Network traffic anomaly identification method and device based on edge detection algorithm

Through the network traffic anomaly identification method of edge detection algorithm, the adaptability problem of threshold detection method and data dependence problem of machine learning algorithm are solved, efficient and accurate abnormal traffic recognition is achieved, false alarm rates and missed rates are reduced, and network environment changes are adapted to changes.

CN120498840APending Publication Date: 2025-08-15HENAN ZHONGYUAN CONSUMER FINANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510802665.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the identification of network traffic anomalies, it is difficult to set thresholds based on threshold detection methods, and it is difficult to adapt to dynamic changes in network traffic. However, machine learning classification algorithms rely on a large amount of labeled data and lack the ability to generalize new anomalies patterns.

Method used

The network traffic anomaly recognition method based on edge detection algorithm is adopted. Through time series data window processing, multi-dimensional feature extraction, angle encoding and improved Canny edge detection process, combined with dynamic baseline and adaptive threshold strategies, the edge characteristics and change trends of traffic data are identified and abnormal traffic is determined.

Benefits of technology

It improves the sensitivity and accuracy of abnormal traffic identification, reduces the false alarm rate and missed alarm rate, reduces the dependence on labeled data, quickly adapts to changes in the network environment, and provides more reliable network security guarantees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498840A_ABST
    Figure CN120498840A_ABST
Patent Text Reader

Abstract

The invention discloses a network traffic anomaly identification method and device based on an edge detection algorithm. The method comprises the following steps: preprocessing traffic data; constructing an image matrix by the preprocessed traffic characteristic data; the improved Canny edge detection process comprises transverse gradient detection and longitudinal gradient detection; establishing a dynamic baseline, setting a threshold range, and judging whether pixels in the image belong to edges or not; if the strength of the edge exceeds a set threshold value and the parameter meets a set condition, judging that the traffic data corresponding to the position is abnormal; and when an edge exceeding a set threshold is detected in a plurality of continuous time intervals and the edge presents a similar change trend on different feature dimensions, determining that the traffic is abnormal. The edge detection algorithm adopted by the invention has stronger feature analysis capability, can deeply mine subtle changes of traffic data in multiple dimensions such as a protocol dimension and a time dimension, and carefully depicts a change trend of traffic features, so that abnormal traffic is more accurately positioned.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and traffic analysis, and relates to a method and device for identifying network traffic anomalies based on an edge detection algorithm. Background Art

[0002] In today's digital age, networks are deeply integrated into every aspect of social life, becoming critical infrastructure for information transmission, business operations, and the functioning of society. With the continuous expansion of network scale, the increasing diversity of network applications, and the continuous evolution of cyberattack methods, network traffic has become highly complex, dynamic, and ever-changing. Against this backdrop, network traffic management faces numerous challenges, of which accurate and timely identification of abnormal traffic is paramount.

[0003] Abnormal traffic can arise from a variety of factors, ranging from non-malicious situations like network failures and configuration errors to malicious activities like network attacks and malware propagation. Regardless of the cause, if abnormal traffic is not promptly and effectively identified and addressed, it can severely impact network stability, availability, and security. For example, a distributed denial of service (DDoS) attack can cause a sharp increase in network traffic, paralyzing network services. Malware spreads, generating large amounts of abnormal traffic, stealing sensitive user information or disrupting system operations. Therefore, building an efficient and accurate network traffic anomaly identification system is crucial to ensuring network stability and security.

[0004] Currently, various technical approaches exist for identifying network traffic anomalies. However, these approaches all have limitations and struggle to meet the stringent accuracy and timeliness requirements of practical applications. Threshold-based detection is a relatively traditional and common method for identifying abnormal traffic. The core concept of this method is to pre-set a traffic threshold range. When actual network traffic exceeds this range, it is identified as abnormal traffic. For example, in network bandwidth management, upper and lower limits are set for bandwidth usage. Once actual usage exceeds these limits, the system triggers an alarm. However, setting thresholds for this method is extremely difficult. If the thresholds are set too wide, many potential anomalies will be missed, making it difficult to promptly identify network security risks. If the thresholds are set too narrow, normal traffic fluctuations can easily trigger false alarms, causing unnecessary interference for network administrators and wasting significant management resources. More importantly, threshold-based detection methods lack the ability to adapt to the dynamic nature of network traffic. During peak network usage, normal traffic may far exceed the normal threshold. Using fixed thresholds to detect such fluctuations can easily misinterpret normal traffic fluctuations as anomalies, thus impacting normal network operation.

[0005] Machine learning classification algorithms have been widely used in recent years in the field of network traffic anomaly identification. This approach collects large amounts of normal and abnormal traffic data to construct a training dataset, which is then used to train classification models such as support vector machines (SVMs) and decision trees. A fully trained model can classify new traffic data and determine whether it is abnormal. While machine learning classification algorithms have improved the accuracy of abnormal traffic identification to a certain extent, they also have several significant drawbacks. First, the algorithms require a large amount of labeled data for training. This data labeling is not only time-consuming and labor-intensive, but also requires the involvement of technical personnel with specialized knowledge, increasing the cost and difficulty of algorithm application. Second, the performance of machine learning models is highly dependent on the completeness and representativeness of the training data. In real-world applications, network environments are complex and ever-changing, and new abnormal patterns emerge continuously. If the training data fails to cover certain specific abnormal situations, the model will struggle to effectively identify these emerging abnormal patterns, resulting in a serious lack of generalization ability and an inability to meet the practical needs of network traffic anomaly identification.

[0006] In summary, existing network traffic anomaly identification technologies and methods have significant deficiencies in accuracy and timeliness, making them ineffective in addressing the complex and ever-changing network environment. Therefore, there is an urgent need to develop a more efficient and accurate network traffic anomaly identification technology to reduce false positives and quickly detect traffic anomalies at an early stage, thereby providing strong guarantees for network stability and security. Summary of the Invention

[0007] The purpose of the present invention is to solve the problems in the existing technology that the threshold detection method is difficult to set the threshold and is difficult to adapt to the dynamic changes of network traffic, and the machine learning classification algorithm relies on a large amount of labeled data and has insufficient generalization ability for new abnormal patterns. A network traffic anomaly identification method and device based on an edge detection algorithm are provided.

[0008] In order to achieve the above object, the present invention adopts the following technical solutions:

[0009] A method for identifying network traffic anomalies based on an edge detection algorithm includes the following steps:

[0010] Traffic data preprocessing:

[0011] Time series data is processed by windowing, using a sliding window mechanism to sample the original network traffic in segments;

[0012] Multi-dimensional feature extraction to analyze indicators from each time window;

[0013] Spatiotemporal feature encoding and multidimensional data fusion combine network traffic features in different proportions to form a time curve reflecting traffic status. Data normalization compresses the fused curve values into a set range to make traffic fluctuations in different time periods comparable. Angle encoding converts the normalized values into angle values, forming a virtual disk that rotates over time, converting data fluctuations into the swing trajectory of a pointer on the disk. Relationship matrix generation constructs an image matrix reflecting data correlation by combining the angles of two time points.

[0014] Edge detection algorithm application:

[0015] Image matrix construction: the preprocessed traffic feature data is constructed into an image matrix with the traffic size as the pixel value, the time series as the row, and the different feature dimensions as the column;

[0016] Improved Canny edge detection process, horizontal gradient detection, uses the Sobel operator to analyze the distribution changes of the protocol dimension, slides the kernel matrix on the grayscale matrix, and calculates the horizontal gradient of each pixel; vertical gradient detection uses a customized convolution kernel to capture traffic mutations in the time dimension;

[0017] Establish a dynamic baseline based on sliding window statistics and set a threshold range to determine whether a pixel in the image belongs to an edge;

[0018] Abnormality determination: Analyze the edge features in the flow data obtained by edge detection. If the edge strength exceeds the set threshold and the edge duration and frequency parameters meet the set conditions, the flow data corresponding to the location is determined to be abnormal. If edges exceeding the set threshold are detected in multiple consecutive time intervals and the edges show similar change trends in different feature dimensions, it is determined to be abnormal flow.

[0019] Abnormal traffic is discarded and normal traffic is forwarded normally.

[0020] The multidimensional feature extraction includes parsing six key indicators from each time window, including the number of data packets, byte entropy value, protocol distribution ratio, port mutation rate, session duration, and flag bit combination; the number of data packets counts the total number of data packets transmitted per unit time; the byte entropy value is used to evaluate data randomness; the protocol distribution ratio counts the proportion of TCP / UDP / ICMP protocols; the port mutation rate calculates the proportion of independent ports accessed per unit time; the session duration records the duration of the network connection; and the flag bit combination analyzes the combination pattern of SYN / FIN / RST control bits in the TCP message.

[0021] The angle coding is specifically:

[0022] The raw data is normalized to obtain a normalized value; the normalized value is converted into an angle value according to a preset conversion rule, wherein the preset conversion rule is: a value of 0 is mapped to an angle of 0° corresponding to the 3 o'clock direction of a clock, and a value of 1 is mapped to an angle of 90° corresponding to the 12 o'clock direction of a clock; a virtual disk that rotates over time is constructed based on the converted angle values, so that data fluctuations are visualized in the form of a swinging trajectory of a pointer on the virtual disk.

[0023] The relationship matrix is generated specifically as follows:

[0024] Obtain a set of angle values corresponding to the data after angle encoding at each time point; arbitrarily select the angle values corresponding to two different time points from the angle value set and combine them; for each set of angle value combinations, calculate the cosine value of the sum of the two angle values; fill the calculated cosine values corresponding to each angle value combination into the corresponding position points of the image matrix according to the predetermined matrix dimension and element position mapping rules, so as to construct an image matrix reflecting the correlation between the data at each time point, wherein the cosine value serves as the grayscale value of the corresponding matrix point.

[0025] The improved Canny edge detection process is specifically as follows:

[0026] Two-dimensional gradient analysis:

[0027] Horizontal gradient detection: The Sobel operator is used to analyze the distribution changes of the protocol dimension, and the kernel matrix is slid on the grayscale matrix to calculate the horizontal gradient of each pixel:

[0028]

[0029] Among them, G x (i, j) represents the lateral gradient value at position (i, j) in the grayscale matrix constructed by the flow characteristic data; K x is the Sobel operator kernel matrix; u and v are loop variables; M is the grayscale matrix;

[0030] Longitudinal gradient detection: Use a custom convolution kernel to capture flow mutations in the time dimension. The convolution operation is:

[0031]

[0032] Among them, G y (i, j) represents the longitudinal gradient value at position (i, j) in the grayscale matrix constructed by the flow characteristic data; the weight coefficient W = [0.5, 1, 0.5];

[0033] Fusion algorithm:

[0034]

[0035] Where λ = 1.2 is the longitudinal gradient enhancement coefficient;

[0036] Adaptive dual-threshold strategy: A dynamic baseline is established based on sliding window statistics. The high threshold is the baseline mean + 3 times the standard deviation, and the low threshold is the baseline mean + 1.5 times the standard deviation. These thresholds are used to determine whether a pixel in the image is an edge.

[0037] Directional feature screening: limit the 45°-135° directional gradient response.

[0038] The method also includes abnormal density assessment and graded alarm:

[0039] For the traffic data image after edge detection, the edge pixel ratio ED is calculated using the following formula: ED = number of edge pixels / total number of pixels; a dynamic threshold is set. When the calculated ED value exceeds the dynamic threshold, a graded alarm mechanism is triggered.

[0040] The method further includes attack pattern recognition:

[0041] Pre-building an attack graph library containing abnormal pattern feature data corresponding to various known network attack patterns; when abnormal traffic is determined to exist, extracting the real-time feature data of the abnormal traffic and comparing it with the abnormal pattern feature data in the attack graph library;

[0042] By calculating the similarity between the real-time feature data and the feature data of each abnormal pattern in the attack library, the abnormal pattern with the highest similarity to the real-time feature data is identified, and then the attack mode corresponding to the abnormal traffic is determined.

[0043] A network traffic anomaly identification device based on edge detection algorithm, including the following modules:

[0044] The traffic data preprocessing module is used to preprocess the original network traffic data and includes the following submodules:

[0045] Time series data windowing submodule: It uses a sliding window mechanism to sample the original network traffic in segments, dividing the continuous traffic data into multiple time windows according to the set window size and sliding step size;

[0046] Multi-dimensional feature extraction submodule: parses multiple traffic indicators from each time window;

[0047] Spatiotemporal feature encoding submodule: Multidimensional data fusion unit: This unit mixes the extracted multidimensional flow features according to a preset ratio to form a time curve reflecting the flow status; Data standardization unit: This unit standardizes the fused time curve values and compresses them into a set range; Angle encoding unit: This unit converts the standardized values into angle values, constructs a virtual disk model that rotates over time, and converts data fluctuations into the swing trajectory of the pointer on the disk; Relationship matrix generation unit: This unit constructs an image matrix reflecting the data correlation by combining the angles of two time points.

[0048] The edge detection algorithm application module is used to perform edge detection on pre-processed traffic feature data and includes the following submodules:

[0049] Image matrix construction submodule: constructs the preprocessed traffic feature data into an image matrix, with the traffic size as the pixel value, the time series as the matrix row, and different feature dimensions as the matrix column;

[0050] Improved Canny edge detection submodule: Horizontal gradient detection unit: uses the Sobel operator to analyze the distribution changes of the protocol dimension, slides the kernel matrix on the grayscale matrix, and calculates the horizontal gradient of each pixel; Longitudinal gradient detection unit: uses a customized convolution kernel to capture the flow mutation in the time dimension and calculates the longitudinal gradient of each pixel;

[0051] Dynamic baseline establishment submodule: This module establishes a dynamic baseline based on the distribution of traffic feature data in a sliding window and sets a threshold range to determine whether a pixel in the image belongs to an edge.

[0052] The intelligent decision-making module is used to determine whether there are abnormalities in traffic data based on edge detection results. It includes the following units:

[0053] Edge feature analysis unit: analyzes the edge features in the traffic data obtained by edge detection, including edge strength, duration, and frequency parameters;

[0054] Abnormality judgment unit: If the intensity of the edge exceeds the preset threshold, and the edge duration and frequency parameters meet the preset conditions, the traffic data corresponding to the location is judged to be abnormal; when edges exceeding the preset threshold are detected in multiple consecutive time intervals, and the edges show similar change trends in different feature dimensions, it is judged to be abnormal traffic.

[0055] The intelligent decision-making module also includes an abnormal density assessment and graded alarm unit, which is used to perform abnormal density assessment on the traffic data image after edge detection and trigger graded alarms.

[0056] The intelligent decision-making module further includes an attack pattern recognition unit, which is used to identify the attack pattern corresponding to the abnormal traffic when it is determined that there is abnormal traffic.

[0057] Compared with the prior art, the present invention has the following beneficial effects:

[0058] The present invention provides a network traffic anomaly identification method based on an edge detection algorithm. Compared with traditional threshold-based detection methods, the edge detection algorithm used has stronger feature analysis capabilities. It can deeply explore subtle changes in traffic data in multiple dimensions such as protocol and time dimensions, and carefully depict the changing trends of traffic characteristics, thereby more accurately locating abnormal traffic. Traditional threshold methods can often only make judgments based on simple numerical ranges and are difficult to cope with complex and changeable traffic characteristics. Edge detection algorithms, on the other hand, effectively improve the sensitivity and accuracy of anomaly detection by capturing the changing boundaries and sharp turning points of the data.

[0059] Accurately distinguish between normal and abnormal fluctuations: Network traffic will experience certain fluctuations during normal operation, which may be caused by normal business activities, changes in the network environment, and other factors. Traditional detection methods tend to misjudge normal traffic fluctuations as abnormalities, resulting in a high false alarm rate; at the same time, some abnormal traffic with similar characteristics to normal traffic fluctuations may be missed. However, this method, through a comprehensive analysis of the multi-dimensional characteristics of traffic data, can accurately identify the characteristic patterns unique to abnormal traffic and effectively distinguish them from the fluctuation characteristics of normal traffic, greatly reducing the probability of false alarms and missed alarms, and providing more reliable protection for network security.

[0060] Free from the constraints of large-scale labeled data: Compared to traditional machine learning classification algorithms, this method does not rely on large amounts of labeled data for model training. The performance of traditional machine learning algorithms is highly dependent on the quality and quantity of labeled data. Collecting, organizing, and annotating large amounts of network traffic data not only requires significant manpower, material resources, and time, but the data annotation process is often subject to subjectivity and errors, which may affect model accuracy. Edge detection algorithms, on the other hand, focus on data trends and sudden changes in features, and do not rely on data labels, reducing the workload of data collection and annotation, and lowering implementation costs.

[0061] Network environments are constantly changing, and new anomaly patterns emerge constantly. Traditional machine learning algorithms, when faced with new network environments and anomaly patterns, require re-collecting annotated data for model training and optimization, resulting in a long adaptation cycle. However, this edge detection algorithm, which detects based on the nature of data changes, can adapt more quickly to new network environments and anomaly patterns. As soon as the changing trends and characteristics of traffic data show anomalies, the algorithm detects them immediately, eliminating the need for complex model adjustments and retraining. This improves the method's adaptability and responsiveness to changing network environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0063] Figure 1 This is a flow chart of the improved Canny edge detection in the present invention;

[0064] Figure 2 This is a diagram showing the architecture of the network traffic anomaly identification device of the present invention;

[0065] Figure 3 This is a module structure diagram of the network traffic anomaly identification device based on the edge detection algorithm in the present invention. DETAILED DESCRIPTION

[0066] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0067] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0068] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0069] The present invention is described in further detail below with reference to the accompanying drawings:

[0070] The present invention provides a method for identifying network traffic anomalies based on an edge detection algorithm, comprising the following steps:

[0071] Traffic data preprocessing:

[0072] Time series data is processed by windowing, using a sliding window mechanism to sample the original network traffic in segments, with each minute as a group. The network traffic data is grouped by time series to ensure continuous monitoring without blind spots.

[0073] Multi-dimensional feature extraction, analyzing indicators from each time window; including packet number, byte entropy value, protocol distribution ratio, port mutation rate, session duration, and flag bit combination;

[0074] Number of data packets: the total number of data packets transmitted per unit time;

[0075] Byte entropy value: used to evaluate data randomness;

[0076] Protocol distribution ratio: statistics on the proportion of TCP / UDP / ICMP and other protocols;

[0077] Port mutation rate: calculates the proportion of independent ports accessed per unit time;

[0078] Session duration: records the duration of the network connection;

[0079] Flag bit combination: Analyzes the combination pattern of control bits such as SYN / FIN / RST in TCP packets.

[0080] Spatiotemporal feature encoding:

[0081] Multi-dimensional data fusion: the characteristics of network traffic are mixed in different proportions to form a time curve reflecting the traffic status;

[0082] Data standardization compresses the fused curve values into a set range, making the flow fluctuations in different time periods comparable;

[0083] Angle coding converts the standardized values into angle values, forming a virtual disk that rotates over time, so that the data fluctuations are converted into the swing trajectory of the pointer on the disk; the angle coding is specifically:

[0084] The raw data is normalized to obtain a normalized value; the normalized value is converted into an angle value according to a preset conversion rule, wherein the preset conversion rule is: a value of 0 is mapped to an angle of 0° corresponding to the 3 o'clock direction of a clock, and a value of 1 is mapped to an angle of 90° corresponding to the 12 o'clock direction of a clock; a virtual disk that rotates over time is constructed based on the converted angle values, so that data fluctuations are visualized in the form of a swinging trajectory of a pointer on the virtual disk.

[0085] Relationship matrix generation: By combining the angles of two time points, an image matrix reflecting the data correlation is constructed. The relationship matrix generation is specifically as follows:

[0086] Obtain a set of angle values corresponding to the data after angle encoding at each time point; arbitrarily select the angle values corresponding to two different time points from the angle value set and combine them; for each set of angle value combinations, calculate the cosine value of the sum of the two angle values; fill the calculated cosine values corresponding to each angle value combination into the corresponding position points of the image matrix according to the predetermined matrix dimension and element position mapping rules, so as to construct an image matrix reflecting the correlation between the data at each time point, wherein the cosine value serves as the grayscale value of the corresponding matrix point.

[0087] Image optimization: compress the generated matrix into a standard size of 128×128 pixels and optimize its clarity.

[0088] Edge detection algorithm application:

[0089] Image matrix construction: the preprocessed traffic feature data is constructed into an image matrix with the traffic size as the pixel value, the time series as the row, and the different feature dimensions as the column;

[0090] See also Figure 1 , which is the improved Canny edge detection process in this invention. Horizontal gradient detection uses the Sobel operator to analyze the distribution changes of the protocol dimension, slides the kernel matrix on the grayscale matrix, and calculates the horizontal gradient of each pixel; vertical gradient detection uses a customized convolution kernel to capture the flow mutation in the time dimension; specifically:

[0091] Two-dimensional gradient analysis:

[0092] Horizontal gradient detection: The Sobel operator is used to analyze the distribution changes of the protocol dimension, and the kernel matrix is slid on the grayscale matrix to calculate the horizontal gradient of each pixel:

[0093]

[0094] Among them, G x (i, j) represents the lateral gradient value at position (i, j) in the grayscale matrix constructed by the flow characteristic data; K x is the Sobel operator kernel matrix; u and v are loop variables; M is the grayscale matrix;

[0095] Longitudinal gradient detection: Use a custom convolution kernel to capture flow mutations in the time dimension. The convolution operation is:

[0096]

[0097] Among them, G y (i, j) represents the longitudinal gradient value at position (i, j) in the grayscale matrix constructed by the flow characteristic data; the weight coefficient W = [0.5, 1, 0.5];

[0098] Fusion algorithm:

[0099]

[0100] Where λ = 1.2 is the longitudinal gradient enhancement coefficient;

[0101] Adaptive dual-threshold strategy: A dynamic baseline is established based on sliding window statistics. The high threshold is the baseline mean + 3 times the standard deviation (sensitive mode), and the low threshold is the baseline mean + 1.5 times the standard deviation (steady-state mode). These thresholds are used to determine whether a pixel in the image is an edge.

[0102] Directional feature screening: limit the 45°-135° directional gradient response.

[0103] Establish a dynamic baseline based on sliding window statistics and set a threshold range to determine whether a pixel in the image belongs to an edge;

[0104] Abnormality determination: Analyze the edge features in the flow data obtained by edge detection. If the edge strength exceeds the set threshold and the edge duration and frequency parameters meet the set conditions, the flow data corresponding to the location is determined to be abnormal. If edges exceeding the set threshold are detected in multiple consecutive time intervals and the edges show similar change trends in different feature dimensions, it is determined to be abnormal flow.

[0105] Abnormal traffic is discarded and normal traffic is forwarded normally.

[0106] Abnormal density assessment and graded alarms:

[0107] For the traffic data image after edge detection, the edge pixel ratio ED is calculated using the following formula: ED = number of edge pixels / total number of pixels; a dynamic threshold is set. When the calculated ED value exceeds the dynamic threshold, a graded alarm mechanism is triggered.

[0108] Attack pattern recognition:

[0109] Pre-building an attack graph library containing abnormal pattern feature data corresponding to various known network attack patterns; when abnormal traffic is determined to exist, extracting the real-time feature data of the abnormal traffic and comparing it with the abnormal pattern feature data in the attack graph library;

[0110] By calculating the similarity between the real-time feature data and the feature data of each abnormal pattern in the attack library, the abnormal pattern with the highest similarity to the real-time feature data is identified, and then the attack mode corresponding to the abnormal traffic is determined.

[0111] See also Figure 3 , is a network traffic anomaly identification device based on edge detection algorithm in the present invention, comprising the following modules:

[0112] The traffic data preprocessing module is used to preprocess the original network traffic data and includes the following submodules:

[0113] Time series data windowing submodule: It uses a sliding window mechanism to sample the original network traffic in segments, dividing the continuous traffic data into multiple time windows according to the set window size and sliding step size;

[0114] Multi-dimensional feature extraction submodule: parses multiple traffic indicators from each time window;

[0115] Spatiotemporal feature encoding submodule: Multidimensional data fusion unit: This unit mixes the extracted multidimensional flow features according to a preset ratio to form a time curve reflecting the flow status; Data standardization unit: This unit standardizes the fused time curve values and compresses them into a set range; Angle encoding unit: This unit converts the standardized values into angle values, constructs a virtual disk model that rotates over time, and converts data fluctuations into the swing trajectory of the pointer on the disk; Relationship matrix generation unit: This unit constructs an image matrix reflecting the data correlation by combining the angles of two time points.

[0116] The edge detection algorithm application module is used to perform edge detection on pre-processed traffic feature data and includes the following submodules:

[0117] Image matrix construction submodule: constructs the preprocessed traffic feature data into an image matrix, with the traffic size as the pixel value, the time series as the matrix row, and different feature dimensions as the matrix column;

[0118] Improved Canny edge detection submodule: Horizontal gradient detection unit: uses the Sobel operator to analyze the distribution changes of the protocol dimension, slides the kernel matrix on the grayscale matrix, and calculates the horizontal gradient of each pixel; Longitudinal gradient detection unit: uses a customized convolution kernel to capture the flow mutation in the time dimension and calculates the longitudinal gradient of each pixel;

[0119] Dynamic baseline establishment submodule: This module establishes a dynamic baseline based on the distribution of traffic feature data in a sliding window and sets a threshold range to determine whether a pixel in the image belongs to an edge.

[0120] The intelligent decision-making module is used to determine whether there are abnormalities in traffic data based on edge detection results. It includes the following units:

[0121] Edge feature analysis unit: analyzes the edge features in the traffic data obtained by edge detection, including edge strength, duration, and frequency parameters;

[0122] Abnormality judgment unit: If the intensity of the edge exceeds the preset threshold, and the edge duration and frequency parameters meet the preset conditions, the traffic data corresponding to the location is judged to be abnormal; when edges exceeding the preset threshold are detected in multiple consecutive time intervals, and the edges show similar change trends in different feature dimensions, it is judged to be abnormal traffic.

[0123] The abnormal density assessment and graded alarm unit is used to perform abnormal density assessment on the traffic data image after edge detection and trigger graded alarms.

[0124] The attack pattern recognition unit is used to identify the attack pattern corresponding to the abnormal traffic when it is determined that there is abnormal traffic.

[0125] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.

Claims

1. A network traffic anomaly identification method based on edge detection algorithm, characterized in that: The following steps are involved: Traffic data preprocessing: Time series data is processed by windowing, using a sliding window mechanism to sample the original network traffic in segments; Multi-dimensional feature extraction to analyze indicators from each time window; Spatiotemporal feature encoding and multidimensional data fusion combine network traffic features in different proportions to form a time curve reflecting traffic status. Data normalization compresses the fused curve values into a set range to make traffic fluctuations in different time periods comparable. Angle encoding converts the normalized values into angle values, forming a virtual disk that rotates over time, converting data fluctuations into the swing trajectory of a pointer on the disk. Relationship matrix generation constructs an image matrix reflecting data correlation by combining the angles of two time points. Edge detection algorithm application: Image matrix construction: the preprocessed traffic feature data is constructed into an image matrix with the traffic size as the pixel value, the time series as the row, and the different feature dimensions as the column; Improved Canny edge detection process, horizontal gradient detection, using the Sobel operator to analyze the distribution changes of the protocol dimension, sliding the kernel matrix on the grayscale matrix, and calculating the horizontal gradient of each pixel; Longitudinal gradient detection uses customized convolution kernels to capture flow mutations in the temporal dimension; Establish a dynamic baseline based on sliding window statistics and set a threshold range to determine whether a pixel in the image belongs to an edge; Abnormality determination: Analyze the edge characteristics in the flow data obtained by edge detection. If the edge strength exceeds the set threshold and the edge duration and frequency parameters meet the set conditions, the flow data corresponding to the location is determined to be abnormal. When edges exceeding the set threshold are detected in multiple consecutive time intervals, and the edges show similar change trends in different feature dimensions, it is determined to be abnormal traffic; Abnormal traffic is discarded and normal traffic is forwarded normally.

2. The method for identifying network traffic anomalies based on an edge detection algorithm according to claim 1, wherein: The multi-dimensional feature extraction includes parsing six key indicators from each time window, including the number of packets, byte entropy, protocol distribution ratio, port mutation rate, session duration, and flag bit combination; The number of data packets counts the total number of data packets transmitted per unit time; the byte entropy value is used to evaluate data randomness; the protocol distribution ratio counts the proportion of TCP / UDP / ICMP protocols; the port mutation rate calculates the proportion of independent ports accessed per unit time; Session duration records the duration of the network connection; The flag bit combination analyzes the combination pattern of the SYN / FIN / RST control bits in the TCP packet.

3. The method for identifying network traffic anomalies based on an edge detection algorithm according to claim 1, wherein: The angle coding is specifically: The raw data is normalized to obtain a normalized value; the normalized value is converted into an angle value according to a preset conversion rule, wherein the preset conversion rule is: a value of 0 is mapped to an angle of 0° corresponding to the 3 o'clock direction of a clock, and a value of 1 is mapped to an angle of 90° corresponding to the 12 o'clock direction of a clock; a virtual disk that rotates over time is constructed based on the converted angle values, so that data fluctuations are visualized in the form of a swinging trajectory of a pointer on the virtual disk.

4. The method for identifying network traffic anomalies based on an edge detection algorithm according to claim 1, wherein: The relationship matrix is generated specifically as follows: Obtain a set of angle values corresponding to the data after angle encoding at each time point; arbitrarily select the angle values corresponding to two different time points from the angle value set and combine them; for each set of angle value combinations, calculate the cosine value of the sum of the two angle values; fill the calculated cosine values corresponding to each angle value combination into the corresponding position points of the image matrix according to the predetermined matrix dimension and element position mapping rules, so as to construct an image matrix reflecting the correlation between the data at each time point, wherein the cosine value serves as the grayscale value of the corresponding matrix point.

5. The method for identifying network traffic anomalies based on an edge detection algorithm according to claim 1, wherein: The improved Canny edge detection process is specifically as follows: Two-dimensional gradient analysis: Horizontal gradient detection: The Sobel operator is used to analyze the distribution changes of the protocol dimension, and the kernel matrix is slid on the grayscale matrix to calculate the horizontal gradient of each pixel: Among them, G x (i, j) represents the lateral gradient value at position (i, j) in the grayscale matrix constructed by the flow characteristic data; K x is the Sobel operator kernel matrix; u and v are loop variables; M is the grayscale matrix; Longitudinal gradient detection: Use a custom convolution kernel to capture flow mutations in the time dimension. The convolution operation is: Among them, G y (i, j) represents the longitudinal gradient value at position (i, j) in the grayscale matrix constructed by the flow characteristic data; the weight coefficient W = [0.5, 1, 0.5]; Fusion algorithm: Where λ = 1.2 is the longitudinal gradient enhancement coefficient; Adaptive dual-threshold strategy: A dynamic baseline is established based on sliding window statistics. The high threshold is the baseline mean + 3 times the standard deviation, and the low threshold is the baseline mean + 1.5 times the standard deviation. These thresholds are used to determine whether a pixel in the image is an edge. Directional feature screening: limit the 45°-135° directional gradient response.

6. The method for identifying network traffic anomalies based on an edge detection algorithm according to claim 1, wherein: The method also includes abnormal density assessment and graded alarm: For the traffic data image after edge detection, the edge pixel ratio ED is calculated using the following formula: ED = number of edge pixels / total number of pixels; a dynamic threshold is set. When the calculated ED value exceeds the dynamic threshold, a graded alarm mechanism is triggered.

7. The method for identifying network traffic anomalies based on an edge detection algorithm according to claim 1, wherein: The method further includes attack pattern recognition: Pre-building an attack graph library, the attack graph library containing abnormal pattern feature data corresponding to multiple known network attack patterns; When it is determined that there is abnormal traffic, real-time feature data of the abnormal traffic is extracted and compared with the abnormal pattern feature data in the attack library; By calculating the similarity between the real-time feature data and the feature data of each abnormal pattern in the attack library, the abnormal pattern with the highest similarity to the real-time feature data is identified, and then the attack mode corresponding to the abnormal traffic is determined.

8. A network traffic anomaly identification device based on edge detection algorithm, characterized in that: Includes the following modules: The traffic data preprocessing module is used to preprocess the original network traffic data and includes the following submodules: Time series data windowing submodule: It uses a sliding window mechanism to sample the original network traffic in segments, dividing the continuous traffic data into multiple time windows according to the set window size and sliding step size; Multi-dimensional feature extraction submodule: parses multiple traffic indicators from each time window; Spatiotemporal feature encoding submodule: Multidimensional data fusion unit: This unit mixes the extracted multidimensional flow features according to a preset ratio to form a time curve reflecting the flow status; Data standardization unit: This unit standardizes the fused time curve values and compresses them into a set range; Angle encoding unit: This unit converts the standardized values into angle values, constructs a virtual disk model that rotates over time, and converts data fluctuations into the swing trajectory of the pointer on the disk; Relationship matrix generation unit: This unit constructs an image matrix reflecting the data correlation by combining the angles of two time points. The edge detection algorithm application module is used to perform edge detection on pre-processed traffic feature data and includes the following submodules: Image matrix construction submodule: constructs the preprocessed traffic feature data into an image matrix, with the traffic size as the pixel value, the time series as the matrix row, and different feature dimensions as the matrix column; Improved Canny edge detection submodule: Horizontal gradient detection unit: uses the Sobel operator to analyze the distribution changes of the protocol dimension, slides the kernel matrix on the grayscale matrix, and calculates the horizontal gradient of each pixel; Longitudinal gradient detection unit: uses a customized convolution kernel to capture the flow mutation in the time dimension and calculates the longitudinal gradient of each pixel; Dynamic baseline establishment submodule: This module establishes a dynamic baseline based on the distribution of traffic feature data in a sliding window and sets a threshold range to determine whether a pixel in the image belongs to an edge. The intelligent decision-making module is used to determine whether there are abnormalities in traffic data based on edge detection results. It includes the following units: Edge feature analysis unit: analyzes the edge features in the traffic data obtained by edge detection, including edge strength, duration, and frequency parameters; Abnormality determination unit: If the edge intensity exceeds the preset threshold, and the edge duration and frequency parameters meet the preset conditions, it is determined that the flow data corresponding to the location is abnormal; When edges exceeding the preset threshold are detected in multiple consecutive time intervals, and the edges show similar change trends in different feature dimensions, it is determined to be abnormal traffic.

9. The network traffic anomaly identification device based on edge detection algorithm according to claim 8, characterized in that: The intelligent decision-making module also includes an abnormal density assessment and graded alarm unit, which is used to perform abnormal density assessment on the traffic data image after edge detection and trigger graded alarms.

10. The network traffic anomaly identification device based on edge detection algorithm according to claim 8, characterized in that: The intelligent decision-making module further includes an attack pattern recognition unit, which is used to identify the attack pattern corresponding to the abnormal traffic when it is determined that there is abnormal traffic.