Computer network security detection system and method

Through the combination of data acquisition, multi-dimensional feature analysis and graph theory algorithms, real-time monitoring of network traffic and user behavior is solved, and the limitations of traditional network security detection systems in identifying and predicting attack paths are achieved, achieving more accurate security threat identification and rapid response.

CN120281505APending Publication Date: 2025-07-08GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510295495.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively deal with complex and diverse cyber attacks, especially in identifying attack paths and predicting the development of attack behaviors. Traditional methods lack multi-module collaboration and attack path deduction functions.

Method used

The data acquisition module is used to collect network traffic and user behavior data in real time, combine multi-dimensional feature analysis and anomaly detection algorithm, and use graph theory algorithm to build attack maps for path deduction, real-time monitoring and accurate identification of potential security threats.

Benefits of technology

It improves the accuracy and real-time nature of security threat identification, comprehensively predicts the development trend of attack behavior, enhances the intelligence and adaptive capabilities of network security detection, and optimizes attack path analysis and response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281505A_ABST
    Figure CN120281505A_ABST
Patent Text Reader

Abstract

The invention relates to a computer network security detection system and method. The system comprises a data acquisition module, a threat identification module and an attack path analysis module, the data acquisition module is used for collecting network traffic, log files and user behavior data from a target network in real time, and performing preliminary filtering and preprocessing on the data; the threat identification module is used for identifying potential security threats by adopting a multi-dimensional feature analysis and anomaly detection algorithm based on the data content provided by the data acquisition module; and the attack path analysis module performs modeling and analysis on possible attack paths by utilizing a graph theory algorithm based on the detection result of the threat identification module so as to predict the development trend of attack behaviors. The invention further provides a computer network security detection method, real-time monitoring, path analysis and response to network security threats are achieved through cooperative work of all the modules, and therefore the accuracy and effectiveness of network security protection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network security, and particularly to a computer network security detection system and method. Specifically, the present invention combines data collection, threat recognition, and attack path analysis organically, and uses multi-dimensional feature analysis, anomaly detection, and graph theory algorithms to monitor network traffic and user behavior in real time, so as to identify potential security threats and predict the development trend of attack behaviors, thereby effectively improving the security and protection level of computer networks. Background Art

[0002] With the rapid development of the Internet and information technology, computer networks have become the core carriers for information transmission and storage. However, network attack means have become increasingly complex and diverse, posing a huge challenge to network security. Traditional network security protection measures mainly rely on firewalls, intrusion detection systems, and intrusion prevention systems, etc. However, these means usually detect based on known threat features or rule bases, and it is difficult to effectively cope with new attacks and advanced persistent threats that are constantly mutating. In addition, traditional methods have limitations in identifying attack paths and predicting the development of attack behaviors, and it is difficult to comprehensively understand the attacker's action trajectories and strategies.

[0003] In the prior art, although security detection systems based on artificial intelligence and big data analysis have emerged, most systems are limited to the analysis of a single module, such as traffic detection or behavior anomaly recognition, and lack multi-module collaboration and attack path deduction functions. Therefore, there is an urgent need for a network security detection system and method that can comprehensively perform multi-dimensional feature analysis, anomaly detection, and attack path analysis, so as to more accurately identify security threats, predict attack paths, and respond in a timely manner, thereby effectively improving network security and protection capabilities.

[0004] To solve the above problems, the present invention proposes a computer network security detection system and method, which adopts the collaborative work of data collection, threat recognition, and attack path analysis modules, and combines multi-dimensional feature analysis, anomaly detection algorithms, and graph theory models, aiming to perform real-time monitoring, path deduction, and response to potential security threats, and provide a more comprehensive and accurate network security protection solution. Summary of the Invention

[0005] To achieve the above invention objectives, the present invention provides the following technical solutions: A computer network security detection system and method, the computer network security detection system includes the following modules:

[0006] A data collection module, which is used to collect network traffic, log files, and user behavior data from the target network in real time, and perform preliminary filtering and preprocessing on the data;

[0007] The threat recognition module, based on the data content provided by the data collection module, uses multi-dimensional feature analysis and anomaly detection algorithms to identify potential security threats;

[0008] The attack path analysis module, based on the detection results of the threat recognition module, uses graph theory algorithms to model and analyze the attack path to predict the development trend of attack behaviors.

[0009] Furthermore, the data collection module consists of a data filtering unit and a data preprocessing unit:

[0010] The data filtering unit is used to filter the collected data according to preset rules, eliminating redundant and irrelevant data. The preset rules include conditions such as IP address, port number, protocol type, and timestamp;

[0011] The data preprocessing unit is used to normalize and denoise the filtered data, specifically including:

[0012] The format conversion sub-unit is used to uniformly convert multi-source heterogeneous data into a standardized format for subsequent analysis;

[0013] The data cleaning sub-unit is used to handle duplicate, missing, and outlier values in the data;

[0014] The feature extraction sub-unit is used to extract multi-dimensional features from the preprocessed data, including time series features, traffic statistical features, and behavior pattern features.

[0015] Furthermore, the threat recognition module consists of a feature extraction unit and an anomaly detection unit:

[0016] The feature extraction unit is used to perform multi-dimensional feature extraction on the data provided by the data collection module, specifically including:

[0017] The time series feature extraction sub-unit is used to perform time series analysis on network traffic and behavior data to obtain the time correlation and periodicity of the data;

[0018] The traffic statistical feature extraction sub-unit is used to statistically analyze the traffic distribution of different protocol types, source IPs, and destination IPs;

[0019] The behavior pattern feature extraction sub-unit is used to analyze user operation behaviors and extract behavior sequence features.

[0020] The anomaly detection unit uses an anomaly detection algorithm based on an improved deep autoencoder, specifically including:

[0021] The data encoding sub-unit is used to perform non-linear encoding on the input features to obtain a low-dimensional representation;

[0022] A data decoding subunit for reconstructing the original input data from a low-dimensional representation;

[0023] A reconstruction error calculation subunit for calculating the error between the reconstructed data and the original data and determining whether there is an anomaly by setting a threshold. The loss function of the reconstruction error is defined as:

[0024]

[0025] where N represents the number of samples of the input data, obtained by counting the total number of preprocessed data in the data acquisition module, X i represents the i-th input data sample, obtained through the data acquisition module, W1 and W2 respectively represent the weight matrices of the encoder and the decoder, with initial values of 0.01, b1 and b2 respectively represent the bias terms of the encoder and the decoder, with initial values of 0, and W1·X i represents the feature mapping of the input data. Each row of W1 corresponds to an encoder neuron, which performs a weighted sum of the weight combinations of the input features. W2·(W1·X i +b1) is the linear transformation of the decoder part, representing the weighted sum of the encoded low-dimensional features and adding the bias term. Among them, the calculation methods of the weight matrices W1, W2 and the bias terms b1, b2 are as follows:

[0026] First, calculate the error of the data sample to obtain L1:

[0027]

[0028] where N represents the number of samples of the input data, X i represents the i-th input data sample, X i-1 represents the (i - 1)-th input data sample. When i = 1, X i-1 = 0;

[0029] According to L1, the results of the weight matrices W1, W2 and the bias terms b1, b2 can be obtained:

[0030]

[0031]

[0032] where, represents the first-order partial derivative of L1 with respect to the weight matrix W1, represents the first-order partial derivative of L1 with respect to the weight matrix W2, represents the first-order partial derivative of L1 with respect to the bias term b1, represents the first-order partial derivative of L1 with respect to the bias term b2.

[0033] Furthermore, the attack path analysis module consists of an attack graph construction unit and a path deduction unit:

[0034] The attack graph construction unit is used to construct an attack graph based on the detection results of the threat identification module and the graph theory model. The attack graph includes nodes and edges, where:

[0035] Nodes represent assets, devices, and services in the network;

[0036] Edges represent actions taken by attackers between nodes;

[0037] The path deduction unit adopts an algorithm based on depth-first search to deduce the paths and steps taken by attackers, including:

[0038] The attack chain construction subunit is used to concatenate attack behaviors into an attack chain according to attack steps and dependencies;

[0039] The path search subunit is used to search for all paths from the initial node to the target node in the attack graph;

[0040] The attack step simulation subunit is used to sequentially simulate attack steps according to the path order to deduce the development process of attack behaviors.

[0041] The present invention also provides a computer network security detection method, and the method includes the following steps:

[0042] Step 1: Through the data collection module, real-time collect network traffic, log files, and user behavior data from the target network, and perform preliminary filtering and preprocessing on the data;

[0043] Step 2: Through the threat identification module, based on the data content provided by the data collection module, adopt multi-dimensional feature analysis and anomaly detection algorithms to identify potential security threats;

[0044] Step 3: Through the attack path analysis module, based on the detection results of the threat identification module, use graph theory algorithms to model and analyze the attack path;

[0045] Step 4: Push the analysis results to the protection system for execution to complete security detection and response.

[0046] Compared with the prior art, the beneficial effects of the present invention:

[0047] 1. Improve the accuracy and real-time performance of security threat identification: Through the real-time collection and preprocessing of network traffic, log files, and user behavior data by the data collection module, and combined with multi-dimensional feature analysis and anomaly detection algorithms based on an improved deep autoencoder in the threat identification module, efficient identification of potential security threats is achieved, effectively reducing the false alarm and missed alarm rates.

[0048] 2. Comprehensively predict the development trend of attack behavior: The attack path analysis module in the present invention uses graph theory algorithms to construct an attack graph and deduce the attack path through depth-first search. It can accurately predict the paths and steps that the attacker may take, thereby predicting the development trend of security threats in advance and providing a basis for the rapid response of the protection system.

[0049] 3. Enhance the intelligence and adaptability of network security detection: By introducing multi-dimensional feature extraction and anomaly detection mechanism based on deep autoencoders, the present invention has the ability to adaptively detect diversified threat features in complex network environments, effectively improving the system's defense level when facing advanced persistent threats.

[0050] 4. Optimize attack path analysis and response efficiency: Through the attack graph construction and path deduction algorithm in the attack path analysis module, the present invention can quickly build an attack chain and simulate attack steps, greatly improving the tracing and analysis efficiency of the attack chain, reducing the time for security incident response, and improving the overall network protection capability. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 A schematic diagram of the system modules provided for this application;

[0052] Figure 2 A schematic diagram of the method steps provided in this application. DETAILED DESCRIPTION

[0053] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0054] refer to Figure 1 , an embodiment of the present invention provides a computer network security detection system, wherein:

[0055] The data collection module collects network traffic, log files, and user behavior data in real time through probe devices deployed in the target network. First, the data filtering unit filters the collected data according to preset rules, eliminating redundant and irrelevant data whose IP addresses, port numbers, protocol types, timestamps, etc. do not meet the requirements, so as to reduce the load of subsequent processing. Subsequently, the data preprocessing unit normalizes and denoises the filtered data. Among them, the format conversion subunit uniformly converts heterogeneous data from different sources into JSON format to achieve data format consistency. The data cleaning subunit removes duplicate records and fills in missing or abnormal values using interpolation methods. Finally, the feature extraction subunit extracts time series features, traffic statistical features, and behavior pattern features from the preprocessed data, such as the duration of TCP connections, request-response delays, user operation behavior sequences, etc., providing multi-dimensional feature inputs for the anomaly detection algorithm of the subsequent threat identification module.

[0056] The threat identification module performs multi-dimensional feature extraction on the preprocessed data provided by the data collection module. First, the feature extraction unit performs time series analysis on network traffic and user behavior data through the time series feature extraction subunit to obtain the time correlation and periodicity of the data, such as the HTTP request interval and traffic fluctuation pattern; the traffic statistical feature extraction subunit then counts the traffic distribution of different protocol types, source IPs, and destination IPs to identify abnormal traffic patterns; the behavior pattern feature extraction subunit further analyzes user operation behaviors and extracts behavior sequence features, such as the operation order of user login, download, and request. Subsequently, the anomaly detection unit uses an algorithm based on an improved deep autoencoder to detect the extracted multi-dimensional features. Specifically, the data encoding subunit non-linearly encodes the input features to obtain a low-dimensional representation, and then the data decoding subunit reconstructs the low-dimensional representation. The reconstruction error calculation subunit judges whether there is an anomaly by calculating the error between the reconstructed data and the original input data and combining the loss function. Once the reconstruction error exceeds the set threshold, it is determined that the data sample has a potential network threat and a security alarm is triggered, thereby effectively improving the accuracy and real-time performance of network security detection. Among them, the loss function is:

[0057]

[0058] where N represents the number of samples of the input data, obtained by counting the total number of preprocessed data in the data collection module, X i represents the i-th input data sample, obtained through the data collection module, W1 and W2 respectively represent the weight matrices of the encoder and decoder, with initial values of 0.01, b1 and b2 respectively represent the bias terms of the encoder and decoder, with initial values of 0, W1·X iRepresents feature mapping of the input data, where each row of W1 corresponds to an encoder neuron that performs a weighted sum of the weight combinations of the input features, and W2·(W1·X i +b1) is the linear transformation of the decoder part, representing a weighted sum of the encoded low-dimensional features and adding a bias term. Among them, the calculation methods of the weight matrices W1, W2 and the bias terms b1, b2 are as follows:

[0059] First, calculate the error of the data sample:

[0060]

[0061] Among them, N represents the number of samples of the input data, X i represents the i-th input data sample, X i-1 represents the (i - 1)-th input data sample. When i = 1, X i-1 = 0;

[0062] According to L1, the results of the weight matrices W1, W2 and the bias terms b1, b2 can be obtained:

[0063]

[0064] Among them, represents the first-order partial derivative of L1 with respect to the weight matrix W1, represents the first-order partial derivative of L1 with respect to the weight matrix W2, represents the first-order partial derivative of L1 with respect to the bias term b1, represents the first-order partial derivative of L1 with respect to the bias term b2.

[0065] Based on the detection results of the threat recognition module, the attack path analysis module conducts deduction and analysis on potential attack paths. First, the attack graph construction unit constructs an attack graph based on the graph theory model, where nodes represent assets, devices or services in the network, such as servers, databases and user terminals; edges represent actions or paths that an attacker may take, such as privilege escalation, lateral movement and data theft. Subsequently, the path deduction unit uses an algorithm based on depth-first search to deduce the paths and steps that an attacker may take. Specifically, the attack chain construction subunit strings attack behaviors into attack chains according to attack steps and dependencies, such as "phishing email → user credential leakage → remote login → data theft"; the path search subunit searches all possible paths from the initial node (such as a user terminal) to the target node (such as a core database) in the attack graph; the attack step simulation subunit then simulates the development process of attack steps in sequence according to the path order, deduces the possible consequences and impacts of attack behaviors, and finally generates a detailed attack path report for security management personnel to refer to, thereby effectively improving the early warning ability and response speed of network security detection.

[0066] Reference Figure 2 In addition, an embodiment of the present invention further provides a computer network security detection method, and the method includes the following steps:

[0067] Step 1: Through a data collection module, collect network traffic, log files, and user behavior data from a target network in real time, and perform preliminary filtering and preprocessing on the data;

[0068] Step 2: Through a threat identification module, based on the data content provided by the data collection module, use multi-dimensional feature analysis and anomaly detection algorithms to identify potential security threats;

[0069] Step 3: Through an attack path analysis module, based on the detection results of the threat identification module, use graph theory algorithms to model and analyze the attack path;

[0070] Step 4: Push the analysis results to a protection system for execution to complete security detection and response.

[0071] It should be noted that, without conflict, the embodiments and the features and technical solutions in the embodiments of the present invention can be combined with each other.

[0072] Obviously, the above-described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosed content of the present invention more thorough and comprehensive. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements on some of the technical features. Any equivalent structure directly or indirectly using the content of the specification and drawings of the present invention in other related technical fields is similarly within the scope of the patent protection of the present invention.

Claims

1. A computer network security detection system, characterized in that, It includes the following modules: The data acquisition module is used to collect network traffic, log files, and user behavior data from the target network in real time, and perform preliminary filtering and preprocessing on the data; The threat identification module, based on the data content provided by the data acquisition module, uses multi-dimensional feature analysis and anomaly detection algorithms to identify potential security threats; The attack path analysis module, based on the detection results of the threat identification module, uses graph theory algorithms to model and analyze the attack path to predict the development trend of attack behaviors.

2. The computer network security detection system according to claim 1, characterized in that, The data acquisition module includes: The data filtering unit is used to filter the collected data according to preset rules, eliminating redundant and irrelevant data. The preset rules include conditions such as IP address, port number, protocol type, and timestamp; The data preprocessing unit is used to perform normalization and denoising processing on the filtered data, specifically including: The format conversion sub-unit is used to uniformly convert multi-source heterogeneous data into a standardized format for subsequent analysis; The data cleaning sub-unit is used to process duplicate, missing, and outlier values in the data; The feature extraction sub-unit is used to extract multi-dimensional features from the preprocessed data, including time series features, traffic statistics features, and behavior pattern features.

3. A computer network security detection system according to claim 1, characterized in that, The threat identification module includes: The feature extraction unit is used to perform multi-dimensional feature extraction on the data provided by the data acquisition module, specifically including: The time series feature extraction sub-unit is used to perform time series analysis on network traffic and behavior data to obtain the time correlation and periodicity of the data; The traffic statistics feature extraction sub-unit is used to count the traffic distribution of different protocol types, source IPs, and destination IPs; The behavior pattern feature extraction sub-unit is used to analyze user operation behaviors and extract behavior sequence features. The anomaly detection unit uses an anomaly detection algorithm based on an improved deep autoencoder, specifically including: The data encoding sub-unit is used to perform non-linear encoding on the input features to obtain a low-dimensional representation; The data decoding sub-unit is used to reconstruct the original input data from the low-dimensional representation; The reconstruction error calculation sub-unit is used to calculate the error between the reconstructed data and the original data, and determine whether there is an anomaly by setting a threshold. The loss function of the reconstruction error is defined as: Among them, N represents the number of samples of the input data, which is obtained by counting the total number of preprocessed data in the data acquisition module, and X i represents the i-th input data sample, which is obtained through the data acquisition module. W1 and W2 respectively represent the weight matrices of the encoder and the decoder, and their initial values are both 0.

01. b1 and b2 respectively represent the bias terms of the encoder and the decoder, and their initial values are both 0. W1·X i represents the feature mapping of the input data. Each row of W1 corresponds to an encoder neuron, and this neuron performs a weighted sum of the weight combinations of the input features. W2·(W1·X i +b1) is the linear transformation of the decoder part, which represents the weighted sum of the encoded low-dimensional features and adding the bias term. Among them, the calculation methods of the weight matrices W1, W2 and the bias terms b1, b2 are as follows: First, calculate the error of the data sample: Among them, N represents the number of samples of the input data, and X i represents the i-th input data sample, and X i-1 represents the (i - 1)-th input data sample. When i = 1, X i-1 = 0; According to L1, the results of the weight matrices W1, W2 and the bias terms b1, b2 can be obtained: Among them, represents the first-order partial derivative of L1 with respect to the weight matrix W1, represents the first-order partial derivative of L1 with respect to the weight matrix W2, represents the first-order partial derivative of L1 with respect to the bias term b1, represents the first-order partial derivative of L1 with respect to the bias term b2.

4. A computer network security detection system according to claim 1, characterized in that, The attack path analysis module includes: The attack graph construction unit is used to construct an attack graph based on the detection results of the threat identification module and based on a graph theory model. The attack graph contains nodes and edges, where: The nodes represent assets, devices, and services in the network; The edges represent the actions taken by the attacker between the nodes; The path deduction unit uses an algorithm based on depth-first search to deduce the possible paths and steps that the attacker may take, including: The attack chain construction sub-unit is used to concatenate attack behaviors into an attack chain according to the attack steps and dependencies; The path search sub-unit is used to search for all paths from the initial node to the target node in the attack graph; The attack step simulation sub-unit is used to sequentially simulate the attack steps according to the path order to deduce the development process of the attack behavior.

5. A computer network security detection method, characterized in that, It includes the following steps: S1. Through the data collection module, collect network traffic, log files, and user behavior data from the target network in real time, and perform preliminary filtering and preprocessing on the data; S2. Through the threat identification module, based on the data content provided by the data collection module, use multi-dimensional feature analysis and anomaly detection algorithms to identify potential security threats; S3. Through the attack path analysis module, based on the detection results of the threat identification module, use graph theory algorithms to model and analyze the attack path; S4. Push the analysis results to the protection system for execution to complete security detection and response.

Citation Information

Cited By

  • Data analysis management method and system based on ocean network security

    CN120602232A

  • Heterogeneous atlas-based network attack path prediction method and device, and medium

    CN120785667A

  • Network security vulnerability detection method and system based on artificial intelligence

    CN121283772A

  • An artificial intelligence-based network security vulnerability detection method and system

    CN121283772B