Mimicry traffic defense method and system based on dynamic graph residual comparison
By constructing dynamic graph sequences and using Transformer networks for anomaly scoring and attack prediction, a mimicry traffic defense method is developed. This method addresses the problems of insufficient modeling of inter-host interaction relationships and rigidity of mimicry defense mechanisms in existing technologies, enabling efficient identification and flexible response to complex network attacks.
Patent Information
- Application Number
- CN202511726481.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-24
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2045-11-24
AI Technical Summary
Existing network traffic detection methods struggle to effectively capture dynamic interactions between hosts when facing multi-stage attacks and complex scenarios. Their mimicry defense mechanisms are rigid and lack interpretability, resulting in insufficient identification capabilities and a high risk of misjudgment.
A mimicry traffic defense method based on dynamic graph residual comparison is adopted. By constructing a dynamic graph sequence, using a temporal graph attention network to encode nodes and graph-level embedding, and combining it with a Transformer network for anomaly scoring and attack prediction, a dual threshold is set for risk classification, and traffic is guided to standard or heterogeneous executors for response.
It significantly improves the ability to identify complex multi-stage attacks, reduces the risk of misjudgment, achieves accurate identification and flexible response to abnormal traffic, and improves the robustness and efficiency of defense decisions.
Smart Images

Figure CN121193544A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security protection technology, specifically to a mimicry traffic defense method and system based on dynamic graph residual comparison. Background Technology
[0002] As cyberattacks become increasingly sophisticated, traditional static feature-based detection methods are inadequate in dealing with complex scenarios such as multi-stage attacks and lateral movement. Existing technologies struggle to effectively capture the dynamic evolution of network topology and the behavioral dependencies between hosts.
[0003] The existing solutions have the following main drawbacks: First, the models generally adopt a static structure and do not introduce dynamic modeling of graph structures, making it impossible to identify the connection frequency and edge weight changes between hosts; second, the mimicry adjudication mechanism is relatively rigid, usually based on fixed traffic classification results to perform defense, without considering the dynamic adjustment of structural uncertainty; third, the models have poor interpretability, making it difficult to provide a clear analysis of the root causes of abnormal behavior, which limits the ability to trace attack sources and optimize strategies. Summary of the Invention
[0004] This invention provides a mimicry traffic defense method and system based on dynamic graph residual comparison, aiming to solve the problems of insufficient modeling of inter-host interaction relationships, rigidity of mimicry defense mechanisms, and lack of interpretability in existing network traffic detection methods.
[0005] To achieve the above objectives, the present invention provides the following technical solution: This invention discloses a mimicry traffic defense method based on dynamic graph residual comparison, comprising: S100: Collect network traffic logs and construct a dynamic graph sequence according to time steps. In the graph, nodes are host IPs, edges represent communication connections between hosts, and edge weights are obtained by transforming the connection features through a mapping function. S200: The node embedding matrix is obtained by encoding the dynamic graph sequence through the temporal graph attention network. The difference between the current node embedding and the historical baseline embedding is calculated to obtain the node-level residual. The difference between the current graph embedding and the historical graph embedding is calculated to obtain the graph-level residual. The node-level residual and the graph-level residual are weighted and fused to construct a unified residual vector. S300: Inputs a unified residual vector sequence as a temporal feature into the Transformer network and outputs node-level anomaly scores and graph-level attack prediction probability distributions in parallel. S400: Combines node-level anomaly scoring with graph-level attack prediction probability distribution to calculate anomaly intensity index, and sets dual thresholds to classify traffic into normal traffic, uncertain anomaly traffic, and high-risk traffic; S500: For uncertain abnormal traffic, it identifies abnormal nodes based on node-level anomaly scores and redirects the traffic to standard mimicry executors. For high-risk traffic, it redirects it to heterogeneous inducement executors and adjusts the response strategy according to the attack type.
[0006] As a preferred embodiment of the present invention, the step of constructing a unified residual vector includes: Set the historical time window length, obtain the node embedding matrix of several time steps before the current time step and calculate the average to obtain the historical baseline embedding, calculate the difference vector between the current node embedding and the historical baseline embedding and calculate the L2 norm to obtain the node anomaly metric. Average pooling is performed on the node embedding matrix at each time step to obtain the graph embedding at each time step. The graph embedding within the historical time window is averaged to obtain the historical graph embedding. The difference vector between the current graph embedding and the historical graph embedding is calculated and the L2 norm is obtained to obtain the graph anomaly metric. The average of the node anomaly metrics for all nodes is calculated, and the average of the node anomaly metrics is summed with the graph anomaly metrics according to the set weight coefficients to obtain a unified residual vector.
[0007] As a preferred embodiment of the present invention, the parallel output step includes: After adding positional encoding to the unified residual vector sequence, it is passed sequentially through a multi-head self-attention layer and a feedforward neural network layer to output the node representation sequence. Each node representation is mapped through a linear layer and then activated by a Sigmoid activation function to obtain a node-level anomaly score. The graph-level representation is obtained by average pooling the node representation sequence. The graph-level representation is then mapped through a linear layer and passed through the Softmax function to obtain the graph-level attack prediction probability distribution.
[0008] As a preferred technical solution of the present invention, the step of calculating the anomaly intensity index includes: calculating the average value of the node-level anomaly scores of all nodes, extracting the maximum probability value from the graph-level attack prediction probability distribution, and weighting and summing the average value of the node-level anomaly scores and the maximum probability value according to a set weight coefficient to obtain the anomaly intensity index.
[0009] As a preferred technical solution of the present invention, the dual thresholds include a safety threshold and a danger threshold. When the abnormal intensity index is lower than the safety threshold, it is determined to be normal flow. When the abnormal intensity index is higher than the danger threshold, it is determined to be high-risk flow. When the abnormal intensity index is between the safety threshold and the danger threshold, it is determined to be uncertain abnormal flow.
[0010] As a preferred technical solution of the present invention, the step of identifying abnormal nodes includes: setting a node abnormal threshold according to the statistical distribution of historical node-level abnormal scores, comparing the node-level abnormal scores of each node with the node abnormal threshold, marking nodes with abnormal scores higher than the node abnormal threshold as abnormal nodes, guiding the traffic corresponding to the abnormal nodes to the standard mimicry executor, and allowing the traffic corresponding to non-abnormal nodes to the real system.
[0011] As a preferred embodiment of the present invention, the standard mimicry actuator is superimposed with a random delay perturbation that follows a normal distribution on the reference response time.
[0012] As a preferred embodiment of the present invention, the heterogeneous induction executor adopts an operating system version, kernel configuration, or instruction set architecture that is different from that of the production system.
[0013] As a preferred embodiment of the present invention, the step of adjusting the response strategy includes: determining the attack type with the highest probability from the graph-level attack prediction probability distribution, and adjusting the response parameters of the standard mimicry executor or the heterogeneous induced executor according to the attack type.
[0014] This invention also proposes a mimicry traffic defense system based on dynamic graph residual comparison, comprising: The dynamic graph construction module is used to collect network traffic logs and construct a dynamic graph sequence according to time steps. In the graph, the nodes are host IPs, the edges represent communication connections between hosts, and the edge weights are obtained by transforming the connection features through a mapping function. The residual comparison module is used to encode the dynamic graph sequence through the temporal graph attention network to obtain the node embedding matrix, calculate the difference between the current node embedding and the historical baseline embedding to obtain the node-level residual, calculate the difference between the current graph embedding and the historical graph embedding to obtain the graph-level residual, and weightedly fuse the node-level residual and the graph-level residual to construct a unified residual vector. The temporal discrimination module is used to input the unified residual vector sequence as temporal feature into the Transformer network and output node-level anomaly scores and graph-level attack prediction probability distributions in parallel. The risk classification module is used to integrate node-level anomaly scoring with graph-level attack prediction probability distribution to calculate anomaly intensity index, and set dual thresholds to classify traffic into normal traffic, uncertain anomaly traffic, and high-risk traffic. The mimicry response module is used to identify abnormal nodes based on node-level anomaly scores for uncertain and abnormal traffic and guide the traffic to standard mimicry executors. For high-risk traffic, it guides it to heterogeneous inducement executors and adjusts the response strategy according to the attack type.
[0015] The beneficial effects of this invention are: 1. This invention employs a dual residual mechanism at both the node and graph levels to simultaneously capture changes in local host behavior and deviations in the global topology, and then uses weighted fusion to form a unified residual vector to drive subsequent discrimination. This dual-layer residual comparison mechanism significantly improves the ability to identify complex multi-stage attacks such as lateral movement and chain attacks, and has a stronger structural awareness capability compared to traditional single-layer feature detection methods.
[0016] 2. This invention, based on the Transformer's parallel output of node-level anomaly scoring and graph-level attack prediction, combined with a dual-threshold buffer strategy, avoids rigid decision-making based on a single threshold. By setting a buffer for uncertain abnormal traffic, the system can flexibly respond to ambiguous risk scenarios, effectively reducing two types of misjudgment risks: local node anomalies that are not significant at the graph level, and high graph-level probability but scattered nodes, thus significantly improving the robustness of defense decisions.
[0017] 3. This invention uses node-level anomaly scoring to accurately identify abnormal nodes and selectively redirect traffic, while dynamically adjusting the mimicry response strategy parameters based on graph-level attack type prediction. This adaptive response mechanism of "node location + type fine-tuning" ensures effective defense against suspicious traffic while avoiding excessive interference with normal business operations, achieving deep coupling between detection results and defense execution, and improving the overall system defense efficiency and anti-probe capability. Attached Figure Description
[0018] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a model diagram of a mimicry traffic defense method based on dynamic graph residual comparison according to the present invention; Figure 2 This is a flowchart illustrating a mimicry traffic defense method based on dynamic graph residual comparison according to the present invention. Figure 3 This is a schematic diagram of the structure of a mimicry traffic defense system based on dynamic graph residual comparison according to the present invention. Detailed Implementation
[0019] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0020] This invention provides a mimicry traffic defense method and system based on dynamic graph residual comparison, the overall model architecture of which is as follows: Figure 1 As shown. Figure 1The technical process, from network traffic collection, dynamic graph construction, residual comparison analysis, time series discrimination to mimicry response, is demonstrated. It aims to solve the problems of insufficient modeling of inter-host interaction relationships, rigidity of mimicry defense mechanisms, and lack of interpretability in existing network traffic detection methods.
[0021] Example 1: As Figure 2 As shown, the present invention provides a mimicry traffic defense method based on dynamic graph residual comparison, comprising: S100: Collect network traffic logs and construct a dynamic graph sequence according to time steps. In the graph, nodes are host IPs, edges represent communication connections between hosts, and edge weights are obtained by transforming the connection features through a mapping function. Specifically, the raw network communication logs are first collected and structured in real time. Each record in the network traffic log represents a connection event and includes the following feature fields: timestamp, source IP address, destination IP address, source port, destination port, protocol type, packet length, TCP state, etc. These features are then combined into a d-dimensional feature vector. ,in Indicates time index: ; The entire input sequence is represented as: ; in Indicates the length of the time series. In time step Recorded connection event feature vectors. This sequence forms the basis for constructing the dynamic graph, preserving fine-grained temporal information of the original behavior.
[0022] For each time point Construct a directed weighted graph Its definition is: ; in For a set of nodes, For edge set, It is an adjacency matrix.
[0023] The components are constructed as follows: Node set By time It consists of all active, unique host IP addresses. Specifically, iterate through the timelines. All connection event records are analyzed, and all source and destination IP addresses are extracted, deduplicated, and used to form a node set. Each node... It corresponds to a unique host IP address.
[0024] If at time Existence from source IP To the destination IP If a connection event occurs, then a directed edge is established in the graph. The direction of the edge points from the source IP to the destination IP. This directed edge can accurately depict the relationship between the initiator and receiver of network communication, which helps to identify targeted attack behaviors such as active scanning and one-way penetration.
[0025] For any edge Its weights are determined by the mapping function. Convert the characteristics of the connection event into real values. Specifically: if ,but ;otherwise .in Represents a node To the node Connection characteristics, including protocol type, port number, packet length, number of connections, etc. Mapping function Its function is to aggregate these multidimensional discrete or continuous features into a single edge weight value.
[0026] In one specific embodiment, the mapping function This can be achieved using a weighted summation method: ; in, Numerical encoding for the protocol type (e.g., TCP=1, UDP=2). Port similarity features This represents the number of data packets within that time step. Total number of bytes These are preset weight coefficients. Through this mapping function, different types of connection events are converted into comparable edge weight values, thereby achieving a quantitative representation of communication strength and behavioral patterns.
[0027] Through the above graph construction process, the system repeatedly performs the above construction operation for consecutive time steps to form a dynamic graph sequence: ; Each figure Captured The communication topology and connection patterns in the time-sequence network not only preserve the structural relationships between nodes but also reflect the evolutionary trajectory of network behavior over time. Compared to traditional feature vector-based methods, this dynamic graph sequence not only preserves the evolutionary information of the communication topology but also effectively reveals cross-node attack chains such as lateral movement and probing scans, providing a data foundation with both structural and temporal information for subsequent anomaly detection and attack identification.
[0028] In practical applications, the time step can be flexibly set according to the characteristics of network traffic, such as 1 second, 5 seconds, or 1 minute, to balance computational efficiency and detection accuracy. For high-speed network environments, a shorter time step helps to capture rapidly changing attack behaviors; for low-speed networks or scenarios requiring long-term monitoring, a longer time step can reduce computational overhead while maintaining the ability to detect slowly evolving attacks.
[0029] S200: The node embedding matrix is obtained by encoding the dynamic graph sequence through the temporal graph attention network. The difference between the current node embedding and the historical baseline embedding is calculated to obtain the node-level residual. The difference between the current graph embedding and the historical graph embedding is calculated to obtain the graph-level residual. The node-level residual and the graph-level residual are weighted and fused to construct a unified residual vector. Furthermore, the step of constructing the unified residual vector includes: Set the historical time window length, obtain the node embedding matrix of several time steps before the current time step and calculate the average to obtain the historical baseline embedding, calculate the difference vector between the current node embedding and the historical baseline embedding and calculate the L2 norm to obtain the node anomaly metric. Average pooling is performed on the node embedding matrix at each time step to obtain the graph embedding at each time step. The graph embedding within the historical time window is averaged to obtain the historical graph embedding. The difference vector between the current graph embedding and the historical graph embedding is calculated and the L2 norm is obtained to obtain the graph anomaly metric. The average of the node anomaly metrics for all nodes is calculated, and the average of the node anomaly metrics is summed with the graph anomaly metrics according to the set weight coefficients to obtain a unified residual vector.
[0030] Specifically, to identify anomalous evolutions in the network structure, this invention introduces a structural residual comparison mechanism. First, a Temporal Graph Attention Network (TGAT) encoder is used to analyze the dynamic graph at each time step t. Encoding is performed. TGAT can simultaneously capture the topological structure and temporal evolution features of a graph, mapping high-dimensional graph structure data to low-dimensional node representations. The resulting node embedding matrix is then obtained. each of the lines Corresponding node exist A low-dimensional representation vector for each time step. This embedding vector integrates the node's own features, neighbor node information, and edge weights, comprehensively depicting the node's behavior and state within the current network topology.
[0031] To detect whether the current graph structure deviates from historical patterns, this invention employs a sliding window mechanism to calculate the historical baseline embedding. Specifically, at the current time... Set the historical time window length to Looking back Node embedding matrix at each time step And calculate its average value as the historical benchmark embedding: ; in That is, time Historical benchmark embedding matrix, Represents a node The historical baseline embedding vector is used. This historical baseline incorporates the overall trend of the recent network structure, providing a comparative baseline for anomaly detection. By comparing with recent history, the system can detect whether the current structure deviates from the recent overall trend, making it suitable for detecting gradually evolving structural anomalies or latent attacks. In practical applications, the choice of window length K needs to balance detection sensitivity and stability. Smaller K values (e.g., K=35) make the system more sensitive to short-term changes, suitable for detecting sudden attacks; larger K values (e.g., K=1020) can smooth out short-term fluctuations, making it more suitable for identifying slowly evolving anomaly patterns.
[0032] The structural residual vector for each node is obtained by calculating the vector difference between the current node embedding and the historical baseline embedding. This residual reflects the instantaneous change in node behavior. ; in For nodes The residual vector. To facilitate measurement and subsequent processing, the L2 norm of this residual vector is further calculated as the anomaly metric for the node: ; In the above formula The larger the value, the stronger the node. The more significant the deviation of the behavior at the current moment compared to its recent historical patterns, the better. This metric can effectively identify localized abnormal behaviors such as sudden changes in communication frequency, abnormal changes in connected objects, and deviations in protocol usage patterns, providing a quantitative basis for accurately locating abnormal hosts.
[0033] To capture global structural changes, graph-level residuals need to be further calculated. First, average pooling is performed on the node embedding matrices at each time step to obtain the graph embedding vectors at each time step: ; in The total number of nodes. Indicates the current time The global graph embedding aggregates information from all nodes, reflecting the state characteristics of the overall network. Subsequently, the average graph embedding within the historical time window is calculated as the historical graph embedding base. ; in This represents the global state averaged historically. Next, the difference between the current graph embedding and the historical graph embeddings is calculated to obtain the graph-level residual vector: ; Further calculation of the L2 norm of the graph-level residual vector yields the graph anomaly metric: ; The graph-level residuals can reflect structural changes in the overall network topology, such as the addition of a large number of nodes, a complete shift in connection patterns, and sudden changes in global communication strength, among other macroscopic anomalies.
[0034] To simultaneously detect local node mutations and global semantic variations, this invention fuses node-level residuals and graph-level residuals to construct a unified residual vector. The specific steps are as follows: First, the average of the node anomaly metrics across all nodes is used to obtain the overall anomaly strength at the node level: ; Then, the average of the node anomaly metrics is calculated. With graph anomaly measure Based on the balance weight hyperparameter Weighted summation yields a unified residual vector. : ; in To balance the weight hyperparameters, this is used to adjust the contribution of global and local anomalies in the final decision. When When the size is large, the system pays more attention to changes in the overall network topology; when When the value is lower, the system is more sensitive to abnormal behavior of individual nodes. In practical applications, this parameter can be adjusted according to defense requirements and network characteristics. For example, it can be set to [specific value] for scenarios focusing on large-scale coordinated attacks. For scenarios where the focus is on single-point intrusion, settings can be configured. .
[0035] This unified residual vector As a key metric for structural anomaly detection, it serves as an input feature in subsequent time-series modeling and decision-making processes, participating in training and evaluation. Through this multi-level residual fusion mechanism, the system can effectively improve its sensitivity and response accuracy to weak structural disturbances, low-frequency attacks, and stealthy behaviors, while simultaneously meeting the dual requirements of local anomaly identification and global situational awareness.
[0036] S300: Inputs a unified residual vector sequence as a temporal feature into the Transformer network and outputs node-level anomaly scores and graph-level attack prediction probability distributions in parallel. Furthermore, the parallel output step includes: After adding positional encoding to the unified residual vector sequence, it is passed sequentially through a multi-head self-attention layer and a feedforward neural network layer to output the node representation sequence. Each node representation is mapped through a linear layer and then activated by a Sigmoid activation function to obtain a node-level anomaly score. The graph-level representation is obtained by average pooling the node representation sequence. The graph-level representation is then mapped through a linear layer and passed through the Softmax function to obtain the graph-level attack prediction probability distribution.
[0037] Specifically, to further capture the evolution trend of structural residual vectors in the time dimension, this invention constructs a Transformer-based temporal discrimination model. Through step S200, the system obtains a unified residual vector sequence over consecutive time steps. This sequence comprehensively reflects the changes in local node behavior and global topology deviations in the network structure.
[0038] Before inputting the residual sequence into the Transformer network, position encoding is first added to the residual vector at each time step. To preserve temporal positional information, positional encoding employs a combination of sine and cosine functions, enabling the model to distinguish inputs at different time steps. The positionally encoded sequences then utilize a multi-head attention mechanism to extract dependencies between sequences. ; Among them, the multi-head attention mechanism can capture the correlation between any two time steps in the sequence and learn various temporal dependency patterns such as short-term mutations and medium-term trends from different representation subspaces. The Transformer outputs a set of node representation sequences: Each of them Represents a node In time The structure is dynamically represented, integrating the node's historical behavior patterns, current state, and association information with other nodes.
[0039] Based on the node representation sequence output by the Transformer, the system performs both node-level and graph-level detection tasks in parallel. For node-level anomaly detection, for each node... The nodes are represented by a single-layer linear mapping. Convert to a scalar, then compress to the [0, 1] interval using the Sigmoid activation function, and calculate its anomaly probability: ; in and The weight and bias parameters of the linear layer are learned through training data. The Sigmoid activation function outputs the value. Represents a node The probability of an anomaly at the current moment. The closer the score is to 1, the more likely the node is to exhibit abnormal behavior; the closer it is to 0, the more normal the node's behavior.
[0040] This mechanism can accurately identify hosts, ports, or connections exhibiting abnormal behavior within the network, enabling host-level or connection-level threat localization. For example, when a host suddenly initiates connections to a large number of different targets or its communication protocol usage patterns change abnormally, its node-level anomaly score will significantly increase.
[0041] For graph-level attack prediction tasks, the system first performs average pooling on the node representation sequence, aggregating all node information into a single graph-level representation vector: ; in The graph-level representation, representing the overall network state within the current time window, captures the semantic features of the global topology. This graph-level representation is then mapped to the attack category space through a linear layer and normalized using the Softmax function to obtain the attack type prediction probability distribution. ; in , The weight and bias parameters for the graph classification module; output This represents the predicted probability distribution within the C-type attack label space. Specifically, ,in This indicates that the current network state belongs to the [number]th [level]. The probability of a certain type of attack is equal to the sum of all probabilities, which is 1.
[0042] The attack type determination is a multi-classification task, and the number of categories C can be defined according to actual defense needs. For example, it may include various types such as normal traffic, denial-of-service (DoS) attacks, port scanning, and brute-force attacks. The model's ability to achieve this relies on supervised learning using training data containing such finely labeled data. This module can quickly classify the overall traffic graph status within the current time window, assisting the mimicry system in attack type identification and response level determination.
[0043] By combining structural residuals and temporal dependencies in Transformer sequence modeling, node-level anomaly scoring and graph-level attack prediction are simultaneously performed on a unified structural embedding output, realizing a linked detection mechanism from fine-grained anomaly identification to global attack judgment. This mechanism not only improves the accuracy and coverage of anomaly detection but also enhances the system's adaptability to multi-source heterogeneous attacks, becoming a core intelligent decision-making module in mimicry defense.
[0044] S400: Combines node-level anomaly scoring with graph-level attack prediction probability distribution to calculate anomaly intensity index, and sets dual thresholds to classify traffic into normal traffic, uncertain anomaly traffic, and high-risk traffic; Furthermore, the step of calculating the anomaly intensity index includes: calculating the average value of the node-level anomaly scores of all nodes, extracting the maximum probability value from the graph-level attack prediction probability distribution, and weighting and summing the average value of the node-level anomaly scores and the maximum probability value according to a set weight coefficient to obtain the anomaly intensity index.
[0045] Specifically, after the structural residual comparison mechanism and the Transformer module complete the initial anomaly identification, a mimicry judgment and conflict mitigation mechanism is further established to address the lack of linkage and buffer space between "detection results" and "defense execution" in traditional intrusion detection. During the detection phase, the system has obtained two key indicators: one is the node-level anomaly score. , indicating the first Each node at time... The abnormal probability; secondly, the graph-level attack prediction results. ,in This represents the predicted probability distribution of the attack label.
[0046] In actual defense scheduling, the system calculates the global anomaly intensity index based on a fusion strategy. The specific steps are as follows: First, calculate the average node-level anomaly score for all nodes: ; in It reflects the average level of node anomalies in the overall network.
[0047] Secondly, predict the probability distribution of graph-level attacks. Extract the maximum probability value from: ; in This represents the confidence level of the strongest attack type at the graph level.
[0048] Finally, the average and maximum probability values of the node-level anomaly scores are compared using the set balancing weight hyperparameters. Weighted summation yields the anomaly intensity index: ; in The weighting of the control node-level anomaly score and attack type confidence level is balanced. This anomaly strength index... By combining information from both local node anomalies and global attack patterns, a more comprehensive picture of the current network security status can be drawn.
[0049] Furthermore, the dual thresholds include a safety threshold and a danger threshold. When the abnormal intensity index is lower than the safety threshold, it is determined to be normal flow. When the abnormal intensity index is higher than the danger threshold, it is determined to be high-risk flow. When the abnormal intensity index is between the safety threshold and the danger threshold, it is determined to be uncertain abnormal flow.
[0050] Specifically, the system uses a dual-threshold strategy to classify traffic into three risk levels. Specifically, it sets security thresholds. and danger threshold ,in Used to determine the level of abnormality: Normal traffic determination: If The system considers the current traffic to be of low risk and classifies it as normal traffic, directly entering the normal execution path without needing to activate the mimicry defense mechanism.
[0051] High-risk traffic determination: If The system identifies highly suspicious behavior, classifies it as high-risk traffic, and immediately triggers the mimicry defense mechanism.
[0052] Uncertainty-based abnormal traffic determination: If The system enters a buffer judgment phase, also known as "conservative mimicry execution mode," and classifies the traffic as uncertain and abnormal. Within the conflict zone, the system recognizes that although the discrimination module has not reached a strong attack consensus, there are still weak abnormal signals such as structural disturbances and node deviations.
[0053] For uncertain and abnormal traffic, the system adopts a buffering strategy: redirecting requests to a mimic execution pool, where virtual nodes (configured in a heterogeneous environment) provide non-core responses, while recording the response path and feature vectors for subsequent verification and relearning.
[0054] This buffering mechanism effectively avoids two common risks of false alarms: localized node anomalies without graph-level anomaly prediction, such as short-term communication pattern deviations in individual hosts that haven't yet formed an attack pattern; and high graph-level attack prediction probability with scattered node anomaly scores, such as spoofed scans or low-frequency poisoning behavior. Through a dual-threshold mechanism, the system effectively reduces the false alarm rate while maintaining detection sensitivity, improving the robustness and controllability of defense decisions. In practical applications, the threshold... and It can be dynamically adjusted according to historical traffic statistics and security policy requirements. The initial threshold can be determined by the statistical distribution of historical normal traffic abnormal intensity indicators to adapt to the defense needs of different network environments.
[0055] S500: For uncertain abnormal traffic, it identifies abnormal nodes based on node-level anomaly scores and redirects the traffic to standard mimicry executors. For high-risk traffic, it redirects it to heterogeneous inducement executors and adjusts the response strategy according to the attack type.
[0056] The system passes the abnormal intensity index After determining that the traffic poses a potential threat, the mimicry response process begins. To improve the system's responsiveness, controllability, and countermeasure effectiveness, this invention not only relies on anomaly intensity indicators... Risk classification is performed, and node-level anomaly scoring is further integrated. Achieve precise traffic redirection, combined with graph-level attack prediction results. Fine-tuning the response strategy enables intelligent adaptive defense.
[0057] Furthermore, the step of identifying abnormal nodes includes: setting a node abnormality threshold based on the statistical distribution of historical node-level abnormality scores; comparing the node-level abnormality score of each node with the node abnormality threshold; marking nodes with abnormality scores higher than the node abnormality threshold as abnormal nodes; guiding the traffic corresponding to the abnormal nodes to the standard mimicry executor; and allowing the traffic corresponding to non-abnormal nodes to pass through to the real system.
[0058] When the discrimination index is satisfied When this occurs, the system determines it to be an uncertain abnormal traffic flow and enters the standard mimicry strategy process.
[0059] The system uses node-level anomaly scoring vectors Implement refined traffic scheduling. The specific steps are as follows: First, set the node anomaly threshold based on the statistical distribution of historical node-level anomaly scores. This threshold can be dynamically determined by analyzing the mean and standard deviation of abnormal scores for all nodes within a historical time window, for example, by setting it to the historical mean plus 1.5 times the standard deviation.
[0060] Secondly, the node-level anomaly score for each node is compared with the node anomaly threshold. For any node... ,like If so, then mark the node as an abnormal node; if If it is, then it is marked as a non-abnormal node.
[0061] Finally, traffic corresponding to abnormal nodes is redirected to the standard mimic execution entity for processing, while traffic corresponding to non-abnormal nodes is directly allowed to pass through the real system. This selective traffic redirection mechanism ensures both defense response to suspicious traffic and avoids excessive interference with normal business operations, thereby improving the overall efficiency of the system.
[0062] Furthermore, the standard mimicry actuator is superimposed with a random delay perturbation that follows a normal distribution on the baseline response time.
[0063] Standard mimicry executions are deployed in logically isolated environments and typically use lightweight virtualized containers to host services. They can simulate normal business processes but do not involve real data or core resources.
[0064] To further disrupt the attacker's detection of the system's response patterns, this invention employs a perturbation mechanism. Specifically, the standard mimicry actuator is superimposed with a normally distributed random delay perturbation on the baseline response time: ; in As the baseline response time, The final response time of the system. Let be the disturbance quantity, which follows the mean . variance is The system follows a normal distribution. By introducing random delays, the system can effectively obscure an attacker's speculation about the system's logic and timing response patterns, making it impossible for the attacker to accurately predict the system's response time, thereby interfering with their judgment of the system's structure and behavioral logic.
[0065] Furthermore, the heterogeneous induction executor adopts an operating system version, kernel configuration, or instruction set architecture that is different from the production system.
[0066] Specifically, when When the system determines that the traffic is high-risk, it enters the enhanced mimicry response mechanism to guide all traffic to the heterogeneous induction executor.
[0067] Heterogeneous deception executors operate in deeply heterogeneous environments, employing different operating system versions, kernel configurations, or instruction set architectures than the production system. For example, if the production system runs a Linux 5.x kernel, the heterogeneous executor can be configured as a FreeBSD system or use a different version of the Linux kernel; if the production system is based on an x86 architecture, the heterogeneous executor can be deployed in an ARM architecture environment. This deep heterogeneity makes it difficult for attackers to determine whether their attack has hit the real target. Even if attackers obtain some information about the executor through fingerprinting or behavioral probing, this information differs significantly from the real production system, thus achieving the system's deception protection objective and greatly increasing the difficulty and cost for attackers to carry out precise attacks.
[0068] Furthermore, the step of adjusting the response strategy includes: determining the attack type with the highest probability from the graph-level attack prediction probability distribution, and adjusting the response parameters of the standard mimicry actuator or the heterogeneous induced actuator according to the attack type.
[0069] The system further predicts graph-level attacks based on the results. Fine-tune the response strategy to achieve precise countermeasures based on attack characteristics. The specific steps are as follows: First, predict the probability distribution of graph-level attacks. The attack type with the highest probability of being identified: ; in This indicates the most likely type of attack.
[0070] Subsequently, the response parameters of the standard mimicry actuator or the heterogeneous induced actuator are adjusted according to the attack type. Specific type-based fine-tuning strategies include: like To counter probe-type attacks, the system injects deceptive information in a targeted manner. For example, it returns TCP RST packets for closed ports and forged banner information for open ports to mislead attackers into drawing incorrect network maps. By providing false service version information or system fingerprints, the system causes attackers to develop subsequent attack strategies based on erroneous information, thus rendering them ineffective.
[0071] like To address brute-force attacks, the system employs an incremental delay response mechanism. As the number of authentication failures from the same source IP increases, the response delay increases significantly, drastically reducing the attacker's efficiency. For example, the first failure results in a 1-second delay, the second in a 2-second delay, the third in a 4-second delay, and so on, making brute-force attacks impractical in terms of time cost.
[0072] like In response to a DoS flood attack, the system automatically tightens its rate limiting policy and prioritizes resource allocation to drop connections from suspected attack sources, while simultaneously protecting the resources of the mimicking execution entity itself from being exhausted. Specific measures include: setting a rate cap on connection requests from a single source IP, dropping requests exceeding the limit; and temporarily blocking abnormally high-frequency connection requests.
[0073] By combining a general perturbation mechanism with a typed fine-tuning strategy, this mechanism can effectively obscure attackers' speculations about the system's logic and timing response patterns, improve the system's adaptability and robustness in uncertain and complex attack scenarios, effectively reduce the risk of misjudgment, and slow down the attacker's breakthrough speed.
[0074] Example 2: In November 2024, a university campus network suffered multiple DDoS attacks, affecting the normal use of its online teaching platform. Attackers used infected IoT devices (smart lights, cameras, etc.) on campus to form a botnet and launch a distributed attack on the academic affairs server. Traditional traffic scrubbing equipment can only perform global rate limiting after the attack traffic reaches a threshold, and cannot accurately identify the controlled botnet devices, thus affecting normal access for teachers and students as well. In March 2025, the university's network center adopted a solution such as... Figure 3 The present invention illustrates a mimicry traffic defense system based on dynamic graph residual comparison, deployed at the access layer of core services such as the academic affairs system, specifically including: The dynamic graph construction module is used to collect network traffic logs and construct a dynamic graph sequence according to time steps. In the graph, the nodes are host IPs, the edges represent communication connections between hosts, and the edge weights are obtained by transforming the connection features through a mapping function. The residual comparison module is used to encode the dynamic graph sequence through the temporal graph attention network to obtain the node embedding matrix, calculate the difference between the current node embedding and the historical baseline embedding to obtain the node-level residual, calculate the difference between the current graph embedding and the historical graph embedding to obtain the graph-level residual, and weightedly fuse the node-level residual and the graph-level residual to construct a unified residual vector. The temporal discrimination module is used to input the unified residual vector sequence as temporal feature into the Transformer network and output node-level anomaly scores and graph-level attack prediction probability distributions in parallel. The risk classification module is used to integrate node-level anomaly scoring with graph-level attack prediction probability distribution to calculate anomaly intensity index, and set dual thresholds to classify traffic into normal traffic, uncertain anomaly traffic, and high-risk traffic. The mimicry response module is used to identify abnormal nodes based on node-level anomaly scores for uncertain and abnormal traffic and guide the traffic to standard mimicry executors. For high-risk traffic, it guides it to heterogeneous inducement executors and adjusts the response strategy according to the attack type.
[0075] On a morning in April 2025 at 10:00 AM, during peak course selection time, the system detected 23 IP addresses within the campus network simultaneously accessing the academic affairs server at a high frequency. The residual comparison module identified a sharp increase in node-level residuals and a deviation of graph-level residuals from the normal fluctuation range; the time-series discrimination module output an attack probability of 0.91, and the risk grading module calculated the anomaly intensity to exceed the danger threshold. The system immediately redirected the relevant traffic to the heterogeneous induction execution entity through the mimicry response module, and superimposed random latency and rate limiting at the response level, reducing the attack intensity by 95%, while maintaining stable access for normal faculty and students. The system did not generate false alarms, and this invention completed identification and response within 3 minutes of the attack initiation.
[0076] In May 2025, a student computer in a laboratory was infected with a worm virus that used low-frequency scanning (5 targets every 10 minutes) to evade traditional detection. The residual comparison module, through dynamic graph sequences, discovered that this node accessed port 445 of 180 different IPs within 6 consecutive time windows. Although the traffic at individual moments was normal, the node-level residuals remained consistently high. The timing discrimination module outputs a scan attack probability of 0.73. The risk grading module classifies it as an uncertain anomaly (…). The system redirects traffic from this host to a standard mimicry executable, returning a forged service banner. The attacker's subsequent exploit code based on the error message fails, and the system-generated anomaly path graph helps administrators quickly locate and isolate the infected host.
[0077] In June 2025, the system detected an external IP address continuously attempting brute-force attacks on the campus SSH service. Each attempt was spaced 30 seconds apart to circumvent rate limits. The system's graph analysis revealed an abnormal connection pattern between this IP address and 12 servers on campus. Although the connection frequency was low, the authentication failure rate was 100%. Node-level anomaly scoring was performed. The timing discrimination module predicts and identifies the attack as a brute-force attack (probability 0.79). The mimicry response module dynamically adjusts response parameters based on the attack type and activates an incremental delay mechanism, reducing attack efficiency by over 90%. Throughout the process, the risk grading module and the mimicry response module work together to ensure that defensive actions always match the threat level.
[0078] Three months after deployment, a total of 67 attack attempts were detected, with a botnet attack interception rate of 91.7%. The average detection response time was reduced from 25 minutes with traditional equipment to 4 minutes, the false alarm rate dropped to 6.5%, and the normal traffic passage rate reached 98.3%. Through a unified residual comparison-driven dynamic discrimination and mimicry response closed loop, the system significantly improved the overall defense efficiency and stability of the campus network.
[0079] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A mimicry-based traffic defense method based on dynamic graph residual comparison, characterized in that, include: S100: Collect network traffic logs and construct a dynamic graph sequence according to time steps. In the graph, nodes are host IPs, edges represent communication connections between hosts, and edge weights are obtained by transforming the connection features through a mapping function. S200: The node embedding matrix is obtained by encoding the dynamic graph sequence through the temporal graph attention network. The difference between the current node embedding and the historical baseline embedding is calculated to obtain the node-level residual. The difference between the current graph embedding and the historical graph embedding is calculated to obtain the graph-level residual. The node-level residual and the graph-level residual are weighted and fused to construct a unified residual vector. S300: Inputs a unified residual vector sequence as a temporal feature into the Transformer network and outputs node-level anomaly scores and graph-level attack prediction probability distributions in parallel. S400: Combines node-level anomaly scoring with graph-level attack prediction probability distribution to calculate anomaly intensity index, and sets dual thresholds to classify traffic into normal traffic, uncertain anomaly traffic, and high-risk traffic; S500: For uncertain abnormal traffic, it identifies abnormal nodes based on node-level anomaly scores and redirects the traffic to standard mimicry executors. For high-risk traffic, it redirects it to heterogeneous inducement executors and adjusts the response strategy according to the attack type.
2. The mimicry traffic defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The steps for constructing a unified residual vector include: Set the historical time window length, obtain the node embedding matrix of several time steps before the current time step and calculate the average to obtain the historical baseline embedding, calculate the difference vector between the current node embedding and the historical baseline embedding and calculate the L2 norm to obtain the node anomaly metric. Average pooling is performed on the node embedding matrix at each time step to obtain the graph embedding at each time step. The graph embedding within the historical time window is averaged to obtain the historical graph embedding. The difference vector between the current graph embedding and the historical graph embedding is calculated and the L2 norm is obtained to obtain the graph anomaly metric. The average of the node anomaly metrics for all nodes is calculated, and the average of the node anomaly metrics is weighted and summed with the graph anomaly metrics according to the set weight coefficients to obtain a unified residual vector.
3. The mimicry-flow defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The parallel output steps include: After adding positional encoding to the unified residual vector sequence, it is passed sequentially through a multi-head self-attention layer and a feedforward neural network layer to output the node representation sequence. Each node representation is mapped through a linear layer and then activated by a Sigmoid activation function to obtain a node-level anomaly score. The graph-level representation is obtained by average pooling the node representation sequence. The graph-level representation is then mapped through a linear layer and passed through the Softmax function to obtain the graph-level attack prediction probability distribution.
4. The mimicry traffic defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The steps for calculating the anomaly intensity index include: calculating the average node-level anomaly score of all nodes, extracting the maximum probability value from the graph-level attack prediction probability distribution, and weighting the average node-level anomaly score and the maximum probability value by a set weighting coefficient to obtain the anomaly intensity index.
5. The mimicry-flow defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The dual thresholds include a safety threshold and a danger threshold. When the abnormal intensity index is lower than the safety threshold, it is determined to be normal flow. When the abnormal intensity index is higher than the danger threshold, it is determined to be high-risk flow. When the abnormal intensity index is between the safety threshold and the danger threshold, it is determined to be uncertain abnormal flow.
6. The mimicry traffic defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The steps for identifying abnormal nodes include: setting a node abnormality threshold based on the statistical distribution of historical node-level abnormality scores; comparing the node-level abnormality scores of each node with the node abnormality threshold; marking nodes with abnormality scores higher than the node abnormality threshold as abnormal nodes; directing the traffic corresponding to the abnormal nodes to the standard mimicry executor; and allowing the traffic corresponding to non-abnormal nodes to pass through to the real system.
7. The mimicry-flow defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The standard mimic actuator is superimposed with a random delay perturbation that follows a normal distribution on the baseline response time.
8. The mimicry traffic defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The heterogeneous induction executor uses an operating system version, kernel configuration, or instruction set architecture that is different from the production system.
9. The mimicry traffic defense method based on dynamic graph residual comparison according to claim 1, characterized in that, The steps for adjusting the response strategy include: determining the attack type with the highest probability from the graph-level attack prediction probability distribution, and adjusting the response parameters of the standard mimicry actuator or the heterogeneous induced actuator according to the attack type.
10. A mimicry-based traffic defense system based on dynamic graph residual comparison, characterized in that, include: The dynamic graph construction module is used to collect network traffic logs and construct a dynamic graph sequence according to time steps. In the graph, the nodes are host IPs, the edges represent communication connections between hosts, and the edge weights are obtained by transforming the connection features through a mapping function. The residual comparison module is used to encode the dynamic graph sequence through the temporal graph attention network to obtain the node embedding matrix, calculate the difference between the current node embedding and the historical baseline embedding to obtain the node-level residual, calculate the difference between the current graph embedding and the historical graph embedding to obtain the graph-level residual, and weightedly fuse the node-level residual and the graph-level residual to construct a unified residual vector. The temporal discrimination module is used to input the unified residual vector sequence as temporal feature into the Transformer network and output node-level anomaly scores and graph-level attack prediction probability distributions in parallel. The risk classification module is used to integrate node-level anomaly scoring with graph-level attack prediction probability distribution to calculate anomaly intensity index, and set dual thresholds to classify traffic into normal traffic, uncertain anomaly traffic, and high-risk traffic. The mimicry response module is used to identify abnormal nodes based on node-level anomaly scores for uncertain and abnormal traffic and guide the traffic to standard mimicry executors. For high-risk traffic, it guides it to heterogeneous inducement executors and adjusts the response strategy according to the attack type.
Citation Information
Patent Citations
Network attack detection method based on dynamic graph coding
CN120602146A
Electric power data anomaly detection method and system combined with edge calculation
CN120611200A
Signaling network vulnerability attack simulation and prevention system based on AI
CN120897194A
System and method for abnormal event detection in the operation of continuous industrial processes
SG131973A1