An AI-based computer abnormal traffic detection system

By combining hypersphere feature space partitioning and sparsity modulation mechanism with prior adjustment factor and composite chaotic mapping strategy, the problem of difficult identification of sparse attack features in the existing technology is solved, realizing high-precision detection of covert attack traffic and reducing false alarm rate and false negative rate.

CN122419984APending Publication Date: 2026-07-17NANTONG INST OF TECH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NANTONG INST OF TECH
Filing Date
2026-06-15
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies lack mechanisms for spatiotemporal joint extraction of statistical and load features and feature modulation through spatial sparsity. This makes it difficult to effectively strip away disguises when facing covert attack traffic. Furthermore, the feature filtering method from a global perspective allows the distribution pattern of normal traffic to mask the weak features of sparse attacks. The lack of a targeted dimensionality reduction intervention mechanism to amplify the features of sparse attacks results in extremely low recognition.

Method used

The feature extraction module obtains spatiotemporal joint feature vectors through hypersphere feature space partitioning and spatial sparsity modulation mechanism. Combined with the feature dimensionality reduction module, a core feature index table is constructed using prior adjustment factors and global information gain rate. Support vector machine is used for traffic anomaly detection. The parameters are optimized using composite chaotic mapping and natural nearest neighbor density evaluation strategy to achieve high-precision classification of sparse attacks.

Benefits of technology

It effectively strips away high-risk traffic disguised as normal business traffic, amplifies the subtle characteristics of sparse attacks, reduces the false alarm rate and false negative rate of security devices in complex network environments, and achieves high-precision decision boundary fitting for sparse attack traffic clusters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419984A_ABST
    Figure CN122419984A_ABST
Patent Text Reader

Abstract

本发明公开了一种基于AI的计算机异常流量检测系统,涉及通信技术领域,包含特征提取模块、特征降维模块及检测模块,特征提取模块采集流量实例,提取统计与负载特征矩阵,通过超球体特征空间划分与空间稀疏度调制机制获取时空联合特征向量;特征降维模块基于联合特征向量构建初始矩阵,结合先验调节因子与全局信息增益率,筛选出核心特征子集矩阵;检测模块采用支持向量机进行流量异常检测;其参数寻优过程利用复合混沌映射初始化候选参数矩阵,采用梯形法牵引策略修正迭代寻优中的超界参数,并基于自然近邻密度评估执行逃逸和收缩策略;本系统能有效放大稀疏攻击微弱特征并克服模型寻优死锁,降低复杂网络环境下的漏报与误报率。
Need to check novelty before this filing date? Find Prior Art