Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

143 results about "Network intrusion detection" patented technology

Industrial internet network intrusion detection method based on pre-trained large language model

The invention provides an industrial internet network intrusion detection method based on a pre-trained large language model, and the method comprises the steps: carrying out the data preprocessing of original network flow data through protocol self-adaptive flow aggregation and session segmentation, feature screening and feature coding; constructing a stream format text data set used for training a generation model GPT-2 and a packet level classification text-label data set used for training a classification model DistilBERT; then fine tuning training is carried out on the generation model GPT-2 and the classification model DistilBERT; then calling a trained generation model GPT-2 to generate a traffic sequence, obtaining a prediction data packet, calling a trained classification model DistilBERT, performing anomaly judgment on sequence data in the prediction data packet one by one, and outputting a classification result of anomaly judgment; the active intrusion detection of first generation and then discrimination is realized. According to the method, prediction can be made before real attack traffic arrives, and network attacks are prevented.
Owner:EAST CHINA JIAOTONG UNIVERSITY

AI-driven efficient network intrusion detection system

The invention relates to the technical field of network security, and particularly discloses an AI-driven efficient network intrusion detection system, which comprises a flow acquisition and preprocessing module, a lightweight rule filtering engine module, an AI behavior analysis engine, a judgment and response module, an online learning module and a log and audit module, during the application period of the technical scheme, through a multi-module collaborative detection and disposal architecture, the functions of flow preprocessing, rule filtering, AI deep analysis, dynamic model optimization and full-dimension protection are integrated, so that known attacks can be quickly intercepted and unknown attacks can be accurately identified during use, and the security of the network flow is improved. And meanwhile, the attack change is dynamically adapted, the attacks are disposed in a grading manner, and the full attack chain is covered, so that an efficient and comprehensive intrusion detection effect is achieved, and the problems of multiple detection blind areas, high resource consumption, poor adaptability and narrow protection range in the prior art are solved.
Owner:SHANGHAI INTELLIGENT & CONNECTED VEHICLE R & D CENTER CO LTD

Network intrusion detection method and system based on federated learning and hybrid clustering

The invention discloses a federated learning and hybrid clustering network intrusion detection method and system, and relates to the technical field of network intrusion detection. The method comprises the following steps: a server issues a current global model parameter to a client participating in the current round of training; after each client receives the global model parameter, taking the global model parameter as an initialization parameter of a local model, performing training by using local data, introducing a clustering-based soft label generation mechanism and a classification and clustering parallel dual-task learning framework in the training process for training, and updating the local model parameter; the client encrypts and uploads the trained model parameters to the server; the server aggregates all client model parameters, generates a new generation of global model, and issues the parameters back to the client for next round of training; and after all rounds of training are finished, the server issues a final model for the client to carry out network intrusion discrimination. According to the method, the negative influence of data non-independent identical distribution is effectively overcome, and sparse attacks are accurately detected.
Owner:BEIJING INFORMATION SCI & TECH UNIV

Multi-generator adversarial network intrusion detection method based on imaging variational enhancement

The invention discloses a multi-generator adversarial network intrusion detection method based on imaging variational enhancement in the technical field of network security, which comprises the following steps of: 1, preprocessing data and encoding images, converting network flow data into a two-dimensional image format, and reserving spatial-temporal characteristics and protocol characteristics of the data for subsequent model training; step 2, constructing a multi-generator adversarial network, adopting a plurality of generators to work in parallel, each generator being responsible for generating attack samples of required categories, and optimizing model parameters of the generators and discriminators through an adversarial training process to enable the distribution of the generated attack samples to be close to the distribution of real attack samples; according to the method, the sample and the classification model are generated through collaborative optimization, the robustness and generalization ability of a network intrusion detection system on an unbalanced data set are remarkably improved, and an innovative solution is provided for network security detection.
Owner:YANGZHOU UNIV

Automobile heterogeneous network intrusion detection method based on QLoRA and knowledge distillation

The invention relates to an automobile heterogeneous network intrusion detection method based on QLoRA and knowledge distillation, and belongs to the technical field of intelligent networked automobile on-board network intrusion detection safety. The technical problems that an existing method is difficult to give consideration to light weight and high precision and cannot adapt to resource constraints of a vehicle-mounted embedded environment are solved. According to the technical scheme, the method comprises the steps that self-adaptive mapping and feature extraction are conducted on original data from a CAN bus and the Ethernet, and a unified annotation data set is constructed; a knowledge distillation framework based on BERT is designed, google-bert is used as a teacher model, tiansz-bert is used as a student model, model parameters are compressed by adopting a QLoRA quantification technology, and partial layers are frozen; knowledge of the teacher model is transmitted to the student model through knowledge distillation, and training is carried out in combination with soft and hard label loss. The technical effects are that lightweight intrusion detection is realized, resource consumption is reduced, high detection precision is maintained, and various network attack threats can be identified.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Network intrusion detection method and system based on artificial intelligence

The invention provides a network intrusion detection method and system based on artificial intelligence, and relates to the technical field of network intrusion detection, and the method comprises the steps: obtaining multi-dimensional behavior data of a terminal domain, a network link domain and an application layer domain, and employing a high-density or hierarchical collection strategy according to a network type; preprocessing the data through a standardization priority or coding priority scheme according to feature types; constructing a CNN-LSTM fusion model adaptive to network dynamics, and extracting space and time sequence correlation features; based on the sample condition, adopting full or incremental training to obtain a convergence model; a result is output through a high-precision or high-speed detection strategy in combination with scene requirements; and continuously iteratively optimizing the model based on the environmental change. The system correspondingly comprises a multi-domain data acquisition module, a data preprocessing module and the like. The method breaks through the limitation of single-domain detection, accurately recognizes cross-domain cooperative attacks, adapts to different network scenes, reduces the false alarm and missing alarm rate, improves the detection real-time performance and stability, and is suitable for various network environments such as enterprise intranets and hybrid clouds.
Owner:LEADCHUANG ANDA (BEIJING) TECHNOLOGY CO LTD

Network intrusion detection system based on auto-encoder and double-branch Transform-CNN fusion architecture

The invention discloses a network intrusion detection system based on an auto-encoder and double-branch Transform-CNN fusion architecture, and the system comprises the following modules: an input layer which inputs a network flow sequence and carries out the preprocessing of the network flow sequence, and obtains a time window sequence with a fixed length; the auto-encoder module is used for performing feature dimension reduction and noise reconstruction on the time window sequence to extract low-dimensional feature representation, and then synchronously inputting the low-dimensional feature representation to a Transform branch and a CNN branch; the Transform branch is used for modeling a global dependency relationship and long-range context information in the time window sequence and completing extraction of global features; the CNN branch is used for extracting local space-time patterns and multi-scale features from the received time window sequence to complete extraction of local features; the attention fusion module is used for carrying out feature weight adjustment on the output of the Transform branch and the CNN branch, realizing dynamic feature fusion and outputting to an output layer; and the output layer outputs a detection result. According to the method, the feature representation capability and the model robustness are remarkably improved while the detection precision is kept.
Owner:ZHEJIANG SCI-TECH UNIV

A network intrusion detection method based on LSTM and attention mechanism

The application discloses a network intrusion detection method based on LSTM and an attention mechanism, and comprises the following steps: 1) data preprocessing and target sample construction; 2) WGAN model establishment and new training sample merging; 3) network intrusion detection model establishment based on LSTM and the attention mechanism; 4) training in the obtained network intrusion detection model; and 5) model performance evaluation. The method can improve the detection accuracy and the detection rate of minority class samples.
Owner:GUANGXI NORMAL UNIV

Computer network intrusion detection method and system based on artificial intelligence

The invention belongs to the technical field of artificial intelligence, and particularly relates to a computer network intrusion detection method and system based on artificial intelligence, and the method comprises the steps: constructing a finite state automaton to carry out the state jump compliance verification of a connection flow, intercepting the illegal flow, only sending the compliance flow into a feature engineering module, and extracting the multi-dimensional behavior features; inputting a deep neural network classification model to determine whether the behavior is an intrusion behavior; according to the technical scheme provided by the invention, the data input to the artificial intelligence model can be ensured to have complete compliance on the protocol level, so that the model is prevented from learning false feature association caused by protocol violation, and the antagonistic attack based on protocol state jump can be effectively resisted on the premise of not depending on adversarial training.
Owner:WEINAN NORMAL UNIV

Computer network intrusion detection system based on abnormal behavior analysis

The invention discloses a computer network intrusion detection system based on abnormal behavior analysis, which belongs to the technical field of network security, and comprises an edge data processing module, a cloud atlas construction module, an anomaly detection evolution module, an intelligent response feedback module and a system optimization module, the edge data processing module is used for collecting three types of multi-modal data including flow packet size distribution, protocol header field compliance and user keyboard tapping interval. According to the invention, edge data processing provides high-quality data, cloud atlas construction clearly presents a network state, anomaly detection evolution accurately identifies and deals with threats, intelligent response feedback timely processes anomalies and feeds back information, system optimization is continuously improved based on feedback, and all modules are closely matched to form a complete closed loop, so that a complex network environment is effectively dealt with; the overall security protection capability of the system is improved, reliable guarantee is provided for scenes such as enterprises, and intelligent development of network security is promoted.
Owner:SHENZHEN JINDA DIGITAL TECHNOLOGY CO LTD

Deep learning-based network intrusion detection method and system

This application provides a network intrusion detection method and system based on deep learning. The method includes: capturing raw network traffic data in real time using traffic collectors deployed on network nodes; performing data cleaning, feature standardization, and feature filtering on the raw traffic data to obtain optimized feature vectors; constructing an ensemble model containing base classifiers and meta classifiers, and training the ensemble model using the optimized feature vectors, wherein training the ensemble model includes stacking the prediction results of the base classifiers to form new feature vectors to train the meta classifiers; collecting network traffic features in real time and preprocessing the network traffic features; inputting the preprocessed network traffic feature vectors into the trained ensemble model, and determining the risk of intrusion behavior based on the output probability of the ensemble model, as well as performing risk classification and alarms.
Owner:HUANENG POWER INT INC +1

A network intrusion real-time detection method based on big data analysis

The application relates to the technical field of data processing, in particular to a network intrusion real-time detection method based on big data analysis. The method acquires access data of each interface in a preset historical period at each time in a to-be-monitored system, and each interface obtains an access data sequence; according to the data correlation degree between the access data sequences of each two interfaces, the mutual reference degree between each two interfaces is acquired; for the access data of any interface at any time in the preset historical period, the abnormal access coefficient of any interface at any time is acquired; the abnormal access early warning index of each interface at any time is acquired by using the abnormal access coefficient of each interface at any time and the mutual reference degree between each two interfaces; and the network intrusion detection of each interface in the to-be-monitored system is carried out by using the abnormal access early warning index of each interface at each time in the preset historical period, so that the real-time performance and accuracy of network intrusion detection are improved.
Owner:SUZHOU KEZHI INFORMATION TECHNOLOGY CO LTD

Self-supervised network intrusion detection method based on multi-scale feature fusion

The invention relates to the technical field of computer network security and deep learning, in particular to a self-supervised network intrusion detection method based on multi-scale feature fusion, and adopts the technical scheme that a local node level contrast learning module and a global sub-graph level contrast learning module are designed and collaboratively optimized in the same graph neural network framework; the limitation of single feature learning view angle of the existing method is overcome; the proposed double-contrast learning normal form drives the model to learn highly distinguishable feature embedding through an elaborately designed positive and negative sample construction strategy and a dynamic weighting mechanism introducing topology perception under the condition of not needing any traffic label; the method is completely based on self-supervised learning, gets rid of dependence on a large amount of expensive and difficult-to-obtain annotation data, and is more suitable for the current situation that real network environment data annotation is scarce; meanwhile, the model has high training and reasoning efficiency, and can meet the requirements for real-time or quasi-real-time detection in an actual scene.
Owner:HAINAN UNIV

Deep learning method, device, storage medium and computer equipment for network intrusion detection identification

ActiveCN118260593BTerm memoryNetwork model
The application discloses a kind of network intrusion detection identification deep learning method, device, storage medium and computer equipment, this method uses Concise-former neural network model based on the improvement of Transformer model, convolution gate self-attention layer is introduced in encoder module, to enhance the mining of local dependence in sequence data for encoder module, further strengthen the expression ability and generalization ability of network, improve the accuracy and stability of intrusion detection, by simplifying network, reduce the algorithm complexity of model, improve the calculation efficiency of model.In addition, the method of the application also uses joint learning to train neural network, so as to greatly improve the calculation speed of the model and reduce the memory consumption under the condition of ensuring accuracy, improve the practicability and flexibility of intrusion detection.Therefore, the present application can effectively detect various types of network intrusion.
Owner:JINAN UNIVERSITY

Network intrusion detection method based on deep learning and related device

The invention discloses a deep learning-based network intrusion detection method and a related device. The method comprises the following steps: inputting to-be-detected network traffic into a pre-constructed network intrusion detection model for detection to obtain a network intrusion detection result; the network intrusion detection model adopts a three-dimensional data sequence generation method based on a bidirectional time sliding window, and can effectively capture a local time sequence relationship between adjacent flow groups, thereby remarkably improving the detection precision of the model. Meanwhile, a context position encoding strategy is introduced into an encoder of the model, position information and context information are combined, and a more efficient and more flexible position encoding mode is provided. The encoder is arranged, so that the capability of the model in identifying network traffic abnormity is enhanced, and the fine change of the traffic mode can be more accurately captured.
Owner:SHAANXI UNIV OF SCI & TECH

A network intrusion detection model end-to-end adversarial training defense method and device

This invention relates to the field of network security technology, and more particularly to a method and apparatus for adversarial training and defense of a network intrusion detection model. The method includes: dynamically outputting attack strategies based on traffic feature vectors and current strategy parameters using an adversarial strategy generator; imposing restrictions on perturbations in the problem space through adversarial domain constraints to ensure that the generated adversarial samples conform to network protocol specifications and feature logic consistency requirements; and forming a dynamic game mechanism by alternately executing adversarial training and strategy parameter optimization between the intrusion detection model and the adversarial strategy generator. This allows the model to gradually improve its defense capabilities against mixed threats in the feature space and problem space as it continuously adapts to increasingly complex attack patterns, ultimately achieving a synergistic improvement in the robustness and generalization of the intrusion detection model.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719

A network traffic concept drift detection method based on count-min sketch data structure

The application relates to a network traffic concept drift detection method based on a Count-Min sketch data structure and belongs to the network traffic analysis field. The application records the multidimensional statistical information of network traffic through a CM sketch data structure, starts from the multidimensional probability distribution of network flow, monitors the multidimensional Hellinger distance change condition every certain period, performs network traffic concept drift detection, and detects the type of network traffic concept drift based on the Euclidean distance. The application records the multidimensional statistical information of network traffic through a CM sketch data structure, saves the storage space, each dimension is relatively independent, can be processed in parallel, and saves the detection time; starts from the multidimensional probability distribution of network flow, monitors the multidimensional Hellinger distance change condition, performs network traffic concept drift detection, reduces the concept drift false detection rate and the missed detection rate, makes the detection result more accurate; can correctly identify the network traffic concept drift type, discovers new applications and distributed drift applications, and has important significance in network intrusion detection and the like.
Owner:BEIJING INST OF COMP TECH & APPL

A network intrusion detection method, system, electronic device and storage medium

The application discloses a network intrusion detection method and system, electronic equipment and a storage medium. The method inputs to-be-detected data into a plurality of trained classifiers to perform network intrusion detection, and obtains an intrusion detection result output by each trained classifier. A firefly algorithm is used to perform firefly position optimization on each first firefly population to obtain a target firefly individual. The target firefly individuals of each first firefly population are combined to form a new population, and a target firefly individual meeting a target condition in the new population is found out. The target firefly individual in the new population is added to each first firefly population as a second firefly population for next iteration until the firefly algorithm reaches a maximum iteration number, and the position of the target firefly individual is obtained. According to a plurality of weight coefficients and the intrusion detection result output by each trained classifier, a final intrusion detection result is calculated. The application can improve the accuracy of network intrusion detection.
Owner:PENG CHENG LAB +2

Model theft attack query detection method for machine learning based network intrusion detection system

PendingCN122339792AAttackEngineering
The application relates to a model stealing attack query detection method for a machine learning-based network intrusion detection system and relates to the technical field of network attack detection.The application aims to solve the technical problem of combining query samples and model responses for comprehensive analysis, adopting a combination of decision boundary leakage evaluation and reconstruction error evaluation to quickly identify model stealing attacks with a small amount of query samples.The technical points are as follows: the prediction results of the query samples are used to construct a cumulative distribution function, the model uncertainty is measured, and potential boundary detection behaviors are detected; the reconstruction error loss of the query samples is calculated by using an automatic encoder, potential abnormal queries deviating from the normal distribution but not showing obvious malicious characteristics are identified; based on the results of the decision boundary leakage evaluation and the reconstruction error evaluation, a model safety coefficient is calculated to comprehensively evaluate the possibility of whether the model is subjected to a model stealing attack in a set period of time.The application is suitable for scenes where the ML-NIDS needs to be quickly detected and real-timely defended.
Owner:HARBIN INST OF TECH

End-to-end vehicle networking intrusion detection method, system and device based on learnable mask

The application discloses an end-to-end vehicle networking intrusion detection method, system and equipment based on a learnable mask, and relates to the technical field of automatic driving.The application constructs an end-to-end architecture comprising data processing, sparse learnable mask selection, multi-layer CNN feature extraction and classification, generates a sparse mask through a trainable mask parameter, realizes adaptive and accurate screening of features, inputs the screened features into a feature intrusion detection model for feature extraction and classification detection output, and simultaneously trains the feature selection and the intrusion detection model in a joint manner and updates the end-to-end parameters by using a joint loss function.The application does not need an independent feature selection process, the model parameters can be updated in a cooperative manner, is suitable for adapting to new attack scenarios of vehicle networking, takes into account the real-time performance and explainability of detection, and is suitable for multi-type network intrusion detection of automatic driving vehicle networking.
Owner:SOUTHEAST UNIV

Network intrusion detection method and device, equipment, storage medium and program product

The invention discloses a network intrusion detection method and device, equipment, a storage medium and a program product. The method comprises the following steps: acquiring network traffic data to be processed; detecting the network flow data by adopting a pre-trained network intrusion detection model to obtain a network intrusion result; wherein the network intrusion detection model is obtained by training a centralized multi-core multi-class support vector machine through a pre-constructed sample set, and the sample set is obtained by performing data enhancement on abnormal samples subjected to network intrusion through a synthetic minority class oversampling algorithm based on distance weight; the problem of unbalanced data sets can be effectively solved, meanwhile, the selection problem of kernel functions can be avoided, and the network intrusion detection performance of the model is improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Computer Network Intrusion Detection and Prevention Methods Based on Anomaly Data Analysis

This application discloses a computer network intrusion detection and defense method based on anomaly data analysis, relating to the field of computer network technology. The method includes: collecting a multi-dimensional dataset; extracting the correlations between anomaly data to form an anomaly correlation rule set; fusing multi-source features to form an anomaly feature set; establishing an intelligent agent model; the intelligent agent executing an attack task; inputting the anomaly data set into the intrusion detection model to obtain the first-stage detection result; comparing and analyzing the first-stage detection result with the first-stage simulated attack result to obtain feedback information; optimizing the second-stage attack strategy and executing the optimized second-stage attack strategy to obtain the second-stage detection result; extracting anomaly features to form a final anomaly feature set; generating repair instructions based on the final anomaly feature set and executing the repair instructions to repair the computer network. This application's method overcomes the limitations of single attack simulation and deepens the two-stage attack optimization, improving detection accuracy.
Owner:XIANYANG VOCATIONAL TECHN COLLEGE

A network intrusion detection method and device, computer equipment and storage medium

The application belongs to the field of information security, and relates to a network intrusion detection method and device, computer equipment and a storage medium. The method comprises the following steps: collecting historical traffic data and performing structural preprocessing on the historical traffic data; based on the difference between normal traffic (majority class) and attack traffic (minority class), new synthetic minority class samples are generated through active boundary oversampling; a branch convolutional neural network model is constructed, independent branch networks are designed for different protocol layers, and normal traffic and various types of abnormal traffic are distinguished; the branch convolutional neural network model is supervised and trained, and model parameters are optimized; the branch convolutional neural network model that has been trained and optimized is deployed to a production environment for real-time traffic intrusion detection; and the prediction feedback of the branch convolutional neural network model in a real environment and new network threat samples are continuously collected. The active boundary can be optimized; controllability and safety are strong; and intelligent identification of protocol layer features can be performed.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

An automated intrusion detection system for dynamic network environments

The application relates to the technical field of network intrusion detection, in particular to an automatic intrusion detection system for a dynamic network environment, which has the technical scheme that in the autonomous decision module of Gaussian probability, a contrast loss function taking normal traffic as the center is designed, so that the model can efficiently distinguish the behavior patterns of normal traffic and abnormal traffic; in the automatic continuous learning framework, a double memory bank is designed to adapt to the concept drift scene in the dynamic network, wherein the stable memory bank is used for storing old knowledge and preventing the catastrophic forgetting of the model, and the high-confidence pseudo label generated in the autonomous decision module of Gaussian probability is used to update the adaptive memory bank, so that the real-time updating and fine-tuning of the autonomous decision module of Gaussian probability are realized; in the continuous learning process, the system does not need to rely on manual labeling, can effectively capture the constantly evolving patterns in the dynamic network scene, significantly enhances the applicability of the intrusion detection system to the concept drift, and realizes automatic intrusion detection.
Owner:HAINAN UNIV

Network intrusion intelligent security detection method and system based on behavior analysis

The invention provides a network intrusion intelligent security detection method and system based on behavior analysis, and relates to the technical field of network security, and the method comprises the steps: firstly capturing behavior logic fragments of an access main body in a network environment, and forming a behavior logic fragment set containing records of an operation behavior logic relation and the like; reconstructing an intention conduction chain reflecting a behavior intention transmission path based on the behavior logic fragment set, performing nodal disassembly on the intention conduction chain to obtain an intention conduction node set, and performing reverse logic deduction matching on the intention conduction node set and a preset intrusion intention node library to obtain a deduction matching result; and finally, an intrusion intention initial conduction node and a full-link conduction path are positioned according to a deduction matching result, a network intrusion security detection instruction is generated and sent to a security response system, the accuracy and timeliness of network intrusion detection are improved, and the network environment security is guaranteed.
Owner:FOSHAN WABON ELECTRONICS TECH

Industrial control system intrusion detection method based on category enhancement graph learning

The invention relates to the technical field of network intrusion detection, in particular to an industrial control system intrusion detection method based on category enhancement graph learning, which comprises the following steps: carrying out communication relationship modeling on flow data among a plurality of industrial control devices to obtain a line graph model, and carrying out graph enhancement on the line graph model to obtain a category enhancement graph; and training the graph convolutional network model based on the category enhanced graph, optimizing the graph convolutional network model by adopting supervised contrast learning and cross entropy loss in the training process, and outputting the optimized graph convolutional network model. In order to solve the problem that interaction data analysis needs a large amount of annotation data, and consequently the effect in an industrial small sample scene is poor, a line graph model is established for data traffic between industrial control devices and is further enhanced, so that the feature difference of different attack categories and the compactness of similar attacks are enhanced; and the intra-class feature similarity and the inter-class difference are constrained by supervising and comparing the loss function, so that the detection robustness and the generalization ability of the model under the low sample condition are remarkably improved.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Network intrusion detection method and system based on firewall

The invention relates to the technical field of data information transmission, in particular to a network intrusion detection method and system based on a firewall, and the method comprises the steps: determining a network instability time period in an association time period of a current moment, and carrying out the detection of the network intrusion according to the condition of a user in an online state at each moment in the network instability time period and the unstable condition of the total flow of a campus network; determining a suspected intrusion time period, obtaining the abnormal behavior intensity of each user according to the active moment of each user in the suspected intrusion time period and the correlation between the user traffic of the active moment and the total traffic of the campus network, and further obtaining the network intrusion risk of the suspected intrusion time period; according to the network intrusion risk of each suspected intrusion time period in the associated time period, the degree of network intrusion threat received at the current moment is obtained, the possibility of misjudgment can be greatly reduced, and therefore the accuracy of a campus network intrusion detection result is improved.
Owner:BEIJING BOHAN TECH CO LTD

A network intrusion detection counter sample defense method and device

The present application relates to the technical field of network security, and particularly relates to a network intrusion detection adversarial sample defense method and device, which comprises the following steps: extracting features of input network traffic to obtain traffic feature vectors of clean samples, which are then used to train a denoising diffusion probability model to obtain a target denoising diffusion probability model; inputting the traffic feature vectors of multiple clean samples into the target denoising diffusion probability model for reconstruction, outputting reconstruction loss corresponding to each clean sample, and determining an adversarial detection threshold based on the statistical distribution of the reconstruction loss corresponding to each clean sample; inputting the traffic feature vector of a to-be-detected sample into the target denoising diffusion probability model to output the reconstruction loss of the to-be-detected sample; determining whether the reconstruction loss of the to-be-detected sample is greater than the adversarial detection threshold, and if yes, determining that the to-be-detected sample is an adversarial sample, otherwise, determining that the to-be-detected sample is a clean sample; and performing adversarial detection based on the denoising diffusion probability model to effectively recover the sample features affected by adversarial perturbations.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719

A network intrusion detection method, device and equipment

The application provides a network intrusion detection method, device and equipment, belongs to the technical field of network security, and solves the problems of insufficient cross-modal feature fusion, weak complex attack modeling capability and poor self-adaptive capability of the traditional network intrusion detection method. The method comprises the following steps: acquiring network traffic data; preprocessing the network traffic data to obtain traffic data packets; extracting features from the traffic data packets to obtain a multi-modal feature set; performing point-line analysis and processing on the multi-modal feature set to obtain heterogeneous graph data; inputting the heterogeneous graph data into a detection model for processing to obtain a graph-level feature vector; and determining intrusion type data according to the graph-level feature vector. The scheme improves the detection accuracy of diversified attacks, enhances the structural perception capability of complex attacks, and improves the robustness and generalization.
Owner:ZHENGZHOU UNIVERSITY OF AERONAUTICS +1