Intrusion detection device and method

By automatically analyzing network threat intelligence through a hybrid decision-making model and an intelligence detection model, and combining it with intelligence platform scoring, the high cost and insufficient detection caused by manually set rules in existing technologies are solved, achieving efficient and accurate intrusion detection.

CN122268607APending Publication Date: 2026-06-23HON HAI PRECISION INDUSTRY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HON HAI PRECISION INDUSTRY CO LTD
Filing Date
2025-09-01
Publication Date
2026-06-23

Smart Images

  • Figure CN122268607A_ABST
    Figure CN122268607A_ABST
Patent Text Reader

Abstract

An intrusion detection device and method. The intrusion detection device transmits a network packet to a hybrid decision model to generate a detection result corresponding to the network packet. The intrusion detection device, in response to the detection result corresponding to an abnormal state, obtains feedback corresponding to target information in the network packet based on the target information. The intrusion detection device transmits the feedback to an emotion information detection model to update the detection result corresponding to the network packet. The intrusion detection technology provided by the present application increases the accuracy of intrusion detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an intrusion detection device and control method. Specifically, this invention relates to an intrusion detection device and control method capable of detecting malicious intrusion network packets and automatically training a detection model. Background Technology

[0002] In recent years, the demand for intrusion detection systems (IDS) to detect intrusions into network packets has been increasing in the field of information security. In existing technologies, the detection rules of IDS are based on manual analysis of Cyber ​​Threat Intelligence (CTI) and are manually set (e.g., blacklisting malicious Indicators of Attack (IoC)).

[0003] However, in such cases, manual maintenance requires a large amount of manpower, and attackers can easily circumvent manually set rules to update the intrusion detection system, and the intrusion detection system cannot detect new types of network attacks.

[0004] In view of this, the industry urgently needs to develop an intrusion detection device and method that can automatically analyze network threat intelligence without the need for manual rule setting and effectively detect malicious network packets. Summary of the Invention

[0005] One object of the present invention is to provide an intrusion detection device, comprising a transceiver interface, a memory, and a processor. The transceiver interface is used to receive network packets containing target information, and the memory is used to store a hybrid decision model and an intelligence detection model. The processor is electrically connected to the transceiver interface and the memory. The processor transmits the network packets to the hybrid decision model to generate a detection result corresponding to the network packets. In response to the detection result corresponding to an abnormal state, the processor obtains feedback corresponding to the target information in the network packets. The processor transmits the feedback to the intelligence detection model to update the detection result corresponding to the network packets.

[0006] In one embodiment of the present invention, the detection result is one of a benign state, a malignant state, and an abnormal state.

[0007] In one embodiment of the present invention, the hybrid decision model includes a supervised detection sub-model and an unsupervised detection sub-model, and the operation of generating the detection result corresponding to the network packet further includes the following operations: transmitting the network packet to the supervised detection sub-model to generate a first detection result; transmitting the network packet to the unsupervised detection sub-model to generate a second detection result; and comparing the first detection result and the second detection result to generate the detection result.

[0008] In one embodiment of the present invention, the operation of the transceiver interface communicating with the information platform and obtaining the feedback corresponding to the target information further includes the following operations: transmitting the target information in the network packet to the information platform; and receiving the feedback corresponding to the target information from the information platform, wherein the feedback is generated by the information platform.

[0009] In one embodiment of the present invention, the operation of updating the detection result corresponding to the network packet further includes the following operation: in response to the information detection model being activated, transmitting the feedback to the information detection model to update the detection result corresponding to the network packet.

[0010] In one embodiment of the present invention, the intelligence detection model is trained based on the following operation: in response to obtaining feedback corresponding to the target information, adding the feedback corresponding to the target information to the feedback set; and training the intelligence detection model based on the feedback set.

[0011] In one embodiment of the present invention, the operation of training the intelligence detection model further includes the following operation: in response to the feedback set meeting the feedback training criteria, training the intelligence detection model based on the feedback set.

[0012] In one embodiment of the invention, the hybrid decision model is trained based on the following operations: in response to updating the detection result corresponding to the network packet, determining at least one target historical network packet corresponding to the target information from a plurality of historical network packets containing a plurality of historical target information; updating the historical detection results of each of the at least one target historical network packet based on the detection result corresponding to the network packet; and training the hybrid decision model based on the updated at least one target historical network packet corresponding to the target information.

[0013] In one embodiment of the present invention, the operation of training the hybrid decision model further includes the following operations: adding the updated target historical network packet corresponding to the target information to the network packet set; and training the hybrid decision model based on the network packet set.

[0014] In one embodiment of the present invention, the operation of training the hybrid decision model further includes the following operation: in response to the network packet set conforming to the packet training criteria, training the hybrid decision model based on the network packet set.

[0015] Another object of the present invention is to provide an intrusion detection method for an electronic device, wherein the electronic device receives a network packet containing target information, and the electronic device stores a hybrid decision model and an intelligence detection model. The intrusion detection method includes the following steps: transmitting the network packet to the hybrid decision model to generate a detection result corresponding to the network packet; in response to the detection result corresponding to an abnormal state, obtaining feedback corresponding to the target information in the network packet; and transmitting the feedback to the intelligence detection model to update the detection result corresponding to the network packet.

[0016] In one embodiment of the present invention, the detection result is one of a benign state, a malignant state, and an abnormal state.

[0017] In one embodiment of the present invention, the hybrid decision model includes a supervised detection sub-model and an unsupervised detection sub-model, and the step of generating the detection result corresponding to the network packet further includes the following steps: transmitting the network packet to the supervised detection sub-model to generate a first detection result; transmitting the network packet to the unsupervised detection sub-model to generate a second detection result; and comparing the first detection result and the second detection result to generate the detection result.

[0018] In one embodiment of the present invention, the step of the electronic device being communicatively connected to an intelligence platform and obtaining feedback corresponding to the target information further includes the following steps: transmitting the target information in the network packet to the intelligence platform; and receiving feedback corresponding to the target information from the intelligence platform, wherein the feedback is generated by the intelligence platform.

[0019] In one embodiment of the present invention, the step of updating the detection result corresponding to the network packet further includes the following steps: in response to the information detection model being activated, transmitting the feedback to the information detection model to update the detection result corresponding to the network packet.

[0020] In one embodiment of the present invention, the intelligence detection model is trained based on the following steps: in response to obtaining feedback corresponding to the target information, adding the feedback corresponding to the target information to a feedback set; and training the intelligence detection model based on the feedback set.

[0021] In one embodiment of the present invention, the step of training the intelligence detection model further includes the following steps: in response to the feedback set meeting the feedback training criteria, training the intelligence detection model based on the feedback set.

[0022] In one embodiment of the present invention, the hybrid decision model is trained based on the following steps: in response to updating the detection result corresponding to the network packet, determining at least one target historical network packet corresponding to the target information from a plurality of historical network packets containing a plurality of historical target information; updating the historical detection results of each of the at least one target historical network packet based on the detection result corresponding to the network packet; and training the hybrid decision model based on the updated at least one target historical network packet corresponding to the target information.

[0023] In one embodiment of the present invention, the step of training the hybrid decision model further includes the following steps: adding the updated target historical network packet corresponding to the target information to the network packet set; and training the hybrid decision model based on the network packet set.

[0024] In one embodiment of the present invention, the step of training the hybrid decision model further includes the following steps: in response to the network packet set conforming to the packet training criteria, training the hybrid decision model based on the network packet set.

[0025] The intrusion detection technology (including at least an apparatus and a method) provided by this invention generates detection results for corresponding network packets through a hybrid decision model. Then, if the detection result corresponds to an abnormal state, this invention also obtains feedback on the target information within the network packet and further analyzes this feedback based on an intelligence detection model to update the detection result. Furthermore, this invention trains the hybrid decision model and the intelligence detection model through online learning. Therefore, the intrusion detection technology provided by this invention does not require manual rule setting, reducing the time cost of manual maintenance and increasing the accuracy of intrusion detection.

[0026] The following detailed description of the technology and embodiments of the present invention, in conjunction with the accompanying drawings, enables those skilled in the art to understand the technical features of the claimed invention. Attached Figure Description

[0027] Figure 1 This is a schematic diagram illustrating the architecture of the intrusion detection device according to the first embodiment;

[0028] Figure 2 To illustrate the intrusion detection operation flowchart of the first embodiment;

[0029] Figure 3 To depict a hybrid decision-making flowchart for certain implementation methods;

[0030] Figure 4A , Figure 4B This is a flowchart illustrating the training operation of an intelligence detection model in certain implementations;

[0031] Figure 5A , Figure 5B , Figure 5C To illustrate the training operation flowchart of a hybrid decision model in certain implementations;

[0032] Figure 6 To depict the intrusion detection architecture flowchart of certain implementations; and

[0033] Figure 7 This is a flowchart illustrating an intrusion detection method in certain implementations. Detailed Implementation

[0034] The intrusion detection device provided by the present invention will be explained below through embodiments. However, these embodiments are not intended to limit the implementation of the present invention to any environment, application, or manner described in these embodiments. Therefore, the description of the embodiments is for illustrative purposes only and is not intended to limit the scope of the present invention. It should be understood that in the following embodiments and drawings, elements not directly related to the present invention have been omitted and are not shown, and the dimensions of each element and the dimensional proportions between elements are merely illustrative and are not intended to limit the scope of the present invention.

[0035] The intrusion detection device of the present invention is used to detect the status of network packets, and the intrusion detection device can be installed in any system or platform that needs to receive network packets. For example, the intrusion detection device can be installed on a physical server of a webpage. When the physical server receives network packets, the intrusion detection device will first receive and analyze the network packets to detect their status. Only when the intrusion detection device determines that the network packet is benign will the packet be allowed to enter the physical server, thereby preventing the physical server and the webpage from being attacked by malicious traffic.

[0036] The intrusion detection device of the first embodiment of the present invention is shown in the schematic diagram. Figure 1 .like Figure 1 As shown, the intrusion detection device 1 includes a processor 11, a memory 12 and a transceiver interface 13, and the processor 11 is electrically connected to the memory 12 and the transceiver interface 13.

[0037] In this embodiment, the transceiver interface 13 is used to receive network packets corresponding to target information. For example, the network packet contains different information such as source IP address, destination IP address, source port number, and destination port number, and the target information can be any of the information contained in the network packet (e.g., source IP address and destination IP address).

[0038] In this embodiment, memory 12 is used to store a hybrid decision model (HDM) and an intelligence detection model (CDM). The HDM is a classification model that can detect the state of network packets (e.g., benign state, malicious state, abnormal state). The CDM is a classification model that can further analyze the feedback of corresponding target information and update the state of the network packet (e.g., update the abnormal state to a malicious state).

[0039] It should be noted that the Hybrid Decision Model (HDM) can generate multiple preliminary detection results (e.g., preliminary detection results generated by multiple detection sub-models in the HDM), and the final detection result is determined by the hybrid decision based on these preliminary detection results. The Intelligence Detection Model (CDM) can be an unsupervised classification model (e.g., K-means clustering model, K-means++ clustering model).

[0040] It should be noted that processor 11 may be various processing units, central processing units (CPUs), microprocessors, or other computing devices known to those skilled in the art to which this application pertains. Memory 12 may be a memory, a universal serial bus (USB), a hard disk, an optical disk, a USB flash drive, or any other storage medium or circuitry known to those skilled in the art to which this application pertains and having the same function. Transceiver interface 13 is an interface capable of receiving and transmitting data, or other interfaces capable of receiving and transmitting data known to those skilled in the art to which this application pertains. Transceiver interface 13 may receive data from sources such as external devices, external web pages, external applications, etc.

[0041] In this invention, the state of network packets is primarily detected using a hybrid decision model (HDM) and an intelligence detection model (CDM). The following paragraphs will describe in detail the implementation details related to this invention.

[0042] In the first embodiment, the intrusion detection device 1 receives network packets containing target information. For clarity, please refer to... Figure 2 Intrusion detection operation flowchart M2.

[0043] First, during operation S201, the intrusion detection device 1 transmits the network packet to the hybrid decision model (HDM). The HDM analyzes the network packet to generate a detection result corresponding to the network packet.

[0044] It should be noted that the detection result is used to indicate the status of the network packet. The intrusion detection device 1 can use the status of the detection result to determine whether the network packet poses a threat to the system or platform that this invention is intended to protect.

[0045] In some implementations, the detection result is one of a benign state, a malign state, and an abnormal state.

[0046] Next, in operation S203, the processor 11 determines whether the detection result corresponds to an abnormal state. If the result of operation S203 is yes, the processor 11 will execute operation S205; if the result of operation S203 is no, the processor 11 will not execute the operation.

[0047] Next, in operation S205, the processor 11 will obtain feedback corresponding to the target information based on the target information in the network packet.

[0048] Finally, in operation S207, the intrusion detection device 1 further analyzes the feedback using the Information Detection Model (CDM) to update the detection result corresponding to the network packet. Based on this, the intrusion detection device 1 can further determine whether the network packet poses a threat.

[0049] In some implementations, the Hybrid Decision Model (HDM) analyzes the network packets using different sub-models within the HDM. For clarity, please refer to [link to relevant documentation]. Figure 3 The Hybrid Decision Model (HDM) is illustrated in flowchart 300. This model also includes a supervised detection sub-model (SDSM) and an unsupervised detection sub-model (UDSM).

[0050] It should be noted that the supervised detection sub-model SDSM can be a supervised classification model (e.g., SVM). The unsupervised detection sub-model UDSM can be an unsupervised classification model (e.g., K-means clustering model).

[0051] First, the supervised detection sub-model SDSM will generate a first detection result R1 corresponding to the network packet, and the unsupervised detection sub-model UDSM will generate a second detection result R2 corresponding to the network packet.

[0052] It should be noted that the supervised detection sub-model SDSM can be trained using multiple training network packets and multiple training labels corresponding to those training network packets. Furthermore, since the unsupervised detection sub-model UDSM is an unsupervised model, it is trained solely using those training network packets.

[0053] Therefore, both the supervised detection sub-model SDSM and the unsupervised detection sub-model UDSM have the ability to classify the input network packets. Since the unsupervised detection sub-model UDSM is not trained using labels, the supervised detection sub-model SDSM has higher classification accuracy than the unsupervised detection sub-model UDSM.

[0054] Next, the present invention can perform hybrid decision-making through a hybrid decision table, comparing the first detection result R1 and the second detection result R2 to determine the detection result, and the hybrid decision-making is implemented through the following hybrid decision table:

[0055] decision making First detection result R1 Second detection result R2 Detection results A benign state benign state benign state B malignant state malignant state malignant state C malignant state benign state malignant state D benign state malignant state Abnormal state

[0056] In decision A, when the first detection result R1 corresponds to a benign state and the second detection result R2 also corresponds to a benign state, the detection result will correspond to a benign state.

[0057] In decision B, when the first detection result R1 corresponds to a malignant state and the second detection result R2 also corresponds to a malignant state, the detection result will correspond to a malignant state.

[0058] In decision C, when the first detection result R1 corresponds to a malignant state and the second detection result R2 corresponds to a benign state, the detection result will correspond to a malignant state.

[0059] It should be noted that, since the supervised detection sub-model SDSM has higher classification accuracy than the unsupervised detection sub-model UDSM, the hybrid decision will give priority to the first detection result R1.

[0060] In decision D, when the first detection result R1 corresponds to a benign state and the second detection result R2 corresponds to a malignant state, the detection result will correspond to an abnormal state.

[0061] It should be noted that since the second detection result R2 generated by the unsupervised detection sub-model UDSM corresponds to a malignant state, the first detection result R1 may be a false-positive classification result. In the above situation, the detection result of the hybrid decision will correspond to an anomalous state, and the network packet needs to be further analyzed to determine the state of the network packet.

[0062] Specifically, processor 11 transmits the network packet to the supervised detection sub-model SDSM to generate a first detection result R1. Next, processor 11 transmits the network packet to the unsupervised detection sub-model UDSM to generate a second detection result R2. Finally, processor 11 compares the first detection result R1 and the second detection result R2 to generate the final detection result.

[0063] In some embodiments, the transceiver interface 13 is also communicatively connected to an intelligence platform, and the intrusion detection device 1 can obtain feedback on the target information based on the intelligence platform.

[0064] It should be noted that this information platform is an open-source cybersecurity information platform. It stores multiple scores from different vendors for various source or destination IP addresses, with each score indicating the degree of a benign or malicious state. Furthermore, because the platform updates scores from different vendors in real time, it also stores scores corresponding to different historical points in time.

[0065] For example, the intrusion detection device 1 transmits a first source IP address (i.e., the target information) to the intelligence platform, and the intelligence platform manufacturer A provides 12 scores for the first source IP address over the past 12 months, and the intelligence platform manufacturer B provides 36 scores for the first source IP address over the past 36 months. The scores recorded by the above manufacturers at different points in time are all feedback to the target information in this invention.

[0066] It should be noted that the feedback can be a structured file provided by the intelligence platform, and the file format of the structured file can be JSON, YAML, or other file formats.

[0067] Next, since different vendors provide inconsistent feedback for the same source IP address, this invention uses a Detection Model (CDM) to analyze and classify the feedback corresponding to the target information. The CDM generates advanced detection results corresponding to this feedback to update the detection results, further updating network packets originally identified as belonging to an abnormal state to network packets belonging to a benign or malicious state.

[0068] Specifically, the processor 11 transmits the target information in the network packet to the intelligence platform. Then, the processor 11 receives feedback from the intelligence platform corresponding to the target information, wherein the feedback is generated by the intelligence platform.

[0069] In some implementations, the CDM (Cognitive Disclosure Model) needs to be in an active state to initiate the update of the detection results corresponding to the network packet. The active state indicates that the CDM has met the conditions for inference (e.g., having sufficient classification accuracy).

[0070] For example, if the intelligence detection model CDM is a K-means clustering model, the start-up state can be a condition such as "when the error value is less than the threshold" or "when the centroid position does not change in three consecutive updates", to indicate that the clustering model has sufficient classification accuracy.

[0071] Specifically, in response to the Information Detection Model (CDM) being activated, the processor 11 sends the feedback to the Information Detection Model (CDM) to update the detection result corresponding to the network packet.

[0072] In some embodiments, to improve the classification ability of the Information Detection Model (CDM), the present invention also trains the CDM simultaneously during the inference process through online learning. Accordingly, the CDM will continuously improve the accuracy of classifying different feedback.

[0073] For clarity, please refer to Figure 4A The training and operation flowchart of the intelligence detection model is M4_1.

[0074] First, in operation S401, the processor 11 determines whether the intrusion detection device 1 has received the feedback corresponding to the target information. If the result of operation S401 is yes, the processor 11 will execute operation S403; if the result of operation S401 is no, the processor 11 will not execute the operation.

[0075] Next, during operation S403, this feedback will be added to the feedback set. As the number of abnormal network packets detected by the intrusion detection device 1 increases, the number of different feedbacks corresponding to each target information stored in the feedback set also increases.

[0076] It should be noted that the feedback set may include multiple historical feedbacks, wherein such historical feedbacks are historical feedbacks corresponding to multiple historical target information that the intrusion detection device 1 has previously obtained.

[0077] Next, in operation S405, processor 11 will train the intelligence detection model CDM based on the feedback set.

[0078] For clarity, please refer to Figure 4B The training flowchart for the intelligence detection model is shown in M4_2. Since some operations are similar, the following description will only cover the differences.

[0079] First, following operation S403, in operation S404, processor 11 determines whether the feedback set meets the feedback training criteria. If the result of operation S404 is yes, processor 11 will execute operation S405; if the result of operation S404 is no, processor 11 will not execute the operation.

[0080] In some implementations, the feedback training criterion may include the number of feedbacks stored in the feedback set. For example, the feedback training criterion may be set to "the number of feedbacks stored in the feedback set is greater than 100", that is, when the number of feedbacks stored in the feedback set is greater than 100, the processor 11 will start training for the intelligence detection model CDM.

[0081] In some implementations, the feedback training criteria may include a time period. For example, the time period may be set to 12 hours, one day, one week, etc. Each time this time period elapses, the processor 11 will initiate training for the intelligence detection model CDM.

[0082] In some implementations, the feedback training criteria may include at least one or a combination of the number of feedbacks stored in the feedback set and the time period. For example, the feedback training criteria may be set to "the number of feedbacks stored in the feedback set is greater than 100", and the time period may be set to "12 hours". In other words, whenever 12 hours have elapsed and the number of feedbacks stored in the feedback set is greater than 100, the processor 11 will initiate training for the intelligence detection model CDM.

[0083] In some embodiments, to improve the classification capability of the Hybrid Decision Model (HDM), the present invention further trains the HDM during the inference process through online learning (i.e., trains the supervised detection sub-model SDSM and the unsupervised detection sub-model UDSM). Accordingly, the HDM will continuously improve the accuracy of classifying different network packets.

[0084] For clarity, please refer to Figure 5A The training and operation flowchart of the hybrid decision model is M5_1.

[0085] First, in operation S501, the processor 11 determines whether the intrusion detection device 1 has updated the detection result corresponding to the network packet. If the result of operation S501 is yes, the processor 11 will execute operation S503; if the result of operation S501 is no, the processor 11 will not execute the operation.

[0086] Next, in operation S503, the processor 11 determines at least one target historical network packet corresponding to the target information from multiple historical network packets containing multiple historical target information.

[0087] It should be noted that the historical network packets containing such historical target information are network packets that the intrusion detection device 1 has received and that have been detected by intrusion. Therefore, each of these historical network packets corresponds to a historical detection result (i.e., benign state or malicious state).

[0088] Next, in operation S505, the processor 11 updates the historical detection results of each of the at least one target historical network packets based on the detection results of the corresponding network packet.

[0089] For example, the first network packet contains a first source IP address (i.e., target information), and the intelligence detection model (CDM) determines that the first network packet corresponds to a malicious state. In other words, the first source IP address has the possibility of malicious intrusion. Therefore, the processor 11 searches for at least one target historical network packet corresponding to the first source IP address from the historical network packets.

[0090] Since the at least one target historical network packet may have been judged as benign by the intrusion detection device 1, the processor 11 updates the benign status of the at least one target historical network packet to a malign status (that is, updates the historical detection results of each of the at least one target historical network packet).

[0091] Conversely, the at least one target historical network packet may have been judged as malicious by the intrusion detection device 1, so the processor 11 updates the malicious status of the at least one target historical network packet to a benign status.

[0092] Finally, in operation S507, the processor 11 trains the hybrid decision model (HDM) based on the updated target historical network packet corresponding to the target information.

[0093] For clarity, please refer to Figure 5B The flowchart for training the hybrid decision model is shown in M5_2. Since some operations are similar, the following description will only focus on the differences.

[0094] First, following up on S505, in S506, the processor 11 adds the updated target historical network packet corresponding to the target information to the network packet set.

[0095] Next, in operation S509, processor 11 trains the hybrid decision model (HDM) based on the network packet set.

[0096] For clarity, please refer to Figure 5C The flowchart for the training operation of the hybrid decision model is shown in M5_3. Since some operations are similar, the following description will only focus on the differences in operation.

[0097] First, following operation S506, in operation S508, processor 11 will determine whether the network packet set conforms to the packet training standard. If the result of operation S508 is yes, processor 11 will execute operation S509; if the result of operation S508 is no, processor 11 will not execute the operation.

[0098] In some implementations, the packet training criterion may include the number of network packets stored in the network packet set. For example, the packet training criterion may be set to "the number of network packets stored in the network packet set is greater than 100", that is, when the number of network packets stored in the network packet set is greater than 100, the processor 11 will start training for the hybrid decision model (HDM).

[0099] In some implementations, the packet training criteria may include a time period. For example, the time period may be set to 12 hours, one day, one week, etc. At the end of each time period, the processor 11 will initiate training for the hybrid decision model (HDM).

[0100] In some implementations, the packet training criteria may include the number of network packets stored in the network packet set, the time period, or at least one or a combination thereof. For example, the packet training criterion may be set to "the number of feedbacks stored in the network packet set is greater than 100", and the time period may be set to "12 hours". In other words, whenever 12 hours have elapsed and the number of network packets stored in the network packet set is greater than 100, the processor 11 will initiate training for the Hybrid Decision Model (HDM).

[0101] Accordingly, the processor 11 can re-label previously misclassified network packets and input them into the Hybrid Decision Model (HDM) for training, thereby improving the model's classification ability. Through the above implementation method, when the intrusion detection device 1 subsequently detects similar network packets, the intrusion detection device 1 can more accurately identify potential threats, thereby improving the overall security protection effect.

[0102] Finally, this implementation method can be divided into an intrusion detection block and an intelligence transmission block. For clarity, please refer to [link / reference]. Figure 6 Intrusion detection architecture flowchart 600.

[0103] First, in the intrusion detection block, the Hybrid Decision Model (HDM) is mainly used to detect intrusions in network packets containing target information in order to generate detection results.

[0104] Next, in the information delivery block, the feedback corresponding to the target information is analyzed primarily through the Information Detection Model (CDM), and the original detection results are updated. The CDM is also trained based on the feedback set. Furthermore, the information delivery block also performs the following steps: determining the target's historical network packets from historical network packets, updating the target's historical network packets, and training the Hybrid Decision Model (HDM) using either the target's historical network packets or a set of network packets.

[0105] As described above, the intrusion detection device 1 provided by this invention generates detection results for corresponding network packets through a hybrid decision model. Then, if the detection result corresponds to an abnormal state, this invention also obtains feedback on the target information within the corresponding network packet and further analyzes this feedback based on the intelligence detection model to update the detection result. Furthermore, this invention trains the hybrid decision model and the intelligence detection model through online learning. Therefore, the intrusion detection device 1 provided by this invention does not require manual rule setting, reducing the time cost of manual maintenance and increasing the accuracy of intrusion detection.

[0106] The second embodiment of the present invention is an intrusion detection method, the flowchart of which is depicted in Figure 7 The intrusion detection method 700 is applicable to electronic devices, such as the intrusion detection device 1 described in the first embodiment. The intrusion detection method 700 performs intrusion detection of network packets through steps S701 to S705.

[0107] First, in step S701, the electronic device transmits network packets to the hybrid decision model to generate detection results corresponding to the network packets.

[0108] Next, in step S703, the electronic device responds to the detection result and corresponds to an abnormal state, and obtains feedback corresponding to the target information based on the target information in the network packet.

[0109] Finally, in step S705, the electronic device transmits the feedback to the intelligence detection model to update the detection result corresponding to the network packet.

[0110] In some implementations, the detection result is one of a benign state, a malign state, and an abnormal state.

[0111] In some embodiments, the hybrid decision model includes a supervised detection sub-model and an unsupervised detection sub-model, and the step of generating the detection result corresponding to the network packet further includes the following steps: transmitting the network packet to the supervised detection sub-model to generate a first detection result; transmitting the network packet to the unsupervised detection sub-model to generate a second detection result; and comparing the first detection result and the second detection result to generate the detection result.

[0112] In some embodiments, the step of the electronic device being communicatively connected to an intelligence platform and obtaining feedback corresponding to the target information further includes the steps of: transmitting the target information in the network packet to the intelligence platform; and receiving feedback corresponding to the target information from the intelligence platform, wherein the feedback is generated by the intelligence platform.

[0113] In some implementations, the step of updating the detection result corresponding to the network packet further includes the following steps: in response to the information detection model being activated, transmitting the feedback to the information detection model to update the detection result corresponding to the network packet.

[0114] In some implementations, the intelligence detection model is trained based on the following steps: in response to receiving feedback corresponding to the target information, adding the feedback corresponding to the target information to a feedback set; and training the intelligence detection model based on the feedback set.

[0115] In some implementations, the step of training the intelligence detection model further includes the following steps: in response to the feedback set meeting the feedback training criteria, training the intelligence detection model based on the feedback set.

[0116] In some implementations, the hybrid decision model is trained based on the following steps: in response to updating the detection result corresponding to the network packet, determining at least one target historical network packet corresponding to the target information from a plurality of historical network packets containing multiple historical target information; updating the historical detection results of each of the at least one target historical network packet based on the detection result corresponding to the network packet; and training the hybrid decision model based on the updated at least one target historical network packet corresponding to the target information.

[0117] In some implementations, the step of training the hybrid decision model further includes the following steps: adding the updated target historical network packet corresponding to the target information to the network packet set; and training the hybrid decision model based on the network packet set.

[0118] In some implementations, the step of training the hybrid decision model further includes the following steps: in response to the network packet set conforming to the packet training criteria, training the hybrid decision model based on the network packet set.

[0119] In addition to the steps described above, the second embodiment can also perform all the operations and steps of the intrusion detection device 1 described in the first embodiment, have the same function, and achieve the same technical effect. Those skilled in the art to which this invention pertains can directly understand how the second embodiment performs these operations and steps based on the first embodiment described above, has the same function, and achieves the same technical effect, so it will not be described in detail here.

[0120] It should be noted that the term "set" (e.g., feedback set, network packet set, historical network packet set) used in the specification and claims of this invention is used only to refer to a data group consisting of multiple elements.

[0121] It should be noted that in the specification and claims of this patent, certain terms (including: detection results) are preceded by "first" or "second," and these "first" or "second" are only used to distinguish different terms. For example, "first" and "second" in "first detection result" and "second detection result" are only used to indicate different detection results generated by different sub-models.

[0122] In summary, the intrusion detection technology (including at least an apparatus and a method) provided by this invention generates detection results for corresponding network packets through a hybrid decision model. Then, if the detection result corresponds to an abnormal state, this invention also obtains feedback on the target information within the network packet and further analyzes this feedback based on an intelligence detection model to update the detection result. Furthermore, this invention trains the hybrid decision model and the intelligence detection model through online learning. Therefore, the intrusion detection technology provided by this invention does not require manual rule setting, reducing the time cost of manual maintenance and increasing the accuracy of intrusion detection.

[0123] The above embodiments are merely illustrative of some implementations of the present invention and to explain the technical features of the present invention, and are not intended to limit the scope and range of protection of the present invention. Any changes or equivalent arrangements that can be easily made by those skilled in the art to which this invention pertains are within the scope of the present invention, and the scope of protection of the present invention is determined by the claims.

[0124] [Symbol Explanation]

[0125] 1: Intrusion detection device

[0126] 11: Processor

[0127] 12: Memory

[0128] 13: Send and receive interface

[0129] HDM: Hybrid Decision Model

[0130] CDM: Intelligence Detection Model

[0131] M2: Intrusion Detection Operation Flowchart

[0132] S201~S207: Operation

[0133] 300: Hybrid Decision Flowchart

[0134] SDSM: Supervised Detection Submodel

[0135] UDSM: Unsupervised Detection Submodel

[0136] R1: First detection result

[0137] R2: Second detection result

[0138] M4_1, M4_2: Intelligence Detection Model Training Operation Flowchart

[0139] S401~S405: Operation

[0140] M5_1, M5_2, M5_3: Training Operation Flowchart for Hybrid Decision Models

[0141] S501~S509: Operation

[0142] 600: Intrusion Detection Architecture Flowchart

[0143] 700: Intrusion Detection Methods

[0144] S701~S705: Steps.

Claims

1. An intrusion detection device, characterized in that, Include The send / receive interface is used to receive network packets containing target information; Memory, used to store hybrid decision-making models and intelligence detection models; and The processor, electrically connected to the transceiver interface and the memory, performs the following operations: The network packet is transmitted to the hybrid decision model to generate a detection result corresponding to the network packet; In response to the detection result corresponding to an abnormal state, feedback corresponding to the target information is obtained based on the target information in the network packet; as well as The feedback is transmitted to the intelligence detection model to update the detection result for the corresponding network packet.

2. The intrusion detection device according to claim 1, characterized in that, The detection result can be one of the following: benign state, malignant state, or abnormal state.

3. The intrusion detection device according to claim 1, characterized in that, The hybrid decision model includes a supervised detection sub-model and an unsupervised detection sub-model, and the operation that generates the detection result corresponding to the network packet also includes the following operations: The network packet is transmitted to the supervised detection sub-model to generate a first detection result; The network packet is transmitted to the unsupervised detection sub-model to generate a second detection result; as well as The first detection result and the second detection result are compared to generate the detection result.

4. The intrusion detection device according to claim 1, characterized in that, The operation of the transceiver interface communicating with the intelligence platform and obtaining the feedback corresponding to the target information also includes the following operations: Transmit the target information in the network packet to the intelligence platform; and The information platform receives feedback corresponding to the target information, wherein the feedback is generated by the information platform.

5. The intrusion detection device according to claim 1, characterized in that, The operation of updating the detection result corresponding to the network packet also includes the following operations: In response to the intelligence detection model being activated, the feedback is sent to the intelligence detection model to update the detection result for the corresponding network packet.

6. The intrusion detection device according to claim 1, characterized in that, The intelligence detection model is trained based on the following operations: In response to receiving feedback corresponding to the target information, the feedback corresponding to the target information is added to the feedback set; and Based on this feedback set, the intelligence detection model is trained.

7. The intrusion detection device according to claim 6, characterized in that, The training of this intelligence detection model also includes the following operations: In response to the feedback set meeting the feedback training criteria, the intelligence detection model is trained based on the feedback set.

8. The intrusion detection device according to claim 1, characterized in that, The hybrid decision-making model is trained based on the following operations: In response to updating the detection result corresponding to the network packet, at least one target historical network packet corresponding to the target information is determined from multiple historical network packets containing multiple historical target information; Based on the detection result of the corresponding network packet, update the historical detection results of each of the at least one target historical network packets; as well as The hybrid decision model is trained based on the updated target historical network packet corresponding to the target information.

9. The intrusion detection device according to claim 8, characterized in that, The training of this hybrid decision model also includes the following operations: Add the updated target-related historical network packet (corresponding to the target information) to the network packet set; and The hybrid decision model is trained based on this set of network packets.

10. The intrusion detection device according to claim 9, characterized in that, The training of this hybrid decision model also includes the following operations: In response to the fact that the network packet set conforms to the packet training standard, the hybrid decision model is trained based on the network packet set.

11. An intrusion detection method, characterized in that, For use in an electronic device, wherein the electronic device receives network packets containing target information, the electronic device stores a hybrid decision model and an intelligence detection model, wherein the intrusion detection method includes the following steps: The network packet is transmitted to the hybrid decision model to generate a detection result corresponding to the network packet; In response to the detection result corresponding to an abnormal state, feedback corresponding to the target information is obtained based on the target information in the network packet; as well as The feedback is transmitted to the intelligence detection model to update the detection result for the corresponding network packet.

12. The intrusion detection method according to claim 11, characterized in that, The detection result can be one of the following: benign state, malignant state, or abnormal state.

13. The intrusion detection method according to claim 11, characterized in that, The hybrid decision model includes a supervised detection sub-model and an unsupervised detection sub-model, and the step of generating the detection result corresponding to the network packet further includes the following steps: The network packet is transmitted to the supervised detection sub-model to generate a first detection result; The network packet is transmitted to the unsupervised detection sub-model to generate a second detection result; as well as The first detection result and the second detection result are compared to generate the detection result.

14. The intrusion detection method according to claim 11, characterized in that, The operation of the electronic device communicating with the intelligence platform and obtaining the feedback corresponding to the target information also includes the following steps: Transmit the target information in the network packet to the intelligence platform; and The information platform receives feedback corresponding to the target information, wherein the feedback is generated by the information platform.

15. The intrusion detection method according to claim 11, characterized in that, The step of updating the detection result corresponding to the network packet also includes the following steps: In response to the intelligence detection model being activated, the feedback is sent to the intelligence detection model to update the detection result for the corresponding network packet.

16. The intrusion detection method according to claim 11, characterized in that, The intelligence detection model is trained based on the following steps: In response to receiving feedback corresponding to the target information, the feedback corresponding to the target information is added to the feedback set; and Based on this feedback set, the intelligence detection model is trained.

17. The intrusion detection method according to claim 16, characterized in that, The steps involved in training this intelligence detection model also include the following: In response to the feedback set meeting the feedback training criteria, the intelligence detection model is trained based on the feedback set.

18. The intrusion detection method according to claim 11, characterized in that, The hybrid decision model is trained based on the following steps: In response to updating the detection result corresponding to the network packet, at least one target historical network packet corresponding to the target information is determined from multiple historical network packets containing multiple historical target information; Based on the detection result of the corresponding network packet, update the historical detection results of each of the at least one target historical network packets; as well as The hybrid decision model is trained based on the updated target historical network packet corresponding to the target information.

19. The intrusion detection method according to claim 18, characterized in that, The steps involved in training this hybrid decision model also include the following: Add the updated target-related historical network packet (corresponding to the target information) to the network packet set; and The hybrid decision model is trained based on this set of network packets.

20. The intrusion detection method according to claim 19, characterized in that, The steps involved in training this hybrid decision model also include the following: In response to the fact that the network packet set conforms to the packet training standard, the hybrid decision model is trained based on the network packet set.