Computer network intrusion detection system and method based on abnormal behavior analysis

By using a computer network intrusion detection system based on abnormal behavior analysis, and employing GGNN and ST-Transformer models for multimodal spatiotemporal fusion and adaptive learning, the system addresses the problem of insufficient cross-layer attack identification in existing technologies, and achieves efficient threat discovery and proactive defense.

CN120896779AActive Publication Date: 2025-11-04NANTONG UNIV

Patent Information

Application Number
CN202511383717.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-11-04
Estimated Expiration
2045-09-26

AI Technical Summary

Technical Problem

Existing network intrusion detection technologies struggle to effectively identify coordinated attacks across network, host, and user layers when faced with fragmented information and dynamic threats. Furthermore, they lack real-time response mechanisms and are unable to effectively curb the lateral penetration of advanced persistent threats.

Method used

A computer network intrusion detection system based on abnormal behavior analysis is adopted. It utilizes GGNN gated graph neural network and ST-Transformer spatiotemporal joint detection model, combined with FPGA accelerated probe and Lamport logic clock for data acquisition and spatiotemporal feature fusion. The model parameters are optimized by improving IPSO particle swarm algorithm, and active response mechanisms such as dynamic honeypot deployment and resource isolation are implemented.

Benefits of technology

It significantly improves the threat detection and response capabilities in complex attack scenarios, accurately captures the covert behavior patterns of cross-layer attack chains, reduces environmental noise interference, and achieves closed-loop protection from threat identification to automatic containment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120896779A_ABST
    Figure CN120896779A_ABST
Patent Text Reader

Abstract

The invention relates to the field of computer network intrusion detection based on abnormal behavior analysis, in particular to a computer network intrusion detection system and method based on abnormal behavior analysis. The method comprises the following steps: acquiring network flow data by using a data acquisition module, and fusing the network flow data to obtain fused network flow data; the feature extraction module performs feature extraction on the fusion network flow data by using a GGNN gating graph neural network, establishes an ST-Transform space-time joint detection model, performs parameter optimization on the detection model by using a multi-target particle swarm optimization algorithm, and the data detection module inputs the feature network flow data into the space-time joint detection model for detection. Outputting a data exception score; and the active response module is used for the system to perform active response according to the grade division of the data exception score. And the threat discovery and disposal capability in a complex attack scene is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a computer network intrusion detection system and method based on abnormal behavior analysis. Background Technology

[0002] Current network intrusion detection technologies generally face challenges such as fragmented multi-dimensional information and insufficient adaptability to dynamic threats. Traditional methods mainly rely on single data source analysis, network traffic statistical features, or host log rule matching, making it difficult to capture coordinated attack behaviors across network, host, and user layers. Detection systems based on static models are prone to performance degradation due to feature distribution drift when facing continuously evolving attack methods, and lack effective identification mechanisms for zero-day attacks. While existing technologies can handle entity associations, they do not solve the spatiotemporal alignment problem of multimodal heterogeneous data and suffer from computational redundancy in real-time streaming scenarios. Furthermore, defense response mechanisms are mostly limited to passive alerts, lacking dynamic isolation and induction countermeasure capabilities linked to detection results, and are unable to effectively curb the lateral penetration of advanced persistent threats. Summary of the Invention

[0003] The purpose of this invention is to solve the above-mentioned problems by designing a computer network intrusion detection system and method based on abnormal behavior analysis.

[0004] To achieve the above objectives, the technical solution of the present invention further includes the following modules in the above-mentioned computer network intrusion detection system based on abnormal behavior analysis:

[0005] The data acquisition module is used to collect network traffic data and fuse the network traffic data to obtain fused network traffic data.

[0006] The feature extraction module is used to extract features from the fused network traffic data using a GGNN gated graph neural network to obtain feature network traffic data.

[0007] The model building module is used to build the ST-Transformer spatiotemporal joint detection model. The improved IPSO particle swarm algorithm is used to optimize the parameters of the detection model to obtain the target ST-Transformer spatiotemporal joint detection model.

[0008] The data detection module is used to input the characteristic network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection and output a data anomaly score.

[0009] The proactive response module is used by the system to proactively respond based on the level classification of the data anomaly score. The proactive response includes at least dynamic honeypot deployment and resource isolation and containment.

[0010] Furthermore, in the aforementioned computer network intrusion detection system based on abnormal behavior analysis, the data acquisition module includes the following sub-modules:

[0011] The acquisition submodule is used to deploy FPGA-accelerated probes at the network boundary to acquire network traffic data, which includes at least network traffic packet sequences, host process call chains, and user operation behavior graphs.

[0012] The mapping submodule is used to time-align the network traffic data using the Lamport logical clock, and then spatially correlate and map the aligned network traffic data to obtain the initial network traffic data.

[0013] The fusion submodule is used to fuse the spatial dimension features in the initial network traffic data and compress the spatiotemporal features in the initial network traffic data to obtain fused network traffic data.

[0014] Furthermore, in the aforementioned computer network intrusion detection system based on abnormal behavior analysis, the feature extraction module includes the following sub-modules:

[0015] The type submodule is used to define the entity nodes and edge types of the fused network traffic data, including at least network layer nodes, host layer nodes, user layer nodes, communication relationship edges, process call edges, and affiliation relationship edges;

[0016] The encoding submodule is used to encode the node features of the fused network traffic data, including network node feature vectors, host node feature vectors and user node feature vectors, to obtain graph structure traffic data.

[0017] Define the message functions in the graph structure traffic data. :

[0018]

[0019] in, Represents a node At time step The hidden state, Represents a node At time step The hidden state, The edge features are represented, including latency and frequency. Represents the training parameters, used to map the concatenated vector to... 3D space Hidden state and Dimensions;

[0020] The update submodule defines the gating update mechanism of the GGNN gated graph neural network as follows:

[0021]

[0022]

[0023]

[0024]

[0025] in, This indicates an update to the gate output, controlling the old hidden state. With new candidate status The fusion ratio; This represents the Sigmoid activation function, with output values ​​between (0,1); This represents the training parameter matrix, which is applied to the concatenated vector. ; This indicates that the gate output is reset, controlling the old hidden state. With new candidate status The degree of impact; This represents the training parameter matrix, which is applied to the concatenated vector. ; This represents the hyperbolic tangent activation function, which normalizes the output value to (-1, 1); This indicates that the gate output is updated, and the old hidden state is linearly combined. and new candidate status ; This represents the training parameter matrix, which is applied to the concatenated vector. ; Represents element-wise multiplication;

[0026] A submodule is obtained, which is used to extract hierarchical features from the graph structure traffic data using the GGNN gated graph neural network to obtain feature network traffic data.

[0027] Furthermore, in the aforementioned computer network intrusion detection system based on abnormal behavior analysis, the model building module includes the following sub-modules:

[0028] A submodule is constructed to build the ST-Transformer spatiotemporal joint detection model based on a dual-stream spatiotemporal attention mechanism.

[0029] The spatial feature extraction submodule utilizes the improved C2FDark backbone network to extract target spatial features through multi-scale convolution.

[0030] The temporal attention fusion submodule is used to construct a dynamic spatial relationship graph. It captures the potential associations between non-adjacent nodes through a graph attention mechanism and models the temporal dependencies of consecutive frames using a variable time window mechanism.

[0031] The dynamic weight allocation submodule is used to adjust the fusion weights of spatial and temporal features based on the data's traffic characteristics. The calculation formula is as follows:

[0032]

[0033] in, Indicates the fusion weight. This represents the Sigmoid activation function. , and This represents the fusion weighting coefficient, used to measure the relative importance of spatial, temporal, and environmental features; Represents spatial eigenvalues. Represents time characteristic values, This represents environmental characteristic values.

[0034] Furthermore, in the aforementioned computer network intrusion detection system based on abnormal behavior analysis, the model building module further includes the following sub-modules:

[0035] The optimization submodule is used to globally optimize the parameters of the ST-Transformer spatiotemporal joint detection model using an improved multi-objective particle swarm optimization algorithm;

[0036] The initialization submodule is used to initialize the population of the multi-objective particle swarm optimization algorithm. The population is the set of optimization parameters for the model, which includes at least: the number of spatiotemporal attention heads and feature fusion weight coefficients. , and Time window length and learning rate decay factor;

[0037] The adjustment submodule is used to adjust the inertia weights using a non-linear decreasing strategy. and acceleration factor and When population diversity < 0.3, increase the base value of the acceleration factor;

[0038] The population update formula for the multi-objective particle swarm optimization algorithm is as follows:

[0039]

[0040]

[0041] in, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles Location, Indicates the first In the next iteration, the particles Location, and This represents a random number between (0,1). Represents particles The individual's historical optimal position; Indicates the globally best historical position;

[0042] A submodule is obtained to retain the top 10% of the fittest particles in each generation for the next generation, and to handle particles that have not been updated for three consecutive generations. Perform local perturbation, in New particles are randomly sampled within ±10% of the neighborhood, and the process is repeated 100 times to obtain the optimal parameter set of the algorithm. The optimal parameter set is then substituted into the ST-Transformer spatiotemporal joint detection model.

[0043] Furthermore, in the aforementioned computer network intrusion detection system based on abnormal behavior analysis, the data detection module further includes the following units:

[0044] The data input unit is used to input the feature network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection;

[0045] The scanning and extraction unit is used to scan the protocol field using the depthwise separable convolution kernel in the model, extract the TCP flag combination pattern, and calculate the temporal and spatial attention in the feature network traffic data.

[0046] The divergence calculation unit is used to calculate the KL divergence in the feature network traffic data using the sliding window algorithm. When the KL value is greater than 0.15 for three consecutive windows, the particle swarm algorithm is triggered to update the model parameters.

[0047] The scoring calculation unit is used to project high-dimensional features onto a 2D plane using t-SNE and detect significant shifts in cluster centers to obtain data anomaly scores.

[0048] Furthermore, in the aforementioned computer network intrusion detection system based on abnormal behavior analysis, the proactive response module further includes the following units:

[0049] The rating unit is used by the system to actively respond based on the rating of the data anomaly score. When the score is ≥80%, a high-interaction honeypot is automatically deployed in the target subnet. When the score is ≥95%, a decoy document matching the attacker's fingerprint is generated.

[0050] The system control unit is used to control suspicious processes, using cgroups to limit CPU usage to ≤10% and memory usage to ≤100MB, and using seccomp to block dangerous system calls;

[0051] The system monitoring unit is used to enable copy-on-write mechanism for sensitive directories and to set up inotify monitoring for critical configuration files.

[0052] Furthermore, in the above-mentioned computer network intrusion detection method based on abnormal behavior analysis, the computer network intrusion detection method includes the following steps:

[0053] Collect network traffic data, and fuse the network traffic data to obtain fused network traffic data;

[0054] Feature network traffic data is obtained by using a GGNN gated graph neural network to extract features from the fused network traffic data.

[0055] A spatiotemporal joint detection model of ST-Transformer was established, and the parameters of the detection model were optimized using the improved IPSO particle swarm algorithm to obtain the target ST-Transformer spatiotemporal joint detection model.

[0056] The characteristic network traffic data is input into the target ST-Transformer spatiotemporal joint detection model for detection, and an anomaly score is output.

[0057] The system takes proactive measures based on the level classification of the data anomaly score. The proactive measures include at least dynamic honeypot deployment and resource isolation and containment.

[0058] Furthermore, in the above-mentioned computer network intrusion detection method based on abnormal behavior analysis, the step of collecting network traffic data and fusing the network traffic data to obtain fused network traffic data includes:

[0059] FPGA acceleration probes are deployed at the network boundary to collect network traffic data, which includes at least network traffic packet sequences, host process call chains, and user operation behavior graphs.

[0060] The network traffic data is time-aligned using the Lamport logical clock, and the aligned network traffic data is spatially correlated and mapped to obtain the initial network traffic data.

[0061] The spatial dimension features in the initial network traffic data are fused, and the spatiotemporal features in the initial network traffic data are compressed to obtain fused network traffic data.

[0062] Furthermore, in the above-mentioned computer network intrusion detection method based on abnormal behavior analysis, the characteristic feature is that the establishment of the ST-Transformer spatiotemporal joint detection model includes:

[0063] The ST-Transformer spatiotemporal joint detection model is constructed based on a dual-stream spatiotemporal attention mechanism.

[0064] By utilizing the improved C2FDark backbone network, spatial features of the target are extracted through multi-scale convolution;

[0065] A dynamic spatial relationship graph is constructed, and the potential associations between non-adjacent nodes are captured through the graph attention mechanism. The temporal dependency of consecutive frames is modeled using the variable time window mechanism.

[0066] The fusion weights of spatial and temporal features are adjusted based on the data's flow characteristics, calculated using the following formula:

[0067]

[0068] in, Indicates the fusion weight. This represents the Sigmoid activation function. , and This represents the fusion weighting coefficient, used to measure the relative importance of spatial, temporal, and environmental features; Represents spatial eigenvalues. Represents time feature values, Represents environmental characteristic values.

[0069] Its beneficial effects lie in significantly improving threat detection and response capabilities in complex attack scenarios through multimodal spatiotemporal fusion and adaptive learning mechanisms. First, a three-dimensional feature cube spanning the network, host, and user layers is constructed. A graph attention mechanism is used to analyze the dynamic relationships between entities, breaking through the limitations of traditional single-dimensional analysis and accurately capturing the covert behavioral patterns of cross-layer attack chains. Second, the spatiotemporal joint modeling algorithm integrates local protocol features and long-range dependencies, combined with dual attention weight allocation, effectively distinguishing normal behavioral fluctuations from real attack signals and significantly reducing environmental noise interference. The elastic incremental learning framework continuously tracks network behavior evolution, rapidly adapting to new attack characteristics while ensuring model stability through parameter fine-tuning and historical memory replay. The proactive response module innovatively transforms detection results into dynamic defense strategies, achieving closed-loop protection from threat identification to automatic containment. Through intelligent honeypot deployment and resource isolation mechanisms, it proactively disrupts the attacker's operational chain, enhancing the overall security system's proactive countermeasure capabilities. Attached Figure Description

[0070] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention.

[0071] Figure 1 This is a schematic diagram of the first embodiment of the computer network intrusion detection system based on abnormal behavior analysis in this invention.

[0072] Figure 2 This is a schematic diagram of a second embodiment of the computer network intrusion detection system based on abnormal behavior analysis in this invention.

[0073] Figure 3 This is a schematic diagram of the third embodiment of the computer network intrusion detection system based on abnormal behavior analysis in this invention.

[0074] Figure 4 This is a schematic diagram of the first embodiment of the computer network intrusion detection method based on abnormal behavior analysis in this invention.

[0075] Figure 5 This is a schematic diagram of the C2FDark backbone network structure in the computer network intrusion detection method based on abnormal behavior analysis in this embodiment of the invention. Detailed Implementation

[0076] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0077] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this specification means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0078] The present invention will now be described in detail with reference to the accompanying drawings, such as... Figure 1 As shown, a computer network intrusion detection system based on abnormal behavior analysis includes the following modules:

[0079] 101. Data acquisition module, used to collect network traffic data and fuse the network traffic data to obtain fused network traffic data;

[0080] Specifically, this embodiment also includes,

[0081] The acquisition submodule is used to deploy FPGA-accelerated probes at the network boundary to acquire network traffic data. The network traffic data includes at least network traffic packet sequences, host process call chains, and user operation behavior graphs.

[0082] The mapping submodule is used to time-align network traffic data using the Lamport logical clock, and then spatially correlate and map the aligned network traffic data to obtain the initial network traffic data.

[0083] The fusion submodule is used to fuse the spatial dimension features in the initial network traffic data and compress the spatiotemporal features in the initial network traffic data to obtain fused network traffic data.

[0084] 102. Feature extraction module, used to extract features from fused network traffic data using GGNN gated graph neural network to obtain feature network traffic data;

[0085] Specifically, this embodiment also includes,

[0086] The type submodule is used to define the entity nodes and edge types of the fused network traffic data, including at least network layer nodes, host layer nodes, user layer nodes, communication relationship edges, process call edges, and affiliation relationship edges;

[0087] The encoding submodule is used to encode node features of converged network traffic data, including network node feature vectors, host node feature vectors and user node feature vectors, to obtain graph-structured traffic data.

[0088] Define message functions in graph structure traffic data :

[0089]

[0090] in, Represents a node At time step The hidden state, Represents a node At time step The hidden state, The edge features are represented, including latency and frequency. Represents the training parameters, used to map the concatenated vector to... 3D space Hidden state and Dimensions;

[0091] The update submodule defines the gating update mechanism for the GGNN gated graph neural network as follows:

[0092]

[0093]

[0094]

[0095]

[0096] in, This indicates an update to the gate output, controlling the old hidden state. With new candidate status The fusion ratio; This represents the Sigmoid activation function, with output values ​​between (0,1); This represents the training parameter matrix, which is applied to the concatenated vector. ; This indicates that the gate output is reset, controlling the old hidden state. With new candidate status The degree of impact; This represents the training parameter matrix, which is applied to the concatenated vector. ; This represents the hyperbolic tangent activation function, which normalizes the output value to (-1, 1); This indicates that the gate output is updated, and the old hidden state is linearly combined. and new candidate status ; This represents the training parameter matrix, which is applied to the concatenated vector. ; Represents element-wise multiplication;

[0097] The resulting submodule is used to extract hierarchical features from graph-structured traffic data using a GGNN gated graph neural network, resulting in feature network traffic data.

[0098] 103. Model building module, used to build the ST-Transformer spatiotemporal joint detection model, and use the improved IPSO particle swarm algorithm to optimize the parameters of the detection model to obtain the target ST-Transformer spatiotemporal joint detection model;

[0099] Specifically, this embodiment also includes,

[0100] A submodule is constructed to build the ST-Transformer spatiotemporal joint detection model based on the dual-stream spatiotemporal attention mechanism.

[0101] The spatial feature extraction submodule utilizes the improved C2FDark backbone network to extract target spatial features through multi-scale convolution.

[0102] The temporal attention fusion submodule is used to construct a dynamic spatial relationship graph. It captures the potential associations between non-adjacent nodes through a graph attention mechanism and models the temporal dependencies of consecutive frames using a variable time window mechanism.

[0103] The dynamic weight allocation submodule is used to adjust the fusion weights of spatial and temporal features based on the data's traffic characteristics. The calculation formula is as follows:

[0104]

[0105] in, Indicates the fusion weight. This represents the Sigmoid activation function. , and This represents the fusion weighting coefficient, used to measure the relative importance of spatial, temporal, and environmental features; Represents spatial eigenvalues. Represents time feature values, Represents environmental characteristic values.

[0106] The optimization submodule is used to globally optimize the parameters of the ST-Transformer spatiotemporal joint detection model using an improved multi-objective particle swarm optimization algorithm;

[0107] The initialization submodule is used to initialize the population for the multi-objective particle swarm optimization algorithm. The population is the set of optimization parameters for the model, which includes at least: the number of spatiotemporal attention heads and feature fusion weight coefficients. , and Time window length and learning rate decay factor;

[0108] The adjustment submodule is used to adjust the inertia weights using a non-linear decreasing strategy. and acceleration factor and When population diversity < 0.3, increase the base value of the acceleration factor;

[0109] The population update formula for the multi-objective particle swarm optimization algorithm is as follows:

[0110]

[0111]

[0112] in, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles Location, Indicates the first In the next iteration, the particles Location, and This represents a random number between (0,1). Represents particles The individual's historical optimal position; Indicates the globally best historical position;

[0113] A submodule is obtained to retain the top 10% of the fittest particles in each generation for the next generation, and to handle particles that have not been updated for three consecutive generations. Perform local perturbation, in New particles are randomly sampled within ±10% of the neighborhood, and the process is repeated 100 times to obtain the optimal parameter set of the algorithm. The optimal parameter set is then substituted into the ST-Transformer spatiotemporal joint detection model.

[0114] 104. Data detection module, used to input feature network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection, and output data anomaly score;

[0115] Specifically, this embodiment also includes,

[0116] The data input unit is used to input the feature network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection.

[0117] The scanning extraction unit is used to scan protocol fields using depthwise separable convolution kernels in the model, extract TCP flag combination patterns, and calculate temporal and spatial attention in feature network traffic data.

[0118] The divergence calculation unit is used to calculate the KL divergence in the feature network traffic data using the sliding window algorithm. When the KL value is greater than 0.15 for three consecutive windows, the particle swarm algorithm is triggered to update the model parameters.

[0119] The scoring calculation unit is used to project high-dimensional features onto a 2D plane using t-SNE and detect significant shifts in cluster centers to obtain data anomaly scores.

[0120] 105. Proactive Response Module: This module is used by the system to proactively respond based on the level of data anomaly scoring. Proactive response includes at least dynamic honeypot deployment and resource isolation and containment.

[0121] Specifically, this embodiment also includes,

[0122] The rating unit is used by the system to proactively respond based on the rating of data anomalies. When the rating is ≥80%, a high-interaction honeypot is automatically deployed in the target subnet. When the rating is ≥95%, a decoy document matching the attacker's fingerprint is generated.

[0123] The system control unit is used to control suspicious processes, using cgroups to limit CPU usage to ≤10% and memory usage to ≤100MB, and using seccomp to block dangerous system calls;

[0124] The system monitoring unit is used to enable copy-on-write mechanism for sensitive directories and to set up inotify monitoring for critical configuration files.

[0125] Its beneficial effects lie in significantly improving threat detection and response capabilities in complex attack scenarios through multimodal spatiotemporal fusion and adaptive learning mechanisms. First, a three-dimensional feature cube spanning the network, host, and user layers is constructed. A graph attention mechanism is used to analyze the dynamic relationships between entities, breaking through the limitations of traditional single-dimensional analysis and accurately capturing the covert behavioral patterns of cross-layer attack chains. Second, the spatiotemporal joint modeling algorithm integrates local protocol features and long-range dependencies, combined with dual attention weight allocation, effectively distinguishing normal behavioral fluctuations from real attack signals and significantly reducing environmental noise interference. The elastic incremental learning framework continuously tracks network behavior evolution, rapidly adapting to new attack characteristics while ensuring model stability through parameter fine-tuning. The proactive response module innovatively transforms detection results into dynamic defense strategies, achieving closed-loop protection from threat identification to automatic containment. Through intelligent honeypot deployment and resource isolation mechanisms, it proactively disrupts the attacker's operational chain, enhancing the overall security system's proactive countermeasure capabilities.

[0126] In this embodiment, please refer to Figure 2 The second embodiment of the computer network intrusion detection system based on abnormal behavior analysis in this invention includes a feature extraction module comprising the following sub-modules:

[0127] The type submodule is used to define the entity nodes and edge types of the fused network traffic data, including at least network layer nodes, host layer nodes, user layer nodes, communication relationship edges, process call edges, and affiliation relationship edges;

[0128] The encoding submodule is used to encode node features of converged network traffic data, including network node feature vectors, host node feature vectors and user node feature vectors, to obtain graph-structured traffic data.

[0129] Define message functions in graph structure traffic data :

[0130]

[0131] in, Represents a node At time step The hidden state, Represents a node At time step The hidden state, The edge features are represented, including latency and frequency. Represents the training parameters, used to map the concatenated vector to... 3D space Hidden state and Dimensions;

[0132] The update submodule defines the gating update mechanism for the GGNN gated graph neural network as follows:

[0133]

[0134]

[0135]

[0136]

[0137] in, This indicates an update to the gate output, controlling the old hidden state. With new candidate status The fusion ratio; This represents the Sigmoid activation function, with output values ​​between (0,1); This represents the training parameter matrix, which is applied to the concatenated vector. ; This indicates that the gate output is reset, controlling the old hidden state. With new candidate status The degree of impact; This represents the training parameter matrix, which is applied to the concatenated vector. ; This represents the hyperbolic tangent activation function, which normalizes the output value to (-1, 1); This indicates that the gate output is updated, and the old hidden state is linearly combined. and new candidate status ; This represents the training parameter matrix, which is applied to the concatenated vector. ; Represents element-wise multiplication;

[0138] The resulting submodule is used to extract hierarchical features from graph-structured traffic data using a GGNN gated graph neural network, resulting in feature network traffic data.

[0139] Its beneficial effect lies in the fact that by using GGNN gated graph neural networks to extract hierarchical features from graph-structured traffic data and performing initial feature fusion and extraction on the data, the accuracy and efficiency of subsequent models in analyzing and identifying abnormal behavior in network traffic data can be improved.

[0140] In this embodiment, please refer to Figure 3 The third embodiment of the computer network intrusion detection system based on abnormal behavior analysis in this invention includes a model building module comprising the following sub-units:

[0141] The optimization submodule is used to globally optimize the parameters of the ST-Transformer spatiotemporal joint detection model using an improved multi-objective particle swarm optimization algorithm;

[0142] The initialization submodule is used to initialize the population for the multi-objective particle swarm optimization algorithm. The population is the set of optimization parameters for the model, which includes at least: the number of spatiotemporal attention heads and feature fusion weight coefficients. , and Time window length and learning rate decay factor;

[0143] The adjustment submodule is used to adjust the inertia weights using a non-linear decreasing strategy. and acceleration factor and When population diversity < 0.3, increase the base value of the acceleration factor;

[0144] The population update formula for the multi-objective particle swarm optimization algorithm is as follows:

[0145]

[0146]

[0147] in, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles Location, Indicates the first In the next iteration, the particles Location, and This represents a random number between (0,1). Represents particles The individual's historical optimal position; Indicates the globally best historical position;

[0148] A submodule is obtained to retain the top 10% of the fittest particles in each generation for the next generation, and to handle particles that have not been updated for three consecutive generations. Perform local perturbation, in New particles are randomly sampled within ±10% of the neighborhood, and the process is repeated 100 times to obtain the optimal parameter set of the algorithm. The optimal parameter set is then substituted into the ST-Transformer spatiotemporal joint detection model.

[0149] Its beneficial effect is that by using the optimized particle swarm optimization algorithm to optimize the parameters of the ST-Transformer spatiotemporal joint detection model, the stability and recognition accuracy of the model can be improved, thereby enhancing the stability and efficiency of subsequent data detection and recognition.

[0150] The above describes the computer network intrusion detection system based on abnormal behavior analysis provided by the embodiments of the present invention. The following describes the computer network intrusion detection method based on abnormal behavior analysis according to the embodiments of the present invention. Please refer to [link / reference]. Figure 4 One embodiment of the computer network intrusion detection method based on abnormal behavior analysis in this invention includes:

[0151] Step 401: Collect network traffic data and fuse the network traffic data to obtain fused network traffic data;

[0152] Step 402: Use GGNN gated graph neural network to extract features from the fused network traffic data to obtain feature network traffic data;

[0153] Step 403: Establish the ST-Transformer spatiotemporal joint detection model, and use the improved IPSO particle swarm algorithm to optimize the parameters of the detection model to obtain the target ST-Transformer spatiotemporal joint detection model.

[0154] Step 404: Input the feature network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection, and output the data anomaly score;

[0155] Step 405: The system takes proactive measures based on the level of data anomaly score. Proactive measures include at least dynamic honeypot deployment and resource isolation and containment.

[0156] Please see Figure 5 The C2FDark backbone network structure diagram in the computer network intrusion detection method based on abnormal behavior analysis in this embodiment of the invention.

[0157] The C2FDark backbone network is the core component of the spatial feature extraction module, used to extract target spatial features from fused network traffic data. Its design goal is to capture the spatial correlations in network traffic data through multi-scale convolutional operations, thereby providing high-quality feature input for subsequent spatiotemporal joint detection (ST-Transformer).

[0158] 1. Network localization and function: Location: The C2FDark backbone network is located in the spatial feature extraction submodule of the model building module. Function: It is responsible for extracting spatial features from the fused network traffic data (node ​​communication relationships, process call chains, etc.) to provide basic feature representation for spatiotemporal joint detection.

[0159] 2. The core idea of ​​multi-scale convolution design is to capture spatial patterns at different granularities. Multi-scale convolution uses convolution kernels of different sizes (3×3) to extract local and global features in parallel.

[0160] Advantages: It can adapt to different spatial structures in network traffic data (individual node behavior, subnet communication patterns, cross-layer interactions, etc.). Improvements include the introduction of depthwise separable convolution to reduce computational cost; residual connections to alleviate the vanishing gradient problem and improve feature propagation efficiency; and an attention mechanism combining channel attention (SE Block) or spatial attention to enhance the weights of important features.

[0161] 3. Input data processing: Input format: fused network traffic data (graph structure traffic data). The data includes entity nodes (network layer, host layer, user layer nodes) and edge types (communication relationships, process calls, etc.). Node features are encoded into vectors (e.g., network node feature vectors, host node feature vectors, etc.). Preprocessing: Spatial association mapping (e.g., adjacency matrix construction) may be performed on the original graph data, transforming the relationships between nodes and edges into tensors suitable for convolution operations.

[0162] 4. Network Structure Inference (Context-Based): Since the document does not provide a complete structure diagram of C2FDark, based on the context and technical background, it is inferred that it may contain the following components: Multi-scale convolutional layers: Multiple convolutional kernels of different sizes are stacked in parallel (3×3) to extract multi-scale features. Each branch is followed by a non-linear activation (ReLU) and normalization layer (such as BatchNorm).

[0163] The feature fusion layer concatenates the outputs of multi-scale convolutions along the channel dimension to form high-dimensional features. Alternatively, a unified representation can be generated through weighted fusion (Global Average Pooling + fully connected layer). The downsampling layer uses pooling operations (MaxPooling or Strided Convolution) to progressively reduce the spatial dimensionality while preserving key features. Improvements include a lightweight design employing a C2F module (similar to the structure in YOLOv7) to enhance efficiency through grouped convolutions and cross-layer connections. Dynamic adjustment dynamically adjusts the convolution kernel size or number of channels based on the spatiotemporal characteristics of the input data.

[0164] The output and subsequent processes involve extracting spatial feature vectors, which serve as one of the inputs to the ST-Transformer model. Subsequent processing includes spatiotemporal joint modeling: combining spatial and temporal features (extracted via graph attention) and fusing them using the ST-Transformer's two-stream attention mechanism.

[0165] Multimodal spatial modeling: C2FDark overcomes the limitations of single-scale analysis in traditional methods by using multi-scale convolution, enabling it to capture the covert behavioral patterns of cross-layer attack chains (such as lateral penetration and anomalous communication patterns). In collaboration with graph neural networks, the node-level features extracted by GGNN (Gated Graph Neural Network) complement C2FDark's multi-scale spatial features, jointly constructing a three-dimensional feature cube and enhancing the model's adaptability to complex attack scenarios.

[0166] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.

Claims

1. A computer network intrusion detection system based on abnormal behavior analysis, characterized in that, The computer network intrusion detection system includes the following modules: The data acquisition module is used to collect network traffic data and fuse the network traffic data to obtain fused network traffic data. The feature extraction module is used to extract features from the fused network traffic data using a GGNN gated graph neural network to obtain feature network traffic data. The model building module is used to build the ST-Transformer spatiotemporal joint detection model. The multi-objective particle swarm optimization algorithm is used to optimize the parameters of the detection model to obtain the target ST-Transformer spatiotemporal joint detection model. The data detection module is used to input the characteristic network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection and output a data anomaly score. The proactive response module is used by the system to proactively respond based on the level classification of the data anomaly score. The proactive response includes at least dynamic honeypot deployment and resource isolation and containment.

2. The computer network intrusion detection system based on abnormal behavior analysis as described in claim 1, characterized in that, The data acquisition module includes the following sub-modules: The acquisition submodule is used to deploy FPGA-accelerated probes at the network boundary to acquire network traffic data, which includes at least network traffic packet sequences, host process call chains, and user operation behavior graphs. The mapping submodule is used to time-align the network traffic data using the Lamport logical clock, and then spatially correlate and map the aligned network traffic data to obtain the initial network traffic data. The fusion submodule is used to fuse the spatial dimension features in the initial network traffic data and compress the spatiotemporal features in the initial network traffic data to obtain fused network traffic data.

3. The computer network intrusion detection system based on abnormal behavior analysis as described in claim 1, characterized in that, The feature extraction module includes the following sub-modules: The type submodule is used to define the entity nodes and edge types of the fused network traffic data, including at least network layer nodes, host layer nodes, user layer nodes, communication relationship edges, process call edges, and affiliation relationship edges; The encoding submodule is used to encode the node features of the fused network traffic data, including network node feature vectors, host node feature vectors and user node feature vectors, to obtain graph structure traffic data. Define the message functions in the graph structure traffic data. : ; in, Represents a node At time step The hidden state, Represents a node At time step The hidden state, The edge features are represented, including latency and frequency. Represents the training parameters, used to map the concatenated vector to... 3D space Hidden state and Dimensions This represents a vector concatenation operation; The update submodule defines the gating update mechanism of the GGNN gated graph neural network as follows: ; ; ; ; in, This indicates an update to the gate output, controlling the old hidden state. With new candidate status The fusion ratio; This represents the Sigmoid activation function, with output values ​​between (0,1); This represents the training parameter matrix, which is applied to the concatenated vector. ; This indicates that the gate output is reset, controlling the old hidden state. With new candidate status The extent of the impact; This represents the training parameter matrix, which is applied to the concatenated vector. ; This represents the hyperbolic tangent activation function, which normalizes the output value to (-1, 1); This indicates that updating the gate output involves a linear combination of the old hidden states. and new candidate status ; This represents the training parameter matrix, which is applied to the concatenated vector. ; Represents element-wise multiplication; A submodule is obtained, which is used to extract hierarchical features from the graph structure traffic data using the GGNN gated graph neural network to obtain feature network traffic data.

4. The computer network intrusion detection system based on abnormal behavior analysis as described in claim 1, characterized in that, The model building module includes the following sub-modules: A submodule is constructed to build the ST-Transformer spatiotemporal joint detection model based on a dual-stream spatiotemporal attention mechanism. The spatial feature extraction submodule utilizes the improved C2FDark backbone network to extract target spatial features through multi-scale convolution. The temporal attention fusion submodule is used to construct a dynamic spatial relationship graph. It captures the potential associations between non-adjacent nodes through a graph attention mechanism and models the temporal dependencies of consecutive frames using a variable time window mechanism. The dynamic weight allocation submodule is used to adjust the fusion weights of spatial and temporal features based on the data's traffic characteristics. The calculation formula is as follows: ; in, Indicates the fusion weight. This represents the Sigmoid activation function. , and This represents the fusion weighting coefficient, used to measure the relative importance of spatial characteristics, temporal characteristics, and external network threats; Represents spatial eigenvalues. Represents time feature values, This indicates the external network threat value.

5. The computer network intrusion detection system based on abnormal behavior analysis as described in claim 1, characterized in that, The model building module also includes the following sub-modules: The optimization submodule is used to globally optimize the parameters of the ST-Transformer spatiotemporal joint detection model using a multi-objective particle swarm optimization algorithm. The initialization submodule is used to initialize the population of the multi-objective particle swarm optimization algorithm. The population is the set of optimization parameters for the model, which includes at least: the number of spatiotemporal attention heads and feature fusion weight coefficients. , and Time window length and learning rate decay factor; The adjustment submodule is used to adjust the inertia weights using a non-linear decreasing strategy. and acceleration factor and When population diversity < 0.3, increase the base value of the acceleration factor; The population update formula for the multi-objective particle swarm optimization algorithm is as follows: ; ; in, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles speed, Indicates the first In the next iteration, the particles Location, Indicates the first In the next iteration, the particles Location, and This represents a random number between (0,1). Represents particles The individual's historical optimal position; Indicates the globally best historical position; A submodule is obtained to retain the top 10% of the fittest particles in each generation for the next generation, and to handle particles that have not been updated for three consecutive generations. Perform local perturbation, in New particles are randomly sampled within ±10% of the neighborhood, and the process is repeated 100 times to obtain the optimal parameter set of the algorithm. The optimal parameter set is then substituted into the ST-Transformer spatiotemporal joint detection model.

6. The computer network intrusion detection system based on abnormal behavior analysis as described in claim 1, characterized in that, The data detection module also includes the following units: The data input unit is used to input the feature network traffic data into the target ST-Transformer spatiotemporal joint detection model for detection; The scanning and extraction unit is used to scan the protocol field using the depthwise separable convolution kernel in the model, extract the TCP flag combination pattern, and calculate the temporal and spatial attention in the feature network traffic data. The divergence calculation unit is used to calculate the KL divergence in the feature network traffic data using the sliding window algorithm. When the KL value is greater than 0.15 for three consecutive windows, the particle swarm algorithm is triggered to update the model parameters. The scoring calculation unit is used to project high-dimensional features onto a 2D plane using t-SNE and detect significant shifts in cluster centers to obtain data anomaly scores.

7. The computer network intrusion detection system based on abnormal behavior analysis as described in claim 1, characterized in that, The active response module also includes the following units: The rating unit is used by the system to actively respond based on the rating of the data anomaly score. When the score is ≥80%, a high-interaction honeypot is automatically deployed in the target subnet. When the score is ≥95%, a decoy document matching the attacker's fingerprint is generated. The system control unit is used to control suspicious processes, using cgroups to limit CPU usage to ≤10% and memory usage to ≤100MB, and using seccomp to block dangerous system calls; The system monitoring unit is used to enable copy-on-write mechanism for sensitive directories and to set up inotify monitoring for critical configuration files.

8. A computer network intrusion detection method based on abnormal behavior analysis, characterized in that, The computer network intrusion detection method includes the following steps: Collect network traffic data, and fuse the network traffic data to obtain fused network traffic data; Feature network traffic data is obtained by using a GGNN gated graph neural network to extract features from the fused network traffic data. A spatiotemporal joint detection model of ST-Transformer was established, and the parameters of the detection model were optimized by a multi-objective particle swarm optimization algorithm to obtain the target ST-Transformer spatiotemporal joint detection model. The characteristic network traffic data is input into the target ST-Transformer spatiotemporal joint detection model for detection, and an anomaly score is output. The system takes proactive measures based on the level classification of the data anomaly score. The proactive measures include at least dynamic honeypot deployment and resource isolation and containment.

9. The computer network intrusion detection method based on abnormal behavior analysis as described in claim 8, characterized in that, The process of collecting network traffic data and fusing the network traffic data to obtain fused network traffic data includes: FPGA acceleration probes are deployed at the network boundary to collect network traffic data, which includes at least network traffic packet sequences, host process call chains, and user operation behavior graphs. The network traffic data is time-aligned using the Lamport logical clock, and the aligned network traffic data is spatially correlated and mapped to obtain the initial network traffic data. The spatial dimension features in the initial network traffic data are fused, and the spatiotemporal features in the initial network traffic data are compressed to obtain fused network traffic data.

10. The computer network intrusion detection method based on abnormal behavior analysis as described in claim 8, characterized in that, The establishment of the ST-Transformer spatiotemporal joint detection model includes: The ST-Transformer spatiotemporal joint detection model is constructed based on a dual-stream spatiotemporal attention mechanism. By utilizing the improved C2FDark backbone network, spatial features of the target are extracted through multi-scale convolution; A dynamic spatial relationship graph is constructed, and the potential associations between non-adjacent nodes are captured through the graph attention mechanism. The temporal dependency of consecutive frames is modeled using the variable time window mechanism. The fusion weights of spatial and temporal features are adjusted based on the data's flow characteristics, calculated using the following formula: ; in, Indicates the fusion weight. This represents the Sigmoid activation function. , and This represents the fusion weighting coefficient, used to measure the relative importance of spatial characteristics, temporal characteristics, and external network threats; Represents spatial eigenvalues. Represents time feature values, This indicates the external network threat value.

Citation Information

Patent Citations

  • Intrusion detection system and method based on intelligent network

    CN118413406A

  • Unbalanced network intrusion detection method based on CNN-Transform fusion module

    CN118764270A

  • Network intrusion detection method and device of gating multilayer perceptron based on spatio-temporal feature fusion

    CN119561744A

  • Network intrusion detection method, device and equipment

    CN120455116A

  • Network intrusion detection method and system based on multi-modal deep learning

    CN120498883A

Cited By

  • Multi-source prior gating enhanced threat intrusion detection and correlation analysis method and system

    CN122419989A