A network security malicious traffic tracing method based on generative adversarial network
By building a unified low-dimensional embedding space through generative adversarial networks, integrating multi-dimensional traffic features, and generating potential malicious traffic samples, we solve the problems of insufficient feature expression and perspective fragmentation in malicious traffic tracing in existing technologies, and achieve dynamic reconstruction and precise tracing of complex attack chains.
Patent Information
- Application Number
- CN202510905589.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-02
AI Technical Summary
Existing technologies in malicious traffic tracing have problems such as limited feature expression capabilities, fragmented perspectives, lack of generation capabilities and deduction mechanisms, and disconnection between judgment and reasoning, resulting in insufficient accuracy of tracing results.
A generative adversarial network is used to construct a unified low-dimensional embedding space, integrate multi-dimensional traffic features, generate potential malicious traffic samples, perform path perturbation encoding and attack context modeling, and achieve dynamic reconstruction and precise tracing of complex attack chains.
It improves the feature expression capability of malicious traffic tracing, the attack behavior deduction capability and the accuracy of the tracing path, and enhances the recognition and linkage tracing effect of complex attack chains.
Smart Images

Figure CN120415910B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security malicious traffic tracing method based on a generative adversarial network. Background Art
[0002] With the continuous evolution of information technology and the rapid expansion of network systems, cybersecurity threats are becoming increasingly complex and diverse. Malicious traffic is becoming increasingly disguised and concealed, seriously impacting the operational stability and information security of network systems. Against this backdrop, the precise identification of malicious traffic and accurate tracing of attack paths have become key and challenging areas of network security research.
[0003] In existing technologies, mainstream malicious traffic tracing methods generally rely on technical means such as rule matching, traffic statistics, or static feature analysis. These methods have the following shortcomings in practical applications:
[0004] 1. Limited feature expression capabilities: Traditional methods are mostly based on shallow semantic features and cannot effectively capture the deep-level protocol behavior patterns, communication structure evolution, and time series changes in traffic data, resulting in insufficient accuracy in tracing results.
[0005] 2. Fragmented perspectives and lack of integration: Existing methods mostly focus on a single perspective (such as traffic packet sequences or communication structures) and fail to achieve unified modeling of multi-dimensional features. This leads to insufficient utilization of semantic information and makes it difficult to accurately portray the full picture of attack behavior.
[0006] 3. Lack of generation capabilities and deduction mechanisms: Traditional methods generally lack the ability to model and generate potential variant behaviors in the attack path. They are unable to simulate unobserved but reasonable behavioral stages in the attack chain, and the traceability path is incomplete.
[0007] 4. Disconnection between discrimination and reasoning: Existing methods usually separate malicious sample discrimination from attack path analysis and lack a unified embedding space evaluation mechanism, resulting in limited traceability credibility and continuity.
[0008] Therefore, how to provide a network security malicious traffic tracing method based on generative adversarial networks is a problem that technicians in this field urgently need to solve. Summary of the Invention
[0009] One purpose of the present invention is to propose a network security malicious traffic tracing method based on generative adversarial networks. The present invention integrates multi-dimensional traffic features, constructs a unified low-dimensional embedding space, generates potential malicious traffic samples, performs path perturbation coding and attack context modeling, and realizes dynamic reconstruction and precise tracing of complex attack chains. It has the advantages of rich feature expression, strong attack behavior deduction capability and high tracing path accuracy.
[0010] According to an embodiment of the present invention, a method for tracing malicious network traffic security based on a generative adversarial network includes the following steps:
[0011] S1. Collect network traffic data, select the target traffic sample to be traced, extract protocol behavior features, communication structure features, and time evolution features, perform semantic encoding on them, and generate protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation;
[0012] S2. Input the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation into the multi-perspective fusion process, build semantic correspondence, and uniformly map them into a low-dimensional embedding space;
[0013] S3 constructs a segmented embedding manifold set based on multiple labeled malicious traffic samples in a low-dimensional embedding space, performs interpolation operations to generate intermediate state embedding representations, and forms an embedded traffic sample sequence;
[0014] S4. Generate attack context embedding representation based on target traffic samples, perform perturbation path encoding on the embedded traffic sample sequence, generate perturbation path embedding representation, and combine it with attack context embedding representation to form a guided condition vector;
[0015] S5. Input the guided condition vector and the random latent variable generated based on the preset distribution sampling into the generator, and the generator performs joint encoding to output the embedded representation of the potential malicious traffic sample;
[0016] S6. Embed the potential malicious traffic sample into the representation input embedding consistency discrimination network, perform true and false identification, and perform path similarity scoring;
[0017] S7. Based on the path similarity score and the positional relationship between the embedded representations of potential malicious traffic samples in the low-dimensional embedding space, an attack chain path graph is constructed, and the shortest path sequence to the embedded representations of the labeled malicious traffic samples is calculated.
[0018] Optionally, the S1 specifically includes:
[0019] S11, collecting original network traffic data within a preset time window, constructing a five-tuple key value based on the source Internet Protocol address, destination Internet Protocol address, source port number, destination port number, and network protocol type, performing stream-level reorganization on the original network data packets, and generating an ordered network session sequence;
[0020] S12. Selecting a target network traffic sample to be traced from the ordered network session sequence based on a behavior matching strategy, wherein the behavior matching strategy includes a rule comparison strategy based on a known malicious feature template;
[0021] S13. Extracting protocol behavior features from the target network traffic sample, wherein the protocol behavior features include a data packet interaction direction sequence, a data packet length sequence, and a protocol field change sequence in a network session;
[0022] S14. Extracting communication structure features for the target network traffic sample, constructing a communication graph model based on the end-to-end network entity interaction relationship, and extracting graph structure parameters such as connection relationship density, path length distribution, node centrality, and structure nesting level;
[0023] S15. Extracting time evolution features for the target network traffic sample, wherein the time evolution features include time interval distribution between data packets, frequency distribution of emergency event time windows, and active time period sequence;
[0024] S16, inputting the protocol behavior features, communication structure features, and time evolution features into the protocol behavior semantic coding structure, the communication structure semantic coding structure, and the time evolution semantic coding structure, respectively, and performing embedding expression mapping, wherein the semantic coding structure includes a normalization layer, a structure parsing layer, and an embedding output layer;
[0025] S17. Output the protocol behavior embedding representation, communication structure embedding representation and time evolution embedding representation respectively.
[0026] Optionally, the S2 specifically includes:
[0027] S21. Receive the protocol behavior embedding representation, the communication structure embedding representation, and the time evolution embedding representation, and perform a unified scale normalization process on the three types of embedding representations to keep the feature amplitude consistent with the statistical distribution;
[0028] S22. Input the normalized protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation into a multi-view semantic alignment structure, wherein the multi-view semantic alignment structure includes three cross-attention channels and obtains a saliency mapping relationship between cross-embedding channels by calculating a semantic interaction matrix between feature dimensions.
[0029] S23. In the multi-view semantic alignment structure, a feature guidance channel is constructed, the protocol behavior embedding representation is used as the leading channel, and attention weighted fusion is performed on the communication structure embedding representation and the time evolution embedding representation to generate a fused feature representation. The fusion process maintains the context structure guidance effect of the main view of the protocol behavior;
[0030] S24. Input the fused feature representation into a unified low-dimensional embedding space mapping structure, wherein the mapping structure includes a multi-layer nonlinear transformation module with inter-layer residual connections, and sets a semantic distance preservation constraint to maintain the spatial geometric relationship between the original three types of embeddings.
[0031] Optionally, the S3 specifically includes:
[0032] S31. Obtaining multiple labeled malicious traffic sample embedding representations in a unified low-dimensional embedding space, performing a joint clustering operation based on the attack behavior label, spatial distribution position, and behavior temporal encoding result corresponding to each labeled malicious traffic sample embedding representation, and constructing a malicious behavior embedding sample cluster set;
[0033] S32. For each malicious behavior embedded sample cluster set, based on the semantic similarity distribution changes between the adjacent labeled malicious traffic sample embedded representations in the cluster set and the stage span information of the attack stage label, identify segmentation boundary points and divide each malicious behavior embedded sample cluster set into a number of local embedding manifold subsegments;
[0034] S33. All local embedded manifold sub-segments are combined into a segmented embedded manifold set according to the attack behavior time sequence and the attack chain structure relationship. The segmented embedded manifold set represents an embedded path structure set composed of multiple local embedded manifold sub-segments with structural continuity relationship.
[0035] S34. Select an interpolation control path based on the attack context embedding representation generated from the target traffic sample, perform an interpolation operation along the interpolation control path in the segmented embedding manifold set, perform an equidistant interpolation operation within the local embedding manifold subsegments, and perform a disturbance control interpolation operation between different local embedding manifold subsegments to generate an intermediate state embedding representation;
[0036] S35. Combining the multiple intermediate state embedding representations with the corresponding labeled malicious traffic sample embedding representations to form an embedded traffic sample sequence, wherein the embedded traffic sample sequence is used to subsequently construct a guiding basis for generating potential malicious traffic samples in the adversarial network input space.
[0037] Optionally, the S4 specifically includes:
[0038] S41. Inputting the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation of the target network traffic sample into an attack context modeling structure, wherein the attack context modeling structure includes temporal feature extraction and behavior intention modeling, and is used to encode the behavior evolution and structure features of the target network traffic sample to generate an attack context embedding representation;
[0039] S42. Input the embedded traffic sample sequence into a path perturbation coding structure. The path perturbation coding structure includes path order-aware coding and perturbation injection control. The path order-aware coding encodes the relative temporal order and embedding space offset relationship between the embedded representations of each malicious traffic sample in the embedded traffic sample sequence to obtain an initial path coding representation.
[0040] S43, perturbation injection control uses the attack context embedding representation as a reference to apply controlled perturbation to the initial path encoding representation. The controlled perturbation includes limiting the perturbation direction and perturbation amplitude in the semantic embedding space and outputting the perturbation path embedding representation.
[0041] S44. Input the attack context embedding representation and the perturbation path embedding representation into the guided condition fusion structure. The guided condition fusion structure adopts a gated residual fusion method to output a guided condition vector. The guided condition vector contains both the context attack intention and the embedded path perturbation information.
[0042] Optionally, the gated residual fusion method includes: inputting the attack context embedding representation into a first fusion channel, and inputting the perturbation path embedding representation into a second fusion channel, the first fusion channel includes a residual mapping unit, which is used to perform identity mapping on the attack context embedding representation and maintain its feature expression integrity, the second fusion channel includes a gated activation unit, which is used to perform a gated weight generation operation on the perturbation path embedding representation, the gating weight is determined based on the attention coefficient matrix between the attack context embedding representation and the perturbation path embedding representation, the weighted perturbation path embedding representation output by the gated activation unit and the attack context embedding representation output by the residual mapping unit are element-by-element weighted fused to obtain a fused embedding representation, and the fused embedding representation is input into the generator structure of the generative adversarial network as a guided condition vector.
[0043] Optionally, the S5 specifically includes:
[0044] S51. Perform random sampling on the latent variable space based on a preset standard normal distribution to generate a random latent variable vector. The preset standard normal distribution is a Gaussian distribution with a mean of zero and a variance of one, which is used to introduce disturbances into the latent space.
[0045] S52. Input the guided condition vector and the random latent variable vector into a feature-guided connection structure, wherein the feature-guided connection structure includes a channel selection structure and a weight control structure. The channel selection structure performs a dimension screening operation based on the difference between the attack context semantic features and the embedded path perturbation features in the guided condition vector to determine the channel to be fused. The weight control structure generates a fusion gating parameter based on the correlation distribution of the elements of each dimension in the channel to be fused, and generates a joint input vector in a weighted fusion manner.
[0046] S53, inputting the joint input vector into a generator structure, wherein the generator structure is composed of multiple layers of nested linear transformation layers, nonlinear activation layers, and batch normalization layers, and extracting fusion features in sequence;
[0047] S54. Set a cross residual connection path in the generator structure to connect the initial features of the guided condition vector and the random latent variable vector to the intermediate hidden layer nodes, and introduce an attention mechanism in the specified fusion layer to complete feature coupling enhancement;
[0048] S55. Output the embedded representation of the potential malicious traffic sample as the input of the subsequent embedding consistency judgment network for true and false identification and path similarity scoring processing.
[0049] Optionally, the S6 specifically includes:
[0050] S61. Construct an embedding consistency discrimination network, wherein the embedding consistency discrimination network includes a true-false discrimination substructure and a path consistency scoring substructure, wherein the true-false discrimination substructure is used to judge the embedding semantic difference between the embedding representation of the potential malicious traffic sample and the embedding representation of the labeled real traffic sample, and the path consistency scoring substructure is used to evaluate the similar path structure between the embedding representation of the potential malicious traffic sample and the embedding representation in the embedded traffic sample sequence;
[0051] S62, embedding the potential malicious traffic sample into the true-false discrimination substructure, and outputting a discrimination probability label based on the embedding feature distribution extracted by the multi-layer discriminant network;
[0052] S63. Input the embedded representation of the potential malicious traffic sample and the embedded traffic sample sequence into the path consistency scoring substructure. Utilize the established sequential structural relationship and embedded spatial position coordinates of the embedded traffic sample sequence to calculate the matching score between the embedded representation of the potential malicious traffic sample and the sample path, and generate a path similarity score.
[0053] Optionally, the S7 specifically includes:
[0054] S71. Obtaining, in a unified low-dimensional embedding space, an embedding spatial position relationship between an embedding representation of a potential malicious traffic sample and an embedding representation of multiple labeled malicious traffic samples, wherein the embedding spatial position relationship includes Euclidean distance, embedding trajectory angle, and local density distribution characteristics;
[0055] S72. Combining the path similarity score results with the embedding spatial position relationship, construct an attack chain path graph. The attack chain path graph uses the embedding representation of the potential malicious traffic sample as the starting node and the embedding representation of the labeled malicious traffic sample as the end node. The edge weights between the nodes are determined by the path similarity score and the spatial position metric.
[0056] S73. In the attack chain path graph, execute a weighted shortest path search algorithm to obtain a shortest path sequence between the embedded representation of the potential malicious traffic sample and the embedded representation of each labeled malicious traffic sample, and construct multiple tracing path candidates based on the shortest path sequence;
[0057] S74. Calculate confidence scores for the multiple traceability path candidates, where the confidence scores are determined based on path similarity scores of embedded representations of nodes in the paths.
[0058] S75. Filter paths with confidence scores higher than a preset threshold as candidate valid paths, and output the candidate valid paths to construct a network attack chain tracing result.
[0059] The beneficial effects of the present invention are:
[0060] (1) This paper improves the structured expression capability of malicious network traffic by constructing a multi-perspective low-dimensional embedding space that integrates protocol behavior features, communication structure features, and time evolution features, and combines embedding semantic alignment with path perturbation modeling. This enables the traceability process to accurately capture the potential connections between attack behaviors and effectively deal with complex and changeable attack paths.
[0061] (2) The present invention introduces a potential space perturbation and guidance condition control mechanism through generative adversarial networks, and combines attack context modeling and embedded path perturbation coding, so that the system has the ability to simulate and evolve the dynamic behavior of target malicious traffic samples, and realizes the accurate generation and authenticity judgment of potential attack samples, thereby improving the accuracy and integrity of traceability path construction.
[0062] (3) The present invention utilizes the relative position relationship between the path consistency score and the low-dimensional embedding space, combined with the construction of the attack chain path graph and the shortest path reasoning mechanism, which not only improves the interpretability and tracking ability of the malicious traffic behavior chain, but also enhances the system's recognition and linkage tracing effect on multi-stage attack behaviors, and solves the problem that traditional methods have weak recognition ability for attack behavior chain fragments and lack of behavior evolution modeling. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0064] Figure 1 This is a flowchart of the network security malicious traffic tracing method based on generative adversarial network proposed by the present invention;
[0065] Figure 2 This is a flow chart of network traffic feature extraction and multi-view fusion proposed by the present invention;
[0066] Figure 3 Schematic diagram of the segmented embedding manifold construction and embedded traffic sample sequence generation process proposed in the present invention. DETAILED DESCRIPTION
[0067] The present invention will now be described in further detail with reference to the accompanying drawings, which are simplified schematic diagrams that illustrate the basic structure of the present invention in a schematic manner.
[0068] refer to Figure 1-Figure 3 The network security malicious traffic tracing method based on generative adversarial network includes the following steps:
[0069] S1. Collect network traffic data, select the target traffic sample to be traced, extract protocol behavior features, communication structure features, and time evolution features, perform semantic encoding on them, and generate protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation;
[0070] S2. Input the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation into the multi-perspective fusion process, build semantic correspondence, and uniformly map them into a low-dimensional embedding space;
[0071] S3 constructs a segmented embedding manifold set based on multiple labeled malicious traffic samples in a low-dimensional embedding space, performs interpolation operations to generate intermediate state embedding representations, and forms an embedded traffic sample sequence;
[0072] S4. Generate attack context embedding representation based on target traffic samples, perform perturbation path encoding on the embedded traffic sample sequence, generate perturbation path embedding representation, and combine it with attack context embedding representation to form a guided condition vector;
[0073] S5. Input the guided condition vector and the random latent variable generated based on the preset distribution sampling into the generator, and the generator performs joint encoding to output the embedded representation of the potential malicious traffic sample;
[0074] S6. Embed the potential malicious traffic sample into the representation input embedding consistency discrimination network, perform true and false identification, and perform path similarity scoring;
[0075] S7. Based on the path similarity score and the positional relationship between the embedded representations of potential malicious traffic samples in the low-dimensional embedding space, an attack chain path graph is constructed, and the shortest path sequence to the embedded representations of the labeled malicious traffic samples is calculated.
[0076] In this embodiment, S1 specifically includes:
[0077] S11, collecting original network traffic data within a preset time window, constructing a five-tuple key value based on the source Internet Protocol address, destination Internet Protocol address, source port number, destination port number, and network protocol type, performing stream-level reorganization on the original network data packets, and generating an ordered network session sequence;
[0078] S12. Selecting a target network traffic sample to be traced from the ordered network session sequence based on a behavior matching strategy, wherein the behavior matching strategy includes a rule comparison strategy based on a known malicious feature template;
[0079] S13. Extracting protocol behavior features from the target network traffic sample, wherein the protocol behavior features include a data packet interaction direction sequence, a data packet length sequence, and a protocol field change sequence in a network session;
[0080] S14. Extracting communication structure features for the target network traffic sample, constructing a communication graph model based on the end-to-end network entity interaction relationship, and extracting graph structure parameters such as connection relationship density, path length distribution, node centrality, and structure nesting level;
[0081] S15. Extracting time evolution features for the target network traffic sample, wherein the time evolution features include time interval distribution between data packets, frequency distribution of emergency event time windows, and active time period sequence;
[0082] S16, inputting the protocol behavior features, communication structure features, and time evolution features into the protocol behavior semantic coding structure, the communication structure semantic coding structure, and the time evolution semantic coding structure, respectively, and performing embedding expression mapping, wherein the semantic coding structure includes a normalization layer, a structure parsing layer, and an embedding output layer;
[0083] S17. Output the protocol behavior embedding representation, communication structure embedding representation and time evolution embedding representation respectively.
[0084] This implementation constructs a five-tuple key-value pair to perform flow-level reorganization of raw network traffic, generating an ordered network session sequence. It then identifies target network traffic samples based on a malicious feature template matching strategy. It then extracts protocol behavior features, communication structure features, and time evolution features, embedding and mapping them through a semantic coding structure. Ultimately, it outputs three types of embedded representations, enabling structured modeling and multi-dimensional characterization of malicious behavior. This implementation effectively improves the expressive integrity and distinguishing capabilities of malicious traffic samples, providing high-quality input for subsequent embedding fusion and traceability reasoning, and enhancing the system's perception and analytical depth of complex network threats.
[0085] In this embodiment, S2 specifically includes:
[0086] S21. Receive the protocol behavior embedding representation, the communication structure embedding representation, and the time evolution embedding representation, and perform a unified scale normalization process on the three types of embedding representations to keep the feature amplitude consistent with the statistical distribution;
[0087] S22. Input the normalized protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation into a multi-view semantic alignment structure, wherein the multi-view semantic alignment structure includes three cross-attention channels and obtains a saliency mapping relationship between cross-embedding channels by calculating a semantic interaction matrix between feature dimensions.
[0088] S23. In the multi-view semantic alignment structure, a feature guidance channel is constructed, the protocol behavior embedding representation is used as the leading channel, and attention weighted fusion is performed on the communication structure embedding representation and the time evolution embedding representation to generate a fused feature representation. The fusion process maintains the context structure guidance effect of the main view of the protocol behavior;
[0089] S24. Input the fused feature representation into a unified low-dimensional embedding space mapping structure, wherein the mapping structure includes a multi-layer nonlinear transformation module with inter-layer residual connections, and sets a semantic distance preservation constraint to maintain the spatial geometric relationship between the original three types of embeddings.
[0090] This embodiment performs unified scale normalization processing on the protocol behavior embedding representation, communication structure embedding representation and time evolution embedding representation, and uses three-way cross-attention channels to construct a semantic interaction matrix in the multi-perspective semantic alignment structure to achieve significant alignment and fusion of the three types of features. With the protocol behavior embedding representation as the dominant channel, the attention weighting method is used to guide other feature channels to generate fused feature representations, which effectively strengthens the dominant role of the protocol behavior perspective in the overall semantic fusion. Subsequently, a unified low-dimensional embedding mapping is completed through a nonlinear transformation module with inter-layer residual connections, and a semantic distance preservation constraint is introduced to maintain the spatial relationship between features. This method not only improves the integration accuracy of multi-class network traffic semantic information, but also enhances the consistency and discrimination of attack behavior representation in the embedding space, providing a more stable and discriminative embedding basis for subsequent malicious traffic reasoning.
[0091] In this embodiment, S3 specifically includes:
[0092] S31. Obtaining multiple labeled malicious traffic sample embedding representations in a unified low-dimensional embedding space, performing a joint clustering operation based on the attack behavior label, spatial distribution position, and behavior temporal encoding result corresponding to each labeled malicious traffic sample embedding representation, and constructing a malicious behavior embedding sample cluster set;
[0093] S32. For each malicious behavior embedded sample cluster set, based on the semantic similarity distribution changes between the adjacent labeled malicious traffic sample embedded representations in the cluster set and the stage span information of the attack stage label, identify segmentation boundary points and divide each malicious behavior embedded sample cluster set into a number of local embedding manifold subsegments;
[0094] S33. All local embedded manifold sub-segments are combined into a segmented embedded manifold set according to the attack behavior time sequence and the attack chain structure relationship. The segmented embedded manifold set represents an embedded path structure set composed of multiple local embedded manifold sub-segments with structural continuity relationship.
[0095] S34. Select an interpolation control path based on the attack context embedding representation generated from the target traffic sample, perform an interpolation operation along the interpolation control path in the segmented embedding manifold set, perform an equidistant interpolation operation within the local embedding manifold subsegments, and perform a disturbance control interpolation operation between different local embedding manifold subsegments to generate an intermediate state embedding representation;
[0096] S35. Combining the multiple intermediate state embedding representations with the corresponding labeled malicious traffic sample embedding representations to form an embedded traffic sample sequence, wherein the embedded traffic sample sequence is used to subsequently construct a guiding basis for generating potential malicious traffic samples in the adversarial network input space.
[0097] In this implementation, in a unified low-dimensional embedding space, the first step is to integrate multiple labeled malicious traffic sample embedding representations through a joint clustering algorithm, and then construct a malicious behavior embedding sample cluster set based on the attack behavior label, spatial location, and behavior temporal characteristics. The clustering boundaries are then identified based on the semantic similarity change and the attack phase span information, and local embedded manifold sub-segments with clear structures are divided. These sub-segments are then sequentially formed into a segmented embedded manifold set according to the time series and chain structure of the attack behavior. Furthermore, the interpolation control path is determined based on the attack context embedding representation of the target traffic sample, and equidistant interpolation is performed within the sub-segment, and perturbation control interpolation is implemented between sub-segments to generate an intermediate state embedding representation that expresses the intermediate state of the attack evolution. Finally, the combination generates an embedded traffic sample sequence, which provides guidance for the subsequent generation of adversarial networks to model potential malicious samples. This implementation effectively models the stage-by-stage and evolutionary continuity of malicious attack behaviors, improving the simulation capability of potential attack paths and the traceability of generated samples.
[0098] In this embodiment, the S4 specifically includes:
[0099] S41. Inputting the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation of the target network traffic sample into an attack context modeling structure, wherein the attack context modeling structure includes temporal feature extraction and behavior intention modeling, and is used to encode the behavior evolution and structure features of the target network traffic sample to generate an attack context embedding representation;
[0100] S42. Input the embedded traffic sample sequence into a path perturbation coding structure. The path perturbation coding structure includes path order-aware coding and perturbation injection control. The path order-aware coding encodes the relative temporal order and embedding space offset relationship between the embedded representations of each malicious traffic sample in the embedded traffic sample sequence to obtain an initial path coding representation.
[0101] S43, perturbation injection control uses the attack context embedding representation as a reference to apply controlled perturbation to the initial path encoding representation. The controlled perturbation includes limiting the perturbation direction and perturbation amplitude in the semantic embedding space and outputting the perturbation path embedding representation.
[0102] S44. Input the attack context embedding representation and the perturbation path embedding representation into the guided condition fusion structure. The guided condition fusion structure adopts a gated residual fusion method to output a guided condition vector. The guided condition vector contains both the context attack intention and the embedded path perturbation information.
[0103] This implementation method extracts the behavior evolution process and attack intent information by inputting the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation of the target network traffic sample into the attack context modeling structure. At the same time, the embedded traffic sample sequence is input into the path perturbation coding structure, and the path sequence perception and perturbation injection mechanism are used to form the initial path coding. The attack context embedding representation is combined with the directionality and amplitude control to generate the perturbation path embedding representation. The contextual attack semantics and path perturbation features are then conditionally co-encoded with the gated residual fusion structure to output a guiding condition vector that comprehensively represents the attack behavior chain. This approach enhances the generative model's ability to understand the evolution path of the malicious attack chain, improves the pertinence and controllability of the potential malicious traffic sample generation process, and provides a more confident semantic basis for subsequent traceability mapping and generation discrimination.
[0104] In this embodiment, the gated residual fusion method includes: inputting the attack context embedding representation into a first fusion channel, and inputting the perturbation path embedding representation into a second fusion channel, the first fusion channel includes a residual mapping unit, which is used to perform identity mapping on the attack context embedding representation and maintain its feature expression integrity, the second fusion channel includes a gated activation unit, which is used to perform a gated weight generation operation on the perturbation path embedding representation, the gating weight is determined based on the attention coefficient matrix between the attack context embedding representation and the perturbation path embedding representation, the weighted perturbation path embedding representation output by the gated activation unit and the attack context embedding representation output by the residual mapping unit are element-by-element weighted fused to obtain a fused embedding representation, and the fused embedding representation is input into the generator structure of the generative adversarial network as a guided condition vector.
[0105] This embodiment sets a residual mapping unit and a gated activation unit, and inputs the attack context embedding representation and the perturbation path embedding representation into two fusion channels respectively, thereby realizing a dual-channel fusion mechanism with complete preservation of context features and dynamic regulation of perturbation features. Among them, the residual mapping unit performs identity mapping on the attack context embedding representation to ensure that its behavioral semantics are not weakened; the gated activation unit generates fusion weights based on the attention coefficient matrix, implements weighted control on the perturbation path embedding representation, and highlights the perturbation dimension that is highly related to the context. Finally, the fused embedding representation is generated by element-by-element weighted fusion as the guiding condition vector input generator structure, making the process of generating potential malicious traffic samples controllable and context-adaptive, effectively improving the pertinence and expression consistency of sample generation in the generative adversarial network, and enhancing the system's modeling and generalization capabilities for complex attack paths.
[0106] In this embodiment, the S5 specifically includes:
[0107] S51. Perform random sampling on the latent variable space based on a preset standard normal distribution to generate a random latent variable vector. The preset standard normal distribution is a Gaussian distribution with a mean of zero and a variance of one, which is used to introduce disturbances into the latent space.
[0108] S52. Input the guided condition vector and the random latent variable vector into a feature-guided connection structure, wherein the feature-guided connection structure includes a channel selection structure and a weight control structure. The channel selection structure performs a dimension screening operation based on the difference between the attack context semantic features and the embedded path perturbation features in the guided condition vector to determine the channel to be fused. The weight control structure generates a fusion gating parameter based on the correlation distribution of the elements of each dimension in the channel to be fused, and generates a joint input vector in a weighted fusion manner.
[0109] S53, inputting the joint input vector into a generator structure, wherein the generator structure is composed of multiple layers of nested linear transformation layers, nonlinear activation layers, and batch normalization layers, and extracting fusion features in sequence;
[0110] S54. Set a cross residual connection path in the generator structure to connect the initial features of the guided condition vector and the random latent variable vector to the intermediate hidden layer nodes, and introduce an attention mechanism in the specified fusion layer to complete feature coupling enhancement;
[0111] S55. Output the embedded representation of the potential malicious traffic sample as the input of the subsequent embedding consistency judgment network for true and false identification and path similarity scoring processing.
[0112] This embodiment constructs a feature-guided connection structure that includes a channel selection structure and a weight control structure, guides the fusion of the guided condition vector with the random latent variable vector generated based on standard normal distribution sampling, and introduces residual connection and attention mechanism to enhance the feature coupling expression, thereby generating an embedded representation of potential malicious traffic samples with synergistic features of attack context semantics and path perturbation features, realizing targeted encoding of guidance information and multi-dimensional potential perturbation modeling, effectively improving the expression accuracy and structural consistency of the generated samples, and providing a stable and discriminative input basis for subsequent embedding consistency judgment and path reasoning.
[0113] In this embodiment, S6 specifically includes:
[0114] S61. Construct an embedding consistency discrimination network, wherein the embedding consistency discrimination network includes a true-false discrimination substructure and a path consistency scoring substructure, wherein the true-false discrimination substructure is used to judge the embedding semantic difference between the embedding representation of the potential malicious traffic sample and the embedding representation of the labeled real traffic sample, and the path consistency scoring substructure is used to evaluate the similar path structure between the embedding representation of the potential malicious traffic sample and the embedding representation in the embedded traffic sample sequence;
[0115] S62, embedding the potential malicious traffic sample into the true-false discrimination substructure, and outputting a discrimination probability label based on the embedding feature distribution extracted by the multi-layer discriminant network;
[0116] S63. Input the embedded representation of the potential malicious traffic sample and the embedded traffic sample sequence into the path consistency scoring substructure. Utilize the established sequential structural relationship and embedded spatial position coordinates of the embedded traffic sample sequence to calculate the matching score between the embedded representation of the potential malicious traffic sample and the sample path, and generate a path similarity score.
[0117] This implementation constructs an embedding consistency discrimination network, combining a true / false discrimination substructure with a path consistency scoring substructure. First, the semantic differences between the embedded representations of potential malicious traffic samples and those of labeled real traffic samples are used to identify true / false traffic, outputting a discrimination probability label. Simultaneously, the sequential structure and spatial positional relationships of the embedded traffic sample sequences are used to perform path structure matching analysis on the embedded representations of potential malicious traffic samples, generating a path similarity score and achieving multi-dimensional consistency judgment of potential samples. This approach comprehensively considers traffic semantics and evolutionary path characteristics, improving the accuracy and reliability of malicious traffic identification. It provides a discriminant basis and path reference for subsequent attack chain analysis and traceability path construction, enhancing the system's ability to perceive and respond to complex network attacks.
[0118] In this embodiment, the S7 specifically includes:
[0119] S71. Obtaining, in a unified low-dimensional embedding space, an embedding spatial position relationship between an embedding representation of a potential malicious traffic sample and an embedding representation of multiple labeled malicious traffic samples, wherein the embedding spatial position relationship includes Euclidean distance, embedding trajectory angle, and local density distribution characteristics;
[0120] S72. Combining the path similarity score results with the embedding spatial position relationship, construct an attack chain path graph. The attack chain path graph uses the embedding representation of the potential malicious traffic sample as the starting node and the embedding representation of the labeled malicious traffic sample as the end node. The edge weights between the nodes are determined by the path similarity score and the spatial position metric.
[0121] S73. In the attack chain path graph, execute a weighted shortest path search algorithm to obtain a shortest path sequence between the embedded representation of the potential malicious traffic sample and the embedded representation of each labeled malicious traffic sample, and construct multiple tracing path candidates based on the shortest path sequence;
[0122] S74. Calculate confidence scores for the multiple traceability path candidates, where the confidence scores are determined based on path similarity scores of embedded representations of nodes in the paths.
[0123] S75. Filter paths with confidence scores higher than a preset threshold as candidate valid paths, and output the candidate valid paths to construct a network attack chain tracing result.
[0124] This implementation constructs a structured attack chain path diagram by analyzing the spatial relationship between the embedded representations of potential malicious traffic samples and the embedded representations of multiple labeled malicious traffic samples in a unified low-dimensional embedding space, and combining this with path similarity scores. It then uses a weighted shortest path search algorithm to identify multiple possible attack traceability paths, and calculates confidence scores based on the similarity between nodes, selecting paths with higher confidence as candidate valid paths. This approach not only enables the ability to characterize the evolution of potential attack behaviors from a spatial semantic dimension, but also effectively improves the accuracy and reliability of traceability path identification through path structure analysis, offering the advantages of efficient, automatic, and interpretable network attack chain reconstruction.
[0125] Example 1:
[0126] To verify the feasibility of this invention, we applied it to the production network environment of a power dispatching center. The real-time transmission of control instructions, telemetry information, and user access requests constituted a complex network communication map. However, the dispatching center's intranet frequently encountered unidentified hosts accessing key dispatching instruction ports, suggesting the presence of slow, APT-like attacks. Conventional intrusion detection systems based on signature detection and fixed rules failed to effectively locate the attack path and trace the source information.
[0127] To address these issues, the center introduced a malicious traffic tracing method based on a generative adversarial network (GAN), proposed in this paper, and deployed it in the bypass flow control links of northbound and southbound switching nodes. The system collects raw network traffic data from a seven-day sliding window, performs flow-level reassembly based on quintuples, and constructs an ordered network session sequence. A behavior matching strategy identifies target network traffic samples with control plane characteristics (such as persistent sessions and unique protocol field transitions). It then extracts three types of features: protocol behavior, communication structure, and time evolution. These features are then embedded into a semantic encoding structure for representation.
[0128] The system feeds the three types of embedded representations into a multi-view fusion module, achieving semantic alignment through a channel-level attention structure. These representations are uniformly mapped into a 128-dimensional low-dimensional embedding space, while preserving the geometric relationships between features. Leveraging historically annotated APT attack traffic samples (such as C&C connections and backdoor activations), a segmented embedding manifold set is generated based on attack phase labels and embedding trajectories. Local linear interpolation is then performed to generate intermediate state representations, forming an embedded traffic sample sequence.
[0129] The embedded representation of the target network traffic sample is used to generate an attack context vector. This is then combined with the embedded traffic sample sequence to generate a perturbed path embedding representation through path perturbation modeling. This representation is fused with the attack context to form a guided condition vector, which is then fed into the generator along with the latent variable sampled from a Gaussian distribution to output an embedded representation of the potentially malicious traffic sample.
[0130] The latent embedding representation is input into the embedding consistency judgment network, which evaluates its semantic difference between true and false and its path structure consistency with the embedded traffic sample sequence, outputting a judgment label and path score. Starting from the latent sample, the system constructs an attack chain path graph within the known malicious sample embedding set. It then combines the embedding space distance (Euclidean distance + angle + density) and similarity scores to construct graph edge weights. It then generates candidate paths through a shortest path search and selects valid traceability paths based on path confidence. The following is the experimental deployment environment data and result statistics:
[0131] Table 1 Comparison results of the technical applications of the National Electric Power Dispatching Center Network Traceability System
[0132] ;
[0133] To further illustrate the practical operation of this method, the following is a trace of an attack path generated by the system: The tracing system captured a target network traffic sample that continuously accessed the scheduling instruction port remotely. In the embedding space, the system determined that its embedding representation had a similarity of 0.89 with that of a "backdoor implant sample." The system then automatically derived the complete attack path sequence along the attack chain graph, consisting of "DNS tunnel communication → remote activation → data return." Ultimately, it recommended marking a temporary task scheduling behavior on an internal Windows host as the tracing root node. The tracing process took only 13.7 seconds, a 78% reduction compared to the original process.
[0134] In summary, this embodiment demonstrates the multi-stage path tracing capability of the present invention for complex APT attacks in an environment with high security requirements. It has full-link technical features such as unified feature fusion, embedding generation, path construction, confidence scoring and interpretable graph output. It is significantly superior to existing rule-based and graph mining methods, and is suitable for network security scenarios in key industries such as electricity, energy, and government affairs.
[0135] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.
Claims
1. A network security malicious traffic tracing method based on generative adversarial network, characterized by: The following steps are involved: S1. Collect network traffic data, select the target traffic sample to be traced, extract protocol behavior features, communication structure features, and time evolution features, perform semantic encoding on them, and generate protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation; S2. Input the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation into the multi-perspective fusion process, build semantic correspondence, and uniformly map them into a low-dimensional embedding space; S3 constructs a segmented embedding manifold set based on multiple labeled malicious traffic samples in a low-dimensional embedding space, performs interpolation operations to generate intermediate state embedding representations, and forms an embedded traffic sample sequence; S4. Generate attack context embedding representation based on target traffic samples, perform perturbation path encoding on the embedded traffic sample sequence, generate perturbation path embedding representation, and combine it with attack context embedding representation to form a guided condition vector; S5. Input the guided condition vector and the random latent variable generated based on the preset distribution sampling into the generator, and the generator performs joint encoding to output the embedded representation of the potential malicious traffic sample; S6. Embed the potential malicious traffic sample into the representation input embedding consistency discrimination network, perform true and false identification, and perform path similarity scoring; S7. Based on the path similarity score and the positional relationship between the embedded representations of potential malicious traffic samples in the low-dimensional embedding space, an attack chain path graph is constructed, and the shortest path sequence to the embedded representations of the labeled malicious traffic samples is calculated; The S4 specifically includes: S41. Inputting the protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation of the target network traffic sample into an attack context modeling structure, wherein the attack context modeling structure includes temporal feature extraction and behavior intention modeling, and is used to encode the behavior evolution and structure features of the target network traffic sample to generate an attack context embedding representation; S42. Input the embedded traffic sample sequence into a path perturbation coding structure. The path perturbation coding structure includes path order-aware coding and perturbation injection control. The path order-aware coding encodes the relative temporal order and embedding space offset relationship between the embedded representations of each malicious traffic sample in the embedded traffic sample sequence to obtain an initial path coding representation. S43, perturbation injection control uses the attack context embedding representation as a reference to apply controlled perturbation to the initial path encoding representation. The controlled perturbation includes limiting the perturbation direction and perturbation amplitude in the semantic embedding space and outputting the perturbation path embedding representation. S44. Input the attack context embedding representation and the perturbation path embedding representation into the guided condition fusion structure. The guided condition fusion structure adopts a gated residual fusion method to output a guided condition vector. The guided condition vector contains both the context attack intention and the embedded path perturbation information. The gated residual fusion method includes: inputting the attack context embedding representation into a first fusion channel, inputting the perturbation path embedding representation into a second fusion channel, obtaining a fused embedding representation, and inputting the fused embedding representation into the generator structure of the generative adversarial network as a guide condition vector.
2. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: Said S1 specifically includes: S11, collecting original network traffic data within a preset time window, constructing a five-tuple key value based on the source Internet Protocol address, destination Internet Protocol address, source port number, destination port number, and network protocol type, performing stream-level reorganization on the original network data packets, and generating an ordered network session sequence; S12. Selecting a target network traffic sample to be traced from the ordered network session sequence based on a behavior matching strategy, wherein the behavior matching strategy includes a rule comparison strategy based on a known malicious feature template; S13. Extracting protocol behavior features from the target network traffic sample, wherein the protocol behavior features include a data packet interaction direction sequence, a data packet length sequence, and a protocol field change sequence in a network session; S14. Extracting communication structure features for the target network traffic sample, constructing a communication graph model based on the end-to-end network entity interaction relationship, and extracting connection relationship density, path length distribution, node centrality, and structure nesting hierarchical graph structure parameters; S15. Extracting time evolution features for the target network traffic sample, wherein the time evolution features include time interval distribution between data packets, frequency distribution of emergency event time windows, and active time period sequence; S16, inputting the protocol behavior features, communication structure features, and time evolution features into the protocol behavior semantic coding structure, the communication structure semantic coding structure, and the time evolution semantic coding structure, respectively, and performing embedding expression mapping, wherein the semantic coding structure includes a normalization layer, a structure parsing layer, and an embedding output layer; S17. Output the protocol behavior embedding representation, communication structure embedding representation and time evolution embedding representation respectively.
3. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: The S2 specifically includes: S21, receiving the protocol behavior embedding representation, the communication structure embedding representation, and the time evolution embedding representation, and performing a unified scale normalization process on the three types of embedding representations; S22. Input the normalized protocol behavior embedding representation, communication structure embedding representation, and time evolution embedding representation into a multi-view semantic alignment structure, wherein the multi-view semantic alignment structure includes three cross-attention channels and obtains a saliency mapping relationship between cross-embedding channels by calculating a semantic interaction matrix between feature dimensions. S23. In the multi-view semantic alignment structure, construct a feature guidance channel, use the protocol behavior embedding representation as the leading channel, perform attention weighted fusion on the communication structure embedding representation and the time evolution embedding representation, and generate a fused feature representation. The attention weighted fusion maintains the context structure guidance effect of the main view of the protocol behavior; S24. Input the fused feature representation into a unified low-dimensional embedding space mapping structure, wherein the mapping structure includes a multi-layer nonlinear transformation module with inter-layer residual connections, and sets a semantic distance preservation constraint to maintain the spatial geometric relationship between the original three types of embeddings.
4. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: The S3 specifically includes: S31. Obtaining multiple labeled malicious traffic sample embedding representations in a unified low-dimensional embedding space, performing a joint clustering operation based on the attack behavior label, spatial distribution position, and behavior temporal encoding result corresponding to each labeled malicious traffic sample embedding representation, and constructing a malicious behavior embedding sample cluster set; S32. For each malicious behavior embedded sample cluster set, based on the semantic similarity distribution changes between the adjacent labeled malicious traffic sample embedded representations in the cluster set and the stage span information of the attack stage label, identify segmentation boundary points and divide each malicious behavior embedded sample cluster set into a number of local embedding manifold subsegments; S33. All local embedded manifold sub-segments are combined into a segmented embedded manifold set according to the attack behavior time sequence and the attack chain structure relationship. The segmented embedded manifold set represents an embedded path structure set composed of multiple local embedded manifold sub-segments with structural continuity relationship. S34. Select an interpolation control path based on the attack context embedding representation generated from the target traffic sample, perform an interpolation operation along the interpolation control path in the segmented embedding manifold set, perform an equidistant interpolation operation within the local embedding manifold subsegments, and perform a disturbance control interpolation operation between different local embedding manifold subsegments to generate an intermediate state embedding representation; S35. Combining the multiple intermediate state embedding representations and the corresponding labeled malicious traffic sample embedding representations into an embedded traffic sample sequence.
5. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: The gated residual fusion method also includes a first fusion channel including a residual mapping unit for performing identity mapping on the attack context embedding representation and maintaining its feature expression integrity, The second fusion channel includes a gated activation unit, which is used to perform a gated weight generation operation on the perturbation path embedding representation. The gating weight is determined based on the attention coefficient matrix between the attack context embedding representation and the perturbation path embedding representation. The weighted perturbation path embedding representation output by the gated activation unit is fused element-by-element with the attack context embedding representation output by the residual mapping unit.
6. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: The S5 specifically includes: S51. Perform random sampling on the latent variable space based on a preset standard normal distribution to generate a random latent variable vector, where the preset standard normal distribution is a Gaussian distribution with a mean of zero and a variance of one; S52. Input the guided condition vector and the random latent variable vector into a feature-guided connection structure, wherein the feature-guided connection structure includes a channel selection structure and a weight control structure. The channel selection structure performs a dimension screening operation based on the difference between the attack context semantic features and the embedded path perturbation features in the guided condition vector to determine the channel to be fused. The weight control structure generates a fusion gating parameter based on the correlation distribution of the elements of each dimension in the channel to be fused, and generates a joint input vector in a weighted fusion manner. S53, inputting the joint input vector into a generator structure, wherein the generator structure is composed of multiple layers of nested linear transformation layers, nonlinear activation layers, and batch normalization layers, and extracting fusion features in sequence; S54. Set a cross residual connection path in the generator structure to connect the initial features of the guided condition vector and the random latent variable vector to the intermediate hidden layer nodes, and introduce an attention mechanism in the specified fusion layer to complete feature coupling enhancement; S55. Output the embedded representation of the potential malicious traffic sample.
7. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: The S6 specifically includes: S61. Construct an embedding consistency discrimination network, wherein the embedding consistency discrimination network includes a true-false discrimination substructure and a path consistency scoring substructure, wherein the true-false discrimination substructure is used to judge the embedding semantic difference between the embedding representation of the potential malicious traffic sample and the embedding representation of the labeled real traffic sample, and the path consistency scoring substructure is used to evaluate the similar path structure between the embedding representation of the potential malicious traffic sample and the embedding representation in the embedded traffic sample sequence; S62, embedding the potential malicious traffic sample into the true-false discrimination substructure, and outputting a discrimination probability label based on the embedding feature distribution extracted by the multi-layer discriminant network; S63. Input the embedded representation of the potential malicious traffic sample and the embedded traffic sample sequence into the path consistency scoring substructure. Utilize the established sequential structural relationship and embedded spatial position coordinates of the embedded traffic sample sequence to calculate the matching score between the embedded representation of the potential malicious traffic sample and the sample path, and generate a path similarity score.
8. The network security malicious traffic tracing method based on generative adversarial network according to claim 1 is characterized in that: The S7 specifically includes: S71. Obtaining, in a unified low-dimensional embedding space, an embedding spatial position relationship between an embedding representation of a potential malicious traffic sample and an embedding representation of multiple labeled malicious traffic samples, wherein the embedding spatial position relationship includes Euclidean distance, embedding trajectory angle, and local density distribution characteristics; S72. Combining the path similarity score results with the embedding spatial position relationship, construct an attack chain path graph. The attack chain path graph uses the embedding representation of the potential malicious traffic sample as the starting node and the embedding representation of the labeled malicious traffic sample as the end node. The edge weights between the nodes are determined by the path similarity score and the spatial position metric. S73. In the attack chain path graph, execute a weighted shortest path search algorithm to obtain a shortest path sequence between the embedded representation of the potential malicious traffic sample and the embedded representation of each labeled malicious traffic sample, and construct multiple tracing path candidates based on the shortest path sequence; S74. Calculate confidence scores for the multiple traceability path candidates, where the confidence scores are determined based on path similarity scores of embedded representations of nodes in the paths. S75. Filter paths with confidence scores higher than a preset threshold as candidate valid paths, and output the candidate valid paths to construct a network attack chain tracing result.
Citation Information
Patent Citations
Artificial intelligence enhanced distributed denial of service attack defense method and system
CN119865343A
Network security malicious traffic detection and tracing method based on generative adversarial network
CN120110746A