Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

353 results about "Network intrusion detection" patented technology

Network intrusion detection method and system based on behavior analysis

The invention relates to the technical field of network security, in particular to a network intrusion detection method and system based on behavior analysis, and the method comprises the steps: collecting real-time data of a target network, the real-time data comprising network flow data, user access logs, equipment state parameters, inter-user interaction logs and trust relationship data; performing space-time correlation analysis on the real-time data to generate a dynamic behavior graph; performing anomaly detection on the dynamic behavior map to generate an abnormal node list; and executing attack blocking based on the abnormal node list. According to the invention, the recognition and defense capabilities of abnormal behaviors are effectively improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Network intrusion detection method and system based on edge attention learning

The invention discloses a network intrusion detection method and system based on edge attention learning, and a storage medium, and the method comprises the steps: converting an original network flow into a network flow diagram, and constructing a training diagram and a test diagram under the condition that a coarse-grained label and a fine-grained label are reserved; edge embedding representation is obtained through edge feature reservation, adaptive weight distribution and multi-layer feature extraction of the training graph and the test graph; based on the edge embedding representation, performing coarse-grained detection to identify a basic attack category, and performing fine-grained classification by using multi-scale feature fusion related to global graph attributes; and adversarial training: through initializing adversarial disturbance and optimizing disturbance based on loss function gradient iteration, superposing final disturbance into the training graph, and based on loss function back propagation updating, obtaining a trained network intrusion detection model. The method provided by the invention can effectively capture the depth characteristics of the key attack and maintain the stable detection performance in the confrontation environment.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Network intrusion detection and defense system based on artificial intelligence

The invention provides a network intrusion detection and defense system based on artificial intelligence, which belongs to the technical field of network security and comprises a three-dimensional behavior map modeling module, a multi-modal adversarial training module and an edge collaborative defense module. Wherein the three-dimensional behavior graph modeling module is used for constructing a dynamic interaction relation graph of a network entity (user / equipment / service) through a space-time fused graph convolutional network (SF-GCN) and calculating an adaptive behavior entropy value Hnet. According to the network intrusion detection and defense system based on artificial intelligence provided by the invention, the comprehensive detection rate is greatly improved, the false alarm rate is greatly reduced, and the missing report rate is greatly reduced; the end-to-end delay is effectively reduced, and the strategy generation speed is greatly increased; the model size is obviously reduced, the reasoning delay is obviously shortened, and the resource consumption is obviously reduced; dynamic defense strategies of finance, Internet of Things and other scenes are supported, and the blocking success rate is greatly improved; the protocol compliance is obviously improved, and the federal learning data leakage risk is greatly reduced.
Owner:SHANGHAI ENYA INTELLIGENT TECH CO LTD

Lightweight network intrusion detection method integrating multiple tasks and transfer learning

The invention relates to a lightweight network intrusion detection method fusing multiple tasks and transfer learning. The method comprises the following steps: acquiring to-be-detected traffic data; the to-be-detected traffic data are input into a multi-task intrusion detection model, whether the to-be-detected traffic is abnormal or not is judged, abnormal traffic is classified, performance indexes of network traffic are predicted, and the multi-task intrusion detection model is constructed based on a pre-trained lightweight deep learning model and is obtained through training of a training set. The training set comprises two-dimensional image data marked as normal traffic or abnormal traffic, attack categories and continuous values. According to the method, collaborative optimization of tasks such as anomaly detection, attack classification and performance prediction is realized, the overall performance of detection is remarkably improved, and meanwhile, efficient and accurate network traffic analysis can still be realized under the condition of limited data by utilizing the pre-trained lightweight deep learning model in transfer learning.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Network intrusion detection method and system based on dynamic graph attention and comparative learning

The invention discloses a network intrusion detection method and system based on dynamic graph attention and comparative learning. Network traffic is constructed into a dynamic heterogeneous graph (nodes are IPs / ports, and sides are traffic sessions), and dynamic feature fusion is carried out by adopting time window division and a GATv2 network. An optimal transmission contrast learning strategy is innovatively introduced, feature and structure distribution alignment is realized through a Wasserstein distance and a Gaussian Wasserstein distance, and the generalization ability of the model to unknown attacks is improved. And finally, combining node embedding and an alignment matrix, and utilizing an MLP classifier to predict an edge anomaly probability. Experiments show that the accuracy and F1-score of the method on multiple data sets are improved by 5.2%-10.5% compared with those of a baseline, the detection performance under complex attacks is remarkably enhanced, and the method is suitable for real-time scenes such as the Internet of Things. The system can be deployed on edge equipment and has high practical value.
Owner:ROCKET FORCE UNIV OF ENG

Network intrusion detection method and system based on recursive gating convolution

The invention discloses a network intrusion detection method and system based on recursive gating convolution, and relates to the technical field of data processing. The method comprises the steps of obtaining to-be-predicted traffic data; obtaining a network intrusion detection model; training the network intrusion detection model, wherein the training comprises the steps of dividing traffic slices for the preprocessed training data according to a fixed time window; calculating a fusion feature value of each time window and the spatial dimension; generating a spatial-temporal characteristic matrix; splicing the spatial-temporal feature matrix with the preprocessed training data to form an enhanced feature set; constructing a teacher model and a student model; training the teacher model and training the student model; and inputting the to-be-predicted traffic data into a trained network intrusion detection model to obtain a prediction result. Through time window division and time-space fusion, the diversity of data is artificially expanded, so that the model contacts richer scenes in training, and the dependence on specific sample distribution is reduced.
Owner:SOUTHWEST PETROLEUM UNIV

Quantum-enhanced multi-scale network intrusion detection method and device, and storage medium

The invention relates to the technical field of artificial intelligence, and provides a quantum-enhanced multi-scale network intrusion detection method, which comprises the following steps: calculating a covariance matrix for an original traffic feature matrix, and obtaining a feature value and a feature vector through feature decomposition, mapping each sample xi to a quantum Hilbert space to generate an enhanced feature matrix, executing complex field transformation on the enhanced feature matrix to generate an entangled feature tensor, and realizing dynamic feature enhancement through a multi-head attention mechanism based on a quantum probability amplitude; performing space-time attention calculation and gating fusion on the feature tensor after dynamic feature enhancement to obtain a space-time fusion feature; converting the space-time fusion features into a time sequence form, extracting behavior features through a multi-scale convolution branch, and fusing the behavior features to obtain a three-dimensional feature tensor; and calculating a mean value of the three-dimensional feature tensor in a sequence dimension, generating a two-dimensional feature matrix, and performing classification prediction, uncertainty quantification and threat grading evaluation based on a classification network, an uncertainty network and a threat grading network.
Owner:HARBIN UNIV OF COMMERCE

Universal intrusion detection and prevention for vehicle networks

A system including a vehicle, a controller, and an intrusion response component. The vehicle has a plurality of network zones, each network zone including a plurality of end points. The controller includes: a network monitoring component configured to interpret network communications associated with at least one of the network zones; and a network intrusion detection component configured to detect an intrusion event in response to the network communications. The intrusion response component is configured to perform an intrusion response operation in response to the detected intrusion event.
Owner:SONATUS INC

Network intrusion detection method and system, terminal and storage medium

The invention provides a network intrusion detection method and system, a terminal and a storage medium, and the method comprises the steps: determining a target sampling strategy according to the sample number of preprocessed data, and carrying out the sampling of the preprocessed data according to the target sampling strategy, and obtaining a sampling sample; inputting the sampled sample into a network intrusion detection model for feature extraction, deep information extraction and multi-head attention mechanism calculation to obtain a global feature vector; performing data type prediction according to the global feature vector, and calculating model loss based on a weight balance loss function dynamically adjusted based on the category number; training the network intrusion detection model according to the model loss; and inputting to-be-detected network data into the converged network intrusion detection model for intrusion detection to obtain a network intrusion detection result. According to the embodiment of the invention, the pre-processed data is sampled in a layered sampling mode, so that the phenomenon of unbalanced sample data category is effectively prevented.
Owner:JIANGXI TONGFU TECH

Network intrusion detection method based on self-attention residual generative adversarial network

The invention discloses a network intrusion detection method based on a self-attention residual generative adversarial network, which belongs to the technical field of network intrusion detection and comprises the following steps: collecting network flow data, and preprocessing the network flow data to obtain real training data; a FARD-WGAN-GP model is constructed and trained, and hybrid pseudo data is generated based on the trained FARD-WGAN-GP model; constructing a time sequence attention detection model; training a time sequence attention detection model based on the real training data and the pseudo data; network intrusion real-time detection is carried out based on the trained time sequence attention detection model; on the basis of the real-time detection result, optimizing the FARD-WGAN-GP model, and on the basis of the optimized FARD-WGAN-GP model, optimizing the time sequence attention detection model; and carrying out network intrusion detection based on the optimized time sequence attention detection model. According to the method, the quality of the generated data is improved, and the detection accuracy is improved.
Owner:ZHENGZHOU UNIV

Network intrusion detection method and system based on multi-modal deep learning

The invention belongs to the technical field of Internet security, and discloses a multi-modal deep learning-based network intrusion detection method and system, which comprises the steps of carrying out collection and modal attribution on multi-source data from different channels, constructing a time-continuous multi-track dynamic sensing track set, integrating a modal attention distribution mechanism, and carrying out multi-modal deep learning. According to the modal energy sensing complexes of each type of modals under different sensing orbits, dynamically distributing modal parameters, and outputting an initial index tensor after multi-orbit modal fusion; receiving an initial index tensor, and establishing a cross-modal dependency relationship by constructing a bidirectional response tensor between a modal and an orbit; constructing a semantic trigger matrix based on semantic tags in a cross-modal dependency relationship, adopting a cross-modal residual connection mechanism, retaining low-order modal coupling features through a parallel residual path, and outputting modal linkage nodes; according to the invention, the identification capability of detection on complex intrusion behaviors is improved, and more comprehensive and accurate detection on complex network attack behaviors is realized.
Owner:聊城大学东昌学院 +1

Knowledge data joint-driven vehicle-mounted CAN network intrusion detection method

The invention discloses a knowledge data joint-driven vehicle-mounted CAN network intrusion detection method, which comprises the following steps of: firstly, carrying out standardization processing on original CAN message data, and extracting structural characteristics of the original CAN message data; through a data preprocessing module, original data is converted into an input format suitable for neural network processing, and is prepared together with a knowledge set for subsequent analysis. The processed data and knowledge set are then input to a spatio-temporal attention module based on sparse attention. In the module, a time sequence attention layer extracts possible time sequence characteristics of attacks by capturing time correlation of CAN messages; and the spatial attention layer analyzes the spatial characteristics of the message and identifies data tampering or other abnormal modes. And after being processed by the space-time attention module, the high-order hidden features extracted by the network are transmitted to the output layer, and a final intrusion detection result is displayed through the full connection layer. And if an abnormal or attack behavior is detected, the system gives an alarm to the user in time.
Owner:SHENZHEN AUTOMOTIVE RES INST BEIJING INST OF TECH (SHENZHEN RES INST OF NAT ENG LAB FOR ELECTRIC VEHICLES) +1

Industrial internet network intrusion detection method based on pre-trained large language model

The invention provides an industrial internet network intrusion detection method based on a pre-trained large language model, and the method comprises the steps: carrying out the data preprocessing of original network flow data through protocol self-adaptive flow aggregation and session segmentation, feature screening and feature coding; constructing a stream format text data set used for training a generation model GPT-2 and a packet level classification text-label data set used for training a classification model DistilBERT; then fine tuning training is carried out on the generation model GPT-2 and the classification model DistilBERT; then calling a trained generation model GPT-2 to generate a traffic sequence, obtaining a prediction data packet, calling a trained classification model DistilBERT, performing anomaly judgment on sequence data in the prediction data packet one by one, and outputting a classification result of anomaly judgment; the active intrusion detection of first generation and then discrimination is realized. According to the method, prediction can be made before real attack traffic arrives, and network attacks are prevented.
Owner:EAST CHINA JIAOTONG UNIVERSITY

Lightweight vehicle-mounted network intrusion detection system and method based on ADGRU-Net hybrid model

The invention belongs to the technical field of vehicle networking safety, and relates to a lightweight in-vehicle network intrusion detection system and method based on an ADGRU-Net hybrid model, and the system comprises a data loading and cleaning module, a time sequence and feature correlation module, and a space-time hybrid deep learning model. The data loading and cleaning module adopts a block-by-block loading mode to convert multi-source heterogeneous original time sequence data into a standard format; the time sequence and feature association module adopts a sliding window mechanism to intercept a data segment containing L continuous time steps with a preset length from multi-source time sequence data, each time step contains N features, and the data segment is transposed and then converted into a two-dimensional single-channel grayscale image through linear scaling; the space-time hybrid deep learning model comprises a spatial feature extraction module, a remodeling module, a time sequence feature extraction module, a time sequence branch decoder, a spatial branch decoder and a feature fusion module; the problem that an existing model is poor in performance in a complex and changeable real attack scene is solved.
Owner:CHANGCHUN UNIV

Cloud edge-end collaborative multi-scene adaptive network intrusion detection method

The invention discloses a cloud side-end cooperative multi-scene adaptive network intrusion detection method, and solves the problems of poor scene adaptation, weak dynamic processing, privacy-precision imbalance and the like in the prior art. The method is realized through four steps: 1, multi-scene traffic collection and hierarchical preprocessing, terminal sensing layer optimization frame processing and traffic classification, edge layer screening of high-value traffic, and cloud fragmentation scheduling; 2, multi-scene adaptive feature fusion is carried out, scene exclusive features and general features are extracted, and 50-dimensional feature vectors are generated; 3, a cloud edge-end collaborative detection model and an edge lightweight model are preliminarily screened, a cloud federal fusion model is finely detected, and dynamic weight and differential privacy are combined; 4, dynamic attack response and model iteration are carried out, attacks are responded in a scene mode, and the stability of the model is guaranteed through anti-forgetting optimization. According to the method, multiple scenes are covered, the detection precision is larger than or equal to 98.5%, the edge delay is smaller than or equal to 40 ms, the privacy leakage risk is reduced by 90%, the renaturation is high, and the robustness is high.
Owner:季亚文

Online network intrusion detection method based on deep learning

The invention discloses an online network intrusion detection method based on deep learning. The method comprises the following steps: acquiring network flow data to be detected; the to-be-detected network flow data is input to a network intrusion detection model, a detection result is obtained, the network intrusion detection model is obtained through training of a training set, the training set is composed of original network data, and the detection result is obtained; the network intrusion detection model comprises a meta-training module, an FAISS index module, a TabPFN inference module, a Cache construction module, a fusion detection module and a continuous maintenance module, rapid response and efficient detection of a dynamic network environment are achieved, and the robustness and the real-time performance of a system in the face of distribution drift are improved.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

Network intrusion detection method and device based on multi-dimensional feature collaborative analysis, and storage medium

The invention relates to the technical field of artificial intelligence, and provides a network intrusion detection method based on multidimensional feature collaborative analysis, and the method comprises the steps: calculating the correlation degree eta ij of any two feature columns in an original traffic feature matrix, and when eta ij is greater than eta thr, generating a new feature through Qij = Xi * Xj + (1-eta ij) * (Xi + Xj), outputting a dimension reduction feature matrix to perform nonlinear spatial transformation on the dimension reduction feature matrix X ', dynamically retrieving associated knowledge through a learnable memory library, fusing current input features and memory enhancement features, and outputting refined features; decomposing the refined features to a biological neural oscillation frequency band, applying carrier modulation, and performing feature reconstruction to generate a space-time correlation tensor; the refined features and the space-time correlation tensor are fused, and the intrusion behavior classification probability is output through multi-stage abstract compression and regularization processing; screening difficult samples based on classification confidence to construct a training library, and obtaining a conventional detection model and a special and precise detection model; and preferentially calling the special and precise model during real-time detection, and switching to the conventional model when the confidence coefficient is smaller than a confidence coefficient threshold value.
Owner:HARBIN UNIV OF COMMERCE

Network intrusion detection method based on improved WGAN sampling and ensemble learning

The invention relates to a network intrusion detection method based on improved WGAN sampling and ensemble learning, and solves the defects that for high-dimensional and class-unbalanced network flow data, a base learner of an integrated model is insufficient in adaptive capacity, noise interference is difficult to restrain, and key attack modes are difficult to mine in the prior art. The method comprises the following steps: acquiring network flow data; performing data enhancement based on a DDWGLO framework; constructing a network intrusion detection model based on Stacking; training a network intrusion detection model; and detecting network intrusion in real time. According to the method, the DDWGLO is adopted for data enhancement, the weight is adaptively allocated based on the Newton-Raphson optimization algorithm improved on the basis of Circle chaotic mapping, and then the accuracy of network intrusion detection is improved.
Owner:ANHUI UNIV

Network intrusion detection system, method and product based on federated learning and P4

The invention discloses an intelligent and efficient network intrusion detection system, method and product based on federated learning and P4. The system comprises an abnormal traffic detection module and an abnormal traffic classification module. The abnormal traffic detection module is used for extracting data packet feature information in network traffic, calculating a traffic reconstruction loss value according to preset parameters, and comparing the reconstruction loss value with a benign threshold and an attack threshold to judge whether the traffic is abnormal traffic; if the traffic is normal traffic, forwarding the traffic, and if the traffic is abnormal traffic, submitting the traffic to an abnormal traffic classification module; and the abnormal flow classification module is used for calculating an energy value of each flow and comparing the energy value of each flow with an energy threshold value of a flow category so as to detect a network attack type. According to the method, the comprehensiveness and the accuracy of network attack detection are remarkably improved, and a new solution is provided for constructing an intelligent and efficient network protection system.
Owner:WUHAN UNIV OF SCI & TECH

Network intrusion detection method and system based on federal continuous learning

The invention discloses a federal continuous learning-based network intrusion detection method and system. The method comprises the following steps of initializing a global model and training related parameters; broadcasting the global model and training related parameters together; performing data preprocessing on the collected data, updating a local model, and adding old knowledge into training of a new model through knowledge distillation to obtain new model parameters; after the local model is trained, the adaptability of the model to the complex and changeable network environment is improved, and if concept drift exists, the above steps are executed again; the training related parameters are uploaded; and receiving training related parameters and updating the global model by using federated weighted average to obtain an updated global model. According to the method and the device, the intrusion detection model can be trained under the conditions of multi-party cooperation and no leakage of privacy data, and meanwhile, the accurate recognition capability of the model for novel security threats is improved, and the adaptability of the model to a complex and changeable network environment is improved.
Owner:TIANJIN UNIVERSITY OF TECHNOLOGY

Network intrusion detection method based on CKAN-BiLSTM

The invention requests to protect a network intrusion detection method based on a CKAN-BiLSTM (Content Kernel Area Network-BiLSTM). The method comprises the following steps: firstly, selecting an NSL-KDD data set widely applied in the field of network security, and performing preprocessing operation on the NSL-KDD data set to improve data quality and a model training effect; then, feature extraction is carried out on input data through a convolutional layer, size adjustment is carried out on features in combination with an adaptive pooling mechanism, and the perception ability of the model to a local mode is enhanced; secondly, inputting the extracted features into a BiLSTM network to fully capture a time sequence dependency relationship in the BiLSTM network; and finally, Kolmogorov-Arnold Network (KAN) is introduced to carry out weighted fusion on the key features, final attack type classification is completed, and efficient and accurate intrusion detection is realized.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Lightweight vehicle-mounted network intrusion detection method based on BERT

The invention belongs to the technical field of vehicle-mounted network intrusion detection, and relates to a BERT-based lightweight vehicle-mounted network intrusion detection method, which comprises the following steps: S1, a data preprocessing stage: converting a CAN sample with a label into a text sample; s2, a model training stage: inputting the text sample with the label into a VehileBERT series model for training, including setting a training hyper-parameter, and transmitting the processed data to the VehileBERT series model for training; and S3, a model test evaluation stage: performing reasoning test on the trained VehileBERT series model. The method has the advantages that the loss caused by light weight is balanced by adjusting the dynamic attention weight, and the VehileBERT model is finally designed to be suitable for vehicle-mounted network intrusion detection. And the real-time requirement of the vehicle-mounted network can be better met.
Owner:CHANGCHUN UNIV

Mobile network intrusion detection early warning method and system based on artificial intelligence

The invention discloses a mobile network intrusion detection early warning method and a mobile network intrusion detection early warning system based on artificial intelligence, and relates to the field of network intrusion detection. The numerical feature information data of the data packet in the to-be-detected mobile network is judged from two perspectives of real time and future, so that intrusion protection measures can be taken in time and possible intrusion in the future can be predicted in advance, and the security of the to-be-detected mobile network is further ensured; wherein the numerical value feature information types susceptible to network intrusion in the initial data packet feature information type set are screened, and an acquisition basis is provided for subsequent acquisition of numerical value feature information data of data packets in historical network intrusion for constructing a final network intrusion severity level mapping equation.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Real-time network intrusion detection method based on genetic algorithm and bidirectional long and short time memory network

The invention discloses a real-time network intrusion detection method based on a genetic algorithm and a bidirectional long-short term memory network, and belongs to the technical field of network security, and the method comprises the following steps: 1, extracting continuous and category network traffic features from a constructed data set, and carrying out the feature preprocessing and preliminary screening; step 2, performing feature selection optimization based on a genetic algorithm so as to screen out an optimal feature combination with high accuracy and low dimension; 3, adopting a bidirectional LSTM algorithm to construct an abnormal traffic detection model based on the feature subset selected by the genetic algorithm, wherein the abnormal traffic detection model is used for identifying normal and abnormal samples in the network traffic; 4, evaluating the performance of the abnormal traffic detection model by adopting the confusion matrix; and step 5, deployment and real-time detection of an abnormal flow detection model. According to the invention, a lightweight and traceable intrusion detection framework is constructed. The generalization ability and precision of the detection model are improved; the method gives consideration to accuracy, interpretability and system response capability.
Owner:NANJING UNIV OF SCI & TECH +1

Computer network intrusion detection system and method based on abnormal behavior analysis

The invention relates to the field of computer network intrusion detection based on abnormal behavior analysis, in particular to a computer network intrusion detection system and method based on abnormal behavior analysis. The method comprises the following steps: acquiring network flow data by using a data acquisition module, and fusing the network flow data to obtain fused network flow data; the feature extraction module performs feature extraction on the fusion network flow data by using a GGNN gating graph neural network, establishes an ST-Transform space-time joint detection model, performs parameter optimization on the detection model by using a multi-target particle swarm optimization algorithm, and the data detection module inputs the feature network flow data into the space-time joint detection model for detection. Outputting a data exception score; and the active response module is used for the system to perform active response according to the grade division of the data exception score. And the threat discovery and disposal capability in a complex attack scene is improved.
Owner:NANTONG UNIV

Network intrusion detection method based on federal map neural network

The invention provides a network intrusion detection method based on a federated graph neural network, which comprises the following steps: carrying out graph structure modeling on network flow data, constructing a local sub-graph of each client, adopting a federated learning framework, carrying out graph neural network model training by the client locally through the local sub-graph, and obtaining a network intrusion detection result; and the encrypted data and model parameters are uploaded to the server, so that the potential safety hazard of data sharing is avoided. And the server aggregates the encrypted remainder set and the model parameter from each client, generates a global model parameter and an aggregated encrypted remainder set, and feeds back the global model parameter and the aggregated encrypted remainder set to the client to realize cross-client collaborative training. The encrypted data is decrypted by introducing the Chinese remainder theorem, so that the security and privacy of the data are ensured, and the feature reconstruction precision is improved at the same time. According to the method, the problem of data islands in cross-organization cooperation is effectively solved, and the real-time performance and accuracy of an intrusion detection system are improved on the premise of ensuring privacy protection.
Owner:SHANGHAI UNIVERSITY OF ELECTRIC POWER

AI-driven efficient network intrusion detection system

The invention relates to the technical field of network security, and particularly discloses an AI-driven efficient network intrusion detection system, which comprises a flow acquisition and preprocessing module, a lightweight rule filtering engine module, an AI behavior analysis engine, a judgment and response module, an online learning module and a log and audit module, during the application period of the technical scheme, through a multi-module collaborative detection and disposal architecture, the functions of flow preprocessing, rule filtering, AI deep analysis, dynamic model optimization and full-dimension protection are integrated, so that known attacks can be quickly intercepted and unknown attacks can be accurately identified during use, and the security of the network flow is improved. And meanwhile, the attack change is dynamically adapted, the attacks are disposed in a grading manner, and the full attack chain is covered, so that an efficient and comprehensive intrusion detection effect is achieved, and the problems of multiple detection blind areas, high resource consumption, poor adaptability and narrow protection range in the prior art are solved.
Owner:SHANGHAI INTELLIGENT & CONNECTED VEHICLE R & D CENTER CO LTD

Network intrusion detection method and system based on federated learning and hybrid clustering

The invention discloses a federated learning and hybrid clustering network intrusion detection method and system, and relates to the technical field of network intrusion detection. The method comprises the following steps: a server issues a current global model parameter to a client participating in the current round of training; after each client receives the global model parameter, taking the global model parameter as an initialization parameter of a local model, performing training by using local data, introducing a clustering-based soft label generation mechanism and a classification and clustering parallel dual-task learning framework in the training process for training, and updating the local model parameter; the client encrypts and uploads the trained model parameters to the server; the server aggregates all client model parameters, generates a new generation of global model, and issues the parameters back to the client for next round of training; and after all rounds of training are finished, the server issues a final model for the client to carry out network intrusion discrimination. According to the method, the negative influence of data non-independent identical distribution is effectively overcome, and sparse attacks are accurately detected.
Owner:BEIJING INFORMATION SCI & TECH UNIV

Multi-generator adversarial network intrusion detection method based on imaging variational enhancement

The invention discloses a multi-generator adversarial network intrusion detection method based on imaging variational enhancement in the technical field of network security, which comprises the following steps of: 1, preprocessing data and encoding images, converting network flow data into a two-dimensional image format, and reserving spatial-temporal characteristics and protocol characteristics of the data for subsequent model training; step 2, constructing a multi-generator adversarial network, adopting a plurality of generators to work in parallel, each generator being responsible for generating attack samples of required categories, and optimizing model parameters of the generators and discriminators through an adversarial training process to enable the distribution of the generated attack samples to be close to the distribution of real attack samples; according to the method, the sample and the classification model are generated through collaborative optimization, the robustness and generalization ability of a network intrusion detection system on an unbalanced data set are remarkably improved, and an innovative solution is provided for network security detection.
Owner:YANGZHOU UNIV

Network intrusion detection method and system based on reliability sample selection

The invention discloses a network intrusion detection method and system based on reliability sample selection, and the method comprises the following steps: carrying out the data enhancement of network intrusion data, and generating a more representative sample; then selecting a high-quality sample for initial model training through reliability evaluation; online training is carried out on the model, and when concept drift is detected, a reliability sample selection strategy guided by an attention mechanism is adopted, and samples valuable for model training are preferentially selected to be updated; when the number of the reliability samples is insufficient, selecting a sample with a high model loss value from the non-reliability samples as a supplementary sample; and inputting a to-be-detected sample into the trained model, and outputting a classification prediction result of the sample by the model. Evaluating the performance of the model by comparing a prediction result of the model with a real label; through the above steps, the abnormal behavior in the network intrusion can be effectively detected, and the adaptability and robustness of a network intrusion detection system are improved.
Owner:HUNAN NORMAL UNIVERSITY +1