Network security protection method and system

Through the neural network model, the risk assessment and differentiated management of server open ports is solved, and the performance bottlenecks and resource waste problems of traditional network security protection technology are achieved, and efficient network security protection is achieved.

CN120342712AInactive Publication Date: 2025-07-18JIANGSU ZHOUQI DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510535390.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional network security protection technology has obvious performance bottlenecks when facing high throughput and low latency requirements, and cannot effectively deal with multiple network attacks, resulting in increased resource waste and monitoring overhead.

Method used

By obtaining characteristic data of the server's open port, using neural network models to determine the risk level, dividing the ports into high-risk and low-risk groups, and performing differentiated management, dynamically adjusting the monitoring frequency to optimize resource allocation.

Benefits of technology

While ensuring security, unnecessary monitoring overhead is reduced and the efficiency and accuracy of network security protection is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342712A_ABST
    Figure CN120342712A_ABST
Patent Text Reader

Abstract

The invention provides a network security protection method and system, and belongs to the technical field of network security, and the method comprises the steps: firstly, obtaining all open ports of a server, obtaining feature data of each open port, the feature data comprising a port number, a protocol, a service name and a corresponding process, and then, carrying out the protection of all the open ports; the risk level of the open ports is determined through a neural network based on the feature data of each open port, the open ports are divided into a first group and a second group based on the risk levels, the risk levels of the open ports belonging to the first group are higher than the risk levels of the open ports belonging to the second group, and finally, the risk levels of the open ports belonging to the second group are lower than the risk levels of the open ports belonging to the second group. And performing differentiated management on the open ports belonging to the first group and the open ports belonging to the second group. According to the network security protection system provided by the embodiment of the invention and the network security protection method provided by the embodiment of the invention, the security is ensured, the resource allocation is optimized, and the unnecessary monitoring overhead is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular, to a network security protection method and system. Background Art

[0002] With the rapid development of information technology, the Internet has penetrated into all fields of social life and has become an indispensable infrastructure in modern society. However, the popularization and complexity of the network have also brought increasingly serious network security problems. Network attack means have been continuously upgraded, from early viruses and Trojans to current distributed denial of service attacks (DDoS), advanced persistent threats (APT), ransomware, zero-day vulnerability exploitation, etc. The targets of attackers have also expanded from individual users to enterprises, government agencies, and even critical infrastructures. Network security threats not only lead to data leakage and property losses, but may also endanger national security and social stability.

[0003] Traditional network security protection technologies mainly include firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and antivirus software, etc. These technologies can resist known network threats to a certain extent, but there are also obvious limitations. With the rapid growth of network traffic, traditional security devices may become performance bottlenecks and cannot meet the requirements of high throughput and low latency. In the process of dealing with different network attacks, real-time monitoring requires a large amount of monitoring resources. Summary of the Invention

[0004] Embodiments of this application provide a network security protection method and system to improve the above problems.

[0005] To achieve the above object, this application adopts the following technical solutions:

[0006] In a first aspect, embodiments of this application propose a network security protection method, the method includes:

[0007] Obtain all open ports of the server, and obtain the characteristic data of each open port, where the characteristic data includes the port number, protocol, service name, and the corresponding process;

[0008] Determine the risk level of the open port based on the characteristic data of each open port, and divide multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group;

[0009] Differentially manage the open ports belonging to the first group and the open ports belonging to the second group.

[0010] In combination with the first aspect, in some feasible embodiments, the risk level of an open port is determined based on the characteristic data of each open port, and multiple open ports are divided into a first group and a second group based on the risk level. Among them, the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group, including:

[0011] Obtain historical risk data, and obtain a risk prediction model based on the historical risk data. Among them, the historical risk data includes the characteristic data corresponding to the open port when a risk situation occurs;

[0012] Import the characteristic data corresponding to each open port into the risk prediction model, and obtain the risk level corresponding to the open port based on the result output by the risk prediction model.

[0013] In combination with the first aspect, in some feasible embodiments, obtain historical risk data, and obtain a risk prediction model based on the historical risk data. Among them, the historical risk data includes the characteristic data corresponding to the open port when a risk situation occurs, including:

[0014] Generate a training set based on the historical risk data. Among them, the training set includes the risk level corresponding to each occurrence of a risk situation and the characteristic data of the corresponding open port;

[0015] Input the characteristic data into a neural network model and perform iterative calculations. Among them, the port number, protocol, service name, and the corresponding process are used as four different dimensions, and the four dimensions form a characteristic vector of the risk level;

[0016] When the iterative calculation process meets the preset conditions, stop the calculation and output the trained neural network model.

[0017] In combination with the first aspect, in some feasible embodiments, when the iterative calculation process meets the preset conditions, stop the calculation and output the trained neural network model, including:

[0018] Set a loss function, obtain the error value in each iteration process based on the loss function, and compare the error value with a preset threshold. If the error value is less than the preset threshold, stop the iterative calculation and output the trained neural network model.

[0019] In combination with the first aspect, in some feasible embodiments, the risk level of an open port is determined based on the characteristic data of each open port, and multiple open ports are divided into a first group and a second group based on the risk level. Among them, the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group, including:

[0020] Input the feature data corresponding to the open ports into a pre-trained neural network model, and determine the risk level of the open ports according to the output result of the neural network model. Among them, in the first monitoring period, the monitoring frequency of the open ports belonging to the first group and the second group is the target frequency.

[0021] Combined with the first aspect, in some feasible embodiments, differential management is performed on the open ports belonging to the first group and the open ports belonging to the second group, including:

[0022] If the open port belongs to the first group, increase the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0023] Combined with the first aspect, in some feasible embodiments, if the open port belongs to the second group, decrease the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0024] A network security protection method proposed in an embodiment of the present application. First, obtain all open ports of the server, and obtain the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process. Then, determine the risk level of the open port through a neural network based on the feature data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level. Among them, the risk level of the open port belonging to the first group is higher than the risk level of the open port belonging to the second group. Finally, differential management is performed on the open ports belonging to the first group and the open ports belonging to the second group. A network security protection method proposed in an embodiment of the present application, a network security protection method proposed in an embodiment of the present application. While ensuring security, optimize resource allocation and reduce unnecessary monitoring overhead.

[0025] In a second aspect, an embodiment of the present application proposes a network security protection system, which is configured to include:

[0026] Obtain all open ports of the server, and obtain the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process;

[0027] Determine the risk level of the open port based on the feature data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level. Among them, the risk level of the open port belonging to the first group is higher than the risk level of the open port belonging to the second group;

[0028] Perform differential management on the open ports belonging to the first group and the open ports belonging to the second group.

[0029] In combination with the second aspect, in some feasible embodiments, the system is configured to: determine the risk level of each open port based on the feature data of the open port, and divide multiple open ports into a first group and a second group based on the risk level, wherein the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group, including:

[0030] Obtain historical risk data, and obtain a risk prediction model based on the historical risk data, wherein the historical risk data includes the feature data corresponding to the open port when a risk situation occurs;

[0031] Import the feature data corresponding to each open port into the risk prediction model, and obtain the risk level corresponding to the open port based on the result output by the risk prediction model.

[0032] In combination with the second aspect, in some feasible embodiments, the system is configured to: obtain historical risk data, and obtain a risk prediction model based on the historical risk data, wherein the historical risk data includes the feature data corresponding to the open port when a risk situation occurs, including:

[0033] Generate a training set based on the historical risk data, wherein the training set includes the corresponding risk level and the feature data of the corresponding open port each time a risk situation occurs;

[0034] Input the feature data into a neural network model and perform iterative calculations, wherein the port number, protocol, service name, and the corresponding process are used as four different dimensions, and the four dimensions constitute a feature vector of the risk level;

[0035] When the process of iterative calculation meets a preset condition, stop the calculation and output the trained neural network model.

[0036] In combination with the second aspect, in some feasible embodiments, the system is configured to: when the process of iterative calculation meets a preset condition, stop the calculation and output the trained neural network model, including:

[0037] Set a loss function, obtain the error value in each iteration process based on the loss function, and compare the error value with a preset threshold. If the error value is less than the preset threshold, stop the iterative calculation and output the trained neural network model.

[0038] In combination with the second aspect, in some feasible embodiments, the system is configured to: determine the risk level of each open port based on the feature data of the open port, and divide multiple open ports into a first group and a second group based on the risk level, wherein the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group, including:

[0039] Input the feature data corresponding to the open ports into the trained neural network model, and determine the risk level of the open ports according to the output results of the neural network model. Among them, in the first monitoring period, the monitoring frequency of the open ports belonging to the first group and the second group is the target frequency.

[0040] Combined with the second aspect, in some feasible implementation manners, the system is configured to: perform differential management on the open ports belonging to the first group and the open ports belonging to the second group, including:

[0041] If the open port belongs to the first group, increase the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0042] Combined with the second aspect, in some feasible implementation manners, the system is configured to: if the open port belongs to the second group, reduce the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0043] A third aspect of the embodiments of the present invention provides an electronic device, which includes:

[0044] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method proposed in the first aspect of the embodiments of the present invention.

[0045] A fourth aspect of the embodiments of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method proposed in the first aspect of the embodiments of the present invention.

[0046] A network security protection system proposed in the embodiments of the present application, first, obtains all open ports of the server, and obtains the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process. Then, based on the feature data of each open port, the risk level of the open port is determined through a neural network, and multiple open ports are divided into a first group and a second group based on the risk level. Among them, the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group. Finally, differential management is performed on the open ports belonging to the first group and the open ports belonging to the second group. A network security protection system proposed in the embodiments of the present application, a network security protection method proposed in the embodiments of the present application, while ensuring security, optimizes resource allocation and reduces unnecessary monitoring overhead. Description of the Drawings

[0047] Figure 1Schematic diagram of a network security protection method proposed in an embodiment of this application. Detailed implementation manners

[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0049] An embodiment of this application proposes a network security protection method. Please refer to Figure 1 , and the method includes the following steps:

[0050] S101: Obtain all open ports of the server and obtain the characteristic data of each open port. The characteristic data includes the port number, protocol, service name, and the corresponding process.

[0051] It can be understood that in this embodiment, a network scanning tool is used to obtain the open ports to obtain the characteristic data of each open port. Exemplarily, a network scanning tool (such as nmap) is used to scan the open ports of the server. nmap is a powerful network scanning tool that can detect information such as open ports, protocols, and service names.

[0052] nmap -sV -p- <server IP address>

[0053] Among them, -sV: Detect service version information.

[0054] -p-: Scan all ports (1 - 65535).

[0055] The output of nmap will list all open ports, protocols, service names, and version information. For example:

[0056] PORT STATE SERVICE VERSION

[0057] 22 / tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)

[0058] 80 / tcp open http Apache httpd 2.4.29 ((Ubuntu))

[0059] 443 / tcp open ssl / http Apache httpd 2.4.29 ((Ubuntu))

[0060] Exemplarily, to obtain the process information corresponding to each open port, the netstat or ss command can be used in combination with the lsof or fuser command.

[0061] Of course, in some other embodiments, an automated script can also be set up:

[0062] Exemplarily,

[0063]

[0064]

[0065] Through the above steps, you can obtain the characteristic data of all open ports on the server, including the port number, protocol, service name, and the corresponding process information.

[0066] S102: Determine the risk level of each open port based on the characteristic data of the open port, and divide the multiple open ports into a first group and a second group based on the risk level. Among them, the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group.

[0067] For the judgment of the risk of each open port, in this embodiment, an artificial intelligence method can be adopted.

[0068] Exemplarily, in this step, historical risk data can be obtained, and a risk prediction model can be obtained based on the historical risk data. Among them, the historical risk data includes the characteristic data corresponding to the open port when a risk situation occurs. Then, the characteristic data corresponding to each open port is imported into the risk prediction model, and based on the result output by the risk prediction model, the risk level corresponding to the open port is obtained.

[0069] Exemplarily, for the following risk data:

[0070]

[0071] First, categorical variables (such as protocol, service name, risk type, etc.) can be converted into numerical forms (such as one-hot encoding or label encoding), and numerical features (such as port number, process ID, etc.) can be standardized. Then, the risk severity is converted into a numerical label (such as: low = 0, medium = 1, high = 2). If the goal is a binary classification problem (whether a risk occurs), then "whether a risk event has occurred" is used as the label (yes = 1, no = 0).

[0072] Select a suitable machine learning algorithm to build a risk prediction model. Commonly used algorithms include: for classification problems (predicting whether a risk will occur), Logistic Regression, Random Forest, Support Vector Machine (SVM), Gradient Boosting Trees (XGBoost, LightGBM); for multi-classification problems (predicting the severity of risks), multi-class Logistic Regression.

[0073] Exemplarily, in this embodiment, the feature data is input into a neural network model for iterative calculation. Among them, the port number, protocol, service name, and the corresponding process are used as four different dimensions, and the four dimensions form a feature vector of the risk level. Then, when the iterative calculation process meets the preset conditions, the calculation is stopped, and the trained neural network model is output.

[0074] Use a deep learning framework (such as TensorFlow or PyTorch) to build a neural network model. The following is a simple example of a multi-layer perceptron (MLP).

[0075]

[0076] The example code is as follows:

[0077]

[0078] Set a loss function, and based on the loss function, obtain the error value in each iteration process, and compare the error value with a preset threshold. If the error value is less than the preset threshold, stop the iterative calculation and output the trained neural network model. After training is completed, save the model for subsequent use.

[0079] It can be understood that for a binary classification problem, use 1 neuron and the Sigmoid activation function.

[0080] For a multi-classification problem, use N neurons (N is the number of classes) and the Softmax activation function.

[0081] According to the output result of the model, assign a risk level to each open port:

[0082] If the model outputs a binary classification result (whether a risk occurs), it can be directly marked as "at risk" or "risk-free".

[0083] If the model outputs the severity of the risk (low, medium, high), the risk level can be divided according to the threshold.

[0084] S103: Differentially manage the open ports belonging to the first group and the open ports belonging to the second group.

[0085] Specifically, as an implementation, input the feature data corresponding to the open ports into a pre-trained neural network model, and determine the risk level of the open ports according to the output result of the neural network model. Among them, in the first monitoring period, the monitoring frequency of the open ports belonging to the first group and the second group is the target frequency.

[0086] Exemplarily, in this embodiment, if an open port belongs to the first group, increase the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period. If an open port belongs to the second group, decrease the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0087] Furthermore, in order to improve the accuracy and efficiency of network security protection, this implementation also introduces an adaptive adjustment mechanism. This mechanism dynamically adjusts the monitoring strategies of open ports in different groups based on the output result of the neural network model. Specifically, if the neural network model predicts that an open port belonging to the first group has a high risk, then in the second monitoring period, the system will automatically increase the monitoring frequency of this port to detect and respond to potential security threats in a timely manner. On the contrary, for open ports belonging to the second group and predicted to have a low risk, the system will appropriately reduce their monitoring frequency, thereby optimizing resource allocation and reducing unnecessary monitoring overhead while ensuring security. This adaptive adjustment mechanism makes network security protection more intelligent and efficient.

[0088] A network security protection method proposed in an embodiment of the present application. First, obtain all open ports of the server and obtain the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process. Then, determine the risk level of the open ports through a neural network based on the feature data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level. Among them, the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group. Finally, perform differential management on the open ports belonging to the first group and the open ports belonging to the second group. The network security protection method proposed in an embodiment of the present application optimizes resource allocation and reduces unnecessary monitoring overhead while ensuring security.

[0089] In a second aspect, an embodiment of the present application proposes a network security protection system, which is configured to include:

[0090] Obtain all open ports of the server and obtain the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process;

[0091] Determine the risk level of the open ports based on the characteristic data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group;

[0092] Differentially manage the open ports belonging to the first group and the open ports belonging to the second group.

[0093] Combined with the second aspect, in some feasible implementation manners, the system is configured to: determine the risk level of the open ports based on the characteristic data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group, including:

[0094] Obtain historical risk data, and obtain a risk prediction model based on the historical risk data, where the historical risk data includes the characteristic data corresponding to the open ports when a risk situation occurs;

[0095] Import the characteristic data corresponding to each open port into the risk prediction model, and obtain the risk level corresponding to the open port based on the result output by the risk prediction model.

[0096] Combined with the second aspect, in some feasible implementation manners, the system is configured to: obtain historical risk data, and obtain a risk prediction model based on the historical risk data, where the historical risk data includes the characteristic data corresponding to the open ports when a risk situation occurs, including:

[0097] Generate a training set based on the historical risk data, where the training set includes the corresponding risk level and the characteristic data of the corresponding open ports each time a risk situation occurs;

[0098] Input the characteristic data into a neural network model and perform iterative calculations, where the port number, protocol, service name, and the corresponding process are used as four different dimensions, and the four dimensions constitute a characteristic vector of the risk level;

[0099] When the iterative calculation process meets a preset condition, stop the calculation and output the trained neural network model.

[0100] Combined with the second aspect, in some feasible implementation manners, the system is configured to: when the iterative calculation process meets a preset condition, stop the calculation and output the trained neural network model, including:

[0101] Set a loss function, obtain the error value in each iteration process based on the loss function, and compare the error value with a preset threshold. If the error value is less than the preset threshold, stop the iterative calculation and output the trained neural network model.

[0102] In combination with the second aspect, in some feasible embodiments, the system is configured to: determine the risk level of each open port based on the feature data of the open port, and divide multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group, including:

[0103] Input the feature data corresponding to the open port into a trained neural network model, and determine the risk level of the open port according to the output result of the neural network model. Wherein, in the first monitoring period, the monitoring frequency of the open ports belonging to the first group and the second group is the target frequency.

[0104] In combination with the second aspect, in some feasible embodiments, the system is configured to: perform differential management on the open ports belonging to the first group and the open ports belonging to the second group, including:

[0105] If the open port belongs to the first group, increase the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0106] In combination with the second aspect, in some feasible embodiments, the system is configured to: if the open port belongs to the second group, reduce the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

[0107] A network security protection system proposed in an embodiment of the present application. First, obtain all open ports of the server, and obtain the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process. Then, determine the risk level of the open port through a neural network based on the feature data of each open port, and divide multiple open ports into a first group and a second group based on the risk level. Wherein, the risk level of the open ports belonging to the first group is higher than that of the open ports belonging to the second group. Finally, perform differential management on the open ports belonging to the first group and the open ports belonging to the second group. A network security protection system proposed in an embodiment of the present application, a network security protection method proposed in an embodiment of the present application, while ensuring security, optimizes resource allocation and reduces unnecessary monitoring overhead.

[0108] Based on the same inventive concept, an embodiment of the present application also proposes an electronic device, which includes:

[0109] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the automatic overheat protection method based on a universal testing machine according to an embodiment of the present application.

[0110] In addition, to achieve the above object, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the network security protection method according to the embodiment of the present application is implemented.

[0111] The following specifically introduces each component of the electronic device:

[0112] Among them, the processor is the control center of the electronic device, which can be a single processor or a collective term for multiple processing elements. For example, the processor is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0113] Optionally, the processor can execute various functions of the electronic device by running or executing software programs stored in the memory and calling data stored in the memory.

[0114] Among them, the memory is used to store the software program for implementing the solution of the present invention and is controlled by the processor for execution. The specific implementation manner can refer to the above method embodiment and will not be elaborated here.

[0115] Optionally, the memory may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may be integrated with the processor or may exist independently and be coupled to the processor through the interface circuit of the electronic device. The embodiments of the present invention do not make specific limitations thereon.

[0116] A transceiver for communicating with a network device or with a terminal device.

[0117] Optionally, the transceiver may include a receiver and a transmitter. Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0118] Optionally, the transceiver may be integrated with the processor or may exist independently and be coupled to the processor through the interface circuit of the router. The embodiments of the present invention do not make specific limitations thereon.

[0119] In addition, the technical effects of the electronic device may refer to the technical effects of the data transmission method in the above method embodiments and will not be elaborated herein.

[0120] It should be understood that the processor in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0121] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0122] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be solid-state drives.

[0123] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.

[0124] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0125] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0126] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

Claims

1. A network security protection method, characterized in that, The method includes: Obtain all open ports of the server, and obtain the characteristic data of each of the open ports, where the characteristic data includes the port number, protocol, service name, and the corresponding process; Determine the risk level of each open port based on the characteristic data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than the risk level of the open ports belonging to the second group; Perform differential management on the open ports belonging to the first group and the open ports belonging to the second group.

2. The network security protection method according to claim 1, characterized in that, Determine the risk level of each open port based on the characteristic data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than the risk level of the open ports belonging to the second group, and it includes: Obtain historical risk data, and obtain a risk prediction model based on the historical risk data, where the historical risk data includes the characteristic data corresponding to the open port when a risk situation occurs; Import the characteristic data corresponding to each open port into the risk prediction model, and obtain the risk level corresponding to the open port based on the result output by the risk prediction model.

3. The network security protection method according to claim 2, characterized in that, Obtain historical risk data, and obtain a risk prediction model based on the historical risk data, where the historical risk data includes the characteristic data corresponding to the open port when a risk situation occurs, and it includes: Generate a training set based on the historical risk data, where the training set includes the risk level corresponding to each occurrence of a risk situation and the characteristic data of the corresponding open port; Input the characteristic data into a neural network model and perform iterative calculations, where the port number, protocol, service name, and the corresponding process are used as four different dimensions, and the four dimensions constitute the characteristic vector of the risk level; Stop the calculation when the iterative calculation process meets the preset conditions, and output the trained neural network model.

4. A network security protection method according to claim 3, characterized in that, Stop the calculation when the iterative calculation process meets the preset conditions, and output the trained neural network model, and it includes: Set a loss function, and obtain the error value in each iteration process based on the loss function, and compare the error value with a preset threshold. If the error value is less than the preset threshold, stop the iterative calculation and output the trained neural network model.

5. A network security protection method according to claim 1, characterized in that, Determine the risk level of each open port based on the characteristic data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level, where the risk level of the open ports belonging to the first group is higher than the risk level of the open ports belonging to the second group, and it includes: Input the feature data corresponding to the open port into the trained neural network model, and determine the risk level of the open port according to the output result of the neural network model. Among them, in the first monitoring period, the monitoring frequency of the open ports belonging to the first group and the second group is the target frequency.

6. A network security protection method according to claim 4, characterized in that, The differential management of the open ports belonging to the first group and the open ports belonging to the second group includes: If the open port belongs to the first group, increase the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

7. A network security protection method according to claim 4, characterized in that If the open port belongs to the second group, decrease the monitoring frequency of the open port in the second monitoring period, where the second monitoring period is the period after the first monitoring period.

8. A network security protection system, characterized in that, The system is configured to: Obtain all open ports of the server and obtain the feature data of each open port. The feature data includes the port number, protocol, service name, and the corresponding process. Determine the risk level of the open port based on the feature data of each open port, and divide the multiple open ports into a first group and a second group based on the risk level. Among them, the risk level of the open ports belonging to the first group is higher than the risk level of the open ports belonging to the second group. Conduct differential management on the open ports belonging to the first group and the open ports belonging to the second group.

9. An electronic device, characterized in that, It includes: At least one processor; And a memory communicatively connected to at least one processor; Among them, the memory stores instructions executable by at least one processor. The instructions are executed by at least one processor so that at least one processor can execute the method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the program is executed by a processor, it implements the method according to any one of claims 1-7.