首页|期刊导航|信息工程大学学报|SAFE-Former:一种针对SSH协议的中间人攻击检测方法

SAFE-Former:一种针对SSH协议的中间人攻击检测方法OA

SAFE-Former:a Method for SSH Man-in-the-Middle Attack Detection

中文摘要英文摘要

针对SSH(Secure Shell)协议中间人攻击检测中传统方法泛化能力不足、应用效率低的问题,提出一种基于时序特征和自学习机制的检测方法.采用FT-Transformer(Feature Tokenizer Transformer)架构,结合时序特征分析与SE-Net(Squeeze-and-Excitation Network)自学习机制,构建SAFE-Former检测模型.通过分析SSH连接建立过程中密钥和算法协商阶段的关键报文,提取协商报文时延比值或占比特征构建代表性特征,利用特征独立编码机制和SE-Net自学习机制捕捉协议交互过程中的时序依赖关系与异常模式,实现对正常与攻击流量的有效区分.实验表明,该方法在互联网环境测试数据集上准确率达98%以上,消融实验与多模型对比分析验证了所提特征与模型的有效性.相比现有主流方法,SAFE-Former在SSH中间人攻击检测方面展现出显著优势.

To address the limitations of traditional methods in secure shell(SSH)man-in-the-middle at‑tack detection,particularly insufficient generalization capability and low application efficiency,a de‑tection method incorporating temporal features and self-learning mechanisms is proposed.In the method,the feature tokenizer transformer(FT-Transformer)architecture is adopted and time series analysis is integrated with squeeze-and-excitation network(SE-Net)self-learning mechanisms to con‑struct the SAFE-Former detection model.Representative features are constructed from delay ratio and proportion characteristics of negotiation packets by analyzing critical packets during the key exchange and algorithm negotiation phases of SSH connection establishment.The feature tokenization mecha‑nism and SE-Net self-learning mechanism are utilized to capture temporal dependencies and anoma‑lous patterns in protocol interactions,enabling effective differentiation between normal and attack traf‑fic.Experimental results demonstrate that the method achieves an accuracy exceeding 98%on Internet environment test datasets.The effectiveness of the proposed features and model is validated through the ablation studies and multi-model comparative analysis.Compared with existing mainstream ap‑proaches,SAFE-Former exhibits significant advantages in SSH man-in-the-middle attack detection.

刘騉;林伟;靳迪;李玎;陈迪

信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001信息工程大学,河南 郑州 450001

信息技术与安全科学

SSH协议中间人攻击检测时序特征自学习机制FT-Transformer

SSH protocolman-in-the-middle attack detectiontemporal featuresself-learning mecha‑nismFT-Transformer

《信息工程大学学报》 2026 (2)

216-222,230,8

国家自然科学基金青年基金(62302520)国家自然科学基金(62402524)

10.3969/j.issn.1671-0673.2026.02.012

评论