A network security intrusion detection system and method based on a fusion graph neural network

By integrating graph neural networks, a deep detection model based on graph neural networks is constructed, which solves the problems of insufficient identification ability and poor adaptability of traditional network intrusion detection systems in complex network environments. It achieves accurate identification and intelligent protection against complex network attacks, and improves detection accuracy and response efficiency.

CN120856447BActive Publication Date: 2026-04-07CHANGCHUN INST OF TECH
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Traditional network intrusion detection systems struggle to cope with complex network attacks, exhibiting insufficient identification capabilities, poor adaptability to protection strategies, and a lack of intelligent response mechanisms. They are unable to effectively capture the complex relationships between network nodes, resulting in low detection accuracy and unreasonable resource allocation.

Method used

By employing a fusion graph neural network approach, a deep detection model based on graph neural networks is constructed to achieve graph convolutional modeling and message passing analysis of multi-source traffic data, generate adaptive protection strategies, identify attack response patterns and generate adversarial detection strategies, and perform multi-layer detection and proactive defense.

Benefits of technology

It improves the early detection capability of covert and coordinated attacks, enhances the system's proactive defense capability against unknown and mutated attacks, achieves a dual improvement in detection accuracy and response efficiency, and solves the problems of rigid strategies and unreasonable resource allocation in traditional systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856447B_ABST
    Figure CN120856447B_ABST
Patent Text Reader

Abstract

The application discloses a network security intrusion detection system and method based on a fusion graph neural network, collects multi-source traffic data in the network operation process, constructs an induced topology graph by using a graph convolution modeling technology, and reveals deep correlation between network nodes; a multi-layer graph propagation and resonance enhancement technology is used to identify a hidden attack mode, a high-quality node embedding representation is generated through a graph attention mechanism and abnormal resonance amplification; a deep graph learning and graph pooling technology is combined to extract an attack behavior graph, an adaptive protection strategy is generated through graph inversion mapping and dynamic topology transformation; a multi-graph layer detection rule decomposition and graph optimization sorting technology is used to construct an interleaved detection sequence, an adaptive response signal is generated through active defense prediction and time difference bottleneck analysis, intelligent detection, accurate analysis and adaptive protection of network intrusion behavior are realized, and the intelligent level and protection effect of network security protection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network security intrusion detection system and method based on graph neural network. BACKGROUND

[0002] With the continuous evolution of network attack technology and the increasing complexity of attack means, the traditional intrusion detection system based on signature matching and statistical analysis has been difficult to cope with the challenges of current network security threats. Modern network attacks show strong concealment, high variability and complex coordination, and attackers often use multi-stage penetration, distributed coordination and dynamic transformation and other advanced attack strategies, which significantly reduces the effectiveness of traditional detection methods.

[0003] The existing intrusion detection technology mainly has the following limitations: first, the detection method based on feature library relies heavily on the pre-defined rules of known attack patterns, and the recognition ability of zero-day attacks and variant attacks is obviously insufficient; second, the traditional detection system adopts a single-point monitoring architecture, lacks overall analysis of network traffic patterns and node behavior correlation, and is difficult to discover cross-node coordinated attacks and distributed intrusion behaviors; third, the detection strategy and response mechanism of the existing system are relatively rigid, and cannot be dynamically optimized according to the changes in network environment and the evolution of attack characteristics, resulting in low detection accuracy and unreasonable resource allocation. In addition, the traditional method has poor real-time performance, high false alarm rate and other problems when processing large-scale network data, which is difficult to meet the security protection needs in modern complex network environment. SUMMARY

[0004] The present application discloses a network security intrusion detection system and method based on graph neural network, aiming to solve the technical problems of insufficient recognition ability of complex network attacks, poor adaptability of protection strategies, and lack of intelligence in response mechanism of traditional intrusion detection systems, by constructing a deep detection model based on graph neural network, establishing an adaptive protection strategy generation mechanism, realizing accurate identification and intelligent protection of hidden attacks, and improving the accuracy, real-time performance and adaptability of network security protection, providing reliable security protection for modern network environment.

[0005] The present application discloses a network security intrusion detection system and method based on graph neural network, aiming to solve the technical problems of insufficient recognition ability of complex network attacks, poor adaptability of protection strategies, and lack of intelligence in response mechanism of traditional intrusion detection systems, by constructing a deep detection model based on graph neural network, establishing an adaptive protection strategy generation mechanism, realizing accurate identification and intelligent protection of hidden attacks, and improving the accuracy, real-time performance and adaptability of network security protection, providing reliable security protection for modern network environment.

[0006] Collecting multi-source traffic data during network operation, the multi-source traffic data including normal node features and induced node features, and constructing an induced topology graph by graph convolution modeling on the multi-source traffic data;

[0007] perform graph attention calculation on the attack response mode to generate an attention vector, perform abnormal resonance amplification in the attention vector to generate a node embedding representation, and perform graph convolution propagation on the node embedding representation to generate a resonance enhancement domain;

[0008] extract an attack behavior graph from the induced node features through deep graph learning, obtain attack intention encoding from the attack behavior graph through graph pooling, generate a defense strategy representation through graph inversion mapping of the attack intention encoding, and construct a dynamic topology transformation based on the defense strategy representation to generate an adaptive defense table;

[0009] perform multi-layer graph propagation on the resonance enhancement domain to identify a hidden attack subgraph, perform graph fusion on the hidden attack subgraph to generate a camouflage graph embedding, perform topology remodeling on the camouflage graph embedding to generate a deceptive network structure, and generate a counter-detection strategy based on the association between the deceptive network structure and the adaptive defense table;

[0010] divide the counter-detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a countermeasure matrix based on the interleaved detection sequence;

[0011] generate an active defense prediction based on the countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete intrusion detection.

[0012] The second aspect of the application provides a network security intrusion detection system based on a fusion graph neural network, comprising:

[0013] A data acquisition module is configured to acquire multi-source traffic data in the network operation process, wherein the multi-source traffic data includes normal node features and induced node features, and the multi-source traffic data is modeled through graph convolution to construct an induced topology graph.

[0014] A message passing module is configured to perform message passing analysis based on the induced topology graph to identify an attack response mode, perform graph attention calculation on the attack response mode to generate an attention vector, perform abnormal resonance amplification in the attention vector to generate a node embedding representation, and perform graph convolution propagation on the node embedding representation to generate a resonance enhancement domain.

[0015] An attack learning module is configured to extract an attack behavior graph from the induced node features through deep graph learning, obtain attack intention encoding from the attack behavior graph through graph pooling, generate a defense strategy representation through graph inversion mapping of the attack intention encoding, and construct a dynamic topology transformation based on the defense strategy representation to generate an adaptive defense table.

[0016] a topology remodeling module, configured to perform multi-layer graph propagation on the resonance enhancement domain to identify a hidden attack subgraph, perform graph atlas fusion on the hidden attack subgraph to generate a camouflage graph embedding, perform topology remodeling on the camouflage graph embedding to generate a deceptive network structure, and generate an adversarial detection strategy based on the deceptive network structure and the adaptive protection table;

[0017] a detection optimization module, configured to decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence;

[0018] a response output module, configured to generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete intrusion detection.

[0019] The beneficial effects of the present application are embodied in the following points: 1. By multi-source flow data acquisition and graph convolution modeling, an induced topology graph is constructed, attack response patterns are identified by combining message passing analysis and graph attention calculation, intelligent conversion from raw network flow to attack pattern recognition is realized, the problem that traditional methods cannot effectively capture complex correlation between network nodes is solved, and the early detection capability of hidden attacks and collaborative attacks is improved. 2. Deep graph learning technology is used to extract attack behavior atlas and construct adaptive protection table, hidden attack subgraphs are identified by multi-layer graph propagation and deceptive network structure is generated, intelligent mapping from attack feature analysis to protection strategy generation is realized, the problem of policy solidification and poor adaptability of traditional protection systems is solved, and the active defense capability of the system against unknown attacks and variant attacks is improved. 3. The multi-layer decomposition of the adversarial detection strategy and the optimization of the interleaved detection sequence generate a graph countermeasure matrix, the adaptive response signal is generated by combining active defense prediction and time difference bottleneck analysis, the closed-loop control from detection strategy configuration to intelligent response execution is completed, the problem of lack of intelligence in the response mechanism of traditional systems and unreasonable resource allocation is solved, and the detection accuracy and response efficiency are improved.

[0020] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS

[0021] The drawings herein show specific examples of the technical solutions described in the present application, and constitute part of the specification together with the specific embodiments, for explaining the technical solutions, principles and effects of the present application.

[0022] Unless specifically stated or defined otherwise, the same reference signs in different drawings represent the same or similar technical features, and different reference signs may also be used to represent the same or similar technical features.

[0023] Figure 1 is a flow diagram of a network security intrusion detection method of a fusion graph neural network according to the present application.

[0024] Figure 2 is a structural block diagram of a network security intrusion detection system of a fusion graph neural network according to the present application. DETAILED DESCRIPTION

[0025] In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular sequences of steps, techniques, etc., in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known methods, devices, and circuits are omitted so as not to obscure the description of the present application with unnecessary detail.

[0026] It is to be understood that the terminology "includes", "has", "holds", "contains" and / or "comprising", "including", "containing", "having" and / or "comprises" used in the specification and in the following claims indicates the presence of the stated features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0027] It is also to be understood that the terminology "and / or" used in the present specification and the appended claims means and includes any and all combinations of one or more of the associated listed items and can be used interchangeably with "or".

[0028] Reference throughout this specification to "one embodiment", "an embodiment", or "a specific embodiment", means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Thus, the appearances of the phrases "in one embodiment", "in an embodiment", "in some embodiments", "in other embodiments", "in additional embodiments", and so on, in various places throughout this specification are not necessarily all referring to the same embodiment, unless otherwise specifically stated. The terms "comprise", "comprises", "comprising", "include", "includes", "including", and "contains", "containing", "contained" and "contains" are to be construed as "including but not limited to", unless otherwise specifically stated.

[0029] The technical solutions of the embodiments of the present application are introduced as follows.

[0030] As shown in Figure 1 The present application provides a network security intrusion detection method of a fusion graph neural network, comprising the following steps S110-S160:

[0031] In step S110, multi-source traffic data in the network operation process is collected, the multi-source traffic data including normal node features and induced node features, and the multi-source traffic data is subjected to graph convolution modeling to construct an induced topology graph.

[0032] Specifically, by deploying traffic monitoring devices on key nodes and boundary devices of the network, data packets and connection information transmitted in the network are captured in real time. Deep packet inspection technology and flow statistical analysis methods are used to extract key features such as node communication behavior, data transmission mode, and connection topology relationship from the original network traffic. The monitoring devices include network probes, traffic analyzers, and distributed sensor nodes, which are deployed in a star and mesh hybrid topology to ensure the completeness of network coverage and the accuracy of monitoring. The multi-source traffic data includes two categories of normal node features and induced node features. The normal node features reflect the standard communication behavior of legitimate users and devices in the network, including communication frequency, data flow size, connection duration, and protocol distribution. The induced node features are obtained by actively implanting specially designed monitoring nodes, which can simulate various network behavior patterns to induce potential attackers to expose their attack intentions and behavior characteristics. The data collection system uses a high-frequency sampling and caching mechanism, with a sampling frequency of 1000 times per second and a cache capacity of GB level, to ensure data integrity under high traffic load. All collected traffic data is aggregated to the central analysis platform through an encrypted transmission channel. The platform is equipped with a real-time processing engine and a mass storage system.

[0033] In some embodiments, the graph convolution modeling of the multi-source traffic data to construct the induced topology graph includes: generating a node baseline template according to the normal node features; forming a feature-template coupling relationship by combining the induced node features and the node baseline template; extracting a stable graph connection area in the feature-template coupling relationship; and forming an induced topology graph based on the topology weight of the stable graph connection area.

[0034] The normal node features include the communication frequency distribution, packet size statistics, connection duration distribution, and protocol usage ratio of the node, and the like. The clustering analysis method is used to group the normal nodes according to the similarity of the behavior characteristics, and each cluster represents a typical normal node behavior mode. The statistical modeling method is used to build the baseline template, and the statistical parameters such as the mean, standard deviation, quantile, and distribution function of each type of normal node feature are calculated. The probability distribution model of the node behavior is established, and the Gaussian mixture model is used to describe the distribution characteristics of the normal node features, and the model parameters are determined by the maximum likelihood estimation method. The baseline template contains the normal value range and change trend of the behavior characteristics, and is used as a reference standard for subsequent anomaly detection and induction analysis. The generation process of the template uses the sliding time window technology, and the window length is determined according to the periodic characteristics of the network traffic, and is usually set to the hour level or day level time scale. The time evolution mechanism of the template is established, and the baseline template parameters are adjusted periodically according to the changes of the network environment and the evolution of the user behavior.

[0035] The feature-template coupling relationship is formed by combining the induced node features and the node baseline template. The acquired induced node features are associated with the established node baseline template, and the coupling relationship between the two is established by comparison and mapping. The construction of the feature-template coupling relationship uses a multi-dimensional similarity calculation method, including Euclidean distance, cosine similarity, and Mahalanobis distance measurement methods. The coupling strength of the induced node features and the baseline template is calculated by the similarity function, and the high coupling strength indicates that the induced node behavior is close to the normal mode, and the low coupling strength indicates that there is a significant behavior deviation. A dynamic adjustment mechanism of the coupling relationship is established, and the coupling parameters are updated in real time according to the time variation of the induced node features and the evolution of the baseline template. The mathematical representation of the coupling relationship uses the form of the association matrix C=[c_ij], wherein c_ij represents the coupling strength of the i th induced node feature and the j th baseline template component. The principal component analysis method is used to reduce the dimension of the coupling relationship, and the main coupling mode and the secondary coupling component are extracted. The stability evaluation index of the coupling relationship is established, and the stability degree of the relationship is evaluated by calculating the time variance and spatial distribution characteristics of the coupling strength.

[0036] The stable graph connection region is extracted in the feature-template coupling relationship. The connection strength analysis and time stability evaluation are combined to determine the connection strength between adjacent nodes in the coupling relationship. The region with high and uniform weight value is marked as a strong connection region. The time stability is evaluated by analyzing the change characteristics of the coupling relationship in the time sequence, and the time variance and change trend of the connection strength are calculated. The stable graph connection region is defined as a spatial region with connection strength exceeding the set threshold and time stability meeting the persistence requirement. The connectivity analysis method in graph theory is used to identify the boundary and range of the connection region, and the depth-first search and breadth-first search algorithms are used to traverse the graph structure. A quality evaluation system for the connection region is established, including connection density, average path length, clustering coefficient and modularity, etc. The identified multiple stable graph connection regions are sorted according to their importance, and the processing priority is determined according to the region size, connection strength and network location. The correlation analysis between regions is established to study the interaction and influence relationship between different stable graph connection regions.

[0037] Using the extracted stable graph connection region information, the topological weight of each node and edge in the graph is calculated, and a complete induced topological graph structure is constructed. The calculation of topological weight considers the importance of nodes in the stable graph connection region, connection strength and network location, etc. The node weight is calculated by the centrality measurement method, including degree centrality, betweenness centrality and eigenvector centrality, etc. The edge weight is determined according to the feature similarity and communication frequency of the two end nodes, and the weight calculation formula is w_ij=α·sim(i,j)+β·freq(i,j), where sim(i,j) is the feature similarity of nodes i and j, freq(i,j) is the communication frequency, and α and β are weight coefficients. The construction of induced topological graph adopts weighted graph representation, and the adjacency matrix of the graph contains connection relationship and weight information. The hierarchical structure of the graph is established, and the graph is divided into core layer, intermediate layer and edge layer according to the importance and functional characteristics of the nodes. The graph layout algorithm is used to arrange the induced topological graph in space, and the force-directed layout or hierarchical layout method is used to realize the reasonable distribution of nodes. The dynamic evolution model of the graph is established to describe the law of the induced topological graph changing with time and network conditions. The topological characteristics of the induced topological graph are analyzed, and the structure parameters such as diameter, average clustering coefficient and small-world characteristics of the graph are calculated.

[0038] In step S120, the message transmission analysis is performed based on the induced topological graph to identify the attack response mode, the graph attention calculation is performed on the attack response mode to generate an attention vector, the abnormal resonance amplification is performed in the attention vector to generate a node embedding representation, and the graph convolution propagation is performed on the node embedding representation to generate a resonance enhancement domain.

[0039] Specifically, attack response patterns are identified based on the induced topological graph for message passing analysis. The message passing analysis adopts an asynchronous message propagation protocol, and each node calculates the message passing intensity according to the state information and connection weight of its neighbor nodes. The message passing mechanism follows the aggregation-update framework of graph neural networks, and the node performs information fusion and state update after collecting messages from neighbors. The identification of attack response patterns is based on the abnormal deviation degree of node behavior, and when the message passing pattern of the node is significantly different from the normal baseline template, the node is marked as a potential attack response point. The attack response intensity calculation formula R = ∑w_ij × |m_i - m_baseline| is established, where R is the response intensity, w_ij is the connection weight, m_i is the message feature of node i, and m_baseline is the baseline message pattern. The message passing process adopts a multi-round iteration mechanism, and the node state is updated according to the received message in each round of iteration. The number of iterations is determined according to the diameter of the graph and the convergence condition. Attack response patterns include single-point attack patterns, collaborative attack patterns, and cascading attack patterns, etc. Different types of patterns correspond to specific message passing features and node response rules. A feature extraction method for pattern recognition is established to extract attack pattern recognition features from the timing characteristics, spatial distribution, and intensity changes of message passing.

[0040] The graph attention calculation is performed on the attack response pattern to generate an attention vector. A multi-head attention architecture is adopted, and each attention head focuses on different aspect features of the attack response pattern. The calculation of attention weights is based on the similarity of node features and attack response intensity, and the attention coefficients are normalized by the softmax function. The mathematical expression of the attention mechanism adopts the scaled dot-product attention form Attention(Q, K, V) = softmax(QK^T / √d_k)V, where Q, K, and V are query, key, and value matrices, respectively, and d_k is the key vector dimension. Multi-head attention is achieved by parallel computing multiple attention functions and concatenating the results, and the final output attention vector contains the importance information of the attack response pattern in different dimensions. The generation of the attention vector considers the temporal dependence and spatial locality of the attack response pattern, and the accuracy of the attention calculation is enhanced through position encoding and neighborhood perception mechanism. The explainability analysis of attention weights is established, and the contribution degree of different nodes and connections in attack detection is displayed through visualization technology. The dimension of the attention vector is determined according to the size of the graph and the requirement of computational complexity, and is usually set to a high-dimensional vector of several tens to several hundred dimensions. The attention dropout technology is adopted to improve the generalization ability of the model, and part of the attention connections are randomly shielded to prevent overfitting phenomenon.

[0041] In some embodiments, the generating node embedding representation by abnormal resonance amplification in the attention vector comprises: segmenting the attention vector into a dominant frequency band and an auxiliary frequency band; transmitting a signal scanning path from the dominant frequency band to the auxiliary frequency band; recording the positions of the points of sudden increase in intensity on the signal scanning path to form a sudden increase point set; and marking the point with the maximum intensity in the sudden increase point set to generate a node embedding representation.

[0042] The attention vector is decomposed and segmented according to the frequency domain characteristics, and the dominant frequency band with energy concentration and the auxiliary frequency band with energy dispersion are identified. The fast Fourier transform technique is used to convert the time domain attention signal into a frequency domain representation, and the amplitude and phase information of each frequency component are obtained. The identification of the dominant frequency band is based on energy distribution analysis, and the power spectral density of each frequency component is calculated. When the power density exceeds a certain proportion of the total energy, the frequency band is divided into a dominant frequency band. The auxiliary frequency band is defined as the remaining frequency components other than the dominant frequency band. These frequency bands usually contain noise signals and secondary attack feature information. An adaptive threshold mechanism for frequency band segmentation is established, and the threshold is dynamically adjusted according to the overall energy distribution and signal-to-noise ratio of the attention vector. A multi-resolution analysis method is used to decompose the attention vector into wavelets, and the distribution characteristics of the dominant frequency band and the auxiliary frequency band are identified at different scales. The dominant frequency band usually corresponds to the main features and key response patterns of the attack behavior, and the auxiliary frequency band may contain detailed information and hidden features of the attack. An importance evaluation index of the frequency band is established to determine the relative importance of the frequency band by calculating the contribution of each frequency band to the attack detection performance.

[0043] The signal scanning path is transmitted from the dominant frequency band to the auxiliary frequency band. The construction of the signal scanning path uses frequency modulation technology, starting from the center frequency of the dominant frequency band and gradually scanning the frequency range of the auxiliary frequency band. The scanning process uses linear frequency modulation or logarithmic frequency modulation, and the variation rate of the scanning frequency is determined according to the bandwidth and resolution requirements of the frequency band. An amplitude modulation mechanism for the scanning signal is established, and the intensity of the scanning signal is adjusted according to the energy distribution and propagation distance of the dominant frequency band. The mathematical description of the signal propagation path uses the transfer function form H(ω)=Y(ω) / X(ω), where Y(ω) is the frequency domain representation of the output signal and X(ω) is the frequency domain representation of the input scanning signal. The selection of the scanning path considers the correlation and coupling strength between frequency bands, and preferentially selects the path between frequency bands with high correlation for scanning. A multi-path parallel scanning strategy is used to simultaneously detect signal propagation in multiple directions and frequency ranges. A real-time monitoring mechanism for the scanning process is established to record the attenuation, distortion and reflection characteristics of the scanning signal during the propagation process.

[0044] The positions of the points of sudden increase in intensity on the scanning path of the recorded signal form a set of points of sudden increase. A method combining gradient analysis and threshold determination is used to determine a point of sudden increase when the rate of change of signal intensity exceeds a set threshold. The mathematical criterion for sudden increase detection is established as |dI / dx|>threshold, where I is the signal intensity, x is the position coordinate on the propagation path, and threshold is the sudden increase detection threshold. The sliding window technique is used for real-time analysis of signal intensity, and the window size is determined according to the signal change characteristics and detection accuracy requirements. The position record of the point of sudden increase includes key information such as spatial coordinates, time stamp and intensity value, forming a complete sudden increase event database. A classification system for points of sudden increase is established, and the points of sudden increase are divided into different types according to the amplitude, duration and frequency characteristics of the intensity sudden increase. The clustering analysis method is used to group the points of sudden increase in space, and the distribution pattern and aggregation characteristics of the points of sudden increase are identified. The construction of the set of points of sudden increase considers the spatio-temporal correlation, and adjacent points of sudden increase may belong to the same attack event or related security threats. An effective screening mechanism for points of sudden increase is established to exclude false points of sudden increase caused by noise and system disturbance.

[0045] The point of sudden increase with the largest intensity in the set of points of sudden increase is marked to generate node embedding representation. A global optimization method is used to search for the position of the point with the highest intensity value in the entire set of points of sudden increase. A standardized method for intensity comparison is established to convert the intensity values at different positions and times into comparable standardized values. The marking of the point of maximum intensity includes position coordinates, intensity value, frequency characteristics and time information, etc. The generation of node embedding representation is based on the feature vectorization of the point of maximum intensity, which converts the multi-dimensional attributes of the point into fixed-dimensional embedding vectors. A nonlinear mapping method is used to map the original features of the intensity point to the embedding space, maintaining the relative relationship and distance information between the features. A standardized processing mechanism for embedding vectors is established to ensure that the embedding representations of different nodes have the same numerical range and distribution characteristics. The final output of node embedding representation adopts the format of dense vector, which is convenient for subsequent graph neural network processing and similarity calculation.

[0046] The graph convolution propagation is used to generate a resonance enhanced domain for the node embedding representation. The graph convolution propagation adopts a combination of spectral domain convolution and spatial domain convolution. The spectral domain convolution is used to propagate global information by using the Laplacian matrix of the graph, and the spatial domain convolution is used to realize local feature extraction by neighborhood aggregation. The mathematical expression of the graph convolution layer is H(l+1)=σ(D^(-1 / 2)AD^(-1 / 2)H^(l)W^(l)), where A is an adjacency matrix, D is a degree matrix, H^(l) is a feature matrix of the lth layer, and W^(l) is a trainable parameter matrix. The formation of the resonance enhanced domain is based on the multi-layer cumulative effect of the graph convolution propagation. Each layer of convolution expands the propagation range of information and enhances the expression ability of features. An adaptive selection mechanism of propagation depth is established to determine the optimal number of convolution layers according to the size of the graph and the complexity of the task. The residual connection and batch normalization techniques are used to stabilize the training process of the deep graph convolution network. The spatial range of the resonance enhanced domain is determined by calculating the effective receptive field, and the size of the receptive field reflects the range of the graph structure that can be perceived by the node. A boundary detection method of the enhanced domain is designed to identify the effective range and decay boundary of the resonance effect.

[0047] In step S130, the induced node features are subjected to deep graph learning to extract an attack behavior graph, graph pooling is performed on the attack behavior graph to obtain attack intention encoding, the attack intention encoding is subjected to graph inversion mapping to generate a protection strategy representation, and a dynamic topology transformation is constructed based on the protection strategy representation to generate an adaptive protection table.

[0048] Specifically, the induced node features are subjected to deep graph learning to extract an attack behavior graph. A hybrid architecture combining a graph convolutional neural network and a graph attention network is used for deep graph learning. The first layer is a feature embedding layer, which maps the induced node features to a unified vector space. The second and third layers are graph convolution layers, which learn the local structural features and global position information of the nodes through a neighborhood information aggregation mechanism. The fourth layer is a graph attention layer, which calculates the attention weights between nodes and highlights important attack association relationships. The construction of the attack behavior graph is based on the learned node representation and edge weight. The nodes in the graph represent attack entities, and the edges represent the propagation paths and influence relationships of attack behaviors. A hierarchical structure of the graph is established, and the attack behaviors are divided into multiple levels according to their severity and impact range. Each level corresponds to a different level of security threat. The attack behavior graph contains key information such as attack source identification, attack path tracking, attack target prediction, and attack impact assessment. A graph contrast learning method is used to enhance the discrimination ability of attack behavior patterns. The unique features of attack behaviors are extracted through positive and negative sample contrast learning.

[0049] Attack intention encoding is obtained by graph pooling from the attack behavior graph. A hierarchical pooling strategy is adopted, including node-level pooling, subgraph-level pooling, and whole-graph-level pooling. Node-level pooling aggregates local features of nodes through max-pooling or average-pooling operations, retaining the most important attack feature information. Subgraph-level pooling divides the attack behavior graph into several semantically related subgraphs, each corresponding to a specific attack intention pattern. Whole-graph-level pooling compresses the entire attack behavior graph into a fixed-dimensional vector representation, forming the global encoding of attack intention. The generation of attack intention encoding adopts learnable pooling parameters, and the pooling weights are optimized through the backpropagation algorithm to obtain the optimal encoding effect. A multi-scale pooling mechanism is established to extract attack intention feature information at different spatial scales, capturing multi-level intentions from fine-grained attack behaviors to coarse-grained attack strategies. Attack intention encoding contains key attribute information such as attack type, attack strength, attack duration, and attack coverage. An attention-guided pooling method is used to assign different pooling weights based on the importance of attack behaviors, highlighting the representation of key attack intentions.

[0050] In some embodiments, the graph inversion mapping of the attack intention encoding to generate a defense strategy representation includes: malicious information interception identification of the attack intention encoding to generate an interception blank area; security gain evaluation according to the interception blank area to form a gain coefficient; generating continuous security coverage by mapping interpolation through the gain coefficient; and implementing feature extraction according to the continuous security coverage to generate a defense strategy representation.

[0051] Malicious information interception identification of attack intention encoding generates an interception blank area. A multi-level detection strategy is adopted, including syntax layer detection, semantic layer detection, and behavior layer detection. Syntax layer detection identifies abnormal encoding formats and data distributions by analyzing the structural features and data patterns of the encoding. Semantic layer detection identifies potential malicious semantics and attack targets by understanding the meaning and intention of the encoding. Behavior layer detection identifies malicious attack behaviors by analyzing the corresponding behavior patterns and impact consequences of the encoding. Interception processing uses information isolation and content filtering technology to separate and remove the identified malicious information from the original encoding. The interception blank area is defined as the hollow area formed in the encoding space after the malicious information is removed, which originally contains attack-related information content. The geometric features of the blank area are described, including the location, size, shape, and boundary features of the blank area. Topological analysis method is used to study the connectivity and distribution pattern of the interception blank area, and the association between different blank areas is identified. The importance evaluation index of the blank area is established, and the security value of the blank area is determined according to the danger level and impact range of the intercepted malicious information.

[0052] The safety gain evaluation based on the intercepted blank area forms a gain coefficient. A multi-factor analysis method is used to comprehensively consider factors such as the importance of the position of the intercepted blank area, the coverage range, and the protection potential. A gain calculation model G = a × S + b × C + g × P is established, where G is the safety gain, S is the importance score of the blank area, C is the coverage range coefficient, P is the protection potential index, a, b, and g are weight parameters. The importance score is determined by analyzing the key degree of the blank area in the attack path and the influence degree on the attack success rate. The coverage range coefficient reflects the number of network nodes and the number of attack vectors that can be protected by the blank area. The protection potential index represents the degree of security performance improvement that can be obtained after deploying protection measures in the blank area. The calculation of the gain coefficient considers the time factor and dynamic changes, and a time-varying gain model is established to describe the evolution law of the gain coefficient with time. The sensitivity analysis method is used to evaluate the influence degree of different factors on the gain coefficient, and the key factors affecting the safety gain are identified. A standardization processing mechanism of the gain coefficient is established to convert the gain indicators of different dimensions and numerical ranges into unified standardized coefficients.

[0053] For example, the continuous safety coverage generated by the mapping interpolation of the gain coefficient includes: determining an observation window according to the gain coefficient and identifying coverage mutation characteristics, the coverage mutation characteristics including a safety intensity change rate, a coverage duration interval, and a recession gradient; tracing a security evolution process along the observation window to form a security situation map; extracting coverage coordinates of each critical point in the security situation map; and arranging the coverage coordinates according to the safety level to generate continuous safety coverage.

[0054] The observation window is determined according to the gain coefficient and the identification of the coverage mutation characteristics. The change rate analysis and gradient detection method is used to identify the coverage mutation characteristics, and the first and second derivatives of the gain coefficient in time and space are calculated. The safety intensity change rate is determined by calculating the difference of the gain coefficient between adjacent time points or spatial points. When the change rate exceeds a certain threshold, it is marked as a mutation characteristic. The coverage duration interval represents the time or spatial range in which the mutation characteristic remains stable, and is determined by analyzing the duration and influence range of the change rate. The recession gradient describes the decay process of the mutation characteristic from the peak value to the normal level, and the gradient parameters are calculated by fitting the decay curve. The determination of the observation window considers the intensity, duration, and influence range of the mutation characteristic, and the window size is adaptively adjusted according to the time and space scales of the mutation characteristic. A multi-resolution observation mechanism is established to set observation windows at different time scales and spatial scales to capture mutation phenomena at different levels. The sliding window technology is used to realize the dynamic adjustment of the observation window, and the window position and size change with the evolution of the mutation characteristic. A window overlap processing mechanism is established, and when multiple observation windows overlap, a priority rule is used to determine the main observation area.

[0055] The security evolution process is tracked along the observation window to form a security posture graph. The security state is represented as a multi-dimensional state vector through the state space method, and the trajectory of the state vector is tracked over time series. A state transition model is established to describe the transition relationship and transition probability between security states, and the model parameters are determined through historical data statistics and expert knowledge. The security posture graph is constructed using graph theory, with nodes representing different security states and edges representing the transition relationship and evolution path between states. The posture graph contains attribute information of the state nodes, such as security level, threat level, coverage intensity, and duration of key parameters. The Markov chain model is used to describe the random evolution process of the security state, and the probability distribution of the future security posture is calculated through the state transition matrix. A hierarchical structure of the posture graph is established to decompose the complex security evolution process into multiple levels and stages, each level corresponding to different time scales and security concerns.

[0056] The coverage coordinates of each critical point are extracted within the security posture graph. The definition of critical points includes turning points of security states, jumping points of threat levels, extreme points of coverage intensity, and bifurcation points of evolution paths, etc. Critical point identification uses key node detection methods in graph theory, including degree centrality, betweenness centrality, and eigenvector centrality. Mathematical criteria for critical points are established to determine the importance ranking of critical points by calculating local features and global influence. The extraction of coverage coordinates includes the precise location of critical points on the time axis and spatial axis, as well as the corresponding security level and coverage intensity, etc. Precise positioning techniques are used to determine the coordinate values of critical points, and interpolation and fitting methods are used to improve coordinate accuracy. Standardization of the coordinate system is established to convert coordinates of different dimensions and numerical ranges into a unified standardized coordinate system. The storage format of coordinate data is designed to support efficient coordinate query, sorting, and analysis operations. The correlation analysis method of coordinates is established to study the spatial relationship and time sequence relationship between different critical points. The extracted coverage coordinates are clustered to identify critical point groups and distribution patterns with similar characteristics.

[0057] The continuous security coverage is generated by arranging the coverage coordinates according to the security levels. Based on the multi-criteria ranking method, the factors such as coverage intensity, threat degree, influence range and response priority are comprehensively considered. The hierarchical standards of security levels are established, and the coverage coordinates are divided into different levels such as critical level, important level, general level and secondary level according to the security importance. The arrangement process adopts stable sorting technology to ensure that the coordinate points with the same security level maintain the original relative position relationship. The generation of continuous security coverage is realized by connecting the arranged coverage coordinates, and the smooth coverage boundary is constructed by using spline interpolation or Bezier curve fitting technology. The continuity checking mechanism of coverage is established to ensure the continuity and consistency of the generated security coverage in space and time. The piecewise linear interpolation method is used to process the mutation area of coverage intensity, and the physical rationality of coverage distribution is maintained. The optimization method of coverage range is designed to optimize the distribution effect of security coverage by adjusting the interpolation parameters and boundary conditions.

[0058] The protection strategy representation is generated according to the feature extraction of continuous security coverage. The multi-scale analysis method is used to extract the coverage features at different spatial and temporal scales. The spatial features include coverage intensity distribution, coverage boundary shape, coverage connectivity and coverage density, etc. The time features include coverage evolution trend, coverage stability and coverage response speed, etc. The construction method of feature vector is established to organize the extracted multi-dimensional features into structured feature vector representation. The generation of protection strategy representation adopts feature coding technology to convert the feature vector into machine-readable strategy description format. The strategy representation includes protection type, protection intensity, protection range and protection timing, etc. The semantic mapping method is used to convert the numerical features into semanticized protection strategy description, which improves the understandability and operability of the strategy. The standardized format of strategy representation is established to ensure the interface compatibility of the generated protection strategy with existing security systems.

[0059] Based on the protection strategy representation, the adaptive protection table is constructed by dynamic topology transformation. The dynamic topology transformation adopts graph transformation theory to convert the static protection strategy representation into dynamic network topology structure. The topology transformation includes node reconfiguration, edge weight adjustment and path re-routing, etc. The protection ability of the system is enhanced by changing the connection relationship and communication path of the network. The construction of adaptive protection table considers the real-time changes of network state and the dynamic evolution of attack threat, and establishes the automatic adjustment mechanism of protection strategy. The protection table contains key information such as protection node configuration, protection path planning, protection resource allocation and protection priority setting, etc. The reinforcement learning method is used to train the adaptive adjustment strategy, and the optimal protection decision is learned through interaction with the environment. The multi-version management mechanism of protection table is established to support the protection configuration of different security levels and application scenarios. The fast deployment interface of protection table is designed to realize the real-time effectiveness and dynamic switching of protection strategy.

[0060] In step S140, a multi-layer graph propagation is performed on the resonance-enhanced domain to identify a hidden attack subgraph, a graph atlas fusion is performed on the hidden attack subgraph to generate a camouflage graph embedding, a topology remodeling is performed on the camouflage graph embedding to generate a deceptive network structure, and an anti-detection strategy is generated based on the association between the deceptive network structure and the adaptive protection table.

[0061] Specifically, a multi-layer graph propagation is performed on the resonance-enhanced domain to identify a hidden attack subgraph. The multi-layer graph is propagated through a recursive message passing mechanism, and each layer expands the receptive field range of information propagation to gradually reveal deep hidden attack association relationships. The first layer of propagation focuses on the direct neighbor connections within the resonance-enhanced domain to extract local attack features and short-range dependency relationships. The second and third layers of propagation are extended to two-hop and three-hop neighbors to capture medium-distance attack collaboration patterns and propagation paths. The deep propagation layer is responsible for identifying long-distance attack strategy associations and global attack layouts. The identification of the hidden attack subgraph is based on abnormal structure pattern detection, and when the topological features of the subgraph significantly deviate from the normal network structure, it is marked as a hidden attack target. A subgraph importance evaluation index is established, which comprehensively considers factors such as the size of the subgraph, the connection density, the centrality index, and the propagation influence. A graph attention mechanism is used to enhance the detection ability of hidden features, and the key attack nodes and connection relationships are highlighted through attention weights. A multi-scale subgraph detection method is established to identify various hidden patterns from single-node attacks to large-scale collaborative attacks at different granularities.

[0062] A graph atlas fusion is performed on the hidden attack subgraph to generate a camouflage graph embedding. An adversarial training framework is designed to fuse the graph atlas, and the generator is responsible for embedding the attack subgraph into the normal graph atlas, and the discriminator is responsible for distinguishing whether the fused graph structure contains attack components. The camouflage mechanism imitates the topological features and statistical properties of the normal network to make the attack subgraph difficult to be identified by traditional detection methods after fusion. The embedding process uses a variational graph autoencoder architecture to compress high-dimensional graph structures into low-dimensional embedding vectors while maintaining the topological properties and semantic information of the graph. An embedding quality evaluation system is established to evaluate the performance of the embedding representation through reconstruction error, structure preservation degree, and camouflage effect indicators. The camouflage graph embedding contains two parts: the original attack features and the camouflage mask features, the former retains the core function of the attack, and the latter provides the appearance features of the camouflage. A multi-level fusion strategy is used to perform feature fusion and embedding generation at the node level, edge level, and subgraph level. An adaptive adjustment mechanism for fusion parameters is established to dynamically adjust the fusion strength and camouflage degree according to the attack type and target network characteristics.

[0063] In some embodiments, the topology remodeling of the camouflage graph embedding generates a deceptive network structure, including: constructing a connection time series according to the camouflage graph embedding; performing topology change analysis on the connection time series to form a change time marker; dividing the connection time series into a stable period and a disturbance period according to the change time marker; and generating a deceptive network structure by comparing the structural distribution characteristics of the stable period and the disturbance period.

[0064] A connection time series is constructed according to the camouflage graph embedding. A sliding time window method is used to divide the camouflage graph embedding into continuous time segments on the time axis, each segment corresponding to the network connection state within a time window. The size of the time window is determined according to the network dynamic characteristics and the connection change frequency, and is usually set to a time scale of minutes or hours. The representation of the connection state is in the form of an adjacency matrix time series A(t)=[a_ij(t)], where a_ij(t) represents the connection state and weight between nodes i and j at time t. The sequence construction process considers dynamic events such as connection establishment, disconnection, strength change and direction change, and records the complete evolution process of the connection through event markers and state transitions. A connection change rate calculation method is established to quantify the dynamic activity level of the network by counting the frequency and amplitude of connection changes within a unit time. Data compression techniques are used to optimize the storage of the time series, reducing the storage space of the sequence data through difference coding and sparse representation. A fast query interface for the sequence is designed to support efficient data retrieval based on time range, node identification and connection type.

[0065] Topological change analysis is performed on the connection time series to form a change time marker. Time series analysis of graph metrics is used to detect topology changes, including changes in structural features such as node degree distribution, clustering coefficient, average path length and network diameter. Change detection uses statistical process control methods to identify change points that exceed the normal fluctuation range by calculating the moving average and control limit of the topology metrics. A change significance evaluation standard is established, and when the change amplitude of the topology metrics exceeds a certain multiple of the historical standard deviation, it is marked as a significant change time. The change time marker contains detailed information such as timestamp, change type, change amplitude and impact range. A multi-scale change detection method is used to identify change events at different levels from micro-connection changes to macro-structure reorganization at different time resolutions. A change pattern classification system is established to classify change events into categories such as burst, gradual, periodic and random according to their duration, impact range and intensity characteristics. A clustering analysis method for change times is designed to identify groups of change events that are similar in time and characteristics.

[0066] The connection time series is divided into stable period and disturbance period by change time marker. The stable period is defined as the time interval between two adjacent change time markers, in which the network topology keeps relatively stable, and the connection change amplitude is small and the change frequency is low. The disturbance period is defined as the time interval centered on the change time marker, in which the network structure changes significantly or fluctuates violently. The time period segmentation adopts an adaptive boundary determination method, which dynamically adjusts the boundary position of the stable period and the disturbance period according to the strength and influence range of the change time marker. The statistical analysis of the time period length is established, and the average duration, length distribution and periodicity characteristics of the stable period and the disturbance period are calculated. The overlapping window processing technology is adopted when the change time markers are too dense to avoid information loss. The time period quality evaluation index is established, including the connection stability in the period, the significant difference between the periods and the accuracy of the segmentation boundary. The standardized processing method of the time period is designed to convert the time period of different lengths into a standardized representation of fixed length, which is convenient for subsequent comparative analysis. The inter-period correlation analysis is established to study the mutual relationship and conversion law between adjacent stable period and disturbance period.

[0067] For example, the structure distribution characteristics of the stable period and the disturbance period are compared to generate a deceptive network structure, including: converting the topology sequence of the stable period into a structure accumulation sequence; superimposing the topology sequence of the disturbance period onto the structure accumulation sequence to form a structure difference graph; extracting a topology jump accumulation in the structure difference graph; and generating a deceptive network structure according to the distribution density of the topology jump accumulation.

[0068] The topology sequence of the stable period is converted into a structure accumulation sequence. The accumulation transformation of the topology sequence adopts a discrete integral method to calculate the accumulation of the topology feature on the time axis C(t)=Σ[τ=0→t]T(τ), where T(τ) is the topology feature value at time τ, and C(t) is the structure accumulation at time t. The accumulation process considers the weight difference of different topology features, and highlights the contribution of important structure features through weighted accumulation method. A normalization processing mechanism of the accumulation sequence is established to convert the accumulation values of different dimensions and numerical ranges into a unified standardized representation. The sliding average technique is used to smooth the accumulation sequence to eliminate noise fluctuations and abnormal jumps in the accumulation process. The structure accumulation sequence contains multi-dimensional accumulation information such as accumulation degree feature, accumulation clustering feature, accumulation path feature and accumulation connectivity feature. An accumulation rate analysis method is established to identify the fast and slow change stages of structure accumulation by calculating the derivative of the accumulation sequence. The storage format of the accumulation sequence is designed, and the compression encoding technology is used to reduce the storage overhead of the sequence data.

[0069] The structural difference map is formed by misaligning the topological sequence of the perturbation period to the structural cumulative sequence. Based on the time offset technique, the perturbation period sequence is translated on the time axis and then superimposed with the cumulative sequence D(t) = C(t) + a x T_d(t - d), where C(t) is the structural cumulative sequence, T_d(t - d) is the perturbation period sequence with time offset d, and a is the superimposition weight coefficient. The time offset d is determined by correlation analysis and cross-correlation function calculation, and the offset value that makes the correlation of the two sequences the strongest or the difference the largest is selected. The superimposition weight coefficient a is dynamically adjusted according to the perturbation intensity and the cumulative reference, to ensure that the difference map after superimposition has appropriate contrast and resolution. The construction of the structural difference map adopts a multi-channel superimposition method, and different types of topological features are independently misaligned, superimposed and difference calculated. A visualization display method of superimposition effect is established, and the spatial distribution of structural difference is intuitively displayed through color coding and contour map. The difference enhancement technique is used to process the superimposition result, and the key structural difference features are highlighted through contrast adjustment and edge sharpening. A resolution control mechanism of the difference map is established, and the time resolution and spatial resolution of the difference map are adjusted according to the analysis accuracy requirement.

[0070] The topological jump cumulative quantity is extracted in the structural difference map. According to the gradient analysis and edge detection method, the jump position is identified by calculating the spatial gradient and time gradient of the difference map. The jump detection adopts a threshold judgment criterion , where is the gradient amplitude of the difference map, and threshold is the jump detection threshold. The extraction of the cumulative quantity adopts the area integration method, and the cumulative integral of the difference value A = ∫∫[Region] D(x, t) dx dt is calculated in the identified jump region. A jump intensity grading system is established, and the jump events are divided into different levels such as strong jump, medium jump and weak jump according to the size of the cumulative quantity. The morphological processing technique is used to regularize the jump region, and the isolated jump points and jump voids are eliminated and filled through dilation and erosion operations. A time series analysis method of the jump cumulative quantity is established, and the distribution rule and evolution trend of the jump events in time are studied. The statistical feature extraction of the cumulative quantity is designed, including the mean, variance, skewness and kurtosis of the cumulative quantity. A clustering analysis method of the cumulative quantity is established, and the jump events are grouped and classified according to the numerical characteristics and spatial positions of the cumulative quantity.

[0071] The deceptive network structure is generated according to the distribution density of the topological jump cumulative quantity. The distribution density is calculated by using the kernel density estimation method, and the probability density distribution of the cumulative quantity in space is calculated by using a Gaussian kernel function or other kernel functions ρ(x) = (1 / nh)Σ[i=1→n]K((x-xi) / h), wherein K is a kernel function, h is a bandwidth parameter, and xi is the position coordinate of the cumulative quantity. The generation of the deceptive network structure adopts the density sampling technology, increases the density of nodes and connections in the high-density area, and reduces the structural complexity in the low-density area. A probability model of structure generation is established, and the generation probability and position distribution of network elements are determined according to the density distribution. A Poisson point process is used to simulate the random distribution of nodes, and the node density function is determined according to the cumulative quantity density distribution. The connection generation adopts a distance-dependent probability model, and the connection probability is related to the distance between nodes and the local density. A structure constraint mechanism is established to ensure that the generated deceptive network meets the basic requirements of connectivity, stability and functionality. A structure optimization method is designed to optimize the topological parameters and connection mode of the deceptive network by using a genetic algorithm or a simulated annealing algorithm.

[0072] The countermeasure detection strategy is generated based on the association between the deceptive network structure and the adaptive protection table. The formulation of the countermeasure detection strategy is based on the game theory framework, and the attack party and the protection party are modeled as game parties to analyze the strategy space and equilibrium solution of the two parties. The strategy generation considers the deception characteristics of the deceptive network structure and the protection ability of the adaptive protection table, and optimizes the overall protection effect through strategy matching and resource allocation. An antagonistic strength evaluation model is established to quantify the antagonistic degree and winning probability between the deceptive attack and the protection strategy. An adaptive countermeasure strategy is trained by using a reinforcement learning method, and the optimal detection and response strategy is learned through repeated interaction with the deceptive attack. The countermeasure detection strategy includes active detection, passive monitoring, induced analysis and counterattack, and the like. A dynamic switching mechanism of the strategy is established to adjust the detection strategy in real time according to the change of the attack situation and the feedback of the antagonistic effect. A cooperative execution framework of the strategy is designed to improve the success rate and robustness of the countermeasure detection through the cooperative work of multiple detection modules.

[0073] In step S150, the countermeasure detection strategy is decomposed into multi-layer detection rules, the multi-layer detection rules are graph-optimized and sequenced to generate an interleaved detection sequence, and a graph countermeasure matrix is generated based on the interleaved detection sequence.

[0074] Specifically, the adversarial detection strategy is decomposed into multi-layer detection rules. A function-oriented hierarchical division method is designed to decompose the adversarial detection strategy into three core layers, i.e., a front-end perception layer, a middle analysis layer, and a back-end decision layer, according to the detection target, processing level, and response mechanism. The detection rules of the front-end perception layer focus on the collection and preliminary filtering of original data, including basic detection components such as traffic capture rules, abnormal traffic identification rules, and real-time monitoring rules. The detection rules of the middle analysis layer are responsible for deep data mining and pattern recognition, and identify and analyze complex attacks through correlation analysis rules, behavior modeling rules, and threat evaluation rules. The detection rules of the back-end decision layer handle high-level threat judgment and response strategy selection, including decision-making components such as threat level judgment rules, response strategy matching rules, and countermeasure activation rules. An information transmission interface between layers is established to realize the coordination between different detection rules through standardized data formats and communication protocols. A modular encapsulation mechanism for rules is designed, and each detection rule includes three standardized components: input interface, processing logic, and output interface.

[0075] In some embodiments, the graph optimization sorting of the multi-layer detection rules generates an interleaved detection sequence, including: converting the multi-layer detection rules into a priority vector field; finding a resource-balanced core in the priority vector field; performing rule propagation from the resource-balanced core as a starting point to form an initial arrangement domain; and performing boundary convergence on the initial arrangement domain to form an interleaved detection sequence.

[0076] The multi-layer detection rules are converted into a priority vector field. A feature space mapping method is used to convert the vector field, and the attribute features of each detection rule are mapped into a vector point in the vector field. The vectorized representation of the detection rule includes rule type, execution complexity, resource demand, detection accuracy, and response time, among other feature dimensions. The calculation of priority uses the analytic hierarchy process to determine the relative weights of each feature dimension by constructing a judgment matrix and calculating a feature vector. The construction of the vector field uses continuous interpolation technology to establish a smooth transition continuous field distribution between discrete rule vector points. A field strength calculation method is established |F(x, y)| = √(Fx And The topological properties and flow characteristics of the vector field are analyzed. 2 +Fy 2 ), where Fx and Fy are the components of the vector field in the x and y directions, respectively. A multi-resolution field representation technique is used to construct a hierarchical representation of the vector field at different levels of accuracy. Boundary conditions of the vector field are designed, and periodic or absorbing boundary conditions are used in the boundary regions of the field. The calculation of the curl and divergence of the field is established, and the flow characteristics of the field are analyzed through

[0077] The resource equilibrium core is searched in the priority vector field. The constructed priority vector field is globally analyzed to identify the key core positions that can achieve the optimal configuration and load balancing of the detection resources. The critical point analysis method in field theory is used to search for the resource equilibrium core. The candidate core positions are determined by finding the zero points, saddle points and extreme points of the vector field. The equilibrium evaluation function E(x, y) = w1·R(x, y) + w2·P(x, y) - w3·C(x, y) is established, where R is the resource utilization rate, P is the performance index, C is the cost function, and w1, w2, w3 are weight coefficients. The gradient analysis method ∇E = 0 is used to solve the extreme points of the equilibrium function, and the stability of the extreme points is judged by the eigenvalue analysis of the Hessian matrix. A competition selection mechanism for multiple candidate cores is established, and the optimal resource equilibrium core is selected from multiple candidate positions through performance comparison and stability analysis. A dynamic tracking algorithm for the core is designed to monitor the migration trajectory of the equilibrium core with changes in system load and rule configuration. A robustness analysis method is used to evaluate the sensitivity of the core position to parameter perturbations, ensuring that the selected equilibrium core has good anti-interference ability. The influence domain analysis of the core is established to determine the effective influence range of the core by calculating the potential function distribution around the core. The characteristic description of the resource equilibrium core includes key parameters such as spatial coordinates, equilibrium strength, stability index and influence radius.

[0078] The initial arrangement domain is formed by propagating rules from the resource equilibrium core. Starting from the determined resource equilibrium core, the arrangement information of the detection rules is propagated to the surrounding space using a diffusion propagation mechanism, gradually constructing an initial arrangement domain covering the entire vector field. An anisotropic diffusion model is used, and the propagation speed and direction are determined according to the local characteristics and gradient direction of the vector field. The propagation control equation is established as where u is the propagation density, D is the diffusion tensor, and S is the source term. The propagation process considers the interaction and competition between rules, and the nonlinear dynamics of rule propagation is modeled by a reaction-diffusion equation. The wave front tracking technique is used to monitor the evolution process of the propagation boundary, and the dynamic characteristics such as the position, shape and propagation speed of the wave front are recorded. A propagation impedance model is established to consider the hindering effect of obstacle regions and low priority regions in the vector field on the propagation process. A multi-source propagation mechanism is designed, and when there are multiple equilibrium cores, multiple propagation sources are started simultaneously to form complex arrangement patterns through the intersection and interference of propagation wave fronts. The propagation termination condition is established, and the propagation process is stopped when the propagation intensity decays below the threshold or reaches the field boundary. The characteristics of the initial arrangement domain include geometric and physical properties such as propagation coverage, density distribution, propagation time and boundary shape.

[0079] The initial arrangement domain is subjected to boundary convergence to form an interleaved detection sequence. Based on the constructed initial arrangement domain, boundary optimization and convergence techniques are used to fine-tune the shape and range of the arrangement domain to generate the final interleaved detection sequence. According to the variational principle, the energy functional where Γ is the boundary curve, k is the curvature, f is the constraint function, and λ is the Lagrange multiplier. The convergence process solves the variational problem using the gradient descent method, iteratively updating the boundary shape until it converges to the optimal configuration. Convergence constraints are established to ensure that the converged boundary satisfies the detection coverage completeness and connectivity requirements. A multi-scale convergence strategy is employed, starting with a coarse initial boundary and gradually refining it to the precise optimal boundary. A convergence stability control mechanism is designed to avoid oscillation and divergence in the convergence process through step adaptation and convergence monitoring. Boundary topology preservation constraints are established to ensure that the basic topological structure of the boundary does not change during the convergence process. The generation of interleaved detection sequences is based on the internal structure of the converged arrangement domain, generating an ordered execution sequence through spatial sampling and rule ordering. Sequence optimization techniques are used to further optimize the generated initial sequence, improving the execution efficiency of the sequence through local search and sequence rearrangement.

[0080] Based on the interleaved detection sequence, a graph countermeasure matrix is generated. The graph countermeasure matrix is represented by a sparse matrix, with row indices corresponding to known attack types and variants, column indices corresponding to each detection rule in the interleaved detection sequence, and matrix element values representing the effectiveness and matching degree of a specific rule against a specific attack. The quantification of countermeasure effectiveness uses statistical analysis of historical detection data to evaluate the countermeasure performance of the rules by calculating detection success rate, false positive rate, and false negative rate. A sparse storage and fast query mechanism for the matrix is established, using compressed row storage format and hash index technology to improve the computational efficiency of matrix operations. An incremental update algorithm for the matrix is designed to quickly expand and adjust the matrix when new attack types or new detection rules are discovered. Matrix decomposition techniques are used to extract the main countermeasure patterns, identifying key attack-countermeasure association patterns through singular value decomposition or non-negative matrix factorization. An intelligent recommendation system for countermeasure strategies is established to automatically select the optimal combination of countermeasure strategies based on the current detected attack characteristics.

[0081] Step S160, based on the graph countermeasure matrix, generate an active defense prediction, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete intrusion detection.

[0082] Specifically, the active defense prediction is generated based on the graph countermeasure matrix. The active defense prediction adopts a matrix vector multiplication operation P=MxV, where P is a prediction vector, M is a graph countermeasure matrix, and V is a current threat feature vector. The prediction generation process considers the time sequence evolution characteristics of attack behavior, predicts the next step of attack and target selection through time series analysis and trend extrapolation. A multi-step prediction mechanism is established to not only predict the immediate attack behavior, but also predict the medium and long-term development trend and possible variation path of the attack. The prediction result contains key information such as attack type probability, attack time window, attack target node and attack intensity level. A probabilistic graph model is used to describe the uncertainty of the prediction, and a Bayesian network and Markov chain are used to model the randomness and conditional dependence of attack behavior. A prediction confidence calculation method is established to evaluate the credibility of the prediction result through the historical prediction accuracy and the current data quality. A hierarchical output mechanism of the prediction result is designed, and the prediction result is divided into three levels of immediate warning, medium-term attention and long-term monitoring according to the threat level and the degree of urgency.

[0083] In some embodiments, the graph classification evaluation of the active defense prediction generates an adaptive response signal, including: time difference bottleneck positioning identification of the active defense prediction generates transmission time difference and calculation time difference; correlation degree evaluation of the calculation time difference is performed by using the transmission time difference to form a time difference correlation graph; key time difference factors are generated by principal component decomposition through the time difference correlation graph; and a response adjustment is implemented according to the key time difference factors to generate an adaptive response signal.

[0084] The time difference bottleneck positioning identification of the active defense prediction generates transmission time difference and calculation time difference. Through an end-to-end time delay decomposition method, the total processing time of the active defense prediction is decomposed into data transmission time delay, calculation processing time delay, storage access time delay, and communication coordination time delay. The measurement of transmission time difference adopts time stamp marking technology, and accurate time marks are set at the starting point and the terminal point of data transmission. The accurate transmission time delay data is obtained by calculating the time difference. The identification of calculation time difference is realized by CPU performance monitoring and task scheduling analysis. The time consumption of calculation processing is quantified by monitoring the utilization rate of the processor, the memory access mode, and the instruction execution period. An accuracy control mechanism of time difference measurement is established, and high-precision timers and synchronous clocks are used to ensure the accuracy and consistency of time difference measurement. Statistical analysis method is used to process the measured time difference data, and statistical parameters such as average time difference, time difference variance and time difference distribution characteristics are calculated. A time difference classification standard is established, and the time difference is divided into different levels such as slight time difference, medium time difference and serious time difference according to the numerical value and influence degree of the time difference.

[0085] The correlation degree of the calculation time difference is evaluated by using the transmission time difference to form a time difference correlation graph. Statistical methods such as Pearson correlation coefficient and Spearman rank correlation coefficient are used to evaluate the correlation degree and quantify the linear and nonlinear correlation strength between the transmission time difference and the calculation time difference. The calculation formula of the correlation strength coefficient r = Σ (xi-xm) (yi-ym) / √ [Σ (xi-xm) 2 ×Σ (yi-ym) 2 ] is established, where xi represents the ith sample value of the transmission time difference, yi represents the ith sample value of the calculation time difference, xm represents the mean value of the transmission time difference samples, and ym represents the mean value of the calculation time difference samples. The construction of the time difference correlation graph adopts a weighted graph representation, where the nodes represent different time difference measurement points, and the edge weights represent the correlation strength between the nodes. The connectivity analysis method in graph theory is used to identify the strongly connected components and critical paths in the time difference correlation graph, revealing the main channels and influence mechanisms of the time difference propagation. The topological feature analysis of the correlation graph is established, and the structure characteristics of the correlation graph are described by calculating the clustering coefficient, average path length and node degree distribution. The graph partitioning algorithm is used to divide the time difference correlation graph into modules, and identify time difference groups and substructures with similar correlation characteristics.

[0086] The key time difference factors are generated by principal component decomposition of the time difference correlation graph. Principal component analysis is performed on the constructed time difference correlation graph to extract key time difference factors and main variation patterns that affect system performance through dimension reduction techniques. The principal component decomposition adopts the eigenvalue decomposition method, and the adjacency matrix of the time difference correlation graph is decomposed as A = QΛQ^T, where Q is the eigenvector matrix and Λ is the eigenvalue diagonal matrix. The identification of key time difference factors is based on the size ordering of eigenvalues, and the eigenvectors corresponding to the first few largest eigenvalues are selected as the main time difference factors. The variance contribution rate calculation method is established to determine the number of principal components to be retained by analyzing the variance contribution rate of each principal component. The factor loading analysis technique is used to explain the physical meaning of each principal component, and the system bottlenecks and performance influencing factors corresponding to each key time difference factor are identified. The factor score calculation method is established to project the original time difference data into the principal component space and obtain the score values of each sample on the key time difference factors. The importance ordering mechanism of the factors is designed, and the key time difference factors are ordered according to the eigenvalue size and variance contribution rate. The stability analysis of the factors is established, and the robustness of the key time difference factors is evaluated through perturbation analysis and sensitivity test. The output of the key time difference factors adopts the standardized vector format, which is convenient for subsequent response adjustment processing and parameter optimization.

[0087] The response adjustment is implemented according to the key time difference factors to generate an adaptive response signal. Based on the feedback control principle, the key time difference factors are used as control inputs to adjust the response characteristics of the system through a proportional-integral-derivative controller. The adjustment target function J = Σwi×fi 2where fi is the deviation value of the ith key time difference factor, and wi is the corresponding weight coefficient. The calibration process adopts the gradient descent optimization method, and gradually reduces the deviation of the time difference factor and the system performance loss by iteratively adjusting the response parameters. A multi-objective calibration strategy is established to simultaneously optimize multiple performance indicators such as response speed, accuracy, and resource consumption. The generation of the adaptive response signal takes into account the dynamic characteristics of the system and environmental changes, and ensures the effectiveness and adaptability of the response signal through adaptive parameter adjustment. Signal modulation technology is used to encode and modulate the generated response signal, ensuring reliable transmission of the signal in complex network environments. A priority management mechanism for signals is established, and different response signals are assigned execution priorities according to threat levels and time urgency. The output of the adaptive response signal contains complete response instruction information such as signal type, parameter configuration, execution timing, and expected effect, enabling comprehensive detection, analysis, and response to network intrusion behavior, and completing the closed-loop control process of the entire intrusion detection system.

[0088] In order to perform the network security intrusion detection method of the fusion graph neural network corresponding to the above-mentioned method embodiment, to realize the corresponding functions and technical effects. Referring to Figure 2 , Figure 2 A structural block diagram of a network security intrusion detection system 200 of a fusion graph neural network provided by an embodiment of the present application is shown. For ease of illustration, only the parts related to the present embodiment are shown. The network security intrusion detection system 200 of the fusion graph neural network provided by the embodiment of the present application comprises:

[0089] A data acquisition module 201 is configured to acquire multi-source traffic data in the network operation process, wherein the multi-source traffic data comprises normal node features and induced node features, and the multi-source traffic data is subjected to graph convolution modeling to construct an induced topology graph.

[0090] A message passing module 202 is configured to perform message passing analysis to identify an attack response mode based on the induced topology graph, perform graph attention calculation on the attack response mode to generate an attention vector, perform abnormal resonance amplification in the attention vector to generate a node embedding representation, and perform graph convolution propagation on the node embedding representation to generate a resonance enhancement domain.

[0091] An attack learning module 203 is configured to perform deep graph learning on the induced node features to extract an attack behavior graph, perform graph pooling on the attack behavior graph to obtain an attack intention encoding, perform graph inversion mapping on the attack intention encoding to generate a defense strategy representation, and construct a dynamic topology transformation based on the defense strategy representation to generate an adaptive defense table.

[0092] The topology remodeling module 204 is configured to perform multi-layer graph propagation on the resonance enhancement domain to identify a hidden attack subgraph, perform graph atlas fusion on the hidden attack subgraph to generate a camouflage graph embedding, perform topology remodeling on the camouflage graph embedding to generate a deceptive network structure, and generate an adversarial detection strategy based on the deceptive network structure and the adaptive protection table.

[0093] The detection optimization module 205 is configured to decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence.

[0094] The response output module 206 is configured to generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete intrusion detection.

[0095] The network security intrusion detection system 200 of the fusion graph neural network described above can implement the network security intrusion detection method of the fusion graph neural network of the method embodiment described above. The optional items in the method embodiment described above are also applicable to the present embodiment, and will not be described in detail here. The remaining contents of the present embodiment can be referred to the contents of the method embodiment described above, and will not be described in detail in the present embodiment.

[0096] The purpose of the above embodiments is to exemplarily reproduce and deduce the technical solutions of the present application, and to completely describe the technical solutions, purposes and effects of the present application. The purpose is to make the public understand the disclosure of the present application more thoroughly and comprehensively, and does not limit the protection scope of the present application.

[0097] The above embodiments are also not an exhaustive enumeration based on the present application. In addition, there can be many other unlisted embodiments. Any substitution and improvement made without violating the concept of the present application is within the protection scope of the present application.

Claims

1. A network security intrusion detection method incorporating graph neural networks, characterized in that, include: Collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. Perform graph convolution modeling on the multi-source traffic data to construct an induced topology graph. Based on the induced topology graph, message passing analysis is performed to identify attack response patterns. Graph attention is then performed on the attack response patterns to generate attention vectors. Anomaly resonance amplification is performed on the attention vectors to generate node embedding representations. Graph convolution propagation is then performed on the node embedding representations to generate resonance enhancement domains. Deep graph learning is performed on the features of the inducing nodes to extract an attack behavior graph. Graph pooling is performed on the attack behavior graph to obtain the attack intent encoding. Graph inversion mapping is performed on the attack intent encoding to generate a protection strategy representation. Based on the protection strategy representation, dynamic topology transformation is constructed to generate an adaptive protection table. The process involves: identifying covert attack subgraphs by performing multi-layer graph propagation on the resonant enhancement domain; generating camouflage graph embeddings by performing graph fusion on the covert attack subgraphs; and generating a deceptive network structure by topological reshaping of the camouflage graph embeddings. This includes: constructing a connection time series based on the camouflage graph embeddings; performing topological change analysis on the connection time series to form change time markers; dividing the connection time series into stable and perturbation periods using the change time markers as boundaries; generating a deceptive network structure by comparing the structural distribution characteristics of the stable and perturbation periods; and generating an adversarial detection strategy based on the association between the deceptive network structure and the adaptive protection table. Specifically, generating the deceptive network structure by comparing the structural distribution characteristics of the stable and perturbation periods includes: converting the topological sequence of the stable period into a structural accumulation sequence; misaligning and superimposing the topological sequence of the perturbation period onto the structural accumulation sequence to form a structural difference map; extracting the topological jump accumulation within the structural difference map; and generating a deceptive network structure according to the distribution density of the topological jump accumulation. The adversarial detection strategy is decomposed into multi-layer detection rules, and the multi-layer detection rules are graph-optimized and sorted to generate an interleaved detection sequence. A graph countermeasure matrix is ​​generated based on the interleaved detection sequence. Based on the graph countermeasure matrix, an active defense prediction is generated. The active defense prediction is then evaluated using graph classification to generate an adaptive response signal, thus completing the intrusion detection.

2. The method according to claim 1, characterized in that, The step of constructing an induced topology graph by performing graph convolution modeling on the multi-source traffic data includes: Generate a node baseline template based on the normal node characteristics; The induced node features and the node baseline template are combined to form a feature-template coupling relationship; Extract the stable graph connection region within the feature-template coupling relationship; An induced topology graph is formed based on the topology weights of the connection regions of the stable graph.

3. The method according to claim 1, characterized in that, The step of generating node embedding representations by performing anomalous resonance amplification on the attention vector includes: The attention vector is segmented into a dominant frequency band and an auxiliary frequency band; The signal scanning path is transmitted from the dominant frequency band to the auxiliary frequency band; Record the positions of intensity spikes along the signal scanning path to form a set of spike points; The point with the highest intensity in the set of sudden increase points is marked to generate a node embedding representation.

4. The method according to claim 1, characterized in that, The step of encoding the attack intent and performing graph inversion mapping to generate a protection strategy representation includes: Malicious information interception and identification are performed on the encoded attack intent to generate an interception blank area; A gain coefficient is generated based on the intercepted blank area; Continuous security coverage is generated by mapping interpolation using the gain coefficients; Based on the continuous security coverage, feature extraction is performed to generate a protection strategy representation.

5. The method according to claim 1, characterized in that, The step of performing graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence includes: Convert the multi-layer detection rules into a priority vector field; Find the resource balancing core in the priority vector field; Starting from the resource balancing core, rules are propagated to form an initial permutation domain; The initial permutation domain is subjected to boundary convergence to form an interleaving detection sequence.

6. The method according to claim 1, characterized in that, The step of performing graph classification evaluation on the active defense prediction to generate an adaptive response signal includes: The active defense prediction is used to identify time difference bottlenecks and generate transmission time difference and computation time difference. The correlation between the transmission time difference and the calculated time difference is evaluated to form a time difference correlation graph. Key time difference factors are generated through principal component decomposition using the aforementioned time difference correlation diagram; An adaptive response signal is generated by implementing response calibration based on the key time difference factors.

7. The method according to claim 4, characterized in that, The process of generating continuous security coverage through mapping interpolation of the gain coefficients includes: The observation window is determined by identifying coverage abruptness features based on the gain coefficient. These coverage abruptness features include the rate of change of security strength, coverage duration interval, and decay gradient. A security situation map is generated by tracing the security evolution process along the observation window; Extract the coverage coordinates of each critical point within the security situation map; Continuous secure coverage is generated by arranging the coverage coordinates according to their security levels.

8. A network security intrusion detection system integrating graph neural networks, characterized in that, include: The data acquisition module is used to collect multi-source traffic data during network operation. The multi-source traffic data includes normal node features and induced node features. The multi-source traffic data is used to perform graph convolution modeling to construct an induced topology graph. The message passing module is used to perform message passing analysis and identify attack response patterns based on the induced topology graph, perform graph attention calculation on the attack response patterns to generate attention vectors, perform abnormal resonance amplification on the attention vectors to generate node embedding representations, and perform graph convolution propagation on the node embedding representations to generate resonance enhancement domains. The attack learning module is used to extract an attack behavior map by deep graph learning on the features of the inducing node, obtain the attack intent encoding by graph pooling from the attack behavior map, generate a protection strategy representation by graph inversion mapping of the attack intent encoding, and construct an adaptive protection table based on the protection strategy representation by dynamic topology transformation. A topology reshaping module is used to perform multi-layer graph propagation to identify covert attack subgraphs in the resonant enhancement domain, perform graph fusion on the covert attack subgraphs to generate camouflage graph embeddings, and perform topology reshaping on the camouflage graph embeddings to generate a deceptive network structure. This includes: constructing a connection time series based on the camouflage graph embeddings; performing topology change analysis on the connection time series to form change time markers; dividing the connection time series into stable periods and perturbation periods using the change time markers as boundaries; generating a deceptive network structure by comparing the structural distribution characteristics of the stable periods and the perturbation periods; and generating an adversarial detection strategy based on the association between the deceptive network structure and the adaptive protection table. The step of generating a deceptive network structure by comparing the structural distribution characteristics of the stable periods and the perturbation periods includes: converting the topology sequence of the stable period into a structure accumulation sequence; misaligning and superimposing the topology sequence of the perturbation period onto the structure accumulation sequence to form a structural difference map; extracting the topological jump accumulation within the structural difference map; and generating a deceptive network structure according to the distribution density of the topological jump accumulation. The detection optimization module is used to decompose the adversarial detection strategy into multi-layer detection rules, perform graph optimization sorting on the multi-layer detection rules to generate an interleaved detection sequence, and generate a graph countermeasure matrix based on the interleaved detection sequence. The response output module is used to generate an active defense prediction based on the graph countermeasure matrix, perform graph classification evaluation on the active defense prediction to generate an adaptive response signal, and complete the intrusion detection.

Citation Information

Patent Citations

  • Network attack dynamic detection and security protection method and system based on artificial intelligence

    CN120342748A