Unknown attack dynamic prediction method and system based on adaptive Kalman filtering
By using an adaptive Kalman filter method to perform real-time observation and processing of network systems, the problem of accurately predicting unknown attacks in complex and noisy environments is solved. This achieves high signal-to-noise ratio state estimation and forward-looking attack warning, reducing false alarm rate and operation and maintenance costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIDIAN UNIV
- Filing Date
- 2026-02-13
- Publication Date
- 2026-05-15
AI Technical Summary
Existing attack prediction methods lack adaptability and generalization ability in complex and noisy network environments, making it difficult to achieve accurate prediction of unknown attacks under conditions of scarce evidence. This results in high false positive and false negative rates and fails to provide an intuitive explanation of the attack chain.
An adaptive Kalman filter-based method is adopted, which uses real-time observation from multiple data sources to perform adaptive Kalman filtering and adaptive adjustment of noise parameters. Combined with forward residual back-calculation and time window estimation, incremental prediction and early warning of unknown attacks are achieved.
Maintaining high signal-to-noise ratio state estimation in complex and noisy environments reduces false alarm and false negative rates, improves attack identification capabilities, and enables forward-looking judgment in scenarios with scarce evidence, thereby reducing operation and maintenance costs and closed-loop processing latency.
Smart Images

Figure CN122053172A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically relating to a method and system for dynamic prediction of unknown attacks based on adaptive Kalman filtering. Background Technology
[0002] In the field of cyberspace security, anomaly detection and attack detection are core means of threat defense. Anomaly detection mainly targets the identification of deviations in system behavior. By analyzing logs, traffic, or host status, it identifies behaviors that significantly differ from normal patterns. Attack detection further combines known attack characteristics, rules, or signatures to qualitatively identify and alert on anomalies. Traditional anomaly detection mainly relies on static statistical thresholds, time-series volatility, or supervised learning models. It learns normal patterns from large amounts of historical data and detects deviations in real-time observation. However, in complex network systems, behavioral states are affected by multiple input sources, random interference, and dynamic policy changes, exhibiting strong nonlinearity, time-varying characteristics, and noisy backgrounds. This makes it difficult for detection methods based on static assumptions to maintain stable recognition performance.
[0003] With the evolution of attack methods, attacks such as Advanced Persistent Threats (APTs) exhibit complex characteristics of multi-stage, low-frequency, and cross-domain latency. Their behavior is discontinuous in time, spreads across spatial domains, and has hidden causal chains. This environment of weak signs, sparse signals, and strong noise renders traditional signature-based or rule-template-based methods generally ineffective. Systems often only detect threats after the attack has become explicit, making early warning difficult. Therefore, research focus has gradually shifted from "detecting known attacks" to "predicting unknown attacks," requiring models to possess adaptability and generalization under conditions of incomplete observations, information delays, and noise disturbances, in order to extract the essential trends of system state changes.
[0004] Currently, existing attack prediction schemes mainly fall into two categories: First, attack prediction methods based on linear models. These methods assume that system behavior follows linear laws or stable statistical characteristics, and extrapolate trends from historical data using models such as linear regression, time difference, autoregressive moving average, or Kalman filtering. Second, attack prediction methods based on graph neural networks. These methods learn and train on historical attack data or logs to build models capable of generalizing to identify unknown attacks, focusing on using behavioral graph modeling and state estimation theory to improve attack prediction capabilities. Their core lies in abstracting system behavior into a time-varying state sequence or graph structure, and applying machine learning / statistical algorithms to identify abnormal patterns.
[0005] However, the aforementioned attack prediction schemes still suffer from the following key problems in complex and noisy network environments: First, linear model-based methods heavily rely on existing attack patterns and human experience, lacking sufficient ability to identify unknown or variant attacks, and facing significant limitations in large-scale cluster networks: their static thresholds or fixed parameters are difficult to adapt to noise superposition and dynamic interference, causing attack features to be masked by the high-noise background, frequent fluctuations in the discrimination boundary, and increased false positive and false negative rates. For example, under benign chaotic data interference such as sudden traffic or time jitter, linear models cannot stably distinguish between anomalies and noise, requiring frequent manual parameter tuning. Second, while graph neural network-based methods have generalization capabilities, they rely on sufficient training data, making it difficult to capture weak signals when evidence is sparse in the early stages of an attack, resulting in severe warning delays; moreover, their black-box nature makes it impossible to provide an intuitive explanation of the attack chain, which is detrimental to operational decision-making.
[0006] In summary, existing attack prediction methods lack online adaptive mechanisms for the statistical characteristics of multiple noises in complex environments, as well as the ability to achieve forward-looking predictions through residual back-calculation and uncertainty modeling under conditions of scarce evidence, resulting in insufficient timeliness and reliability of attack predictions. Summary of the Invention
[0007] To address the aforementioned problems in the existing technology, this invention provides a method and system for dynamic prediction of unknown attacks based on adaptive Kalman filtering. The technical problem to be solved by this invention is achieved through the following technical solution: In a first aspect, this invention proposes a dynamic prediction method for unknown attacks based on adaptive Kalman filtering, comprising: Step 1: Observe the system status in real time based on multi-domain data sources, and obtain multi-domain integrity observations based on the obtained multi-domain observations; Step 2: Perform adaptive Kalman filtering on the multi-domain integrity observations, including real-time state prediction, observation updates, and adaptive adjustment of noise parameters, to obtain the system state estimate; Step 3: Perform forward residual back-calculation based on system state estimation to predict unknown attack increments and obtain attack prediction results; Step 4: Estimate the time window based on the system state estimation and attack prediction results to achieve attack early warning.
[0008] Secondly, this invention proposes an unknown attack dynamic prediction system based on adaptive Kalman filtering, used to implement the method proposed in the first aspect of this invention. The system includes: The multi-source data acquisition unit is used to observe the system status in real time based on multi-domain data sources, and to obtain multi-domain integrity observations based on the obtained multi-domain observations. The adaptive Kalman filter unit is used to perform adaptive Kalman filtering on multi-domain integrity observations, including real-time state prediction, observation updates and adaptive adjustment of noise parameters, to obtain system state estimates. The attack prediction unit is used to perform forward residual back-calculation based on system state estimation in order to predict unknown attack increments and obtain attack prediction results. The attack warning unit is used to estimate the time window based on system state estimation and attack prediction results, thereby enabling attack warning.
[0009] The beneficial effects of this invention are: The present invention provides a dynamic prediction method for unknown attacks based on adaptive Kalman filtering. First, the system state is observed in real time through multi-domain data sources, and multi-domain integrity observations are obtained based on the obtained multi-domain observations. Then, adaptive Kalman filtering is performed on the multi-domain integrity observations, including real-time state prediction, observation updates, and adaptive adjustment of noise parameters, to obtain a system state estimate. Next, forward residual back-calculation is performed based on the system state estimate to realize incremental prediction of unknown attacks and obtain attack prediction results. Finally, time window estimation is performed based on the system state estimate and attack prediction results to achieve attack early warning. This method proposes two main approaches. First, it introduces an adaptive Kalman filtering and attack detection mechanism for complex and noisy environments. Through real-time estimation and dynamic parameter tuning, it adaptively updates the Kalman gain and related parameters, enabling interpretable differentiation between anomalous and attack behaviors. This ensures high signal-to-noise ratio state estimation and stable category boundaries even under chaotic and complex noise conditions, reducing false alarm / false negative rates and maintaining system stability even under fluctuating noise levels, thus improving attack identification capabilities. Second, it proposes a forward-looking residual inference and attack prediction mechanism for scenarios with scarce evidence. Based on consistency checks, it inversely infers residual dynamics and propagates uncertainty constraints, outputting attack detection results and attack arrival time windows. This transforms early signs with insufficient evidence but significant trends into actionable pre-set actions, enabling forward-looking judgment and resource pre-deployment guidance. This improves early warning lead time and arrival window coverage, while reducing closed-loop processing latency and maintenance costs.
[0010] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0011] Figure 1 A flowchart illustrating the dynamic prediction method for unknown attacks based on adaptive Kalman filtering provided in an embodiment of the present invention; Figure 2 A framework diagram for adaptive Kalman filter attack prediction provided in an embodiment of the present invention; Figure 3This is a flowchart of the forward residual back-calculation and adaptive update process provided in an embodiment of the present invention; Figure 4 The diagram shows the structure of an unknown attack dynamic prediction system based on adaptive Kalman filtering, as provided in an embodiment of the present invention. Detailed Implementation
[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0013] The first aspect of this invention provides a method for dynamic prediction of unknown attacks based on adaptive Kalman filtering. See also... Figure 1 , Figure 1 The flowchart illustrates the unknown attack dynamic prediction method based on adaptive Kalman filtering provided in this embodiment of the invention. The method mainly includes the following steps: Step 1: Observe the system status in real time based on multi-domain data sources, and obtain multi-domain integrity observations based on the obtained multi-domain observations.
[0014] 11) Obtain different observation components of the system using multi-domain data sources, and perform saturation function normalization on each observation component to form a multi-domain observation.
[0015] In this embodiment, for the network physical system scenario being monitored, a multi-domain data source detector is provided, including a process monitor, a network monitor, and a file activity monitor. Each detector asynchronously aggregates measurement data through a communication network to observe the status of the protected system and obtain multi-domain observations. Specifically, the multi-domain observations include process domain observations, network domain observations, and file domain observations.
[0016] Specifically, the present invention abstracts the protected system into a discrete-time nonlinear state-space model.
[0017] Let the first The observation windows are: ; Define a saturation function to constrain each observed component to... Interval: ; Then in the window Inside, keep track of time The system observation state vector is: ; In the formula, For process domain observations, For network domain observations, For document domain observations.
[0018] The following sections will provide a detailed introduction to these three types of observations.
[0019] (a) Process Domain Observations In this embodiment, the process domain primarily characterizes the running state and resource consumption level of critical processes, reflecting behaviors such as spoofed execution and abnormal resource consumption, and is defined as follows: 1. CPU normalized utilization :
[0020] in, The CPU busy time increment for the host within the window is obtained by differentiating the fields in / proc / stat. This represents the number of logical cores.
[0021] 2. Normalized memory usage :
[0022] in, Total memory, This is the average amount of memory used within the window, derived from MemTotal and MemAvailable in / proc / meminfo.
[0023] 3. Normalized occupancy of FD (file handle) :
[0024] in, The average number of allocated file handles within the window, sampled by / proc / sys / fs / file-nr. It is located on the system handle and is obtained from / proc / sys / fs / file-max.
[0025] (ii) Network Domain Observations In this embodiment, the network domain focuses on characterizing communication traffic features and interaction structures to identify suspicious communication behaviors such as lateral movement and external control, and is defined as follows: 1. Normalization of inbound and outbound throughput , : ; ; in, Accumulate byte differential for the network card within the window, by get, This is the upper bound of the bandwidth, taken as the upper bound of the statistics during the normal period.
[0026] 2. Normalization of active connection strength : ; in, This is a statistical value representing the number of active connections within the window. The normalized upper bound for the connection number is calculated from the normal period.
[0027] 3. Remote IP diversity normalization : ; in, The number of different remote IPs within the window. The normalized upper bound.
[0028] (III) Document Domain Observations In this embodiment, the file domain focuses on the access and modification behavior of configuration files and sensitive files to detect malicious tampering and persistence actions, and pre-defines three types of critical path sets: configuration file sets. Sensitive file set Executable / Script Set Let the set of file events within the window be... ,event With path With operation type .
[0029] 1. Configure change strength : ;
[0030] 2. Sensitive Access Strength :
[0031]
[0032] 3. Executable / script write-to-disk strength and execution intensity : ;
[0033] 12) Perform deviation calculation and domain risk aggregation on multi-domain observations. By calculating the deviation of each dimension observation from the normal baseline, domain risk is obtained by equal-weight aggregation within the domain. The domain risk is then mapped to the smaller domain integrity observation to obtain three-domain integrity observations.
[0034] First, in the normal window set Above, for each dimension observation Calculate a robust baseline: ;
[0035] Then, the deviation of each dimension's observed value from the normal baseline is calculated; where, the first... The degree of deviation is defined as: ; Define the three-domain parameter sets respectively: ; ; ; Then, the domain risk is aggregated using equal weighting within the domain:
[0036] Then map the domain risk to the smallest domain integrity observation: , ; Thus, the three-domain integrity observation is obtained, denoted as: .
[0037] Step 2: Perform adaptive Kalman filtering on the multi-domain integrity observations, including real-time state prediction, observation updates, and adaptive adjustment of noise parameters, to obtain the system state estimate.
[0038] Specifically, this embodiment constructs an adaptive Kalman state estimation model. During system operation, the future system state is predicted in real time based on the above model, and a set of predicted states during system operation is obtained. The degree of similarity between the elements in the set is calculated by the relationship between the set of predicted states and the set of safe states, which is used as the system reliability value.
[0039] Optionally, this embodiment mainly uses state prediction based on the Extended Kalman Filter (EKF) algorithm as an example. This algorithm predicts the prior state at the current moment based on the optimal state at the previous moment, and updates the current optimal state by combining the current observed state. Then, it calculates the reliability value by combining the predicted state sequence with the baseline information of the task system. The reliability value is taken into consideration as a weight adjustment factor in the attack detection discrimination process. The EKF algorithm is mainly divided into three parts: state prediction, state update, and adaptive parameter tuning. Step 2 can be specifically implemented through the following sub-steps 21)-23).
[0040] 21) Based on the system's previous state estimate and nonlinear state propagation function, predict the prior state estimate and prior noise covariance matrix.
[0041] First, for state prediction, the prior state vector at the current moment can be obtained by predicting the optimal state at the previous moment and combining it with the control vector and process noise.
[0042] Specifically, let the three-domain behavioral state vector be: ; in, This indicates the integrity status of the three domains; the smaller the value, the more dangerous the situation. Indicates the rate of change in integrity; This represents the change in the rate of change. Let... For a moment The posterior optimal estimate, For a moment Prior estimates, This is process noise; For a moment -1 process noise covariance matrix; This is a nonlinear state propagation function.
[0043] The prediction formula for prior state estimation is: ; in, It is a nonlinear function that calculates the prior state vector at the current moment, specifically expressed as:
[0044] in, For window spacing; For three-domain normal integrity basis; The regression coefficients are used to ensure that the integrity of the system converges back to the baseline after normal fluctuations. The damping coefficient is used to suppress the amplification of benign jitter. To provide the acceleration inertia coefficient, causing the unknown attack-driving term to exhibit a phased and continuous trend, the function... For element-wise Sigmoid saturation function:
[0045] Ensure that the integrity component falls within the bounded interval and suppress divergence.
[0046] Secondly, the prediction of the prior noise covariance matrix is mainly derived from the noise covariance and the noise observed at the previous time step, resulting in the prior estimated noise covariance matrix for the current time step, which can be expressed as: ; in, and They are time points Prior covariance and time The posterior covariance; The process noise covariance matrix; nonlinear function The Jacobian matrix is in block diagonal form: ; For any field ,set up ; Then the domain Jacobi blocks are: ; Therefore, the above covariance propagation formula can propagate uncertainty numerically stably.
[0047] 22) Based on Kalman gain and combined with multi-domain integrity observations, the prior state estimate is updated by observation to obtain the posterior optimal state estimate and the posterior noise covariance matrix.
[0048] 22a) Calculate the Kalman gain based on the prior noise covariance matrix.
[0049] Specifically, in this embodiment, the Kalman gain is calculated by combining the Jacobian matrix of the observation matrix, the observation noise covariance matrix, and the noise covariance matrix obtained from the prediction part. The calculation formula is as follows: ; In the formula, For a moment Kalman gain; For a moment The prior noise covariance matrix; For a moment The observation noise covariance matrix; For observation function The Jacobian matrix.
[0050] It should be noted that the multi-domain integrity observation in this invention is derived from the three-domain integrity observation. ,in, Depend on The calculated value is a three-domain integrity index. Since the observations directly correspond to only the three-domain integrity components, the observation function can be taken as a linear choice form. Therefore, the observation model can be written as: ; ; in, To observe noise.
[0051] 22b) Calculate the optimal estimate at the current time based on the Kalman gain and the three-domain integrity observation to obtain the posterior optimal state estimate.
[0052] Specifically, this embodiment calculates the optimal estimate for the current time step based on the prior estimate obtained in the prediction phase, combined with the Kalman gain, observation values, and observation function obtained in the previous step. The calculation formula is as follows: ; In the formula, For a moment The posterior optimal state estimate; For a moment Prior state estimation; For a moment Three-domain integrity observation; The predicted observations are the mappings of the prior states to the observation space.
[0053] in, The term characterizes the deviation between observation integrity and prediction integrity, and the driving filter performs joint correction on the integrity of the three domains and its velocity trend term and acceleration trend term.
[0054] 22c) Update the current best estimated noise covariance matrix based on the Kalman gain and the prior noise covariance to obtain the posterior noise covariance matrix.
[0055] Specifically, this embodiment updates the current optimal estimated noise covariance matrix based on the Kalman gain, the Jacobian matrix of the observation function, and the prior estimated noise covariance matrix. To enhance numerical stability, the Joseph form is used for updating, expressed as: ; In the formula, For a moment The posterior noise covariance matrix; It is the identity matrix. This form ensures that, under conditions of finite numerical accuracy... The symmetry and positive semidefiniteness of the filter improve the stability of the filter.
[0056] 23) Reliability and residual consistency are used as anomaly triggering constraints, and when anomalies are determined, Sage-Husa online estimation and power step size scaling are used to dynamically and adaptively adjust the noise parameters; where the noise parameters include the process noise covariance matrix and the observation noise covariance matrix.
[0057] 23a) Calculate the system reliability value.
[0058] Specifically, during the execution process, the system state combines an adaptive Kalman prediction model with a safety baseline to continuously predict and store system state prediction information for a future period of time.
[0059] Suppose that at a certain moment, the optimal estimate of the system state and the confidence level are respectively... and The prediction module, given a prediction window length... Then, calculate the future. The system generates a priori prediction sequence for each step and sends the corresponding set of predicted states for that time period to the reliability assessment and attack detection module. The predicted state set is defined as follows: ; in, Indicates at time Given the known conditions, for the future... The prior prediction state of the step.
[0060] For the desired state of the system, its desired trajectory is considered fixed, such as the baseline constant vector. . From normal window set The statistically obtained three-domain integrity baseline and trend baseline constitute the following: ; Setting the velocity and acceleration baseline to 0 indicates that, under normal conditions, the overall integrity of the system exhibits stable, small fluctuations without a sustained downward trend. Therefore, a reference state set is constructed: ; The attack detection module combines its own predicted state set With reference state set Calculate the difference to obtain the distance sequence. The formula for calculating each element is shown below: ; In the formula, For the first The state deviation distance of one forward-looking step; To measure the weight matrix and reflect the importance and uncertainty suppression of different state components, the matrix is constructed using the method of "constructing the inverse Mahalanobis distance weights of the predicted covariance and the stability term": ; The first prediction formula obtained by rolling the prior noise covariance matrix is... Predicting covariance using priors; This is a numerically stable term, which avoids matrix non-invertibility and enhances numerical robustness. It is an identity matrix. When the prediction uncertainty of a certain component is large, its deviation will relatively suppress its contribution to the distance; when the prediction of a certain component is relatively certain, its deviation will significantly increase the distance value, thereby improving the credibility of the reliability assessment.
[0061] Based on distance sequence Given the size of each element, the reliability calculation formula is as follows: ; In the formula, For a moment The system reliability value; The scaling factor controls the rate at which distance decays to the reliability value; The distance cutoff is set as the upper limit to suppress the excessive influence of extreme outliers on the reliability value; the larger the reliability value, the more reliable it is, indicating that it is closer to the safety baseline; the closer the reliability value is to 0, the more the system state deviates from the safety baseline, and the higher the risk of anomalies / attacks.
[0062] 23b) Define the chi-square statistic of residual consistency. .
[0063] Specifically, when the system enters an abnormal state, to make the filter more confident in the model's rapid response to state changes, the process noise covariance matrix can be adjusted. Increase, then appropriately decrease the observation noise covariance matrix This makes the system more sensitive to observations; when the system stabilizes, the covariance is then recovered, making... Decrease Increasing the step size makes the estimation smoother and more robust. To avoid sudden changes in speed, the step size decreases exponentially from the previous step size, reflecting the goal of the fastest descent, which is rapid at first and then stable.
[0064] Optionally, this embodiment uses residual consistency and reliability values as trigger values.
[0065] First, we define observational innovation (residual) as:
[0066] in, For the three-domain integrity observation; For observation functions; For observation function The Jacobian matrix is a 3×9 selection matrix. For a moment Prior state estimation.
[0067] Define innovation covariance as:
[0068] For a moment The prior noise covariance matrix; For a moment The observation noise covariance matrix.
[0069] The chi-square statistic of residual consistency is defined as follows:
[0070] when A large value indicates a discrepancy between observation and prediction, suggesting an anomaly risk.
[0071] 23c) Define anomaly indicator variables based on the chi-square statistic of reliability and residual consistency.
[0072] Specifically, according to the description in step 23a), the system reliability is... The smaller the value, the further the system's predicted trajectory deviates from the safety baseline. To avoid over-parameter tuning caused solely by noise spikes, a combined triggering mechanism of statistical anomalies and reliability degradation is employed.
[0073] Therefore, define the exception indicator variable. for:
[0074] In the formula, significance level Down, degrees of freedom The chi-square threshold; This is the lower limit threshold for reliability. Since the observation dimension of this invention is 3, it is typically taken as... .
[0075] like If it is continuous, it is considered an anomaly in this instance; if it is continuous... Second-rate This is considered a persistent anomaly. A strong trigger is only applied when both statistical anomalies and low reliability occur simultaneously, to avoid over-parameter tuning due to single-point noise.
[0076] 23d) If continuous Second-rate The system is determined to be continuously abnormal, and the noise parameters are scaled according to the system scenario using the Sage-Husa adaptive basis and power step size.
[0077] First, after each update, a sliding method is used to match innovations based on the Sage–Husa adaptive basis to obtain an unscaled process noise covariance estimate. Covariance estimation of observation noise The expression is:
[0078]
[0079] in, To bring the process uncertainty closer to the residual energy back through the Kalman gain; Use the difference between innovation and prediction covariance to calibrate observation noise. If As the value increases, the weight of new evidence rises, leading to faster convergence. A smaller value results in smoother, more robust Q / R estimates, which are also more resistant to occasional noise. This step provides a mild, statistically consistent Q / R estimate, serving as a baseline for the next step of accelerated scaling.
[0080] Then, to ensure rapid response in the early stages of anomalies and automatic convergence in later stages, two multiplication step sizes are designed, the size of which is equal to the power of the previous step: ; Then use reliability modulation of the effective step size:
[0081] Decreasing step size exponentially allows for adjustments that start large and then decrease, avoiding oscillations; multiplying by Make the step size larger as the reliability increases. If reduce, Enlarging increases sensitivity more quickly, while decreasing it automatically slows down and stabilizes the system, thus naturally linking reaction speed with reliability.
[0082] Finally, the noise parameters are scaled according to the system scenario.
[0083] like And continuously exceeding the threshold If the system determines that the anomaly is continuous, then the scaling formula for the noise parameter is:
[0084] In the formula, To Perform feature decomposition. For a moment Scaled process noise covariance matrix For a moment Scaled observation noise covariance matrix, and These are the process noise covariance estimates and observation noise covariance estimates obtained based on the Sage–Husa adaptive basis, respectively. and These are the scaling steps for the process noise covariance and the observation noise covariance, respectively, obtained based on the power-law step size; When the system determines a persistent anomaly, increase... I believe the situation may change rapidly, so I will appropriately reduce... Let the gain be more dependent on re-observation; if If the value increases, it becomes less reliable, so the amplification / contraction range is increased to achieve a rapid response to anomalies.
[0085] If the system is deemed normal, the scaling formula for the noise parameter is:
[0086] When the system determines that it is normal, reduce To make the model smoother and moderately increase Make the filter more robust to occasional observation noise; if Increase (system trust). As the size decreases, the adjustment slows down, achieving a smooth convergence.
[0087] Furthermore, consider the gain. relation: ; like Decrease, the denominator becomes smaller. If the value increases, it becomes more reliant on observation for rapid correction; if Increase As it rises, It may also rise, making it more sensitive to new information; conversely, a recovery branch... Decrease Enlargement will lead to This reduces the noise and makes the estimation smoother and more resistant to noise.
[0088] Since this invention mainly reflects the unknown attack trend in the three-domain acceleration components Therefore, during implementation, it is possible to... The acceleration is adjusted to assign higher scaling weights to the diagonal elements to enhance sensitivity to rapid advances of unknown attacks.
[0089] 23e) If or The smallest eigenvalue is less than If so, then projection correction will be performed.
[0090] Furthermore, to avoid numerical divergence and matrix nondefiniteness, if or The smallest eigenvalue is less than the numerical stability term. Then perform projection correction: ; in , To Perform eigenvalue decomposition Clip the eigenvalues to Post-reconstruction ensures positive semi-definiteness and amplitude boundaries. Covariance updates employ the Joseph form to ensure finite accuracy. Its symmetry and positive semidefiniteness are more robust. If it enters a persistent anomaly and then returns to normal and persists... Next, Reset to the initial value, such as (Scale), to avoid long-term anomalies causing the step size to be too small, which would affect the rapid response to the next anomaly.
[0091] 23f) According to the adaptive rule and Perform adaptive updates using the following formula:
[0092] In the formula, and These represent the adaptive update smoothing coefficients of the process noise covariance matrix and the observation noise covariance matrix, respectively. and They are time points Scaled process noise covariance matrix and observation noise covariance matrix.
[0093] like rise, reduce: Increase Rising rapidly By appropriately lowering the gain, the response speed is increased, achieving the effect of timely detection of anomalies; like pullback Recovery: Get smaller decline, The gain is increased, the estimation is smoothed, and steady-state convergence and noise reduction are achieved.
[0094] In summary, this embodiment addresses the common problems of existing technologies in complex and noisy environments, such as fixed thresholds / parameters, sensitivity to sudden fluctuations, susceptibility to false alarms and false negatives, and the need for frequent manual parameter tuning. It proposes an adaptive Kalman filtering and attack detection method. See [link to relevant documentation]. Figure 2, Figure 2 This is a framework diagram for adaptive Kalman filter attack prediction provided in an embodiment of the present invention. The method first extracts multidimensional observations from the process domain, network domain, and file domain, and constructs a three-domain integrity observation vector. This leads to the establishment of a state-space model for prediction and updating; and the introduction of Sage-Husa adaptive estimation during the filtering process to address process noise. With observation noise Online correction is implemented, combined with power-law step scaling to adaptively track changes in noise intensity and uncertainty. In the discrimination phase, residual statistics are constructed using innovative residuals and chi-square consistency tests, and combined with reliability... The gating mechanism constrains abnormal triggering, thereby maintaining the stability of the discrimination boundary under strong noise and sudden disturbances.
[0095] This method not only suppresses the interference of benign spikes on detection results under noisy conditions such as network jitter, load fluctuation, and missing logs, significantly reducing false positives and false negatives, but also supports online self-calibration and long-term stable operation of changes in noise statistical characteristics, such as Joseph form covariance updates and numerical stability constraints. This reduces the cost of manual threshold maintenance and repeated parameter tuning, and provides more stable and interpretable residuals and confidence basis for subsequent unknown attack analysis, thereby improving detection efficiency and reducing deployment and maintenance costs as a whole.
[0096] Step 3: Perform forward residual back-calculation based on system state estimation to achieve unknown attack increment prediction and obtain attack prediction results.
[0097] 31) Based on system state estimation, forward prediction is performed through the state propagation function to generate a forward state prediction sequence for the next N steps, and the reliability values of each node of the system host are obtained.
[0098] Specifically, by solving the Kalman estimation problem in step 2, we can achieve the prediction of the future of nodes. Forward prediction and uncertainty propagation of steps to obtain time Host node reliability .in, Representing the host diagram One of the main units, side This represents the communication or service dependencies between hosts. We assume that attackers tend to target the most vulnerable bridge points in the network, therefore we use weak node centrality as the structural basis for attack detection. Given nodes with low "reliability," we perform a local expansion search in the cluster graph centered on that node. The weak node scores are calculated using residual statistics and coupled with anomaly strength to form the final judgment. Attack judgment mainly consists of two parts: weak node calculation and anomaly memory fusion judgment with multiple nodes.
[0099] 32) Using each node of the host as the center, adaptively calculate the search radius, perform weak node search and identification in the system host graph, and calculate the weak node centrality to obtain the normalized weak node centrality value.
[0100] Specifically, optimal percolation theory reveals that low-degree nodes, which act as "bridges" between "hubs," are the true key to dismantling a network. Removing a "weak node" can simultaneously sever connections between multiple "hubs," creating a massive chain reaction. Therefore, this embodiment assumes that attackers tend to target this point.
[0101] In this embodiment, weak node calculation includes three parts: local search radius adaptation, collective influence of the sphere front, and weak node centrality with low degree penalty, as detailed below: 32a) Adaptive calculation of search radius .
[0102] Let the sampling period be Forward gaze duration Let the average lag of "event correlation" between adjacent nodes be . Then the node search radius Pick:
[0103] In the formula, , A host node in the host graph Reliability value, To preset a reliability threshold, and .
[0104] 32b) In the system host diagram, with nodes Centered on, with Using the search radius, a weak node search is performed to obtain the weak nodes of the unweighted undirected graph. Weak nodes in a weighted directed graph .
[0105] Specifically, for complex network scenarios, considering both unauthorized and authorized cases, in the host graph... In China, with Center, radius The ball is Its frontier is .
[0106] For an unweighted undirected graph, the degree of each node is denoted as . ,but:
[0107] For a weighted directed graph ,but:
[0108] 32c) weak nodes and Centrality and normalization are performed to obtain normalized weak node centrality values.
[0109] Specifically, this embodiment introduces a low-penalty parameter. We then perform weak node and normalization processing.
[0110] For unweighted and undirected graphs:
[0111] For weighted directed graphs:
[0112] When comparing across nodes, perform extreme value normalization:
[0113] Thus, the normalized weak node centrality values are obtained.
[0114] 33) Maintain an anomalous memory state for each host node, combine the normalized weak node centrality value and the anomalous memory, calculate the instantaneous evidence strength of the weak node, and aggregate neighborhood information to obtain the comprehensive attack score.
[0115] 33a) For each host node Maintain an abnormal memory state .
[0116] Understandably, each host node The abnormal memory state is updated step by step, that is:
[0117] in, Forgetting factor (evaporation rate) ), Pick Forward gaze duration , As weight; To innovate residuals; , Use residual scaling to suppress extreme values; ( ) is the neighborhood decay kernel, It is the shortest path. After calculation and projection, we get: .
[0118] When the reliability of the machine decreases Increased size, abnormal residual size: When the number of host computers increases and the reliability of multiple host computers in the same neighborhood also decreases, the number of abnormal memories will accumulate and increase.
[0119] 33b) Define the instantaneous strength of evidence for a node Its expression is:
[0120] In the formula, For nodes Reliability value; Indicates the weighting coefficient. This represents the residual weighting coefficient.
[0121] 33c) For any node In adaptive radius Inner convergence neighborhood evidence , denoted as:
[0122] In the formula, Indicates Centered on, with A sphere of radius; express, For neighborhood decay kernels, ; For the shortest path; Represents a node The strength of immediate evidence.
[0123] 33d) Integrating weak node centrality values and instantaneous evidence strength and aggregated neighborhood evidence The overall attack score is obtained and recorded as:
[0124] In the formula, This represents the normalized centrality value of weak nodes.
[0125] Understandable, Strengthen the influence of low-severity bridge nodes; when local and neighboring anomalies persist, It rises naturally over time. This represents the weighting coefficient.
[0126] 34) Use time-varying thresholds to determine the comprehensive attack score and output the probabilistic result.
[0127] 34a) Set a time-varying threshold that is adaptively updated based on the score distribution of recent normal windows. , represented as: ; In the formula, Update the weight coefficients for the threshold; Under the recent normal window The 95th percentile represents the 95th percentile under normal circumstances. The values are all lower than this value; Indicates the previous moment The time-varying threshold.
[0128] 34b) If the overall attack score of the current node is greater than or equal to the time-varying threshold, then the node is determined to be under attack.
[0129] Specifically, the judgment rule can be expressed by the formula:
[0130] 34c) Use a smoothing mapping to map the overall attack score of nodes identified as being attacked to an attack probability, and output the attack determination result and the attack probability; wherein, the formula for calculating the attack probability is:
[0131] In the formula, For nodes The probability of being attacked. This indicates the control slope.
[0132] In summary, this embodiment proposes a forward residual inference and attack prediction method for scenarios with scarce evidence. Please refer to [link to relevant documentation]. Figure 3 , Figure 3 This is a flowchart of the forward residual back-calculation and adaptive update provided in an embodiment of the present invention, which involves three-domain observations. After normalization and alignment, the state integrity index is calculated. Subsequently, risk state and dynamic equations are constructed, and the state evolution function is used to... Perform prior prediction to obtain This characterizes the dynamic evolution of risk over time. Based on this, the forward residual is calculated. It achieves reverse-engineering anomaly triggering against early, evidence-scarce attacks by measuring the trend and cumulative deviation of residuals; at the same time, it enables an adaptive update module to adjust noise parameters online based on the statistical characteristics of residuals. And combined with abnormal memories Historical anomaly patterns are preserved to achieve robust adaptation to complex and noisy environments. Finally, in the attack prediction phase, weak node centrality is considered. Strength of local evidence Aggregating evidence with neighboring regions Weighted fusion is performed to form an entity-level attack prediction score.
[0133] This method not only enables earlier warnings through trend prediction and confidence region calculation in cases of insufficient evidence and fragmented behavior, increasing the lead time for attack detection, but also accumulates and amplifies low-frequency, latent, and phased-evolving abnormal clues and automatically decays them during the recovery period, reducing the risk of missed detection due to scarce evidence. At the same time, it can output probabilistic risk results and actionable guidelines such as arrival time windows, reducing the time and resource costs caused by manual investigation and delayed response, and improving the foresight and business availability of threat analysis.
[0134] Step 4: Estimate the time window based on the system state estimation and attack prediction results to achieve attack early warning.
[0135] Specifically, based on the forward-looking state prediction sequence and its reliability value Estimate the possible time window for an attack. Among them, among them, Represents a node At any moment Given the future, the first... The prior prediction state of the step, Represents a node The first prediction formula obtained by rolling the prior noise covariance matrix. Prior prediction of covariance, node The future The reliability value of the step, for and represent the earliest arrival time and the latest arrival time of the attack, respectively. The expression is: ;
[0136]
[0137] In the formula, Sampling time, The sampling period is The forward step size that triggers the attack earliest. For unsafe domains, As a reliability threshold, For additional forward stride, The symbol is a probability symbol, representing the probability of the event within the parentheses occurring. For confidence level, Represents a node At any moment Given the future, the first... The prior prediction state of the step.
[0138] This invention constructs a confidence ellipsoid for future time moments by rolling propagation of the covariance of the forward-looking predicted state, and uses the probability of entering the unsafe region as the attack occurrence criterion, thereby achieving a probabilistic and interval-based description of attack risk. By utilizing the earliest and latest times when the forward-looking predicted sequence enters the unsafe region at the confidence level, the attack arrival time window is calculated, thus providing a time basis for advance deployment and resource pre-positioning of the defense system. The attack risk probability is continuously output through a smoothing mapping function, avoiding the jitter caused by hard threshold judgment, thereby improving the continuity and interpretability of the risk assessment results on the time axis.
[0139] In summary, this invention addresses the shortcomings of traditional technologies in discriminating between different threats in complex and noisy environments and in predicting attacks under conditions of scarce evidence. It proposes a dynamic prediction method for unknown attacks based on adaptive Kalman filtering, aiming to enable the system to stably and accurately identify potential threats and provide early risk warnings even in situations with incomplete information and noise. By constructing a collaborative framework integrating "automatic adjustment, trend prediction, and intelligent decision-making," the security system can achieve higher prediction accuracy, stronger robustness, and faster response speed. Specifically, this invention proposes, on the one hand, an adaptive Kalman filtering and attack discrimination mechanism for complex and noisy environments. Through real-time estimation and dynamic parameter tuning, it achieves adaptive updates of Kalman gain and related parameters, enabling interpretable differentiation between abnormal and attack behaviors. This ensures high signal-to-noise ratio state estimation and stable category boundaries even under chaotic and complex noise conditions, reducing false alarm / false negative rates and maintaining system stability under fluctuating noise levels, thus improving attack identification capabilities. On the other hand, it proposes forward residual back-calculation and attack prediction for scenarios with scarce evidence. Based on consistency checks, it back-calculates residual dynamics and propagates uncertainty constraints, outputting attack detection results and attack arrival time windows. This transforms early signs with insufficient evidence but significant trends into actionable pre-set actions, achieving forward-looking judgment and resource pre-deployment guidance, increasing early warning lead time and arrival window coverage, and reducing closed-loop processing latency and maintenance costs.
[0140] Based on the same inventive concept, a second aspect of this invention also provides a dynamic prediction system for unknown attacks based on adaptive Kalman filtering, used to implement the method provided in the first aspect of this invention. Please refer to... Figure 4 , Figure 4 This is a structural block diagram of an unknown attack dynamic prediction system based on adaptive Kalman filtering provided in an embodiment of the present invention. The system includes: The multi-source data acquisition unit is used to observe the system status in real time based on multi-domain data sources, and to obtain multi-domain integrity observations based on the obtained multi-domain observations. The adaptive Kalman filter unit is used to perform adaptive Kalman filtering on multi-domain integrity observations, including real-time state prediction, observation updates and adaptive adjustment of noise parameters, to obtain system state estimates. The attack prediction unit is used to perform forward residual back-calculation based on system state estimation in order to predict unknown attack increments and obtain attack prediction results. The attack warning unit is used to estimate the time window based on system state estimation and attack prediction results, thereby enabling attack warning.
[0141] The system provided by this invention is applicable to multi-device converged cyber-physical system scenarios, such as smart grids and industrial control systems. In these scenarios, attackers may launch unknown attacks through data tampering or control commands, such as spoofed data injection attacks, causing observed data to deviate from the normal model. This invention targets key state vectors to perceive and predict system states and unknown attacks under conditions of complex noise, scarce evidence, and cross-domain latency. By fusing measurement data from multiple levels, it estimates the dynamic evolution of the system state in real time and predicts the evolution trend of potential attacks, thereby improving system security and stability.
[0142] It should be noted that the system implementation is basically similar to the method implementation, so the description is relatively simple. For relevant details, please refer to the description in the method implementation. Therefore, the above-mentioned dynamic prediction system for unknown attacks based on adaptive Kalman filtering can achieve early prediction of unknown attacks, identification of key nodes, and automatic generation of handling priorities under conditions of complex and noisy environments, incomplete observations, and scarce attack evidence. This significantly improves the initiative, stability, and interpretability of the network security defense system.
[0143] The above description, in conjunction with specific preferred embodiments, provides a further detailed explanation of the present invention. It should not be construed that the specific implementation of the present invention is limited to these descriptions. For those skilled in the art, various simple deductions or substitutions can be made without departing from the concept of the present invention, and all such modifications and substitutions should be considered within the scope of protection of the present invention.
Claims
1. A method for dynamic prediction of unknown attacks based on adaptive Kalman filtering, characterized in that, include: Step 1: Observe the system status in real time based on multi-domain data sources, and obtain multi-domain integrity observations based on the obtained multi-domain observations; Step 2: Perform adaptive Kalman filtering on the multi-domain integrity observations, including real-time state prediction, observation updates, and adaptive adjustment of noise parameters, to obtain a system state estimate; Step 3: Perform forward residual back-calculation based on the system state estimation to achieve unknown attack increment prediction and obtain attack prediction results; Step 4: Based on the system state estimation and the attack prediction results, perform time window estimation to achieve attack early warning.
2. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 1, characterized in that, Step 2 includes: 21) Based on the system's previous state estimate and nonlinear state propagation function, predict the prior state estimate and prior noise covariance matrix; 22) Based on the Kalman gain and combined with the multi-domain integrity observation, the prior state estimate is updated by observation to obtain the posterior optimal state estimate and the posterior noise covariance matrix. 23) Reliability and residual consistency are used as anomaly triggering constraints, and when an anomaly is determined, Sage-Husa online estimation and power step size scaling are used to dynamically and adaptively adjust the noise parameters; wherein, the noise parameters include the process noise covariance matrix and the observation noise covariance matrix.
3. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 2, characterized in that, In step 21), the prediction formula for the prior state estimation is: ; In the formula, For a moment Prior state estimation, For nonlinear state propagation functions, For a moment The posterior optimal estimate, This is process noise; The prediction formula for the prior noise covariance matrix is: ; In the formula, For a moment The prior noise covariance matrix; For a moment The posterior noise covariance matrix; Nonlinear state propagation function Jacobian matrix, For a moment -1 is the process noise covariance matrix.
4. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 2, characterized in that, Step 22) includes: 22a) Calculate the Kalman gain based on the prior noise covariance matrix. The calculation formula is as follows: ; In the formula, For a moment Kalman gain; For a moment The prior noise covariance matrix; For a moment The observation noise covariance matrix; For observation function Jacobian matrix; 22b) Calculate the optimal estimate for the current time step based on the Kalman gain and the multi-domain integrity observation, and obtain the posterior optimal state estimate. The calculation formula is as follows: ; In the formula, For a moment The posterior optimal state estimate; For a moment Prior state estimation; For a moment Three-domain integrity observation; The predicted observations are mapped from the prior state to the observation space. 22c) Update the current optimal estimated noise covariance matrix based on the Kalman gain and the prior noise covariance to obtain the posterior noise covariance matrix, expressed by the formula: ; In the formula, For a moment The posterior noise covariance matrix; It is an identity matrix.
5. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 2, characterized in that, Step 23) includes: 23a) Calculate the system reliability value using the following formula: ; In the formula, For a moment The system reliability value; The scaling factor controls the rate at which distance decays to the reliability value; This is set as the upper limit of the distance truncation to suppress the excessive influence of extreme outliers on the reliability value; For the first The state deviation distance for each forward look step is expressed as: ; Indicates at time Given the future, the first... The prior prediction state of the step, The baseline constant vector; The weight matrix is expressed as follows: ; The first prediction formula obtained by rolling the prior noise covariance matrix is... Predicting covariance using priors; It is a numerically stable term; It is the identity matrix; 23b) Define the chi-square statistic of residual consistency. Its expression is: In the formula, Its expression is: For the three-domain integrity observation, For observation functions; For observation function Jacobian matrix; For a moment Prior state estimation; To innovate the covariance, its expression is: For observation function Jacobian matrix; For a moment The prior noise covariance matrix; For a moment The observation noise covariance matrix; 23c) Define an anomaly indicator variable based on the reliability and the chi-square statistic of residual consistency, denoted as Its expression is: In the formula, significance level Down, degrees of freedom The chi-square threshold; This is the lower limit threshold for reliability. 23d) If continuous Second-rate The system was determined to be continuously abnormal, and the noise parameters were scaled according to the system scenario using the Sage-Husa adaptive basis formula and power-law step size. If the system determines that the anomaly is continuous, the scaling formula for the noise parameter is: If the system is deemed normal, the scaling formula for the noise parameter is: In the formula, For eigenvalue decomposition operation, For a moment Scaled process noise covariance matrix For a moment Scaled observation noise covariance matrix, and These are the process noise covariance estimates and observation noise covariance estimates obtained based on the Sage–Husa adaptive basis, respectively. and These are the scaling steps for the process noise covariance and the observation noise covariance, respectively, obtained based on the power-law step size; 23e) If or The smallest eigenvalue is less than Then, projection correction is performed, i.e. ; 23f) According to the adaptive rule and Perform adaptive updates using the following formula: In the formula, and Let these represent the adaptive update smoothing coefficients of the process noise covariance matrix and the observation noise covariance matrix, respectively. For a moment The prior noise covariance matrix, For a moment Kalman gain, For observation function Jacobian matrix; and They are time points Scaled process noise covariance matrix and observation noise covariance matrix.
6. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 1, characterized in that, Step 3 includes: 31) Based on the system state estimation, forward prediction is performed through the state propagation function to generate a forward state prediction sequence for the next N steps, and the reliability values of each node of the system host are obtained. 32) Using each node of the host as the center, adaptively calculate the search radius, perform weak node search and identification in the system host graph, and calculate the weak node centrality to obtain the normalized weak node centrality value. 33) Maintain an abnormal memory state for each host node, combine the normalized weak node centrality value and the abnormal memory, calculate the instantaneous evidence strength of the weak node, and aggregate neighborhood information to obtain the comprehensive attack score. 34) Use a time-varying threshold to determine the comprehensive attack score and output the probabilistic result.
7. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 6, characterized in that, Step 33) includes: 33a) For each host node Maintain an abnormal memory state ; 33b) Define the instantaneous strength of evidence for a node Its expression is: In the formula, For nodes Reliability value; Indicates the weighting coefficient. Represents the residual weighting coefficient. , For residuals, To innovate residuals; 33c) For any node In adaptive radius Inner convergence neighborhood evidence , denoted as: In the formula, Represented by node Centered on, with A spherical region with radius [missing information]; For neighborhood decay kernels, ; For the shortest path; Represents a node The immediate strength of evidence; 33d) Integrate the weak node centrality value and the instantaneous evidence strength. and aggregated neighborhood evidence The overall attack score is obtained and recorded as: In the formula, For nodes The overall attack score, To normalize the centrality values of weak nodes, This represents the weighting coefficient.
8. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 7, characterized in that, Step 34) includes: 34a) Set a time-varying threshold that is adaptively updated based on the score distribution of recent normal windows. , represented as: ; In the formula, Update the weight coefficients for the threshold; Under the recent normal window The 95th percentile represents the 95th percentile under normal circumstances. The values are all lower than this value; Indicates the previous moment The time-varying threshold; 34b) If the overall attack score of the current node is greater than or equal to the time-varying threshold, then the node is determined to have been attacked; 34c) Use a smooth mapping to map the comprehensive attack score of nodes identified as being attacked to an attack probability, and output the attack determination result and the attack probability; wherein, the formula for calculating the attack probability is: In the formula, For nodes The probability of being attacked. This indicates the control slope.
9. The method for dynamic prediction of unknown attacks based on adaptive Kalman filtering according to claim 6, characterized in that, Step 4 includes: Prediction sequence based on forward-looking state and its reliability value Estimate the possible time window for an attack. ;in, Represents a node At any moment Given the future, the first... The prior prediction state of the step, Represents a node The first prediction formula obtained by rolling the prior noise covariance matrix. Prior prediction of covariance, node The future The reliability value of the step, for and represent the earliest arrival time and the latest arrival time of the attack, respectively. The expression is: ; In the formula, Sampling time, The sampling period is The forward step size that triggers the attack earliest. For unsafe domains, As a reliability threshold, For additional forward stride, The symbol is a probability symbol, representing the probability of the event within the parentheses occurring. For confidence level, Represents a node At any moment Given the future, the first... The prior prediction state of the step.
10. A dynamic prediction system for unknown attacks based on adaptive Kalman filtering, used to implement the method as described in any one of claims 1-9, characterized in that, The system includes: The multi-source data acquisition unit is used to observe the system status in real time based on multi-domain data sources, and to obtain multi-domain integrity observations based on the obtained multi-domain observations. An adaptive Kalman filter unit is used to perform adaptive Kalman filtering on the multi-domain integrity observations, including real-time state prediction, observation update and adaptive adjustment of noise parameters, to obtain a system state estimate. The attack prediction unit is used to perform forward residual back-calculation based on the system state estimation to achieve unknown attack increment prediction and obtain attack prediction results. An attack warning unit is used to estimate a time window based on the system state estimate and the attack prediction result to achieve attack warning.