Communication dynamic analysis method for virtual network security

By constructing a joint probability distribution model and multi-scale decomposition technology, combined with the LSTM neural network model, the identification and propagation path prediction problems of abnormal data in virtual machine network communication are solved, and efficient detection and early warning of virtual network security is achieved.

CN120415917AActive Publication Date: 2025-08-01深圳宸元网信科技有限公司

Patent Information

Application Number
CN202510911957.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2025-08-01
Estimated Expiration
2045-07-03

AI Technical Summary

Technical Problem

The prior art is difficult to fully and accurately identify complex and dynamically changing network communication exceptions between virtual machines, and cannot capture multi-scale changes in abnormal data and propagation paths, resulting in lag in abnormal response and widening of risks.

Method used

By collecting the communication node identification, packet transmission interval time and interaction duration between virtual machines, a joint probability distribution model is built, multi-scale decomposition and difference analysis are performed, and combined with the LSTM neural network model, the propagation path and starting node of abnormal communication data are identified and predicted.

Benefits of technology

It significantly improves the accuracy and intelligence level of virtual network security detection, can effectively identify and predict complex communication abnormal behaviors, and improves the initiative and intelligence level of network security defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415917A_ABST
    Figure CN120415917A_ABST
Patent Text Reader

Abstract

The invention discloses a virtual network security-oriented communication dynamic analysis method, which relates to the technical field of network security, and comprises the following steps of: acquiring a communication time sequence; performing multi-scale decomposition on the communication sequential sequence to obtain a reference communication sequential sequence; calculating a slope and a propagation rate, and determining abnormal communication data based on the slope and the propagation rate; determining continuous abnormal communication data according to the periodic characteristics of the abnormal communication data and the propagation sequence of the abnormal communication data in network nodes, and determining an initial node and a propagation path of the continuous abnormal communication data by adopting reverse time sequence recursive analysis; inputting the starting node of the continuous abnormal communication data and the abnormal data characteristics of the propagation path into the LSTM neural network model, and predicting subsequent abnormal nodes; according to the method, high-precision identification of communication abnormity is facilitated, and the security detection capability and the response efficiency in a virtualized network environment are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a communication dynamic analysis method for virtual network security. Background Art

[0002] With the wide application of cloud computing and virtualization technologies, enterprises and institutions widely use virtual machines for business deployment to improve resource utilization and management flexibility. However, the frequent and complex network communications between virtual machines make network security threats present the characteristics of concealment, complexity, and diversification. Traditional network security detection means usually identify anomalies based on predefined feature rules or static communication patterns, and have the following obvious deficiencies:

[0003] First of all, most of the existing technologies adopt detection methods based on static features or single-dimensional data analysis, and it is difficult to comprehensively and accurately model complex and dynamically changing virtual network communication data, resulting in insufficient accuracy in identifying abnormal data;

[0004] Secondly, current methods for virtual machine network security detection pay less attention to the multi-scale change characteristics of communication data, and cannot capture the change trends and patterns of abnormal data at different time scales, and are prone to missing concealed abnormal communications;

[0005] In addition, existing network anomaly detection technologies often ignore the propagation path and its periodic characteristics of abnormal communication data, and it is difficult to effectively identify persistent abnormal attacks or concealed advanced persistent threat (APT) attacks, and there is a lack of predictive analysis of the propagation trend and path of abnormal data, resulting in lagged abnormal response and risk expansion.

[0006] Therefore, there is an urgent need for a method and system that can comprehensively utilize the multi-dimensional features of communication data, combine multi-scale analysis methods, accurately identify network abnormal data, and can effectively analyze the abnormal propagation path and trend, and further improve the intelligent level of network security detection. Summary of the Invention

[0007] The present invention aims to at least solve one of the technical problems existing in the prior art; for this purpose, the present invention proposes a communication dynamic analysis method for virtual network security.

[0008] To achieve the above object, the present invention provides a communication dynamic analysis method for virtual network security, including:

[0009] The server node collects the communication node identifiers, packet transmission interval time, and interaction duration between virtual machines, and reconstructs the communication data based on the joint probability distribution of the transmission interval and the duration to obtain a communication time series;

[0010] Perform multi-scale decomposition on the communication timing sequence, fuse the decomposition results of different scales, and obtain the reference communication timing sequence;

[0011] Calculate the difference sequence between the communication timing sequence and the reference communication timing sequence, calculate the first-order difference sequence of the difference sequence and determine its slope, calculate the propagation rate of the difference sequence between network nodes, and determine abnormal communication data based on the slope and propagation rate;

[0012] According to the periodic characteristics of the abnormal communication data and its propagation order in the network nodes, determine the continuous abnormal communication data, and use reverse-time recursive analysis to determine the starting node and propagation path of the continuous abnormal communication data;

[0013] Input the abnormal data characteristics of the starting node and propagation path of the continuous abnormal communication data into the LSTM neural network model to predict subsequent abnormal nodes in the communication timing sequence.

[0014] Further, the reconstructing communication data based on the joint probability distribution of the transmission interval and the duration includes:

[0015] Statistically count the occurrence frequencies of the packet transmission interval time and the interaction duration in the original communication data, and calculate the joint probability of the transmission interval and the interaction duration according to the occurrence frequencies;

[0016] According to the joint probability, construct a two-dimensional probability distribution matrix with the transmission interval as the vertical axis and the interaction duration as the horizontal axis;

[0017] According to the probability density change characteristics of the two-dimensional probability distribution matrix, determine the effective data region where the probability density is higher than the average probability density;

[0018] According to the effective data region, select the original communication data that falls within this effective data region, reconstruct the communication data and form a communication timing sequence.

[0019] Further, the method of performing multi-scale decomposition on the communication timing sequence and fusing the decomposition results of different scales includes:

[0020] Perform discrete wavelet transform on the communication timing sequence to obtain multi-scale approximation coefficient sequences and detail coefficient sequences;

[0021] Calculate the variance of each scale detail coefficient sequence respectively, sort according to the variance size and determine the detail coefficient sequence of the main scale;

[0022] Use the determined detail coefficient sequence of the main scale and the corresponding approximation coefficient sequence to perform inverse wavelet transform to respectively reconstruct time-domain component sequences of different scales;

[0023] According to the time-domain component sequences of different scales obtained by reconstruction, they are fused into a reference communication time sequence by weighted superposition.

[0024] Further, calculating the first-order difference sequence of the difference sequence and determining its slope includes:

[0025] Based on the obtained difference sequence, explicitly calculate its first-order difference sequence :

[0026] , ;

[0027] In the formula: is the difference between adjacent data points of the difference sequence; and are the differences between two consecutive data points of the difference sequence, and the length of the first-order difference sequence is n - 1;

[0028] Perform linear regression on the first-order difference sequence to calculate its slope, and the specific formula for slope calculation is explicitly:

[0029] ;

[0030] In the formula: is the slope of the first-order difference sequence, i is the sequence index, , is the arithmetic mean of the first-order difference sequence.

[0031] Further, determining the abnormal communication data based on the slope and propagation rate includes:

[0032] Preset the slope threshold as , and the data propagation rate threshold under normal circumstances is ;

[0033] Compare and judge the calculated slope and the propagation rate :

[0034] When the absolute value of the slope , and , then mark the corresponding communication data as abnormal communication data;

[0035] Otherwise, do not mark the corresponding communication data as abnormal communication data.

[0036] Further, the method for obtaining the periodic characteristics of the abnormal communication data includes:

[0037] Perform discrete Fourier transform on the data amplitude sequence of the abnormal communication data to obtain the corresponding frequency-domain sequence;

[0038] Specifically, the data amplitude sequence of the abnormal communication data is ; where represents the difference amplitude of the i-th abnormal data point relative to the reference communication sequence; n is the length of the abnormal communication data sequence;

[0039] Specifically, the calculation formula for performing discrete Fourier transform on the data amplitude sequence is as follows:

[0040] ;

[0041] In the formula: represents the Fourier transform result of the k-th frequency component, that is, the amplitude value of the k-th frequency component, is the imaginary unit, and , and the sequence length n is the number of sampling points for the discrete Fourier transform;

[0042] Calculate the power spectral density values of each frequency component in the frequency domain sequence, and sort them in descending order according to the numerical values;

[0043] Among them, the calculation formula for the power spectral density value is:

[0044] ;

[0045] In the formula: is the power spectral density corresponding to the k-th frequency component, is the conjugate complex number of the k-th frequency component, is the amplitude value of the k-th frequency component;

[0046] Determine the frequency component in the first position after sorting as the dominant frequency component;

[0047] Calculate the period length according to the frequency value corresponding to the dominant frequency component, and determine the period length as the period characteristic of the abnormal communication data;

[0048] Among them, the calculation formula for the period length is:

[0049] ;

[0050] In the formula: represents the period length of the abnormal communication data, is the frequency value corresponding to the dominant frequency component.

[0051] Furthermore, the method for obtaining the propagation order is as follows:

[0052] Record the timestamps when each node in the network detects abnormal communication data;

[0053] Sort the nodes according to the timestamps when abnormal communication data is detected at each node, in ascending order of the timestamp values.

[0054] According to the sorted node order and the network topology connection relationship between the nodes, determine the propagation order of the abnormal communication data among the network nodes, and output the determined propagation order.

[0055] Further, the determining the starting node and propagation path of the continuous abnormal communication data includes:

[0056] According to the propagation order of the continuous abnormal communication data among the network nodes, determine that the last node in the propagation order is the initial backtracking node;

[0057] According to the network topology connection relationship, starting from the initial backtracking node, determine forward the previous nodes that are directly connected to it and are before this node in the propagation order;

[0058] Use the determined previous node as the new backtracking node, repeat the process of determining the previous node, and backtrack step by step in reverse until the first node in the propagation order is determined, and determine this node as the starting node of the continuous abnormal communication data;

[0059] According to the connection relationship between the nodes determined in the above reverse backtracking process, determine the complete propagation path of the continuous abnormal communication data from the starting node to the initial backtracking node, and output the starting node and propagation path of the continuous abnormal communication data.

[0060] Further, the predicting the subsequent abnormal nodes in the communication time series sequence includes:

[0061] According to the abnormal data characteristics of the starting node and propagation path of the continuous abnormal communication data, construct an abnormal characteristic sequence of the abnormal propagation of communication nodes;

[0062] Input the abnormal characteristic sequence into the LSTM neural network model to predict the occurrence probability of abnormal communication data at each node at the next moment;

[0063] Determine the nodes whose predicted abnormal occurrence probability exceeds the preset probability threshold as the subsequent abnormal nodes, and output the determined subsequent abnormal nodes.

[0064] A communication dynamic analysis system for virtual network security, implemented based on the above-mentioned communication dynamic analysis method for virtual network security,is characterized by including:

[0065] An acquisition module, used for the server node to collect the communication node identifiers, packet transmission interval time, and interaction duration between virtual machines, reconstruct the communication data based on the joint probability distribution of the transmission interval and duration, and obtain the communication time series sequence;

[0066] A decomposition module, which is used to perform multi-scale decomposition on the communication timing sequence, fuse the decomposition results of different scales, and obtain a reference communication timing sequence;

[0067] An anomaly acquisition module, which is used to calculate the difference sequence between the communication timing sequence and the reference communication timing sequence, calculate the first-order difference sequence of the difference sequence and determine its slope, calculate the propagation rate of the difference sequence between network nodes, and determine abnormal communication data based on the slope and propagation rate;

[0068] An anomaly analysis module, which is used to determine persistent abnormal communication data according to the periodic characteristics of the abnormal communication data and its propagation order in the network nodes, and use reverse timing recursive analysis to determine the starting node and propagation path of the persistent abnormal communication data;

[0069] A detection module, which is used to input the abnormal data characteristics of the starting node and propagation path of the persistent abnormal communication data into the LSTM neural network model to predict subsequent abnormal nodes in the communication timing sequence.

[0070] Compared with the prior art, the beneficial effects of the present invention are:

[0071] The present invention constructs a joint probability distribution model based on the packet transmission interval and the interaction duration, identifies and retains the representative effective data regions in the virtual machine communication, reconstructs and forms a real and reliable communication timing sequence, effectively solves the problems of serious interference of redundant data in the virtual communication flow and difficulty in accurately extracting communication behavior characteristics in the prior art, and significantly improves the quality of preposed data for anomaly detection and the basic analysis accuracy.

[0072] Furthermore, the communication timing sequence is decomposed by multi-scale wavelet transform, the dominant scale is determined by combining the variance contributions of the detail sequences of each scale, and a reference communication timing sequence is constructed for difference analysis, which solves the problems of weak recognition ability for short-time burst and slow and hidden anomalies and high false alarm rate of traditional anomaly detection methods, and significantly enhances the adaptability and recognition ability of the system to complex communication anomaly behaviors at different time scales.

[0073] In addition, through the joint discrimination mechanism of the difference sequence slope and the propagation rate between nodes, abnormal communication data with a propagation trend is accurately identified. Further, by combining frequency-domain periodic analysis and the network topology backtracking path algorithm, the abnormal propagation starting point and the complete path are determined, and the LSTM neural network model is introduced to realize the intelligent prediction of subsequent abnormal nodes, systematically solving the problems of difficult traceability and difficult early warning of abnormal events in the prior art, and significantly improving the initiative and intelligent level of network security defense. Description of the Drawings

[0074] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0075] Figure 1 It is a schematic flowchart of the method of the present invention;

[0076] Figure 2 It is a schematic structural diagram of the system of the present invention. Detailed implementation manners

[0077] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0078] Please refer to Figure 1 , the first aspect embodiment of the present invention provides a communication dynamic analysis method for virtual network security, including:

[0079] S101: The server node collects the communication node identifiers between virtual machines, the data packet transmission interval time, and the interaction duration, and reconstructs the communication data based on the joint probability distribution of the transmission interval and the duration to obtain a communication time series;

[0080] It should be noted that: The server node refers to a physical or virtual server used for collecting and analyzing virtual machine communication data, which obtains communication data through a network monitoring module deployed in the virtualization platform. The communication data includes:

[0081] Communication node identifiers between virtual machines:

[0082] Specifically, it is the unique network identifier of each virtual machine node in the virtualization platform, which may specifically include an IP address, a MAC address, or a unique UUID identifier of the virtual machine, and is collected by monitoring the network traffic records of the virtual switch;

[0083] Data packet transmission interval time:

[0084] Specifically, it is the sending or receiving time interval between consecutive communication data packets. The server node accurately records the receiving or sending time of each data packet, and then calculates the transmission interval between each data packet one by one. The specific calculation method is: , The time interval of the i-th data packet transmission, and They are the timestamps of the i-th and the (i - 1)-th data packets respectively;

[0085] Interaction duration:

[0086] Specifically, it is the total duration of communication activities between two specific virtual machine nodes. Specifically, the server node records the timestamps of the first communication data packet and the last communication data packet between each pair of virtual machine nodes according to the virtual machine communication data traffic, and then calculates the communication duration: , is the communication interaction duration between virtual machine nodes, is the communication timestamp of the first data packet between virtual machine nodes, is the communication timestamp of the last data packet between virtual machine nodes;

[0087] In implementation, the reconstructing communication data based on the joint probability distribution of transmission interval and duration includes:

[0088] S101.1 Statistically analyze the occurrence frequencies of the packet transmission intervals and interaction durations in the original communication data, and calculate the joint probability of the transmission interval and the interaction duration according to the occurrence frequencies;

[0089] Among them, the process of statistically analyzing the occurrence frequencies of the packet transmission intervals and interaction durations in the original communication data and calculating the joint probability is specifically as follows:

[0090] Divide the transmission intervals of the original communication data into multiple equal-width intervals, such as 0–10 ms, 10–20 ms, 20–30 ms, etc.;

[0091] Divide the interaction durations into multiple equal-width duration intervals, such as 0–1 s, 1–2 s, 2–3 s, etc.;

[0092] Statistically analyze the number of data packets that simultaneously fall into each transmission interval and interaction duration interval;

[0093] Calculate the proportion of the number of data packets in each combined interval to the total number of all data packets to form the joint probability :

[0094] ;

[0095] In the formula: is the number of data packets that simultaneously fall into the transmission interval and the interaction duration interval, is the total number of all data packets;

[0096] S101.2 Construct a two-dimensional probability distribution matrix with the transmission interval as the vertical axis and the interaction duration as the horizontal axis according to the joint probability;

[0097] Among them, all the calculated joint probability values are arranged according to the corresponding transmission interval range (vertical axis) and interaction duration range (horizontal axis) to form a two-dimensional matrix M:

[0098] ;

[0099] In the formula: Each element in the matrix represents the joint probability of a specific combination range;

[0100] S101.3 Determine the effective data region where the probability density is higher than the average probability density according to the probability density change characteristics of the two-dimensional probability distribution matrix;

[0101] Among them, the process of determining the effective data region according to the probability density change characteristics of the two-dimensional probability distribution matrix is specifically as follows:

[0102] Calculate the average value of all joint probability values in the two-dimensional probability distribution matrix M :

[0103] ;

[0104] In the formula: , are respectively the total number of intervals of the transmission interval and the interaction duration;

[0105] Determine the interval where the joint probability value exceeds the average value as the effective data region to form a two-dimensional effective region mask matrix E, where:

[0106] ;

[0107] S101.4 Select the original communication data that falls into the effective data region according to the effective data region, reconstruct the communication data and form a communication time series;

[0108] Among them, the process of selecting the original communication data and reconstructing the communication data according to the effective data region is specifically as follows:

[0109] Traverse all the original communication data, and judge whether its transmission interval and interaction duration simultaneously fall into the positions marked as 1 in the effective data region mask matrix E. If they fall in simultaneously, select the communication data and keep the timestamp and order information of the original data packet unchanged;

[0110] After the selection is completed, sort them strictly in ascending order of the original data packet timestamp to ensure that the reconstructed communication data time series is accurate and continuous, and is exactly the same as the original communication data in time order to ensure data authenticity and time series continuity, so as to obtain the reconstructed communication time series, which is specifically expressed as:

[0111] ;

[0112] Where: is the transmission interval time of the i-th data packet after reconstruction, and n is the total number of communication data after reconstruction;

[0113] Assume that in the original communication data packet sequence, the 3rd, 4th, 7th, and 8th data packets fall into the valid data area. Then, it is clear that the selected data packets still retain the timestamp information of the original data packets. For example, see Table 1 below:

[0114] Table 1: Timestamp Information Table

[0115]

[0116] The reconstructed communication timing sequence is clearly: ;

[0117] S102: Perform multi-scale decomposition on the communication timing sequence, and fuse the decomposition results of different scales to obtain a reference communication timing sequence;

[0118] In implementation, the method of performing multi-scale decomposition on the communication timing sequence and fusing the decomposition results of different scales includes:

[0119] S102.1: Perform discrete wavelet transform on the communication timing sequence to obtain a multi-scale approximation coefficient sequence and detail coefficient sequence;

[0120] It should be noted that the discrete wavelet transform is a standard multi-scale analysis method, using db4 or sym4. Specifically: input the communication timing sequence into the wavelet filter bank. First, perform low-pass filtering and downsampling to clearly obtain an approximation coefficient sequence reflecting the long-term trend of the original sequence , and at the same time, perform high-pass filtering and downsampling to clearly obtain a detail coefficient sequence reflecting the short-term fluctuations of the sequence . Using the approximation coefficient sequence as the input, continue to perform low-pass and high-pass filtering at the next scale, and downsample to clearly obtain the approximation coefficient sequence and the detail coefficient sequence at the next scale; and so on, complete the multi-scale (such as three-level) discrete wavelet transform, and finally obtain a set of approximation coefficient sequences and a set of detail coefficient sequences ;

[0121] S102.2: Calculate the variance of each scale detail coefficient sequence respectively, sort according to the variance size, and determine the detail coefficient sequence of the main scale;

[0122] It should be noted that the method for calculating the variance of each scale detail coefficient sequence and determining the main scale is specifically as follows: Taking the detail coefficient sequence of the k-th scale as an example, the variance calculation formula is:

[0123] ;

[0124] In the formula: is the variance of the detail coefficient sequence of the k-th scale; is the i-th element in the detail coefficient sequence of the k-th scale; is the arithmetic mean of the detail coefficient sequence of the k-th scale; is the total number of elements in the detail coefficient sequence of the k-th scale;

[0125] After calculating the variances of all scale detail coefficient sequences, sort them from largest to smallest according to the variance values, and select the scale ranked r (such as r = 2) as the main scale to clearly indicate that these scales contribute most significantly to the short-term fluctuations of the original sequence;

[0126] S102.3: Use the determined main scale detail coefficient sequence and the corresponding approximation coefficient sequence to perform inverse wavelet transform to respectively reconstruct the time domain component sequences of different scales;

[0127] It should be noted that the method for using the determined main scale detail coefficient sequence and the corresponding approximation coefficient sequence to perform inverse wavelet transform to respectively reconstruct the time domain component sequences of different scales is specifically as follows:

[0128] For the selected main scale detail coefficient sequence (for example and the corresponding approximation coefficient sequence (for example ), perform inverse wavelet transform respectively; Taking the k-th scale as an example, the inverse wavelet transform specifically includes:

[0129] Upsample the detail coefficient sequence of the k-th scale and the approximation coefficient sequence respectively, and insert zero values for sequence expansion;

[0130] The upsampled sequences are respectively processed by the corresponding wavelet reconstruction filters (i.e., low-pass and high-pass filters);

[0131] Sum the two sequences processed by the filters point by point to obtain the time domain component sequence corresponding to the k-th scale ;

[0132] S(102.4): According to the reconstructed time domain component sequences of different scales, fuse them into a reference communication time series sequence by weighted superposition;

[0133] It should be noted that the method of weighted superposition and fusion of the time-domain component sequences of different scales into the reference communication time sequence is specifically as follows:

[0134] For each time-domain component sequence reconstructed above perform weighted superposition, and the specific weighting coefficients are determined by the correlation coefficients between each scale sequence and the original communication time sequence; the specific correlation coefficients The calculation formula is:

[0135] ;

[0136] In the formula: is the i-th element in the original communication time sequence, is the i-th element in the time-domain component sequence of the k-th scale, , are the arithmetic means of the two sequences respectively, and n is the sequence length;

[0137] After obtaining the correlation coefficients, calculate the weights of the time-domain component sequences of each scale :

[0138] ;

[0139] Finally, the reference communication time sequence is explicitly obtained through the following formula:

[0140] ;

[0141] In the formula: is the i-th element in the reference communication time sequence; is the weight of the time-domain component sequence of the k-th scale; is the i-th element in the time-domain component sequence of the k-th scale;

[0142] S103: Calculate the difference sequence between the communication time sequence and the reference communication time sequence, calculate the first-order difference sequence of the difference sequence and determine its slope, calculate the propagation rate of the difference sequence between network nodes, and determine abnormal communication data based on the slope and propagation rate;

[0143] It should be noted that: the calculation method of the difference sequence is: Let the original communication time sequence be denoted as, , and the reference communication time sequence be denoted as, , where the sequence lengths are both n, and each data point and have strictly corresponding timestamps; then the difference sequence is explicitly expressed as:

[0144] , , ;

[0145] In the formula: is the difference between the original communication timing sequence and the reference sequence at the i-th time point, and are the corresponding i-th data points in the communication timing sequence and the reference communication timing sequence respectively, and the sequence length n is defined as the total number of data points in the data analysis interval;

[0146] Among them, calculating the first-order difference sequence of the difference sequence and determining its slope includes:

[0147] Based on the obtained difference sequence D, calculate its first-order difference sequence :

[0148] , ;

[0149] In the formula: is the difference between adjacent data points of the difference sequence; and are the differences between two consecutive data points of the difference sequence, and the length of the first-order difference sequence is n - 1;

[0150] Perform linear regression on the first-order difference sequence to calculate its slope, and the specific formula for slope calculation is defined as:

[0151] ;

[0152] In the formula: is the slope of the first-order difference sequence, i is the sequence index, , is the arithmetic mean of the first-order difference sequence;

[0153] It can be understood that: This slope objectively reflects the change rate of the difference sequence, and is specifically expressed as:

[0154] If the slope , then the difference sequence gradually increases with time;

[0155] If the slope , then the difference sequence gradually decreases with time;

[0156] The absolute value of the slope value The larger it is, the more intense the change trend;

[0157] It should be noted that the specific calculation method of the propagation rate is as follows: If an abnormal change data point in the difference sequence is first observed at network node m exceeding a preset abnormal amplitude threshold, then record the first timestamp of the abnormal data observed at this node as ; Subsequently, the same abnormal feature data point is first observed at the next network node n exceeding the preset abnormal amplitude threshold, and record the first timestamp of the abnormal data observed at this node as ; Then the propagation time interval of the difference sequence between network node m and node n is clearly: ; The network topology connection distance (such as the number of hops) between network node m and node n is clearly , then the clear calculation formula for the propagation rate is: ;

[0158] It should be noted that: Among them, the network topology connection distance (i.e., the number of hops ) between network node m and node n is determined by the pre-obtained and stored network topology mapping table. The specific method is:

[0159] First, clearly establish the topology connection matrix (adjacency matrix) between network nodes, and record the direct connection relationships between all nodes; use the breadth-first search (BFS) algorithm, starting from node m, search for the shortest path length to reach node n in the network topology graph as the number of hops ;

[0160] Exemplarily: If node m and node n are connected through two intermediate nodes, node x and node y, then the number of hops is ;

[0161] Among them, determining the abnormal communication data based on the slope and propagation rate includes:

[0162] The preset slope threshold is , and the data propagation rate threshold under normal circumstances is ;

[0163] Compare and judge the calculated slope and the propagation rate :

[0164] When the absolute value of the slope , and , then mark the corresponding communication data as abnormal communication data;

[0165] Otherwise, do not mark the corresponding communication data as abnormal communication data;

[0166] Exemplarily: Assume that the set slope threshold is , and the propagation rate threshold is (hops / second); if through calculation, the slope of the actual data , and at the same time the propagation rate , then the condition is met, and at this time it is clearly determined that the corresponding communication data is abnormal communication data.

[0167] S104: According to the periodic characteristics of the abnormal communication data and its propagation order in the network nodes, determine the continuous abnormal communication data, and use reverse time series recursive analysis to determine the starting node and propagation path of the continuous abnormal communication data;

[0168] Specifically, the method for obtaining the periodic characteristics of the abnormal communication data includes:

[0169] S104.1: Perform discrete Fourier transform on the data amplitude sequence of the abnormal communication data to obtain the corresponding frequency domain sequence;

[0170] Specifically, the data amplitude sequence of the abnormal communication data is ; where represents the difference amplitude of the i-th abnormal data point relative to the reference communication sequence; n is the length of the abnormal communication data sequence;

[0171] Specifically, the calculation formula for performing discrete Fourier transform on the data amplitude sequence is as follows:

[0172] ;

[0173] In the formula: represents the Fourier transform result of the k-th frequency component, that is, the amplitude value of the k-th frequency component, is the imaginary unit, and , the sequence length n is the number of sampling points for discrete Fourier transform;

[0174] S104.2: Calculate the power spectral density values of each frequency component in the frequency domain sequence, and sort them in descending order according to the numerical values;

[0175] Among them, the calculation formula for the power spectral density value is:

[0176] ;

[0177] In the formula: is the power spectral density corresponding to the k-th frequency component, is the conjugate complex number of the k-th frequency component, is the amplitude value of the k-th frequency component;

[0178] S104.3: Determine the dominant frequency component as the frequency component located in the first position after sorting;

[0179] S104.4: Calculate the period length according to the frequency value corresponding to the dominant frequency component, and determine the period length as the period feature of the abnormal communication data;

[0180] Among them, the period length calculation formula is:

[0181] ;

[0182] In the formula: represents the period length of the abnormal communication data, is the frequency value corresponding to the dominant frequency component;

[0183] Specifically, the method for obtaining the propagation order is as follows:

[0184] S104.5: Record the timestamps when each node in the network detects abnormal communication data;

[0185] S104.6: Sort the nodes according to the timestamps when each node detects abnormal communication data in ascending order of the timestamp values;

[0186] Specifically, obtain the set of nodes in the network where abnormal communication data has been clearly observed, denoted as: , where is a certain node identifier in the network, which can specifically be the IP address of the node, the MAC address, or the unique identifier of the virtual machine, and m is the total number of nodes in the network where abnormal communication data has been clearly observed;

[0187] Record the exact timestamps when each node in the above network node set first appears abnormal communication data, forming a corresponding set of nodes and timestamps, specifically denoted as: , where, represents the network node The timestamp when abnormal communication data first appears, and the precision of the timestamp is clearly in milliseconds to ensure that the appearance order of abnormal data of different nodes can be objectively distinguished;

[0188] S104.7: Determine the propagation order of the abnormal communication data among the network nodes according to the sorted node order and the network topology connection relationship between the nodes, and output the determined propagation order;

[0189] Exemplarily: Assume that the network nodes where abnormal communication data has been clearly detected currently include Node A, Node B, Node C, and Node D; the timestamps when each node detected abnormal communication data are respectively: Node A: 2024-05-30 10:00:05.200; Node B: 2024-05-30 10:00:06.500; Node C: 2024-05-30 10:00:08.300; Node D: 2024-05-30 10:00:10.600;

[0190] According to the above timestamps, after sorting the nodes in ascending order of the time when abnormal data was detected, the determined node order is: Node A → Node B → Node C → Node D;

[0191] Furthermore, given the network topology connection relationship: there is a direct connection between Node A and Node B; there is a direct connection between Node B and Node C; there is a direct connection between Node C and Node D; there is no direct connection between Node A and Node C, and between Node A and Node D; there is no direct connection between Node B and Node D; based on the sorted node order and the above - defined network topology connection relationship, the propagation order of the abnormal communication data can be determined as: Node A → Node B → Node C → Node D;

[0192] The above node order conforms to the logic of the gradual propagation of abnormal data among nodes: Abnormal data first appears at Node A, then at Node B later, and there is a direct connection between them; subsequently, abnormal data appears at Node C, which has a direct connection with Node B; finally, abnormal data appears at Node D, which has a direct connection with Node C; ultimately, the propagation order is clearly output in tabular form (as shown in Table 2 below):

[0193] Table 2: Propagation Order Data Table

[0194]

[0195] Specifically, the persistent abnormal communication data refers to abnormal communication data that propagates among network nodes in the same node order in multiple consecutive cycles, and the propagation process exhibits stable periodic repetition characteristics; the persistent abnormal communication data shows a clear dominant periodic component in the frequency domain and the abnormal data propagation path repeats without difference in consecutive cycles in the time domain;

[0196] In implementation, the method of using reverse - time sequential recursion analysis to determine the starting node and propagation path of the persistent abnormal communication data includes:

[0197] S104.1: According to the propagation order of the persistent abnormal communication data among network nodes, determine the last node in the propagation order as the initial backtracking node;

[0198] Exemplarily, assume that the node propagation order sequence is as follows: → → → , then the node that is clearly located at the end of the propagation order sequence is used as the initial backtracking node;

[0199] S104.2: According to the network topology connection relationship, starting from the initial backtracking node, determine forward the previous nodes that are directly connected to it and are located before this node in the propagation order;

[0200] S104.3: Use the determined previous node as the new backtracking node, and repeat the process of determining the previous node, backtracking step by step in reverse until the first node in the propagation order is determined, and determine this node as the starting node of the continuous abnormal communication data;

[0201] S104.4: According to the connection relationship between the nodes determined in the above reverse backtracking process, determine the complete propagation path of the continuous abnormal communication data from the starting node to the initial backtracking node, and output the starting node and propagation path of the continuous abnormal communication data;

[0202] Exemplarily, if the network topology connection relationship is as follows: , , , which means that there is a clear direct network connection relationship between node A and B, B and C, and C and D, then according to the network topology connection relationship, it is clearly judged that the node that has a direct connection with and is located before the node in the propagation order is node , then determine that node is the direct previous node of node . Subsequently, use the just determined previous node as the new backtracking node, repeat the above process, and continue to determine forward the nodes that are directly connected to it and are located in front in the propagation order;

[0203] Continuing the example, the current node is the backtracking node. According to the network topology relationship, it is clearly judged that the previous node that is directly connected to node and is located before node is node , then determine that node is the direct previous node of node . Repeat the above recursive analysis until the first node in the propagation order is clearly determined (such as node ). At this time, node is the node in the network that first detects the continuous abnormal communication data, and there is no earlier node in the propagation path. Therefore, node Determine the starting node of the continuously abnormal communication data. Finally, according to the above backtracking analysis process, the complete propagation path is determined as: → → → 。

[0204] S105: Input the starting node of the continuously abnormal communication data and the abnormal data features of the propagation path into the LSTM neural network model to predict the subsequent abnormal nodes in the communication time series;

[0205] Specifically, the abnormal data features include the occurrence frequency of the node's historical abnormal communication data, specifically the number of times the node detects abnormal communication data per unit time (such as per hour or per day); the amplitude change feature of the node's historical abnormal communication data, specifically the average value, variance, maximum value or median of the difference sequence of the historical abnormal communication data relative to the reference communication data; the historical delay feature of the propagation of abnormal communication data between network nodes, specifically the historical average value or historical median of the time difference between two adjacent nodes detecting abnormal communication data successively; the historical probability of the propagation of abnormal data to subsequent nodes after the node has had abnormal communication data in history, specifically the historical statistical probability that the subsequent node directly adjacent to the node has abnormal communication data at the next moment after the node detects abnormal data;

[0206] In implementation, predicting the subsequent abnormal nodes in the communication time series includes:

[0207] S105.1: Construct an abnormal feature sequence for the abnormal propagation of communication nodes according to the starting node of the continuously abnormal communication data and the abnormal data features of the propagation path;

[0208] S105.2: Input the abnormal feature sequence into the LSTM neural network model to predict the occurrence probability of abnormal communication data at each node at the next moment;

[0209] It should be noted that: the training process of the LSTM neural network model is to obtain historical abnormal feature recognition data, divide the historical abnormal feature recognition data into a training set and a test set, where the historical abnormal feature recognition data includes abnormal data features and their corresponding abnormal occurrence probabilities; construct an LSTM neural network, input the abnormal data features in the training set and the abnormal occurrence probabilities as outputs into the LSTM neural network for training to obtain an initial LSTM neural network, use the test set to verify the initial LSTM neural network model, and use the initial LSTM neural network with an input less than or equal to the test error threshold as the LSTM neural network model; the abnormal data features and abnormal occurrence probabilities in the historical abnormal feature recognition data are actually collected by technicians or statistically obtained according to historical data records;

[0210] S105.3: Determine the nodes whose predicted abnormal occurrence probability exceeds the preset probability threshold as subsequent abnormal nodes, and output the determined subsequent abnormal nodes.

[0211] Please refer to Figure 2 , based on the same inventive concept, the second aspect of the present invention provides a communication dynamic analysis system for virtual network security. For the details not described in this embodiment, please refer to the relevant parts in Embodiment 1. The system includes:

[0212] An acquisition module 201, configured to collect communication node identifiers, data packet transmission interval times, and interaction durations between virtual machines for server nodes, reconstruct communication data based on the joint probability distribution of the transmission interval and the duration, and obtain a communication time series sequence;

[0213] A decomposition module 202, configured to perform multi-scale decomposition on the communication time series sequence, and fuse the decomposition results of different scales to obtain a reference communication time series sequence;

[0214] An abnormal acquisition module 203, configured to calculate the difference sequence between the communication time series sequence and the reference communication time series sequence, calculate the first-order difference sequence of the difference sequence and determine its slope, calculate the propagation rate of the difference sequence between network nodes, and determine abnormal communication data based on the slope and the propagation rate;

[0215] An abnormal analysis module 204, configured to determine persistent abnormal communication data according to the periodic characteristics of the abnormal communication data and its propagation order in network nodes, and use reverse time series recursive analysis to determine the starting node and propagation path of the persistent abnormal communication data;

[0216] A detection module 205, configured to input the abnormal data characteristics of the starting node and propagation path of the persistent abnormal communication data into an LSTM neural network model to predict subsequent abnormal nodes in the communication time series sequence.

[0217] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless network. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0218] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only one way, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0219] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0220] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0221] Some of the data in the above formula are taken as numerical values after removing the dimension. The formula is obtained by software simulation of a large amount of collected data, which is the formula closest to the actual situation. The preset parameters and preset thresholds in the formula are set by those skilled in the art according to the actual situation or obtained through simulation of a large amount of data.

[0222] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A communication dynamic analysis method for virtual network security, characterized in that Including: The server node collects the communication node identifiers, the data packet transmission interval time, and the interaction duration among virtual machines, reconstructs the communication data based on the joint probability distribution of the transmission interval and the duration, and obtains the communication time series sequence. Perform multi-scale decomposition on the communication time series sequence, and fuse the decomposition results of different scales to obtain the benchmark communication time series sequence. Calculate the difference sequence between the communication time series sequence and the benchmark communication time series sequence, calculate the first-order difference sequence of the difference sequence and determine its slope, calculate the propagation rate of the difference sequence among network nodes, and determine the abnormal communication data based on the slope and the propagation rate. Determine the continuous abnormal communication data according to the periodic characteristics of the abnormal communication data and its propagation order among network nodes, and use reverse time series recursive analysis to determine the starting node and propagation path of the continuous abnormal communication data. Input the abnormal data characteristics of the starting node and propagation path of the continuous abnormal communication data into the LSTM neural network model to predict the subsequent abnormal nodes in the communication time series sequence.

2. The communication dynamic analysis method for virtual network security according to claim 1, characterized in that, The reconstructing of the communication data based on the joint probability distribution of the transmission interval and the duration includes: Statistical the occurrence frequencies of the data packet transmission interval time and the interaction duration in the original communication data, and calculate the joint probability of the transmission interval and the interaction duration according to the occurrence frequencies. According to the joint probability, construct a two-dimensional probability distribution matrix with the transmission interval as the vertical axis and the interaction duration as the horizontal axis. According to the probability density change characteristics of the two-dimensional probability distribution matrix, determine the effective data region where the probability density is higher than the average probability density. According to the effective data region, select the original communication data falling into the effective data region, reconstruct the communication data and form a communication time series sequence.

3. The communication dynamic analysis method for virtual network security according to claim 2, wherein The method of performing multi-scale decomposition on the communication time series sequence and fusing the decomposition results of different scales includes: Perform discrete wavelet transform on the communication time series sequence to obtain multi-scale approximation coefficient sequences and detail coefficient sequences. Calculate the variance of each scale detail coefficient sequence respectively, sort according to the variance size and determine the detail coefficient sequence of the main scale. Use the determined detail coefficient sequence of the main scale and the corresponding approximation coefficient sequence to perform inverse wavelet transform to reconstruct the time domain component sequences of different scales respectively. According to the reconstructed time domain component sequences of different scales, fuse them into a benchmark communication time series sequence by weighted superposition.

4. The communication dynamic analysis method for virtual network security according to claim 3, wherein Calculating the first-order difference sequence of the difference sequence and determining its slope includes: Based on the obtained difference sequence, explicitly calculate its first-order difference sequence : , ; In the formula: is the difference between adjacent data points of the difference sequence; and is the difference between two consecutive data points of the difference sequence, and the length of the first-order difference sequence is n - 1; For the first-order difference sequence perform linear regression to calculate its slope, and the specific formula for slope calculation is clearly defined as: ; Where: is the slope of the first-order difference sequence, and i is the sequence index, , is the arithmetic mean of the first-order difference sequence.

5. A communication dynamic analysis method for virtual network security according to claim 4, characterized in that, The determining of the abnormal communication data based on the slope and the propagation rate includes: The preset slope threshold is , and under normal circumstances, the data propagation rate threshold is ; For the calculated slope and propagation rate , make a comparison and judgment: When the absolute value of the slope and , the corresponding communication data is marked as abnormal communication data; Otherwise, do not mark the corresponding communication data as abnormal communication data.

6. A communication dynamic analysis method for virtual network security according to claim 5, characterized in that The method for obtaining the periodic characteristics of the abnormal communication data includes: Perform discrete Fourier transform on the data amplitude sequence of the abnormal communication data to obtain the corresponding frequency domain sequence. Specifically, the data amplitude sequence of the abnormal communication data is ; where represents the difference amplitude of the i-th abnormal data point relative to the reference communication sequence; n is the length of the abnormal communication data sequence; Specifically, the calculation formula for performing discrete Fourier transform on the data amplitude sequence is as follows: ; In the formula: represents the Fourier transform result of the k-th frequency component, that is, the amplitude value of the k-th frequency component, is the imaginary unit, and , the sequence length n is the number of sampling points of the discrete Fourier transform; Calculate the power spectral density values of each frequency component in the frequency domain sequence, and sort them from high to low according to the numerical values. Among them, the power spectral density value calculation formula is: ; Where: is the power spectral density corresponding to the k-th frequency component, is the conjugate complex number of the k-th frequency component, is the amplitude value of the k-th frequency component; Determine the dominant frequency component as the frequency component ranked first after sorting. Calculate the period length according to the frequency value corresponding to the dominant frequency component, and determine the period length as the period feature of the abnormal communication data; Among them, the formula for calculating the period length is: ; In the formula: represents the cycle length of the abnormal communication data, is the frequency value corresponding to the dominant frequency component.

7. A communication dynamic analysis method for virtual network security according to claim 6, characterized in that, The method for obtaining the propagation order is as follows: Record the timestamps when each node in the network detects abnormal communication data; According to the timestamps when each node detects abnormal communication data, sort the nodes in ascending order of the timestamp values; According to the sorted node order and the network topology connection relationship between the nodes, determine the propagation order of the abnormal communication data in the network nodes, and output the determined propagation order.

8. A communication dynamic analysis method for virtual network security according to claim 7, characterized in that The determination of the starting node and propagation path of the continuous abnormal communication data includes: According to the propagation order of the continuous abnormal communication data in the network nodes, determine the last node in the propagation order as the initial backtracking node; According to the network topology connection relationship, starting from the initial backtracking node, determine the previous node that is directly connected to it and is before this node in the propagation order; Use the determined previous node as the new backtracking node, repeat the process of determining the previous node, and backtrack step by step in reverse until the first node in the propagation order is determined, and determine this node as the starting node of the continuous abnormal communication data; According to the connection relationship between the nodes determined in the above reverse backtracking process, determine the complete propagation path of the continuous abnormal communication data from the starting node to the initial backtracking node, and output the starting node and propagation path of the continuous abnormal communication data.

9. A communication dynamic analysis method for virtual network security according to claim 8, characterized in that The prediction of subsequent abnormal nodes in the communication time series sequence includes: According to the abnormal data characteristics of the starting node and propagation path of the continuous abnormal communication data, construct an abnormal feature sequence for the abnormal propagation of communication nodes; Input the abnormal feature sequence into the LSTM neural network model to predict the occurrence probability of abnormal communication data of each node at the next moment; Determine the nodes with the predicted abnormal occurrence probability exceeding the preset probability threshold as subsequent abnormal nodes, and output the determined subsequent abnormal nodes.

10. A communication dynamic analysis system for virtual network security, which is implemented based on the communication dynamic analysis method for virtual network security described in any one of claims 1-9, characterized in that Including: An acquisition module, which is used for the server node to collect the communication node identifiers between virtual machines, the packet transmission interval time and the interaction duration, and reconstruct the communication data based on the joint probability distribution of the transmission interval and the duration to obtain the communication time series sequence; A decomposition module, which is used to perform multi-scale decomposition on the communication time series sequence and fuse the decomposition results of different scales to obtain a reference communication time series sequence; An abnormal acquisition module, which is used to calculate the difference sequence between the communication time series sequence and the reference communication time series sequence, calculate the first-order difference sequence of the difference sequence and determine its slope, calculate the propagation rate of the difference sequence between network nodes, and determine abnormal communication data based on the slope and the propagation rate; An abnormal analysis module, which is used to determine continuous abnormal communication data according to the period feature of the abnormal communication data and its propagation order in the network nodes, and use reverse time series recursive analysis to determine the starting node and propagation path of the continuous abnormal communication data; A detection module, configured to input the starting node of the continuous abnormal communication data and the abnormal data features of the propagation path into an LSTM neural network model to predict subsequent abnormal nodes in the communication time series.

Citation Information

Patent Citations

  • Cloud virtual machine load prediction method based on multi-scale analysis and deep network model

    CN114064203A

  • Intelligent monitoring system for time sequence index abnormity in large-scale cloud network environment

    CN115454778A

  • Micro-service flow abnormity monitoring method and device based on traffic data

    CN119211002A

  • Intelligent runoff pollution monitoring and responding method and system

    CN119642902A

  • Communication equipment anomaly detection method based on channel attention and frequency domain analysis

    CN120067805A

Cited By

  • Storage cabinet abnormal trend prediction system based on time series data analysis

    CN121580256A

  • Communication data security analysis processing method and system, and storage medium

    CN122001683A

  • A communication data security analysis processing method and system, and a storage medium

    CN122001683B