Threat detection method for network transmission and process activity

Through data preprocessing, feature fusion, and genetic algorithms, the threat rule base and KNN matching analysis are constructed, which solves the accuracy of network transmission and process activity threat detection, and achieves efficient and accurate threat detection.

CN120301635AActive Publication Date: 2025-07-11BEIJING YOUANXIN NETWORK TECHNOLOGY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510419231.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-11
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

The existing threat detection methods for network transmission and process activities are insufficient in terms of accuracy. False alarms and underreporting problems are common, making it difficult to achieve efficient and accurate detection in real time or accurate time.

Method used

By comprehensively collecting and preprocessing data, extracting traffic characteristics and physical characteristics, fusion, and using genetic algorithms to build a threat rule base, optimizing distance difference calculation, and combining KNN algorithm for matching analysis to achieve threat detection.

Benefits of technology

It improves the accuracy and reliability of detection, reduces false alarms and missed reports, adapts to changes in different network environments and attack methods, and is suitable for real-time threat detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301635A_ABST
    Figure CN120301635A_ABST
Patent Text Reader

Abstract

The invention provides a threat detection method and system for network transmission and process activity, and relates to the technical field of network security, and the method comprises the steps: collecting data of the network transmission and process activity, and carrying out the preprocessing of the data, thereby obtaining the data of the network transmission and process activity; extracting flow characteristics and physical characteristics according to data of network transmission and process activities; and performing fusion according to the extracted flow features and physical features to obtain fused feature data, constructing a threat rule base through a genetic algorithm according to historical data, obtaining normal behaviors and known threat modes, and setting a first reference point as a feature mean vector of the normal behavior mode and a second reference point as a feature mean vector of the known threat mode. According to the method, efficient and accurate detection of threats in network transmission and process activities is realized through comprehensive collection and preprocessing of data, extraction of key features, feature fusion, construction of a threat rule base, optimization of distance difference calculation and matching analysis by using KNN.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a threat detection method for network transmission and process activities. Background Art

[0002] With the rapid development of information technology, the network has become an indispensable infrastructure for the operation of modern society and personal life. The wide application of network technology has greatly improved the information transmission efficiency, promoted resource sharing and collaborative work. However, network security issues have become increasingly prominent, becoming a key factor restricting the further development of the network. Abnormal behaviors in network transmission and process activities, such as data leakage, malware infection, DDoS attacks, etc., have become the main threat sources of network security. These threats may not only lead to the leakage of personal privacy and the loss of enterprise assets, but also have a serious impact on national security and social stability.

[0003] There are various types of network threats, including viruses, Trojans, worms, ransomware, spyware, etc., and new threat forms keep emerging. The data generated by network transmission and process activities is huge, and the data formats are diverse, including text, images, videos, etc. Normal behaviors and abnormal behaviors in the data are often intertwined, making it difficult to distinguish them through simple rules or patterns. Network security threats are real-time, requiring threat detection systems to be able to process and analyze data in real-time or near real-time, and discover and respond to threats in a timely manner. The accuracy of threat detection is an important indicator for evaluating the performance of detection systems. However, due to the diversity of threats and the complexity of data, some existing detection methods have deficiencies in terms of accuracy. False positives and false negatives are common problems in threat detection, resulting in the waste of security resources or the exposure of security vulnerabilities. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a threat detection method for network transmission and process activities, which realizes the efficient and accurate detection of threats in network transmission and process activities by comprehensively collecting and preprocessing data, extracting key features, feature fusion, constructing a threat rule library, optimizing the calculation of distance difference, and using KNN for matching analysis.

[0005] To solve the above technical problems, the technical solution of the present invention is as follows:

[0006] In a first aspect, a threat detection method for network transmission and process activities, the method includes:

[0007] Collect data on network transmission and process activities, and preprocess the data to obtain data on network transmission and process activities;

[0008] Extract traffic features and physical features according to the data on network transmission and process activities;

[0009] Fuse the extracted traffic features and physical features to obtain fused feature data;

[0010] Based on historical data, construct a threat rule library through genetic algorithms, obtain normal behaviors and known threat patterns, set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern;

[0011] For each fused feature data, calculate the distance differences from the two reference points, and optimize the non-linear transformation of the distance differences through the L-BFGS algorithm to generate new features;

[0012] According to the threat rule library, the new features are analyzed through KNN matching. By identifying threat data, the matching results are obtained to achieve threat detection of network transmission and process activities.

[0013] Furthermore, collect data on network transmission and process activities, preprocess the data to obtain data on network transmission and process activities, including:

[0014] Collect the original data in network transmission and process activities;

[0015] Clean the collected original data to remove noise, outliers, and incorrect data, and obtain the preprocessed data on network transmission and process activities.

[0016] Furthermore, based on the data of network transmission and process activities, extract traffic features and physical features, including:

[0017] Extract traffic features from network transmission and physical features from process activities according to the preprocessed data;

[0018] Through extracting traffic features and physical features, perform dimensionality reduction to obtain optimized traffic features and physical features.

[0019] Furthermore, fuse the extracted traffic features and physical features to obtain fused feature data, including:

[0020] Based on the extracted traffic features and physical features, perform feature selection to obtain the selected feature data;

[0021] For the selected feature data, perform weighted fusion, directly concatenate the traffic features and physical features into a long vector, and generate fused feature data.

[0022] Furthermore, based on historical data, construct a threat rule library through genetic algorithms, obtain normal behaviors and known threat patterns, set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern, including:

[0023] Generate an initial population through a genetic algorithm based on historical network traffic and process activity data, where each individual represents a potential threat rule;

[0024] Perform crossover and mutation operations on the selected individuals to generate new individuals. The crossover operation produces new individuals by swapping parts of the genes of two individuals, and the mutation operation introduces diversity by randomly changing certain genes of an individual. Repeat the evaluation and optimization process until the maximum number of iterations is reached;

[0025] Organize the optimized individuals into a threat rule library;

[0026] According to the normal behavior patterns and known threat patterns in the threat rule library, set the feature mean vector of the normal behavior pattern as the first reference point B1, and the feature mean vector of the known threat pattern as the second reference point B2;

[0027] According to each feature in the normal behavior pattern, calculate the average value of all samples on this feature to obtain the feature mean vector B1 of the normal behavior pattern. According to each feature in the threat pattern, calculate the average value of all samples on this feature to obtain the feature mean vector B2 of the threat pattern.

[0028] Furthermore, for each fused feature data, calculate the distance difference from the two reference points, and optimize the non-linear transformation of the distance difference through the L-BFGS algorithm to generate new features, including:

[0029] According to each fused feature data, calculate the Euclidean distance from the normal behavior reference point, calculate the Euclidean distance from the threat reference point, and obtain the distance difference between the two reference points through Δd = d2 - d1;

[0030] Construct a non-linear transformation function of the distance difference according to the distance difference between the two reference points;

[0031] Obtain the optimized non-linear transformation function by optimizing the objective function;

[0032] Transform each distance difference Δd through the optimized non-linear transformation function to obtain a new feature value.

[0033] Furthermore, according to the threat rule library, the new features are analyzed by KNN for matching, and the matching results are obtained by identifying threat data to achieve threat detection of network transmission and process activities, including:

[0034] Use the threat rule library and the new feature data to calculate the distance between the new features and each feature vector in the threat rule library using the Euclidean distance;

[0035] Based on the distances of each feature vector, using the distance matrix and the value of K, where the value of K represents the number of nearest neighbors to be considered in the KNN algorithm, obtain the statistical results of threat types;

[0036] According to the statistical results of threat types, check whether there are the quantities of threat types in the statistical results of threat types to obtain the matching results;

[0037] Based on the matching results, realize the threat detection of network transmission and process activities.

[0038] In a second aspect, a threat detection system for network transmission and process activities includes:

[0039] An acquisition module, configured to collect data on network transmission and process activities, preprocess the data, and obtain the data on network transmission and process activities;

[0040] An extraction module, configured to extract traffic features and physical features according to the data on network transmission and process activities; fuse the extracted traffic features and physical features to obtain fused feature data;

[0041] A processing module, configured to construct a threat rule library through a genetic algorithm according to historical data, obtain normal behaviors and known threat patterns, set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern; for each fused feature data, calculate the distance differences from the two reference points, and optimize the non-linear transformation of the distance differences through the L-BFGS algorithm to generate new features; according to the threat rule library, perform matching analysis on the new features through KNN, and identify threat data to obtain matching results.

[0042] In a third aspect, a computing device includes:

[0043] One or more processors;

[0044] A storage device, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enable the one or more processors to implement the method described above.

[0045] In a fourth aspect, a computer-readable storage medium stores a program, and when the program is executed by a processor, the method described above is implemented.

[0046] The above solution of the present invention has at least the following beneficial effects:

[0047] Improve detection accuracy. Through multi-source data fusion and feature extraction, it can more comprehensively reflect the true state of network activities and improve the detection accuracy. Optimize the distance difference calculation and non-linear transformation to enhance the discrimination ability of new features, which helps to more accurately identify threats. Use genetic algorithms to construct a flexible threat rule base that can adapt to changes in different network environments and attack methods. KNN matching analysis is characterized by fast speed and is suitable for real-time threat detection. Through precise feature extraction and matching analysis, reduce false positives and false negatives, and improve reliability. The construction of the threat rule base is based on historical data and genetic algorithm optimization, which helps to more accurately identify normal behaviors and threat behaviors. This method combines technical means such as multi-source data fusion, genetic algorithms, and KNN matching analysis to provide strong adaptability, high efficiency, and low false positive rate for network transmission and process activity threat detection, providing strong support for network security protection. Brief Description of the Drawings

[0048] Figure 1 It is a schematic flowchart of a threat detection method for network transmission and process activities provided by an embodiment of the present invention.

[0049] Figure 2 It is a schematic diagram of a threat detection system for network transmission and process activities provided by an embodiment of the present invention. Detailed Embodiment

[0050] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art.

[0051] As Figure 1 shown, an embodiment of the present invention proposes a threat detection method for network transmission and process activities, and the method includes the following steps:

[0052] Step 11: Collect data on network transmission and process activities, and preprocess the data to obtain data on network transmission and process activities;

[0053] Step 12: Extract traffic features and physical features according to the data on network transmission and process activities;

[0054] Step 13: Perform fusion on the extracted traffic features and physical features to obtain fusion feature data;

[0055] Step 14: Based on historical data, construct a threat rule base through a genetic algorithm to obtain normal behaviors and known threat patterns. Set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern;

[0056] Step 15: For each fused feature data, calculate the distance difference from the two reference points, and optimize the non - linear transformation of the distance difference through the L - BFGS algorithm to generate new features;

[0057] Step 16: According to the threat rule base, perform matching analysis on the new features through KNN. By identifying threat data, obtain the matching results to achieve threat detection for network transmission and process activities.

[0058] In the embodiment of the present invention, by collecting data on network transmission and process activities, comprehensively covering various behaviors in the network environment, extracting traffic features and physical features can capture key information for network transmission and process activities, which helps to more accurately identify abnormal behaviors. These features can reflect the essential features of network activities. Fusing traffic features and physical features can comprehensively consider multiple aspects of network transmission and process activities, improve the comprehensiveness of threat detection, and the fused feature data can enhance the ability to identify abnormal behaviors. Constructing a threat rule base through a genetic algorithm can learn normal behaviors and known threat patterns from historical data, improve the intelligence level of threat detection, and set the feature mean vectors of the normal behavior pattern and the known threat pattern as reference points. Calculating the distance difference between the fused feature data and the reference points can sensitively reflect the differences between data, which helps to identify potential threats. Optimizing the non - linear transformation of the distance difference through the L - BFGS algorithm can more accurately reflect the complex relationships between data and improve the accuracy of threat detection. The KNN algorithm has the characteristics of simplicity, effectiveness, and easy implementation, and is suitable for real - time or quasi - real - time threat detection scenarios. By performing matching analysis on the new features through KNN, threat data can be accurately identified, and the matching results can be obtained to achieve threat detection for network transmission and process activities.

[0059] In a preferred embodiment of the present invention, the above - mentioned Step 11 may include:

[0060] Step 111: Collect the original data in network transmission and process activities;

[0061] Step 112: Clean the collected original data to remove noise, outliers, and incorrect data, and obtain the pre - processed data of network transmission and process activities.

[0062] In the embodiments of the present invention, the data cleaning process greatly improves the quality of data. The original data often contains a large amount of noise, outliers, and incorrect data, which will interfere with the subsequent analysis and processing. By cleaning and removing the useless data, the dimension and computational amount of the data can be reduced, thereby improving the processing speed, enabling the system to respond to security events more quickly. By improving data quality, enhancing processing efficiency, and promoting data integration and expansion, etc., it provides strong support for threat detection of network transmission and process activities.

[0063] In a specific embodiment of the present invention, the specific steps include:

[0064] Step 111, obtain process activity data through the collected network transmission data, such as network traffic, packet information, connection logs, etc., and deploy data collection agents at network boundaries and key servers to ensure the comprehensiveness and real-time nature of the data.

[0065] Step 112, clean the collected original data, correct, delete, or mark the detected outliers to avoid interference with subsequent analysis, check the integrity, consistency, and rationality of the data, such as IP address format, timestamp order, etc., and convert the data into a unified format and unit.

[0066] In a preferred embodiment of the present invention, the above step 12 may include:

[0067] Step 121, extract traffic characteristics in network transmission and physical characteristics in process activities according to the preprocessed data;

[0068] Step 122, perform dimensionality reduction processing through the extracted traffic characteristics and physical characteristics to obtain optimized traffic characteristics and physical characteristics.

[0069] In the embodiments of the present invention, by extracting traffic characteristics in network transmission, such as packet size, transmission frequency, IP address, port number, etc., to depict the patterns and rules of network behavior, and extracting physical characteristics in process activities, such as CPU usage rate, memory occupancy, process status, file access records, etc., to reflect the running status and potential risks of the process. Through dimensionality reduction processing, redundant information in the characteristics can be removed, the dimension and computational amount of the data can be reduced, and the optimized characteristics reflect the essential characteristics of network behavior and process status. Dimensionality reduction processing can retain the key information in the characteristics, while enhancing the discrimination ability between the characteristics. The dimensionality-reduced characteristic data has a smaller scale and faster processing speed.

[0070] In a specific embodiment of the present invention, the specific steps include:

[0071] Step 121, monitor the CPU usage, memory occupancy, disk and other system resource usage of the process, record the status changes such as the creation, execution, and termination of the process, as well as the communication situation between processes, analyze the file access behavior of the process, including operations such as reading, writing, and deleting, and information such as the file path, size, and type accessed. Based on the process activity data, detect abnormal behaviors such as malware execution and unauthorized access, and extract key features in network transmission and process activities.

[0072] Step 122, remove highly correlated redundant features, select features that contribute more to threat detection, project the original features into a low-dimensional space through linear transformation, reduce the feature dimension while retaining the main information, and perform standardization or normalization processing on the reduced-dimensional features so that different features have the same scale and enhance the discrimination ability of the features.

[0073] In a preferred embodiment of the present invention, the above step 13 may include:

[0074] Step 131, perform feature selection based on the extracted traffic features and physical features to obtain the selected feature data;

[0075] Step 132, perform weighted fusion on the selected feature data, directly concatenate the traffic features and physical features into a long vector, and generate the fused feature data.

[0076] In the embodiments of the present invention, by removing redundant, irrelevant or noisy features, feature selection improves the overall quality of the data, reduces the data dimension, reduces the storage and computing requirements, improves the efficiency of data processing, and has a significant effect when dealing with large-scale data sets or real-time data. The selected key features reflect the essential features and laws of the data, and the refined feature set is easier to understand and interpret, reducing the threshold of data analysis. The traffic features and physical features are fused into a long vector, and weighted fusion allows for flexible adjustment according to the importance of different features, making the fused feature data meet the actual analysis requirements and improving the utilization rate of information.

[0077] In a specific embodiment of the present invention, the specific steps include:

[0078] Step 131, through the extracted traffic features and physical features, select the features that contribute more to the target variable and have lower redundancy according to the results of feature evaluation and redundancy check, and form a new feature set with the selected features.

[0079] Step 132, the selected feature data, through Obtain the standardized result, where z is the standardized value, x is the original data point, μ is the mean of the dataset, and σ is the standard deviation of the dataset, so that different features have the same scale. According to the evaluation result of the feature importance, assign a weight to each feature, and the weight can be determined based on the feature importance score, correlation coefficient, or other business logics. The weighted traffic features and physical features are directly concatenated into a long vector, and the concatenated long vector is used as the fusion feature data.

[0080] In a preferred embodiment of the present invention, step 14 may include:

[0081] Step 141, generate an initial population through a genetic algorithm according to historical network traffic and process activity data, and each individual represents a potential threat rule;

[0082] Step 142, perform crossover and mutation operations on the selected individuals to generate new individuals. The crossover operation generates new individuals by exchanging part of the genes of two individuals, and the mutation operation introduces diversity by randomly changing some genes of the individuals. Repeat the evaluation and optimization process until the maximum number of iterations is reached;

[0083] Step 143, organize the optimized individuals into a threat rule library;

[0084] Step 144, according to the normal behavior pattern and known threat pattern in the threat rule library, set the feature mean vector of the normal behavior pattern as the first reference point B1, and the feature mean vector of the known threat pattern as the second reference point B2;

[0085] Step 145, according to the normal behavior pattern, through Obtain the feature mean vector B1 of the normal behavior pattern, where f 1i represents the j-th feature value of the i-th sample, N n is the number of samples of the normal behavior pattern, M is the number of features of each sample, i is the index of the sample, and j is the index of the feature. According to the threat pattern, through Obtain the feature mean vector B2 of the threat pattern, where g 1i represents the j-th feature value of the i-th sample, N t is the number of samples of the known threat pattern, M is the number of features of each sample, i is the index of the sample, and j is the index of the feature.

[0086] In the embodiments of the present invention, the crossover operation generates new individuals by exchanging parts of the genes of two individuals to explore new regions in the solution space. The mutation operation introduces diversity by randomly changing some genes of an individual to prevent the population from falling into a local optimal solution. The optimized individuals are sorted into a threat rule library to make the rules more structured and facilitate management and use. The characteristic mean vectors of the normal behavior pattern and the known threat pattern are set as reference points, providing a reference standard for subsequent anomaly detection. By comparing the difference between the characteristic vector of the new data and the reference point, data points deviating from the normal behavior pattern or approaching the threat pattern can be detected in a timely manner, thus triggering the anomaly detection mechanism and improving the efficiency of anomaly detection.

[0087] In a specific embodiment of the present invention, the specific steps include:

[0088] Step 141: By collecting historical network traffic data and process activity data, define the structure of the threat rules, randomly generate a certain number of individuals to form an initial population. The genes of each individual (i.e., the specific parameters of the threat rules) can be randomly set or set based on the statistical information in the historical data.

[0089] Step 142: Select the individuals with better performance according to the fitness of the individuals (such as the number of detected threats, false alarm rate, etc.). Select two individuals, exchange their partial genes (i.e., partial parameters of the threat rules) to generate new individuals. These new individuals inherit some characteristics of the parent individuals. Randomly select some genes of an individual for mutation, that is, change the values of these genes. The mutation operation helps to introduce diversity and prevent the population from falling into a local optimal solution. Evaluate the newly generated individuals, and repeat the processes of selection, crossover, mutation, and evaluation until the maximum iteration number is reached or other stopping conditions are met.

[0090] Step 143: Select the individuals with the highest fitness from the optimized population. The threat rules represented by these individuals have higher accuracy and effectiveness. The selected individuals are decoded into threat rules and sorted into a threat rule library.

[0091] Step 144: Extract the normal behavior pattern and the known threat pattern from the threat rule library. The normal behavior pattern represents the normal activity characteristics in the network, and the known threat pattern represents the known malicious activity characteristics. Calculate the characteristic mean vector of the normal behavior pattern as the first reference point, and calculate the characteristic mean vector of the known threat pattern as the second reference point.

[0092] Step 145: For each sample in the normal behavior pattern, extract its characteristic value. According to the normal behavior pattern, calculate through the above formula to obtain the characteristic mean vector of the normal behavior pattern. For the threat pattern, calculate through the above formula to obtain the characteristic mean vector of the threat pattern.

[0093] In a preferred embodiment of the present invention, step 15 may include:

[0094] Step 151, according to each fused feature data, through calculate the Euclidean distance of the normal behavior reference point, where x j is the j-th eigenvalue of the fused feature data vector x, and b 1j is the j-th eigenvalue of the normal behavior reference point B1, j is the index of the feature, through calculate the Euclidean distance of the threat reference point, where b 2j is the j-th eigenvalue of the normal behavior reference point B2, j is the index of the feature, and through Δd = d2 - d1, obtain the distance difference between the two reference points;

[0095] Step 152, according to the distance difference between the two reference points, construct a non-linear transformation function of the distance difference f(Δd; θ) = max(0, θ1Δd + θ2), where θ = [θ1, θ2] is the parameter to be optimized;

[0096] Step 153, through the objective function obtain the optimized non-linear transformation function, where N is the number of samples, l is the serial number of the sample, Δd l is the distance difference of the l-th sample, and y l is the classification label y of the l-th sample l = 1 indicates threat, and y l = 0 indicates normal;

[0097] Step 154, transform each distance difference Δd through the optimized non-linear transformation function f(Δd; θ) to obtain a new eigenvalue.

[0098] In the embodiment of the present invention, by calculating the Euclidean distance, the differences between the fused feature data and the normal behavior reference point and the threat reference point can be quantified. The distance difference Δd reflects the relative positions of the data points with respect to the two reference points, which is helpful for subsequent classification and recognition. The non-linear transformation function can capture the complex relationship between the distance difference and the classification label, improving the classification accuracy. By optimizing the parameter θ, the transformation function can better adapt to the data distribution. By optimizing the objective function, the non-linear transformation function can better fit the data, improving the classification accuracy. The optimization algorithm can automatically adjust the parameters, and the transformed new eigenvalue can better represent the relative relationship between the data point and the two reference points, enhancing the feature representation ability of the data.

[0099] In a specific embodiment of the present invention, the specific steps include:

[0100] Step 151: According to each fused feature data, calculate the Euclidean distance of the normal behavior reference point through the above formula, calculate the Euclidean distance of the threat reference point through the above formula, and obtain the distance difference between the two reference points through Δd = d2 - d1.

[0101] Step 152: Construct a non-linear transformation function of the distance difference according to the distance difference between the two reference points.

[0102] Step 153: Calculate through the above formula to obtain the optimized non-linear transformation function.

[0103] Step 154: For the distance difference Δd of each sample i , use the optimized non-linear transformation function f(Δd i ; θ) for transformation to obtain a new eigenvalue.

[0104] In a preferred embodiment of the present invention, the above step 16 may include:

[0105] Step 161: Calculate the distance between the new feature and each feature vector in the threat rule library using the Euclidean distance through the threat rule library and the new feature data;

[0106] Step 162: According to the distance of each feature vector, obtain the statistical result of the threat type through the distance matrix and the K value, where the K value represents the number of nearest neighbors to be considered in the KNN algorithm;

[0107] Step 163: Check whether there is a threat type quantity in the threat type statistical result according to the statistical result of the threat type to obtain a matching result;

[0108] Step 164: According to the matching result, realize the threat detection of network transmission and process activities.

[0109] In the embodiment of the present invention, by calculating the Euclidean distance, the similarity between the new feature and each feature vector in the threat rule library can be quantified. The distance information is used in the subsequent KNN classification algorithm to generate the threat type of the new feature. The KNN algorithm is based on the locality principle, that is, similar samples may belong to the same category. By selecting the nearest K neighbors, classification can be carried out more effectively. The selection of the K value can be adjusted according to the actual situation to adapt to different data sets and classification requirements. Through statistics and threshold judgment, a clear classification result can be obtained, that is, whether the new feature belongs to a certain threat type. By considering the voting results of multiple nearest neighbors, the influence of a single outlier on the classification result can be reduced. Through threat detection, potential security threats can be discovered and processed in time, enhancing the security of the network system.

[0110] In a specific embodiment of the present invention, the specific steps include:

[0111] Step 161: Based on the threat rule library and the new feature data, obtain the distances between the new feature and each feature vector in the threat rule library according to Step 151.

[0112] Step 162: Sort the distances in the distance matrix or list to obtain the K feature vectors with the smallest distances and their corresponding threat types. Initialize a counter to count the occurrence times of each threat type. The statistics stored in the counter are the statistical results of each threat type.

[0113] Step 163: Set a threshold. For example, K / 2 means that more than half of the nearest neighbors belong to a certain threat type. Traverse the statistical results to check whether the number of a certain threat type exceeds the set threshold. If the number of a certain threat type exceeds the threshold, the new feature matches that threat type; if the number of no threat type exceeds the threshold, the new feature does not match any threat type or belongs to the normal type.

[0114] Step 164: Define threat detection metrics and rules by collecting and integrating multi-source data; perform multi-source data correlation analysis according to the threat detection metrics and rules; formulate and execute response strategies based on the analysis results to achieve threat detection of network transmission and process activities.

[0115] As Figure 2 shown, an embodiment of the present invention further provides a threat detection system 20 for network transmission and process activities, including:

[0116] An acquisition module 21, configured to collect data on network transmission and process activities, preprocess the data, and obtain data on network transmission and process activities;

[0117] An extraction module 22, configured to extract traffic features and physical features according to the data on network transmission and process activities; fuse the extracted traffic features and physical features to obtain fused feature data;

[0118] A processing module 23, configured to construct a threat rule library through a genetic algorithm according to historical data, obtain normal behaviors and known threat patterns, set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern; for each fused feature data, calculate the distance difference from the two reference points, and optimize the non-linear transformation of the distance difference through the L-BFGS algorithm to generate new features; according to the threat rule library, perform matching analysis on the new features through KNN, and obtain matching results by identifying threat data.

[0119] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A threat detection method for network transmission and process activities, characterized in that, The method includes: Collect data on network transmission and process activities, preprocess the data to obtain data on network transmission and process activities; Extract traffic features and physical features based on the data on network transmission and process activities; Fuse the extracted traffic features and physical features to obtain fused feature data; Based on historical data, construct a threat rule library through a genetic algorithm, obtain normal behaviors and known threat patterns, set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern; For each piece of fused feature data, calculate the distance difference from the two reference points, and optimize the non-linear transformation of the distance difference through the L-BFGS algorithm to generate new features; According to the threat rule library, the new features are analyzed by KNN for matching, and by identifying threat data, a matching result is obtained to achieve threat detection of network transmission and process activities.

2. The threat detection method for network transmission and process activities according to claim 1, wherein Collect data on network transmission and process activities, preprocess the data to obtain data on network transmission and process activities, including: Collect raw data in network transmission and process activities; Clean the collected raw data to remove noise, outliers, and incorrect data to obtain preprocessed data on network transmission and process activities.

3. The threat detection method for network transmission and process activities according to claim 2, wherein Extract traffic features and physical features based on the data on network transmission and process activities, including: Extract traffic features in network transmission and physical features in process activities based on the preprocessed data; Perform dimensionality reduction processing by extracting traffic features and physical features to obtain optimized traffic features and physical features.

4. The threat detection method for network transmission and process activities according to claim 3, characterized in that, Fuse the extracted traffic features and physical features to obtain fused feature data, including: Perform feature selection based on the extracted traffic features and physical features to obtain selected feature data; Perform weighted fusion on the selected feature data, directly concatenate the traffic features and physical features into a long vector to generate fused feature data.

5. The threat detection method for network transmission and process activities according to claim 4, characterized in that, Based on historical data, construct a threat rule library through a genetic algorithm, obtain normal behaviors and known threat patterns, set the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern, including: Generate an initial population through a genetic algorithm based on historical network traffic and process activity data, and each individual represents a potential threat rule; Perform crossover and mutation operations on the selected individuals to generate new individuals. The crossover operation generates new individuals by exchanging part of the genes of two individuals, and the mutation operation introduces diversity by randomly changing some genes of the individuals. Repeat the evaluation and optimization process until the maximum number of iterations is reached; Organize the optimized individuals into a threat rule library; According to the normal behavior pattern and known threat pattern in the threat rule library, set the feature mean vector of the normal behavior pattern as the first reference point B1, and the feature mean vector of the known threat pattern as the second reference point B2; According to each feature in the normal behavior pattern, calculate the average value of all samples on this feature to obtain the feature mean vector B1 of the normal behavior pattern. According to each feature in the threat pattern, calculate the average value of all samples on this feature to obtain the feature mean vector B2 of the threat pattern.

6. The threat detection method for network transmission and process activities according to claim 5, wherein For each fused feature data, calculate the distance difference from the two reference points, and optimize the non-linear transformation of the distance difference through the L-BFGS algorithm to generate new features, including: According to each fused feature data, calculate the Euclidean distance to the normal behavior reference point, calculate the Euclidean distance to the threat reference point, and obtain the distance difference between the two reference points through Δd = d2 - d1; According to the distance difference between the two reference points, construct a non-linear transformation function of the distance difference; Obtain the optimized non-linear transformation function by optimizing the objective function; Transform each distance difference Δd through the optimized non-linear transformation function to obtain a new eigenvalue.

7. The threat detection method for network transmission and process activities according to claim 6, wherein According to the threat rule library, the new features are analyzed by KNN for matching. By identifying threat data, the matching result is obtained to achieve threat detection of network transmission and process activities, including: Through the threat rule library and the new feature data, use the Euclidean distance to calculate the distance between the new feature and each feature vector in the threat rule library; According to the distance of each feature vector, through the distance matrix and the K value, obtain the statistical result of the threat type, where the K value represents the number of nearest neighbors to be considered in the KNN algorithm; According to the statistical result of the threat type, check whether there is a threat type count in its threat type statistical result to obtain the matching result; According to the matching result, achieve threat detection of network transmission and process activities.

8. A threat detection system for network transmission and process activities, the system implementing the method according to any one of claims 1 to 7, characterized in that, Including: An acquisition module for collecting data on network transmission and process activities, preprocessing the data to obtain data on network transmission and process activities; An extraction module for extracting traffic features and physical features according to the data on network transmission and process activities; Fuse the extracted traffic features and physical features to obtain fused feature data; A processing module for constructing a threat rule library through a genetic algorithm according to historical data, obtaining normal behavior and known threat patterns, setting the first reference point as the feature mean vector of the normal behavior pattern, and the second reference point as the feature mean vector of the known threat pattern; for each fused feature data, calculate the distance difference from the two reference points, and optimize the non-linear transformation of the distance difference through the L-BFGS algorithm to generate new features; according to the threat rule library, the new features are analyzed by KNN for matching. By identifying threat data, the matching result is obtained.

9. A computing device, characterized in that, Including: One or more processors; A storage device for storing one or more programs, which when executed by the one or more processors cause the one or more processors to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, A program is stored in the computer-readable storage medium, and when the program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Virtual platform threat behavior analysis method and system based on KNN

    CN110012013A

  • Network security internal threat detection method

    CN115203683A

  • Data transmission threat detection method and system based on AI drive

    CN117938496A

  • Transverse threat detection method and system based on flow characteristic analysis

    CN118890209A

  • Internal threat detection method based on user classification and behavior feature analysis

    CN119337273A