Edge side attack aggregation analysis method based on flow self-learning
By using traffic self-learning models for unsupervised modeling and dynamic honeypot technology on the edge side, unknown suspicious traffic can be identified and deeply analyzed, solving the problem of delayed response of the edge security protection system when facing unknown attacks, and achieving efficient attack tracing and defense.
Patent Information
- Application Number
- CN202511025014.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-12
AI Technical Summary
Existing edge security protection systems are difficult to adapt to unknown or variant attacks, and lack effective in-depth analysis and traceability mechanisms, resulting in delayed security responses and the inability to accurately and efficiently block and counter attack behaviors.
An unsupervised learning model based on traffic self-learning is used to model real-time traffic on the edge side. Unsupervised anomaly detection is used to identify unknown suspicious traffic. After high-threat traffic is detected, a dynamic honeypot environment is automatically orchestrated to conduct deep interaction and behavior capture, extract attack indicators, and ultimately form a highly credible attack evidence chain.
It achieves accurate identification, in-depth analysis and effective tracing of edge-side attacks, and improves the edge network's automated analysis and response capabilities to advanced and unknown attacks.
Smart Images

Figure CN120639490A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network traffic analysis, and more specifically, to an edge-side attack aggregation analysis method based on traffic self-learning. Background Art
[0002] With the rapid development of technologies such as the Internet of Things (IoT), 5G communications, and the Industrial Internet, network boundaries are extending from traditional centralized data centers to distributed edge nodes close to users. While this architectural shift offers the advantages of low latency and high bandwidth, it also shifts the focus of network security protection downward. Edge devices are numerous, diverse, and have limited computing resources, making them ideal targets for cyber attackers, especially those engaged in automated and distributed attacks. Attackers can exploit the vulnerabilities of edge nodes as a springboard to launch large-scale, stealthy attacks, posing a serious threat to the security and stability of the entire network.
[0003] Traditional edge security protection relies heavily on intrusion detection systems (IDS) based on fixed rules or signatures. While these approaches are effective for detecting known attacks, they struggle against unknown or mutated attacks, such as zero-day attacks and advanced persistent threats (APTs). The lag in rule base updates also makes them difficult to adapt to rapidly evolving attack methods. To address this shortcoming, machine learning techniques have been introduced to detect anomalies by modeling network traffic. However, most of these solutions employ supervised learning models and rely heavily on high-quality, large-scale, annotated attack samples. However, obtaining comprehensive attack samples is extremely difficult in real-world edge environments, resulting in insufficient model generalization. Furthermore, existing anomaly detection solutions often lack effective in-depth analysis and forensic tracing mechanisms after discovering suspicious traffic. They typically remain at the alert level, unable to conduct further interactive behavioral analysis of suspicious traffic to confirm the authenticity of the attack. Furthermore, they struggle to effectively correlate alert information distributed across different timeframes and nodes to form a complete chain of attack evidence that can be used for decision-making and response. The lack of this analytical capability leads to delayed security responses and the inability to accurately and efficiently block and counter attacks.
[0004] Therefore, an optimized edge-side attack aggregation analysis solution is expected. Summary of the Invention
[0005] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides an edge-side attack aggregation analysis method based on traffic self-learning, which performs self-learning modeling on the real-time traffic on the edge side through an unsupervised learning model, and intelligently identifies unknown suspicious traffic that deviates from normal behavior patterns in a manner that does not rely on attack samples. Once high-threat traffic is detected, a dynamic honeypot environment will be automatically orchestrated and deployed, and the suspicious traffic will be introduced into an isolated analysis environment through traffic redirection technology. In the honeypot, malicious traffic is deeply interacted and behavior captured to extract high-value attack indicators. Finally, the acquired attack indicators are aggregated and associated with the source information of the traffic to form a complete and highly reliable attack evidence chain. In this way, accurate identification, in-depth analysis and effective tracing of edge-side attacks can be achieved, thereby effectively improving the edge network's automated analysis and response capabilities to advanced and unknown attacks.
[0006] According to one aspect of the present application, a method for edge-side attack aggregation analysis based on traffic self-learning is provided, which includes:
[0007] Obtain the original real-time traffic flow from the edge switch;
[0008] Performing feature engineering on the original real-time traffic flow to obtain a traffic feature vector, where the traffic feature vector includes an IP quintuple;
[0009] Performing GAN-based unsupervised anomaly detection on the traffic feature vector to obtain an anomaly detection result;
[0010] In response to the abnormal detection result being high-risk suspicious traffic, the decision engine generates a honeypot orchestration instruction based on the IP five-tuple;
[0011] In response to the honeypot orchestration instruction, the honeypot management module generates a traffic redirection rule and a honeypot container instance;
[0012] After directing the malicious traffic flow to the honeypot container instance through the traffic redirection rule, performing deep behavioral analysis on the malicious traffic flow to obtain attack indicators;
[0013] The attack indicator and the IP quintuple are combined to obtain an attack evidence chain.
[0014] Compared with the existing technology, the edge-side attack aggregation analysis method based on traffic self-learning provided by this application performs self-learning modeling on the real-time traffic on the edge through an unsupervised learning model, and intelligently identifies unknown suspicious traffic that deviates from normal behavior patterns in a way that does not rely on attack samples. Once high-threat traffic is detected, a dynamic honeypot environment will be automatically orchestrated and deployed, and suspicious traffic will be introduced into an isolated analysis environment through traffic redirection technology. In the honeypot, malicious traffic is deeply interacted and behavior captured to extract high-value attack indicators. Finally, the acquired attack indicators are aggregated and associated with the source information of the traffic to form a complete, highly reliable attack evidence chain. In this way, accurate identification, in-depth analysis and effective tracing of edge-side attacks can be achieved, thereby effectively improving the edge network's automated analysis and response capabilities to advanced, unknown attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0016] Figure 1 This is a flowchart of an edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application.
[0017] Figure 2 This is a data flow diagram of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application.
[0018] Figure 3 This is a flowchart of sub-step S2 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application.
[0019] Figure 4 This is a flowchart of sub-step S3 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application.
[0020] Figure 5 This is a flowchart of sub-step S32 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application.
[0021] Figure 6 This is a flowchart of sub-step S5 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application.
[0022] Figure 7This is a flowchart of sub-step S6 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. DETAILED DESCRIPTION
[0023] As used in this application and the claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" are not intended to refer to the singular but may include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.
[0024] Although the present application makes various references to certain modules in the system according to embodiments of the present application, any number of different modules can be used and run on the user terminal and / or server. The modules are illustrative only, and different aspects of the system and method can use different modules.
[0025] Flowcharts are used in this application to illustrate the operations performed by the systems according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in exact order. Instead, the various steps may be processed in reverse order or simultaneously, as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0026] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0027] It is worth noting that in this application, all actions to obtain data are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.
[0028] In response to the technical problems described in the above background technology, the present application proposes an edge-side attack aggregation analysis method based on traffic self-learning, which uses an unsupervised learning model to self-learn real-time traffic on the edge side, and intelligently identifies unknown suspicious traffic that deviates from normal behavior patterns in a way that does not rely on attack samples. Once high-threat traffic is detected, a dynamic honeypot environment will be automatically orchestrated and deployed, and suspicious traffic will be introduced into an isolated analysis environment through traffic redirection technology. In the honeypot, malicious traffic is deeply interacted and behavior captured to extract high-value attack indicators. Finally, the acquired attack indicators are aggregated and associated with the source information of the traffic to form a complete, highly reliable attack evidence chain. In this way, accurate identification, in-depth analysis and effective tracing of edge-side attacks can be achieved, thereby effectively improving the edge network's automated analysis and response capabilities to advanced, unknown attacks.
[0029] Figure 1 This is a flowchart of an edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 2 Schematic diagram of data flow of edge attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 1 and Figure 2 As shown, the edge-side attack aggregation analysis method based on traffic self-learning includes the following steps: S1, obtaining the original real-time traffic flow from the edge-side switch; S2, performing feature engineering on the original real-time traffic flow to obtain a traffic feature vector, wherein the traffic feature vector includes an IP five-tuple; S3, performing GAN-based unsupervised anomaly detection on the traffic feature vector to obtain an anomaly detection result; S4, in response to the anomaly detection result being high-risk suspicious traffic, the decision engine generates a honeypot orchestration instruction based on the IP five-tuple; S5, in response to the honeypot orchestration instruction, the honeypot management module generates a traffic redirection rule and a honeypot container instance; S6, after guiding the malicious traffic flow to the honeypot container instance through the traffic redirection rule, performing deep behavioral analysis on the malicious traffic flow to obtain an attack indicator; S7, combining the attack indicator and the IP five-tuple to obtain an attack evidence chain.
[0030] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, the step S1 obtains the original real-time traffic flow from the edge-side switch. It should be understood that the edge-side switch, as a traffic aggregation node, carries the real-time communication traffic of all access devices, and these traffic flows may contain potential traces of malicious attacks. By obtaining the original real-time traffic flow, the communication details of various devices in the edge network are fully retained, including normal business traffic and potential malicious traffic. These original data cover key information such as the source and destination addresses, protocol types, and interactive content of the traffic, providing complete and unprocessed basic data for subsequent analysis, ensuring that traffic information of various communication protocols is included, and providing original materials for identifying suspicious traffic that deviates from normal behavior patterns, extracting attack features, and forming an attack evidence chain, thereby supporting the effective implementation of the entire edge-side attack aggregation analysis process.
[0031] During implementation, a high-performance traffic probe is deployed on the mirrored port or behind the optical splitter of an edge switch. This probe uses a hardware-accelerated packet capture engine to non-interferely capture full, real-time traffic. The probe is connected to the switch using optical fiber or high-speed Ethernet cables to ensure port speeds of 10 Gbps or higher, preventing traffic loss due to bandwidth bottlenecks. During the acquisition process, the probe captures all raw data packets flowing through the switch, including MQTT and CoAP protocol traffic from IoT devices, Modbus protocol traffic from industrial control equipment, and traditional TCP / UDP protocol traffic. For each packet, the probe preserves the complete frame structure, including the Ethernet frame header, IP header, transport layer protocol header (TCP / UDP), and application layer payload. Using a built-in high-precision clock module, each packet is timestamped to ensure that the timing characteristics of the traffic accurately reflect the real-time communication status of the edge network. To address traffic bursts caused by the dense deployment of edge devices, the probe is equipped with a dynamic caching mechanism. When the instantaneous traffic exceeds the processing threshold, packets are temporarily stored in a ring buffer and processed later when processing resources are free, preventing data overflow. The collected original traffic is written to the probe's local high-speed storage medium in real time in PCAP format and synchronized to the pre-processing module of the edge-side analysis node through a dedicated encrypted channel. The entire process does not filter or modify the original data packets, ensuring the integrity and originality of the traffic and providing untampered basic data support for subsequent feature engineering.
[0032] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, the step S2 performs feature engineering on the original real-time traffic flow to obtain a traffic feature vector, and the traffic feature vector includes an IP quintuple. It should be understood that the IP quintuple contains the source IP address, destination IP address, source port, destination port, and transport layer protocol type, which can uniquely identify a network connection or session. Specifically, the key features of the original real-time traffic flow are extracted through feature engineering and integrated into a traffic feature vector, and the unstructured original real-time traffic flow data is converted into a structured feature representation that can be directly processed by the model. It can retain key information such as the identity of the traffic, interaction patterns, and behavioral patterns, and provide effective input for subsequent unsupervised anomaly detection based on GAN. Among them, Figure 3 FIG is a flowchart of sub-step S2 of the edge attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 3 As shown, the step S2 includes the following steps: S21, using a high-performance traffic probe to extract non-load features from the original real-time traffic flow, the non-load features including IP quintuple, TLS / SSL handshake features and timing and statistical features; S22, integrating the IP quintuple, TLS / SSL handshake features and timing and statistical features into the traffic feature vector.
[0033] Specifically, in step S21, a high-performance traffic probe is used to extract non-load features from the original real-time traffic flow, and the non-load features include IP quintuples, TLS / SSL handshake features, and timing and statistical features. It should be understood that the IP quintuple is used to identify the communication subject and the communication link, the TLS / SSL handshake features are used to reflect the standard characteristics of the encrypted interaction, and the timing and statistical features are used to reflect the time distribution characteristics and behavioral patterns of the traffic. Specifically, the present application uses a high-performance traffic probe to extract IP quintuples, TLS / SSL handshake features, and timing and statistical features from the original traffic in real time and accurately, ensuring that the acquired non-load features completely cover the identity identification, encryption interaction mode and behavioral patterns of the traffic, providing high-quality, multi-dimensional basic data for subsequent feature integration, while avoiding efficiency loss and decryption complexity caused by processing load content, ensuring the real-time and reliability of feature extraction, and supporting the timeliness requirements of edge-side attack analysis.
[0034] Specifically, the step S22 integrates the IP five-tuple, TLS / SSL handshake features, and timing and statistical features into the traffic feature vector. Specifically, the IP five-tuple, TLS / SSL handshake features, and timing and statistical features are converted into a numerical vector in a unified format, and heterogeneity is eliminated through encoding (such as IP address hashing, protocol parameter mapping) and normalization (such as timing value standardization), ensuring that the traffic feature vector contains complete information on the identity of the traffic, encrypted interaction, and behavioral patterns, forming a fixed-length, structured traffic feature vector, providing standardized input for subsequent operations, so that the model can effectively learn the characteristic distribution of normal traffic.
[0035] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, the step S3 performs GAN-based unsupervised anomaly detection on the traffic feature vector to obtain anomaly detection results. It should be understood that GAN-based unsupervised anomaly detection can capture the normal traffic feature distribution through adversarial learning between the generator and the discriminator, and then identify anomalies. Specifically, the traffic feature vector is subjected to unsupervised anomaly detection through the GAN model, the traffic feature vector is reconstructed using the generator, and the distance and reconstruction loss between the reconstructed feature and the original feature are calculated in combination with the discriminator to obtain an anomaly score, and then the anomaly detection result is generated by comparing with the preset threshold, thereby accurately identifying high-threat suspicious traffic that deviates from normal behavior patterns, and realizing effective detection of unknown attacks on the edge side. Among them, Figure 4 FIG3 is a flowchart of sub-step S3 of the edge attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 4 As shown, the step S3 includes the following steps: S31, inputting the traffic feature vector into the generator of GAN to obtain a reconstructed traffic feature vector; S32, inputting the reconstructed traffic feature vector and the traffic feature vector into the discriminator of GAN to obtain a discriminator feature distance; S33, calculating the reconstruction loss between the reconstructed traffic feature vector and the original traffic feature vector; S34, calculating the anomaly score based on the discriminator feature distance and the reconstruction loss; S35, generating the anomaly detection result based on the comparison between the anomaly score and a preset threshold.
[0036] Specifically, step S31 involves inputting the traffic feature vector into the GAN generator to obtain a reconstructed traffic feature vector. Specifically, the generator employs a multi-layer neural network structure. The first layer uses the ReLU activation function to map the input traffic feature vector to a higher dimension to enhance feature expression. The second layer uses batch normalization to mitigate the vanishing gradient problem and then maps the features to an intermediate dimension. The third layer uses the Sigmoid activation function to map the features back to a reconstructed traffic feature vector with the same dimension as the input vector, ensuring that the output features are within a reasonable numerical range for subsequent comparison with the original feature vector.
[0037] Specifically, in step S32, the reconstructed traffic feature vector and the traffic feature vector are input into the discriminator of the GAN to obtain the discriminator feature distance. It should be understood that the discriminator obtains the intermediate layer activation coding of the reconstructed traffic feature vector and the traffic feature vector through the feature extraction layer, retains the core structural information of the features, and then comprehensively models the temporal and spatial correlation differences between the two in the interactive coding layer. Finally, the dense interactive coding is converted into a specific discriminator feature distance through the decoding layer. The larger the distance value, the more significant the difference between the original feature and the reconstructed feature. Among them, Figure 5 FIG is a flowchart of sub-step S32 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 5 As shown, the step S32 includes the steps of: S321, inputting the reconstructed traffic feature vector and the traffic feature vector into the discriminator of the GAN to obtain the reconstructed traffic feature intermediate layer activation coding vector and the traffic feature intermediate layer activation coding vector; S322, performing feature dense interaction on the reconstructed traffic feature intermediate layer activation coding vector and the traffic feature intermediate layer activation coding vector to obtain the reconstructed traffic feature-original traffic feature dense interaction coding vector; S323, performing feature decoding on the reconstructed traffic feature-original traffic feature dense interaction coding vector to obtain the discriminator feature distance.
[0038] More specifically, in step S321, the reconstructed traffic feature vector and the traffic feature vector are input into the GAN discriminator to obtain the reconstructed traffic feature intermediate layer activation coding vector and the traffic feature intermediate layer activation coding vector. It should be understood that since it is difficult to capture deep structural features by directly comparing the original feature vectors, the GAN discriminator can capture the subtle differences between the original traffic feature vector and the reconstructed traffic feature vector in the feature space by learning the difference pattern between the original traffic feature vector and the reconstructed traffic feature vector. In this way, the intermediate layer activation coding vector that can reflect the core structure of the reconstructed traffic feature and the original traffic feature is obtained from the discriminator processing process, effectively retaining the key structural information of the feature and providing high-quality input for feature-intensive interaction.
[0039] More specifically, in a specific example of the present application, step S322 includes: first, performing local feature perception and linear interpolation-based dimension unification on the reconstructed traffic feature intermediate layer activation coding vector to obtain a sequence distribution of the reconstructed traffic feature intermediate layer activation coding local granularity coding vector, which is expressed as follows:
[0040] c i =Sigmoid(W conv ·V1[i:i+k]+b conv )
[0041] S={Interp(ci ,d target )|i=1,...,m}
[0042] Among them, Sigmoid(·) is the sigmoid activation function, W conv is the convolution weight, V1 is the activation coding vector of the intermediate layer of the reconstructed traffic feature, V1[i:i+k] is the subvector from index i to i+k in V1, i is the number of activation coding vectors of the intermediate layer of the reconstructed traffic feature, k is the window size, and b conv is the bias term, c i To reconstruct the i-th local feature fragment in the intermediate layer activation encoding vector of the traffic feature, Interp(·,·) is a bilinear interpolation operation, d target is the target dimension, m is the number of local granularity coding vectors of the intermediate layer activation coding of the reconstructed traffic features, and S is the sequence distribution of the local granularity coding vectors of the intermediate layer activation coding of the reconstructed traffic features.
[0043] That is, the activation coding vector of the intermediate layer of the reconstructed traffic feature is deconstructed into finer-grained components, and the dimensions are unified through linear interpolation to form a sequence distribution of the local granularity coding vector of the activation coding of the intermediate layer of the reconstructed traffic feature composed of multiple equal-length coding vectors, so that the internal structure of the reconstructed traffic feature has explorable position and order properties, retaining the local details and core structural information of the feature, and providing a structured input form for subsequent interactive detection.
[0044] Then, the traffic feature intermediate layer activation coding vectors are inserted into different positions of the sequence distribution of the reconstructed traffic feature intermediate layer activation coding local granularity coding vectors, and then input into the interactive encoder based on the bidirectional LSTM model to obtain a set of reconstructed traffic feature-original traffic feature cross-position interactive coding vectors, which can be expressed as follows:
[0045] S (j) =[S1,...,S j-1 ,V2,S j ,...,S m ]
[0046] h (j) =BiLSTM([S1,...,S j-1 ,V2,S j ,...,S m ])
[0047] Among them, S (j) is the sequence distribution of the local granularity encoding vector of the intermediate layer activation encoding of the j-th reconstructed traffic feature after interpolation, S1, S j-1 、S j and S mare the local granularity encoding vectors of the intermediate layer activation encoding of the traffic feature reconstructed after interpolation of the 1st, j-1th, jth, and mth layers in S, respectively. V2 is the activation encoding vector of the intermediate layer of the traffic feature. [·,...,·] is vector concatenation. BiLSTM(·) is a bidirectional LSTM model. h (j) The sequence distribution of the cross-position interaction encoding vector of the j-th reconstructed traffic feature-original traffic feature.
[0048] That is, the traffic feature intermediate layer activation coding vector is used as an information probe and systematically inserted into every possible position of the sequence distribution of the reconstructed traffic feature intermediate layer activation coding local granularity coding vector to generate a variety of mixed sequences. Then, each mixed sequence is deeply encoded through a bidirectional LSTM model to capture the global contextual interaction patterns at different positions, and a set of reconstructed traffic feature-original traffic feature cross-position interaction coding vectors covering all insertion positions is obtained. Each reconstructed traffic feature-original traffic feature cross-position interaction coding vector reflects the contextual dependency between the traffic feature intermediate layer activation coding vector and the reconstructed traffic feature local structure at a specific position, comprehensively capturing the complex interaction patterns between the two at different structural positions, and providing a multi-dimensional interaction representation for identifying subtle differences between features.
[0049] Finally, the set of cross-position interaction coding vectors of the reconstructed traffic feature and the original traffic feature is dynamically aggregated to obtain the dense interaction coding vector of the reconstructed traffic feature and the original traffic feature, which is expressed as follows:
[0050]
[0051] Among them, h (k) is the sequence distribution of the k-th reconstructed traffic feature-original traffic feature cross-position interaction coding vector, μ is the mean of the reconstructed traffic feature-original traffic feature cross-position interaction coding vector, W g is the gating weight matrix, g j is the gate value, v inter To reconstruct the traffic feature-original traffic feature dense interaction encoding vector.
[0052] That is, through the dynamic aggregation mechanism, the set of cross-position interaction coding vectors of reconstructed traffic features and original traffic features is weighted, the influence of key interaction patterns is amplified, and secondary information is suppressed. The multi-dimensional interaction representation is integrated into a dense interaction coding vector of reconstructed traffic features and original traffic features that can concentrate on reflecting the core differences between the two. It can accurately capture the essential differences between the reconstructed traffic features and the original traffic features, enhance the ability to represent the complex relationship between the two, and provide a more discriminative feature basis for subsequent feature decoding and the calculation of discriminator feature distance.
[0053] More specifically, step S323 performs feature decoding on the dense interaction coding vector of the reconstructed traffic features and the original traffic features to obtain the discriminator feature distance. That is, the abstract reconstructed traffic features and the original traffic features dense interaction coding vector are converted into a quantitative distance value that can be directly used to measure differences, namely the discriminator feature distance. This can effectively characterize the degree of structural difference between the reconstructed traffic features and the original traffic features, providing a key basis for subsequent anomaly score calculation, and improving the accuracy of edge-side anomaly detection. Specifically, the decoding network adopts a three-layer fully connected neural network architecture. The first layer maps the dense interaction coding vector of the reconstructed traffic features and the original traffic features to a 256-dimensional feature space, using the LeakyReLU activation function to introduce nonlinear transformations to enhance the ability to express complex difference patterns. The second layer further compresses it to 64 dimensions, and stabilizes the feature distribution through batch normalization operations to prevent gradient fluctuations from affecting decoding accuracy. The third layer is the output layer, which maps the 64-dimensional features to a single scalar value, namely the discriminator feature distance, through linear transformations.
[0054] Specifically, in a specific example of the present application, the step S33 includes: calculating the L1 norm or L2 norm between the reconstructed traffic feature vector and the original traffic feature vector as the reconstruction loss. Specifically, the reconstruction loss is used to quantify the accuracy of the generator's restoration of the original traffic feature vector, and its size directly reflects the degree of fit between the original traffic and the normal pattern learned by the generator. The normal traffic on the edge side conforms to the distribution learned by the generator, so the reconstruction loss is small. The abnormal traffic deviates from the distribution, making it difficult for the generator to accurately restore it, and the reconstruction loss is large. By calculating the difference between the reconstructed traffic feature vector and the original traffic feature vector, the generator's reconstruction error of the original traffic feature can be quantified, reflecting the degree to which the original traffic deviates from the normal pattern in numerical form, and providing a key error indicator for the subsequent anomaly score calculation.
[0055] Specifically, step S34 calculates the anomaly score based on the discriminator feature distance and the reconstruction loss. It should be understood that the discriminator feature distance reflects the structural difference between the original and reconstructed vectors in the feature space, and the reconstruction loss reflects the restoration error of the generator. The two characterize the degree of traffic anomaly from different dimensions. This application fuses the discriminator feature distance and the reconstruction loss according to a certain weight to calculate an anomaly score that can comprehensively reflect the degree of traffic anomaly, so that the abnormal state of the edge-side traffic can be uniformly quantified, providing a clear numerical basis for subsequent anomaly judgment.
[0056] Specifically, the step S35 generates the anomaly detection result based on the comparison between the anomaly score and the preset threshold. It should be understood that the preset threshold is determined based on the anomaly score distribution of normal traffic on the edge side, and is the critical value for distinguishing normal from abnormal traffic. If the threshold is not compared, it is impossible to clearly determine whether the traffic is a threat based solely on the absolute size of the anomaly score. For example, when the score of 0.6 is near the upper limit of the normal range, its attribution must be clarified through the threshold. That is, the calculated anomaly score is compared with the preset threshold. When the score exceeds the threshold, it is determined to be high-threat suspicious traffic, otherwise it is determined to be normal traffic, thereby outputting a clear anomaly detection result to support subsequent decision-making in edge-side attack analysis.
[0057] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, in step S4, in response to the abnormal detection result being high-level suspicious traffic, the decision engine generates a honeypot orchestration instruction based on the IP five-tuple. It should be understood that the IP five-tuple, as the core information that uniquely identifies the traffic, can accurately locate the source and destination addresses, ports, and protocols of the traffic. Generating the honeypot orchestration instruction based on this can accurately convey the location information and analysis requirements of high-level suspicious traffic, so that the honeypot management module can quickly match the corresponding honeypot type and generate directional redirection rules, ensuring that malicious traffic is accurately introduced into the isolated honeypot container, which not only avoids the continuous threat of malicious traffic to the edge network, but also provides a complete source of behavioral data for the subsequent extraction of attack indicators and the formation of the attack evidence chain.
[0058] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, in step S5, in response to the honeypot orchestration instruction, the honeypot management module generates traffic redirection rules and honeypot container instances. Specifically, the honeypot management module responds to the honeypot orchestration instruction, extracts the corresponding type of honeypot image from the predefined template library and quickly instantiates the container to build an isolated honeypot environment. At the same time, the traffic redirection rules are issued through the SDN controller to ensure that all traffic matching the target IP five-tuple is directed to the honeypot container, achieving safe isolation and targeted capture of high-level suspicious traffic, and creating a controllable scenario for subsequent in-depth behavioral analysis. The generated honeypot container instance provides a simulation environment that matches the suspicious traffic, ensuring that malicious traffic can fully interact in this environment, and the traffic redirection rules accurately introduce the target traffic into the honeypot to avoid its impact on the normal edge network. The two work together to fully capture the behavior of malicious traffic, providing a safe and complete data source for the extraction of attack indicators. Among them, Figure 6 FIG is a flowchart of sub-step S5 of the edge-side attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 6As shown, the step S5 includes the following steps: S51, in response to receiving the honeypot orchestration instruction, the honeypot management module extracts the image of the corresponding honeypot type from the predefined honeypot template library; S52, based on the image of the corresponding honeypot type, a container is quickly instantiated to obtain the honeypot container instance; S53, a traffic redirection rule is issued through the SDN controller, and the traffic redirection rule is used to direct all traffic matching the IP five-tuple to the honeypot container instance.
[0059] Specifically, in step S51, in response to receiving the honeypot orchestration instruction, the honeypot management module extracts the image of the corresponding honeypot type from the predefined honeypot template library. Specifically, the honeypot orchestration instruction contains a honeypot type identifier for high-security suspicious traffic. Different types of suspicious traffic must match the honeypot of a specific service environment to trigger effective interaction. The predefined honeypot template library stores images adapted to different protocols and service types. The corresponding type of honeypot image successfully extracted from the template library can accurately match the communication protocol and service characteristics of high-security suspicious traffic, ensuring that the subsequently instantiated honeypot container can simulate the target service environment, attract malicious traffic to interact, avoid the lack of malicious behavior due to environmental mismatch, and provide an effective interaction scenario foundation for deep behavioral analysis.
[0060] Specifically, step S52 rapidly instantiates a container based on the image of the corresponding honeypot type to obtain the honeypot container instance. It should be understood that the honeypot image is a static file. When the honeypot management module receives the honeypot orchestration instruction and extracts the corresponding type of honeypot image from the predefined template library, it is rapidly instantiated and converted into a running honeypot container instance. This provides an isolated environment with service responsiveness, ensuring that an interactive honeypot environment is established while traffic persists. At the same time, the container's isolation prevents malicious traffic from impacting the normal edge network. Specifically, the honeypot management module calls the API interface of the lightweight container engine, reuses the read-only layer of the image through the overlay2 storage driver, and only creates a writable layer for the new instance to save the runtime state, reducing disk IO overhead. At the same time, by utilizing the image metadata preloaded into the edge node memory, the hardware initialization step of the traditional virtual machine is skipped, and the necessary system call interface is directly mapped. In addition, through preset resource quotas, such as limiting CPU usage to 1 core and memory to 512MB, lightweight isolation is achieved to avoid resource congestion on the normal services of the edge node.
[0061] Specifically, in step S53, a traffic redirection rule is issued through the SDN controller, and the traffic redirection rule is used to direct all traffic matching the IP quintuple to the honeypot container instance. It should be understood that the SDN controller is the core network control component used to implement the issuance and execution of traffic redirection rules. It can receive instructions from the honeypot management module and issue traffic redirection rules for specific IP quintuples to the edge switch to control the forwarding path of network traffic. Specifically, when the honeypot management module needs to direct high-level suspicious traffic matching the target IP quintuple to the honeypot container instance, it will send a rule configuration request to the SDN controller. Based on the request, the SDN controller generates a corresponding flow table entry, which contains traffic matching conditions and forwarding actions. Subsequently, the SDN controller sends the flow table entry to the edge switch through protocols such as OpenFlow, so that the switch forwards the traffic according to the rules, ensuring that all suspicious traffic that meets the conditions is accurately directed to the honeypot container, while normal traffic is not affected. Through this centralized traffic control mechanism, the SDN controller can quickly respond to the needs of the honeypot management module, adjust the traffic path of the edge network in real time, and provide flexible and efficient traffic steering support for the isolation and analysis of suspicious traffic.
[0062] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, in step S6, after the malicious traffic flow is directed to the honeypot container instance through the traffic redirection rule, the malicious traffic flow is subjected to deep behavioral analysis to obtain an attack indicator. It should be understood that although the honeypot container provides an isolated environment, the unanalyzed raw traffic data is disordered and cannot be directly used as attack evidence or defense basis. Therefore, the present application extracts attack indicators from the interaction data by performing deep behavioral analysis on the malicious traffic flow, and converts the raw traffic into attack features that can be used for decision-making to obtain an attack indicator. Among them, Figure 7 FIG. 6 is a flow chart of sub-step S6 of the edge attack aggregation analysis method based on traffic self-learning according to an embodiment of the present application. Figure 7 As shown, the step S6 includes the following steps: S61, the honeypot container instance performs multi-dimensional data collection on the malicious traffic flow to obtain PCAP logs, MQTT interaction logs, Shell command records and downloaded malicious sample files; S62, inputs the PCAP logs, MQTT interaction logs, Shell command records and downloaded malicious sample files into the attack prompter extraction engine to obtain the attack indicator, wherein the attack indicator includes malware hash, C2 server IP, exploited MQTT topic and attacker's Shell command.
[0063] Specifically, in step S61, the honeypot container instance performs multi-dimensional data collection on the malicious traffic flow to obtain PCAP logs, MQTT interaction logs, Shell command records, and downloaded malicious sample files. Specifically, the honeypot container instance uses built-in collection components to comprehensively record the network interactions, protocol communications, command operations, and file transfers of the malicious traffic flow, generating PCAP logs containing complete message details, MQTT interaction logs that record subscription and publishing behaviors at the protocol level, Shell command records that capture the operation instructions executed by the attacker, and malicious sample files downloaded by attack tools or malicious programs. This ensures that the collected data can fully reflect the entire attack process from access to implementation, providing a comprehensive and original data source for the subsequent extraction of attack indicators.
[0064] Specifically, step S62 inputs the PCAP log, MQTT interaction log, Shell command record, and downloaded malicious sample file into the attack indicator extraction engine to obtain the attack indicator, which includes the malware hash, C2 server IP, exploited MQTT topic, and the attacker's Shell command. Specifically, the attack indicator extraction engine performs targeted analysis on the input multi-dimensional data, identifies and extracts the remote control server IP of the malicious traffic communication from the PCAP log, filters out frequently exploited protocol topics from the MQTT interaction log, extracts the key operation instructions executed by the attacker from the Shell command record, and calculates a unique hash value for the downloaded malicious sample file. Ultimately, the attack indicator is obtained, which includes the malware hash, C2 server IP, exploited MQTT topic, and the attacker's Shell command, converting the raw data into structured key feature information that can be directly used for attack analysis.
[0065] In the above-mentioned edge-side attack aggregation analysis method based on traffic self-learning, the step S7 combines the attack indicator and the IP quintuple to obtain an attack evidence chain. It should be understood that the attack indicator focuses on the characteristics and targets of the attack behavior, while the IP quintuple identifies the source and destination addresses, ports and protocols of the malicious traffic. The present application integrates the two types of information through a joint operation to build a logical closed loop to ensure that the attack behavior can be fully traced. Specifically, the attack indicator is associated and integrated with the IP quintuple, and a mapping relationship between the two is established. For example, the traffic corresponding to a certain IP quintuple initiates a specific attack behavior, communicates with a specific C2 server, etc., to form a complete attack evidence chain containing traffic source identification, attack behavior characteristics, and control node information, so that scattered technical indicators are converted into an evidence system with causal correlation, providing a coherent and verifiable basis for attack tracing, responsibility determination and defense response.
[0066] In summary, the edge-side attack aggregation analysis method based on traffic self-learning based on the embodiment of the present application is clarified, which performs self-learning modeling on the real-time traffic on the edge side through an unsupervised learning model, and intelligently identifies unknown suspicious traffic that deviates from normal behavior patterns in a manner that does not rely on attack samples. Once high-threat traffic is detected, a dynamic honeypot environment will be automatically orchestrated and deployed, and the suspicious traffic will be introduced into an isolated analysis environment through traffic redirection technology. In the honeypot, malicious traffic is deeply interacted and behavior captured to extract high-value attack indicators. Finally, the acquired attack indicators are aggregated and associated with the source information of the traffic to form a complete, highly reliable attack evidence chain. In this way, accurate identification, in-depth analysis and effective tracing of edge-side attacks can be achieved, thereby effectively improving the edge network's automated analysis and response capabilities to advanced, unknown attacks.
[0067] The basic principles of the present invention have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in the present invention are merely illustrative and non-limiting, and should not be construed as necessarily possessed by each embodiment of the present invention. Furthermore, the specific details of the above embodiments are provided for illustrative purposes and to facilitate understanding, and are not intended to be limiting. These details do not necessarily limit the present invention to being implemented using these specific details.
[0068] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, please refer to the relevant description of other embodiments. In the several embodiments provided by the present invention, it should be understood that the disclosed system and method can be implemented in other ways. For example, the system embodiment described above is only schematic. For example, the unit division is only a logical function division, and there may be other division methods in actual implementation. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.
[0069] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be encompassed therein. Any reference to a figure in a claim should not be construed as limiting the claim to which it relates.
[0070] In addition, it is obvious that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units stated in the system claims can also be implemented by one unit through software or hardware.
[0071] Finally, it should be noted that the above description has been provided for purposes of illustration and description. Furthermore, the above embodiments are intended only to illustrate the technical solutions of the present invention and are not intended to be limiting. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art will appreciate that the technical solutions of the present invention may be modified or replaced with equivalents without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for edge-side attack aggregation analysis based on traffic self-learning, characterized in that: include: Obtain the original real-time traffic flow from the edge switch; Performing feature engineering on the original real-time traffic flow to obtain a traffic feature vector, where the traffic feature vector includes an IP quintuple; Performing GAN-based unsupervised anomaly detection on the traffic feature vector to obtain an anomaly detection result; In response to the abnormal detection result being high-risk suspicious traffic, the decision engine generates a honeypot orchestration instruction based on the IP five-tuple; In response to the honeypot orchestration instruction, the honeypot management module generates a traffic redirection rule and a honeypot container instance; After directing the malicious traffic flow to the honeypot container instance through the traffic redirection rule, performing deep behavioral analysis on the malicious traffic flow to obtain attack indicators; The attack indicator and the IP quintuple are combined to obtain an attack evidence chain.
2. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 1 is characterized in that: Performing feature engineering on the original real-time traffic flow to obtain a traffic feature vector includes: Extracting non-load features from the original real-time traffic flow using a high-performance traffic probe, wherein the non-load features include IP five-tuple, TLS / SSL handshake features, and timing and statistical features; The IP five-tuple, TLS / SSL handshake features, and timing and statistical features are integrated into the traffic feature vector.
3. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 2 is characterized in that: Performing GAN-based unsupervised anomaly detection on the traffic feature vector to obtain an anomaly detection result, including: Inputting the traffic feature vector into the generator of GAN to obtain a reconstructed traffic feature vector; Inputting the reconstructed traffic feature vector and the traffic feature vector into the discriminator of the GAN to obtain a discriminator feature distance; Calculating a reconstruction loss between the reconstructed traffic feature vector and the original traffic feature vector; Calculating an anomaly score based on the discriminator feature distance and the reconstruction loss; The anomaly detection result is generated based on a comparison between the anomaly score and a preset threshold.
4. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 3 is characterized in that: Inputting the reconstructed traffic feature vector and the traffic feature vector into the discriminator of the GAN to obtain a discriminator feature distance, including: Inputting the reconstructed traffic feature vector and the traffic feature vector into the discriminator of GAN to obtain the reconstructed traffic feature intermediate layer activation coding vector and the traffic feature intermediate layer activation coding vector; Performing feature-intensive interaction on the reconstructed traffic feature intermediate layer activation coding vector and the traffic feature intermediate layer activation coding vector to obtain a reconstructed traffic feature-original traffic feature intensive interaction coding vector; Feature decoding is performed on the reconstructed traffic feature-original traffic feature dense interaction coding vector to obtain the discriminator feature distance.
5. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 4 is characterized in that: Performing feature-intensive interaction on the reconstructed traffic feature intermediate layer activation coding vector and the traffic feature intermediate layer activation coding vector to obtain a reconstructed traffic feature-original traffic feature intensive interaction coding vector, including: Performing local feature perception and linear interpolation-based dimension unification on the reconstructed traffic feature intermediate layer activation coding vector to obtain a sequence distribution of the reconstructed traffic feature intermediate layer activation coding local granularity coding vector; After inserting the traffic feature intermediate layer activation coding vectors into different positions of the sequence distribution of the reconstructed traffic feature intermediate layer activation coding local granularity coding vectors, they are input into an interactive encoder based on a bidirectional LSTM model to obtain a set of reconstructed traffic feature-original traffic feature cross-position interactive coding vectors; The set of the reconstructed traffic feature-original traffic feature cross-position interaction coding vectors is dynamically aggregated to obtain the reconstructed traffic feature-original traffic feature dense interaction coding vector.
6. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 3 is characterized in that: Calculating the reconstruction loss between the reconstructed traffic feature vector and the original traffic feature vector includes: An L1 norm or an L2 norm between the reconstructed traffic feature vector and the original traffic feature vector is calculated as the reconstruction loss.
7. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 1 is characterized in that: In response to the honeypot orchestration instruction, the honeypot management module generates traffic redirection rules and honeypot container instances, including: In response to receiving the honeypot orchestration instruction, the honeypot management module extracts an image corresponding to the honeypot type from a predefined honeypot template library; Quickly instantiate a container based on the image of the corresponding honeypot type to obtain the honeypot container instance; A traffic redirection rule is issued through the SDN controller, where the traffic redirection rule is used to direct all traffic matching the IP five-tuple to the honeypot container instance.
8. The edge-side attack aggregation analysis method based on traffic self-learning according to claim 7 is characterized in that: After the malicious traffic flow is directed to the honeypot container instance through the traffic redirection rule, a deep behavioral analysis is performed on the malicious traffic flow to obtain attack indicators, including: The honeypot container instance collects multi-dimensional data on the malicious traffic flow to obtain PCAP logs, MQTT interaction logs, Shell command records, and downloaded malicious sample files; The PCAP logs, MQTT interaction logs, Shell command records, and downloaded malicious sample files are input into the attack indicator extraction engine to obtain the attack indicators, which include malware hashes, C2 server IPs, exploited MQTT topics, and attackers’ Shell commands.
Citation Information
Cited By
Defense matrix method for network attack traffic identification
CN120979812A