APT identification system based on conformal antenna array and multi-modal behavior fusion
The APT identification system, which integrates conformal antenna arrays and multimodal behavior, achieves deep fusion and collaborative analysis of radio frequency signals and network behavior characteristics. This solves the problem of insufficient cross-layer attack identification capabilities in existing technologies, enabling rapid and accurate threat identification and response, and improving the system's security and protection effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- LIANYUNGANG CHENGYI INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-01-23
- Publication Date
- 2026-04-21
AI Technical Summary
Existing APT identification technologies lack the ability to deeply integrate and collaboratively analyze radio frequency signal characteristics and network session behavior characteristics, resulting in limited ability to identify cross-layer attacks of advanced persistent threats and making it difficult to achieve rapid and accurate detection and response.
An APT identification system based on conformal antenna array and multimodal behavior fusion is adopted. The conformal antenna array captures radio frequency signals, and features are extracted by combining radio frequency sensing unit and network behavior sensing unit. The multimodal fusion decision engine is used to perform joint discrimination and source tracing of deep learning model, and a root of trust module is introduced to ensure data integrity. Finally, the response controller executes the response strategy.
It achieves high-accuracy identification of covert cross-layer attacks and rapid, precise dynamic closed-loop response, improving the security protection capabilities of communication systems and enhancing the security and reliability of the systems.
Smart Images

Figure CN121908273A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to an APT identification system based on conformal antenna array and multimodal behavior fusion. Background Technology
[0002] With the rapid development of wireless communication technology, wireless networks have permeated all aspects of social life, from personal communication to the Industrial Internet of Things and critical infrastructure. However, the openness of wireless communication channels also exposes them to increasingly severe security threats, especially Advanced Persistent Threat (APT) attacks. APT attacks are usually launched by well-organized and well-resourced attackers, and are highly covert, persistent, and targeted, posing a huge threat to national security, corporate secrets, and personal privacy.
[0003] To circumvent traditional security detection mechanisms, APT attacks often employ complex, covert communication channels spanning the physical and network layers to steal data or control commands. For example, at the physical layer, attackers may use low-power, wide-spectrum signals to communicate, drowning out the signal energy in background noise, making it difficult to detect using traditional spectrum monitoring methods. At the network layer, attackers may conceal data transmission by disguising malicious data as normal traffic, exploiting redundant parts of protocol fields, or manipulating timing.
[0004] Currently, existing protection methods mostly rely on network-side traffic analysis or host-side detection, lacking real-time signal perception and protection capabilities that are deeply integrated with the radio frequency / antenna layer. While conformal antenna technology can achieve low-visibility antenna layouts that fit the platform, there is still no mature integrated hardware and software solution in terms of security perception that can integrate "radio frequency anomalies (physical layer)" and "network behavior (protocol layer)" in real time, thereby improving the identification rate of covert channels, bypass communication, physical layer interference, and APT penetration, and supporting active protection.
[0005] In summary, existing APT identification technologies lack an effective mechanism for deep integration and collaborative analysis of the characteristics of radio frequency signals and the behavioral characteristics of network sessions. This results in limited ability to identify highly covert cross-layer attack methods and makes it difficult to form a fast, accurate, and collaborative detection and response mechanism. Summary of the Invention
[0006] To address the problems existing in the background technology, this invention proposes an APT identification system based on conformal antenna array and multimodal behavior fusion. This system solves the problems of the separation between physical layer signal perception and network layer behavior analysis, the limited ability to identify cross-layer covert attack methods, and the lack of coordination in response mechanisms in existing APT identification technologies. It achieves deep fusion and collaborative analysis of radio frequency physical layer signal characteristics and network layer behavior characteristics, enabling rapid and accurate identification and dynamic closed-loop response to advanced persistent threats, thereby improving the overall security protection capability of the communication system.
[0007] To achieve the above objectives, the present invention adopts the following technical solution: An APT identification system based on conformal antenna array and multimodal behavior fusion includes: A conformal antenna array, mounted on the surface of the target device, is used for the acquisition and active modulation of radio frequency signals; The radio frequency sensing unit is connected to the conformal antenna array and collects and extracts physical layer signal features from the radio frequency signals; The network behavior perception unit collects network traffic data and extracts network layer behavioral features. The multimodal fusion decision engine is connected to the radio frequency sensing unit and the network behavior sensing unit respectively. It receives physical layer signal features and network layer behavior features, performs joint discrimination and source tracing through a multi-task deep learning model, and generates threat identification results. The root of trust module is used to ensure the integrity of the data acquisition and decision-making links of the radio frequency sensing unit, the network behavior sensing unit, and the multimodal fusion decision engine. The response controller is connected to the multimodal fusion decision engine and the conformal antenna array, and executes corresponding response strategies based on the threat identification results to ensure communication security.
[0008] Specifically, the conformal antenna array includes several antenna elements configured in an array form, which are attached to the surface of the target device. The conformal antenna array integrates a controllable phase shifter, a variable impedance unit, a multi-channel low-noise amplifier, and a high-speed analog-to-digital converter.
[0009] The controllable phase shifter adjusts the phase of the received signal of each antenna element to dynamically shape the direction of the main beam of the antenna array, thereby enhancing the ability to receive signals in a specific direction or avoiding known interference sources. The variable impedance unit is a PIN diode or an RF MEMS device. By changing the impedance characteristics of the antenna unit to adjust its resonant frequency, a high impedance notch filter is formed at a specific narrowband frequency, thereby achieving selective suppression of hostile signals within the target frequency band. The multi-channel low-noise amplifier is connected to the signal output terminal of the conformal antenna array and is used to amplify the weak radio frequency signals captured by the conformal antenna array. The high-speed analog-to-digital converter is located near the conformal antenna array and has a sampling rate of ≥100MS / s. It is used to convert the amplified analog radio frequency signal into a digital signal and transmit the digital signal to the radio frequency sensing unit.
[0010] Specifically, the radio frequency sensing unit includes: (1) The signal preprocessing subunit receives the digital radio frequency signal output by the conformal antenna array and executes the following sequentially: S1. Perform a 5-level multi-scale decomposition of the signal using the db4 wavelet basis function to obtain approximate coefficients. and detail coefficient Soft thresholding is used for high-frequency detail coefficients. ,in The standard deviation of noise. Given the signal length, the formula for reconstructing the denoised signal is: ; in This is the inverse wavelet transform. The approximation coefficients are for 5 levels. The detail coefficients after thresholding; S2. The denoised signal is processed by short-time Fourier transform. Time-frequency analysis was performed to calculate the time-frequency matrix. ,in For the number of time frames, The number of frequency points; the calculation formula is: ; (2) Physical layer feature extraction subunit, which extracts physical layer signal features based on the preprocessed signal, specifically including: a. Cyclic Spectrum Characteristics: Calculating the cyclic spectrum to assess the cyclic stationary characteristics of covert communication. : ; Among them, the cycle frequency Extracting the peak positions and amplitudes of the cyclic spectrum to construct a feature vector. ,in The number of effective cycle frequency points; b. Cross-correlation RF fingerprint: Calculates the cross-correlation coefficient between the signal and several known device RF templates in the template library. : ; in For device radio frequency templates, , The mean, , The standard deviation is used; the resulting set of cross-correlation coefficients are used as fingerprint features to form a fingerprint feature vector. ,in Number of templates; c. Sparse representation coefficients: based on a pre-defined overcomplete dictionary. The sparse coefficient eigenvector is solved by minimizing the L1 norm. : ; in, To reconstruct the error threshold; d. Transient features: Extracting wavelet detail coefficients The peak amplitude and time position constitute the transient feature vector. ,in This represents the number of transient peak values.
[0011] Specifically, the network behavior sensing unit includes: (1) Traffic collection subunit, which collects network traffic metadata based on NetFlow v9 or IPFIX RFC7011 protocol. The collected fields include: source IP address, destination IP address, source port, destination port, transport layer protocol, session start timestamp, session end timestamp, data packet timestamp, total number of bytes, and total number of packets. (2) Network layer feature extraction subunit: Extracts network layer behavioral features based on the collected traffic data, specifically including: a. Session duration characteristics: Calculating session duration ,in The timestamp for the start of the session. Set the session end timestamp; set the duration threshold as follows: ,when The time markers are used to construct a session duration feature vector. , where 0 represents a normal session and 1 represents a long session; b. Packet interval distribution characteristics: the interval time of data packets within a session. Statistics were compiled, among which Given the timestamp of the i-th data packet, calculate the mean, variance, and skewness of the packet interval within the session to form a feature vector. ; c. Port / Protocol Statistics: Statistics on port usage frequency within a preset time window. ,in This represents the number of times port p appears. The total number of ports is defined; abnormal ports are marked, including non-IANA standard ports and unauthorized service ports, and a feature vector of abnormal ports is generated. , where M is the number of ports being monitored; Statistical Protocol Distribution Characteristics The element represents the proportion of traffic accounted for by each protocol; d. Host lateral path graph characteristics: Constructing the host communication graph , where nodes Indicates the host IP or device ID, side Indicates host and Communication relationships between them, edge weights , for and Number of bytes communicated between them Total number of bytes; generate adjacency matrix ,like If it exists, then ,otherwise .
[0012] Specifically, the multimodal fusion decision engine includes: (1) Feature preprocessing module, receives physical layer features and network layer features, and performs the following operations: S1, Circulation Spectrum Features Cross-correlation radio frequency fingerprint features Sparse representation coefficient characteristics Transient characteristics Concatenate them into a three-dimensional tensor according to a fixed time window. ,in The number of time windows. =4 represents the number of physical layer feature types. It is a single feature dimension; S2. Session duration characteristics of each host or device Packet interval distribution characteristics Abnormal port characteristics The number of abnormal ports and port usage frequency are statistically analyzed. Maximum value, protocol distribution characteristics Concatenate into a node attribute vector of host or device i , Construct a node feature matrix using the feature dimension. , Number of hosts or devices; S3. Using linear interpolation, the physical layer temporal tensor... Forced matching with the timestamps of network layer features to ensure that at the same time t... and For the same communication scenario, the alignment formula is: ; in The sampling time of adjacent physical layers; (2) The cross-modal fusion module adopts a dual-branch neural network architecture to process the physical layer temporal features and the network layer graph structure features respectively. For the physical layer branch, a Transformer encoder is used to process the temporal tensor. Output physical layer global features For network layer branches, a graph attention network (GAT) is used to process the graph structure. The process transforms host relationships and host attributes into global semantic vectors to capture lateral dependencies between hosts. The computation process includes: a. Regarding the first Layer node features Perform a linear transformation. Initially The row vectors are used to obtain the high-dimensional embedding: ; in This is the layer weight matrix; b. Calculate the first Attention weights of node j to node i : ; ; in For attention coefficient vectors, This represents the concatenation of features from nodes i and j. Let be the set of neighboring nodes of node i. For activation functions; c. Aggregate neighbor features: ; in, It is the ReLU activation function; d. After three layers of GAT, the global features of the network layer are obtained by averaging the embeddings of all nodes through MeanPooling. : ; Finally, global features from the physical and network layers are fused through an attention fusion layer, and the weights of the physical and network layer features are learned using a multilayer perceptron (MLP). Its satisfaction : ; Output fusion features : ; (3) Multi-task decision-making module, based on feature fusion Using this as input, perform three tasks: APT classification, attack type identification, and attack attribution. a. APT classification task: Output threat probability through a fully connected layer. The loss function is: ; in For batch size, The sample labels are 0 for normal communication and 1 for APT attacks. For the model to the first The predicted probability of each sample; b. Attack type identification task: Output the probability distribution of attack types through fully connected layers and Softmax layers. The loss function is: ; in Number of attack types For the first The sample belongs to the first The true label of the class, For the model to predict the first The sample belongs to the first The probability of a class; c. Attack attribution task: Calculate the attack source confidence based on the node embeddings obtained from the network layer GAT. ,in Embedded for the current host's node. Pre-trained attack source embedding; subsequently, through adjacency matrix The specific steps for generating an attack path are as follows: c1. Filter candidate attack sources, selecting the top three hosts with the highest attack source confidence as candidates for the path starting point; c2. From the adjacency matrix... Extract non-zero edges and retain edge weights. c3. Starting from the candidate attack source and ending at the target host, select the host with the largest edge weight among the current host's neighbors as the next hop each time; c4. Verify and check if each host on the path has abnormal characteristics; c5. If the verification passes, output the path; otherwise, change the candidate attack source and repeat steps c3 and c4 until a reasonable path is found. The final total loss function is ,in The mean squared error loss of the tracing path; (4) Result output module: Based on the multi-task decision results, generate executable output and calculate threat score. Mapped to Threat Score: S ; in For the Sigmoid function, As the scoring weight, This is a bias term.
[0013] Specifically, the root trust module is a hardware-level trusted execution environment (TEE) or a trusted platform module conforming to the TPM2.0 standard. It establishes a dedicated communication link with the radio frequency sensing unit, network behavior sensing unit, multimodal fusion decision engine, and response controller via a hardware encrypted bus. The interaction logic includes: a. When the radio frequency sensing unit and the network behavior sensing unit are powered on, they automatically send the SHA-256 hash value of their own firmware to the root of trust module. The root of trust module calls the pre-embedded device manufacturer's public key to verify the digital signature corresponding to the firmware hash value. If the verification is successful, it sends an allow operation command to the corresponding sensing unit and the sensing unit starts the feature acquisition process. If the verification fails, it triggers a hardware reset of the sensing unit and writes the alarm to the audit log of the root of trust. b. After the radio frequency sensing unit extracts physical layer signal features and the network behavior sensing unit extracts network layer behavior features, the following process is executed before transmitting the data to the multimodal fusion decision engine: The sensing unit calculates the SHA-256 hash value of the feature data and sends the hash value to the root trust module. The root trust module uses its own unique private key to digitally sign the hash value. Then, the sensing unit transmits the original feature data and the root trust signature together to the multimodal fusion decision engine through the encryption bus. After receiving the data, the multimodal fusion decision engine calls the public key of the root trust module to verify the signature. If the verification is successful, the feature data is processed; if the verification fails, the data is discarded and an alarm is triggered. c. The model loading and decision output of the multimodal fusion decision engine are verified by the root of trust module: When the multimodal fusion decision engine is started by loading the model, the deep learning model file and the SHA-256 hash value of the decision policy are sent to the root of trust module. The root of trust module verifies the digital signature of the model / policy. If the signature verification is successful, loading and running are allowed. After generating the threat identification result, the SHA-256 hash value of the result is calculated and sent to the root of trust module for signing. The signed decision result is sent to the response controller. If the response controller verifies the signature, the response policy is executed.
[0014] Specifically, the response strategy executed by the response controller includes: a. Threat Score At the same time, control commands are sent to the conformal antenna array to adjust the controllable phase shifter and variable impedance unit, suppressing the attack source radio frequency signal through beamforming or blocking specific hostile frequency bands through band notch; blocking policies are issued to the gateway, cutting off the attack's lateral propagation path based on the attack source IP's ACL rules and port isolation commands. b. Threat Score When the link migration is triggered, the conformal antenna array is switched to the backup communication frequency band, and the service traffic is guided to switch to the redundant link. Attack-related radio frequency snapshots are obtained through the high-speed analog-to-digital converter of the conformal antenna array, and network packets of the attack link are collected through the network behavior awareness unit, encrypted and uploaded to the trust root module for storage. c. Threat Score When an alarm log is generated, it is synchronized to the audit log of the root trust module and a warning notification is pushed to the system administrator.
[0015] In summary, the beneficial technical effects of the present invention are as follows: 1. Improved accuracy in identifying covert and cross-layer attacks: This invention constructs a complete profile of the communication scenario by deeply integrating and collaboratively analyzing the signal characteristics of the radio frequency physical layer and the communication behavior characteristics of the network layer. The multimodal analysis mechanism can effectively identify covert communication channels and APT attack patterns that are difficult to detect in a single dimension. For example, it can associate weak abnormal radio frequency signals with abnormal host communication behavior within the network, thereby significantly improving the accuracy of identification.
[0016] 2. Achieves rapid and accurate dynamic closed-loop response: This invention can not only identify threats, but also execute graded, cross-level collaborative defense strategies based on quantified threat scores. The system can automatically complete closed-loop control from perception and decision-making to response. At the physical layer, it achieves directional suppression of attack signals by adjusting the conformal antenna array, and at the network layer, it blocks or isolates the attack source IP, achieving rapid and accurate handling of threats and greatly improving the system's protection timeliness and initiative.
[0017] 3. Enhanced system security and trustworthiness: By introducing a hardware root of trust module, this invention ensures the integrity of data and operations throughout the entire chain from feature acquisition and model loading to decision execution. This hardware-level security mechanism can effectively prevent the system itself from being maliciously tampered with or deceived, ensuring the reliability of threat identification results and the effective execution of response strategies, which is crucial for defending against high-level APT attacks. Attached Figure Description
[0018] Figure 1 This is a system overview diagram of the present invention. Detailed Implementation
[0019] To make the technical means, creative features, objectives and effects of this invention clearer and easier to understand, the invention will be further described below in conjunction with the accompanying drawings and specific embodiments.
[0020] Example like Figure 1As shown, the present invention provides an APT identification system based on conformal antenna array and multimodal behavior fusion, including a conformal antenna array, a radio frequency sensing unit, a network behavior sensing unit, a multimodal fusion decision engine, a root of trust module, and a response controller.
[0021] The conformal antenna array includes several antenna elements configured as an array, which are attached to the surface of the target device. The conformal antenna array integrates a controllable phase shifter, a variable impedance unit, a multi-channel low-noise amplifier, and a high-speed analog-to-digital converter.
[0022] A controllable phase shifter dynamically shapes the direction of the main beam of the antenna array by adjusting the phase of the received signal of each antenna element, thereby enhancing the ability to receive signals in a specific direction or avoiding known interference sources. The variable impedance unit is a PIN diode or an RF MEMS device. By changing the impedance characteristics of the antenna unit, its resonant frequency can be adjusted, forming a high-impedance notch filter at a specific narrowband frequency, thereby achieving selective suppression of hostile signals within the target frequency band. A multi-channel low-noise amplifier is connected to the signal output of a conformal antenna array to amplify the weak radio frequency signals captured by the conformal antenna array. A high-speed analog-to-digital converter is located near the conformal antenna array with a sampling rate of ≥100MS / s. It is used to convert the amplified analog radio frequency signal into a digital signal and transmit the digital signal to the radio frequency sensing unit.
[0023] The radio frequency sensing unit is connected to the conformal antenna array to acquire and extract physical layer signal features from the radio frequency signals, specifically including: (1) The signal preprocessing subunit receives the digital radio frequency signal output from the conformal antenna array and executes the following sequentially: S1. Perform a 5-level multi-scale decomposition of the signal using the db4 wavelet basis function to obtain approximate coefficients. and detail coefficient Soft thresholding is used for high-frequency detail coefficients. ,in The standard deviation of noise. Given the signal length, the formula for reconstructing the denoised signal is: ; in This is the inverse wavelet transform. The approximation coefficients are for 5 levels. The detail coefficients after thresholding; S2. The denoised signal is processed by short-time Fourier transform. Time-frequency analysis was performed to calculate the time-frequency matrix. ,in For the number of time frames, The number of frequency points; the calculation formula is: ; (2) Physical layer feature extraction subunit, which extracts physical layer signal features based on the preprocessed signal, specifically including: a. Cyclic Spectrum Characteristics: Calculating the cyclic spectrum to assess the cyclic stationary characteristics of covert communication. : ; Among them, the cycle frequency Extracting the peak positions and amplitudes of the cyclic spectrum to construct a feature vector. ,in The number of effective cycle frequency points; b. Cross-correlation RF fingerprint: Calculates the cross-correlation coefficient between the signal and several known device RF templates in the template library. : ; in For device radio frequency templates, , The mean, , The standard deviation is used; the resulting set of cross-correlation coefficients are used as fingerprint features to form a fingerprint feature vector. ,in Number of templates; c. Sparse representation coefficients: based on a pre-defined overcomplete dictionary. The sparse coefficient eigenvector is solved by minimizing the L1 norm. : ; in, To reconstruct the error threshold; d. Transient features: Extracting wavelet detail coefficients The peak amplitude and time position constitute the transient feature vector. ,in This represents the number of transient peak values.
[0024] The network behavior awareness unit collects network traffic data and extracts network layer behavioral features, specifically including: (1) Traffic collection subunit, which collects network traffic metadata based on NetFlow v9 or IPFIX RFC7011 protocol. The collected fields include: source IP address, destination IP address, source port, destination port, transport layer protocol, session start timestamp, session end timestamp, data packet timestamp, total number of bytes, and total number of packets. (2) Network layer feature extraction subunit: Extracts network layer behavioral features based on the collected traffic data, specifically including: a. Session duration characteristics: Calculating session duration ,in The timestamp for the start of the session. Set the session end timestamp; set the duration threshold as follows: ,when The time markers are used to construct a session duration feature vector. , where 0 represents a normal session and 1 represents a long session; b. Packet interval distribution characteristics: the interval time of data packets within a session. Statistics were compiled, among which Given the timestamp of the i-th data packet, calculate the mean, variance, and skewness of the packet interval within the session to form a feature vector. ; c. Port / Protocol Statistics: Statistics on port usage frequency within a preset time window. ,in This represents the number of times port p appears. The total number of ports is defined; abnormal ports are marked, including non-IANA standard ports and unauthorized service ports, and a feature vector of abnormal ports is generated. , where M is the number of ports being monitored; Statistical Protocol Distribution Characteristics The element represents the proportion of traffic accounted for by each protocol; d. Host lateral path graph characteristics: Constructing the host communication graph , where nodes Indicates the host IP or device ID, side Indicates host and Communication relationships between them, edge weights , for and Number of bytes communicated between them Total number of bytes; generate adjacency matrix ,like If it exists, then ,otherwise .
[0025] The multimodal fusion decision engine is connected to the radio frequency sensing unit and the network behavior sensing unit, respectively, to receive physical layer signal features and network layer behavior features. It then uses a multi-task deep learning model for joint discrimination and source tracing to generate threat identification results, specifically including: (1) Feature preprocessing module, receives physical layer features and network layer features, and performs the following operations: S1, Circulation Spectrum Features Cross-correlation radio frequency fingerprint features Sparse representation coefficient characteristics Transient characteristics Concatenate them into a three-dimensional tensor according to a fixed time window. ,in The number of time windows. =4 represents the number of physical layer feature types. It is a single feature dimension; S2. Session duration characteristics of each host or device Packet interval distribution characteristics Abnormal port characteristics The number of abnormal ports and port usage frequency are statistically analyzed. Maximum value, protocol distribution characteristics Concatenate into a node attribute vector of host or device i , Construct a node feature matrix using the feature dimension. , Number of hosts or devices; S3. Using linear interpolation, the physical layer temporal tensor... Forced matching with the timestamps of network layer features to ensure that at the same time t... and For the same communication scenario, the alignment formula is: ; in The sampling time of adjacent physical layers; (2) The cross-modal fusion module adopts a dual-branch neural network architecture to process the physical layer temporal features and the network layer graph structure features respectively. For the physical layer branch, a Transformer encoder is used to process the temporal tensor. Output physical layer global features For network layer branches, a graph attention network (GAT) is used to process the graph structure. The process transforms host relationships and host attributes into global semantic vectors to capture lateral dependencies between hosts. The computation process includes: a. Regarding the first Layer node features Perform a linear transformation. Initially The row vectors are used to obtain the high-dimensional embedding: ; in This is the layer weight matrix; b. Calculate the first Attention weights of node j to node i : ; ; in For attention coefficient vectors, This represents the concatenation of features from nodes i and j. Let be the set of neighboring nodes of node i. For activation functions; c. Aggregate neighbor features: ; in, It is the ReLU activation function; d. After three layers of GAT, the global features of the network layer are obtained by averaging the embeddings of all nodes through MeanPooling. : ; Finally, global features from the physical and network layers are fused through an attention fusion layer, and the weights of the physical and network layer features are learned using a multilayer perceptron (MLP). Its satisfaction : ; Output fusion features : ; (3) Multi-task decision-making module, based on feature fusion Using this as input, perform three tasks: APT classification, attack type identification, and attack attribution. a. APT classification task: Output threat probability through a fully connected layer. The loss function is: ; in For batch size, The sample labels are 0 for normal communication and 1 for APT attacks. For the model to the first The predicted probability of each sample; b. Attack type identification task: Output the probability distribution of attack types through fully connected layers and Softmax layers. The loss function is: ; in Number of attack types For the first The sample belongs to the first The true label of the class, For the model to predict the first The sample belongs to the first The probability of a class; c. Attack attribution task: Calculate the attack source confidence based on the node embeddings obtained from the network layer GAT. ,in Embedded for the current host's node. Pre-trained attack source embedding; subsequently, through adjacency matrix The specific steps for generating an attack path are as follows: c1. Filter candidate attack sources, selecting the top three hosts with the highest attack source confidence as candidates for the path starting point; c2. From the adjacency matrix... Extract non-zero edges and retain edge weights. c3. Starting from the candidate attack source and ending at the target host, select the host with the largest edge weight among the current host's neighbors as the next hop each time; c4. Verify and check if each host on the path has abnormal characteristics; c5. If the verification passes, output the path; otherwise, change the candidate attack source and repeat steps c3 and c4 until a reasonable path is found. The final total loss function is ,in The mean squared error loss of the tracing path; (4) Result output module: Based on the multi-task decision results, generate executable output and calculate threat score. Mapped to Threat Score: S ; in For the Sigmoid function, As the scoring weight, This is a bias term.
[0026] The root trust module ensures the integrity of the data acquisition and decision-making links of the RF sensing unit, network behavior sensing unit, and multimodal fusion decision engine. Specifically, the root trust module is a hardware-level trusted execution environment (TEE) or a trusted platform module conforming to the TPM2.0 standard. It establishes a dedicated communication link with the RF sensing unit, network behavior sensing unit, multimodal fusion decision engine, and response controller through a hardware encrypted bus. The interaction logic includes: a. When the radio frequency sensing unit and the network behavior sensing unit are powered on, they automatically send the SHA-256 hash value of their own firmware to the root of trust module. The root of trust module calls the pre-embedded public key of the device manufacturer to verify the digital signature corresponding to the firmware hash value. If the verification is successful, it sends an instruction to allow operation to the corresponding sensing unit, and the sensing unit starts the feature acquisition process. If the verification fails, it triggers the hardware reset of the sensing unit and writes the alarm to the audit log of the root of trust. b. After the radio frequency sensing unit extracts physical layer signal features and the network behavior sensing unit extracts network layer behavior features, the following process is executed before transmitting the data to the multimodal fusion decision engine: The sensing unit calculates the SHA-256 hash value of the feature data and sends the hash value to the root trust module. The root trust module uses its own unique private key to digitally sign the hash value. Then, the sensing unit transmits the original feature data and the root trust signature together to the multimodal fusion decision engine through the encryption bus. After receiving the data, the multimodal fusion decision engine calls the public key of the root trust module to verify the signature. If the verification is successful, the feature data is processed; if the verification fails, the data is discarded and an alarm is triggered. c. The model loading and decision output of the multimodal fusion decision engine are verified by the root of trust module: When the multimodal fusion decision engine is started by loading the model, the deep learning model file and the SHA-256 hash value of the decision policy are sent to the root of trust module. The root of trust module verifies the digital signature of the model / policy. If the signature verification is successful, loading and running are allowed. After generating the threat identification result, the SHA-256 hash value of the result is calculated and sent to the root of trust module for signing. The signed decision result is sent to the response controller. If the response controller verifies the signature, the response policy is executed.
[0027] The response controller connects to the multimodal fusion decision engine and the conformal antenna array. Based on the threat identification results, it executes corresponding response strategies to ensure communication security. The response strategies include: a. Threat Score At the same time, control commands are sent to the conformal antenna array to adjust the controllable phase shifter and variable impedance unit, suppressing the attack source radio frequency signal through beamforming or blocking specific hostile frequency bands through band notch; blocking policies are issued to the gateway, cutting off the attack's lateral propagation path based on the attack source IP's ACL rules and port isolation commands. b. Threat Score When the link migration is triggered, the conformal antenna array is switched to the backup communication frequency band, and the service traffic is guided to switch to the redundant link. Attack-related radio frequency snapshots are obtained through the high-speed analog-to-digital converter of the conformal antenna array, and network packets of the attack link are collected through the network behavior awareness unit, encrypted and uploaded to the trust root module for storage. c. Threat Score When an alarm log is generated, it is synchronized to the audit log of the root trust module and a warning notification is pushed to the system administrator.
[0028] Therefore, this invention provides an APT identification system based on conformal antenna array and multimodal behavior fusion. By deeply fusing physical layer radio frequency features and network layer behavioral features, adopting a parallel processing architecture of Transformer and Graph Attention Network (GAT), introducing a hardware root of trust to ensure end-to-end integrity, and finally executing a cross-layer closed-loop response based on threat scores, this system achieves an integrated security protection closed loop of "cross-layer perception - multimodal fusion decision-making - collaborative response - end-to-end trustworthiness". This solves the pain points of traditional protection technologies, such as the disconnect between physical layer perception and network layer analysis, insufficient ability to identify covert cross-layer attacks, and a single response mechanism. It improves the accuracy of APT attack identification, the effectiveness of threat handling, and the security of the system itself, providing an efficient and reliable solution for ensuring the security of critical wireless communication infrastructure.
[0029] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. An APT identification system based on conformal antenna array and multimodal behavior fusion, characterized in that, include: A conformal antenna array, mounted on the surface of the target device, is used for the acquisition and active modulation of radio frequency signals; The radio frequency sensing unit is connected to the conformal antenna array and collects and extracts physical layer signal features from the radio frequency signals; The network behavior perception unit collects network traffic data and extracts network layer behavioral features. The multimodal fusion decision engine is connected to the radio frequency sensing unit and the network behavior sensing unit respectively. It receives physical layer signal features and network layer behavior features, performs joint discrimination and source tracing through a multi-task deep learning model, and generates threat identification results. The root of trust module is used to ensure the integrity of the data acquisition and decision-making links of the radio frequency sensing unit, network behavior sensing unit, and multimodal fusion decision engine. The response controller is connected to the multimodal fusion decision engine and the conformal antenna array, and executes corresponding response strategies based on the threat identification results to ensure communication security.
2. The APT identification system based on conformal antenna array and multimodal behavior fusion according to claim 1, characterized in that: The conformal antenna array includes several antenna elements configured in an array form, which are attached to the surface of the target device. The conformal antenna array integrates a controllable phase shifter, a variable impedance unit, a multi-channel low-noise amplifier, and a high-speed analog-to-digital converter.
3. The APT identification system based on conformal antenna array and multimodal behavior fusion according to claim 2, characterized in that, The radio frequency sensing unit specifically includes: (1) The signal preprocessing subunit receives the digital radio frequency signal output by the conformal antenna array and executes the following sequentially: S1. Perform a 5-level multi-scale decomposition of the signal using the db4 wavelet basis function to obtain approximate coefficients. and detail coefficient Soft thresholding is used for high-frequency detail coefficients. ,in The standard deviation of noise. Given the signal length, the formula for reconstructing the denoised signal is: ; in This is the inverse wavelet transform. The approximation coefficients are for 5 levels. These are the detail coefficients after thresholding. S2. The denoised signal is processed by short-time Fourier transform. Time-frequency analysis was performed to calculate the time-frequency matrix. ,in For the number of time frames, This represents the number of frequency points. (2) Physical layer feature extraction subunit, which extracts physical layer signal features based on the preprocessed signal, specifically including: a. Cyclic Spectrum Characteristics: Calculating the cyclic spectrum to assess the cyclic stationary characteristics of covert communication. : ; Among them, the cycle frequency Extracting the peak positions and amplitudes of the cyclic spectrum to construct a feature vector. ,in The number of effective cycle frequency points; b. Cross-correlation RF fingerprint: Calculates the cross-correlation coefficient between the signal and several known device RF templates in the template library. : ; in For device radio frequency templates, , The mean, , The standard deviation is used; the resulting set of cross-correlation coefficients are used as fingerprint features to form a fingerprint feature vector. ,in Number of templates; c. Sparse representation coefficients: based on a pre-defined overcomplete dictionary. The sparse coefficient eigenvector is solved by minimizing the L1 norm. : ; in, To reconstruct the error threshold; d. Transient features: Extracting wavelet detail coefficients The peak amplitude and time position constitute the transient feature vector. ,in This represents the number of transient peak values.
4. The APT identification system based on conformal antenna array and multimodal behavior fusion according to claim 3, characterized in that, The network behavior sensing unit includes: (1) Traffic collection subunit, which collects network traffic metadata based on NetFlow v9 or IPFIX RFC7011 protocol. The collected fields include: source IP address, destination IP address, source port, destination port, transport layer protocol, session start timestamp, session end timestamp, data packet timestamp, total number of bytes, and total number of packets. (2) Network layer feature extraction subunit: Extracts network layer behavioral features based on the collected traffic data, specifically including: a. Session duration characteristics: Calculating session duration ,in The timestamp for the start of the session. Set the session end timestamp; set the duration threshold as follows: ,when The time markers are used to construct a session duration feature vector. , where 0 represents a normal session and 1 represents a long session; b. Packet interval distribution characteristics: the interval time of data packets within a session. Statistics were compiled, among which Given the timestamp of the i-th data packet, calculate the mean, variance, and skewness of the packet interval within the session to form a feature vector. ; c. Port / Protocol Statistics: Statistics on port usage frequency within a preset time window. ,in This represents the number of times port p appears. The total number of ports is defined; abnormal ports are marked, including non-IANA standard ports and unauthorized service ports, and a feature vector of abnormal ports is generated. , where M is the number of ports being monitored; Statistical Protocol Distribution Characteristics The element represents the proportion of traffic accounted for by each protocol; d. Host lateral path graph characteristics: Constructing the host communication graph , where nodes Indicates the host IP or device ID, side Indicates host and Communication relationships between them, edge weights , for and Number of bytes communicated between them Total number of bytes; generate adjacency matrix ,like If it exists, then ,otherwise .
5. The APT identification system based on conformal antenna array and multimodal behavior fusion according to claim 4, characterized in that, The multimodal fusion decision engine includes: (1) Feature preprocessing module, receives physical layer features and network layer features, and performs the following operations: S1, Circulation Spectrum Features Cross-correlation radio frequency fingerprint features Sparse representation coefficient characteristics Transient characteristics Concatenate them into a three-dimensional tensor according to a fixed time window. ,in The number of time windows. =4 represents the number of physical layer feature types. It is a single feature dimension; S2. Session duration characteristics of each host or device Packet interval distribution characteristics Abnormal port characteristics The number of abnormal ports and port usage frequency are statistically analyzed. Maximum value, protocol distribution characteristics Concatenate into a node attribute vector of host or device i , Construct a node feature matrix using the feature dimension. , Number of hosts or devices; S3. Using linear interpolation, the physical layer temporal tensor... Forced matching with the timestamps of network layer features to ensure that at the same time t... and For the same communication scenario, the alignment formula is: ; in The sampling time of adjacent physical layers; (2) The cross-modal fusion module adopts a dual-branch neural network architecture to process the physical layer temporal features and the network layer graph structure features respectively. For the physical layer branch, a Transformer encoder is used to process the temporal tensor. Output physical layer global features For network layer branches, a graph attention network (GAT) is used to process the graph structure. The process transforms host relationships and host attributes into global semantic vectors to capture lateral dependencies between hosts. The computation process includes: a. Regarding the first Layer node features Perform a linear transformation. Initially The row vectors are used to obtain the high-dimensional embedding: ; in This is the layer weight matrix; b. Calculate the first Attention weights of node j to node i : ; ; in This is the attention coefficient vector. This represents the concatenation of features from nodes i and j. Let be the set of neighboring nodes of node i. For activation functions; c. Aggregate neighbor features: ; in, It is the ReLU activation function; d. After three layers of GAT, the global features of the network layer are obtained by averaging the embeddings of all nodes through MeanPooling. : ; Finally, global features from the physical and network layers are fused through an attention fusion layer, and the weights of the physical and network layer features are learned using a multilayer perceptron (MLP). Its satisfaction : ; Output fusion features : ; (3) Multi-task decision-making module, based on feature fusion As input, perform three tasks: APT classification, attack type identification, and attack attribution. a. APT classification task: Output threat probability through a fully connected layer. The loss function is: ; in For batch size, The sample labels are 0 for normal communication and 1 for APT attacks. For the model to the first The predicted probability of each sample; b. Attack type identification task: Output the probability distribution of attack types through fully connected layers and Softmax layers. The loss function is: ; in Number of attack types For the first The sample belongs to the first The true label of the class, For the model to predict the first The sample belongs to the first The probability of a class; c. Attack attribution task: Calculate the attack source confidence based on the node embeddings obtained from the network layer GAT. ,in Embedded for the current host's node. Pre-trained attack source embedding; subsequently, through adjacency matrix The specific steps for generating an attack path are as follows: c1. Filter candidate attack sources, selecting the top three hosts with the highest attack source confidence as candidates for the path starting point; c2. From the adjacency matrix... Extract non-zero edges and retain edge weights. c3. Starting from the candidate attack source and ending at the target host, select the host with the largest edge weight among the current host's neighbors as the next hop each time; c4. Verify and check if each host on the path has abnormal characteristics; c5. If the verification passes, output the path; otherwise, change the candidate attack source and repeat steps c3 and c4 until a reasonable path is found. The final total loss function is ,in The mean squared error loss of the tracing path; (4) Result output module: Based on the multi-task decision results, generate executable output and calculate threat score. Mapped to Threat Score: S ; in For the Sigmoid function, As the scoring weight, This is a bias term.
6. The APT identification system based on conformal antenna array and multimodal behavior fusion according to claim 5, characterized in that: The root of trust module is a hardware-level trusted execution environment (TEE) or a trusted platform module conforming to the TPM2.0 standard. It establishes a dedicated communication link with the radio frequency sensing unit, network behavior sensing unit, multimodal fusion decision engine, and response controller via a hardware encrypted bus. The interaction logic includes: a. When the radio frequency sensing unit and the network behavior sensing unit are powered on, they automatically send the SHA-256 hash value of their own firmware to the root of trust module. The root of trust module calls the pre-embedded device manufacturer's public key to verify the digital signature corresponding to the firmware hash value. If the verification is successful, it sends an allow operation command to the corresponding sensing unit and the sensing unit starts the feature acquisition process. If the verification fails, it triggers a hardware reset of the sensing unit and writes the alarm to the audit log of the root of trust. b. After the radio frequency sensing unit extracts physical layer signal features and the network behavior sensing unit extracts network layer behavior features, the following process is executed before transmitting the data to the multimodal fusion decision engine: The sensing unit calculates the SHA-256 hash value of the feature data and sends the hash value to the root trust module. The root trust module uses its own unique private key to digitally sign the hash value. Then, the sensing unit transmits the original feature data and the root trust signature together to the multimodal fusion decision engine through the encryption bus. After receiving the data, the multimodal fusion decision engine calls the public key of the root trust module to verify the signature. If the verification is successful, the feature data is processed; if the verification fails, the data is discarded and an alarm is triggered. c. The model loading and decision output of the multimodal fusion decision engine are verified by the root of trust module: When the multimodal fusion decision engine is started by loading the model, the deep learning model file and the SHA-256 hash value of the decision policy are sent to the root of trust module. The root of trust module verifies the digital signature of the model / policy. If the signature verification is successful, loading and running are allowed. After generating the threat identification result, the SHA-256 hash value of the result is calculated and sent to the root of trust module for signing. The signed decision result is sent to the response controller. If the response controller verifies the signature, the response policy is executed.
7. The APT identification system based on conformal antenna array and multimodal behavior fusion according to claim 6, characterized in that, The response strategies executed by the response controller include: a. Threat Score At the same time, control commands are sent to the conformal antenna array to adjust the controllable phase shifter and variable impedance unit, suppressing the attack source radio frequency signal through beamforming or blocking specific hostile frequency bands through band notch; blocking policies are issued to the gateway, cutting off the attack's lateral propagation path based on the attack source IP's ACL rules and port isolation commands. b. Threat Score When the link migration is triggered, the conformal antenna array is switched to the backup communication frequency band, and the service traffic is guided to switch to the redundant link. Attack-related radio frequency snapshots are obtained through the high-speed analog-to-digital converter of the conformal antenna array, and network packets of the attack link are collected through the network behavior awareness unit, encrypted and uploaded to the trust root module for storage. c. Threat Score When an alarm log is generated, it is synchronized to the audit log of the root trust module and a warning notification is pushed to the system administrator.