Original traffic risk grading transfer method based on anomaly detection
By constructing a confidence structure vector and neural controlled differential equations, the problem of unstable traffic behavior modeling in network security detection is solved, the accuracy of risk identification and the efficiency of security response are improved, and a cross-time risk identification and automated handover link is established.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING TAIHE ANYU TECHNOLOGY CO LTD
- Filing Date
- 2026-03-11
- Publication Date
- 2026-04-24
AI Technical Summary
When faced with large volumes of high-dimensional, unstructured raw traffic, existing network security detection systems struggle to accurately depict the internal patterns of traffic behavior over time. Furthermore, risk classification and alert results are not integrated with automated flow mechanisms, leading to unstable analysis results and wasted resources.
An anomaly detection-based approach is adopted to construct a confidence structure vector. Through neural controlled differential equations and weighted ordinal regression models, the original flow is continuously modeled to generate anomaly dynamic trajectory codes and establish a cross-time risk identification and automated handover link.
It achieves stable modeling of traffic behavior in the continuous time domain, improves the accuracy of risk identification and the efficiency of security response, reduces manual intervention, and improves the continuity of risk classification and the efficiency of automated flow.
Smart Images

Figure CN121923935A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of raw traffic anomaly modeling, risk classification and automated security handling technology in the field of network security, and in particular to a raw traffic risk classification and transfer method based on anomaly detection. Background Technology
[0002] With the growth of network infrastructure and the increase in business types, the raw traffic generated in the network environment is showing a continuous upward trend. Raw traffic is complex in origin, massive in quantity, and spans a continuous time span. In high-concurrency scenarios, it further develops into a large-volume, high-dimensional, and unstructured system, placing significant pressure on security analysis in terms of data processing and risk identification. Existing security detection systems mostly rely on rule templates, static features, or fixed field matching methods, lacking the ability to continuously model abnormal communication behavior, weak signal threats, and potential risks across time periods. They often exhibit biases when facing scenarios with data noise, missing fields, and mixed protocols, making it difficult to accurately depict the internal patterns of traffic behavior changes over time.
[0003] Traditional anomaly detection methods typically output risk alerts in the form of single-point scores during traffic analysis, failing to reflect the evolutionary trend of behavior over continuous time, resulting in a lack of contextual relevance in the analysis results. The same behavior may exhibit completely different risk patterns at different time periods, but traditional detection methods struggle to capture such cross-temporal correlations, thus affecting the final judgment. In terms of risk classification, existing technologies generally rely on fixed thresholds, which cannot be automatically adjusted according to behavioral changes. Scores for different data qualities lack a unified measurement standard, and the output of levels within continuous time periods often jumps, lacking a continuous structure, causing instability in the subsequent security decision-making process.
[0004] On the other hand, raw traffic typically only generates alarm records after entering the security analysis system. These alarm results are not linked to automated workflow mechanisms, and there is no unified mapping between the severity of risk and subsequent handling paths. This results in high-risk information failing to reach the emergency response chain in a timely manner, while low- and medium-risk information consumes significant resources in manual processing, significantly limiting overall workflow efficiency. As attack patterns become more multi-stage, low-frequency, and weakly correlated, single alarm notifications are insufficient to support real-time response needs. Security systems require the ability to build a continuous processing chain between risk identification, risk classification, and task workflow.
[0005] Against this backdrop, cybersecurity scenarios urgently require a technical solution that can model raw traffic behavior in a continuous time domain, generate structured risk representations from multidimensional confidence information, introduce adaptive mechanisms in risk level output, and form a closed loop with automated handover processes. This would enable traffic risk handling to shift from "single-point identification" to an integrated model of "continuous modeling, hierarchical decision-making, and automatic transfer," thereby improving the accuracy of risk identification and the efficiency of security response. Summary of the Invention
[0006] One objective of this invention is to propose a risk-based graded handover method for raw traffic based on anomaly detection. This invention introduces a confidence structure vector construction mechanism and a multi-component neural controlled differential equation modeling structure to perform dynamic state evolution and anomaly dynamic trajectory encoding on the continuous behavior of raw traffic. Based on a weighted ordinal regression model, it completes the adaptive classification of risk levels and constructs a cross-time risk identification and automated handover link, which has the advantages of low response latency, high stability of level determination, and continuity of graded handover process.
[0007] A method for risk classification and handover of raw traffic based on anomaly detection according to an embodiment of the present invention includes the following steps: S1. Traffic collection and confidence generation: Collect raw traffic, construct a confidence structure vector containing probability components, stability components, data quality components, similarity components, and time continuity components, and arrange them in a preset order. S2. Construct control sequences, generate flow control sequences, confidence control sequences, and abnormal trajectory control sequences within a continuous time window, and maintain consistency in the location dimension; S3. Execute the neural controlled differential equation, input the three types of control sequences into the neural controlled differential equation, introduce a step size adjustment strategy based on stability components and a position adaptive control kernel to obtain the abnormal dynamic trajectory encoding; S4. Ordinal regression modeling: The abnormal dynamic trajectory code and confidence structure vector are fed into the ordinal regression model. Sample weights are set based on the data quality component, and time series regularization terms are constructed based on the stability component. S5. Threshold learning: Threshold learning is performed based on weighted loss, time series regularization term and monotonicity constraint to output risk level; S6. Risk Level Transfer: Based on the risk level, high-risk information is transferred to the emergency response unit, medium-risk information is transferred to the analysis unit, and low-risk information is transferred to the inspection unit, and the transfer process is recorded.
[0008] Optionally, S1 specifically includes: Within a continuous time window, the average and peak values of the anomaly scores for the original traffic are calculated, and the probability component is obtained through a preset mapping. The stability component is obtained based on the change range of risk scores and the fluctuation range of behavioral trajectories in adjacent time windows. The data quality component is obtained based on the proportion of missing fields, the number of abnormal fields, and the noise level. The similarity component is obtained according to the distance between the current features and the features of normal samples or historical threat features in the embedding space. The temporal continuity component is obtained based on the duration and frequency of recurrence of the risk scores on the time axis. The five components, namely the probability component, stability component, data quality component, similarity component, and temporal continuity component, are arranged in a fixed position to form a confidence structure vector.
[0009] Optionally, S2 specifically includes: Under a preset time step, the original flow samples arranged in chronological order are sequentially written into the flow control sequence, so that adjacent elements in the flow control sequence record the original flow field values at different time steps. Under the same time index, the confidence structure vector is arranged in chronological order to form a confidence control sequence. The difference between the built-in confidence structure vectors of adjacent time windows is accumulated to obtain a trajectory increment sequence reflecting the magnitude of confidence changes. This sequence corresponds one-to-one with each component in the confidence structure vector in the position dimension and is arranged in chronological order to form an abnormal trajectory control sequence, ensuring that the flow control sequence, confidence control sequence, and abnormal trajectory control sequence are consistent in both the position and time dimensions.
[0010] Optionally, S3 specifically includes: During the state evolution phase, a step-size scaling strategy based on stability components is introduced, which maps the values of stability components to a preset scaling range. The evolution step size is adjusted at each time step, so that the state exhibits different response modes under different stability conditions. The stability components are derived from fixed-position components inside the confidence structure vector. Their changes on the time axis can characterize the volatility of the behavior trajectory. The step-size scaling mechanism is consistent with the trend of behavior change. In the control contribution modeling stage, a position adaptive control kernel is constructed to establish independent weights for the five types of position components in the confidence structure vector. The influence of different components in the state update remains distinct, and they do not overlap or mix with each other. The position adaptive control kernel performs weight calculations before the control input enters the differential equation. The state evolution process can perceive the internal composition position of the confidence structure and guide the state trajectory to form differentiated responses in different dimensions. In the state output stage, the intermediate and final states of the continuous time steps are connected in chronological order to generate an abnormal dynamic trajectory code, which describes the dynamic evolution of abnormal behavior in continuous time. The abnormal dynamic trajectory code does not directly copy the control sequence, nor does it simply record the state. Instead, it uses the continuous state change trajectory as the expression method, so that the risk classification stage can receive complete time evolution information.
[0011] Optionally, the step-size scaling strategy for the stability component in step S3 specifically includes: In the stability component acquisition stage, the system reads the stability component from the confidence structure vector at each time index, arranges the stability components of all time indices in order, and forms a stability component sequence. The stability component sequence is consistent with the control sequence in the time dimension, and the subsequent scaling process is synchronized with the state update process. In the stability component mapping stage, the system sets a step scaling interval and a mapping method. After entering the mapping method, the stability component is converted into scaling coefficients. The scaling coefficient sequence and the stability component sequence maintain the same position. The mapping method can be set as linear mapping, piecewise mapping, or monotonic mapping. Linear mapping performs a linear transformation on the original values of the stability component and outputs continuous scaling coefficients. Piecewise mapping divides the stability component into multiple numerical intervals and generates constant scaling coefficients within the intervals. Monotonic mapping maintains the monotonic change of the scaling coefficients with the values of the stability components, and the scaling result is consistent with the order of the stability components. In the step size scaling generation stage, the system performs a multiplication operation between the scaling factor and the original step size at each time index, and uses the product as the actual step size corresponding to the time index. The actual step size sequence maintains the same length as the three types of control sequences and forms an independent value at each time index. The state update process forms a continuous step size sequence throughout the entire interval. In the step-size application phase, the system reads the corresponding actual step size at each time index and advances the state variables in the state update equation with the actual step size; the state update is repeatedly executed on consecutive time indices, and a complete state trajectory is formed after all updates are completed; the step-size scaling strategy only applies to the time advancement logic, does not change the control sequence structure, the dimension of the state variables, or the form of the differential equation; finally, the actual step-size sequence and the state trajectory maintain a one-to-one correspondence, and the entire state evolution process is directly driven by the numerical structure of the stability component sequence.
[0012] Optionally, the construction of the position adaptive control kernel in step S3 specifically includes: In the location index construction stage, the control kernel reads the arrangement order of the five components in the confidence structure vector and records the index numbers of the five fixed positions; the index numbers are consistent with the position alignment structure in the confidence control sequence and the abnormal trajectory control sequence; the location index constitutes the first layer input of the control kernel, and the weight calculation is performed on the fixed position set; In the position weight matrix construction stage, the system initializes a weight matrix that corresponds one-to-one with the five positions; each weight parameter in the matrix occupies a fixed row and column position, forming five independent channels; the weight matrix does not expand in the time dimension, is not bound to the time step, is not bound to the control sequence length, and is only bound to the number of positions; the weight parameter in each position channel participates in the calculation independently during the calculation stage. In the weight update rule construction stage, the system sets a gradient-based update method; the update method performs numerical adjustment based on the partial derivative of the loss function in each iteration; the update process does not perform mixed updates of the five position components, and the weight parameters corresponding to the five position components advance along independent update paths; the weight update rule adopts a fixed learning rate, fixed iteration interval or fixed step size mode, and does not introduce shared update paths between positions. In the control input fusion stage, the system reads the corresponding value from the three types of control sequences at each time index, and performs position-by-position multiplication with the weight parameters at the corresponding positions in the weight matrix to obtain the weighted control vector. The weighted control vector maintains a five-dimensional structure, and the weighted results at the five positions constitute the final output of the control kernel at the same time index. The weighted control vector is consistent with the flow control sequence in dimension and can enter the control input channel of the neural controlled differential equation. In the time series direction, the position adaptive control kernel repeats the above operation process; the control input for each time index goes through the steps of position index extraction, weight matrix invocation, and position-by-position weighting; after all time indices are completed, the system forms a weighted control sequence arranged in chronological order; the weighted control sequence is consistent with the three types of control sequences in the time dimension, consistent with the confidence structure vector in the position dimension, and consistent with the position adaptive control kernel in the weight dimension; the position adaptive control kernel does not change the number of time steps of the control sequence, does not change the number of dimensions of the control sequence, and does not change the arrangement order of the control sequence, but only performs independent weighting operations on the values at five fixed positions.
[0013] Optionally, S4 specifically includes: Anomaly trajectory encoding and confidence structure vectors are combined according to the same time index to form a risk grading input sequence. At each time index, sample weights are constructed using the values of the data quality component in the confidence structure vector, and these sample weights are introduced into the ordinal regression loss term. In continuous time indices, a time-series regularization term is constructed using the values of the stability component in the confidence structure vector, and a numerical penalty is applied to the difference in grade output between adjacent time indices, resulting in a continuous grading structure in the time direction. During the grade division process, the grade thresholds within the ordinal regression model are the variables to be optimized, and monotonicity constraints are applied during the optimization process to ensure that all grade thresholds are arranged in a fixed order. Under the combined effect of the loss term, the time-series regularization term, and the monotonicity constraints, the training process of the grade thresholds is completed, generating the risk grade output.
[0014] Optionally, the level threshold learning in step S5 specifically includes: After establishing the ordinal regression model, sample weights are constructed using the data quality component in the confidence structure vector, and these weights are introduced into the loss term of each time index, ensuring that the influence of samples with different quality levels on the loss calculation remains distinct. In the continuous time index, temporal constraints are constructed using the stability component in the confidence structure vector, and numerical penalties are applied to the difference in level outputs between adjacent time indices, resulting in a continuous output sequence in the time direction. The thresholds corresponding to each risk level are set as trainable variables, and monotonicity conditions are applied during training, ensuring that all thresholds do not overlap in numerical order. After completing all iteration steps, level thresholds that meet the monotonicity requirements are formed, and the final risk level output is generated.
[0015] Optionally, S6 specifically includes: After generating risk levels, a corresponding relationship table is established for the level results of each time index. The highest level information is written to the receiving queue of the emergency response unit, the intermediate level information is written to the receiving queue of the analysis unit, and the lowest level information is written to the receiving queue of the inspection unit. During the writing process, the timestamp, the receiving object, and the writing position are recorded to form a traceable handover record. After all information is written, the status of each receiving queue is scanned to confirm the information status, and the scan results are used as a completion mark of the handover process.
[0016] The beneficial effects of this invention are: (1) This invention constructs a confidence structure vector and performs a structured expression of probability components, stability components, data quality components, similarity components and time continuity components with fixed positions within a continuous time window, so that the original flow forms a unified measurement basis under multi-dimensional indicators. In the process of constructing control sequences, the three types of control sequences are consistent in the position dimension and time dimension, so that the trend of abnormal behavior changes can be tracked in a continuous time period, thereby improving the stability of anomaly detection results in cross-time period analysis.
[0017] (2) In the state modeling stage, the present invention introduces multi-component neural controlled differential equations and uses step size scaling strategy and position adaptive control kernel to numerically adjust the state evolution of continuous time steps, so that the flow behavior forms a differentiated dynamic structure under different stability conditions; the abnormal dynamic trajectory encoding can truly present the evolution trajectory of behavior on the time axis, so that the subsequent risk classification model can obtain a complete temporal expression, which is conducive to improving the identification ability in complex threat scenarios.
[0018] (3) In the risk classification stage, the present invention constructs a weighted ordinal regression model, introduces sample weights based on data quality components and time series regularization terms based on stability components, and completes the learning of level thresholds through monotonicity constraints, so that the risk level output maintains structural continuity in the time direction; in the handover stage, the classification results are mapped to the emergency response, analysis and inspection links, and a traceable automated handover process is constructed to realize the continuous connection of risk identification, risk classification and response links. Attached Figure Description
[0019] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention, but do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of a method for risk classification and transfer of raw traffic based on anomaly detection proposed in this invention; Figure 2 This is a schematic diagram of the improved neural controlled differential equation for a risk classification and transfer method for raw traffic based on anomaly detection proposed in this invention. Figure 3 This diagram illustrates the weighted ordinal regression and risk classification of a risk classification and transfer method for raw traffic based on anomaly detection proposed in this invention. Detailed Implementation
[0020] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0021] refer to Figure 1-3A method for risk classification and handover of raw traffic based on anomaly detection includes the following steps: S1. Traffic collection and confidence generation: Collect raw traffic, construct a confidence structure vector containing probability components, stability components, data quality components, similarity components, and time continuity components, and arrange them in a preset order. S2. Construct control sequences, generate flow control sequences, confidence control sequences, and abnormal trajectory control sequences within a continuous time window, and maintain consistency in the location dimension; S3. Execute the neural controlled differential equation, input the three types of control sequences into the neural controlled differential equation, introduce a step size adjustment strategy based on stability components and a position adaptive control kernel to obtain the abnormal dynamic trajectory encoding; S4. Ordinal regression modeling: The abnormal dynamic trajectory code and confidence structure vector are fed into the ordinal regression model. Sample weights are set based on the data quality component, and time series regularization terms are constructed based on the stability component. S5. Threshold learning: Threshold learning is performed based on weighted loss, time series regularization term and monotonicity constraint to output risk level; S6. Risk Level Transfer: Based on the risk level, high-risk information is transferred to the emergency response unit, medium-risk information is transferred to the analysis unit, and low-risk information is transferred to the inspection unit, and the transfer process is recorded.
[0022] In this embodiment, S1 specifically includes: Within a continuous time window, the average and peak values of the anomaly scores for the original traffic are calculated, and the probability component is obtained through a preset mapping. The stability component is obtained based on the change range of risk scores and the fluctuation range of behavioral trajectories in adjacent time windows. The data quality component is obtained based on the proportion of missing fields, the number of abnormal fields, and the noise level. The similarity component is obtained according to the distance between the current features and the features of normal samples or historical threat features in the embedding space. The temporal continuity component is obtained based on the duration and frequency of recurrence of the risk scores on the time axis. The five components, namely the probability component, stability component, data quality component, similarity component, and temporal continuity component, are arranged in a fixed position to form a confidence structure vector.
[0023] In this embodiment, S2 specifically includes: Under a preset time step, the original flow samples arranged in chronological order are sequentially written into the flow control sequence, so that adjacent elements in the flow control sequence record the original flow field values at different time steps. Under the same time index, the confidence structure vector is arranged in chronological order to form a confidence control sequence. The difference between the built-in confidence structure vectors of adjacent time windows is accumulated to obtain a trajectory increment sequence reflecting the magnitude of confidence changes. This sequence corresponds one-to-one with each component in the confidence structure vector in the position dimension and is arranged in chronological order to form an abnormal trajectory control sequence, ensuring that the flow control sequence, confidence control sequence, and abnormal trajectory control sequence are consistent in both the position and time dimensions.
[0024] In this embodiment, S3 specifically includes: During the state evolution phase, a step-size scaling strategy based on stability components is introduced, which maps the values of stability components to a preset scaling range. The evolution step size is adjusted at each time step, so that the state exhibits different response modes under different stability conditions. The stability components are derived from fixed-position components inside the confidence structure vector. Their changes on the time axis can characterize the volatility of the behavior trajectory. The step-size scaling mechanism is consistent with the trend of behavior change. In the control contribution modeling stage, a position adaptive control kernel is constructed to establish independent weights for the five types of position components in the confidence structure vector. The influence of different components in the state update remains distinct, and they do not overlap or mix with each other. The position adaptive control kernel performs weight calculations before the control input enters the differential equation. The state evolution process can perceive the internal composition position of the confidence structure and guide the state trajectory to form differentiated responses in different dimensions. In the state output stage, the intermediate and final states of the continuous time steps are connected in chronological order to generate an abnormal dynamic trajectory code, which describes the dynamic evolution of abnormal behavior in continuous time. The abnormal dynamic trajectory code does not directly copy the control sequence, nor does it simply record the state. Instead, it uses the continuous state change trajectory as the expression method, so that the risk classification stage can receive complete time evolution information.
[0025] The intermediate state is a time-step state vector generated by the neural controlled differential equation on a continuous time index, recording the local changes of the input behavior at each time position; the terminal state refers to the final state vector at the end of the time window evolution, recording the overall impact of all inputs within the window; both states are arranged in chronological order, and when connected, they form a complete dynamic trajectory expression.
[0026] In this embodiment, the step size scaling strategy for the stability component in step S3 specifically includes: In the stability component acquisition stage, the system reads the stability component from the confidence structure vector at each time index, arranges the stability components of all time indices in order, and forms a stability component sequence; the stability component sequence and the control sequence are consistent in the time dimension, and the scaling process is synchronized with the state update process; In the stability component mapping stage, the system sets a step scaling interval and a mapping method. After entering the mapping method, the stability component is converted into scaling coefficients. The scaling coefficient sequence and the stability component sequence maintain the same position. The mapping method can be set as linear mapping, piecewise mapping, or monotonic mapping. Linear mapping performs a linear transformation on the original values of the stability component and outputs continuous scaling coefficients. Piecewise mapping divides the stability component into multiple numerical intervals and generates constant scaling coefficients within the intervals. Monotonic mapping maintains the monotonic change of the scaling coefficients with the values of the stability components, and the scaling result is consistent with the order of the stability components. In the step size scaling generation stage, the system performs a multiplication operation between the scaling factor and the original step size at each time index, and uses the product as the actual step size corresponding to the time index. The actual step size sequence maintains the same length as the three types of control sequences and forms an independent value at each time index. The state update process forms a continuous step size sequence throughout the entire interval. In the step-size application phase, the system reads the corresponding actual step size at each time index and advances the state variables in the state update equation with the actual step size; the state update is repeatedly executed on consecutive time indices, and a complete state trajectory is formed after all updates are completed; the step-size scaling strategy only applies to the time advancement logic, does not change the control sequence structure, the dimension of the state variables, or the form of the differential equation; finally, the actual step-size sequence and the state trajectory maintain a one-to-one correspondence, and the entire state evolution process is directly driven by the numerical structure of the stability component sequence.
[0027] In this embodiment, the construction of the position adaptive control kernel in step S3 specifically includes: In the location index construction stage, the control kernel reads the arrangement order of the five components in the confidence structure vector and records the index numbers of the five fixed positions; the index numbers are consistent with the position alignment structure in the confidence control sequence and the abnormal trajectory control sequence; the location index constitutes the first layer input of the control kernel, and the weight calculation is performed on the fixed position set; In the position weight matrix construction stage, the system initializes a weight matrix that corresponds one-to-one with the five positions; each weight parameter in the matrix occupies a fixed row and column position, forming five independent channels; the weight matrix does not expand in the time dimension, is not bound to the time step, is not bound to the control sequence length, and is only bound to the number of positions; the weight parameter in each position channel participates in the calculation independently during the calculation stage. In the weight update rule construction stage, the system sets a gradient-based update method; the update method performs numerical adjustment based on the partial derivative of the loss function in each iteration; the update process does not perform mixed updates of the five position components, and the weight parameters corresponding to the five position components advance along independent update paths; the weight update rule adopts a fixed learning rate, fixed iteration interval or fixed step size mode, and does not introduce shared update paths between positions. In the control input fusion stage, the system reads the corresponding value from the three types of control sequences at each time index, and performs position-by-position multiplication with the weight parameters at the corresponding positions in the weight matrix to obtain the weighted control vector. The weighted control vector maintains a five-dimensional structure, and the weighted results at the five positions constitute the final output of the control kernel at the same time index. The weighted control vector is consistent with the flow control sequence in dimension and can enter the control input channel of the neural controlled differential equation. In the time series direction, the position adaptive control kernel repeats the above operation process; the control input for each time index goes through the steps of position index extraction, weight matrix invocation, and position-by-position weighting; after all time indices are completed, the system forms a weighted control sequence arranged in chronological order; the weighted control sequence is consistent with the three types of control sequences in the time dimension, consistent with the confidence structure vector in the position dimension, and consistent with the position adaptive control kernel in the weight dimension; the position adaptive control kernel does not change the number of time steps of the control sequence, does not change the number of dimensions of the control sequence, and does not change the arrangement order of the control sequence, but only performs independent weighting operations on the values at five fixed positions.
[0028] In this embodiment, S4 specifically includes: Anomaly trajectory encoding and confidence structure vectors are combined according to the same time index to form a risk grading input sequence. At each time index, sample weights are constructed using the values of the data quality component in the confidence structure vector, and these sample weights are introduced into the ordinal regression loss term. In continuous time indices, a time-series regularization term is constructed using the values of the stability component in the confidence structure vector, and a numerical penalty is applied to the difference in grade output between adjacent time indices, resulting in a continuous grading structure in the time direction. During the grade division process, the grade thresholds within the ordinal regression model are the variables to be optimized, and monotonicity constraints are applied during the optimization process to ensure that all grade thresholds are arranged in a fixed order. Under the combined effect of the loss term, the time-series regularization term, and the monotonicity constraints, the training process of the grade thresholds is completed, generating the risk grade output.
[0029] In this embodiment, the ordinal regression loss term in step S4 specifically includes: the ordinal regression loss term consists of three parts, namely position loss, weight correction loss and rank order loss, and the three parts jointly participate in the numerical calculation at each time index; The location loss takes the difference between the model output level distribution and the reference level as input, and weights the difference according to the ordinal relationship to keep the output level and the reference level numerically close in structure; the reference level is derived from the risk state corresponding to the input sequence and remains consistent in the direction of the continuous time index; the location loss is calculated independently at each time index and forms a loss sequence in chronological order. The weighted correction loss constructs a weight sequence using the data quality components in the confidence structure vector. The weight parameter of each time index is multiplied by the position loss to form a weighted loss with quality differentiation. The data quality components reflect the field integrity and noise level of the input sample. The weighted correction loss is synchronized with the confidence structure vector in the time direction, so that samples under different quality conditions maintain differentiated influence in the overall calculation path. The rank order loss is constructed based on the rank thresholds within the ordinal regression model. It checks the numerical differences between all thresholds and penalizes threshold pairs that are in reverse order. The penalty term is executed in each iteration to ensure that all thresholds maintain a monotonically increasing structure during training. The rank order loss only affects the threshold optimization path and does not directly affect the input features.
[0030] In this embodiment, the ordinal regression model in step S4 specifically includes: The ordinal regression model consists of four parts: an input layer, a feature fusion layer, a rank distribution generation layer, and a threshold optimization structure. The input layer receives the abnormal dynamic trajectory encoding and the confidence structure vector, and aligns the two types of inputs in the numerical dimension to ensure that the trajectory information and confidence information maintain a consistent structure in the same feature space. The feature fusion layer performs a linear transformation and a continuous mapping of the time direction on the input data to form a fusion sequence containing the trajectory pattern and the confidence structure. The fusion sequence maintains a fixed dimension across all time indices, allowing the computation process to proceed in a unified space. The rank distribution generation layer outputs a set of distribution values corresponding to multiple ranks based on the fusion sequence. The distribution values are arranged according to the ordinal relationship, which can reflect the relative position of the input in the rank space. The distribution generation process does not rely on independent classifiers, but models the order relationship between ranks in a continuous manner. The output distribution values are consistently arranged on the time axis and do not change in dimension between different time indices. The threshold optimization structure establishes level boundaries based on the distribution values. All boundaries exist as independent variables and are updated in each training round according to the loss. The update process maintains the monotonic order between the boundaries to avoid the levels being arranged in reverse order. The boundary variables participate in the loss calculation together with the distribution values during the training process, so that the final level output conforms to the ordinal relationship. The overall structure of the ordinal regression model mainly consists of an input layer, a feature fusion layer, a rank distribution generation layer, and a threshold optimization structure. Each part operates independently, ultimately forming a set of continuous rank outputs in the time series direction. The ordinal regression model maintains a stable dimension when fusing trajectory encoding and confidence structure, maintains ordinal relationships when generating rank distributions, and maintains a monotonic structure during threshold training, enabling it to form a complete risk level sequence within a continuous time window.
[0031] In this embodiment, the construction timing regularization term in step S4 specifically includes: The construction process of the time series regularization term includes three stages: difference extraction, stability mapping, and penalty calculation. The difference extraction stage performs a numerical difference operation on the level outputs of adjacent time indices to obtain a set of paired difference sequences. These difference sequences maintain consistency with the temporal order of the input flow, reflecting the magnitude of level changes at consecutive time steps. The stability mapping step extracts stability components from the confidence structure vector and arranges the stability components into a stability sequence according to the time index. The stability sequence records the fluctuation of the input behavior in the time dimension. At each time index, the system maps the stability component to a regularization coefficient within a preset interval and maintains a linked structure between the regularization coefficient and the corresponding item in the difference sequence. The penalty calculation step takes the difference sequence and the regularization coefficient sequence as input, and performs numerical multiplication and squaring operations at each time index to obtain the temporal penalty amount. The penalty amounts are arranged sequentially in the time direction to form a temporal regularization sequence. Each element of the regularization sequence is only related to the level change of the adjacent time step and does not have a linkage relationship with other contents of the control sequence, thus structurally maintaining the invention's individual constraint on temporal continuity. The final time regularization term is the sum of the penalty amounts corresponding to all time indices, maintaining the same optimization path as the ordinal regression loss term. During training, the time regularization term restricts the output of the risk level from changing drastically in a short period of time, making the risk level sequence present a smooth structure on the time axis. The entire regularization process relies on the numerical input of the stability component, which is consistent with the dynamic changes of the control sequence, and can form an independent time direction constraint logic in continuous time modeling scenarios.
[0032] In this embodiment, the level threshold learning in step S5 specifically includes: After establishing the ordinal regression model, sample weights are constructed using the data quality component in the confidence structure vector, and these weights are introduced into the loss term of each time index, ensuring that the influence of samples with different quality levels on the loss calculation remains distinct. In the continuous time index, temporal constraints are constructed using the stability component in the confidence structure vector, and numerical penalties are applied to the difference in level outputs between adjacent time indices, resulting in a continuous output sequence in the time direction. The thresholds corresponding to each risk level are set as trainable variables, and monotonicity conditions are applied during training, ensuring that all thresholds do not overlap in numerical order. After completing all iteration steps, level thresholds that meet the monotonicity requirements are formed, and the final risk level output is generated.
[0033] In this embodiment, the numerical penalty in step S5 specifically includes introducing an additional loss amount to the difference in the level output of adjacent time indices; when the difference exceeds a preset range, the penalty amount increases; the penalty amount participates in the loss accumulation during training, so that the model tends to generate a more continuous level sequence when updating parameters.
[0034] In this embodiment, S6 specifically includes: After generating risk levels, a corresponding relationship table is established for the level results of each time index. The highest level information is written to the receiving queue of the emergency response unit, the intermediate level information is written to the receiving queue of the analysis unit, and the lowest level information is written to the receiving queue of the inspection unit. During the writing process, the timestamp, the receiving object, and the writing position are recorded to form a traceable handover record. After all information is written, the status of each receiving queue is scanned to confirm the information status, and the scan results are used as a completion mark of the handover process.
[0035] Example 1: In a continuously running network environment, the method of this invention was applied to a raw traffic analysis link to observe its performance under real-world conditions. Traffic fluctuations were significant at different times, and traditional detection methods often resulted in numerous false alarms during high-traffic periods, failing to form continuous judgments based on temporal changes in behavior, leading to increasing pressure on manual screening. To improve this situation, the method of this invention was used to continuously model traffic, generating a confidence structure vector. Simultaneously, traffic control sequences, confidence control sequences, and abnormal trajectory control sequences were constructed, allowing behavioral changes to be structurally expressed within a time window. During processing, the confidence structure vector exhibited smooth changes in relatively stable phases, but significant fluctuations occurred during phases with risky behavior. The three control sequences maintained a consistent positional structure, ensuring the continuity of behavioral changes over time. Subsequently, a neural controlled differential equation was input, and the system formed intermediate states at each time index and terminal states at the end of the window, forming an abnormal dynamic trajectory code through a temporal connection structure. The trajectory code presented the overall trend of behavior, providing a reliable basis for subsequent classification. Building upon this, the ordinal regression model fuses trajectory encoding and confidence structure vectors, constructs sample weights based on data quality components, and then constructs a time-series regularization term based on stability components, resulting in a time-continuous structure for the grade output. This invention reduces unnecessary jumps under the same flow conditions, making the analysis results more closely reflect the actual direction of behavioral changes.
[0036] Table 1: Comparison of traditional methods and the present invention in continuous detection
[0037] As can be seen from the multi-batch detection results in Table 1, under the same original flow conditions, the traditional method and the present invention show stable differences in various indicators. The average confidence fluctuation of the traditional method is generally in a high range, with multiple batches exceeding 0.30, indicating that changes in behavior over time are easily affected by noise, and the judgment process is not stable enough. The confidence fluctuation of the present invention is significantly reduced within the same batch, with multiple batches maintaining a range of 0.16 to 0.21, making the behavioral changes present a clearer structure in continuous modeling and avoiding invalid jumps in a short period of time.
[0038] Regarding the continuity of risk level output, traditional methods generally yield low results, with values mostly falling between 0.58 and 0.65. This corresponds to frequent abrupt changes in risk levels within the sequence, introducing additional uncertainty into risk assessment. This invention maintains risk level continuity within the same batch within the range of 0.89 to 0.95, with changes more closely reflecting actual behavioral trends. This allows the risk level to form a stable curve over time, facilitating subsequent analysis of the direction of risk changes.
[0039] The number of manual interventions further highlights the difference between the two methods. Traditional methods generally involve a high number of manual interventions across multiple batches, with some batches approaching 90, impacting overall processing efficiency. This invention significantly reduces the number of manual interventions within the same batch, mostly remaining in the 40 to 50 range. This reduction in manual intervention indicates that risk grading has completed most of the screening work in the automated stage, eliminating the need for repeated manual confirmation and thus improving overall process efficiency.
[0040] The comparison of these indicators shows that the present invention has a significantly better ability to capture behavioral changes in continuous traffic scenarios than traditional methods. The level sequence is more stable, the fluctuation is smaller, and the manual processing requirement is lower, making it suitable for real-time detection scenarios with high concurrency and high noise.
[0041] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A method for risk classification and handover of raw traffic based on anomaly detection, characterized in that, Includes the following steps: S1. Traffic collection and confidence generation: Collect raw traffic, construct a confidence structure vector containing probability components, stability components, data quality components, similarity components, and time continuity components, and arrange them in a preset order. S2. Construct control sequences, generate flow control sequences, confidence control sequences, and abnormal trajectory control sequences within a continuous time window, and maintain consistency in the location dimension; S3. Execute the neural controlled differential equation. Input the three types of control sequences, namely flow control sequence, confidence control sequence and abnormal trajectory control sequence, into the neural controlled differential equation. Introduce a step size adjustment strategy based on stability components and a position adaptive control kernel to obtain the abnormal dynamic trajectory code. S4. Ordinal regression modeling: The abnormal dynamic trajectory code and confidence structure vector are fed into the ordinal regression model. Sample weights are set based on the data quality component, and time series regularization terms are constructed based on the stability component. S5. Threshold learning: Threshold learning is performed based on weighted loss, time series regularization term and monotonicity constraint to output risk level; S6. Risk Level Transfer: Based on the risk level, high-risk information is transferred to the emergency response unit, medium-risk information is transferred to the analysis unit, and low-risk information is transferred to the inspection unit, and the transfer process is recorded.
2. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, S1 specifically includes: Within a continuous time window, the average and peak values of the anomaly scores for the original traffic are calculated, and the probability component is obtained through a preset mapping. The stability component is obtained based on the change range of risk scores and the fluctuation range of behavioral trajectories in adjacent time windows. The data quality component is obtained based on the proportion of missing fields, the number of abnormal fields, and the noise level. The similarity component is obtained according to the distance between the current features and the features of normal samples or historical threat features in the embedding space. The temporal continuity component is obtained based on the duration and frequency of recurrence of the risk scores on the time axis. The five components, namely the probability component, stability component, data quality component, similarity component, and temporal continuity component, are arranged in a fixed position to form a confidence structure vector.
3. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, S2 specifically includes: Under a preset time step, the original flow samples arranged in chronological order are sequentially written into the flow control sequence, so that adjacent elements in the flow control sequence record the original flow field values at different time steps. Under the same time index, the confidence structure vector is arranged in chronological order to form a confidence control sequence. The difference between the built-in confidence structure vectors of adjacent time windows is accumulated to obtain a trajectory increment sequence reflecting the magnitude of confidence changes. This sequence corresponds one-to-one with each component in the confidence structure vector in the position dimension and is arranged in chronological order to form an abnormal trajectory control sequence, ensuring that the flow control sequence, confidence control sequence, and abnormal trajectory control sequence are consistent in both the position and time dimensions.
4. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, S3 specifically includes: During the state evolution phase, a step-size scaling strategy based on stability components is introduced, which maps the values of stability components to a preset scaling range. The evolution step size is adjusted at each time step, so that the state exhibits different response modes under different stability components. The stability components are derived from fixed-position components inside the confidence structure vector. Their changes on the time axis can characterize the volatility of the behavior trajectory. The step-size scaling mechanism is consistent with the trend of behavior change. In the control contribution modeling stage, a position-adaptive control kernel is constructed, and independent weights are established for the five types of positional components in the confidence structure vector. The influence of different components in state updates remains distinct, without mutual overlap or mixing. The position-adaptive control kernel performs weight calculations before the control input enters the differential equation. During the state evolution process, it can perceive the internal composition of the confidence structure and guide the state trajectory to form differentiated responses in different dimensions. The five types of positional components include probability components, stability components, data quality components, similarity components, and temporal continuity components. In the state output stage, the intermediate and final states of the continuous time steps are connected in chronological order to generate an abnormal dynamic trajectory code, which describes the dynamic evolution law of abnormal behavior in continuous time.
5. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, The step-size scaling strategy for the stability component in step S3 specifically includes: In the stability component acquisition stage, the system reads the stability component from the confidence structure vector at each time index, arranges the stability components of all time indices in order, and forms a stability component sequence; the stability component sequence and the control sequence are consistent in the time dimension, and the scaling process is synchronized with the state update process; In the stability component mapping stage, the system sets a step scaling interval and a mapping method. After entering the mapping method, the stability component is converted into scaling coefficients. The scaling coefficient sequence and the stability component sequence maintain the same position. The mapping method can be set as linear mapping, piecewise mapping, or monotonic mapping. Linear mapping performs a linear transformation on the original values of the stability component and outputs continuous scaling coefficients. Piecewise mapping divides the stability component into a preset value interval and generates constant scaling coefficients within the interval. Monotonic mapping maintains the monotonic change of the scaling coefficients with the values of the stability components, and the scaling result is consistent with the order of the stability components. In the step size scaling generation stage, the system performs a multiplication operation between the scaling factor and the original step size at each time index, and uses the product as the actual step size corresponding to the time index. The actual step size sequence maintains the same length as the three types of control sequences and forms an independent value at each time index. The state update process forms a continuous step size sequence throughout the entire interval. In the step-size application phase, the system reads the corresponding actual step size at each time index and advances the state variables in the state update equation with the actual step size; the state update is repeatedly executed on consecutive time indices, and a complete state trajectory is formed after all updates are completed; the step-size scaling strategy only applies to the time advancement logic, does not change the control sequence structure, the dimension of the state variables, or the form of the differential equation; finally, the actual step-size sequence and the state trajectory maintain a one-to-one correspondence, and the entire state evolution process is directly driven by the numerical structure of the stability component sequence.
6. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, The construction of the position adaptive control kernel in step S3 specifically includes: In the location index construction stage, the control kernel reads the arrangement order of the five components in the confidence structure vector and records the index numbers of the five fixed positions; the index numbers are consistent with the position alignment structure in the confidence control sequence and the abnormal trajectory control sequence; the location index constitutes the first layer input of the control kernel, and the weight calculation is performed on the fixed position set; In the position weight matrix construction stage, the system initializes a weight matrix that corresponds one-to-one with the five positions; each weight parameter in the weight matrix occupies a fixed row and column position, forming five independent channels; the weight matrix does not expand in the time dimension, is not bound to the time step, and is not bound to the control sequence length, but is only bound to the number of positions; the weight parameter in each position channel participates in the calculation independently during the calculation stage; In the weight update rule construction stage, the system sets a gradient-based update method; the update method performs numerical adjustment based on the partial derivative of the loss function in each iteration; the update process does not perform mixed updates of the five position components, and the weight parameters corresponding to the five position components advance along independent update paths; the weight update rule adopts a fixed learning rate, fixed iteration interval or fixed step size mode, and does not introduce shared update paths between positions. In the control input fusion stage, the system reads the corresponding value from the three types of control sequences at each time index, and performs position-by-position multiplication with the weight parameters at the corresponding positions in the weight matrix to obtain the weighted control vector. The weighted control vector maintains a five-dimensional structure, and the weighted results at the five positions constitute the final output of the control kernel at the same time index. The weighted control vector is consistent with the flow control sequence in dimension and can enter the control input channel of the neural controlled differential equation. Each time index's control input undergoes position index extraction, weight matrix retrieval, and position-by-position weighting steps. After all time indices are completed, the system forms a weighted control sequence arranged in chronological order. The weighted control sequence maintains consistency with the three types of control sequences in the time dimension, with the confidence structure vector in the position dimension, and with the position adaptive control kernel in the weight dimension. The position adaptive control kernel does not change the number of time steps, the number of dimensions, or the order of the control sequence; it only performs independent weighting operations on the values at five fixed positions.
7. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, S4 specifically includes: Anomaly trajectory encoding and confidence structure vectors are combined according to the same time index to form a risk grading input sequence. At each time index, sample weights are constructed using the values of the data quality component in the confidence structure vector, and these sample weights are introduced into the ordinal regression loss term. In continuous time indices, a time-series regularization term is constructed using the values of the stability component in the confidence structure vector, and a numerical penalty is applied to the difference in grade output between adjacent time indices, resulting in a continuous grading structure in the time direction. During the grade division process, the grade thresholds within the ordinal regression model are the variables to be optimized, and monotonicity constraints are applied during the optimization process to ensure that all grade thresholds are arranged in a fixed order. Under the combined effect of the loss term, the time-series regularization term, and the monotonicity constraints, the training process of the grade thresholds is completed, generating the risk grade output.
8. The method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, The level threshold learning in step S5 specifically includes: After establishing the ordinal regression model, sample weights are constructed using the data quality component in the confidence structure vector, and these weights are introduced into the loss term of each time index, ensuring that the influence of samples with different quality levels on the loss calculation remains distinct. In the continuous time index, temporal constraints are constructed using the stability component in the confidence structure vector, and numerical penalties are applied to the difference in level outputs between adjacent time indices, resulting in a continuous output sequence in the time direction. The thresholds corresponding to each risk level are set as trainable variables, and monotonicity conditions are applied during training, ensuring that all thresholds do not overlap in numerical order. After completing all iteration steps, level thresholds that meet the monotonicity requirements are formed, and the final risk level output is generated.
9. A method for risk classification and handover of raw traffic based on anomaly detection according to claim 1, characterized in that, S6 specifically includes: After generating risk levels, a corresponding relationship table is established for the level results of each time index. The highest level information is written to the receiving queue of the emergency response unit, the intermediate level information is written to the receiving queue of the analysis unit, and the lowest level information is written to the receiving queue of the inspection unit. During the writing process, the timestamp, the receiving object, and the writing position are recorded to form a traceable handover record. After all information is written, the status of each receiving queue is scanned to confirm the information status, and the scan results are used as a completion mark of the handover process.
Citation Information
Patent Citations
Industrial Internet of Things abnormal traffic grading detection method and system
CN117395183A
Traffic prediction method based on continuous evolution graph neural controlled differential equation
CN117556949A
Multi-dimensional network intrusion behavior intelligent identification method based on deep learning
CN121530656A
Continuously generalized ordinal regression
US20230040110A1