Intrusion detection method, system and equipment based on zero sample learning and medium
By employing a zero-shot learning-based intrusion detection method, and utilizing multi-source data and coupled autoencoders and graph convolutional neural networks to establish feature-semantic space mapping, the problem of detecting unknown attacks in existing technologies is solved, and efficient detection of diverse attacks in cloud network environments is achieved.
Patent Information
- Application Number
- CN202511350211.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-09-22
AI Technical Summary
Existing intrusion detection technologies are ill-equipped to handle the diverse and ever-changing attack scenarios in cloud network environments, especially unknown attack patterns, making systems vulnerable to zero-day vulnerability attacks.
We adopt a zero-shot learning-based intrusion detection method. By constructing a zero-shot learning model, we extract known intrusion category features from multi-source raw data, establish a mapping between the feature space and the semantic space, and combine coupled autoencoders and graph convolutional neural networks to realize the mapping between known intrusion category features and unknown intrusion category semantic space.
It improves the detection accuracy for unknown attack categories, adapts to different types and variations of intrusion behavior, alleviates the problem of sample distribution divergence, and enhances the model's generalization ability and detection accuracy.
Smart Images

Figure CN120850302A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intrusion detection technology, and in particular to an intrusion detection method, system, device, and medium based on zero-shot learning. Background Technology
[0002] Traditional intrusion detection technologies typically rely on machine learning and deep learning methods. They train models using features of known attack methods to match captured abnormal traffic with known attack characteristics, ultimately identifying attack data and its attack type.
[0003] However, existing intrusion detection models based on abnormal traffic can only detect a very limited number of attack types, which is insufficient to cope with the increasingly diverse and ever-changing attack landscape in cloud network environments. Furthermore, they often can only detect known attack patterns, making the system vulnerable to zero-day vulnerability attacks. Summary of the Invention
[0004] The present invention aims to provide an intrusion detection method, system, device, and medium based on zero-shot learning, which can adapt to different types and changing intrusion behaviors, alleviate the problem of sample distribution divergence, and effectively improve the reliability of zero-shot migration and the detection accuracy for unknown attack categories.
[0005] In a first aspect, embodiments of the present invention provide an intrusion detection method based on zero-shot learning, comprising: Based on the known intrusion categories, collect raw data from multiple sources, extract features of the known intrusion categories from the raw data from the multiple sources, and generate a training sample set. A zero-shot learning model is constructed, wherein the zero-shot learning model establishes a mapping between the feature space and the semantic space through an intrusion scenario knowledge graph based on word vectors; the hidden layer of the zero-shot learning model is equipped with a coupled autoencoder; the coupled autoencoder includes a jointly learned known intrusion category autoencoder and an unknown intrusion category autoencoder. The zero-shot learning model is trained using the training sample set to learn the mapping logic between the known intrusion category features and the word vectors, and the mapping logic is transferred to the semantic space of unknown intrusion categories. Real-time data is input into the trained zero-shot learning model to obtain the intrusion category of the real-time data.
[0006] As an improvement to the above scheme, the multi-source raw data includes network traffic data, log data, configuration data, authentication data, abnormal behavior data, and system performance data.
[0007] As an improvement to the above scheme, the step of collecting multi-source raw data based on known intrusion categories, extracting known intrusion category features from the multi-source raw data, and generating a training sample set includes: Collect raw data from multiple sources based on known intrusion categories; Features associated with known intrusion categories are extracted from the multi-source raw data, and the features are converted into binary vectors to form an initial feature set. The correlation between features in the initial feature set is calculated using the Pearson correlation coefficient. Based on the correlation, feature fusion is performed to obtain known intrusion category features.
[0008] As an improvement to the above scheme, the input of the coupled autoencoder is a first feature matrix of known intrusion categories, a first semantic attribute matrix of known intrusion categories, and a second feature matrix of unknown intrusion categories; Based on the first feature matrix and the first semantic attribute matrix, a first mapping matrix for known intrusion categories is obtained through a known intrusion category autoencoder; Based on the first mapping matrix, initialize the second mapping matrix for unknown intrusion categories; Based on the second mapping matrix and the second feature matrix, the second semantic attribute matrix of the unknown intrusion category is obtained through the unknown intrusion category autoencoder; The first mapping matrix, the second mapping matrix, and the second semantic attribute matrix are updated until the zero-shot learning model converges.
[0009] As an improvement to the above scheme, the construction of a zero-shot learning model, which establishes a mapping between the feature space and the semantic space through a knowledge graph of intrusion scenarios based on word vectors, includes: Establish a tag set to form a tag space; the tags in the tag set are bound to intrusion categories. Based on the general knowledge graph and the tag set, an intrusion scenario knowledge graph is established with word vectors as node attributes, forming a semantic space; A feature extraction module is constructed to extract attack features from the input data, forming a feature space; Based on the intrusion scenario knowledge graph, a graph convolutional neural network is established to map the feature space to the semantic space and output a semantic category weight matrix; the semantic category weight matrix represents the semantic association strength between the input data and each intrusion category. Construct a classifier to output the classification result of the intrusion category based on the semantic category weight matrix; A zero-shot learning model is obtained based on the tag set, the intrusion scenario knowledge graph, the feature extraction module, the graph convolutional neural network, and the classifier.
[0010] As an improvement to the above scheme, the step of establishing an intrusion scenario knowledge graph with word vectors as node attributes based on the general knowledge graph and the tag set, forming a semantic space, includes: Based on the general semantic classification knowledge graph and the tag set, known intrusion category nodes, unknown intrusion category nodes, and associated element nodes are defined to form a first knowledge graph subset; Obtain the word vectors of the intrusion category, and embed the word vectors as node attributes into the first knowledge graph subset to obtain the second knowledge graph subset; A general scenario-related knowledge graph is adopted. Based on the first knowledge graph subset and the second knowledge graph subset, an intrusion scenario knowledge graph is obtained to form a semantic space.
[0011] As an improvement to the above scheme, the step of establishing a graph convolutional neural network based on the intrusion scenario knowledge graph to map the feature space to the semantic space and output a semantic category weight matrix includes: Obtain an intrusion scenario knowledge graph and establish a graph convolutional neural network, wherein the nodes of the graph convolutional neural network correspond to the nodes of the intrusion scenario knowledge graph; The output of the feature extraction module is connected to the graph convolutional neural network, so that the graph convolutional neural network fuses neighbor features into the nodes based on the output of the feature extraction module; The graph convolutional neural network outputs a semantic category weight matrix through several layers of iteration; the elements in the semantic category weight matrix represent the semantic correlation between the features of the input data and the nodes in the intrusion scenario knowledge graph.
[0012] As an improvement to the above scheme, the classifier adopts a direct attribute prediction model. The classifier includes several sub-classifiers, the number of which is consistent with the number of semantic attributes. These sub-classifiers are used to calculate the association probability between semantic attributes and labels. The classifier obtains the target label based on the association probability calculated by each sub-classifier.
[0013] As an improvement to the above scheme, the step of training the zero-shot learning model using the training sample set, learning the mapping logic between the known intrusion category features and the word vectors, and transferring the mapping logic to the semantic space of unknown intrusion categories includes: The training sample set is input into the constructed zero-shot learning model. Based on the intrusion scenario knowledge graph, the mapping logic between the known intrusion category features and the word vectors is learned, and the semantic association of nodes in the intrusion scenario knowledge graph is obtained. Based on the semantic correlation, the mapping logic is transferred to unknown intrusion categories, so that the trained zero-shot learning model can perform semantic space mapping on the input data and achieve intrusion category classification.
[0014] As an improvement to the above scheme, before inputting real-time data into the trained zero-shot learning model to obtain the intrusion category of the real-time data, the zero-shot learning-based intrusion detection method further includes: The trained zero-shot learning model was migrated to a cloud environment to test its ability to detect unknown intrusion categories. The parameters of the zero-shot learning model are updated based on the test results.
[0015] As an improvement to the above scheme, updating the parameters of the zero-shot learning model based on the test results includes: Undetected network attacks of unknown intrusion types were filtered from the test results, and the original data and attack chain of the network attacks were obtained through source tracing analysis. The training sample set is updated based on the original data and the attack chain to incrementally train the zero-shot learning model.
[0016] Secondly, embodiments of the present invention provide an intrusion detection system based on zero-shot learning, comprising: The training sample set generation module is used to collect multi-source raw data based on known intrusion categories, extract known intrusion category features from the multi-source raw data, and generate a training sample set. The model building module is used to build a zero-shot learning model. The zero-shot learning model establishes a mapping between the feature space and the semantic space through an intrusion scenario knowledge graph based on word vectors. The hidden layer of the zero-shot learning model is equipped with a coupled autoencoder. The coupled autoencoder includes a jointly learned known intrusion category autoencoder and an unknown intrusion category autoencoder. The model training module is used to train the zero-shot learning model using the training sample set, learn the mapping logic between the known intrusion category features and the word vectors, and transfer the mapping logic to the semantic space of unknown intrusion categories. The model application module is used to input real-time data into the trained zero-shot learning model to obtain the intrusion category of the real-time data.
[0017] Thirdly, embodiments of the present invention provide an intrusion detection device based on zero-shot learning, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the intrusion detection method based on zero-shot learning as described above.
[0018] Fourthly, a computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the zero-shot learning-based intrusion detection method described above.
[0019] Compared with existing technologies, this invention discloses an intrusion detection method, system, device, and medium based on zero-shot learning. It collects multi-source raw data according to known intrusion categories, extracts known intrusion category features from the multi-source raw data, and generates a training sample set. A zero-shot learning model is constructed, which establishes a mapping between the feature space and semantic space through an intrusion scenario knowledge graph based on word vectors. The hidden layer of the zero-shot learning model is equipped with a coupled autoencoder, which includes a jointly learned known intrusion category autoencoder and an unknown intrusion category autoencoder. The zero-shot learning model is trained using the training sample set to learn the mapping logic between the known intrusion category features and the word vectors, and this mapping logic is transferred to the semantic space of unknown intrusion categories. Real-time data is input into the trained zero-shot learning model to obtain the intrusion category of the real-time data. Using this invention, it is possible to adapt to different types and changing intrusion behaviors and improve the detection accuracy for unknown attack categories. Attached Figure Description
[0020] Figure 1 This is a flowchart illustrating the steps of an intrusion detection method based on zero-shot learning provided in an embodiment of the present invention. Figure 2 This is a schematic diagram of the structure of the direct attribute prediction model provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an intrusion detection system based on zero-shot learning provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of an intrusion detection device based on zero-shot learning provided in an embodiment of the present invention. Detailed Implementation
[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0022] In the description and claims, it should be understood that the terms "first," "second," etc., used in the description and claims are only for the purpose of distinguishing the description of the same technical features, and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated, nor necessarily the order of description or chronological order. The terms are interchangeable where appropriate. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature.
[0023] Traditional intrusion detection technologies can often only detect known attack patterns, and deep learning algorithms have very high requirements for datasets, needing massive amounts of valid data to achieve high recognition accuracy. However, for new and unknown attack methods, without sufficient real-world data support, they cannot be effectively identified, making the system vulnerable to zero-day vulnerability attacks.
[0024] Based on the above considerations, this invention provides an intrusion detection method based on zero-shot learning. Please refer to... Figure 1 In this embodiment, the intrusion detection method based on zero-shot learning is specifically executed through steps S1 to S4: S1. Based on the known intrusion categories, collect multi-source raw data, extract known intrusion category features from the multi-source raw data, and generate a training sample set; S2. Construct a zero-shot learning model, wherein the zero-shot learning model establishes a mapping between the feature space and the semantic space through an intrusion scenario knowledge graph based on word vectors; the hidden layer of the zero-shot learning model is equipped with a coupled autoencoder; the coupled autoencoder includes a jointly learned known intrusion category autoencoder and an unknown intrusion category autoencoder. S3. The zero-shot learning model is trained using the training sample set to learn the mapping logic between the known intrusion category features and the word vectors, and the mapping logic is transferred to the semantic space of unknown intrusion categories. S4. Input the real-time data into the trained zero-shot learning model to obtain the intrusion category of the real-time data.
[0025] It should be noted that the known intrusion categories refer to network attack types in the cybersecurity field that have been clearly identified and possess distinct characteristics and behavioral patterns. Known intrusion categories form the basis for zero-shot learning models to learn the mapping rules between features and semantics. Network attacks of unknown intrusion categories do not deviate from the existing cybersecurity system, but due to differences in their characteristic manifestations compared to known intrusion categories, current intrusion detection schemes struggle to accurately identify them. The multi-source raw data, collected based on known intrusion categories and obtained from multiple data sources, refers to data that retains the complete form and initial information of the data sources themselves; this can be raw data packets or raw data entries, etc.
[0026] In this embodiment of the invention, the core function of the zero-shot learning model is to map the feature space to the semantic space through an intrusion scenario knowledge graph based on word vectors. Through the knowledge graph and mapping mechanism, quantifiable data features are associated with abstract semantics. Simultaneously, the semantic relationships between intrusion categories provided by the intrusion scenario knowledge graph can provide a basis for the subsequent mapping and transfer of unknown intrusion categories, which is the core support for zero-shot learning in this invention.
[0027] Because the known and unknown classes in a zero-shot learning model are disjoint, overfitting and mapping domain shifts can easily occur during deep learning training, significantly reducing the model's learning efficiency. This invention addresses this issue by implementing a coupled autoencoder, which can mitigate the problem of sample distribution divergence.
[0028] It should be noted that the hidden layer of the zero-shot learning model focuses on learning the abstract semantic representation of the data. By setting the coupled autoencoder in the hidden layer, the deep information of multi-source features can be more efficiently fused, providing a more accurate intermediate representation for the mapping between features and semantics.
[0029] In the above scheme, by establishing a mapping between the feature space and semantic space through a knowledge graph of intrusion scenarios based on word vectors, the semantic commonalities of attacks can be captured, eliminating the need to train a separate model for each attack feature and improving the model's generalization ability. Through joint learning of autoencoders for known intrusion categories and autoencoders for unknown intrusion categories, the feature semantic mapping of known intrusion categories and the mapping of unknown categories can form mutual constraints, avoiding the disconnect between the learning of known and unknown categories, alleviating the problem of sample distribution divergence, and improving the reliability of zero-sample transfer. Furthermore, based on the semantic mapping rules of known attacks, new types of attacks can be detected directly, adapting to different types and changes in intrusion behavior and improving the detection accuracy for unknown attack categories.
[0030] In one preferred embodiment, the multi-source raw data includes network traffic data, log data, configuration data, authentication data, abnormal behavior data, and system performance data.
[0031] Network traffic data can be used to analyze communication patterns and detect abnormal traffic, including information such as the source address, destination address, port number, and protocol type of network packets. Log data can be used to track abnormal operations and events, including system logs, security logs, and application logs, which record information such as the running status of the system and applications and user actions. Configuration data can be used to identify improper configurations and vulnerabilities, including network device configuration information, firewall rules, and router configurations. Authentication data can be used to detect abnormal logins and unauthorized access, including user login information, access permissions, and account activity records. Abnormal behavior data is used to identify potential intrusion activities, including abnormal login attempts, abnormal operational behaviors, and abnormal data access. System performance data can be used to discover the impact of abnormal behavior on system performance, including system performance indicators such as CPU utilization, memory usage, and disk I / O.
[0032] In this embodiment of the invention, by selecting the above-mentioned multi-source raw data, it is possible to cover the traces and characteristics of common intrusion attack behaviors, which is crucial for subsequent intrusion category feature extraction.
[0033] As a preferred implementation, step S1 involves collecting multi-source raw data based on known intrusion categories, extracting known intrusion category features from the multi-source raw data, and generating a training sample set, including: Collect raw data from multiple sources based on known intrusion categories; Features associated with known intrusion categories are extracted from the multi-source raw data, and the features are converted into binary vectors to form an initial feature set. The correlation between features in the initial feature set is calculated using the Pearson correlation coefficient. Based on the correlation, feature fusion is performed to obtain known intrusion category features.
[0034] It should be noted that the features associated with known intrusion categories refer to the features in the multi-source raw data that can reflect the corresponding intrusion category events.
[0035] Preferably, network traffic data features include packet size, packet direction, packet frequency, and transmission protocol. Log data features include timestamp, event type, source IP, destination IP, source port, destination port, and operation type. Configuration data features include firewall rules and access control lists. Authentication data features include user login time, IP address, login frequency, and device information. Abnormal behavior data features include abnormal type, abnormal time, scope of impact, and degree; the abnormal type is login failure or access anomaly; the scope and degree of impact are individual user, user group, or the entire system. System performance data features include CPU utilization, memory utilization, and IO read / write rate. Other data features include statistical features and periodic features extracted using time-series data.
[0036] Next, these features are converted into binary vectors using embedding representation or numerical methods to form an initial feature set. In some preferred embodiments, considering that the multi-source feature data differs significantly and has inconsistent distribution ranges, it will inevitably affect the training effect of the model. Therefore, this embodiment of the invention uses zero-mean normalization (z-score normalization) to normalize the initial feature set.
[0037] Preferably, the correlation coefficient matrix of the features is calculated using the Pearson correlation coefficient. Based on the correlation coefficient matrix, features with high correlation to the predicted value are selected, and other redundant or weakly correlated features are cleaned up. The features with high correlation are then fed into the zero-shot learning model for training, and weights are automatically assigned.
[0038] In the above scheme, the correlation between features in the initial feature set is calculated using the Pearson correlation coefficient to achieve redundancy removal and ensure that the fused features can fully cover the key information of known intrusion categories.
[0039] In this embodiment of the invention, the known intrusion category autoencoder consists of a first encoder and a first decoder, and the unknown intrusion category autoencoder consists of a second encoder and a second decoder.
[0040] As a preferred embodiment, the semantic vector of the known intrusion category is defined as follows: The semantic vector of the unknown intrusion category is ; Let k be the semantic representation of the i-th intrusion category, and k be the dimension of the semantic representation. and Let be the projection matrices in the first encoder and the second encoder, respectively, where d is the feature dimension. Correspondingly, the projection matrices in the first decoder and the second decoder are expressed as: and .
[0041] The known intrusion category autoencoder is represented as: (1); in, The number of samples of known intrusion categories; The feature vector of a sample with a known intrusion category; This is a semantic attribute matrix for known intrusion categories. This is a weighting factor for the importance of the loss between the first decoder and the first encoder. It is the Frobenius norm.
[0042] In equation (1), the first term is the loss of the first decoder, which projects semantic attributes into the feature space; the second term is the loss of the first encoder, which projects features into the semantic attribute space.
[0043] Similarly, the autoencoder for unknown intrusion categories is represented as: (2); in, The number of samples of unknown intrusion category; The feature vector of the sample of unknown intrusion category; This is a semantic attribute matrix for unknown intrusion categories. is a weighting factor for the importance of the loss of the second decoder and the loss of the second encoder.
[0044] The coupled autoencoder combines known intrusion type autoencoders and unknown intrusion type autoencoders, represented as: (3); A regularization term was added to equation (3). To ensure It will not deviate excessively ,parameter , , and Used to adjust right The degree of compatibility.
[0045] By differentiating equation (1) and assuming it has a unique solution, we can obtain: (4).
[0046] By setting the matrix Equation (4) can be simplified to the Sylvester equation: (5).
[0047] Similarly, equation (2) can be optimized and expressed as: (6); Where I is the identity matrix.
[0048] Based on this, taking the derivative of equation (3) and assuming it has a unique solution, we can obtain: (7); make Then equation (7) can be simplified to: (8); Similarly, we can obtain: (9); (10); in, .
[0049] Further, preferably, the input of the coupled autoencoder is a first feature matrix of known intrusion categories, a first semantic attribute matrix of known intrusion categories, and a second feature matrix of unknown intrusion categories; Based on the first feature matrix and the first semantic attribute matrix, a first mapping matrix for known intrusion categories is obtained through a known intrusion category autoencoder; Based on the first mapping matrix, initialize the second mapping matrix for unknown intrusion categories; Based on the second mapping matrix and the second feature matrix, the second semantic attribute matrix of the unknown intrusion category is obtained through the unknown intrusion category autoencoder; The first mapping matrix, the second mapping matrix, and the second semantic attribute matrix are updated until the zero-shot learning model converges.
[0050] In this embodiment of the invention, the input to the zero-shot learning model algorithm incorporating a coupled autoencoder is the first feature matrix. First semantic attribute matrix Second characteristic matrix and adjusting weight parameters , , and Its output is the first mapping matrix of known intrusion categories. The second mapping matrix of unknown intrusion categories Second semantic attribute matrix .
[0051] The specific training logic is as follows: initialize the first mapping matrix according to equation (5). and order If the coupled autoencoder still fails to converge, then update the second semantic attribute matrix according to equation (6). Update the second mapping matrix according to equation (8). And update the first mapping matrix according to equation (10). .
[0052] In the above scheme, the known intrusion category autoencoder and the unknown intrusion category autoencoder are updated alternately during training. The mapping logic of the two is adapted to each other through backpropagation, and finally converges to a consistent optimal semantic space.
[0053] As a preferred implementation, step S2 involves constructing a zero-shot learning model. This zero-shot learning model establishes a mapping between the feature space and the semantic space using a word-vector-based intrusion scenario knowledge graph, and is executed through steps S21 to S26. S21. Establish a tag set to form a tag space; the tags in the tag set are bound to intrusion categories. S22. Based on the general knowledge graph and the tag set, establish an intrusion scenario knowledge graph with word vectors as node attributes to form a semantic space; S23. Construct a feature extraction module to extract attack features from the input data and form a feature space; S24. Based on the intrusion scenario knowledge graph, establish a graph convolutional neural network to map the feature space to the semantic space and output a semantic category weight matrix; the semantic category weight matrix represents the semantic association strength between the input data and each intrusion category. S25. Construct a classifier to output the classification result of the intrusion category based on the semantic category weight matrix; S26. Based on the tag set, the intrusion scenario knowledge graph, the feature extraction module, the graph convolutional neural network, and the classifier, a zero-shot learning model is obtained.
[0054] In this embodiment of the invention, the zero-shot learning model is composed of a feature space, a semantic space, and a label space. The zero-shot learning model trains a classifier using known intrusion category samples. Where X is the feature space and Y is the intrusion category, the process of predicting unknown intrusion category samples and classifying them is realized.
[0055] In a preferred implementation, the tag set mentioned in step S21 includes known intrusion category tags and unknown intrusion category tags. The output of the classifier is to match the input data with the tags to complete the identification of the intrusion category. By binding tags with intrusion categories, the embedding of the tag space and semantic space can be achieved.
[0056] In some preferred embodiments, the word vectors are selected based on features of each intrusion category. For example, network protocol or service names are represented as vectors, such as HTTP, SSH, and FTP, to identify specific protocols or services in communication. Each type of attack is represented as a vector, such as DDoS, SQL injection, and malware, to identify and classify different types of attacks. IP addresses, port numbers, and hostnames are represented as vectors to detect anomalous behavior associated with specific IPs, ports, or hosts. Network traffic characteristics are represented as vectors, such as packet size, frequency, and direction, to identify anomalous traffic. Keywords and phrases are represented as vectors, such as "login failed," "too many password attempts," and "unauthorized access," to identify log entries or communication content related to security incidents.
[0057] It should be noted that the intrusion scenario knowledge graph is constructed specifically for intrusion scenarios. The relationships between nodes in the intrusion scenario knowledge graph and word vectors can jointly constitute the semantic space of the zero-shot learning model, realizing the computability and associativity of semantics.
[0058] It should also be noted that the feature extraction module described in step S23 has a pre-set extraction logic for intrusion category features. In some preferred embodiments, the feature extraction module is a pre-trained feature extraction network; in other preferred embodiments, the feature extraction module is trained together with the zero-shot learning module.
[0059] Graph convolutional neural networks can leverage the node relationships in a knowledge graph to aggregate neighbor node information, learn the association between data features and graph semantics, and avoid mapping bias caused by ignoring the semantic relationships.
[0060] In the above scheme, the association between semantic space and feature space enables effective detection of unknown attacks; furthermore, in the construction of semantic space, the intrusion scenario knowledge graph and graph convolutional neural network enable the model to understand the semantic essence of intrusion behavior, thereby improving the generalization ability for attack variants.
[0061] Further, preferably, step S22, establishing an intrusion scenario knowledge graph with word vectors as node attributes based on the general knowledge graph and the tag set, forming a semantic space, includes: Based on the general semantic classification knowledge graph and the tag set, known intrusion category nodes, unknown intrusion category nodes, and associated element nodes are defined to form a first knowledge graph subset; Obtain the word vectors of the intrusion category, and embed the word vectors as node attributes into the first knowledge graph subset to obtain the second knowledge graph subset; A general scenario-related knowledge graph is adopted. Based on the first knowledge graph subset and the second knowledge graph subset, an intrusion scenario knowledge graph is obtained to form a semantic space.
[0062] In this embodiment of the invention, to effectively utilize the explicit relationships between all concepts, a knowledge graph is introduced into the construction of the semantic relationship module. The concepts used are divided into Y+Z+O, where Y represents attack patterns of known intrusion categories, Z represents attack patterns of unknown intrusion categories, and O represents attack traces and impacts. Then, using an equal number of known intrusion category nodes, unknown intrusion category nodes, and related element nodes, an intrusion scenario knowledge graph corresponding to these concepts is constructed.
[0063] Preferably, the general semantic classification knowledge graph adopts WordNet, which is a broad English lexical semantic network. It can extract the least common hyperordinate subset for all invisible and visible classes. Then, the path length is used in the hyperordinate subset to calculate the similarity between each class and other classes. Finally, these similarities are used to construct semantic vectors with hierarchical characteristics.
[0064] Preferably, the general-purpose scene-related knowledge graph adopts ConceptNet, which can connect words and phrases at the edge of natural language.
[0065] In the above scheme, the first subset of the knowledge graph, by defining nodes based on a semantic classification knowledge graph, ensures comprehensive coverage of intrusion category nodes and related elements, providing a structured foundation for semantic space construction. The second subset of the knowledge graph, by embedding word vectors as node attributes, enables precise measurement of semantic relationships between nodes. Furthermore, by integrating a general scenario-related knowledge graph, the intrusion scenario knowledge graph not only includes general semantics but also incorporates the specific association logic of intrusion detection scenarios, avoiding a disconnect between general knowledge and specific scenarios.
[0066] Preferably, step S24, establishing a graph convolutional neural network based on the intrusion scenario knowledge graph to map the feature space to the semantic space and outputting a semantic category weight matrix, includes: Obtain an intrusion scenario knowledge graph and establish a graph convolutional neural network, wherein the nodes of the graph convolutional neural network correspond to the nodes of the intrusion scenario knowledge graph; The output of the feature extraction module is connected to the graph convolutional neural network, so that the graph convolutional neural network fuses neighbor features into the nodes based on the output of the feature extraction module; The graph convolutional neural network outputs a semantic category weight matrix through several layers of iteration; the elements in the semantic category weight matrix represent the semantic correlation between the features of the input data and the nodes in the intrusion scenario knowledge graph.
[0067] The nodes of the graph convolutional neural network correspond one-to-one with the nodes of the intrusion scenario knowledge graph, making the network structure naturally adaptable to the topology of the semantic space. Through the features of neighboring nodes, the graph convolutional neural network enables zero-shot learning models to capture the multi-dimensional relationship between features and semantics; for the iteration of an L-order graph convolutional neural network, each layer l is the feature matrix of the previous layer. As input, a feature matrix is generated. The final output semantic category weight matrix transforms the correlation between features and semantic nodes into specific numerical values, providing a clear and interpretable decision basis for subsequent classifiers.
[0068] In some preferred embodiments, in a graph convolutional neural network, the propagation rule for a single convolution operation across all nodes is expressed as follows: (11); in, , The feature matrix output by the feature extraction module; A is the preset training weight matrix of the previous layer; D is the relational adjacency matrix of the intrusion scenario knowledge graph; and D is the degree matrix of A. This is a non-linear activation function. In some preferred embodiments, the non-linear activation function is Leaky ReLU.
[0069] The above scheme implements a weighted summation of the neighboring nodes of each node in the knowledge graph, which is then multiplied by the parameter matrix to obtain the features of the nodes in the new layer. The final layer of the network can output the semantic category weight matrix for all categories.
[0070] In a preferred embodiment, the classifier employs a direct attribute prediction model. The classifier includes several sub-classifiers, the number of which is consistent with the number of semantic attributes. These sub-classifiers are used to calculate the association probability between semantic attributes and labels. The classifier obtains the target label based on the association probability calculated by each sub-classifier.
[0071] In this embodiment of the invention, a classifier is learned for the attributes of various known classes using a Direct Attribute Prediction model (DAP). Then, the relevance probability corresponding to each attribute is calculated. In the prediction and classification stage, the class with the highest relevance probability is taken as the final prediction result.
[0072] See Figure 2 , Figure 2 This is a schematic diagram of the direct attribute prediction model. For a labeled dataset of known intrusion categories, A labeled dataset for unknown intrusion categories. ; This is a semantic attribute matrix; This is the feature matrix of the input data.
[0073] Semantic attributes The probabilistic relationship between the label layer and the label layer can be derived using Bayes' theorem: (12); Furthermore, the posterior probability of each unknown intrusion category is expressed as: (13); in, For semantic attributes of unknown intrusion categories, The attribute probabilities obtained from the input data x using DAP; This represents the prior probability of an unknown intrusion category.
[0074] For the test sample x, there exists a classifier. It can predict the label type of unknown intrusion categories, and combine it with the maximum a posteriori (MAP) estimate to obtain the classification criteria for sample x: (14).
[0075] In the above scheme, the direct attribute prediction model is used for classification prediction, which can process test data in real time. Furthermore, due to its data structure characteristics, it is not necessary to obtain all the test data at once. These advantages make the method easier to implement and have greater potential for future expansion.
[0076] As a preferred implementation, step S3, training the zero-shot learning model using the training sample set to learn the mapping logic between the known intrusion category features and the word vectors, and transferring the mapping logic to the semantic space of unknown intrusion categories, includes: The training sample set is input into the constructed zero-shot learning model. Based on the intrusion scenario knowledge graph, the mapping logic between the known intrusion category features and the word vectors is learned, and the semantic association of nodes in the intrusion scenario knowledge graph is obtained. Based on the semantic correlation, the mapping logic is transferred to unknown intrusion categories, so that the trained zero-shot learning model can perform semantic space mapping on the input data and achieve intrusion category classification.
[0077] It should be noted that the training sample set includes data under known intrusion categories. Based on the architecture of the zero-shot learning model given in the embodiments of the present invention, after inputting the training sample set into the model, the semantic association information in the semantic space can be enriched. After training, the model forms a complete mapping logic covering known and unknown classes. Input data can be mapped to the semantic space through the same framework, ensuring the consistency of the classification process, and providing a unified and reliable logical foundation for subsequent classification output based on the semantic category weight matrix.
[0078] In a preferred embodiment, before performing step S4, the intrusion detection method based on zero-shot learning further includes: The trained zero-shot learning model was migrated to a cloud environment to test its ability to detect unknown intrusion categories. The parameters of the zero-shot learning model are updated based on the test results.
[0079] Through the model training process in step S3, the optimal model can be obtained under the training sample set. In this embodiment of the invention, the model is further transferred to a cloud environment to test its actual network intrusion detection performance. On the one hand, it can expose the differences between the training environment and the actual cloud environment, and adapt the model to the characteristics of the cloud environment through parameter updates; on the other hand, it can accurately discover the model's missed detection and false positive problems for new types of attacks in real-world scenarios, and improve the practical accuracy of unknown class detection through parameter adjustments.
[0080] Further, preferably, updating the parameters of the zero-shot learning model based on the test results includes: Undetected network attacks of unknown intrusion types were filtered from the test results, and the original data and attack chain of the network attacks were obtained through source tracing analysis. The training sample set is updated based on the original data and the attack chain to incrementally train the zero-shot learning model.
[0081] It should be noted that the zero-shot learning model provided in this embodiment of the invention supports incremental training. For example, the number of nodes and the architecture of its intrusion network knowledge graph are adjustable, and can be updated based on test data, or even data from the actual application in step S4, to achieve incremental training of the model.
[0082] In this embodiment of the invention, relying on the massive attack data in the cloud network environment, the original data and attack links of unknown types of network attacks that could not be detected normally are preserved through source tracing analysis, further expanding the training set and improving the accuracy and detection rate of the model.
[0083] The intrusion detection method based on zero-shot learning provided in this embodiment of the invention establishes a mapping between the feature space and the semantic space by using an intrusion scenario knowledge graph based on word vectors. This method can capture the semantic commonalities of attacks without training a separate model for each attack feature, thus improving the generalization of the model. Furthermore, based on the semantic mapping rules of known attacks, it can directly detect new types of attacks, adapt to different types and changing intrusion behaviors, and improve the detection accuracy for unknown attack categories.
[0084] This invention provides an intrusion detection system based on zero-shot learning. Please refer to [link to relevant documentation]. Figure 3 The zero-shot learning-based intrusion detection system includes a training sample set generation module 11, a model building module 12, a model training module 13, and a model application module 14, wherein: The training sample set generation module 11 is used to collect multi-source raw data based on known intrusion categories, extract known intrusion category features from the multi-source raw data, and generate a training sample set. The model building module 12 is used to build a zero-shot learning model, which establishes a mapping between the feature space and the semantic space through an intrusion scenario knowledge graph based on word vectors. Model training module 13 is used to train the zero-shot learning model using the training sample set, learn the mapping logic between the known intrusion category features and the word vectors, and transfer the mapping logic to the semantic space of unknown intrusion categories; The model application module 14 is used to input real-time data into the trained zero-shot learning model to obtain the intrusion category of the real-time data.
[0085] In one preferred embodiment, the multi-source raw data includes network traffic data, log data, configuration data, authentication data, abnormal behavior data, and system performance data.
[0086] In a preferred embodiment, the training sample set generation module 11 is used for: Collect raw data from multiple sources based on known intrusion categories; Features associated with known intrusion categories are extracted from the multi-source raw data, and the features are converted into binary vectors to form an initial feature set. The correlation between features in the initial feature set is calculated using the Pearson correlation coefficient. Based on the correlation, feature fusion is performed to obtain known intrusion category features.
[0087] In a preferred embodiment, the input of the coupled autoencoder is a first feature matrix of known intrusion categories, a first semantic attribute matrix of known intrusion categories, and a second feature matrix of unknown intrusion categories; Based on the first feature matrix and the first semantic attribute matrix, a first mapping matrix for known intrusion categories is obtained through a known intrusion category autoencoder; Based on the first mapping matrix, initialize the second mapping matrix for unknown intrusion categories; Based on the second mapping matrix and the second feature matrix, the second semantic attribute matrix of the unknown intrusion category is obtained through the unknown intrusion category autoencoder; The first mapping matrix, the second mapping matrix, and the second semantic attribute matrix are updated until the zero-shot learning model converges.
[0088] In a preferred embodiment, the model building module 12 includes: A tag set creation unit is used to create a tag set to form a tag space; the tags in the tag set are bound to intrusion categories. The intrusion scenario knowledge graph establishment unit is used to establish an intrusion scenario knowledge graph with word vectors as node attributes based on the general knowledge graph and the tag set, forming a semantic space; The attack feature extraction unit is used to construct the feature extraction module, which extracts attack features from the input data to form a feature space. The graph convolutional neural network building unit is used to build a graph convolutional neural network based on the intrusion scenario knowledge graph to map the feature space to the semantic space and output a semantic category weight matrix; the semantic category weight matrix is the semantic association strength between the input data and each intrusion category. A classifier building unit is used to build a classifier to output the classification result of the intrusion category based on the semantic category weight matrix; The model integration unit is used to obtain a zero-shot learning model based on the label set, the intrusion scenario knowledge graph, the feature extraction module, the graph convolutional neural network, and the classifier.
[0089] Further, preferably, the intrusion scenario knowledge graph establishment unit is specifically used for: Based on the general semantic classification knowledge graph and the tag set, known intrusion category nodes, unknown intrusion category nodes, and associated element nodes are defined to form a first knowledge graph subset; Obtain the word vectors of the intrusion category, and embed the word vectors as node attributes into the first knowledge graph subset to obtain the second knowledge graph subset; A general scenario-related knowledge graph is adopted. Based on the first knowledge graph subset and the second knowledge graph subset, an intrusion scenario knowledge graph is obtained to form a semantic space.
[0090] Preferably, the graph convolutional neural network building unit is specifically used for: Obtain an intrusion scenario knowledge graph and establish a graph convolutional neural network, wherein the nodes of the graph convolutional neural network correspond to the nodes of the intrusion scenario knowledge graph; The output of the feature extraction module is connected to the graph convolutional neural network, so that the graph convolutional neural network fuses neighbor features into the nodes based on the output of the feature extraction module; The graph convolutional neural network outputs a semantic category weight matrix through several layers of iteration; the elements in the semantic category weight matrix represent the semantic correlation between the features of the input data and the nodes in the intrusion scenario knowledge graph.
[0091] Preferably, the classifier adopts a direct attribute prediction model, and the classifier includes several sub-classifiers. The number of sub-classifiers is consistent with the number of semantic attributes. They are used to calculate the association probability between semantic attributes and labels. The classifier obtains the target label based on the association probability calculated by each sub-classifier.
[0092] In a preferred embodiment, the model training module 13 is used for: The training sample set is input into the constructed zero-shot learning model. Based on the intrusion scenario knowledge graph, the mapping logic between the known intrusion category features and the word vectors is learned, and the semantic association of nodes in the intrusion scenario knowledge graph is obtained. Based on the semantic correlation, the mapping logic is transferred to unknown intrusion categories, so that the trained zero-shot learning model can perform semantic space mapping on the input data and achieve intrusion category classification.
[0093] In a preferred embodiment, the intrusion detection system based on zero-shot learning further includes a model testing and updating module, used for: The trained zero-shot learning model was migrated to a cloud environment to test its ability to detect unknown intrusion categories. The parameters of the zero-shot learning model are updated based on the test results.
[0094] Further, preferably, updating the parameters of the zero-shot learning model based on the test results includes: Undetected network attacks of unknown intrusion types were filtered from the test results, and the original data and attack chain of the network attacks were obtained through source tracing analysis. The training sample set is updated based on the original data and the attack chain to incrementally train the zero-shot learning model.
[0095] The intrusion detection system based on zero-shot learning provided in this invention establishes a mapping between the feature space and semantic space through a knowledge graph of intrusion scenarios based on word vectors. This enables the capture of semantic commonalities in attacks, eliminating the need to train a separate model for each attack feature and improving the model's generalization ability. Through joint learning of autoencoders for known and unknown intrusion categories, the feature semantic mappings of known intrusion categories and the mappings of unknown categories form mutual constraints, preventing a disconnect between the learning of known and unknown categories, alleviating the problem of sample distribution divergence, and improving the reliability of zero-shot transfer. Furthermore, based on the semantic mapping patterns of known attacks, it can directly detect novel attacks, adapting to different types and changing intrusion behaviors and improving the detection accuracy for unknown attack categories.
[0096] See Figure 4 , Figure 4 This is a structural block diagram of an intrusion detection device based on zero-shot learning provided in an embodiment of the present invention. The zero-shot learning-based intrusion detection device includes a processor 31, a memory 32, and a computer program stored in the memory 32 and executable on the processor 31. When the processor 31 executes the computer program, it implements the steps in the various embodiments of the zero-shot learning-based intrusion detection method described above, such as steps S1 to S4.
[0097] For example, the computer program may be divided into one or more modules / units, which are stored in the memory 32 and executed by the processor 31 to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the zero-shot learning-based intrusion detection device.
[0098] The zero-shot learning-based intrusion detection device may include, but is not limited to, a processor 31 and a memory 32. Those skilled in the art will understand that the schematic diagram is merely an example of a zero-shot learning-based intrusion detection device and does not constitute a limitation on the device. It may include more or fewer components than illustrated, or combine certain components, or use different components. For example, the zero-shot learning-based intrusion detection device may also include input / output devices, network access devices, buses, etc.
[0099] The processor 31 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor 31 is the control center of the zero-shot learning-based intrusion detection device, connecting all parts of the device via various interfaces and lines.
[0100] The memory 32 can be used to store the computer program and / or modules. The processor 31 implements various functions of the zero-shot learning-based intrusion detection device by running or executing the computer program and / or modules stored in the memory 32 and calling the data stored in the memory 32. The memory 32 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 32 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0101] Wherein, if the modules / units integrated in the zero-shot learning-based intrusion detection device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by the processor 31, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0102] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. An intrusion detection method based on zero-shot learning, characterized in that, include: Based on the known intrusion categories, collect raw data from multiple sources, extract features of the known intrusion categories from the raw data from the multiple sources, and generate a training sample set. A zero-shot learning model is constructed, which establishes a mapping between the feature space and the semantic space through an intrusion scenario knowledge graph based on word vectors; The hidden layers of the zero-shot learning model are equipped with coupled autoencoders; the coupled autoencoders include jointly learned known intrusion category autoencoders and unknown intrusion category autoencoders; The zero-shot learning model is trained using the training sample set to learn the mapping logic between the known intrusion category features and the word vectors, and the mapping logic is transferred to the semantic space of unknown intrusion categories. Real-time data is input into the trained zero-shot learning model to obtain the intrusion category of the real-time data.
2. The intrusion detection method based on zero-shot learning as described in claim 1, characterized in that, The multi-source raw data includes network traffic data, log data, configuration data, authentication data, abnormal behavior data, and system performance data.
3. The intrusion detection method based on zero-shot learning as described in claim 1, characterized in that, The process of collecting multi-source raw data based on known intrusion categories, extracting known intrusion category features from the multi-source raw data, and generating a training sample set includes: Collect raw data from multiple sources based on known intrusion categories; Features associated with known intrusion categories are extracted from the multi-source raw data, and the features are converted into binary vectors to form an initial feature set. The correlation between features in the initial feature set is calculated using the Pearson correlation coefficient. Based on the correlation, feature fusion is performed to obtain known intrusion category features.
4. The intrusion detection method based on zero-shot learning as described in claim 1, characterized in that, The input to the coupled autoencoder is a first feature matrix of known intrusion categories, a first semantic attribute matrix of known intrusion categories, and a second feature matrix of unknown intrusion categories; Based on the first feature matrix and the first semantic attribute matrix, a first mapping matrix for known intrusion categories is obtained through a known intrusion category autoencoder; Based on the first mapping matrix, initialize the second mapping matrix for unknown intrusion categories; Based on the second mapping matrix and the second feature matrix, the second semantic attribute matrix of the unknown intrusion category is obtained through the unknown intrusion category autoencoder; The first mapping matrix, the second mapping matrix, and the second semantic attribute matrix are updated until the zero-shot learning model converges.
5. The intrusion detection method based on zero-shot learning as described in claim 1, characterized in that, The construction of the zero-shot learning model, which establishes a mapping between the feature space and the semantic space through a knowledge graph of intrusion scenarios based on word vectors, includes: Establish a tag set to form a tag space; the tags in the tag set are bound to intrusion categories. Based on the general knowledge graph and the tag set, an intrusion scenario knowledge graph is established with word vectors as node attributes, forming a semantic space; A feature extraction module is constructed to extract attack features from the input data, forming a feature space; Based on the intrusion scenario knowledge graph, a graph convolutional neural network is established to map the feature space to the semantic space and output a semantic category weight matrix; the semantic category weight matrix represents the semantic association strength between the input data and each intrusion category. Construct a classifier to output the classification result of the intrusion category based on the semantic category weight matrix; A zero-shot learning model is obtained based on the tag set, the intrusion scenario knowledge graph, the feature extraction module, the graph convolutional neural network, and the classifier.
6. The intrusion detection method based on zero-shot learning as described in claim 5, characterized in that, The step of establishing an intrusion scenario knowledge graph with word vectors as node attributes based on the general knowledge graph and the tag set, forming a semantic space, includes: Based on the general semantic classification knowledge graph and the tag set, known intrusion category nodes, unknown intrusion category nodes, and associated element nodes are defined to form a first knowledge graph subset; Obtain the word vectors of the intrusion category, and embed the word vectors as node attributes into the first knowledge graph subset to obtain the second knowledge graph subset; A general scenario-related knowledge graph is adopted. Based on the first knowledge graph subset and the second knowledge graph subset, an intrusion scenario knowledge graph is obtained to form a semantic space.
7. The intrusion detection method based on zero-shot learning as described in claim 5, characterized in that, The step of establishing a graph convolutional neural network based on the intrusion scenario knowledge graph to map the feature space to the semantic space and output a semantic category weight matrix includes: Obtain an intrusion scenario knowledge graph and establish a graph convolutional neural network, wherein the nodes of the graph convolutional neural network correspond to the nodes of the intrusion scenario knowledge graph; The output of the feature extraction module is connected to the graph convolutional neural network, so that the graph convolutional neural network fuses neighbor features into the nodes based on the output of the feature extraction module; The graph convolutional neural network outputs a semantic category weight matrix through several layers of iteration; the elements in the semantic category weight matrix represent the semantic correlation between the features of the input data and the nodes in the intrusion scenario knowledge graph.
8. The intrusion detection method based on zero-shot learning as described in claim 5, characterized in that, The classifier employs a direct attribute prediction model and includes several sub-classifiers, the number of which is consistent with the number of semantic attributes. These sub-classifiers are used to calculate the association probability between semantic attributes and labels. The classifier obtains the target label based on the association probability calculated by each sub-classifier.
9. The intrusion detection method based on zero-shot learning as described in claim 1, characterized in that, The step of training the zero-shot learning model using the training sample set, learning the mapping logic between the known intrusion category features and the word vectors, and transferring the mapping logic to the semantic space of unknown intrusion categories includes: The training sample set is input into the constructed zero-shot learning model. Based on the intrusion scenario knowledge graph, the mapping logic between the known intrusion category features and the word vectors is learned, and the semantic association of nodes in the intrusion scenario knowledge graph is obtained. Based on the semantic correlation, the mapping logic is transferred to unknown intrusion categories, so that the trained zero-shot learning model can perform semantic space mapping on the input data and achieve intrusion category classification.
10. The intrusion detection method based on zero-shot learning as described in claim 1, characterized in that, Before inputting real-time data into the trained zero-shot learning model to obtain the intrusion category of the real-time data, the zero-shot learning-based intrusion detection method further includes: The trained zero-shot learning model was migrated to a cloud environment to test its ability to detect unknown intrusion categories. The parameters of the zero-shot learning model are updated based on the test results.
11. The intrusion detection method based on zero-shot learning as described in claim 10, characterized in that, The step of updating the parameters of the zero-shot learning model based on the test results includes: Undetected network attacks of unknown intrusion types were filtered from the test results, and the original data and attack chain of the network attacks were obtained through source tracing analysis. The training sample set is updated based on the original data and the attack chain to incrementally train the zero-shot learning model.
12. An intrusion detection system based on zero-shot learning, characterized in that, include: The training sample set generation module is used to collect multi-source raw data based on known intrusion categories, extract known intrusion category features from the multi-source raw data, and generate a training sample set. The model building module is used to build a zero-shot learning model, which establishes a mapping between the feature space and the semantic space through an intrusion scenario knowledge graph based on word vectors. The hidden layers of the zero-shot learning model are equipped with coupled autoencoders; the coupled autoencoders include jointly learned known intrusion category autoencoders and unknown intrusion category autoencoders; The model training module is used to train the zero-shot learning model using the training sample set, learn the mapping logic between the known intrusion category features and the word vectors, and transfer the mapping logic to the semantic space of unknown intrusion categories. The model application module is used to input real-time data into the trained zero-shot learning model to obtain the intrusion category of the real-time data.
13. An intrusion detection device based on zero-shot learning, characterized in that, The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the zero-shot learning-based intrusion detection method as described in any one of claims 1 to 11.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the zero-shot learning-based intrusion detection method as described in any one of claims 1 to 11.
Citation Information
Patent Citations
Zero sample learning method
CN111914929A
Intrusion detection method and device in integrated mode
CN118473708A
Multi-level ensemble classifers for cybersecurity machine learning applications
US20220147815A1
Cited By
Photograph land utilization classification method and system based on knowledge graph
CN121095792A