Network traffic anomaly detection model of petroleum industrial control software based on improved grey wolf optimization algorithm
摘要
To enhance cybersecurity in petroleum industrial control systems, this study proposes a network traffic anomaly detection model based on a Deep Belief Network (DBN) optimized by an Improved Grey Wolf Optimization (IGWO) algorithm. Network traffic data are collected using a Sniffer Data Flow Capture Tool, and four feature attributes - source and destination IP addresses along with source and destination port numbers - are extracted via information entropy to serve as inputs to the DBN. The IGWO algorithm optimizes the weights and biases of the DBN, thereby improving detection accuracy. Experimental results validate the effectiveness of the proposed model: under normal conditions, the feature entropy ranges from 0.55 to 0.6, whereas during attacks, the entropy decreases notably in the destination IP and port attributes. The model processes each data link within 0.36 s, with outputs closely aligning with actual results. Across various attack scenarios, it achieves high accuracy (0.99), precision (0.97), and recall (0.98), significantly strengthening network security through rapid threat identification.