Deep Learning Malicious Attack Detection in TCPS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Transportation cyber-physical systems (TCPS) are vulnerable to security attacks due to open wireless communication, with limited effective methods for detecting malicious attacks, especially as they become more camouflaged and complex, and traditional methods fail to accurately identify new types of malicious behaviors.

Innovation Solution

A deep learning method is employed to extract and learn features from data flows in TCPS, involving data preprocessing, feature selection, and a deep learning model trained using a Restriction Boltzmann Machine and back propagation algorithm to distinguish between malicious and normal behaviors, enabling accurate identification of malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network protocol feature-based detection methods are used, then the detection process is simple, but the detection accuracy is low and cannot identify new types of malicious behaviors

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional network protocol-based detection mechanisms with a deep learning-based detection system. The deep learning model learns patterns from data flow features automatically, substituting manual protocol analysis with automated machine learning-based identification, thereby improving detection accuracy for both known and unknown attack types.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the detection parameters from network protocol features to data flow features extracted from actual traffic. By focusing on statistical properties, packet patterns, and behavioral characteristics of data flows rather than protocol structures, the system achieves better detection accuracy while adapting to evolving attack methods.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If deep learning models with large data volumes are used, then detection accuracy is improved, but training time and computational resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidmodel training time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary data processing and feature extraction before model training. By pre-processing the data flows, extracting relevant features, and organizing them into training datasets in advance, the system reduces the computational burden during model training and accelerates the overall detection system deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the training process into distinct phases: data collection, feature extraction, model training, and evaluation. This segmentation allows for optimized processing at each stage, enabling parallel computation where possible and reducing overall training time while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11777957B2Method for detecting malicious attacks based on deep learning in traffic cyber physical system
Publication Date: 2023.10.03 HANGZHOU DIANZI UNIV
  • US11777957B2 patent drawing

AI summary

Disclosed is a method for detection a malicious attack based on deep learning in a transportation cyber-physical system (TCPS), comprising: extracting original feature data of a malicious data flow and a normal data flow from a TCPS; cleaning and coding original feature data; selecting key features from the feature data; cleaning and coding the key features to establish a deep learning model; finally, inputing unknown behavior data to be identified into the deep learning model to identify whether the data is malicious data, thereby detecting a malicious attack. The present invention uses a deep learning method to extract and learn the behavior of a program in a TCPS, and detect the malicious attack according to the deep learning result, and effectively identify the malicious attack in the TCPS.