The invention discloses an
intranet terminal abnormal
network behavior identification method and
system, and the method comprises the steps: capturing network flow, extracting multi-dimensional heterogeneous features, and obtaining a feature embedding vector set through vectorization coding and IP segmentation embedding
processing; constructing a semantic-
space mapping mechanism between features, converting a logic neighborhood relationship in a network protocol into an Euclidean space neighborhood relationship in a pseudo-spatial feature grid, and stacking along a time dimension to generate a four-dimensional feature topology
tensor; respectively extracting local correlation, axis distribution and long-distance dependence characteristics by using squares, bars and expansion
convolution kernels which are arranged in parallel, and carrying out self-adaptive weighted fusion; and finally, based on the fusion
feature vector, determining abnormity through a full-connection classification layer. According to the method, the discrete traffic data is converted into the pseudo-space
tensor with semantic topology, so that the
logic structure of network behaviors is effectively recovered, and the recognition precision of hidden attacks in an internal network and an industrial control environment is remarkably improved in cooperation with multi-scale
convolution.