Delay attack detection method and system based on dual-communication delay correlation analysis
By establishing lightweight monitoring communications in the network link and building a bidirectional LSTM model, learning and comparing the delay fluctuation mode, the problems of high false alarm rate and poor real-time performance of delay attack detection are solved, and accurate identification of malicious delay attacks is achieved.
Patent Information
- Application Number
- CN202510403204.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-22
AI Technical Summary
Existing delay attack detection methods are prone to false alarms in dynamic network environments, and attackers can smooth out delay changes through obfuscation, resulting in the inability to accurately identify malicious delay attacks.
Establish lightweight monitoring communications between network links and devices that are the same as the main control communication, build a delay fluctuation correlation analysis model based on bidirectional LSTM, learn the delay fluctuation mode under normal circumstances by monitoring communication data, and compare it with real-time monitoring communication, and use a dynamic threshold detection mechanism to identify delay attacks.
Effectively distinguishing between normal communication and malicious attacks, reducing false alarms caused by network jitter, and able to identify attacks that are injected in small delays or disguised as network jitter, which is simple to implement and highly portable.
Smart Images

Figure CN120358047A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network delay attack detection, and particularly to a delay attack detection method and system based on dual communication delay correlation analysis. Background Art
[0002] A time delay attack is a new type of network attack. Its basic principle lies in maliciously manipulating the timing of data packets during network transmission, deliberately introducing millisecond-level delays, thereby disrupting the real-time synchronization and stability of the system. In this kind of attack, the attacker does not attempt to steal data or directly control the device, but by disturbing the transmission timing, making application systems that rely on strict timing control make decision-making mistakes or synchronization anomalies, such as autonomous driving vehicles, factory assembly lines, etc., and then cause serious security consequences. With the wide application of the Internet of Things and the Industrial Internet in key areas, such attacks pose a new threat to public safety and personal safety, and sufficient attention needs to be paid and corresponding protection measures need to be taken.
[0003] Existing time delay attack detection methods mainly include: (1) Statistical analysis and baseline modeling. This kind of method establishes a normal baseline for the transmission delay of data packets in the network, and then monitors the actual delay data in real time, compares it with the baseline, and looks for abnormal fluctuations. (2) Machine learning and intrusion detection systems (IDS). Using machine learning models to train historical delay data to construct a delay anomaly detector to identify delay distributions significantly different from the normal mode; or taking delay characteristics as a dimension of attack behavior, combining with other network traffic characteristics to construct a multi-dimensional anomaly detection model. However, the current time delay attack detection methods still have the following limitations: in a dynamic network environment, the naturally existing network jitter may lead to false alarms; at the same time, the attacker may adopt confusing means to make the delay change smoother or simulate the situation of network jitter, resulting in the existing methods being unable to accurately identify real malicious time delay attacks. To solve these problems, there is an urgent need to provide an effective time delay attack detection method currently. Summary of the Invention
[0004] To overcome the above deficiencies of the prior art, the present invention proposes a time delay attack detection method and system based on dual communication delay correlation analysis.
[0005] The technical solution adopted by the present invention to solve its technical problems is as follows:
[0006] The first aspect of the present invention relates to a time delay attack detection method based on dual communication delay correlation analysis, and the method includes the following steps:
[0007] 1) Construct monitoring communication: Establish a lightweight monitoring communication between the same network links and devices as the main control communication to form a dual communication parallel transmission architecture;
[0008] 2) Collect communication data: Synchronously collect the transmission data of the master control communication and the monitoring communication, extract indicators such as communication duration, communication time interval, throughput, etc., and construct a time series feature dataset.
[0009] 3) Model training: Construct an analysis and inference model for delay fluctuation correlation based on bidirectional LSTM, and use the collected time series feature datasets of the master control communication and the monitoring communication for training to learn the correlation between the delay fluctuation patterns of the master control communication network and the monitoring communication under normal circumstances.
[0010] 4) Attack detection: Infer the delay fluctuation pattern of the master control communication based on the real-time delay fluctuation of the monitoring communication, compare it with the actual delay fluctuation pattern of the master control communication, and determine whether the master control communication is under a delay attack by establishing a dynamic threshold detection mechanism, and trigger warnings and traffic isolation.
[0011] Preferably, the construction of the monitoring communication in step 1) specifically includes:
[0012] Step 101, obtain the communication situation between devices of the master control communication, including communication protocols, communication frequencies, etc., and determine which other communications can be used between devices in addition to this master control communication.
[0013] Step 102, select the other communication with the least impact on the system and network load as the monitoring communication; taking Siemens S7 communication as the master control communication between the SCADA system and the PLC as an example, lightweight TCP communication can be used as the monitoring communication. Establish a TCP communication server on the PLC side and a TCP communication client on the SCADA side, maintain a communication frequency similar to that of the master control communication, and continuously communicate.
[0014] Preferably, the collection of communication data in step 2) specifically includes:
[0015] Step 201, keep the master control communication continuously communicate under normal circumstances, and the monitoring communication also keeps communicating continuously at a frequency similar to that of the master control communication; use the network traffic capture tool wireshark to capture the data packets of the two communications.
[0016] Step 202, divide the captured data packets into groups according to the time stamp unit, and extract the maximum value, minimum value, average value, standard deviation of the communication time for each complete communication in each group, the maximum value, minimum value, average value, standard deviation of the communication time interval, the root mean square, and the communication throughput, and respectively construct the time series feature datasets of the master control communication and the monitoring communication under normal circumstances.
[0017] Preferably, the model training in step 3) specifically includes:
[0018] Step 301, Sliding window enhancement; calculate the time-domain statistics within the window, including mean, standard deviation, maximum value, minimum value, and range; calculate the differential features, including the mean and standard deviation of the first-order difference; calculate the trend feature, i.e., the window slope. The sliding window helps the model identify local trends and periodic fluctuations by aggregating information from adjacent time points, providing effective serialized input for the subsequent model training.
[0019] Step 302, Model construction and training; use a bidirectional LSTM layer to capture the temporal features before and after. The bidirectional LSTM processes the input sequence through two independent LSTM networks, one forward (from front to back) and the other backward (from back to front), enabling the model to utilize both past and future information simultaneously. For the input sequence x1, x, …, x T , the output of the bidirectional LSTM can be expressed as:
[0020]
[0021] where is the forward output value, is the backward output value, h t is the final output value, hidden_dim is the hidden state dimension of each LSTM cell. Gradually abstract the temporal features by stacking multiple layers of LSTM, and use Dropout between layers to prevent overfitting. Then, use the attention mechanism to dynamically focus on important time steps, and calculate the attention score for the hidden state h t at each time step:
[0022] u t = W2·tanh(W1·h t + b1)+ b2 (4)
[0023] Calculate the time-step weight distribution through Softmax:
[0024]
[0025] And sum up the hidden states of all time steps after weighting:
[0026]
[0027] where W1 and W2 are linear transformation matrices, and b1 and b2 are bias terms at the top layer; The Tanh activation function maps the features to the interval [-1, 1], enhancing the non-linear expression ability and avoiding gradient saturation at the same time; Softmax normalization ensures that all weights α tThe sum is 1, realizing the physical explanation of "attention allocation"; finally, the context vector c is used as the input of the deep regression head, and regression prediction is carried out through a multi-layer fully connected network; the deep regression head includes three layers in total, namely high-dimensional feature expansion, feature compression and abstraction, and final regression prediction. The main calculation formula is as follows:
[0028]
[0029] where W is the weight, x is the input feature after two-layer processing, and b is the bias; the result of the regression prediction is the average communication duration of the main control communication at the current time stamp; after the three parts of the model are constructed, the collected time series feature dataset is used for training to learn the correlation between the main control communication network delay fluctuation pattern and the monitoring communication delay fluctuation pattern under normal conditions.
[0030] Preferably, the attack detection in step 4) specifically includes:
[0031] Perform dynamic difference calculation; adopt the trapezoidal area accumulation method within the sliding window to convert the time series change of the prediction error into numerical integration. Let the time series within the window be t i , t i+1 ,..., t i+n , and the corresponding prediction errors are e i , e i+1 ,..., e i+n , then the dynamic error D i The calculation formula is:
[0032]
[0033] This integral value not only retains the error amplitude information but also strengthens the characteristics of continuous abnormal fluctuations through time dimension weighting; then calculate the mean μ t and standard deviation σ t of the dynamic difference within the window, and define the dynamic threshold:
[0034] Threshold t = μ t + k·σ t (9)
[0035] where k is the sensitivity coefficient, calibrated through historical data; at the same time, perform exponential smoothing on the statistics μ t and σ t to reduce the impact of sudden noise; when the dynamic error exceeds the dynamic threshold, it is determined that the main control communication is under a delay attack.
[0036] The second aspect of the present invention relates to a delay attack detection system based on dual communication delay correlation analysis, including a memory and one or more processors. Executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement a delay attack detection method based on dual communication delay correlation analysis of the present invention.
[0037] The third aspect of the present invention relates to a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, it implements a delay attack detection method based on dual communication delay correlation analysis of the present invention.
[0038] The present invention provides a network state benchmark independent of the main control communication by monitoring the communication. Combining the dual-channel delay correlation analysis, it can effectively distinguish normal communication, network congestion, and malicious attacks, and solves the problems of high false alarm rate and poor real-time performance of traditional delay attack detection methods. The technical concept of the present invention is: establish a lightweight monitoring communication between the same network links and devices as the main control communication, construct a delay fluctuation correlation analysis and reasoning model based on bidirectional LSTM, learn the correlation between the delay fluctuation patterns of the main control communication network and the monitoring communication delay fluctuation patterns under normal circumstances, infer the delay fluctuation of the main control communication based on the real-time captured monitoring communication delay fluctuation, and analyze and compare it with the actual delay fluctuation of the main control communication to determine whether a delay attack has occurred.
[0039] The advantages of the present invention are: reducing false alarms that may be caused by network jitter, being able to effectively identify tiny delay injections or delay attacks disguised as network jitter by attackers on network communication, and having simple implementation and high portability. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a flowchart of the method of the present invention.
[0041] Figure 2 is a model structure diagram of the present invention.
[0042] Figure 3 is a schematic diagram of the system structure of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following further describes the present invention with reference to the accompanying drawings
[0044] Embodiment 1
[0045] Refer to Figure 1 , this embodiment relates to a delay attack detection method based on dual communication delay correlation analysis, including the following steps:
[0046] 1) Construct monitoring communication: Establish a lightweight monitoring communication between the same network links and devices as the main control communication to form a dual communication parallel transmission architecture.
[0047] 2) Collect communication data: Synchronously collect the transmission data of the master control communication and the monitoring communication, extract indicators such as communication duration, communication time interval, throughput, etc., and construct a time series feature dataset.
[0048] 3) Model training: Construct a delay fluctuation correlation analysis and inference model based on bidirectional LSTM, and use the collected time series feature dataset of the master control communication and the monitoring communication for training to learn the correlation between the delay fluctuation patterns of the master control communication network and the monitoring communication delay fluctuation patterns under normal conditions.
[0049] 4) Attack detection: Infer the delay fluctuation pattern of the master control communication based on the real-time monitoring communication delay fluctuation, compare it with the actual master control communication delay fluctuation pattern, and determine whether the master control communication is under a delay attack by establishing a dynamic threshold detection mechanism, and trigger warnings and traffic isolation.
[0050] In the above step 1), constructing the monitoring communication includes the following steps:
[0051] Step 101, Obtain the communication situation of the master control communication between devices, including communication protocols, communication frequencies, etc., and determine which other communications can be used between devices in addition to this master control communication.
[0052] Step 102, Select the other communication with the least impact on the system and network load as the monitoring communication. Taking Siemens S7 communication as the master control communication between the SCADA system and the PLC as an example, lightweight TCP communication can be used as the monitoring communication. Establish a TCP communication server on the PLC side and a TCP communication client on the SCADA side, maintain a communication frequency similar to that of the master control communication, and continuously communicate.
[0053] In the above step 2), collecting communication data includes the following steps:
[0054] Step 201, Keep the master control communication continuously communicate under normal conditions, and the monitoring communication also keeps communicating continuously at a frequency similar to that of the master control communication. Use the network traffic capture tool wireshark to capture the data packets of the two communications.
[0055] Step 202, Divide the captured data packets into groups according to the time stamp unit, and extract the maximum value, minimum value, average value, standard deviation of the communication time for each complete communication in each group, the maximum value, minimum value, average value, standard deviation of the communication time interval, the root mean square, and the communication throughput, and respectively construct the time series feature dataset of the master control communication and the time series feature dataset of the monitoring communication under normal conditions.
[0056] In the above step 3), model training includes the following steps:
[0057] Step 301, Sliding window enhancement: Calculate the time-domain statistics within the window, including mean, standard deviation, maximum value, minimum value, and range. Calculate the differential features, including the mean and standard deviation of the first-order difference. Calculate the trend feature, i.e., the window slope. The sliding window helps the model identify local trends and periodic fluctuations by aggregating information from adjacent time points, providing effective serialized input for the subsequent model training.
[0058] Step 302, Model construction and training: Use a bidirectional LSTM layer to capture temporal features in both forward and backward directions. The bidirectional LSTM processes the input sequence through two independent LSTM networks, one in the forward direction (from front to back) and the other in the backward direction (from back to front), enabling the model to utilize both past and future information simultaneously. For the input sequence x1, x, …, x T , the output of the bidirectional LSTM can be expressed as:
[0059]
[0060] where is the forward output value, is the backward output value, h t is the final output value, hidden_dim is the hidden state dimension of each LSTM cell. Gradually abstract the temporal features by stacking multiple layers of LSTM, and use Dropout between layers to prevent overfitting. Then, use the attention mechanism to dynamically focus on important time steps, and calculate the attention scores for the hidden state h t at each time step:
[0061] u t = W2·tanh(W1·h t + b1)+ b2 (4)
[0062] Calculate the time-step weight distribution through Softmax:
[0063]
[0064] And sum up the weighted hidden states of all time steps:
[0065]
[0066] where W1 and W2 are linear transformation matrices, b1 and b2 are bias terms at the top layer. The Tanh activation function maps the features to the interval [-1, 1], enhancing the non-linear expression ability while avoiding gradient saturation. Softmax normalization ensures that all weights α tThe sum is 1, realizing the physical explanation of "attention allocation"; finally, the context vector c is used as the input of the deep regression head, and regression prediction is performed through a multi-layer fully connected network; the deep regression head includes three layers in total, namely high-dimensional feature expansion, feature compression and abstraction, and final regression prediction. The main calculation formula is:
[0067]
[0068] where W is the weight, x is the input feature after two-layer processing, and b is the bias; the result of the regression prediction is the average communication duration of the main control communication at the current timestamp; after the three parts of the model are constructed, the collected time series feature dataset is used for training to learn the association between the main control communication network delay fluctuation pattern and the monitoring communication delay fluctuation pattern under normal conditions.
[0069] In step 4), the attack detection includes the following steps:
[0070] Perform dynamic difference calculation; use the trapezoidal area accumulation method within the sliding window to convert the time series change of the prediction error into numerical integration. Let the time series within the window be t i , t i+1 ,..., t i+n , and the corresponding prediction error is e i , e i+1 ,..., e i+n , then the dynamic error D i The calculation formula is:
[0071]
[0072] This integral value not only retains the error amplitude information but also strengthens the continuous abnormal fluctuation characteristics through time dimension weighting; then calculate the mean μ t and standard deviation σ t of the dynamic difference within the window, and define the dynamic threshold:
[0073] Threshold t = μ t + k·σ t (9)
[0074] where k is the sensitivity coefficient, calibrated through historical data; at the same time, perform exponential smoothing on the statistics μ t and σ t to reduce the impact of sudden noise; when the dynamic error exceeds the dynamic threshold, it is determined that the main control communication has been attacked by delay.
[0075] Embodiment 2
[0076] Refer to Figure 3This embodiment relates to a delay attack detection system based on dual communication delay correlation analysis, including a memory and one or more processors, wherein the memory stores executable code, and when the one or more processors execute the executable code, they are used to implement a delay attack detection method based on dual communication delay correlation analysis of the present invention.
[0077] Example 3
[0078] This embodiment relates to a computer-readable storage medium on which a program is stored. When the program is executed by a processor, a delay attack detection method based on dual-communication delay correlation analysis of the present invention is implemented.
[0079] The contents described in the embodiments of this specification are merely an enumeration of the implementation forms of the inventive concept. The protection scope of the present invention should not be regarded as limited to the specific forms described in the embodiments. The protection scope of the present invention also extends to equivalent technical means that can be conceived by those skilled in the art based on the inventive concept.
Claims
1. A delay attack detection method based on double communication delay correlation analysis, characterized in that: It includes the following steps: 1) Construct monitoring communication: Establish lightweight monitoring communication between the same network links and devices as the main control communication to form a dual-communication parallel transmission architecture; 2) Collect communication data: Synchronously collect the transmission data of the main control communication and the monitoring communication, extract indicators such as communication duration, communication time interval, throughput, etc., and construct a time-series feature dataset; 3) Model training: Construct a delay fluctuation correlation analysis and inference model based on bidirectional LSTM, and use the collected time-series feature datasets of the main control communication and the monitoring communication for training to learn the correlation between the main control communication network delay fluctuation pattern and the monitoring communication delay fluctuation pattern under normal conditions; 4) Attack detection: Infer the delay fluctuation pattern of the main control communication based on the real-time monitoring communication delay fluctuation, compare it with the actual main control communication delay fluctuation pattern, and determine whether the main control communication is under a delay attack by establishing a dynamic threshold detection mechanism, and trigger warnings and traffic isolation.
2. A delay attack detection method based on dual-communication delay correlation analysis according to claim 1, wherein: Step 1) specifically includes: Step 101, Obtain the communication situation of the main control communication between devices, including communication protocols, communication frequencies, etc., and determine which other communications can be used between devices in addition to this main control communication; Step 102, Select the other communication with the least impact on the system and network load as the monitoring communication.
3. A delay attack detection method based on dual-communication delay correlation analysis according to claim 1, wherein: Step 2) specifically includes: Step 201, Keep the main control communication continuously communicate under normal conditions, and the monitoring communication also keeps communicating at a frequency similar to that of the main control communication; Use the network traffic capture tool wireshark to capture the data packets of the two communications; Step 202, Divide the captured data packets into groups according to the time stamp unit, and extract the maximum value, minimum value, average value, standard deviation of the communication time for each complete communication in each group, the maximum value, minimum value, average value, standard deviation of the communication time interval, the root mean square, and the communication throughput, and construct the main control communication time-series feature dataset and the monitoring communication time-series feature dataset under normal conditions respectively.
4. A delay attack detection method based on dual-communication delay correlation analysis according to claim 1, wherein: Step 3) specifically includes: Step 301, Sliding window enhancement; Calculate the time-domain statistics within the window, including mean, standard deviation, maximum value, minimum value, range; Calculate the differential features, including the mean and standard deviation of the first-order difference; Calculate the trend feature, that is, the window slope; The sliding window helps the model identify local trends and periodic fluctuations by aggregating information at adjacent time points, providing effective serialized input for the subsequent model training. Step 302, model construction and training; use a bidirectional LSTM layer to capture temporal features before and after. The bidirectional LSTM processes the input sequence through two independent LSTM networks, one forward and the other backward, which enables the model to utilize both past and future information simultaneously. For the input sequence x1, x, …, x T , the output of the bidirectional LSTM can be expressed as: Among them is the forward output value, is the reverse output value, h t is the final output value, hidden_dim is the hidden state dimension of each LSTM cell, and the time series features are gradually abstracted by stacking multiple layers of LSTM. Dropout is used between layers to prevent overfitting; then the attention mechanism is used to dynamically focus on important time steps, and the hidden state h t Calculate the attention score: u t = W2·tanh(W1·h t + b1)+ b2 (4) Calculate the time-step weight distribution through Softmax: And weighted sum the hidden states of all time steps: where W1 and W2 are linear transformation matrices, and b1 and b2 are bias terms at the top layer; the Tanh activation function maps features to the interval [-1, 1], enhancing the non-linear expression ability while avoiding gradient saturation; Softmax normalization ensures that all weights α t and sum to 1, realizing the physical interpretation of "attention allocation"; finally, the context vector c is used as the input of the deep regression head, and regression prediction is performed through a multi-layer fully connected network; the deep regression head consists of three layers in total, namely high-dimensional feature expansion, feature compression and abstraction, and final regression prediction. The main calculation formula is as follows: Where W is the weight, x is the input feature after two - layer processing, and b is the bias; the result of the regression prediction is the average communication duration of the master - control communication at the current timestamp. After the three parts of the model are all constructed, the collected time - series feature dataset is used for training to learn the correlation between the normal - case master - control communication network delay fluctuation pattern and the monitored communication delay fluctuation pattern.
5. A delay attack detection method based on dual - communication delay correlation analysis according to claim 1, characterized in that: Step 4) specifically includes: Perform dynamic difference calculation; adopt the trapezoidal area accumulation method within the sliding window to transform the time series change of the prediction error into numerical integration. Let the time series within the window be t i , t i+1 ,..., t i+n , and the corresponding prediction errors are e i , e i+1 ,..., e i+n . Then the dynamic error d i The calculation formula is: This integral value not only retains the error amplitude information but also strengthens the characteristics of continuous abnormal fluctuations through time - dimension weighting; then calculate the mean value μ t and the standard deviation σ t , and define the dynamic threshold: Threshold t = μ t + k·σ t (9) where k is the sensitivity coefficient, calibrated by historical data; at the same time, exponential smoothing is performed on the statistics μ t and σ t to reduce the impact of sudden noise; when the dynamic error exceeds the dynamic threshold, it is determined that the main control communication has been subject to a delay attack.
6. A delay attack detection system based on double communication delay correlation analysis, characterized in that, It includes a memory and one or more processors. Executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement a delay attack detection method based on dual - communication delay correlation analysis according to any one of claims 1 - 5.
7. A computer-readable storage medium, characterized in that, A program is stored thereon. When the program is executed by a processor, it implements a delay attack detection method based on dual - communication delay correlation analysis according to any one of claims 1 - 5.