Network security analysis method and device, equipment and medium
By building a device relationship map and relevance mining access information characteristics, the problem of low reliability of network security analysis in traditional methods is solved, and in-depth analysis of complex network environments and efficient threat detection are achieved.
Patent Information
- Application Number
- CN202510714108.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-05
AI Technical Summary
In the prior art, in home or enterprise networks, security analysis methods based on network traffic are difficult to ensure the reliability of the analysis. Especially in FTTR systems, when facing complex relationships between devices, traditional methods are difficult to effectively deal with new and unknown threats.
By building a device relationship map, based on the operation log of the target network device, determine the traffic mode and connection relationship of the access device, perform association mining, output target access information characteristics, conduct network security analysis, and output target security analysis results.
It improves the detection capabilities of new attack methods, covert attacks and complex attack chains, enhances the reliability of network security analysis, and adapts to more complex and dynamic network environments.
Smart Images

Figure CN120434026A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a network security analysis method and apparatus, device, and medium. Background Art
[0002] With the rapid development of information technology, network security issues have become an increasing global concern, facing increasingly complex and diverse threats. Traditional network security protection typically focuses on analysis based on network traffic. However, with the increasing number of devices and the increasing complexity of network topologies, traditional security analysis methods often suffer from insufficient analytical accuracy and an inability to effectively address complex inter-device relationships. This is especially true in FTTR (Fiber to the Room) systems based on home or enterprise networks, where access devices may be numerous. Simple comparative analysis based on network traffic makes it difficult to ensure reliable network security analysis. Summary of the Invention
[0003] In view of this, the purpose of this application is to provide a network security analysis method and apparatus, equipment and medium to improve the problem of relatively low reliability of network security analysis in the prior art.
[0004] To achieve the above objectives, this application adopts the following technical solutions: A network security analysis method, comprising: Based on the operation log of the target network device, construct a device relationship map corresponding to the target network device, wherein each access device in the device relationship map belongs to a device that accesses the network through the target network device, and two access devices that have a connection relationship in the device relationship map have a correlation relationship; Based on the device access information corresponding to other access devices in the device relationship graph, performing association mining on the device access information corresponding to the target access device, and outputting target access information features, wherein the device access information is used to characterize the traffic pattern of the corresponding access device; Based on the target access information characteristics, a network security analysis is performed on the target access device, and a target security analysis result is output, wherein the target security analysis result is used to characterize the type of access behavior of the target access device.
[0005] In a preferred embodiment of the present application, in the above-mentioned network security analysis method, the step of constructing a device relationship map corresponding to the target network device based on the operation log of the target network device includes: Determining device access information corresponding to each access device based on the target network device's operation log, wherein the device access information represents a traffic pattern including access request frequency, access request size, and access request address; For each pair of access devices, determining whether the device access information corresponding to the two access devices is correlated, and if the corresponding device access information is correlated, determining the two access devices as having a correlation, wherein the correlation between the device access information at least includes accessing the same access request address within the same time interval and / or having similar access request frequencies and access request sizes within the same time interval; Connect access devices with related relationships to form a device relationship map.
[0006] In a preferred embodiment of the present application, in the above-mentioned network security analysis method, the step of performing association mining on the device access information corresponding to the target access device based on the device access information corresponding to other access devices in the device relationship graph and outputting the target access information features includes: Performing feature space mapping on the device access information corresponding to each access device in the device relationship graph, and outputting the device access mapping feature corresponding to each access device; If there are no other access devices having a relevant relationship with the target access device in the device relationship graph, then performing multiple-level deep mining on the device access features corresponding to the target access device, and outputting the device access depth features corresponding to each level; If there are other access devices that have a correlation with the target access device in the device relationship graph, the device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining, and in the process of deep mining at each level, the device access mapping features corresponding to other access devices are integrated to output the device access deep features corresponding to each level; Based on the device access depth features at each level, the target access information features are output.
[0007] In a preferred embodiment of the present application, in the above-mentioned network security analysis method, if there are other access devices having a correlation with the target access device in the device relationship map, the device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining, and in the deep mining process of each level, the device access mapping features corresponding to the other access devices are integrated to output the device access deep features corresponding to each level, including: If there are other access devices having a correlation with the target access device in the device relationship map, each of the other access devices having a correlation with the target access device is determined as a related access device corresponding to the target access device; Transferring the device access mapping features corresponding to the target access device and other access devices other than the relevant access device in the device relationship graph to the device access mapping features corresponding to the relevant access device to form a device access transfer feature corresponding to the relevant access device; The device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining, and in the deep mining process of each level, the device access transfer features corresponding to each of the related access devices are integrated to output the device access depth features corresponding to each level.
[0008] In a preferred embodiment of the present application, in the above-mentioned network security analysis method, the step of transferring the device access mapping features corresponding to the target access device and other access devices other than the relevant access device in the device relationship graph to the device access mapping features corresponding to the relevant access device to form the device access transfer features corresponding to the relevant access device includes: In the device relationship graph, determining each other access device having a maximum connection parameter with the target access device to obtain at least one candidate access device, wherein the connection parameter is used to represent the length of the shortest traversal path between the device and the target access device; performing clustering processing on the at least one candidate access device to form a corresponding central access device, and fusing at least one device access mapping feature corresponding to the at least one candidate access device into the device access mapping feature corresponding to the central access device to form a device access fusion feature corresponding to the central access device; For each of the related access devices, when there is a traversal path between the related access device and the central access device that does not include the target access device and other related access devices, the device access mapping feature corresponding to the related access device is determined as the corresponding device access transfer feature. When there is a traversal path between the related access device and the central access device that does not include the target access device and other related access devices, along the corresponding shortest traversal path, in the direction from the central access device to the related access device, the device access fusion feature corresponding to the central access device is sequentially transferred to the device access mapping feature corresponding to the related access device to form a corresponding device access transfer feature.
[0009] In a preferred embodiment of the present application, in the above-mentioned network security analysis method, the device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining, and in the deep mining process of each level, the device access transfer features corresponding to each of the related access devices are integrated to output the device access deep features corresponding to each level, including: Based on the similarity between the device access transfer feature corresponding to each of the related access devices and the device access mapping feature corresponding to the target access device, traversing the related access devices in ascending order of similarity to form the currently traversed related access devices; Based on the number of current traversals, perform feature compression on the device access transfer characteristics corresponding to the currently traversed related access devices a corresponding number of times to form a corresponding first access compression feature; The device access depth feature corresponding to the previous level is subjected to feature compression processing to form a corresponding second access compression feature, and, based on the first access compression feature corresponding to the currently traversed related access device, the second access compression feature is subjected to related feature mining to output the device access depth feature corresponding to the current level, wherein the device access depth feature corresponding to the 0th level is the device access mapping feature corresponding to the target access device.
[0010] In a preferred embodiment of the present invention, in the above network security analysis method, the network security analysis method further includes: Performing feature space mapping on the sample device access information corresponding to each sample access device in the sample device relationship graph through a spatial mapping unit in the candidate analysis network, and outputting a sample device access mapping feature corresponding to each sample access device, wherein the candidate analysis network further includes a first deep mining unit, a second deep mining unit, and an analysis output unit; If there are no other sample access devices having a correlation with the target sample access device in the sample device relationship graph, performing multiple-level deep mining on the sample device access features corresponding to the target sample access device by the first deep mining unit, and outputting the sample device access deep features corresponding to each level; If there are other sample access devices having a correlation with the target sample access device in the sample device relationship map, the second deep mining unit performs multiple levels of deep mining on the sample device access mapping features corresponding to the target sample access device, and in the deep mining process of each level, the sample device access mapping features corresponding to other sample access devices are integrated to output the sample device access deep features corresponding to each level; Outputting target sample access information features based on the sample device access depth features at each level through the analysis output unit, and performing network security analysis on the target sample access device based on the target sample access information features, and outputting sample security analysis results; Based on the error between the sample security analysis result and the corresponding network security label, the candidate analysis network is updated to form a target analysis network.
[0011] This application also provides a network security analysis device, comprising: A graph construction module is configured to construct a device relationship graph corresponding to the target network device based on the operation log of the target network device, wherein each access device in the device relationship graph belongs to a device that performs network access through the target network device, and two access devices that have a connection relationship in the device relationship graph have a correlation relationship; an association mining module for performing association mining on the device access information corresponding to the target access device based on the device access information corresponding to other access devices in the device relationship graph, and outputting target access information features, wherein the device access information is used to characterize the traffic pattern of the corresponding access device; The security analysis module is used to perform network security analysis on the target access device based on the target access information characteristics and output a target security analysis result, wherein the target security analysis result is used to characterize the type of access behavior of the target access device.
[0012] Based on the above, the present application further provides an electronic device, including: memory for storing computer programs; The processor connected to the memory is used to execute the computer program stored in the memory to implement the above-mentioned network security analysis method.
[0013] On the basis of the above, the present application also provides a computer-readable storage medium, which stores a computer program, and when the computer program is run, it executes the various steps of the above-mentioned network security analysis method.
[0014] The network security analysis method, apparatus, device, and medium provided by the present application first construct a corresponding device relationship map based on the operation log of the target network device; secondly, based on the device access information corresponding to other access devices in the device relationship map, the device access information corresponding to the target access device is associated with mining, and the target access information characteristics are output; then, based on the target access information characteristics, a network security analysis is performed on the target access device, and the target security analysis results are output. Based on the above content, complex abnormal behaviors can be deeply analyzed (capturing the potential semantics in the device access information) through association mining and feature analysis of device access information, adapting to more complex and dynamic network environments. Traditional security analysis methods often rely on rule libraries or known attack patterns for detection, and are difficult to cope with new and unknown threats. Therefore, the comprehensive security analysis method provided by the present application can effectively improve the detection capabilities of new attack methods, covert attacks, and complex attack chains, enhance the reliability of network security analysis, and thus improve the relatively low reliability of network security analysis in the existing technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings.
[0016] Figure 1 This is a structural block diagram of the electronic device provided in an embodiment of the present application.
[0017] Figure 2 A flowchart of the network security analysis method provided in an embodiment of the present application.
[0018] Figure 3 A schematic diagram of the device relationship map provided in an embodiment of the present application.
[0019] Figure 4 A schematic diagram of multiple levels of deep mining and fusion provided in an embodiment of the present application.
[0020] Figure 5 A block diagram of a network security analysis device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0022] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0023] like Figure 1 As shown, an embodiment of the present application provides an electronic device, wherein the electronic device may include a memory, a processor, and a network security analysis device.
[0024] Specifically, the memory and the processor are directly or indirectly electrically connected to enable data transmission or interaction. For example, the memory and the processor may be electrically connected via one or more communication buses or signal lines. The network security analysis device includes at least one software function module stored in the memory in the form of software or firmware. The processor is configured to execute an executable computer program stored in the memory, such as the software function module and computer program included in the network security analysis device, to implement the network security analysis method provided in the embodiments of the present application.
[0025] Optionally, the memory may be, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.
[0026] Furthermore, the processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), a system on chip (SoC), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0027] I understand. Figure 1 The structure shown is only for illustration, and the electronic device may also include Figure 1 More or fewer components than shown, or with Figure 1 The different configurations shown may, for example, further include a communication unit for exchanging information with other devices.
[0028] Combine Figure 2 , the embodiment of the present application also provides a network security analysis method applicable to the above electronic device. Among them, the method steps defined in the process related to the network security analysis method can be implemented by the electronic device. Figure 2 The specific process shown is explained in detail.
[0029] Step S110: constructing a device relationship graph corresponding to the target network device based on the operation log of the target network device.
[0030] In an embodiment of the present application, the electronic device can construct a device relationship map corresponding to the target network device based on the target network device's operation log (which may include device access information for each access device). Each access device in the device relationship map is a device that accesses the network through the target network device, and two access devices that are connected in the device relationship map have a correlation relationship. Furthermore, the specific application scenario of the target network device can be FTTR-B (Business FTTR), an all-optical networking solution for businesses and enterprises, a Wi-Fi solution specifically designed for businesses. Utilizing an all-optical networking solution combining fiber access, optical fiber composite cable, and Wi-Fi 6, Wi-Fi coverage is extended to every corner of the enterprise, providing network services for employees' online work, such as live broadcasts and online meetings. Furthermore, the target network device can also be used to provide IPTV (Internet Protocol Television) services.
[0031] Step S120 , based on the device access information corresponding to other access devices in the device relationship graph, perform association mining on the device access information corresponding to the target access device, and output target access information features.
[0032] In an embodiment of the present application, after constructing the device relationship graph, the electronic device can perform correlation mining on the device access information corresponding to the target access device (which can be any access device) based on the device access information corresponding to other access devices in the device relationship graph, and output the target access information characteristics. The device access information is used to characterize the traffic pattern of the corresponding access device. In other words, it is necessary not only to mine the potential semantic information in the traffic pattern of the target access device, but also to combine the potential semantic information in the traffic patterns of other access devices to make the semantic representation ability of the target access information characteristics better.
[0033] Step S130: Perform network security analysis on the target access device based on the target access information characteristics, and output a target security analysis result.
[0034] In an embodiment of the present application, after mining the target access information features, the electronic device can perform a network security analysis on the target access device based on the target access information features and output a target security analysis result. The target security analysis result is used to characterize the type of access behavior of the target access device, such as normal traffic, DDoS attack, port scan, malware propagation, and brute force attack. For example, the target access information features can be fully connected to obtain corresponding fully connected features. For example, when the output result includes 5 types, the fully connected feature can be a 1*5 vector. Then, the fully connected feature can be mapped by a classification function such as softmax to form a corresponding probability distribution. The size of the probability distribution is also 1*5, such as (probability of normal traffic, probability of DDoS attack, probability of port scan, probability of malware propagation, probability of brute force attack). In this way, the type corresponding to the probability with the maximum value can be determined as the target security analysis result.
[0035] Based on the above content, through association mining and feature analysis of device access information, complex abnormal behaviors can be deeply analyzed (capturing the potential semantics in device access information) to adapt to more complex and dynamic network environments. Traditional security analysis methods often rely on rule bases or known attack patterns for detection, and are difficult to deal with new and unknown threats. Therefore, the comprehensive security analysis method provided by this application can effectively improve the detection capabilities of new attack methods, covert attacks and complex attack chains, enhance the reliability of network security analysis, and thus improve the relatively low reliability of network security analysis in the existing technology.
[0036] First, it should be noted that for step S110 , the specific method of constructing the device relationship map corresponding to the target network device is not limited and can be selected according to actual needs.
[0037] For example, in an alternative embodiment, in order to improve the reliability of the constructed device relationship map, considering that traffic patterns have a high degree of influence on the determination results of the types of access behaviors such as normal traffic, DDoS attacks, port scans, malware propagation, and brute force attacks, based on this, the above-mentioned step S110 may further include the following sub-steps: First, based on the target network device's operation logs, the device access information corresponding to each access device can be determined. The traffic pattern represented by the device access information includes access request frequency (e.g., approximately 1,000 requests per day, with an average interval of 1 second between requests), access request size (e.g., request size is stable, with an average request size of 50KB), and access request addresses (e.g., most requests are concentrated on one or a few fixed server IP addresses, indicating normal interaction between the device and known services). Secondly, for each pair of access devices, determining whether the device access information corresponding to the two access devices is correlated, and if so, determining the two access devices as having a correlation, where the device access information being correlated at least includes accessing the same access request address within the same time interval and / or having similar access request frequencies and access request sizes within the same time interval (similarity may mean that the difference between the corresponding parameters is less than a corresponding threshold, which can be configured as needed); Then, the access devices with related relationships can be connected to form a device relationship map.
[0038] For example: For possible normal traffic: the daily HTTP request frequency is roughly stable, with approximately 1,000 requests sent per day and an average interval of 1 second between each request. The request size is stable, with an average request size of 50KB. Most requests are concentrated on one or a few fixed server IP addresses, reflecting normal interaction between the device and known services. That is: "request_count": 1000; "average_request_interval": 1s; "average_request_size": 50KB; "target_ip_count": 3; "target_ips": [192.168.1.10, 192.168.1.11, 192.168.1.12]; Possible DDoS attack patterns: A sharp increase in HTTP requests, reaching 1,000 requests per second, persists for more than a few minutes; each HTTP request is between 200KB and 500KB in size, significantly larger than the normal 50KB; and requests are no longer concentrated on a few fixed IP addresses but are distributed to a large number of different IP addresses (e.g., more than 100). This indicates that the device is conducting a distributed denial of service (DDoS) attack, namely: "request_count": 60000; "average_request_interval": 0.01s; "average_request_size": 300KB; "target_ip_count": 150; "target_ips": [203.0.113.1, 203.0.113.2, 203.0.113.3, ..., 203.0.113.100]; For possible port scanning: Frequently sending a large number of small HTTP requests to a large number of different IP addresses, with an interval of several hundred milliseconds between each request; each request is small, about 10KB; the requests are distributed to a large number of IP addresses (such as hundreds of IP addresses), and the ports and protocol types of these IP addresses vary. This may indicate that the device is performing a port scan, that is: "request_count": 5000; "average_request_interval": 0.5s; "average_request_size": 10KB; "target_ip_count": 300; "target_ips": [192.168.1.10, 192.168.1.11, 203.0.113.1, 203.0.113.2, ..., 203.0.113.300]; For possible malware dissemination: the frequency of HTTP requests sent suddenly increases, reaching 10 requests per second for several hours; the request size is between 50KB and 100KB, which is within the normal range, but the sudden change in the request pattern is noteworthy; the requests are distributed across multiple IP addresses, and the target IP addresses have a suspicious geographic distribution, such as distribution across multiple countries or data centers, indicating that the device may be disseminating malware or conducting other forms of attack, namely: "request_count": 36000; "average_request_interval": 0.1s; "average_request_size": 75KB; "target_ip_count": 50; "target_ips": [185.0.113.1, 185.0.113.2, 200.0.113.3, 200.0.113.4, ..., 200.0.113.50]; Possible brute force attacks: dozens of HTTP requests are sent per second with extremely short intervals, typically less than 1 second. Each HTTP request is small, approximately 5KB, which is typical of brute force requests. Requests are concentrated on a few specific target IP addresses, typically different login pages of the same web application, indicating that the device is conducting a brute force attack. Specifically: "request_count": 3000; "average_request_interval": 0.05s; "average_request_size": 5KB; "target_ip_count": 2; "target_ips": [192.168.1.20, 192.168.1.21].
[0039] Secondly, it should be noted that for step S120 , the specific method of performing association mining on the device access information corresponding to the target access device is not limited and can be selected according to actual needs.
[0040] For example, in an alternative embodiment, in order to fully integrate device access information through association mining, thereby ensuring that the semantic information represented by the obtained target access information features has a high degree of reliability, the above-mentioned step S120 can further include step S121, step S122, step S123 and step S124, and the specific content of each step is as follows.
[0041] Step S121 , performing feature space mapping on the device access information corresponding to each access device in the device relationship graph, and outputting the device access mapping feature corresponding to each access device.
[0042] In an embodiment of the present application, feature space mapping can be performed on the device access information corresponding to each access device in the device relationship graph, and the device access mapping features corresponding to each access device can be output. For example, a word embedding model can be used to perform word embedding processing on the device access information to obtain corresponding embedded features as the corresponding device access mapping features.
[0043] Step S122: If there are no other access devices related to the target access device in the device relationship graph, perform multiple-level deep mining on the device access features corresponding to the target access device, and output the device access depth features corresponding to each level.
[0044] In an embodiment of the present application, after obtaining the device access mapping features, if no other access devices related to the target access device exist in the device relationship graph, multiple levels of deep mining are performed on the device access features corresponding to the target access device, and the device access deep features corresponding to each level are output. In other words, if there are no other related access devices, fusion is not performed to avoid introducing interference information, which may lead to low semantic accuracy of the obtained target access information features. In addition, for example, in the first level of deep mining, the device access features can be first processed by convolution and / or pooling to achieve feature compression and extract high-level semantic features. Then, the high-level semantic features can be self-attention processed to obtain the first level of device access depth features. For the subsequent levels of deep mining, the device access depth features of the previous level can be convolution and / or pooling processed to achieve feature compression and extract high-level semantic features. Then, the high-level semantic features can be self-attention processed to obtain the current level of device access depth features. Based on this, the depth of the device access depth features can be gradually increased to ensure the reliability of semantic mining.
[0045] Step S123: If there are other access devices in the device relationship map that have a relevant relationship with the target access device, the device access mapping features corresponding to the target access device are deeply mined at multiple levels, and in the deep mining process of each level, the device access mapping features corresponding to other access devices are integrated to output the device access depth features corresponding to each level.
[0046] In an embodiment of the present application, after obtaining the device access mapping features, if other access devices with a correlation with the target access device exist in the device relationship graph, the device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining. During each level of deep mining, the device access mapping features corresponding to the other access devices are integrated to output the device access deep features corresponding to each level. This allows for both level-by-level mining of high-level semantic features and integration of other relevant semantic information.
[0047] Step S124: outputting target access information features based on the device access depth features at each level.
[0048] In an embodiment of the present application, after obtaining the device access depth features of each level, the target access information features can be output based on the device access depth features of each level. For example, in an alternative embodiment, the device access depth features of the last level can be directly used as the target access information features. For another example, in another alternative embodiment, the device access depth features of each level can be expanded, and then the expanded features can be spliced, and then the spliced features can be processed by convolution or the like to obtain the target access information features. For another example, in another alternative embodiment, the device access depth features of other levels can be interpolated to obtain interpolated features of the same size as the device access depth features of the first level, and then the interpolated features and the device access depth features of the first level can be added or averaged to obtain the target access information features.
[0049] It can be understood that in the above-mentioned step S123, the specific method of performing multiple levels of deep mining on the device access mapping features corresponding to the target access device is not limited. For example, in an alternative embodiment, in order to achieve reliable fusion of relevant semantic information in the process of deep mining, the above-mentioned step S123 can further include step S123a, step S123b and step S123c. The specific content of each step is as follows.
[0050] Step S123a: If there are other access devices having a correlation with the target access device in the device relationship map, each other access device having a correlation with the target access device is determined as a related access device corresponding to the target access device.
[0051] In an embodiment of the present application, if there are other access devices that have a relevant relationship with the target access device in the device relationship map, each other access device that has a relevant relationship with the target access device will be determined as a relevant access device corresponding to the target access device, that is, the directly connected access device will be determined as the relevant access device.
[0052] Step S123b: transfer the device access mapping features corresponding to the target access device and other access devices other than the related access device in the device relationship map to the device access mapping features corresponding to the related access device to form the device access transfer features corresponding to the related access device.
[0053] In an embodiment of the present application, the device access mapping features corresponding to the target access device and other access devices other than the relevant access device in the device relationship graph can be transferred to the device access mapping features corresponding to the relevant access device to form the device access transfer features corresponding to the relevant access device. In other words, the device access mapping features of the other access devices other than the relevant access device can be transferred to the relevant access device first. This avoids the problem of low reliability of feature transfer when directly transferring the device access mapping features of the other access devices to the target access device due to low correlation.
[0054] Step S123c, performing multiple levels of deep mining on the device access mapping features corresponding to the target access device, and in the deep mining process of each level, integrating the device access transfer features corresponding to each of the related access devices, and outputting the device access depth features corresponding to each level.
[0055] In an embodiment of the present application, after feature transfer is performed to obtain the corresponding device access transfer feature, the device access mapping feature corresponding to the target access device is deeply mined at multiple levels, and in the deep mining process of each level, the device access transfer feature corresponding to each of the related access devices is integrated to output the device access depth feature corresponding to each level.
[0056] It is understood that in the above step S123b, the specific manner of performing feature transfer is not limited. For example, in an alternative embodiment, in order to ensure the reliability of feature transfer while also ensuring the efficiency of feature transfer and reducing the amount of computation, the above step S123b may further include the following sub-steps: First, in the device relationship graph, each other access device with the maximum connection parameter to the target access device can be determined to obtain at least one candidate access device, wherein the connection parameter is used to characterize the length of the shortest traversal path to the target access device, that is, the length of the shortest traversal path between the candidate access device and the target access device has the maximum value, which can also be understood as the minimum degree of correlation between the candidate access device and the target access device, such as Figure 3 Access device 9, access device 10 and access device 11; Secondly, clustering is performed on the at least one candidate access device to form a corresponding central access device (only one central access device may be determined, such as access device 9), and at least one device access mapping feature corresponding to the at least one candidate access device is fused into the device access mapping feature corresponding to the central access device to form a device access fusion feature corresponding to the central access device. For example, a mean feature of the at least one device access mapping feature corresponding to the at least one candidate access device may be calculated, and then the mean feature is added to the device access mapping feature corresponding to the central access device to obtain a corresponding device access fusion feature. Then, for each of the related access devices, when there is no traversal path between the related access device and the central access device that does not include the target access device and other related access devices (such as related access device 1), the device access mapping feature corresponding to the related access device is determined as the corresponding device access transfer feature, and when there is a traversal path between the related access device and the central access device that does not include the target access device and other related access devices (such as related access device 2, related access device 3 and related access device 4), along the corresponding shortest traversal path, in the direction from the central access device to the related access device, the device access fusion feature corresponding to the central access device is sequentially transferred to the device access mapping feature corresponding to the related access device to form a corresponding device access transfer feature, wherein the feature transfer process can be achieved by cross-attention, for example, in Figure 3 In the figure, based on the device access fusion feature corresponding to the access device 9, the device access mapping feature corresponding to the access device 6 is cross-attention processed to obtain the corresponding cross-attention feature. Then, based on the cross-attention feature, the device access mapping feature corresponding to the relevant access device 2 is cross-attention processed to form the device access transfer feature corresponding to the relevant access device 2. The device access transfer features corresponding to the relevant access device 3 and the relevant access device 4 are formed in the same way and will not be described one by one here.
[0057] It is understandable that, in the above step S123c, the specific manner of fusing the device access transfer features corresponding to each of the related access devices is not limited. For example, in an alternative embodiment, in order to achieve sequential fusion of the device access transfer features of each of the related access devices in a multi-level deep mining process to avoid semantic explosion or distortion problems, the above step S123c may further include the following: First, based on the similarity between the device access transfer feature corresponding to each of the related access devices and the device access mapping feature corresponding to the target access device, the related access devices may be traversed in ascending order of similarity to form the currently traversed related access devices, i.e., the first traversed related access device has the smallest similarity. Secondly, based on the number of current traversals, feature compression can be performed a corresponding number of times on the device access transfer characteristics corresponding to the currently traversed related access device to form a corresponding first access compression feature. For example, for the first traversed related access device, feature compression can be performed once on the corresponding device access transfer feature (one feature compression can be achieved through convolution and / or pooling), for the second traversed related access device, feature compression can be performed twice on the corresponding device access transfer feature, for the third traversed related access device, feature compression can be performed three times on the corresponding device access transfer feature, and so on. Then, the device access depth feature corresponding to the previous level can be subjected to feature compression processing to form a corresponding second access compression feature, and, based on the first access compression feature corresponding to the currently traversed related access device, the second access compression feature can be subjected to related feature mining to output the device access depth feature corresponding to the current level. For example, the second access compression feature can be subjected to cross-attention processing based on the first access compression feature to obtain the corresponding cross-attention feature. Then, the cross-attention feature and the second access compression feature can be added to obtain the corresponding device access depth feature, wherein the device access depth feature corresponding to the 0th level is the device access mapping feature corresponding to the target access device, such as Figure 4 shown.
[0058] Thirdly, it should be noted that steps S120 and S130 can be implemented by a trained neural network (i.e., a trained target analysis network). The training process of the neural network is as follows: First, a spatial mapping unit in the candidate analysis network can be used to perform feature space mapping on the sample device access information corresponding to each sample access device in the sample device relationship graph, and output the sample device access mapping features corresponding to each sample access device. The candidate analysis network further includes a first deep mining unit, a second deep mining unit, and an analysis output unit. In addition, the feature space mapping process is as described above. Secondly, if there are no other sample access devices having a correlation with the target sample access device in the sample device relationship graph, the first deep mining unit performs multiple levels of deep mining on the sample device access features corresponding to the target sample access device, and outputs the sample device access deep features corresponding to each level, as described above. Then, if there are other sample access devices that have a correlation with the target sample access device in the sample device relationship graph, the second deep mining unit performs multiple levels of deep mining on the sample device access mapping features corresponding to the target sample access device, and in the deep mining process of each level, the sample device access mapping features corresponding to other sample access devices are integrated to output the sample device access deep features corresponding to each level, as described above. Furthermore, the analysis output unit may output target sample access information features based on the sample device access depth features at each level, and perform network security analysis on the target sample access device based on the target sample access information features, and output sample security analysis results, as described above. Finally, based on the error (such as cross entropy error, etc.) between the sample security analysis result and the corresponding network security label (i.e., the type of the corresponding access behavior), the candidate analysis network is updated to form a target analysis network. For example, the network parameters in the candidate analysis network are updated in the direction of reducing the error so that the error converges, thereby completing the training and obtaining the corresponding target analysis network (i.e., learning the mapping relationship between sample data and labels).
[0059] Combine Figure 5 The present application also provides a network security analysis device applicable to the above electronic device. The network security analysis device may include a graph construction module, an association mining module, and a security analysis module.
[0060] The graph construction module can be used to construct a device relationship graph corresponding to the target network device based on the operation log of the target network device, wherein each access device in the device relationship graph belongs to a device that accesses the network through the target network device, and there is a correlation relationship between two access devices that have a connection relationship in the device relationship graph. In the embodiment of the present application, the graph construction module can be used to execute Figure 2 As shown in step S110, for the relevant content of the graph construction module, reference can be made to the above description of step S110.
[0061] The association mining module can be used to perform association mining on the device access information corresponding to the target access device based on the device access information corresponding to other access devices in the device relationship graph, and output the target access information characteristics, wherein the device access information is used to characterize the traffic pattern of the corresponding access device. In the embodiment of the present application, the association mining module can be used to perform Figure 2 As shown in step S120, for the relevant content of the association mining module, reference may be made to the above description of step S120.
[0062] The security analysis module can be used to perform network security analysis on the target access device based on the target access information characteristics and output a target security analysis result, wherein the target security analysis result is used to characterize the type of access behavior of the target access device. In the embodiment of the present application, the security analysis module can be used to perform Figure 2 As shown in step S130, for the relevant content of the security analysis module, reference may be made to the above description of step S130.
[0063] In an embodiment of the present application, corresponding to the above-mentioned network security analysis method applied to the electronic device, a computer-readable storage medium is also provided, in which a computer program is stored. When the computer program is run, each step of the network security analysis method is executed.
[0064] Among them, the steps executed when the aforementioned computer program is running will not be described here one by one, and reference can be made to the above explanation of the network security analysis method.
[0065] In summary, the network security analysis method, apparatus, device, and medium provided by the present application first construct a corresponding device relationship map based on the operation log of the target network device; secondly, based on the device access information corresponding to other access devices in the device relationship map, the device access information corresponding to the target access device is associated with mining, and the target access information characteristics are output; then, based on the target access information characteristics, a network security analysis is performed on the target access device, and the target security analysis results are output. Based on the above, through association mining and feature analysis of device access information, complex abnormal behaviors can be deeply analyzed (capturing the potential semantics in the device access information), adapting to more complex and dynamic network environments. Traditional security analysis methods often rely on rule libraries or known attack patterns for detection, making it difficult to cope with new and unknown threats. Therefore, the comprehensive security analysis method provided by the present application can effectively improve the detection capabilities of new attack methods, covert attacks, and complex attack chains, enhance the reliability of network security analysis, and thus improve the relatively low reliability of network security analysis in the existing technology.
[0066] In the several embodiments provided in the embodiments of the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device and method embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0067] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0068] If the functions are implemented in the form of software modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, electronic device, or network device, etc.) to perform all or part of the steps of the methods described in each embodiment of this application. The aforementioned storage media include various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks. It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article, or device. Without further constraints, an element defined by the phrase "comprises a..." does not preclude the existence of additional identical elements in the process, method, article or apparatus that includes the element.
[0069] The above description is merely a preferred embodiment of the present application and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. A network security analysis method, characterized in that: include: Based on the operation log of the target network device, construct a device relationship map corresponding to the target network device, wherein each access device in the device relationship map belongs to a device that accesses the network through the target network device, and two access devices that have a connection relationship in the device relationship map have a correlation relationship; Based on the device access information corresponding to other access devices in the device relationship graph, performing association mining on the device access information corresponding to the target access device, and outputting target access information features, wherein the device access information is used to characterize the traffic pattern of the corresponding access device; Based on the target access information characteristics, a network security analysis is performed on the target access device, and a target security analysis result is output, wherein the target security analysis result is used to characterize the type of access behavior of the target access device.
2. The network security analysis method according to claim 1, characterized in that: The step of constructing a device relationship graph corresponding to the target network device based on the operation log of the target network device includes: Determining device access information corresponding to each access device based on the target network device's operation log, wherein the device access information represents a traffic pattern including access request frequency, access request size, and access request address; For each pair of access devices, determining whether the device access information corresponding to the two access devices is correlated, and if the corresponding device access information is correlated, determining the two access devices as having a correlation, wherein the correlation between the device access information at least includes accessing the same access request address within the same time interval and / or having similar access request frequencies and access request sizes within the same time interval; Connect access devices with related relationships to form a device relationship map.
3. The network security analysis method according to claim 1, characterized in that: The step of performing association mining on the device access information corresponding to the target access device based on the device access information corresponding to other access devices in the device relationship graph and outputting target access information features includes: Performing feature space mapping on the device access information corresponding to each access device in the device relationship graph, and outputting the device access mapping feature corresponding to each access device; If there are no other access devices having a relevant relationship with the target access device in the device relationship graph, then performing multiple-level deep mining on the device access features corresponding to the target access device, and outputting the device access depth features corresponding to each level; If there are other access devices that have a correlation with the target access device in the device relationship graph, the device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining, and in the process of deep mining at each level, the device access mapping features corresponding to other access devices are integrated to output the device access deep features corresponding to each level; Based on the device access depth features at each level, the target access information features are output.
4. The network security analysis method according to claim 3, characterized in that: If there are other access devices having a correlation with the target access device in the device relationship graph, the step of performing multiple levels of deep mining on the device access mapping features corresponding to the target access device, and fusing the device access mapping features corresponding to the other access devices in the deep mining process of each level to output the device access deep features corresponding to each level includes: If there are other access devices having a correlation with the target access device in the device relationship map, each of the other access devices having a correlation with the target access device is determined as a related access device corresponding to the target access device; Transferring the device access mapping features corresponding to the target access device and other access devices other than the relevant access device in the device relationship graph to the device access mapping features corresponding to the relevant access device to form a device access transfer feature corresponding to the relevant access device; The device access mapping features corresponding to the target access device are subjected to multiple levels of deep mining, and in the deep mining process of each level, the device access transfer features corresponding to each of the related access devices are integrated to output the device access depth features corresponding to each level.
5. The network security analysis method according to claim 4, characterized in that: The step of transferring the device access mapping features corresponding to the target access device and other access devices other than the relevant access device in the device relationship graph to the device access mapping features corresponding to the relevant access device to form the device access transfer features corresponding to the relevant access device includes: In the device relationship graph, determining each other access device having a maximum connection parameter with the target access device to obtain at least one candidate access device, wherein the connection parameter is used to represent the length of the shortest traversal path between the device and the target access device; performing clustering processing on the at least one candidate access device to form a corresponding central access device, and fusing at least one device access mapping feature corresponding to the at least one candidate access device into the device access mapping feature corresponding to the central access device to form a device access fusion feature corresponding to the central access device; For each of the related access devices, when there is a traversal path between the related access device and the central access device that does not include the target access device and other related access devices, the device access mapping feature corresponding to the related access device is determined as the corresponding device access transfer feature. When there is a traversal path between the related access device and the central access device that does not include the target access device and other related access devices, along the corresponding shortest traversal path, in the direction from the central access device to the related access device, the device access fusion feature corresponding to the central access device is sequentially transferred to the device access mapping feature corresponding to the related access device to form a corresponding device access transfer feature.
6. The network security analysis method according to claim 4, characterized in that: The step of performing multiple levels of deep mining on the device access mapping features corresponding to the target access device, and in the deep mining process of each level, fusing the device access transfer features corresponding to each of the related access devices to output the device access deep features corresponding to each level, includes: Based on the similarity between the device access transfer feature corresponding to each of the related access devices and the device access mapping feature corresponding to the target access device, traversing the related access devices in ascending order of similarity to form the currently traversed related access devices; Based on the number of current traversals, perform feature compression on the device access transfer characteristics corresponding to the currently traversed related access devices a corresponding number of times to form a corresponding first access compression feature; The device access depth feature corresponding to the previous level is subjected to feature compression processing to form a corresponding second access compression feature, and, based on the first access compression feature corresponding to the currently traversed related access device, the second access compression feature is subjected to related feature mining to output the device access depth feature corresponding to the current level, wherein the device access depth feature corresponding to the 0th level is the device access mapping feature corresponding to the target access device.
7. The network security analysis method according to any one of claims 1 to 6, characterized in that: The network security analysis method further includes: Performing feature space mapping on the sample device access information corresponding to each sample access device in the sample device relationship graph through a spatial mapping unit in the candidate analysis network, and outputting a sample device access mapping feature corresponding to each sample access device, wherein the candidate analysis network further includes a first deep mining unit, a second deep mining unit, and an analysis output unit; If there are no other sample access devices having a correlation with the target sample access device in the sample device relationship graph, performing multiple-level deep mining on the sample device access features corresponding to the target sample access device by the first deep mining unit, and outputting the sample device access deep features corresponding to each level; If there are other sample access devices having a correlation with the target sample access device in the sample device relationship map, the second deep mining unit performs multiple levels of deep mining on the sample device access mapping features corresponding to the target sample access device, and in the deep mining process of each level, the sample device access mapping features corresponding to other sample access devices are integrated to output the sample device access deep features corresponding to each level; Outputting target sample access information features based on the sample device access depth features at each level through the analysis output unit, and performing network security analysis on the target sample access device based on the target sample access information features, and outputting sample security analysis results; Based on the error between the sample security analysis result and the corresponding network security label, the candidate analysis network is updated to form a target analysis network.
8. A network security analysis device, characterized in that: include: A graph construction module is configured to construct a device relationship graph corresponding to the target network device based on the operation log of the target network device, wherein each access device in the device relationship graph belongs to a device that performs network access through the target network device, and two access devices that have a connection relationship in the device relationship graph have a correlation relationship; an association mining module for performing association mining on the device access information corresponding to the target access device based on the device access information corresponding to other access devices in the device relationship graph, and outputting target access information features, wherein the device access information is used to characterize the traffic pattern of the corresponding access device; The security analysis module is used to perform network security analysis on the target access device based on the target access information characteristics and output a target security analysis result, wherein the target security analysis result is used to characterize the type of access behavior of the target access device.
9. An electronic device, characterized in that: include: memory for storing computer programs; A processor connected to the memory, configured to execute a computer program stored in the memory to implement the network security analysis method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed, executes the network security analysis method according to any one of claims 1 to 7.