信息安全研究 ›› 2026, Vol. 12 ›› Issue (8): 721-729.DOI: 10.12379/j.issn.2096-1057.2026.08.04

• • 上一篇    

基于贝叶斯优化与时空注意力的恶意流量 检测方法

韩刚,王浩然,苏天森,马妍,薛玉皎   

  • 发布日期:2026-08-12

Malicious Traffic Detection Method Based on Bayesian Optimization and Spatiotemporal Attention

Han Gang, Wang Haoran, Su Tiansen, Ma Yan, and Xue Yujiao   

  • Published:2026-08-12

摘要: 针对当前恶意网络流量检测技术准确率不足、超参数依赖手动调整的问题,本文提出一种基于贝叶斯优化与时空注意力的双向循环网络恶意流量检测方法,通过双向长短时记忆网络提取网络流量数据的时间特征和空间特征,使用贝叶斯优化搜索最优的网络参数。本文创新性地提出多尺度流量协议增强模块,通过多级协议解析、动态特征融合与注意力协同机制,显著增强了对复杂攻击链的时空特征表征能力。同时,为建立时空特征间的深度关联,本文提出多头时空注意力机制,通过4组并行注意力头协同建模毫秒级协议瞬变、秒级交互时序、分钟级攻击链演进及跨协议关联特性,有效提升对隐蔽威胁的识别精度。采用CIC-IDS2017数据集进行实验,结果表明,本文方法在多分类和二分类的准确率分别达到99.46%和99.59%,性能均优于其他方法。

关键词: 恶意流量检测;贝叶斯优化;注意力机制;循环神经网络;数据特征

Abstract: To address the limitations inherent in current malicious network traffic detection methods, specifically suboptimal detection accuracy and reliance on manual hyperparameter tuning, this study proposes a malicious traffic detection method based on Bayesian optimization and a spatiotemporal attention mechanism. It adopts bidirectional long short-term memory (BiLSTM) to extract temporal and spatial features of network traffic data, and leverages Bayesian optimization to search for optimal network hyperparameters.A bidirectional architecture extracts temporal and spatial features from network traffic data, while Bayesian optimization automatically searches for optimal network parameters. Innovatively, we introduce a Multi-scale Traffic Protocol Enhancement Module that significantly enhances spatiotemporal feature representation for complex attack chains through multi-level protocol parsing, dynamic feature fusion, and attention coordination. Concurrently, to establish deep correlations between spatiotemporal features, we propose a Multi-head Spatiotemporal Attention Mechanism. This employs four parallel attention heads to cooperatively model millisecond-level protocol transients, second-level interaction sequences, minute-scale attack chain evolution, and cross-protocol correlation characteristics, effectively improving detection accuracy for stealthy threats. Experimental validation on the CIC-IDS2017 dataset demonstrates that the proposed method achieves multiclass and binary classification accuracies of 99.46% and 99.59%, respectively, outperforming comparative approaches.

Key words: malicious traffic detection; Bayesian optimization; attention mechanism; recurrent neural network; data features

中图分类号: