The invention belongs to the technical field of
network security detection, and provides an
artificial intelligence-driven
network intrusion detection method,
system and device. The method comprises the steps of multi-source
metadata extraction and preprocessing, causal
feature discovery and selection, meta learning detection model reasoning, known
attack screening, causal comparative analysis and
branch judgment, adaptive threshold adjustment and interpretable
report generation. According to the method, initial parameters of three
layers of MLP are optimized by adopting an MAML framework, so that the model can be quickly adapted only by a small amount of
fine tuning in a zero-day
attack and few-sample scene, and the limitation that traditional
machine learning depends on a large number of historical samples is broken through; meanwhile, by constructing a baseline normal causal graph and an abnormal causal graph, adopting GED to quantify the similarity of the two graphs and accurately distinguishing zero-day
attack and
concept drift based on a preset threshold value, the industrial pain point that zero-day attack detection is difficult is solved,
misinformation caused by
concept drift is avoided, it is ensured that resources are only used for real
attack analysis, and the detection efficiency is improved.