Network flow threat analysis method based on operating system instruction hierarchy
By monitoring and analyzing operating system instruction data in real time, building dynamic behavior matrix and instruction-level traffic maps, combined with Benford’s Law and graph neural network technologies, the existing network security detection methods are difficult to cope with new types of network attacks, and efficient and accurate threat detection and attack path analysis are achieved.
Patent Information
- Application Number
- CN202510333590.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-13
AI Technical Summary
Existing cybersecurity detection methods are difficult to effectively deal with new cyber attacks such as advanced persistent threats (APTs), zero-day attacks and file-independent malicious code execution, especially in the case of encrypted traffic, tunnel communications, and traffic obfuscation.
By monitoring the operating system instruction data in real time, a dynamic behavior matrix and instruction-level traffic map are constructed, and using Benford’s Law, decision tree classification algorithm, graph neural network and Bayesian update technologies, threat detection and attack path analysis are carried out, abnormal instructions are identified and attack paths are generated.
It realizes more accurate and efficient network traffic threat detection, can identify known and unknown attack behaviors, reduce false alarms, improve detection accuracy, and provide stronger security protection capabilities.
Smart Images

Figure CN120151049A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a method for analyzing network traffic threats based on the operating system instruction level. Background Art
[0002] With the continuous evolution of network attack means, network security threats have gradually shown a trend of higher concealment, intelligence, and complexity. Traditional network traffic analysis and security detection methods are difficult to cope with new attack means, such as advanced persistent threats (APT), zero-day attacks, fileless malware execution, etc. Currently, the mainstream network security detection methods are mainly divided into two categories: feature matching and abnormal behavior analysis. The feature matching method (such as signature-based intrusion detection system IDS) relies on a known threat sample library and can accurately detect known malicious traffic, but its detection ability for new threats and variant attacks is limited. The abnormal behavior analysis method is based on statistical modeling or machine learning, and identifies unknown attacks by detecting patterns that deviate from normal behavior. However, when analyzing traffic behavior at the network level, attackers can bypass detection by using encrypted traffic, tunnel communication, traffic obfuscation, etc., reducing the effectiveness of traditional anomaly detection methods.
[0003] In recent years, security analysis methods based on the operating system level have gradually received attention. Compared with traditional detection methods based on network packets, traffic analysis at the operating system instruction level can directly monitor process behavior, system calls, and network interactions at the host level, thus providing a more fine-grained security monitoring ability. Currently, the Linux platform can use eBPF (Extended Berkeley Packet Filter) for kernel-level system call monitoring, while the Windows platform can use ETW (Event Tracing for Windows) for accurate event tracking. The introduction of these technologies provides strong support for real-time network traffic threat analysis at the host level. However, how to effectively utilize operating system instruction data, perform structured modeling on it, and combine it with large-scale network behavior analysis to achieve efficient and accurate threat detection is still the focus and difficulty of current research. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a method for analyzing network traffic threats based on the operating system instruction level, which solves the problem that how to effectively utilize operating system instruction data, perform structured modeling on it, and combine it with large-scale network behavior analysis to achieve efficient and accurate threat detection is still the focus and difficulty of current research.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a method for analyzing network traffic threats based on the operating system instruction level, which includes
[0008] Real-time monitoring of operating system instruction data, constructing a dynamic behavior matrix and generating an instruction-level traffic graph;
[0009] The operating system instruction data includes process management instructions, network communication instructions, file read and write instructions, and subscribed process events and network events;
[0010] Analyze the instruction-level traffic graph, calculate the first digit distribution of the instruction data and compare it with the expected distribution of Benford’s Law, calculate the deviation degree of the instruction behavior through statistical methods and generate an anomaly score, and combine the decision tree classification algorithm for risk classification to determine abnormal instructions;
[0011] Use a graph neural network for abnormal instruction classification, identify known attack behaviors and unknown abnormal behaviors, directly associate the abnormal instruction classification results, generate an attack path, and use Bayesian update to calculate the attack path risk score;
[0012] Based on the analysis results of the attack path, analyze high-risk IP / ports for intelligent traffic blocking and process isolation.
[0013] As a preferred solution of the method for analyzing network traffic threats based on the operating system instruction level of the present invention, wherein: the construction of the dynamic behavior matrix and the generation of the instruction-level traffic graph include:
[0014] Preprocess the collected instruction data, set the sliding window size W, and within the current window, construct a short-term behavior matrix Z;
[0015] Use the window average method to calculate the instruction execution frequency within the window, accumulate the data within the past n windows, construct a long-term behavior matrix, update the long-term behavior matrix X using the exponential decay method, and form a complete dynamic behavior feature matrix C by linearly weighting the short-term behavior matrix and the long-term behavior matrix;
[0016] Sort the instruction call order for each process in the dynamic behavior feature matrix C to form an instruction time series, and count the call frequency between different instructions to form instruction pairs;
[0017] Use the flow hashing method to map the instruction sequence into a fixed-length Sketch structure to form an instruction-level traffic hash matrix M, use an adjacency list to store the instruction call relationship, and calculate the out-degree D o and in-degree D a ;
[0018] Based on the out-degree D o and the in-degree D a Calculate the average call traffic weight F of the instructions;
[0019] Based on the instruction call relationship of the matrix M, generate instruction dependency paths to form a directed edge set;
[0020] Generate an instruction-level traffic graph based on the node set, the directed edge set, and the average call traffic weight.
[0021] As a preferred solution of the network traffic threat analysis method based on the operating system instruction level described in the present invention, wherein: using a graph neural network for abnormal instruction classification and identifying known attack behaviors and unknown abnormal behaviors includes:
[0022] Obtain the calculated instruction anomaly scores and risk behavior annotations, parse the instruction-level traffic graph, obtain the call relationship between instructions, establish an instruction call adjacency matrix, record the neighbor nodes of each instruction, and form an initial topological structure of the instruction call relationship;
[0023] Set a threshold Y. If the anomaly score of a neighbor node is greater than the threshold, it is a high-value neighbor; otherwise, it is a low-value neighbor. Calculate the high-value neighbor ratio E of each instruction;
[0024] Set a threshold y. If E is less than the threshold y, it indicates that the instruction lacks high-value association relationships and the adjacency structure needs to be further optimized. Generate new instructions based on Mixup, calculate the correlation between the newly generated instructions and the original instructions using cosine similarity, set a threshold T. If the correlation is greater than T, establish a new adjacency relationship. If the newly generated instructions pass the Markov chain check and similarity check, add them to the adjacency matrix;
[0025] Use MLP to calculate the edge classification scores, set a threshold o, filter out the edges with edge classification scores greater than the threshold o, and generate the final adjacency matrix by combining the screening results of the edge classifier and the adjacency matrix generated by Mixup;
[0026] Based on the final adjacency matrix, use the multi-head attention mechanism of the multi-head attention graph convolutional network to calculate the relationship between different instructions and the attention weights between each instruction node v and neighbor node h to obtain an optimized instruction feature vector;
[0027] Perform Dropout processing on the instruction feature vector to obtain an enhanced instruction feature vector;
[0028] Extract the execution time of each instruction from the instruction feature vector to form a time series of the instructions, use the LSTM model to calculate the time dependency of the instructions to obtain the time series features of the instructions, unify the dimensions of the instruction feature vector and the time series features through global pooling, and fuse the two features through a fully connected layer to construct the final fused instruction classification features;
[0029] Use a Softmax classifier to calculate the classification probability of attack behaviors and output the final classification results, including known attack behaviors and unknown attack behaviors.
[0030] As a preferred solution of the network traffic threat analysis method based on the operating system instruction level described in the present invention, wherein: the parsing of the instruction-level traffic graph, calculating the first-digit distribution of instruction data and comparing it with the expected distribution of Benford’s Law includes:
[0031] Based on the instruction-level traffic graph, extract the data points and call order of all instruction behaviors, calculate the instruction call frequency of each process, count the instruction call order, analyze the instruction execution sequence of the same process, and standardize the instruction call frequency data.
[0032] Traverse the standardized instruction call frequency data, for the call times of each instruction, extract the first digit, count the occurrence probability K of each first digit in all instruction call frequencies, calculate the theoretical expected probability K' according to Benford’s Law, and calculate the error between the actual distribution K and K'.
[0033] As a preferred solution of the network traffic threat analysis method based on the operating system instruction level described in the present invention, wherein: calculating the deviation degree of instruction behaviors by statistical methods and generating an anomaly score, and combining with a decision tree classification algorithm for risk classification to determine abnormal instructions includes:
[0034] Calculate the MAD, KS test, and KL divergence of all first digits. After normalizing the calculation results of MAD, KS test, and KL divergence, use a linear weighted method to calculate the comprehensive anomaly score.
[0035] Construct a classification decision tree, set input variables, target classification, and classification rules.
[0036] Traverse all abnormal instruction data points, apply the decision tree rules, and obtain the final classification results, including high risk, medium risk, and low risk.
[0037] As a preferred solution of the network traffic threat analysis method based on the operating system instruction level described in the present invention, wherein: directly associating the classification results of abnormal instructions to generate an attack path, and using Bayesian update to calculate the risk score of the attack path:
[0038] Form an instruction execution log based on the classification results of abnormal instructions.
[0039] Construct an attack chain graph, define the nodes and edges of the attack chain graph, determine the initial attack entry point, and use time series analysis to determine the time order of the attack chain.
[0040] Calculate the risk scores of each node in the attack chain through Bayesian update, set the prior probability of an attack occurring, and calculate the conditional probability of attack behaviors occurring in all path nodes within the attack chain;
[0041] Set the risk score R as the weighted sum of the attack chain paths, set a threshold J, and if the risk score exceeds the threshold J, mark it as a high-risk attack path.
[0042] As a preferred solution of the network traffic threat analysis method based on the operating system instruction level described in the present invention, wherein: based on the analysis results of the attack path, analyzing high-risk IP / ports for intelligent traffic blocking and process isolation includes:
[0043] Read the attack chain path and extract the network connection information of malicious instructions;
[0044] Define the risk weights of protocol types, and calculate the network connection threat score in the attack path through the access frequency of the target IP and the access frequency of the target port based on the weighted summation method. Set a threshold O. If the score is greater than the threshold O, block the target IP in real time, block high-risk ports, otherwise add it to the observation list;
[0045] Based on the attack chain path, extract the list of abnormal processes, downgrade the permissions of the identified malicious processes, and if the process is still active, execute forced termination;
[0046] Store the data collected and analyzed into the database.
[0047] As a preferred solution of the network traffic threat analysis method based on the operating system instruction level described in the present invention, wherein: storing the data collected and analyzed into the database means storing the collected instruction data, the instruction feature data generated by analysis, and the formulated defense measures into the database, performing regular backups on the stored data and setting user access permissions, and only allowing authorized users to access.
[0048] In a second aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and wherein: when the computer program is executed by the processor, it implements any step of the network traffic threat analysis method based on the operating system instruction level described in the first aspect of the present invention.
[0049] In a third aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and wherein: when the computer program is executed by the processor, it implements any step of the network traffic threat analysis method based on the operating system instruction level described in the first aspect of the present invention.
[0050] The beneficial effects of the present invention are as follows: The present invention combines eBPF and ETW for real-time instruction data capture, constructs a dynamic behavior feature matrix and an instruction-level traffic map, and performs threat detection and attack path analysis through technologies such as Benford's Law statistical analysis, decision tree classification algorithm, graph neural network, and Bayesian update. It can provide more accurate attack behavior recognition ability and identify the complete attack chain, realize more intelligent threat analysis, reduce false alarms, improve the detection accuracy, thereby accurately tracing the behavior trajectory of the attacker and providing stronger security protection ability. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0052] Figure 1 It is a flowchart of the network traffic threat analysis method based on the operating system instruction level in Embodiment 1. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0053] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific embodiments of the present invention with reference to the accompanying drawings of the specification.
[0054] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0055] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that excludes other embodiments.
[0056] Embodiment 1, referring to Figure 1 , which is the first embodiment of the present invention. This embodiment provides a network traffic threat analysis method based on the operating system instruction level, including the following steps:
[0057] S1. Real-time monitor the operating system instruction data, construct a dynamic behavior matrix, and generate an instruction-level traffic map;
[0058] Specifically, instruction-level data capture is performed through eBPF (Linux) + ETW (Windows). eBPF can run directly in the kernel, avoiding the impact on performance and security caused by traditional syscall hooking methods. ETW provides more accurate Windows event tracking capabilities, enabling efficient data collection and storage;
[0059] Load the eBPF program in the Linux kernel, monitor the system call table, and capture the following key instructions: process management instructions, network communication instructions, and file read / write instructions;
[0060] In Windows, subscribe to process events and network events through ETW to achieve the same monitoring capabilities;
[0061] When each instruction is executed, collect the following information: process ID, call time, call parameters, and return value;
[0062] Preprocess the collected instruction data, including data integrity verification and standardization. Convert the preprocessed data into behavior feature vectors and perform feature normalization;
[0063] Set the sliding window size W, for example: window size = 1000 instructions or 1-second interval. If the number of instructions inside the sliding window is less than 1000 → keep the current window unmoved. If the sliding window exceeds the threshold → slide backward, delete the earliest instructions. Inside the current window, construct the short-term behavior matrix Z. The rows of the matrix represent the behavior of an operating system instruction captured inside the current sliding window, that is, the process ID. Each column represents the feature information of this instruction, including instruction type, execution time, call parameters, and return value;
[0064] Use the window averaging method to calculate the instruction execution frequency inside the window, accumulate the data from the past n windows, construct the long-term behavior matrix, use the exponential decay method to update the long-term behavior matrix X, and synthesize the short-term behavior matrix and the long-term behavior matrix through the linear weighting method to form the complete dynamic behavior feature matrix C;
[0065] Sort the instruction call order for each process in the dynamic behavior feature matrix C to form an instruction time series, and count the call frequency between different instructions to form instruction pairs;
[0066] Use the stream hashing method to map the instruction sequence into a fixed-length Sketch structure to form the instruction-level traffic hash matrix M. The rows of the matrix represent an instruction call pair, for example: the i-th instruction calls the i+1-th instruction. The columns represent the hash index and call weight of the instruction;
[0067] Use an adjacency list to store the instruction call relationship and calculate the out-degree D of each instruction o and in-degree Da :
[0068]
[0069] Wherein, W(I i , I j ) is the weight of instruction I i calling instruction I j , indicating the frequency of directly executing I i after I j , W(I j , I i ) is the number of times (weight) of directly calling instruction I j , that is, the call relationship existing from I i to I j to I i ;
[0070]
[0071] Wherein, count(I i →I j ) is the number of times that instruction I i immediately calls instruction I j after execution, is the total number of times that instruction I i calls all subsequent instructions, count(I j ←I i ) is the number of times that instruction I j was directly called by instruction I i before, is the total number of calls of all possible pre-order instructions that can call I j , and k is all possible targets (subsequent instructions or pre-order instructions) of instruction calls;
[0072] Calculate the average call flow weight F of the instruction based on the out-degree D o and the in-degree D a :
[0073]
[0074] Extract the set of unique instructions from matrix M as the node set of the instruction-level flow graph, including extracting the hash index of all instructions and parsing the metadata of the instructions (instruction type, process ID, call parameters, and call time) and storing them as the node set;
[0075] Generate instruction dependency paths based on the instruction call relationships in matrix M to form a set of directed edges, including extracting all instruction pairs and parsing the instruction call relationships (starting instruction, ending instruction, and call frequency between instructions) and storing them as the set of directed edges;
[0076] Generate an instruction-level traffic graph based on a node set, a directed edge set, and an average call traffic weight.
[0077] By real-time monitoring of operating system instruction data, combined with the construction of a dynamic behavior matrix and the generation of an instruction-level traffic graph, more accurate and efficient network traffic threat analysis is achieved. First, eBPF (Linux) and ETW (Windows) are used for instruction-level data capture, avoiding the security and performance issues brought by traditional syscall hooking methods, and realizing low-interference and high-precision system call monitoring. Second, a dynamic behavior matrix is constructed. The short-term and long-term behavior patterns are maintained through a sliding window mechanism, and the exponential decay method is used to smooth historical data, ensuring that the system can accurately identify short-term abnormal fluctuations and long-term behavior trends, and effectively reducing false alarms. Further, the flow hash method is used to generate an instruction-level traffic hash matrix, which reduces storage and computational costs while ensuring the integrity of instruction call relationships. Finally, the instruction call relationships are stored in an adjacency list, the out-degree, in-degree, and average call traffic weight of instructions are calculated, and then an instruction-level traffic graph is generated to intuitively display the dependency relationships between instructions, forming a basis for complete attack chain analysis. Compared with traditional threat detection methods based on log or traffic analysis, the present invention can provide a finer-grained attack behavior recognition ability, accurately trace the attack path, and improve the real-time detection and defense response ability, effectively coping with advanced threats such as APT attacks, zero-day vulnerability exploitation, and ransomware propagation.
[0078] S2. Analyze the instruction-level traffic graph, calculate the first-digit distribution of instruction data and compare it with the expected distribution of Benford’s Law, calculate the deviation degree of instruction behavior through statistical methods and generate an anomaly score, and combine the decision tree classification algorithm for risk classification to determine abnormal instructions;
[0079] Specifically, analyzing the instruction-level traffic graph, calculating the first-digit distribution of instruction data and comparing it with the expected distribution of Benford’s Law includes:
[0080] Based on the instruction-level traffic graph, extract the data points and call order of all instruction behaviors, calculate the instruction call frequency of each process, count the instruction call order, analyze the instruction execution sequence of the same process, and standardize the instruction call frequency data;
[0081] Traverse the standardized instruction call frequency data, for the call times of each instruction, extract the first digit, count the occurrence probability K of each first digit in all instruction call frequencies, calculate the theoretical expected probability K’ according to Benford’s Law, and calculate the error between the actual distribution K and K’.
[0082] By parsing the instruction-level traffic graph and combining statistical analysis with Benford’s Law, accurate detection of process behavior is achieved. Compared with traditional security analysis methods based on network traffic or system logs, this method can capture system instruction behavior in real time and quantify the instruction call patterns of processes through dynamic behavior modeling. By calculating the distribution of the first digits of instruction call frequencies and comparing it with the expected distribution of Benford’s Law, abnormal processes such as malware execution, covert tunnel communication, and data leakage attacks can be effectively identified. In addition, combined with the sliding window mechanism, normalization processing, and error calculation, this method significantly improves the accuracy of anomaly detection, reduces the false alarm rate, and has higher real-time performance, intelligence level, and adaptability. It can be widely applied to network security protection scenarios such as advanced persistent threat (APT) detection, malware analysis, and abnormal behavior monitoring.
[0083] Furthermore, the deviation degree of instruction behavior is calculated by statistical methods and an anomaly score is generated. Combining with the decision tree classification algorithm for risk classification, the abnormal instructions are determined to include:
[0084] Calculate the MAD (Mean Absolute Deviation) of all first digits, KS test (Kolmogorov-Smirnov test), and KL divergence (Kullback-Leibler). After normalizing the calculation results of MAD, KS test, and KL divergence, use the linear weighted method to calculate the comprehensive anomaly score;
[0085] Construct a classification decision tree, set the input variables, including the comprehensive anomaly score, whether the process has external network communication, and whether the instruction belongs to a high-risk category (such as execve, sendto), and the target classification, including low risk, medium risk, and high risk;
[0086] Set the classification rules, including setting thresholds Q and q based on the Top-K selection method, and Q < q. If the comprehensive anomaly score is less than threshold Q and there is no external communication, it is a low risk. If the comprehensive anomaly score is greater than or equal to threshold Q and less than threshold q, and the process has external communication, it is a medium risk. If the comprehensive anomaly score is greater than or equal to threshold q and the process involves high-risk instructions, it is a high risk;
[0087] The decision logic is: Condition 1: The anomaly score evaluates the global anomaly degree. Condition 2: Whether the process involves external IP connections. Condition 3: Whether the instruction involves high-risk behaviors (such as execve);
[0088] Traverse all abnormal instruction data points, apply the decision tree rules, obtain the final classification results, mark high-risk behaviors, and monitor medium-risk behaviors.
[0089] Perform multi-level anomaly detection through MAD, KS test, and KL divergence to avoid false positives or false negatives that may be caused by a single indicator and improve the accuracy of detection. Normalization processing ensures that the scores of different statistical methods are on the same scale, avoiding affecting the reliability of anomaly score calculation due to different numerical ranges of different indicators. Linear weighted calculation synthesizes the anomaly score, enabling the score to reflect both the overall data deviation (MAD), detect local significant changes (KS test), and probability distribution anomalies (KL divergence), ensuring a more accurate comprehensive assessment of abnormal behaviors. Classify instruction behaviors through a decision tree model, which can be adaptively adjusted according to changes in the actual environment without the need to manually set complex detection rules, improving the flexibility and adaptability of detection. The classification rules consider anomaly scores, process network behaviors, and instruction high-risk levels, making the classification of high-risk instructions more accurate and effectively reducing the false positive rate. By setting classification rules (anomaly score thresholds Q / q, whether the process involves external network communication, and whether the instruction belongs to a high-risk category), the classification model becomes more interpretable and can be flexibly adjusted in actual deployment.
[0090] S3. Use a graph neural network for abnormal instruction classification, identify known attack behaviors and unknown abnormal behaviors, directly associate the classification results of abnormal instructions, generate attack paths, and use Bayesian update to calculate the risk scores of attack paths;
[0091] Specifically, using a graph neural network for abnormal instruction classification and identifying known attack behaviors and unknown abnormal behaviors includes:
[0092] Obtain the calculated instruction anomaly scores and risk behavior annotations, parse the instruction-level traffic graph, obtain the call relationships between instructions, establish an instruction call adjacency matrix, record the neighbor nodes of each instruction, and form the initial topological structure of the instruction call relationship;
[0093] Set a threshold Y based on the Z-Score statistical method. If the anomaly score of a neighbor node is greater than the threshold, it is a high-value neighbor; otherwise, it is a low-value neighbor. Calculate the high-value neighbor ratio E of each instruction based on the number of high-value neighbors divided by the sum of the number of high-value and low-value neighbors:
[0094] Set the threshold y based on quantiles. If E is less than the threshold y, it indicates that the instruction lacks high-value association relationships and the adjacency structure needs to be further optimized. Then, each instruction and its execution parameters are used as a text record, and the TF-IDF method is used to calculate the word frequency and inverse document frequency of the instruction, and a TF-IDF vector is generated for each instruction. The cosine similarity is used to calculate the similarity between the text vectors of two instructions. Based on the Gaussian mixture model, set the threshold U. If the similarity is greater than the threshold U, the two instructions are semantically similar. Calculate the difference in anomaly scores between the two instructions. Based on the IQR (interquartile range) method, set the threshold u. Only retain the instructions with semantic similarity greater than the threshold U and anomaly score difference less than the threshold u as new neighbors, and update the instruction-level traffic graph and the adjacency matrix;
[0095] Define the Mixup target dataset, use the high-value neighbors as Mixup candidate sample data, and set a random selection strategy. If instruction x 1 and x 2 have the same category (such as system call, file operation, or network communication), then Mixup is allowed. If instruction x 1 and x 2 are semantically unrelated (such as sendto() and open()), then no Mixup is performed to prevent the introduction of invalid samples. Use the Beta distribution to sample the mixing ratio s and generate a new instruction feature d;
[0096] Check the Mixup samples based on the instruction dependency relationship, calculate the distribution of the newly generated instruction d in the adjacency matrix. If d is connected to the high-value neighbors in the current instruction traffic graph, then the Mixup sample is valid. If d is only connected to the low-value neighbors, then discard the sample;
[0097] Use the Markov chain to calculate the state transition probability P' of the newly generated instruction. If P' is lower than the global average level, then the Mixup sample is invalid and not added to the training data;
[0098] Use the cosine similarity to calculate the correlation between the newly generated instruction and the original instructions. Based on the K-means clustering, set the threshold T. If the correlation is greater than T, then establish a new adjacency relationship. If the newly generated instruction passes the Markov chain check and the similarity check, then add it to the adjacency matrix;
[0099] Use the MLP to calculate the edge classification score, and based on the Otsu adaptive threshold segmentation method, set the threshold o. Screen out the edges with edge classification scores greater than the threshold o, and only retain the adjacency edges that simultaneously meet the anomaly score, semantic similarity, and edge classification score screening conditions;
[0100] Combine the screening results of the edge classifier and the adjacency matrix generated by Mixup to generate the final adjacency matrix;
[0101] Based on the final adjacency matrix, the multi-head attention mechanism of the multi-head attention graph convolutional network is used to calculate the relationships between different instructions and the attention weights between each instruction node v and its neighbor nodes h, obtaining an optimized instruction feature vector. LeakyReLU is used as the activation function to ensure the optimization of negative gradients and improve the model convergence speed;
[0102] The instruction feature vector is processed by Dropout to obtain an enhanced instruction feature vector;
[0103] The execution time of each instruction is extracted from the instruction feature vector to form a time series of instructions. The LSTM model is used to calculate the temporal dependencies of the instructions to obtain the time series features of the instructions. The dimensions of the instruction feature vector and the time series features are unified through global pooling, and the two features are fused through a fully connected layer to construct the final fused instruction classification features;
[0104] The Softmax classifier is used to calculate the classification probabilities of attack behaviors and output the final classification results, including known attack behaviors and unknown attack behaviors. Among them, the known attack behaviors are further subdivided into specific types, including data leakage, remote command execution, or lateral movement attacks, etc.
[0105] By constructing an instruction-level traffic graph, optimizing the adjacency matrix, performing Mixup data augmentation, using multi-head attention GCN, LSTM time series modeling, and a Softmax classifier, high-precision detection of known attack behaviors and identification of unknown abnormal behaviors are achieved, effectively solving the limitations of traditional methods in aspects such as incomplete parsing of attack paths, insufficient accuracy in classifying abnormal instructions, and weak adaptability to new types of attacks. First, the construction of the instruction-level traffic graph structures the dependency relationships between instructions, providing a data basis for subsequent analysis. The TF-IDF semantic analysis combined with cosine similarity optimizes the adjacency matrix, ensuring that the model can accurately depict the logical associations between instructions and improving the interpretability of instruction call patterns. On this basis, Mixup generates high-value instruction samples, calculates the state transition probability through a Markov chain, and screens out enhanced samples with reasonable execution sequences, enhancing the model's ability to identify unknown abnormal behaviors. Subsequently, the multi-head attention GCN calculates the instruction association weights, further refining the modeling of attack paths, making the tracing of complex attack patterns (such as APT attacks) more accurate. At the same time, LSTM time series analysis ensures that the model can capture the dynamic changes in attack behaviors and avoid false alarms caused by static detection. Finally, the Softmax classifier combined with the global pooling strategy accurately classifies the attack types on the basis of fusing instruction sequence information and structural features, realizing a complete detection process from data capture, relationship modeling, behavior enhancement, deep learning inference to attack classification. This enables the proposed solution to break through the limitations of traditional traffic analysis and feature matching methods, accurately identify known attacks while dynamically adapting to changes in new attack techniques, and effectively enhance network security defense capabilities.
[0106] Furthermore, directly associate the abnormal instruction classification results to generate an attack path, and use Bayesian update to calculate the attack path risk score:
[0107] Based on the abnormal instruction classification results, extract the process ID, call time, and instruction dependency relationships to form an instruction execution log;
[0108] Construct an attack chain graph, define the nodes of the attack chain graph as different attack stages (such as process creation, malicious code execution, remote communication), and the edges as the logical associations between attack steps (such as "execute code" → "connect to C&C server"). Determine the initial attack entry point, use time series analysis to determine the time order of the attack chain. If process G triggers the network behavior of process g within 10 ms, an attack propagation path is formed;
[0109] Calculate the risk scores of each node in the attack chain through Bayesian update, set the prior probability of an attack occurring, and calculate the conditional probability of an attack behavior occurring for all path nodes within the attack chain:
[0110]
[0111] Wherein, P(A|B) is the probability of a successful attack after observing the attack behavior B, P(B|A) is the probability of B occurring when A occurs, P(A) is the prior probability of the attack chain, and P(B) is the combined probability of all events in the attack chain occurring;
[0112] Set the risk score R as the weighted sum of the attack chain paths, set the threshold J based on the statistical distribution of the attack scores calculated from historical attack data. If the risk score exceeds the threshold J, it is marked as a high-risk attack path.
[0113] By directly utilizing the results of abnormal instruction classification, it avoids the long data collection and analysis processes in traditional methods, improves the detection efficiency, makes the generation of attack paths more real-time and dynamic, can quickly identify potential threats, and reduces the attack response time. Combining the instruction call relationships, it can accurately trace the malicious processes, identify hidden attack behaviors, improve the detection coverage rate. By recording the process ID, call time, and instruction dependency relationships, it can accurately restore the attacker's operation process, enhance the interpretability of attack analysis. Using high-precision timestamps, it can accurately locate the attacker's behavior sequence and avoid incorrect analysis caused by timing errors. By constructing an attack chain graph, it can visually display the attacker's action path, enabling security analysts to quickly understand the attack process. Adopting a directed graph structure, it can establish the time series dependency relationships of attack behaviors and improve the accuracy of attack recognition. By defining attack behaviors in stages (such as process creation, code execution, network communication, etc.), corresponding defense strategies can be formulated for different attack types. By analyzing process events in a short time window, it can quickly identify abnormal interaction behaviors between processes and improve the detection efficiency. Combining the analysis of the attack propagation path, it can identify the attacker's initial entry point (InitialAccess), thereby strengthening security protection targeted. Using the Bayesian update method, it can dynamically adjust the risk score of the attack path based on historical data and real-time monitoring results, improving the detection accuracy. Using a weighted scoring method, it can comprehensively evaluate the risk level of the attack path and improve the detection accuracy.
[0114] S4. Based on the analysis results of the attack path, analyze high-risk IP / ports for intelligent traffic blocking and process isolation;
[0115] Specifically, based on the analysis results of the attack path, analyzing high-risk IP / ports for intelligent traffic blocking and process isolation includes:
[0116] Read the attack chain path, extract the network connection information of malicious instructions, including the target IP address, target port number, transmission protocol type, and connection status;
[0117] Define the risk weights of protocol types. Calculate the threat score of network connections in the attack path based on the access frequency of the target IP and the access frequency of the target port using the weighted summation method. Set a threshold O through historical attack data. If the score is greater than the threshold O, block the target IP in real time and block high-risk ports; otherwise, add it to the observation list.
[0118] Based on the attack chain path, extract the list of abnormal processes, downgrade the permissions of the identified malicious processes to prevent them from obtaining higher permissions, and if the process is still active, execute forced termination.
[0119] Store the data generated by collection and analysis in the database.
[0120] Based on the analysis results of the attack path, achieve intelligent traffic blocking and process isolation of high-risk IP / ports, accurately identify the network communication behavior of attackers, dynamically evaluate the risk level of network connections, and quickly execute permission downgrading and forced termination of malicious processes based on the attack chain path. Compared with the security policy of traditional static rules, this method reduces the false alarm rate, improves the attack detection accuracy, realizes real-time and automated traffic blocking, and effectively prevents lateral movement attacks, malicious remote control, and persistent threats. At the same time, this method supports long-term data storage and attack traceability, can provide more accurate security guarantees for advanced threat detection (APT), zero-trust security architecture, and adaptive network defense, and enhances the overall network security defense ability.
[0121] Further, storing the data generated by collection and analysis in the database means storing the collected instruction data, the instruction feature data generated by analysis, and the formulated defense measures in the database, regularly backing up the stored data, and setting user access permissions to only allow authorized users to access.
[0122] Through the structured storage of the database, provide efficient data retrieval capabilities, support the security team to quickly query historical behavior data, and ensure data recoverability through regular backup + intelligent backup optimization to prevent data loss caused by attacks, misoperations, or hardware failures.
[0123] This embodiment also provides a computer device, applicable to the situation of the network traffic threat analysis method based on the operating system instruction level, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the network traffic threat analysis method based on the operating system instruction level proposed in the above embodiment.
[0124] The computer device can be a terminal, which includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0125] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method for analyzing network traffic threats based on the operating system instruction level proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM for short), Electrically Erasable Programmable Read-Only Memory (EEPROM for short), Erasable Programmable Read-Only Memory (EPROM for short), Programmable Read-Only Memory (PROM for short), Read-Only Memory (ROM for short), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0126] In summary, the present invention combines eBPF and ETW for real-time instruction data capture, constructs a dynamic behavior feature matrix and an instruction-level traffic map, and performs threat detection and attack path analysis through technologies such as Benford's Law statistical analysis, decision tree classification algorithm, graph neural network, and Bayesian update. It can provide more accurate attack behavior recognition capabilities and identify a complete attack chain, achieve more intelligent threat analysis, reduce false alarms, improve detection accuracy, thereby accurately tracing the behavior trajectory of the attacker and providing stronger security protection capabilities.
[0127] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A network traffic threat analysis method based on the operating system instruction level, characterized by: include, Monitor operating system instruction data in real time, build a dynamic behavior matrix and generate instruction-level flow graphs; The operating system instruction data includes process management instructions, network communication instructions, file read and write instructions, and subscription process events and network events; Analyze the instruction-level flow graph, calculate the first digit distribution of instruction data and compare it with the expected distribution of Benford's Law, calculate the degree of instruction behavior deviation through statistical methods and generate anomaly scores, combine the decision tree classification algorithm to perform risk classification, and identify abnormal instructions; Use graph neural networks to classify abnormal instructions, identify known attack behaviors and unknown abnormal behaviors, directly associate abnormal instruction classification results, generate attack paths, and use Bayesian updates to calculate attack path risk scores; Based on the analysis results of the attack path, high-risk IP / ports are analyzed for intelligent traffic blocking and process isolation.
2. The network traffic threat analysis method based on the operating system instruction level as claimed in claim 1 is characterized by: The constructing of the dynamic behavior matrix and generating the instruction-level flow graph comprises: Preprocess the collected instruction data, set the sliding window size W, and construct the short-term behavior matrix Z within the current window; Use the window average method to calculate the instruction execution frequency in the window, accumulate the data in the past n windows, build a long-term behavior matrix, use the exponential decay method to update the long-term behavior matrix X, and use the linear weighted method to combine the short-term behavior matrix and the long-term behavior matrix to form a complete dynamic behavior feature matrix C; Sort the instruction calling order of each process in the dynamic behavior feature matrix C to form an instruction time series, and count the calling frequencies between different instructions to form instruction pairs; Use the flow hash method to map the instruction sequence into a fixed-length Sketch structure to form an instruction-level flow hash matrix M. Use the adjacency table to store the instruction call relationship and calculate the out-degree D of each instruction. o and in-degree D a ; Based on out-degree D o and in-degree D a Calculate the average call traffic weight F of the instruction; Based on the instruction call relationship of the matrix M, the instruction dependency path is generated to form a directed edge set; Generate an instruction-level flow graph based on the node set, directed edge set and average call flow weight.
3. The network traffic threat analysis method based on the operating system instruction level as claimed in claim 2 is characterized by: The use of graph neural networks to classify abnormal instructions and identify known attack behaviors and unknown abnormal behaviors includes: Obtain the calculated instruction anomaly scores and risk behavior annotations, parse the instruction-level flow graph, obtain the call relationship between instructions, establish an instruction call adjacency matrix, record the neighbor nodes of each instruction, and form the initial topological structure of the instruction call relationship; Set a threshold Y. If the abnormality score of a neighbor node is greater than the threshold, it is a high-value neighbor. Otherwise, it is a low-value neighbor. Calculate the proportion of high-value neighbors E for each instruction. Set a threshold y. If E is less than the threshold y, it means that the instruction lacks a high-value association relationship and needs to further optimize the adjacency structure. Generate new instructions based on Mixup. Use cosine similarity to calculate the correlation between the newly generated instructions and the original instructions. Set a threshold T. If the correlation is greater than T, establish a new adjacency relationship. If the newly generated instruction passes the Markov chain check and similarity check, add it to the adjacency matrix. Use MLP to calculate the edge classification score, set the threshold o, filter out the edges whose edge classification scores are greater than the threshold o, and combine the screening results of the edge classifier and the adjacency matrix generated by Mixup to generate the final adjacency matrix; Based on the final adjacency matrix, the multi-head attention mechanism of the multi-head attention graph convolutional network is used to calculate the relationship between different instructions and the attention weight between each instruction node v and its neighbor node h to obtain the optimized instruction feature vector; Performing Dropout processing on the instruction feature vector to obtain an enhanced instruction feature vector; The execution time of each instruction is extracted from the instruction feature vector to form the time series of the instruction. The time dependency of the instruction is calculated using the LSTM model to obtain the time series features of the instruction. The dimensions of the instruction feature vector and the time series features are unified through global pooling, and the two features are fused through a fully connected layer to construct the final fused instruction classification features. Use the Softmax classifier to calculate the attack behavior classification probability and output the final classification results, including known attack behaviors and unknown attack behaviors.
4. The method for analyzing network traffic threats based on the operating system instruction level according to claim 3, characterized in that: The analysis of the instruction-level flow graph, calculation of the first digit distribution of instruction data and comparison with the expected distribution of Benford's Law include: Based on the instruction-level flow graph, extract the data points and call order of all instruction behaviors, calculate the instruction call frequency of each process, count the instruction call order, analyze the instruction execution sequence of the same process and standardize the instruction call frequency data; Traverse the standardized instruction call frequency data, extract the first digit of the number of calls for each instruction, count the occurrence probability K of each first digit in all instruction call frequencies, calculate the theoretical expected probability K' according to Benford's Law, and calculate the error between the actual distribution K and K'.
5. The method for analyzing network traffic threats based on the operating system instruction level according to claim 4, characterized in that: The method of calculating the deviation degree of instruction behavior by statistical methods and generating anomaly scores, combining the decision tree classification algorithm for risk classification, and determining abnormal instructions includes: Calculate the MAD, KS test, and KL divergence of all first digits. After normalizing the MAD, KS test, and KL divergence calculation results, use the linear weighted method to calculate the comprehensive anomaly score; Construct a classification decision tree, set input variables, target classification and classification rules; Traverse all abnormal instruction data points, apply decision tree rules, and obtain the final classification results, including high risk, medium risk, and low risk.
6. The method for analyzing network traffic threats based on the operating system instruction level as claimed in claim 5, characterized in that: The directly associated abnormal instruction classification results are used to generate an attack path, and the attack path risk score is calculated using Bayesian updating: Generating instruction execution logs based on abnormal instruction classification results; Construct an attack chain graph, define the nodes and edges of the attack chain graph, determine the initial attack entry point, and use time series analysis to determine the time sequence of the attack chain; The risk score of each node in the attack chain is calculated through Bayesian updating, the prior probability of the attack is set, and the conditional probability of the attack behavior occurring at all path nodes in the attack chain is calculated; Set the risk score R as the weighted sum of the attack chain paths, set the threshold J, and if the risk score exceeds the threshold J, it is marked as a high-risk attack path.
7. The method for analyzing network traffic threats based on the operating system instruction level according to claim 6, characterized in that: The analysis results based on the attack path and the analysis of high-risk IP / ports for intelligent traffic blocking and process isolation include: Read the attack chain path and extract the network connection information of malicious instructions; Define the risk weight of the protocol type, calculate the network connection threat score in the attack path based on the weighted sum method through the access frequency of the target IP and the access frequency of the target port, set the threshold O, and if the score is greater than the threshold O, block the target IP in real time and block the high-risk port, otherwise put it in the observation list; Based on the attack chain path, extract the abnormal process list, downgrade the permissions of the identified malicious process, and forcibly terminate it if the process is still active; The data collected and analyzed are stored in a database.
8. The method for analyzing network traffic threats based on the operating system instruction level according to claim 7, characterized in that: Storing the collected and analyzed data in a database refers to storing the collected instruction data, the instruction feature data generated by the analysis, and the formulated defense measures in the database, backing up the stored data regularly, and setting user access rights to allow only authorized users to access.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network traffic threat analysis method based on the operating system instruction level according to any one of claims 1 to 8 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network traffic threat analysis method based on the operating system instruction level according to any one of claims 1 to 8 are implemented.
Citation Information
Cited By
Network threat detection and blocking system based on multi-dimensional behavior analysis
CN120639524A
A network threat detection and blocking system based on multi-dimensional behavioral analysis
CN120639524B
Cooperative office network security management method and system based on artificial intelligence, and medium
CN120710768A
Power terminal bypass safety monitoring analysis method
CN120729654A
Terminal data transmission security management method and device and storage medium
CN120750659A