Network traffic detection method and device, computer equipment and readable storage medium

By using a hybrid deep learning model that combines GRU and NTM to extract short-term and long-term dependency information of network traffic data, the problem that traditional methods are difficult to cope with evolving attack patterns is solved, and higher network traffic detection accuracy is achieved.

CN120675773APending Publication Date: 2025-09-19CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510844699.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Traditional network traffic detection methods are based on predefined signatures and are difficult to cope with ever-evolving attack patterns, resulting in low accuracy of detection results.

Method used

A hybrid deep learning model combining the gated recurrent unit (GRU) and the neural Turing machine (NTM) is used to extract the short-term and long-term dependency information of network traffic data and perform classification processing to improve detection accuracy.

Benefits of technology

It achieves effective detection of evolving attack patterns, improves the accuracy of network traffic detection, and avoids the shortcomings of detection methods based on predefined signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675773A_ABST
    Figure CN120675773A_ABST
Patent Text Reader

Abstract

The invention relates to a network traffic detection method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: acquiring to-be-detected network flow data; inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used for representing short-term dependency information of the network traffic data, and the second traffic feature is used for representing long-term dependency information of the network traffic data; and performing classification processing on the network flow data according to the first flow feature and the second flow feature to obtain a classification result of the network flow data, and obtaining a detection result of the network flow data based on the classification result. By adopting the method, the network flow detection accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a network traffic detection method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Art

[0002] In the field of network security technology, in order to avoid abnormal network traffic intrusion, it is very important to detect network traffic.

[0003] In traditional technology, when detecting network traffic, predefined signatures are generally used to obtain network traffic detection results; however, detection methods based on predefined signatures are difficult to cope with the ever-evolving attack patterns, resulting in low accuracy of the detection results, which in turn leads to low accuracy of network traffic detection. Summary of the Invention

[0004] Based on this, it is necessary to provide a network traffic detection method, device, computer equipment, computer-readable storage medium and computer program product that can improve the accuracy of network traffic detection in response to the above technical problems.

[0005] In a first aspect, the present application provides a network traffic detection method, comprising:

[0006] Obtain the network traffic data to be detected;

[0007] Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data;

[0008] The network traffic data is classified and processed according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and a detection result of the network traffic data is obtained based on the classification result.

[0009] In one embodiment,

[0010] The pre-trained network traffic detection model includes at least a gated recurrent unit and a neural Turing machine;

[0011] Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data includes:

[0012] Preprocessing the network traffic data to obtain preprocessed network traffic data;

[0013] Inputting the preprocessed network traffic data into the gated loop unit, and performing multiple feature extraction processes on the preprocessed network traffic data through the gated loop unit to obtain a first traffic feature of the network traffic data;

[0014] The first traffic feature is input into the neural Turing machine, and the neural Turing machine queries a pre-stored memory matrix based on the first traffic feature to obtain a second traffic feature of the network traffic data; the memory matrix stores long-term dependency information of the network traffic. In one embodiment, the querying of a pre-stored memory matrix based on the first traffic feature by the neural Turing machine to obtain the second traffic feature of the network traffic data includes:

[0015] generating, by the neural Turing machine, a reading vector corresponding to the first traffic feature;

[0016] Determining, based on the read vector, an attention weight of a row vector of each row in a pre-stored memory matrix;

[0017] According to the attention weight of the row vector of each row, the row vector of each row is fused to obtain a read output result corresponding to the read vector;

[0018] Based on the read output result, a second traffic feature of the network traffic data is obtained.

[0019] In one embodiment, after inputting the network traffic data into the gated loop unit and performing multiple feature extraction processes on the network traffic data by the gated loop unit to obtain the first traffic feature of the network traffic data, the method further includes:

[0020] Generating a write vector and an erase vector corresponding to the first traffic feature by the neural Turing machine;

[0021] A pre-stored memory matrix is ​​updated according to the write vector and the erase vector.

[0022] In one embodiment, classifying the network traffic data according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data includes:

[0023] fusing the first traffic feature and the second traffic feature to obtain a fused traffic feature of the network traffic data;

[0024] Performing feature extraction again on the fused traffic features to obtain target traffic features of the network traffic data;

[0025] Based on the target traffic characteristics, the network traffic data is classified and processed to obtain a classification result of the network traffic data.

[0026] In one embodiment, the classifying the network traffic data based on the target traffic characteristics to obtain the classification result of the network traffic data includes:

[0027] Determining the predicted probability of the network traffic data under each preset traffic type based on the target traffic characteristics;

[0028] Filtering out the preset traffic type with the highest predicted probability from the preset traffic types;

[0029] Based on the preset traffic type with the highest prediction probability, a classification result of the network traffic data is obtained.

[0030] In one embodiment, the pre-trained network traffic detection model is trained in the following manner:

[0031] Obtaining sample network traffic data and actual classification results of the sample network traffic data;

[0032] Preprocessing the sample network traffic data to obtain preprocessed sample network traffic data;

[0033] Inputting the preprocessed network traffic data into a network traffic detection model to be trained to obtain a first traffic feature and a second traffic feature of the sample network traffic data;

[0034] Classify the sample network traffic data according to the first traffic feature and the second traffic feature of the sample network traffic data to obtain a classification result of the sample network traffic data;

[0035] According to the difference between the classification result of the sample network traffic data and the actual classification result, the network traffic detection model to be trained is iteratively trained to obtain the pre-trained network traffic detection model.

[0036] In a second aspect, the present application further provides a network traffic detection device, comprising:

[0037] A data acquisition module is used to obtain network traffic data to be detected;

[0038] a feature extraction module, configured to input the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data;

[0039] The classification processing module is used to classify the network traffic data according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and obtain a detection result of the network traffic data based on the classification result.

[0040] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0041] Obtain the network traffic data to be detected;

[0042] Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data;

[0043] The network traffic data is classified and processed according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and a detection result of the network traffic data is obtained based on the classification result.

[0044] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:

[0045] Obtain the network traffic data to be detected;

[0046] Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data;

[0047] The network traffic data is classified and processed according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and a detection result of the network traffic data is obtained based on the classification result.

[0048] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the following steps:

[0049] Obtain the network traffic data to be detected;

[0050] Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data;

[0051] The network traffic data is classified and processed according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and a detection result of the network traffic data is obtained based on the classification result.

[0052] The above-mentioned network traffic detection method, device, computer equipment, computer-readable storage medium and computer program product obtain the network traffic data to be detected, and then input the network traffic data into a pre-trained network traffic detection model to obtain the first traffic feature and the second traffic feature of the network traffic data; the first traffic feature is used to characterize the short-term dependency information of the network traffic data, and the second traffic feature is used to characterize the long-term dependency information of the network traffic data; finally, according to the first traffic feature and the second traffic feature, the network traffic data is classified and processed to obtain the classification result of the network traffic data, and the detection result of the network traffic data is obtained based on the classification result. In this way, when performing network traffic detection, the short-term dependency information of the network traffic data is captured by extracting the first traffic feature of the network traffic data, and the long-term dependency information of the network traffic data is captured by extracting the second traffic feature of the network traffic data, thereby achieving the purpose of simultaneously capturing the short-term dependency information and the long-term dependency information of the network traffic data, and the two form complementary advantages; moreover, based on the short-term dependency information and the long-term dependency information of the network traffic data, when detecting the network traffic data, it is possible to discover sudden signs of new attacks through the short-term dependency information, and to correlate the attack behaviors at different stages with the help of the long-term dependency information, thereby comprehensively covering the dynamic characteristics of complex attacks in the time dimension. Even the constantly evolving attack pattern can expose its abnormal nature in the long-short time correlation analysis, thereby achieving the purpose of effectively detecting the constantly evolving attack pattern, even the complex and constantly evolving attack pattern, making the final detection result more accurate, thereby improving the accuracy of network traffic detection, and avoiding the defect that the detection method based on predefined signatures is difficult to cope with the constantly evolving attack pattern, resulting in a low accuracy rate of the obtained detection result. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.

[0054] Figure 1 A diagram showing an application environment of a network traffic detection method according to an embodiment;

[0055] Figure 2 A flowchart illustrating steps of obtaining a first flow characteristic and a second flow characteristic of network flow data in one embodiment;

[0056] Figure 3 A flowchart of steps for obtaining classification results of network traffic data in one embodiment;

[0057] Figure 4 1 is a flow chart of a network traffic detection method according to another embodiment;

[0058] Figure 5 1 is a flow chart of a network intrusion detection method based on a hybrid deep learning model in one embodiment;

[0059] Figure 6 is a structural block diagram of a network traffic detection device in one embodiment;

[0060] Figure 7 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0061] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0062] In the field of network security, denial of service (DoS) and distributed denial of service (DDoS) attack detection has always been a very challenging key issue. Traditional detection methods rely on predefined signatures and are difficult to cope with evolving attack patterns, while existing machine learning methods are insufficient in processing the temporal characteristics and long-term memory of network traffic. Based on this, the present application proposes a network traffic detection method, specifically a hybrid deep learning model GM that combines a gated recurrent unit (GRU) and a neural Turing machine (NTM) to enhance intrusion detection capabilities. The model uses the GRU layer to process sequential data and capture short-term dependencies in network traffic; the NTM relies on its external memory matrix and read-write head mechanism to achieve long-term pattern recognition and effectively detect complex and evolving attack patterns.

[0063] In an exemplary embodiment, Figure 1 As shown, a network traffic detection method is provided. This embodiment uses the method applied to a terminal as an example. It is understood that the method can also be applied to a server, or to a system including a terminal and a server, and implemented through interaction between the terminal and the server. The terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, etc. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0064] In this embodiment, the following steps are included from step S101 to step S103, wherein:

[0065] Step S101: Acquire network traffic data to be detected.

[0066] The network traffic data to be detected refers to the network traffic data that currently needs to be detected, and can be various types of unknown network traffic data, such as encrypted network traffic data, unencrypted network traffic data, etc.

[0067] For example, the terminal obtains the unknown network traffic data in transmission and uses the unknown network traffic data in transmission as the network traffic data to be detected. Of course, the terminal can also obtain the network traffic data to be detected from a local database.

[0068] In step S102, the network traffic data is input into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize the short-term dependency information of the network traffic data, and the second traffic feature is used to characterize the long-term dependency information of the network traffic data.

[0069] Among them, the pre-trained network traffic detection model is a hybrid model used to extract the first traffic feature and the second traffic feature of the network traffic data, and identify the classification results of the network traffic data based on the first traffic feature and the second traffic feature of the network traffic data, such as a hybrid deep learning model, a hybrid neural network model, a hybrid machine learning model, etc.

[0070] Among them, the first traffic feature refers to the traffic feature used to characterize the short-term dependency information of network traffic data. Specifically, it is a set of micro-features that reflect the instantaneous dynamic changes of traffic within a time window of seconds, minutes or hours, such as the number of requests, the proportion of high-frequency IPs, the proportion of page visits, a sudden increase or decrease in traffic rate in a short period of time (such as a port suddenly receiving tens of thousands of requests within 10 seconds), abnormal timing intervals between adjacent data packets (such as a sudden reduction in time intervals caused by high-frequency short connections), instantaneous distortion of protocol interaction patterns (such as the high frequency of malformed URIs in HTTP requests), sudden access behavior of source / destination IPs and ports (such as a single IP trying to connect to thousands of different ports within minutes), and unexpected distribution of data packet sizes (such as intensive transmission of a large number of abnormally small data packets).

[0071] Among them, short-term dependency information of network traffic data refers to the short-term dependencies and patterns of network traffic data, specifically referring to traffic time series correlations at the second, minute, or hour level. Examples include a surge in the number of requests within a given second, a surge in the proportion of high-frequency IP addresses, high-frequency IP requests for multiple consecutive seconds, sudden changes in traffic rate, number of connections, and packet size within adjacent time windows, abnormal request patterns for specific protocols (such as HTTP and DNS) (such as high-frequency short connections and malformed packets), and burst access patterns of source / destination IP addresses and ports (such as traffic surges in DDoS attacks). It should be noted that even if attack patterns are constantly evolving, their launch is often accompanied by short-term anomalies in traffic characteristics. Short-term dependency analysis can detect such "unexpected changes" through real-time monitoring. Moreover, complex attacks are often carried out in stages, with different short-term traffic characteristics in each stage. Short-term dependency modeling can identify the current attack steps.

[0072] Among them, the second traffic feature refers to the traffic feature used to characterize the long-term dependent information of network traffic data, specifically a set of macro-features that reflect the historical evolution of traffic within the hourly, daily or weekly time windows. For example, at 8 pm every Friday, normal traffic will have a periodic small peak, a gradual shift of the traffic baseline over a long period of time (such as the average daily traffic of a server group has steadily increased by 15% for a week), a periodic fluctuation pattern (such as the traffic peak at a fixed time on the 1st of each month), the statistical characteristics of historical connection relationships (such as a certain IP frequently attempting to connect to a specific high-risk port in the past 30 days), long-term changes in the proportion of protocol usage (such as the UDP traffic share has continued to climb from the usual 20% to 45%), and the correlation of abnormal behaviors across time periods (such as similar abnormal login requests occurring in the same time period on different dates).

[0073] Long-term dependency information in network traffic data refers to the long-term dependencies and patterns in network traffic data. Specifically, it refers to historical correlations in traffic at the hourly, daily, or weekly levels. Examples include changes in traffic baselines over several days (e.g., the periodic patterns of normal business traffic), statistical characteristics of historical connection patterns (e.g., the access frequency of a particular IP address within a week, the gradual shift in protocol distribution), and cross-period anomaly correlations (e.g., similar attack attempts within the same time period on different dates). It should be noted that some attacks gradually infiltrate through long periods of latency, and their traffic characteristics may only vary slightly from day to day (e.g., a slowly increasing amount of data outbound). Long-term dependency analysis can identify these "trend anomalies" by comparing them to historical baselines. Some evolving attacks may employ "intermittent activity" strategies (e.g., launching attacks every Wednesday morning). Long-term dependency modeling can capture these temporal patterns and avoid under-detection by short-term analysis. The different stages of a complex attack chain may be separated by days or even months (e.g., the time difference between the reconnaissance and penetration stages). Long-term dependency analysis can identify such attacks by correlating characteristics of different stages with historical data (e.g., the same IP address performing a port scan two weeks ago suddenly attempts to exploit a vulnerability).

[0074] Exemplarily, the terminal inputs the network traffic data into a pre-trained network traffic detection model, and performs short-term dependency information extraction processing and long-term dependency information extraction processing on the network traffic data through the pre-trained network traffic detection model to obtain the short-term dependency information of the network traffic data and the long-term dependency information of the network traffic data, and then uses the short-term dependency information of the network traffic data as the first traffic feature of the network traffic data, and uses the long-term dependency information of the network traffic data as the second traffic feature of the network traffic data.

[0075] Step S103: classify the network traffic data according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and obtain a detection result of the network traffic data based on the classification result.

[0076] The classification result of the network traffic data refers to the traffic type of the network traffic data, such as normal traffic or abnormal traffic; abnormal traffic refers to denial of service (DoS), distributed denial of service (DDoS), etc. The classification result of the network traffic data is determined based on the first traffic feature and the second traffic feature.

[0077] The detection result of the network traffic data refers to the classification result of the network traffic data.

[0078] Exemplarily, the terminal determines the first weight of the first traffic feature and the second weight of the second traffic feature through a pre-trained network traffic detection model, and then fuses the first traffic feature and the second traffic feature according to the first weight of the first traffic feature and the second weight of the second traffic feature to obtain a fused traffic feature; then, based on the fused traffic feature, calculates multiple traffic types of network traffic data (such as normal, DoS and DDoS), as well as the predicted probability of each traffic type; then, selects the traffic type with the largest predicted probability as the classification result of the network traffic data; finally, the classification result of the network traffic data is used as the detection result of the network traffic data.

[0079] In the above-mentioned network traffic detection method, the network traffic data to be detected is obtained, and then the network traffic data is input into a pre-trained network traffic detection model to obtain the first traffic feature and the second traffic feature of the network traffic data; the first traffic feature is used to characterize the short-term dependency information of the network traffic data, and the second traffic feature is used to characterize the long-term dependency information of the network traffic data; finally, the network traffic data is classified and processed according to the first traffic feature and the second traffic feature to obtain the classification result of the network traffic data, and the detection result of the network traffic data is obtained based on the classification result. In this way, when performing network traffic detection, the short-term dependency information of the network traffic data is captured by extracting the first traffic feature of the network traffic data, and the long-term dependency information of the network traffic data is captured by extracting the second traffic feature of the network traffic data, thereby achieving the purpose of simultaneously capturing the short-term dependency information and the long-term dependency information of the network traffic data, and the two form complementary advantages; moreover, based on the short-term dependency information and the long-term dependency information of the network traffic data, when detecting the network traffic data, it is possible to discover sudden signs of new attacks through the short-term dependency information, and to correlate the attack behaviors at different stages with the help of the long-term dependency information, thereby comprehensively covering the dynamic characteristics of complex attacks in the time dimension. Even the constantly evolving attack pattern can expose its abnormal nature in the long-short time correlation analysis, thereby achieving the purpose of effectively detecting the constantly evolving attack pattern, even the complex and constantly evolving attack pattern, making the final detection result more accurate, thereby improving the accuracy of network traffic detection, and avoiding the defect that the detection method based on predefined signatures is difficult to cope with the constantly evolving attack pattern, resulting in a low accuracy rate of the obtained detection result.

[0080] In an exemplary embodiment, Figure 2 As shown, the above step S102, inputting the network traffic data into the pre-trained network traffic detection model to obtain the first traffic feature and the second traffic feature of the network traffic data, includes the following steps S201 to S203. Among them:

[0081] Step S201 , preprocessing the network traffic data to obtain preprocessed network traffic data.

[0082] In step S202 , the pre-processed network traffic data is input into a gated loop unit, and the gated loop unit performs multiple feature extraction processes on the pre-processed network traffic data to obtain a first traffic feature of the network traffic data.

[0083] In step S203, the first traffic feature is input into the neural Turing machine, and the neural Turing machine queries a pre-stored memory matrix based on the first traffic feature to obtain a second traffic feature of the network traffic data; the memory matrix stores long-term dependency information of the network traffic.

[0084] The pre-trained network traffic detection model includes at least a gated recurrent unit and a neural Turing machine. Of course, the pre-trained network traffic detection model may also include a fully connected layer (Dense layer) and an output layer, as shown in the figure.

[0085] The pre-processed network traffic data refers to network traffic data that is normalized and structured according to a suitable time window (such as 1 second, 5 seconds, etc.).

[0086] Among them, the gated recurrent unit can perform multiple feature extraction processes, such as performing two feature extraction processes; wherein, the first feature extraction process (through Figure 5 The second feature extraction process (through the GRU layer 1 in the network flow data) is used to process the network flow data in sequence to capture the original short-term dependencies and patterns in the network flow data, such as capturing the short-term anomalies of "sudden increase in the number of requests" and "surge in the proportion of high-frequency IP addresses". Figure 5 ) is used to further extract temporal dependencies, thereby obtaining refined short-term dependencies and patterns. This is to further abstract and semantically refine these short-term dependencies and patterns to enhance the network traffic detection model's understanding of sequence data, such as identifying "continuous high-frequency IP request" patterns. Moreover, the gating mechanism of the gated recurrent unit determines whether to retain or forget information by resetting the gate and updating the gate, effectively solving the gradient vanishing and exploding problems and stably transferring gradients in long sequences. For example, refer to Figure 5 ,The gated recurrent unit includes two layers of networks, namely layer 1 and layer 2. Layer 1 includes 64 units, which is used to process network traffic data in sequence to capture the original short-term dependencies and patterns in the network traffic data. Layer 2 includes 32 units, which is used to further refine the temporal dependencies, thereby obtaining the refined short-term dependencies and patterns.

[0087] The neural Turing machine includes a controller (implemented by the GRU layer), an external memory matrix (stored in the Memory), and a read / write head. Figure 5 The memory matrix stores long-term dependency information of network traffic and interacts with the GRU layer through read and write operations. During read operations, the controller generates a read vector to query the memory matrix and calculate the attention weight to obtain the read output. During write operations, the controller generates a write vector and an erase vector to update the memory content of the matrix to adapt to the ever-changing attack pattern.

[0088] The memory matrix is ​​stored in the Neural Turing Machine's memory and is specifically used to store long-term network traffic dependency information. Different rows in the memory matrix represent different long-term network traffic dependency information. Long-term network traffic dependency information refers to long-term dependency information calculated by combining network traffic data from historical time periods. It is used to reflect the historical evolution of traffic. For example, normal traffic has a periodic small peak at 8 pm every Friday night, the average daily traffic of a server group has steadily increased by 15% for a week, traffic peaks at a fixed time on the 1st of each month, a certain IP address has frequently attempted to connect to a specific high-risk port in the past 30 days, the proportion of UDP traffic has continued to climb from the normal 20% to 45%, and similar abnormal login requests appear at the same time on different days.

[0089] The second traffic feature of the network traffic data refers to the long-term dependency information corresponding to the first traffic feature.

[0090] Exemplarily, the terminal divides the network traffic data to be detected into blocks according to preset time windows (such as 1 second, 5 seconds, etc.) to obtain network traffic data of different time windows; then, the network traffic data of different time windows is subjected to feature extraction processing to obtain network traffic features of different time windows, such as the number of requests, the proportion of high-frequency IP addresses, the proportion of page visits, etc.; then, the network traffic features of different time windows are normalized to obtain normalized network traffic features of different time windows; then, the normalized network traffic features of different time windows are combined to obtain preprocessed network traffic data. Then, the terminal inputs the preprocessed network traffic data into the gated loop unit in the pre-trained network traffic detection model, and performs a first feature extraction process on the preprocessed network traffic data through the gated loop unit to obtain a first initial traffic feature of the network traffic data, which is used to represent the short-term dependencies and patterns of the network traffic data; then, the gated loop unit performs a second feature extraction process on the first initial traffic feature to obtain a first traffic feature of the network traffic data, which is used to represent the refined short-term dependencies and patterns of the network traffic data. Finally, the terminal inputs the first traffic feature into the neural Turing machine in the pre-trained network traffic detection model. Based on the first traffic feature, the neural Turing machine queries the pre-stored memory matrix to obtain the long-term dependency information corresponding to the first traffic feature as the second traffic feature of the network traffic data.

[0091] For example, refer to Figure 5, the network traffic data to be detected is received through the input layer, and then the network traffic data to be detected is input into layer 1 (64 units) of the GRU (gated recurrent unit) layer, and feature extraction processing is performed on the network traffic data to be detected through layer 1 to obtain the first initial traffic feature of the network traffic data; then, the first initial traffic feature of the network traffic data is input into layer 2 (32 units) of the GRU (gated recurrent unit) layer, and feature extraction processing is performed on the first initial traffic feature through layer 2 to obtain the first traffic feature of the network traffic data; finally, the first traffic feature of the network traffic data is input into the NTM (neural Turing machine) Layer, based on the first traffic feature, generates a reading vector corresponding to the first traffic feature through the NTM (neural Turing machine) layer; according to the reading vector, queries the memory matrix pre-stored in the memory, and calculates the attention weight of the row vector of each row in the pre-stored memory matrix; according to the attention weight of the row vector of each row, fuses the row vector of each row to obtain a fused vector as the reading output result corresponding to the reading vector; uses the reading output result as the second traffic feature of the network traffic data, that is, outputs the first traffic feature through the GRU (gated recurrent unit) layer, and outputs the second traffic feature through the NTM (neural Turing machine) layer.

[0092] In this embodiment, the network traffic data is preprocessed to obtain preprocessed network traffic data, and then the preprocessed network traffic data is input into the gated loop unit. The gated loop unit performs multiple feature extraction processes on the preprocessed network traffic data to obtain a first traffic feature of the network traffic data. Finally, the first traffic feature is input into the neural Turing machine, and the neural Turing machine queries a pre-stored memory matrix based on the first traffic feature to obtain a second traffic feature of the network traffic data. In this way, the first traffic feature and the second traffic feature of the network traffic data are extracted by the gated loop unit and the neural Turing machine, which is conducive to simultaneously capturing short-term dependency information and long-term dependency information of the network traffic data. The two form complementary advantages, which is conducive to the subsequent discovery of sudden signs of new attacks through short-term dependency information, and can also use long-term dependency information to associate attack behaviors at different stages, thereby comprehensively covering the dynamic characteristics of complex attacks in the time dimension. Even a constantly evolving attack pattern can expose its abnormal nature in the long-short time correlation analysis, thereby achieving the purpose of effectively detecting constantly evolving attack patterns, even complex and constantly evolving attack patterns, thereby improving the accuracy of network traffic detection.

[0093] In an exemplary embodiment, the above step S203, based on the first traffic feature, queries the pre-stored memory matrix through the neural Turing machine to obtain the second traffic feature of the network traffic data, specifically including the following contents: generating a reading vector corresponding to the first traffic feature through the neural Turing machine; determining the attention weight of the row vector of each row in the pre-stored memory matrix according to the reading vector; fusing the row vector of each row according to the attention weight of the row vector of each row to obtain the reading output result corresponding to the reading vector; and obtaining the second traffic feature of the network traffic data based on the reading output result.

[0094] The read vector refers to a vector used to query the memory matrix, which is obtained by performing a linear transformation projection on the first traffic feature.

[0095] The attention weight of the row vector of each row is used to characterize the importance of the row vector of each row, which is specifically determined based on the similarity between the reading vector and the row vector of each row in the memory matrix.

[0096] The second traffic feature of the network traffic data refers to the read output result corresponding to the read vector.

[0097] Exemplarily, a linear transformation and projection process is performed on the first traffic feature through a neural Turing machine to obtain a reading vector corresponding to the first traffic feature, and then the similarity between the reading vector and the row vector of each row in a pre-stored memory matrix is ​​calculated, such as the cosine similarity; then, the similarity between the reading vector and the row vector of each row in the pre-stored memory matrix is ​​normalized to obtain the normalized similarity between the reading vector and the row vector of each row in the pre-stored memory matrix, which is used as the attention weight of the row vector of each row in the memory matrix; then, according to the attention weight of the row vector of each row, the row vector of each row is fused to obtain a fused vector as the read output result corresponding to the reading vector; finally, the read output result is used as the second traffic feature of the network traffic data.

[0098] In this embodiment, a reading vector corresponding to the first traffic feature is generated by a neural Turing machine; based on the reading vector, the attention weight of the row vector of each row in the pre-stored memory matrix is ​​determined; according to the attention weight of the row vector of each row, the row vector of each row is fused to obtain a reading output result corresponding to the reading vector; based on the reading output result, a second traffic feature of the network traffic data is obtained; in this way, the pre-stored memory matrix is ​​queried through the reading vector corresponding to the first traffic feature to obtain the second traffic feature of the network traffic data, which is beneficial for referring to the second traffic feature used to characterize the long-term dependency information of the network traffic data when subsequently detecting the network traffic data, so as to associate the attack behaviors in different stages with the help of the long-term dependency information, thereby fully covering the dynamic characteristics of complex attacks in the time dimension, which is beneficial for accurately identifying the traffic type of the network traffic data, thereby further improving the accuracy of network traffic detection.

[0099] In an exemplary embodiment, the above step S202, after inputting the network traffic data into the gated loop unit and performing multiple feature extraction processes on the network traffic data through the gated loop unit to obtain the first traffic feature of the network traffic data, also includes the step of updating the pre-stored memory matrix, specifically including the following contents: generating a write vector and an erase vector corresponding to the first traffic feature through a neural Turing machine; and updating the pre-stored memory matrix according to the write vector and the erase vector.

[0100] The write vector is used to represent the vector written to the memory matrix, such as the relevant vector of a new DDoS variant (such as distributed requests from a new region). It is used to determine what new features to store in order to update the memory matrix and allow the network traffic detection model to remember the pattern of this new attack so that it can recognize similar traffic next time it encounters it.

[0101] Among them, the erasure vector refers to the vector used to erase the relevant content in the memory matrix. It is used to decide which old content in the memory matrix to delete, such as deleting old and useless patterns to adapt to complex and evolving attack patterns.

[0102] Exemplarily, when a new DDoS variant is detected (such as a distributed request from a new region), the terminal performs a first conversion process on the first traffic feature through a neural Turing machine to obtain a write vector corresponding to the first traffic feature (i.e., the new feature to be stored), and performs a second conversion process on the first traffic feature to obtain an erase vector corresponding to the first traffic feature (i.e., deciding which old content in the memory matrix to delete); then, the memory matrix is ​​"erased" through the erase vector, such as weakening the old attack feature of a row in the memory matrix by a ratio of 0.3, or directly deleting the content of a row in the memory matrix; finally, the write vector is "added" to the corresponding position in the memory matrix to update the memory matrix.

[0103] In this embodiment, a neural Turing machine is used to generate a write vector and an erase vector corresponding to the first traffic feature, and then a pre-stored memory matrix is ​​updated based on the write vector and the erase vector, thereby achieving the purpose of timely updating the memory matrix, which is conducive to adapting to the ever-changing attack patterns, thereby improving the detection effect of the ever-evolving new attack patterns, further improving the accuracy of network traffic detection, and reducing the dependence on static data sets.

[0104] In an exemplary embodiment, Figure 3 As shown, the above step S103, based on the first flow feature and the second flow feature, classifies the network flow data to obtain the classification result of the network flow data, including the following steps S301 to S303.

[0105] Step S301: The first traffic feature and the second traffic feature are fused to obtain a fused traffic feature of the network traffic data.

[0106] Step S302: performing feature extraction processing on the fused traffic features again to obtain target traffic features of the network traffic data.

[0107] Step S303: classify the network traffic data based on the target traffic characteristics to obtain a classification result of the network traffic data.

[0108] The fused traffic feature includes a first traffic feature and a second traffic feature.

[0109] Among them, the fused traffic features are subjected to feature extraction again, mainly achieved through the fully connected layer, which is used for feature abstraction and nonlinear combination, reducing the dimension and promoting feature interaction, improving the ability of the network traffic detection model to detect complex patterns of network traffic, enhancing the effect of distinguishing normal, DoS and DDoS traffic, preventing overfitting, and improving the generalization ability of the network traffic detection model.

[0110] The target traffic feature may refer to the fused traffic feature after dimensionality reduction.

[0111] Exemplarily, the terminal determines the first weight of the first traffic feature and the second weight of the second traffic feature through a pre-trained network traffic detection model, and fuses the first traffic feature and the second traffic feature according to the first weight of the first traffic feature and the second weight of the second traffic feature to obtain a fused traffic feature of the network traffic data; then, the fused traffic feature is subjected to feature extraction again to obtain a fused traffic feature after dimensionality reduction as the fused traffic feature of the network traffic data; finally, based on the target traffic feature, the network traffic data is classified to obtain the traffic type corresponding to the target traffic feature as the classification result of the network traffic data.

[0112] In this embodiment, the first traffic feature and the second traffic feature are fused to obtain a fused traffic feature of the network traffic data, and then the fused traffic feature is subjected to feature extraction again to obtain a target traffic feature of the network traffic data. Finally, based on the target traffic feature, the network traffic data is classified to obtain a classification result of the network traffic data. In this way, when classifying the network traffic data, the target traffic feature obtained based on the first traffic feature and the second traffic feature is comprehensively considered, so that the purpose of the complex and evolving attack pattern can be effectively identified, so that the final detection result is more accurate, thereby improving the accuracy of network traffic detection.

[0113] In an exemplary embodiment, the above-mentioned step S303 classifies the network traffic data based on the target traffic characteristics to obtain the classification results of the network traffic data, which specifically include the following contents: based on the target traffic characteristics, determining the predicted probability of the network traffic data under each preset traffic type; from each preset traffic type, screening out the preset traffic type with the largest predicted probability; based on the preset traffic type with the largest predicted probability, obtaining the classification results of the network traffic data.

[0114] The preset traffic types include normal, DoS, and DDoS.

[0115] The sum of the predicted probabilities of network traffic data under each preset traffic type is 1.

[0116] Exemplarily, the terminal calculates the predicted probability of network traffic data under each preset traffic type based on the target traffic characteristics; then, from each preset traffic type, the preset traffic type with the highest predicted probability is screened out, for example, the predicted probabilities corresponding to normal, DoS, and DDoS are 0.1, 0.7, and 0.2, respectively, then the preset traffic type with the highest predicted probability refers to DoS; finally, the preset traffic type with the highest predicted probability is used as the classification result of the network traffic data, for example, the traffic type of the network traffic data is DoS.

[0117] For example, refer to Figure 5 After the GRU layer outputs the first traffic feature and the NTM layer outputs the second traffic feature, the first traffic feature and the second traffic feature are fused to obtain the fused traffic feature, and the fused traffic feature is input into the fully connected layer (16 units, ReLU). The fused traffic feature is abstracted and nonlinearly combined through the fully connected layer to obtain the target traffic feature; finally, the target traffic feature is input into the output layer (3 units, SoftMax). The target traffic feature is classified through the output layer to obtain the classification results (probability 1, probability 2, probability 3), corresponding to the three categories of normal, DoS and DDoS, that is, normal corresponds to probability 1, DoS corresponds to probability 2, and DDoS corresponds to probability 3, and the classification results are output.

[0118] In this embodiment, based on the target traffic characteristics, the predicted probability of network traffic data under each preset traffic type is determined; from each preset traffic type, the preset traffic type with the largest predicted probability is screened out as the classification result of the network traffic data; in this way, by predicting the predicted probability corresponding to each preset traffic type and determining the classification result of the network traffic data based on the predicted probability, it is beneficial to further improve the accuracy of network traffic detection.

[0119] In an exemplary embodiment, a pre-trained network traffic detection model is trained in the following manner: obtaining sample network traffic data and actual classification results of the sample network traffic data; pre-processing the sample network traffic data to obtain pre-processed sample network traffic data; inputting the pre-processed network traffic data into the network traffic detection model to be trained to obtain first traffic characteristics and second traffic characteristics of the sample network traffic data; classifying the sample network traffic data according to the first traffic characteristics and second traffic characteristics of the sample network traffic data to obtain classification results of the sample network traffic data; iteratively training the network traffic detection model to be trained according to the difference between the classification results of the sample network traffic data and the actual classification results to obtain a pre-trained network traffic detection model.

[0120] The sample network traffic data refers to the network traffic data used as training data.

[0121] The actual classification results of the sample network traffic data include normal, DoS, and DDoS.

[0122] Among them, the network traffic detection model to be trained can refer to a hybrid deep learning model, a hybrid machine learning model, etc.

[0123] Exemplarily, the terminal obtains sample network traffic data and actual classification results of the sample network traffic data from a local database or the network; then preprocesses the sample network traffic data to obtain preprocessed sample network traffic data; then inputs the preprocessed sample network traffic data into the network traffic detection model to be trained, performs multiple feature extraction processes on the preprocessed sample network traffic data through the gated loop unit in the network traffic detection model to be trained, and obtains the first traffic feature of the sample network traffic data; then inputs the first traffic feature of the sample network traffic data into the neural Turing machine in the network traffic detection model to be trained, and generates a first traffic feature of the sample network traffic data through the neural Turing machine. The method comprises the following steps: first, a read vector corresponding to a flow feature of the sample network traffic data is obtained; based on the read vector, an attention weight of a row vector of each row in a pre-stored memory matrix is ​​determined; according to the attention weight of the row vector of each row, the row vector of each row is fused to obtain a read output result corresponding to the read vector as a second flow feature of the sample network traffic data; then, the first flow feature and the second flow feature of the sample network traffic data are fused to obtain a fused flow feature of the sample network traffic data; the fused flow feature of the sample network traffic data is subjected to feature extraction again to obtain a target flow feature of the sample network traffic data; based on the target flow feature, the sample network traffic data is classified to obtain a classification result of the sample network traffic data. Finally, a loss value is calculated based on the difference between the classification result of the sample network traffic data and the actual classification result. If the loss value is greater than or equal to a preset threshold, the model parameters of the network traffic detection model to be trained are adjusted according to the loss value, and the above model training process is repeated until the loss value obtained based on the classification result output by the adjusted network traffic detection model is less than the preset threshold, then the model training is stopped, and the adjusted network traffic detection model is used as the pre-trained network traffic detection model.

[0124] In this embodiment, the network traffic detection model to be trained is iteratively trained using sample network traffic data and the actual classification results of the sample network traffic data to obtain a pre-trained network traffic detection model, which is beneficial to improving the accuracy of the network traffic data classification results output by the pre-trained network traffic detection model, thereby improving the accuracy of network traffic detection.

[0125] In an exemplary embodiment, Figure 4 As shown, another network traffic detection method is provided, which is described by taking the method applied to a terminal as an example, and includes the following steps S401 to S409. Among them:

[0126] Step S401: Acquire network traffic data to be detected.

[0127] Step S402: pre-process the network traffic data to obtain pre-processed network traffic data.

[0128] Step S403: input the pre-processed network traffic data into the gated loop unit in the pre-trained network traffic detection model, perform multiple feature extraction processes on the pre-processed network traffic data through the gated loop unit, and obtain the first traffic feature of the network traffic data.

[0129] The first traffic feature is used to characterize short-term dependency information of network traffic data.

[0130] Among them, the terminal can also obtain sample network traffic data and the actual classification results of the sample network traffic data; preprocess the sample network traffic data to obtain preprocessed sample network traffic data; input the preprocessed network traffic data into the network traffic detection model to be trained to obtain the first traffic feature and the second traffic feature of the sample network traffic data; classify the sample network traffic data according to the first traffic feature and the second traffic feature of the sample network traffic data to obtain the classification results of the sample network traffic data; according to the difference between the classification results of the sample network traffic data and the actual classification results, iteratively train the network traffic detection model to be trained to obtain a pre-trained network traffic detection model.

[0131] In step S404, the first traffic feature is input into a neural Turing machine in a pre-trained network traffic detection model, and a reading vector corresponding to the first traffic feature is generated by the neural Turing machine; based on the reading vector, the attention weight of the row vector of each row in the pre-stored memory matrix is ​​determined.

[0132] Among them, the memory matrix stores the long-term dependency information of network traffic.

[0133] In step S405 , the row vectors of each row are fused according to the attention weight of the row vectors of each row to obtain a read output result corresponding to the read vector; based on the read output result, a second traffic feature of the network traffic data is obtained.

[0134] The second traffic feature is used to characterize the long-term dependency information of network traffic data.

[0135] Among them, the terminal can also generate a write vector and an erase vector corresponding to the first traffic feature through a neural Turing machine; and update a pre-stored memory matrix according to the write vector and the erase vector.

[0136] Step S406: The first traffic feature and the second traffic feature are fused to obtain a fused traffic feature of the network traffic data.

[0137] Step S407: performing feature extraction processing on the fused traffic features again to obtain target traffic features of the network traffic data.

[0138] Step S408: Determine the predicted probability of network traffic data under each preset traffic type based on the target traffic characteristics.

[0139] Step S409 , screening out the preset traffic type with the highest predicted probability from the preset traffic types; and obtaining a classification result of the network traffic data based on the preset traffic type with the highest predicted probability.

[0140] In the above-mentioned network traffic detection method, when performing network traffic detection, the short-term dependency information of the network traffic data is captured by extracting the first traffic feature of the network traffic data, and the long-term dependency information of the network traffic data is captured by extracting the second traffic feature of the network traffic data, thereby achieving the purpose of simultaneously capturing the short-term dependency information and the long-term dependency information of the network traffic data, and the two form complementary advantages; moreover, based on the short-term dependency information and the long-term dependency information of the network traffic data, when detecting the network traffic data, it is possible to discover sudden signs of new attacks through the short-term dependency information, and to correlate attack behaviors at different stages with the help of the long-term dependency information, thereby comprehensively covering the dynamic characteristics of complex attacks in the time dimension. Even the continuously evolving attack pattern can expose its abnormal nature in the long-term and short-term correlation analysis, thereby achieving the purpose of effectively detecting the continuously evolving attack pattern, even the complex and continuously evolving attack pattern, making the final detection result more accurate, thereby improving the accuracy of network traffic detection, and avoiding the defect that the detection method based on predefined signatures is difficult to cope with the continuously evolving attack pattern, resulting in a low accuracy rate of the obtained detection result.

[0141] In order to more clearly illustrate the network traffic detection method provided by the embodiment of the present application, the network traffic detection method is specifically described below using a specific embodiment. In an exemplary embodiment, Figure 5 As shown, this application also provides a network intrusion detection method based on a hybrid deep learning model, the specific contents are as follows:

[0142] Traditional signature-based detection methods have difficulty dealing with new and evolving attack patterns, and existing models perform poorly in time series data processing and long-term memory, making it difficult to identify complex, time-dependent attack patterns. From the perspective of real-time and adaptability, the model needs to adapt to dynamic network environments and detect zero-day attacks and slow attacks. This application proposes a hybrid deep learning model GM that combines the advantages of gated recurrent units (GRUs) and neural Turing machines (NTMs) for detecting denial of service (DoS) and distributed denial of service (DDoS) attacks; Reference Figure 5 , its working principle and process are as follows:

[0143] 1. Data preprocessing involves segmenting, merging, and shuffling the data to balance normal, DoS, and DDoS samples. Min-Max scaling is used to normalize data features, mapping them to the 0-1 range to accelerate neural network convergence. One-hot encoding is used to convert classification labels into numerical format to facilitate model training.

[0144] 2. The input layer receives preprocessed network traffic data, which has been normalized and structured into appropriate time windows in preparation for subsequent processing. The GRU layer consists of two layers. GRU Layer 1, with 64 units, processes data sequentially, capturing short-term dependencies and patterns in the traffic data. GRU Layer 2, with 32 units, further refines temporal dependencies and enhances the model's understanding of sequential data. Its gating mechanism uses reset and update gates to determine whether to retain or forget information, effectively addressing the vanishing and exploding gradient problems and ensuring stable gradient propagation over long sequences.

[0145] 3. NTM layer: This layer consists of a controller (implemented by the GRU layer), an external memory matrix, and a read / write head. The external memory matrix stores long-term dependencies on network traffic and interacts with the GRU layer through read and write operations. During read operations, the controller generates a read vector to query the memory and calculate attention weights to obtain the read output. During write operations, the controller generates a write vector and an erase vector to update the memory content to adapt to changing attack patterns.

[0146] 4. Dense layer (fully connected layer): The data processed by GM enters the Dense layer with 16 units and uses the ReLU activation function. This layer performs feature abstraction and nonlinear combination, reduces dimensionality, and promotes feature interaction. This improves the model's ability to detect complex patterns in network traffic, enhances the ability to distinguish between normal, DoS, and DDoS traffic, prevents overfitting, and improves model generalization.

[0147] 5. Output layer: It consists of 3 units and uses the SoftMax activation function. It corresponds to the three categories of normal, DoS, and DDoS. The model outputs the probability distribution of each category to achieve the classification of network traffic.

[0148] 6. During the detection process, the model extracts packet features and analyzes them sequentially during real-time network traffic monitoring. The GRU layer captures short-term patterns, while the NTM layer identifies long-term dependencies, comprehensively determining whether the traffic is normal, DoS, or DDoS. Through data preprocessing, feature selection, hybrid architecture design, extensive training, and continuous verification and fine-tuning, we ensure high detection accuracy and reliability.

[0149] In addition, the network intrusion detection system involved in the method can be deployed in a new network element NWDAF (Network Data Analytics Function), specifically applied to core network security monitoring, network security management and content filtering.

[0150] For example, regarding network security, the 5G core network connects a vast number of devices and users, facing severe security challenges such as hacker attacks and data leaks. The GM model monitors 5G core network traffic in real time, enabling timely detection of DoS and DDoS attacks. By learning from large amounts of network traffic data, the model can accurately distinguish between normal and abnormal traffic, such as identifying malicious attacks disguised as normal traffic. This ensures stable network operation and prevents service interruptions and data leaks.

[0151] For example, in network slicing management, the 5G core network uses network slicing to meet diverse service needs, such as industrial control and high-definition video. Each slice has specific performance requirements, requiring rational resource allocation and management. The GM model analyzes traffic patterns and resource usage within each slice, predicting resource demand and helping operators dynamically adjust resource allocation. For example, in the industrial control slice, the model predicts upcoming traffic peaks and allocates more resources in advance, ensuring low latency and high reliability of data transmission.

[0152] The above embodiments can achieve the following technical effects: (1) Through time series and long-term dependency processing, it can simultaneously capture short-term traffic anomalies and long-term attack patterns, that is, GRU processes short-term dependencies and NTM manages long-term memory, forming complementary advantages; (2) Through the memory mechanism of NTM, the model can adapt to new attack patterns or new attack strategies through memory updates, reduce dependence on static data sets, and solve the problem of insufficient detection of new attacks by traditional models.

[0153] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of the steps or stages in other steps or other steps. It is understandable that the various steps in different embodiments can be freely combined as needed, and the various non-contradictory schemes formed by the combination all fall within the scope of protection of this application.

[0154] Based on the same inventive concept, embodiments of the present application also provide a network traffic detection device for implementing the aforementioned network traffic detection method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations in one or more network traffic detection device embodiments provided below can be found in the above-mentioned limitations on the network traffic detection method and will not be further elaborated here.

[0155] In an exemplary embodiment, Figure 6 As shown, a network traffic detection device is provided, including: a data acquisition module 610, a feature extraction module 620 and a classification processing module 630, wherein:

[0156] The data acquisition module 610 is used to acquire the network traffic data to be detected.

[0157] The feature extraction module 620 is used to input the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize the short-term dependency information of the network traffic data, and the second traffic feature is used to characterize the long-term dependency information of the network traffic data.

[0158] The classification processing module 630 is used to classify the network traffic data according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and obtain a detection result of the network traffic data based on the classification result.

[0159] In an exemplary embodiment, the pre-trained network traffic detection model includes at least a gated recurrent unit and a neural Turing machine;

[0160] The feature extraction module 620 is also used to preprocess the network traffic data to obtain preprocessed network traffic data; input the preprocessed network traffic data into the gated loop unit, and perform multiple feature extraction processes on the preprocessed network traffic data through the gated loop unit to obtain a first traffic feature of the network traffic data; input the first traffic feature into the neural Turing machine, and query the pre-stored memory matrix based on the first traffic feature through the neural Turing machine to obtain a second traffic feature of the network traffic data; the memory matrix stores long-term dependency information of the network traffic.

[0161] In an exemplary embodiment, the feature extraction module 620 is also used to generate a reading vector corresponding to the first traffic feature through a neural Turing machine; determine the attention weight of the row vector of each row in a pre-stored memory matrix based on the reading vector; perform fusion processing on the row vector of each row according to the attention weight of the row vector of each row to obtain a reading output result corresponding to the reading vector; and obtain a second traffic feature of the network traffic data based on the reading output result.

[0162] In an exemplary embodiment, the network traffic detection device provided in the present application also includes a matrix update module for generating a write vector and an erase vector corresponding to the first traffic feature through a neural Turing machine; and updating a pre-stored memory matrix according to the write vector and the erase vector.

[0163] In an exemplary embodiment, the classification processing module 630 is also used to fuse the first traffic feature and the second traffic feature to obtain a fused traffic feature of the network traffic data; perform feature extraction on the fused traffic feature again to obtain a target traffic feature of the network traffic data; and perform classification processing on the network traffic data based on the target traffic feature to obtain a classification result of the network traffic data.

[0164] In an exemplary embodiment, the classification processing module 630 is also used to determine the predicted probability of network traffic data under each preset traffic type based on the target traffic characteristics; filter out the preset traffic type with the highest predicted probability from each preset traffic type; and obtain the classification result of the network traffic data based on the preset traffic type with the highest predicted probability.

[0165] In an exemplary embodiment, the network traffic detection device provided by the present application also includes a model training module for obtaining sample network traffic data and actual classification results of the sample network traffic data; preprocessing the sample network traffic data to obtain preprocessed sample network traffic data; inputting the preprocessed network traffic data into the network traffic detection model to be trained to obtain the first traffic feature and the second traffic feature of the sample network traffic data; classifying the sample network traffic data according to the first traffic feature and the second traffic feature of the sample network traffic data to obtain the classification results of the sample network traffic data; iteratively training the network traffic detection model to be trained according to the difference between the classification results of the sample network traffic data and the actual classification results to obtain a pre-trained network traffic detection model.

[0166] Each module in the aforementioned network traffic detection device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0167] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 7As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected via a system bus, and the communication interface, the display unit and the input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a mobile cellular network, near field communication (NFC) or other technologies. When the computer program is executed by the processor, a network traffic detection method is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.

[0168] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0169] In an exemplary embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0170] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0171] In an exemplary embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0172] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0173] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile memory and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a programmable logic unit (PLC), a data processing logic unit based on quantum computing, an artificial intelligence (AI) processor, and the like.

[0174] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0175] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A network traffic detection method, characterized in that: The method comprises: Obtain the network traffic data to be detected; Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data; The network traffic data is classified and processed according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and a detection result of the network traffic data is obtained based on the classification result.

2. The method according to claim 1, characterized in that The pre-trained network traffic detection model includes at least a gated recurrent unit and a neural Turing machine; Inputting the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data includes: Preprocessing the network traffic data to obtain preprocessed network traffic data; Inputting the preprocessed network traffic data into the gated loop unit, and performing multiple feature extraction processes on the preprocessed network traffic data through the gated loop unit to obtain a first traffic feature of the network traffic data; The first traffic feature is input into the neural Turing machine, and the neural Turing machine queries a pre-stored memory matrix based on the first traffic feature to obtain a second traffic feature of the network traffic data; the memory matrix stores long-term dependency information of the network traffic.

3. The method according to claim 2, characterized in that The step of querying a pre-stored memory matrix based on the first traffic feature by the neural Turing machine to obtain a second traffic feature of the network traffic data includes: generating, by the neural Turing machine, a reading vector corresponding to the first traffic feature; Determining, based on the read vector, an attention weight of a row vector of each row in a pre-stored memory matrix; According to the attention weight of the row vector of each row, the row vector of each row is fused to obtain a read output result corresponding to the read vector; Based on the read output result, a second traffic feature of the network traffic data is obtained.

4. The method according to claim 2, characterized in that After inputting the network traffic data into the gated loop unit and performing multiple feature extraction processes on the network traffic data by the gated loop unit to obtain a first traffic feature of the network traffic data, the method further includes: Generating a write vector and an erase vector corresponding to the first traffic feature by the neural Turing machine; A pre-stored memory matrix is ​​updated according to the write vector and the erase vector.

5. The method according to claim 1, wherein The classifying the network traffic data according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data includes: fusing the first traffic feature and the second traffic feature to obtain a fused traffic feature of the network traffic data; Performing feature extraction again on the fused traffic features to obtain target traffic features of the network traffic data; Based on the target traffic characteristics, the network traffic data is classified and processed to obtain a classification result of the network traffic data.

6. The method according to claim 5, characterized in that The classifying and processing the network traffic data based on the target traffic characteristics to obtain the classification result of the network traffic data includes: Determining the predicted probability of the network traffic data under each preset traffic type based on the target traffic characteristics; Filtering out the preset traffic type with the highest predicted probability from the preset traffic types; Based on the preset traffic type with the highest prediction probability, a classification result of the network traffic data is obtained.

7. The method according to any one of claims 1 to 6, characterized in that The pre-trained network traffic detection model is trained in the following way: Obtaining sample network traffic data and actual classification results of the sample network traffic data; Preprocessing the sample network traffic data to obtain preprocessed sample network traffic data; Inputting the preprocessed network traffic data into a network traffic detection model to be trained to obtain a first traffic feature and a second traffic feature of the sample network traffic data; Classify the sample network traffic data according to the first traffic feature and the second traffic feature of the sample network traffic data to obtain a classification result of the sample network traffic data; According to the difference between the classification result of the sample network traffic data and the actual classification result, the network traffic detection model to be trained is iteratively trained to obtain the pre-trained network traffic detection model.

8. A network traffic detection device, characterized in that: The device comprises: A data acquisition module is used to obtain network traffic data to be detected; a feature extraction module, configured to input the network traffic data into a pre-trained network traffic detection model to obtain a first traffic feature and a second traffic feature of the network traffic data; the first traffic feature is used to characterize short-term dependency information of the network traffic data, and the second traffic feature is used to characterize long-term dependency information of the network traffic data; The classification processing module is used to classify the network traffic data according to the first traffic feature and the second traffic feature to obtain a classification result of the network traffic data, and obtain a detection result of the network traffic data based on the classification result.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.