An abnormal network intrusion detection system based on FPGA and artificial intelligence

By combining FPGA and artificial intelligence, the network intrusion detection system solves the problems of network packet analysis errors and slow inference speed, and achieves efficient anomaly detection of high-speed network traffic.

CN121098574BActive Publication Date: 2026-04-14BEIJING QICE TECH
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING QICE TECH
Filing Date
2025-09-04
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing technologies suffer from errors in network packet analysis and have slow inference speeds, resulting in low efficiency in detecting anomalies in high-speed network traffic.

Method used

An abnormal network intrusion detection system based on FPGA and artificial intelligence is adopted. The network sensing unit acquires and parses network packet information, uses AI models for real-time calculation, and combines intrusion detection unit and response unit to perform packet analysis and response processing. The analysis unit adjusts model parameters to improve detection accuracy and speed.

Benefits of technology

It improves the efficiency of anomaly detection in high-speed network traffic, reduces the false alarm rate, and achieves higher detection accuracy and real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098574B_ABST
    Figure CN121098574B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, in particular to an abnormal network intrusion detection system based on FPGA and artificial intelligence. The system obtains and analyzes network message information of a network link entering the FPGA through a network perception unit, generates a data packet for AI intrusion detection model reasoning based on the obtained data information; an intrusion detection unit is constructed based on an AI model, outputs an intrusion detection result based on the input data packet, so that an intrusion response unit can more accurately determine a response processing mechanism based on the intrusion detection result and adjust the response processing mechanism; the analysis unit determines the intrusion detection state based on the detection rate in the preset period after the adjustment of the response processing mechanism, adjusts the corresponding parameters based on the intrusion detection state, generates AI detection model fine-tuning parameters, so that the intrusion detection state can be more effectively adjusted to be qualified. The application improves the abnormal detection efficiency of high-speed network traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an abnormal network intrusion detection system based on FPGA and artificial intelligence. Background Technology

[0002] The background technology of anomaly network intrusion detection systems stems from the limitations of traditional security protection methods. With the widespread adoption of internet technology, network attacks have become increasingly diversified and covert, making passive defense devices such as firewalls ineffective against internal attacks and unknown threats. Early systems primarily relied on rule matching and signature detection, identifying known attack patterns by analyzing network traffic characteristics (such as protocol type and packet size) or host audit logs. As attack methods evolved, methods based on statistical analysis and machine learning matured, including algorithms such as support vector machines and decision trees, capable of detecting traffic anomalies and behavioral deviations. In recent years, deep learning technology has significantly improved the ability to identify new types of attacks by automatically extracting features, such as CNNs for spatial features and RNNs for temporal traffic analysis. The evolution of distributed architectures has made multi-probe collaborative detection possible, combining with situational awareness technology to achieve global threat assessment. The current technological challenge lies in balancing detection real-time performance and accuracy while reducing false positive rates.

[0003] Chinese Patent Publication No. CN102571494B discloses an intrusion detection system and method based on FPGA. This invention designs and implements an intrusion detection system based on FPGA, improves processing performance through hardware circuit implementation, selects a binary tree structure packet classification algorithm for packet classification, adopts an XOR Hash algorithm suitable for FPGA processing for character matching, and updates the implementation rules by adding or modifying the original intrusion rule implementation logic, and performs separate matching of hash collisions.

[0004] It is evident that existing technologies suffer from the following problems: errors in network packet analysis and slow inference speed, resulting in low efficiency in detecting anomalies in high-speed network traffic. Summary of the Invention

[0005] To address this issue, the present invention provides an anomaly network intrusion detection system based on FPGA and artificial intelligence, which overcomes the problems of errors in network packet analysis and slow inference speed in existing technologies, resulting in low efficiency in detecting anomalies in high-speed network traffic.

[0006] To achieve the above objectives, the present invention provides an abnormal network intrusion detection system based on FPGA and artificial intelligence, comprising:

[0007] The network sensing unit is used to acquire and parse network packet information entering the network link in the FPGA to obtain data packets;

[0008] An intrusion detection unit, connected to the network perception unit, includes a feature extraction module for converting the original fields in the data packets extracted based on a parallel architecture into feature vectors, an artificial intelligence module for real-time calculation of the feature vectors based on an AI model trained on network intrusion samples to obtain anomaly scores, and a detection result fusion module for fusing the rule parsing results and anomaly scores in the data packets based on threshold conditions to obtain intrusion detection results, wherein the threshold conditions include a threshold for the anomaly scores.

[0009] An intrusion response unit, connected to the intrusion detection unit, is used to determine the response processing mechanism based on the intrusion detection result and to make adjustments based on the response processing mechanism. The response processing mechanism includes traffic blocking, packet filtering and forwarding, and alarm notification.

[0010] An analysis unit, connected to the intrusion response unit, is used to calculate the detection rate within a preset period after adjustment based on the processing mechanism, determine the intrusion detection status based on the detection rate, adjust the threshold of the anomaly score based on the intrusion detection status, and adjust the number of parallel pipelines in the parallel architecture of the feature module based on the intrusion detection status after adjusting the threshold of the anomaly score. The detection rate is the ratio of correctly identified abnormal traffic to the total real abnormal traffic, and the abnormal traffic is the network traffic data that is abnormal in the intrusion detection results output by the intrusion detection unit.

[0011] Furthermore, the network awareness unit includes: a packet parsing module connected to the intrusion detection unit for parsing the basic characteristics of network packet information; a flow table parsing module connected to the intrusion detection unit for scanning hardware flow tables and parsing the state information of each network flow; and a rule parsing module connected to the intrusion detection unit for obtaining routing rules and firewall rules information to parse the rule parsing results. The network awareness unit is also used to fuse the results obtained by the packet parsing module, the flow table parsing module, and the rule parsing module to generate data packets.

[0012] Furthermore, it also includes: a traffic context storage unit, which is connected to the network sensing unit and the intrusion detection unit respectively, for updating the flow table based on the result obtained by the packet parsing module in the network sensing module, and transmitting the data after updating the flow table to the flow table parsing module in the network sensing unit for parsing, so as to update the data packet; the traffic context storage unit is also used to receive the intrusion detection result of the intrusion detection unit to record network session information.

[0013] Furthermore, it also includes a network packet caching unit, which is connected to the intrusion response unit to store network packet information and adjust the network packet information based on the response processing mechanism of the intrusion response unit.

[0014] Furthermore, the analysis unit is also used to obtain the detection rate for multiple historical periods and calculate the average of the multiple detection rates when the intrusion detection status is unqualified; the analysis unit is also used to adjust the threshold of the abnormal score based on the difference between the preset detection rate and the average when the average value is less than the preset detection rate; wherein, the intrusion detection status is determined to be unqualified when the detection rate is less than the preset detection rate.

[0015] Furthermore, the analysis unit is also used to reduce the threshold of the abnormal score based on the difference between the preset detection rate and the average value, and the reduction of the threshold of the abnormal score is proportional to the difference.

[0016] Furthermore, the intrusion detection unit is equipped with a real-time traffic probe cluster to sense the delay time of the attack situation; the analysis unit is also used to calculate the integral of the plotted real-time traffic probe label-delay time curve when the intrusion detection status is unqualified after adjusting the threshold of the anomaly score based on the average of multiple detection rates; the analysis unit is also used to adjust the threshold of the anomaly score based on the ratio of the integral to the preset integral when the integral is greater than the preset integral.

[0017] Furthermore, the analysis unit is also used to reduce the threshold of abnormal scores based on the ratio of the integral to the preset integral, and the reduction of the threshold of abnormal scores is proportional to the ratio.

[0018] Furthermore, the analysis unit is also used to repeatedly adjust the threshold of the abnormal score at least once if the intrusion detection status is unqualified after adjusting the threshold of the abnormal score based on the integral, until the number of adjustments is less than a preset number and the intrusion detection status is qualified, or the number of adjustments is equal to the preset number and the adjustment stops; the analysis unit is also used to calculate the variance of the detection rate over multiple historical periods if the intrusion detection status is unqualified after the adjustment stops; the analysis unit is also used to adjust the number of parallel pipelines in the parallel architecture of the feature module based on the difference between the preset variance and the variance if the variance is less than a preset variance; wherein, the intrusion detection status is determined to be qualified when the detection rate is greater than or equal to the preset detection rate.

[0019] Furthermore, the analysis unit is also used to increase the number of parallel pipelines in the parallel architecture of the feature module based on the difference between the preset variance and the variance, and the increase in the number of parallel pipelines in the parallel architecture of the feature module is proportional to the difference.

[0020] Compared with existing technologies, the beneficial effects of this invention are as follows: The system acquires and parses network packet information, historical flow table information, and switch and firewall rule information from the network links entering the FPGA through a network sensing unit. Based on the acquired data, it generates data packets for AI intrusion detection model inference. The intrusion detection unit, based on the AI ​​model, outputs intrusion detection results based on the input data packets, automatically generating and issuing intrusion response rules. This allows the intrusion response unit to more accurately determine the response handling mechanism based on the intrusion detection results and adjust it accordingly. The analysis unit determines the intrusion detection status within a preset period based on the detection rate after adjustment of the response handling mechanism, and adjusts corresponding parameters based on the intrusion detection status to generate AI detection model fine-tuning parameters. This fine-tuning of the AI ​​model enables more effective adjustment of the intrusion detection status to meet requirements. This invention utilizes FPGA and AI models to accurately analyze network data packets and improve model inference speed, thereby improving the efficiency of anomaly detection in high-speed network traffic.

[0021] Furthermore, by generating data packets by integrating the results obtained from the packet parsing module, flow table parsing module, and rule parsing module in the network sensing unit, the present invention can make the data packets more accurate, thereby making the subsequent judgment based on the data packets more effective, and thus improving the efficiency of anomaly detection in high-speed network traffic.

[0022] Furthermore, the present invention stores updated data packets by using a traffic context storage unit, thereby making the data packets more accurate and making the subsequent judgment based on the data packets more effective, thus improving the efficiency of anomaly detection in high-speed network traffic.

[0023] Furthermore, this invention determines the threshold for adjusting the anomaly score based on the average detection rate of multiple historical periods when the intrusion detection status is unqualified. This allows for more effective adjustment of the anomaly score threshold based on accurate causes, thereby enabling more accurate analysis of data packets and improving the efficiency of anomaly detection for high-speed network traffic.

[0024] Furthermore, the present invention adjusts the threshold of the anomaly score based on the difference between the preset detection rate and the average value, which can more accurately adjust the threshold of the anomaly score, thereby enabling more accurate analysis of data packets and improving the efficiency of anomaly detection for high-speed network traffic.

[0025] Furthermore, this invention determines whether to adjust the anomaly score threshold based on the integral of the plotted real-time traffic probe label-delay time curve. By analyzing the delay time, the anomaly score threshold can be adjusted more effectively, thereby enabling more accurate analysis of data packets and improving the efficiency of anomaly detection in high-speed network traffic.

[0026] Furthermore, the present invention adjusts the threshold of the anomaly score based on the ratio of the curve integral to the preset integral, which can adjust the threshold of the anomaly score more accurately, thereby enabling more accurate analysis of data packets and improving the efficiency of anomaly detection in high-speed network traffic.

[0027] Furthermore, this invention determines whether to adjust the number of parallel pipelines in the parallel architecture of the feature module based on the intrusion detection status after stopping the adjustment of the anomaly score threshold. This can more effectively adjust the number of parallel pipelines, thereby further accelerating the model inference speed and improving the accuracy of intrusion detection, and further improving the anomaly detection efficiency for high-speed network traffic.

[0028] Furthermore, the present invention adjusts the number of parallel pipelines in the parallel architecture of the feature module based on the preset variance and the difference of variance, which can more accurately adjust the number of parallel pipelines, thereby further improving the accuracy of intrusion detection and further improving the efficiency of anomaly detection for high-speed network traffic. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of the structure of an abnormal network intrusion detection system based on FPGA and artificial intelligence according to an embodiment of the present invention;

[0030] Figure 2 This is a flowchart illustrating the steps of an abnormal network intrusion detection method based on FPGA and artificial intelligence according to an embodiment of the present invention.

[0031] Figure 3 This is an overall block diagram of the abnormal network intrusion detection method based on FPGA and artificial intelligence according to an embodiment of the present invention;

[0032] Figure 4 This is a flowchart illustrating the steps for determining the detection result based on the comparison between the detection rate and the preset detection rate in an embodiment of the present invention. Detailed Implementation

[0033] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0034] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0035] It should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0036] Please see Figure 1 As shown, it is a schematic diagram of the structure of the abnormal network intrusion detection system based on FPGA and artificial intelligence according to an embodiment of the present invention.

[0037] The system includes a network sensing unit, an intrusion detection unit, an intrusion response unit, and an analysis unit.

[0038] The network sensing unit is used to acquire and parse network packet information of the network link entering the FPGA to obtain data packets;

[0039] The intrusion detection unit is connected to the network perception unit and includes a feature extraction module for converting the original fields in the data packet extracted based on a parallel architecture into feature vectors, an artificial intelligence module for calculating the feature vectors in real time based on an AI model trained on network intrusion samples to obtain anomaly scores, and a detection result fusion module for fusing the rule parsing results and anomaly scores in the data packet based on threshold conditions to obtain intrusion detection results, wherein the threshold conditions include a threshold for the anomaly scores.

[0040] The intrusion response unit is connected to the intrusion detection unit and is used to decide on the response processing mechanism based on the intrusion detection result, and to make adjustments based on the response processing mechanism. The response processing mechanism includes traffic blocking, packet filtering and forwarding, and alarm notification.

[0041] An analysis unit, connected to the intrusion response unit, is used to calculate the detection rate within a preset period after adjustment based on the processing mechanism, determine the intrusion detection status based on the detection rate, adjust the threshold of the anomaly score based on the intrusion detection status, and adjust the number of parallel pipelines in the parallel architecture of the feature module based on the intrusion detection status after adjusting the threshold of the anomaly score. The detection rate is the ratio of correctly identified abnormal traffic to the total real abnormal traffic, and the abnormal traffic is the network traffic data that is abnormal in the intrusion detection results output by the intrusion detection unit.

[0042] Specifically, the FPGA, as the primary traffic processing device, is connected in series in the network link. Network traffic enters the FPGA and is parsed by the network awareness unit to generate command packets. The intrusion detection unit performs inference based on the data packets and outputs the detection results. The intrusion response unit outputs network control policies (routing and firewall rules) and link data filtering and forwarding policies based on the detection results.

[0043] Specifically, the intrusion detection unit (IDU) performs multi-dimensional threat detection and inference tasks based on FPGA hardware logic. This includes attack signature detection, anomaly detection, and protocol analysis. The analysis results are written back to the hardware flow table in the FPGA and then sent to the intrusion response unit.

[0044] Specifically, the intrusion response unit determines the response and handling mechanism based on the intrusion detection results. This includes traffic blocking (firewall and router linkage), packet filtering and forwarding (supporting packet capture and forensics), and alerting.

[0045] Specifically, the main workflow of the intrusion detection unit is as follows: First, the parallel architecture processing in the feature extraction module receives the raw data packets transmitted by the network perception unit. Using FPGA hardware acceleration technology, it parses the header information and payload features of 16 data packets in parallel, and transforms the continuous data packet sequence into a 32-dimensional feature vector through a sliding window algorithm. Second, the real-time inference engine of the artificial intelligence module deploys a lightweight LSTM neural network model trained on network intrusion samples. After receiving the feature vector, the input layer of the neural network model is Z-score normalized, the hidden layer analyzes the traffic temporal features through three time steps, and the final output layer generates an anomaly probability score in the range of 0-1. For example, 0.82 indicates an 82% attack probability. The model weights are updated every 10 minutes through online learning to adapt to new attack patterns. Finally, the detection result is output through the detection result fusion module, which performs multi-data fusion.

[0046] Specifically, the detection rate is the network traffic data required for anomaly detection results in the intrusion detection results obtained by the real-time traffic probe cluster.

[0047] Please see Figure 2 The diagram shown is a flowchart of the steps of the abnormal network intrusion detection method based on FPGA and artificial intelligence according to an embodiment of the present invention.

[0048] The steps of the anomaly network intrusion detection method based on FPGA and artificial intelligence include:

[0049] S1, through the network sensing unit, is used to acquire and parse network message information of the network link entering the FPGA to obtain data packets;

[0050] S2, an intrusion detection unit connected to the network sensing unit includes a feature extraction module for converting the original fields in the data packet extracted based on a parallel architecture into feature vectors, an artificial intelligence module for calculating the feature vectors in real time based on an AI model trained on network intrusion samples to obtain an anomaly score, and a detection result fusion module for fusing the rule parsing results and the anomaly score in the data packet based on threshold conditions to obtain an intrusion detection result, wherein the threshold conditions include a threshold for the anomaly score.

[0051] S3, the intrusion response unit connected to the intrusion detection unit makes a decision on the response processing mechanism based on the intrusion detection result, and makes adjustments based on the response processing mechanism, wherein the response processing mechanism includes traffic blocking, packet filtering and forwarding, and alarm notification;

[0052] S4, the analysis unit connected to the intrusion response unit calculates the detection rate within a preset period after adjustment based on the processing mechanism, determines the intrusion detection status based on the detection rate, adjusts the threshold of the anomaly score based on the intrusion detection status, and adjusts the number of parallel pipelines in the parallel architecture of the feature module based on the intrusion detection status after adjusting the threshold of the anomaly score. The detection rate is the ratio of correctly identified abnormal traffic to the total real abnormal traffic, and the abnormal traffic is the network traffic data that is abnormal in the intrusion detection results output by the intrusion detection unit.

[0053] Please see Figure 3 As shown, it is an overall block diagram of the abnormal network intrusion detection method based on FPGA and artificial intelligence according to an embodiment of the present invention.

[0054] Specifically, the network sensing unit is used for information and data collection and analysis, including a packet parsing module, a flow table parsing module, and a rule parsing module. The packet parsing module extracts basic packet characteristics from input network packets, such as IP address, protocol, port number, and payload, and updates the flow table. The flow table parsing module scans the hardware flow table to obtain the status information of each network flow. The rule parsing module obtains routing rules and firewall rules from external switches, routers, and firewalls, and parses out the rule information. Based on the packet, flow table, and rule information, data packets for detection are generated.

[0055] Specifically, the traffic context storage unit is implemented using flow table context memory based on Block RAM in the FPGA, or it can be implemented based on DDR RAM. This component records the traffic characteristics, statistical values, historical detection information, and other information for each network session.

[0056] Specifically, the network packet caching unit is implemented based on RAM. Data packets on the network link are stored in the network packet cache. Based on the decision of the intrusion response module, the packet data in the packet cache is read, forwarded, or filtered and discarded.

[0057] Specifically, this method enables real-time network intrusion detection and analysis, and automated response without manual intervention. All units are implemented based on FPGA hardware logic, supporting model and configuration updates. The network detection unit can perceive data plane and control plane characteristics, such as firewalls and routing rules, on the hardware.

[0058] Please see Figure 4 The diagram shows a flowchart illustrating the steps of determining the detection status based on a comparison between the detection rate and a preset detection rate according to an embodiment of the present invention. The analysis unit in this embodiment is further configured to acquire the detection rate for multiple historical periods and calculate the average of the multiple detection rates when the intrusion detection status is unqualified; the analysis unit is also configured to adjust the threshold of the abnormal score based on the difference between the preset detection rate and the average when the average value is less than the preset detection rate; wherein, the intrusion detection status is determined to be unqualified when the detection rate is less than the preset detection rate.

[0059] Specifically, the numerical settings of subsequent preset or critical parameters are based on the fault tolerance thresholds of the FPGA hardware acceleration layer and the AI ​​decision-making layer, as well as some historical data obtained through statistics and analysis during the historical judgment process.

[0060] Specifically, if the preset detection rate L0 = 0.86, the comparison process between the detection rate L and the preset detection rate L0 is as follows:

[0061] If the detection rate L is greater than or equal to the preset detection rate L0, it indicates that the intrusion detection status is qualified.

[0062] If the detection rate L is less than the preset detection rate L0, it indicates that the intrusion detection status is unqualified. Then, the detection rates of multiple historical periods are obtained, and the average value of multiple detection rates is calculated.

[0063] Specifically, if the average value is less than the preset average value, it indicates that the threshold for determining the abnormal score of the intrusion detection result in the intrusion detection unit is set too high, causing some low-frequency attacks to be filtered out, resulting in more missed detections. In this case, the threshold for the abnormal score is adjusted based on the difference between the preset detection rate and the average value. The preset difference between the preset detection rate and the average value is P0 = 0.05. The comparison process between the preset difference P and the preset difference P0 is as follows:

[0064] If the difference P between the preset detection rate and the average value is less than or equal to the preset difference P0, then the threshold for abnormal scores will be adjusted to 0.92 times the original threshold for abnormal scores.

[0065] If the difference P between the preset detection rate and the average value is greater than the preset difference P0, then the threshold for abnormal scores will be adjusted to 0.78 times the original threshold for abnormal scores.

[0066] Specifically, if the intrusion detection status is still unqualified after adjusting the threshold of the abnormal score, the latency of the attack situation is perceived by the real-time traffic probe cluster, and a real-time traffic probe number-latency curve is plotted, while the integral of the curve is calculated.

[0067] Specifically, if the integral of the real-time traffic probe label-delay time curve is greater than the preset integral, it indicates that the platform is processing a complex attack pattern due to a significant increase in latency, requiring more computing resources. It also reflects an expansion in attack scale or enhanced stealth of attack methods, necessitating a longer period to confirm the integrity of the attack chain. Therefore, the threshold for the abnormal score is adjusted based on the ratio of the integral to the preset integral. The preset ratio Q0 = 1.5. The comparison process between the integral and the preset integral Q0 is as follows:

[0068] If the ratio Q of the integral to the preset integral is less than or equal to the preset ratio Q0, the threshold of the abnormal score will be adjusted to 0.94 times the threshold of the abnormal score after adjustment based on the average of the detection rates of multiple historical periods.

[0069] If the ratio Q of the integral to the preset integral is greater than the preset ratio Q0, the threshold of the abnormal score will be adjusted to 0.89 times the threshold of the abnormal score after adjustment based on the average of the detection rates of multiple historical periods.

[0070] Specifically, the intrusion detection status is re-evaluated after adjusting the threshold for the anomaly score. If the intrusion detection status is still unqualified, the threshold for the anomaly score is adjusted at least once until the number of adjustments is less than the preset number and the intrusion detection status is qualified, or the number of adjustments is equal to the preset number and the adjustment is stopped. If the intrusion detection status is still unqualified after the adjustment is stopped, the variance of the detection rate for multiple historical periods is calculated.

[0071] Specifically, if the variance is less than the preset variance, it indicates that the detection rate of the historical periods is unqualified and the dispersion is low. This is because the number of parallel pipelines in the feature extraction module parallel architecture is too small, causing the feature extraction module delay time to exceed the data packet arrival interval, resulting in pipeline blockage and packet loss. This leads to missed detections during intrusion detection. Therefore, the number of parallel pipelines in the feature module parallel architecture is adjusted based on the difference between the preset variance and the original variance. The preset difference between the two variances is R0 = 0.1. The comparison process between the preset difference R and the preset difference R0 is as follows:

[0072] If the difference R between the preset variance and the variance is less than or equal to the preset difference R0, then the number of parallel pipelines in the parallel architecture of the feature module will be adjusted to 1.7 times the original number, and the results will be rounded up.

[0073] If the difference R between the preset variance and the variance is greater than the preset difference R0, then the number of parallel pipelines in the parallel architecture of the feature module will be adjusted to 2.6 times the original number, and the results will be rounded up.

[0074] Specifically, after re-examining and adjusting the number of parallel pipelines in the parallel architecture of the feature module, the intrusion detection status is checked. If the intrusion detection status is still unsatisfactory, the number of times the detection rate is lower than the preset detection rate in multiple historical periods is obtained. If the number is greater than the preset number, it indicates that the number of network intrusion samples used to train the AI ​​model is small and the distribution of attack types in the network intrusion samples is uneven, which makes the AI ​​model unable to perform accurate intrusion detection, resulting in errors in the intrusion detection results. Therefore, the number of network intrusion samples is adjusted based on the ratio of the number of times the detection rate is lower than the preset detection rate in multiple historical periods to the preset number. The preset ratio T0 of the number of times the detection rate is lower than the preset detection rate in multiple historical periods to the preset number is 1.33. The comparison process between the ratio T of the number of times the detection rate is lower than the preset detection rate in multiple historical periods to the preset number and the preset ratio T0 is as follows:

[0075] If the ratio T is less than or equal to the preset ratio T0, the number of network intrusion samples will be adjusted to 1.7 times the original number of network intrusion samples. The adjusted values ​​will be rounded up, and the types of network intrusion samples after adjustment will be evenly distributed.

[0076] If the ratio T is greater than the preset ratio T0, the number of network intrusion samples will be adjusted to 2.4 times the original number of network intrusion samples. The adjusted values ​​will be rounded up, and the types of network intrusion samples after adjustment will be evenly distributed.

[0077] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

[0078] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. An abnormal network intrusion detection system based on FPGA and artificial intelligence, characterized in that, include: The network sensing unit is used to acquire and parse network packet information entering the network link in the FPGA to obtain data packets; An intrusion detection unit, connected to the network perception unit, includes a feature extraction module for converting the original fields in the data packets extracted based on a parallel architecture into feature vectors, an artificial intelligence module for real-time calculation of the feature vectors based on an AI model trained on network intrusion samples to obtain anomaly scores, and a detection result fusion module for fusing the rule parsing results and anomaly scores in the data packets based on threshold conditions to obtain intrusion detection results, wherein the threshold conditions include a threshold for the anomaly scores. An intrusion response unit, connected to the intrusion detection unit, is used to determine the response processing mechanism based on the intrusion detection result and to make adjustments based on the response processing mechanism. The response processing mechanism includes traffic blocking, packet filtering and forwarding, and alarm notification. An analysis unit, connected to the intrusion response unit, is used to calculate the detection rate within a preset period after adjustment based on the processing mechanism, determine the intrusion detection status based on the detection rate, adjust the threshold of the anomaly score based on the intrusion detection status, and adjust the number of parallel pipelines in the parallel architecture of the feature extraction module based on the intrusion detection status after adjusting the threshold of the anomaly score. The detection rate is the ratio of correctly identified abnormal traffic to the total real abnormal traffic, and the abnormal traffic is the network traffic data that is abnormal in the intrusion detection results output by the intrusion detection unit. The analysis unit is also used to repeatedly adjust the threshold of the abnormal score at least once if the intrusion detection status is unqualified after adjusting the threshold of the abnormal score, until the number of adjustments is less than the preset number and the intrusion detection status is qualified, or the number of adjustments is equal to the preset number and the adjustment stops. The analysis unit is also used to calculate the variance of the detection rate over multiple historical periods when the intrusion detection status is unqualified after the adjustment is stopped. The analysis unit is also used to adjust the number of parallel pipelines in the parallel architecture of the feature extraction module based on the difference between the preset variance and the variance when the variance is less than the preset variance. The intrusion detection status is deemed qualified when the detection rate is greater than or equal to the preset detection rate.

2. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 1, characterized in that, The network sensing unit includes: The message parsing module, which is connected to the intrusion detection unit, is used to parse the basic characteristics of network message information; The flow table parsing module, which is connected to the intrusion detection unit, is used to scan the hardware flow table and parse the state information of each network flow; The rule parsing module, which is connected to the intrusion detection unit, is used to obtain routing rules and firewall rules information in order to parse the rule parsing results; The network sensing unit is also used to fuse the results obtained by the packet parsing module, the flow table parsing module, and the rule parsing module to generate data packets.

3. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 2, characterized in that, Also includes: A traffic context storage unit, which is connected to the network sensing unit and the intrusion detection unit respectively, is used to update the flow table based on the result obtained by the packet parsing module in the network sensing module, and transmit the data after updating the flow table to the flow table parsing module in the network sensing unit for parsing, so as to update the data packet; The traffic context storage unit is also used to receive the intrusion detection results from the intrusion detection unit in order to record network session information.

4. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 1, characterized in that, Also includes: A network packet caching unit, which is connected to the intrusion response unit, is used to store network packet information and adjust the network packet information based on the response processing mechanism of the intrusion response unit.

5. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 1, characterized in that, The analysis unit is also used to obtain the detection rate for multiple historical periods when the intrusion detection status is unqualified, and to calculate the average of the multiple detection rates; The analysis unit is also used to adjust the threshold of the abnormal score based on the difference between the preset detection rate and the average score when the average value is less than the preset detection rate. Wherein, if the detection rate is less than the preset detection rate, the intrusion detection status is determined to be unqualified.

6. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 5, characterized in that, The analysis unit is also used to reduce the threshold of the abnormal score based on the difference between the preset detection rate and the average value, and the reduction of the threshold of the abnormal score is proportional to the difference.

7. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 6, characterized in that, The intrusion detection unit is also equipped with a real-time traffic probe cluster to sense the delay time of the attack situation; The analysis unit is also used to calculate the integral of the plotted real-time flow probe number-delay time curve when the intrusion detection status is unqualified after adjusting the threshold of the abnormal score based on the average of multiple detection rates. The analysis unit is also used to adjust the threshold of abnormal scores based on the ratio of the integral to the preset integral when the integral is greater than the preset integral.

8. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 7, characterized in that, The analysis unit is also used to reduce the threshold of abnormal scores based on the ratio of the integral to the preset integral, and the reduction of the threshold of abnormal scores is proportional to the ratio.

9. The abnormal network intrusion detection system based on FPGA and artificial intelligence according to claim 1, characterized in that, The analysis unit is also used to increase the number of parallel pipelines in the parallel architecture of the feature extraction module based on the difference between the preset variance and the variance, and the increase in the number of parallel pipelines in the parallel architecture of the feature extraction module is proportional to the difference.

Citation Information

Patent Citations

  • Field programmable gate array-based (FPGA-based) intrusion detection system and method

    CN102571494B

  • Intrusion prevention system and method

    CN107612948A

  • Vehicle-mounted OTA parallel upgrading method and system for multiple subnets and multiple ECUs

    CN116860300A