一种基于知识库的智能安全服务优化方法

Authors

  • 周欣然 (通讯作者) 深圳大学经济学院,深圳 518060,广东,中国

关键词:

网络安全知识库; 特征选择; 路径选择; 知识反馈

摘要

网络安全知识库对网络安全数据进行了标准化与整合,为实时网络安全防护方案提供了可靠的基础。然而,当前对网络安全知识库的研究主要集中在其构建上,而利用知识库优化面向实时网络安全防护的智能安全服务这一潜力仍有待深入挖掘。因此,如何有效利用网络安全领域海量的历史知识并建立实时更新的反馈机制,从而提升安全服务对恶意流量的检测能力,已成为一个重要课题。本文的贡献有四个方面:第一,设计了一个反馈接口,用攻击流量特征、网络服务功能(NSF)的检测结果以及系统资源占用等信息更新知识库;第二,提出一种把PageRank与RandomForest相结合的特征选择方法,用以识别知识库中影响力较大的特征并动态融入各NSF;第三,提出一种把图注意力网络(GAT)与深度强化学习(DRL)相结合的路径选择方法,用以学习知识库的局部知识并确定服务功能链(SFC)内的最优流量路径;第四,实验结果表明,知识库能够依据反馈信息实时更新,优化后的服务在准确率、召回率与F1分数上均超过96%。与预设路径以及采用深度Q网络(DQN)方法选出的路径相比,本文方法把恶意流量检测率平均分别提升12.4%与4.6%,把路径的恶意流量总检测能力(TMTDC)分别提升18.1%与11.5%,并显著降低了路径检测时延。经验证,本文提出的智能安全优化方法能够实时监测恶意流量、更新知识,并增强系统对恶意流量的检测能力。

Abstract

The network security knowledge base standardizes and integrates network security data, providing a reliable foundation for real-time network security protection solutions. However, current research on network security knowledge bases mainly focuses on their construction, while the potential to optimize intelligent security services for real-time network security protection requires further exploration. Therefore, how to effectively utilize the vast amount of historical knowledge in the field of network security and establish a feedback mechanism to update it in real time, thereby enhancing the detection capability of security services against malicious traffic, has become an important issue. Our contribution is fourfold. First, we design a feedback interface to update the knowledge base with information such as features of attack traffic, detection outcomes from network service functions (NSF), and system resource utilization. Second, we introduce a feature selection method that combines PageRank and RandomForest to identify influential features in the knowledge base and dynamically incorporate them into the NSFs. Third, we propose a path selection method that combines graph attention network (GAT) and deep reinforcement learning (DRL) to learn the local knowledge of the knowledge base and determine the optimal traffic path within the Service Function Chains (SFC). Finally, experimental results demonstrate that the knowledge base can be updated in real time according to feedback information, and the optimized service achieves an accuracy, recall, and F1 score exceeding 96%. Compared to preset paths and paths selected using the deep Q-network (DQN) method, our proposed method increases the malicious traffic detection rate by an average of 12.4% and 4.6%, respectively, enhances the total malicious traffic detection capability (TMTDC) of the path by 18.1% and 11.5%, and significantly reduces path detection delay. It has been verified that the proposed intelligent security optimization method can monitor malicious traffic in real time, update knowledge, and enhance the system's detection capability against malicious traffic.

References

[1] Mehmood A, Khanan A, Umar M M. Secure knowledge and cluster-based intrusion detection mechanism for smart wireless sensor networks. IEEE Access, 2017, 6: 5688-5694.

[2] 潘强. 智能无线传感器网络安全策略研究与实现. 沈阳师范大学, 2011.

[3] Zhang J, Wang Z, Ma N, et al. Enabling efficient service function chaining by integrating NFV and SDN: architecture, challenges and opportunities. IEEE Network, 2018, 32(6): 152-159.

[4] Mittal M, Kumar K, Behal S. Deep learning approaches for detecting DDoS attacks: a systematic review. Soft Computing, 2023, 27(18): 13039-13075.

[5] 郑承蔚, 王海凤, 刘瑞. SDN中DDoS攻击检测研究综述. 计算机工程与应用, 2024, 60(24).

[6] 王兴伟, 易波, 李福亮. SDN/NFV基本理论与服务编排技术应用实践. 北京: 科学出版社, 2021.

[7] Li K, Zhou H, Tu Z, et al. CSKB: a cyber security knowledge base based on knowledge graph. Singapore: Springer, 2020: 100-113.

[8] 朱若彬. 网络安全知识图谱构建关键技术研究. 哈尔滨工业大学, 2025.

Downloads

发布日期

2026-08-09

How to Cite

周欣然. 一种基于知识库的智能安全服务优化方法. 现代工程与应用. 2026, 4(3): 25-41. DOI: https://doi.org/10.61784/mea2029.