A detection method integrating deep feature extraction and attack identification
By analyzing signal responses and adjusting the detection logic structure in deep feature space, the problem of difficulty in establishing logical connections between features in traditional methods is solved, and accurate identification and efficient response to attack behaviors are achieved.
Patent Information
- Application Number
- CN202510962714.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-14
AI Technical Summary
Traditional detection methods that integrate deep feature extraction and attack identification have difficulty establishing logical connections between features when dealing with attack behaviors with nonlinear or high-dimensional sparse features, resulting in misjudgments and omissions. They also lack a dynamic adjustment mechanism, affecting the recognition and response efficiency in high-risk scenarios.
By obtaining the signal response of network behavior in the deep feature space, analyzing the fluctuation range between adjacent features, generating a list of abnormal signals, and recursively adjusting the detection logic structure, and combining the time distribution relationship to perform priority sorting and priority adjustment, a collaborative control priority sequence is generated, and finally a multi-dimensional collaborative attack detection mechanism is reconstructed.
It effectively identifies abnormal signals and dynamically resolves incorrect associations, improving response efficiency and handling accuracy in complex input scenarios and ensuring timely handling of hidden attacks.
Smart Images

Figure CN120455178B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence security detection technology, and in particular to a detection method integrating deep feature extraction and attack identification. Background Art
[0002] The field of AI security detection technology primarily involves methods and means for identifying and protecting against potential security threats in AI systems. Core issues within this field include identifying and preventing security risks such as adversarial attacks, data tampering, and model theft faced by AI models. It also encompasses analysis of anomalies in the input and output behavior of deep learning models, credibility assessment based on training data sources, and the use of feature analysis techniques to identify illegal operations. This field systematically integrates interdisciplinary knowledge such as machine learning, computer vision, and network security to ensure the stability and security of AI systems during deployment and operation. Traditional detection methods that integrate deep feature extraction with attack identification use intermediate layer features in neural networks to obtain multi-level semantic information during the identification of attack behaviors targeting AI models, and then analyze these features using recognition techniques to determine whether an attack is present. These methods include extracting static image features based on the output of intermediate layers of convolutional networks, analyzing perturbations in sequence inputs using time series models, segmenting feature distribution differences using clustering algorithms, and using statistical analysis to determine the offset between the current input and the training sample distribution.
[0003] Traditional detection methods rely on feature extraction from the intermediate layers of neural networks and combine them with clustering or statistical methods to identify attacks. They over-rely on static model structures when processing input disturbance patterns and judging distribution offsets. When attack behaviors exhibit nonlinear or high-dimensional sparse features in the input sequence, existing methods find it difficult to establish logical connections between features in a timely manner, resulting in unclear associations between abnormal signals, and further misjudgments and omissions in multi-step evaluations. In scenarios with concurrent inputs and complex behavioral dependencies, existing detection logic lacks a dynamic adjustment mechanism for detection status and priority, which can easily cause delays in the detection process and imbalances in priorities, thereby affecting the method's recognition and response efficiency under high-risk behaviors. Summary of the Invention
[0004] The purpose of the present invention is to solve the shortcomings of the prior art and propose a detection method that integrates deep feature extraction and attack identification.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: a detection method integrating deep feature extraction and attack identification, comprising the following steps:
[0006] S1: Obtain the signal response of network behavior in the deep feature space, analyze the fluctuation range between adjacent features, determine whether there is a security assessment deviation caused by abnormal signals, mark them as abnormal signals, and generate an abnormal signal list;
[0007] S2: Based on the abnormal signal list, recursively adjust the detection logic sequence of the abnormal signal and the associated signals, remove the abnormal association of the marked signal, update the detection logic structure, and generate a benchmark detection snapshot;
[0008] S3: Based on the benchmark detection snapshot, count the number of network behavior pre-dependencies that have not completed security assessment, trace the starting behavior, prioritize the behaviors based on their time distribution, and generate a management priority list;
[0009] S4: According to the management priority list, extract the network behavior detection time that has not yet completed the security assessment, determine whether there is any behavior that exceeds the detection time range, and adjust the detection priority of the corresponding behavior to generate a collaborative control priority sequence.
[0010] As a further solution of the present invention, the abnormal signal list includes a feature fluctuation exceeding standard mark, a safety assessment conflict mark, and a real-time signal deviation behavior; the benchmark detection snapshot includes an updated detection logic diagram, a set of eliminated abnormal signals, and behavior correction status information; the management priority list includes a behavior sequence table generated according to the time distribution relationship, a behavior pre-dependence quantity indicator, and a priority sorting index; the collaborative control priority sequence includes the detection time tight behavior identification result, the priority adjustment plan, and the detection time matching status.
[0011] As a further solution of the present invention, the specific steps of obtaining the abnormal signal list are:
[0012] S111: Obtain the signal response of the network behavior in the deep feature space, detect the signal change rate of adjacent features, and compare it with the real-time signal of the corresponding behavior to identify the feature fluctuation range between the two and generate feature fluctuation distribution data;
[0013] S112: Based on the characteristic fluctuation distribution data and the rated signal interval, determine whether the characteristic fluctuation range of the behavior exceeds the interval, select the signal interaction path that meets the conditions, and record the interaction direction, signal-related behavior, and fluctuation amplitude to obtain an abnormal signal marking result;
[0014] S113: Based on the abnormal signal marking result, filter the signal interaction paths whose fluctuation amplitude exceeds the rated range, extract the corresponding behavior combinations and interaction types, and establish an abnormal signal list.
[0015] As a further solution of the present invention, the specific steps of obtaining the benchmark detection snapshot are:
[0016] S211: Read the abnormal path in the abnormal signal list, retrieve the endpoint behavior corresponding to the abnormal path, locate the downstream signal interaction relationship of the behavior, record the signal interaction number indirectly associated with the abnormal path, and generate an abnormal diffusion path number set;
[0017] S212: Based on the abnormal diffusion path number set, statistically analyze the behavior number information, match the signal interaction relationship between behaviors, calculate the behavior connection adjustment strength value, and perform adjustment if the behavior connection adjustment strength value is higher than the judgment threshold to obtain a signal interaction update matrix;
[0018] S213: According to the signal interaction update matrix, the behavior number and the connected out-edge information are extracted, the state of the current time node is frozen after the structure is updated, the adjusted global signal connection information is retained, and the version number and time label are marked to establish a benchmark detection snapshot.
[0019] As a further solution of the present invention, the specific steps for obtaining the management priority list are:
[0020] S311: Based on the benchmark detection snapshot, extract the task completion flag of the behavior, read the input edge signal interaction path list of the behavior that has not completed the safety assessment, and count the number of previous behaviors to obtain a predecessor relationship number table;
[0021] S312: According to the preceding relationship quantity table, identify the behavior with zero preceding behavior quantity as the topological starting point, sequentially scan the connection edge information in the signal distribution graph, perform a topological sorting process, and generate a topological hierarchical order result;
[0022] S313: According to the topological hierarchy order result, extract the corresponding time coding information for each behavior, split the time coding field, calculate the topological hierarchy depth value of the behavior, identify the management priority, arrange the behavior numbers according to the numerical value, and establish a management priority list.
[0023] As a further solution of the present invention, the specific steps for obtaining the collaborative control priority sequence are:
[0024] S411: Extract the detection time of each behavior from the security assessment behavior in the management priority list, identify the remaining available time from the current time node to the task deadline, record the time difference, and record the mapping between the behavior number and the timeout status to generate a behavior timeout identification matrix;
[0025] S412: Based on the behavior numbers marked as having time conflicts in the behavior timeout identification matrix, the original priority values are updated, the original order of the behaviors that have not timed out is retained, and the updated priority information is paired with the behavior numbers to generate a priority adjustment value table;
[0026] S413: Reorder the behaviors that have not undergone safety assessment according to the priority adjustment value table, use the adjusted priorities as the main sequence basis, and establish a collaborative control priority sequence in combination with the original signal interaction relationship structure and time conflict situation.
[0027] As a further embodiment of the present invention, the method further comprises step S5:
[0028] S5: Based on the collaborative control priority sequence, uniformly update the detection status and priority information of the network behavior, rebuild the detection view model, identify standardized detection instructions, and obtain a multi-dimensional collaborative attack detection mechanism;
[0029] The multi-dimensional collaborative attack detection mechanism includes a behavior state distribution diagram, a task priority mapping structure, and an information display framework that meets the detection standards.
[0030] As a further solution of the present invention, the specific steps of obtaining the multi-dimensional collaborative attack detection mechanism are:
[0031] S511: Based on the collaborative control priority sequence, sequentially read the entity state of each behavior in the current detection, extract the signal interaction structure and priority information of adjacent behaviors, update the priority number and path frequency field of the interaction behavior, and generate priority interaction synchronization data;
[0032] S512: Based on the priority interaction synchronization data, identify a time series structure indexed by behavior priority, divide the behavior into corresponding detection periods, determine the distribution range and central tendency within the same period, and obtain a detection layout coordinate matrix based on the priority order;
[0033] S513: According to the behavior layout information recorded in the detection layout coordinate matrix, a behavior graphic border style, a connection path line type, and a field display method are selected to perform standardized detection for each behavior to obtain a multi-dimensional collaborative attack detection mechanism.
[0034] Compared with the prior art, the advantages and positive effects of the present invention are:
[0035] In the present invention, by analyzing the fluctuation range of signal responses in the deep feature space, it is possible to effectively identify detection deviations caused by abnormal signals, and then clearly mark and classify potential anomalies. Relying on the recursive adjustment of the logical sequence of abnormal signals and their associated signals, the false association relationship can be dynamically resolved and the detection structure can be rebuilt, thereby reducing the impact of false judgment interference on the detection logic. Priority sorting is performed based on the time distribution law of network behavior, and the processing progress of key behaviors can be promptly promoted when the detection is not completed. By continuously tracking the behavior detection time, active intervention and priority adjustment of timed-out behaviors can be achieved, and ultimately the overall detection process has dynamic coordination capabilities and multi-dimensional linkage recognition capabilities, effectively improving the response efficiency and handling accuracy of hidden attacks in complex input scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a schematic diagram of the main steps of the present invention;
[0037] Figure 2 This is a flowchart for obtaining an abnormal signal list in the present invention;
[0038] Figure 3 This is a flowchart for obtaining a benchmark detection snapshot in the present invention;
[0039] Figure 4 A flowchart for obtaining a management priority list in the present invention;
[0040] Figure 5 This is a flow chart for obtaining the collaborative control priority sequence in the present invention;
[0041] Figure 6 This is a flowchart for obtaining the multi-dimensional collaborative attack detection mechanism in the present invention. DETAILED DESCRIPTION
[0042] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0043] In the description of the present invention, it should be understood that the terms "length," "width," "up," "down," "front," "back," "left," "right," "vertical," "horizontal," "top," "bottom," "inside," "outside," and the like, indicating positions or relationships, are based on the positions or relationships shown in the accompanying drawings and are intended only to facilitate the description of the present invention and simplify the description. They do not indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limiting the present invention. Furthermore, in the description of the present invention, "plurality" means two or more, unless otherwise expressly and specifically defined.
[0044] Example 1
[0045] See also Figure 1 The present invention provides a technical solution: a detection method integrating deep feature extraction and attack identification, comprising the following steps:
[0046] S1: Obtain the signal response of network behavior in the deep feature space, analyze the fluctuation range between adjacent features, determine whether there is a security assessment deviation caused by abnormal signals, mark them as abnormal signals, and generate an abnormal signal list;
[0047] S2: Based on the abnormal signal list, recursively adjust the detection logic sequence of abnormal signals and associated signals, remove the abnormal association of marked signals, update the detection logic structure, and generate a benchmark detection snapshot;
[0048] S3: Based on the baseline detection snapshot, count the number of network behavior pre-dependencies that have not completed security assessments, trace the starting behavior, prioritize the behaviors based on their time distribution, and generate a management priority list;
[0049] S4: Based on the management priority list, extract the detection time of network behaviors that have not yet completed security assessment, determine whether there are behaviors that exceed the detection time range, adjust the detection priority of the corresponding behaviors, and generate a collaborative control priority sequence;
[0050] S5: Based on the collaborative control priority sequence, the detection status and priority information of network behaviors are uniformly updated, the detection view model is rebuilt, and standardized detection instructions are identified to obtain a multi-dimensional collaborative attack detection mechanism.
[0051] The abnormal signal list includes characteristic fluctuation exceeding standard marks, safety assessment conflict marks, and real-time signal deviation behaviors. The benchmark detection snapshot includes the updated detection logic diagram, the set of eliminated abnormal signals, and the status information after behavior correction. The management priority list includes the behavior sequence table generated according to the time distribution relationship, the behavior pre-dependency quantity indicator, and the priority sorting index. The collaborative control priority sequence includes the detection time-sensitive behavior identification results, priority adjustment plan, and detection time matching status. The multi-dimensional collaborative attack detection mechanism includes the behavior status distribution diagram, the task priority mapping structure, and the information display framework that meets the detection standards.
[0052] See also Figure 2 ,The specific steps to obtain the abnormal signal list are:
[0053] S111: Obtain the signal response of the network behavior in the deep feature space, detect the signal change rate of adjacent features, and compare it with the real-time signal of the corresponding behavior to identify the feature fluctuation range between the two and generate feature fluctuation distribution data;
[0054] By obtaining the network behavior signal response of IoT devices in the deep feature space, for example, for the network behavior of smart door lock devices in smart homes, specifically obtaining its signal response data in the deep feature space after being processed by the multi-layer perceptron (MLP), the response data quantifies the device operation status and communication mode, and detects the signal change rate at adjacent time points (for example, every 100 milliseconds). Specifically, the difference between the current signal value and the previous signal value is calculated, and then divided by the time interval to obtain the change rate. For example, if the signal response of the smart door lock at 10:00:00.000 is 500 units, and the signal response at 10:00:00.100 is 505 units, then the signal change rate is (505-500). ) / 0.1=50 units per second, and compare this change rate with the real-time signal of the smart door lock. The real-time signal is the original signal continuously collected by the sensor, such as the current signal or data transmission rate generated by each switch operation of the smart door lock. By comparing the signal change rate and the real-time signal, the characteristic fluctuation range between the two is identified. Specifically, it is judged by setting an allowable deviation range. For example, if the normal fluctuation range of the real-time signal is 10 units, and the calculated change rate exceeds this range, it is considered that there is a characteristic fluctuation, and the characteristic fluctuation distribution data is generated. The data is stored in matrix form, and each row represents the characteristic fluctuation at a time point, including the signal response value, change rate, real-time signal value and fluctuation range.
[0055] S112: Based on the characteristic fluctuation distribution data and the rated signal interval, determine whether the characteristic fluctuation range of the behavior exceeds the interval, select the signal interaction path that meets the conditions, and record the interaction direction, signal-related behavior, and fluctuation amplitude to obtain the abnormal signal marking result;
[0056] Based on the above characteristic fluctuation distribution data, which includes the signal response, change rate, real-time signal value and fluctuation range of the smart door lock device at different time points, the preset rated signal interval is used to judge whether the characteristic fluctuation range of the behavior exceeds the interval. The rated signal interval is obtained based on the statistical analysis of a large amount of normal operation data. Through the statistical analysis of historical normal operation data, for example, the signal fluctuation data of the smart door lock in normal opening, closing and standby states are collected, and its probability distribution model is constructed. The 99.7% confidence interval is set as the rated signal interval, and its interval range is set to [20, 80] signal units. The specific judgment process is to traverse each record in the characteristic fluctuation distribution data and check whether its fluctuation range is within [20 ,80] interval, if the fluctuation range exceeds this interval, for example, the fluctuation range is 90 signal units, then the signal interaction path is filtered, and its interaction direction (for example, from the door lock to the server or from the server to the door lock), signal associated behavior (for example, "illegal attempt to unlock" or "remote tampering of parameters") and fluctuation amplitude (the specific value exceeding the rated interval, for example, 90-80=10 units) are recorded. For example, if it is detected that the fluctuation amplitude of the signal from the smart door lock to the server reaches 15 units at 10:01:05, which exceeds the preset interval, it is marked as abnormal, and the abnormal signal marking result is obtained. The result is presented in a list form, and each record includes the path, direction, associated behavior and specific fluctuation amplitude of the abnormal signal.
[0057] S113: Based on the abnormal signal marking results, filter the signal interaction paths whose fluctuation amplitudes exceed the rated range, extract the corresponding behavior combinations and interaction types, and create an abnormal signal list;
[0058] Based on the abnormal signal marking results, the results list in detail the signal interaction paths, interaction directions, signal-related behaviors, and fluctuation amplitudes marked as abnormal. Signal interaction paths whose fluctuation amplitudes exceed a rated range are screened. The rated range is set to [20, 80] signal units in S112. For example, in the abnormal signal marking results, if the fluctuation amplitude of a path is 15 units, and the value by which it exceeds the rated range is 15 (i.e., 95-80), it is screened out, and the corresponding behavior combination and interaction type are extracted. The behavior combination refers to two or more network behaviors involved in the abnormal signal interaction, such as "illegal user login" and "database access." The interaction type refers to the protocol or mode of signal transmission, such as "TCP connection" or "UDP data packet." For example, if an abnormal signal with a fluctuation amplitude of 15 units is screened out, its path is "user terminal" to "authentication server", its associated behavior is "login request failure", and its interaction type is "HTTPS POST", the information is organized to create an abnormal signal list. The list is presented in a table format and contains all identified abnormal signal paths, associated behavior combinations, interaction types, and corresponding fluctuation amplitudes.
[0059] See also Figure 3 ,The specific steps to obtain the benchmark detection snapshot are:
[0060] S211: Read the abnormal path in the abnormal signal list, retrieve the behavior corresponding to the abnormal path endpoint, locate the downstream signal interaction relationship of the behavior, record the signal interaction number indirectly associated with the abnormal path, and generate an abnormal diffusion path number set;
[0061] Using the abnormal signal list, which contains the paths, behavior combinations, and interaction types of all abnormal signals, the endpoint behavior corresponding to the abnormal path is retrieved. For example, if the abnormal path is "user terminal -> authentication server," the endpoint behavior is "authentication server." The downstream signal interaction relationship of this endpoint behavior is located. This is identified by analyzing the communication logs and network topology between the authentication server and network components (such as database servers and application servers). For example, after a successful authentication, the authentication server will send an authorization token to the application server, or after an authentication failure, it will log a failure message to the log server. The signal interaction number indirectly associated with the abnormal path is recorded. The number represents the subsequent signal interaction affected by the spread of the abnormal behavior. For example, if the "authentication server" generates an error log due to an abnormal login attempt, the signal interaction related to the error log (such as the log transmission to the SIEM system) will be recorded with a number. For example, the error log transmission number is "LOG-20250625-001." This generates an abnormal diffusion path number set, which contains the unique identifiers of all signal interactions indirectly associated with the endpoint behavior of the abnormal path.
[0062] S212: Based on the abnormal diffusion path number set, the behavior number information is counted and the signal interaction relationship between the behaviors is matched using the formula:
[0063] ;
[0064] Calculate the behavior connection adjustment strength value. If the behavior connection adjustment strength value is higher than the judgment threshold, perform the adjustment to obtain the signal interaction update matrix.
[0065] in, Represents the behavior connection adjustment strength value, Representative The signal strength of the behavior, represents the signal strength of the target behavior, Representative Behavioral signaling bias, Representative Behavior and The strength of signal interactions between behaviors, Representative Behavioral interaction factors, Representative The processing parameters of the behavior, and Both represent The control threshold parameter of the behavior, The total number of representative behaviors, The number of behaviors representing signal interactions;
[0066] Based on the abnormal diffusion path number set, the behavior number information is counted. For example, if the abnormal diffusion path number set includes "LOG-20250625-001", "DB-20250625-002", etc., then the relevant behavior numbers are obtained by statistics, such as "log recording service" and "database query service". The signal interaction relationship between the behaviors is matched, and by querying the network traffic records and configuration information, it is determined whether there is direct or indirect signal transmission between the behaviors. For example, there is log transmission of UDP port 514 between "log recording service" and "SIEM system", and the formula is used. Calculate behavioral connection adjustment strength values;
[0067] in, Represents the behavioral connection adjustment strength value, which is used to quantify the urgency and degree of network connection adjustment required due to the spread of abnormal behavior. The larger the value, the higher the urgency of the adjustment.
[0068] Representative The signal strength of the behavior, for example, the alarm signal strength sent by a smart camera when it detects abnormal activity, is measured by packet rate or connection activity, and the value range is set to [100, 1000] Mbps;
[0069] The signal strength representing the target behavior, for example, the strength of the alarm signal received by the security management platform, is usually The unit is consistent with that of , and the value range is set to [100, 1000] Mbps;
[0070] Representative The signal deviation of the behavior indicates the degree of deviation between the current signal strength and the historical normal signal strength, expressed as a percentage, and the value range is set to [0, 100];
[0071] Representative Behavior and The signal interaction strength between behaviors, for example, the amount of data transmitted per second between two servers, in Mbps, with the value range set to [1, 1000] Mbps;
[0072] Representative The interaction factor of a behavior is used to measure the importance or sensitivity of the behavior in the entire network. The value range is set to [0.1, 1.0]. The larger the value, the more important the behavior.
[0073] Representative The processing parameter of the behavior indicates the computing resources or time cost required for the behavior to process a signal. The unit is milliseconds / signal, and the value range is set to [1, 100] ms / signal;
[0074] and Both represent The control threshold parameter of the behavior is used to set the upper and lower limits of the behavior, for example, the maximum allowed delay and minimum throughput of a behavior, and the value range is set to [0, 100];
[0075] Represents the total number of behaviors, which here refers to the total number of behaviors involved in the abnormal diffusion path number set;
[0076] Represents the number of behaviors that interact with the signal, here refers to the number of behaviors that interact with the signal. The number of behaviors with which the behavior has direct signal interaction;
[0077] The benefit of the formula is that by introducing the comprehensive consideration of signal strength deviation, signal interaction strength, behavior interaction factor, behavior processing parameter and control threshold parameter, it can more accurately quantify the priority and urgency of behavior connection adjustment, especially through The term can amplify the effect of smaller signal deviations on the adjusted intensity value, while The term reflects the combined effect of the intensity and importance of multiple interactive behaviors. It effectively balances the impact of behavior processing costs and control limitations on adjustment intensity, thereby achieving a more timely and accurate response and control of the spread of abnormal network behavior in the overall approach.
[0078] Assume that there are two behaviors A and B. The signal strength of behavior A is Mbps, its signal deviation %, signal strength of behavior B (target behavior) Mbps, signal interaction strength between behavior A and behavior B Mbps, interaction factor for behavior B , processing parameters of behavior A ms / signal, control threshold parameter for behavior B , ,here (Because we only care about the connection adjustment from behavior A to behavior B), (Because behavior A only interacts with behavior B).
[0079] Substitute the parameters into the formula for calculation:
[0080] ;
[0081] This behavior connects the adjustment strength value It indicates that the connection needs to be adjusted. If the behavioral connection adjustment strength value is higher than the judgment threshold, the adjustment is performed. The judgment threshold is set to 60. Its setting is based on the analysis of historical network failures and security events. By collecting a large amount of data, such as abnormal events that caused network interruptions or security vulnerabilities in the past year, analyzing the distribution of their behavioral connection adjustment strength values, and using the 95th percentile as the threshold, it ensures that the connection causing the problem can be identified and adjusted in a timely manner. , indicating that the connection adjustment intensity is high and needs to be adjusted. For example, adjusting the network bandwidth allocation between behavior A and behavior B, or redirecting part of the traffic to the backup path, obtains the signal interaction update matrix, which records all signal interactions that need to be adjusted and the adjusted parameter values.
[0082] S213: Update the matrix based on signal interaction, extract the behavior number and connected out-edge information, freeze the state of the current time node after updating the structure, retain the adjusted global signal connection information, mark the version number and time label, and establish a benchmark detection snapshot;
[0083] According to the above signal interaction update matrix, the matrix contains the signal interaction that needs to be adjusted and the adjusted parameter values, extract the behavior number and the outgoing edge information of the connection. For example, if the matrix records the connection adjustment of the behavior "file server" to "storage device", extract the behavior number of "file server" (such as "FS-001") and its outgoing edge information (such as "connect to storage device, port 2049"), and freeze the state of the current time node after updating the structure. The specific update method includes adjusting the routing table, firewall rules or load balancing configuration of the network device. For example, adjust the connection bandwidth between "file server" and "storage device" from 100Mbps to 2 00Mbps and immediately apply this configuration change. Then, at the current time point (for example, 15:50:00 on June 25), a snapshot of the entire network topology and all signal connection states is recorded, and the adjusted global signal connection information is retained. For example, the current network interface status, IP address, port mapping, and detailed information of all active connections of each device are recorded, and the version number and time label are marked. For example, the version number is "V1.2.3" and the time label is "20250625155000". A baseline detection snapshot is established. This snapshot is a read-only copy of the complete network status and configuration information for subsequent anomaly detection and comparison.
[0084] See also Figure 4 ,The specific steps for obtaining the management priority list are:
[0085] S311: Based on the benchmark detection snapshot, extract the task completion flag of the behavior. For the behavior that has not completed the safety assessment, read its input edge signal interaction path list and count the number of previous behaviors to obtain the predecessor relationship number table;
[0086] Based on the benchmark detection snapshot, which contains the adjusted global signal connection information, version number and time label, the task completion flag of the behavior is extracted. For example, for the "user authentication" behavior, its task completion flag is "authentication successful" or "authentication failed", which is obtained by querying the behavior status recorded in the benchmark detection snapshot. For behaviors that have not completed security assessment, the input edge signal interaction path list is read. The input edge is the path for the signal to enter the behavior. For example, for the "data processing module", its input edge comes from the "data acquisition module" or "external data source", which is determined by analyzing the network connection information in the snapshot. The number of previous behaviors is also counted, that is, how many behaviors' output signals are directly connected to the input end of the currently unevaluated behavior. For example, if the "data processing module" receives data from three different "data acquisition modules", the number of previous behaviors is 3. A predecessor relationship quantity table is obtained, which records each behavior that has not completed security assessment and its corresponding predecessor behavior number.
[0087] S312: According to the table of the number of predecessor relations, the behavior with the number of previous behaviors being zero is identified as the topological starting point, the connection edge information in the signal distribution graph is sequentially scanned, a topological sorting process is performed, and a topological hierarchical order result is generated;
[0088] According to the predecessor number table, which lists in detail each behavior that has not completed the security assessment and the number of its predecessor behaviors, behaviors with a predecessor number of zero are identified as topological starting points. Behaviors do not depend on the input of other behaviors and are the starting point of the signal processing chain. For example, if the number of predecessor behaviors of "Data Acquisition Module A" is 0, it is identified as the topological starting point. The connection edge information in the signal distribution graph is scanned in sequence. The signal distribution graph is a graphical representation of all behaviors and their signal interaction relationships in the network. The connection edge represents the path of the signal flow from one behavior to another. For example, the connection from "Data Acquisition Module A" to "Data Processing Module B" is scanned. A topological sorting process is performed, specifically using the Kahn algorithm or the DFS algorithm. By iteratively removing nodes with an in-degree of zero and updating the in-degree of their neighbor nodes until all nodes are sorted, a topological hierarchical order result is generated. The result is presented in the form of an ordered list. Each behavior is assigned to its topological level in the entire signal processing chain. For example, level 1: Data Acquisition Module A, Data Acquisition Module C; level 2: Data Processing Module B; level 3: Data Storage Module D.
[0089] S313: According to the topological hierarchy order results, extract the corresponding time coding information for each behavior, split the time coding field, and use the formula:
[0090] ;
[0091] Calculate the topological depth value of the behavior, identify the management priority, sort the behavior numbers according to the value, and establish a management priority list;
[0092] in, Represents the topological depth value of the behavior, Representative The time code value of each behavior, represents the mean of the time code, Representative The topological level number of each behavior, represents the standard deviation of the topological level numbers, The basic parameters representing management priorities, represents the influence coefficient, represents the correction factor, Total number of representative behaviors;
[0093] According to the topological hierarchy order result, each behavior is assigned to its topological hierarchy in the signal processing link, and the corresponding time coding information is extracted for each behavior. The time coding information is an identifier of the behavior executed or completed at a specific time point. For example, for a data processing behavior, its time coding includes the data reception time, processing start time, and processing completion time. The time coding field is split. For example, if the time code is "20250625103015_001", it is split into date "20250625", time "103015" and sequence number "001". The formula is used. , calculate the topological level depth value of the behavior;
[0094] in, Represents the topological depth value of the behavior, which measures the criticality and management priority of the behavior in the entire network topology. A larger value indicates a higher management priority.
[0095] Representative The time code value of each action, for example, expressed in Unix timestamp format of the action completion timestamp, in seconds, with a value range of [1672531200, 1704067200] (corresponding to the approximate range of 2023 and 2024);
[0096] The mean of the time code is the average of all behavior time codes, and the unit and range are the same as same;
[0097] Representative The topological level number of the behavior. For example, if the behavior is at the third level of the topology, then , the value range is set to [1, 10];
[0098] Represents the standard deviation of the topological level number, which is used to measure the discreteness of the topological level. The value range is set to [0, 3].
[0099] The basic parameter representing the management priority is used to set the benchmark for the management priority. The value range is set to [0.1, 1.0]. For example, it is set to 0.5.
[0100] Represents the influence coefficient, which is used to adjust the influence of time encoding and topological level on depth value. The value range is set to [0.01, 0.1]. For example, it is set to 0.05.
[0101] Represents the correction factor, which is used to fine-tune the final depth value. The value range is set to [1.0, 2.0]. For example, it is set to 1.2;
[0102] Represents the total number of behaviors, which here refers to the total number of all behaviors to be evaluated;
[0103] The benefit of the formula is that it quantifies the topological depth of the behavior more finely by comprehensively considering the temporal coding deviation and topological level distribution of the behavior. The term can reflect the discrete degree of the time for completing the behavior, while the The term reflects the stability of the hierarchical distribution of behaviors in the topological structure. By combining it with the basic parameters, influence coefficients, and correction factors, this formula can effectively identify behaviors that have large temporal deviations and significant characteristics in the topological hierarchical distribution, thereby achieving more accurate management priority sorting in the overall approach.
[0104] Example: Suppose there are three behaviors, whose time coding values and topological level numbers are shown in Table 1;
[0105] Table 1: Behavior time coding and topological level numbering table
[0106]
[0107] As shown in Table 1, there are rows A1, A2, and A3 and their time coding values and topological level numbers. First, the mean of the time coding is calculated. and the standard deviation of the topological level numbers ,
[0108] Second;
[0109] For topological level numbers, the mean is ;
[0110] Standard deviation
[0111] ;
[0112] Setting basic parameters for management priorities ; Influence coefficient , correction factor ;
[0113] Substitute the parameters into the formula to calculate the topological depth value of the behavior :
[0114] ;
[0115] Identify management priorities and arrange behavior numbers according to numerical values. The larger the topological depth value, the higher the management priority of the behavior. For example, if the depth value of a behavior is 26.08, its management priority is higher than that of a behavior with a depth value of 15.00. Establish a management priority list, which is arranged in descending order of topological depth value, indicating the order of security assessment or intervention for each behavior.
[0116] See also Figure 5 ,The specific steps for obtaining the collaborative control priority sequence are:
[0117] S411: Extract the detection time of each behavior from the security assessment behavior in the management priority list, identify the remaining available time from the current time node to the task deadline, record the time difference, and record the mapping between the behavior number and the timeout status to generate a behavior timeout identification matrix;
[0118] According to the management priority list, the list arranges the behaviors to be security evaluated in descending order according to the topological hierarchy depth value, and extracts the detection time of each behavior. The detection time refers to the specific moment when the behavior is detected by the system. For example, for the "unlock attempt" behavior of the smart door lock, its detection time is 10:00:00 on June 25. Identify the remaining available time from the current time node to the task deadline. The task deadline is pre-set. For example, the security evaluation of the "unlock attempt" behavior of the smart door lock must be completed within 30 seconds after the detection. The remaining available time is obtained by calculating the difference between the current time and the deadline, for example If the current time is 10:00:10 on June 25 and the deadline is 10:00:30 on June 25, the remaining available time is 20 seconds. Record the time difference and the mapping between the behavior number and the timeout status. The timeout status includes "timed out" or "not timed out". For example, if the remaining available time is -5 seconds (i.e. timed out), it is recorded as "Behavior X: timed out", otherwise it is recorded as "Behavior X: not timed out". Generate a behavior timeout identification matrix, which is presented in a table format and includes the numbers, detection time, task deadline, remaining available time and timeout status of all behaviors to be evaluated.
[0119] S412: Based on the behavior numbers marked as having time conflicts in the behavior timeout identification matrix, the original priority values are updated, the original order of the behaviors that have not timed out is retained, and the updated priority information is paired with the behavior numbers to generate a priority adjustment value table;
[0120] Based on the behavior numbers marked as having time conflicts in the behavior timeout identification matrix, where a time conflict refers to a situation where the remaining available time is negative or below a preset threshold (e.g., 5 seconds), the original priority values are updated. For example, if the original priority value range is 1-100, the priority value of the behavior with a time conflict will be increased. The specific update method is: a fixed penalty value (e.g., 20) is added to the original priority value, or it is multiplied by an adjustment factor (e.g., 1.5). For example, if the original priority of a timed-out behavior is 50, it will be updated to 50 + 20 = 70. The original ranking of the behaviors that have not timed out is retained, and the priority values of the behaviors that have not timed out remain unchanged. For example, if the original priority of the behaviors that have not timed out is 40, it will remain 40 after the update. The updated priority information is paired with the behavior number, for example, forming a key-value pair of "behavior number - updated priority". This generates a priority adjustment value table that lists each behavior number and its new priority value after considering the time conflict.
[0121] S413: Reorder the behaviors that have not undergone safety assessment according to the priority adjustment value table, use the adjusted priorities as the main sequence basis, and establish a collaborative control priority sequence based on the original signal interaction relationship structure and time conflict conditions;
[0122] According to the priority adjustment value table, which contains the priority value of each behavior after time conflict adjustment, behaviors that have not undergone security assessment are reordered. The reordering is based on the new priority value in the priority adjustment value table. The larger the value, the higher the priority. For example, if the adjusted priority of behavior A is 80 and that of behavior B is 60, behavior A is ranked before behavior B. Using the adjusted priority as the main basis means that when sorting, the adjusted priority is considered first. If the priorities are the same, the original signal interaction relationship structure and time conflict situation are referenced. The original signal interaction relationship structure refers to the position of the behavior in the network topology and the connection relationship with the behavior. The time conflict situation refers to the remaining available time of the behavior. For example, when the priorities are the same, the behavior on the critical path with the shorter remaining time is prioritized. A collaborative control priority sequence is established. This sequence is a final ordered list that indicates the final priority order of detection and control of each behavior in the multi-dimensional collaborative attack detection mechanism, ensuring efficient collaborative processing of abnormal behaviors while considering security and timeliness.
[0123] See also Figure 6 ,The specific steps for obtaining the multi-dimensional collaborative attack ,detection mechanism are as follows:
[0124] S511: Based on the collaborative control priority sequence, sequentially read the entity state of each behavior in the current detection, extract the signal interaction structure and priority information of adjacent behaviors, update the priority number and path frequency field of the interaction behavior, and generate priority interaction synchronization data;
[0125] Based on the collaborative control priority sequence, the sequence indicates the final detection and control priority of each behavior in the multi-dimensional collaborative attack detection mechanism in the form of an ordered list, and reads the entity status of each behavior in the current detection in sequence. The entity status includes real-time data such as the operation status of the behavior, resource usage, input and output traffic, etc. For example, for the "abnormal login attempt" behavior, the entity status includes the number of attempts, source IP, login account, response time, etc., and extracts the signal interaction structure and the priority information of adjacent behaviors. The signal interaction structure refers to the data flow and dependency relationship between behaviors. For example, the interaction between the login service and the database service, the priority information of the adjacent behavior is the priority of the current behavior in the collaborative control priority sequence. It is the priority value of the directly connected behavior. For example, if the downstream of "abnormal login attempt" is "database query", the priority of "database query" is extracted, and the priority number and path frequency field of the interactive behavior are updated. The priority number is the sequence number of the behavior in the collaborative control priority sequence. The path frequency field records the number of times the behavior is accessed or executed within a given time. For example, if the "abnormal login attempt" behavior occurs 10 times in the past minute, the path frequency is updated to 10, and priority interaction synchronization data is generated. The data is presented in a real-time updated table, which includes the entity status of each behavior, signal interaction structure, adjacent behavior priority, priority number and path frequency.
[0126] S512: Based on the priority interaction synchronization data, identify the time series structure indexed by the behavior priority, divide the behavior into corresponding detection periods, determine the distribution range and central trend within the same period, and combine the priority order to obtain the detection layout coordinate matrix;
[0127] Based on the priority interaction synchronization data, which includes the entity state, signal interaction structure, adjacent behavior priority, priority number and path frequency of each behavior, the time series structure with behavior priority as the index is identified, that is, behaviors with the same priority number are classified together and sorted according to their detection time to form a time series. For example, all behaviors with a priority of 1 constitute a time series, and all behaviors with a priority of 2 constitute another time series. The behaviors are divided into corresponding detection cycles. The detection cycle is a preset time window. For example, every 5 minutes is a detection cycle. The behavior is assigned to the corresponding cycle according to its timestamp. For example, behaviors with a detection time between 10:00:00 and 10:05:00 It is divided into the first detection cycle, and the distribution range and central tendency within the same cycle are determined. The distribution range refers to the difference between the maximum and minimum values of the behavior entity status data within the cycle, and the central tendency refers to the average or median of the behavior entity status data within the cycle. For example, it is determined whether the distribution range of the "number of failed logins" in the 10:00-10:05 cycle exceeds the normal threshold, and whether the average value is significantly higher than the historical average. The system combines the priority order to obtain the detection layout coordinate matrix. The matrix is a multidimensional data structure that maps the detection cycle, priority number and entity status data of each behavior to specific coordinates. For example, the rows of the matrix represent the detection cycle, the columns represent the priority, and the cells store the aggregated status information of the corresponding behavior.
[0128] S513: Based on the behavior layout information recorded in the detection layout coordinate matrix, a behavior graphic border style, a connection path line type, and a field display method are selected to perform standardized detection for each behavior, thereby obtaining a multi-dimensional coordinated attack detection mechanism.
[0129] Based on the behavior layout information recorded in the detection layout coordinate matrix, the matrix maps the detection cycle, priority number and entity status data of each behavior to specific coordinates, and selects the behavior graphic border style, connection path line type and field display method. For example, for behaviors with high priority and abnormal fluctuations, the graphic border style is a thick red solid line, the connection path line type is a dotted red line, and the field display method is to highlight key abnormal indicators, while for normal behaviors, a thin green solid line is selected. The selection is based on the priority, abnormality level and user configuration of the behavior. Standardized detection is performed for each behavior. Standardized detection refers to the unified analysis and evaluation of behavioral data according to predefined rules and algorithms. For example, for network traffic anomaly detection, standardized detection includes traffic threshold comparison, protocol compliance check and anomaly pattern matching, resulting in a multi-dimensional collaborative attack detection mechanism. This mechanism integrates all behavioral information that has been visually configured and standardized into a unified interface or report, allowing security analysts to intuitively and efficiently identify and respond to multi-dimensional collaborative attacks.
[0130] The above are merely preferred embodiments of the present invention and do not limit the present invention in any other form. Any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall still fall within the scope of protection of the technical solution of the present invention.
Claims
1. A detection method integrating deep feature extraction and attack identification, characterized in that: The following steps are involved: S1: Obtain the signal response of network behavior in the deep feature space, analyze the fluctuation range between adjacent features, determine whether there is a security assessment deviation caused by abnormal signals, mark them as abnormal signals, and generate an abnormal signal list; S2: Based on the abnormal signal list, recursively adjust the detection logic sequence of the abnormal signal and the associated signals, remove the abnormal association of the marked signal, update the detection logic structure, and generate a benchmark detection snapshot; The specific steps for obtaining the benchmark detection snapshot are: S211: Read the abnormal path in the abnormal signal list, retrieve the endpoint behavior corresponding to the abnormal path, locate the downstream signal interaction relationship of the behavior, record the signal interaction number indirectly associated with the abnormal path, and generate an abnormal diffusion path number set; S212: Based on the abnormal diffusion path number set, statistically analyze the behavior number information, match the signal interaction relationship between behaviors, calculate the behavior connection adjustment strength value, and perform adjustment if the behavior connection adjustment strength value is higher than the judgment threshold to obtain a signal interaction update matrix; S213: extracting the behavior number and the outgoing edge information of the connection according to the signal interaction update matrix, freezing the state of the current time node after updating the structure, retaining the adjusted global signal connection information, marking the version number and time label, and establishing a benchmark detection snapshot; S3: Based on the benchmark detection snapshot, count the number of network behavior pre-dependencies that have not completed security assessment, trace the starting behavior, prioritize the behaviors based on their time distribution, and generate a management priority list; The specific steps for obtaining the management priority list are: S311: Based on the benchmark detection snapshot, extract the task completion flag of the behavior, read the input edge signal interaction path list of the behavior that has not completed the safety assessment, and count the number of previous behaviors to obtain a predecessor relationship number table; S312: According to the preceding relationship quantity table, identify the behavior with zero preceding behavior quantity as the topological starting point, sequentially scan the connection edge information in the signal distribution graph, perform a topological sorting process, and generate a topological hierarchical order result; S313: Extracting corresponding time code information for each behavior based on the topological hierarchy order result, splitting the time code field, calculating the topological hierarchy depth value of the behavior, identifying the management priority, arranging the behavior numbers according to the numerical values, and establishing a management priority list; S4: Extracting the detection time of network behaviors that have not yet completed security assessment based on the management priority list, determining whether there are behaviors that exceed the detection time range, and adjusting the detection priority of the corresponding behaviors to generate a collaborative control priority sequence; S5: Based on the collaborative control priority sequence, uniformly update the detection status and priority information of the network behavior, rebuild the detection view model, identify standardized detection instructions, and obtain a multi-dimensional collaborative attack detection mechanism; The multi-dimensional collaborative attack detection mechanism includes a behavior state distribution diagram, a task priority mapping structure, and an information display framework that meets the detection standards.
2. The detection method integrating deep feature extraction and attack identification according to claim 1 is characterized in that: The abnormal signal list includes characteristic fluctuation exceeding standard marks, safety assessment conflict marks, and real-time signal deviation behaviors; the benchmark detection snapshot includes updated detection logic diagrams, a set of eliminated abnormal signals, and behavior correction status information; the management priority list includes a behavior sequence table generated according to the time distribution relationship, a behavior pre-dependency quantity indicator, and a priority sorting index; the collaborative control priority sequence includes detection time tight behavior identification results, priority adjustment plans, and detection time matching status.
3. The detection method integrating deep feature extraction and attack identification according to claim 1 is characterized in that: The specific steps for obtaining the abnormal signal list are: S111: Obtain the signal response of the network behavior in the deep feature space, detect the signal change rate of adjacent features, and compare it with the real-time signal of the corresponding behavior to identify the feature fluctuation range between the two and generate feature fluctuation distribution data; S112: Based on the characteristic fluctuation distribution data and the rated signal interval, determine whether the characteristic fluctuation range of the behavior exceeds the interval, select the signal interaction path that meets the conditions, and record the interaction direction, signal-related behavior, and fluctuation amplitude to obtain an abnormal signal marking result; S113: Based on the abnormal signal marking result, filter the signal interaction paths whose fluctuation amplitude exceeds the rated range, extract the corresponding behavior combinations and interaction types, and establish an abnormal signal list.
4. The detection method integrating deep feature extraction and attack identification according to claim 1 is characterized in that: The specific steps for obtaining the collaborative control priority sequence are: S411: Extract the detection time of each behavior from the security assessment behavior in the management priority list, identify the remaining available time from the current time node to the task deadline, record the time difference, and record the mapping between the behavior number and the timeout status to generate a behavior timeout identification matrix; S412: Based on the behavior numbers marked as having time conflicts in the behavior timeout identification matrix, the original priority values are updated, the original order of the behaviors that have not timed out is retained, and the updated priority information is paired with the behavior numbers to generate a priority adjustment value table; S413: Reorder the behaviors that have not undergone safety assessment according to the priority adjustment value table, use the adjusted priorities as the main sequence basis, and establish a collaborative control priority sequence in combination with the original signal interaction relationship structure and time conflict situation.
5. The detection method integrating deep feature extraction and attack identification according to claim 1 is characterized in that: The specific steps of obtaining the multi-dimensional collaborative attack detection mechanism are as follows: S511: Based on the collaborative control priority sequence, sequentially read the entity state of each behavior in the current detection, extract the signal interaction structure and priority information of adjacent behaviors, update the priority number and path frequency field of the interaction behavior, and generate priority interaction synchronization data; S512: Based on the priority interaction synchronization data, identify a time series structure indexed by behavior priority, divide the behavior into corresponding detection periods, determine the distribution range and central tendency within the same period, and obtain a detection layout coordinate matrix based on the priority order; S513: According to the behavior layout information recorded in the detection layout coordinate matrix, a behavior graphic border style, a connection path line type, and a field display method are selected to perform standardized detection for each behavior to obtain a multi-dimensional collaborative attack detection mechanism.
Citation Information
Patent Citations
Hammer attack defense method and device for dynamic memory
CN115357952A
Priority asynchronous processing method and system for network security
CN119402257A