Network information security adaptive threat intelligence analysis and response method and system
By performing time-sequential processing, frequency domain analysis and multi-head attention fusion on encrypted traffic, identifying commands and controlling heartbeat signals in encrypted traffic, solving the problem of high misjudgment rate in the existing technology, and achieving efficient autonomous evolution of threat detection and defense capabilities.
Patent Information
- Application Number
- CN202511086750.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-08-05
AI Technical Summary
The existing technology cannot effectively identify command and control communications in encrypted traffic, the high misjudgment rate and the lack of automated feedback links lead to the inability to continuously evolve defense capabilities and the inability to form a closed-loop autoevolution capability to fight against advanced threats.
Encrypted traffic by collecting the transport layer security protocol, generating a time-sequential traffic matrix, parsing communication metadata and matching it with the threat intelligence library, performing multi-level wavelet packet decomposition to extract frequency domain composite anomaly indicators, using multi-head attention mechanism fusion indicators to identify heartbeat signal characteristics, generate threat confidence scores, and activate active rule chains to intercept traffic when the threshold is reached, and update the threat intelligence library.
It significantly improves the accuracy of encryption threat detection, forms a continuous autonomous evolution closed-loop mechanism for defense capabilities, reduces the misjudgment rate of normal and malicious encrypted traffic, and ensures the continuous self-evolution ability to fight against advanced threats.
Smart Images

Figure CN120602225A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network security threat detection and response, and in particular to a network information security adaptive threat intelligence analysis and response method and system. Background Art
[0002] Current advanced persistent threat attacks commonly exploit transport layer security (TLS) encrypted channels to conceal command and control communications. This type of communication is highly concealed and dynamically mutating, with adaptively adjusted heartbeat signal periods and protocol fields disguised as legitimate interactions. Cybersecurity defense systems urgently need to overcome the bottleneck of deep parsing of encrypted traffic to capture the periodic characteristics of disguised heartbeat signals.
[0003] Currently, a representative solution uses a protocol compliance detection engine based on fixed rules and statistical features. This solution primarily analyzes metadata during the Transport Layer Security (TLS) handshake phase, such as the server name indicator field and certificate chain information, matches it against a pre-set blacklist of malicious domain names and addresses, and uses static thresholds to identify abnormal data connections. The detection results trigger pre-defined fixed policies to execute traffic interception actions.
[0004] However, this solution suffers from significant technical shortcomings. It cannot identify implicit distribution patterns of encrypted payloads in the frequency domain, such as unusual fluctuations in energy spectral density or sudden changes in information entropy. This results in a high rate of misjudgment of normal business traffic and command-and-control communications with similar encrypted semantics. Furthermore, after interception, new attack signatures must be manually verified and re-injected into the system. The lack of an automated feedback loop hinders the continuous evolution of defense capabilities and prevents the formation of a closed-loop, self-evolving capability to combat advanced threats. Summary of the Invention
[0005] The present application provides a network information security adaptive threat intelligence analysis and response method and system to solve the problem of high misjudgment rate in the existing technology.
[0006] In a first aspect, the present application provides a network information security adaptive threat intelligence analysis and response method, comprising: Collecting the payload byte stream in the transport layer security protocol encrypted traffic, dividing the payload byte stream into fixed time windows, and generating a time-series traffic matrix; Parsing the communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in a threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavioral anomaly determination results; Perform multi-level wavelet packet decomposition on the traffic matrix to extract the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component. Based on a predefined abnormality template, the energy spectrum density, information entropy, and variation coefficient are weighted and normalized to generate a frequency-domain composite abnormality index that characterizes the energy distribution, complexity, and stability of the heartbeat signal. The frequency domain composite anomaly indicator and the threat fingerprint are integrated through a multi-head attention mechanism to identify the periodic characteristics of the command and control heartbeat signal and the protocol violation pattern hidden in the encrypted traffic, and generate a threat confidence score; If the threat confidence score exceeds the preset risk threshold, the dynamic rule chain engine is activated to intercept the corresponding communication traffic, and the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time are used as new attack features. After the validity is confirmed through the verification mechanism, it is fed back to the threat intelligence library for update, realizing a closed-loop linkage between threat defense and intelligence update.
[0007] Optionally, multi-level wavelet packet decomposition is performed on the traffic matrix to extract the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component. Based on a predefined abnormality template, the energy spectrum density, information entropy, and variation coefficient are weighted fused and normalized to generate a frequency domain composite abnormality index that characterizes the energy distribution, complexity, and stability of the heartbeat signal, including: Performing a multi-scale decomposition operation on the traffic matrix to generate a plurality of sub-band components in the frequency domain, calculating a unit frequency energy value for each high-frequency sub-band component, and generating an energy spectral density based on the unit frequency energy value; At the same time, the sequence disorder of the component sequence is calculated as the information entropy, and the variation amplitude parameter of the component time-frequency dimension is extracted as the time-frequency variation coefficient; A predefined anomaly template containing weighted ratio parameters and benchmark reference values is loaded, the energy spectral density, information entropy and time-frequency variation coefficient are input into a weighted calculation model, a fusion operation is performed, and a standardized adjustment process is performed on the fusion result to generate a frequency domain composite anomaly indicator that characterizes the energy distribution, complexity and stability of the heartbeat signal.
[0008] Optionally, performing a multi-scale decomposition operation on the traffic matrix to generate multiple frequency domain sub-band components, calculating a unit frequency energy value for each high-frequency sub-band component, and generating an energy spectral density based on the unit frequency energy value, including: Performing a multi-level decomposition operation on the traffic matrix, splitting the input component into a low-frequency component and a high-frequency component at each level of decomposition, repeating the multi-level decomposition operation until a preset number of levels is reached, and generating a plurality of frequency domain sub-band components; Filtering all the frequency domain sub-band components marked as high frequency, and for each high frequency sub-band component, calculating the sum of squares of the values of each high frequency component, and dividing the sum by the frequency range width of the high frequency component to generate a unit frequency energy value; The energy value per unit frequency is multiplied by a preset coefficient, and the output is an energy spectrum density representing the energy intensity.
[0009] Optionally, the frequency domain composite anomaly indicator and the threat fingerprint are fused through a multi-head attention mechanism to identify periodic features of command and control heartbeat signals and protocol violation patterns hidden in encrypted traffic, and generate a threat confidence score, including: Constructing a multi-head attention model and inputting the frequency domain composite anomaly index and the threat fingerprint, focusing on different feature dimensions through multiple attention heads, and calculating the adjustment feature contribution ratios of multiple weight distribution matrices; Based on the contribution ratio of the regulated features of multiple weight distribution matrices, a fused feature vector is generated. The periodic repetitive signal pattern of the command and control heartbeat signal hidden in the encrypted traffic is identified from the fused feature vector as the periodic feature of the heartbeat signal, and the deviation sequence from the standard protocol rules is detected as a protocol violation pattern. The heartbeat signal periodic feature and the protocol violation pattern are integrated to generate a threat confidence score.
[0010] Optionally, a multi-head attention model is constructed and the frequency domain composite anomaly index and the threat fingerprint are input. Multiple attention heads focus on different feature dimensions and calculate the contribution ratio of the adjusted features of multiple weight distribution matrices, including: Construct a multi-head attention model, wherein the multi-head attention model includes a projection matrix group and an attention head component group, wherein the projection matrix group includes three sets of projection matrices, and the number of the projection matrices is equal to the number of attention heads; Inputting the frequency domain composite anomaly indicator and the threat fingerprint into the multi-head attention model, performing an alignment operation to generate feature data, and multiplying the feature data by the three projection matrices in the projection matrix group to generate query projection data, key projection data, and value projection data; Splitting the query projection data, key projection data, and value projection data into a plurality of sub-blocks, inputting each sub-block into a corresponding attention head component in the attention head component group, multiplying the sub-block of the query projection data by the transposed matrix of the sub-block of the key projection data to generate an original weight matrix, dividing the original weight matrix by the square root of the feature dimension to generate a scaled weight matrix, performing an exponential operation on the scaled weight matrix row by row, and summing the results to generate a weight distribution matrix; Perform weight calculation within each attention head component, multiply the weight distribution matrix by the value projection data sub-block to generate head output data, perform proportional distribution calculation, multiply the head output data by a preset head weight coefficient to output a proportional calculation result; The ratio calculation results of all attention head components are spliced along the feature dimension to generate the adjusted feature contribution ratios of multiple weight distribution matrices.
[0011] Optionally, if the threat confidence score exceeds a preset risk threshold, the dynamic rule chain engine is activated to intercept the corresponding communication traffic, and the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time are used as new attack features. After the validity is confirmed through the verification mechanism, the features are fed back to the threat intelligence library to achieve a closed-loop linkage between threat defense and intelligence updates, including: Comparing the threat confidence score with a preset risk threshold, and activating a dynamic rule chaining engine to intercept corresponding communication traffic if the threat confidence score exceeds the preset risk threshold; Based on the rule chain, the corresponding communication traffic is blocked, and the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time are extracted to form new attack characteristics; The credibility of the new attack feature is checked through a verification mechanism, and the data block of the verified new attack feature is added to the control communication feature, which is then fed back to the threat intelligence library for update, thus realizing a closed-loop linkage between threat defense and intelligence update.
[0012] Optionally, parsing the communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in a threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavior anomaly determination results, including: Separating communication metadata from the payload byte stream, retrieving command and control communication features from the threat intelligence library, and using a similarity calculation mechanism to perform item-by-item pairing comparisons between the communication metadata and the control communication features to obtain a matching correlation value; Perform protocol rule verification checks, determine the compliance of communication behavior against the standard protocol specification process template, obtain protocol compliance determination results, detect the time interval distribution and data volume deviation of the communication sequence, and generate behavior anomaly indication values; The matching correlation degree value, protocol compliance determination result and behavior anomaly indication value are integrated. When the behavior anomaly indication value exceeds a predefined threshold, the corresponding new communication mode is added to the control communication feature to generate a threat fingerprint in the form of a dynamically updated storable digital identifier.
[0013] In a second aspect, the present application provides a network information security adaptive threat intelligence analysis and response system, comprising: A collection module is used to collect the payload byte stream in the transport layer security protocol encrypted traffic, split the payload byte stream into fixed time windows, and generate a time-series traffic matrix; a matching module for parsing communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in a threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavioral anomaly determination results; a decomposition module for performing multi-level wavelet packet decomposition on the traffic matrix, extracting the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component, and performing weighted fusion and normalization on the energy spectrum density, information entropy, and variation coefficient based on a predefined anomaly template to generate a frequency-domain composite anomaly index that characterizes the energy distribution, complexity, and stability of the heartbeat signal; A fusion module is configured to fuse the frequency domain composite anomaly indicator and the threat fingerprint through a multi-head attention mechanism, identify the periodic characteristics of the command and control heartbeat signal and the protocol violation pattern hidden in the encrypted traffic, and generate a threat confidence score; The activation module is used to activate the dynamic rule chain engine to intercept the corresponding communication traffic if the threat confidence score exceeds the preset risk threshold, and use the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time as new attack features. After confirming the validity through the verification mechanism, it is fed back to the threat intelligence library for update, realizing a closed-loop linkage between threat defense and intelligence update.
[0014] In a third aspect, the present application provides a computing device comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a network information security adaptive threat intelligence analysis and response method as described in the first aspect above.
[0015] In a fourth aspect, the present application provides a computer storage medium storing a computer program. When the computer program is executed by a computer, it implements a network information security adaptive threat intelligence analysis and response method as described in the first aspect.
[0016] This application collects payload byte streams from transport layer security protocol encrypted traffic and segments them into a time-series traffic matrix according to fixed time windows, constructing a time series framework for analyzing periodic behavior. It then analyzes the payload byte stream communication metadata, correlates it with known command and control features in the threat intelligence library, and generates a dynamically updated threat fingerprint based on protocol compliance and behavioral anomalies, overcoming the limitations of traditional static rule bases that often require updates. The traffic matrix is further subjected to multi-level wavelet packet decomposition to extract the energy spectral density, information entropy, and time-frequency coefficient of variation of high-frequency subband components. A frequency-domain composite anomaly index is generated through weighted fusion and normalization of predefined anomaly templates, accurately capturing the hidden heartbeat signal spectral features that are difficult to identify using traditional statistical methods. A multi-head attention mechanism is then used to fuse the frequency-domain index with the threat fingerprint, identifying hidden heartbeat periodicity and protocol violation patterns in encrypted traffic and outputting a threat confidence score, significantly improving the accuracy of encrypted threat detection. Finally, when the threat score exceeds a preset threshold, a dynamic rule chaining engine is activated to intercept the corresponding traffic. Furthermore, the identified new attack features are fed back to the threat intelligence library after verification, forming a closed-loop mechanism for the continuous and autonomous evolution of defense capabilities.
[0017] Furthermore, by performing multi-scale wavelet packet decomposition on the time-series traffic matrix, multi-frequency sub-signal components are generated, establishing a separation basis for high-frequency noise and covert signals. The energy per unit frequency is calculated for each high-frequency sub-band to obtain the energy spectral density, quantifying the energy concentration characteristics of the heartbeat signal. The component sequence disorder is calculated as information entropy to identify signs of human entropy manipulation, and the time-frequency dimension variation amplitude parameter is extracted as the coefficient of variation to detect periodic stability flaws. A predefined anomaly template containing weighted ratios and baseline values is then loaded. The energy spectral density, information entropy, and time-frequency coefficient of variation are input into a weighted fusion model and normalized to output a frequency-domain composite anomaly indicator. This process effectively distinguishes spectral obfuscation between service traffic and attack traffic through quantified physical features. This results in a frequency-domain probe combination with significant anti-obfuscation capabilities, transforming high-frequency signal energy distribution anomalies, camouflage complexity deviations, and periodic stability defects into quantifiable attack fingerprints, addressing the challenge of deep camouflage for advanced threats in the frequency domain.
[0018] These and other aspects of the present application will become more readily apparent from the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0020] Figure 1A flowchart of a network information security adaptive threat intelligence analysis and response method provided by the present application is shown; Figure 2 A scenario diagram showing a network information security adaptive threat intelligence analysis and response method provided by the present application is shown; Figure 3 A schematic diagram of the structure of a network information security adaptive threat intelligence analysis and response system provided by the present application is shown; Figure 4 A schematic structural diagram of a computing device provided by the present application is shown. DETAILED DESCRIPTION
[0021] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0022] In some of the processes described in the specification and claims of this application and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to being different types.
[0023] Researchers have found that the current threat analysis of transport layer security protocol encrypted traffic in the field of network security has significant shortcomings. Traditional encrypted traffic analysis technologies based on plaintext feature matching or single dimensions are difficult to effectively capture the deep patterns of malicious command and control communications hidden in encrypted payloads. However, it is unable to identify the implicit distribution patterns of encrypted payloads in the frequency domain, such as abnormal fluctuations in energy spectrum density or sudden changes in information entropy, resulting in a high misjudgment rate for normal business traffic and command and control communications with similar encrypted semantics. Therefore, there is an urgent need for an adaptive threat intelligence analysis and response method that can deeply integrate time-frequency domain features, automatically correlate threat intelligence, and achieve closed-loop evolution of defense.
[0024] In response to the above problems, the present invention proposes a network information security adaptive threat intelligence analysis and response method. The core of the method is to integrate the multi-dimensional correlation analysis of time-domain traffic structure and frequency-domain deep features into the network information security adaptive threat intelligence analysis and response, and realize the self-evolution of intelligence and defense through a closed-loop linkage mechanism. The method significantly reduces the misjudgment rate between normal and malicious encrypted traffic by finely characterizing the frequency-domain distribution anomalies and stability characteristics of encrypted traffic; at the same time, it constructs an automated closed-loop link of "detection-interception-feature extraction-verification-knowledge update", ensuring the continuous self-evolution capability of the defense system against unknown advanced threats.
[0025] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0026] Figure 1 A flowchart of a network information security adaptive threat intelligence analysis and response method is provided for an embodiment of the present application, such as Figure 1 As shown, the method includes: 101. Collecting a payload byte stream in the transport layer security protocol encrypted traffic, dividing the payload byte stream into fixed time windows, and generating a time-series traffic matrix; In the above steps, transport layer security protocol encrypted traffic refers to the encrypted network data stream generated by the secure transmission protocol used in network communications, which ensures that the data is not stolen or tampered with during transmission; the payload byte stream refers to the byte sequence part that carries the actual data content in the encrypted traffic, and does not contain the header metadata of the network data packet; the fixed time window refers to a pre-set interval of the same time length, which is used to divide the continuous byte stream into multiple blocks of equal length, each block corresponding to a time period; the time-series traffic matrix refers to the conversion of the blocks after the time window is divided into a data array structure arranged in chronological order, where each row represents the numerical summary information of the byte stream after processing in a time window, where the time dimension represents the window sequence index.
[0027] In an embodiment of the present application, a general network packet capture tool is first used to monitor the network interface, and the transport layer security protocol traffic is filtered and captured, and only the payload byte sequence portion is extracted. This involves discarding the packet header information after capturing the original data packet, and retaining only the continuous stream of payload bytes. Then, the captured continuous byte stream is divided into equal intervals according to fixed time length intervals, and the byte stream blocks are divided by timer and counter tools to ensure that each block contains the complete byte sequence within its time window. The specific segmentation process is: initialize the timer, and whenever the time reaches the window length, intercept the current accumulated byte sequence as a block; if the byte stream does not fill a window, it is padded with zeros or the remaining part is retained. Then, the byte sequence of each time window block is processed and analyzed to generate the feature summary value of the window, and the feature summaries of all windows are arranged in chronological order into a matrix structure. In this way, the byte stream is converted into a time-series matrix that is easy to handle, which is convenient for subsequent analysis. For example, in a practical application, a fixed time window of 2 seconds is set. The captured TLS encrypted traffic payload byte stream is a long sequence, such as the initial portion of the byte sequence [65, 120, 200, ..., 150], with a total duration of 10 seconds. After segmentation, five time windows are generated: the first 2-second window contains the byte sequence [65, 120], with a total byte count of 2 and an average of 92.5; the second 2-second window contains the byte sequence [200, 180], with a total byte count of 2 and an average of 190; and so on. The fifth window may be padded with zeros due to insufficient byte sequences, such as the byte sequence [5, 0], with a total byte count of 1 and an average of 2.5. All window features are organized into a time-series traffic matrix: the first row represents the total number of bytes and the average value of time index 1 ([2, 92.5]), the second row represents the value of time index 2 ([2, 190]), and the fifth row represents the value of time index 5 ([1, 2.5] or [2, 2.5]), forming a complete matrix structure for time series pattern recognition.
[0028] In practical applications, for example, in an experiment, researchers first collected the payload byte streams of the Transport Layer Security Protocol encrypted traffic from Company A's network environment, specifically collecting 10,000-byte data samples; then, they divided these byte streams into 50 independent segments according to a fixed time window of 200 milliseconds; finally, they generated a time-series traffic matrix to facilitate subsequent analysis of encryption behavior characteristics.
[0029] In the overall solution of step 101 above, the payload byte stream in the transport layer security protocol encrypted traffic is collected and divided into fixed time windows to finally generate a time-series traffic matrix. This process realizes the structured processing of network traffic data, which facilitates subsequent efficient time series analysis, abnormal behavior detection and network security monitoring applications.
[0030] 102. Parse the communication metadata of the payload byte stream, match and correlate the communication metadata with known command and control communication features in the threat intelligence library, and generate a dynamically updated threat fingerprint based on protocol compliance and behavior anomaly determination results; Optionally, step 102 may specifically include the following steps: 1021. Separate the communication metadata from the payload byte stream, retrieve command and control communication features from the threat intelligence library, and use a similarity calculation mechanism to perform item-by-item pairing comparisons between the communication metadata and the control communication features to obtain a matching correlation value. 1022. Perform protocol rule verification and check, determine the compliance of communication behavior against the standard protocol specification process template, obtain protocol compliance determination results, detect the time interval distribution and data volume deviation of the communication sequence, and generate a behavior anomaly indicator value; 1023. Integrate the matching correlation degree value, the protocol compliance determination result, and the behavior anomaly indication value. When the behavior anomaly indication value exceeds a predefined threshold, add the corresponding new communication mode to the control communication feature to generate a threat fingerprint in the form of a dynamically updated storable digital identifier.
[0031] In the above steps, communication metadata refers to the part of network communication-related information extracted from the payload byte stream, such as communication descriptive information such as source address, destination address, port number, and timestamp. The threat intelligence library refers to a data set that stores known malicious activity patterns, including command and control communication characteristics. These characteristics describe, for example, the typical behavior sequence of an attacker remotely controlling a device. The similarity calculation mechanism refers to a standard method for measuring the degree of similarity between two data items. The matching correlation value refers to a numerical value that indicates the degree of match between the communication metadata and the known characteristics. The protocol rule verification check refers to checking whether the communication behavior complies with the standard protocol specification process template. The template defines expected rules such as normal communication handshake steps. The behavior anomaly indication value refers to a numerical value that reflects the degree to which the communication behavior deviates from the normal state. The predefined threshold refers to the set anomaly judgment boundary value. The new communication pattern refers to the detected abnormal communication sequence. The dynamically updated threat fingerprint refers to the malicious behavior digital identifier generated or updated based on the detection results.
[0032] In an embodiment of the present application, first, step 1021 is used to separate communication metadata from the payload byte stream, retrieve command and control communication features from the threat intelligence library, and use a similarity calculation mechanism to compare the communication metadata with the control communication features one by one to obtain a matching correlation value. The implementation process of this step includes first using a general metadata extraction tool, such as a parser developed based on a Python script, to separate metadata fields, such as source address, destination address, port number, and timestamp, from the payload byte stream generated in step 101. Then, accessing the threat intelligence library, which can be a local database or a cloud storage service, retrieves known command and control communication features through a matching query interface, such as a feature describing a target with a source address within a specific malicious IP range. Then, using a similarity calculation mechanism, such as a cosine similarity algorithm, the correspondence between the metadata fields and the features is compared one by one. For example, for the source address, the similarity score between the metadata value and the feature value is calculated. Finally, the calculation results of all fields are summarized, such as taking an average, to obtain a matching correlation value, such as a percentage value. For example, in actual applications, the input payload byte stream comes from TLS encrypted traffic and contains metadata such as source address 19216811 and destination address 10001 port 443. A characteristic source address range of 19216810-192168254 is retrieved from the threat intelligence library. The similarity score is calculated by calculating the distance difference between the source address 19216811 and the characteristic range. Based on the distance function, the score is 75. Other metadata such as port 443 are compared with the characteristic port 443 with a similarity of 100. The overall match correlation value is calculated as a weighted average of 85, indicating a high degree of match.
[0033] Next, in step 1022, a protocol rule verification check is performed, and the compliance of the communication behavior is determined by comparing it with the standard protocol specification process template, obtaining a protocol compliance determination result, detecting the time interval distribution and data volume deviation of the communication sequence, and generating a behavior anomaly indicator value. The implementation process of this step includes firstly performing a protocol rule verification check based on the matching correlation degree value outputted in step 1021 as the input context, utilizing the standard protocol specification process template, such as the TLS protocol handshake sequence rule stored in the memory data structure, comparing the metadata field behavior of the communication sequence, such as whether the consecutive request and response steps conform to the expected process, determining compliance, and outputting a text result such as compliance or non-compliance. Then, the time interval distribution of the communication sequence is detected, and the degree of difference between the time point intervals is calculated using a simple variance statistical method. The data volume deviation is also calculated, and the abnormal fluctuation of the byte flow size is analyzed using the standard deviation method. Finally, the compliance determination and time data deviation are integrated to generate a comprehensive behavior anomaly indicator value, such as a percentage value. The specific process is to extract time series from communication metadata, such as the interval between requests in milliseconds, and data series, such as the number of bytes in each communication block, and use variance to calculate the interval distribution. For example, if the time interval is 100 milliseconds to 150 milliseconds, compared with the normal range of 50 milliseconds to 100 milliseconds, the calculated variance value is greater than the normal range of 60, indicating high deviation. The data volume deviation is calculated based on the moving average. For example, if the traffic value is 200 bytes to 300 bytes, compared with the normal value of 150, the calculated standard deviation is 40, which is higher than the baseline 30, indicating high deviation. Compliance judgment, for example, if a communication sequence lacks a TLS end handshake marker, is determined to be non-compliant. Integrating these factors generates a behavior anomaly indicator value, such as 65, which is higher than the normal threshold of 50 and is considered abnormal. For example, in actual applications, the matching correlation degree value is 85. After determining that the communication may be abnormal, the protocol rule verification is performed, and the communication sequence time interval is detected to be 120 milliseconds to 130 milliseconds, the data volume is 500 bytes to 600 bytes, the standard template expects an interval of 50 to 100 milliseconds and a data volume of 300 to 400 bytes, the calculated time interval variance is 70, the data volume standard deviation is 80, the compliance is determined to be non-compliant, and the integration generates a behavior anomaly indication value of 70.
[0034] Finally, in step 1023, the matching correlation value, protocol compliance determination result, and behavior anomaly indicator value are integrated. When the behavior anomaly indicator value exceeds a predefined threshold, the corresponding new communication pattern is added to the control communication feature to generate a threat fingerprint in the form of a dynamically updated, storable digital identifier. The implementation process of this step includes first taking the behavior anomaly indicator value output from step 1022 as input, integrating it with other elements, such as the matching correlation value (e.g., 85) and the protocol compliance determination result (e.g., non-compliant), and generating a comprehensive score through weighted averaging or logical rules. Then, when the behavior anomaly indicator value exceeds a predefined threshold, such as a set threshold of 60, it is considered a confirmed anomaly. The newly detected communication pattern, extracted from the metadata anomaly sequence, is added to the command and control communication feature of the threat intelligence library as a new entry. Finally, a digital identifier generator is used to convert the new feature into a storable threat fingerprint, such as a unique identification string, to facilitate subsequent query and tracking, enabling dynamic updates. For example, in actual applications, the input matching correlation value is 85, the protocol compliance judgment result is non-compliant, the behavior anomaly indication value is 70, and the integrated comprehensive score of 75 exceeds the predefined threshold of 60. Therefore, new communication patterns are extracted from the communication metadata, such as the repeated request sequence of the source address 19216811, and this pattern is added to the threat intelligence library. Then, a dynamically updated threat fingerprint is generated, such as a hexadecimal IDFP123AB stored in the database to complete the fingerprint update.
[0035] In practical applications, for example, in an experiment, researchers collected a payload byte stream of 10,000 bytes from transport layer security protocol encrypted traffic in network system A. They then parsed the communication metadata of the payload byte stream, including elements such as the source address and destination port, and matched it against 20 known command and control communication features stored in threat intelligence library B. The cosine similarity algorithm was used to calculate the correlation between the communication metadata and the features item by item, resulting in an average matching correlation with a minimum value of 0.75 and a maximum value of 0.95. They then performed a protocol rule verification check, referencing the process template of standard protocol specification template C, and determined that the communication behavior compliance result was abnormal. They also detected the time interval distribution of the communication sequence, finding an average deviation of 50 milliseconds. The calculated data volume deviation exceeded the baseline value of 60 bytes, generating a behavior anomaly indicator value. Finally, the matching correlation value, protocol compliance determination result, and behavior anomaly indicator value were integrated. When the anomaly indicator value exceeded the preset threshold of 30, the corresponding new communication pattern was added to the control communication feature library, generating a dynamically updated threat fingerprint in the form of a storable digital identifier.
[0036] In the overall solution of step 102 above, by parsing the communication metadata of the byte stream of the encrypted traffic payload of the transport layer security protocol, it is matched and correlated with the known command and control communication characteristics in the threat intelligence library. Furthermore, multi-dimensional indicators are integrated based on the protocol rule verification check and behavioral anomaly detection to achieve protocol compliance determination and dynamic monitoring of behavioral anomalies. This technology comprehensively matches the correlation analysis results, protocol compliance status, and communication sequence deviation indicators. When anomalies are detected that exceed the preset security threshold, the new communication pattern characteristics are automatically updated to the threat intelligence library, generating a threat fingerprint in the form of a storable digital identifier with dynamic evolution capabilities, ultimately forming an active defense mechanism that can continuously detect new attack methods.
[0037] 103. Perform multi-level wavelet packet decomposition on the traffic matrix to extract the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component. Based on a predefined abnormality template, perform weighted fusion and normalization on the energy spectrum density, information entropy, and variation coefficient to generate a frequency-domain composite abnormality index that characterizes the energy distribution, complexity, and stability of the heartbeat signal. Optionally, step 103 may specifically include the following steps: 1031. Perform a multi-scale decomposition operation on the traffic matrix to generate multiple sub-band components in the frequency domain, calculate a unit frequency energy value for each high-frequency sub-band component, and generate an energy spectral density based on the unit frequency energy value; Among them, step 1031 may specifically include the following process: performing a multi-level decomposition operation on the traffic matrix, splitting the input component into a low-frequency component and a high-frequency component at each level of decomposition, repeating the multi-level decomposition operation until a preset number of levels is reached, and generating multiple frequency domain sub-band components; screening all the frequency domain sub-band components marked as high frequency, and for each high-frequency sub-band component, counting the square sum of the values of each high-frequency component, dividing it by the frequency range width of the high-frequency component, and generating a unit frequency energy value; multiplying the unit frequency energy value by a preset coefficient, and outputting it as an energy spectrum density representing the energy intensity.
[0038] 1032. Simultaneously calculate the sequence disorder of the component sequence as information entropy, and extract the variation amplitude parameter of the component time-frequency dimension as the time-frequency variation coefficient; 1033. Load a predefined anomaly template containing weighted ratio parameters and benchmark reference values, input the energy spectrum density, information entropy, and time-frequency variation coefficient into a weighted calculation model, perform a fusion operation, and perform a standardized adjustment process on the fusion result to generate a frequency domain composite anomaly indicator that characterizes the energy distribution, complexity, and stability of the heartbeat signal.
[0039] In the above steps, the traffic matrix refers to the time-series data array structure generated in step 101, in which each row represents a feature summary sequence of a time window. Multi-level wavelet packet decomposition refers to a technique that uses wavelet functions such as Daubechies wavelets to decompose signals, decomposing the signal into multiple sub-band components of different frequencies. High-frequency sub-band components refer to signal components that represent higher-frequency components after decomposition. Energy spectral density refers to the calculated energy intensity value per unit frequency. Information entropy refers to an indicator of the degree of disorder of a component sequence calculated using information theory formulas. The time-frequency coefficient of variation refers to a parameter that measures the amplitude of the component change in the time and frequency dimensions, usually the standard deviation divided by the mean. The predefined anomaly template refers to a reference value template stored in a configuration file, which includes a weighted ratio parameter and a benchmark reference value. Weighted fusion refers to the operation of multiplying multiple indicators by their respective weights and then summing them. Normalization refers to the mathematical processing of adjusting data to a uniform scale range. The frequency domain composite anomaly index refers to the final generated value that comprehensively reflects the degree of anomaly in terms of energy distribution, complexity, and stability.
[0040] In the embodiment of the present application, first, through step 1031, a multi-scale decomposition operation is performed on the traffic matrix to generate multiple sub-band components in the frequency domain. For each high-frequency sub-band component, the unit frequency energy value is calculated, and the energy spectral density is generated based on the unit frequency energy value. The implementation process of this step includes using a discrete wavelet transform algorithm such as Daubechies wavelet to perform a multi-level decomposition operation, where each level of decomposition splits the input component into a low-frequency component and a high-frequency component. The specific decomposition process is as follows: the preset decomposition level is 3, the starting flow matrix is used as input, the first level of decomposition splits the row vector of the matrix into a low-frequency component and a high-frequency component, and the high-frequency component is stored as a subband. The second level uses the previous round of low-frequency components as input to continue splitting into new low-frequency and high-frequency components. This process is repeated until the preset level 3 is reached to generate multiple high-frequency subband components, and then all subband components marked as high-frequency are screened. For each high-frequency component sequence, the sum of the squares of its values is calculated and divided by the frequency range width to generate a unit frequency energy value. When calculating the unit frequency energy value, the frequency range width is set based on the frequency resolution of the wavelet coefficient. Finally, the unit frequency energy value is multiplied by a preset coefficient such as 1.2 to output the energy spectrum density representing the energy intensity. For example, in actual applications, the input traffic matrix has two rows of data. The first row represents the feature summary of time index 1, which is 20 total bytes and 40 average value. The second row is 30 total bytes and 50 average value. The preset decomposition level is 3. After decomposition using Daubechies wavelet, two high-frequency sub-band components are obtained. The first high-frequency component sequence is the values 0.5 and 0.6. The frequency range width is set to 1kHz. The square sum of 0.5 square plus 0.6 square is equal to 0.61. Dividing it by the width of 1kHz obtains the unit frequency energy value of 0.61. Multiplying it by the preset coefficient 1.2 outputs the energy spectrum density of 0.732. The second high-frequency component is similarly calculated to generate other energy spectrum densities.
[0041] Next, through step 1032, the sequence disorder of the component sequences is simultaneously calculated as information entropy, and the variation amplitude parameters of the component time-frequency dimension are extracted as the time-frequency coefficient of variation. This step is implemented by using the Shannon entropy formula to calculate the sequence disorder as information entropy for each high-frequency subband component sequence. Specifically, the information entropy is calculated by normalizing the sequence values to a probability distribution and applying the Shannon entropy formula to sum the probabilities multiplied by the negative of the log probability. Simultaneously, for the same component sequence, the standard deviation of the time-frequency dimension is calculated divided by the mean as the time-frequency coefficient of variation. Specifically, the variation amplitude parameter is extracted by calculating the mean of the sequence values in the time dimension, such as 0.5 and 0.6, with a calculated mean of 0.55 and a standard deviation of 0.05. The coefficient of variation is equal to the standard deviation of 0.05 divided by the mean of 0.55, which is approximately 0.09. For example, in practical applications, a high-frequency subband component sequence has values of 0.3 and 0.7, and the probability distribution after normalization is 0.3 / 1 and 0.7 / 1. The entropy value calculated by the Shannon entropy formula is the negative value of Log0.3 of probability 0.3 multiplied by 0.3 plus the negative value of Log0.7 of probability 0.7 multiplied by 0.7, which is approximately 0.881. The information entropy output is 0.881. The mean of the same sequence is 0.5, the standard deviation is 0.2, and the time-frequency variation coefficient is calculated as 0.2 divided by 0.5, which is equal to 0.4.
[0042] Finally, in step 1033, a predefined anomaly template containing weighted ratio parameters and benchmark reference values is loaded, the energy spectral density, information entropy, and time-frequency variation coefficient are input into the weighted calculation model, a fusion operation is performed, and the fusion result is subjected to normalization adjustment processing to generate a frequency domain composite anomaly index representing the energy distribution, complexity, and stability of the heartbeat signal. The implementation process of this step includes loading a predefined anomaly template from a configuration file such as a JSON file, the template containing weighted ratio parameters such as energy spectral density weight 0.4, information entropy weight 0.3, and variation coefficient weight 0.3, as well as benchmark reference values such as energy spectral density benchmark 1.0, information entropy benchmark 1.0, and variation coefficient benchmark 0.2, then inputting the indicators output from steps 1031 and 1032 into the weighted calculation model and performing a weighted fusion operation. Specifically, the fusion operation is performed by multiplying each indicator by the weight using a weighted summation formula and then summing them. Then, the fusion result is subjected to normalization adjustment processing. Specifically, the normalization is to calculate the difference between the weighted fusion value and the benchmark reference value, divide it by the benchmark value range, multiply it by 100 to convert it into a percentage value, and output the frequency domain composite anomaly index. For example, in actual applications, the input energy spectral density is 0.732, the information entropy is 0.881, and the time-frequency variation coefficient is 0.4. The template weights are 0.4, 0.3, and 0.3 respectively, and the benchmark values are 1.0, 1.0, and 0.2 respectively. The weighted fusion calculation is 0.732 multiplied by 0.4 plus 0.881 multiplied by 0.3 plus 0.4 multiplied by 0.3, which is approximately 0.2928 plus 0.2643 plus 0.12, which equals 0.6771. The benchmark value range for normalization is set to 0.5. The calculated normalized value is equal to 0.6771 minus 0 benchmark and the range of 0.5. The normalized output is 0.6771 divided by 0.5 multiplied by 100, which equals 135.42. This means that an abnormality index higher than 100 is abnormal, and a frequency domain composite abnormality index of 135.42 is generated to evaluate the degree of abnormality of the heartbeat signal.
[0043] In a real-world application, within a network security monitoring platform, technicians conducted an in-depth analysis of encrypted traffic collected from Data Center B. They first captured 15 consecutive minutes of TLS encrypted payload from the network's edge gateway, creating a traffic matrix consisting of 4,500 200-millisecond time windows. When the system processed time window 1024, it performed a three-level wavelet packet decomposition on the 1,840-byte payload. Using the DB4 wavelet basis function, a seven-layer iterative calculation was performed, ultimately generating 16 subband components covering the 0-500 Hz frequency range. Three key high-frequency sub-bands (215-245Hz, 335-370Hz, and 410-440Hz) were selected for feature extraction. For the 245Hz bandwidth sub-band, the sum of squares of the data points was calculated to be 18,740, which was then divided by the 30Hz bandwidth to obtain a unit frequency energy value of 624.7, which was then multiplied by the preset calibration coefficient of 1.15 to generate an energy spectral density of 718.4. The information entropy of the sub-band was calculated based on the distribution of 256 byte values and obtained to be 2.48. The time-frequency fluctuation was analyzed through a sliding window to extract a coefficient of variation of 0.22. The system calls the preset anomaly detection template and performs weighted fusion with an energy spectrum density weight of 0.45, an information entropy weight of 0.3, and a coefficient of variation weight of 0.25 (718.4×0.45+2.48×0.3+0.22×0.25=324.28). After being converted by a standardized function, a -0.87 frequency domain composite anomaly index is generated. This index dynamically reflects the energy focus, data chaos characteristics, and transmission stability of potential control instructions in the current communication flow.
[0044] In the overall solution of step 103 above, after extracting high-frequency subband components through multi-level wavelet packet decomposition of the transport layer encrypted traffic matrix, the three characteristic parameters of energy spectral density, information entropy, and time-frequency variation coefficient are systematically calculated. Based on the weight configuration and benchmark parameter settings for various indicators in the predefined anomaly detection template, the dynamic weighted fusion model comprehensively quantifies the signal energy distribution form, complexity characteristics, and frequency domain stability performance. After standardized calibration, a multi-dimensional frequency domain composite anomaly index is finally generated. By integrating the energy intensity spectral characteristics of the high-frequency subbands, the statistical chaos characteristics of the sequence, and the time-frequency fluctuation characteristics, this index comprehensively represents the degree of abnormal deviation of the encrypted heartbeat signal in the three dimensions of energy distribution balance, information structure complexity, and time stability, providing a quantitative judgment at the frequency domain level for subsequent abnormal communication detection.
[0045] 104. Fusing the frequency domain composite anomaly indicator and the threat fingerprint through a multi-head attention mechanism, identifying the periodic characteristics of the command and control heartbeat signal and the protocol violation pattern hidden in the encrypted traffic, and generating a threat confidence score; Optionally, step 104 may specifically include the following steps: 1041. Construct a multi-head attention model and input the frequency domain composite anomaly index and the threat fingerprint. Focus on different feature dimensions through multiple attention heads and calculate the adjustment feature contribution ratios of multiple weight distribution matrices. Among them, step 1041 may specifically include the following processes: constructing a multi-head attention model, the multi-head attention model includes a projection matrix group and an attention head component group, the projection matrix group includes three groups of projection matrices, and the number is equal to the number of attention heads; inputting the frequency domain composite anomaly index and the threat fingerprint into the multi-head attention model, performing an alignment operation to generate feature data, multiplying the feature data with the three groups of projection matrices in the projection matrix group respectively to generate query projection data, key projection data and value projection data; dividing the query projection data, key projection data and value projection data into multiple sub-blocks, and inputting each sub-block into the corresponding attention matrix in the attention head component group. The attention head component multiplies the sub-block of the query projection data and the transposed matrix of the sub-block of the key projection data to generate an original weight matrix, divides the original weight matrix by the square root of the feature dimension to generate a scaled weight matrix, performs exponential operation on the scaled weight matrix row by row and sums them to generate a weight distribution matrix; performs weight calculation inside each attention head component, multiplies the weight distribution matrix with the sub-block of the value projection data to generate head output data, performs proportional distribution calculation, multiplies the head output data by a preset head weight coefficient to output a proportional calculation result; the proportional calculation results of all attention head components are spliced along the feature dimension to generate the adjusted feature contribution ratio of multiple weight distribution matrices.
[0046] 1042. Generate a fused feature vector based on the contribution ratio of the regulated features of multiple weight distribution matrices, identify the periodic repetitive signal pattern of the command and control heartbeat signal hidden in the encrypted traffic from the fused feature vector as the periodic feature of the heartbeat signal, and detect the deviation sequence from the standard protocol rule as the protocol violation pattern, integrate the heartbeat signal periodic feature and the protocol violation pattern to generate a threat confidence score.
[0047] In the above steps, the multi-head attention mechanism refers to a neural network component that uses multiple parallel attention modules to process input data. The frequency domain composite anomaly index refers to the numerical value output from the previous step, reflecting the degree of energy anomaly of the heartbeat signal in the frequency domain. The threat fingerprint refers to a dynamically updated malicious behavior identifier, such as a unique string ID. The attention head refers to an independent module in the multi-head attention, each module focusing on a different part of the input. The projection matrix group refers to a collection of weight matrices used to map the input data into different spaces. The query projection data refers to the vector data used to retrieve relevant information after projection. The key projection data refers to the key vector data used to match the query. The value projection data refers to the vector data storing the actual value. The weight distribution matrix refers to the matrix representing the probability of attention allocation. The adjusted feature contribution ratio refers to the calculated weight value indicating the importance of different features in the fusion. The fused feature vector refers to the unified vector representation formed by integrating all features. The periodic feature of the command and control heartbeat signal refers to the periodically repeated signal pattern detected in the encrypted traffic, such as the timed communication sequence. The protocol violation pattern refers to the sequence identified that deviates from the standard protocol rules. The threat confidence score refers to the generated numerical score indicating the confidence level of the detected threat.
[0048] In an embodiment of the present application, first, through step 1041, a multi-head attention model is constructed and the frequency domain composite anomaly index and the threat fingerprint are input. By focusing on different feature dimensions through multiple attention heads, the adjustment feature contribution ratio of multiple weight distribution matrices is calculated. The implementation process of this step includes constructing a multi-head attention model, which includes a projection matrix group and an attention head component group, wherein the projection matrix group is composed of three groups of pre-trained weight matrices, the number of which is equal to the number of attention heads, and then inputting the frequency domain composite anomaly index and the threat fingerprint. The specific alignment operation is to splice or element-wise average two input feature sequences such as numerical arrays to generate feature data vectors, and then multiply the feature data vectors with the three groups of matrices of the projection matrix group respectively to generate query projection data, key projection data and value projection data, and then divide these projection data into multiple sub-blocks, each sub-block corresponds to an attention head. If 4 attention heads are set, the projection data is divided into 4 equal blocks, and each sub-block is input Enter the corresponding attention head component. Inside each component, the query projection sub-block and the key projection sub-block are multiplied by the transposed matrix to generate the original weight matrix, and then the original weight matrix is divided by the square root of the feature dimension for scaling. Then, the scaled weight matrix is subjected to exponential operation row by row and summed to generate a weight distribution matrix. Specifically, the softmax operation is to calculate the exponential value and divide it by the sum of the row exponents to normalize it into a probability distribution. Then, inside the attention head, the weight distribution matrix is multiplied by the value projection data sub-block to generate the head output data, and the proportional distribution calculation is performed. This process is repeated for all attention heads, and finally the proportional calculation results of all heads are spliced along the feature dimension to generate the adjusted feature contribution ratio of multiple weight distribution matrices. For example, the input frequency domain composite anomaly index value is 100, the threat fingerprint numerical code is 120, and the feature data vector is constructed as [100, 120]. The projection matrix uses a simple diagonal matrix such as [[1,0], [0,1]] to multiply and query the projection data [100,120]. The key projection data is the same, and the value projection data is [100,120]. It is divided into 2 sub-blocks corresponding to 2 attention heads. The sub-blocks are query block
[100] , key block
[100] , and value block
[100] . The original weight matrix is calculated by multiplying 100 by 100 and transposing it to 10000. The scaling process is divided by the square root of 2, which is approximately 7071. The weight distribution matrix has a probability of 1 after softmax. The head output data is 100 multiplied by the weight 1 to get 100. The ratio calculation is multiplied by the head weight coefficient 0.5 to get 50. The other head outputs 50 similarly. After splicing, the feature contribution ratio is adjusted to the vector [50,50] for subsequent feature fusion.
[0049] Secondly, through step 1042, based on the contribution ratio of the adjustment features of multiple weight distribution matrices, a fused feature vector is generated, and the periodic repetitive signal pattern of the command and control heartbeat signal hidden in the encrypted traffic is identified from the fused feature vector as a periodic feature of the heartbeat signal, and the deviation sequence from the standard protocol rules is detected as a protocol violation pattern, and the heartbeat signal periodic feature and the protocol violation pattern are integrated to generate a threat confidence score. The implementation process of this step includes: first, based on the adjustment feature contribution ratio vector as input, a fused feature vector is generated through splicing or weighted summation operation, and then the periodic repetitive signal pattern is identified from the fused feature vector, and the repetitive pattern is detected using the fast Fourier transform algorithm or autocorrelation analysis. The frequency component is calculated by applying FFT, and the peak position corresponds to the periodic feature, such as the repetitive pattern every 5 time units. The periodic feature of the heartbeat signal is output, and the deviation sequence from the standard protocol rule is detected at the same time. The pre-stored protocol rule template such as the handshake step sequence is loaded, and the deviation of the fused feature vector sequence is compared. For example, the rule requires the sequence value to be stable, but a large fluctuation is detected, and the standard deviation or difference is calculated as the protocol violation pattern. Finally, the periodic feature and the violation pattern value are integrated, and the threat confidence score is generated using linear weighting or logistic regression. For example, if the input adjustment ratio vector is [50, 30, 70], a fused feature vector [50, 30, 70] is generated. FFT is applied to detect the presence of a periodic peak interval of 2 units in the sequence, outputting a heartbeat signal periodic feature value of 0.9. At the same time, the rule template expectation value is compared to calculate the root mean square deviation of the sequence [50, 30, 70] within a stationary difference of less than 10, and the output protocol violation mode value is 0.5. The integrated weight is 0.7 multiplied by 0.9 plus 0.3 multiplied by 0.5, which is 0.78. The resulting threat confidence score is 0.78, indicating medium-high threat confidence.
[0050] In a real-world application, during the operation of a cybersecurity system, technicians conducted an in-depth analysis of encrypted traffic in the 200-millisecond time window of the 217th event. The system's feature extraction module receives two key inputs: a frequency-domain composite anomaly indicator value of -0.76 generated by wavelet packet decomposition, and a dynamically updated 128-bit hexadecimal threat fingerprint identifier of 3E5A7B. Processing is performed using a three-head attention fusion mechanism. First, a multi-head attention architecture consisting of three sets of 384-dimensional projection matrices is constructed to uniformly transform the two features into a 768-dimensional combination vector. Operations are performed using the projection matrix group. The frequency-domain anomaly indicator is projected using the weight matrices WQ1, WK1, and WV1 to generate a 256-dimensional query vector, a key vector, and a value vector. The threat fingerprint is projected using the matrix group WQ2, WK2, and WV2 to generate a three-vector group of corresponding dimensions. In the first attention head processing stage, the 215-dimensional query block is multiplied by the transposed key block matrix to produce the original weight matrix elements, whose values range from -12.8 to +15.3. This matrix is divided by the square root of the feature dimension, 32, and then scaled to a range of -0.4 to +0.48. Normalization is then performed on the row-wise exponential to obtain a weight distribution matrix, where the maximum value of 0.92 clearly highlights the frequency-domain fluctuation characteristics of the anomaly indicator. This weight matrix is then multiplied by the 136-dimensional value vector block to generate the head output data, which is then multiplied by the preset head weight coefficient of 0.33. In subsequent parallel processing, the second attention head detects a weight peak of 0.87, corresponding to a protocol violation signature within the threat fingerprint. The third attention head captures a periodic signal pattern in the time dimension, with a peak amplitude of 0.94 pulses separated by 0.72 seconds in the weight distribution matrix. The outputs of the three attention heads are concatenated along the feature dimension to form a 1024-dimensional fused feature vector, from which two key threat signatures are identified: the periodicity of the heartbeat signal, manifested as a recurring energy spike every 0.72 seconds at the spectral level, with a temporal standard deviation of only 0.05 seconds; and the protocol violation pattern, manifested as three consecutive sequences of anomalous data blocks that deviate from the Transport Layer Security protocol handshake specification, each block being 403 bytes long. Finally, the features are integrated through the fully connected layer to output a threat confidence score of 0.86, which quantifies the credible threat level of latent command and control communications in the current encrypted stream.
[0051] In the overall solution of step 104 above, a multi-head attention mechanism is used to fuse frequency-domain composite anomaly indicators and threat fingerprint data. The system utilizes multiple attention heads to focus on different feature dimensions and calculate the adjusted feature contribution ratio of the weight distribution matrix. This then generates a fused feature vector, from which the periodic characteristics of the command and control heartbeat signal and its protocol violation patterns hidden within the encrypted traffic are accurately identified, ultimately generating a comprehensive threat confidence score. This technology leverages the attention head weight distribution mechanism to adjust the contribution ratio of the frequency-domain energy anomaly indicator and the threat fingerprint feature. It then simultaneously detects periodic communication patterns and protocol rule deviation sequences within the integrated fused features, achieving a joint analysis of the multi-dimensional features of the encrypted heartbeat signal and generating a confidence score that quantitatively represents the threat risk.
[0052] 105. If the threat confidence score exceeds the preset risk threshold, the dynamic rule chain engine is activated to intercept the corresponding communication traffic, and the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time are used as new attack features. After the validity is confirmed through the verification mechanism, the updates are fed back to the threat intelligence library to achieve a closed-loop linkage between threat defense and intelligence updates.
[0053] Optionally, step 105 may specifically include the following steps: 1051. Compare the threat confidence score with a preset risk threshold. If the threat confidence score exceeds the preset risk threshold, activate a dynamic rule chaining engine to intercept corresponding communication traffic. 1052. Block the corresponding communication traffic based on the rule chain, extract the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time, and form a new attack feature; 1053. The credibility of the new attack feature is verified through a verification mechanism, and the data block of the new attack feature that is verified to be valid is added to the control communication feature, and the updated data is fed back to the threat intelligence library to achieve a closed-loop linkage between threat defense and intelligence update.
[0054] In the above steps, the threat confidence score refers to the numerical score generated from step 104, which represents the credibility level of the detected threat, the preset risk threshold refers to the pre-set danger judgment critical value, the dynamic rule chain engine refers to the program module that can modify the interception rules, the new attack feature refers to the malicious behavior pattern data identified this time, including the periodic characteristics of the heartbeat signal and the protocol violation pattern, the verification mechanism refers to the method of verifying the effectiveness of the new feature through the testing process, the feedback update refers to the feedback of the verified new data to the database, the threat intelligence library refers to the database that stores the characteristics of malicious activities, and the closed-loop linkage refers to the formation of a complete cycle system of detection, defense, and update.
[0055] In the embodiment of the present application, first, step 1051 is used to compare the threat confidence score with the preset risk threshold. If the score exceeds the threshold, the dynamic rule chain engine is activated to intercept the corresponding communication traffic. The implementation process of this step includes comparing the threat confidence score output in step 104, such as a value of 0.78, with a preset risk threshold, such as a set value of 0.7. If 0.78 is greater than 0.7, an activation instruction is triggered. The specific activation operation is to call the rule chain engine interface and send an interception command containing a traffic identifier. For example, after the engine receives the command, it blocks TLS encrypted traffic with a source address of 19216811. For example, in an actual application, the input threat confidence score is 0.85, and the preset risk threshold is 0.6. Because 0.85 is greater than 0.6, the rule chain engine is triggered to intercept the target IP communication.
[0056] Next, through step 1052, based on the rule chain blocking the corresponding communication traffic, the heartbeat signal periodicity characteristics and protocol violation patterns identified this time are extracted to form a new attack feature. The implementation process of this step includes, after the rule chain engine completes the traffic interception, extracting the heartbeat signal periodicity characteristics recorded in step 104, such as the cycle time value of 2 seconds, and the protocol violation pattern, such as the handshake step missing mark. The specific extraction operation is to copy the calculation result metadata of this round of detection and integrate the two features into a structured data object as a new attack feature. For example, in actual applications, the heartbeat signal periodicity characteristic value is a repetition interval of 3 seconds, and the protocol violation pattern value is a packet length abnormality mark. The integration generates a new attack feature object containing fields.
[0057] Finally, in step 1053, the credibility of the new attack signature is verified through a verification mechanism. The verified new attack signature data block is added to the control communication signature and fed back to the threat intelligence library for update, achieving a closed-loop linkage. The implementation process of this step includes executing a verification mechanism on the new attack signature. Specifically, the verification is performed by replaying historical traffic to test its detection accuracy and calculating reliability indicators such as false alarm rate. If the false alarm rate is less than 5, it is considered credible. For example, if the attack traffic is correctly identified 90 times out of 100 replay tests, it is verified to be valid. The signature object is then converted to a database-compatible format and added to the control communication signature list of the threat intelligence library. For example, the new signature is appended to the signature library JSON file, completing the threat intelligence library update, ultimately forming a closed-loop process from detection to defense and then to knowledge update. For example, in actual applications, a new attack signature is verified through 500 test traffic with an accuracy rate of 95%. After being determined to be valid, it is updated to the threat intelligence library and a new entry with the signature ID CMD999 is added.
[0058] In actual application, during the implementation of a large-scale network security platform, while analyzing ingress traffic at the C Financial Data Center, the system identified a specific encrypted session with a threat confidence score of 0.83, exceeding the pre-set risk threshold of 0.75. The system immediately activated the dynamic rule chaining engine and generated three interception strategies to block communications on the target port of the session. Technicians extracted the core attack signatures detected: a signature template for a 1.2-second heartbeat signal energy spike and a packet sequence pattern that violated the Transport Layer Security (TLS) handshake process three times in a row. These were combined into a new attack signature template. This signature template was sent to an isolated verification environment for dual validation through replaying attack traffic and continuously monitoring behavioral patterns. After 72 hours of validation, it was confirmed that the signature had an accuracy rate of over 95% for similar malicious communications. This signature was ultimately compiled into a hexadecimal signature code and synchronized with the eighth version of the control communication signature set in the D Threat Intelligence Library, forming a closed-loop mechanism with immediate defense strategy implementation and dynamic feedback from attack signatures.
[0059] In the overall solution of step 105 above, when the threat confidence score exceeds the preset risk threshold, the dynamic rule chain execution engine is automatically activated to intercept the target encrypted traffic. At the same time, the detected heartbeat signal periodic characteristics and protocol violation patterns are structured and extracted as new attack features. After the feature validity verification is completed through the automated credibility verification process, the verified new attack feature data block is reversely injected into the command and control communication feature set in the threat intelligence library, thereby forming a closed-loop linkage mechanism of attack behavior blocking and threat feature autonomous evolution, and ultimately achieving continuous dynamic enhancement of threat defense capabilities.
[0060] The following is a complete example of steps 101 to 105: like Figure 2 As shown in the figure, in a network security practice at an enterprise data center, the system monitors Transport Layer Security (TLS) encrypted traffic. First, a 25-minute payload byte stream is collected and segmented into 200-millisecond time windows to generate 750 time-series traffic matrices. When processing window 518, the system analyzes the communication metadata of the 1920-byte payload and matches it with 120 known control communication features in the threat intelligence database. The highest match score is 0.88, and three abnormal handshake behaviors are detected. Based on this, a 128-bit threat fingerprint 9F4A2C is dynamically generated. A 4-level wavelet packet decomposition is performed on this window. The unit frequency energy value of 624 is calculated in the high-frequency subband of 285-320 Hz. Calibrated with a coefficient of 1.15, the energy spectral density is 717.6. Simultaneously, an information entropy of 2.53 and a time-frequency coefficient of variation of 0.21 are obtained. These three parameters are fused with a weighting of 0.45:0.3:0.25, and the output is a normalized frequency domain composite anomaly index of -0.84.
[0061] Anomaly indicators and threat fingerprints are fused using a three-head attention mechanism: the first head captures periodic energy pulses with an interval of 1.28 seconds ± 0.03 seconds, with a peak weight of 0.93; the second head identifies four consecutive anomalous data packets (398, 417, 435, and 452 bytes in length); and the third head correlates the threat fingerprint features with a weighting coefficient of 0.89. This fusion generates a 1024-dimensional feature vector, which is then passed through a fully connected layer to calculate a threat confidence score of 0.84.
[0062] When the score exceeds the preset threshold of 0.8, the dynamic rule chaining engine blocks the target IP's port 443 communication within 300 milliseconds. The extracted heartbeat cycle signature and protocol violation sequence were sandbox-verified: 20,000 replays of the attack traffic confirmed a cycle signature detection accuracy rate exceeding 95%, and a 100% reproducibility rate for protocol deviation behavior. After 28 hours, the compiled signature code CTI-213 was updated to the threat intelligence database and simultaneously distributed to 350 protection nodes across the network, achieving a complete closed-loop defense from attack occurrence to signature update.
[0063] Figure 3 The present invention provides a schematic diagram of a network information security adaptive threat intelligence analysis and response system. Figure 3 As shown, the system includes: The acquisition module 31 is used to collect the payload byte stream in the transport layer security protocol encrypted traffic, split the payload byte stream into fixed time windows, and generate a time-series traffic matrix; a matching module 32 for parsing communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in a threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavioral anomaly determination results; A decomposition module 33 is configured to perform multi-level wavelet packet decomposition on the flow matrix, extract the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component, and perform weighted fusion and normalization on the energy spectrum density, information entropy, and variation coefficient based on a predefined anomaly template to generate a frequency-domain composite anomaly index that characterizes the energy distribution, complexity, and stability of the heartbeat signal; A fusion module 34 is configured to fuse the frequency domain composite anomaly indicator and the threat fingerprint through a multi-head attention mechanism, identify the periodic characteristics of the command and control heartbeat signal and the protocol violation pattern hidden in the encrypted traffic, and generate a threat confidence score; The activation module 35 is used to activate the dynamic rule chain engine to intercept the corresponding communication traffic if the threat confidence score exceeds the preset risk threshold, and use the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time as new attack features. After confirming the validity through the verification mechanism, it is fed back to the threat intelligence library for update, thereby realizing a closed-loop linkage between threat defense and intelligence update.
[0064] Figure 3 The network information security adaptive threat intelligence analysis and response system can perform Figure 1 The implementation principles and technical effects of the network information security adaptive threat intelligence analysis and response method described in the illustrated embodiment are not further elaborated. The specific manner in which each module and unit performs operations in the network information security adaptive threat intelligence analysis and response system in the above embodiment has been described in detail in the embodiment of the method and will not be elaborated on here.
[0065] In one possible design, Figure 3 A network information security adaptive threat intelligence analysis and response system of the embodiment shown can be implemented as a computing device, such as Figure 4 As shown, the computing device may include a storage component 41 and a processing component 42; The storage component 41 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 42 .
[0066] The processing component 42 is used for the above Figure 1 The network information security adaptive threat intelligence analysis and response method of the embodiment.
[0067] The processing component 42 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented as one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above method.
[0068] The storage component 41 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0069] Of course, a computing device may also include other components, such as input / output interfaces, display components, communication components, etc.
[0070] The input / output interface provides an interface between the processing component and the peripheral interface module, which can be an output device, an input device, etc.
[0071] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.
[0072] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.
[0073] The present application also provides a computer storage medium storing a computer program, wherein the computer program can achieve the above-mentioned Figure 1 A network information security adaptive threat intelligence analysis and response method according to the illustrated embodiment.
[0074] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0075] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0076] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer or server) to execute the methods described in each embodiment or certain portions of the embodiments.
[0077] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A network information security adaptive threat intelligence analysis and response method, characterized in that: include: Collecting the payload byte stream in the transport layer security protocol encrypted traffic, dividing the payload byte stream into fixed time windows, and generating a time-series traffic matrix; Parsing the communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in a threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavioral anomaly determination results; Perform multi-level wavelet packet decomposition on the traffic matrix to extract the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component. Based on a predefined abnormality template, the energy spectrum density, information entropy, and variation coefficient are weighted and normalized to generate a frequency-domain composite abnormality index that characterizes the energy distribution, complexity, and stability of the heartbeat signal. The frequency domain composite anomaly indicator and the threat fingerprint are integrated through a multi-head attention mechanism to identify the periodic characteristics of the command and control heartbeat signal and the protocol violation pattern hidden in the encrypted traffic, and generate a threat confidence score; If the threat confidence score exceeds the preset risk threshold, the dynamic rule chain engine is activated to intercept the corresponding communication traffic, and the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time are used as new attack features. After the validity is confirmed through the verification mechanism, it is fed back to the threat intelligence library for update, realizing a closed-loop linkage between threat defense and intelligence update.
2. The method according to claim 1, characterized in that Perform multi-level wavelet packet decomposition on the traffic matrix to extract the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component. Based on a predefined abnormality template, perform weighted fusion and normalization on the energy spectrum density, information entropy, and variation coefficient to generate a frequency domain composite abnormality index that characterizes the energy distribution, complexity, and stability of the heartbeat signal, including: Performing a multi-scale decomposition operation on the traffic matrix to generate a plurality of sub-band components in the frequency domain, calculating a unit frequency energy value for each high-frequency sub-band component, and generating an energy spectral density based on the unit frequency energy value; At the same time, the sequence disorder of the component sequence is calculated as the information entropy, and the variation amplitude parameter of the component time-frequency dimension is extracted as the time-frequency variation coefficient; A predefined anomaly template containing weighted ratio parameters and benchmark reference values is loaded, the energy spectral density, information entropy and time-frequency variation coefficient are input into a weighted calculation model, a fusion operation is performed, and a standardized adjustment process is performed on the fusion result to generate a frequency domain composite anomaly indicator that characterizes the energy distribution, complexity and stability of the heartbeat signal.
3. The method according to claim 2, characterized in that Performing a multi-scale decomposition operation on the traffic matrix to generate multiple frequency domain sub-band components, calculating a unit frequency energy value for each high frequency sub-band component, and generating an energy spectral density based on the unit frequency energy value, including: Performing a multi-level decomposition operation on the traffic matrix, splitting the input component into a low-frequency component and a high-frequency component at each level of decomposition, repeating the multi-level decomposition operation until a preset number of levels is reached, and generating a plurality of frequency domain sub-band components; Filtering all the frequency domain sub-band components marked as high frequency, and for each high frequency sub-band component, calculating the sum of squares of the values of each high frequency component, and dividing the sum by the frequency range width of the high frequency component to generate a unit frequency energy value; The energy value per unit frequency is multiplied by a preset coefficient, and the output is an energy spectrum density representing the energy intensity.
4. The method according to claim 1, wherein The frequency domain composite anomaly indicator and the threat fingerprint are integrated through a multi-head attention mechanism to identify the periodic characteristics of the command and control heartbeat signal and protocol violation patterns hidden in the encrypted traffic, and generate a threat confidence score, including: Constructing a multi-head attention model and inputting the frequency domain composite anomaly index and the threat fingerprint, focusing on different feature dimensions through multiple attention heads, and calculating the adjustment feature contribution ratios of multiple weight distribution matrices; Based on the contribution ratio of the regulated features of multiple weight distribution matrices, a fused feature vector is generated. The periodic repetitive signal pattern of the command and control heartbeat signal hidden in the encrypted traffic is identified from the fused feature vector as the periodic feature of the heartbeat signal, and the deviation sequence from the standard protocol rules is detected as a protocol violation pattern. The heartbeat signal periodic feature and the protocol violation pattern are integrated to generate a threat confidence score.
5. The method according to claim 4, characterized in that Construct a multi-head attention model and input the frequency domain composite anomaly index and the threat fingerprint. Use multiple attention heads to focus on different feature dimensions and calculate the contribution ratio of the adjusted features of multiple weight distribution matrices, including: Construct a multi-head attention model, wherein the multi-head attention model includes a projection matrix group and an attention head component group, wherein the projection matrix group includes three sets of projection matrices, and the number of the projection matrices is equal to the number of attention heads; Inputting the frequency domain composite anomaly indicator and the threat fingerprint into the multi-head attention model, performing an alignment operation to generate feature data, and multiplying the feature data by the three projection matrices in the projection matrix group to generate query projection data, key projection data, and value projection data; Splitting the query projection data, key projection data, and value projection data into a plurality of sub-blocks, inputting each sub-block into a corresponding attention head component in the attention head component group, multiplying the sub-block of the query projection data by the transposed matrix of the sub-block of the key projection data to generate an original weight matrix, dividing the original weight matrix by the square root of the feature dimension to generate a scaled weight matrix, performing an exponential operation on the scaled weight matrix row by row, and summing the results to generate a weight distribution matrix; Perform weight calculation within each attention head component, multiply the weight distribution matrix by the value projection data sub-block to generate head output data, perform proportional distribution calculation, multiply the head output data by a preset head weight coefficient to output a proportional calculation result; The ratio calculation results of all attention head components are spliced along the feature dimension to generate the adjusted feature contribution ratios of multiple weight distribution matrices.
6. The method according to claim 1, characterized in that If the threat confidence score exceeds the preset risk threshold, the dynamic rule chain engine is activated to intercept the corresponding communication traffic. The identified heartbeat signal periodicity and protocol violation pattern are used as new attack signatures. After the validity is confirmed through the verification mechanism, the signatures are fed back to the threat intelligence library, achieving a closed-loop linkage between threat defense and intelligence updates, including: Comparing the threat confidence score with a preset risk threshold, and activating a dynamic rule chaining engine to intercept corresponding communication traffic if the threat confidence score exceeds the preset risk threshold; Based on the rule chain, the corresponding communication traffic is blocked, and the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time are extracted to form new attack characteristics; The credibility of the new attack feature is checked through a verification mechanism, and the data block of the verified new attack feature is added to the control communication feature, which is then fed back to the threat intelligence library for update, thus realizing a closed-loop linkage between threat defense and intelligence update.
7. The method according to claim 1, characterized in that Parsing the communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in the threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavioral anomaly determination results, including: Separating communication metadata from the payload byte stream, retrieving command and control communication features from the threat intelligence library, and using a similarity calculation mechanism to perform item-by-item pairing comparisons between the communication metadata and the control communication features to obtain a matching correlation value; Perform protocol rule verification checks, determine the compliance of communication behavior against the standard protocol specification process template, obtain protocol compliance determination results, detect the time interval distribution and data volume deviation of the communication sequence, and generate behavior anomaly indication values; The matching correlation degree value, protocol compliance determination result and behavior anomaly indication value are integrated. When the behavior anomaly indication value exceeds a predefined threshold, the corresponding new communication mode is added to the control communication feature to generate a threat fingerprint in the form of a dynamically updated storable digital identifier.
8. A network information security adaptive threat intelligence analysis and response system, characterized in that: include: A collection module is used to collect the payload byte stream in the transport layer security protocol encrypted traffic, split the payload byte stream into fixed time windows, and generate a time-series traffic matrix; a matching module for parsing communication metadata of the payload byte stream, matching and correlating the communication metadata with known command and control communication features in a threat intelligence library, and generating a dynamically updated threat fingerprint based on protocol compliance and behavioral anomaly determination results; a decomposition module for performing multi-level wavelet packet decomposition on the traffic matrix, extracting the energy spectrum density, information entropy, and time-frequency variation coefficient of each high-frequency sub-band component, and performing weighted fusion and normalization on the energy spectrum density, information entropy, and variation coefficient based on a predefined anomaly template to generate a frequency-domain composite anomaly index that characterizes the energy distribution, complexity, and stability of the heartbeat signal; A fusion module is configured to fuse the frequency domain composite anomaly indicator and the threat fingerprint through a multi-head attention mechanism, identify the periodic characteristics of the command and control heartbeat signal and the protocol violation pattern hidden in the encrypted traffic, and generate a threat confidence score; The activation module is used to activate the dynamic rule chain engine to intercept the corresponding communication traffic if the threat confidence score exceeds the preset risk threshold, and use the periodic characteristics of the heartbeat signal and the protocol violation pattern identified this time as new attack features. After confirming the validity through the verification mechanism, it is fed back to the threat intelligence library for update, realizing a closed-loop linkage between threat defense and intelligence update.
9. A computing device, characterized in that It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a network information security adaptive threat intelligence analysis and response method as described in any one of claims 1 to 7.
10. A computer storage medium, characterized in that A computer program is stored, and when the computer program is executed by a computer, a network information security adaptive threat intelligence analysis and response method as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Threat entity extraction method based on autoregression tag subsequences
CN118536508A
Self-evolution network security defense strategy generation and dynamic deployment method
CN119561793A
Network security active defense method and system for detecting abnormal network behaviors
CN119628910A
Network security penetration detection method and system based on artificial intelligence
CN120050079A
System and Method of Cyber Threat Intensity Determination and Application to Cyber Threat Mitigation
US20160241581A1
Cited By
Network intrusion prevention method and system based on embedded real-time operating system terminal
CN120825347A
Network intrusion prevention method and system based on embedded real-time operating system terminal
CN120825347B
Micro-isolation and differential encryption method and system based on industrial protocol perception and medium
CN121077782A
Micro-isolation and differential encryption method, system and medium based on industrial protocol perception
CN121077782B
Computer-based network monitoring system and method
CN121193636A