;
[0032] S402. For each search individual, import the corresponding initial position as the model hyperparameters into the any deep learning model to obtain the corresponding first deep learning model, then apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to perform model training and testing on the first deep learning model to obtain the corresponding first output error situation index value and the first calculation required duration index value, and finally import the first output error situation index value and the first calculation required duration index value into the objective function F, and use the output result as the corresponding fitness, and then execute step S403, where the calculation formula of the objective function F is as follows:
[0033] F = d E × d T
[0034] where d E represents the output error situation index value of the deep learning model, and d T represents the calculation required duration index value of the deep learning model;
[0035] S403. Take the initial position of a search individual with the minimum fitness as the initial global optimal position x best , and also initialize the current iteration number t' = 0, then execute step S404;
[0036] S404. Calculate the current average position of the search population according to the current positions of the respective search individuals, and determine the corresponding first new position for each of the search individuals, then execute step S405, where the first new position of each of the search individuals is determined according to the following formula:
[0037] x new1,i′,d′ = x best,d′ + α1 × rand(0, 1) × (x mean,d′ - x i′,d′ )
[0038] where x new1,i′,d′ represents the component of the first new position of the i'-th search individual in the d'-th dimension, x best,d′ represents the component of the global optimal position x best in the d'-th dimension, x mean,d′ represents the component of the current average position of the search population in the d'-th dimension, x i′,d′ represents the component of the current position of the i'-th search individual in the d'-th dimension;
[0039] S405. For each of the search individuals, take the corresponding first new position as the model hyperparameter and import it into any of the deep learning models to obtain the corresponding second deep learning model, then apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the second deep learning model to obtain the corresponding second output error situation index value and the second calculation required duration index value, and finally import the second output error situation index value and the second calculation required duration index value into the objective function F, and take the output result as the corresponding and new fitness, then execute step S406;
[0040] S406. Determine whether the fitness corresponding to the current position of the \(i'\)-th search individual is greater than the current fitness of the \(i'\)-th search individual. If so, update the current position of the \(i'\)-th search individual to the first new position of the \(i'\)-th search individual, and then execute step S407; otherwise, directly execute step S407;
[0041] S407. Determine whether the fitness corresponding to the global optimal position \(x\) best is greater than the minimum value among the current fitnesses of all search individuals. If so, update the global optimal position \(x\) best to the current position of any search individual with this minimum value, and then execute step S408; otherwise, directly execute step S408;
[0042] S408. Update and calculate the current average position of the search population based on the current positions of all search individuals, and determine the corresponding second new positions for all search individuals, and then execute step S409. Among them, the second new positions of all search individuals are determined according to the following formula:
[0043]
[0044] In the formula, \(x\) new2,i′,d′ represents the component of the second new position of the \(i'\)-th search individual in the \(d'\)-th dimension, \(\beta(i')\) represents the first intermediate variable corresponding to the \(i'\)-th search individual, \(\delta(i')\) represents the second intermediate variable corresponding to the \(i'\)-th search individual, \(i''\) represents a positive integer less than or equal to \(I\), \(\text{mod}()\) represents the modulo function, \(x\) i″,d′ represents the component of the current position of the \(i''\)-th search individual in the search population in the \(d'\)-th dimension, \(\beta_r(i')\) represents the third intermediate variable corresponding to the \(i'\)-th search individual, \(\delta_r(i')\) represents the fourth intermediate variable corresponding to the \(i'\)-th search individual, \(\max()\) represents the maximum value function, \(\theta(i')\) represents the fifth intermediate variable corresponding to the \(i'\)-th search individual, \(r(i')\) represents the sixth intermediate variable corresponding to the \(i'\)-th search individual, and \(\pi\) represents 180 degrees;
[0045] S409. For each of the search individuals, import the corresponding second new position as a model hyperparameter into any of the deep learning models to obtain the corresponding third deep learning model. Then, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the third deep learning model to obtain the corresponding third output error situation index value and the third calculation required duration index value. Finally, import the third output error situation index value and the third calculation required duration index value into the objective function F, and use the output result as the corresponding new fitness, and then execute step S410;
[0046] S410. Determine whether the fitness corresponding to the current position of the i'-th search individual is greater than the current fitness of the i'-th search individual. If so, update the current position of the i'-th search individual to the second new position of the i'-th search individual, and then execute step S411; otherwise, directly execute step S411;
[0047] S411. Determine whether the fitness corresponding to the global optimal position x best is greater than the minimum value among the current fitnesses of the search individuals. If so, update the global optimal position x best to the current position of any search individual with this minimum value, and then execute step S412; otherwise, directly execute step S412;
[0048] S412. Update and calculate the current average position of the search population based on the current positions of the search individuals, and determine the corresponding third new position for each search individual, and then execute step S413. Among them, the third new position of each search individual is determined according to the following formula:
[0049]
[0050] In the formula, x new3,i′,d′ represents the component of the third new position of the i'-th search individual in the d'-th dimension, represents the seventh intermediate variable corresponding to the i'-th search individual, represents the eighth intermediate variable corresponding to the i'-th search individual, represents the ninth intermediate variable corresponding to the i'-th search individual, represents the tenth intermediate variable corresponding to the i'-th search individual, represents the eleventh intermediate variable corresponding to the i'-th search individual;
[0051] S413. For each of the search individuals, import the corresponding third new position as a model hyperparameter into any of the deep learning models to obtain a corresponding fourth deep learning model. Then, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the fourth deep learning model to obtain a corresponding fourth output error situation metric value and a fourth calculation required duration metric value. Finally, import the fourth output error situation metric value and the fourth calculation required duration metric value into the objective function F, and use the output result as the corresponding new fitness, and then execute step S414;
[0052] S414. Determine whether the fitness corresponding to the current position of the i'-th search individual is greater than the current fitness of the i'-th search individual. If so, update the current position of the i'-th search individual to the third new position of the i'-th search individual, and then execute step S415; otherwise, directly execute step S415;
[0053] S415. Determine whether the fitness corresponding to the global optimal position x best is greater than the minimum value among the current fitnesses of the search individuals. If so, update the global optimal position x best to the current position of any search individual with this minimum value, and then execute step S416; otherwise, directly execute step S416;
[0054] S416. Increment the current iteration number t' by 1, and determine whether the current iteration number t' has reached the maximum iteration number T. If so, use the global optimal position x best as the hyperparameter of any deep learning model and the optimal search result for minimizing the objective function F; otherwise, return to execute step S404.
[0055] In a possible design, execute corresponding preset security policies according to the firewall threat detection result, including:
[0056] When the firewall threat detection result indicates that the new HTTP request message is an abnormal request message, intercept the new HTTP request message; otherwise, allow the new HTTP request message to pass.
[0057] In a second aspect, a firewall threat detection device based on a deep learning model is provided, including a request message collection unit, a feature extraction and processing unit, a learning model acquisition unit, a model hyperparameter optimization unit, a learning model selection unit, a detection model generation unit, and a detection model deployment unit;
[0058] The request message collection unit is configured to collect a plurality of normal HTTP request messages and a plurality of abnormal HTTP request messages;
[0059] The feature extraction and processing unit is communicatively connected to the request message collection unit and is configured to perform feature extraction and processing on each of the plurality of normal HTTP request messages to obtain a plurality of firewall threat negative sample data corresponding one-to-one to the plurality of normal HTTP request messages, and perform the feature extraction and processing on each of the plurality of abnormal HTTP request messages to obtain a plurality of firewall threat positive sample data corresponding one-to-one to the plurality of abnormal HTTP request messages;
[0060] The learning model acquisition unit is configured to acquire a plurality of deep learning models with different structures;
[0061] The model hyperparameter optimization unit is respectively communicatively connected to the feature extraction and processing unit and the learning model acquisition unit, and is configured to apply the plurality of firewall threat negative sample data and the plurality of firewall threat positive sample data to each deep learning model among the plurality of deep learning models, and optimize the hyperparameters of the corresponding model based on an optimization algorithm to obtain an optimal search result corresponding to the hyperparameters and for minimizing the objective function F, where the calculation formula of the objective function F is as follows:
[0062] F = d E ×d T
[0063] In the formula, d E represents an output error situation index value of the deep learning model, and d T represents a calculation required duration index value of the deep learning model;
[0064] The learning model selection unit is communicatively connected to the model hyperparameter optimization unit and is configured to select a certain deep learning model with the smallest objective function F from the plurality of deep learning models;
[0065] The detection model generation unit is communicatively connected to the learning model selection unit and is configured to import the optimal search result of the hyperparameters of the certain deep learning model and the model parameters obtained during the optimization process and corresponding to the optimal search result into the certain deep learning model to obtain a firewall threat detection model;
[0066] The detection model deployment unit is communicatively connected to the detection model generation unit, and is configured to deploy the firewall threat detection model to the firewall side, so that when the firewall side receives a new HTTP request message, it first performs the feature extraction process on the new HTTP request message, then imports the feature extraction result into the firewall threat detection model, outputs the firewall threat detection result corresponding to the new HTTP request message, and finally executes the corresponding preset security policy according to the firewall threat detection result.
[0067] In a third aspect, the present invention provides a computer device, including a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the firewall threat detection method as described in the first aspect or any possible design in the first aspect.
[0068] In a fourth aspect, the present invention provides a computer-readable storage medium, on which instructions are stored. When the instructions are run on a computer, the firewall threat detection method as described in the first aspect or any possible design in the first aspect is executed.
[0069] In a fifth aspect, the present invention provides a computer program product, including a computer program or instructions. When the computer program or the instructions are executed by a computer, the firewall threat detection method as described in the first aspect or any possible design in the first aspect is implemented.
[0070] Beneficial effects of the above solution:
[0071] (1) The present invention provides a new firewall threat detection solution based on a deep learning model that can take into account both detection accuracy and detection speed. That is, first, based on multiple normal and abnormal HTTP request messages, multiple positive and negative firewall threat sample data are preprocessed. Then, for each model among multiple deep learning models, the positive and negative firewall threat sample data are applied, and the hyperparameters of the corresponding model are optimized based on an optimization algorithm to obtain the optimal search result corresponding to the hyperparameters and used to minimize the objective function that adopts the product of the output error situation index value and the calculation required duration index value. Then, a certain model with the smallest objective function is selected from multiple models, and the optimal search result of the corresponding hyperparameters and the corresponding model parameters are imported to obtain the firewall threat detection model. Finally, the firewall threat detection model is deployed to the firewall side for firewall threat detection. In this way, by selecting a firewall threat detection model that can take into account both detection accuracy and detection speed from multiple deep learning models with different structures for firewall threat detection, the demand for computing power required for detection can be reduced while ensuring detection accuracy, improving the applicability of the detection model on the firewall side, and facilitating practical application and promotion. Brief Description of the Drawings
[0072] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0073] Figure 1 It is a schematic flow chart of the firewall threat detection method based on a deep learning model provided by an embodiment of the present application.
[0074] Figure 2 It is a schematic flow chart of the feature extraction process for HTTP request messages provided by an embodiment of the present application.
[0075] Figure 3 It is a schematic flow chart of optimizing the hyperparameters of a deep learning model based on an optimization algorithm provided by an embodiment of the present application.
[0076] Figure 4 It is a schematic structural diagram of the firewall threat detection device based on a deep learning model provided by an embodiment of the present application.
[0077] Figure 5 It is a schematic structural diagram of the computer device provided by an embodiment of the present application. Detailed Description of the Embodiments
[0078] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the present invention in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structural drawings is only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these embodiments. It should be noted here that the description of these embodiment modes is used to help understand the present invention, but does not constitute a limitation to the present invention.
[0079] It should be understood that although terms such as first and second may be used herein to describe various objects, these objects should not be limited by these terms. These terms are only used to distinguish one object from another. For example, the first object can be called the second object, and similarly, the second object can be called the first object, without departing from the scope of the exemplary embodiments of the present invention.
[0080] It should be understood that for the term "and / or" that may appear in this text, it is merely a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, B exists alone, or both A and B exist simultaneously; another example, A, B, and / or C can represent any one of A, B, and C or any combination of them; for the term " / and" that may appear in this text, it is a description of another association object relationship, indicating that two relationships can exist. For example, A / and B can represent two situations: A exists alone or both A and B exist simultaneously; in addition, for the character " / " that may appear in this text, generally it represents that the associated objects before and after are in an "or" relationship.
[0081] Embodiment
[0082] As Figures 1 to 3 shown, the firewall threat detection method provided in the first aspect of this embodiment and based on a deep learning model can be, but is not limited to, executed by a computer device with certain computing resources, such as a cloud server, a personal computer (Personal Computer, PC, referring to a multi-purpose computer with a size, price, and performance suitable for personal use; desktop computers, laptops, small laptops, tablet computers, and ultrabooks, etc. all belong to personal computers), a smart phone, a personal digital assistant (Personal Digital Assistant, PDA), or a wearable device, etc. As Figure 1 shown, the firewall threat detection method can be, but is not limited to, including the following steps S1 to S7.
[0083] S1. Collect a plurality of normal HTTP request messages and a plurality of abnormal HTTP request messages.
[0084] In the step S1, the normal HTTP request message refers to an HTTP (Hypertext Transfer Protocol) request message without firewall threats; the abnormal HTTP request message refers to an HTTP request message with firewall threats. These messages can be collected conventionally. For example, first determine the application targets and scenarios of firewall threat detection (which can specifically be network security, malicious script attacks, anomaly detection, or other tasks related to HTTP requests), then determine the data capture tool (which specifically refers to a network packet capture tool, such as Wireshark, etc.) and configure the capture tool to obtain the target capture tool. Finally, based on the application targets and scenarios, capture normal HTTP request messages in the real network environment and / or simulation environment through the target capture tool, and capture abnormal HTTP request messages in several attack scenarios simulated in the experimental environment through the target capture tool.
[0085] S2. Perform feature extraction processing on the multiple normal HTTP request messages respectively to obtain multiple firewall threat negative sample data corresponding one-to-one to the multiple normal HTTP request messages, and perform the feature extraction processing on the multiple abnormal HTTP request messages respectively to obtain multiple firewall threat positive sample data corresponding one-to-one to the multiple abnormal HTTP request messages.
[0086] In the step S2, since the normal HTTP request message refers to an HTTP request message without firewall threats, the feature extraction result obtained based on the normal HTTP request message is used as firewall threat negative sample data. Specifically, as Figure 2 shown, performing feature extraction processing on the multiple normal HTTP request messages respectively to obtain multiple firewall threat negative sample data corresponding one-to-one to the multiple normal HTTP request messages includes but is not limited to the following steps S201 to S206.
[0087] S201. For a certain HTTP request message among the multiple normal HTTP request messages, use an HTTP parsing tool to parse the corresponding message to obtain an HTTP parsing result.
[0088] In the step S201, the HTTP parsing tool can be but is not limited to specifically the HTTP parsing library http-parser. In addition, the HTTP parsing result specifically includes but is not limited to components such as the request method, URL (Uniform Resource Locator), request headers, and request body.
[0089] S202. Perform key information extraction processing on the HTTP parsing result to obtain the original key information.
[0090] In step S202, the original key information includes but is not limited to URL path, URL parameters, request method (such as GET method or POST method, etc.), request header information, request body content, source IP address, target IP address, and port number, etc.
[0091] S203. Perform URL processing and text processing on the original key information to obtain new key information.
[0092] In step S203, the specific means of the URL processing and text processing are prior arts, and the purpose is to convert the original key information into a form that is easy for the model to understand.
[0093] S204. Perform numerical conversion processing on the new key information to obtain key numerical values.
[0094] In step S204, the specific means of the numerical conversion processing are prior arts, for example, using the One-Hot encoding method.
[0095] S205. Perform missing value filling processing on the key numerical values to obtain new key numerical values.
[0096] In step S205, the specific means of the missing value filling processing are prior arts, and the purpose is to ensure the integrity of the data.
[0097] S206. Perform standardization processing on the new key numerical values to obtain multiple firewall threat negative sample data corresponding to the certain HTTP request message.
[0098] In step S206, the specific means of the standardization processing are prior arts, and the purpose is to ensure that the data is on a similar scale, which helps the model converge faster.
[0099] In step S2, since the abnormal HTTP request message refers to the HTTP request message with firewall threats, the feature extraction result obtained based on the abnormal HTTP request message is used as the firewall threat positive sample data. In addition, the specific acquisition process of the firewall threat positive sample data can be obtained by the conventional derivation of the foregoing steps S201 - S206, and will not be elaborated here.
[0100] S3. Obtain multiple deep learning models with different structures.
[0101] In the step S3, Deep Learning specifically refers to machine learning based on deep neural network models and methods; it is developed on the basis of algorithm models such as statistical machine learning and artificial neural networks, combined with the development of contemporary big data and high computing power. The most important technical feature of Deep Learning is the ability to automatically extract features, and the extracted features are also called deep features or deep feature representations. Compared with manually designed features, deep features have stronger and more robust representation capabilities. Specifically, the multiple deep learning models include, but are not limited to, perceptrons, multi-layer perceptrons, recurrent neural networks, long short-term memory networks, autoencoders, and / or variational autoencoders, etc. In addition, the specific acquisition method of the deep learning model is an existing method. Taking the bidirectional LSTM model with self-attention mechanism injected as an example, it can be obtained according to the following steps: First, select a target model construction tool (such as pytorch), and introduce the libraries and modules for model construction (such as torch, torch.nn) on the target model construction tool; then determine the input sequence information, and based on the libraries and modules, construct a self-attention mechanism layer by setting different weights for the input sequence information (for example, the input sequence information is the request method, URL, and request header in the HTTP request message, and the weights are 4:2:4 respectively); then, based on the libraries and modules, construct an original bidirectional LSTM model according to the forward information and backward information of the input sequence information; finally, integrate the self-attention mechanism layer into the original bidirectional LSTM model to obtain the bidirectional LSTM model with self-attention mechanism injected.
[0102] S4. For each deep learning model among the multiple deep learning models, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data, and optimize the hyperparameters of the corresponding model based on an optimization algorithm to obtain an optimal search result with corresponding hyperparameters and used to minimize the objective function F, where the calculation formula of the objective function F is as follows:
[0103] F = d E ×d T
[0104] In the formula, d E represents the index value of the output error situation of the deep learning model, and d T represents the index value of the required calculation time of the deep learning model.
[0105] In step S4, the model hyperparameters refer to the parameters preset in the learning model. These parameters cannot be directly learned from the data in the standard model training process but need to be manually set to optimize the performance of the model. For example, there are the number of hidden layer nodes, learning rate, batch size, etc. The output error situation index value is used to reflect the detection accuracy of the model. The smaller its value, the higher the detection accuracy of the model. It specifically includes but is not limited to the average deviation value, variance, and / or average error rate of the overall sample, etc., and can be obtained through routine statistics during the model training and testing processes. The calculation required duration index value is used to reflect the detection speed of the model. The shorter its value, the faster the detection speed of the model, and it can be obtained through routine timing during the model testing process. The objective function F is used as a comprehensive index that takes into account both detection accuracy and detection speed. The smaller its result, the better the training model can comprehensively achieve the optimal performance in the two objective dimensions of detection accuracy and detection speed, so as to select the optimal firewall threat detection model that takes into account both detection accuracy and detection speed subsequently. In addition, specifically, the optimization algorithm can be but is not limited to using the particle swarm optimization algorithm, Newton optimization algorithm, genetic optimization algorithm, Grey Wolf Algorithm, whale optimization algorithm, or tuna swarm optimization algorithm, etc.
[0106] In step S4, considering that different optimization algorithms have different advantages and disadvantages, in order to comprehensively utilize the performance of the foregoing optimization algorithms to achieve the purpose of making the best use of advantages and avoiding disadvantages, preferably, as Figure 3 shown, for each deep learning model among the multiple deep learning models, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data, and optimize the hyperparameters of the corresponding model based on the optimization algorithm to obtain the optimal search result corresponding to the hyperparameters and used to minimize the objective function F, including the following steps S401 to S416.
[0107] S401. For any one of the multiple deep learning models, initialize the optimization algorithm parameters corresponding to and including the number of search individuals I in the search population, the maximum number of iterations T, the first learning factor α1, the second learning factor α2, the third learning factor α3, the fourth learning factor α4, the fifth learning factor α5, and the sixth learning factor α6, and randomly generate the initial positions of each search individual in the search population, and then execute step S402. Among them, the initial positions of each search individual are randomly generated based on the following formula:
[0108]
[0109] Wherein, i' represents a positive integer less than or equal to I, d' represents a positive integer less than or equal to D', D' represents the number of dimensions of the parameter vector to be optimized, and the parameter vector to be optimized contains all hyperparameters of any of the deep learning models. represents the component of the initial position of the i'-th search individual in the search population on the d'-th dimension of the parameter vector to be optimized, u c,d′ represents the upper limit of the parameter search space on the d'-th dimension, l c,d′ represents the lower limit of the parameter search space on the d'-th dimension, and rand(0,1) represents a pure decimal random generation function.
[0110] In step S401, considering that different deep learning models may have different model hyperparameters, the parameter vector to be optimized may vary for different deep learning models.
[0111] S402. For each search individual, import the corresponding initial position as the model hyperparameters into any of the deep learning models to obtain the corresponding first deep learning model. Then, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the first deep learning model to obtain the corresponding first output error situation index value and the first calculation required duration index value. Finally, import the first output error situation index value and the first calculation required duration index value into the objective function F, and take the output result as the corresponding fitness, and then execute step S403, where the calculation formula of the objective function F is as follows:
[0112] F = d E ×d T
[0113] Wherein, d E represents the output error situation index value of the deep learning model, d T represents the calculation required duration index value of the deep learning model.
[0114] In step S402, considering that some hyperparameters need to be integers (such as the number of hidden layer nodes), it is necessary to round the corresponding parameter values before importing the initial position as the model hyperparameters into the model. For example, round the value of the number of hidden layer nodes. The aforementioned application of the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the first deep learning model is a conventional calibration and verification method, which will not be elaborated here. In addition, when obtaining the first output error situation index value and the first calculation required duration index value, it is also necessary to record the model parameters corresponding to the initial position and obtained through model training for use in subsequent step S6.
[0115] S403. Take the initial position of a search individual with the minimum fitness as the initial global optimal position x best , and also initialize the current iteration number t′ = 0, then execute step S404.
[0116] S404. Calculate the current average position of the search population according to the current positions of the respective search individuals, and for each of the search individuals, determine the corresponding first new position, then execute step S405, where the first new position of each of the search individuals is determined according to the following formula:
[0117] x new1,i′,d′ = x best,d′ + α1×rand(0,1)×(x mean,d′ - x i′,d′ )
[0118] In the formula, x new1,i′,d′ represents the component of the first new position of the i′-th search individual in the d′-th dimension, x best,d′ represents the component of the global optimal position x best in the d′-th dimension, x mean,d′ represents the component of the current average position of the search population in the d′-th dimension, x i′,d′ represents the component of the current position of the i′-th search individual in the d′-th dimension.
[0119] S405. For each of the search individuals, import the corresponding first new position into any one of the deep learning models to obtain the corresponding second deep learning model, then apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the second deep learning model, obtain the corresponding second output error situation index value and the second calculation required duration index value, and finally import the second output error situation index value and the second calculation required duration index value into the objective function F, and take the output result as the corresponding and new fitness, then execute step S406.
[0120] In the step S405, since it is also considered that some hyperparameters need to be integers (such as the number of hidden layer nodes), it is necessary to round the corresponding parameter values before importing the first new position as a model hyperparameter into the model. For example, round the value of the number of hidden layer nodes. The aforementioned application of the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the second deep learning model is also a conventional calibration and verification method, which will not be elaborated here. In addition, when obtaining the second output error situation index value and the second calculation required duration index value, it is also necessary to record the model parameters corresponding to the first new position and obtained through model training for use in the subsequent step S6.
[0121] S406. Determine whether the fitness corresponding to the current position of the i'-th search individual is greater than the current fitness of the i'-th search individual. If so, update the current position of the i'-th search individual to the first new position of the i'-th search individual, and then execute step S407; otherwise, directly execute step S407.
[0122] S407. Determine whether the fitness corresponding to the global optimal position x best is greater than the minimum value among the current fitnesses of the respective search individuals. If so, update the global optimal position x best to the current position of any search individual having this minimum value, and then execute step S408; otherwise, directly execute step S408.
[0123] S408. Update and calculate the current average position of the search population based on the current positions of the respective search individuals, and determine the corresponding second new position for each search individual, and then execute step S409, where the second new position of each search individual is determined according to the following formula:
[0124]
[0125] In the formula, x new2,i′,d′ represents the component of the second new position of the i'-th search individual in the d'-th dimension, β(i') represents the first intermediate variable corresponding to the i'-th search individual, δ(i') represents the second intermediate variable corresponding to the i'-th search individual, i'' represents a positive integer less than or equal to I, mod() represents the remainder function, x i″,d′represents the component of the current position of the i''-th search individual in the search population on the d'-th dimension, βr(i') represents the third intermediate variable corresponding to the i'-th search individual, δr(i') represents the fourth intermediate variable corresponding to the i'-th search individual, max() represents the maximum value function, θ(i') represents the fifth intermediate variable corresponding to the i'-th search individual, r(i') represents the sixth intermediate variable corresponding to the i'-th search individual, and π represents 180 degrees.
[0126] S409. For each of the search individuals, import the corresponding second new position into any one of the deep learning models to obtain the corresponding third deep learning model. Then, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the third deep learning model to obtain the corresponding third output error situation index value and the third calculation required duration index value. Finally, import the third output error situation index value and the third calculation required duration index value into the objective function F, and use the output result as the corresponding new fitness, and then execute step S410.
[0127] In step S409, it is also considered that some hyperparameters need to be integers (such as the number of hidden layer nodes). Therefore, before importing the second new position as a model hyperparameter into the model, it is necessary to round the corresponding parameter values. For example, round the value of the number of hidden layer nodes. The aforementioned application of the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the third deep learning model is also a conventional calibration and verification method, which will not be elaborated here. In addition, when obtaining the third output error situation index value and the third calculation required duration index value, it is also necessary to record the model parameters corresponding to the second new position and obtained through model training for use in subsequent step S6.
[0128] S410. Determine whether the fitness corresponding to the current position of the i'-th search individual is greater than the current fitness of the i'-th search individual. If so, update the current position of the i'-th search individual to the second new position of the i'-th search individual, and then execute step S411. Otherwise, directly execute step S411.
[0129] S411. Determine whether the fitness corresponding to the global optimal position x best is greater than the minimum value among the current fitnesses of all the search individuals. If so, update the global optimal position x best to the current position of any search individual with this minimum value, and then execute step S412. Otherwise, directly execute step S412.
[0130] S412. Update and calculate the current average position of the search population based on the current positions of the respective search individuals, and for each of the search individuals, determine a corresponding third new position, and then execute step S413, where the third new position of each of the search individuals is determined according to the following formula:
[0131]
[0132] In the formula, x new3,i′,d′ represents the component of the third new position of the i'-th search individual in the d'-th dimension, represents the seventh intermediate variable corresponding to the i'-th search individual, represents the eighth intermediate variable corresponding to the i'-th search individual, represents the ninth intermediate variable corresponding to the i'-th search individual, represents the tenth intermediate variable corresponding to the i'-th search individual, represents the eleventh intermediate variable corresponding to the i'-th search individual.
[0133] S413. For each of the search individuals, import the corresponding third new position into any one of the deep learning models to obtain a corresponding fourth deep learning model, and then apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to perform model training and testing on the fourth deep learning model to obtain a corresponding fourth output error situation index value and a fourth calculation required duration index value. Finally, import the fourth output error situation index value and the fourth calculation required duration index value into the objective function F, and use the output result as the corresponding and new fitness, and then execute step S414.
[0134] In step S413, it is also considered that some hyperparameters need to be integers (such as the number of hidden layer nodes). Therefore, before importing the third new position as a model hyperparameter into the model, it is necessary to round the corresponding parameter values. For example, round the value of the number of hidden layer nodes. The aforementioned application of the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to perform model training and testing on the fourth deep learning model is also a conventional calibration and verification method, which will not be elaborated here. In addition, when obtaining the fourth output error situation index value and the fourth calculation required duration index value, it is also necessary to record the model parameters corresponding to the third new position and obtained through model training for use in subsequent step S6.
[0135] S414. Determine whether the fitness corresponding to the current position of the i'-th search individual is greater than the current fitness of the i'-th search individual. If so, update the current position of the i'-th search individual to the third new position of the i'-th search individual, and then execute step S415; otherwise, directly execute step S415.
[0136] S415. Determine whether the fitness corresponding to the global optimal position x best is greater than the minimum value among the current fitnesses of the respective search individuals. If so, update the global optimal position x best to the current position of any search individual having this minimum value, and then execute step S416; otherwise, directly execute step S416.
[0137] S416. Increment the current iteration number t' by 1, and determine whether the current iteration number t' has reached the maximum iteration number T. If so, use the global optimal position x best as the hyperparameter of any one of the deep learning models and the optimal search result for minimizing the objective function F; otherwise, return to execute step S404.
[0138] Based on the foregoing steps S401 to S416, since in each iteration process, each search individual performs three fitness calculations by means of a spiral and the group center respectively, it can be regarded as a fusion of the particle swarm optimization algorithm and the whale optimization algorithm. Therefore, under all equal conditions, its optimization performance will be better than other optimization algorithms, which is conducive to quickly and accurately obtaining the optimal search result of the hyperparameter and for minimizing the objective function F.
[0139] S5. Select a certain deep learning model from the multiple deep learning models that has the minimum objective function F.
[0140] In step S5, specifically, according to the fitness corresponding to the global optimal position x best of each deep learning model, if it is found that the fitness corresponding to the global optimal position x best of a certain model is the minimum value, then use this model as a certain deep learning model that has the minimum objective function F.
[0141] S6. Import the optimal search result of the hyperparameters of the certain deep learning model and the model parameters obtained during the optimization process and corresponding to this optimal search result into the certain deep learning model to obtain a firewall threat detection model.
[0142] In step S6, the optimal search result of the hyperparameters of the certain deep learning model is the global optimal position x best, also considering that some hyperparameters need to be integers (such as the number of nodes in the hidden layer), it is necessary to round the corresponding parameter values before importing the optimization search results of the hyperparameters of a certain deep learning model as model hyperparameters into the model. For example, round the value of the number of nodes in the hidden layer. In addition, the model parameters obtained during the optimization process and corresponding to the optimization search results are the model parameters recorded in the aforementioned S402, S404, S409, or S413 and obtained through model training.
[0143] S7. Deploy the firewall threat detection model to the firewall side so that when the firewall side receives a new HTTP request message, it first performs the feature extraction process on the new HTTP request message, then imports the feature extraction result into the firewall threat detection model, outputs the firewall threat detection result corresponding to the new HTTP request message, and finally executes the corresponding preset security policy according to the firewall threat detection result.
[0144] In step S7, the firewall side is specifically but not limited to the web side. The firewall threat detection result can specifically reflect the existence of a firewall threat by indicating that the new HTTP request message is an abnormal request message or reflect the non-existence of a firewall threat by indicating that the new HTTP request message is a normal request message. Specifically, executing the corresponding preset security policy according to the firewall threat detection result includes but is not limited to: when the firewall threat detection result indicates that the new HTTP request message is an abnormal request message, intercept the new HTTP request message; otherwise, allow the new HTTP request message to pass.
[0145] Based on the firewall threat detection method described in the foregoing steps S1 to S7, a new firewall threat detection solution based on a deep learning model that can take into account both detection accuracy and detection speed is provided. That is, first, based on multiple normal and abnormal HTTP request messages, multiple positive and negative firewall threat sample data are preprocessed. Then, for each model among multiple deep learning models, the positive and negative firewall threat sample data are applied, and the hyperparameters of the corresponding model are optimized based on an optimization algorithm to obtain an optimal search result corresponding to the hyperparameters and used to minimize the objective function that is the product of the output error situation index value and the calculation required duration index value. Then, a certain model with the smallest objective function is selected from multiple models, and the optimal search result of the corresponding hyperparameters and the corresponding model parameters are imported to obtain a firewall threat detection model. Finally, the firewall threat detection model is deployed to the firewall side to perform firewall threat detection. In this way, by selecting a firewall threat detection model that can take into account both detection accuracy and detection speed from multiple deep learning models with different structures to perform firewall threat detection, the demand for computing power required for detection can be reduced while ensuring detection accuracy, the applicability of the detection model on the firewall side can be improved, and it is convenient for practical application and promotion.
[0146] Based on the technical solution of the foregoing first aspect, this embodiment further provides a possible design one for optimizing model hyperparameters based on a new heuristic algorithm. That is, for each deep learning model among the multiple deep learning models, the multiple negative firewall threat sample data and the multiple positive firewall threat sample data are applied, and the hyperparameters of the corresponding model are optimized based on an optimization algorithm to obtain an optimal search result corresponding to the hyperparameters and used to minimize the objective function F, including but not limited to the following steps S421 to S429.
[0147] S421. For any one of the deep learning models among the multiple deep learning models, initialize the optimization algorithm parameters corresponding to and including the maximum number of iterations T, and randomly generate an initial search value array of the set of parameters to be optimized. Then, execute step S422, where the set of parameters to be optimized includes all the hyperparameters of the any one deep learning model, and the initial search value array y of the set of parameters to be optimized 0 is expressed as follows:
[0148]
[0149] In the formula, d″ represents a positive integer less than or equal to D″, and D″ represents the total number of parameters in the set of parameters to be optimized. represents the initial search value corresponding to the d″-th parameter in the set of parameters to be optimized, u c,d″ represents the upper limit of the parameter search space corresponding to the d″-th parameter, and l c,d″denotes the lower limit of the parameter search space corresponding to the d″-th parameter, and rand(0,1) denotes a fractional random generation function.
[0150] S422. Import the initial search value array of the set of parameters to be optimized as model hyperparameters into any of the deep learning models to obtain a fifth deep learning model. Then, apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the fifth deep learning model to obtain a fifth output error situation metric value and a fifth calculation required duration metric value. Finally, import the fifth output error situation metric value and the fifth calculation required duration metric value into the objective function F, and use the output result as the fitness corresponding to the initial search value array. Then, execute step S423, where the calculation formula of the objective function F is as follows:
[0151] F = d E ×d T
[0152] In the formula, d E denotes the output error situation metric value of the deep learning model, and d T denotes the calculation required duration metric value of the deep learning model.
[0153] In step S422, the specific technical details can be obtained by referring to the conventional derivation in the foregoing step S402 and will not be elaborated here. In addition, when obtaining the fifth output error situation metric value and the fifth calculation required duration metric value, it is also necessary to record the model parameters corresponding to the initial search value array and obtained through model training for use in the subsequent step S6.
[0154] S423. Take the initial search value array of the set of parameters to be optimized as the current optimal search value array, initialize the current iteration number t′ = 0, and also initialize the forbidden change countdown value of each parameter in the set of parameters to be optimized to zero. Then, execute step S424.
[0155] S424. Based on the current optimal search value array, perform independent increment processing and decrement processing on each parameter in the set of parameters to be optimized and with a current forbidden change countdown value of zero to obtain 2×D″′ new search value arrays of the set of parameters to be optimized. Then, execute step S425, where D″′ represents the total number of parameters in the set of parameters to be optimized and with a current forbidden change countdown value of zero, and 1 ≤ D″′ ≤ D″.
[0156] In the step S424, the increasing process or the decreasing process needs to be carried out within the corresponding parameter search space, and it can be a quantitative step-by-step increase / decrease, or a non-quantitative random increase / decrease. Moreover, it is also possible to first perform a quantitative step-by-step increase / decrease on each parameter in the set of parameters to be optimized whose current freeze countdown value is zero respectively, and then if it is found that the update of the current optimal search value array has not been completed (that is, step S429 is directly executed in the subsequent step S428), then perform a non-quantitative random increase / decrease on each parameter in the set of parameters to be optimized whose current freeze countdown value is zero respectively, so as to avoid falling into a local optimal solution. For example, if there are the following five parameters in the set of parameters to be optimized: parameter A, parameter B, parameter C, parameter D, and parameter E, where the current freeze countdown values of parameter A, parameter B, and parameter E are zero respectively (that is, D″′ takes the value of 3), then based on the current optimal search value array, an independent increase process and a decrease process can be performed on parameter A respectively to obtain two different new search value arrays of the set of parameters to be optimized (one obtained based on the increase process and the other obtained based on the decrease process); based on the current optimal search value array, an independent increase process and a decrease process can be performed on parameter B respectively to obtain two different new search value arrays of the set of parameters to be optimized; based on the current optimal search value array, an independent increase process and a decrease process can be performed on parameter E respectively to obtain two different new search value arrays of the set of parameters to be optimized; thus, 2×3 = 6 new search value arrays can be obtained, and each array represents a neighborhood search direction in the search space.
[0157] S425. For each of the 2×D″′ new search value arrays, import the corresponding array as the model hyperparameter into any one of the deep learning models to obtain the sixth deep learning model corresponding to the array, and then apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to train and test the sixth deep learning model to obtain the sixth output error situation index value and the sixth calculation required duration index value corresponding to the array. Finally, import the sixth output error situation index value and the sixth calculation required duration index value into the objective function F, and use the output result as the fitness corresponding to the array, and then execute step S426.
[0158] In the step S425, the specific technical details can be obtained by referring to the conventional derivation in the foregoing step S402, and will not be elaborated here. In addition, when obtaining the sixth output error situation index value and the sixth calculation required duration index value, it is also necessary to record the corresponding data and the model parameters obtained through model training for use in the subsequent step S6.
[0159] S426. For each of the arrays, subtract the fitness of the corresponding array from the fitness of the array corresponding to the current optimal search value array to obtain the fitness difference value of the corresponding array. When the fitness difference value is greater than zero and is the largest fitness difference value in this time, update the freeze countdown value of the corresponding unique variable parameter to a positive integer value that is positively correlated with the fitness difference value, and then execute step S427, where the unique variable parameter refers to a parameter in the set of parameters to be optimized and is used to obtain the corresponding array through increase processing or decrease processing.
[0160] In step S426, the fact that the fitness difference value is greater than zero and is the largest fitness difference value in this time means that the best search value array has been obtained in the neighborhood search direction corresponding to the corresponding parameter in this time. Therefore, it is necessary to update the freeze countdown value of the corresponding parameter to a positive integer that is positively correlated with the fitness difference value to temporarily lock the search result in this neighborhood search direction. In addition, continuing with the example in step S424 above, among the six new search value arrays corresponding to parameter A, parameter B, and parameter E, if the fitness difference value of a certain new search value array corresponding to parameter B is greater than zero and is the largest fitness difference value in this time (i.e., the largest among the six fitness difference values in this time), then update the freeze countdown value of parameter B from zero to a positive integer value that is positively correlated with the fitness difference value, while the freeze countdown values of parameter A and parameter E remain zero.
[0161] S427. Determine whether there is any parameter in the set of parameters to be optimized whose current freeze countdown value is zero. If not, decrement the current freeze countdown value of each parameter in the set of parameters to be optimized by 1, and then return to execute step S427. Otherwise, execute step S428.
[0162] In step S427, the fact that the current freeze countdown values of all parameters in the set of parameters to be optimized are not zero means that it is impossible to return to execute step S424 later. Therefore, they need to be decremented together until the current freeze countdown value of at least one parameter is zero.
[0163] S428. Determine whether there is any fitness difference value greater than zero among the fitness difference values of each of the arrays. If so, update the current optimal search value array to the array corresponding to the minimum fitness among the 2×D″′ new search value arrays, and then execute step S429. Otherwise, directly execute step S429.
[0164] Increment the current iteration count \(t'\) by 1, and determine whether the current iteration count \(t'\) has reached the maximum iteration count \(T\). If so, use the current optimal search value array as the hyperparameters of any deep learning model and the optimization search result for minimizing the objective function \(F\). Otherwise, return to step S424 for execution.
[0165] Based on the foregoing possible design 1, by optimizing the model hyperparameters through the steps of the foregoing new heuristic algorithm, it is possible to temporarily lock the search results in different iteration counts for the search results in each best neighborhood search direction based on different fitness difference values during the optimization process, thereby facilitating the rapid search for the optimal model hyperparameters. Also, by first performing a quantitative step-by-step increase / decrease on the parameters to be adjusted and then an indefinite random increase / decrease, it is possible to avoid falling into local optimal solutions and further facilitate obtaining the optimization search result quickly and accurately.
[0166] As Figure 4 shown, in the second aspect of this embodiment, a virtual device for implementing the firewall threat detection method described in the first aspect or possible design 1 is provided, including a request message collection unit, a feature extraction and processing unit, a learning model acquisition unit, a model hyperparameter optimization unit, a learning model selection unit, a detection model generation unit, and a detection model deployment unit;
[0167] The request message collection unit is used to collect a plurality of normal HTTP request messages and a plurality of abnormal HTTP request messages;
[0168] The feature extraction and processing unit, communicatively connected to the request message collection unit, is used to perform feature extraction and processing on each of the plurality of normal HTTP request messages to obtain a plurality of firewall threat negative sample data corresponding one-to-one to the plurality of normal HTTP request messages, and perform the feature extraction and processing on each of the plurality of abnormal HTTP request messages to obtain a plurality of firewall threat positive sample data corresponding one-to-one to the plurality of abnormal HTTP request messages;
[0169] The learning model acquisition unit is used to acquire a plurality of deep learning models with different structures;
[0170] The model hyperparameter optimization unit, communicatively connected to the feature extraction and processing unit and the learning model acquisition unit respectively, is used to apply the plurality of firewall threat negative sample data and the plurality of firewall threat positive sample data to optimize the hyperparameters of the corresponding model for each deep learning model among the plurality of deep learning models based on an optimization algorithm, and obtain the optimization search result of the corresponding hyperparameters for minimizing the objective function \(F\), where the calculation formula of the objective function \(F\) is as follows:
[0171] F = d E × d T
[0172] Wherein, d E represents the output error situation index value of the deep learning model, and d T represents the calculation required duration index value of the deep learning model;
[0173] The learning model selection unit, communicatively connected to the model hyperparameter optimization unit, is configured to select a certain deep learning model with the smallest target function F from the multiple deep learning models;
[0174] The detection model generation unit, communicatively connected to the learning model selection unit, is configured to import the optimized search result of the hyperparameters of the certain deep learning model and the model parameters corresponding to the optimized search result obtained during the optimization process into the certain deep learning model to obtain a firewall threat detection model;
[0175] The detection model deployment unit, communicatively connected to the detection model generation unit, is configured to deploy the firewall threat detection model to the firewall side, so that when the firewall side receives a new HTTP request message, it first performs the feature extraction process on the new HTTP request message, then imports the feature extraction result into the firewall threat detection model, outputs a firewall threat detection result corresponding to the new HTTP request message, and finally executes a corresponding preset security policy according to the firewall threat detection result.
[0176] For the working process, working details and technical effects of the foregoing device provided in the second aspect of this embodiment, reference may be made to the firewall threat detection method described in the first aspect or possibly designed, which will not be elaborated herein.
[0177] Such as Figure 5As shown, in the third aspect of this embodiment, a computer device for executing the firewall threat detection method described in the first aspect or any possible design is provided, including a memory, a processor, and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the firewall threat detection method described in the first aspect or any possible design. Specifically, the memory may include, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a flash memory, a first-in first-out memory (FIFO), and / or a first-in last-out memory (FILO), etc.; the processor may include, but is not limited to, a microprocessor of the STM32F105 series. In addition, the computer device may further include, but is not limited to, a power module, a display screen, and other necessary components.
[0178] For the working process, working details, and technical effects of the foregoing computer device provided in the third aspect of this embodiment, reference may be made to the firewall threat detection method described in the first aspect or any possible design, which will not be elaborated here.
[0179] In the fourth aspect of this embodiment, a computer-readable storage medium storing instructions including the firewall threat detection method described in the first aspect or any possible design is provided, that is, instructions are stored on the computer-readable storage medium, and when the instructions run on a computer, the firewall threat detection method described in the first aspect or any possible design is executed. Among them, the computer-readable storage medium refers to a carrier for storing data, and may include, but is not limited to, a floppy disk, an optical disc, a hard disk, a flash memory, a USB flash drive, and / or a memory stick, etc. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices.
[0180] For the working process, working details, and technical effects of the foregoing computer-readable storage medium provided in the fourth aspect of this embodiment, reference may be made to the firewall threat detection method described in the first aspect or any possible design, which will not be elaborated here.
[0181] In the fifth aspect of this embodiment, a computer program product is provided, including a computer program or instructions, and when the computer program or the instructions are executed by a computer, the firewall threat detection method described in the first aspect or any possible design is implemented. Among them, the computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices.
[0182] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A firewall threat detection method based on a deep learning model, characterized in that: include: Collect multiple normal HTTP request messages and multiple abnormal HTTP request messages; Performing feature extraction processing on the multiple normal HTTP request messages respectively to obtain multiple firewall threat negative sample data corresponding one-to-one to the multiple normal HTTP request messages, and performing the feature extraction processing on the multiple abnormal HTTP request messages respectively to obtain multiple firewall threat positive sample data corresponding one-to-one to the multiple abnormal HTTP request messages; Obtain multiple deep learning models with different structures; For each deep learning model in the multiple deep learning models, the multiple firewall threat negative sample data and the multiple firewall threat positive sample data are applied, and the hyperparameters of the corresponding model are optimized based on the optimization algorithm to obtain the optimal search result corresponding to the hyperparameters and used to minimize the objective function F, wherein the calculation formula of the objective function F is as follows: F=d E ×d T Where, d E Represents the output error indicator value of the deep learning model, d T Indicates the time required for calculation of the deep learning model; Selecting a deep learning model having the smallest objective function F from the multiple deep learning models; Importing the optimization search result of the hyperparameters of the deep learning model and the model parameters obtained in the optimization process and corresponding to the optimization search result into the deep learning model to obtain a firewall threat detection model; The firewall threat detection model is deployed to the firewall side, so that when the firewall side receives a new HTTP request message, it first performs the feature extraction processing on the new HTTP request message, and then imports the feature extraction result into the firewall threat detection model, outputs the firewall threat detection result corresponding to the new HTTP request message, and finally executes the corresponding preset security policy according to the firewall threat detection result.
2. The firewall threat detection method according to claim 1, characterized in that: Performing feature extraction processing on the multiple normal HTTP request messages respectively to obtain multiple firewall threat negative sample data corresponding to the multiple normal HTTP request messages, including: For a certain HTTP request message among the multiple normal HTTP request messages, use an HTTP parsing tool to parse the corresponding message to obtain an HTTP parsing result; Perform key information extraction processing on the HTTP parsing result to obtain original key information; Performing URL processing and text processing on the original key information to obtain new key information; Performing numerical conversion processing on the new key information to obtain a key value; Perform missing completion processing on the key values to obtain new key values; The new key value is standardized to obtain a plurality of firewall threat negative sample data corresponding to the certain HTTP request message.
3. The firewall threat detection method according to claim 1, characterized in that: The multiple deep learning models include perceptrons, multi-layer perceptrons, recurrent neural networks, long short-term memory networks, autoencoders and / or variational autoencoders.
4. The firewall threat detection method according to claim 1, characterized in that: The optimization algorithm adopts a particle swarm optimization algorithm, a Newton optimization algorithm, a genetic optimization algorithm, a gray wolf optimization algorithm, a whale optimization algorithm or a tuna swarm optimization algorithm.
5. The firewall threat detection method according to claim 1, characterized in that: For each deep learning model in the multiple deep learning models, the multiple firewall threat negative sample data and the multiple firewall threat positive sample data are applied, and the hyperparameters of the corresponding model are optimized based on the optimization algorithm to obtain the optimal search result corresponding to the hyperparameters and for minimizing the objective function F, including the following steps S401 to S416: S401. For any deep learning model among the multiple deep learning models, initialize the optimization algorithm parameters corresponding to and including the number of search individuals I, the maximum number of iterations T, the first learning factor α1, the second learning factor α2, the third learning factor α3, the fourth learning factor α4, the fifth learning factor α5 and the sixth learning factor α6 of the search population, and randomly generate the initial position of each search individual in the search population, and then execute step S402, wherein the initial position of each search individual is randomly generated based on the following formula: Wherein, i′ represents a positive integer less than or equal to I, d′ represents a positive integer less than or equal to D′, D′ represents the number of dimensions of the parameter vector to be optimized, and the parameter vector to be optimized contains all the hyperparameters of any deep learning model. represents the component of the initial position of the i′th search individual in the search population on the d′th dimension of the parameter vector to be optimized, u c,d′ represents the upper limit of the parameter search space in the d′th dimension, l c,d′ represents the lower limit of the parameter search space in the d′th dimension, and rand(0,1) represents a pure decimal random generator function; S402. For each search individual, the corresponding initial position is imported as a model hyperparameter into any deep learning model to obtain a corresponding first deep learning model, and then the multiple firewall threat negative sample data and the multiple firewall threat positive sample data are applied to perform model training and testing on the first deep learning model to obtain a corresponding first output error situation index value and a first calculation required time index value, and finally the first output error situation index value and the first calculation required time index value are imported into the objective function F, and the output result is used as the corresponding fitness, and then step S403 is executed, wherein the calculation formula of the objective function F is as follows: F=d E ×d T Where, d E Represents the output error indicator value of the deep learning model, d T Indicates the time required for calculation of the deep learning model; S403. Take the initial position of a search individual with the minimum fitness as the initial global optimal position x best , and also initialize and set the current iteration number t′=0, and then execute step S404; S404. Calculate the current average position of the search population according to the current position of each search individual, and determine the corresponding first new position for each search individual, and then execute step S405, wherein the first new position of each search individual is determined according to the following formula: x new1,i′,d′ =x best,d′ +α1×rand(0,1)×(x mean,d′ -x i′,d′ ) In the formula, x new1,i′,d′ represents the component of the first new position of the i′th search individual in the d′th dimension, x best,d′ Denotes the global optimal position x best The component in the d′th dimension, x mean,d′ represents the component of the current average position of the search population in the d′th dimension, x i′,d′ represents the component of the current position of the i′th search individual in the d′th dimension; S405. For each search individual, the corresponding first new position is imported into any one of the deep learning models as a model hyperparameter to obtain a corresponding second deep learning model, and then the plurality of firewall threat negative sample data and the plurality of firewall threat positive sample data are applied to perform model training and testing on the second deep learning model to obtain a corresponding second output error situation index value and a second calculation required time index value, and finally the second output error situation index value and the second calculation required time index value are imported into the objective function F, and the output result is used as the corresponding and new fitness, and then step S406 is executed; S406. Determine whether the fitness corresponding to the current position of the i′th search individual is greater than the current fitness of the i′th search individual. If so, update the current position of the i′th search individual to the first new position of the i′th search individual, and then execute step S407. Otherwise, directly execute step S407. S407. Determine the global optimal position x best Is the corresponding fitness greater than the minimum value among the current fitness of each search individual? If so, the global optimal position x best Update to the current position of any search individual with the minimum value, and then execute step S408, otherwise directly execute step S408; S408. The current average position of the search population is calculated based on the current position of each search individual, and the corresponding second new position is determined for each search individual, and then step S409 is executed, wherein the second new position of each search individual is determined according to the following formula: In the formula, x new2,i′,d′ represents the component of the second new position of the i′th search individual in the d′th dimension, β(i′) represents the first intermediate variable corresponding to the i′th search individual, δ(i′) represents the second intermediate variable corresponding to the i′th search individual, i″ represents a positive integer less than or equal to I, mod() represents a remainder function, x i″,d′ represents the component of the current position of the i′-th search individual in the search population on the d′-th dimension, βr(i′) represents the third intermediate variable corresponding to the i′-th search individual, δr(i′) represents the fourth intermediate variable corresponding to the i′-th search individual, max() represents the maximum value function, θ(i′) represents the fifth intermediate variable corresponding to the i′-th search individual, r(i′) represents the sixth intermediate variable corresponding to the i′-th search individual, and π represents 180 degrees; S409. For each search individual, the corresponding second new position is imported into any one of the deep learning models as a model hyperparameter to obtain a corresponding third deep learning model, and then the plurality of firewall threat negative sample data and the plurality of firewall threat positive sample data are applied to perform model training and testing on the third deep learning model to obtain a corresponding third output error situation index value and a third calculation required time index value, and finally the third output error situation index value and the third calculation required time index value are imported into the objective function F, and the output result is used as the corresponding and new fitness, and then step S410 is executed; S410. Determine whether the fitness corresponding to the current position of the i′th search individual is greater than the current fitness of the i′th search individual. If so, update the current position of the i′th search individual to the second new position of the i′th search individual, and then execute step S411. Otherwise, directly execute step S411. S411. Determine the global optimal position x best Is the corresponding fitness greater than the minimum value among the current fitness of each search individual? If so, the global optimal position x best Update to the current position of any search individual with the minimum value, and then execute step S412, otherwise directly execute step S412; S412. The current average position of the search population is calculated based on the current position of each search individual, and the corresponding third new position is determined for each search individual, and then step S413 is executed, wherein the third new position of each search individual is determined according to the following formula: In the formula, x new3,i′,d′ represents the component of the third new position of the i′th search individual in the d′th dimension, represents the seventh intermediate variable corresponding to the i′th search individual, represents the eighth intermediate variable corresponding to the i′th search individual, represents the ninth intermediate variable corresponding to the i′th search individual, represents the tenth intermediate variable corresponding to the i′th search individual, represents the eleventh intermediate variable corresponding to the i′th search individual; S413. For each search individual, the corresponding third new position is imported into any one of the deep learning models as a model hyperparameter to obtain a corresponding fourth deep learning model, and then the plurality of firewall threat negative sample data and the plurality of firewall threat positive sample data are applied to perform model training and testing on the fourth deep learning model to obtain a corresponding fourth output error situation index value and a fourth calculation required time index value, and finally the fourth output error situation index value and the fourth calculation required time index value are imported into the objective function F, and the output result is used as the corresponding and new fitness, and then step S414 is executed; S414. Determine whether the fitness corresponding to the current position of the i′th search individual is greater than the current fitness of the i′th search individual. If so, update the current position of the i′th search individual to the third new position of the i′th search individual, and then execute step S415. Otherwise, directly execute step S415. S415. Determine the global optimal position x best Is the corresponding fitness greater than the minimum value among the current fitness of each search individual? If so, the global optimal position x best Update to the current position of any search individual with the minimum value, and then execute step S416, otherwise directly execute step S416; S416. Increment the current number of iterations t′ by 1, and determine whether the current number of iterations t′ reaches the maximum number of iterations T. If so, set the global optimal position x best As the hyperparameter of any of the deep learning models and the optimal search result for minimizing the objective function F, otherwise return to execute step S404.
6. The firewall threat detection method according to claim 1, characterized in that: Executing corresponding preset security policies according to the firewall threat detection results, including: When the firewall threat detection result indicates that the new HTTP request message is an abnormal request message, the new HTTP request message is intercepted; otherwise, the new HTTP request message is allowed to pass.
7. A firewall threat detection device based on a deep learning model, characterized in that: It includes a request message collection unit, a feature extraction processing unit, a learning model acquisition unit, a model hyperparameter optimization unit, a learning model selection unit, a detection model generation unit and a detection model deployment unit; The request message collecting unit is used to collect a plurality of normal HTTP request messages and a plurality of abnormal HTTP request messages; The feature extraction processing unit is communicatively connected to the request message collection unit, and is used to perform feature extraction processing on the multiple normal HTTP request messages respectively to obtain multiple firewall threat negative sample data corresponding to the multiple normal HTTP request messages one by one, and perform feature extraction processing on the multiple abnormal HTTP request messages respectively to obtain multiple firewall threat positive sample data corresponding to the multiple abnormal HTTP request messages one by one; The learning model acquisition unit is used to acquire multiple deep learning models with different structures; The model hyperparameter optimization unit is respectively communicatively connected to the feature extraction processing unit and the learning model acquisition unit, and is used to apply the multiple firewall threat negative sample data and the multiple firewall threat positive sample data to each deep learning model in the multiple deep learning models, and optimize the hyperparameters of the corresponding model based on the optimization algorithm to obtain the optimal search result corresponding to the hyperparameters and used to minimize the objective function F, wherein the calculation formula of the objective function F is as follows: F=d E ×d T Where, d E Represents the output error indicator value of the deep learning model, d T Indicates the time required for calculation of the deep learning model; The learning model selection unit is communicatively connected to the model hyperparameter optimization unit, and is used to select a deep learning model with the smallest objective function F from the multiple deep learning models; The detection model generation unit is communicatively connected to the learning model selection unit, and is used to import the optimization search result of the hyperparameters of the certain deep learning model and the model parameters obtained in the optimization process and corresponding to the optimization search result into the certain deep learning model to obtain a firewall threat detection model; The detection model deployment unit is communicatively connected to the detection model generation unit, and is used to deploy the firewall threat detection model to the firewall side, so that when the firewall side receives a new HTTP request message, it first performs the feature extraction processing on the new HTTP request message, and then imports the feature extraction result into the firewall threat detection model, outputs the firewall threat detection result corresponding to the new HTTP request message, and finally executes the corresponding preset security policy according to the firewall threat detection result.
8. A computer device, characterized in that: It includes a memory, a processor and a transceiver which are communicatively connected in sequence, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program to execute the firewall threat detection method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on the computer, the firewall threat detection method as described in any one of claims 1 to 6 is executed.
10. A computer program product comprising a computer program or instructions, characterized in that The computer program or the instruction, when executed by a computer, implements the firewall threat detection method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Threat intelligence industrial firewall based on machine learning
CN111669354A