Malicious traffic detection method and system based on interaction optimization graph

By constructing interactive optimization graphs and combining graph neural network technology, the problem of insufficient accuracy of malicious traffic detection in the existing technology is solved, and efficient identification of complex multi-stage attacks is achieved.

CN120301666APending Publication Date: 2025-07-11FUZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510532844.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and identify complex multi-stage malicious network traffic, and the association between attack activities is not fully utilized.

Method used

Build an interactive optimization graph, and use graph neural network technology to perform malicious traffic detection by integrating the statistical features of the fusion node and the higher-order neighborhood features, including traffic data preprocessing, interaction optimization graph construction, advanced neighborhood feature fusion and the application of Transformer model.

Benefits of technology

It improves the accuracy of malicious traffic detection, effectively explores the deep nonlinear relationship between traffic, and improves the accuracy of detection indicators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301666A_ABST
    Figure CN120301666A_ABST
Patent Text Reader

Abstract

The invention provides a malicious traffic detection method and system based on an interactive optimization graph. The method comprises the following steps: S1, analyzing a network original flow Pcap packet, retaining an IP data packet according to the type of the data packet, and filtering other types of data packets; s2, traffic is grouped according to bidirectional flow, and data packets belonging to the same bidirectional flow are sorted according to timestamps; s3, constructing an interaction optimization graph of each bidirectional flow; s4, obtaining a high-order neighborhood fusion feature sequence of each node according to the interactive optimization graph; s5, inputting the high-order neighborhood fusion feature sequence of each node into a Transform model to obtain node high-dimensional feature representation, and storing the node high-dimensional feature representation; and step S6, inputting the high-dimensional feature representation of the node into an XGBoost classifier to obtain a classification result. According to the invention, malicious traffic detection is realized by using a graph neural network technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of malicious traffic detection and deep learning, and specifically relates to a malicious traffic detection method and system based on an interactive optimization graph. Background Art

[0002] With the in-depth development of the Internet and the increasing popularity of global informatization, the network has become an indispensable infrastructure for all walks of life in modern society. From the business systems within the enterprise to the interconnection of smart devices, the network has penetrated into all aspects of people's daily life. However, with the increase of digital transformation and network dependence, network security issues have become increasingly prominent, especially the threat of malicious traffic, which has become one of the important factors affecting network security. In network traffic, attack behaviors are often distributed, and there are complex correlations between attack activities. In addition, some attacks present a complex multi-stage process. Attackers may first enter the system through phishing emails or vulnerabilities, and then use the stolen information to further initiate privilege escalation or data theft. In these processes, the attack activities not only occur independently, but also have a close relationship in time and space. Therefore, it is necessary to use graph neural network technology to detect malicious traffic. Summary of the invention

[0003] The purpose of the present invention is to propose a malicious traffic detection method and system based on an interactive optimization graph, which combines the topological relationship between the traffic to construct an interactive optimization graph to reflect the spatiotemporal information of the traffic, and by fusing the statistical characteristics of the nodes with the high-order neighborhood characteristics, it excavates the deeper nonlinear relationship between the nodes, thereby improving the accuracy of multiple detection indicators.

[0004] To achieve the above object, the technical solution of the present invention is as follows:

[0005] The present invention proposes a malicious traffic detection method based on an interactive optimization graph, comprising the following steps:

[0006] Step S1, parse the original network traffic Pcap packet, retain the IP data packet according to the data packet type, and filter other types of data packets such as ARP, ICMP, IGMP, etc.;

[0007] Step S2, grouping the traffic according to the bidirectional flow, and sorting the data packets belonging to the same bidirectional flow according to the timestamp;

[0008] Step S3: construct an interaction optimization graph for each bidirectional flow;

[0009] Step S4, obtaining a high-order neighborhood fusion feature sequence of each node according to the interactive optimization graph;

[0010] Step S5: Input the high-order neighborhood fusion feature sequence of each node into the Transformer model to obtain the high-dimensional feature representation of the node, and save it;

[0011] Step S6: Input the high-dimensional feature representation of the node into the XGBoost classifier to obtain the classification result.

[0012] Preferably, the specific content of step S3 is as follows:

[0013] Step S31: Denote the sorted two-way flow by timestamp as F = {p1, p2,..., p n}, where p1, p2,..., p n are all data packets in the two-way flow F, and the number of data packets is n. The timestamp attribute T(p i ) of the data packet p i in the two-way flow F satisfies T(p1) < T(p2) < … < T(p n );

[0014] Divide each sorted two-way flow by timestamp into r data packet subsets, and each data packet subset is denoted as S j , j ∈ [1, r], and it satisfies that all data packets in each data packet subset have the same direction. The expression is as follows:

[0015]

[0016] where S a and S b represent two different data packet subsets; Dir(p i ) is the direction attribute of the data packet p i ;

[0017] Step S32: Introduce a virtual node v virtual to form an interactive optimization graph, and the virtual node serves as the last new data packet subset;

[0018] Step S33: The node set V of the interactive optimization graph is V = {v1, v2, …, v n , v virtual}, where v1, v2, …, v n represent using the data packets p1, p2,..., p n as nodes; the edge set E of the interactive optimization graph consists of two types of edges: the edge set Λ(S j ) inside the r + 1 data packet subsets and the edge set Γ(S j , S j+1);Establish an edge between adjacent data packets within the same data packet subset; establish an edge between the head nodes and an edge between the tail nodes of adjacent data packet subsets; if there is only one data packet in the data packet subset, then the only data packet acts as both the head node and the tail node. The expression is as follows:

[0019]

[0020] Denote the (m + 1)-th node in the data packet subset S j The length of the data packet subset S j Denote the head node in the data packet subset S j Denote the tail node in the data packet subset S j

[0021] Preferably, the step S4 is specifically as follows:

[0022] Step S41, Obtain the high-order neighborhood nodes N i (v k ) of the node v in the interaction optimization graph: i

[0023] N k (v i ) = {v j | distance(v i , v j ) ≤ k}

[0024] In the formula, distance(v i , v j ) represents the shortest path distance between the node v i and the node v j in the graph, and k represents the order of the high order;

[0025] Step S42, Obtain the adjacency matrix A of the graph and the initial feature matrix X of the graph through the interaction optimization graph. Each row of the initial feature matrix X corresponds to the features of each node; multiplying the adjacency matrix A by X can obtain the first-order neighborhood fusion feature matrix X1. Each row of the matrix X1 corresponds to the first-order neighborhood fusion features of each node. The first-order neighborhood fusion feature of the node v i is And so on, calculate the neighborhood fusion feature matrices of each order according to the adjacency matrix A and the initial feature matrix X; obtain the high-order neighborhood fusion feature sequence of the node v i through the initial feature matrix X and the neighborhood fusion feature matrices of each order where represents the feature of the node v i , ​​​​Denote the node v i The k-order neighborhood fusion feature of

[0026] Preferably, the features of each node include: the total number of forward data packets, the data packet length, the total length of forward data packets, the maximum data packet length in forward data packets, the minimum data packet length in forward data packets, the average length of forward data packets, the standard deviation of forward data packet lengths, the time interval between two adjacent data packets, the maximum time interval between all forward data packets, the minimum time interval between all forward data packets, the average time interval between all forward data packets, the standard deviation of time intervals of forward data packets, the maximum number of routing hops that a data packet can pass through, an indication of the priority of data packet processing in the network, the window size in the TCP protocol, the offset in TCP data packets, and the payload length of UDP data packets.

[0027] Preferably, step S5 is specifically as follows:

[0028] Step S51: Calculate the Laplacian matrix of the graph through interactive optimization graph, and use the eigenvector of the Laplacian matrix of the graph as the Laplacian position encoding of each node and splice it into the fusion feature sequence to obtain

[0029] Step S52: Input the high-order neighborhood fusion feature sequence after splicing the Laplacian position encoding of node v i into multiple encoder layers of the Transformer; Step S53: Perform average pooling on the output obtained through the self-attention mechanism of the Transformer to obtain the final high-dimensional representation of node v

[0030] The expression is as follows: i The final high-dimensional representation The expression is as follows:

[0031]

[0032] where T is the number of time steps, i.e., the length of the sequence, denotes the output of node v i at the L-th encoder layer;

[0033] Step S54: Use the cross-entropy loss function during training and use the Adam optimizer to minimize the loss function.

[0034] Preferably, S52 is specifically as follows:

[0035] Input the high-order neighborhood fusion feature sequence after adding the Laplacian position encoding of node v i into the Transformer; Map to the hidden layer dimension d of the Transformer model through a linear projection layer h , represents node v i as the input to the first layer of the Transformer, M represents a learnable matrix for mapping the dimension to the hidden layer dimension d of the Transformer model h , each layer of the Transformer contains a multi-head self-attention layer and a feed-forward neural network layer, and there is a residual connection and layer normalization operation between each sub-layer:

[0036]

[0037] wherein, represents node v i as the input to the l-th layer, LayerNorm() represents the layer normalization operation, MSA() represents the multi-head attention mechanism, represents the output after the residual connection and layer normalization, FFN() represents the feed-forward neural network layer, represents node v i as the output of the l-th layer, l ∈ [1, L], and L represents the last layer of the Transformer

[0038] Preferably, the loss function in S54 has the following expression:

[0039]

[0040] wherein, N is the number of categories, y c is the true label, p c is the probability that the model predicts as the c-th category

[0041] Preferably, step S6 is specifically: input the high-dimensional feature representation i of each node v output by the Transformer into the XGBoost classifier for malicious traffic classification to obtain the final label

[0042] The present invention also proposes a malicious traffic detection system based on an interactive optimization graph. The system is implemented by using any of the above-mentioned malicious traffic detection methods based on an interactive optimization graph, and includes a traffic data preprocessing module, an interactive optimization graph construction module, a high-order neighborhood feature fusion module, and a training and prediction module;

[0043] The traffic data preprocessing module is used to sort the network raw traffic Pcap packets according to two-way flows;

[0044] The constructed interactive optimization graph module is used to divide each bidirectional flow into several data packet subsets according to the sending direction of the data packets, and add virtual nodes as the last new data packet subset, and establish edge connections within the data packet subsets and between adjacent data packet subsets;

[0045] The high-order neighborhood feature fusion module obtains a high-order neighborhood fusion feature sequence for each node for input to the Transformer model by fusing the features of the high-order neighborhood nodes of each node in the interactive optimization graph;

[0046] The training and prediction module inputs the high-order neighborhood fusion feature sequence of each node into the Transformer module, obtains a high-dimensional representation of each node through the self-attention mechanism, and passes it through the XGBoost classifier to realize the classification detection of the malicious traffic to be detected.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] The present invention combines the topological relationship between flows to construct an interactive optimization graph to reflect the spatio-temporal information of the flows, and by fusing the statistical features and high-order neighborhood features of the nodes, deeper non-linear relationships between the nodes are mined, so as to realize the detection of malicious traffic by using graph neural network technology, and effectively improve the accuracy of multiple detection indexes. Description of the Drawings

[0049] Figure 1 It is a schematic flowchart of the method according to an embodiment of the present invention.

[0050] Figure 2 It is a schematic diagram of the data packet features according to an embodiment of the present invention.

[0051] Figure 3 It is a schematic diagram of the interactive optimization graph according to an embodiment of the present invention.

[0052] Figure 4 It is a performance analysis of different graph construction methods according to an embodiment of the present invention (USTC-TFC dataset).

[0053] Figure 5 It is a performance analysis of different graph construction methods according to an embodiment of the present invention (DoH-DGA-Malware-Traffic-HKD dataset).

[0054] Figure 6 It is a performance analysis of different classifiers according to an embodiment of the present invention (USTC-TFC dataset).

[0055] Figure 7 It is a performance analysis of different classifiers according to an embodiment of the present invention (DoH-DGA-Malware-Traffic-HKD dataset).

[0056] Figure 8 is the high - order neighborhood fusion contrast analysis of the embodiment of the present invention (USTC - TFC dataset).

[0057] Figure 9 is the high - order neighborhood fusion contrast analysis of the embodiment of the present invention (DoH - DGA - Malware - Traffic - HKD dataset). Detailed implementation manners

[0058] The technical solution of the present invention will be specifically described below with reference to the accompanying drawings.

[0059] The present invention provides a malicious traffic detection method based on an interactive optimization graph. First, pre - process the USTC - TFC and DoH - DGA - Malware - Traffic - HKD original traffic datasets and sort the traffic according to bidirectional flows. At the same time, the data packets belonging to the same bidirectional flow are sorted according to timestamps; then construct an interactive optimization graph; then obtain the high - order neighborhood fusion feature sequence of each node according to the interactive optimization graph; finally, input the high - order neighborhood fusion feature sequence of each node into a Transformer to obtain the high - dimensional feature representation of the node and input it into an XGBoost classifier for prediction. As Figure 1 shown, it specifically includes the following steps:

[0060] Step (1): Collect network traffic and perform pre - processing;

[0061] In the original Pcap file, there are not only IP data packets but also other types of packets, such as ARP, ICMP, IGMP, etc. We only retain IP data packets for experiments because other types of packets are usually not directly related to the traffic carried by IP data packets. Removing irrelevant protocols can improve processing efficiency and avoid unnecessary redundant information;

[0062] For the USTC - TFC dataset, we select the first 7 data packets of each bidirectional flow as representatives to construct an interactive optimization graph. That is, if the number of data packets in a bidirectional flow exceeds 7, only the first 7 data packets are taken; if the number of data packets in a bidirectional flow is less than 7, all its data packets are taken, and there is no need to fill zero nodes to make the number of nodes in each graph consistent. For the DoH - DGA - Malware - Traffic - HKD dataset, we select the first 1000 data packets of each bidirectional flow to construct an interactive optimization graph. Figure 2 Specifically describes the features of each data packet.

[0063] Step (2): Construct an interactive optimization graph:

[0064] As Figure 3As shown, the two-way flow is divided into several data packet subsets, and corresponding edges are established.

[0065] Step (3): Third-order neighborhood feature fusion sequence;

[0066] In the USTC-TFC dataset and the DoH-DGA-Malware-Traffic-HKD dataset, obtain the third-order neighborhood nodes of node v i in the interactive optimization graph;

[0067] Fuse the features of the third-order neighborhood nodes of node v i to obtain the third-order neighborhood fusion feature sequence of node v i ;

[0068] Step (4): Training and prediction

[0069] Calculate the Laplacian matrix of the graph through the interactive optimization graph, and use the eigenvectors of the Laplacian matrix of the graph as the Laplacian position encoding of each node and splice it into the fusion feature sequence to obtain

[0070] Splice the third-order neighborhood fusion feature sequence of node v i after splicing the Laplacian position encoding; Map it to the hidden layer dimension d h = 64 of the Transformer model through a linear projection layer, denote the input of node v i in the first layer of the Transformer, M represents a learnable matrix for mapping the dimension to the hidden layer dimension d h of the Transformer model. Each layer of the Transformer contains a multi-head self-attention layer (MSA) and a feed-forward neural network layer (FFN), and there is a residual connection and a layer normalization operation between each sub-layer. Among them, denote the input of node v i in the l-th layer, LayerNorm() represents the layer normalization operation, and MSA() represents the multi-head attention mechanism. denote the output after the residual connection and layer normalization, and FFN() represents the feed-forward neural network layer. denote the output of node v i in the l-th layer, where l ∈ [1, L];

[0071] Perform average pooling on the output obtained through the self-attention mechanism of the Transformer to obtain the final high-dimensional representation of the node As shown in formula (1). Among them, T = 4 is the number of time steps, i.e., the length of the sequence, and L = 2;

[0072]

[0073] Input the high-dimensional representation of the node into the XGBoost classifier to obtain the final detection and recognition result.

[0074] Step (4): Test traffic data;

[0075] During the simulation experiment of this embodiment, the training set consists of 60% of the samples, and the remaining 40% is used to construct the test set. All experiments are tested on a server with an Intel(R) Xeon(R) CPU E5-2620 v4 @ 2.10GHz and three NVIDIA Tesla P100 16GB GPUs. Figure 4 and Figure 5 are the performances of using the GCN module to extract features under different graph construction methods. It can be found that in the USTC-TFC and DoH-DGA-Malware-Traffic-HKD datasets, the performance of the interactive optimization graph is the best. Figure 6 and Figure 7 are the performances of the two datasets under different classifiers. It can be found that the effect of classifying the features extracted by Transformer using the XGBoost classifier is the best. Figure 8 and Figure 9 are the comparison results of the detection without fusing the high-order neighborhood features of the nodes and the fusion of the neighborhood features of nodes 1-5. It can be found that in the two datasets, each evaluation index of fusing the third-order neighborhood features of the nodes is the best, indicating that appropriately increasing the neighborhood order can improve the performance to a certain extent.

[0076] The above are only the preferred embodiments of the present invention. All equivalent changes and modifications made according to the scope of the patent application of the present invention shall fall within the scope covered by the present invention.

Claims

1. A malicious traffic detection method based on an interaction-optimized graph, characterized in that It includes the following steps: Step S1: Parse the network raw traffic Pcap packet, retain the IP data packets according to the packet type, and filter other types of data packets; Step S2: Group the traffic according to two-way flows, and sort the data packets belonging to the same two-way flow according to the time stamp; Step S3: Construct the interaction optimization graph for each two-way flow; Step S4: Obtain the high-order neighborhood fusion feature sequence of each node according to the interaction optimization graph; Step S5: Input the high-order neighborhood fusion feature sequence of each node into the Transformer model to obtain the high-dimensional feature representation of the node, and save it; Step S6: Input the high-dimensional feature representation of the node into the XGBoost classifier to obtain the classification result.

2. The malicious traffic detection method based on an interaction optimization graph according to claim 1, wherein The specific content of step S3 is as follows: Step S31: Denote the sorted two-way stream by timestamp as F = {p1, p2,..., p n}, where p1, p2,..., p n are all data packets in the two-way stream F and the number of data packets is n. The timestamp attribute T(p i ) of the data packet p in the two-way stream F satisfies T(p1) < T(p2) < … < T(p i ); n ​ Divide each two-way stream sorted by timestamp into r data packet subsets, and each data packet subset is denoted as S j , where j ∈ [1, r], and all data packets in each data packet subset have the same direction, and the expression is as follows: Among them, S a and S b represent two different data packet subsets; Dir(p i ) is the direction attribute of the data packet p i . Step S32: Introduce a virtual node v virtual Form an interaction optimization graph, with the virtual node as the last new data packet subset; Step S33. The node set V of the interaction optimization graph is V = {v1, v2, …, v n , v virtual}, where v1, v2, …, v n represent taking data packets p1, p2, …, p n as nodes; the edge set E of the interaction optimization graph consists of two types of edges: the edge set Λ(S j ) within r + 1 data packet subsets and the edge set Γ(S j , S j+1 ) between r adjacent data packet subsets; an edge is established between adjacent data packets within the same data packet subset; an edge is established between the head nodes and an edge is established between the tail nodes of adjacent data packet subsets; if there is only one data packet within a data packet subset, then the only data packet acts as both the head node and the tail node, and the expression is as follows: Denote the (m + 1)-th node in the data packet subset S j , len(S j ) denotes the length of the data packet subset S j . Denote the head node in the data packet subset S j . Denote the tail node in the data packet subset S j .

3. A malicious traffic detection method based on an interaction-optimized graph according to claim 1, characterized in that The specific content of step S4 is as follows: Step S41: Obtain the high-order neighborhood nodes N i of the node v k (v i ): N k (v i ) = {v j | distance(v i , v j ) ≤ k} where distance(v i ,v j ) represents the shortest path distance between node v i and node v j in the graph, and k represents the order of the higher order; Step S42: Obtain the adjacency matrix A of the graph and the initial feature matrix X of the graph from the interaction optimization graph. Each row of the initial feature matrix X corresponds to the features of each node. Calculate the neighborhood fusion feature matrices of each order according to the adjacency matrix A and the initial feature matrix X; obtain the high-order neighborhood fusion feature sequence of node v i where the high-order neighborhood fusion feature sequence of node v where represents the features of node v i and represents the k-order neighborhood fusion features of node v i .

4. The malicious traffic detection method based on an interaction optimization graph according to claim 3, wherein The features of each node include: the total number of forward data packets, the packet length, the total length of forward data packets, the maximum packet length in forward data packets, the minimum packet length in forward data packets, the average length of forward data packets, the standard deviation of the lengths of forward data packets, the time interval between two adjacent data packets, the maximum time interval between all forward data packets, the minimum time interval between all forward data packets, the average time interval between all forward data packets, the standard deviation of the time intervals of forward data packets, the maximum number of routing hops that a data packet can pass through, the priority indicating the processing of the data packet in the network, the window size in the TCP protocol, the offset in the TCP data packet, and the payload length of the UDP data packet.

5. A malicious traffic detection method based on an interaction optimization graph according to claim 1, characterized in that, The specific content of step S5 is as follows: Step S51: Calculate the Laplacian matrix of the graph through interactive optimization graph, and use the eigenvectors of the Laplacian matrix of the graph as the Laplacian position encoding of each node and splice it into the fusion feature sequence to obtain Step S52: Concatenate the node v i with the high-order neighborhood fusion feature sequence after Laplacian position encoding and input it into multiple encoder layers of the Transformer; Step S53: Perform average pooling on the output obtained through the self-attention mechanism of the Transformer to obtain node v i Final high-dimensional representation The expression is as follows: where T is the number of time steps, i.e., the length of the sequence, represents the node v i output of the encoder layer at the L-th layer; Step S54: Use the cross-entropy loss function during training, and use the Adam optimizer to minimize the loss function.

6. The malicious traffic detection method based on an interaction optimization graph according to claim 5, wherein The specific content of S52 is as follows: Add the node v i to the high-order neighborhood fusion feature sequence after adding Laplacian position encoding and map it to the hidden layer dimension d of the Transformer model through a linear projection layer h , denote the input of node v i at the first layer of the Transformer. M represents a learnable matrix used to map the dimension to the hidden layer dimension d of the Transformer model h . Each layer of the Transformer contains a multi-head self-attention layer and a feed-forward neural network layer, and there is a residual connection and layer normalization operation between each sub-layer: Among them, represents the input of node v i at the l-th layer. LayerNorm() represents the layer normalization operation, and MSA() represents the multi-head attention mechanism. represents the output after residual connection and layer normalization. FFN() represents the feed-forward neural network layer. represents the output of node v i at the l-th layer, where l ∈ [1, L], and L represents the last layer of the Transformer.

7. A malicious traffic detection method based on an interaction optimization graph according to claim 5, characterized in that The loss function in S54 The expression is as follows: where N is the number of categories, and y c is the true label, and p c is the probability that the model predicts as the c-th category.

8. A malicious traffic detection system based on an interaction-optimized graph, characterized in that, The system is implemented by using the malicious traffic detection method based on the interaction optimization graph described in any one of claims 1-7, and includes a traffic data preprocessing module, an interaction optimization graph construction module, a high-order neighborhood feature fusion module, and a training and prediction module; The traffic data preprocessing module is used to sort the network raw traffic Pcap packets according to two-way flows; The interaction optimization graph construction module is used to divide each two-way flow into several data packet subsets according to the sending direction of the data packets, add a virtual node as the last new data packet subset, and establish edge connections within the data packet subsets and between adjacent data packet subsets; The high-order neighborhood feature fusion module obtains the high-order neighborhood fusion feature sequence of each node by fusing the features of the high-order neighborhood nodes in the interaction optimization graph for input to the Transformer model; The training and prediction module inputs the high-order neighborhood fusion feature sequence of each node into the Transformer module, obtains the high-dimensional representation of each node through the self-attention mechanism, and passes it through the XGBoost classifier to realize the classification detection of the malicious traffic to be detected.