An intrusion attack detection method and device, electronic equipment and storage medium
By constructing a local training graph of the network and performing multi-view dimensionality reduction consistency learning and dimensionality increase comparison learning, the problem of insufficient detection accuracy and robustness of existing technologies in the 5G environment is solved, and efficient identification of covert intrusion attacks is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING UNIV OF POSTS & TELECOMM
- Filing Date
- 2026-04-07
- Publication Date
- 2026-06-30
AI Technical Summary
Existing intrusion detection technologies are ill-suited to complex network topologies and highly dynamic traffic scenarios in 5G environments. They fail to fully utilize features, resulting in limited detection accuracy and generalization capabilities, making it difficult to effectively identify covert intrusion attacks.
By constructing a local training graph of the network and its corresponding node feature matrix and communication feature matrix, a node representation model is used to perform dimensionality reduction consistency learning and dimensionality increase comparative learning to generate multi-view node representation views, thereby improving detection accuracy and robustness.
It achieves high-precision detection of covert intrusion attacks, improves the robustness of the intrusion detection system, and can effectively identify attack behaviors in complex network environments.
Smart Images

Figure CN122316732A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security, and more specifically, to an intrusion attack detection method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the upgrading of global communication infrastructure and the acceleration of digitalization, the widespread adoption of 5G networks and the large-scale application of IoT devices are driving the rapid implementation of scenarios such as the Internet of Things and the Industrial Internet, forming a complex and integrated network ecosystem. The surge in the number of terminal devices, the diversification of service types, and the cloudification of network architecture have led to a continuous expansion of the network attack surface. Network traffic is characterized by high dimensionality, heterogeneity, and high noise, making intrusion behaviors more covert and weak-disturbance attacks more frequent. This places higher demands on intrusion detection systems, and network security has become a significant bottleneck for digital applications, with critical information infrastructure facing particularly prominent security threats. To address these challenges, intrusion detection technology has continuously evolved. While early statistical detection models and SVM feature embedding methods can achieve attack identification, they heavily rely on expert experience and are difficult to adapt to the complex network topology and highly dynamic traffic scenarios in the 5G environment. They also suffer from insufficient feature utilization and inadequate mining of local structure and neighborhood correlation information, limiting detection accuracy and generalization capabilities. Summary of the Invention
[0003] In view of this, the purpose of this application is to provide an intrusion attack detection method, device, electronic device and storage medium that can fully exploit network topology and neighborhood characteristics to improve the detection accuracy and robustness of covert intrusion attacks.
[0004] In a first aspect, embodiments of this application provide an intrusion attack detection method, the method comprising: Obtain a local network training graph constructed with the first network communication device as a node, the communication data between the first network communication devices and the attack detection label as edge attributes, and the first node feature matrix and the communication feature matrix between the first nodes corresponding to the local training graph; The local training graph and its corresponding first node feature matrix and first node inter-communication feature matrix are input into the node representation model to obtain a first node representation view under a first structural perspective corresponding to the local training graph, and a second node representation view under a second structural perspective that is complementary to the first structural perspective. The first node representation view and the second node representation view are subjected to dimensionality reduction consistency learning and dimensionality increase comparison learning to obtain the total loss value of the node representation model. After updating the node representation model based on the total loss value, the node representation model continues to be trained until a preset training stop condition is met, at which point training stops, and intrusion attack detection is performed based on the trained node representation model.
[0005] Secondly, embodiments of this application also provide an intrusion attack detection device, the device comprising: The acquisition module is used to acquire a local network training graph constructed with the first network communication device as a node, the communication data between the first network communication devices and the attack detection label as edge attributes, and the first node feature matrix and the communication feature matrix between the first nodes corresponding to the local training graph. The input module is used to input the local training graph and its corresponding first node feature matrix and first node communication feature matrix into the node representation model to obtain a first node representation view under a first structural perspective corresponding to the local training graph, and a second node representation view under a second structural perspective complementary to the first structural perspective. The learning module is used to perform dimensionality reduction consistency learning and dimensionality increase comparison learning on the first node representation view and the second node representation view to obtain the total loss value of the node representation model. The training module is used to update the node representation model according to the total loss value and continue training the node representation model until a preset training stop condition is met, so as to perform intrusion attack detection based on the trained node representation model.
[0006] Thirdly, embodiments of this application also provide an electronic device, including: a processor, a storage medium, and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the machine-readable instructions to perform the steps of the intrusion attack detection method as described in any of the first aspects.
[0007] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the intrusion attack detection method as described in any of the first aspects.
[0008] This application provides an intrusion attack detection method, apparatus, electronic device, and storage medium. The method includes: inputting a local training graph and its corresponding first node feature matrix and first node communication feature matrix into a node representation model to obtain a first node representation view from a first structural perspective corresponding to the local training graph and a second node representation view from a second structural perspective complementary to the first structural perspective; performing dimensionality reduction consistency learning and dimensionality increase comparative learning on the first node representation view and the second node representation view to obtain the total loss value of the node representation model; updating the node representation model and continuing to train the node representation model to perform intrusion attack detection based on the trained node representation model. This application can fully exploit network topology and neighborhood features, improving the detection accuracy and robustness of covert intrusion attacks. Attached Figure Description
[0009] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1 A flowchart of an intrusion attack detection method provided in an embodiment of this application is shown; Figure 2 A flowchart illustrating the extraction process of the node representation view provided in an embodiment of this application is shown. Figure 3 A flowchart illustrating the determination of the total loss value provided in an embodiment of this application is shown; Figure 4 This paper shows a schematic diagram of the structure of an intrusion attack detection device provided in an embodiment of this application; Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0011] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the accompanying drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.
[0012] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0013] To enable those skilled in the art to utilize the content of this application, and in conjunction with the specific application scenario of "cybersecurity," the following implementation methods are provided. For those skilled in the art, the general principles defined herein can be applied to other embodiments and application scenarios without departing from the spirit and scope of this application. Although this application is primarily described in the context of "cybersecurity," it should be understood that this is merely an exemplary embodiment.
[0014] It should be noted that the term "comprising" will be used in the embodiments of this application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.
[0015] The following is a detailed description of an intrusion attack detection method provided in the embodiments of this application.
[0016] Reference Figure 1 The diagram shown is a flowchart illustrating an intrusion attack detection method provided in an embodiment of this application. The exemplary steps of this embodiment are described below: S101. Obtain a local network training graph constructed with the first network communication device as a node, the communication data between the first network communication devices and the attack detection label as edge attributes, and the first node feature matrix and the communication feature matrix between the first nodes corresponding to the local training graph.
[0017] In this application's embodiments, the first network communication device refers to a device capable of network communication used to construct a local network training graph, such as a host, user terminal, sensor node, or base station. Communication data between the first network communication devices refers to traffic data generated during network communication between them, including traffic volume, packet length, connection time, and rate; each communication generates a piece of traffic data. The local network training graph is constructed based on a portion of the total training traffic data, forming a graph structure with the first network communication devices as nodes and the communication data between the first network communication devices and attack detection tags as edge attributes.
[0018] The local training graph stores the relationships between the first network communication devices. The first node feature matrix corresponding to the local training graph contains the feature vectors of each first network communication device, which stores the identifier, address, and other attribute information of the first network communication devices. The communication feature matrix between the first nodes corresponding to the local training graph contains the communication feature vectors between every two connected first network communication devices, which stores traffic size, packet length, connection time, rate, etc.
[0019] Here, this application embodiment provides the process of acquiring all training traffic data and the process of constructing the local training graph of the network, as detailed below: (1) Obtain all training traffic data according to the following steps: Step 1: Obtain raw traffic data; Step 2: Clean the raw data traffic set.
[0020] In this embodiment, a script is used to verify the integrity and availability of the original traffic data in the original NetFlow traffic dataset, removing dirty data with problems such as missing data or incorrect format, avoiding model training deviations caused by data quality defects, and completing the acquisition of high-quality data.
[0021] Step 3: Group the original traffic dataset according to the type of intrusion attack (such as DOS attack) to obtain the traffic data subset corresponding to each type of intrusion attack; extract the traffic data of the preset training ratio (80%) from the traffic data subset corresponding to each type of intrusion attack to obtain the training traffic data.
[0022] In this embodiment, a hierarchical grouping sampling strategy is adopted, which extracts samples based on different types of intrusion attacks. This strategy can evenly cover various attack samples, reduce the data size while maintaining the category distribution characteristics of the original data, and avoid category distribution shift, thereby ensuring the rationality and stability of the data for subsequent model training.
[0023] In addition, embodiments of this application can also extract a preset test ratio of test traffic data from the traffic data subsets corresponding to each type of intrusion attack in order to test the node representation model.
[0024] Step 4: Perform feature encoding on each training traffic data to obtain traffic sample data.
[0025] In this embodiment, feature encoding mainly targets different types of features in the initial training traffic data and adopts a differentiated processing method to ensure the effectiveness and standardization of features, providing high-quality feature input for the subsequent construction of local network training graphs. The specific processing process is as follows: For categorical features (i.e., textual features, such as intrusion attack categories) in the training traffic data, the occurrence probability (or occurrence ratio) of each category is calculated from all training traffic data. The categorical features of each initial training traffic data are encoded and transformed so that the encoding results can closely fit the task objectives of intrusion detection, effectively improve the feature discrimination ability, and help the model accurately distinguish between normal traffic and various types of attack traffic.
[0026] Simultaneously, all numerical traffic features in the training traffic data, except for node identifiers and intrusion attack labels, are standardized. Through normalization operations, all numerical feature values are converted into a standard normal distribution with a mean of 0 and a variance of 1, eliminating the dimensional differences between different numerical features and avoiding model training bias caused by inconsistent feature scales. Finally, the categorical features after target encoding are combined with the standardized numerical features to construct edge feature vectors of uniform specifications, completing the feature encoding of the initial training traffic data and obtaining the final training traffic data. This provides standardized and highly adaptable feature support for the subsequent construction of nodes and edges in the local training graph of the network.
[0027] (2) Construct a local training graph of the network according to the following steps: Step 1: Divide all traffic sample data into multiple traffic sample data groups according to the preset division rules.
[0028] Step 2: For each traffic sample data group, the source network communication device and the target network communication device in the traffic sample data group are taken as the first network communication device, and a local network training graph is constructed with the first network communication device as the node and the communication data and attack detection tags between the first network communication devices as the edge attributes.
[0029] In the embodiments of this application, each traffic sample data group corresponds to the construction of a local network training graph, which is a directed graph, forming a set of local network training graphs, reducing the size of a single graph and improving training efficiency.
[0030] In addition, in this embodiment of the application, a global network training graph can be constructed based on all traffic sample data groups, with the second network communication device as the node and the communication data between the second network communication devices as the edge attribute.
[0031] The second network communication device refers to a device capable of network communication used to construct a global network training graph, such as a host, user terminal, sensor node, or base station. Communication data between the second network communication devices refers to the traffic data generated during network communication between them.
[0032] In addition, a network test graph can be constructed based on the test traffic data, with third network communication devices as nodes and communication data between third network communication devices as edge attributes, to test the node representation model.
[0033] In this application, a third network communication device refers to a device capable of network communication used to construct a network test map, such as a host, user terminal, sensor node, or base station. Communication data between third network communication devices refers to traffic data generated during network communication between them.
[0034] S102. Input the local training graph and its corresponding first node feature matrix and first node inter-communication feature matrix into the node representation model to obtain the first node representation view under the first structural perspective corresponding to the local training graph, and the second node representation view under the second structural perspective complementary to the first structural perspective.
[0035] In the embodiments of this application, a structural perspective refers to the angle or method of understanding a local training image. The complementarity of the first and second structural perspectives means that content that cannot be understood from the first structural perspective can be understood from the second structural perspective.
[0036] The first node representation view contains the first node representation of each node, which is a feature representation of each node in the local training graph from the first structural perspective. It includes the core features of each node in the local training graph and the basic communication and relationship features between nodes. It focuses on the shallow structural information and direct interaction relationships of nodes, and can intuitively reflect the basic attributes and simple communication patterns of nodes. The second node representation view contains the second node representation of each node, which is a feature representation of each node in the local training graph from the second structural perspective. It includes the deep semantic features of each node in the local training graph, the indirect relationship features between nodes and the hidden interaction patterns. It focuses on the global structural information and potential relationship relationships of nodes. It can capture the deep structural differences and hidden features not covered in the first node representation view, thus complementing the first node representation view and jointly providing comprehensive and multi-dimensional node feature support for subsequent comparative learning.
[0037] Here, the node representation model adopts a symmetric dual GAT (Graph Attention Network) architecture as the basic framework for representation learning. It consists of an encoder GAT and a generator GAT, which share node and edge attributes but assume different semantic roles: the encoder is responsible for extracting structural semantics from the original local training graph, while the generator generates another structural perspective based on the encoder's output, constructing the multi-view representation required for cross-view contrastive learning. (Refer to...) Figure 2 The diagram shown is a flowchart of the node representation view extraction process provided in an embodiment of this application: S201. Input the local training image, the first node feature matrix, and the first node inter-communication feature matrix into the encoder in the node representation model to perform adaptive aggregation of the features of each node and its neighboring nodes under the self-attention mechanism, so as to obtain the first node representation view under the first structural perspective.
[0038] In this embodiment, the encoder's input is a local training graph and node and edge features (V, Q, X, E), where V represents the node set, Q represents the edge set, X is the node feature matrix, and E is the edge feature matrix (i.e., the first node inter-communication feature matrix). The encoder aggregates neighborhood messages using a self-attention mechanism to generate a first node representation view. The specific implementation process is as follows: Step 1: For each edge in the local training graph, calculate the fusion weight corresponding to the edge based on the source node feature vector, target node feature vector, and neighboring node feature vector of the source node in the first node feature matrix.
[0039] In this embodiment, the source node refers to the initiating network node of the communication relationship corresponding to each edge in the local training graph, that is, the node that generates communication traffic and actively initiates data interaction (corresponding to the node at the starting end of the edge in the first node feature matrix); the target node refers to the receiving network node of the communication relationship corresponding to each edge in the local training graph, that is, the node that receives communication traffic and passively responds to data interaction (corresponding to the node at the ending end of the edge in the first node feature matrix); the adjacent node refers to other network nodes that have a direct communication connection with the source node (that is, are directly associated through an edge). These nodes belong to the same local training graph as the source node, share the same communication link, and their feature vectors participate in the calculation of the fusion weight corresponding to the source node, forming a direct adjacency relationship with the source node, jointly supporting the accurate solution of the fusion weight, and ensuring that the weight calculation can reflect the association characteristics between the source node and the surrounding nodes.
[0040] Specifically, the source node feature vector, target node feature vector, and neighboring node feature vector of the source node corresponding to the edge in the first node feature matrix are substituted into the following formula to obtain the fusion weight corresponding to the edge: ; in, Let be the fusion weights corresponding to the edges ij that directly connect the source node i and the target node j. For an improved ReLU activation function, This is the weight matrix. Here, T is the attention parameter (used to calculate the correlation between different node pairs), and T is the transpose. The source node feature vector, For the target node feature vector, Let be the set of neighboring nodes of the source node. These are the feature vectors of adjacent nodes. l For the encoder's first l The encoder can have one or more layers, and each layer will perform adaptive aggregation. This is the theoretical formula for the DAT model, which will not be elaborated here.
[0041] Step 2: Aggregate the neighborhood features of each node according to the fusion weights corresponding to each edge, the first node feature matrix, and the first node inter-communication feature matrix to obtain the first node representation view from the perspective of the first structure.
[0042] In this embodiment, the core purpose of neighborhood feature aggregation is to weightedly fuse the features of each node with the features of its surrounding associated nodes to form a node representation that comprehensively reflects the first structural perspective (shallow structural information, direct interaction relationships). The specific implementation process is as follows: First, clarify the core role of the fusion weights corresponding to each edge—to measure the contribution of the features of the source node, target node, and adjacent nodes of the source node associated with each edge to the neighborhood feature aggregation of the target node. The higher the weight value, the higher the proportion of the corresponding node feature in the aggregation process, thereby highlighting key node features and suppressing interference from irrelevant features. Second, for each node in the local training graph, with that node as the core, select all edges directly associated with that node (i.e., all edges corresponding to that node as the source node or target node), extract the fusion weights corresponding to these edges, and simultaneously extract the fusion weights from the first node feature moments. The first method extracts the feature vector of the node itself and the feature vectors of all its neighboring nodes from the matrix. Then, it extracts the communication feature vectors between the node and each of its neighboring nodes from the first inter-node communication feature matrix. Subsequently, it performs a weighted product operation on the feature vectors of the neighboring nodes and the fusion weights of the corresponding edges to obtain the weighted feature vectors of each neighboring node. At the same time, it performs a weighted fusion operation on the inter-node communication feature vectors and the corresponding fusion weights to obtain the weighted communication feature vectors. Finally, it fuses and summarizes the feature vectors of the node itself, the weighted feature vectors of all its neighboring nodes, and the weighted communication feature vectors. It then performs feature transformation through a nonlinear activation function (such as LeakyReLU) to eliminate feature redundancy and enhance feature expressive power. Finally, it obtains the feature representation of each node from the first structural perspective. After summing the feature representations of all nodes, it constitutes the first node representation view from the first structural perspective.
[0043] It is important to note that the aggregation process in this step strictly adheres to the core requirements of the first structural perspective, focusing on the shallow structural information and direct interaction relationships of nodes. It only aggregates the features of adjacent nodes that have direct communication relationships with the node, as well as the direct communication features, without involving the mining of deep hidden relationships, which is completely consistent with the definition of the first node representation view mentioned above. At the same time, through the weighting effect of the fusion weights, it is ensured that the aggregated node representation can accurately reflect the node's own attributes and the interaction characteristics of its surrounding directly related nodes, providing reliable feature support for subsequent comparative learning with the second node representation view, and avoiding the problem of insufficient disclosure in the specification due to unclear aggregation logic.
[0044] S202. Input the local training image, the communication feature matrix between the first nodes, and the first node representation view into the generator in the node representation model to obtain the second node representation view from the second structural perspective.
[0045] In this embodiment of the application, the generator GAT receives the first node representation view output by the encoder. Based on the same local training graph G and the communication feature matrix E between the first nodes, a structural perspective different from the original encoding is generated as a pseudo-view for cross-view comparative learning. The generation formula is as follows: .
[0046] in, The second node represents the view.
[0047] Here, the generator is not trained adversarially; it is only used as the second node to represent the view generation path, providing support for subsequent dual-view comparison learning.
[0048] S103. Perform dimensionality reduction consistency learning and dimensionality increase comparison learning on the first node representation view and the second node representation view to obtain the total loss value of the node representation model.
[0049] In this embodiment, this step employs a progressively enhanced contrastive learning strategy combining low-dimensional hash consistency with high-dimensional projection contrast. Joint optimization is performed on the complementary node representation views generated by the first and second structural perspectives, effectively addressing the issues of noise interference and training instability in high-dimensional space contrast. This allows for accurate capture of fine-grained anomaly attack patterns in network traffic under unlabeled conditions, referencing... Figure 3 The diagram shown is a flowchart for determining the total loss value according to an embodiment of this application. The specific implementation process is as follows: S301. Divide and reduce the dimensions of the first node representation view and the second node representation view to obtain the dimension-reduced representation of each first node and its corresponding dimension-reduced representation of the second node.
[0050] In this embodiment, the dimensionality reduction representation of each first node and its corresponding second node are obtained based on the features of the same node. Specifically: Step 1: Divide the first node representation view into the second node representation view to obtain multiple first node representation subviews and a second node representation subview corresponding to each first node representation subview; the node corresponding to each first node representation subview is the same as the node corresponding to its second node representation subview.
[0051] In this embodiment, it is assumed that the first node representation view and the second node representation view contain node representations of node 1, node 2, node 3, and node 4. The first node representation view is divided into a first node representation subview A containing node representations of node 1 and node 2, and a first node representation subview B containing node representations of node 3 and node 4. Then, the second node representation view is divided into a second node representation subview C containing node representations of node 1 and node 2, and a second node representation subview D containing node representations of node 3 and node 4. Specifically, first node representation subview A corresponds to second node representation subview C, and first node representation subview B corresponds to second node representation subview D.
[0052] Step 2: Perform dimensionality reduction processing on each first node representation subview and its corresponding second node representation subview to obtain the dimensionality reduction representation of each first node and its corresponding second node.
[0053] In this embodiment of the application, the dimensionality reduction representation of any first node representing a subview and its corresponding second node is performed according to the following steps to obtain the dimensionality reduction representation of the first node and its corresponding second node: i. Determine the average value of all nodes in the subview represented by the first node as the view center of the subview represented by the first node; and determine the average value of all nodes in the subview represented by the second node as the view center of the subview represented by the second node corresponding to the subview represented by the first node.
[0054] In this embodiment, the view center corresponding to the first node representing the subview refers to the average value represented by all nodes in the subview represented by the first node. This can be expressed by the following formula: ; in, The first node represents the view center corresponding to the subview. The first node represents the set of nodes in the subview. Let the first node represent the i-th node in the subview.
[0055] In this embodiment, the view center corresponding to the second node represents the subview, which is the average value represented by all nodes in the subview. This can be expressed by the following formula: ; in, The second node represents the view center corresponding to the subview. The second node represents the set of nodes in the subview. Let the second node represent the i-th node in the subview.
[0056] ii. Map the view center of the subview represented by the first node and the view center of the corresponding subview represented by the second node to a low-dimensional hash space to reduce the impact of noise and achieve stable view alignment. This is suitable for identifying small-scale communication anomalies and yields the dimensionality reduction representation of the first node and its corresponding dimensionality reduction representation of the second node.
[0057] In this embodiment of the application, the view center of the subview represented by the first node is substituted into the following formula to obtain the dimensionality-reduced representation of the first node. : ; in, Indicates normalization. It is a learnable linear projection matrix.
[0058] In this embodiment, the view center of the subview represented by the second node is substituted into the following formula to obtain the dimensionality-reduced representation of the first node and its corresponding dimensionality-reduced representation of the second node. : .
[0059] S302. Perform a consistency comparison on the dimensionality reduction representation of each first node and its corresponding dimensionality reduction representation of the second node to obtain the consistency loss value of the node representation model.
[0060] In this embodiment, the dimensionality reduction representations of each first node and its corresponding second node are substituted into the following formula to obtain the consistency loss value of the node representation model. : ; in, The number of dimensions in the reduced-dimensional representation of the first node. The transpose of the dimensionality-reduced representation of the i-th first node. Dimensionally reduced representation of the i-th first node The corresponding second node is represented by a reduced dimension.
[0061] S303. Based on the dimensionality reduction representation of each first node and its corresponding dimensionality reduction representation of the second node, perform dimensionality-upgrading comparison learning on the first node representation view and the second node representation view to obtain the comparison loss value of the node representation model.
[0062] In this embodiment, based on stable alignment of the hash space, the low-dimensional hash representation is mapped to a high-dimensional semantic space to uncover more detailed structural differences and amplify the semantic differences between normal and attack views. Specifically: Step 1: Perform dimensionality upscaling on the dimensionality-reduced representations of each first node and its corresponding dimensionality-reduced representations of the second node to obtain the dimensionality-upscaling representations of each first node and its corresponding dimensionality-upscaling representations of the second node.
[0063] In this embodiment of the application, the dimensionality reduction representation of any first node and its corresponding dimensionality reduction representation of the second node are subjected to dimensionality increase processing according to the following steps to obtain the dimensionality increase representation of the first node and its corresponding dimensionality increase representation of the second node: i. Substitute the reduced-dimensional representation of the first node into the following formula to obtain the increased-dimensional representation of the first node. : ; in, and Both can learn projection matrices. The first node is represented by a reduced dimension. This is the activation function (used for nonlinear transformations).
[0064] ii. Substitute the reduced-dimensional representation of the second node corresponding to the reduced-dimensional representation of the first node into the following formula to obtain the increased-dimensional representation of the second node corresponding to the increased-dimensional representation of the first node. : .
[0065] Step 2: Compare the upgraded dimensionality representations of each first node with their corresponding upgraded dimensionality representations of the second node to obtain the comparison loss value of the node representation model.
[0066] In this embodiment, the contrastive loss value of the node representation model is obtained by substituting the upgraded dimensionality representations of each first node and its corresponding upgraded dimensionality representations of the second node into the following formula. : ; in, Let T be the upgraded representation of the i-th first node, and T be the transpose. For the i-th second node, the dimension-upgraded representation is given. For the j-th second node, the dimension-upgraded representation is given. This is an adjustable temperature coefficient. The p-dot product inside the exp function is used to calculate the cosine similarity.
[0067] S304. The consistency loss value and the contrast loss value are fused to obtain the total loss value of the node representation model.
[0068] In this embodiment, the low-dimensional hash consistency loss and the high-dimensional InfoNCE contrastive loss are combined to form a progressive contrastive learning total loss. The consistency loss value... And compare loss values Substituting into the following formula, we obtain the total loss value of the node representation model. : ; in, The consistency loss value corresponds to the fusion weight. To compare the loss values with the corresponding fusion weights.
[0069] S104. After updating the node representation model based on the total loss value, continue training the node representation model until the preset training stopping condition is met, and then stop training to perform intrusion attack detection based on the trained node representation model.
[0070] In this application embodiment, intrusion attack detection based on the trained node representation model includes: Step 1: Obtain a global network training graph constructed with the second network communication device as the node, the communication data between the second network communication devices and the attack detection label as the edge attributes, and the second node feature matrix and the communication feature matrix between the second nodes corresponding to the global network training graph.
[0071] Step 2: Train the intrusion attack detection model based on the global network training graph, the second node feature matrix, the second node inter-communication feature matrix, and the trained node representation model.
[0072] In this embodiment, the global network training graph, the second node feature matrix, and the second inter-node communication feature matrix are input into the encoder of the trained node representation model to obtain a high-dimensional semantic view (data of the same type as the aforementioned first node representation view). The high-dimensional semantic view is used as a sample, and the intrusion attack marker corresponding to the high-dimensional semantic view is used as a label to train the intrusion attack detection model. The intrusion attack marker is used to indicate whether the source node corresponding to each edge in the high-dimensional semantic view is the node that initiated the intrusion attack.
[0073] Step 3: Perform intrusion attack detection based on the trained intrusion attack detection model.
[0074] In this embodiment of the application, the intrusion attack detection result output by the intrusion attack detection model is whether the source network communication device is an intrusion attacker.
[0075] Based on the same inventive concept, this application also provides an intrusion attack detection device corresponding to the intrusion attack detection method. Since the principle of the device in this application is similar to that of the intrusion attack detection method described above, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.
[0076] Reference Figure 4The diagram shown is a schematic of an intrusion attack detection device provided in an embodiment of this application. The device includes: The acquisition module 401 is used to acquire a local network training graph constructed with the first network communication device as a node, the communication data between the first network communication devices and the attack detection label as edge attributes, and the first node feature matrix and the communication feature matrix between the first nodes corresponding to the local training graph. The input module 402 is used to input the local training graph and its corresponding first node feature matrix and first node communication feature matrix into the node representation model to obtain a first node representation view under a first structural perspective corresponding to the local training graph, and a second node representation view under a second structural perspective complementary to the first structural perspective. Learning module 403 is used to perform dimensionality reduction consistency learning and dimensionality increase comparison learning on the first node representation view and the second node representation view to obtain the total loss value of the node representation model. The training module 404 is used to update the node representation model according to the total loss value and continue training the node representation model until a preset training stop condition is met, so as to perform intrusion attack detection based on the trained node representation model.
[0077] like Figure 5 As shown in the embodiment of this application, an electronic device 500 includes a processor 501, a memory 502, and a bus. The memory 502 stores machine-readable instructions executable by the processor 501. When the electronic device is running, the processor 501 communicates with the memory 502 via the bus, and the processor 501 executes the machine-readable instructions to perform the steps of the intrusion attack detection method described above.
[0078] Specifically, the memory 502 and processor 501 mentioned above can be general-purpose memory and processor, without any specific limitations. When the processor 501 runs the computer program stored in the memory 502, it can execute the above-mentioned intrusion attack detection method.
[0079] Corresponding to the above-described intrusion attack detection method, this application embodiment also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the above-described intrusion attack detection method.
[0080] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some communication interfaces; the indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms.
[0081] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0082] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0083] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0084] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An intrusion attack detection method, characterized in that, The method includes: Obtain a local network training graph constructed with the first network communication device as a node, the communication data between the first network communication devices and the attack detection label as edge attributes, and the first node feature matrix and the communication feature matrix between the first nodes corresponding to the local training graph; The local training graph and its corresponding first node feature matrix and first node inter-communication feature matrix are input into the node representation model to obtain a first node representation view under a first structural perspective corresponding to the local training graph, and a second node representation view under a second structural perspective that is complementary to the first structural perspective. The first node representation view and the second node representation view are subjected to dimensionality reduction consistency learning and dimensionality increase comparison learning to obtain the total loss value of the node representation model. After updating the node representation model based on the total loss value, the node representation model continues to be trained until a preset training stop condition is met, at which point training stops, and intrusion attack detection is performed based on the trained node representation model.
2. The intrusion attack detection method according to claim 1, characterized in that, The step of inputting the local training graph and its corresponding first node feature matrix and first node communication feature matrix into the node representation model to obtain a first node representation view from a first structural perspective corresponding to the local training graph, and a second node representation view from a second structural perspective complementary to the first structural perspective, includes: The local training image, the first node feature matrix, and the first node inter-node communication feature matrix are input into the encoder in the node representation model to perform adaptive aggregation of the features of each node and its neighboring nodes under the self-attention mechanism, thereby obtaining the first node representation view under the first structural perspective. The local training graph, the first inter-node communication feature matrix, and the first node representation view are input into the generator in the node representation model to obtain the second node representation view from the second structural perspective.
3. The intrusion attack detection method according to claim 2, characterized in that, The step of inputting the local training map, the first node feature matrix, and the first inter-node communication feature matrix into the encoder of the node representation model to perform adaptive aggregation of the neighborhood features of the nodes under a self-attention mechanism, thereby obtaining the first node representation view from the first structural perspective, includes: For each edge in the local training graph, the fusion weight corresponding to the edge is calculated based on the source node feature vector, target node feature vector, and adjacent node feature vector of the source node in the first node feature matrix. The neighborhood features of each node are aggregated based on the fusion weights corresponding to each edge, the first node feature matrix, and the first node inter-communication feature matrix to obtain the first node representation view from the perspective of the first structure.
4. The intrusion attack detection method according to claim 1, characterized in that, The step of performing dimensionality reduction consistency learning and dimensionality increase comparison learning on the first node representation view and the second node representation view to obtain the total loss value of the node representation model includes: The first node representation view and the second node representation view are divided and dimensionality reduced to obtain the dimensionality reduction representation of each first node and its corresponding dimensionality reduction representation of the second node; each dimensionality reduction representation of the first node and its corresponding dimensionality reduction representation of the second node are obtained based on the features of the same node. A consistency comparison is performed on the dimensionality reduction representation of each first node and its corresponding dimensionality reduction representation of the second node to obtain the consistency loss value of the node representation model; Based on the dimensionality reduction representation of each first node and its corresponding dimensionality reduction representation of the second node, the first node representation view and the second node representation view are subjected to dimensionality-upgrading comparative learning to obtain the comparative loss value of the node representation model; The consistency loss value and the contrast loss value are fused to obtain the total loss value of the node representation model.
5. The intrusion attack detection method according to claim 4, characterized in that, The step of partitioning and dimensionality-reducing the first node representation view and the second node representation view to obtain the dimensionality-reduced representation of each first node and its corresponding dimensionality-reduced representation of the second node includes: The first node representation view and the second node representation view are divided to obtain multiple first node representation subviews and a second node representation subview corresponding to each first node representation subview; the node corresponding to each first node representation subview is the same as the node corresponding to its corresponding second node representation subview. Dimensionality reduction is performed on each first node representation subview and its corresponding second node representation subview to obtain the dimensionality reduction representation of each first node and its corresponding second node.
6. The intrusion attack detection method according to claim 4, characterized in that, The step of performing dimensionality-upgrading comparison learning on the first node representation view and the second node representation view based on the dimensionality-downgrading representation of each first node and its corresponding dimensionality-downgrading representation of the second node, to obtain the comparison loss value of the node representation model, includes: The dimension-reduced representations of each first node and their corresponding dimension-reduced representations of the second node are subjected to dimension-up processing to obtain the dimension-upped representations of each first node and their corresponding dimension-upped representations of the second node. By comparing the upgraded dimensionality representations of each first node with their corresponding upgraded dimensionality representations of the second node, the comparison loss value of the node representation model is obtained.
7. The intrusion attack detection method according to claim 1, characterized in that, The intrusion attack detection based on the trained node representation model includes: Obtain a global network training graph constructed with the second network communication device as a node, the communication data between the second network communication devices and the attack detection label as edge attributes, and the second node feature matrix and the communication feature matrix between the second nodes corresponding to the global network training graph; The intrusion attack detection model is trained based on the global network training graph, the second node feature matrix, the second node inter-communication feature matrix, and the trained node representation model. Intrusion attack detection is performed based on the trained intrusion attack detection model.
8. An intrusion attack detection device, characterized in that, The device includes: The acquisition module is used to acquire a local network training graph constructed with the first network communication device as a node, the communication data between the first network communication devices and the attack detection label as edge attributes, and the first node feature matrix and the communication feature matrix between the first nodes corresponding to the local training graph. The input module is used to input the local training graph and its corresponding first node feature matrix and first node communication feature matrix into the node representation model to obtain a first node representation view under a first structural perspective corresponding to the local training graph, and a second node representation view under a second structural perspective complementary to the first structural perspective. The learning module is used to perform dimensionality reduction consistency learning and dimensionality increase comparison learning on the first node representation view and the second node representation view to obtain the total loss value of the node representation model. The training module is used to update the node representation model according to the total loss value and continue training the node representation model until a preset training stop condition is met, so as to perform intrusion attack detection based on the trained node representation model.
9. An electronic device, characterized in that, include: The device includes a processor, a storage medium, and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the machine-readable instructions to perform the steps of the intrusion attack detection method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the intrusion attack detection method as described in any one of claims 1 to 7.