Network security dynamic early warning method and system based on deep learning
Through the dynamic early warning method of network security based on deep learning, the neural network model optimized by GRU network and PSO algorithm is used to realize real-time monitoring and early warning of network security, solving the problems of post-repair in the existing technology, and improving the early warning efficiency of network security.
Patent Information
- Application Number
- CN202510626413.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-07-11
AI Technical Summary
Most of the existing network defense technologies are post-repair, and real-time early warning and monitoring cannot be achieved, which poses a network security risk.
The network security dynamic warning method based on deep learning is adopted, and the network security identification neural network model optimized by GRU gated recurrent unit neural network and PSO particle swarm algorithm is used to analyze real-time network access data in combination with intrusion detection sensor data to generate dynamic warnings and repair measures.
Real-time monitoring and early warning of network security is realized, the early warning efficiency of network security is improved, network attacks are sensed in a timely manner, and the smooth operation of network security is ensured.
Smart Images

Figure CN120301686A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a network security dynamic early warning method and system based on deep learning. Background Art
[0002] With the advent of the network era, network attacks have become more and more frequent. There are many network defense technologies in the field of network security, such as network firewall technology, network encryption technology, virus prevention and control technology, vulnerability scanning and repair technology, etc. These defense methods defend and repair the problems that occur in network security from different angles, and are relatively common means to maintain network security. However, the existing network defense technologies basically repair after the attack has occurred, which belongs to the behavior of maintaining after the danger has occurred, that is, there is still a possibility of endangering network security and may cause irreversible damage to the network. Therefore, how to conduct real-time early warning and monitoring of network security is a technical problem that needs to be solved urgently at present. Summary of the Invention
[0003] The purpose of the present invention is to solve the above problems and design a network security dynamic early warning method and system based on deep learning.
[0004] Furthermore, in the above-mentioned network security dynamic early warning method based on deep learning, the network security dynamic early warning method includes the following steps:
[0005] Obtain historical network attack data in the intrusion detection sensor, perform data preprocessing on the historical network attack data to obtain a historical network attack data set; classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set;
[0006] Based on the GRU gated recurrent unit neural network, establish a GRU network security recognition neural network model, and use the PSO particle swarm optimization algorithm to optimize the GRU network security recognition neural network model to obtain an initial PSO-GRU network security recognition neural network model;
[0007] Input the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and input the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model;
[0008] Obtain real-time network access data in the intrusion detection sensor, input the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data;
[0009] Judge the network security environment of the system according to the dynamic data of the system network security. If the network security environment of the system is in a completely dangerous state, give a warning to the server.
[0010] If the security environment of the system is in a partially dangerous state, generate partial danger repair measures according to the network security repair database, and transmit the partial danger repair measures to the mobile terminal of the management personnel.
[0011] Further, in the above network security dynamic warning method, obtaining historical network attack data in the intrusion detection sensor, performing data preprocessing on the historical network attack data to obtain a historical network attack data set; classifying the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set, including:
[0012] Obtain historical network attack data in the intrusion detection sensor, and the historical network attack data at least includes malware attacks, SQL injection, zero-day vulnerability exploitation, password attacks, cross-site scripting, and changing URL parameters;
[0013] Use One-hot encoding to encode the non-numerical attribute data in the historical network attack data to obtain encoded network attack data;
[0014] Perform attribute normalization on the numerical attribute data in the historical network attack data based on the maximum-minimum normalization formula to obtain normalized network attack data;
[0015] Merge the encoded network attack data and the normalized network attack data to obtain a historical network attack data set;
[0016] Use the decision tree classification algorithm to classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set.
[0017] Further, in the above network security dynamic warning method, establishing a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and using the PSO particle swarm algorithm to optimize the GRU network security recognition neural network model to obtain an initial PSO-GRU network security recognition neural network model, including:
[0018] Establish a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network;
[0019] Use the PSO particle swarm algorithm to select the adaptive learning rate of the Adam optimizer to obtain the target Adam optimizer;
[0020] Optimize the parameters in the GRU network security recognition neural network model based on the target Adam optimizer to obtain the first GRU network security recognition neural network model;
[0021] Set the binary cross-entropy loss function as the loss function of the first GRU network security recognition neural network model;
[0022] Set the Sigmoid activation function as the activation function of the first GRU network security recognition neural network model;
[0023] Add a Dropout layer between the two layers of GRU gated recurrent unit neural networks in the first GRU network security recognition neural network model to obtain the initial PSO-GRU network security recognition neural network model.
[0024] Further, in the above network security dynamic warning method, the step of inputting the training historical network attack dataset into the initial PSO-GRU network security recognition neural network model for training, and inputting the test historical network attack dataset into the initial PSO-GRU network security recognition neural network model for testing to obtain the target PSO-GRU network security recognition neural network model includes:
[0025] The target PSO-GRU network security recognition neural network model includes at least an input layer, a Dropout layer, and an output layer;
[0026] The target PSO-GRU network security recognition neural network model obtains real-time network access data and conducts network security attack recognition.
[0027] Further, in the above network security dynamic warning method, the step of obtaining real-time network access data in the intrusion detection sensor, inputting the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data includes:
[0028] The network security dynamic data includes at least a completely dangerous state, a partially dangerous state, and a safe state;
[0029] The completely dangerous state means that network attack data accounts for 80% of the real-time network access data within a preset 10-minute time period;
[0030] The partially dangerous state means that network attack data accounts for 10%-79% of the real-time network access data within a preset 10-minute time period;
[0031] The safe state means that there is no network attack data or network attack data accounts for 1%-5% of the real-time network access data.
[0032] Furthermore, in the above-mentioned network security dynamic warning method, for judging the network security environment of the system according to the system network security dynamic data, if the network security environment of the system is in a completely dangerous state, warning the server includes:
[0033] Judging the network security environment of the system according to the system network security dynamic data, if the network security environment of the system is in a completely dangerous state, warning the server;
[0034] Obtaining the received feedback data in the system, if the received feedback data in the system is not received within 1 minute, making an emergency intelligent voice call to the management personnel;
[0035] If the network security environment of the system remains in a completely dangerous state within 2 minutes, automatically cutting off the access address.
[0036] Furthermore, in the above-mentioned network security dynamic warning method, if the security environment of the system is in a partially dangerous state, generating partial danger repair measures according to the network security repair database and transmitting the partial danger repair measures to the mobile terminal of the management personnel includes:
[0037] Using a crawler to obtain network security attack repair data on the Internet and historical network security attack repair data in the system;
[0038] Using the K-means clustering algorithm to cluster the network security attack repair data and the historical network security attack repair data to obtain a network security repair database;
[0039] If it is judged that the security environment of the system is in a partially dangerous state, obtaining the network attack method in the partially dangerous state;
[0040] Generating partial danger repair measures for the network attack method in the partially dangerous state based on the network security repair database;
[0041] Transmitting the partial danger repair measures to the mobile terminal of the management personnel and obtaining the received feedback of the mobile terminal;
[0042] If the received feedback of the mobile terminal is not received within 5 minutes, warning the server.
[0043] Furthermore, in the above-mentioned network security dynamic warning system, the network security dynamic warning system includes:
[0044] A data acquisition module, configured to acquire historical network attack data in an intrusion detection sensor, perform data preprocessing on the historical network attack data to obtain a historical network attack data set; classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set;
[0045] A model establishment module, configured to establish a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and optimize the GRU network security recognition neural network model by using the PSO particle swarm optimization algorithm to obtain an initial PSO-GRU network security recognition neural network model;
[0046] A model training module, configured to input the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and input the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model;
[0047] A security recognition module, configured to acquire real-time network access data in an intrusion detection sensor, input the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data;
[0048] A security warning module, configured to judge the network security environment of the system according to the system network security dynamic data, and if the network security environment of the system is in a completely dangerous state, give a warning to the server;
[0049] A security repair module, configured to, if the security environment of the system is in a partially dangerous state, generate partially dangerous repair measures according to a network security repair database, and transmit the partially dangerous repair measures to the mobile terminal of the management personnel.
[0050] Furthermore, in the above network security dynamic warning system, the data acquisition module includes the following sub-modules:
[0051] An acquisition sub-module, configured to acquire historical network attack data in an intrusion detection sensor, where the historical network attack data at least includes malware attacks, SQL injections, zero-day vulnerability exploits, password attacks, cross-site scripting, and URL parameter changes;
[0052] An encoding sub-module, configured to encode non-numerical attribute data in the historical network attack data by using one-hot encoding to obtain encoded network attack data;
[0053] A normalization sub-module, configured to perform attribute normalization on the numerical attribute data in the historical network attack data based on the maximum-minimum normalization formula to obtain normalized network attack data;
[0054] A merging sub-module, configured to merge the encoded network attack data and the normalized network attack data to obtain a historical network attack data set;
[0055] A classification sub-module, configured to classify the historical network attack data set by using a decision tree classification algorithm to obtain a training historical network attack data set and a testing historical network attack data set.
[0056] Furthermore, in the above-mentioned network security dynamic warning system, the security repair module includes the following sub-modules:
[0057] An acquisition sub-module, configured to use a crawler to acquire network security attack repair data on the Internet and historical network security attack repair data in the system;
[0058] A building sub-module, configured to perform clustering on the network security attack repair data and the historical network security attack repair data by using the K-means clustering algorithm to obtain a network security repair database;
[0059] A judgment sub-module, configured to, if it is judged that the security environment of the system is in a partially dangerous state, acquire the network attack methods in the partially dangerous state;
[0060] A repair sub-module, configured to generate partial danger repair measures for the network attack methods in the partially dangerous state based on the network security repair database;
[0061] Transmit the partial danger repair measures to the mobile terminal of the management personnel and obtain the reception feedback of the mobile terminal;
[0062] If the reception feedback of the mobile terminal is not received within 5 minutes, give a warning to the server.
[0063] Its beneficial effects are as follows: by obtaining historical network attack data in the intrusion detection sensor, preprocessing the historical network attack data to obtain a historical network attack data set; classifying the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set; establishing a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and optimizing the GRU network security recognition neural network model using the PSO particle swarm algorithm to obtain an initial PSO-GRU network security recognition neural network model; inputting the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and inputting the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model; obtaining real-time network access data in the intrusion detection sensor, inputting the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data; judging the network security environment of the system according to the system network security dynamic data. If the network security environment of the system is in a completely dangerous state, a warning is given to the server. If the security environment of the system is in a partially dangerous state, partial danger repair measures are generated according to the network security repair database, and the partial danger repair measures are transmitted to the mobile terminal of the management personnel. It can effectively conduct dynamic early warning of network security, timely sense the network attack data in the real-time access data in the system, and classify the network attack data, improve the early warning efficiency of network security, and effectively ensure the stable operation of network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention.
[0065] Figure 1 Schematic diagram of the first embodiment of a network security dynamic early warning method based on deep learning in an embodiment of the present invention;
[0066] Figure 2 Schematic diagram of the second embodiment of a network security dynamic early warning method based on deep learning in an embodiment of the present invention;
[0067] Figure 3 Schematic diagram of the third embodiment of a network security dynamic early warning method based on deep learning in an embodiment of the present invention;
[0068] Figure 4Schematic diagram of the first embodiment of a network security dynamic early warning system based on deep learning in the embodiments of the present invention; Detailed implementation manners
[0069] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0070] Those skilled in the art of the present technology can understand that unless specifically stated, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present invention means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups.
[0071] The present invention will be specifically described below with reference to the accompanying drawings. As Figure 1 shown, a network security dynamic early warning method based on deep learning, the network security dynamic early warning method includes the following steps:
[0072] Step 101: Obtain historical network attack data in the intrusion detection sensor, perform data preprocessing on the historical network attack data to obtain a historical network attack data set; classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set;
[0073] Specifically, in this embodiment, the historical network attack data in the intrusion detection sensor is obtained. The historical network attack data at least includes malware attacks, SQL injections, zero-day vulnerability exploitations, password attacks, cross-site scripting, and changing URL parameters; the non-numerical attribute data in the historical network attack data is encoded using one-hot encoding to obtain encoded network attack data; the numerical attribute data in the historical network attack data is normalized based on the maximum-minimum normalization formula to obtain normalized network attack data; the encoded network attack data and the normalized network attack data are merged to obtain a historical network attack data set; the decision tree classification algorithm is used to classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set.
[0074] Step 102: Establish a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and optimize the GRU network security recognition neural network model using the PSO particle swarm algorithm to obtain an initial PSO-GRU network security recognition neural network model;
[0075] Specifically, in this embodiment, a GRU network security recognition neural network model is established based on the GRU gated recurrent unit neural network; the PSO particle swarm optimization algorithm is used to select the adaptive learning rate of the Adam optimizer to obtain the target Adam optimizer; based on the target Adam optimizer, the parameters in the GRU network security recognition neural network model are optimized to obtain the first GRU network security recognition neural network model; the binary cross-entropy loss function is set as the loss function of the first GRU network security recognition neural network model; the Sigmoid activation function is set as the activation function of the first GRU network security recognition neural network model; a Dropout layer is added between the two layers of GRU gated recurrent unit neural networks in the first GRU network security recognition neural network model to obtain the initial PSO-GRU network security recognition neural network model.
[0076] Step 103: Input the training historical network attack dataset into the initial PSO-GRU network security recognition neural network model for training, and input the test historical network attack dataset into the initial PSO-GRU network security recognition neural network model for testing to obtain the target PSO-GRU network security recognition neural network model.
[0077] Specifically, in this embodiment, the target PSO-GRU network security recognition neural network model at least includes an input layer, a Dropout layer, and an output layer; the target PSO-GRU network security recognition neural network model obtains network access data in real time and conducts network security attack recognition.
[0078] Step 104: Obtain the real-time network access data in the intrusion detection sensor, input the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain the system network security dynamic data.
[0079] Specifically, in this embodiment, the network security dynamic data at least includes a completely dangerous state, a partially dangerous state, and a safe state; the completely dangerous state means that the network attack data accounts for 80% of the real-time network access data within a preset 10-minute time period; the partially dangerous state means that the network attack data accounts for 10%-79% of the real-time network access data within a preset 10-minute time period; the safe state means that there is no network attack data or the network attack data accounts for 1%-5% of the real-time network access data.
[0080] Step 105: Judge the network security environment of the system according to the system network security dynamic data. If the network security environment of the system is in a completely dangerous state, give a warning to the server.
[0081] Specifically, in this embodiment, the network security environment of the system is judged according to the dynamic data of system network security. If the network security environment of the system is in a completely dangerous state, a warning is given to the server; the received feedback data in the system is obtained. If the received feedback data in the system is not received within 1 minute, an emergency intelligent voice call is made to the management personnel; if the network security environment of the system remains in a completely dangerous state within 2 minutes, the access address is automatically cut off.
[0082] Step 106: If the security environment of the system is in a partially dangerous state, partial danger repair measures are generated according to the network security repair database, and the partial danger repair measures are transmitted to the mobile terminal of the management personnel.
[0083] Specifically, in this embodiment, web crawlers are used to obtain the network security attack repair data on the Internet and the historical network security attack repair data in the system; the K-means clustering algorithm is used to cluster the network security attack repair data and the historical network security attack repair data to obtain the network security repair database; if it is judged that the security environment of the system is in a partially dangerous state, the network attack methods in the partially dangerous state are obtained; based on the network security repair database, partial danger repair measures are generated for the network attack methods in the partially dangerous state; the partial danger repair measures are transmitted to the mobile terminal of the management personnel, and the received feedback of the mobile terminal is obtained; if the received feedback of the mobile terminal is not received within 5 minutes, a warning is given to the server.
[0084] Its beneficial effects are as follows: By obtaining historical network attack data in the intrusion detection sensor, preprocessing the historical network attack data to obtain a historical network attack data set; classifying the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set; establishing a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and optimizing the GRU network security recognition neural network model using the PSO particle swarm algorithm to obtain an initial PSO-GRU network security recognition neural network model; inputting the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and inputting the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model; obtaining real-time network access data in the intrusion detection sensor, inputting the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data; judging the network security environment of the system according to the system network security dynamic data. If the network security environment of the system is in a completely dangerous state, a warning is issued to the server; if the security environment of the system is in a partially dangerous state, partial danger repair measures are generated according to the network security repair database, and the partial danger repair measures are transmitted to the mobile terminal of the management personnel. It can effectively conduct dynamic early warning of network security, timely sense network attack data in real-time access data in the system, and classify the network attack data, improving the early warning efficiency of network security and effectively ensuring the stable operation of network security.
[0085] In this embodiment, please refer to Figure 2 , the second embodiment of a network security dynamic early warning method based on deep learning in the embodiment of the present invention. Obtaining historical network attack data in the intrusion detection sensor, preprocessing the historical network attack data to obtain a historical network attack data set; classifying the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set includes the following steps:
[0086] Step 201, obtain historical network attack data in the intrusion detection sensor. The historical network attack data includes at least malware attacks, SQL injection, zero-day vulnerability exploitation, password attacks, cross-site scripting, and changing URL parameters;
[0087] Step 202, encode the non-numerical attribute data in the historical network attack data using one-hot encoding to obtain encoded network attack data;
[0088] Step 203: Perform attribute normalization on the numerical attribute data in the historical network attack data based on the maximum-minimum normalization formula to obtain normalized network attack data;
[0089] Step 204: Combine the encoded network attack data and the normalized network attack data to obtain a historical network attack data set;
[0090] Step 205: Use the decision tree classification algorithm to classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set.
[0091] In this embodiment, please refer to Figure 3 , the third embodiment of a network security dynamic early warning method and system based on deep learning in the embodiments of the present invention. If the security environment of the system is in a partially dangerous state, partial danger repair measures are generated according to the network security repair database, and the partial danger repair measures are transmitted to the mobile terminal of the administrator, including the following steps:
[0092] Step 301: Use a crawler to obtain network security attack repair data on the Internet and historical network security attack repair data in the system;
[0093] Step 302: Use the K-means clustering algorithm to cluster the network security attack repair data and the historical network security attack repair data to obtain a network security repair database;
[0094] Step 303: If it is determined that the security environment of the system is in a partially dangerous state, obtain the network attack method in the partially dangerous state;
[0095] Step 304: Generate partial danger repair measures for the network attack method in the partially dangerous state based on the network security repair database;
[0096] Step 305: Transmit the partial danger repair measures to the mobile terminal of the administrator and obtain the receiving feedback of the mobile terminal;
[0097] Step 306: If the receiving feedback of the mobile terminal is not received within 5 minutes, give an early warning to the server.
[0098] The above describes a network security dynamic early warning method provided by the embodiments of the present invention. Next, a network security dynamic early warning system based on wireless connection in the embodiments of the present invention is described. Please refer to Figure 4 , an embodiment of the network security dynamic early warning system in the embodiments of the present invention includes:
[0099] A data acquisition module, configured to acquire historical network attack data in an intrusion detection sensor, perform data preprocessing on the historical network attack data to obtain a historical network attack data set; classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set;
[0100] A model establishment module, configured to establish a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and optimize the GRU network security recognition neural network model by using the PSO particle swarm optimization algorithm to obtain an initial PSO-GRU network security recognition neural network model;
[0101] A model training module, configured to input the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and input the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model;
[0102] A security recognition module, configured to acquire real-time network access data in an intrusion detection sensor, input the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data;
[0103] A security warning module, configured to judge the network security environment of the system according to the system network security dynamic data. If the network security environment of the system is in a completely dangerous state, a warning is given to the server;
[0104] A security repair module, configured to, if the security environment of the system is in a partially dangerous state, generate partially dangerous repair measures according to a network security repair database, and transmit the partially dangerous repair measures to the mobile terminal of the administrator.
[0105] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A network security dynamic early warning method based on deep learning, characterized in that The network security dynamic early warning method includes the following steps: Obtain historical network attack data in the intrusion detection sensor, perform data preprocessing on the historical network attack data to obtain a historical network attack data set; classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set; Based on the GRU gated recurrent unit neural network, establish a GRU network security recognition neural network model, and use the PSO particle swarm optimization algorithm to optimize the GRU network security recognition neural network model to obtain an initial PSO-GRU network security recognition neural network model; Input the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and input the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model; Obtain real-time network access data in the intrusion detection sensor, input the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data; Judge the network security environment of the system according to the system network security dynamic data. If the network security environment of the system is in a completely dangerous state, give an early warning to the server; If the security environment of the system is in a partially dangerous state, generate partially dangerous repair measures according to the network security repair database, and transmit the partially dangerous repair measures to the mobile terminal of the management personnel.
2. The network security dynamic early warning method based on deep learning according to claim 1, characterized in that The obtaining of historical network attack data in the intrusion detection sensor, performing data preprocessing on the historical network attack data to obtain a historical network attack data set; classifying the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set includes: Obtain historical network attack data in the intrusion detection sensor, where the historical network attack data at least includes malware attacks, SQL injection, zero-day vulnerability exploitation, password attacks, cross-site scripting, and changing URL parameters; Use one-hot encoding to encode the non-numerical attribute data in the historical network attack data to obtain encoded network attack data; Perform attribute normalization on the numerical attribute data in the historical network attack data based on the maximum-minimum normalization formula to obtain normalized network attack data; Merge the encoded network attack data and the normalized network attack data to obtain a historical network attack data set; Use the decision tree classification algorithm to classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set.
3. The network security dynamic early warning method based on deep learning according to claim 1, characterized in that The establishing of a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network and using the PSO particle swarm optimization algorithm to optimize the GRU network security recognition neural network model to obtain an initial PSO-GRU network security recognition neural network model includes: Establish a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network; The adaptive learning rate of the Adam optimizer is selected using the PSO particle swarm optimization algorithm to obtain the target Adam optimizer; Based on the target Adam optimizer, the parameters in the GRU network security recognition neural network model are optimized to obtain the first GRU network security recognition neural network model; The binary cross-entropy loss function is used as the loss function of the first GRU network security recognition neural network model; The Sigmoid activation function is set as the activation function of the first GRU network security recognition neural network model; A Dropout layer is added between the two layers of GRU gated recurrent unit neural networks in the first GRU network security recognition neural network model to obtain the initial PSO-GRU network security recognition neural network model.
4. A network security dynamic early warning method based on deep learning according to claim 1, characterized in that, The training historical network attack dataset is input into the initial PSO-GRU network security recognition neural network model for training, and the test historical network attack dataset is input into the initial PSO-GRU network security recognition neural network model for testing to obtain the target PSO-GRU network security recognition neural network model, including: The target PSO-GRU network security recognition neural network model includes at least an input layer, a Dropout layer, and an output layer; The target PSO-GRU network security recognition neural network model obtains real-time network access data and recognizes network security attacks.
5. A network security dynamic early warning method based on deep learning according to claim 1, characterized in that, The real-time network access data in the intrusion detection sensor is obtained, and the real-time network access data is input into the target PSO-GRU network security recognition neural network model for recognition to obtain the system network security dynamic data, including: The network security dynamic data includes at least a completely dangerous state, a partially dangerous state, and a safe state; The completely dangerous state means that the network attack data accounts for 80% of the real-time network access data within a preset 10-minute time period; The partially dangerous state means that the network attack data accounts for 10%-79% of the real-time network access data within a preset 10-minute time period; The safe state means that there is no network attack data or the network attack data accounts for 1%-5% of the real-time network access data.
6. The network security dynamic early warning method based on deep learning according to claim 1, characterized in that Based on the system network security dynamic data, the network security environment of the system is judged. If the network security environment of the system is in a completely dangerous state, a warning is given to the server, including: Based on the system network security dynamic data, the network security environment of the system is judged. If the network security environment of the system is in a completely dangerous state, a warning is given to the server; The received feedback data in the system is obtained. If the received feedback data in the system is not received within 1 minute, an emergency intelligent voice call is made to the management personnel; If the network security environment of the system remains in a completely dangerous state within 2 minutes, the access address is automatically cut off.
7. The network security dynamic early warning method based on deep learning according to claim 1, characterized in that If the security environment of the system is in a partially dangerous state, partial danger repair measures are generated according to the network security repair database, and the partial danger repair measures are transmitted to the mobile terminal of the management personnel, including: Use a crawler to obtain network security attack repair data on the Internet and historical network security attack repair data in the system; Use the K-means clustering algorithm to cluster the network security attack repair data and the historical network security attack repair data to obtain a network security repair database; If it is determined that the security environment of the system is in a partially dangerous state, obtain the network attack methods in the partially dangerous state; Generate partial danger repair measures for the network attack methods in the partially dangerous state based on the network security repair database; Transmit the partial danger repair measures to the mobile terminal of the management personnel and obtain the receiving feedback of the mobile terminal; If the receiving feedback of the mobile terminal is not received within 5 minutes, give a warning to the server.
8. A network security dynamic early warning system based on deep learning, characterized in that, The network security dynamic warning system includes the following modules: The data acquisition module is used to obtain historical network attack data in the intrusion detection sensor, perform data preprocessing on the historical network attack data to obtain a historical network attack data set; classify the historical network attack data set to obtain a training historical network attack data set and a test historical network attack data set; The model establishment module is used to establish a GRU network security recognition neural network model based on the GRU gated recurrent unit neural network, and use the PSO particle swarm algorithm to optimize the GRU network security recognition neural network model to obtain an initial PSO-GRU network security recognition neural network model; The model training module is used to input the training historical network attack data set into the initial PSO-GRU network security recognition neural network model for training, and input the test historical network attack data set into the initial PSO-GRU network security recognition neural network model for testing to obtain a target PSO-GRU network security recognition neural network model; The security recognition module is used to obtain real-time network access data in the intrusion detection sensor, input the real-time network access data into the target PSO-GRU network security recognition neural network model for recognition to obtain system network security dynamic data; The security warning module is used to judge the network security environment of the system according to the system network security dynamic data. If the network security environment of the system is in a completely dangerous state, give a warning to the server; The security repair module is used to, if the security environment of the system is in a partially dangerous state, generate partial danger repair measures according to the network security repair database, and transmit the partial danger repair measures to the mobile terminal of the management personnel.
9. The network security dynamic early warning system based on deep learning according to claim 8, wherein The data acquisition module includes the following sub-modules: The acquisition sub-module is used to obtain historical network attack data in the intrusion detection sensor, and the historical network attack data at least includes malware attacks, SQL injection, zero-day vulnerability exploitation, password attacks, cross-site scripting, and changing URL parameters; The encoding sub-module is used to encode the non-numerical attribute data in the historical network attack data by using One-hot encoding to obtain encoded network attack data; A normalization sub-module, which is used to perform attribute normalization on the numerical attribute data in the historical network attack data based on the maximum-minimum normalization formula to obtain normalized network attack data; A merging sub-module, which is used to merge the encoded network attack data and the normalized network attack data to obtain a historical network attack data set; A classification sub-module, which is used to classify the historical network attack data set by using a decision tree classification algorithm to obtain a training historical network attack data set and a test historical network attack data set.
10. A network security dynamic early warning system based on deep learning according to claim 8, characterized in that, The security repair module includes the following sub-modules: An acquisition sub-module, which is used to use a crawler to obtain network security attack repair data on the Internet and historical network security attack repair data in the system; A building sub-module, which is used to perform clustering on the network security attack repair data and the historical network security attack repair data by using the K-means clustering algorithm to obtain a network security repair database; A judgment sub-module, which is used to obtain the network attack method in the partially dangerous state if it is judged that the security environment of the system is in a partially dangerous state; A repair sub-module, which is used to generate partial danger repair measures for the network attack method in the partially dangerous state based on the network security repair database; Transmit the partial danger repair measures to the mobile terminal of the management personnel and obtain the receiving feedback of the mobile terminal; If the receiving feedback of the mobile terminal is not received within 5 minutes, give an early warning to the server.