Network anomaly traffic monitoring and attack defense system based on artificial intelligence
By combining the deep learning model of convolutional neural network and long-term memory network and the abnormal traffic type feature library, the shortcomings of traditional network detection systems in identifying unknown attacks and dynamic defense are solved, and accurate identification and efficient defense of network abnormal traffic are achieved.
Patent Information
- Application Number
- CN202510778907.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-08-22
AI Technical Summary
Traditional network anomaly detection systems based on rule matching are difficult to identify unknown attack patterns, with high false alarm rates and missed alarm rates, lack of deep mining of the spatiotemporal characteristics of network traffic, and lack of dynamic adaptation between defense strategies and attack types, resulting in insufficient real-time and accuracy in the face of complex attacks.
A hybrid deep learning model based on convolutional neural network CNN and long-term memory network LSTM is used for traffic feature extraction and pattern analysis, combining an abnormal traffic type feature library and defense strategy mapping relationship table to achieve accurate identification and dynamic defense of network abnormal traffic.
Through the multi-level feature extraction and dynamic defense strategies of deep learning models, unknown threats including zero-day attacks can be effectively identified, underreport rate, improve defense efficiency and business continuity, and achieve precise protection against complex attacks.
Smart Images

Figure CN120528675A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to an artificial intelligence-based network abnormal traffic monitoring and attack defense system. Background Art
[0002] As network attack methods become increasingly complex and diverse, traditional rule-matching-based network anomaly detection systems have become unable to cope with the threats of new attacks.
[0003] The existing technology has the following limitations: First, the static rule base cannot effectively identify unknown attack patterns, resulting in insufficient zero-day attack defense capabilities; Secondly, the single threshold judgment mechanism lacks in-depth exploration of the spatiotemporal characteristics of network traffic, resulting in high false positive and false negative rates. Furthermore, there's a lack of dynamic adaptation between defense strategies and attack types, often resulting in a one-size-fits-all, coarse-grained approach to protection. This impacts normal business traffic and makes it difficult to precisely intercept specific attack types. Traditional systems, in particular, exhibit significant deficiencies in real-time performance, accuracy, and adaptability when facing complex attacks like distributed denial of service (DDoS) and advanced persistent threats. Summary of the Invention
[0004] The purpose of the present invention is to provide an artificial intelligence-based network abnormal traffic monitoring and attack defense system to solve at least one of the above technical problems.
[0005] The purpose of the present invention can be achieved through the following technical solutions: An artificial intelligence-based network abnormal traffic monitoring and attack defense system, including: The data preprocessing module is used to receive raw traffic data, perform cleaning, deduplication, and normalization, and divide the processing results into data segments according to preset time windows; A network traffic analysis module, comprising a pre-trained deep learning model, is configured to receive the data segments, perform feature extraction and pattern analysis, and output an analysis result representing the degree of traffic anomaly, wherein the analysis result includes at least a score representing the overall degree of anomaly and a feature vector representing the characteristics of the traffic pattern; The attack determination module first compares the score value with a preset abnormality threshold to determine whether there is abnormal network traffic. If abnormal traffic is determined to be present, the feature vector is further matched with a pre-built abnormal traffic type feature library to determine the specific abnormal traffic type based on the matching result; The attack defense module is used to receive the specific abnormal traffic type determination result, automatically trigger and execute the corresponding defense strategy, and the defense strategy includes traffic restriction, IP address ban, and traffic redirection.
[0006] As a further technical solution, the deep learning model is a hybrid model combining a convolutional neural network (CNN) and a long short-term memory (LSTM) network. The convolutional neural network is used to extract the spatial features of traffic data, and the long short-term memory network is used to process the time series features of traffic data. The feature vector comes from the output of the intermediate layer or the final feature fusion layer of the hybrid model.
[0007] As a further technical solution, the abnormal traffic type feature library stores typical traffic feature vector patterns corresponding to different types of network attacks; The attack determination module performs similarity calculation on the received feature vector and the feature vector pattern in the feature library, and determines the abnormal traffic type with the highest matching degree according to the similarity calculation result.
[0008] As a further technical solution, the attack defense module pre-stores a mapping relationship table between anomaly types and defense strategies; The mapping relationship table defines defense strategies and strategy parameters corresponding to different abnormal traffic types; The attack defense module queries the mapping relationship table and automatically executes a matching defense strategy based on the specific abnormal traffic type received.
[0009] As a further technical solution, when the abnormal traffic type is a distributed denial of service attack, executing a defense strategy includes: Identify malicious IP clusters based on entropy analysis of attack source IP addresses; Implement traffic rate limiting and IP address blocking on the malicious IP cluster; Redirect network abnormal traffic that exceeds the preset abnormality threshold to the cleaning center.
[0010] As a further technical solution, the attack defense module monitors the effectiveness of the executed defense strategy in real time; If the score output by the network traffic analysis module does not drop to the safety threshold within the preset time, the defense strategy level will be automatically upgraded, including: Expand the scope of IP blocking, increase traffic limit rate, or switch to a backup cleaning node.
[0011] As a further technical solution, the attack defense module sends an alarm message to the security operation and maintenance center when triggering the defense strategy; The warning information includes the abnormality type, attack source IP information, current defense strategy and processing suggestions.
[0012] As a further technical solution, the system further includes: Strategy optimization module, used to: Collecting the defense strategies executed by the attack defense module and their corresponding defense effect data; Based on the reinforcement learning algorithm, a defense strategy effectiveness evaluation model is established; According to historical defense effect data, the policy parameters in the mapping relationship table between the anomaly type and the defense policy are dynamically adjusted.
[0013] Beneficial effects of the present invention: (1) Through the deep learning model, multi-level feature extraction and pattern analysis of network traffic can effectively capture new attack features that cannot be covered by traditional rule libraries. The hybrid model based on the combination of convolutional neural network (CNN) and long short-term memory network (LSTM) combines the advantages of spatial features and time series analysis, and can learn complex nonlinear relationships from traffic data, thereby identifying unknown threats including zero-day attacks. The dynamic matching mechanism of the abnormal traffic type feature library further enhances the system's ability to generalize attack patterns. The similarity calculation of feature vectors achieves accurate classification of attack types, which reduces the risk of missed reports compared to traditional static rule matching. (2) By constructing a mapping table between anomaly types and defense strategies, a closed-loop optimization process from attack detection to defense execution is achieved. The attack determination module not only determines whether an anomaly exists, but also determines the specific attack type based on the feature vector matching results, providing a refined basis for the selection of defense strategies. The defense module can dynamically adjust response measures based on different attack characteristics. For example, it implements IP entropy analysis and cluster blocking for distributed denial of service attacks to avoid the accidental damage to normal traffic caused by traditional one-size-fits-all strategies. At the same time, by real-time monitoring of defense effects and dynamically upgrading policy levels, the adaptive matching of protection measures and attack intensity is ensured, thereby improving defense efficiency and business continuity assurance capabilities.
[0014] (3) In the face of complex attacks such as distributed denial of service attacks and advanced persistent threats, end-to-end intelligent protection is achieved through a multi-module collaborative working mechanism. The network traffic analysis module's deep feature extraction capability can effectively distinguish attack traffic from normal business flows, reducing the false alarm rate. The attack judgment module's multi-dimensional matching mechanism can accurately identify hybrid attack characteristics. The defense module's strategy combination execution, such as traffic cleaning and IP blocking, can specifically dismantle the attack chain. In addition, through the linkage of real-time alarms and operation and maintenance recommendations, a virtuous cycle of "detection-judgment-defense-optimization" is formed, comprehensively improving the comprehensive ability to fight against advanced network threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The present invention will be further described below with reference to the accompanying drawings.
[0016] Figure 1 It is a system structure block diagram of the present invention; Figure 2 This is the workflow diagram of the attack and defense module; Figure 3 The flowchart for monitoring the effectiveness of the implemented defense strategies in the attack defense module. DETAILED DESCRIPTION
[0017] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0018] See also Figure 1-Figure 3 As shown, the present invention is an artificial intelligence-based network abnormal traffic monitoring and attack defense system, comprising: The data preprocessing module is used to receive raw traffic data, perform cleaning, deduplication, and normalization, and divide the processing results into data segments according to preset time windows; Data cleaning: processing missing values: through interpolation or statistical methods; outlier detection: identifying and correcting or deleting abnormal data points based on Z-score and IQR methods; invalid data filtering: eliminating data packets that do not comply with protocol specifications or have incorrect formats; Data deduplication: Identify duplicate traffic based on the five-tuple of source IP, destination IP, source port, destination port, protocol, and timestamp; process session-level duplicate data to maintain session integrity Data normalization: For numerical features, use Z-score normalization or Min-Max scaling; for categorical features, use One-Hot Encoding or Label Encoding; for temporal features, extract statistical features within the time window, such as traffic rate and number of connections; Data segmentation: fixed time window: such as 5 minutes, 10 minutes; sliding time window: window overlap rate is configurable; adaptive time window: dynamically adjust the window size based on the traffic change rate; The network traffic analysis module includes a pre-trained deep learning model for receiving the data segments, performing feature extraction and pattern analysis, and outputting analysis results representing the degree of traffic anomaly. The analysis results include at least a score representing the overall degree of anomaly and a feature vector representing the characteristics of the traffic pattern. The deep learning model is trained based on a labeled network traffic dataset and includes feature labels for normal traffic and known attack traffic. Through supervised learning, the model can accurately distinguish between normal traffic and attack traffic, improving the accuracy of feature extraction. The labeled known attack features can enhance the model's memory of typical attack patterns, providing a reliable basis for anomaly scoring and feature vector generation, solving the problem that traditional rule bases cannot cover new attack features and reducing the risk of missed reports. The hybrid deep learning model architecture includes: CNN components: Convolutional layer: uses multiple convolution kernels of different sizes to extract local features; Pooling layer: reduces dimensionality and extracts key features; Spatial feature extraction: identifies spatial dependencies in traffic patterns; LSTM component: Processing time series characteristics: Capturing the changing trend of traffic over time; Long short-term memory unit: Solving the gradient vanishing problem of traditional RNN; Time series feature extraction: Analyzing the time series correlation and periodicity of traffic; Feature fusion layer: concatenates the output features of CNN and LSTM; uses a fully connected layer for feature fusion and dimensionality reduction; and outputs a fixed-dimensional feature vector to represent the traffic pattern. Anomaly score generation: Anomaly detection based on reconstruction error, autoencoder structure; Probability distribution model: Calculate the probability that the input data belongs to the normal category; Hybrid model output: Combine feature vector and anomaly score for comprehensive judgment; The attack determination module first compares the score value with a preset abnormality threshold to determine whether there is abnormal network traffic. If abnormal traffic is determined to be present, the feature vector is further matched with a pre-built abnormal traffic type feature library to determine the specific abnormal traffic type based on the matching result; For example: The feature library matching process includes: Feature library construction: feature vector templates for known attack types; automatic discovery of new abnormal patterns based on clustering algorithms; feature vector update mechanism: regular addition of new attack patterns; Similarity calculation: Cosine similarity: calculates the directional similarity of feature vectors; Euclidean distance: calculates the spatial distance of feature vectors; Mahalanobis distance: considers the correlation between features; Matching strategy: Nearest neighbor matching: selects the most similar known attack type; Threshold matching: only matches are considered if the similarity exceeds the threshold; Multi-pattern matching: identifies complex attack scenarios; The attack defense module is used to receive the specific abnormal traffic type determination result, automatically trigger and execute the corresponding defense strategy, and the defense strategy includes traffic restriction, IP address ban, and traffic redirection.
[0019] Defense strategies are implemented in the following ways: Traffic limiting: rate limiting based on IP, port, and protocol; implemented using token bucket or leaky bucket algorithms; dynamic adjustment of limiting parameters; IP address blocking: Temporary blocking: blocking strategy based on time window; Graded blocking: setting different blocking durations based on attack severity; Automatic unblocking mechanism; Traffic redirection: Cleaning center redirection: directs suspicious traffic to dedicated cleaning equipment; honeypot trapping: directs attack traffic to false targets; load balancing: distributes traffic among multiple servers.
[0020] In this embodiment, the original traffic data is cleaned, deduplicated, and normalized to eliminate invalid data and redundant information, ensuring that the traffic data format of the input model is unified and the features are standardized, thereby improving the accuracy and efficiency of subsequent analysis; the data is divided into segments according to the preset time window to facilitate capturing the dynamic changes in traffic in the time dimension, such as periodic attack patterns, and provide support for anomaly detection based on time series features; the deep learning model outputs scoring values and feature vectors to achieve an overall degree of abnormal traffic evaluation and pattern feature characterization. Compared with traditional single threshold detection, it can more accurately distinguish between attack types and normal traffic fluctuations; the attack judgment module implements a two-layer judgment based on the scoring values and feature vectors to determine whether there is an anomaly and the specific attack type. The attack defense module automatically executes the strategy according to the results, shortening the manual intervention process and improving the emergency response speed.
[0021] The deep learning model is a hybrid model combining a convolutional neural network (CNN) and a long short-term memory (LSTM) network. The convolutional neural network is used to extract the spatial features of traffic data, and the long short-term memory network is used to process the time series features of traffic data. The feature vector is derived from the output of the intermediate layer or the final feature fusion layer of the hybrid model. The input of the convolutional neural network is a two-dimensional matrix representation of the traffic data, and the input of the long short-term memory network is a serialized traffic feature vector. Clarifying the input format can optimize the model's efficiency in analyzing the spatiotemporal features of traffic data. The two-dimensional matrix facilitates CNN's capture of spatial correlations between data packets, such as port distribution and protocol type, and the serialized vector facilitates LSTM's analysis of traffic trends over time, such as connection frequency fluctuations. The combination of the two can achieve multi-level feature mining of traffic data and enhance the model's ability to identify complex attack patterns, such as periodic DDoS attacks.
[0022] In this embodiment, the convolutional neural network (CNN) extracts spatial features: it captures the spatial dependencies of traffic data, such as port distribution and protocol type associations, through convolutional layers and pooling layers, and identifies local anomalies in traffic patterns, such as abnormal port scans; the long short-term memory network (LSTM) processes temporal features: it uses long short-term memory units to analyze the changing trends of traffic over time, such as sudden changes in connection frequency and abnormal session duration, and detects periodic or continuous attacks, such as sudden increases in traffic caused by DDoS attacks; the hybrid model combines the advantages of CNN and LSTM to learn complex nonlinear relationships in traffic data, effectively identify new types of attacks that traditional rule bases cannot cover, such as zero-day attacks, and reduce the false negative rate; the feature vector comes from the middle layer or fusion layer of the model, contains comprehensive information on spatiotemporal features, and provides rich feature dimensions for accurate matching of attack types.
[0023] The abnormal traffic type feature library stores typical traffic feature vector patterns corresponding to different types of network attacks; The attack determination module calculates the similarity between the received feature vector and the feature vector pattern in the feature library, and determines the abnormal traffic type with the highest matching degree based on the similarity calculation result; when the similarity exceeds the preset matching threshold, it is determined to be a successful match; if the similarity of all feature vector patterns is lower than the threshold, it is marked as an unknown abnormal type; the threshold mechanism is used to avoid misjudging normal traffic with low similarity as an attack, thereby reducing the false alarm rate; the marking of unknown abnormal types can trigger manual review or dynamic feature library update process, enhance the system's early warning capability for zero-day attacks, and make up for the defect that traditional static rule libraries cannot identify unknown attacks.
[0024] In this embodiment, a pre-built abnormal traffic type feature library stores characteristic vector patterns of typical attacks, supports rapid matching of known attacks, such as port scanning and brute force cracking, and improves detection efficiency; the matching degree of the feature vector is quantified through algorithms such as cosine similarity and Euclidean distance to achieve accurate classification of attack types, avoid the ambiguity of traditional rule matching, and reduce false alarms; when the feature vector is not similar enough to the pattern in the library, it can trigger an early warning of unknown anomalies, provide clues for manual analysis or dynamic updating of the feature library, and enhance adaptability to new threats.
[0025] The attack defense module pre-stores a mapping table between anomaly types and defense strategies. Strategy parameters include configurable parameters such as traffic limit thresholds, IP blocking durations, and redirection bandwidth limits. These configurable parameters provide flexibility in defense strategies. For example, traffic limit thresholds can be adjusted for DDoS attacks of varying scales to avoid excessively restricting normal services. Differentiated IP blocking durations balance security and user experience, addressing the problem of traditional one-size-fits-all strategies accidentally harming normal traffic and enabling refined defense. The mapping relationship table defines defense strategies and strategy parameters corresponding to different abnormal traffic types; The attack defense module queries the mapping relationship table and automatically executes a matching defense strategy based on the specific abnormal traffic type received.
[0026] In this embodiment, through the abnormal type-defense strategy mapping relationship table, differentiated strategies such as traffic redirection and IP blocking are implemented for different attack types, such as DDoS and port scanning, to avoid the accidental damage of normal business by a one-size-fits-all strategy and improve the accuracy of defense; at the same time, strategy parameters such as traffic limit threshold and blocking duration are configurable, which can adapt to different network environments and attack intensities, such as low-intensity restrictions for small-scale attacks and high-intensity blocking for large-scale attacks, balancing security and business continuity; it can also automatically query and execute strategies according to the attack type, reduce manual decision-making delays, ensure that threats are quickly blocked when attacks occur, and reduce losses.
[0027] When the abnormal traffic type is a distributed denial of service attack, the defense strategy includes: Identify malicious IP clusters based on entropy analysis of attack source IP addresses. Identify abnormally concentrated IP clusters by calculating the information entropy of IP address distribution. Higher entropy values indicate more abnormal IP distribution. Entropy analysis quantifies the degree of IP address anomaly and automatically locates attack source clusters, avoiding the inefficiency of individual IP detection. Combined with traffic restrictions and blocking measures, it quickly cuts off the connection between the attack source and target, while redirecting high-risk traffic to a scrubbing center, achieving layered defense against DDoS attacks and improving real-time response capabilities. Implement traffic rate limiting and IP address blocking on the malicious IP cluster; Redirect network abnormal traffic that exceeds the preset abnormality threshold to the cleaning center.
[0028] In this embodiment, the degree of abnormality is quantified by the information entropy of the IP address distribution, and the attack source cluster is automatically identified. The higher the entropy value, the more abnormal the IP distribution, avoiding the inefficiency of IP-by-IP detection; at the same time, traffic rate limitation + IP ban is performed on the malicious IP cluster to cut off the connection between the attack source and the target; high-risk traffic is redirected to the cleaning center, filtering the attack traffic while ensuring normal business bandwidth, realizing multi-layer protection of detection-isolation-cleaning; and based on the distributed characteristics of DDoS attacks, defense resources are concentrated on malicious clusters to avoid excessive restrictions across the entire network and improve defense efficiency.
[0029] The attack defense module monitors the effectiveness of the executed defense strategy in real time; If the score output by the network traffic analysis module does not drop to the safety threshold within the preset time, the defense strategy level will be automatically upgraded, including: Expand the scope of IP blocking, increase traffic limiting rate, or switch to a backup cleaning node. The security threshold is the historical mean of the normal traffic score plus three standard deviations; dynamically set the security threshold based on statistical laws to adapt to traffic fluctuations in different network environments and avoid misjudgments caused by fixed thresholds; automatically upgrade the policy mechanism, such as expanding the blocking scope, and dynamically adjust the defense strength according to the attack intensity to ensure that the abnormal score is continuously and effectively reduced in complex attack scenarios, ensuring the availability of network services; In this embodiment, by continuously tracking the score value of the network traffic analysis module, it is evaluated whether the current strategy is effective in reducing the degree of anomalies, avoiding the risk of the strategy being ineffective but not perceived; at the same time, when the score does not drop to the safety threshold within the preset time, the ban range is automatically expanded, the limit rate is increased, or the cleaning node is switched to adapt to changes in attack intensity, such as the spread of attack sources or increased traffic, to ensure that the defense strength matches the threat level, and to avoid the failure of static strategies in complex attack scenarios. Through the monitoring-assessment-upgrade closed loop, the defense effect is continuously optimized to ensure the stability of network services.
[0030] As a further technical solution, the attack defense module sends an alarm message to the security operation and maintenance center when triggering the defense strategy; The alarm information includes the anomaly type, attack source IP information, current defense strategy, and handling suggestions. These handling suggestions are generated based on a historical defense case library, including references to optimal defense strategies for similar attacks. The historical case library provides decision support for operations and maintenance personnel, shortening manual response time. Structured alarms, including anomaly type, attack source, and current strategy, improve information transmission efficiency, allowing operations and maintenance personnel to quickly grasp attack trends. This creates a collaborative protection system that combines automatic defense with manual assistance, enhancing system manageability.
[0031] In this embodiment, the alarm information contains the exception type, attack source IP, current strategy and processing suggestions, providing structured real-time situation information to security operation and maintenance personnel, shortening manual analysis time and facilitating rapid intervention and processing.
[0032] The system further comprises: Strategy optimization module, used to: Collecting the defense strategies executed by the attack defense module and their corresponding defense effect data; Based on the reinforcement learning algorithm, a defense strategy effectiveness evaluation model is established; According to historical defense effect data, the policy parameters in the mapping relationship table between the anomaly type and the defense policy are dynamically adjusted.
[0033] For example: 1. State space definition: Input features: The anomaly score value output by the network traffic analysis module indicates the overall degree of anomaly; The feature vector output by the attack determination module represents the traffic pattern characteristics; The type and parameters of the currently executed defense strategy, such as traffic limit threshold and IP blocking range; Real-time network indicators: bandwidth utilization, number of normal connections, and attack traffic ratio; State representation: Encode the above features into a multi-dimensional vector; ;in is the time step; The score value representing the abnormality, represents the traffic pattern feature vector, Indicates the current defense strategy and parameters. Represents real-time network metrics; 2. Action Space Definition Executable actions: Adjust policy parameters: for example, increase the traffic limit threshold from 100 Mbps to 150 Mbps; Switch policy type: for example, switch from IP blocking to traffic redirection; Expand / reduce the scope of defense: such as increasing the number of banned IP addresses and adjusting the port range for redirected traffic.
[0034] Action Representation: Discrete Action Set , each action corresponds to a specific strategy adjustment operation; 3. Reward Function Design Core goal: Maximize defense effectiveness, i.e., reduce anomaly scores, and minimize the impact on normal business operations; Reward calculation: ; is the difference between the anomaly scores of the current time step and the previous time step. A decrease in the score is a positive reward; The normal traffic change rate is used, and a decrease in traffic is a negative reward to avoid accidentally killing normal services; The rate of change in click traffic percentage. A decrease in percentage indicates a positive reward. > , , which means giving priority to the decrease in abnormal scores, and the optimal weight can be determined through historical data training; 4. Reinforcement Learning Model Selection Algorithm type: Uses deep Q network DQN or policy gradient algorithm PPO, which adapts to high-dimensional state space and continuous action space; Model structure: Input layer: receives the state vector ; Hidden layer: a multi-layer fully connected neural network that extracts the mapping relationship between state features and action values; Output layer: If DQN is used, output the Q value Q of each action ( , ); If PPO is used, the output action probability distribution π( | ).
[0035] 5. Training and Optimization Process Data collection: When the attack defense module executes the strategy, the real-time collection status ,action ,award and next state +1, stored in the experience replay buffer; Model training: randomly sample batches of data from the buffer, update the model parameters through backpropagation, and optimize the goal to maximize the expected cumulative reward; ,in, is the discount factor, reflecting the importance of future rewards; is the total number of time steps; Strategy Update: Regularly synchronize the trained model parameters to the policy optimization module of the attack defense module, and update the mapping table parameters between anomaly types and defense strategies, such as traffic limit thresholds and ban durations.
[0036] In this embodiment, by collecting defense strategy and effect data, such as the rate of decrease of abnormal scores and the impact rate of normal traffic, an evaluation model is established using a reinforcement learning algorithm, and policy parameters such as traffic limit thresholds and ban duration are dynamically adjusted to learn from historical experience and improve the accuracy of policy matching. At the same time, attack methods continue to evolve, and the dynamic adjustment mechanism can avoid the lag of static strategies. For example, it automatically optimizes IP entropy analysis parameters or cleans node configurations based on the characteristics of new DDoS attacks to ensure that the defense strategy is always effective. Then, through the cycle of data collection-model evaluation-parameter adjustment, the defense strategy is continuously iterated to form a positive feedback of detection-defense-optimization, thereby improving the comprehensive protection effectiveness against various network threats in the long term.
[0037] The above is a detailed description of an embodiment of the present invention. However, the content described is only a preferred embodiment of the present invention and should not be considered to limit the scope of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.
Claims
1. An artificial intelligence-based network abnormal traffic monitoring and attack defense system, characterized by: include: The data preprocessing module is used to receive raw traffic data, perform cleaning, deduplication, and normalization, and divide the processing results into data segments according to preset time windows; A network traffic analysis module, comprising a pre-trained deep learning model, is configured to receive the data segments, perform feature extraction and pattern analysis, and output an analysis result representing the degree of traffic anomaly, wherein the analysis result includes at least a score representing the overall degree of anomaly and a feature vector representing the characteristics of the traffic pattern; The attack determination module first compares the score value with a preset abnormality threshold to determine whether there is abnormal network traffic. If abnormal traffic is determined to be present, the feature vector is further matched with a pre-built abnormal traffic type feature library to determine the specific abnormal traffic type based on the matching result; The attack defense module is used to receive the specific abnormal traffic type determination result, automatically trigger and execute the corresponding defense strategy, and the defense strategy includes traffic restriction, IP address ban, and traffic redirection.
2. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to claim 1 is characterized in that: The deep learning model is a hybrid model combining a convolutional neural network (CNN) and a long short-term memory (LSTM) network. The convolutional neural network is used to extract the spatial features of traffic data, and the long short-term memory network is used to process the time series features of traffic data. The feature vector comes from the output of the intermediate layer or the final feature fusion layer of the hybrid model.
3. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to claim 2 is characterized in that: The abnormal traffic type feature library stores typical traffic feature vector patterns corresponding to different types of network attacks; The attack determination module performs similarity calculation on the received feature vector and the feature vector pattern in the feature library, and determines the abnormal traffic type with the highest matching degree according to the similarity calculation result.
4. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to any one of claims 1 to 3, characterized in that: The attack defense module pre-stores a mapping relationship table between anomaly types and defense strategies; The mapping relationship table defines defense strategies and strategy parameters corresponding to different abnormal traffic types; The attack defense module queries the mapping relationship table and automatically executes a matching defense strategy based on the specific abnormal traffic type received.
5. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to claim 4 is characterized in that: When the abnormal traffic type is a distributed denial of service attack, the defense strategy includes: Identify malicious IP clusters based on entropy analysis of attack source IP addresses; Implement traffic rate limiting and IP address blocking on the malicious IP cluster; Redirect network abnormal traffic that exceeds the preset abnormality threshold to the cleaning center.
6. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to claim 4 is characterized in that: The attack defense module monitors the effectiveness of the executed defense strategy in real time; If the score output by the network traffic analysis module does not drop to the safety threshold within the preset time, the defense strategy level will be automatically upgraded, including: Expand the scope of IP blocking, increase traffic limit rate, or switch to a backup cleaning node.
7. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to any one of claims 1 to 3, characterized in that: The attack defense module sends an alarm message to the security operation and maintenance center when the defense strategy is triggered; The warning information includes the abnormality type, attack source IP information, current defense strategy and processing suggestions.
8. The artificial intelligence-based network abnormal traffic monitoring and attack defense system according to claim 1 is characterized in that: The system further comprises: Strategy optimization module, used to: Collecting the defense strategies executed by the attack defense module and their corresponding defense effect data; Based on the reinforcement learning algorithm, a defense strategy effectiveness evaluation model is established; According to historical defense effect data, the policy parameters in the mapping relationship table between the anomaly type and the defense policy are dynamically adjusted.
Citation Information
Cited By
Traffic processing method and device, electronic equipment and storage medium
CN120750664A
IPv6 attack automatic forbidding method and system based on NAT64
CN121077825A
An automatic blocking method and system for IPv6 attack based on NAT64
CN121077825B
Traffic monitoring system based on network audio-visual new media
CN121792223A
Information security control method and system for large-scale network environment
CN121841784A