Fast DDoS attack detection method based on multi-modal data feature enhancement and combination

Through the multimodal data feature enhancement and combination method, the problems of low accuracy and poor generalization capabilities in traditional DDoS attack detection methods are solved, and efficient and real-time DDoS attack detection is achieved, which is suitable for industrial control systems.

CN120358050APending Publication Date: 2025-07-22CHINA HYDROELECTRIC ENGINEERING CONSULTING GROUP CHENGDU RESEARCH HYDROELECTRIC INVESTIGATION DESIGN AND INSTITUTE +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510424925.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The method of DDoS attack detection based on feature selection in the prior art has problems such as low accuracy, poor generalization ability, and inability to meet real-time requirements.

Method used

The multimodal data feature enhancement and combination method is adopted to obtain multimodal data from the industrial control system, preprocess and alignment, and feature enhancement is performed using a modal attention mechanism and a multi-layer perceptron. Combining similarity measurement function and constraint optimization, dynamic weighting and attention mechanism build a global optimal feature combination, optimize the feature selection process, and train the DDoS attack detection model.

Benefits of technology

It improves the accuracy and generalization ability of DDoS attack detection, meets real-time requirements, can quickly respond to different types of DDoS attacks, and ensures the network security of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358050A_ABST
    Figure CN120358050A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of industrial control security, discloses a quick DDoS attack detection method based on multi-modal data feature enhancement and combination, and solves the problems of low accuracy, poor generalization ability and incapability of meeting the real-time requirement of a DDoS attack detection method based on feature selection in the traditional technology. According to the method, feature enhancement is carried out on unusual DDoS attack types through multi-modal data, in the feature combination process, firstly, redundancy elimination is carried out on candidate feature subsets through feature pre-screening and a similarity-based metric function, then correlation analysis is carried out on the candidate feature subsets and various different types of DDoS attacks, and finally, the correlation between the candidate feature subsets and the DDoS attacks is determined. And a multi-objective optimization problem is converted into a simple constraint problem, so that a solution with excellent performance can be quickly found. Then, an attention mechanism is used, a feature selection process is optimized through a feature selection adaptive weighting algorithm, and it is guaranteed that feature selection is optimal when facing different DDoS attack types; and finally, training the model by using the extracted optimal feature combination subset.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control security, and particularly relates to a fast DDoS attack detection method based on multi-modal data feature enhancement and combination. Background Art

[0002] Nowadays, the wide application of industrial control systems (ICS) has become a key factor in promoting production efficiency and accuracy. However, with the popularization of ICS, its network security problems have become increasingly prominent, especially distributed denial of service (DDoS) attacks against industrial control system networks. There are various types of such attacks, and any type of DDoS attack can cause serious damage to the production system, resulting in significant production and property losses. Currently, the method of using machine learning to detect DDoS attacks has become the mainstream idea in the field of industrial control security because it has the advantages of high accuracy and strong scalability compared with traditional model-based methods.

[0003] The current methods for DDoS attack detection based on feature selection mainly include filter-based methods, wrapper-based methods, and automated feature selection methods based on deep learning self-optimization:

[0004] Filter-based methods mainly evaluate the importance of each feature through statistical or information-theoretic methods. This method has a fast detection speed, but it usually assumes that features are independent and does not consider the interaction between features, resulting in a low accuracy rate.

[0005] Wrapper-based methods evaluate the quality of feature subsets through a prediction model, capturing the interaction between features and having a high prediction accuracy. However, this method usually uses a pre-trained model, which may fall into a local optimal feature subset, is insensitive to uncommon DDoS attack types, and when the DDoS attack type changes, the trained prediction model cannot update the feature set in real time, with poor generalization ability and not meeting the real-time requirement.

[0006] Automated feature selection methods based on deep learning self-optimization can process high-dimensional data and non-linear features by designing complex neural network architectures, and can perform automated feature selection for different types of DDoS attacks to obtain a global optimal feature subset. However, it is strongly dependent on the data volume and has a low detection efficiency, also not meeting the real-time requirement of detection. Summary of the Invention

[0007] The technical problem to be solved by the present invention is to propose a fast DDoS attack detection method based on multi-modal data feature enhancement and combination, so as to solve the problems of low accuracy, poor generalization ability and inability to meet the real-time requirements existing in the traditional DDoS attack detection method based on feature selection.

[0008] The technical solution adopted by the present invention to solve the above technical problems is as follows:

[0009] A fast DDoS attack detection method based on multi-modal data feature enhancement and combination includes the following steps:

[0010] S1. Obtain multi-modal data for different types of DDoS attacks on industrial control systems and perform preprocessing. The multi-modal data includes traffic data, log data, and professional domain knowledge;

[0011] S2. Align and normalize the multi-modal data, then extract and fuse features, and then use the modal attention mechanism and multi-layer perceptron for feature enhancement to obtain a feature set;

[0012] S3. Based on prior knowledge, initially screen the feature set, initialize the feature combination solution space according to the initially screened feature set. The feature combination solution space includes multiple feature combination subsets, and use a similarity metric function to remove redundant feature combination subsets in the feature combination solution space;

[0013] S4. For the feature combination solution space after removing redundancy, by introducing constraint conditions, reconstruct the multi-objective feature selection problem into a constrained optimization problem, and obtain multiple candidate feature combination subsets by solving the constrained optimization problem;

[0014] S5. For each candidate feature combination subset, select candidate features in the subset through dynamic weighting and attention mechanism, and calculate the detection accuracy applied to the DDoS attack detection model respectively, and obtain the feature combination subset with the highest detection accuracy for each type of DDoS attack as the global optimal feature combination subset;

[0015] S6. Use the global optimal feature combination as the key index of the DDoS attack detection model to train the DDoS attack detection model;

[0016] S7. In actual application, extract corresponding features according to the real-time traffic of the industrial control system as the input of the trained DDoS attack detection model to obtain the DDoS attack detection result.

[0017] Further, in step S1, the preprocessing includes:

[0018] Check whether there are missing values in the traffic data of different types of DDoS attacks, fill them using interpolation filling or forward and backward value filling methods, and correct outliers using statistical methods;

[0019] Clean the log data corresponding to the traffic data of different types of DDoS attacks, remove irrelevant content, and standardize the text format. Then, convert the text information in the log into numerical features through natural language processing techniques;

[0020] According to professional domain knowledge, combine known attack patterns with abnormal behaviors in network traffic to provide context information for different types of DDoS attacks, and then convert them into numerical features through encoding techniques.

[0021] Furthermore, in step S2, the method for aligning multimodal data includes:

[0022] Align the traffic data and log data according to the time axis, and align the professional domain knowledge with the traffic data and log data through semantic or context information.

[0023] Furthermore, in step S2, use the modal attention mechanism and multi-layer perceptron for feature enhancement, and the obtained feature set includes:

[0024] First, use the modal attention mechanism to highlight the features of a few DDoS attack classes and common DDoS attack classes in the fused features, and suppress irrelevant features;

[0025] Then, use the multi-layer perceptron to perform a non-linear transformation on the fused features processed by the modal attention mechanism to generate the feature set Z final :

[0026] Z final =σ(W2*ReLU(W1*Z + b1)+b2);

[0027] Among them, ReLU is the activation function, σ is the final activation operation, W1 and W2 are the weight matrices of the fully connected layers in the multi-layer perceptron, and b1 and b2 are the corresponding bias terms.

[0028] Furthermore, in step S3, the method for removing redundant feature combination subsets in the feature combination solution space using the similarity metric function includes:

[0029] Calculate the similarity between any two feature combination subsets in the feature combination solution space through the similarity metric function. When the similarity is greater than the given threshold, retain one feature combination subset and delete the other feature combination subset.

[0030] Furthermore, in step S4, the constraint condition is expressed as:

[0031] P(S), subject to Cov(S) ≥ γ, Corr(S, C k ) ≥ κ;

[0032] Wherein, P(S) represents the detection performance of the input traffic data containing all DDoS attack types, Cov(S) represents the feature coverage rate, and Corr(S, C k ) represents the correlation between the feature and the attack type C k and γ and κ are preset thresholds.

[0033] Furthermore, in step S4, the setting methods of γ and κ include:

[0034] In the initial stage, both γ and κ are set to 1. Under this condition, the feature combination subset is constrained and optimized, and the detection performance P(S) is calculated; subsequently, γ and κ are adjusted by the bisection method, and the value of P(S) is recalculated and evaluated after each adjustment. When the change of the threshold γ or κ causes a significant decrease in P(S), that is, the decrease amplitude exceeds the given amplitude threshold, the adjustment operation is stopped, and the threshold γ or κ before this adjustment is retained as the final set value.

[0035] Furthermore, in step S5, the selection of candidate features in the subset by the dynamic weighting and attention mechanism includes:

[0036] The candidate feature s in the subset i is given a dynamic weight ω i , and is updated based on the attention mechanism:

[0037]

[0038] Wherein, W is the initial weight matrix, and e i represents the importance score of the feature s i ;

[0039] In the process of optimizing and selecting candidate features, the features with larger weights are preferentially retained.

[0040] Furthermore, in step S5, by calculating the detection accuracy rates applied to the DDoS attack detection model respectively, the feature combination subset with the highest detection accuracy rate for each type of DDoS attack is obtained as the global optimal feature combination subset, including:

[0041] The candidate feature combination subsets after dynamic weight adjustment are respectively applied to the DDoS attack detection model, and the detection accuracy rates of the model for different types of DDoS attacks are calculated. If the detection accuracy rate corresponding to a certain candidate feature combination subset exceeds the preset accuracy threshold, it is determined that the subset is a feature combination subset that meets the requirements and is used as the global optimal feature combination subset.

[0042] Further, step S5 further includes: when the requirements are not met, that is, when no candidate feature combination subset can reach the accuracy threshold, the fast variant algorithm of NSGA-II is used to accelerate the convergence of the feature combination solving process, and the feature combination subset that maximizes the detection accuracy is selected as the global optimal feature combination.

[0043] The beneficial effects of the present invention are as follows:

[0044] (1) Through multi-modal data fusion and the exploration of the interaction between features by a multi-layer perceptron, the complex relationships between features are fully considered, enhancing the ability of the detection model to capture various DDoS attack features, thus greatly improving the detection accuracy.

[0045] (2) Use multi-modal data to enhance minority class features, and construct the global optimal feature combination through dynamic weighting and attention mechanism, enabling the model to adapt to different types of DDoS attacks. Whether it is a common attack or an uncommon attack type, it can maintain a high detection accuracy. When the DDoS attack type changes, the model can also respond in a timely manner with the global optimal feature combination, enhancing the generalization ability of the model.

[0046] (3) By means of the steps of fast feature screening and removal of redundant feature combination subsets, irrelevant features and redundant feature subsets are reduced, and the subsequent algorithm complexity is lowered. At the same time, the multi-objective optimization problem is transformed into a simple constraint problem, and the fast variant algorithm of NSGA-II is introduced to accelerate the feature combination solving process, significantly improving the detection efficiency, meeting the real-time requirements for DDoS attack detection in industrial control systems, being able to operate stably in real-time scenarios, discover and respond to DDoS attacks in a timely manner, and effectively ensuring the network security of industrial control systems. Description of the Drawings

[0047] Figure 1 It is a flowchart of the fast DDoS attack detection method based on multi-modal data feature enhancement and combination in the present invention;

[0048] Figure 2 It is a framework diagram of multi-modal data feature enhancement in the present invention;

[0049] Figure 3 It is a framework diagram of the generation of dynamic weighted optimal feature combination in the present invention. Detailed Embodiments

[0050] The present invention aims to provide a fast DDoS attack detection method based on multi-modal data feature enhancement and combination, which solves the problems of low accuracy, poor generalization ability, and inability to meet real-time requirements in the traditional DDoS attack detection method based on feature selection. Its core idea is: through multi-modal data, feature enhancement is performed on uncommon DDoS attack types, and at the same time, a multi-layer perceptron is combined to fully explore the interaction between features, and a dynamic weighting and attention mechanism is used to construct a globally optimal feature combination, which is applicable to the fast detection of various different types of DDoS attacks. The present invention solves the problems of feature independence, local optimality, and poor generalization ability in the filter method and wrapper method by performing feature enhancement on the minority class through multi-modal data and constructing a globally optimal feature combination. At the same time, it reduces the dependence on a large amount of data and the training time, improves the detection efficiency, and can operate stably in real-time scenarios.

[0051] Specifically, the present invention combines the characteristics of the temporal variation of traffic with the text characteristics of system log formatting, and uses the reasoning enhancement of professional domain knowledge. While highlighting the features, it also avoids the computational consumption caused by a large amount of redundant data and improves the detection efficiency. In addition, during the feature combination process, first, candidate feature subsets are de-redundant through feature pre-screening and a similarity-based metric function, and then correlation analysis is performed with various different types of DDoS attacks, transforming the multi-objective optimization problem into a simple constraint problem to quickly find a solution with excellent performance. Then, the attention mechanism is used to optimize the feature selection process through an adaptive weighting algorithm for feature selection, ensuring that the feature selection reaches the optimal when facing different DDoS attack types. Finally, the model is trained using the extracted optimal feature combination subset to obtain a trained detection model. In practical applications, corresponding features are extracted from real-time traffic as the input of the detection model to achieve fast and accurate detection of DDoS attacks.

[0052] In terms of specific implementation, the flow of the fast DDoS attack detection method based on multi-modal data feature enhancement and combination provided by the present invention is shown in Figure 1 , and it includes the following implementation steps:

[0053] S1. Acquisition and preprocessing of multi-modal data

[0054] In this step, multi-modal data for different types of DDoS attacks on industrial control systems is acquired and preprocessed, where the multi-modal data includes traffic data, log data, and professional domain knowledge of the attacks.

[0055] To ensure the quality and consistency of the input data, it is necessary to preprocess the traffic data, log information, and domain knowledge. Specifically, it includes: checking for missing values in the traffic data of different attack types, filling them using interpolation or forward / backward filling methods, and correcting outliers using statistical methods. Cleaning the log information, removing irrelevant content, normalizing the text format, using natural language processing techniques to convert the text data into numerical features, generating labels based on the error information and specific events in the logs as auxiliary features for training and detection, and finally performing standardization processing to ensure the consistency of the numerical features. Introducing domain knowledge for minority class enhancement, combining known attack patterns with abnormal behaviors in network traffic to provide more context information for different types of DDoS attacks, and then converting them into numerical features through encoding techniques for subsequent fusion of multimodal data.

[0056] S2. Multimodal Data Feature Enhancement

[0057] In this step, the multimodal data is aligned and normalized, then features are extracted and fused, and then a modal attention mechanism and a multi-layer perceptron are used for feature enhancement to obtain a feature set.

[0058] Specifically, first, it is ensured that the data from different data sources can be aligned according to the time sequence or other correlation relationships. For example, the traffic data and log information can be aligned according to the time axis. Since the domain knowledge usually has no direct time correlation with the traffic data and log information, it can be aligned through semantic or context information.

[0059] Among them, the alignment method formula for traffic data and log information is as follows:

[0060] x′ p ,x′ t =Align(x p ,x t ,T);

[0061] Since the traffic attack patterns defined in the domain knowledge can match the abnormal behaviors in the traffic features, and the keywords in the log data can be mapped to the rule descriptions in the domain knowledge, so by generating the correlation matrix A of the domain knowledge x k and the traffic feature x' p 、log feature x' t , finally, the aligned data representation of the domain knowledge is:

[0062] x′ k =A*x k ;

[0063] Then, the aligned multimodal data is normalized to obtain:

[0064]

[0065] The dimension of all normalized data is d z 。

[0066] Then, perform minority class data augmentation through a concatenation operation to obtain the augmented data:

[0067] X = Concat(x″ p , x″ t , x″ k );

[0068] Next, perform feature extraction to obtain the preliminary fused feature set Z:

[0069] Z = FeatureExtraction(X);

[0070] Then use ModalAttention (modal attention) to highlight the features of the minority DDoS attack classes and common DDoS attack classes enhanced with multi-modal data and suppress irrelevant features.

[0071] Finally, use the multi-layer perceptron MLP to perform a non-linear transformation on the fused feature set Z to generate the final feature set Z final :

[0072] Z final = σ(W2 * ReLU(W1 * Z + b1) + b2);

[0073] Through the MLP, the deep interaction relationships between features can be mined, providing a basis for the rapid detection of DDoS attacks, where W1 and W2 are the weight matrices of the fully connected layers, b1 and b2 are the corresponding bias terms, ReLU is the activation function, and σ is the final activation operation. The finally generated feature set Z final will be used as the subsequent input.

[0074] For the specific process of multi-modal data feature augmentation in this step, please refer to Figure 2 。

[0075] S3. Initial screening of the feature set and redundancy removal

[0076] In this step, based on prior knowledge, the feature set is initially screened, the feature combination solution space is initialized according to the initially screened feature set, the feature combination solution space includes multiple feature combination subsets, and the redundant feature combination subsets in the feature combination solution space are removed using a similarity metric function.

[0077] Specifically, through rapid correlation analysis and importance ranking of prior knowledge, the feature combinations are preliminarily screened. Features with lower weights are directly removed, reducing the number of irrelevant features and significantly reducing the subsequent algorithm complexity. After the preliminary screening is completed, the solution space G of the feature combinations is initialized. Each vector sequence in G represents a feature selection subset, and 1 and 0 are used to indicate whether a feature is selected. Then, through the similarity measurement function, subsets with high similarity are removed to reduce redundancy and retain diverse subsets. The similarity calculation formula is as follows:

[0078]

[0079] That is, the similarity between any two feature combination subsets in the solution space of the feature combinations is calculated through the above formula. When the similarity is greater than the given threshold, one feature combination subset is retained and the other is deleted.

[0080] S4. Problem Reconstruction and Constraint Handling

[0081] In this step, for the solution space of the feature combinations after removing redundancy, by introducing constraint conditions, the multi-objective feature selection problem is reconstructed into a constrained optimization problem, and multiple candidate feature combination subsets are obtained by solving the constrained optimization problem.

[0082] Specifically, by introducing the constraint condition P(S), the multi-objective feature selection problem is reformulated as a constrained optimization problem:

[0083] P(S), subject to Cov(S)≥γ, Corr(S,C k )≥κ;

[0084] where P(S) represents the performance of the detection accuracy of the input traffic data containing all DDoS attack types, Cov(S) represents the feature coverage rate, Corr(S,C k ) represents the correlation between the feature and the attack type C k , and γ and κ are preset thresholds. The solution range is further narrowed according to the thresholds. By solving the constrained optimization problem, the complexity of the feature subset search space is reduced and the solution speed is improved.

[0085] Among them, the preset thresholds γ and κ can be determined in the following ways:

[0086] In the initial stage, both γ and κ are set to 1 to ensure that the coverage and relevance of the initial solution are at a high level. Under this condition, the feature combination subset is constrained and optimized, the classification performance P(S) is calculated and its value is recorded. Subsequently, γ and κ are adjusted by the bisection method, and the two left and right boundary values of γ and κ after each adjustment are recorded. After each adjustment, the value of P(S) is recalculated and evaluated. During the adjustment process, P(S) under different thresholds is compared to ensure that P(S) is always at a high level, and only the top K best P(S) values are recorded. When the change in the threshold γ or κ causes a significant decrease in P(S), the adjustment operation is stopped, and the thresholds γ and κ that keep P(S) at a high level are retained as the final set values.

[0087] This process effectively reduces the complexity of the feature subset search space, while ensuring the optimization of the classification performance, and significantly improves the solution speed of the constrained optimization problem.

[0088] S5. Generation of Dynamically Weighted Optimal Feature Combinations

[0089] In this step, for each candidate feature combination subset, the candidate features in the subset are selected through a dynamic weighting and attention mechanism, and by calculating the detection accuracy of the DDoS attack detection model respectively, the feature combination subset with the highest detection accuracy for each type of DDoS attack is obtained as the global optimal feature combination subset.

[0090] Specifically, for each feature s in the solution sequence of the candidate feature subset i a dynamic weight ω i is assigned and updated based on the attention mechanism. The formula is as follows:

[0091]

[0092] where W is the initial weight matrix, and e i represents the importance score of feature s i . During the optimization process, features with larger weights are retained preferentially, and through the dynamic adjustment of the weights, the feature combination gradually adapts to all types of DDoS attacks.

[0093] The subsets of candidate feature combinations after dynamic weight adjustment are respectively applied to the DDoS attack detection model, and the detection accuracy of the model for different types of DDoS attacks is calculated. If the detection accuracy corresponding to a certain subset of candidate feature combinations exceeds the preset accuracy threshold, it is determined that this subset is a feature combination subset that meets the requirements and is used as the global optimal feature combination subset. When the requirements are not met, that is, no subset of candidate feature combinations can reach the accuracy threshold, a fast variant of the optimization algorithm NSGA-II is used to accelerate the feature weight optimization and improve the efficiency and accuracy of generating the optimal feature subset. Finally, the optimal feature combination subset applicable to all types of DDoS attacks is output, and the specific process is as Figure 3 shown.

[0094] S6. Training of the attack detection model

[0095] In this step, the global optimal feature combination is used as the key index of the DDoS attack detection model, and the DDoS attack detection model is trained to obtain a trained DDoS attack detection model.

[0096] S7. DDoS attack detection:

[0097] In this step, the trained DDoS attack detection model is deployed in the industrial control system, and the corresponding features are extracted from the real-time traffic of the industrial control system as the input of the trained DDoS attack detection model, so as to obtain the DDoS attack detection result.

[0098] Embodiment

[0099] The fast DDoS attack detection method based on multi-modal data feature enhancement and combination provided in this embodiment includes the following implementation steps:

[0100] I. Acquisition and preprocessing of multi-modal data

[0101] In this embodiment, the actual attacked network traffic data of an industrial control system is collected. The missing values in the traffic data are filled by the mean method, and the outliers are corrected by statistical methods. For example, in an industrial control system, when capturing traffic through a network traffic capture tool, the flag bit information of the SEQ / ACK analysis field in some packets may be lost, resulting in the loss of timestamp data, and interpolation can be used for filling; for outliers, for example, the source IP address and the destination IP address do not conform to the IP protocol specification, logical replacement can be used for correction or the abnormal data can be directly deleted.

[0102] In this embodiment, attacked log information consistent with network attack traffic data is adopted. Among them, some content is irrelevant to attack detection (such as normal operation log information), so the method of regular expression matching is used to remove the irrelevant content. Based on this embodiment, only the information with log levels of ERROR or WARNING is retained, and the filtered logs are as follows:

[0103] 2024-12-24 10:23:45 ERROR Unauthorized access attempt detected from IP: 192.168.1.105 to resource: / control_panel

[0104] 2024-12-24 10:23:47 WARNING High CPU usage detected on Node: PLC-1

[0105] 2024-12-24 10:23:48 ERROR DDoS attack detected from multiple sources targeting resource: / api / v1 / data

[0106] After that, the log information is normalized, key fields are extracted, such as timestamp, log level, event description, etc., and the text information in the logs is converted into numerical features through natural language processing technology.

[0107] II. Multi-modal Data Feature Enhancement

[0108] In this embodiment, the traffic data and log information are initially aligned based on the timestamp field. Since there may be a certain offset or out-of-sync between the timestamps of the traffic data and log information (for example, the time of traffic records is accurate to milliseconds, while the time of log records is accurate to seconds), the method of time window can be used for alignment. For example, if the time window is set to 5 seconds, the traffic data with timestamp 2024-12-24 10:23:45 can be aligned with the log information of 2024-12-24 10:23:47.

[0109] Since there may be no direct temporal correlation between the attack patterns in the domain knowledge and the traffic data or log information, it is necessary to achieve alignment based on semantic or context information. For example, extract the features in the traffic data and log information and match them with the attack patterns: By counting the traffic records of the source IP 192.168.1.105, it is found that it sent a large number of packets to multiple destination IP addresses in a short period of time, which conforms to the feature of "frequent source IP switching"; the keyword "Unauthori zed access attempt" is included in the log description, which is semantically consistent with the attack pattern of "malicious login attempt" in the domain knowledge. Enhance the traffic data and log information with the aligned timeline and the domain knowledge aligned based on semantics.

[0110] In addition, convert the preprocessed data into standardized data of the same scale through linear normalization to ensure that different modality data have the same data range during feature fusion, avoid the impact of feature range differences on the fusion effect, and at the same time establish the mapping between the features and the normalized data, so as to find the corresponding features according to the output of the optimal feature combination.

[0111] For example, in an industrial control system, obtain network traffic data through a network traffic capture tool, and extract the following feature fields from the traffic data: src_ip, dst_ip, src_port, dst_port, protocol_type, packets_per_second, bytes_per_second, average_packet_size, flag_distribution, traffic_direction, session_duration, packet_interarrival_time, max_packet_interarrival_time, min_packet_interarrival_time, session_packet_count, session_byte_count, burst_size, burst_duration, bidirectional_byte_ratio, bidirectional_packet_ratio, expressed as:

[0112]

[0113] Through the features of multi-modal data x t 、x k After fusing with the features of the above captured traffic data x p Use Modal Attention and MLP for feature enhancement to output the final feature set Zfinal :

[0114] z final = [z1, z2, z3, z4, z5, z6, z7, z8, z9, z 10 , z 11 , z 12 , z 13 , z 14 , z 15 , z 16 , z 17 , z 18 , z 19 , z 20 ;

[0115] III. Initial Screening of Feature Set and Redundancy Removal

[0116] In this embodiment, a fast correlation analysis is performed on the feature fields in Z final . The features are screened by combining prior knowledge, and the information that is significantly not helpful for DDoS detection, such as affected_resource, is removed. The finally retained feature set is:

[0117] Z filtered = [z1, z2, z3, z4, z5, z6, z7, z8, z9, z 10 , z 11 , z 12 , z 14 , z 15 , z 16 , z 17 , z 18 , z 19 , z 20 ;

[0118] For the screened feature set Z filtered , the solution space G of the feature combination is initialized. The solution space G contains multiple feature combination subsets, and each subset S i is represented by a vector, where {1, 0} indicates whether a feature is selected. To reduce redundancy, the similarity Sim(S i , S j ) between any two subsets in the solution space is calculated. When the similarity is greater than a given threshold, one subset is retained and the other is deleted.

[0119] IV. Problem Reconstruction and Constraint Handling

[0120] For the feature combination subsets after redundancy removal, a constraint optimization process is introduced: initially set γ = 1 and κ = 1, calculate the classification performance P(S), and record the initial classification performance P0. By adjusting γ and κ according to the dichotomy method, record the top-k subsets S that make P(S) at a relatively high leveli As a candidate subset (k = 3 is adopted in this embodiment), when the classification performance shows a significant decrease, the iterative process is stopped, and a candidate feature combination subset is obtained:

[0121] S temp ={S2, S6, S 18};

[0122] V. Generation of Dynamically Weighted Optimal Feature Combinations

[0123] For the candidate feature combination subset S temp , in this embodiment, the candidate features are optimized through dynamic weight allocation and the attention mechanism to generate an optimal feature combination applicable to all DDoS attack types. Specifically, by verifying each subset in S temp , through dynamic weight allocation, the classifier is made to achieve the optimal effect that each subset can achieve.

[0124] The dynamic weight allocation and the optimization formula according to the attention mechanism are as follows:

[0125]

[0126] On the basis of weight adjustment, to further accelerate the process of selecting the globally optimal feature combination, a fast variant algorithm of NSGA-II is introduced to accelerate the convergence of the feature combination solution process. After the convergence of the feature combination solution space corresponding to the candidate subset is completed, the feature combination subset that maximizes the detection accuracy is selected as the globally optimal combination.

[0127] In this embodiment, the output globally optimal feature combination subset is:

[0128] Z optimal ={z6, z 12 , z 17 , z 18};

[0129] VI. Model Training

[0130] Using the globally optimal feature combination subset obtained above as a key indicator for DDoS attack detection, the attack detection model is trained to obtain a DDoS attack detection model with high accuracy, fast detection speed, and meeting the real-time requirements.

[0131] VII. DDoS Attack Detection

[0132] Deploy the trained DDoS attack detection model to the industrial control system, extract the corresponding features from the real-time traffic of the industrial control system as the input of the trained DDoS attack detection model, so as to obtain the DDoS attack detection result.

[0133] Finally, it should be noted that the above embodiments are only preferred embodiments and are not intended to limit the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the spirit and scope of the present invention as defined by the claims, several modifications, equivalent substitutions, improvements, etc. should all be included within the protection scope of the present invention.

Claims

1. A fast DDoS attack detection method based on multi-modal data feature enhancement and combination, characterized in that: It includes the following steps: S1. Obtain multi-modal data for different types of DDoS attacks against industrial control systems and perform preprocessing. The multi-modal data includes traffic data, log data, and professional domain knowledge; S2. Align and normalize the multi-modal data, then extract and fuse features, and then use the modal attention mechanism and multi-layer perceptron for feature enhancement to obtain a feature set; S3. Based on prior knowledge, perform a preliminary screening on the feature set, initialize the feature combination solution space according to the preliminarily screened feature set. The feature combination solution space includes multiple feature combination subsets, and use the similarity metric function to remove redundant feature combination subsets in the feature combination solution space; S4. For the feature combination solution space after removing redundancy, by introducing constraint conditions, reconstruct the multi-objective feature selection problem into a constrained optimization problem, and obtain multiple candidate feature combination subsets by solving the constrained optimization problem; S5. For each candidate feature combination subset, select the candidate features in the subset through the dynamic weighting and attention mechanism, and calculate the detection accuracy rate applied to the DDoS attack detection model respectively, and obtain the feature combination subset with the highest detection accuracy rate for each type of DDoS attack as the global optimal feature combination subset; S6. Use the global optimal feature combination as the key index of the DDoS attack detection model to train the DDoS attack detection model; S7. In actual application, extract corresponding features according to the real-time traffic of the industrial control system as the input of the trained DDoS attack detection model to obtain the DDoS attack detection result.

2. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination according to claim 1, characterized in that In step S1, the preprocessing includes: Check whether there are missing values in the traffic data of different types of DDoS attacks, fill them using interpolation filling or forward and backward value filling methods, and correct outliers using statistical methods; Clean the log data corresponding to the traffic data of different types of DDoS attacks, remove irrelevant content, and standardize the text format, and then convert the text information in the log into numerical features through natural language processing technology; According to professional domain knowledge, combine known attack patterns with abnormal behaviors in network traffic to provide context information for different types of DDoS attacks, and then convert them into numerical features through coding technology.

3. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination as claimed in claim 1, wherein In step S2, the method for aligning multi-modal data includes: Align the traffic data and log data according to the time axis, and align the professional domain knowledge with the traffic data and log data through semantic or context information.

4. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination according to claim 1, characterized in that, In step S2, using the modal attention mechanism and multi-layer perceptron for feature enhancement to obtain a feature set includes: First, use the modal attention mechanism to highlight the features of a few DDoS attack classes and common DDoS attack classes in the fused features, and suppress irrelevant features; Then, a multi-layer perceptron is used to perform a non-linear transformation on the fused features processed by the modal attention mechanism to generate a feature set Z final : Z final = σ(W2 * ReLU(W1 * Z + b1) + b2); Among them, ReLU is the activation function, σ is the final activation operation, W1 and W2 are the weight matrices of the fully connected layers in the multi-layer perceptron, and b1 and b2 are the corresponding bias terms.

5. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination according to claim 1, characterized in that, In step S3, the method of removing redundant feature combination subsets in the feature combination solution space by using a similarity metric function includes: Calculating the similarity between any two feature combination subsets in the feature combination solution space through a similarity metric function. When the similarity is greater than a given threshold, one feature combination subset is retained and the other is deleted.

6. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination according to claim 1, characterized in that In step S4, the constraint condition is expressed as: P(S), subject to Cov(S)≥γ, Corr(S,C k )≥κ; Among them, P(S) represents the detection performance of the input traffic data containing all DDoS attack types, Cov(S) represents the feature coverage rate, and Corr(S, C k ) represents the correlation between the feature and the attack type C k , and γ and κ are preset thresholds.

7. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination as claimed in claim 6, wherein, In step S4, the setting methods of γ and κ include: In the initial stage, both γ and κ are set to 1. Under this condition, the feature combination subset is constrained and optimized, and the detection performance P(S) is calculated. Subsequently, γ and κ are adjusted by the bisection method. After each adjustment, the value of P(S) is recalculated and evaluated. When the change in the threshold γ or κ causes a significant decrease in P(S), that is, the decrease amplitude exceeds a given amplitude threshold, the adjustment operation is stopped, and the threshold γ or κ before this adjustment is retained as the final set value.

8. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination according to claim 1, wherein In step S5, the selection of candidate features in the subset by using a dynamic weighting and attention mechanism includes: For the candidate feature s in the subset i Assign a dynamic weight ω i , and update it based on the attention mechanism: Among them, W is the initial weight matrix, and e i represents the importance score of feature s i . During the optimization selection process of candidate features, features with larger weights are preferentially retained.

9. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination according to claim 1, characterized in that In step S5, by calculating the detection accuracy rates applied to the DDoS attack detection model respectively, obtaining the feature combination subset with the highest detection accuracy rate for each type of DDoS attack as the globally optimal feature combination subset, includes: Applying the candidate feature combination subsets after dynamic weight adjustment to the DDoS attack detection model respectively, and calculating the detection accuracy rates of the model for different types of DDoS attacks. If the detection accuracy rate corresponding to a certain candidate feature combination subset exceeds a preset accuracy threshold, it is determined that this subset is a qualified feature combination subset and used as the globally optimal feature combination subset.

10. The fast DDoS attack detection method based on multi-modal data feature enhancement and combination as claimed in claim 9, wherein Step S5 further includes: when the requirements are not met, that is, no candidate feature combination subset can reach the accuracy threshold, using a fast variant algorithm of NSGA-II to accelerate the convergence of the feature combination solution process, and selecting the feature combination subset with the maximum detection accuracy rate as the globally optimal feature combination.