Network intrusion detection method and system, electronic equipment and storage medium
By dynamically updating the network traffic sample data set and continuously training the malicious network traffic identification model, the problem of insufficient model adaptability in the existing technology is solved, efficient detection of complex and dynamic network environments is achieved, false alarm rates and missed rates are reduced, and the accuracy and reliability of network intrusion detection are improved.
Patent Information
- Application Number
- CN202510542555.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-08
AI Technical Summary
In actual application, the existing network intrusion detection system has a large difference between the training data and the real network environment, resulting in a decline in model performance and high false alarms and missed alarm rates, making it difficult to adapt to complex and dynamic network environments.
By obtaining the initial network traffic sample data set, the training feature reconstruction model detects unknown network traffic sample data, and updates the data set based on the unknown data. The updated data set is used to train and fine-tune the parameters of the malicious network traffic recognition model to form a closed-loop process of continuous learning to ensure that the model can adapt to changes in the network environment.
It significantly improves the accuracy and reliability of network intrusion detection, reduces the false alarm rate and missed alarm rate, enhances the ability to identify malicious traffic, and can timely adjust and optimize the model to adapt to the ever-changing network environment.
Smart Images

Figure CN120281552A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technologies, and in particular, to a network intrusion detection method, a network intrusion detection system, an electronic device, and a computer-readable storage medium. Background Art
[0002] Due to the rapid development of the Internet and the increasingly complex network structure, network security issues have become more and more serious, and the number of network vulnerabilities and intrusion cases of computer systems has been increasing continuously. Therefore, in such a background, the Network Intrusion Detection System (NIDS) has become the focus of many network security researchers as a key tool for detecting and preventing various network security vulnerabilities. The core functions of NIDS include monitoring and analyzing user and system activities, checking system configurations and vulnerabilities, evaluating the integrity of critical resources and data files, identifying known attack patterns, statistically analyzing abnormal behaviors, managing operating system logs, and detecting user behaviors that violate security policies. These functions enable NIDS to effectively handle most network security problems.
[0003] In recent years, the research fields related to NIDS have covered machine learning and deep learning, and the research results of researchers in these two directions have gradually increased. In terms of machine learning, researchers mainly focus on signature-based detection techniques, which identify potential threats by matching known attack patterns; and anomaly detection techniques, which identify significant deviations by analyzing and learning normal network behavior patterns, usually using clustering analysis and Support Vector Machine (SVM). The application of deep learning mainly involves using Convolutional Neural Network (CNN) and Recurrent Neural Network (RNN) to process and analyze large-scale data sets. These powerful networks can extract key features to help more accurately identify intrusion behaviors. In addition, for attacks that rely on time series, such as Distributed Denial of Service (DDoS) attacks, Long Short-Term Memory (LSTM) is often used to analyze and predict.
[0004] However, these methods often face adaptability and performance issues in practical applications. The main reason is that most of the methods are trained on publicly available training sets that have been screened and processed, and there are significant differences between these data sets and the actual network environment. Therefore, when these models are deployed to a real network environment, due to the complexity and dynamic changes of the environment, the performance of the models often drops sharply, resulting in high false alarm and miss rate, which seriously affects the effectiveness of the system. Therefore, seeking a more adaptable network intrusion detection system that can be updated and adjusted in a timely manner to adapt to the changing network environment should be the main research direction at present, and further improvements to the existing technologies are required for this purpose. Summary of the Invention
[0005] In view of the above problems, embodiments of the present invention are proposed to provide a network intrusion detection method, a network intrusion detection system, an electronic device, and a computer-readable storage medium that overcome the above problems or at least partially solve the above problems.
[0006] To solve the above problems, embodiments of the present invention disclose a network intrusion detection method, the method comprising:
[0007] Obtain an initial network traffic sample data set;
[0008] Train a feature reconstruction model based on the initial network traffic sample data set, and use the feature reconstruction model to detect unknown network traffic sample data;
[0009] Update the initial network traffic sample data set according to the unknown network traffic sample data;
[0010] Train a malicious network traffic recognition model using the updated network traffic sample data set;
[0011] Perform network intrusion detection through the trained malicious network traffic recognition model.
[0012] Optionally, the obtaining of the initial network traffic sample data set includes:
[0013] Capture network data streams through a network traffic capture tool;
[0014] Parse and extract features from the network data streams to form the initial network traffic sample data set.
[0015] Optionally, the training of the feature reconstruction model based on the initial network traffic sample data set and the use of the feature reconstruction model to detect unknown network traffic sample data include:
[0016] Based on the initial network traffic sample dataset, train a deep neural network model as the feature reconstruction model;
[0017] Input the newly collected network traffic sample data into the feature reconstruction model to obtain the corresponding reconstructed sample data;
[0018] Calculate the error value between the newly collected network traffic sample data and the reconstructed sample data;
[0019] Compare the error value with a preset threshold;
[0020] If the error value is greater than the preset threshold, determine that the newly collected network traffic sample data is the unknown network traffic sample data.
[0021] Optionally, the deep neural network model includes an input layer, an encoding layer, and a decoding layer;
[0022] Among them, the input layer is used to receive network traffic sample data, the encoding layer is used to convert the network traffic sample data into a low-dimensional feature vector, and the decoding layer is used to reconstruct the low-dimensional feature vector into output sample data.
[0023] Optionally, the updating of the initial network traffic sample dataset according to the unknown network traffic sample data includes:
[0024] Label the network intrusion type of the unknown network traffic sample data;
[0025] Add the labeled unknown network traffic sample data to the initial network traffic sample dataset to form an updated network traffic sample dataset.
[0026] Optionally, the training of the malicious network traffic recognition model using the updated network traffic sample dataset includes:
[0027] Based on the updated network traffic sample dataset, use the few-shot learning method to fine-tune the parameters of the malicious network traffic recognition model.
[0028] Optionally, the fine-tuning of the parameters of the malicious network traffic recognition model using the few-shot learning method based on the updated network traffic sample dataset includes:
[0029] Select various network traffic sample data from the updated network traffic sample dataset according to a predetermined rule to form a sample subset for fine-tuning;
[0030] Based on the sample subset for fine-tuning, adjust the parameters of the malicious network traffic recognition model.
[0031] Optionally, after performing network intrusion detection using the trained malicious network traffic recognition model, the method further includes:
[0032] Continuously obtain new network traffic sample data;
[0033] Use the feature reconstruction model to detect unknown network traffic sample data in the new network traffic sample data, and update the network traffic sample data set according to the detection result;
[0034] Adjust the parameters of the malicious network traffic recognition model based on the updated network traffic sample data set;
[0035] Perform network intrusion detection on the new network traffic sample data using the adjusted malicious network traffic recognition model.
[0036] An embodiment of the present invention also discloses a network intrusion detection system, the system includes:
[0037] An initial data acquisition module, configured to acquire an initial network traffic sample data set;
[0038] An unknown sample detection module, configured to train a feature reconstruction model based on the initial network traffic sample data set, and use the feature reconstruction model to detect unknown network traffic sample data;
[0039] An initial data update module, configured to update the initial network traffic sample data set according to the unknown network traffic sample data;
[0040] A recognition model training module, configured to train a malicious network traffic recognition model using the updated network traffic sample data set;
[0041] A network intrusion detection module, configured to perform network intrusion detection using the trained malicious network traffic recognition model.
[0042] Optionally, the initial data acquisition module includes:
[0043] A data stream capture module, configured to capture network data streams through a network traffic capture tool;
[0044] A parsing and extraction module, configured to parse and extract features from the network data streams to form the initial network traffic sample data set.
[0045] Optionally, the unknown sample detection module includes:
[0046] A reconstruction model training module, configured to train a deep neural network model as the feature reconstruction model based on the initial network traffic sample data set;
[0047] A reconstructed sample determination module, configured to input newly collected network traffic sample data into the feature reconstruction model to obtain corresponding reconstructed sample data;
[0048] An error value calculation module, configured to calculate the error value between the newly collected network traffic sample data and the reconstructed sample data;
[0049] An error comparison module, configured to compare the error value with a preset threshold;
[0050] An unknown sample determination module, configured to determine that the newly collected network traffic sample data is the unknown network traffic sample data if the error value is greater than the preset threshold.
[0051] Optionally, the deep neural network model includes an input layer, an encoding layer, and a decoding layer;
[0052] Wherein, the input layer is configured to receive network traffic sample data, the encoding layer is configured to convert the network traffic sample data into a low-dimensional feature vector, and the decoding layer is configured to reconstruct the low-dimensional feature vector into output sample data.
[0053] Optionally, the initial data update module includes:
[0054] An unknown sample annotation module, configured to annotate the unknown network traffic sample data with network intrusion types;
[0055] A dataset update module, configured to add the annotated unknown network traffic sample data to the initial network traffic sample dataset to form an updated network traffic sample dataset.
[0056] Optionally, the recognition model training module is configured to fine-tune the parameters of the malicious network traffic recognition model based on the updated network traffic sample dataset by using a few-shot learning method.
[0057] Optionally, the recognition model training module includes:
[0058] A sample subset extraction module, configured to select various network traffic sample data from the updated network traffic sample dataset according to a predetermined rule to form a sample subset for fine-tuning;
[0059] A model parameter adjustment module, configured to adjust the parameters of the malicious network traffic recognition model based on the sample subset for fine-tuning.
[0060] Optionally, the system further includes:
[0061] A sample continuous acquisition module, configured to continuously acquire new network traffic sample data after the network intrusion detection module performs network intrusion detection through the trained malicious network traffic recognition model;
[0062] A detection and update module, configured to use the feature reconstruction model to detect unknown network traffic sample data in the new network traffic sample data, and update the network traffic sample data set according to the detection result;
[0063] A parameter adjustment module, configured to adjust the parameters of the malicious network traffic recognition model based on the updated network traffic sample data set;
[0064] The network intrusion detection module is further configured to perform network intrusion detection on the new network traffic sample data through the adjusted malicious network traffic recognition model.
[0065] An embodiment of the present invention also discloses an electronic device, including: one or more processors; and one or more machine-readable media storing instructions thereon, which when executed by the one or more processors, cause the electronic device to execute a network intrusion detection method as described above.
[0066] An embodiment of the present invention also discloses a computer-readable storage medium, and the computer program stored thereon causes a processor to execute a network intrusion detection method as described above.
[0067] Embodiments of the present invention include the following advantages:
[0068] A network intrusion detection solution provided by an embodiment of the present invention obtains an initial network traffic sample data set; trains a feature reconstruction model based on the initial network traffic sample data set, and uses the feature reconstruction model to detect unknown network traffic sample data; updates the initial network traffic sample data set according to the unknown network traffic sample data; trains a malicious network traffic recognition model using the updated network traffic sample data set; and performs network intrusion detection through the trained malicious network traffic recognition model.
[0069] In the embodiments of the present invention, by dynamically updating the data set, the difference between the training data and the actual network environment is reduced, and new types of traffic data (unknown network traffic sample data) that appear in the actual network environment can be identified and integrated, so that the data set is closer to the real network environment, significantly improving the adaptability to complex and dynamic network environments. By continuously updating and training the malicious network traffic recognition model, it is ensured that the model can learn the latest network traffic patterns and features, optimizing the performance of the model in the real network environment, effectively reducing the false alarm rate and the missed alarm rate, thereby enhancing the ability to identify malicious traffic and improving the accuracy and reliability of network intrusion detection. A dynamic update mechanism is introduced, which can adjust and optimize the model in a timely manner and has the ability of continuous learning, so as to adapt to the changing network environment and make up for the deficiencies of the existing technology in dynamic adjustment. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1 is a flowchart of the steps of a network intrusion detection method according to an embodiment of the present invention;
[0071] Figure 2 is a schematic flowchart of a network intrusion detection system according to an embodiment of the present invention;
[0072] Figure 3 is a schematic diagram of the life cycle of a continuous learning controller according to an embodiment of the present invention;
[0073] Figure 4 is a block diagram of the structure of a network intrusion detection system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0074] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0075] A network intrusion detection solution proposed by the embodiments of the present invention effectively improves the adaptability and detection accuracy to dynamic network environments. First, an initial network traffic sample data set is obtained through a network traffic capture tool, and a feature reconstruction model is trained based on this, and the model is used to detect unknown network traffic sample data; subsequently, the detected unknown sample data is type-labeled and the data set is updated; then, the updated data set is used to train and fine-tune the parameters of the malicious network traffic recognition model; finally, network intrusion detection is performed through the trained model, and a closed-loop process of traffic collection, detection, update, and retraining is formed through a continuous learning controller to ensure continuous adaptation to new network traffic and environmental changes, significantly reducing the false alarm and missed alarm rates.
[0076] Refer to Figure 1, showing a step flowchart of a network intrusion detection method according to an embodiment of the present invention. This network intrusion detection method can be applied to a network intrusion detection system (abbreviated as the system), and the network intrusion detection method specifically may include the following steps:
[0077] Step 101, obtain an initial network traffic sample data set.
[0078] First, use a network traffic capture tool to capture network data streams. These tools can record network packets in real time or offline, forming original network traffic files. To ensure the comprehensiveness and representativeness of the data, the capture process needs to cover traffic data in different time periods and different network environments. For example, it can include normal business traffic and potential abnormal traffic. After the capture is completed, the system will use a network traffic analysis tool to parse and extract features from these network traffic files. The parsing process involves decomposing the original data packets into analyzable fields, such as source address, destination address, port number, protocol type, etc., and feature extraction further refines representative statistical features or behavioral features, such as the frequency of data packets, the number of bytes, the connection duration, etc. These features can reflect the behavioral patterns of network traffic and lay the foundation for subsequent model training. After parsing and feature extraction, the system will form a structured initial network traffic sample data set as the data input for the subsequent steps.
[0079] To ensure the quality of the data set, the system may preprocess the data, such as removing noise data or filling in missing values, to improve the integrity and usability of the data. In addition, the construction of the initial network traffic sample data set also needs to consider the diversity of the data, ensuring that it contains various types of network traffic so that the subsequent model can learn a wide range of traffic patterns.
[0080] For example, in an enterprise network environment, the system may capture employees' daily office traffic, server access traffic, and possible external access attempts through a capture tool, forming an initial network traffic sample data set containing various traffic features.
[0081] Step 102, train a feature reconstruction model based on the initial network traffic sample data set, and use the feature reconstruction model to detect unknown network traffic sample data.
[0082] Based on the initial network traffic sample dataset, design and train a deep neural network model as a feature reconstruction model. This model adopts a three-layer architecture, including an input layer, an encoding layer, and a decoding layer. The input layer receives the sample data in the initial network traffic sample dataset, and each sample data contains multiple feature dimensions; the encoding layer compresses the input sample data into a low-dimensional feature representation through a multi-layer perceptron, reducing the data dimension to extract the core features; the decoding layer then reconstructs the low-dimensional feature representation into an output sample data with the same dimension as the input sample data through another multi-layer perceptron. The training objective is to minimize the difference between the input sample data and the output sample data, and usually optimize the model parameters by calculating the reconstruction error.
[0083] After training, the feature reconstruction model can learn the common feature distribution patterns in the initial network traffic sample dataset and use this as a benchmark for subsequent detection. After training is completed, the system records the feature reconstruction model as a fixed detection tool for processing newly collected network traffic sample data. In the detection stage, the system inputs the newly collected network traffic sample data into the feature reconstruction model to obtain the corresponding reconstructed sample data, and calculates the reconstruction error between the two. The error calculation is usually based on a mathematical formula, and a comprehensive error value is obtained by comparing the differences between the original data and the reconstructed data in each dimension. If this error value is greater than the preset threshold, it is determined that the newly collected network traffic sample data is an unknown network traffic sample data because its feature distribution is significantly different from the samples in the initial network traffic sample dataset. For example, in a network environment, if the system detects a newly collected network traffic sample data, the distribution of its packet frequency and byte count is quite different from the normal traffic pattern in the initial network traffic sample dataset, and the calculated reconstruction error exceeds the threshold, then this sample data will be determined as an unknown network traffic sample data, which may represent a new attack pattern or abnormal behavior.
[0084] Step 103, update the initial network traffic sample dataset according to the unknown network traffic sample data.
[0085] First, add the detected unknown network traffic sample data to a dedicated unknown sample repository for temporarily storing and managing these sample data with significant differences in feature distribution from the initial network traffic sample data set. The design of the unknown sample repository aims to facilitate subsequent processing, ensure that the unknown network traffic sample data is not lost, and provide convenience for batch operations. Next, perform network intrusion type annotation on the unknown network traffic sample data in the unknown sample repository. This annotation process can be manual or combined with semi-automated tools, with the purpose of assigning a specific type label to each unknown network traffic sample data, such as normal traffic, a certain known attack type (such as distributed denial of service attack), or a brand-new unknown attack type. The annotation may involve detailed analysis of the sample data, including its behavior patterns, source characteristics, etc., to ensure the accuracy of the label. Since the amount of unknown network traffic sample data is usually small, the annotation cost is relatively low, but its accuracy is crucial for subsequent model training. After the annotation is completed, add these annotated unknown network traffic sample data to the initial network traffic sample data set to form an updated network traffic sample data set. This update process not only expands the coverage of the data set, making it contain more types of network traffic patterns, but also reflects changes in the network environment, such as new attack methods or changes in traffic characteristics. For example, if a set of unknown network traffic sample data is detected during the operation of the system, and its characteristics show high-frequency short connections and are confirmed as a new type of scanning attack after annotation, then after adding these sample data to the initial network traffic sample data set, the updated network traffic sample data set will contain the characteristics of this new attack type, providing more comprehensive data support for subsequent model training.
[0086] Step 104, use the updated network traffic sample data set to train the malicious network traffic recognition model.
[0087] First, at the initial stage of operation, the malicious network traffic recognition model is pre-trained based on the initial network traffic sample dataset to build the initial malicious traffic recognition ability. The pre-training process includes constructing a training set and a sub-task pool. A variety of network traffic types (including normal traffic) are randomly selected from the initial network traffic sample dataset. Support sets and query sets are constructed for each type to form multiple sub-tasks. The system uses a multi-layer perceptron as the model base, randomly initializes the model parameters, and calculates the local loss and global loss through sub-task batches, iteratively updating the model parameters until the model converges or reaches the predefined number of iterations, forming the initial malicious network traffic recognition model. Subsequently, during the operation of the system, when an updated network traffic sample dataset is formed, the system dynamically fine-tunes the malicious network traffic recognition model based on this dataset. The specific steps in the fine-tuning stage include selecting various network traffic sample data from the updated network traffic sample dataset according to the predefined rules to form a sample subset for fine-tuning. Then, based on this sample subset, the parameters of the malicious network traffic recognition model are adjusted to optimize the classification performance of the model for the new type of network traffic sample data. During the fine-tuning process, the system uses the few-shot learning method to ensure that even if the number of newly added sample data is limited, the model performance can be effectively improved. For example, if the updated network traffic sample dataset contains a new type of malicious traffic pattern, such as a low-frequency stealth attack, the system can integrate the characteristics of this pattern into the malicious network traffic recognition model through fine-tuning, enabling it to accurately identify such attacks without misjudging them as normal traffic.
[0088] Step 105, perform network intrusion detection through the trained malicious network traffic recognition model.
[0089] First, use the trained and fine-tuned malicious network traffic recognition model to classify and identify the newly collected network traffic sample data. The trained malicious network traffic recognition model can classify the input network traffic sample data into normal traffic or different types of malicious traffic based on the feature patterns it has learned, such as distributed denial-of-service attacks, data leakage attempts, etc. The recognition process involves inputting the features of the newly collected network traffic sample data into the model, calculating the output classification result through the parameters inside the model, and determining whether there is a network intrusion behavior based on the result. If malicious traffic is detected, the system can trigger corresponding alarm or defense mechanisms to protect network security. In addition, to ensure that the system can adapt to the constantly changing network environment, a continuous learning closed-loop process is also included.
[0090] Specifically, during operation, the system continuously obtains new network traffic sample data through a network traffic capture tool, and uses a feature reconstruction model to detect unknown network traffic sample data among these new data, adding the sample data determined to be unknown to the unknown sample repository. Subsequently, the system labels the sample data in the unknown sample repository with network intrusion types, and adds the labeled sample data to the network traffic sample dataset to form an updated dataset. Based on the updated dataset, the system adjusts the parameters of the malicious network traffic recognition model again to enable it to learn the latest traffic patterns and threat features. The adjusted malicious network traffic recognition model continues to be used to identify malicious traffic in new network traffic sample data, completing network intrusion detection. Through this iterative process, the system forms a continuous learning operation mechanism, ensuring the dynamic update of the detection ability. For example, in an enterprise network, if the system detects a set of abnormal traffic through a trained malicious network traffic recognition model and confirms it as new malware communication, and then updates the model through the continuous learning mechanism, the system can identify and alarm more quickly and accurately when similar traffic appears next time.
[0091] A network intrusion detection solution provided by an embodiment of the present invention includes: obtaining an initial network traffic sample dataset; training a feature reconstruction model based on the initial network traffic sample dataset, and using the feature reconstruction model to detect unknown network traffic sample data; updating the initial network traffic sample dataset according to the unknown network traffic sample data; training a malicious network traffic recognition model using the updated network traffic sample dataset; and performing network intrusion detection through the trained malicious network traffic recognition model.
[0092] In an embodiment of the present invention, by dynamically updating the dataset, the difference between the training data and the actual network environment is reduced. It can identify and integrate new types of traffic data (unknown network traffic sample data) that appear in the actual network environment, making the dataset closer to the real network environment and significantly improving the adaptability to complex and dynamic network environments. By continuously updating and training the malicious network traffic recognition model, it is ensured that the model can learn the latest network traffic patterns and features, optimizing the performance of the model in the real network environment, effectively reducing the false alarm rate and the missed alarm rate, thereby enhancing the ability to identify malicious traffic and improving the accuracy and reliability of network intrusion detection. A dynamic update mechanism is introduced, which can adjust and optimize the model in a timely manner and has the ability of continuous learning, so as to adapt to the changing network environment and make up for the deficiencies of the prior art in dynamic adjustment.
[0093] In an exemplary embodiment of the present invention, one implementation of obtaining the initial network traffic sample dataset is: capturing network data streams through a network traffic capture tool; parsing and extracting features from the network data streams to form the initial network traffic sample dataset.
[0094] A network traffic capture tool is a device or software that can record network data packets in real-time or offline. Its function is to comprehensively collect communication data in the network, including but not limited to the sending and receiving times of data packets, source addresses, destination addresses, port information, etc. These tools can cover traffic data in different network environments to ensure that the captured data is representative and diverse. For example, in an enterprise network environment, a network traffic capture tool is used to capture employees' daily office traffic, server access traffic, and external access attempt traffic, forming a data set containing various traffic patterns. After capturing the network data stream, the data is parsed and feature extracted. The parsing process involves decomposing the original data packets into analyzable fields, such as extracting basic information like the protocol type and data length of the data packets; while feature extraction further refines representative features, such as statistical features like the frequency of data packets, byte count statistics, connection duration, or behavioral features based on time series. These features can reflect the behavioral patterns of network traffic and lay the foundation for subsequent model training and detection. To ensure the quality of the data, the parsed data may be preprocessed, such as removing noise data or filling in missing values, to improve the integrity and usability of the data. In addition, the feature extraction process needs to consider the diversity of the data to ensure that the initial network traffic sample data set contains various types of network traffic patterns, such as normal traffic and potential abnormal traffic, so that the subsequent feature reconstruction model can learn a wide range of feature distributions.
[0095] Since capturing the network data stream through the network traffic capture tool and performing parsing and feature extraction can form a comprehensive and high-quality initial network traffic sample data set, this directly guarantees the data basis for the subsequent feature reconstruction model training, thereby improving the accuracy of detecting unknown network traffic sample data, and further providing important support for the adaptability and accuracy of the entire network intrusion detection method.
[0096] In an exemplary embodiment of the present invention, an implementation manner of training a feature reconstruction model based on the initial network traffic sample data set and using the feature reconstruction model to detect unknown network traffic sample data is as follows: Based on the initial network traffic sample data set, train a deep neural network model as the feature reconstruction model; input the newly collected network traffic sample data into the feature reconstruction model to obtain the corresponding reconstructed sample data; calculate the error value between the newly collected network traffic sample data and the reconstructed sample data; compare the error value with a preset threshold; if the error value is greater than the preset threshold, then determine that the newly collected network traffic sample data is unknown network traffic sample data.
[0097] Based on the initial network traffic sample dataset, a deep neural network model is designed and trained as a feature reconstruction model. This model typically adopts a multi-layer architecture, including an input layer, an encoding layer, and a decoding layer. The input layer receives the sample data in the initial network traffic sample dataset. The encoding layer compresses the input sample data into a low-dimensional feature representation through a multi-layer perceptron to extract the core features. The decoding layer then reconstructs the low-dimensional feature representation into output sample data with the same dimension as the input sample data through another multi-layer perceptron. The training objective is to minimize the difference between the input sample data and the output sample data. Usually, the model parameters are adjusted by optimizing the reconstruction error to ensure that the model can learn the common feature distribution patterns in the initial network traffic sample dataset.
[0098] After training, the feature reconstruction model becomes a fixed detection tool for processing newly collected network traffic sample data. In the detection phase, the newly collected network traffic sample data is input into the feature reconstruction model to obtain the corresponding reconstructed sample data. Subsequently, the error value between the newly collected network traffic sample data and the reconstructed sample data is calculated. This error value is usually based on a mathematical formula and obtains a comprehensive value by comparing the differences between the two sets of data in each dimension to measure the similarity of the feature distribution. Then, this error value is compared with a preset threshold. The preset threshold is a critical value preset according to the feature distribution of the initial network traffic sample dataset and the model training results, and is used to distinguish known and unknown traffic. If the error value is greater than the preset threshold, it is determined that the newly collected network traffic sample data is unknown network traffic sample data because its feature distribution is significantly different from the samples in the initial network traffic sample dataset.
[0099] For example, in an enterprise network environment, if a set of newly collected network traffic sample data is detected, and its packet frequency and connection duration are significantly different from the normal traffic patterns in the initial dataset, and the calculated error value exceeds the preset threshold, then this sample data will be determined as unknown network traffic sample data, which may represent a new attack pattern or abnormal behavior.
[0100] Since a deep neural network model is used as the feature reconstruction model and unknown network traffic sample data is accurately detected by comparing the error value with the preset threshold, it can effectively identify new traffic patterns different from the existing data distribution, thus providing key inputs for data update and model optimization, and further improving the adaptability and detection accuracy of the entire network intrusion detection method for the dynamic network environment.
[0101] In an exemplary embodiment of the present invention, one implementation of updating the initial network traffic sample dataset based on unknown network traffic sample data is as follows: perform network intrusion type annotation on the unknown network traffic sample data; add the annotated unknown network traffic sample data to the initial network traffic sample dataset to form an updated network traffic sample dataset.
[0102] First, perform network intrusion type annotation on the unknown network traffic sample data detected by the feature reconstruction model. This annotation process is a key link in data processing. The purpose is to assign a specific type label to each unknown network traffic sample data so that the subsequent model can correctly identify and learn the features of these data. The annotation can be carried out manually. Network security experts classify according to the behavior patterns, source characteristics, traffic statistical information, etc. of the sample data. For example, it can be marked as normal traffic, a certain known attack type (such as distributed denial of service attack), or a new unknown attack type. In addition, the annotation may also combine semi-automated tools, initially classify through preset rules or auxiliary algorithms, and then confirmed by humans to improve efficiency and accuracy.
[0103] Since the quantity of unknown network traffic sample data is usually small, the cost of annotation is relatively controllable, but its accuracy is crucial for subsequent model training. After annotation, add these annotated unknown network traffic sample data to the initial network traffic sample dataset to form an updated network traffic sample dataset. This update process not only expands the coverage of the dataset, making it contain more types of network traffic patterns, but also can reflect the changes in the network environment in a timely manner, such as new attack methods or the evolution of traffic characteristics.
[0104] For example, in an enterprise network environment, if a group of unknown network traffic sample data is detected, and its characteristics show high-frequency short connections and are confirmed as a new type of scanning attack after annotation, then after adding these annotated sample data to the initial network traffic sample dataset, the updated network traffic sample dataset will contain the characteristics of this new attack type, providing more comprehensive data support for the training of subsequent malicious network traffic recognition models.
[0105] Since by performing network intrusion type annotation on the unknown network traffic sample data and adding it to the initial network traffic sample dataset to form an updated network traffic sample dataset, it can continuously expand the data coverage and reflect the latest network threat characteristics, thereby providing data support closer to the actual environment for subsequent model training, and further enhancing the adaptability and detection accuracy of the entire network intrusion detection method to the dynamic network environment.
[0106] In an exemplary embodiment of the present invention, an implementation of training the malicious network traffic recognition model using the updated network traffic sample data set is as follows: Based on the updated network traffic sample data set, a small-sample learning method is used to fine-tune the parameters of the malicious network traffic recognition model.
[0107] The small-sample learning method is a machine learning technique that can quickly learn new tasks with limited data volume, and is particularly suitable for scenarios in the field of network security where the number of unknown network traffic sample data is small but rapid adaptation is required. In this process, first, various types of network traffic sample data are selected from the updated network traffic sample data set according to a predetermined rule to form a sample subset for fine-tuning. These sample subsets usually contain various types of network traffic data, such as normal traffic and different types of malicious traffic, to ensure that the model can learn diverse feature patterns. Then, based on this sample subset, the parameters of the malicious network traffic recognition model are adjusted, and the classification performance of the model for new types of network traffic sample data is improved by optimizing the objective function (such as the cross-entropy loss function).
[0108] The fine-tuning process usually includes multiple iterative steps. In each iteration, the local loss and the global loss are calculated, and the model parameters are updated according to the preset learning rate until the model performance reaches the expectation or the number of iterations reaches the upper limit.
[0109] For example, in an enterprise network environment, if the updated network traffic sample data set contains sample data of a new type of low-frequency stealth attack, after fine-tuning the parameters of the malicious network traffic recognition model using the small-sample learning method, the model can quickly learn the feature pattern of this attack, so as to accurately identify similar traffic in subsequent detections and not misjudge it as normal traffic.
[0110] Since the parameters of the malicious network traffic recognition model are fine-tuned using the small-sample learning method based on the updated network traffic sample data set, it can quickly learn new traffic patterns with limited new data volume, thereby effectively improving the model's ability to identify unknown threats, and further enhancing the adaptability and detection accuracy of the entire network intrusion detection method in a dynamic network environment.
[0111] In an exemplary embodiment of the present invention, an implementation after network intrusion detection using the trained malicious network traffic recognition model is as follows: Continuously obtain new network traffic sample data; use the feature reconstruction model to detect unknown network traffic in the new network traffic sample data, and update the network traffic sample data set according to the detection results; adjust the parameters of the malicious network traffic recognition model based on the updated network traffic sample data set; perform network intrusion detection on the new network traffic sample data using the adjusted malicious network traffic recognition model.
[0112] Continuously obtain new network traffic sample data during operation. This process is achieved through a network traffic capture tool, which can capture network data streams in real-time or offline, ensuring timely acquisition of the latest network traffic information, including normal traffic and potential abnormal traffic. Then, use a feature reconstruction model to detect unknown network traffic in these new network traffic sample data. The feature reconstruction model is a deep neural network model trained based on the initial or updated network traffic sample data set. By inputting the new network traffic sample data into the model, the corresponding reconstructed sample data is obtained, and the error value between the two is calculated. If the error value is greater than the preset threshold, it is determined that the sample data is an unknown network traffic sample data, indicating that its feature distribution is significantly different from the existing data set. The detection results will be used to update the network traffic sample data set. The specific steps include adding the detected unknown network traffic sample data to the unknown sample repository, performing network intrusion type annotation, and then adding the annotated sample data to the existing network traffic sample data set to form an updated network traffic sample data set. Subsequently, based on the updated network traffic sample data set, parameter adjustment is performed on the malicious network traffic recognition model. This adjustment process usually adopts the few-shot learning method, selects a sample subset from the updated data set, and improves the recognition ability of new types of traffic by optimizing the model parameters. Finally, through the adjusted malicious network traffic recognition model, network intrusion detection is performed on the new network traffic sample data to identify malicious traffic and trigger corresponding alarm or defense mechanisms.
[0113] For example, in an enterprise network environment, if new network traffic sample data is continuously obtained and a set of unknown traffic is detected through the feature reconstruction model, and after annotation, it is confirmed as new malicious software communication traffic. After updating the data set and adjusting the malicious network traffic recognition model, similar traffic can be quickly identified in subsequent detections to avoid potential threats.
[0114] Since a closed-loop continuous learning mechanism is formed by continuously obtaining new network traffic sample data, using the feature reconstruction model to detect unknown traffic, updating the network traffic sample data set, and adjusting the malicious network traffic recognition model, it can timely learn new threat features, thereby effectively improving the adaptability and detection accuracy of the entire network intrusion detection method to the dynamic network environment, and reducing the false alarm and missed alarm rates.
[0115] Based on the above related description of an embodiment of a network intrusion detection method, a network intrusion detection system is introduced below. Refer to Figure 2 , which shows a schematic flowchart of a network intrusion detection system according to an embodiment of the present invention. The execution process of this network intrusion detection system can refer to the following steps:
[0116] Step 1, Detection of unknown network traffic: Train a reconstruction model based on an autoencoder on an existing network traffic sample set, and detect unknown network traffic not included in the existing network traffic sample set based on the reconstruction error.
[0117] Step 2, Identification of malicious network traffic: After collecting a certain amount of unknown network traffic samples, use the few-shot learning algorithm NAML to update and train the malicious network traffic identification model.
[0118] Step 3, Continuous learning controller: Organize the life cycle of the system operation in the order of traffic collection, unknown traffic detection, unknown traffic annotation, retraining of the malicious traffic identification model, and traffic collection, so that the system can continuously adapt to new network traffic and network environment through continuous learning.
[0119] To achieve the detection of unknown network traffic, the specific steps of the unknown network traffic detection in Step 1 are as follows:
[0120] Step 1-1, Network traffic sample collection: First, use a network traffic capture tool to capture and form a network traffic file, and then use a network traffic analysis tool to parse and extract features from the network traffic file to form network traffic samples. Denote the formed network traffic sample set as FS.
[0121] Step 1-2, Detection model training: Use an autoencoder to train a reconstruction model, encode the original samples into a low-dimensional feature space, and reconstruct the samples from the low-dimensional feature space. On this basis, determine whether it is an unknown network traffic sample by testing the deviation between the original sample and the reconstructed sample.
[0122] Step 1-3, Sample detection: Given a network traffic sample x for detection.
[0123] Among them, the network traffic capture tool can be, for example, Wireshark, etc., and the network traffic analysis tool can be, for example, CICFlowMeter, etc.
[0124] Unknown network traffic is a network traffic sample with a large difference in feature distribution from the samples in the existing sample set FS. And for training the detection model, the specific steps of the detection model training in Step 1-2 are as follows:
[0125] Step 1-2-1, Model design: The model is a three-layer deep neural network, and the specific architecture is as follows:
[0126] Input layer: The input of the model is a network traffic sample x ∈ R Kγ1 , where K is the dimension of the feature.
[0127] Encoding layer: Use a multi-layer perceptron to process x and encode it into a hidden vector of dimension H, denoted as h (H < K).
[0128] Decoding layer: Similarly, use a multi-layer perceptron to process h and transform it back into a vector of dimension K, denoted as
[0129] Step 1-2-2, Model training: The model aims to minimize the difference between the input sample x and the reconstructed sample and uses this as the training objective. Denote the trained reconstruction model as RM.
[0130] Furthermore, to determine whether it is an unknown sample, the specific steps of sample detection in Step 1-3 are as follows:
[0131] Step 1-3-1, Sample reconstruction: Input x into the reconstruction model RM to obtain the reconstructed sample
[0132] Step 1-3-2, Unknown determination: Calculate the reconstruction error error based on Equation (1). If error is greater than the specified threshold, then determine x as an unknown sample.
[0133]
[0134] To be able to identify malicious network traffic, the specific steps of malicious network traffic identification in Step 2 are as follows:
[0135] Step 2-1, Training phase: Before starting the life cycle of the continuous learning controller, pre-train the malicious network traffic identification model based on the initial sample set FS;
[0136] Step 2-2, Fine-tuning phase: After starting the life cycle of the continuous learning controller and collecting and annotating a certain amount of unknown samples, re-train the malicious network traffic identification model based on the expanded sample set FS.
[0137] For further design, the specific steps of the fine-tuning phase in Step 2-2 are as follows:
[0138] Step 2-2-1, Fine-tuning set construction: Randomly select K training samples from each network traffic type in FS to form the fine-tuning set DTun.
[0139] Step 2-2-2, Model fine-tuning: Use the fine-tuning set DTun to update the model parameters θ according to Equation (2).
[0140]
[0141] The specific steps of the training phase in Step 2-1 are as follows:
[0142] Step 2-1-1, Training Set Construction: Given the initial sample set FS, construct the training set;
[0143] Step 2-1-2, Model Training: Given the subtask pool TS, train the model.
[0144] The specific steps of the training set construction in Step 2-1-1 are as follows:
[0145] Step 2-1-1-1, Randomly select N network traffic types from FS, where normal network traffic must be included;
[0146] Step 2-1-1-2, Randomly select K training samples for the first network traffic type to form the support set DSup1;
[0147] Step 2-1-1-3, Randomly select another K' training samples for each network traffic type to form the query set DQue1, and finally form the subtask T1=(DSup1, DQue1);
[0148] Step 2-1-1-4, Repeatedly execute Step 2-1-1-2 and Step 2-1-1-3 for M times to form a subtask pool TS={T1, T2,..., T M};
[0149] The specific steps of the model training in Step 2-1-2 are as follows:
[0150] Step 2-1-2-1, Use a multi-layer perceptron as the model base and randomly initialize the model parameters θ;
[0151] Step 2-1-2-2, Extract m subtasks from TS to form the subtask batch TB1;
[0152] Step 2-1-2-3, For each subtask T in TB1 k , use the support set DSupk and calculate the local loss LLock according to Equation (3), where L(...) refers to the cross-entropy loss function, and L(θ; DSupk) refers to the loss of the model with parameters θ on the support set DSupk, and calculate the local model parameters θ k , where α is the learning rate, is the gradient calculation operator, and finally obtain m local model parameters θ1, θ2,..., θ m ;
[0153] LLoc k = L(θ; DSup k ) (3)
[0154]
[0155] Step 2-1-2-4: Use the query set DQuek to calculate the global loss LGlo according to Equation (5), and update the model parameter θ according to Equation (6), where β is the learning rate;
[0156]
[0157] Step 2-1-2-5: Repeatedly execute Step 2-1-2-2, Step 2-1-2-3, and Step 2-1-2-4 until the model converges or reaches the predefined number of iterations. Denote the trained malicious network traffic recognition model as TM.
[0158] Finally, for continuous learning, as Figure 3 shown, a schematic diagram of the life cycle of the continuous learning controller according to an embodiment of the present invention is shown. The continuous learning controller in Step 3 can perform related operations according to the following steps:
[0159] Step 3-1: Traffic collection: During the operation of the system, network traffic samples will be continuously collected;
[0160] Step 3-2: Unknown traffic detection: Based on Step 1-3, perform unknown detection on each newly collected network traffic sample, and add the network traffic samples determined to be unknown to the unknown sample library;
[0161] Step 3-3: Unknown traffic annotation: Label the new samples in the unknown sample library with network intrusion types, and add the labeled new samples to the existing sample set FS;
[0162] Step 3-4: Retraining of the malicious traffic recognition model: Based on Step 2-2, perform few-shot fine-tuning on the malicious traffic recognition model TM using the expanded sample set FS, so that TM can continuously adapt to the new network environment;
[0163] Step 3-5: Life cycle iteration: Return to Step 3-1 to start a new round of continuous learning.
[0164] Among them, unknown traffic detection can be performed in an offline manner. The annotation may be a network intrusion type not included in the existing sample set FS, or a network intrusion type already included in FS (the intrusion environment has changed). Since the number of unknown samples is usually small, the cost of annotation is also low.
[0165] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0166] Referring to Figure 4 , a structural block diagram of a network intrusion detection system according to an embodiment of the present invention is shown. The network intrusion detection system may specifically include the following modules.
[0167] An initial data acquisition module 41, configured to acquire an initial network traffic sample data set;
[0168] An unknown sample detection module 42, configured to train a feature reconstruction model based on the initial network traffic sample data set, and use the feature reconstruction model to detect unknown network traffic sample data;
[0169] An initial data update module 43, configured to update the initial network traffic sample data set according to the unknown network traffic sample data;
[0170] An identification model training module 44, configured to train a malicious network traffic identification model by using the updated network traffic sample data set;
[0171] A network intrusion detection module 45, configured to perform network intrusion detection through the trained malicious network traffic identification model.
[0172] In an exemplary embodiment of the present invention, the initial data acquisition module 41 includes:
[0173] A data stream capture module, configured to capture network data streams through a network traffic capture tool;
[0174] A parsing and extraction module, configured to parse and extract features from the network data streams to form the initial network traffic sample data set.
[0175] In an exemplary embodiment of the present invention, the unknown sample detection module 42 includes:
[0176] A reconstruction model training module, configured to train a deep neural network model as the feature reconstruction model based on the initial network traffic sample data set;
[0177] A reconstructed sample determination module, configured to input newly collected network traffic sample data into the feature reconstruction model to obtain corresponding reconstructed sample data;
[0178] An error value calculation module, configured to calculate an error value between the newly collected network traffic sample data and the reconstructed sample data;
[0179] An error comparison module, configured to compare the error value with a preset threshold;
[0180] An unknown sample determination module, configured to determine that the newly collected network traffic sample data is the unknown network traffic sample data if the error value is greater than the preset threshold.
[0181] In an exemplary embodiment of the present invention, the deep neural network model includes an input layer, an encoding layer, and a decoding layer;
[0182] Wherein, the input layer is configured to receive network traffic sample data, the encoding layer is configured to convert the network traffic sample data into a low-dimensional feature vector, and the decoding layer is configured to reconstruct the low-dimensional feature vector into output sample data.
[0183] In an exemplary embodiment of the present invention, the initial data update module 43 includes:
[0184] An unknown sample annotation module, configured to perform network intrusion type annotation on the unknown network traffic sample data;
[0185] A dataset update module, configured to add the labeled unknown network traffic sample data to the initial network traffic sample dataset to form an updated network traffic sample dataset.
[0186] In an exemplary embodiment of the present invention, the recognition model training module 44 is configured to perform parameter fine-tuning on the malicious network traffic recognition model based on the updated network traffic sample dataset by using a few-shot learning method.
[0187] In an exemplary embodiment of the present invention, the recognition model training module 44 includes:
[0188] A sample subset extraction module, configured to select various types of network traffic sample data from the updated network traffic sample dataset according to a predetermined rule to form a sample subset for fine-tuning;
[0189] A model parameter adjustment module, configured to adjust the parameters of the malicious network traffic recognition model based on the sample subset for fine-tuning.
[0190] In an exemplary embodiment of the present invention, the system further includes:
[0191] A sample continuous acquisition module, configured to continuously acquire new network traffic sample data after the network intrusion detection module 45 performs network intrusion detection through the trained malicious network traffic recognition model;
[0192] A detection and update module, configured to use the feature reconstruction model to detect unknown network traffic in the new network traffic sample data, and update the network traffic sample data set according to the detection result;
[0193] A parameter adjustment module, configured to adjust the parameters of the malicious network traffic recognition model based on the updated network traffic sample data set;
[0194] The network intrusion detection module 45 is further configured to perform network intrusion detection on the new network traffic sample data through the adjusted malicious network traffic recognition model.
[0195] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0196] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0197] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0198] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing terminal devices generate means for implementing the functions specified in Figure 1 one or more flows or multiple flows and / or blocks Figure 1 one or more blocks or multiple blocks.
[0199] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one process Figure 1 or more processes and / or blocks Figure 1 or more blocks specified in the block.
[0200] These computer program instructions may also be loaded onto a computer or other programmable data processing terminal device, such that a series of operational steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 or more processes and / or blocks Figure 1 or more blocks specified in the block.
[0201] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0202] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.
[0203] The above has introduced in detail a network intrusion detection method and a network intrusion detection system provided by the present invention. Specific examples are used in this text to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A network intrusion detection method, characterized in that The method includes: Obtaining an initial network traffic sample data set; Training a feature reconstruction model based on the initial network traffic sample data set, and using the feature reconstruction model to detect unknown network traffic sample data; Updating the initial network traffic sample data set according to the unknown network traffic sample data; Training a malicious network traffic recognition model using the updated network traffic sample data set; Performing network intrusion detection through the trained malicious network traffic recognition model.
2. The method according to claim 1, wherein The obtaining of the initial network traffic sample data set includes: Capturing network data streams through a network traffic capture tool; Parsing and extracting features from the network data streams to form the initial network traffic sample data set.
3. The method according to claim 1, wherein The training of the feature reconstruction model based on the initial network traffic sample data set and the use of the feature reconstruction model to detect unknown network traffic sample data include: Training a deep neural network model as the feature reconstruction model based on the initial network traffic sample data set; Inputting newly collected network traffic sample data into the feature reconstruction model to obtain corresponding reconstructed sample data; Calculating the error value between the newly collected network traffic sample data and the reconstructed sample data; Comparing the error value with a preset threshold; If the error value is greater than the preset threshold, determining that the newly collected network traffic sample data is the unknown network traffic sample data.
4. The method according to claim 3, wherein The deep neural network model includes an input layer, an encoding layer, and a decoding layer; Among them, the input layer is used to receive network traffic sample data, the encoding layer is used to convert the network traffic sample data into a low-dimensional feature vector, and the decoding layer is used to reconstruct the low-dimensional feature vector into output sample data.
5. The method according to claim 1, wherein The updating of the initial network traffic sample data set according to the unknown network traffic sample data includes: Labeling the network intrusion types of the unknown network traffic sample data; Adding the labeled unknown network traffic sample data to the initial network traffic sample data set to form an updated network traffic sample data set.
6. The method according to claim 1, characterized in that, The training of the malicious network traffic recognition model using the updated network traffic sample data set includes: Based on the updated network traffic sample data set, using a small sample learning method to fine-tune the parameters of the malicious network traffic recognition model.
7. The method according to claim 6, wherein The using of the small sample learning method to fine-tune the parameters of the malicious network traffic recognition model based on the updated network traffic sample data set includes: Selecting various network traffic sample data from the updated network traffic sample data set according to a predetermined rule to form a sample subset for fine-tuning; Adjusting the parameters of the malicious network traffic recognition model based on the sample subset for fine-tuning.
8. The method according to claim 1, characterized in that, After performing network intrusion detection through the trained malicious network traffic recognition model, the method further includes: Continuously obtaining new network traffic sample data; Using the feature reconstruction model to detect unknown network traffic in the new network traffic sample data, and updating the network traffic sample data set according to the detection results; Adjust the parameters of the malicious network traffic recognition model based on the updated network traffic sample dataset; Perform network intrusion detection on the new network traffic sample data through the adjusted malicious network traffic recognition model.
9. A network intrusion detection system, characterized in that, The system includes: An initial data acquisition module, configured to acquire an initial network traffic sample dataset; An unknown sample detection module, configured to train a feature reconstruction model based on the initial network traffic sample dataset and use the feature reconstruction model to detect unknown network traffic sample data; An initial data update module, configured to update the initial network traffic sample dataset according to the unknown network traffic sample data; A recognition model training module, configured to train a malicious network traffic recognition model using the updated network traffic sample dataset; A network intrusion detection module, configured to perform network intrusion detection through the trained malicious network traffic recognition model.
10. An electronic device, characterized in that, Includes: One or more processors; And One or more machine-readable media having instructions stored thereon, which when executed by the one or more processors cause the electronic device to perform the network intrusion detection method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, The computer program stored therein causes the processor to perform the network intrusion detection method according to any one of claims 1 to 8.