Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

253 results about "Network intrusion detection" patented technology

Network intrusion detection method and system based on dynamic graph attention and comparative learning

The invention discloses a network intrusion detection method and system based on dynamic graph attention and comparative learning. Network traffic is constructed into a dynamic heterogeneous graph (nodes are IPs / ports, and sides are traffic sessions), and dynamic feature fusion is carried out by adopting time window division and a GATv2 network. An optimal transmission contrast learning strategy is innovatively introduced, feature and structure distribution alignment is realized through a Wasserstein distance and a Gaussian Wasserstein distance, and the generalization ability of the model to unknown attacks is improved. And finally, combining node embedding and an alignment matrix, and utilizing an MLP classifier to predict an edge anomaly probability. Experiments show that the accuracy and F1-score of the method on multiple data sets are improved by 5.2%-10.5% compared with those of a baseline, the detection performance under complex attacks is remarkably enhanced, and the method is suitable for real-time scenes such as the Internet of Things. The system can be deployed on edge equipment and has high practical value.
Owner:ROCKET FORCE UNIV OF ENG

Network intrusion detection method and system based on recursive gating convolution

The invention discloses a network intrusion detection method and system based on recursive gating convolution, and relates to the technical field of data processing. The method comprises the steps of obtaining to-be-predicted traffic data; obtaining a network intrusion detection model; training the network intrusion detection model, wherein the training comprises the steps of dividing traffic slices for the preprocessed training data according to a fixed time window; calculating a fusion feature value of each time window and the spatial dimension; generating a spatial-temporal characteristic matrix; splicing the spatial-temporal feature matrix with the preprocessed training data to form an enhanced feature set; constructing a teacher model and a student model; training the teacher model and training the student model; and inputting the to-be-predicted traffic data into a trained network intrusion detection model to obtain a prediction result. Through time window division and time-space fusion, the diversity of data is artificially expanded, so that the model contacts richer scenes in training, and the dependence on specific sample distribution is reduced.
Owner:SOUTHWEST PETROLEUM UNIV

Quantum-enhanced multi-scale network intrusion detection method and device, and storage medium

The invention relates to the technical field of artificial intelligence, and provides a quantum-enhanced multi-scale network intrusion detection method, which comprises the following steps: calculating a covariance matrix for an original traffic feature matrix, and obtaining a feature value and a feature vector through feature decomposition, mapping each sample xi to a quantum Hilbert space to generate an enhanced feature matrix, executing complex field transformation on the enhanced feature matrix to generate an entangled feature tensor, and realizing dynamic feature enhancement through a multi-head attention mechanism based on a quantum probability amplitude; performing space-time attention calculation and gating fusion on the feature tensor after dynamic feature enhancement to obtain a space-time fusion feature; converting the space-time fusion features into a time sequence form, extracting behavior features through a multi-scale convolution branch, and fusing the behavior features to obtain a three-dimensional feature tensor; and calculating a mean value of the three-dimensional feature tensor in a sequence dimension, generating a two-dimensional feature matrix, and performing classification prediction, uncertainty quantification and threat grading evaluation based on a classification network, an uncertainty network and a threat grading network.
Owner:HARBIN UNIV OF COMMERCE

Network intrusion detection method based on self-attention residual generative adversarial network

The invention discloses a network intrusion detection method based on a self-attention residual generative adversarial network, which belongs to the technical field of network intrusion detection and comprises the following steps: collecting network flow data, and preprocessing the network flow data to obtain real training data; a FARD-WGAN-GP model is constructed and trained, and hybrid pseudo data is generated based on the trained FARD-WGAN-GP model; constructing a time sequence attention detection model; training a time sequence attention detection model based on the real training data and the pseudo data; network intrusion real-time detection is carried out based on the trained time sequence attention detection model; on the basis of the real-time detection result, optimizing the FARD-WGAN-GP model, and on the basis of the optimized FARD-WGAN-GP model, optimizing the time sequence attention detection model; and carrying out network intrusion detection based on the optimized time sequence attention detection model. According to the method, the quality of the generated data is improved, and the detection accuracy is improved.
Owner:ZHENGZHOU UNIV

Knowledge data joint-driven vehicle-mounted CAN network intrusion detection method

The invention discloses a knowledge data joint-driven vehicle-mounted CAN network intrusion detection method, which comprises the following steps of: firstly, carrying out standardization processing on original CAN message data, and extracting structural characteristics of the original CAN message data; through a data preprocessing module, original data is converted into an input format suitable for neural network processing, and is prepared together with a knowledge set for subsequent analysis. The processed data and knowledge set are then input to a spatio-temporal attention module based on sparse attention. In the module, a time sequence attention layer extracts possible time sequence characteristics of attacks by capturing time correlation of CAN messages; and the spatial attention layer analyzes the spatial characteristics of the message and identifies data tampering or other abnormal modes. And after being processed by the space-time attention module, the high-order hidden features extracted by the network are transmitted to the output layer, and a final intrusion detection result is displayed through the full connection layer. And if an abnormal or attack behavior is detected, the system gives an alarm to the user in time.
Owner:SHENZHEN AUTOMOTIVE RES INST BEIJING INST OF TECH (SHENZHEN RES INST OF NAT ENG LAB FOR ELECTRIC VEHICLES) +1

Industrial internet network intrusion detection method based on pre-trained large language model

The invention provides an industrial internet network intrusion detection method based on a pre-trained large language model, and the method comprises the steps: carrying out the data preprocessing of original network flow data through protocol self-adaptive flow aggregation and session segmentation, feature screening and feature coding; constructing a stream format text data set used for training a generation model GPT-2 and a packet level classification text-label data set used for training a classification model DistilBERT; then fine tuning training is carried out on the generation model GPT-2 and the classification model DistilBERT; then calling a trained generation model GPT-2 to generate a traffic sequence, obtaining a prediction data packet, calling a trained classification model DistilBERT, performing anomaly judgment on sequence data in the prediction data packet one by one, and outputting a classification result of anomaly judgment; the active intrusion detection of first generation and then discrimination is realized. According to the method, prediction can be made before real attack traffic arrives, and network attacks are prevented.
Owner:EAST CHINA JIAOTONG UNIVERSITY

Lightweight vehicle-mounted network intrusion detection system and method based on ADGRU-Net hybrid model

The invention belongs to the technical field of vehicle networking safety, and relates to a lightweight in-vehicle network intrusion detection system and method based on an ADGRU-Net hybrid model, and the system comprises a data loading and cleaning module, a time sequence and feature correlation module, and a space-time hybrid deep learning model. The data loading and cleaning module adopts a block-by-block loading mode to convert multi-source heterogeneous original time sequence data into a standard format; the time sequence and feature association module adopts a sliding window mechanism to intercept a data segment containing L continuous time steps with a preset length from multi-source time sequence data, each time step contains N features, and the data segment is transposed and then converted into a two-dimensional single-channel grayscale image through linear scaling; the space-time hybrid deep learning model comprises a spatial feature extraction module, a remodeling module, a time sequence feature extraction module, a time sequence branch decoder, a spatial branch decoder and a feature fusion module; the problem that an existing model is poor in performance in a complex and changeable real attack scene is solved.
Owner:CHANGCHUN UNIV

Cloud edge-end collaborative multi-scene adaptive network intrusion detection method

The invention discloses a cloud side-end cooperative multi-scene adaptive network intrusion detection method, and solves the problems of poor scene adaptation, weak dynamic processing, privacy-precision imbalance and the like in the prior art. The method is realized through four steps: 1, multi-scene traffic collection and hierarchical preprocessing, terminal sensing layer optimization frame processing and traffic classification, edge layer screening of high-value traffic, and cloud fragmentation scheduling; 2, multi-scene adaptive feature fusion is carried out, scene exclusive features and general features are extracted, and 50-dimensional feature vectors are generated; 3, a cloud edge-end collaborative detection model and an edge lightweight model are preliminarily screened, a cloud federal fusion model is finely detected, and dynamic weight and differential privacy are combined; 4, dynamic attack response and model iteration are carried out, attacks are responded in a scene mode, and the stability of the model is guaranteed through anti-forgetting optimization. According to the method, multiple scenes are covered, the detection precision is larger than or equal to 98.5%, the edge delay is smaller than or equal to 40 ms, the privacy leakage risk is reduced by 90%, the renaturation is high, and the robustness is high.
Owner:季亚文

Network intrusion detection method and device based on multi-dimensional feature collaborative analysis, and storage medium

PendingCN120768617ABiological modelsSecuring communicationNeural oscillationAlgorithm
The invention relates to the technical field of artificial intelligence, and provides a network intrusion detection method based on multidimensional feature collaborative analysis, and the method comprises the steps: calculating the correlation degree eta ij of any two feature columns in an original traffic feature matrix, and when eta ij is greater than eta thr, generating a new feature through Qij = Xi * Xj + (1-eta ij) * (Xi + Xj), outputting a dimension reduction feature matrix to perform nonlinear spatial transformation on the dimension reduction feature matrix X ', dynamically retrieving associated knowledge through a learnable memory library, fusing current input features and memory enhancement features, and outputting refined features; decomposing the refined features to a biological neural oscillation frequency band, applying carrier modulation, and performing feature reconstruction to generate a space-time correlation tensor; the refined features and the space-time correlation tensor are fused, and the intrusion behavior classification probability is output through multi-stage abstract compression and regularization processing; screening difficult samples based on classification confidence to construct a training library, and obtaining a conventional detection model and a special and precise detection model; and preferentially calling the special and precise model during real-time detection, and switching to the conventional model when the confidence coefficient is smaller than a confidence coefficient threshold value.
Owner:HARBIN UNIV OF COMMERCE

Network intrusion detection method based on improved WGAN sampling and ensemble learning

The invention relates to a network intrusion detection method based on improved WGAN sampling and ensemble learning, and solves the defects that for high-dimensional and class-unbalanced network flow data, a base learner of an integrated model is insufficient in adaptive capacity, noise interference is difficult to restrain, and key attack modes are difficult to mine in the prior art. The method comprises the following steps: acquiring network flow data; performing data enhancement based on a DDWGLO framework; constructing a network intrusion detection model based on Stacking; training a network intrusion detection model; and detecting network intrusion in real time. According to the method, the DDWGLO is adopted for data enhancement, the weight is adaptively allocated based on the Newton-Raphson optimization algorithm improved on the basis of Circle chaotic mapping, and then the accuracy of network intrusion detection is improved.
Owner:ANHUI UNIV

Network intrusion detection method based on CKAN-BiLSTM

The invention requests to protect a network intrusion detection method based on a CKAN-BiLSTM (Content Kernel Area Network-BiLSTM). The method comprises the following steps: firstly, selecting an NSL-KDD data set widely applied in the field of network security, and performing preprocessing operation on the NSL-KDD data set to improve data quality and a model training effect; then, feature extraction is carried out on input data through a convolutional layer, size adjustment is carried out on features in combination with an adaptive pooling mechanism, and the perception ability of the model to a local mode is enhanced; secondly, inputting the extracted features into a BiLSTM network to fully capture a time sequence dependency relationship in the BiLSTM network; and finally, Kolmogorov-Arnold Network (KAN) is introduced to carry out weighted fusion on the key features, final attack type classification is completed, and efficient and accurate intrusion detection is realized.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Real-time network intrusion detection method based on genetic algorithm and bidirectional long and short time memory network

The invention discloses a real-time network intrusion detection method based on a genetic algorithm and a bidirectional long-short term memory network, and belongs to the technical field of network security, and the method comprises the following steps: 1, extracting continuous and category network traffic features from a constructed data set, and carrying out the feature preprocessing and preliminary screening; step 2, performing feature selection optimization based on a genetic algorithm so as to screen out an optimal feature combination with high accuracy and low dimension; 3, adopting a bidirectional LSTM algorithm to construct an abnormal traffic detection model based on the feature subset selected by the genetic algorithm, wherein the abnormal traffic detection model is used for identifying normal and abnormal samples in the network traffic; 4, evaluating the performance of the abnormal traffic detection model by adopting the confusion matrix; and step 5, deployment and real-time detection of an abnormal flow detection model. According to the invention, a lightweight and traceable intrusion detection framework is constructed. The generalization ability and precision of the detection model are improved; the method gives consideration to accuracy, interpretability and system response capability.
Owner:NANJING UNIV OF SCI & TECH +1

Computer network intrusion detection system and method based on abnormal behavior analysis

The invention relates to the field of computer network intrusion detection based on abnormal behavior analysis, in particular to a computer network intrusion detection system and method based on abnormal behavior analysis. The method comprises the following steps: acquiring network flow data by using a data acquisition module, and fusing the network flow data to obtain fused network flow data; the feature extraction module performs feature extraction on the fusion network flow data by using a GGNN gating graph neural network, establishes an ST-Transform space-time joint detection model, performs parameter optimization on the detection model by using a multi-target particle swarm optimization algorithm, and the data detection module inputs the feature network flow data into the space-time joint detection model for detection. Outputting a data exception score; and the active response module is used for the system to perform active response according to the grade division of the data exception score. And the threat discovery and disposal capability in a complex attack scene is improved.
Owner:NANTONG UNIV

AI-driven efficient network intrusion detection system

The invention relates to the technical field of network security, and particularly discloses an AI-driven efficient network intrusion detection system, which comprises a flow acquisition and preprocessing module, a lightweight rule filtering engine module, an AI behavior analysis engine, a judgment and response module, an online learning module and a log and audit module, during the application period of the technical scheme, through a multi-module collaborative detection and disposal architecture, the functions of flow preprocessing, rule filtering, AI deep analysis, dynamic model optimization and full-dimension protection are integrated, so that known attacks can be quickly intercepted and unknown attacks can be accurately identified during use, and the security of the network flow is improved. And meanwhile, the attack change is dynamically adapted, the attacks are disposed in a grading manner, and the full attack chain is covered, so that an efficient and comprehensive intrusion detection effect is achieved, and the problems of multiple detection blind areas, high resource consumption, poor adaptability and narrow protection range in the prior art are solved.
Owner:SHANGHAI INTELLIGENT & CONNECTED VEHICLE R & D CENTER CO LTD

Network intrusion detection method and system based on federated learning and hybrid clustering

The invention discloses a federated learning and hybrid clustering network intrusion detection method and system, and relates to the technical field of network intrusion detection. The method comprises the following steps: a server issues a current global model parameter to a client participating in the current round of training; after each client receives the global model parameter, taking the global model parameter as an initialization parameter of a local model, performing training by using local data, introducing a clustering-based soft label generation mechanism and a classification and clustering parallel dual-task learning framework in the training process for training, and updating the local model parameter; the client encrypts and uploads the trained model parameters to the server; the server aggregates all client model parameters, generates a new generation of global model, and issues the parameters back to the client for next round of training; and after all rounds of training are finished, the server issues a final model for the client to carry out network intrusion discrimination. According to the method, the negative influence of data non-independent identical distribution is effectively overcome, and sparse attacks are accurately detected.
Owner:BEIJING INFORMATION SCI & TECH UNIV

Multi-generator adversarial network intrusion detection method based on imaging variational enhancement

The invention discloses a multi-generator adversarial network intrusion detection method based on imaging variational enhancement in the technical field of network security, which comprises the following steps of: 1, preprocessing data and encoding images, converting network flow data into a two-dimensional image format, and reserving spatial-temporal characteristics and protocol characteristics of the data for subsequent model training; step 2, constructing a multi-generator adversarial network, adopting a plurality of generators to work in parallel, each generator being responsible for generating attack samples of required categories, and optimizing model parameters of the generators and discriminators through an adversarial training process to enable the distribution of the generated attack samples to be close to the distribution of real attack samples; according to the method, the sample and the classification model are generated through collaborative optimization, the robustness and generalization ability of a network intrusion detection system on an unbalanced data set are remarkably improved, and an innovative solution is provided for network security detection.
Owner:YANGZHOU UNIV

Sensitivity-based network intrusion detection resampling method, system, equipment and medium

The invention discloses a sensitivity-based network intrusion detection resampling method, system and device and a medium, and relates to the technical field of data detection, and the method comprises the steps: obtaining network data containing normal traffic and attack traffic; prior probabilities and class condition probabilities of the two classes of data are calculated respectively, then posterior probabilities are obtained, and the sensitivity weight of each sample is calculated; carrying out putting-back undersampling on a normal flow sample according to the sensitivity weight; carrying out replacement oversampling on the attack traffic sample according to the sensitivity weight; a sampling process is repeated to generate a plurality of balance training subsets, and a base classifier is trained based on each subset; and calculating voting weights based on the performance evaluation indexes of the base classifiers on the verification set, and obtaining weighted voting results based on the voting weights to classify new data. Random undersampling neglects the importance of boundary samples to decision boundary learning, and sensitivity weighted sampling can guide the model to sample the boundary samples, so that important information is prevented from being lost.
Owner:GUANGXI POWER GRID CORP

Automobile heterogeneous network intrusion detection method based on QLoRA and knowledge distillation

The invention relates to an automobile heterogeneous network intrusion detection method based on QLoRA and knowledge distillation, and belongs to the technical field of intelligent networked automobile on-board network intrusion detection safety. The technical problems that an existing method is difficult to give consideration to light weight and high precision and cannot adapt to resource constraints of a vehicle-mounted embedded environment are solved. According to the technical scheme, the method comprises the steps that self-adaptive mapping and feature extraction are conducted on original data from a CAN bus and the Ethernet, and a unified annotation data set is constructed; a knowledge distillation framework based on BERT is designed, google-bert is used as a teacher model, tiansz-bert is used as a student model, model parameters are compressed by adopting a QLoRA quantification technology, and partial layers are frozen; knowledge of the teacher model is transmitted to the student model through knowledge distillation, and training is carried out in combination with soft and hard label loss. The technical effects are that lightweight intrusion detection is realized, resource consumption is reduced, high detection precision is maintained, and various network attack threats can be identified.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Network intrusion detection method and system based on artificial intelligence

The invention provides a network intrusion detection method and system based on artificial intelligence, and relates to the technical field of network intrusion detection, and the method comprises the steps: obtaining multi-dimensional behavior data of a terminal domain, a network link domain and an application layer domain, and employing a high-density or hierarchical collection strategy according to a network type; preprocessing the data through a standardization priority or coding priority scheme according to feature types; constructing a CNN-LSTM fusion model adaptive to network dynamics, and extracting space and time sequence correlation features; based on the sample condition, adopting full or incremental training to obtain a convergence model; a result is output through a high-precision or high-speed detection strategy in combination with scene requirements; and continuously iteratively optimizing the model based on the environmental change. The system correspondingly comprises a multi-domain data acquisition module, a data preprocessing module and the like. The method breaks through the limitation of single-domain detection, accurately recognizes cross-domain cooperative attacks, adapts to different network scenes, reduces the false alarm and missing alarm rate, improves the detection real-time performance and stability, and is suitable for various network environments such as enterprise intranets and hybrid clouds.
Owner:LEADCHUANG ANDA (BEIJING) TECHNOLOGY CO LTD

Network intrusion real-time detection method based on big data analysis

The invention relates to the technical field of data processing, in particular to a network intrusion real-time detection method based on big data analysis, and the method comprises the steps: obtaining access data of each interface in a to-be-monitored system at each moment in a preset historical time period, and obtaining an access data sequence by each interface; obtaining a mutual reference degree between every two interfaces according to a data association degree between the access data sequences of every two interfaces, and obtaining an abnormal access coefficient of any interface at any moment for access data of any interface at any moment in a preset historical time period; obtaining an abnormal access early warning index of each interface at any moment by using the abnormal access coefficient of each interface at any moment and the mutual reference degree between every two interfaces; and network intrusion detection is performed on each interface in the to-be-monitored system by using the abnormal access early warning index of each interface at each moment in the preset historical time period, so that the real-time performance and accuracy of network intrusion detection are improved.
Owner:SUZHOU KEZHI INFORMATION TECHNOLOGY CO LTD

Network intrusion detection system based on auto-encoder and double-branch Transform-CNN fusion architecture

The invention discloses a network intrusion detection system based on an auto-encoder and double-branch Transform-CNN fusion architecture, and the system comprises the following modules: an input layer which inputs a network flow sequence and carries out the preprocessing of the network flow sequence, and obtains a time window sequence with a fixed length; the auto-encoder module is used for performing feature dimension reduction and noise reconstruction on the time window sequence to extract low-dimensional feature representation, and then synchronously inputting the low-dimensional feature representation to a Transform branch and a CNN branch; the Transform branch is used for modeling a global dependency relationship and long-range context information in the time window sequence and completing extraction of global features; the CNN branch is used for extracting local space-time patterns and multi-scale features from the received time window sequence to complete extraction of local features; the attention fusion module is used for carrying out feature weight adjustment on the output of the Transform branch and the CNN branch, realizing dynamic feature fusion and outputting to an output layer; and the output layer outputs a detection result. According to the method, the feature representation capability and the model robustness are remarkably improved while the detection precision is kept.
Owner:ZHEJIANG SCI-TECH UNIV

A network intrusion detection method based on LSTM and attention mechanism

The application discloses a network intrusion detection method based on LSTM and an attention mechanism, and comprises the following steps: 1) data preprocessing and target sample construction; 2) WGAN model establishment and new training sample merging; 3) network intrusion detection model establishment based on LSTM and the attention mechanism; 4) training in the obtained network intrusion detection model; and 5) model performance evaluation. The method can improve the detection accuracy and the detection rate of minority class samples.
Owner:GUANGXI NORMAL UNIV

Network intrusion detection method based on adaptive ensemble learning and concept drift detection

The invention discloses a network intrusion detection method based on adaptive ensemble learning and concept drift detection, and the method can improve the detection accuracy and adaptability of an intrusion detection system under the conditions of unknown attacks and data concept drift. The precision of an existing model is remarkably reduced, and manual intervention is needed for recovery. The invention aims to provide a self-adaptive detection framework, so that the system can automatically identify and quickly adjust the failure of the model, autonomously complete the learning of new attacks and the updating of the model, and avoid frequent manual retraining. According to the method, the unknown attack detection capability is improved, and by integrating a plurality of heterogeneous classifiers and dynamically optimizing the combination of the heterogeneous classifiers, the method has stronger detection capability on never seen attack behaviors. Different models identify anomalies from different angles, the coverage rate of unknown attacks is improved, and the defect that a traditional single model misses detection of unknown threats is overcome.
Owner:NANJING FOREST POLICE COLLEGE +1

Computer network intrusion detection method and system based on artificial intelligence

The invention belongs to the technical field of artificial intelligence, and particularly relates to a computer network intrusion detection method and system based on artificial intelligence, and the method comprises the steps: constructing a finite state automaton to carry out the state jump compliance verification of a connection flow, intercepting the illegal flow, only sending the compliance flow into a feature engineering module, and extracting the multi-dimensional behavior features; inputting a deep neural network classification model to determine whether the behavior is an intrusion behavior; according to the technical scheme provided by the invention, the data input to the artificial intelligence model can be ensured to have complete compliance on the protocol level, so that the model is prevented from learning false feature association caused by protocol violation, and the antagonistic attack based on protocol state jump can be effectively resisted on the premise of not depending on adversarial training.
Owner:WEINAN NORMAL UNIV

Computer network intrusion detection system based on abnormal behavior analysis

The invention discloses a computer network intrusion detection system based on abnormal behavior analysis, which belongs to the technical field of network security, and comprises an edge data processing module, a cloud atlas construction module, an anomaly detection evolution module, an intelligent response feedback module and a system optimization module, the edge data processing module is used for collecting three types of multi-modal data including flow packet size distribution, protocol header field compliance and user keyboard tapping interval. According to the invention, edge data processing provides high-quality data, cloud atlas construction clearly presents a network state, anomaly detection evolution accurately identifies and deals with threats, intelligent response feedback timely processes anomalies and feeds back information, system optimization is continuously improved based on feedback, and all modules are closely matched to form a complete closed loop, so that a complex network environment is effectively dealt with; the overall security protection capability of the system is improved, reliable guarantee is provided for scenes such as enterprises, and intelligent development of network security is promoted.
Owner:SHENZHEN JINDA DIGITAL TECHNOLOGY CO LTD

Big data analysis processing method for intelligent network security

The invention provides a big data analysis processing method for intelligent network security, and relates to the technical field of network security analysis. The big data analysis processing method comprises the following steps: S1, collecting data from network traffic, system logs, application logs, endpoint equipment data, a network intrusion detection system, a firewall and other security equipment; s2, removing noise and redundant data from the collected data through cleaning and standardization technologies, and converting the data into a data format suitable for analysis; and S3, extracting meaningful features from the converted network security data, and extracting feature data capable of representing network behaviors by using a statistical method and a data analysis tool. According to the invention, artificial intelligence, machine learning, a data mining technology and a big data analysis platform are combined to help to identify, predict and cope with network security threats, so that the accuracy, response speed and pre-judgment capability of network security protection can be remarkably improved, and modern complex and changeable network attack threats can be effectively coped with.
Owner:QUANYU (SHENZHEN) INFORMATION TECHNOLOGY CO LTD

A network intrusion detection system based on deep reinforcement learning method against attack

PendingCN122640162APattern recognitionAlgorithm
A network intrusion detection system counterattack method, the method comprises the following steps: training a Transform flow feature encoder based on a SimCLR contrast learning framework, extracting a feature representation of a network flow, and constructing a flow feature embedding space; using flow feature similarity to retrieve the most similar benign flow for the target malicious flow, pre-training a strategy network through behavior cloning to achieve imitation learning warm-up; using flow feature similarity increments as intermediate rewards, weighting with escape rewards to construct a deep reinforcement learning reward function; using a curriculum learning strategy to dynamically adjust the reward weight, training a PPO algorithm in a continuous action space to generate a counterattack flow, and realizing counterattack. The cold start problem of deep reinforcement learning is solved through imitation learning warm-up, the sparse reward problem in long sequence decision is alleviated through similarity intermediate reward, and the success rate of counterattack is significantly improved.
Owner:SHANGHAI JIAOTONG UNIV

Class imbalance network intrusion detection method and system

The invention provides a class imbalance network intrusion detection method and system, and belongs to the technical field of network security, and the method comprises the steps: introducing a hypergraph to simulate an interaction relationship between network entities, and capturing group-based high-order interaction behaviors in a network; selecting a topological feature as a persistent structure according to the duration, and setting a hyper-parameter weight to update the current edge; student models on benign behaviors and malicious behaviors are trained through a comparison knowledge distillation method, and benign behaviors and malicious behaviors are distinguished. Therefore, the boundary of benign and malicious behaviors is clearer, the discrimination is improved, the adverse effect of class imbalance distribution on the detection performance is effectively relieved, and the network intrusion detection precision is enhanced.
Owner:SHANDONG NORMAL UNIV