An ethernet intrusion detection method and system
By extracting features from physical and information domain data in train communication networks, and employing feature fusion based on Z-value standardization, short-time Fourier transform, grey relational analysis, and attention mechanism, a target intrusion detection model was constructed. This model addresses the shortcomings of existing technologies in jointly modeling physical and information domain data, thereby improving the accuracy of intrusion detection and the ability to identify complex attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-25
- Publication Date
- 2026-04-21
AI Technical Summary
Existing Ethernet intrusion detection methods lack joint modeling and deep correlation analysis of physical and information domain data, making it difficult to accurately identify complex cross-domain attack behaviors. Furthermore, insufficient weight quantification and fusion of multi-domain features result in low accuracy of the model when dealing with differences in the importance of different features. Insufficient extraction and utilization of time-series and frequency-domain features lead to intrusion detection with insufficient accuracy for real-time traffic data.
By acquiring physical and information domain data from the train communication network, Z-value standardization and short-time Fourier transform are used to extract time and frequency domain features. Grey relational analysis is used to calculate feature weights. The model is then built by combining a structured state-space sequence model and a convolutional neural network, and feature fusion is performed through an attention mechanism to construct a target intrusion detection model.
It achieves a comprehensive characterization of physical and information domain data, improves the integrity and accuracy of intrusion detection, can accurately identify different types of intrusion attack events, and enhances the ability to identify complex and diverse attacks.
Smart Images

Figure CN121441558B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of train communication network security technology, specifically relating to an Ethernet intrusion detection method and system. Background Technology
[0002] With the development of modern train communication networks, Ethernet has become the core infrastructure for information transmission within trains and between the train and the ground. Train communication networks need to simultaneously transmit large amounts of control signals, monitoring data, and passenger information, resulting in highly dynamic and complex network data traffic. In this environment, various network attacks, such as unauthorized access, data tampering, and denial-of-service attacks, occur frequently, posing a serious threat to train operation safety and the reliability of information systems.
[0003] Most existing Ethernet intrusion detection methods rely on single-domain data or simple statistical features, typically focusing only on information domain features such as network traffic, packet length, or protocol type, while neglecting the correlation between physical domain data (e.g., train speed, network voltage, network flow, and transformer temperature) and information domain data. These methods cannot comprehensively characterize network status and its potential abnormal behavior, and are insufficient in identifying complex attack scenarios, such as multiple types of attacks simultaneously targeting both the physical and information layers, easily leading to false positives, false negatives, and delayed responses. Furthermore, existing methods lack effective quantification and fusion mechanisms for the weights of multi-domain features, making it difficult to model when feature diversity and importance vary significantly. Their ability to mine temporal relationships and frequency domain patterns between features is limited, and they lack systematic processing for high-order feature representation and abstract feature extraction, resulting in unstable performance of intrusion detection models when dealing with real-time traffic data. Summary of the Invention
[0004] The technical problem this invention aims to solve is that existing Ethernet intrusion detection methods for train communication networks lack joint modeling and deep correlation analysis of physical and information domain data, making it difficult to accurately identify complex cross-domain attack behaviors; insufficient weight quantification and fusion of multi-domain features leads to low accuracy in handling differences in the importance of different features; and in terms of extracting and utilizing time-series and frequency-domain features, there is a lack of efficient abstraction and comprehensive expression of multi-dimensional features, resulting in insufficient accuracy of intrusion detection for real-time traffic data. This invention provides an Ethernet intrusion detection method and system.
[0005] Summary of the Invention: In a first aspect, the present invention provides an Ethernet intrusion detection method, comprising:
[0006] Physical domain data and information domain data are obtained from the train communication network. The physical domain data includes primary network current, primary network voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking level. The information domain data includes basic flow, communication protocol, connection behavior, timing correlation information and load information.
[0007] The primary grid current, primary grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data are normalized using the Z-value standardization method, and finally the time domain features are extracted. The time domain features include the mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor, and signal energy of the window data.
[0008] The basic traffic, communication protocol, connection behavior, timing correlation information and payload information in the information domain data are transformed into frequency domain signals using short-time Fourier transform. Finally, frequency domain features are extracted. The frequency domain signal includes frequency components, spectrum and frequency distribution. The frequency domain features include spectrum centroid, spectrum standard deviation, spectrum skewness and spectrum kurtosis.
[0009] The weights of each time-domain feature and each frequency-domain feature are calculated using grey relational analysis.
[0010] Based on the weights of each time-domain feature and each frequency-domain feature, a structured state-space sequence model is used to model the time-domain features, and a convolutional neural network is used to model the frequency-domain features, thereby obtaining abstract feature representations of the time-domain features and abstract feature representations of the frequency-domain features, respectively.
[0011] The abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features are fused, and the weights of each time-domain feature and frequency-domain feature are weighted through an attention mechanism to obtain the fused feature representation.
[0012] Based on the fused feature representation, a target intrusion detection model is obtained, and the target intrusion detection model is used to analyze the time domain features and the frequency domain features to identify different types of intrusion attack events.
[0013] Furthermore, the primary grid current, primary grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data are normalized using the Z-value standardization method, and finally the time-domain features are extracted, including:
[0014] The Z-value normalization method is used to normalize the primary side grid current, primary side grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking stage in the physical domain data, and the normalized result is obtained.
[0015] Based on the normalization result, the time-domain features are extracted.
[0016] Furthermore, the step of using short-time Fourier transform to convert the basic traffic, communication protocol, connection behavior, timing correlation information, and payload information in the information domain data into frequency domain signals, and finally extracting frequency domain features, including:
[0017] The basic traffic, communication protocol, connection behavior, timing correlation information and payload information in the information domain data are converted into the frequency domain signal using short-time Fourier transform.
[0018] The frequency domain features are extracted based on the frequency domain signal.
[0019] Furthermore, the calculation of the weights of each time-domain feature and frequency-domain feature using grey relational analysis includes:
[0020] The weights of each time-domain feature are calculated using grey relational analysis. The formula for calculating the weights of each time-domain feature using grey relational analysis is as follows:
[0021]
[0022] in, The weight set representing the temporal features, Indicates the first Weights of each time-domain feature, Indicates the first Each time-domain feature gray relational degree coefficient Indicates the first Each time-domain feature gray relational degree coefficient The number of time-domain features;
[0023] The formula for calculating the gray relational coefficient of the time domain feature is as follows:
[0024]
[0025] in, These are the time-domain feature resolution coefficients. Indicates the first The absolute difference between each time-domain feature value and its reference data Indicates the minimum difference. This indicates the maximum difference.
[0026] The weights of each frequency domain feature are calculated using grey relational analysis. The formula for calculating the weights of each frequency domain feature using grey relational analysis is as follows:
[0027]
[0028] in, The weight set represents the frequency domain features. Indicates the first Weights of each frequency domain feature Indicates the first Individual frequency domain feature gray correlation coefficient, Indicates the first Individual frequency domain feature gray correlation coefficient, The number of frequency domain features;
[0029] The formula for calculating the gray relational coefficient of the frequency domain feature is as follows:
[0030]
[0031] in, These are the frequency domain characteristic resolution coefficients. Indicates the first The absolute difference between each frequency domain eigenvalue and its reference data Indicates the minimum difference. This indicates the maximum difference.
[0032] Furthermore, based on the weights of each time-domain feature and the weights of each frequency-domain feature, a structured state-space sequence model is used to model the time-domain features, and a convolutional neural network is used to model the frequency-domain features, respectively obtaining abstract feature representations of the time-domain features and abstract feature representations of the frequency-domain features, including:
[0033] Based on the weights of each time-domain feature, a structured state-space sequence model is used to model the time-domain features, thereby obtaining an abstract feature representation of the time-domain features;
[0034] The formula for the abstract feature representation of time-domain features is as follows;
[0035]
[0036] in, Abstract feature representation representing time-domain features, This represents the output dimension of the structured state-space model. Represents the time-domain characteristic matrix. Represents a structured state-space sequence model;
[0037] Based on the weights of each frequency domain feature, a convolutional neural network is used to model the frequency domain features to obtain an abstract feature representation of the frequency domain features;
[0038] The formula for the abstract feature representation of frequency domain features is as follows;
[0039]
[0040] in, This represents the output dimension of the convolutional neural network model. An abstract feature representation of frequency domain characteristics.
[0041] Further, the process of fusing the abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features, and weighting the weights of each time-domain feature and frequency-domain feature through an attention mechanism to obtain the fused feature representation, includes:
[0042] The abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features are fused to form a joint feature vector, wherein the formula for forming the joint feature vector is as follows:
[0043]
[0044] in, Represents the joint eigenvector;
[0045] Based on the joint feature vector, the weights of each time-domain feature and frequency-domain feature are weighted using an attention mechanism to obtain the fused feature representation. The formula for obtaining the fused feature representation is as follows:
[0046]
[0047] in, This represents the fusion feature representation. Represents a non-linear activation function. This represents a weight given to distinguish the proportion of features in the entire time domain from those in the frequency domain.
[0048] Furthermore, based on the fused feature representation, a target intrusion detection model is obtained, and the target intrusion detection model is used to analyze the time-domain features and the frequency-domain features to identify different types of intrusion attack events, including:
[0049] Based on the fused feature representation, the time-domain features and the frequency-domain features are input into the target intrusion detection model;
[0050] The target intrusion detection model analyzes the time-domain and frequency-domain features to output the probability of various attacks occurring.
[0051] Based on the probability of various attacks occurring, different types of intrusion attack events can be identified.
[0052] Furthermore, after identifying different types of intrusion attack events based on the probability or confidence level of various attacks, the method further includes: outputting corresponding alarm information or response information, wherein the alarm information includes text, charts, and a real-time monitoring interface, and the response information includes triggering firewall rules, system log recording, and a graphical interface.
[0053] Furthermore, obtaining the target intrusion detection model includes:
[0054] The fused feature representation is input into the intrusion detection model, and the intrusion detection model is trained using a supervised learning method to obtain a preliminary intrusion detection model;
[0055] The preliminary intrusion detection model is verified and optimized to obtain the target intrusion detection model.
[0056] Secondly, the present invention also provides an Ethernet intrusion detection system, comprising:
[0057] The data acquisition module is used to acquire physical domain data and information domain data from the train communication network. The physical domain data includes primary network current, primary network voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking level. The information domain data includes basic flow, communication protocol, connection behavior, timing correlation information and load information.
[0058] The normalized data module is used to normalize the primary grid current, primary grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data using the Z-value normalization method, and finally extract the time domain features, which include the mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor, and signal energy of the window data.
[0059] The feature extraction module is used to convert basic traffic, communication protocols, connection behavior, timing correlation information and payload information into frequency domain signals using short-time Fourier transform, and finally extract frequency domain features. The frequency domain signal includes frequency components, spectrum and frequency distribution, and the frequency domain features include spectrum centroid, spectrum standard deviation, spectrum skewness and spectrum kurtosis.
[0060] The analysis and calculation module is used to calculate the weights of each time-domain feature and each frequency-domain feature using the grey relational analysis method.
[0061] The modeling and representation module, based on the weights of each time-domain feature and the weights of each frequency-domain feature, uses a structured state-space sequence model to model the time-domain features and a convolutional neural network to model the frequency-domain features, thereby obtaining abstract feature representations of the time-domain features and abstract feature representations of the frequency-domain features, respectively.
[0062] The weighted fusion module is used to fuse the abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features, and to weight the weights of each time-domain feature and frequency-domain feature through an attention mechanism to obtain the fused feature representation;
[0063] An intrusion identification module is used to obtain a target intrusion detection model based on the fused feature representation, and to analyze the time-domain features and frequency-domain features using the target intrusion detection model to identify different types of intrusion attack events.
[0064] The beneficial effects of this invention are:
[0065] 1. This invention extracts features by simultaneously utilizing physical domain data and information domain data, reflecting network status from both the signal and protocol levels. This avoids the problem of incomplete features caused by relying solely on data from a single domain, thus improving the completeness of intrusion detection.
[0066] 2. This invention employs a multi-dimensional extraction method combining time-domain and frequency-domain features, and uses a weighted attention mechanism for feature fusion to explore the correlations and differences between different features, thereby improving feature expressive power and overcoming the shortcomings of simple splicing, which makes it difficult to fully utilize feature correlations.
[0067] 3. This invention analyzes the fused features using a trained intrusion detection model, accurately identifies different types of intrusion attack events based on the probability of various attacks occurring, improves detection accuracy, and enhances the ability to identify complex and diverse attacks. Attached Figure Description
[0068] Figure 1 This is a flowchart illustrating an Ethernet intrusion detection method according to the present invention;
[0069] Figure 2 This is a flowchart illustrating an Ethernet intrusion detection method according to the present invention;
[0070] Figure 3 This is a flowchart illustrating the structure of an Ethernet intrusion detection system according to the present invention. Detailed Implementation
[0071] like Figure 1-2 As shown, the present invention includes an Ethernet intrusion detection method, comprising:
[0072] S1. Obtain physical domain data and information domain data from the train communication network respectively. The physical domain data includes primary side network current, primary side network voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking level. The information domain data includes basic flow, communication protocol, connection behavior, timing association information and load information.
[0073] Physical domain data refers to physical quantities reflecting the operation of the train and the status of the power system. These include key data related to train operation, such as primary-side grid current, primary-side grid voltage, transformer primary-side current, transformer oil pump current, three-phase isolation transformer temperature, traction transformer oil temperature, train speed, traction power level, and actual traction power value. Information domain data consists of quantitative indicators at the network packet level, including: basic traffic such as the number of data packets per second and the number of bytes per second, as well as average packet size and packet length distribution skewness; communication protocols such as the proportion of the first packet of the Transmission Control Protocol (TCP), the proportion of the Internet Control Message Protocol (ICP) packets, the proportion of the train real-time data protocol (RTG) packets, and the number of protocol types; connection behavior such as the retransmission packet ratio, the average session duration, and the TCP window change rate; time-series correlation information such as packet interval autocorrelation coefficient, traffic burst index, traffic self-similarity index, and wavelet decomposition energy ratio; and payload information such as payload hash similarity, payload content information entropy, and the number of network transmission protocol methods.
[0074] S2. The primary side grid current, primary side grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking level in the physical domain data are normalized using the Z-value standardization method to extract time-domain features, which include window data mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor and signal energy.
[0075] S21. The Z-value normalization method is used to normalize the primary side grid current, primary side grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking stage in the physical domain data to obtain the normalization result.
[0076] S22. Based on the normalization result, extract the time-domain features.
[0077] For example, the primary grid current, primary grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data of the time domain dimension are normalized using the Z-value standardization method to extract time domain features. The time domain features include: window data mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor, over-mean rate, signal energy, etc.
[0078] First, the Z-value normalization method is used to normalize the primary grid current, primary grid voltage, train speed, and three-phase isolation transformer temperature in the physical domain data. The time-domain features are then combined into a vector form, and the time-domain feature matrix is obtained based on this.
[0079]
[0080] Arrange the above vector forms in chronological order to construct the time-domain feature matrix:
[0081]
[0082] Then, the temporal features are extracted and calculated as follows, where, This represents the original signal, i.e., physical domain data. Window length:
[0083]
[0084] S3. The basic traffic, communication protocol, connection behavior, timing correlation information and load information in the information domain data are converted into frequency domain signals using short-time Fourier transform, and finally frequency domain features are extracted. The frequency domain signal includes frequency components, spectrum and frequency distribution, and the frequency domain features include spectrum centroid, spectrum standard deviation, spectrum skewness and spectrum kurtosis.
[0085] S31. The basic traffic, communication protocol, connection behavior, timing correlation information and payload information in the information domain data are converted into the frequency domain signal using short-time Fourier transform;
[0086] In one embodiment, over time, the basic traffic, communication protocols, connection behaviors, timing correlation information, and payload information in the information domain data are converted into frequency domain signals through short-time Fourier transform.
[0087] S32. Extract frequency domain features based on the frequency domain signal.
[0088] In one embodiment, frequency domain features are extracted from the frequency domain signal, and a two-dimensional spectrogram is constructed from these features. This combines the information of the signal in both time and frequency dimensions to form an image. In this image, the horizontal axis represents time, and the vertical axis represents frequency. Each point shows the intensity of a certain frequency at a certain moment, i.e., the spectral characteristics of the signal. By observing the frequency characteristics of the signal from multiple perspectives, patterns or anomalies can be discovered.
[0089] Based on a two-dimensional spectrogram, the variation of the signal at different frequencies is reflected. Frequency domain characteristics include spectral centroid, spectral standard deviation, spectral skewness, and spectral kurtosis.
[0090] For example, frequency domain features are extracted from information domain data from the frequency domain dimension. These frequency domain features include: spectral centroid, spectral standard deviation, spectral skewness, spectral kurtosis, and other features.
[0091] Frequency domain feature processing method: Fuse frequency domain features into a two-dimensional spectrogram. The construction method is as follows:
[0092] (a1) Define the basic spectrum framework: ,in, S ( f ) represents the basic spectrum framework, x Represents a time-domain signal. FFT ( x ) indicates performing a short-time Fourier transform on the time-domain signal, and N represents the signal length, i.e., the sampling window length.
[0093] (a2) Define the band energy fusion function: ,in, For frequency variables, For frequency band energy weighting coefficients, For the first Bandwidth energy, ; The number of frequency bands to be divided; For rectangular window functions, ; For the first Frequency band center frequency, ; , The first Lower and upper frequency limits; For the first Half bandwidth .
[0094] (a3) Integrate the features into the base spectrum:
[0095] Frequency domain features are extracted and calculated as follows:
[0096]
[0097]
[0098] in, It is the Dirac delta function, used at the reference frequency. Create a pulse at a point whose intensity is the sum of the entropy coordinates. Decide. These are global control parameters. ; and The horizontal and vertical axes of the entropy coordinates are:
[0099]
[0100] Where SampEn represents the sample entropy, and ApEn represents the approximate entropy. =30°, , . and These are the right and upper boundaries of the spectrum, respectively. Based on the calculated... Different frequency points were obtained ( ) and time frame count ( Two-dimensional spectrum diagram below: .
[0101] S4. Use grey relational analysis to calculate the weights of each time-domain feature and each frequency-domain feature;
[0102] S41. Use grey relational analysis to calculate the weights of each time-domain feature;
[0103] In one embodiment, grey relational analysis is used to calculate the weights of each time-domain feature and frequency-domain feature, and these weights can identify features that better reflect intrusion attack behavior.
[0104] Specifically as follows:
[0105] The formula for calculating the weights of each time-domain feature using grey relational analysis is as follows:
[0106]
[0107] in, The weight set representing the temporal features, Indicates the first Weights of each time-domain feature, Indicates the first Each time-domain feature gray relational degree coefficient Indicates the first Each time-domain feature gray relational degree coefficient The number of time-domain features;
[0108] The formula for calculating the gray relational coefficient of the time domain feature is as follows:
[0109]
[0110] in, These are the time-domain feature resolution coefficients. Indicates the first The absolute difference between each time-domain feature value and its reference data Indicates the minimum difference. This indicates the maximum difference.
[0111]
[0112] in, Indicates the first i The result of normalizing the time-domain features This represents the result of selecting a set of reference data from the time-domain features and performing normalization processing:
[0113] Among them, the time-domain features are normalized:
[0114]
[0115] in, Indicates the first The temporal feature sequence at time step, Indicates the first The first moment Each time-domain feature Indicates the first The minimum value of all time-domain features at time t. Indicates the first The maximum value of all time-domain features at time t.
[0116] S42. Use grey relational analysis to calculate the weights of each frequency domain feature. The formula for calculating the weights of each frequency domain feature using grey relational analysis is as follows.
[0117]
[0118] in, The weight set represents the frequency domain features. Indicates the first Weights of each frequency domain feature Indicates the first Individual frequency domain feature gray correlation coefficient, Indicates the first Individual frequency domain feature gray correlation coefficient, The number of frequency domain features;
[0119] The formula for calculating the gray relational coefficient of the frequency domain feature is as follows:
[0120]
[0121] in, These are the frequency domain characteristic resolution coefficients. Indicates the first The absolute difference between each frequency domain eigenvalue and its reference data Indicates the minimum difference. This indicates the maximum difference.
[0122]
[0123] in, This represents the result of normalizing the frequency domain features. This represents the result of selecting a set of reference data from the frequency domain features and performing normalization processing:
[0124] Among them, the frequency domain features are normalized:
[0125]
[0126] in, Indicates the first Frequency domain feature sequence at time step Indicates the first The first moment Individual frequency domain features, Indicates the first The minimum value of all frequency domain features at time t. Indicates the first The maximum value of all frequency domain features at time t.
[0127] In one embodiment, the focus is adjusted based on the weights of each feature, placing greater emphasis on the features most important for intrusion detection. By combining the weight information of various time-domain and frequency-domain features, the correlation between features from different domains and their impact on intrusion attack behavior can be captured more accurately.
[0128] Responsiveness.
[0129] S5. Based on the weights of each time-domain feature and each frequency-domain feature, a structured state-space sequence model is used to model the time-domain features, and a convolutional neural network is used to model the frequency-domain features, thereby obtaining abstract feature representations of the time-domain features and abstract feature representations of the frequency-domain features, respectively.
[0130] S51. Based on the weights of each time-domain feature, a structured state-space sequence model is used to model the time-domain features to obtain an abstract feature representation of the time-domain features;
[0131] In one embodiment, the time-domain features are modeled based on the weights of each time-domain feature. A structured state-space sequence model is used to capture the temporal variation patterns in the time-domain features, transforming the time-domain features into a more abstract representation. This is a new, simpler, and more efficient representation, namely, an abstract feature representation of the time-domain features.
[0132] S52. Based on the weights of each frequency domain feature, a convolutional neural network is used to model the frequency domain features to obtain an abstract feature representation of the frequency domain features.
[0133] In one embodiment, a convolutional neural network (CNN) is a deep learning method that automatically learns and extracts important patterns and information from frequency domain features through multiple convolutional layers. Based on the weights of each frequency domain feature, a CNN is used to model the frequency domain features. After processing by the CNN, relevant information is extracted from the frequency domain data, transforming the frequency domain features into abstract features suitable for processing by the corresponding model—that is, an abstract feature representation of the frequency domain features. The relevant information refers to features in the frequency domain data that are helpful for the corresponding model's recognition and classification tasks, including: local patterns of the frequency domain features, spectral trends, and important frequency components.
[0134] For example, (i) Temporal feature modeling: Temporal features are modeled using a structured state-space sequence model:
[0135] First, construct the parameter matrix. ,
[0136]
[0137] in,
[0138] Then, eigenvalue decomposition is performed on the parameter matrix.
[0139]
[0140] in, λ u Represents the first parameter matrix u 1 eigenvalue, Represents an eigenvalue diagonal matrix. express The square array, its first u Columns represent eigenvalues λ u The corresponding feature vector.
[0141] Next, the sign of the eigenvalue diagonal matrix is flipped and controlled-scaled to obtain a new state matrix. .
[0142]
[0143]
[0144] in, Indicates the scaling factor. This represents the matrix after sign flipping the diagonal matrix of the feature. The purpose of sign flipping and controlled scaling is as follows: sign flipping the initial matrix can cause the matrix to oscillate in opposite directions under the same input, amplifying small differences in features and making subsequent attacks easier to detect; while controlled scaling is to ensure that the amplified differences do not become too large and cause overflow, thus reducing the false positive rate.
[0145] Finally, after obtaining the new state matrix, a structured state-space sequence model is established:
[0146]
[0147] in, This is a parameter matrix; the specific values need to be obtained through training. This represents a hidden state, i.e., an intermediate process state. Indicates the first The temporal characteristics of a moment y k Indicates the first k The output of each iteration is calculated, ultimately yielding the entire sequence representation, which is an abstract feature representation of the time-domain features.
[0148]
[0149] in, Abstract feature representation representing time-domain features, Represents a structured state-space sequence model. Represents the time-domain characteristic matrix. This represents the output dimension of the structured state-space model.
[0150] (ii) Frequency domain feature modeling: The frequency domain features are modeled using a convolutional neural network.
[0151] Since time-domain features are one-dimensional vectors while frequency-domain features are two-dimensional vectors, there is a dimensionality mismatch problem when fusing the two sets of features. The traditional approach is to brute-force reduce the dimensionality of the entire spectrum, but this method easily loses time-frequency complementary information or introduces invalid parameters by adding zero truncation. This invention proposes a global time-frequency heterooperation pooling dimensionality reduction method. Specifically, on the same spectrum, "averaging in the time direction" captures the overall trend, and "maximizing in the frequency direction" captures sudden spikes. Then, the two complementary contours are concatenated into a one-dimensional structured vector. The dimensionality reduction using global time-frequency heterooperation pooling is as follows:
[0152] First, global average pooling is performed in the time direction to capture the distribution of average energy. :
[0153]
[0154] in, Representing a two-dimensional spectrum One pixel, This represents all frequency points in the spectrum. Indicates the size of the time window for constructing the spectrogram ( ).
[0155] Then, max pooling is performed in the frequency direction to capture the maximum spectral distribution. :
[0156]
[0157] Next, the average energy and the maximum spectral distribution are concatenated to obtain the input sequence of the convolutional neural network:
[0158]
[0159] in, This represents the number of input frequency domain features.
[0160] Finally, a convolutional neural network is used to encode the frequency domain features to obtain an abstract feature representation of the frequency domain features.
[0161]
[0162] in, Abstract feature representation of frequency domain features. W F The weights of each frequency domain feature are represented. This represents the output dimension of the convolutional neural network model. CNN stands for Convolutional Neural Network.
[0163] S6. The abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features are fused, and the weights of each time-domain feature and frequency-domain feature are weighted through an attention mechanism to obtain the fused feature representation;
[0164] S61. The abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features are fused to form a joint feature vector;
[0165] In one embodiment, fusing the abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features involves merging them into a new joint feature vector. Combining two different types of features allows for a more comprehensive reflection of the data.
[0166] S62. Based on the joint feature vector, the weights of each time-domain feature and frequency-domain feature are weighted by an attention mechanism to obtain the fused feature representation.
[0167] In one embodiment, an attention mechanism is used to weight the temporal and frequency domain features in the joint feature vector, assigning a weight to each feature that represents its importance to the intrusion detection result. Since the weights of the temporal and frequency domain features are different, the attention mechanism dynamically adjusts their weights to obtain a fused feature representation that more accurately represents the features of the data. The attention mechanism is an algorithm that helps the model focus on more important parts by dynamically adjusting the weights of input features.
[0168] Specifically, introducing an attention fusion mechanism will and The fusion process is performed. First, the abstract feature representations of the time domain features and the abstract feature representations of the frequency domain features are fused and concatenated to form a joint feature vector:
[0169]
[0170] in, This represents the joint eigenvector.
[0171] The importance of introducing attention mechanisms to learn two modalities:
[0172]
[0173] in, This represents the fusion feature representation. α This represents a weight assigned to distinguish the proportion of features in the time domain from those in the frequency domain. , This represents a non-linear activation function.
[0174] Define cross-entropy loss: ,in, Indicates the attack category index. The first one representing the true label One portion, The model predicts the first Class probability.
[0175] The acquisition of the target intrusion detection model includes:
[0176] The fused feature representation is input into the intrusion detection model, and the intrusion detection model is trained using a supervised learning method to obtain a preliminary intrusion detection model;
[0177] The preliminary intrusion detection model is verified and optimized to obtain the target intrusion detection model.
[0178] In one embodiment, physical domain data and information domain data collected from the train communication network are compiled into a complete training dataset. This dataset includes data from normal network operation as well as data from various attack scenarios. Supervised learning methods such as neural networks and convolutional networks are used to learn from the training dataset. By repeatedly analyzing the relationship between features in the training data and corresponding attack labels, the internal parameters are continuously adjusted to capture the correspondence between physical domain features, information domain features, and intrusion behaviors, thus obtaining a preliminary intrusion detection model. The preliminary intrusion detection model is then validated and optimized by testing its recognition performance on an independent validation dataset, checking the false positive rate and false negative rate, and adjusting the parameters or training strategy of the preliminary intrusion detection model based on the test results to achieve optimal performance, resulting in a target intrusion detection model that can be directly used for intrusion detection.
[0179] For example, such as Figure 2 As shown, a target intrusion detection model is obtained and verified by establishing a simulation platform. Based on the actual network topology of high-speed trains, a train communication network simulation platform is built in the Mininet environment using an open-source controller. ECNN represents the train formation network switch, ETBN represents the backbone network switch, and the lower boxes represent the devices in the train communication network. This simulation platform contains a total of 8 carriages, divided into two train formations. The train formations are networked within each other using ECNN, and the two train formations are connected via ETBN.
[0180] Construct five attack scenarios:
[0181] 1) Tampering attack: Gain control of h3:BCU in cars 3 and 6, tamper with the application data of h3:BCU (such as the actual value of train braking force), and send the tampered value to the network according to the original application protocol specifications.
[0182] 2) Replay attack: Add an attacking host to the network and use a man-in-the-middle attack method to hijack the data sent from h3:TCU of vehicles 2 and 7 to h1:CCU1 and h2:CCU2 of vehicles 1 and 8. Then, according to its original application protocol specifications, periodically send outdated data to h1:CCU1 and h2:CCU2 of vehicles 1 and 8, such as a side network stream.
[0183] 3) Error data injection attack: Add an attack host to the network and intermittently simulate car 4 and car 5 h1:IOM1 sending error data (such as traction transformer oil temperature).
[0184] 4) Denial-of-Service attack: Adding an attacking host to the network and injecting a large number of UDP packets into the network, causing network flooding.
[0185] 5) Probe attack: Add an attacking host to the network to scan network IP addresses and ports.
[0186] S7. Based on the fused feature representation, obtain a target intrusion detection model, and use the target intrusion detection model to analyze the time domain features and the frequency domain features to identify different types of intrusion attack events.
[0187] S71. Based on the fused feature representation, the time-domain features and the frequency-domain features are input into the target intrusion detection model;
[0188] In one embodiment, based on the fused feature representation, time-domain features and frequency-domain features are input into the target intrusion detection model, which analyzes the features to assess whether they represent potential network intrusions.
[0189] S72. Analyze the time-domain features and frequency-domain features using the target intrusion detection model, and output the probability of various attacks occurring;
[0190] In one embodiment, each attack category, such as tampering, replay, and denial-of-service, has a probability value representing the likelihood of that attack type occurring. After analyzing the input time-domain and frequency-domain features using a targeted intrusion detection model, the probability of each possible attack type is output.
[0191] S73. Identify different types of intrusion attack events based on the probability of each type of attack occurring.
[0192] In one embodiment, the final attack type is selected from candidate attack types based on the predicted probability value and according to a set threshold or classification criterion.
[0193] It also includes: outputting corresponding alarm or response information, where alarm information includes text, charts, and a real-time monitoring interface, and response information includes triggering firewall rules, system log recording, and a graphical interface.
[0194] In one embodiment, if the probability of a certain attack type exceeds a certain threshold, an alert is generated and the network administrator is notified. Defense mechanisms are also activated, such as cutting off the attack source and isolating the network. By clearly defining the attack category and its corresponding probability, specific attack events are identified and responded to briefly. Alert information includes detailed information about the attack event, presented in various formats, including text, charts, and real-time monitoring interfaces. Response information primarily addresses emergency handling measures for the attack event, including triggering firewall rules, system logging, and graphical interfaces.
[0195] This invention utilizes both physical and information domain data for feature extraction, reflecting network status at both the signal and protocol levels. This avoids the problem of incomplete features caused by relying solely on data from a single domain, thus improving the completeness of intrusion detection. It employs a multi-dimensional extraction method using time and frequency domain features, and utilizes a weighted attention mechanism for feature fusion to uncover the correlations and differences between different features, enhancing feature representation capabilities and overcoming the shortcomings of simple splicing, which fails to fully utilize feature correlations. Furthermore, by analyzing the fused features through a trained intrusion detection model, it accurately identifies different types of intrusion attack events based on the probability of various attacks, improving detection accuracy and enhancing the ability to identify complex and diverse attacks.
[0196] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of protection of this application is limited to these examples; within the framework of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of one or more embodiments of this application as described above, which are not provided in detail for the sake of brevity.
[0197] One or more embodiments in this application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of this application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of one or more embodiments in this application should be included within the protection scope of this application.
[0198] Figure 3 This is a flowchart illustrating the structure of an Ethernet intrusion detection system according to the present invention.
[0199] Based on the same concept, the present invention also discloses an Ethernet intrusion detection system, comprising:
[0200] The data acquisition module 31 is used to acquire physical domain data and information domain data from the train communication network respectively. The physical domain data includes primary side network current, primary side network voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking level. The information domain data includes basic flow, communication protocol, connection behavior, timing association information and load information.
[0201] The normalized data module 32 is used to normalize the primary side grid current, primary side grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data using the Z-value normalization method, and finally extract the time domain features, which include the mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor, and signal energy of the window data.
[0202] The feature extraction module 33 is used to convert basic traffic, communication protocol, connection behavior, timing correlation information and load information into frequency domain signals using short-time Fourier transform, and finally extract frequency domain features. The frequency domain signal includes frequency components, spectrum and frequency distribution, and the frequency domain features include spectrum centroid, spectrum standard deviation, spectrum skewness and spectrum kurtosis.
[0203] The analysis and calculation module 34 is used to calculate the weights of each time-domain feature and each frequency-domain feature using the grey relational analysis method.
[0204] The modeling representation module 35, based on the weights of each time-domain feature and the weights of each frequency-domain feature, uses a structured state-space sequence model to model the time-domain features and a convolutional neural network to model the frequency-domain features, thereby obtaining abstract feature representations of the time-domain features and abstract feature representations of the frequency-domain features, respectively.
[0205] The weighted fusion module 36 is used to fuse the abstract feature representation of the time-domain features and the abstract feature representation of the frequency-domain features, and to weight the weights of each time-domain feature and frequency-domain feature through an attention mechanism to obtain the fused feature representation;
[0206] The intrusion identification module 37 is used to obtain a target intrusion detection model based on the fused feature representation, and to use the target intrusion detection model to analyze the time domain features and the frequency domain features to identify different types of intrusion attack events.
Claims
1. An Ethernet intrusion detection method, characterized in that, include: Physical domain data and information domain data are obtained from the train communication network. The physical domain data includes primary network current, primary network voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking level. The information domain data includes basic flow, communication protocol, connection behavior, timing correlation information and load information. The primary grid current, primary grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data are normalized using the Z-value standardization method, and finally the time domain features are extracted. The time domain features include the mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor, and signal energy of the window data. The basic traffic, communication protocol, connection behavior, timing correlation information and payload information in the information domain data are transformed into frequency domain signals using short-time Fourier transform. Finally, frequency domain features are extracted. The frequency domain signal includes frequency components, spectrum and frequency distribution. The frequency domain features include spectrum centroid, spectrum standard deviation, spectrum skewness and spectrum kurtosis. The weights of each time-domain feature and each frequency-domain feature are calculated using grey relational analysis. Based on the weights of each time-domain feature and each frequency-domain feature, a structured state-space sequence model is used to model the time-domain features, and a convolutional neural network is used to model the frequency-domain features, resulting in abstract feature representations of the time-domain features and frequency-domain features, respectively, including: Based on the weights of each time-domain feature, a structured state-space sequence model is used to model the time-domain features, thereby obtaining an abstract feature representation of the time-domain features; The formula for the abstract feature representation of time-domain features is as follows; in, Abstract feature representation of time-domain features This represents the output dimension of the structured state-space model. Represents the time-domain characteristic matrix. Represents a structured state-space sequence model. A set of weights representing temporal features; Based on the weights of each frequency domain feature, a convolutional neural network is used to model the frequency domain features to obtain an abstract feature representation of the frequency domain features; The formula for the abstract feature representation of frequency domain features is as follows; in, This represents the output dimension of the convolutional neural network model. An abstract feature representation of frequency domain features; CNN stands for Convolutional Neural Network. A set of weights representing frequency domain features; The abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features are fused, and the weights of each time-domain feature and frequency-domain feature are weighted through an attention mechanism to obtain the fused feature representation. Based on the fused feature representation, a target intrusion detection model is obtained, and the target intrusion detection model is used to analyze the time-domain features and the frequency-domain features to identify different types of intrusion attack events.
2. The Ethernet intrusion detection method as described in claim 1, characterized in that, The primary grid current, primary grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current, and traction braking level in the physical domain data are normalized using the Z-value standardization method, and finally the time-domain features are extracted, including: The Z-value normalization method is used to normalize the primary side grid current, primary side grid voltage, train speed, three-phase isolation transformer temperature, transformer primary current, transformer oil pump current and traction braking stage in the physical domain data, and the normalized result is obtained. Based on the normalization result, the time-domain features are extracted.
3. The Ethernet intrusion detection method as described in claim 1, characterized in that, The method employs short-time Fourier transform to convert the basic traffic, communication protocols, connection behavior, timing correlation information, and payload information in the information domain data into frequency domain signals, ultimately extracting frequency domain features, including: The basic traffic, communication protocol, connection behavior, timing correlation information and payload information in the information domain data are converted into the frequency domain signal using short-time Fourier transform. Frequency domain features are extracted based on the frequency domain signal.
4. The Ethernet intrusion detection method as described in claim 1, characterized in that, The calculation of the weights of each time-domain feature and each frequency-domain feature using grey relational analysis includes: The weights of each time-domain feature are calculated using grey relational analysis. The formula for calculating the weights of each time-domain feature using grey relational analysis is as follows: in, The weight set representing the temporal features, Indicates the first Weights of each time-domain feature, Indicates the first Each time-domain feature gray relational degree coefficient Indicates the first Each time-domain feature gray relational degree coefficient The number of time-domain features; The formula for calculating the gray relational coefficient of the time domain feature is as follows: in, These are the time-domain feature resolution coefficients. Indicates the first The absolute difference between each time-domain feature value and its reference data Indicates the minimum difference. Indicates the maximum difference; The weights of each frequency domain feature are calculated using grey relational analysis. The formula for calculating the weights of each frequency domain feature using grey relational analysis is as follows: in, The weight set represents the frequency domain features. Indicates the first Weights of each frequency domain feature Indicates the first Individual frequency domain feature gray correlation coefficient, Indicates the first Individual frequency domain feature gray correlation coefficient, The number of frequency domain features; The formula for calculating the gray relational coefficient of the frequency domain feature is as follows: in, These are the frequency domain characteristic resolution coefficients. Indicates the first The absolute difference between each frequency domain eigenvalue and its reference data Indicates the minimum difference. This indicates the maximum difference.
5. The Ethernet intrusion detection method as described in claim 4, characterized in that, The process of fusing the abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features, and weighting the weights of each time-domain feature and frequency-domain feature through an attention mechanism to obtain the fused feature representation, includes: The abstract feature representations of the time-domain features and the abstract feature representations of the frequency-domain features are fused to form a joint feature vector, wherein the formula for forming the joint feature vector is as follows: in, Represents the joint eigenvector; Based on the joint feature vector, the weights of each time-domain feature and frequency-domain feature are weighted using an attention mechanism to obtain the fused feature representation. The formula for obtaining the fused feature representation is as follows: in, This represents the fusion feature representation. α This represents a weight assigned to distinguish the proportion of features in the time domain from those in the frequency domain. This represents a non-linear activation function.
6. The Ethernet intrusion detection method as described in claim 1, characterized in that, The process involves obtaining a target intrusion detection model based on the fused feature representation, and then using this model to analyze the time-domain and frequency-domain features to identify different types of intrusion attack events, including: Based on the fused feature representation, the time-domain features and the frequency-domain features are input into the target intrusion detection model; The target intrusion detection model analyzes the time-domain and frequency-domain features to output the probability of various attacks occurring. Based on the probability of various attacks occurring, different types of intrusion attack events can be identified.
7. The Ethernet intrusion detection method as described in claim 6, characterized in that, After identifying different types of intrusion attack events based on the probability or confidence level of various attacks, the method further includes: outputting corresponding alarm information or response information, wherein the alarm information includes text, charts and real-time monitoring interface, and the response information includes triggering firewall rules, system log recording and graphical interface.
8. The Ethernet intrusion detection method as described in claim 1, characterized in that, The acquisition of the target intrusion detection model includes: The fused feature representation is input into the intrusion detection model, and the intrusion detection model is trained using a supervised learning method to obtain a preliminary intrusion detection model; The preliminary intrusion detection model is verified and optimized to obtain the target intrusion detection model.
9. A system for implementing the Ethernet intrusion detection method according to any one of claims 1-8, characterized in that, include: The data acquisition module (31) is used to acquire physical domain data and information domain data from the train communication network respectively. The physical domain data includes primary side network current, primary side network voltage, train speed, three-phase isolation transformer temperature, transformer primary side current, transformer oil pump current and traction braking level. The information domain data includes basic flow, communication protocol, connection behavior, timing association information and load information. The normalized data module (32) is used to normalize the primary side grid current, primary side grid voltage, train speed, three-phase isolation transformer temperature, transformer primary side current, transformer oil pump current and traction braking level in the physical domain data using the Z-value normalization method, and finally extract the time domain features, including the mean, standard deviation, maximum value, minimum value, skewness, kurtosis, waveform factor and signal energy of the window data; The feature extraction module (33) is used to convert basic traffic, communication protocol, connection behavior, timing correlation information and load information into frequency domain signals using short-time Fourier transform, and finally extract frequency domain features. The frequency domain signals include frequency components, spectrum and frequency distribution, and the frequency domain features include spectrum centroid, spectrum standard deviation, spectrum skewness and spectrum kurtosis. The analysis and calculation module (34) is used to calculate the weights of each time-domain feature and each frequency-domain feature using the grey relational analysis method; The modeling representation module (35) uses a structured state space sequence model to model the time-domain features based on the weights of each time-domain feature and the weights of each frequency-domain feature, and uses a convolutional neural network to model the frequency-domain features, thereby obtaining abstract feature representations of the time-domain features and abstract feature representations of the frequency-domain features respectively. The weighted fusion module (36) is used to fuse the abstract feature representation of the time domain feature and the abstract feature representation of the frequency domain feature, and to weight the weights of each time domain feature and frequency domain feature through an attention mechanism to obtain the fused feature representation; The intrusion identification module (37) is used to obtain a target intrusion detection model based on the fused feature representation, and to use the target intrusion detection model to analyze the time domain features and the frequency domain features to identify different types of intrusion attack events.
Citation Information
Patent Citations
Network intrusion detection method and system based on STBform model
CN117811850A
Seismic signal classification and identification method based on multi-feature fusion
CN119644425A