Intelligent network intrusion detection system based on 5G network

Through the 5G network intrusion intelligent detection system integrating a variety of advanced technologies and intelligent modules, the problem that traditional detection methods are difficult to deal with new attacks in the 5G network environment is solved, efficient and accurate intrusion detection and threat prevention are achieved, and the identification and defense capabilities of complex network threats are enhanced.

CN120302291AInactive Publication Date: 2025-07-11SHANDONG YUNZHIHUI INFORMATION TECHNOLOGY SERVICE CO LTD
View PDF 0 Cites 8 Cited by

Patent Information

Application Number
CN202510484256.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing network intrusion detection systems are difficult to adapt to new attacks in real time in 5G network environments, especially zero-day attacks, variant attacks and advanced persistent threats (APTs). Traditional rule-based detection methods cannot effectively identify and defend against complex cyber threats.

Method used

It adopts an intelligent detection system based on 5G network, integrating traffic anomaly detection, data encryption tamper detection, abnormality analysis and evaluation, attack prediction and prevention, dynamic isolation and protection, reverse tracking and traceability, redirection and isolation protection and other modules, combining machine learning, deep learning and reinforcement learning algorithms to achieve adaptive intrusion detection and threat prevention.

Benefits of technology

Improves detection capabilities for zero-day attacks, variant attacks, and advanced persistent threats, enhances the response speed and accuracy of defense systems, and can predict potential attacks in dynamic network environments and automatically optimize defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120302291A_ABST
    Figure CN120302291A_ABST
Patent Text Reader

Abstract

The invention discloses a network intrusion intelligent detection system based on a 5G network, and relates to the technical field of network security. Comprising a traffic anomaly detection and analysis module, a data encryption tampering detection module, an anomaly analysis and evaluation module, an attack prediction and prevention module, a dynamic isolation and protection module, a reverse tracking and tracing module and a redirection and isolation protection module. According to the system, more efficient and more accurate intrusion detection and threat defense can be realized in a 5G network environment by integrating a plurality of advanced technologies and intelligent modules. Compared with a traditional rule-based detection method, the system can adaptively learn and identify a new attack mode, and the detection capability for zero-day attacks, variant attacks and advanced persistent threats (APT) is enhanced. Besides, by combining deep learning and reinforcement learning algorithms, the system can predict potential attacks in a dynamically changing network environment and automatically optimize a defense strategy, and the response speed and accuracy of the defense system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and specifically to a network intrusion intelligent detection system based on 5G network. Background Art

[0002] With the rapid development of 5G technology, the speed, capacity and connectivity of the network have been significantly improved, but this also makes the network face more complex and diverse security threats. Traditional network security defense technologies, such as rule-based intrusion detection systems (IDS) and signature-based firewalls, have been unable to cope with new attacks in the 5G network environment. 5G networks are highly dynamic, heterogeneous and distributed, which makes intrusion behaviors more hidden. Traditional security detection technologies are often unable to identify and effectively defend against these threats in a timely manner.

[0003] To address this problem, modern network security protection systems have begun to introduce technologies such as artificial intelligence (AI), machine learning (ML), and deep learning (DL) to improve the efficiency and intelligence level of network intrusion detection. Based on this, current intrusion detection systems are gradually turning to a more intelligent and automated direction, dynamically identifying attacks through big data analysis, real-time traffic monitoring, and behavior pattern analysis. At the same time, the large number of terminal devices, massive data flows, and complex network topology in 5G networks provide attackers with more attack paths, so relying solely on traditional static detection methods can no longer effectively respond to potential threats.

[0004] Specifically, existing network intrusion detection systems usually rely on fixed rules and feature libraries, and are difficult to adapt to new attack methods in real time, especially in the face of zero-day attacks, variant attacks, and advanced persistent threats (APTs). In addition, as network complexity increases, how to quickly and accurately identify attack behaviors in massive data and take automated defense measures remains a technical challenge that needs to be solved. Summary of the invention

[0005] In view of the shortcomings of the prior art, the present invention provides a network intrusion intelligent detection system based on 5G network to solve the problems raised in the above background technology.

[0006] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: a network intrusion intelligent detection system based on 5G network, including a traffic anomaly detection and analysis module, a data encryption tampering detection module, an anomaly analysis and evaluation module, an attack prediction and prevention module, a dynamic isolation and protection module, a reverse tracking and tracing module, and a redirection and isolation protection module;

[0007] The traffic anomaly detection and analysis module discovers abnormal traffic by analyzing the traffic characteristics from different devices and applications in the 5G network. Based on a machine learning model, by training a large dataset of normal traffic and attack traffic, it automatically learns the normal pattern of traffic. Once traffic deviates from the normal pattern, it is quickly marked as a potential intrusion behavior.

[0008] The data encryption and tampering detection module encrypts the network transmission data using advanced encryption algorithms to ensure that the data is not stolen or tampered with during transmission. At the same time, combined with data tampering detection technology, it monitors the integrity of data packets in real time. Once data tampering is detected, it is automatically marked as a potential security threat.

[0009] The anomaly analysis and evaluation module conducts in-depth learning analysis on the behavior of terminal users accessing the 5G network, establishes a behavior model for each user based on historical data, and discovers abnormal user behavior. When a user's behavior deviates from their historical pattern, it automatically issues an alarm and evaluates the risk level of the user's behavior.

[0010] The attack prediction and prevention module monitors the network status and traffic changes in real time. Based on the current network environment, attack trends, and potential threats, the system predicts possible network attacks and takes preventive measures, such as automatically switching network paths and blocking malicious IPs.

[0011] The dynamic isolation and protection module dynamically isolates the network according to the usage of 5G network resources to ensure that network resources in different regions and at different levels are not affected by the spread of attacks.

[0012] The reverse tracing and source tracing module quickly identifies the attack source and path through deep packet analysis and reverse tracing technology for source tracing. Using global real-time monitoring and the timestamp information of data packets, the system restores the entire process of the attack behavior.

[0013] The redirection and isolation protection module guides malicious traffic to a virtual isolation environment for analysis and detection through redirection and traffic splitting technologies.

[0014] To further optimize this technical solution, the traffic anomaly detection and analysis module adopts a hybrid architecture combining a convolutional neural network (CNN) and a long short-term memory network (LSTM) to adaptively capture the spatial features and temporal dynamic changes of traffic and perform a detection process based on an adaptive traffic pattern.

[0015] To further optimize this technical solution, the detection process based on the adaptive traffic pattern includes the following specific steps:

[0016] Feature extraction and spatial mapping;

[0017] Temporal pattern learning and capture;

[0018] Anomaly detection and adaptive threshold judgment;

[0019] Model training and adjustment.

[0020] To further optimize this technical solution, in the data encryption and tampering detection module, a quantum encryption and data tampering detection model is constructed, and the model construction steps are as follows:

[0021] Quantum key distribution (QKD);

[0022] Quantum encryption process;

[0023] Packet integrity detection;

[0024] Dynamic key update and detection.

[0025] To further optimize this technical solution, the anomaly analysis and evaluation module incorporates a model that combines behavioral biometrics and multimodal analysis for user behavior anomaly analysis and risk assessment;

[0026] This model does not rely on single behavioral data such as login time, location, and device fingerprint, but comprehensively considers the user's operation habits, historical behavior patterns, and terminal device information, and uses a deep learning model for multi-dimensional analysis to achieve more accurate anomaly detection and risk assessment.

[0027] When the model that combines behavioral biometrics and multimodal analysis is used to further optimize this technical solution, it includes the following specific processes:

[0028] User behavior pattern establishment;

[0029] Anomaly detection;

[0030] Multimodal anomaly analysis;

[0031] Risk assessment and security measures;

[0032] Model update and adaptability enhancement.

[0033] When the attack prediction and prevention module is used to further optimize this technical solution, it includes the following processes:

[0034] Attack environment modeling;

[0035] Attack prediction model;

[0036] Reinforcement learning defense strategy optimization;

[0037] Attack prevention and emergency response;

[0038] Attack recognition and continuous optimization.

[0039] To further optimize this technical solution, in the process of attack prediction and prevention, it specifically includes:

[0040] Collect network status data as the input for reinforcement learning and deep learning models;

[0041] Based on deep learning such as CNN and LSTM, predict the occurrence probability of network attacks;

[0042] Continuously optimize the defense strategy through reinforcement learning algorithms such as Q-learning or DQN to enhance the system's ability to respond to new attacks;

[0043] After predicting an attack, select the optimal defense measure according to the reinforcement learning model and execute it automatically;

[0044] Combine online learning and transfer learning techniques to continuously optimize the defense strategy and adapt to new attacks.

[0045] To further optimize this technical solution, the dynamic isolation and protection module is based on the dynamic isolation technology of software-defined network (SDN) and combines network slicing technology. By flexibly controlling the access rights and resource allocation of different network slices, accurate network resource isolation is achieved without affecting the overall network performance;

[0046] Once the system detects an attack behavior, automatically isolate the attacked area and physically or logically isolate it from the normal network to prevent the spread of the attack.

[0047] To further optimize this technical solution, the redirection and isolation protection module is based on the traffic diversion mechanism of "deception technology". By simulating a real network environment, it induces attackers to direct malicious traffic to a virtual "honeypot" network. The "honeypot" network effectively simulates a real network system, analyzes the characteristics of attack traffic in real time, and generates a defense strategy.

[0048] Compared with the prior art, the present invention provides a network intrusion intelligent detection system based on a 5G network, which has the following beneficial effects:

[0049] This network intrusion intelligent detection system based on a 5G network can achieve more efficient and accurate intrusion detection and threat defense in a 5G network environment by integrating a variety of advanced technologies and intelligent modules. Compared with traditional rule-based detection methods, the system can adaptively learn and identify new attack patterns, enhancing the detection ability for zero-day attacks, variant attacks, and advanced persistent threats (APTs). In addition, by combining deep learning and reinforcement learning algorithms, the system can predict potential attacks in a dynamically changing network environment and automatically optimize the defense strategy, improving the response speed and accuracy of the defense system. Brief Description of the Drawings

[0050] Figure 1 This is a schematic structural diagram of an intelligent network intrusion detection system based on the 5G network proposed by the present invention;

[0051] Figure 2 This is a schematic flowchart of a time-series pattern adaptive detection model in an intelligent network intrusion detection system based on the 5G network proposed by the present invention;

[0052] Figure 3 This is a schematic flowchart of an encryption and data tampering detection model in an intelligent network intrusion detection system based on the 5G network proposed by the present invention;

[0053] Figure 4 This is a schematic flowchart of an anomaly analysis and evaluation model in an intelligent network intrusion detection system based on the 5G network proposed by the present invention;

[0054] Figure 5 This is a schematic flowchart of an attack prediction and prevention model in an intelligent network intrusion detection system based on the 5G network proposed by the present invention. Specific embodiments

[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] Embodiment 1:

[0057] Please refer to Figures 1-5 , an intelligent network intrusion detection system based on the 5G network, including a traffic anomaly detection and analysis module, a data encryption and tampering detection module, an anomaly analysis and evaluation module, an attack prediction and prevention module, a dynamic isolation and protection module, a reverse tracking and tracing module, and a redirection and isolation protection module.

[0058] By integrating a variety of advanced technologies and intelligent modules, it can achieve more efficient and accurate intrusion detection and threat defense in a 5G network environment. Compared with traditional rule-based detection methods, the system can adaptively learn and identify new attack patterns, enhancing the detection ability for zero-day attacks, variant attacks, and advanced persistent threats (APTs). In addition, by combining deep learning and reinforcement learning algorithms, the system can predict potential attacks in a dynamically changing network environment and automatically optimize defense strategies, improving the response speed and accuracy of the defense system.

[0059] The traffic anomaly detection and analysis module discovers abnormal traffic by analyzing the traffic characteristics from different devices and applications in the 5G network. Based on a machine learning model, by training a large dataset of normal traffic and attack traffic, it automatically learns the normal pattern of traffic. Once traffic deviates from the normal pattern, it is quickly marked as a potential intrusion behavior.

[0060] In this embodiment, the traffic anomaly detection and analysis module adopts a hybrid architecture combining a convolutional neural network (CNN) and a long short-term memory network (LSTM) to adaptively capture the spatial features and temporal dynamic changes of traffic and perform a detection process based on an adaptive traffic pattern.

[0061] An adaptive traffic recognition method based on deep learning is adopted, and a convolutional neural network (CNN) and a long short-term memory network (LSTM) are combined to analyze the traffic time series. The spatial features of traffic data are extracted by CNN, and then the LSTM is used to capture the law of temporal changes, enhancing the system's detection ability for zero-day attacks and variant attacks.

[0062] Furthermore, the detection process based on the adaptive traffic pattern includes the following specific steps:

[0063] S100: Feature extraction and spatial mapping;

[0064] S101: Temporal pattern learning and capture;

[0065] S102: Anomaly detection and adaptive threshold judgment;

[0066] S103: Model training and adjustment.

[0067] The data encryption and tampering detection module encrypts the network transmission data by using an advanced encryption algorithm to ensure that the data is not stolen or tampered with during the transmission process. At the same time, it combines data tampering detection technology to monitor the integrity of data packets in real time. Once data tampering is detected, it is automatically marked as a potential security threat.

[0068] In this embodiment, in the data encryption and tampering detection module, a quantum encryption and data tampering detection model is constructed, and the model construction steps are as follows:

[0069] S200: Quantum key distribution (QKD);

[0070] S201: Quantum encryption process;

[0071] S202: Packet integrity detection;

[0072] S203: Dynamic key update and detection.

[0073] Quantum encryption technology is introduced to enhance the security of data transmission. Quantum key distribution (QKD) is applied in 5G networks, which can not only prevent conventional eavesdropping attacks but also resist the cracking threats that may be brought by quantum computing.

[0074] The anomaly analysis and evaluation module conducts in-depth learning analysis on the behaviors of end users accessing the 5G network, establishes a behavior model for each user based on historical data, and discovers abnormal user behaviors; when a user's behavior deviates from their historical pattern, it automatically issues an alarm and evaluates the risk level of the user's behavior.

[0075] In this embodiment, the anomaly analysis and evaluation module incorporates a model that combines behavioral biometric technology and multimodal analysis for abnormal user behavior analysis and risk assessment.

[0076] This model does not rely on a single piece of behavioral data, such as login time, location, and device fingerprint. Instead, it comprehensively considers the user's operation habits, historical behavior patterns, and terminal device information, and uses a deep learning model for multi-dimensional analysis to achieve more accurate anomaly detection and risk assessment.

[0077] When the model that combines behavioral biometric technology and multimodal analysis is in use, it includes the following specific processes:

[0078] S300: Establishment of user behavior patterns;

[0079] S301: Anomaly detection;

[0080] S302: Multimodal anomaly analysis;

[0081] S303: Risk assessment and security measures;

[0082] S304: Model update and adaptability enhancement.

[0083] Combining behavioral biometric technology and multimodal analysis can combine multiple pieces of information such as the user's operation habits, login location, and device fingerprint to perform more accurate anomaly detection. Especially in 5G networks, user terminals are more diverse and complex, and behavior recognition and analysis are more challenging.

[0084] The attack prediction and prevention module, by continuously monitoring the network status and traffic changes, the system predicts possible network attacks based on the current network environment, attack trends, and potential threats and takes preventive measures, such as automatically switching network paths and blocking malicious IPs.

[0085] In this embodiment, when the attack prediction and prevention module conducts attack prediction and prevention, it includes the following processes:

[0086] S400: Modeling of the attack environment;

[0087] S401: Attack prediction model;

[0088] S402: Optimization of reinforcement learning defense strategy;

[0089] S403: Attack prevention and emergency response;

[0090] S404: Attack identification and continuous optimization.

[0091] Specifically include:

[0092] Collect network status data as the input of reinforcement learning and deep learning models;

[0093] Based on deep learning such as CNN and LSTM, predict the occurrence probability of network attacks;

[0094] Continuously optimize the defense strategy through reinforcement learning algorithms such as Q - learning or DQN to enhance the system's ability to handle new types of attacks;

[0095] After predicting an attack, select the optimal defense measure according to the reinforcement learning model and execute it automatically;

[0096] Combine online learning and transfer learning techniques to continuously optimize the defense strategy and adapt to new types of attacks.

[0097] The reinforcement learning algorithm is introduced. By simulating the environment of various attack behaviors, the model is trained to make autonomous decisions and optimize the defense strategy. The introduction of reinforcement learning enables the system to not only identify known attack types but also predict possible future new types of attacks.

[0098] Dynamic isolation and protection module, according to the usage of 5G network resources, dynamically performs network isolation to ensure that network resources in different regions and at different levels are not affected by the spread of attacks.

[0099] In this embodiment, the dynamic isolation and protection module is based on the dynamic isolation technology of software - defined network (SDN) and combines network slicing technology. By flexibly controlling the access rights and resource allocation of different network slices, accurate network resource isolation is achieved without affecting the overall network performance;

[0100] Once the system detects an attack behavior, it automatically isolates the attacked area and physically or logically isolates it from the normal network to prevent the spread of the attack.

[0101] Reverse tracking and tracing module, through deep packet analysis and reverse tracking technology, quickly identifies the attack source and path for tracing. Using global real - time monitoring and the timestamp information of data packets, the system restores the whole process of the attack behavior.

[0102] In this embodiment, in a 5G network, attackers usually use camouflage means to hide the attack source, increasing the difficulty of tracking. A traceability mechanism based on blockchain technology is introduced. By leveraging the immutability and transparency of the blockchain, it ensures that the tracking records of the attack path can be permanently stored and not tampered with, providing a strong evidence chain.

[0103] The redirection and isolation protection module uses redirection and traffic splitting technologies to divert malicious traffic to a virtual isolation environment for analysis and detection.

[0104] In this embodiment, the redirection and isolation protection module, based on the traffic splitting mechanism of "deception technology", by simulating a real network environment, induces the attacker to divert malicious traffic to a virtual "honeypot" network. The "honeypot" network effectively simulates a real network system, analyzes the characteristics of the attack traffic in real time, and generates a defense strategy.

[0105] Embodiment 2:

[0106] Please refer to Figures 2-5 , for the intelligent network intrusion detection system based on the 5G network described in Embodiment 1, specific implementation applications are carried out for individual modules.

[0107] As Figure 2 shown, in the traffic anomaly detection and analysis module, considering the characteristics of the 5G network (high speed, large number of connections, low latency), a time-series pattern adaptive detection model is designed to effectively identify normal traffic and abnormal traffic. Based on the time-series characteristics of the traffic and combining the capabilities of deep learning, it can learn the traffic pattern from historical data and predict and detect abnormal traffic.

[0108] Suppose we have a traffic dataset , where represents the traffic characteristics at a certain time point (which can be various network metrics, such as packet size, transmission rate, source / destination IP, etc.), and is the label of the traffic at this time point, marked as "normal" or "abnormal". The goal of the model is to learn the patterns extracted from normal traffic and abnormal traffic and automatically identify potential attack behaviors.

[0109] Step 1: Feature extraction and spatial mapping

[0110] First, preprocess the traffic feature to convert it into a two-dimensional format suitable for convolution operations. Specifically, we can convert each traffic data point into a multi-dimensional feature matrix, where each dimension represents different network metrics (for example, transmission rate, packet length, delay, etc.). For time-series traffic data, we can define a sliding window to extract the information of the local area.

[0111] Suppose is the traffic flow sequence within a time period, and the convolution operation can be described as:

[0112]

[0113] where is the convolution kernel, is the traffic flow feature at time point and is the bias term, and \( m \) is the size of the convolution kernel. Through the convolution operation, we can extract local traffic patterns.

[0114] Step 2: Temporal Pattern Learning and Capture

[0115] After obtaining the output of the convolutional layer, the traffic flow sequence will be fed into a Long Short-Term Memory network (LSTM). LSTM can capture dependencies over long time spans, which is particularly important for temporal data in 5G networks. The core calculation formula of LSTM is as follows:

[0116]

[0117] where is the forget gate, is the input gate, is the candidate memory cell, is the memory cell, is the output gate, is the hidden state. LSTM can dynamically remember or forget important information in historical traffic data and capture temporal dependencies through these gating mechanisms.

[0118] Step 3: Anomaly Detection and Adaptive Threshold Judgment

[0119] Based on the features and temporal information extracted by convolution and LSTM, we need to classify the traffic flow to determine whether it is abnormal. Here, we introduce an adaptive threshold function to make a judgment based on the traffic flow features at each time point and the patterns learned from history. We assume that the predicted value of the traffic flow can be obtained in the following way:

[0120]

[0121] where are the weights of the prediction layer, are the features output by convolution and LSTM, indicates whether the traffic flow is normal. We use the adaptive threshold to determine the division between abnormal and normal:

[0122]

[0123] Among them, is a threshold value dynamically adjusted according to the current traffic environment and is adjusted as the traffic changes. Specifically, it can be dynamically calculated through the variance and mean of historical traffic:

[0124]

[0125] Among them, is the mean of the predicted values of historical traffic, is the standard deviation, is a constant controlling sensitivity, used to balance the occurrence of false positives and false negatives.

[0126] Step 4: Model training and adjustment

[0127] With a large dataset of normal traffic and attack traffic, we can train this model using standard supervised learning methods. By optimizing the loss function:

[0128]

[0129] to train the model parameters , enabling the model to accurately distinguish normal traffic from abnormal traffic.

[0130] In addition, an adaptive learning rate and an early stopping strategy are used to optimize the generalization ability of the model, ensuring that the model can not only identify known attack patterns but also adapt to new attack means.

[0131] In practical applications, the system first trains this model by collecting a large amount of normal traffic and attack traffic data. After training is completed, the system can input the traffic characteristics at each moment into the model. After convolution and LSTM processing, the predicted value is output to determine whether the traffic is abnormal. If the predicted value exceeds the dynamically adjusted threshold , then this traffic is determined to be abnormal and the alarm mechanism is triggered.

[0132] As Figure 3 shown, in the data encryption tampering detection module, the encryption and data tampering detection model includes the following processes:

[0133] Step 1: Quantum key distribution (QKD)

[0134] Quantum key distribution (QKD) uses qubits to transmit keys. Once the states of these qubits are stolen or measured, irreversible changes will occur, thus revealing eavesdropping behavior.

[0135] In QKD, the key generation process of qubits can be expressed as:

[0136]

[0137] where is the amplitude of the qubit, is the quantum state, representing the superposition state of the qubit. The key is generated through the superposition state or entangled state of qubits. When a qubit is stolen or observed, its quantum state will change irreversibly, and thus it can be detected by the receiving party.

[0138] In a 5G network, QKD is used to generate symmetric keys, and the keys are used for subsequent data encryption. After the sender and the receiver complete the QKD process through the quantum channel and generate the shared key, both parties can use this key for subsequent encryption operations. If there is eavesdropping, the QKD protocol will detect it and interrupt the key generation process in a timely manner.

[0139] Step 2: Quantum encryption process

[0140] After using the shared key generated by QKD, the data will be encrypted. We adopt a method that combines quantum encryption and traditional encryption algorithms (such as the composite encryption method of quantum encryption and traditional encryption). Assume that the data stream is the plaintext data to be encrypted. The data stream after quantum encryption can be expressed as:

[0141]

[0142] where represents the encrypted data, represents the quantum encryption operation, is the quantum key. The quantum encryption operation encrypts jointly through qubits and traditional encryption algorithms (such as AES) to ensure the security of data under quantum computing attacks.

[0143] The sender uses the shared quantum key to encrypt the data. In a 5G network, adopting the quantum encryption algorithm ensures that even if a quantum computer can crack the traditional encryption algorithm, the security of the data can still be guaranteed.

[0144] Step 3: Packet integrity detection

[0145] To prevent data from being tampered with during transmission, we introduce a hash function and a timestamp, and combine digital signature technology for integrity detection. For each data packet , calculate its hash value and sign it:

[0146]

[0147] Among them, is the hash value of the data packet and is the digital signature generated based on the private key The hash value and the signature are sent together as the integrity identifier of the data packet.

[0148] After receiving the data packet, the receiver first verifies the signature through the public key and checks the hash value of the data packet. If the data packet is not tampered with during transmission, the hash value and the signature match.

[0149] Tamper detection formula:

[0150]

[0151] If the verification fails, it means that the data packet is tampered with during transmission, and the system will automatically trigger the alarm mechanism.

[0152] The sender calculates the hash value of the data packet and signs it, and the receiver verifies it through the public key. In the 5G network, combining the timestamp and the hash value can further enhance the real-time performance and accuracy of tamper detection, especially in a high-speed and large-scale network environment.

[0153] Step 4: Dynamic key update and detection

[0154] To further enhance the security of data transmission, the system will regularly update the key to avoid the threats of key leakage or quantum computing. Each time the key is updated, a new quantum key and a new encryption key will be generated to ensure that the system does not rely on the same key for a long time. The update process can be represented by the following formula:

[0155]

[0156] Among them, is the amplitude of the new qubit, is the new quantum state, representing the new quantum key. The new key is also redistributed through the QKD protocol to ensure the security of the update process.

[0157] Regularly regenerating and distributing the key is to avoid the potential security risks of using the same key for a long time. Especially in the context of the gradual maturity of quantum computing technology, timely key update helps to improve the security of data transmission.

[0158] Such as Figure 4As shown in the figure, in the anomaly analysis and assessment module, the goal of the model is to identify behavioral anomalies by analyzing the user's historical behavior patterns, and then evaluate their risk levels and trigger corresponding security measures.

[0159] The model is constructed as follows:

[0160] Step 1: Establishment of user behavior patterns

[0161] The user's behavior pattern can be regarded as a set of points in a high-dimensional space, where each point represents the behavioral characteristics of the user at a certain moment. We assume that the behavior pattern of each user can be represented as a vector in the multi-dimensional feature space:

[0162]

[0163] where, represents the user at time behavior feature vector, represents the th feature (such as operation habits, device fingerprints, login locations, etc.), is the dimension number of the behavior features. These feature data can be collected through sensors (such as GPS, device fingerprint recognition, etc.), operation logs (such as clicks, keyboard inputs, mouse operations, etc.) and the user's historical behavior.

[0164] To establish the user's behavior pattern, we use an autoencoder to compress and extract the main patterns of these behavior features. The autoencoder learns the normal behavior pattern of the user by minimizing the reconstruction error.

[0165] Step 2: Anomaly detection

[0166] Once the model has established the user's behavior pattern, we will then compare the new behavior data with the historical model. If the current behavior deviates from the historical pattern, the system will mark it as an abnormal behavior. To evaluate the deviation, we can define a behavior deviation metric , and determine whether it is abnormal by calculating the distance between the current behavior feature vector and the historical pattern:

[0167]

[0168] where, represents -norm, which is used to measure the difference between the current behavior and the normal behavior. For example, the Euclidean distance ( ) is used to measure the degree of deviation of the behavior. If exceeds a preset threshold , the system will mark this behavior as abnormal.

[0169] Step 3: Multimodal Anomaly Analysis

[0170] In traditional behavior analysis models, usually only a single data source is considered, such as the user's login time, device fingerprint, etc. However, in a 5G environment, the user's behavior information is more complex, and it is often necessary to combine multiple information sources to make accurate judgments. Therefore, we incorporate multimodal analysis into the model.

[0171] Suppose we have multiple modalities , where each modality represents a different information source (such as user behavior logs, geographical location information, device fingerprints, etc.). The behavior characteristics of each modality can be expressed as:

[0172]

[0173] To fuse multimodal information, we use a weighted fusion strategy, assign a weight to each modality , and then perform a weighted average of the anomaly scores of all modalities to obtain the final anomaly score :

[0174]

[0175] where represents the anomaly score of the th modality, and the weight is dynamically adjusted according to the importance and reliability of the modality. Through multimodal fusion, we can more accurately evaluate the anomaly of user behavior on the basis of considering multiple pieces of information.

[0176] Step 4: Risk Assessment and Security Measures

[0177] Once an abnormal behavior is detected, next we need to conduct a risk assessment on this behavior. According to the severity and frequency of the anomaly, we use a risk assessment function to quantify the risk level of the behavior , and decide whether to take further security measures:

[0178]

[0179] where is the risk assessment function, is the anomaly score, is the behavior tolerance threshold of the user (dynamically calculated based on historical behavior and risk models). If exceeds a preset risk threshold , the system will trigger a security alert or take defensive measures (such as forced authentication, restricted access rights, etc.).

[0180] Step 5: Model Update and Adaptability Enhancement

[0181] Since the user's behavior pattern may change over time, we need to update the user's behavior model regularly. Each time new behavior data arrives, the system incorporates it into the training set and uses incremental learning (such as online learning algorithms) to update the autoencoder model, ensuring that the model can adapt to changes in user behavior.

[0182] As Figure 5 shown, in a 5G network, due to a wider attack surface, more diverse and complex attack methods, traditional defense systems often struggle to cope with new or mutated attacks. To address this issue, the attack prediction and prevention model combines deep learning and reinforcement learning techniques, aiming to proactively take corresponding preventive measures by dynamically monitoring and predicting the occurrence of network attacks.

[0183] The attack prediction and prevention model is constructed as follows:

[0184] Step 1: Attack environment modeling

[0185] First, the attack environment needs to be defined, which includes network status, traffic patterns, historical attack data, and external threat intelligence, etc. These data will be used as the input of the model to train the reinforcement learning model to predict the probability of an attack occurring.

[0186] Assume that the network status at time can be represented as a vector , and this status includes information such as the current network traffic, device status, network load, user behavior, etc.:

[0187]

[0188] Among them, represents the th feature in the network status, such as the change rate of traffic, the number of connections, the packet loss rate, etc.

[0189] Step 2: Attack prediction model

[0190] We assume that the network status is time-series data, and the model will predict the probability of future attacks based on historical data.

[0191] The output of the attack prediction is a probability , indicating the probability of a network attack occurring within the time .

[0192]

[0193] Among them, is a deep learning model trained based on historical data, Represent the parameters of the model. Through training, the model can learn the occurrence patterns of attacks from historical attack patterns, thereby predicting the probability of future attacks.

[0194] Step 3: Optimization of Reinforcement Learning Defense Strategy

[0195] Through the reinforcement learning algorithm, the system can adopt appropriate defense strategies when potential attacks are monitored. Suppose we use Q-learning or Deep Q-Network (DQN) to train the defense strategy. First, a state space needs to be defined , representing various possible states of the network (such as attack and non-attack states, whether network traffic is abnormal, etc.), and an action space , representing the defense measures that the system can take (such as automatically switching network paths, blocking malicious IPs, restricting bandwidth, etc.).

[0196] Through the training of Q-learning or DQN, the system can continuously optimize the defense strategy, making the defense measures more intelligent and able to make corresponding adjustments according to the type and trend of attacks.

[0197] Step 4: Attack Prevention and Emergency Response

[0198] After the system predicts potential attacks and optimizes the defense strategy through the reinforcement learning model, the system will take corresponding preventive measures. Suppose the preventive measures taken by the system can be represented by the following formula:

[0199]

[0200] That is, in the current state , the system selects the optimal defense action according to the Q-learning model and executes the corresponding preventive measures. These measures can include but are not limited to:

[0201] Automatically switch network paths to bypass attack traffic;

[0202] Start an intelligent firewall to block malicious IPs;

[0203] Restrict the bandwidth of certain suspicious devices.

[0204] If the system fails to take effective defense measures and detects an attack, the system will trigger an emergency response mechanism, such as notifying the administrator, starting isolation measures, sending alerts, etc.

[0205] Step 5: Attack Identification and Continuous Optimization

[0206] During the defense process, the system not only needs to predict and prevent attacks, but also continuously optimize the defense model to ensure the ability to respond to new types of attacks. For example, a model based on deep Q-learning can continuously perform online learning. After each attack event, the system updates the Q-values based on feedback and rewards, thereby improving future defense strategies.

[0207] Reinforcement learning not only helps the system predict known attacks, but also enables it to autonomously learn and optimize defense strategies according to the dynamic network environment, enhancing the system's ability to respond to unknown attacks. This proactive prediction and defense mechanism is the key to addressing complex 5G network security challenges.

[0208] The beneficial effects of the present invention are as follows:

[0209] The intelligent network intrusion detection system based on 5G network can achieve more efficient and accurate intrusion detection and threat defense in the 5G network environment by integrating a variety of advanced technologies and intelligent modules. Compared with traditional rule-based detection methods, the system can adaptively learn and identify new attack patterns, enhancing the detection ability for zero-day attacks, variant attacks, and advanced persistent threats (APTs). In addition, by combining deep learning and reinforcement learning algorithms, the system can predict potential attacks in a dynamically changing network environment and automatically optimize defense strategies, improving the response speed and accuracy of the defense system.

[0210] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0211] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An intelligent network intrusion detection system based on 5G network, characterized in that, It includes a traffic anomaly detection and analysis module, a data encryption and tampering detection module, an anomaly analysis and evaluation module, an attack prediction and prevention module, a dynamic isolation and protection module, a reverse tracing and source tracing module, and a redirection and isolation protection module; The traffic anomaly detection and analysis module discovers abnormal traffic by analyzing the traffic characteristics from different devices and applications in the 5G network; Based on a machine learning model, by training a large dataset of normal traffic and attack traffic, it automatically learns the normal pattern of traffic. Once traffic deviates from the normal pattern, it is quickly marked as a potential intrusion behavior; The data encryption and tampering detection module encrypts the network transmission data using advanced encryption algorithms to ensure that the data is not stolen or tampered with during transmission. At the same time, combined with data tampering detection technology, it real-time monitors the integrity of data packets. Once it is found that the data is tampered with, it is automatically marked as a potential security threat; The anomaly analysis and evaluation module conducts in-depth learning analysis on the behavior of end-users accessing the 5G network, establishes a behavior model for each user based on historical data, and discovers abnormal user behavior; When the user's behavior deviates from its historical pattern, it automatically issues an alarm and evaluates the risk level of the user's behavior; The attack prediction and prevention module, by real-time monitoring the network status and traffic changes, the system predicts possible network attacks according to the current network environment, attack trends and potential threats and takes preventive measures, such as automatically switching network paths, blocking malicious IPs; The dynamic isolation and protection module dynamically isolates the network according to the usage of 5G network resources to ensure that network resources in different regions and at different levels are not affected by the spread of attacks; The reverse tracing and source tracing module, through deep packet analysis and reverse tracing technology, quickly identifies the attack source and path for source tracing. Using global real-time monitoring and the timestamp information of data packets, the system restores the whole process of the attack behavior; The redirection and isolation protection module, through redirection and traffic splitting technologies, guides malicious traffic to a virtual isolation environment for analysis and detection.

2. An intelligent network intrusion detection system based on a 5G network according to claim 1, characterized in that, The traffic anomaly detection and analysis module adopts a hybrid architecture combining a convolutional neural network (CNN) and a long short-term memory network (LSTM) to adaptively capture the spatial features and temporal dynamic changes of traffic and perform a detection process based on an adaptive traffic pattern.

3. The intelligent network intrusion detection system based on 5G network according to claim 2, wherein The detection process based on the adaptive traffic pattern includes the following specific steps: Feature extraction and spatial mapping; Temporal pattern learning and capture; Anomaly detection and adaptive threshold judgment; Model training and adjustment.

4. An intelligent network intrusion detection system based on a 5G network according to claim 1, characterized in that, In the data encryption and tampering detection module, a quantum encryption and data tampering detection model is constructed. The steps for model construction are as follows: Quantum key distribution (QKD); Quantum encryption process; Data packet integrity detection; Dynamic key update and detection.

5. An intelligent network intrusion detection system based on a 5G network according to claim 1, characterized in that, The anomaly analysis and evaluation module has a built-in model combining behavior biometric technology and multimodal analysis for user behavior anomaly analysis and risk assessment; This model does not rely on a single piece of behavioral data, such as login time, location, and device fingerprint. Instead, it comprehensively considers the user's operation habits, historical behavior patterns, and terminal device information, and uses a deep learning model for multi-dimensional analysis to achieve more accurate anomaly detection and risk assessment.

6. An intelligent network intrusion detection system based on a 5G network according to claim 5, characterized in that, When the model combining behavioral biometrics technology and multi-modal analysis is in use, it includes the following specific processes: Establishment of user behavior patterns; Anomaly detection; Multi-modal anomaly analysis; Risk assessment and security measures; Model update and adaptability enhancement.

7. An intelligent network intrusion detection system based on a 5G network according to claim 1, characterized in that, When the attack prediction and prevention module conducts attack prediction and prevention, it includes the following processes: Attack environment modeling; Attack prediction model; Optimization of reinforcement learning defense strategies; Attack prevention and emergency response; Attack identification and continuous optimization.

8. An intelligent network intrusion detection system based on a 5G network according to claim 7, characterized in that, In the process of attack prediction and prevention, it specifically includes: Collect network status data as the input for reinforcement learning and deep learning models; Based on deep learning such as CNN and LSTM, predict the occurrence probability of network attacks; Continuously optimize the defense strategy through reinforcement learning algorithms such as Q-learning or DQN to enhance the system's ability to respond to new types of attacks; After predicting an attack, select the optimal defense measure according to the reinforcement learning model and execute it automatically; Combine online learning and transfer learning technologies to continuously optimize the defense strategy and adapt to new types of attacks.

9. An intelligent network intrusion detection system based on 5G network according to claim 1, characterized in that, The dynamic isolation and protection module is based on the dynamic isolation technology of software-defined network (SDN) and combines network slicing technology. By flexibly controlling the access rights and resource allocation of different network slices, it can achieve precise network resource isolation without affecting the overall network performance; Once the system detects an attack behavior, it automatically isolates the attacked area and physically or logically isolates it from the normal network to prevent the spread of the attack.

10. An intelligent network intrusion detection system based on a 5G network according to claim 1, characterized in that, The redirection and isolation protection module is based on the traffic diversion mechanism of "deception technology". By simulating a real network environment, it induces attackers to direct malicious traffic to a virtual "honeypot" network. The "honeypot" network effectively simulates a real network system, analyzes the characteristics of attack traffic in real time, and generates defense strategies.

Citation Information

Cited By

  • Internet of things card abnormal flow identification and multistage response control system

    CN120812593A

  • Cloud security intrusion analysis method applied to industrial data processing

    CN120825331A

  • A cloud security intrusion analysis method applied to industrial data processing

    CN120825331B

  • Multi-mode network intrusion behavior intelligent traceability and cooperative blocking system

    CN120896778A

  • Photovoltaic power station network security situation awareness and early warning method and system

    CN121000455A