Network attack dynamic detection and security protection method and system based on artificial intelligence

By constructing a dynamic network behavior map and a reinforcement learning algorithm to generate a protection instruction set, the insufficient identification of multi-protocol collaborative attack patterns in the existing technology is solved, and efficient and accurate network attack detection and protection are achieved.

CN120342748APending Publication Date: 2025-07-18TIBET LANGJIE INFORMATION TECH CO LTD
View PDF 0 Cites 20 Cited by

Patent Information

Application Number
CN202510655997.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing network attack detection and protection technologies are difficult to effectively deal with multi-protocol and cross-device collaborative attack modes, lack self-learning capabilities, and cannot achieve adaptive and efficient protection deployment in a dynamic network environment.

Method used

By collecting multi-protocol communication data streams, a dynamically updated network behavior map is built, and a protection instruction set is generated using deep residual timing networks and reinforcement learning algorithms to realize the identification and response to abnormal behaviors.

Benefits of technology

It significantly improves the ability to express behavior patterns on complex network structures, improves the accuracy and forward-looking detection, and ensures rapid blocking of high-risk behaviors and minimal disturbances in normal business.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342748A_ABST
    Figure CN120342748A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network attacks, in particular to a network attack dynamic detection and security protection method and system based on artificial intelligence, and the method comprises the following steps: S1, data collection: collecting a multi-protocol communication data flow of network equipment, and generating a multi-dimensional feature vector; s2, constructing a cross-protocol behavior graph: generating a dynamically updated network behavior graph; s3, anomaly detection: identifying an abnormal behavior mode through the deep residual sequential network, and outputting threat evaluation parameters; s4, protection strategy generation: generating a dynamic protection instruction set through a reinforcement learning decision algorithm; and S5, protection execution: executing the dynamic protection instruction set to complete safety protection operation. According to the method, the multi-protocol fusion behavior graph is constructed, and an abnormal detection mechanism of graph nerve and differential modeling and a dynamic response strategy driven by reinforcement learning are introduced, so that high-precision identification and efficient protection of network attacks are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network attacks, and particularly to a method and system for dynamically detecting and securely protecting network attacks based on artificial intelligence. Background Art

[0002] As enterprise information systems and critical infrastructure increasingly rely on network interconnections, network attacks have shown trends of diversification, automation, and chain evolution. The attack methods have gradually evolved from traditional single-point scanning to cross-protocol and cross-device collaborative attack patterns. Therefore, there is an urgent need to build an intelligent protection system with self-learning and self-perception capabilities to achieve dynamic detection and rapid response to network attack behaviors. Artificial intelligence technologies, especially methods such as graph neural networks, time series modeling, and reinforcement learning, provide new breakthrough means for network security situation awareness, enabling stronger generalization capabilities and effectiveness in communication behavior modeling, anomaly recognition, and response decision-making.

[0003] Most of the existing network attack detection and protection technologies rely on static feature matching, single-protocol traffic analysis, or fixed rule libraries for behavior recognition, and it is difficult to effectively cope with attack scenarios with hidden attack paths, heterogeneous protocol types, and complex behavior chains. On the one hand, there is a lack of a unified expression method for behavior characteristics in multi-protocol communication, making it difficult to completely model attack behaviors between different protocols. On the other hand, traditional detection algorithms usually ignore the spatio-temporal evolution relationship between devices and behaviors in the network structure, resulting in insufficient attack pattern recognition capabilities. At the same time, response strategies are usually based on manual settings or static configurations, and it is difficult to achieve adaptive, high-priority, and low-disturbance protection deployments in dynamic network environments. Summary of the Invention

[0004] The present invention provides a method and system for dynamically detecting and securely protecting network attacks based on artificial intelligence, which improves the real-time performance, accuracy, and response efficiency of network attack detection and is applicable to dynamic and complex enterprise-level or industrial-level network environments.

[0005] The method for dynamically detecting and securely protecting network attacks based on artificial intelligence includes the following steps:

[0006] S1, data collection: Collect multi-protocol communication data streams of network devices, extract original behavior characteristics through a heterogeneous protocol parsing engine, and generate a multi-dimensional feature vector including timestamp weights;

[0007] S2, cross-protocol behavior graph construction: Use the multi-dimensional feature vector as input, and generate a dynamically updated network behavior graph based on a cross-protocol session association algorithm. The network behavior graph includes device nodes, communication relationship edges, and behavior pattern subgraphs;

[0008] S3, Anomaly Detection: Input the network behavior graph into the dynamic detection model, identify the abnormal behavior patterns through the deep residual time series network, and output threat assessment parameters including threat level, attack type, and propagation path;

[0009] S4, Protection Strategy Generation: According to the threat assessment parameters, combined with the current network topology state parameters, generate a dynamic protection instruction set through the reinforcement learning decision algorithm;

[0010] S5, Protection Execution: Execute the dynamic protection instruction set to complete security protection operations including traffic cleaning, protocol filtering, and device isolation.

[0011] Optionally, the data collection in S1 includes:

[0012] S11, Multi-Protocol Data Stream Collection: Obtain the original communication data stream in a non-intrusive manner through bypass mirroring collection devices deployed at the network boundary and core switching nodes, and set up an information buffer for temporarily storing heterogeneous protocol data streams;

[0013] S12, Protocol Fingerprint Dynamic Matching: Use a protocol recognition algorithm based on packet header feature clustering for the collected original communication data stream to identify unknown protocol types;

[0014] S13, Protocol Semantic Parse Tree Construction: Construct a hierarchical structure parse tree for the identified protocol types;

[0015] S14, Time-Weighted Feature Calculation: For each protocol field, calculate the time decay weight ω t to reflect the data freshness;

[0016] S15, Multi-Dimensional Feature Vector Generation: Fuse the protocol field features and the time decay weight to generate a standardized multi-dimensional feature vector.

[0017] Optionally, the protocol fingerprint dynamic matching in S12 includes:

[0018] S121, Packet Header Preprocessing: Perform a truncation operation on the collected original communication data stream, extract the first λ bytes to form the protocol fingerprint feature H i ={b1, b2,..., b λ}, where λ is the preset packet header length, b j is the decimal value of the jth byte. For packets with a length less than λ, perform zero value padding, and filter the noise data that satisfies , where μ k is the mean of the kth byte in the historical data, ε = 3σ is the dynamic noise threshold, and σ is the historical standard deviation of the corresponding position;

[0019] S122, Feature Encoding Conversion: Convert the byte sequence of the message header into a numerical feature vector;

[0020] S123, Improved Similarity Calculation: Adopt a dual-modal similarity measurement method combining weighted Hamming distance and byte distribution entropy;

[0021] S124, Density Clustering Analysis: Use the improved adaptive density clustering algorithm DBSCAN to cluster fingerprint samples, and the core point condition is N ρ (H i ) ≥ N min , where N ρ (H i ) is the number of samples similar to sample H within the neighborhood of radius ρ, ρ is the clustering radius, and N i is the minimum neighborhood number threshold for core points; min is the minimum neighborhood number threshold for core points;

[0022] S125, Protocol Type Inference: Perform matching with known protocol samples on the clustering results to determine whether it belongs to an existing protocol category.

[0023] Optionally, the cross-protocol behavior graph construction in S2 includes:

[0024] S21, Device Node Dynamic Extraction: Generate a unique device identifier ID based on the multi-dimensional feature vector dev , when the device similarity Sim dev > k', it is determined to be the same device, where k' is the similarity threshold for device merging;

[0025] S22, Cross-Protocol Session Association: Calculate the transition probability P(s j |s i ) within the time window ΔT. When P(s j |s i ) > ι, establish an edge, where ι is the establishment threshold for cross-protocol communication edges;

[0026] S23, Relationship Edge Weight Calculation: Determine the initial weight W of the edge by combining communication frequency and time decay factor edge ;

[0027] S24, Behavior Subgraph Discovery: Use the improved spectral clustering algorithm to identify and extract behavior subgraphs in the graph structure;

[0028] S25, Graph Dynamic Update: Achieve incremental update of the behavior graph through an event-driven mechanism, and the trigger condition is where, respectively represent the adjacency matrices of the current and previous cycle graphs, ‖·‖ Fis the Frobenius norm of the matrix, ρ is the threshold for triggering updates due to changes in the graph structure. When the update trigger condition is satisfied, the operations to be performed include:

[0029] Remove all edge weights W edge Expired edges of <τ>, where τ is the edge weight threshold;

[0030] Merge all sub - graph similarities Sim subgraph Sub - graphs of >v', where v' is the sub - graph similarity merging threshold.

[0031] Optionally, the behavior sub - graph discovery in S24 includes:

[0032] S241, Graph structure pre - processing: Construct a weighted adjacency matrix A and normalize the node attribute vectors;

[0033] S242, Improved Laplacian matrix construction: Construct a hybrid Laplacian matrix L that fuses node attributes and topological structures hybrid ;

[0034] S243, Feature vector optimization: Perform eigen - decomposition on the hybrid Laplacian matrix L hybrid Extract the eigen - vectors corresponding to the top k largest eigenvalues and satisfy where, λ i is the eigenvalue of the Laplacian matrix, m is the total number of nodes, and ψ is the eigenvalue cumulative contribution rate threshold;

[0035] S244, Dynamic sub - graph clustering: Use an improved k - means clustering algorithm with a sliding time window constraint for dynamic sub - graph clustering;

[0036] S245, Sub - graph validity verification: Perform double - validity verification on each clustering result sub - graph C p including modularity constraint and diameter constraint.

[0037] Optionally, the anomaly detection in S3 includes:

[0038] S31, Graph spectrum spatio - temporal encoding: Combine a graph convolutional attention network (GCAN) with temporal causal convolution (TCC) to fuse the structural relationships between nodes and time - series information, and extract the spatio - temporal feature representation of the graph spectrum;

[0039] S32, Neural differential equation feature extraction: Model the continuous evolution process of graph spectrum features over time through a neural ordinary differential equation, use the spatio - temporal encoding result as the dynamic input, and extract the behavior change trend through a differential solver to achieve multi - scale modeling and state representation of potential anomaly patterns;

[0040] S33, Adversarial Generative Evaluation: Use a generative adversarial network to output threat levels, attack types, and propagation paths, and evaluate the credibility of the results through a discriminator to achieve intelligent identification of multi-dimensional threats.

[0041] Optionally, the generation of the protection strategy in S4 includes:

[0042] S41, Multi-dimensional State Encoding: Construct a joint state vector that integrates threat assessment results and network topology information

[0043] S42, Constrained Reinforcement Learning Policy Optimization: Use the PPO (Proximal Policy Optimization) algorithm to optimize the protection strategy under security constraints;

[0044] S43, Protection Instruction Compilation: Map the optimal actions selected in the policy network to an executable set of protection instructions.

[0045] Optionally, the protection execution in S5 includes:

[0046] S51, Dynamic Sorting of Instruction Priorities: Based on the threat level in the threat assessment parameters and the network asset value matrix, perform real-time priority division and execution sorting on the dynamic protection instruction set to generate a protection instruction execution sequence;

[0047] S52, Deployment of a Distributed Execution Engine: Select the optimal deployment node to execute protection operations according to the current network topology state and protection instruction type;

[0048] S53, Implementation of Fine-grained Protection Operations: Execute differentiated protection actions according to the instruction type.

[0049] Optionally, the implementation of the fine-grained protection operations includes:

[0050] Traffic Cleaning: Dynamically inject cleaning rules into the mirrored traffic path and use the threat fingerprint generation engine to perform bypass filtering on abnormal traffic;

[0051] Protocol Filtering: Reconstruct the parser logic of the corresponding protocol to intercept and block data packets carrying attack feature fields;

[0052] Device Isolation: Combine BGP routing flow specification hijacking and 802.1x port control policies to impose dual restrictions of physical isolation and logical isolation on controlled devices.

[0053] An artificial intelligence-based network attack dynamic detection and security protection system for implementing the above-mentioned artificial intelligence-based network attack dynamic detection and security protection method, including the following modules:

[0054] Data acquisition module: Collect multi-protocol communication data streams of network devices, and extract original behavior features through a heterogeneous protocol parsing engine to generate multi-dimensional feature vectors including timestamp weights;

[0055] Behavior graph construction module: Construct a dynamically updated network behavior graph based on multi-dimensional feature vectors. The network behavior graph includes device nodes, communication relationship edges, and behavior pattern subgraphs;

[0056] Anomaly detection module: Input the network behavior graph into a deep residual time series model to identify abnormal behavior patterns, and output threat assessment parameters including threat level, attack type, and propagation path;

[0057] Policy generation module: Generate a protection instruction set using a reinforcement learning decision algorithm based on threat assessment parameters and the current network topology status;

[0058] Protection execution module: Execute the protection instruction set to implement traffic cleaning, protocol filtering, and device isolation operations for network attacks.

[0059] Advantages of the present invention:

[0060] In the present invention, by introducing heterogeneous protocol parsing, time weighting mechanism, and multi-source data fusion technology, a standardized multi-dimensional feature vector is constructed, and combined with cross-protocol session association, a dynamically updated network behavior graph is generated, realizing unified representation and behavior association modeling among different communication protocols, and significantly improving the comprehensive expression ability for complex network structures and device behavior patterns.

[0061] In the present invention, by adopting a deep residual model combining graph convolutional attention mechanism and time causal convolution, and introducing neural differential equations to continuously model the feature evolution process, multi-scale and temporal consistency modeling of abnormal behaviors is realized. Cooperating with an adversarial generation evaluation network, threat parameters such as threat level, attack type, and propagation path can be output simultaneously, effectively overcoming the deficiency of traditional methods in weak recognition ability for sudden attacks, zero-day vulnerabilities, and chained attack paths, and greatly improving the detection accuracy and response forward-looking.

[0062] In the present invention, by constructing a dynamic policy optimization model based on reinforcement learning, on the basis of combining network topology status and threat assessment parameters, an executable instruction set including actions such as traffic cleaning, protocol filtering, and device isolation is generated, and node selection and task deployment are carried out through a distributed execution engine. Through the linkage mechanism of priority sorting, multi-level constraints, and fine-grained execution strategies, high-risk behaviors are quickly blocked and normal services are minimally disturbed, significantly improving the timeliness, intelligence, and coverage breadth of protection response. Description of the drawings

[0063] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only those of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0064] Figure 1 Schematic diagram of the detection and security protection method for the embodiments of the present invention;

[0065] Figure 2 Schematic diagram of the system function modules for the embodiments of the present invention. Detailed implementation manners

[0066] The present invention will be described in detail below with reference to the drawings and specific embodiments. For some well-known technologies, those skilled in the art can also adopt other alternative methods for implementation; moreover, the drawings are only for more specifically describing the embodiments and are not intended to specifically limit the present invention.

[0067] As Figure 1 shown, the network attack dynamic detection and security protection method based on artificial intelligence includes the following steps:

[0068] S1, Data collection: Collect the multi-protocol communication data streams of network devices, extract the original behavior characteristics through a heterogeneous protocol parsing engine, and generate a multi-dimensional feature vector including timestamp weights;

[0069] S2, Cross-protocol behavior graph construction: Use the multi-dimensional feature vector as the input, and generate a dynamically updated network behavior graph based on the cross-protocol session association algorithm. The network behavior graph includes device nodes, communication relationship edges, and behavior pattern sub-graphs;

[0070] S3, Anomaly detection: Input the network behavior graph into the dynamic detection model, identify the abnormal behavior patterns through a deep residual time series network, and output threat assessment parameters including threat level, attack type, and propagation path;

[0071] S4, Protection strategy generation: According to the threat assessment parameters, combined with the current network topology state parameters, generate a dynamic protection instruction set through a reinforcement learning decision algorithm;

[0072] S5, Protection execution: Execute the dynamic protection instruction set to complete security protection operations including traffic cleaning, protocol filtering, and device isolation.

[0073] The data collection in S1 includes:

[0074] S11, Multi - protocol data stream collection: Through bypass mirroring collection devices deployed at network boundaries and core switching nodes, obtain the original communication data stream in a non - invasive manner. Set up an information buffer for temporarily storing heterogeneous protocol data streams. The condition for the buffer capacity C is expressed as:

[0075] C = max(R×T win , C min );

[0076] Where, R is the network peak traffic rate, T win is the preset collection time window, and C min is the minimum capacity threshold to ensure data integrity;

[0077] S12, Protocol fingerprint dynamic matching: Adopt a protocol recognition algorithm based on packet - header feature clustering for the collected original communication data stream to identify unknown protocol types;

[0078] S13, Protocol semantic parsing tree construction: Construct a hierarchical structure parsing tree for the identified protocol types, expressed as:

[0079]

[0080] Where, Tree proto is the established hierarchical semantic structure tree, L is the number of protocol layers. For example, some protocols include multiple layers such as frame headers, command areas, and data areas, is the field type of the l - th layer, is the set of separator positions for separating fields;

[0081] S14, Time - weighted feature calculation: For each protocol field, calculate the time - decay weight ω t to reflect data freshness, expressed as:

[0082]

[0083] Where, α is the time - decay factor, and its value range is 0.05 - 0.2, t now is the current timestamp, and t i is the original timestamp corresponding to the data packet;

[0084] S15, Multi - dimensional feature vector generation: Integrate protocol field features and time - decay weights to generate a standardized multi - dimensional feature vector, expressed as:

[0085]

[0086] Where, is the standardized multi - dimensional feature vector, f1,..., f nThe numerical feature values of the 1st,... nth protocol fields respectively, σ1,... σ n The standard deviations of the 1st,... nth corresponding features respectively, and n is the total dimension of the multi-dimensional features;

[0087] The numerical feature value f of the protocol field is expressed as:

[0088]

[0089] where f k is the numerical feature value of the kth field, is the original value (string type, numerical type, enumeration type, IP address type) of the kth protocol field, is the numerical mapping function defined according to the field type;

[0090] (1) Numerical fields (such as port number, length, flag bit):

[0091] (2) Enumeration fields (such as protocol method, status code): After one-hot encoding and then sparse weight merging, it is expressed as:

[0092] where e i is the enumeration value set, γ i is the training weight of the ith enumeration value, is the indicator function, which is 1 when it holds, otherwise 0, and m is the number of enumeration values;

[0093] (3) IP address type fields (such as source / destination address): After converting the four segments of numbers of the IPv4 address into integers and then normalizing, it is expressed as:

[0094]

[0095] where a i ∈[0, 255] is the four decimal values of the IP;

[0096] (4) String type fields (such as User-Agent, Host name): After hash encoding and then taking the average value, it is expressed as:

[0097]

[0098] where s' is the string field, and Embed(s' i ) is the embedding value of the character or substring (a predefined hash function can be used).

[0099] The dynamic matching of the protocol fingerprint in S12 includes:

[0100] S121, Message Header Preprocessing: Perform a truncation operation on the collected original communication data stream, and extract the first λ bytes to form the protocol fingerprint feature H i ={b1, b2,..., b λ}, where λ is the preset message header length, and the value range is 16–64 bytes. b j ∈[0, 255] is the decimal value of the j-th byte. For messages with a length less than λ, zero-value padding is performed, and noise data satisfying is filtered, where μ k is the mean value of the k-th byte in the historical data, ε = 3σ is the dynamic noise threshold, and σ is the historical standard deviation at the corresponding position;

[0101] S122, Feature Encoding Conversion: Convert the message header byte sequence into a numerical feature vector, expressed as:

[0102]

[0103] where β = 256 is the byte normalization base, is the bitwise exclusive OR operation, m = 0xAA is the preset mask constant, f(b λ ) is the character printability encoding function,

[0104] S123, Improved Similarity Calculation: Adopt a dual-modal similarity measurement method combining weighted Hamming distance and byte distribution entropy, expressed as:

[0105]

[0106] where D(H i , H j ) is the final similarity distance value, used to measure the structural difference between two protocol fingerprints. H i , H j are the byte sequences of the i-th and j-th message headers respectively, respectively represent the values of the i-th and j-th messages at the k-th byte position. v k is the mutation weight of the k-th byte, d H is the improved Hamming distance function, E is the byte value distribution entropy, p c is the frequency of the byte value c in the sequence H, and γ = 0.3 is the entropy difference adjustment coefficient;

[0107] S124, Density Clustering Analysis: Use the improved adaptive density clustering algorithm DBSCAN to cluster the fingerprint samples. The core point condition is N ρ (H i ) ≥ Nmin , where N ρ (H i ) is the number of samples similar to the sample H within the neighborhood of radius ρ, ρ = 0.7D i is the clustering radius, D avg is the average similarity distance, N avg = 5 is the threshold for the minimum neighborhood number of core points; min S125, protocol type inference: Perform matching of known protocol samples on the clustering results to determine whether it belongs to the existing protocol category, expressed as:

[0108] S125, Protocol type inference: Perform matching of known protocol samples on the clustering results to determine whether it belongs to the existing protocol category, expressed as:

[0109]

[0110] where C k is the k-th cluster, S p is the set of feature samples corresponding to the known protocol p, P known is the set of currently recognized protocol categories. When Match(C k ) < δ, create a new protocol category P new , δ = 0.65 is the matching threshold.

[0111] The construction of the cross-protocol behavior graph in S2 includes:

[0112] S21, dynamic extraction of device nodes: Generate a unique device identifier ID based on the multi-dimensional feature vector dev , when the device similarity Sim dev > k', it is determined to be the same device, where k' = 0.85 is the similarity threshold for device merging, expressed as:

[0113]

[0114] where is the feature weight of protocol k, StrField k is the representative string field in protocol k (such as MAC address, device name, etc.), IPField k is the IP address field in protocol k (such as source / destination IP), is all the numerically transformed field feature sub-vectors in protocol k, and Hash is the unique device identifier generated by the hash function;

[0115]

[0116] where S i is the similarity score on the i-th dimension, including the similarity of string-type fields, the similarity of IP address-type fields and their behavior statistical features, and the similarity of protocol feature sub-vectors generated based on the combination of numerical and enumerated protocol fields, ωi is the weight for each similarity dimension;

[0117] S22, cross - protocol session association: Within the time window ΔT, calculate the transition probability P(s j |s i ), and establish an edge when P(s j |s i ) > ι, where ι = 0.6 is the edge - establishment threshold for cross - protocol communication, expressed as:

[0118]

[0119] where s i , s j are two heterogeneous - protocol sessions, represents the spatio - temporal feature vector of the session, including the start time, end time, and protocol feature vector, ζ = 0.5ΔT is the temperature coefficient, and Ω is the set of all sessions within the current time window;

[0120] S23, relationship - edge weight calculation: Combine the communication frequency and time - decay factor to determine the initial weight W edge of the edge, expressed as:

[0121]

[0122] where F com is the communication frequency within the current time window, F max is the historical maximum communication frequency, is the frequency - decay factor, v = 0.1 is the time - decay rate, t now is the current system timestamp, and t last is the timestamp of the most recent communication;

[0123] S24, behavior sub - graph discovery: Use the improved spectral clustering algorithm to identify and extract the behavior sub - graphs in the graph structure;

[0124] S25, graph - spectrum dynamic update: Achieve incremental update of the behavior graph through the event - driven mechanism, and the trigger condition is where, represent the adjacency matrices of the graph in the current and previous cycles respectively, ‖·‖ F is the Frobenius norm of the matrix, ρ = 0.15 is the threshold for triggering graph - structure change and update. When the update trigger condition is met, the operations to be performed include:

[0125] Remove the expired edges with all edge weights W edge < τ, where τ = 0.2 is the edge - weight threshold;

[0126] Merge the similarity Sim of all subgraphs subgraph Subgraphs of v', where v' = 0.7 is the merging threshold of subgraph similarity.

[0127] The behavior subgraph discovery in S24 includes:

[0128] S241, Graph structure preprocessing: Construct a weighted adjacency matrix A and normalize the node attribute vectors, expressed as:

[0129]

[0130] where A ij is the edge weight between node i and node j, are the multi-dimensional feature vectors of node i and node j respectively, α = 1.5 is the similarity scaling factor, W edge is the initial weight of the communication edge between nodes;

[0131]

[0132] where is the normalized feature vector of node i, is the mean vector of all node features, is the standard deviation vector of all node features, ∈ = 10 -5 is a small constant to prevent division by zero;

[0133] S242, Improved Laplacian matrix construction: Construct a hybrid Laplacian matrix L hybrid , expressed as:

[0134] L hybrid = D -1 / 2 (A + θS)D -1 / 2 ;

[0135] where D is the degree matrix, D ii = ∑ j A ij , S is the node attribute similarity matrix, i.e., the cosine similarity of the normalized node features, θ = 0.4 is the attribute fusion weight;

[0136] S243, Feature vector optimization: Perform eigenvalue decomposition on the hybrid Laplacian matrix L hybrid and extract the eigenvectors corresponding to the top k largest eigenvalues, and satisfy where λ i is the eigenvalue of the Laplacian matrix, m is the total number of nodes, ψ = 0.85 is the eigenvalue cumulative contribution rate threshold;

[0137] S244, Dynamic Subgraph Clustering: An improved k-means clustering algorithm with a sliding time window constraint is used for dynamic subgraph clustering, expressed as:

[0138]

[0139] where c p is the initialization center of the p-th cluster, U q is the candidate initialization vector, is the similarity function with the historical cluster center, is the r-th cluster center in the historical window, and t = 3 is the length of the historical clustering window;

[0140]

[0141] where J is the clustering loss function, U i is the data point to be clustered, is the historical center of the p-th class, and μ = 0.3 is the historical center consistency penalty coefficient;

[0142] S245, Subgraph Validity Verification: Double validity verification is performed on each clustered result subgraph C p , including modularity constraint and diameter constraint, expressed as:

[0143] Modularity Constraint:

[0144] where A ij is the weight of the corresponding edge in the adjacency matrix, d i is the weighted degree of node i, d j is the weighted degree of node j, m is the sum of the total edge weights in the graph, and ω = 0.4 is the modularity threshold;

[0145] Diameter Constraint: Shortest Path Length(i,j) ≤ d max ;

[0146] where the Shortest Path Length(i,j) is the shortest path length between node i and node j in the subgraph C p , and d max = 6 is the maximum allowable diameter of the subgraph.

[0147] The anomaly detection in S3 includes:

[0148] S31, Spatio-Temporal Encoding of the Graph Spectrum: The combination of a graph convolutional attention network (GCAN) and temporal causal convolution (TCC) is used to fuse the structural relationship between nodes and time series information, and extract the spatio-temporal feature representation of the graph spectrum, expressed as:

[0149]

[0150] Among them, is the spatio-temporal joint feature of the encoded spectrum, A is the adjacency matrix of the current spectrum, and X is the node original feature matrix. is the spectrum state representation at the t-th moment, and τ is the length of the historical spectrum window;

[0151]

[0152] Among them, H (l+1) is the intermediate feature representation of the (l + 1)-th layer. is the adjacency matrix with self-loops added, I is the identity matrix. is the corresponding degree matrix, W k is the weight of the k-th graph convolution kernel, Θ k is the feature adjustment parameter of the k-th attention channel, K' = 3 is the number of convolution channels, Attn is the weight matrix generated by the multi-head attention mechanism, H (l) is the intermediate feature representation of the l-th layer, and σ is the ReLU activation function;

[0153]

[0154] Among them, is the time encoding feature at the t-th moment, δ = 5 is the length of the time convolution window, Γ i is the weight of the i-th time convolution kernel. is the gated activation function (Sigmoid mixing function). is the spectrum state representation at the (t - i)-th moment;

[0155] S32, Neural Differential Equation Feature Extraction: Model the continuous evolution process of spectrum features over time through a neural ordinary differential equation, use the spatio-temporal encoding result as the dynamic input, and extract the trend of behavior changes through a differential solver to achieve multi-scale modeling and state representation of potential abnormal patterns, expressed as:

[0156]

[0157] Among them, is the feature state vector at the current moment t, f θ is the function on the right side of the differential equation, and θ is the neural network parameter;

[0158]

[0159] Among them, is the adjacency matrix with self-loops added. is the corresponding degree matrix, W and U are the weight parameters of the graph convolution layer, Z is the hidden layer feature representation extracted by GCN, σ' is the Sigmoid activation function, r and z are the reset gate and update gate of GRU respectively, Wr , W z , W h are the input weight matrices corresponding to the GRU, and U r , U z , U h are the hidden state weight matrices corresponding to the GRU, is the candidate state update value;

[0160]

[0161] Among them, is the output feature representation at the end point of differential solution, is the initial feature representation at the starting point of differential solution, t0 is the starting time of integration, and t1 is the ending time of integration;

[0162] S33, adversarial generative evaluation: Use a generative adversarial network to output the threat level, attack type, and propagation path, and evaluate the result credibility through a discriminator to achieve intelligent identification of multi-dimensional threats, expressed as:

[0163]

[0164] Among them, G is the threat parameter generator, and D is the discriminator, which is used to judge the authenticity of the generated output during training, is the credibility threshold of the generated output, L threat is the threat level score of the output, T attack is the identified attack type label, P path is the attack propagation path graph;

[0165] The threat parameter generator G includes three functional channels:

[0166] Threat level channel: Output the threat level probability based on spatio-temporal pyramid pooling and softmax layer;

[0167] Attack type channel: Use a prototype contrast clustering module to identify multi-class attack types;

[0168] Propagation path channel: Generate the attack path through a differentiable graph search algorithm.

[0169] The generation of protection strategies in S4 includes:

[0170] S41, multi-dimensional state encoding: Construct a joint state vector that fuses the threat assessment result and network topology information Expressed as:

[0171]

[0172] Among them, is the multi-dimensional state vector for policy decision-making, is the threat level distribution vector, is the attack type coding vector, is the attack propagation path feature vector, and Normalize is the normalization function, is the topological state vector, is the device load rate, is the device asset value level, is the current active connection number of the device;

[0173] S42, Constraint Reinforcement Learning Policy Optimization: The PPO (Proximal Policy Optimization) algorithm is adopted to optimize the protection policy under security constraints. The objective function is expressed as:

[0174]

[0175] where E is the mathematical expectation, s is the state vector, is the action, and π θ is the current policy model, is the previous round of policy, is the Generalized Advantage Estimation (GAE) function, which is used to measure the relative advantage of the current action, is the TD error at time t + k, ζ = 0.95 is the discount factor, λ = 0.8 is the GAE smoothing coefficient, and η = 0.2 is the KL divergence adjustment coefficient, is the security policy tolerance error, is the security action space constraint, is the conflict judgment function, with conflict being 1 and no conflict being 0, c isolate is the current isolation instruction count, is the maximum tolerable number of isolated devices, is the set of action pairs with policy conflicts, are the i-th and j-th candidate actions respectively;

[0176] S43, Protection Instruction Compilation: Map the optimal action selected from the policy network to an executable protection instruction set, which is expressed as:

[0177]

[0178] where InstSet is the generated dynamic protection instruction set, is the state-action value function under the current policy, is the dimension of the policy action, and Map is the mapping function from the policy action to the execution instruction;

[0179]

[0180] Among them, v1 = 0.7 is the high-priority action threshold, and v2 = 0.4 is the medium-priority action threshold.

[0181] The protection execution in S5 includes:

[0182] S51, Instruction Priority Dynamic Sorting: Based on the threat level and network asset value matrix in the threat assessment parameters, perform real-time priority division and execution sorting on the dynamic protection instruction set to generate a protection instruction execution sequence, specifically including:

[0183] When the threat level is higher than 0.8 and the target node is a core asset, the protection instruction is executed immediately;

[0184] When the threat level is between 0.6 and 0.8, the protection instruction is scheduled within 3 seconds;

[0185] The remaining general protection instructions enter the polling scheduling queue and are executed according to the resource idle state;

[0186] S52, Distributed Execution Engine Deployment: According to the current network topology status and protection instruction type, select the optimal deployment node to execute the protection operation, specifically including:

[0187] Allocate traffic cleaning instructions to the border gateway device and the core switching node;

[0188] Embed protocol filtering instructions into the middleware layer corresponding to the target protocol stack;

[0189] Execute device isolation instructions jointly by the SDN controller and the terminal protection agent to achieve joint isolation of the control plane and the data plane;

[0190] S53, Fine-grained Protection Operation Implementation: Execute differential protection actions according to the instruction type.

[0191] The fine-grained protection operation implementation includes:

[0192] Traffic cleaning: Dynamically inject cleaning rules into the mirror traffic path, and use the threat fingerprint generation engine to perform bypass filtering on abnormal traffic;

[0193] Protocol filtering: Reconstruct the parser logic of the corresponding protocol to intercept and block data packets carrying attack feature fields;

[0194] Device isolation: Combine BGP routing flow specification hijacking and 802.1x port control strategy to impose dual restrictions of physical isolation and logical isolation on the controlled device.

[0195] As Figure 2 shown, the network attack dynamic detection and security protection system based on artificial intelligence is used to implement the above-mentioned network attack dynamic detection and security protection method based on artificial intelligence, and includes the following modules:

[0196] Data acquisition module: Collect multi-protocol communication data streams of network devices, and extract original behavior features through a heterogeneous protocol parsing engine to generate a multi-dimensional feature vector including timestamp weights.

[0197] Behavior graph construction module: Construct a dynamically updated network behavior graph based on the multi-dimensional feature vector. The network behavior graph includes device nodes, communication relationship edges, and behavior pattern subgraphs.

[0198] Anomaly detection module: Input the network behavior graph into a deep residual time series model to identify abnormal behavior patterns and output threat assessment parameters including threat levels, attack types, and propagation paths.

[0199] Policy generation module: Generate a protection instruction set using a reinforcement learning decision algorithm according to the threat assessment parameters and the current network topology state.

[0200] Protection execution module: Execute the protection instruction set to implement traffic cleaning, protocol filtering, and device isolation operations for network attacks.

[0201] The present invention covers any alternatives, modifications, equivalent methods, and solutions made within the spirit and scope of the present invention. For the public to have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention. However, those skilled in the art can fully understand the present invention without these detailed descriptions. In addition, well-known methods, processes, procedures, components, and circuits are not described in detail to avoid unnecessary confusion to the essence of the present invention.

[0202] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements can be made without departing from the principle of the present invention, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for dynamically detecting and securely protecting against network attacks based on artificial intelligence, characterized in that, It includes the following steps: S1, Data collection: Collect the multi-protocol communication data stream of network devices, extract the original behavior features through a heterogeneous protocol parsing engine, and generate a multi-dimensional feature vector including timestamp weights; S2, Cross-protocol behavior graph construction: Take the multi-dimensional feature vector as the input, and generate a dynamically updated network behavior graph based on the cross-protocol session association algorithm. The network behavior graph includes device nodes, communication relationship edges, and behavior pattern subgraphs; S3, Anomaly detection: Input the network behavior graph into a dynamic detection model, identify abnormal behavior patterns through a deep residual time series network, and output threat assessment parameters including threat level, attack type, and propagation path; S4, Protection strategy generation: According to the threat assessment parameters, combined with the current network topology state parameters, generate a dynamic protection instruction set through a reinforcement learning decision algorithm; S5, Protection execution: Execute the dynamic protection instruction set to complete security protection operations including traffic cleaning, protocol filtering, and device isolation.

2. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 1, wherein, The data collection in S1 includes: S11, Multi-protocol data stream collection: Obtain the original communication data stream in a non-intrusive manner through bypass mirroring collection devices deployed at network boundaries and core switching nodes, and set an information buffer for temporarily storing heterogeneous protocol data streams; S12, Protocol fingerprint dynamic matching: Use a protocol recognition algorithm based on packet header feature clustering for the collected original communication data stream to identify unknown protocol types; S13, Protocol semantic parsing tree construction: Construct a hierarchical structure parsing tree for the identified protocol types; S14, Time-weighted feature calculation: For each protocol field, calculate the time decay weight ω t to reflect data freshness; S15, Multi-dimensional feature vector generation: Fuse protocol field features with time decay weights to generate a standardized multi-dimensional feature vector.

3. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 2, wherein The protocol fingerprint dynamic matching in S12 includes: S121, Message Header Preprocessing: Perform a truncation operation on the collected original communication data stream, and extract the first λ bytes to form the protocol fingerprint feature H i ={b1, b2,..., b λ}, where λ is the preset message header length, and b j is the decimal value of the j-th byte. For messages with a length less than λ, zero-padding is performed, and noise data that satisfies is filtered, where μ k is the mean value of the k-th byte in the historical data, ε = 3σ is the dynamic noise threshold, and σ is the historical standard deviation at the corresponding position; S122, Feature encoding conversion: Convert the packet header byte sequence into a numerical feature vector; S123, Improved similarity calculation: Adopt a bimodal similarity metric method combining weighted Hamming distance and byte distribution entropy; S124, Density Clustering Analysis: Use the improved adaptive density clustering algorithm DBSCAN to cluster fingerprint samples, and the core point condition is N ρ (H i )≥N min , where N ρ (H i ) is the number of samples similar to sample H i within the neighborhood of radius ρ, ρ is the clustering radius, and N min is the minimum neighborhood number threshold for core points; S125, Protocol type inference: Perform known protocol sample matching on the clustering results to determine whether it belongs to existing protocol categories.

4. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 3, wherein The cross-protocol behavior graph construction in S2 includes: S21, Device node dynamic extraction: Generate a unique device identifier ID based on a multi-dimensional feature vector dev , when the device similarity Sim dev > k', it is determined to be the same device, where k' is the similarity threshold for device merging; S22, Cross - protocol session association: within the time window ΔT, calculate the transition probability P(s j |s i ) between heterogeneous protocol sessions. When P(s j |s i ) > ι, establish an edge, where ι is the establishment threshold for cross - protocol communication edges; S23, Relationship Edge Weight Calculation: Determine the initial weight W of the edge by combining the communication frequency and the time decay factor edge ; S24, Behavior subgraph discovery: Use an improved spectral clustering algorithm to identify and extract behavior subgraphs in the graph structure; S25, Graph Spectrum Dynamic Update: Achieve incremental update of the behavior graph through an event-driven mechanism, and the trigger condition is where represent the graph adjacency matrices of the current and previous cycles respectively, and ‖·‖ F is the Frobenius norm of the matrix, ρ is the threshold for triggering an update due to graph structure changes. When the update trigger condition is met, the operations to be performed include: Remove all edge weights W edge <Expired edges of τ, where τ is the edge weight threshold; Merge the similarity Sim of all subgraphs subgraph Subgraphs of >v', where v' is the subgraph similarity merging threshold.

5. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 4, wherein, The behavior subgraph discovery in S24 includes: S241, Graph structure preprocessing: Construct a weighted adjacency matrix A and standardize the node attribute vector; S242. Improved Laplacian matrix construction: Construct a hybrid Laplacian matrix L that combines node attributes and topological structure hybrid ; S243, Feature vector optimization: For the mixed Laplacian matrix L hybrid perform eigen-decomposition, extract the eigenvectors corresponding to the first k largest eigenvalues, and satisfy where λ i is the eigenvalue of the Laplacian matrix, m is the total number of nodes, and ψ is the eigenvalue cumulative contribution rate threshold; S244, Dynamic subgraph clustering: Use an improved k-means clustering algorithm with a sliding time window constraint to perform dynamic subgraph clustering; S245, Sub - graph validity verification: For each sub - graph C of the clustering result p perform double validity verification, including modularity constraint and diameter constraint.

6. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 1, wherein The anomaly detection in S3 includes: S31, Graph spectrum spatio-temporal encoding: Combine graph convolutional attention network with temporal causal convolution, fuse the structural relationship between nodes and time series information, and extract the spatio-temporal feature representation of the graph spectrum; S32, Neural differential equation feature extraction: Model the continuous evolution process of graph spectrum features over time through neural ordinary differential equations, use the spatio-temporal encoding result as the dynamic input, and extract the behavior change trend through a differential solver to realize multi-scale modeling and state representation of potential abnormal patterns; S33, Adversarial Generative Evaluation: Use a generative adversarial network to output threat levels, attack types, and propagation paths, and evaluate the credibility of the results through a discriminator to achieve intelligent identification of multi-dimensional threats.

7. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 6, wherein The generation of the protection strategy in S4 includes: S41, Multi-dimensional state encoding: Construct a joint state vector that integrates threat assessment results and network topology information S42, Constraint Reinforcement Learning Policy Optimization: Adopt the PPO algorithm to optimize the protection strategy under security constraints; S43, Protection Instruction Compilation: Map the optimal actions selected in the policy network to an executable set of protection instructions.

8. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 7, wherein, The protection execution in S5 includes: S51, Dynamic Sorting of Instruction Priorities: Based on the threat level in the threat assessment parameters and the network asset value matrix, perform real-time priority division and execution sorting on the dynamic protection instruction set to generate a protection instruction execution sequence; S52, Deployment of a Distributed Execution Engine: According to the current network topology state and the type of protection instruction, select the optimal deployment node to execute the protection operation; S53, Implementation of Fine-Grained Protection Operations: Execute differentiated protection actions according to the instruction type.

9. The method for dynamically detecting and securely protecting against network attacks based on artificial intelligence according to claim 8, wherein The implementation of the fine-grained protection operations includes: Traffic Cleaning: Dynamically inject cleaning rules into the mirror traffic path, and use the threat fingerprint generation engine to bypass and filter abnormal traffic; Protocol Filtering: Reconstruct the parser logic of the corresponding protocol to intercept and block data packets carrying attack feature fields; Device Isolation: Combine BGP routing flow specification hijacking and 802.1x port control policies to implement double restrictions of physical isolation and logical isolation on controlled devices.

10. An artificial intelligence-based network attack dynamic detection and security protection system for implementing the artificial intelligence-based network attack dynamic detection and security protection method according to any one of claims 1-9, characterized in that, It includes the following modules: Data Acquisition Module: Collect multi-protocol communication data streams of network devices, and extract original behavior features through a heterogeneous protocol parsing engine to generate a multi-dimensional feature vector including timestamp weights; Behavior Graph Construction Module: Construct a dynamically updated network behavior graph based on the multi-dimensional feature vector. The network behavior graph includes device nodes, communication relationship edges, and behavior pattern subgraphs; Anomaly Detection Module: Input the network behavior graph into a deep residual time series model to identify abnormal behavior patterns and output threat assessment parameters including threat levels, attack types, and propagation paths; Policy Generation Module: Generate a set of protection instructions using a reinforcement learning decision algorithm based on the threat assessment parameters and the current network topology state; Protection Execution Module: Execute the set of protection instructions to implement traffic cleaning, protocol filtering, and device isolation operations for network attacks.

Citation Information

Cited By

  • Local area network equipment identification method and system based on artificial intelligence driving

    CN120602337A

  • Artificial intelligence driven local area network device identification method and system

    CN120602337B

  • Security assessment method and system based on Internet of Vehicles

    CN120710790A

  • A safety assessment method and system based on vehicle-to-everything (V2X)

    CN120710790B

  • Network security event analysis method, system and equipment

    CN120729618A