The access of high proportion of clean energy and high proportion of power electronic devices has significantly improved the level of digitization and interconnection of The Energy Internet, resulting in an increase in the attack surface of The Energy Internet. As an important national infrastructure, The Energy Internet has become an important target of high-level persistent threats. In response to advanced persistent threats, the sequence model is applied to the field of intrusion detection by virtue of its superiority in capturing long-distance dependencies. However, the sequence model will face the problem of loss of local information and semantic information, which makes it difficult to further improve the detection accuracy. In order to solve the above problems, this paper proposes an intrusion detection method based on state space model-CGP-Mamba. Firstly, this paper proposes a temporal feature extraction technology combining CNN and Mamba, which breaks through the limitation of sequence model on local feature extraction and improves the model's ability to capture local information. Secondly, a log semantic representation method based on BERT is proposed, which solves the problem of insufficient semantic understanding in complex scenes and improves the semantic representation ability of the model. Finally, the PagFM fusion mechanism is introduced to realize the deep fusion of semantic information and temporal information, which enhances the global recognition ability of the model. CGP-Mamba is compared with ATLAS and other methods on two log detection datasets, and the precision rate reaches 96.23%. The contribution of each model component is evaluated by ablation experiments.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CGP-Mamba: An Intrusion Detection Method Based on State Space Model

  • Jingheng He,
  • Gang Wang,
  • Naiwei Liu,
  • Lingfei Kong

摘要

The access of high proportion of clean energy and high proportion of power electronic devices has significantly improved the level of digitization and interconnection of The Energy Internet, resulting in an increase in the attack surface of The Energy Internet. As an important national infrastructure, The Energy Internet has become an important target of high-level persistent threats. In response to advanced persistent threats, the sequence model is applied to the field of intrusion detection by virtue of its superiority in capturing long-distance dependencies. However, the sequence model will face the problem of loss of local information and semantic information, which makes it difficult to further improve the detection accuracy. In order to solve the above problems, this paper proposes an intrusion detection method based on state space model-CGP-Mamba. Firstly, this paper proposes a temporal feature extraction technology combining CNN and Mamba, which breaks through the limitation of sequence model on local feature extraction and improves the model's ability to capture local information. Secondly, a log semantic representation method based on BERT is proposed, which solves the problem of insufficient semantic understanding in complex scenes and improves the semantic representation ability of the model. Finally, the PagFM fusion mechanism is introduced to realize the deep fusion of semantic information and temporal information, which enhances the global recognition ability of the model. CGP-Mamba is compared with ATLAS and other methods on two log detection datasets, and the precision rate reaches 96.23%. The contribution of each model component is evaluated by ablation experiments.