Man-in-the-middle attack detection method and device
By obtaining communication network equipment information, computing device security coefficient and data transmission deviation, combined with feature vector similarity, efficient detection of man-in-the-middle attacks is achieved, solving the problem of insufficient accuracy and adaptability in the prior art, and improving the accuracy and flexibility of detection.
Patent Information
- Application Number
- CN202510595427.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-08-29
AI Technical Summary
The existing man-in-the-middle attack detection methods are prone to false positives or missed reports when facing changing attack patterns, and have low accuracy and adaptability.
By obtaining device information in the communication network, the communication device security coefficient is calculated, the data transmission deviation is calculated based on the bandwidth, network delay and packet loss rate, and the feature vector similarity is calculated based on the characteristic information of the current communication data, and the risk assessment value is finally calculated for man-in-the-middle attack detection.
It improves the accuracy and adaptability of man-in-the-middle attack detection, and can more accurately identify and deal with complex and changeable attack patterns.
Smart Images

Figure CN120567441A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure communication technology, and in particular to a method and device for detecting man-in-the-middle attacks. Background Art
[0002] With the development of network technology, communication scenarios are becoming increasingly complex and diverse. Man-in-the-middle attacks, a common and highly threatening form of network attack, pose a severe challenge to communication systems. A man-in-the-middle attack involves an attacker intercepting, tampering with, or forging communication data to steal information or compromise the integrity and availability of communications without the knowledge of either party. Traditional rule-based man-in-the-middle attack detection methods are prone to false positives and false negatives in the face of constantly changing attack patterns, resulting in low accuracy and adaptability.
[0003] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention
[0004] The embodiments of the present invention provide a method and device for detecting man-in-the-middle attacks, which effectively improve accuracy and adaptability.
[0005] In one aspect, an embodiment of the present invention provides a method for detecting a man-in-the-middle attack, comprising the following steps:
[0006] Acquire device information in the communication network, the device information including hardware information, software information and network environment information;
[0007] Calculating a safety factor of the communication device based on the device information;
[0008] Calculate data transmission deviation based on bandwidth, network delay and packet loss rate;
[0009] Calculate the feature vector similarity based on the feature information of the current communication data;
[0010] Calculating a risk assessment value based on the communication device safety factor, the data transmission deviation, and the feature vector similarity;
[0011] A man-in-the-middle attack detection is performed based on the risk assessment value to obtain a detection result.
[0012] In some embodiments, calculating the communication device safety factor based on the device information includes:
[0013] Calculating a hardware device security value based on the hardware information;
[0014] Calculating a software device security value based on the software information;
[0015] Calculating a network environment security value based on the network environment information;
[0016] The communication device security factor is calculated based on the hardware device security value, the software device security value, the network environment security value and the hash value of the device identification.
[0017] In some embodiments, the hardware information includes the number of processor cores, clock frequency, memory capacity, storage read / write speed, network interface type, current computing capability of the graphics processor, and current cache capacity. Calculating the hardware device security value based on the hardware information includes:
[0018] The hardware device security value is calculated based on the number of processor cores, clock frequency, memory capacity, storage read and write speed, network interface type, current computing power of the graphics processor, current cache capacity, maximum memory capacity, maximum computing power and maximum cache capacity of the graphics processor.
[0019] In some embodiments, the software information includes an operating system type and a protection level of installed security software, and calculating the software device security value based on the software information includes:
[0020] The software device security value is calculated based on the operating system type, the protection level of the installed security software, and the amount of installed security software.
[0021] In some embodiments, the network environment information includes network topology information, average connectivity of network nodes, and a network congestion index, and calculating the network environment security value based on the network environment information includes:
[0022] The network environment security value is calculated based on network topology information, average connectivity of network nodes and network congestion index.
[0023] In some embodiments, calculating the data transmission deviation based on bandwidth, network delay, and packet loss rate includes:
[0024] Obtain the current network load and the traffic change rate at the previous moment;
[0025] Calculating a target time interval based on the current network load, the traffic change rate at the previous moment, the initial time interval, and the maximum transmission rate permitted by the network;
[0026] Calculating a window size according to the bandwidth, the network delay, the packet loss rate, and the current load of the network;
[0027] performing data flow monitoring processing according to the target time interval, wherein the data flow monitoring processing is used to calculate the communication data flow according to the window size and the size of the data packet in the window;
[0028] Calculating a maximum data transmission volume based on the bandwidth, the network delay, the packet loss rate, a network congestion index, and an average connectivity of network nodes;
[0029] The data transmission deviation is calculated according to the communication data flow, the maximum data transmission volume, the packet loss rate and the network congestion index.
[0030] In some embodiments, the characteristic information of the current communication data includes the length of the communication data, the distance between the source IP address and the destination IP address in the data packet header, the information entropy of the data content, the repetition rate of the data segments, and the standard deviation of the time interval of data transmission. The calculating the characteristic vector similarity based on the characteristic information of the current communication data includes:
[0031] The current data feature vector is obtained by combining the communication data length, the distance between the source IP address and the destination IP address in the data packet header, the information entropy of the data content, the data segment repetition rate, and the standard deviation of the data transmission time interval;
[0032] Constructing a normal communication data feature vector based on historical normal communication data;
[0033] The feature vector similarity is calculated based on the current data feature vector and the normal communication data feature vector.
[0034] In some embodiments, performing man-in-the-middle attack detection based on the risk assessment value to obtain a detection result includes:
[0035] If the risk assessment value is greater than a preset risk assessment threshold, the presence of a man-in-the-middle attack is considered as the detection result;
[0036] If the risk assessment value is less than or equal to a preset risk assessment threshold, then the absence of a man-in-the-middle attack is taken as the detection result.
[0037] On the other hand, an embodiment of the present invention provides a man-in-the-middle attack detection device, comprising:
[0038] The first module is used to obtain device information in the communication network, wherein the device information includes hardware information, software information and network environment information;
[0039] A second module is used to calculate the safety factor of the communication device according to the device information;
[0040] The third module is used to calculate the data transmission deviation based on bandwidth, network delay and packet loss rate;
[0041] The fourth module is used to calculate the feature vector similarity based on the feature information of the current communication data;
[0042] A fifth module is configured to calculate a risk assessment value based on the communication device safety factor, the data transmission deviation, and the feature vector similarity;
[0043] The sixth module is used to perform man-in-the-middle attack detection according to the risk assessment value to obtain a detection result.
[0044] In another aspect, an embodiment of the present invention provides a computer device, comprising:
[0045] at least one processor;
[0046] at least one memory for storing at least one program;
[0047] When the at least one program is executed by the at least one processor, the at least one processor implements the method.
[0048] On the other hand, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.
[0049] The beneficial effects of the present invention are as follows:
[0050] The embodiment of the present invention first obtains device information in the communication network, then calculates the communication device security factor based on the device information, calculates the data transmission deviation based on the bandwidth, network delay and packet loss rate, and calculates the feature vector similarity based on the feature information of the current communication data. Then, based on the communication device security factor, the data transmission deviation and the feature vector similarity, a risk assessment value is calculated. Finally, based on the risk assessment value, man-in-the-middle attack detection is performed to obtain a detection result, thereby enabling man-in-the-middle attack detection to be achieved by combining device security, transmission security and data security, thereby improving accuracy and adaptability.
[0051] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained through the structures particularly pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0053] Figure 1This is a flow chart of a method for detecting a man-in-the-middle attack according to an embodiment of the present invention;
[0054] Figure 2 This is a schematic structural diagram of a man-in-the-middle attack detection device according to an embodiment of the present invention;
[0055] Figure 3 The figure is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0056] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present application. They are merely examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the appended claims.
[0057] It will be understood that the terms "first", "second", etc. used in this application may be used herein to describe various concepts, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0058] The terms "at least one", "plurality", "each", "any", etc. used in this application include "at least one", "two" or more, "plurality" or "each", "any" or "any one", "each" or "any one" as used herein.
[0059] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0060] Before explaining the embodiments of the present application in detail, some of the nouns and terms involved in the embodiments of the present application are first explained. The nouns and terms involved in the embodiments of the present application are subject to the following explanations.
[0061] Man-in-the-Middle Attack (MITM): This is an "indirect" intrusion attack. This attack mode uses various technical means to virtually place a computer controlled by the intruder between two communicating computers in a network connection. This computer is called the "middleman".
[0062] In the current digital age, communication security is crucial. Man-in-the-middle attacks, a common and highly threatening cyberattack, pose a severe challenge to communication systems. With the rapid development of network technology, communication scenarios are becoming increasingly complex and diverse. From traditional Internet communications to emerging sectors such as the Internet of Things and the Industrial Internet, data transmission faces numerous security risks. A man-in-the-middle attack involves an attacker intercepting, tampering with, or forging communication data to steal information or compromise the integrity and availability of communications without the knowledge of either party. However, with the continuous expansion of network scale and the diversification of applications, man-in-the-middle attack methods are becoming increasingly subtle and sophisticated. Attackers may exploit vulnerabilities in the network topology, such as masquerading as a communication node in complex network topologies through methods such as ARP spoofing to intercept data packets. Alternatively, they may exploit the instability of data transmission during network congestion to tamper with transmitted data. Existing man-in-the-middle attack protection technologies have certain limitations. Some methods only provide protection from a single dimension. For example, relying solely on encryption technology can protect data confidentiality to a certain extent, but it cannot effectively deal with attackers' interference with communication processes and destruction of data integrity. Other detection methods based on rule matching are difficult to adapt to ever-changing attack patterns, are prone to false positives or omissions, and have low accuracy and adaptability.
[0063] In view of this, an embodiment of the present invention obtains device information in the communication network, then calculates the security factor of the communication device, calculates the data transmission deviation based on the bandwidth, network delay and packet loss rate, and calculates the feature vector similarity based on the feature information of the current communication data, and then calculates the risk assessment value. Finally, man-in-the-middle attack detection is performed to obtain the detection result, thereby realizing man-in-the-middle attack detection by combining device security, transmission security and data security, thereby improving accuracy and adaptability.
[0064] The embodiment of the present application provides a method for detecting a man-in-the-middle attack, which relates to the field of secure communication technology. The embodiment of the present application provides a method for detecting a man-in-the-middle attack that can be applied to a terminal, a server, or software running on a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, and a car terminal, etc., but is not limited thereto; the server side can be configured as an independent physical server, or as a server cluster or distributed system consisting of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network; the software can be an application that implements a method for detecting a man-in-the-middle attack, etc., but is not limited to the above forms.
[0065] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.
[0066] The following is a detailed explanation of the embodiments of the present application with reference to the accompanying drawings:
[0067] Figure 1 This is an optional flowchart of a man-in-the-middle attack detection method provided in an embodiment of the present application. Figure 1 The method may include but is not limited to steps S101 to S106.
[0068] Step S101: Acquire device information in the communication network, where the device information includes hardware information, software information, and network environment information;
[0069] Step S102: Calculate the safety factor of the communication device based on the device information;
[0070] Step S103: Calculate the data transmission deviation based on the bandwidth, network delay, and packet loss rate;
[0071] Step S104: Calculate the feature vector similarity based on the feature information of the current communication data;
[0072] Step S105: Calculate a risk assessment value based on the communication equipment safety factor, data transmission deviation, and feature vector similarity;
[0073] Step S106: Perform a man-in-the-middle attack detection based on the risk assessment value to obtain a detection result.
[0074] Steps S101 to S106 shown in the embodiment of the present application implement man-in-the-middle attack detection, improving accuracy and adaptability.
[0075] In step S101 of some embodiments, device information in the communication network can be obtained through a network request. Device information in the communication network can also be obtained through other means, but is not limited to these. Among them, device information includes hardware information, software information, and network environment information. This embodiment collects various types of information from the devices of both communicating parties. For hardware information, detailed collection is made of the number of CPU cores, clock frequency, memory capacity, storage read and write speed, GPU computing power, cache size, etc. These hardware parameters directly affect the computing and storage capabilities of the device, and are therefore related to the device's performance in resisting attacks. In terms of software information, it covers the operating system type, version number, list of installed security software and its protection level. Different operating systems and security software configurations determine the software security protection level of the device. Network environment information can include network topology (represented in the form of an adjacency matrix), average connectivity of nodes in the network, network congestion level indicators, etc. The network topology affects the security of the communication path, the average connectivity of nodes reflects the complexity and potential risks of the network, and the congestion level affects the stability and security of data transmission.
[0076] In some embodiments, in step S102, calculating the communication device safety factor based on the device information may include but is not limited to steps S201 to S204:
[0077] Step S201: Calculate the hardware device security value based on the hardware information;
[0078] Step S202: Calculate the software device security value based on the software information;
[0079] Step S203: Calculate the network environment security value based on the network environment information;
[0080] Step S204: Calculate the communication device security factor based on the hardware device security value, the software device security value, the network environment security value, and the hash value of the device identification.
[0081] In some embodiments, the hardware information can be used to first calculate the hardware device security value by comprehensively considering the contribution of hardware parameters to device security through logarithmic operations, proportional operations, etc. Then, based on the software information, a weighted calculation is performed on factors such as the protection level of the security software and the operating system to calculate the software device security value. Then, based on the network environment information and combined with the network environment factors, the network environment security value is calculated. Finally, the communication device security factor is calculated based on the hardware device security value, software device security value, network environment security value, and the hash value of the device identification, where the calculation formula for the communication device security factor is: S device =l1×S har +l2×S sof +S net +H(ID)×ε, where S device is the safety factor of communication equipment, S har is the hardware device security value, S sof is the software device security value, S net is the network environment security value, l1 is the weight of the hardware device security value, l2 is the weight of the software device security value, l1+l2=1, H(ID) is the hash value of the device identifier, which contains the unique identification information of the device, and ε is the adjustment coefficient. In the calculation formula of the communication equipment security factor, l1×S har and l2×S sof The hardware and software security values are included in the calculation according to the set weights, reflecting the different importance of hardware and software in the overall security of the device; net Directly add to reflect the impact of the network environment on device security; H(ID)×ε introduces a fine-tuning factor related to device uniqueness into the security factor calculation through the device identification hash value and adjustment coefficient. Through this calculation process, the communication device security factor S is obtained device , quantifying the security level of communication equipment from a comprehensive perspective. The communication equipment security factor comprehensively reflects the security of the equipment's hardware and software, as well as the network environment in which it operates, and is an important basic indicator for subsequent risk assessments.
[0082] In some embodiments, in step S201, calculating the hardware device security value based on the hardware information may include but is not limited to the following steps:
[0083] The hardware device security value is calculated based on the processor's core number, clock frequency, memory capacity, storage read and write speed, network interface type, the graphics processor's current computing power, current cache capacity, maximum memory capacity, the graphics processor's maximum computing power, and maximum cache capacity.
[0084] In some embodiments, a hardware device security value can be calculated based on hardware information, where the hardware information includes the number of processor cores, clock frequency, memory capacity, storage read / write speed, network interface type, current computing power of the graphics processor, and current cache capacity. These hardware parameters have a direct and critical impact on the device's computing processing, data storage, and transmission capabilities. The hardware device security value can be calculated based on the number of processor cores, clock frequency, memory capacity, storage read / write speed, network interface type, current computing power of the graphics processor, current cache capacity, maximum memory capacity, maximum computing power of the graphics processor, and maximum cache capacity. The calculation formula for the hardware device security value is: Where S har is the hardware device security value, C is the number of processor cores, f is the clock frequency, M is the memory capacity, and M nc is the maximum memory capacity, R s is the storage read and write speed, α is the weighting coefficient of device storage, β is the weighting coefficient of network interface, T n is the network interface type, G c is the current computing power of the graphics processor, G max is the maximum computing power of the graphics processor, C cache is the current cache capacity, C max is the maximum cache capacity. It is understandable that taking the logarithm of the product of the number of processor cores and the clock frequency can reflect the fundamental role of the processor's computing power in security; the ratio of memory capacity to maximum memory capacity reflects the memory resource utilization and security-related conditions; the square root of storage read and write speed combined with the weighting coefficient considers the contribution of storage to security; the network interface type reflects its role in network connection security through the weighting coefficient; the ratio of the graphics processor's computing power and cache capacity to their respective maximum values and multiplying them by the corresponding coefficient measures the impact of graphics processing and cache functions on device security. The device hardware security value S is obtained by calculation. har , quantifying the security level of the device hardware level.
[0085] In some embodiments, in step S202, calculating the software device security value based on the software information may include but is not limited to the following steps:
[0086] The software device security value is calculated based on the operating system type, the protection level of the installed security software, and the amount of installed security software.
[0087] In some embodiments, a software device security value may be calculated based on software information, where the software information includes the operating system type and the protection level of installed security software. The software device security value may be calculated based on the operating system type, the protection level of installed security software, and the amount of installed security software, where the calculation formula for the software device security value is: Where S sof is the software device security value, n is the number of installed security software, L s The protection level of the installed security software, s (i) is the weight of the i-th security software, γ s is the weighting coefficient of the operating system type, O s is the operating system type. It is understandable that the weight of the installed security software reflects factors such as its protection capabilities and functional integrity. Different security software has different weights due to differences in function and performance. The operating system type will affect device security due to its own security design and vulnerability status. The weighted sum of the installed security software reflects the comprehensive role of security software in overall software security protection. The higher the protection level of the security software and the greater the weight, the greater its contribution to the device software security value. The operating system type is multiplied by the corresponding weighting coefficient γ s , quantify the impact of the operating system on security and include it in the calculation. The device software security value S is obtained through calculation sof , quantified the security level of the device from a software perspective.
[0088] In some embodiments, in step S203, calculating the network environment security value based on the network environment information may include but is not limited to the following steps:
[0089] The network environment security value is calculated based on network topology information, average connectivity of network nodes and network congestion indicators.
[0090] In some embodiments, a network environment security value may be calculated based on network environment information, wherein the network environment information includes network topology information, average connectivity of network nodes, and a network congestion index. The network environment security value may be calculated based on the network topology information, average connectivity of network nodes, and a network congestion index, wherein the network environment security value is calculated using the following formula: Where S net is the network environment security value, D avg is the average connectivity of network nodes, C cong is the network congestion index, N topo is the network topology information, |N topo | is the determinant value of the structural adjacency matrix of the network topology information. It can be understood that the average connectivity of network nodes reflects the closeness and complexity of the connections between nodes in the network. The higher the connectivity, the greater the potential security risk. The network congestion index reflects the congestion of the network when transmitting data. Congestion may cause data transmission anomalies and create conditions for man-in-the-middle attacks. The network topology information is presented in the form of a structural adjacency matrix, and its determinant value |N topo|It contains characteristic information of network topology. Different topologies have different impacts on network security. This item reflects the impact of connectivity on network security by performing logical operations on the average connectivity of nodes. When the connectivity deviates from a certain range (5 is used as a reference here), the value of this item will change accordingly, reflecting the increase or decrease of security risks; (1-C cong ) reflects the relationship between network congestion and security. The higher the congestion, the smaller the value, which means the greater the impact on network security. Based on the determinant value of the adjacency matrix of the network topology information structure, the impact of the topology structure on security is quantified through logarithmic operations and other methods. Through this series of operations, the network environment security value S is obtained. net , quantifies the security level of the environment in which devices communicate from the perspective of the network environment.
[0091] In some embodiments, in step S103, calculating the data transmission deviation based on the bandwidth, network delay, and packet loss rate may include but is not limited to the following steps:
[0092] Obtain the current network load and the traffic change rate at the previous moment;
[0093] Calculate the target time interval based on the current network load, the traffic change rate at the previous moment, the initial time interval, and the maximum transmission rate allowed by the network;
[0094] Calculate the window size based on bandwidth, network delay, packet loss rate, and current network load;
[0095] Performing data flow monitoring processing according to a target time interval, the data flow monitoring processing being used to calculate communication data flow based on a window size and a size of a data packet within the window;
[0096] Calculate the maximum data transmission capacity based on bandwidth, network delay, packet loss rate, network congestion index and average connectivity of network nodes;
[0097] The data transmission deviation is calculated based on the communication data flow, maximum data transmission volume, packet loss rate and network congestion level indicators.
[0098] In some embodiments, the communication data flow can be monitored in real time at dynamically changing time intervals during the communication process. The time interval is dynamically adjusted according to the real-time network load and the flow change rate at the previous moment. When the network load is high or the flow changes drastically, the time interval is shortened to monitor the data more frequently; otherwise, the time interval is appropriately increased. Adaptive sliding window technology is used, and the window size is adjusted in real time based on indicators such as network delay, bandwidth, packet loss rate, and network congestion level, and within each window, the communication data flow is statistically calculated. The current network load L can be obtained first. load(t) and the flow rate change rate at the previous moment The target time interval is calculated based on the current network load, the traffic change rate at the previous moment, the initial time interval, and the maximum transmission rate allowed by the network. The target time interval is calculated as follows: Where Δt(t) is the target time interval, Δt0 is the initial time interval, and L load (t) is the current load of the network, is the flow rate change rate at the previous moment, V max The maximum transmission rate permitted by the network. The current network load reflects the data transmission pressure on the network. A higher load indicates a more congested network and a greater likelihood of data transmission anomalies. The traffic change rate at the previous moment reflects how quickly data traffic changes within adjacent time intervals. A higher rate of change indicates more drastic traffic fluctuations. This part, along with the current network load L load (t) increases, the denominator Increase, so that the value of this part decreases, that is, the monitoring interval will be shortened, which reflects the logic of strengthening monitoring when the network load is high; In this part, the flow rate change rate at the current moment Relative to the maximum transmission rate V allowed by the network max When the value is larger, the smaller the value of this part is, the shorter the monitoring interval will be. This reflects the principle that more frequent monitoring is required when traffic changes drastically. The target interval for dynamic monitoring that adapts to the current state of the network is obtained through calculation.
[0099] Then, the window size is calculated based on the bandwidth, network delay, packet loss rate, and current network load. The calculation formula for the window size is: Where W(t) is the window size, B(t) is the bandwidth, and T delay (t) is the network delay, P loss (t) is the packet loss rate. These parameters reflect the network's transmission capacity, data transmission time, data loss, and load pressure at the current moment. It can be understood that B(t)×T delay (t)×(1-P loss Part (t) comprehensively reflects the theoretical data transmission volume determined by bandwidth, delay and packet loss rate under ideal conditions (without considering network load); The theoretical data transmission rate is adjusted based on the real-time network load. When the real-time network load is high, this value is reduced and the window size is adjusted accordingly to adapt to the network status. The calculated window size dynamically reflects the current network status and reflects the range of data packets suitable for traffic statistics under the current network status.
[0100] Then, data flow monitoring processing is performed according to the target time interval. The data flow monitoring processing is used to calculate the communication data flow according to the window size and the size of the data packet in the window. The calculation formula of the communication data flow is: Where F(t) is the communication data flow, d i (t) is the size of the i-th data packet in the window. For example, the communication data flow F(t) can be monitored at a target time interval Δt(t). According to the dynamically adjusted target time interval, the flow and transmission rate information of the communication data are periodically collected to provide a real-time and accurate data basis for subsequent operations such as calculating the data transmission deviation, analyzing the characteristics of the communication data, and determining whether there is a man-in-the-middle attack. It can be understood that within a certain window range, the system analyzes the data packets in the window one by one. Each data packet has its own specific size d i (t), where i represents the sequence number of the data packet in the window, ranging from 0 to W(t)-1. The sizes of all data packets in the window can be summed up. This summation is a statistical process for the communication data flow within the window. By accumulating the size of each data packet, the communication data flow F(t) within the current window time is obtained.
[0101] The maximum data transmission volume is calculated based on bandwidth, network delay, packet loss rate, network congestion index, and average connectivity of network nodes. The calculation formula for the maximum data transmission volume is: Where M max (t) is the maximum data transmission capacity, B(t) is the bandwidth, which determines the upper limit of the network's data transmission capacity, T delay (t) is the network delay, which reflects the time it takes for data to be transmitted in the network. loss (t) is the packet loss rate, which reflects the proportion of data packets lost during transmission. C cong (t) is the network congestion index, which measures the congestion of the network. avg is the average connectivity of network nodes, showing the closeness and complexity of the connections between network nodes. These parameters fully reflect the current operating status of the network. It can be understood that B(t)×T delay (t)×(1-P loss (t)) Preliminary calculation of theoretical transmission volume without considering congestion and node connectivity; 1-C cong (t) Adjust the preliminary theoretical transmission volume. The higher the network congestion level, the smaller the value of this part, which means that the transmission volume is reduced due to congestion; Further fine-tune the transmission volume according to the average connectivity of network nodes. Different connectivity will affect the overall transmission efficiency of the network. The maximum data transmission volume M in the current network state is obtained by calculation.max (t), this theoretical value takes into account the ideal transmission capacity of the network as well as the current network congestion and packet loss.
[0102] Finally, the data transmission deviation is calculated based on the communication data flow, maximum data transmission volume, packet loss rate and network congestion index. The calculation formula of the data transmission deviation is: Where D is the data transmission deviation. It can be understood that Calculate the relative difference between the actual communication data flow and the maximum data transmission volume to reflect the degree to which the flow deviates from the theoretical value; 1+P loss (t) Considering the impact of packet loss rate on data transmission, the higher the packet loss rate, the larger the value of this part, indicating that the weight of packet loss on data transmission anomalies increases; 1+C cong (t) reflects the effect of network congestion on data transmission. Higher congestion levels increase this value, indicating a more significant impact of congestion on data transmission anomalies. The data transmission deviation D is calculated, which measures the difference between actual data transmission and theoretically normal data transmission. A higher deviation indicates a higher likelihood of data transmission anomalies, potentially due to man-in-the-middle attacks that interfere with or tamper with data transmission.
[0103] In some embodiments, in step S104, calculating the feature vector similarity based on the feature information of the current communication data may include but is not limited to the following steps:
[0104] The current data feature vector is obtained by combining the communication data length, the distance between the source IP address and the destination IP address in the data packet header, the information entropy of the data content, the data segment repetition rate, and the standard deviation of the data transmission time interval;
[0105] Constructing a normal communication data feature vector based on historical normal communication data;
[0106] Calculate the feature vector similarity based on the current data feature vector and the normal communication data feature vector.
[0107] In some embodiments, the feature vector similarity can be calculated based on the feature information of the current communication data, wherein the feature information of the current communication data includes the length of the communication data, the distance between the source IP address and the destination IP address in the data packet header, the information entropy of the data content, the repetition rate of the data segments, and the standard deviation of the time interval of the data transmission. ip , the information entropy E of the data content, the repetition rate R of the data fragment dup and the standard deviation of the time interval between data transmissions σ tCombine them to get the current data feature vector, where the expression of the current data feature vector is: Where, is the current data feature vector, L is the communication data length, reflecting the amount of data, and abnormal length changes may indicate attack behavior; H ip is the distance between the source IP address and the destination IP address in the data packet header, which can reflect the network location relationship and changes of the two communicating parties. Abnormal changes in the IP address distance may indicate illegal access or impersonation. E is the information entropy of the data content, which is used to measure the uncertainty and confusion of the data. If the information entropy is abnormal, it may mean that the data has been tampered with. dup is the data fragment repetition rate, which reflects the proportion of repeated content in the data. Abnormal repetition rate may be caused by abnormal data duplication or interference caused by attacks; t The standard deviation of the data transmission time interval reflects fluctuations in the data transmission time interval. Abnormal fluctuations may be related to data transmission anomalies caused by attacks. The current data feature vector integrates feature information from multiple dimensions to form a comprehensive quantitative representation of the characteristics of the current communication data. It is understandable that deep feature extraction can be performed on the current communication data, and this can be further expanded to a joint analysis of the data in the time and frequency domains to extract features such as the main frequency component and spectrum bandwidth to construct a rich and comprehensive current data feature vector.
[0108] Then, based on the historical normal communication data, a normal communication data feature vector is constructed. For example, the historical normal communication data can be trained to construct the normal communication data feature vector. It can be understood that current communication data refers to the communication data set being processed and analyzed at a specific moment or time period. For example, in a network security monitoring scenario, all network communication data packets are captured in real time. Historical normal communication data is data that conforms to normal communication patterns and rules, which has been pre-defined or determined through historical data learning. For example, in an enterprise network, the communication data of employees accessing the enterprise's internal servers and commonly used office software servers during normal office hours, after long-term observation and analysis, it is determined that its data characteristics (such as data length range, source IP address range, etc.) conform to normal business logic. This data belongs to historical normal communication data.
[0109] Then, the feature vector similarity is calculated based on the current data feature vector and the normal communication data feature vector. The calculation formula of the feature vector similarity is: Where S is the feature vector similarity, is the current data feature vector, is the normal communication data feature vector. It can be understood that the feature vector similarity reflects the degree of closeness between the current communication data and the normal communication pattern. The lower the similarity, the more the current communication data deviates from the normal pattern, and there may be a man-in-the-middle attack that has tampered or forged the communication data. It is the part that calculates the cosine of the angle between two vectors, which measures the similarity of the vectors in direction; The impact of differences in vector modulus on similarity is further considered. Through the comprehensive calculation of these two parts, a similarity value within a certain range (usually between 0 and 1) is obtained, which reflects the degree of similarity between the current communication data characteristics and the normal communication data characteristics.
[0110] In some embodiments, in step S105, a risk assessment value may be calculated based on the communication device safety factor, the data transmission deviation, and the feature vector similarity, wherein the risk assessment value is calculated as follows: R = k1 × (1-S device )+k2×D+k3×(1-S), where R is the risk assessment value, S device is the safety factor of communication equipment, D is the data transmission deviation, S is the feature vector similarity, k1 is the weight of the safety factor of communication equipment, k2 is the weight of the data transmission deviation, and k3 is the weight of the feature vector similarity. These weights determine the relative importance of each indicator in risk assessment. It can be understood that k1×(1-S device ) part, with the safety factor S of the communication equipment device As the security of the device decreases (i.e., device security deteriorates), this value increases, and its contribution to the risk assessment value R increases. k²×D reflects the impact of data transmission deviation on risk. The greater the deviation D, the larger the value of this term, and the higher the risk. k³×(1-S) represents the effect of similarity on risk. The lower the similarity S (i.e., the more abnormal the data characteristics), the larger the value of this term. The sum of these three components yields the risk assessment value R, which quantifies the risk level of man-in-the-middle attacks facing the current communication.
[0111] In some embodiments, in step S106, based on the risk assessment value, a man-in-the-middle attack detection is performed to obtain a detection result, which may include but is not limited to the following steps:
[0112] If the risk assessment value is greater than the preset risk assessment threshold, the presence of a man-in-the-middle attack will be detected as a result;
[0113] If the risk assessment value is less than or equal to the preset risk assessment threshold, the absence of a man-in-the-middle attack is considered as a detection result.
[0114] In some embodiments, a risk assessment threshold R can be pre-set according to specific security requirements and application scenarios. thr, this threshold represents the upper limit of the risk that the system can accept. The risk assessment value R can be compared with the preset risk assessment threshold R thr By comparing, it can be determined whether the risk level of the current communication exceeds the acceptable range. If the risk assessment value is greater than the preset risk assessment threshold, that is, R>R thr , then the existence of a man-in-the-middle attack is considered as the detection result. Once such a judgment is made, the system will immediately trigger a series of pre-set protection measures, such as collecting attack evidence, re-authenticating the identities of both parties in communication, blocking the communication link or switching to a backup link, etc., to deal with the man-in-the-middle attack and ensure communication security; if the risk assessment value is less than or equal to the preset risk assessment threshold, that is, R <R thr , then the absence of man-in-the-middle attack is regarded as the detection result, and the current communication is considered relatively safe. The system continues to monitor the communication process in real time and continuously assess the risk.
[0115] In some embodiments, hardware information from both communicating devices is collected, including information such as the number of processor cores, clock frequency, memory capacity, storage read / write speed, and cache size; software information, including operating system type, version number, list of installed security software and its protection level; and network environment information, such as network topology, average node connectivity, and congestion level. A targeted calculation formula is then used to comprehensively consider various factors to quantitatively assess the device's security status and determine the communication device's security factor. This comprehensive assessment method accurately captures potential security risk factors within the device itself and the network environment in which it resides. Compared to assessment methods that only consider a single or limited number of factors, it more accurately reflects the device's actual security status, providing a solid and reliable foundation for subsequent risk assessments and effectively avoiding man-in-the-middle attack protection vulnerabilities caused by insufficient device security assessments.
[0116] This embodiment introduces a multi-factor dynamic weight adjustment mechanism that comprehensively considers factors such as communication duration, cumulative communication data volume, current network load, rate of change of device safety factor, similarity between the current data feature vector and the normal communication data feature vector, and rate of change of high-order statistical characteristics of data traffic (such as skewness change rate and kurtosis change rate). The weight coefficient is calculated using a sophisticated formula to construct a comprehensive risk assessment function. This multi-factor comprehensive risk assessment method fully considers the dynamic changes and mutual influence of various key aspects of the communication process, avoiding the one-sidedness and limitations of single-factor assessments. It can scientifically and rationally assess whether a man-in-the-middle attack exists based on different communication scenarios and real-time changing network conditions.
[0117] The beneficial effects of implementing the embodiments of the present invention include: the embodiments of the present invention first obtain device information in the communication network, then calculate the communication device security factor based on the device information, calculate the data transmission deviation based on the bandwidth, network delay and packet loss rate, and calculate the feature vector similarity based on the feature information of the current communication data, and then calculate the risk assessment value based on the communication device security factor, the data transmission deviation and the feature vector similarity. Finally, based on the risk assessment value, man-in-the-middle attack detection is performed to obtain a detection result, thereby enabling man-in-the-middle attack detection to be achieved by combining device security, transmission security and data security, thereby improving accuracy and adaptability.
[0118] like Figure 2 As shown, an embodiment of the present invention further provides a man-in-the-middle attack detection device, comprising:
[0119] The first module 801 is used to obtain device information in the communication network, including hardware information, software information and network environment information;
[0120] The second module 802 is used to calculate the safety factor of the communication device based on the device information;
[0121] The third module 803 is used to calculate the data transmission deviation based on the bandwidth, network delay and packet loss rate;
[0122] The fourth module 804 is configured to calculate the feature vector similarity based on the feature information of the current communication data;
[0123] The fifth module 805 is used to calculate the risk assessment value based on the communication equipment safety factor, the data transmission deviation and the feature vector similarity;
[0124] The sixth module 806 is configured to perform a man-in-the-middle attack detection based on the risk assessment value and obtain a detection result.
[0125] The contents of the above method embodiments are all applicable to the present device embodiments. The functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0126] like Figure 3 As shown, an embodiment of the present invention further provides a computer device, including:
[0127] at least one processor 901;
[0128] At least one memory 902, configured to store at least one program;
[0129] When at least one program is executed by at least one processor, the at least one processor implements Figure 1 The method shown.
[0130] The contents of the above method embodiments are all applicable to the present device embodiments. The functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0131] The embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program, which is executed by a processor to implement Figure 1 The method shown.
[0132] The contents of the above method embodiments are all applicable to the present storage medium embodiment. The functions specifically implemented by the present storage medium embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0133] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.
Claims
1. A method for detecting a man-in-the-middle attack, characterized in that: The following steps are involved: Acquire device information in the communication network, the device information including hardware information, software information and network environment information; Calculating a safety factor of the communication device based on the device information; Calculate data transmission deviation based on bandwidth, network delay and packet loss rate; Calculate the feature vector similarity based on the feature information of the current communication data; Calculating a risk assessment value based on the communication device safety factor, the data transmission deviation, and the feature vector similarity; A man-in-the-middle attack detection is performed based on the risk assessment value to obtain a detection result.
2. The method according to claim 1, characterized in that Calculating the communication device safety factor according to the device information includes: Calculating a hardware device security value based on the hardware information; Calculating a software device security value based on the software information; Calculating a network environment security value based on the network environment information; The communication device security factor is calculated based on the hardware device security value, the software device security value, the network environment security value and the hash value of the device identification.
3. The method according to claim 2, characterized in that The hardware information includes the number of processor cores, clock frequency, memory capacity, storage read / write speed, network interface type, current computing power of the graphics processor, and current cache capacity. Calculating the hardware device security value based on the hardware information includes: The hardware device security value is calculated based on the number of processor cores, clock frequency, memory capacity, storage read and write speed, network interface type, current computing power of the graphics processor, current cache capacity, maximum memory capacity, maximum computing power and maximum cache capacity of the graphics processor.
4. The method according to claim 2, characterized in that The software information includes an operating system type and a protection level of installed security software. Calculating the software device security value based on the software information includes: The software device security value is calculated based on the operating system type, the protection level of the installed security software, and the amount of installed security software.
5. The method according to claim 2, characterized in that The network environment information includes network topology information, average connectivity of network nodes, and a network congestion index. Calculating the network environment security value based on the network environment information includes: The network environment security value is calculated based on network topology information, average connectivity of network nodes and network congestion index.
6. The method according to claim 1, characterized in that The calculation of data transmission deviation based on bandwidth, network delay and packet loss rate includes: Get the current network load and the traffic change rate at the previous moment; Calculating a target time interval based on the current network load, the traffic change rate at the previous moment, the initial time interval, and the maximum transmission rate permitted by the network; Calculating a window size according to the bandwidth, the network delay, the packet loss rate, and the current load of the network; performing data flow monitoring processing according to the target time interval, wherein the data flow monitoring processing is used to calculate the communication data flow according to the window size and the size of the data packet in the window; Calculating a maximum data transmission volume based on the bandwidth, the network delay, the packet loss rate, a network congestion index, and an average connectivity of network nodes; The data transmission deviation is calculated according to the communication data flow, the maximum data transmission volume, the packet loss rate and the network congestion index.
7. The method according to claim 1, characterized in that The characteristic information of the current communication data includes the length of the communication data, the distance between the source IP address and the destination IP address in the data packet header, the information entropy of the data content, the repetition rate of the data segments, and the standard deviation of the time interval of data transmission. The calculating the characteristic vector similarity based on the characteristic information of the current communication data includes: The current data feature vector is obtained by combining the communication data length, the distance between the source IP address and the destination IP address in the data packet header, the information entropy of the data content, the data segment repetition rate, and the standard deviation of the data transmission time interval; Constructing a normal communication data feature vector based on historical normal communication data; The feature vector similarity is calculated based on the current data feature vector and the normal communication data feature vector.
8. The method according to claim 1, characterized in that The step of performing man-in-the-middle attack detection based on the risk assessment value to obtain a detection result includes: If the risk assessment value is greater than a preset risk assessment threshold, the presence of a man-in-the-middle attack is considered as the detection result; If the risk assessment value is less than or equal to a preset risk assessment threshold, then the absence of a man-in-the-middle attack is taken as the detection result.
9. A man-in-the-middle attack detection device, characterized in that: include: The first module is used to obtain device information in the communication network, wherein the device information includes hardware information, software information and network environment information; A second module is used to calculate the safety factor of the communication device according to the device information; The third module is used to calculate the data transmission deviation based on bandwidth, network delay and packet loss rate; The fourth module is used to calculate the feature vector similarity based on the feature information of the current communication data; A fifth module is configured to calculate a risk assessment value based on the communication device safety factor, the data transmission deviation, and the feature vector similarity; The sixth module is used to perform man-in-the-middle attack detection according to the risk assessment value to obtain a detection result.
10. A computer device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the method according to any one of claims 1 to 8.
Citation Information
Cited By
Network security situation prediction method and system based on artificial intelligence
CN121000533A
A method and system for predicting cybersecurity situation based on artificial intelligence
CN121000533B