CN110300127A - A kind of network inbreak detection method based on deep learning, device and equipment - Google Patents
A kind of network inbreak detection method based on deep learning, device and equipment Download PDFInfo
- Publication number
- CN110300127A CN110300127A CN201910701606.0A CN201910701606A CN110300127A CN 110300127 A CN110300127 A CN 110300127A CN 201910701606 A CN201910701606 A CN 201910701606A CN 110300127 A CN110300127 A CN 110300127A
- Authority
- CN
- China
- Prior art keywords
- network
- intrusion detection
- deep learning
- invasion
- detected
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/14—Network analysis or design
- H04L41/145—Network analysis or design involving simulating, designing, planning or modelling of a network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The invention discloses a kind of network inbreak detection method based on deep learning, device, equipment, method and computer readable storage mediums, comprising: acquires the flow parameter of network to be detected;The flow parameter is input to and is previously-completed in the trained intrusion detection network based on deep learning, the network to be detected is performed intrusion detection;Wherein, the intrusion detection network based on deep learning includes input layer, picture scroll lamination, pond layer, full articulamentum, extreme learning machine layer and output layer;After the intrusion detection for completing the network to be detected, the invasion type of the network to be detected is determined according to intrusion detection result.Method, apparatus, equipment and computer readable storage medium provided by the present invention, improve the accuracy rate of network invasion monitoring result.
Description
Technical field
The present invention relates to computer network security technology fields, more particularly to a kind of network intrusions based on deep learning
Detection method, device, equipment and computer readable storage medium.
Background technique
With the high speed development of internet, the Working Life of user increasingly be unable to do without network.It is answered according to China internet
Anxious center CNCERT, " China's internet security situation symposium in 2018 " of in April, 2019 newest publication, network coverage model
It encloses and is growing ever-increasing simultaneously with netizen's quantity, the information security issue that China faces becomes increasingly complicated, covers
Aspect includes, and the security risk that key message infrastructure, cloud platform etc. face is still more prominent, APT attack, leaking data,
The problems such as distributed denial of service attack (" ddos attack "), is also more serious.2018, CNCERT coordinated disposition network security
Event about 10.6 ten thousand, wherein Phishing event is most, followed by behind security breaches, rogue program, webpage tamper, website
The events such as door, ddos attack.CNCERT persistently organizes computer rogue program normalization strike work, successfully closes within 2018
772 biggish Botnets of magnitude control are closed, control of the hacker to about 3,900,000 infection hosts within the border has successfully been cut off.
Current internet mode keeps reforming innovation, netizen's scale is in sustainable growth and generates magnanimity application message
" big data " constructs safe cyberspace as the hot spot of society urgently to be resolved under the epoch.Intrusion detection can be accomplished
Rapidly, accurately, it is analyzed from data ocean in time and realizes illegal attack.Intrusion Detection Technique exists at present
Data processing lower to UNKNOWN TYPE attack detecting ability and inappropriate lead to relatively low two problems of correct verification and measurement ratio.
In summary as can be seen that the accuracy rate for how improving network invasion monitoring is current problem to be solved.
Summary of the invention
The object of the present invention is to provide it is a kind of by the network inbreak detection method of deep learning, device, equipment and based on
Calculation machine readable storage medium storing program for executing, to solve lower to UNKNOWN TYPE attack detecting ability in the prior art and inappropriate data processing
The problem for causing the accuracy rate of intrusion detection relatively low.
In order to solve the above technical problems, the present invention provides a kind of network inbreak detection method based on deep learning, comprising:
Acquire the flow parameter of network to be detected;The flow parameter is input to and is previously-completed the trained invasion based on deep learning
It detects in network, the network to be detected is performed intrusion detection;Wherein, the intrusion detection network packet based on deep learning
Include input layer, picture scroll lamination, pond layer, full articulamentum, extreme learning machine layer and output layer;Complete the network to be detected
After intrusion detection, the invasion type of the network to be detected is determined according to intrusion detection result.
Preferably, the flow parameter of the acquisition network to be detected includes:
It is acquired using the network topology for including n topological node and each topological node r parameter of acquisition described to be checked
The flow parameter of survey grid network.
Preferably, the picture scroll lamination of the intrusion detection network based on deep learning is using Relu function as activation letter
Number, using mean filter as convolution filter.
Preferably, described be input to the flow parameter is previously-completed the trained intrusion detection net based on deep learning
In network, to include: before carrying out online intrusion detection to the network to be detected
According to default training batch size and default iteration wheel number, entered using pre-selection loss function and pretreated sample
It invades type sample data set to be trained the intrusion detection network based on deep learning pre-established, be instructed twice until adjacent
Practice error between output result and be less than default error threshold, completes the training of the intrusion detection network based on deep learning.
Preferably, the default training batch size of the foundation and default iteration wheel number, using pre-selection loss function and in advance
Treated, and sample invasion type sample data set is trained the intrusion detection network based on deep learning pre-established, directly
It is less than default error threshold to error between the adjacent output result of training twice, completes the intrusion detection based on deep learning
The training of network includes:
NSL-KDD data set is set as invasion type sample data set, the invasion type sample data set is carried out pre-
Processing, so that the invasion type sample data set is classified as 3 big invasion types and 38 small types of invasion;
Training batch size is set as 30, iteration wheel number is set to 300 wheels, using cross entropy as loss function,
The intrusion detection network based on deep learning pre-established is instructed using the invasion type sample data after classification
Practice, until error is less than default error threshold between the adjacent output result of training twice, completes the entering based on deep learning
Invade the training of detection network.
The present invention also provides a kind of network invasion monitoring device based on deep learning, comprising:
Acquisition module, for acquiring the flow parameter of network to be detected;
Detection module is previously-completed the trained intrusion detection based on deep learning for the flow parameter to be input to
In network, the network to be detected is performed intrusion detection;Wherein, the intrusion detection network based on deep learning includes defeated
Enter layer, picture scroll lamination, pond layer, full articulamentum, extreme learning machine layer and output layer;
Determining module, after the intrusion detection for completing the network to be detected, according to the determination of intrusion detection result
The invasion type of network to be detected.
Preferably, the acquisition module is specifically used for:
It is acquired using the network topology for including n topological node and each topological node r parameter of acquisition described to be checked
The flow parameter of survey grid network.
Preferably, the picture scroll lamination of the intrusion detection network based on deep learning is using Relu function as activation letter
Number, using mean filter as convolution filter.
The network invasion monitoring equipment based on deep learning that the present invention also provides a kind of, comprising:
Memory, for storing computer program;Processor realizes above-mentioned one kind when for executing the computer program
The step of network inbreak detection method based on deep learning.
The present invention also provides a kind of computer readable storage medium, meter is stored on the computer readable storage medium
Calculation machine program, the computer program realize a kind of above-mentioned network invasion monitoring side based on deep learning when being executed by processor
The step of method.
Network inbreak detection method provided by the present invention based on deep learning joins the flow for acquiring network to be detected
Number, which is input to, to be previously-completed in the trained intrusion detection network based on deep learning, and network invasion monitoring is carried out, and is obtained described
The invasion type of network to be detected.The intrusion detection network based on deep learning includes: input layer, picture scroll lamination, Chi Hua
Layer, full articulamentum, extreme learning machine layer and output layer.The intrusion detection network based on deep learning of offer of the present invention
It is to be constructed based on figure convolutional neural networks and extreme learning machine, possesses excellent characteristic of division and good learning ability
With generalized ability, the type of network intrusions can be quickly identified and be positioned, the accuracy of network invasion monitoring is improved.
Detailed description of the invention
It, below will be to embodiment or existing for the clearer technical solution for illustrating the embodiment of the present invention or the prior art
Attached drawing needed in technical description is briefly described, it should be apparent that, the accompanying drawings in the following description is only this hair
Bright some embodiments for those of ordinary skill in the art without creative efforts, can be with root
Other attached drawings are obtained according to these attached drawings.
Fig. 1 is the first specific embodiment of the network inbreak detection method provided by the present invention based on deep learning
Flow chart;
Fig. 2 is the schematic network structure of the network invasion monitoring network provided by the present invention based on deep learning;
Fig. 3 is second of specific embodiment of the network inbreak detection method provided by the present invention based on deep learning
Flow chart;
Fig. 4 is a kind of structural block diagram of the network invasion monitoring device based on deep learning provided in an embodiment of the present invention.
Specific embodiment
Core of the invention be to provide it is a kind of by the network inbreak detection method of deep learning, device, equipment and based on
Calculation machine readable storage medium storing program for executing carries out net using the intrusion detection network based on figure convolutional neural networks and extreme learning machine building
Network intrusion detection improves the accuracy rate of network invasion monitoring result.
In order to enable those skilled in the art to better understand the solution of the present invention, with reference to the accompanying drawings and detailed description
The present invention is described in further detail.Obviously, described embodiments are only a part of the embodiments of the present invention, rather than
Whole embodiments.Based on the embodiments of the present invention, those of ordinary skill in the art are not making creative work premise
Under every other embodiment obtained, shall fall within the protection scope of the present invention.
Referring to FIG. 1, Fig. 1 is the first tool of the network inbreak detection method provided by the present invention based on deep learning
The flow chart of body embodiment;Specific steps are as follows:
Step S101: the flow parameter of network to be detected is acquired;
It is acquired using the network topology for including n topological node and each topological node r parameter of acquisition described to be checked
The flow parameter of survey grid network, then the flow parameter for being input to the intrusion detection network based on deep learning is X ∈ Rn×r, R is
The set of all real numbers.Then network is from ring adjacency matrixWherein, I is unit index matrix, and A is
Network adjacent matrix, D are to include the degree matrix from ring, Dii=∑j(Aij+Iii), wherein DiiFor the diagonal element of matrix D, Aij
For the element that the i-th row j of matrix A is arranged, i and j are respectively line number and row number.
Step S102: the flow parameter is input to and is previously-completed the trained intrusion detection network based on deep learning
In, the network to be detected is performed intrusion detection;Wherein, the intrusion detection network based on deep learning includes input
Layer, picture scroll lamination, pond layer, full articulamentum, extreme learning machine layer and output layer;
As shown in Fig. 2, the intrusion detection network based on deep learning includes input layer, picture scroll lamination (Graph
CNN), pond layer (pooling), full articulamentum (Full Connect), extreme learning machine layer (ELM) and output layer.
Wherein, the picture scroll lamination is using Relu function as activation primitive.The convolution filter of the picture scroll lamination is adopted
With mean filter, output valve are as follows:W1For the weight of first layer.In order to reduce calculation amount and mention
High generalization ability uses, and it is 0.5 that inactivation rate is arranged after the layer.
The pond layer of the intrusion detection network based on deep learning is all made of the maximum pond of 2*2.
The neuron number of the full articulamentum is 1000, and the output of the full articulamentum will be input to the limit
Habit machine layer.
The extreme learning machine layer is by way of avoiding backpropagation come the training process of accelerans network.The pole
Limit the output of learning machine layer are as follows: H=g (WXi+ b), wherein the activation primitive of g () expression hidden layer;W and b are respectively indicated
The weight matrix generated at random and biasing.
The output result of the output layer is more classification, output valve of classifying are as follows:
Wherein,The value Y of the output layer output is one-hot (one-hot coding) form, wherein
Classification be digital 1 corresponding classification;I is that size is HHTUnit matrix;D is regularization coefficient, and D is constant.
Step S103: it after the intrusion detection for completing the network to be detected, is determined according to intrusion detection result described to be checked
The invasion type of survey grid network.
Network inbreak detection method provided by the present embodiment constructs institute based on figure convolutional neural networks and extreme learning machine
The intrusion detection network based on deep learning is stated, the excellent sort feature of figure convolutional neural networks is utilized, realizes network intrusions
Quick positioning, improve user perception;Limit of utilization learning machine avoids the training process of the backpropagation of network parameter, thus
Realize quick training and the on-line checking of network invasion monitoring.Method provided by the present embodiment, it is right in the prior art to solve
The problem that UNKNOWN TYPE attack detecting ability is lower and inappropriate data processing causes accuracy rate relatively low, improves network intrusions
The accuracy of detection.
Based on the above embodiment, in the present embodiment, it can be adopted according to default trained batch size and default iteration wheel number
With pre-selection loss function and pretreated sample invasion type sample data set to the entering based on deep learning pre-established
It invades detection network to be trained, until error is less than default error threshold between the adjacent output result of training twice, described in completion
The training of intrusion detection network based on deep learning.Referring to FIG. 3, Fig. 3 is provided by the present invention based on deep learning
The flow chart of second of specific embodiment of network inbreak detection method;Specific steps are as follows:
Step S301: it is acquired using the network topology for including n topological node and each topological node r parameter of acquisition
The flow parameter of the network to be detected;
Step S302: NSL-KDD data set is set as invasion type sample data set, to the invasion type sample data
Collection is pre-processed, so that the invasion type sample data set is classified as 3 big invasion types and 38 small types of invasion;
Step S303: training batch size is set as 30, iteration wheel number is set to 300 wheels, using cross entropy conduct
Loss function, using the invasion type sample data after classification to the intrusion detection net based on deep learning pre-established
Network is trained, until adjacent training twice, which exports error between result, is less than default error threshold, is completed described based on depth
The training of the intrusion detection network of study;
When error is less than ∈=10 between adjacent output result trained twice-4When, then deconditioning.
After the training for completing the invasion inspection side network based on deep learning, target network parameter is obtained.In test set
In, the invasion inspection side network based on deep learning is as shown in table 1 to the test result of three kinds of typical invasion types:
The test result table of 1 three kinds of table typical invasion types
Step S304: the flow parameter is input in the intrusion detection network based on deep learning for completing training,
The network to be detected is performed intrusion detection;
Step S305: it after the intrusion detection for completing the network to be detected, is determined according to intrusion detection result described to be checked
The invasion type of survey grid network.
The network inbreak detection method of offer of the present invention possesses excellent characteristic of division and good learning ability
With generalized ability, the type of network intrusions can be quickly identified and be positioned, the accuracy of network invasion monitoring is improved.
Referring to FIG. 4, Fig. 4 is a kind of network invasion monitoring device based on deep learning provided in an embodiment of the present invention
Structural block diagram;Specific device may include:
Acquisition module 100, for acquiring the flow parameter of network to be detected;
Detection module 200 is previously-completed the trained invasion based on deep learning for the flow parameter to be input to
It detects in network, the network to be detected is performed intrusion detection;Wherein, the intrusion detection network packet based on deep learning
Include input layer, picture scroll lamination, pond layer, full articulamentum, extreme learning machine layer and output layer;
Determining module 300 determines institute according to intrusion detection result after the intrusion detection for completing the network to be detected
State the invasion type of network to be detected.
The network invasion monitoring device based on deep learning of the present embodiment is for realizing above-mentioned based on deep learning
Network inbreak detection method, therefore the specific embodiment in the network invasion monitoring device based on deep learning is visible hereinbefore
The network inbreak detection method based on deep learning embodiment part, for example, acquisition module 100, detection module 200, really
Cover half block 300, is respectively used to realize step S101 in the above-mentioned network inbreak detection method based on deep learning, S102 and
S103, so, specific embodiment is referred to the description of corresponding various pieces embodiment, and details are not described herein.
The specific embodiment of the invention additionally provides a kind of network invasion monitoring equipment based on deep learning, comprising: storage
Device, for storing computer program;Processor is realized above-mentioned a kind of based on deep learning when for executing the computer program
Network inbreak detection method the step of.
The specific embodiment of the invention additionally provides a kind of computer readable storage medium, the computer readable storage medium
On be stored with computer program, the computer program realizes a kind of above-mentioned network based on deep learning when being executed by processor
The step of intrusion detection method.
Each embodiment in this specification is described in a progressive manner, the highlights of each of the examples are with it is other
The difference of embodiment, same or similar part may refer to each other between each embodiment.For being filled disclosed in embodiment
For setting, since it is corresponded to the methods disclosed in the examples, so being described relatively simple, related place is referring to method part
Explanation.
Professional further appreciates that, unit described in conjunction with the examples disclosed in the embodiments of the present disclosure
And algorithm steps, can be realized with electronic hardware, computer software, or a combination of the two, in order to clearly demonstrate hardware and
The interchangeability of software generally describes each exemplary composition and step according to function in the above description.These
Function is implemented in hardware or software actually, the specific application and design constraint depending on technical solution.Profession
Technical staff can use different methods to achieve the described function each specific application, but this realization is not answered
Think beyond the scope of this invention.
The step of method described in conjunction with the examples disclosed in this document or algorithm, can directly be held with hardware, processor
The combination of capable software module or the two is implemented.Software module can be placed in random access memory (RAM), memory, read-only deposit
Reservoir (ROM), electrically programmable ROM, electrically erasable ROM, register, hard disk, moveable magnetic disc, CD-ROM or technology
In any other form of storage medium well known in field.
Above to it is provided by the present invention by the network inbreak detection method of deep learning, device, equipment and just based on
Calculation machine readable storage medium storing program for executing is described in detail.Specific case used herein to the principle of the present invention and embodiment into
Elaboration is gone, the above description of the embodiment is only used to help understand the method for the present invention and its core ideas.It should be pointed out that pair
For those skilled in the art, without departing from the principle of the present invention, the present invention can also be carried out
Some improvements and modifications, these improvements and modifications also fall within the scope of protection of the claims of the present invention.
Claims (10)
1. a kind of network inbreak detection method based on deep learning characterized by comprising
Acquire the flow parameter of network to be detected;
The flow parameter is input to and is previously-completed in the trained intrusion detection network based on deep learning, to described to be checked
Survey grid network performs intrusion detection;Wherein, the intrusion detection network based on deep learning includes input layer, picture scroll lamination, pond
Change layer, full articulamentum, extreme learning machine layer and output layer;
After the intrusion detection for completing the network to be detected, the invasion class of the network to be detected is determined according to intrusion detection result
Type.
2. the method as described in claim 1, which is characterized in that the flow parameter of acquisition network to be detected includes:
The survey grid to be checked is acquired using the network topology for including n topological node and each topological node r parameter of acquisition
The flow parameter of network.
3. the method as described in claim 1, which is characterized in that the picture scroll product of the intrusion detection network based on deep learning
Layer uses Relu function as activation primitive, using mean filter as convolution filter.
4. the method as described in claim 1, which is characterized in that it is described the flow parameter is input to be previously-completed it is trained
In intrusion detection network based on deep learning, to include: before carrying out online intrusion detection to the network to be detected
According to default training batch size and default iteration wheel number, class is invaded using pre-selection loss function and pretreated sample
Type sample data set is trained the intrusion detection network based on deep learning pre-established, until it is adjacent train twice it is defeated
Error is less than default error threshold between result out, completes the training of the intrusion detection network based on deep learning.
5. method as claimed in claim 4, which is characterized in that the default training batch size of the foundation and default iteration wheel
Number, using pre-selection loss function and pretreated sample invasion type sample data set to pre-establishing based on deep learning
Intrusion detection network be trained, until error is less than default error threshold between the adjacent output result of training twice, complete
The training of the intrusion detection network based on deep learning includes:
NSL-KDD data set is set as invasion type sample data set, the invasion type sample data set is pre-processed,
So that the invasion type sample data set is classified as 3 big invasion types and 38 small types of invasion;
Training batch size is set as 30, iteration wheel number is set to 300 wheels, using cross entropy as loss function, is utilized
The invasion type sample data after classification is trained the intrusion detection network based on deep learning pre-established, directly
It is less than default error threshold to error between the adjacent output result of training twice, completes the intrusion detection based on deep learning
The training of network.
6. a kind of network invasion monitoring device based on deep learning characterized by comprising
Acquisition module, for acquiring the flow parameter of network to be detected;
Detection module is previously-completed the trained intrusion detection network based on deep learning for the flow parameter to be input to
In, the network to be detected is performed intrusion detection;Wherein, the intrusion detection network based on deep learning includes input
Layer, picture scroll lamination, pond layer, full articulamentum, extreme learning machine layer and output layer;
Determining module determines described to be checked after the intrusion detection for completing the network to be detected according to intrusion detection result
The invasion type of survey grid network.
7. device as claimed in claim 6, which is characterized in that the acquisition module is specifically used for:
The survey grid to be checked is acquired using the network topology for including n topological node and each topological node r parameter of acquisition
The flow parameter of network.
8. device as claimed in claim 6, which is characterized in that the picture scroll product of the intrusion detection network based on deep learning
Layer uses Relu function as activation primitive, using mean filter as convolution filter.
9. a kind of network invasion monitoring equipment based on deep learning characterized by comprising
Memory, for storing computer program;
Processor is realized a kind of based on depth as described in any one of claim 1 to 5 when for executing the computer program
The step of network inbreak detection method of habit.
10. a kind of computer readable storage medium, which is characterized in that be stored with computer on the computer readable storage medium
Program is realized a kind of based on deep learning as described in any one of claim 1 to 5 when the computer program is executed by processor
Network inbreak detection method the step of.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201910701606.0A CN110300127A (en) | 2019-07-31 | 2019-07-31 | A kind of network inbreak detection method based on deep learning, device and equipment |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201910701606.0A CN110300127A (en) | 2019-07-31 | 2019-07-31 | A kind of network inbreak detection method based on deep learning, device and equipment |
Publications (1)
Publication Number | Publication Date |
---|---|
CN110300127A true CN110300127A (en) | 2019-10-01 |
Family
ID=68032334
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201910701606.0A Pending CN110300127A (en) | 2019-07-31 | 2019-07-31 | A kind of network inbreak detection method based on deep learning, device and equipment |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN110300127A (en) |
Cited By (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111181930A (en) * | 2019-12-17 | 2020-05-19 | 中移(杭州)信息技术有限公司 | DDoS attack detection method, device, computer equipment and storage medium |
CN111556017A (en) * | 2020-03-25 | 2020-08-18 | 中国科学院信息工程研究所 | Network intrusion detection method based on self-coding machine and electronic device |
CN111614665A (en) * | 2020-05-20 | 2020-09-01 | 重庆邮电大学 | Intrusion detection method based on deep residual hash network |
CN112383516A (en) * | 2020-10-29 | 2021-02-19 | 博雅正链(北京)科技有限公司 | Graph neural network construction method and abnormal flow detection method based on graph neural network |
CN112861913A (en) * | 2021-01-12 | 2021-05-28 | 浙江大学 | Intrusion alarm message correlation method based on graph convolution network |
CN113179276A (en) * | 2021-04-30 | 2021-07-27 | 中国人民解放军国防科技大学 | Intelligent intrusion detection method and system based on explicit and implicit feature learning |
CN114024713A (en) * | 2021-09-30 | 2022-02-08 | 广东电网有限责任公司电力调度控制中心 | Anti-intrusion method for low-voltage power line carrier communication system |
CN114070899A (en) * | 2020-07-27 | 2022-02-18 | 深信服科技股份有限公司 | Message detection method, device and readable storage medium |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107154923A (en) * | 2016-03-04 | 2017-09-12 | 中国矿业大学 | A kind of network inbreak detection method based on the very fast learning machine of multilayer |
US20170337467A1 (en) * | 2016-05-18 | 2017-11-23 | Nec Laboratories America, Inc. | Security system using a convolutional neural network with pruned filters |
CN108664687A (en) * | 2018-03-22 | 2018-10-16 | 浙江工业大学 | A kind of industrial control system space-time data prediction technique based on deep learning |
CN108898015A (en) * | 2018-06-26 | 2018-11-27 | 暨南大学 | Application layer dynamic intruding detection system and detection method based on artificial intelligence |
CN109388944A (en) * | 2018-11-06 | 2019-02-26 | 吉林大学 | A kind of intrusion detection method based on KPCA and ELM |
CN109981691A (en) * | 2019-04-30 | 2019-07-05 | 山东工商学院 | A kind of real-time ddos attack detection system and method towards SDN controller |
-
2019
- 2019-07-31 CN CN201910701606.0A patent/CN110300127A/en active Pending
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107154923A (en) * | 2016-03-04 | 2017-09-12 | 中国矿业大学 | A kind of network inbreak detection method based on the very fast learning machine of multilayer |
US20170337467A1 (en) * | 2016-05-18 | 2017-11-23 | Nec Laboratories America, Inc. | Security system using a convolutional neural network with pruned filters |
CN108664687A (en) * | 2018-03-22 | 2018-10-16 | 浙江工业大学 | A kind of industrial control system space-time data prediction technique based on deep learning |
CN108898015A (en) * | 2018-06-26 | 2018-11-27 | 暨南大学 | Application layer dynamic intruding detection system and detection method based on artificial intelligence |
CN109388944A (en) * | 2018-11-06 | 2019-02-26 | 吉林大学 | A kind of intrusion detection method based on KPCA and ELM |
CN109981691A (en) * | 2019-04-30 | 2019-07-05 | 山东工商学院 | A kind of real-time ddos attack detection system and method towards SDN controller |
Non-Patent Citations (1)
Title |
---|
魏思政: "基于深度学习的入侵检测方法研究", 《中国优秀硕士学位论文全文数据库 信息科技辑》 * |
Cited By (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111181930A (en) * | 2019-12-17 | 2020-05-19 | 中移(杭州)信息技术有限公司 | DDoS attack detection method, device, computer equipment and storage medium |
CN111556017A (en) * | 2020-03-25 | 2020-08-18 | 中国科学院信息工程研究所 | Network intrusion detection method based on self-coding machine and electronic device |
CN111556017B (en) * | 2020-03-25 | 2021-07-27 | 中国科学院信息工程研究所 | Network intrusion detection method based on self-coding machine and electronic device |
CN111614665A (en) * | 2020-05-20 | 2020-09-01 | 重庆邮电大学 | Intrusion detection method based on deep residual hash network |
CN114070899A (en) * | 2020-07-27 | 2022-02-18 | 深信服科技股份有限公司 | Message detection method, device and readable storage medium |
CN114070899B (en) * | 2020-07-27 | 2023-05-12 | 深信服科技股份有限公司 | Message detection method, device and readable storage medium |
CN112383516A (en) * | 2020-10-29 | 2021-02-19 | 博雅正链(北京)科技有限公司 | Graph neural network construction method and abnormal flow detection method based on graph neural network |
CN112861913A (en) * | 2021-01-12 | 2021-05-28 | 浙江大学 | Intrusion alarm message correlation method based on graph convolution network |
CN113179276A (en) * | 2021-04-30 | 2021-07-27 | 中国人民解放军国防科技大学 | Intelligent intrusion detection method and system based on explicit and implicit feature learning |
CN113179276B (en) * | 2021-04-30 | 2022-07-12 | 中国人民解放军国防科技大学 | Intelligent intrusion detection method and system based on explicit and implicit feature learning |
CN114024713A (en) * | 2021-09-30 | 2022-02-08 | 广东电网有限责任公司电力调度控制中心 | Anti-intrusion method for low-voltage power line carrier communication system |
CN114024713B (en) * | 2021-09-30 | 2023-08-08 | 广东电网有限责任公司电力调度控制中心 | Anti-intrusion method for power line carrier communication system |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN110300127A (en) | A kind of network inbreak detection method based on deep learning, device and equipment | |
CN106209862B (en) | A kind of steal-number defence implementation method and device | |
CN107579956B (en) | User behavior detection method and device | |
CN110995714B (en) | Method, device and medium for detecting group attack on Web site | |
TWI684151B (en) | Method and device for detecting illegal transaction | |
US20180337935A1 (en) | Anomalous entity determinations | |
CN103593609B (en) | Trustworthy behavior recognition method and device | |
CN107493277B (en) | Large data platform online anomaly detection method based on maximum information coefficient | |
CN104967629A (en) | Network attack detection method and apparatus | |
CN107819631A (en) | A kind of unit exception detection method, device and equipment | |
CN108616545A (en) | A kind of detection method, system and electronic equipment that network internal threatens | |
CN106716382A (en) | Methods and systems for aggregated multi-application behavioral analysis of mobile device behaviors | |
CN107465651A (en) | Network attack detecting method and device | |
CN108334758A (en) | A kind of detection method, device and the equipment of user's ultra vires act | |
CN107392022A (en) | Reptile identification, processing method and relevant apparatus | |
CN107169499A (en) | A kind of Risk Identification Method and device | |
CN108076060A (en) | Neutral net Tendency Prediction method based on dynamic k-means clusters | |
CN107632722A (en) | A kind of various dimensions user ID authentication method and device | |
CN107026731A (en) | A kind of method and device of subscriber authentication | |
CN107395608A (en) | A kind of network access method for detecting abnormality and device | |
CN116996286A (en) | Network attack and security vulnerability management framework platform based on big data analysis | |
CN107992978A (en) | It is a kind of to net the method for prewarning risk and relevant apparatus for borrowing platform | |
Muslihi et al. | Detecting SQL injection on web application using deep learning techniques: a systematic literature review | |
Spillatura et al. | Conditional spectrum record selection faithful to causative earthquake parameter distributions | |
CN112039885A (en) | Website risk assessment method and device |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
RJ01 | Rejection of invention patent application after publication |
Application publication date: 20191001 |
|
RJ01 | Rejection of invention patent application after publication |