Network intrusion detection method and system based on behavior analysis

Through the network intrusion detection method based on behavior analysis, a variety of real-time network data are collected and analyzed, dynamic behavior maps are generated and abnormal detection is performed, which solves the shortcomings of existing systems in the face of new attacks and large-scale data processing, and achieves efficient and accurate network intrusion detection and attack blocking.

CN120110778AInactive Publication Date: 2025-06-06GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 7 Cited by

Patent Information

Application Number
CN202510315695.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing network intrusion detection systems are not effective in the face of new or mutated attacks, and there are problems of data diversity, real-time, accuracy and attack blocking delay when dealing with large-scale and dynamically changing network data.

Method used

A network intrusion detection method based on behavior analysis is adopted, and a variety of real-time data is collected, and a space-time correlation analysis is performed to generate a dynamic behavior map, abnormal detection is performed and an abnormal node list is generated, and an attack block is finally performed based on this list.

Benefits of technology

Real-time monitoring, accurate analysis and rapid response to network behavior is achieved, which significantly improves the accuracy and efficiency of network intrusion detection and effectively ensures the safe and stable operation of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110778A_ABST
    Figure CN120110778A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a network intrusion detection method and system based on behavior analysis, and the method comprises the steps: collecting real-time data of a target network, the real-time data comprising network flow data, user access logs, equipment state parameters, inter-user interaction logs and trust relationship data; performing space-time correlation analysis on the real-time data to generate a dynamic behavior graph; performing anomaly detection on the dynamic behavior map to generate an abnormal node list; and executing attack blocking based on the abnormal node list. According to the invention, the recognition and defense capabilities of abnormal behaviors are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and specifically to a network intrusion detection method and system based on behavior analysis. Background Art

[0002] With the rapid development of Internet technology, the network environment is becoming increasingly complex, and network attack methods are becoming more diverse and covert. Traditional network intrusion detection systems mainly rely on preset rules and signature libraries. These methods are effective in the face of known attacks, but they are often incapable of dealing with new or mutated attack methods.

[0003] In addition, existing network intrusion detection methods face many challenges when processing large-scale, dynamically changing network data:

[0004] Data diversity: There are many types of network data, including network traffic data, user access logs, device status parameters, etc. How to effectively integrate these multi-source heterogeneous data and build a comprehensive network behavior model is a major challenge.

[0005] Real-time requirement: Network attacks are often sudden and real-time, requiring the intrusion detection system to be able to collect and analyze data in real time and respond quickly.

[0006] Accuracy issues: Existing anomaly detection methods are often affected by normal behavior variability and noise, resulting in a high false alarm rate, which affects the accuracy of detection.

[0007] Insufficient behavioral analysis: Traditional detection methods often lack in-depth analysis of network behavior and cannot effectively identify complex attack behaviors.

[0008] Attacks are not blocked in time: Even if anomalies are detected, existing systems often have delays in blocking attacks and are unable to block attacks in time, resulting in increased losses.

[0009] Therefore, improvements are needed. Summary of the invention

[0010] In order to solve the above technical problems, the present application provides a network intrusion detection method and system based on behavior analysis.

[0011] The first object of the invention of this application is achieved through the following technical solutions:

[0012] A network intrusion detection method based on behavior analysis comprises the following steps:

[0013] Collecting real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data;

[0014] Performing spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior map;

[0015] Perform anomaly detection on the dynamic behavior graph to generate an abnormal node list;

[0016] Attack blocking is performed based on the abnormal node list.

[0017] In a preferred embodiment, the real-time data of the target network is collected, and the real-time data includes network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data, including:

[0018] The network traffic data includes source IP, destination IP, packet size, and traffic values ​​recorded over time;

[0019] The user terminal access log includes a log entry of the user terminal ID, access timestamp, and request interface path;

[0020] The device status parameters include the CPU usage of the router, the number of active sessions of the firewall, and the port flow value of the switch;

[0021] The user interaction log includes communication frequency and shared resource records;

[0022] The trust relationship data includes user authority level and device security domain affiliation.

[0023] In a preferred embodiment, performing spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior graph includes:

[0024] Aggregate the network traffic data according to a preset fixed time window to generate a set of <source node, destination node, total traffic value> triples in each window;

[0025] Parsing the user terminal access log, sorting the continuous access paths of the same user terminal ID by time, and forming a user terminal behavior sequence;

[0026] Parse the interaction logs between users and generate user interaction edges;

[0027] Calculating the correlation coefficients between the device status parameters to generate a correlation coefficient matrix;

[0028] Generate a dynamic behavior graph G = (V, E, W) including timestamps and real-time data, where:

[0029] The node set V includes network devices and user terminals, and the network devices include routers, firewalls, and switches;

[0030] The edge set E includes a traffic transmission edge and a user-side access edge. The traffic transmission edge is a transmission path from a source IP to a destination IP, and the user-side access edge is an access path from a user-side ID to a request interface path.

[0031] The weight matrix W includes flow value and correlation coefficient.

[0032] In a preferred embodiment, the step of calculating the correlation coefficients between the device state parameters and generating a correlation coefficient matrix includes:

[0033] Construct a device parameter matrix M, where rows represent network devices and columns represent different parameter types;

[0034] Based on preset formula Calculate the Pearson correlation coefficient ρ between any two columns of parameters ij , generate the correlation coefficient matrix P.

[0035] In a preferred embodiment, performing anomaly detection on the dynamic behavior graph and generating an abnormal node list includes:

[0036] Based on the time convolution network, the multi-scale time series features of network traffic data are extracted and the feature vector F is output. t ;

[0037] Based on the graph neural network, the neighbor features of each node in the node set are aggregated to generate the node embedding vector F g ;

[0038] Fusion F t With F g Get the joint eigenvector F f , based on the preset formula Calculate F f The Mahalanobis distance D from the mean μ of historical normal data M :

[0039] When D M Greater than the first preset threshold ε 1 When the corresponding node is marked as an abnormal node, an abnormal node list L = {v 1 ,v 2 ,...,v n}, each abnormal node is labeled with an abnormal confidence score_i.

[0040] In a preferred embodiment, the attack blocking is performed based on the abnormal node list, including:

[0041] When the score_i of the abnormal node is greater than a preset threshold ε, extracting network traffic data associated with the abnormal node;

[0042] Perform STL decomposition on the extracted network traffic data and output the residual component R;

[0043] Calculate the standard deviation σ(R) of the residual component R. When σ(R)>K·σ_hist, where K is the preset coefficient and σ_hist is the standard deviation of the historical normal period, it is determined to be an attack;

[0044] Send attack instructions to the firewall to block all inbound and outbound traffic of abnormal nodes.

[0045] The second invention objective of this application is achieved through the following technical solutions:

[0046] A network intrusion detection system based on behavior analysis, including

[0047] Collection module: collects real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data;

[0048] The first generation module performs spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior map;

[0049] The second generation module is used to perform anomaly detection on the dynamic behavior graph and generate an abnormal node list;

[0050] Execution module: based on the abnormal node list, execute attack blocking.

[0051] The third invention objective of this application is achieved through the following technical solutions:

[0052] A computer device comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned network intrusion detection method based on behavior analysis are implemented.

[0053] The fourth invention objective of this application is achieved through the following technical solutions:

[0054] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned network intrusion detection method based on behavior analysis are implemented.

[0055] In summary, the present application includes at least one of the following beneficial technical effects:

[0056] By comprehensively collecting real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data, a multi-dimensional data foundation is constructed. Then, the real-time data is deeply mined using spatiotemporal correlation analysis technology to generate a dynamic behavior map, which can reflect the behavior patterns and interaction relationships between entities in the network in real time. Subsequently, by performing anomaly detection on the dynamic behavior map, the system can accurately identify abnormal nodes that deviate from the normal behavior pattern and generate an abnormal node list. Finally, based on the abnormal node list, the system performs attack blocking operations. When the behavior of the abnormal node exceeds the preset threshold, it further analyzes and blocks all its inbound and outbound traffic, thereby effectively defending against network attacks. This method realizes real-time monitoring, precise analysis, and rapid response to network behavior, significantly improves the accuracy and efficiency of network intrusion detection, and effectively ensures the safe and stable operation of the network system. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 This is a flowchart of an implementation of a network intrusion detection method based on behavior analysis in the present application;

[0058] Figure 2 This is a flowchart of an implementation of step S10 in an embodiment of a network intrusion detection method based on behavior analysis of the present application;

[0059] Figure 3 This is a flowchart of an implementation of step S20 in an embodiment of a network intrusion detection method based on behavior analysis of the present application;

[0060] Figure 4 This is a flowchart of implementing step S204 in an embodiment of a network intrusion detection method based on behavior analysis of the present application;

[0061] Figure 5 is a flowchart of an implementation of step S30 in an embodiment of a network intrusion detection method based on behavior analysis;

[0062] Figure 6 is a flowchart of an implementation of step S40 in an embodiment of a network intrusion detection method based on behavior analysis;

[0063] Figure 7 This is a principle block diagram of a computer device of the present application. DETAILED DESCRIPTION

[0064] The following is combined with Figure 1-7 This application is described in further detail.

[0065] In one embodiment, if Figure 1 As shown, the present application discloses a network intrusion detection method based on behavior analysis, which specifically includes the following steps:

[0066] S10: Collecting real-time data of the target network, the real-time data including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data;

[0067] S20: Performing spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior map;

[0068] S30: performing anomaly detection on the dynamic behavior graph to generate an abnormal node list;

[0069] S40: Based on the abnormal node list, perform attack blocking.

[0070] In this embodiment, a multi-dimensional data foundation is constructed by comprehensively collecting real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data. Then, the real-time data is deeply mined using spatiotemporal correlation analysis technology to generate a dynamic behavior map, which can reflect the behavior patterns and interaction relationships between entities in the network in real time. Subsequently, by performing anomaly detection on the dynamic behavior map, the system can accurately identify abnormal nodes that deviate from the normal behavior pattern and generate an abnormal node list. Finally, based on the abnormal node list, the system performs an attack blocking operation. When the behavior of the abnormal node exceeds the preset threshold, it further analyzes and blocks all its inbound and outbound traffic, thereby effectively defending against network attacks. This method realizes real-time monitoring, precise analysis, and rapid response to network behavior, significantly improves the accuracy and efficiency of network intrusion detection, and effectively ensures the safe and stable operation of the network system.

[0071] Figure 2 , S10, including:

[0072] S101: The network traffic data includes source IP, destination IP, data packet size, and traffic values ​​recorded over time;

[0073] S102: The user terminal access log includes a log entry of the user terminal ID, access timestamp, and request interface path;

[0074] S103: The device status parameters include the CPU usage of the router, the number of active sessions of the firewall, and the port flow value of the switch;

[0075] S104: The user interaction log includes communication frequency and shared resource records;

[0076] S105: The trust relationship data includes user authority level and device security domain affiliation.

[0077] In this embodiment, in step S10, the system collects detailed network traffic data including source IP, destination IP, packet size and traffic values ​​recorded over time, as well as user access logs of user terminal ID, access timestamp and request interface path. These data provide rich network behavior information for subsequent analysis. At the same time, device status parameters such as CPU usage of routers, number of active sessions of firewalls, port traffic values ​​of switches, etc., reflect the real-time operating status of network devices and provide important basis for anomaly detection. In addition, user interaction logs and trust relationship data further reveal user behavior patterns and trust relationships between entities, enhancing the depth and accuracy of behavior analysis.

[0078] Through spatiotemporal correlation analysis, these multi-dimensional data are integrated to generate dynamic behavior graphs, which show the behavior patterns in the network and the complex interactions between entities in real time. Subsequently, the anomaly detection algorithm conducts in-depth analysis of the dynamic behavior graph, accurately identifies abnormal nodes that deviate from normal behavior patterns, and generates a list of abnormal nodes. Based on this list, the system performs attack blocking operations and effectively defends against network attacks. This method realizes comprehensive monitoring, in-depth analysis and rapid response of network behavior, significantly improves the accuracy and efficiency of network intrusion detection, and effectively ensures the safe and stable operation of the network system.

[0079] Figure 3 , S20, including:

[0080] S201: Aggregate the network traffic data according to a preset fixed time window to generate a set of <source node, destination node, total traffic value> triples in each window;

[0081] S202: parsing the user terminal access log, sorting the continuous access paths of the same user terminal ID by time, and forming a user terminal behavior sequence;

[0082] S203: parsing the user interaction logs and generating user interaction edges;

[0083] S204: Calculate the correlation coefficients between the device state parameters and generate a correlation coefficient matrix;

[0084] S205: Generate a dynamic behavior graph G=(V, E, W) including timestamp and real-time data, where:

[0085] S206: The node set V includes network devices and user terminals, and the network devices include routers, firewalls, and switches;

[0086] S207: The edge set E includes a traffic transmission edge and a user terminal access edge, wherein the traffic transmission edge is a transmission path from a source IP to a destination IP, and the user terminal access edge is an access path from a user terminal ID to a request interface path;

[0087] S208: The weight matrix W includes flow value and correlation coefficient.

[0088] In this embodiment, step S20 realizes the refined modeling of network behavior and the construction of dynamic behavior graphs through in-depth data processing and analysis. First, by aggregating network traffic data according to a preset fixed time window, a set of <source node, destination node, total traffic value> triples is generated, which effectively captures the spatiotemporal characteristics of network traffic. At the same time, the user-side access log is parsed to form a user-side behavior sequence, revealing the temporal pattern and access path of user behavior. In addition, by parsing the user-to-user interaction log to generate user interaction edges, the interactive relationship between users is further demonstrated. In terms of device state parameters, the correlation coefficient is calculated and the correlation coefficient matrix is ​​generated, revealing the intrinsic connection and influence between different device state parameters. Based on these processed data, the system generates a dynamic behavior graph G = (V, E, W) containing timestamps and real-time data, where the node set V covers network devices (such as routers, firewalls, switches) and user terminals, the edge set E includes traffic transmission edges and user-side access edges, and the weight matrix W is composed of traffic values ​​and correlation coefficients.

[0089] This dynamic behavior graph not only reflects the traffic transmission, user access and device status in the network in real time, but also quantifies the importance of these behaviors and status through the weight matrix. Thus, it provides rich and accurate behavior characteristics and associations for subsequent anomaly detection, enabling the system to more accurately identify abnormal nodes and effectively improve the real-time and accuracy of network intrusion detection. At the same time, this detection method based on dynamic behavior graphs also enhances the system's adaptability to complex network environments and its ability to defend against new attacks.

[0090] Figure 4 , S204, including:

[0091] SA1: Construct a device parameter matrix M, where rows represent network devices and columns represent different parameter types;

[0092] SA2: Based on preset formula Calculate the Pearson correlation coefficient ρ between any two columns of parameters ij , generate the correlation coefficient matrix P.

[0093] In this embodiment, by constructing a device parameter matrix M, different state parameters of network devices are represented in a matrix, with rows representing different network devices and columns representing various parameter types, such as CPU usage, number of active sessions, etc. Then, using the preset formula Calculate the Pearson correlation coefficient ρ between any two columns of parameters ij, thus generating the correlation coefficient matrix P. The effect of this process is that it reveals the intrinsic connection and mutual influence between the state parameters of network devices, and provides important correlation information for the construction of dynamic behavior graphs.

[0094] By calculating this correlation coefficient, the system can better understand the operating status of network devices and discover potential risk factors. For example, when the correlation between two device parameters suddenly increases or decreases, it may indicate that an abnormal change has occurred in the network environment. This analysis method improves the accuracy of network intrusion detection and makes the system more targeted when identifying abnormal behavior. At the same time, the correlation coefficient matrix gives the dynamic behavior map richer semantic information, which helps the system to more comprehensively evaluate network security, thereby effectively improving network defense capabilities.

[0095] Figure 5 , S30, including:

[0096] S301: Based on the time convolution network, extract the multi-scale time series features of network traffic data and output the feature vector F t ;

[0097] S302: Based on the graph neural network, aggregate the neighbor features of each node in the node set to generate the node embedding vector F g ;

[0098] S303: Fusion F t With F g Get the joint eigenvector F f , based on the preset formula Calculate F f The Mahalanobis distance D from the mean μ of historical normal data M :

[0099] S304: When D M Greater than the first preset threshold ε 1 When the corresponding node is marked as an abnormal node, an abnormal node list L = {v 1 ,v 2 ,...,v n}, each abnormal node is labeled with an abnormal confidence score_i.

[0100] In this embodiment, a time convolutional network (TCN) is used to extract multi-scale time series features of network traffic data and output a feature vector F t This process can capture the changing patterns of traffic data at different time scales. Subsequently, the neighbor features of each node in the node set are aggregated through the graph neural network (GNN) to generate the node embedding vector F g, which helps to understand the complex relationships between entities in the network. Then, these two types of feature vectors are fused to obtain the joint feature vector F f , and based on the preset formula Calculate the Mahalanobis distance D between it and the mean μ of historical normal data M , in order to quantify the difference between the current node behavior and the normal behavior.

[0101] The effectiveness of this method is that it can integrate timing characteristics and topological relationships to provide a more comprehensive behavioral representation for anomaly detection. By calculating the Mahalanobis distance, the system can effectively identify nodes that deviate greatly from normal behavior patterns. When the calculation result exceeds the first preset threshold, the system marks the node as an abnormal node, generates a list of abnormal nodes, and annotates the abnormal confidence, which helps security operations personnel to prioritize and process according to the degree of abnormality. The method in this embodiment not only improves the accuracy of anomaly detection, but also enhances the interpretability and operability of the detection results through the annotation of confidence, thereby significantly improving the overall performance and response speed of the network intrusion detection system.

[0102] Figure 6 , S40, including:

[0103] S401: When the score_i of the abnormal node is greater than a preset threshold ε, extracting network traffic data associated with the abnormal node;

[0104] S402: Perform STL decomposition on the extracted network traffic data and output a residual component R;

[0105] S403: Calculate the standard deviation σ(R) of the residual component R. When σ(R)>K·σ_hist, where K is a preset coefficient and σ_hist is the standard deviation of the historical normal period, it is determined to be an attack;

[0106] S404: Send an attack instruction to the firewall to block all inbound and outbound traffic of abnormal nodes.

[0107] In this embodiment, for the nodes in the abnormal node list whose confidence score_i is greater than the preset threshold ε, the associated network traffic data is extracted, and the STL decomposition of the time series is performed to separate the residual component R. By calculating the standard deviation σ(R) of the residual component R and comparing it with the standard deviation of the historical normal period, if σ(R)>K·σ_hist, it is determined that the abnormal node has an attack behavior.

[0108] The effect of this method is that it can accurately identify attack behaviors in the network and take quick action. STL decomposition helps to remove the periodic and trend components of traffic data, thereby more clearly revealing the impact of abnormal behavior. By comparing the standard deviation of the residual components, the system can quantify the degree of abnormality and effectively distinguish normal fluctuations from potential attack activities. Once it is determined to be an attack, the system immediately sends an attack instruction to the firewall to block all inbound and outbound traffic of the abnormal node, thereby promptly curbing the spread of the attack and protecting network resources from infringement. The method in this embodiment not only improves the sensitivity and accuracy of attack detection, but also significantly shortens the response time through the automated blocking process, thereby enhancing the defense capability of the network intrusion detection system and the overall security of the network.

[0109] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0110] In one embodiment, a network intrusion detection system based on behavior analysis is provided, and the network intrusion detection system based on behavior analysis corresponds to the network intrusion detection method based on behavior analysis in the above embodiment. The network intrusion detection system based on behavior analysis includes:

[0111] Collection module: collects real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data;

[0112] The first generation module performs spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior map;

[0113] The second generation module is used to perform anomaly detection on the dynamic behavior graph and generate an abnormal node list;

[0114] Execution module: based on the abnormal node list, execute attack blocking.

[0115] Optional, words include:

[0116] The first module includes: the network traffic data includes source IP, destination IP, packet size and traffic value recorded over time;

[0117] The second module includes: the client access log includes a log entry of the client ID, access timestamp, and request interface path;

[0118] The third module includes: the device status parameters include the CPU usage of the router, the number of active sessions of the firewall, and the port flow value of the switch;

[0119] The fourth module includes: the user interaction log includes communication frequency and shared resource records;

[0120] The fifth module includes: the trust relationship data includes user authority level and device security domain affiliation.

[0121] Optionally, also include:

[0122] The third generation module aggregates the network traffic data according to a preset fixed time window to generate a set of <source node, destination node, total traffic value> triples in each window;

[0123] Formation module: parsing the user terminal access log, sorting the continuous access paths of the same user terminal ID by time, and forming a user terminal behavior sequence;

[0124] The fourth generation module: parses the user interaction logs and generates user interaction edges;

[0125] The fifth generation module is used to calculate the correlation coefficients between the device state parameters and generate a correlation coefficient matrix;

[0126] The sixth generation module: generates a dynamic behavior graph G = (V, E, W) including timestamps and real-time data, where:

[0127] The sixth module includes: the node set V includes network devices and user terminals, and the network devices include routers, firewalls, and switches;

[0128] The seventh module includes: the edge set E includes a traffic transmission edge and a user terminal access edge, wherein the traffic transmission edge is a transmission path from a source IP to a destination IP, and the user terminal access edge is an access path from a user terminal ID to a request interface path;

[0129] The eighth module includes: the weight matrix W includes flow value and correlation coefficient.

[0130] Optionally, also include:

[0131] Construction module: construct the device parameter matrix M, where rows represent network devices and columns represent different parameter types;

[0132] The seventh generation module: based on the preset formula Calculate the Pearson correlation coefficient ρ between any two columns of parameters ij , generate the correlation coefficient matrix P.

[0133] Optionally, also include:

[0134] The first output module: Based on the time convolutional network, it extracts the multi-scale time series features of network traffic data and outputs the feature vector F t ;

[0135] The eighth generation module: Based on the graph neural network, aggregate the neighbor features of each node in the node set and generate the node embedding vector F g ;

[0136] The first computing module: Fusion F t With F g Get the joint eigenvector F f , based on the preset formula Calculate F f The Mahalanobis distance D from the mean μ of historical normal data M :

[0137] The ninth generation module: When D M Greater than the first preset threshold ε 1 When the corresponding node is marked as an abnormal node, an abnormal node list L = {v 1 ,v 2 ,...,v n}, each abnormal node is labeled with an abnormal confidence score_i.

[0138] Optionally, also include:

[0139] The first extraction module: when the score_i of the abnormal node is greater than the preset threshold ε, extract the network traffic data associated with the abnormal node;

[0140] The second output module: performs STL decomposition on the extracted network traffic data and outputs the residual component R;

[0141] The second calculation module: calculates the standard deviation σ(R) of the residual component R. When σ(R)>K·σ_hist, where K is a preset coefficient and σ_hist is the standard deviation of the historical normal period, it is determined to be an attack;

[0142] Blocking module: Send attack instructions to the firewall to block all inbound and outbound traffic of abnormal nodes.

[0143] For the specific definition of a network intrusion detection system based on behavior analysis, please refer to the definition of a network intrusion detection method based on behavior analysis above, which will not be repeated here. Each module in the above-mentioned network intrusion detection system based on behavior analysis can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0144] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 7As shown. The computer device includes a processor, a memory, a network interface and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store real-time data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a network intrusion detection method based on behavior analysis is implemented.

[0145] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, a network intrusion detection method based on behavior analysis is implemented.

[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, a network intrusion detection method based on behavior analysis is implemented.

[0147] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0148] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

Claims

1. A network intrusion detection method based on behavior analysis, characterized in that: Includes steps: Collecting real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data; Performing spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior map; Perform anomaly detection on the dynamic behavior graph to generate an abnormal node list; Attack blocking is performed based on the abnormal node list.

2. A network intrusion detection method based on behavior analysis according to claim 1, characterized in that: The real-time data of the target network is collected, and the real-time data includes network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data, including: The network traffic data includes source IP, destination IP, packet size, and traffic values ​​recorded over time; The user terminal access log includes a log entry of the user terminal ID, access timestamp, and request interface path; The device status parameters include the CPU usage of the router, the number of active sessions of the firewall, and the port flow value of the switch; The user interaction log includes communication frequency and shared resource records; The trust relationship data includes user authority level and device security domain affiliation.

3. A network intrusion detection method based on behavior analysis according to claim 1, characterized in that: The performing of spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior graph includes: Aggregate the network traffic data according to a preset fixed time window to generate a set of <source node, destination node, total traffic value> triples in each window; Parsing the user terminal access log, sorting the continuous access paths of the same user terminal ID by time, and forming a user terminal behavior sequence; Parse the interaction logs between users and generate user interaction edges; Calculating the correlation coefficients between the device status parameters to generate a correlation coefficient matrix; Generate a dynamic behavior graph G = (V, E, W) including timestamps and real-time data, where: The node set V includes network devices and user terminals, and the network devices include routers, firewalls, and switches; The edge set E includes a traffic transmission edge and a user-side access edge. The traffic transmission edge is a transmission path from a source IP to a destination IP, and the user-side access edge is an access path from a user-side ID to a request interface path. The weight matrix W includes flow value and correlation coefficient.

4. A network intrusion detection method based on behavior analysis according to claim 3, characterized in that: The calculating the correlation coefficients between the device state parameters to generate a correlation coefficient matrix includes: Construct a device parameter matrix M, where rows represent network devices and columns represent different parameter types; Based on preset formula Calculate the Pearson correlation coefficient ρ between any two columns of parameters ij , generate the correlation coefficient matrix P.

5. A network intrusion detection method based on behavior analysis according to claim 1, characterized in that: The performing of anomaly detection on the dynamic behavior graph to generate an abnormal node list includes: Based on the time convolution network, the multi-scale time series features of network traffic data are extracted and the feature vector F is output. t ; Based on the graph neural network, the neighbor features of each node in the node set are aggregated to generate the node embedding vector F g ; Fusion F t With F g Get the joint eigenvector F f , based on the preset formula Calculate F f The Mahalanobis distance D from the mean μ of historical normal data M : When D M When it is greater than the first preset threshold ε1, the corresponding node is marked as an abnormal node, and an abnormal node list L = {v1, v2, ..., v n }, each abnormal node is labeled with an abnormal confidence score_i.

6. A network intrusion detection method based on behavior analysis according to claim 1, characterized in that: The performing attack blocking based on the abnormal node list includes: When the score_i of the abnormal node is greater than a preset threshold ε, extracting network traffic data associated with the abnormal node; Perform STL decomposition on the extracted network traffic data and output the residual component R; Calculate the standard deviation σ(R) of the residual component R. When σ(R)>K·σ_hist, where K is the preset coefficient and σ_hist is the standard deviation of the historical normal period, it is determined to be an attack; Send attack instructions to the firewall to block all inbound and outbound traffic of abnormal nodes.

7. A network intrusion detection based on behavior analysis, characterized in that: include Collection module: collects real-time data of the target network, including network traffic data, user access logs, device status parameters, user interaction logs, and trust relationship data; The first generation module performs spatiotemporal correlation analysis on the real-time data to generate a dynamic behavior map; The second generation module is used to perform anomaly detection on the dynamic behavior graph and generate an abnormal node list; Execution module: based on the abnormal node list, execute attack blocking.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of a network intrusion detection method based on behavior analysis as described in claims 1-6 are implemented.

9. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of a network intrusion detection method based on behavior analysis as claimed in claims 1 to 6.

Citation Information

Cited By

  • Low-delay network security detection method and system

    CN120415923A

  • Network asset detection method, device and equipment and storage medium

    CN120750628A

  • Access control management method and system of Internet of Things equipment

    CN120811779A

  • Network intrusion detection method and system based on firewall

    CN121567475A

  • A firewall-based network intrusion detection method and system

    CN121567475B