Network traffic monitoring method and device, equipment and storage medium

By obtaining operating system attribute information, determining the monitoring service interface, collecting traffic data and calculating the probability of the coefficient of variation sequence and the threshold range, the problem of uniformity in heterogeneous terminal port monitoring is solved, real-time detection of unknown risks and abnormal traffic is achieved, and the flexibility and accuracy of network traffic monitoring are improved.

CN120639666APending Publication Date: 2025-09-12INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER

Patent Information

Application Number
CN202510715276.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing technologies lack a unified method for monitoring heterogeneous terminal ports and are unable to detect unknown risks or abnormal traffic in real time. Traditional methods also lack the ability to dynamically manage high-risk ports.

Method used

By obtaining operating system attribute information, determining the matching monitoring service interface, collecting traffic data, calculating the probability of the coefficient of variation sequence and the traffic threshold range, and dynamically analyzing abnormal traffic, seamless cross-platform monitoring and real-time detection can be achieved.

Benefits of technology

It improves cross-platform adaptability and compatibility, realizes real-time monitoring of network traffic behavior, reduces false positives and missed positives, and enhances monitoring flexibility and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639666A_ABST
    Figure CN120639666A_ABST
Patent Text Reader

Abstract

The invention discloses a network flow monitoring method and device, equipment and a storage medium, and the monitoring method comprises the steps: obtaining the system attribute information of an installed operating system, and determining a matched monitoring service interface according to the system attribute information; the method comprises the following steps: collecting flow data of a system in a set time length through a monitoring service interface in combination with a set collection tool, and determining at least one flow sequence according to the flow data; determining a variable coefficient sequence probability and a flow threshold range of each flow sequence under the set time length; and determining a monitoring result of the corresponding flow sequence according to each variable coefficient sequence probability and the corresponding flow threshold range. The problems that a unified heterogeneous terminal port monitoring method is lacked and unknown risks or abnormal traffic cannot be detected in real time are solved, the cross-platform adaptability and compatibility can be improved, and the flexibility and accuracy of traffic monitoring are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a method, device, equipment and storage medium for monitoring network traffic. Background Art

[0002] In information security management, the security baseline serves as the starting point and foundation for system security and is crucial for ensuring robust protection across the entire network environment. Within the security baseline strategy, monitoring and managing high-risk ports is a crucial component of ensuring endpoint security. High-risk ports are ports that are easily exploited by attackers and are typically open and exposed to the external network environment. Because default ports for certain services pose a high security risk, these ports become targets for attackers if misconfigured or not closed promptly. Therefore, strict monitoring and management of these ports are essential to ensure network security. However, traditional monitoring of high-risk ports relies primarily on static configuration and rule-based detection methods. While these methods can identify known risky ports, they lack the real-time monitoring capabilities for unknown risks or abnormal traffic.

[0003] In addition, traditional monitoring methods lack terminal compatibility architecture. Mainstream operating systems such as Kylin and Tongxin have differences in security baseline configuration, especially in high-risk port numbers and traffic collection methods. There is a lack of a unified heterogeneous terminal port monitoring method to cope with the complexity and heterogeneity of port activities in large-scale network environments. Summary of the Invention

[0004] The present invention provides a network traffic monitoring method, apparatus, device and storage medium to solve the problems in the prior art of lacking a unified heterogeneous terminal port monitoring method and being unable to detect unknown risks or abnormal traffic in real time.

[0005] According to a first aspect of the present invention, there is provided a method for monitoring network traffic, comprising:

[0006] Obtain the system attribute information of the installed operating system and determine the matching monitoring service interface based on the system attribute information;

[0007] Collecting flow data of the system over a set period of time through a monitoring service interface in combination with a set collection tool, and determining at least one flow sequence based on the flow data;

[0008] Determine the probability of the coefficient of variation sequence and the flow threshold range of each flow sequence under the set time length;

[0009] The monitoring result of the corresponding flow sequence is determined according to the probability of each variation coefficient sequence and the corresponding flow threshold range, wherein the flow threshold range is different according to the set confidence coefficient.

[0010] According to a second aspect of the present invention, there is provided a network traffic monitoring device, comprising:

[0011] A matching module is used to obtain the system attribute information of the installed operating system and determine the matching monitoring service interface based on the system attribute information;

[0012] A collection module, configured to collect flow data of the system over a set period of time through a monitoring service interface in combination with a set collection tool, and determine at least one flow sequence based on the flow data;

[0013] A determination module, configured to determine the probability of a coefficient of variation sequence and a flow threshold range of each flow sequence within the set time length;

[0014] The monitoring module is used to determine the monitoring result of the corresponding flow sequence according to the probability of each variation coefficient sequence and the corresponding flow threshold range, wherein the flow threshold range is different according to the set confidence coefficient.

[0015] According to a third aspect of the present invention, there is provided an electronic device, comprising:

[0016] at least one processor; and

[0017] a memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the network traffic monitoring method described in any embodiment of the present invention.

[0019] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network traffic monitoring method described in any embodiment of the present invention when executed.

[0020] By introducing a complete network traffic collection, analysis, and monitoring architecture, this invention addresses the existing problems of a lack of a unified heterogeneous terminal port monitoring method and the inability to detect unknown risks or abnormal traffic in real time. It ensures seamless operation in different operating system environments, improving cross-platform adaptability and compatibility. Furthermore, it can collect network traffic data in real time and dynamically analyze and monitor abnormal traffic, enabling real-time monitoring of network traffic behavior. This enhances the flexibility and accuracy of network traffic monitoring and avoids the false positives and missed positives associated with fixed thresholds in traditional methods.

[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0023] Figure 1 is a flow chart of a network traffic monitoring method provided according to embodiment 1 of the present invention;

[0024] Figure 2 is a flow chart of a network traffic monitoring method provided according to the second embodiment of the present invention;

[0025] Figure 3 1 is a schematic diagram of the structure of a network traffic monitoring device provided according to a third embodiment of the present invention;

[0026] Figure 4 The present invention is a schematic diagram of the structure of an electronic device for implementing a method for monitoring network traffic according to an embodiment of the present invention. DETAILED DESCRIPTION

[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0029] Example 1

[0030] Figure 1 A flowchart of a method for monitoring network traffic is provided for the first embodiment of the present invention. This embodiment is applicable to monitoring network traffic in a terminal. The method can be executed by a network traffic monitoring device. The network traffic monitoring device can be implemented in the form of hardware and / or software. The network traffic monitoring device can be configured in a computer device. Figure 1 As shown, the method includes:

[0031] S101: Obtain system attribute information of the installed operating system, and determine a matching monitoring service interface based on the system attribute information.

[0032] In this embodiment, considering the differences in security baseline configurations among terminal operating systems in existing technologies, a six-layer monitoring architecture is designed. From bottom to top, the architecture consists of the operating system compatibility layer, the collection layer, the transport layer, the real-time analysis layer, the data layer, and the application UI layer. The operating system compatibility layer provides a unified interface for monitoring service invocations, while the collection layer provides information collection and data support. The real-time analysis layer incorporates abnormal traffic analysis technology to monitor abnormal traffic in real time and assess risk. The application UI provides a customized interface for managing traffic flow monitoring and high-risk port monitoring.

[0033] Furthermore, the operating system compatibility layer is located at the bottom of the architecture, and undertakes the basic support functions of the entire system, mainly responsible for the management and virtualization of hardware resources. By encapsulating and abstracting the underlying functions of different terminal operating systems, the monitoring service can work normally on various operating systems without having to pay attention to the details of the specific operating system. It also customizes interfaces for each functional module for different operating systems, and can automatically identify and load the corresponding driver and kernel modules according to the operating system type and version information to ensure seamless operation in different operating system environments.

[0034] In this embodiment, system attribute information includes operating system type and version information. The monitoring service interface is the channel for interaction between the monitoring system and the terminal device. Different system attributes require different monitoring service interfaces to achieve the best monitoring service effect. By collecting and analyzing system attribute information, the most suitable monitoring service interface for the current system can be determined.

[0035] Optionally, during operation, the operating system compatibility layer will obtain relevant attribute information of the current operating system, automatically identify and load the corresponding driver and kernel module, and pass the attribute information to the monitoring interface selection module. The monitoring interface selection module filters out the most matching monitoring service interface from the pre-defined interface list based on the received system attribute information. After determining the matching monitoring service interface, the operating system compatibility layer matches the service interface to ensure that it can operate normally in the current operating system environment. During system operation, the operating system compatibility layer can detect changes in system attributes in a timely manner and re-determine the matching monitoring service interface. For example: when collecting information, the system command uname-a can be used to identify that the current operating system is Kylin. When collecting network interface status information, some versions of the Kylin system are compatible with the traditional command ifconfig-a and can be called directly. If the current operating system is identified as Tongxin, this command may not be installed in some versions of the Tongxin system. When developing this function, it is necessary to consider other commands such as ip address.

[0036] S102: Collect the flow data of the system within a set time period through the monitoring service interface in combination with the set collection tool, and determine at least one flow sequence based on the flow data.

[0037] In this example, after receiving a collection instruction, the monitoring service interface passes it to the data collection layer. The collection tool in the collection layer then performs data collection operations based on the received collection instruction. The collection tool can be Wireshark or tcpdump. Furthermore, the set time duration is a continuous period of time, such as 5 seconds, 10 minutes, or a day. This embodiment does not specifically limit the collection tool or the set time duration.

[0038] The collection layer is responsible for collecting terminal information, including traffic data, port information, and service information. Traffic data includes packet size and rate, port information includes the source IP address, destination IP address, protocol, and port number, and service information includes the application name, path, and configuration file path associated with the port number. Network traffic is received, decoded, monitored, and transmitted in real time through mirrored ports on network devices such as routers and switches. The collection layer is customized for data collection across multiple operating system protocols and interfaces, ensuring coverage of all ports and services requiring monitoring.

[0039] In this embodiment, traffic data includes data such as traffic packet size, traffic rate, source IP address, destination IP address, source port, and destination port. Furthermore, the collected traffic data is preprocessed, such as data cleaning, data normalization, and data sampling. Optionally, a collection of traffic data packets with the same source IP address, destination IP address, source port, and destination port is considered a traffic sequence.

[0040] For example, when transmitting traffic data, in order to reduce the impact on the collection layer and avoid excessive data disturbance, a local high-speed memory buffer queue is set up during the transmission process to temporarily store the collected data for preliminary screening and processing. The screening specifically includes deduplication processing, port filtering, and content length filtering. Deduplication refers to the removal of duplicate data packets or collected information. Port filtering prioritizes retaining high-risk port data. Content length filtering discards empty data packets with a length of 0 or data with abnormal format. The processing steps include field extraction and parsing, data format standardization, and data desensitization. The writing and reading of buffer data are processed in parallel using multi-threaded asynchronous transmission technology. The collection thread is responsible for writing the collected data into the buffer, and the transmission thread asynchronously reads from the buffer and sends it to the real-time analysis layer. The filtered network data is stored in a persistent message queue for subsequent analysis. In addition, the transport layer has horizontal scalability. When the data volume increases dramatically, the load is smoothly distributed through a load balancing mechanism. Specifically, a load weight is set for each resource unit (thread or computing node). Resource units with higher loads are assigned higher weights. Data request tasks are assigned requests according to the weight, and resource units with lower weights are assigned more requests to ensure high reliability and scalability of the system.

[0041] S103: Determine the probability of the coefficient of variation sequence and the flow threshold range of each flow sequence within the set time length.

[0042] In this embodiment, the set time length defines the specific time interval for analyzing the traffic sequence. For example, when studying the changing pattern of network traffic within a certain day, the set time length is set to 24 hours. Furthermore, after obtaining the traffic sequence data, an appropriate window length is set according to actual needs, which represents the number of traffic data points contained in each window. At the same time, a fixed step size is determined, that is, the number of data points that the window moves forward each time. For example, a window length of 10 means that each window contains 10 consecutive traffic data points; a fixed step size of 1 means that the window moves forward by one data point each time.

[0043] Optionally, the set time length can affect the number of windows, which slide over the traffic sequence within the set time length at a fixed step size. For example, if the total number of traffic data points within the set time length is N, the window length is l, and the fixed step size is s, then the number of time windows n can be calculated by the formula (when Nl is divisible by s), or by rounding (when Nl is not divisible by s).

[0044] Furthermore, starting from the beginning of the traffic sequence, the first time window is defined according to the window length. The data within this window constitutes a subsequence. The mean and standard deviation of this subsequence are calculated, and the coefficient of variation (CV) of this subsequence is calculated based on the mathematical expectation and variance of the subsequence. Then, the window is slid forward for a set time length at a fixed step size to obtain a new subsequence. The above calculation process is repeated until the window slides to the end of the traffic sequence.

[0045] In this embodiment, the subsequence variation coefficient values ​​calculated under each time window are arranged in the order of window sliding to form a variation coefficient sequence of the traffic sequence. For example: [CV1, CV2, CV3, ..., CV 16 ]. Each element in the coefficient of variation sequence corresponds to the fluctuation of flow data in a specific time window, which represents the fluctuation trend of flow over time under the set window length L.

[0046] Furthermore, the mathematical expectation and variance of the coefficient of variation values ​​for all traffic sequences within each time window are calculated. After obtaining the mathematical expectation and variance of the coefficient of variation values, a preset method is used to calculate the probability of the coefficient of variation sequence, and combined with a pre-set confidence coefficient, the threshold range for traffic flow is calculated. Pre-set methods can include Chebyshev's inequality, probability calculation under the normal distribution assumption, and Monte Carlo simulation.

[0047] S104. Determine the monitoring result of the corresponding flow sequence according to the probability of each variation coefficient sequence and the corresponding flow threshold range, wherein the flow threshold range varies according to the set confidence coefficient.

[0048] In this embodiment, the monitoring result of the flow sequence is determined based on the calculated probability of the coefficient of variation sequence and its corresponding flow threshold range. For example, when the probability of the coefficient of variation sequence is within the flow threshold range, it can be considered that the flow sequence is within the normal fluctuation range within the set time length. At this time, the monitoring result of the flow sequence is recorded as "normal", and relevant information such as the start and end time of the flow sequence, the corresponding coefficient of variation value and the probability of the coefficient of variation sequence are recorded for subsequent review and analysis; if the probability of the coefficient of variation sequence is not within the flow threshold range, it means that the fluctuation of the flow sequence within the set time length has exceeded the normal range, and there may be an abnormality. The degree to which the probability of the coefficient of variation sequence of the flow sequence exceeds the threshold range is further analyzed. If it is determined that there is an abnormality, the monitoring result of the flow sequence is recorded as "abnormal". At the same time, the specific circumstances of the abnormality are recorded in detail, including time window information, probability of the coefficient of variation sequence and the specific value exceeding the threshold, etc., to provide a basis for subsequent abnormality investigation and processing.

[0049] In this embodiment, the traffic threshold range is not fixed but changes with the confidence coefficient. Specifically, when network traffic is stable, the confidence coefficient is dynamically lowered to reduce the probability that the coefficient of variation sequence falls within the normal range, thereby increasing the sensitivity of anomaly detection. This allows for adequate detection of anomalies and effectively reduces the false positive rate. When network traffic fluctuates significantly, the confidence coefficient is raised to increase the probability that the coefficient of variation sequence falls within the normal range, thereby reducing the false positive rate.

[0050] The above technical solution of this embodiment solves the problems of lack of a unified heterogeneous terminal port monitoring method and inability to detect unknown risks or abnormal traffic in real time in the existing technology by introducing a complete network traffic collection, analysis and monitoring architecture. It can ensure seamless operation in different operating system environments and improve cross-platform adaptability and compatibility. At the same time, it can also collect network traffic data in real time and dynamically analyze and monitor abnormal traffic, realizing real-time monitoring of network traffic behavior, enhancing the flexibility and accuracy of network traffic monitoring, and avoiding the false alarm and missed alarm problems caused by fixed thresholds in traditional methods.

[0051] Example 2

[0052] Figure 2 The flowchart of a network traffic monitoring method provided in the second embodiment of the present invention, the relationship between this embodiment and the above embodiment further refines the specific implementation of determining at least one traffic sequence based on the traffic data. At the same time, based on the above embodiment, this embodiment further refines the specific implementation of determining the probability of the variation coefficient sequence of each traffic sequence under the set time length and the traffic threshold range. In addition, based on the above embodiment, this embodiment further refines the specific implementation of determining the monitoring results of the corresponding traffic sequence based on the probability of the variation coefficient sequence and the corresponding traffic threshold range. Figure 2 As shown, the network traffic monitoring method provided in this embodiment includes:

[0053] S201: Obtain system attribute information of the installed operating system, and determine a matching monitoring service interface according to the system attribute information.

[0054] S202: Collect the flow data of the system within a set time period through the monitoring service interface in combination with the set collection tool.

[0055] S203: Analyze the traffic data and classify traffic data with the same source IP, destination IP, source port, and destination port into the same traffic sequence.

[0056] In this embodiment, traffic sequences with the same source IP, destination IP, source port, and destination port can be used as independent monitoring units. By monitoring the behavior of these traffic sequences, potential malicious behavior or risks can be more easily discovered. By grouping these traffic data into the same traffic sequence, the location of potential malicious behavior or risks can be more quickly located.

[0057] S204. For each traffic sequence, obtain the sliding window length, and determine the window variation coefficient value of the traffic sequence under the sliding window length according to a given variation coefficient calculation formula combined with the window traffic data under the sliding window length.

[0058] In this embodiment, after acquiring the traffic sequence data for different traffic sequences, a fixed-size window is set on the traffic sequence. This window can be moved in a certain step size, which is called a sliding window. Furthermore, an appropriate sliding window length l is set based on actual needs. For example, if the network traffic data changes frequently, a smaller window size can be set to capture short-term fluctuations in the data; for traffic data that changes relatively slowly, the window size can be appropriately increased to capture more representative data features.

[0059] Furthermore, the window variation coefficient value of the traffic sequence under the sliding window length is calculated by using a preset variation coefficient calculation formula, wherein the window variation coefficient can reflect the fluctuation of the traffic sequence.

[0060] For example, for the traffic sequence L, a sliding window length of l is selected, and the window variation coefficient value under the sliding window length of l is calculated according to the following variation coefficient calculation formula:

[0061]

[0062] Where CV is the coefficient of variation of the window, a is the standard deviation of the flow within the window length, and b is the mean of the flow within the window length.

[0063] S205: Determine new window traffic data according to the sliding window length with a set step size, re-determine the window variation coefficient value of the traffic sequence, and summarize the window variation coefficient values ​​to form a variation coefficient sequence of the traffic sequence.

[0064] In this embodiment, the step size represents the distance the window moves each time. A smaller step size results in more frequent window movement, which can more accurately reflect changes in traffic data, but also increases the computational complexity. A larger step size reduces the computational complexity but may miss some detailed data changes. Therefore, an appropriate step size is set based on actual needs. For example, the step size can be 1 time interval.

[0065] In this embodiment, the sliding window length l is maintained constant, and the window is gradually slid with a step size s. The operation of calculating the window coefficient of variation for the sliding window length l in S204 is repeated until the end of the traffic sequence. The sliding window length l and the step size s are both adjustable hyperparameters, and the sliding step size s may not be equal to the sliding window length l. Furthermore, the coefficient of variation values ​​for different time windows are summarized to form a coefficient of variation sequence for the traffic sequence, which serves as a benchmark for subsequent network traffic data analysis. By analyzing all traffic sequences in each time window in real time, real-time monitoring of network traffic is achieved.

[0066] S206: Determine the expected value of the coefficient of variation and the variance of the coefficient of variation sequence.

[0067] In this embodiment, the expected value and variance of the coefficient of variation are calculated for each coefficient of variation value in the coefficient of variation sequence. The variance of the coefficient of variation is used to define the degree of deviation of the flow rate from its mathematical expectation on the coefficient of variation.

[0068] For example, the window sequence is defined as T = {t1, t2, ..., t n}, where t is a window, and all traffic sequences under window t are defined as L = {l1,l2,...,l m}, then the mathematical expectation μ and variance σ of the coefficient of variation in the current window 2 The calculation method is:

[0069]

[0070] Among them, μ is the expected value of the coefficient of variation, i∈[1,m], m is the number of all traffic sequences under window t, l i Expressed as the i-th traffic sequence, σ 2 is the variance of the coefficient of variation.

[0071] S207. Determine the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation, and determine the flow threshold range under the set time length in combination with a pre-set confidence coefficient.

[0072] In this embodiment, after obtaining the mathematical expectation and variance of the coefficient of variation, a preset method is used to calculate the probability of the coefficient of variation sequence, and combined with a pre-set confidence coefficient to calculate the flow threshold range. The preset method may include Chebyshev's inequality, probability calculation under the normal distribution assumption, and Monte Carlo simulation.

[0073] Furthermore, by calculating the probability of the coefficient of variation sequence based on the mathematical expectation and variance of the variation values ​​and a preset method, the centralized trend and fluctuation of network traffic can be more clearly reflected, and the accuracy of identifying abnormal network traffic behavior can be improved. By introducing the confidence coefficient, the traffic threshold range is not fixed, but is dynamically adjusted according to the data characteristics of normal traffic and the tolerance of the network environment for traffic anomalies. When the network environment has a high tolerance for traffic anomalies, a larger confidence coefficient can be selected. In this case, the traffic threshold range will become wider, allowing traffic to have a larger fluctuation range without being judged as abnormal. When the network environment is more sensitive to traffic anomalies and requires more accurate identification of anomalies, a smaller confidence coefficient can be selected. The traffic threshold range will become narrower, making it easier to detect abnormal traffic fluctuations.

[0074] S208: Determine at least one level of alarm threshold range based on the traffic threshold range.

[0075] In this embodiment, the classification is performed based on the degree to which the probability of the coefficient of variation sequence exceeds the traffic threshold range, considering the service requirements for network performance and stability, and referring to industry standards and best practices to determine the threshold range of the graded alarm.

[0076] Specifically, the graded alarm threshold range can be divided into three levels, as shown in the following table, where τ represents the flow threshold range, μ is the expected value of the coefficient of variation, and σ is the standard deviation of the coefficient of variation:

[0077] grade Alarm range normal μ-2σ<τ<μ+2σ Low risk μ-3σ<τ<μ+3σ High risk τ>μ+3σorτ<μ-3σ

[0078] Table 1

[0079] S209: If the probability of the coefficient of variation sequence belongs to the flow threshold range, the flow sequence being in the normal flow range is taken as a monitoring result.

[0080] In this embodiment, if the probability of the coefficient of variation sequence is within the flow threshold range, the flow sequence is within the normal flow range, and the current network flow is considered normal. At this time, a corresponding monitoring result record is generated. The record content may include but is not limited to: the identifier of the flow sequence (such as the network area, time period, etc. to which the flow belongs), the specific value of the probability of the coefficient of variation sequence, the specific parameters of the flow threshold range, the judgment result (normal flow range), and the monitoring time and other information. In the process of sending the monitoring result to the client, a suitable communication method and protocol are selected. For example, the HTTP / HTTPS protocol can be used to send the monitoring result to the client in a format such as JSON or XML through the network interface. At the same time, an error handling mechanism is set. If a network failure or client no response occurs during the sending process, the error information is recorded and appropriate retransmission operations are performed to ensure that the monitoring result can be successfully delivered to the client. After receiving the monitoring result, the client can perform corresponding display and processing, such as displaying a prompt message that the network flow is normal on the monitoring interface for reference by network administrators.

[0081] Alternatively, if the probability of the coefficient of variation sequence falls outside the traffic threshold, the traffic sequence is considered to be abnormal. In this case, a monitoring result record is also generated, detailing the relevant information and sending it to the client. Upon receiving the abnormal monitoring result, the client can trigger further processing, such as conducting more in-depth traffic analysis or issuing an alert to alert network administrators.

[0082] S210. If the probability of the coefficient of variation sequence belongs to one of the alarm threshold ranges, it is determined that the traffic sequence is in the abnormal traffic range, and the level corresponding to the alarm threshold range is determined as the abnormal level of the traffic sequence, and being in the abnormal traffic range and the corresponding abnormal level are determined as the monitoring results.

[0083] In this embodiment, the levels corresponding to the alarm threshold range may be a normal risk level, a low risk level, and a high risk level.

[0084] Specifically, if the probability of the coefficient of variation sequence is greater than the traffic threshold range, the traffic sequence is in the abnormal traffic range. At this time, the probability of the coefficient of variation sequence of the traffic sequence is further analyzed. If the probability of the coefficient of variation sequence is in the normal risk threshold range, the traffic sequence is in a normal risk state. At this time, the system only generates an alarm message. The alarm message should contain the basic information of the traffic sequence (such as the network area to which it belongs, the monitoring time period, etc.), a description of the normal risk state, and related timestamps, etc. Then, the alarm message is sent to the client through a specific communication channel (such as a network interface, using the HTTP / HTTPS protocol). After the client receives the alarm message, it can be displayed on the interface to prompt the network administrator that the current traffic is in a normal risk state.

[0085] If the probability of the coefficient of variation sequence falls within the low-risk threshold, the traffic sequence is considered low-risk. The network traffic corresponding to the traffic sequence is then rate-limited. By identifying the source and destination of the traffic, specific rate-limiting parameters, such as maximum bandwidth and traffic rate limits, are determined based on the network topology and traffic control policy. The rate-limiting operation is then implemented using the traffic control functions of network devices (such as routers and switches) to keep network traffic within a safe range. Alternatively, protocol access restrictions can be implemented on the ports corresponding to the network traffic. For ports corresponding to the traffic sequence, the system analyzes the protocols used by the ports (such as TCP, UDP, and HTTP) and, based on pre-defined security policies, restricts access to certain protocols. For example, non-essential UDP access can be prohibited, or the number of concurrent HTTP connections can be limited. The anomaly is then uploaded to a log file. The log file should record in detail the time of the anomaly, the traffic sequence identifier, the probability of the coefficient of variation sequence, and the rate-limiting and port protocol access restriction measures implemented to facilitate subsequent auditing and analysis. Finally, an alert message containing detailed information about the low-risk status is generated and sent to the client. Upon receiving the alert, the client can provide a manual review function. Specifically, network administrators can determine whether it is a false alarm based on the actual situation. If it is considered a false alarm, they can mark and feedback it through the client interface. The system will record the relevant information and take corresponding measures.

[0086] If the probability of the coefficient of variation sequence is within the high-risk threshold range, the traffic sequence is in a high-risk state. For high-risk ports, measures are immediately taken to block related traffic. Through the access control rules of network security devices (such as firewalls), all inbound and outbound traffic of the port is prohibited to prevent potential attacks or malicious behaviors from causing further damage to the network. Then, the service port is transferred to the network service originally running on the high-risk port. Then, the configuration file of the network service is modified to change the listening port of the service from the high-risk port to the target port. At the same time, the relevant network device configuration (such as the port mapping rules of the router) is updated to ensure that the network service can run normally on the new port. During the service port transfer process, the system records detailed information of the operation, including the port number before and after the transfer, service name, operation time, etc., and uploads this information to the log file.

[0087] For example, the alarm information is calculated by the real-time analysis layer to obtain the alarm results, sort and aggregate the alarm information according to conditions such as time and alarm type, and provide user interaction buttons to support management operations such as alarm confirmation and ignoring.

[0088] The technical solution described above in this embodiment provides an abnormal traffic detection algorithm based on a sliding coefficient of variation. This algorithm can calculate the degree of traffic anomaly based on network traffic volatility and enable real-time monitoring of traffic behavior. By analyzing the sliding coefficient of variation sequence, a graded alert mechanism is introduced, providing different levels of alerts based on the severity of abnormal traffic. This ensures that users can respond to and address various abnormal situations in a timely manner, enhances the flexibility and accuracy of traffic monitoring, and avoids the false positives and missed negatives caused by fixed thresholds in traditional methods.

[0089] Furthermore, this embodiment provides one implementation method, which can specifically determine the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation, and determine the flow threshold range under the set time length in combination with a pre-set confidence coefficient as follows:

[0090] a1) determining the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation in combination with Chebyshev's inequality.

[0091] In this embodiment, the expected value μ and variance σ of the coefficient of variation are obtained through a series of calculations. 2 Finally, the probability of the coefficient of variation sequence is calculated by combining Chebyshev's inequality. The specific formula is as follows:

[0092]

[0093] Among them, μ and σ 2 Denote the expected value of the coefficient of variation and the variance of the coefficient of variation respectively, and ε is the tolerance range, which indicates the maximum distance that the probability of the coefficient of variation sequence deviates from its expectation. Through Chebyshev's inequality, it can be estimated that the probability of the probability of the coefficient of variation sequence taking a value in the interval (μ-ε,μ+ε) is not less than

[0094] b1) Obtaining a threshold coefficient according to the confidence coefficient and the threshold coefficient determination formula.

[0095] In this embodiment, the tolerance range ε ​​is defined as a safety distance. The safety distance is related to the standard deviation of the coefficient of variation of the traffic sequence. Let the safety distance ε = kσ (k>0), where k is the threshold coefficient and σ is the standard deviation of the coefficient of variation, reflecting the degree of dispersion of the coefficient of variation of the traffic sequence relative to its expected value. By introducing the threshold coefficient k, we can flexibly adjust the size of the safety distance to adapt to different network environments and business needs. When the value of k is large, the safety distance ε will also increase accordingly, which means that the system is more tolerant of traffic data deviations from the mean; conversely, when the value of k is small, the safety distance becomes smaller, and the system is more sensitive to fluctuations in traffic data.

[0096] Furthermore, the lower limit of the confidence coefficient is set to α (0 < α < 1). The confidence coefficient α specifies the degree of confidence in the event {|X - μ| < ε}, where X represents the coefficient of variation of the flow data and μ is the mean of the coefficient of variation. In other words, the probability that the coefficient of variation X of the flow data falls within the interval centered at the mean μ and with a safety distance ε as the radius is at least α.

[0097] Given the known coefficient of variation σ 2 and the probability of the event {|X-μ|<ε} is at least α, let The threshold coefficient determination formula is derived from formula (1), and the derivation process is as follows:

[0098] Substituting ε=kσ into In, get

[0099] at this time,

[0100] Solution,

[0101] Under the condition that the probability of the event {|X-μ|<ε} is at least α, we can deduce that:

[0102]

[0103] Where k is the threshold coefficient and α is the confidence coefficient. Formula (2) can reasonably set the normal fluctuation range of traffic data according to different confidence level requirements, so as to more accurately judge whether the traffic data is in a normal state and timely detect abnormal situations in network traffic.

[0104] c1) determining a flow rate threshold range within the set time period based on the threshold coefficient, the expected value of the coefficient of variation, and the variance of the coefficient of variation.

[0105] In this embodiment, when the sliding coefficient of variation sequence is below the confidence lower limit α, that is, When the threshold value τ is defined, we have The calculation formula of the threshold value τ is τ = μ ± kσ, where μ is the expected value of the coefficient of variation of the coefficient of variation sequence. The threshold value τ is actually the boundary value of the flow threshold range.

[0106] Specifically, the flow threshold range can be expressed as (μ-kσ, μ+kσ), which is determined based on the expected value of the coefficient of variation and the standard deviation of the coefficient of variation sequence, combined with a given confidence coefficient α. It defines the flow threshold range of the coefficient of variation sequence under a certain confidence coefficient. When the probability of the coefficient of variation sequence exceeds the flow threshold range (μ-kσ, μ+kσ), it means that under the current confidence coefficient, an abnormal situation has occurred in the flow sequence.

[0107] Based on the above embodiment, this embodiment also proposes another optional embodiment. After determining the monitoring result of the corresponding traffic sequence, this optional embodiment can further optimize and include:

[0108] a2) If the monitoring result of the traffic sequence indicates that the traffic sequence is abnormal, determining the network service information corresponding to the traffic sequence and performing network anomaly analysis.

[0109] In this optional embodiment, after determining the monitoring results of the traffic sequence, if it is in an abnormal state, the stored traffic data is queried and analyzed. The traffic data may include the timestamp, source address, destination address, traffic size, etc. of the traffic. Specific algorithms and techniques (such as a path tracing algorithm based on the network topology structure) are used to identify the specific path of the traffic in the network. For example, a traffic attack initiated by a certain IP is tracked to view its source and the network nodes it passes through, including relevant information of routers, switches and other devices, such as the IP address of the device, port connection status, etc. Further, an abnormal analysis is performed on the network service information. The network service information may include the service number information, port number information and IP information of the traffic sequence. Network abnormality analysis operations may include traffic pattern recognition, protocol analysis operations, and whitelist comparison operations.

[0110] b2) Record the analysis results of the network anomaly analysis and send them to the anomaly review platform for anomaly review and determination.

[0111] In this optional embodiment, the analysis results of the network anomaly analysis are uploaded to a log file and sent to the anomaly audit platform. In order to ensure the security of the data during transmission, the sent anomaly analysis results can be encrypted. Furthermore, after receiving the analysis result data, the anomaly audit platform parses the data and matches the parsed data with the platform's built-in anomaly determination rules. If the analysis result meets the conditions of a certain rule, it is preliminarily determined to be an anomaly of the corresponding type. For example, if the analysis result shows that the traffic of a certain IP address exceeds the threshold set in the rule in a short period of time, it is preliminarily determined to be a traffic anomaly.

[0112] Furthermore, historical data can be compared to see if the anomaly bears similarities to past abnormal events; correlation analysis can be performed to check if the anomaly is related to anomalies in other devices, users, or systems; and machine learning models can be used to further mine and analyze the data to discover potential abnormal patterns. By comprehensively considering these multi-dimensional analysis results, more accurate anomaly determination conclusions can be drawn.

[0113] Optionally, the anomaly review platform supports manual review for complex anomalies that are difficult to automatically identify. Professional reviewers can review detailed analysis results, including raw traffic data and device logs, and make judgments based on their experience and expertise. Reviewers can also propose modifications to the platform's rules and algorithms, adding new rules or adjusting existing rules based on actual circumstances to improve the platform's anomaly detection capabilities.

[0114] In this optional embodiment, determining the network service information corresponding to the traffic sequence and performing network anomaly analysis may be further specified as follows:

[0115] a3) Determine the service number information, port number information and IP information corresponding to the traffic sequence and use them as the network service information of the traffic sequence.

[0116] In this optional embodiment, a collection tool is used to collect service number information, port number information, and IP information of network traffic. The IP information may include the source IP and destination IP of the traffic sequence, the port number information may include the port number and protocol type, and the service number information may include the communication frequency, access time, access protocol, and other behavioral characteristics of the service source.

[0117] b3) Using a pre-stored IP whitelist, determine whether the IP address in the IP information is abnormal.

[0118] In this optional embodiment, the IP whitelist includes known trusted IP addresses, such as enterprise internal network addresses and trusted access sources for specific services. The network service information of the traffic sequence is compared with the service information in the IP whitelist. If the source IP address of the traffic sequence is on the whitelist, accesses commonly used ports, and the protocol type matches the expected service scenario, the IP address of the traffic sequence is considered trustworthy. If the source IP address of the traffic sequence is not on the whitelist, further analysis of the traffic sequence is performed.

[0119] c3) When the IP address is determined to be an abnormal IP, abnormal behavior determination is performed on the service number information.

[0120] In this optional embodiment, when determining that the IP address is an abnormal IP, a correlation analysis is performed based on the service source's communication frequency, access time, access protocol and other behavioral characteristics, such as whether the same target or port is frequently attempted in a short period of time (such as >100 times / minute), whether high-frequency access occurs during non-working hours, whether abnormal protocols are used, etc. By setting thresholds, it is determined whether there is abuse, port scanning and other abnormal behaviors.

[0121] d3) When it is determined that the service number information has abnormal behavior, determine the port number included in the port number information.

[0122] In this optional embodiment, if there is abnormal behavior in the service number information, the abnormal behavior is traced and the port number of the traffic sequence is found. Specifically, the port number information used by the abnormal traffic can be obtained through a network packet capture tool (such as Wireshark) or a traffic monitoring module in the service number background. For example, if it is found that the abnormal high-frequency traffic is transmitted through the TCP protocol and the destination port is 8080, then port 8080 may be the port number related to the abnormal behavior.

[0123] e3) If the port number does not belong to the high-risk registered ports, the high-risk status of the port number is recorded and added to the high-risk registered ports; otherwise, the port number is blocked.

[0124] In this optional embodiment, for a determined port number, its port number is compared with the port number of a high-risk filing port. A list of high-risk filing ports is maintained in the system, which can be stored through a data structure such as a hash table. The list records in detail the known high-risk port numbers and related description information. For example, some common high-risk ports such as 21 (the default port for the FTP protocol, which is vulnerable to weak password attacks) and 135 (the RPC port, which has been used for various malicious attacks) will be registered in the high-risk filing port list. At the same time, the system will regularly update and maintain the high-risk filing port list to reflect the latest security trends and vulnerability information.

[0125] If the comparison result shows that the port has been registered as a high-risk port, port blocking measures will be taken immediately. Specifically, external access to the port is closed through a firewall or network device. For example, a firewall usually supports restricting traffic in and out of a specific port through an access control list (ACL). The system will add a rule to the firewall to prohibit access requests from the external network to the high-risk port. At the same time, in order to ensure the normal operation of the business, the business originally running on the high-risk port will be migrated to a safe port through service transfer. When the port number is not listed as a high-risk port, but the traffic is judged to be abnormal, the system will record the status of the port and mark it as an abnormal state. Relevant information about the port can be recorded, including the port number, the network service to which it belongs, the direction of the traffic (source to destination or destination to source), etc. At the same time, key information such as the source IP and port number is persistently stored to form a log file. The storage format of the log file usually adopts a standardized format, such as a common text format or JSON format, to facilitate subsequent reading and analysis. To ensure the security and reliability of log files, the system selects appropriate storage media (such as disk arrays, distributed storage systems, etc.) for storage and regularly backs up log files to prevent data loss. Furthermore, the abnormal port information is added to the list of high-risk registered ports to facilitate subsequent audits and analysis. During the addition process, the port information is further organized and improved, such as adding characteristic descriptions of the abnormal traffic and the time the anomaly was discovered. By continuously updating the list of high-risk registered ports, the system can accumulate more security data and improve its ability to identify and prevent network security threats.

[0126] Network administrators or security personnel can regularly audit and analyze the high-risk port list and log files. By reviewing the high-risk port list, they can understand the current high-risk ports on the network and assess network security risks. Log file analysis can also help identify potential security issues, such as abnormal traffic patterns, the source and purpose of attacks, and so on. For example, if statistical analysis of log files reveals that a source IP address frequently attempts to access multiple high-risk ports, this could be a port scan, requiring further preventative measures.

[0127] During the audit and analysis process, data analysis tools and techniques (such as data mining and machine learning) can be used to delve deeper into large amounts of log data to uncover hidden security threats and trends. For example, machine learning algorithms can be used to train log data to build anomaly traffic detection models, improving the accuracy and efficiency of abnormal traffic detection. Furthermore, based on the results of the audit and analysis, network security policies can be adjusted promptly, firewall rules optimized, and high-risk port lists updated to continuously improve network security.

[0128] Example 3

[0129] Figure 3 This is a schematic diagram of the structure of a network traffic monitoring device provided by the third embodiment of the present invention. Figure 3 As shown, the device includes:

[0130] The matching module 31 is used to obtain the system attribute information of the installed operating system and determine the matching monitoring service interface according to the system attribute information;

[0131] The collection module 32 is used to collect the flow data of the system within a set time length through the monitoring service interface in combination with the set collection tool, and determine at least one flow sequence based on the flow data;

[0132] A determination module 33 is configured to determine the probability of a coefficient of variation sequence and a flow threshold range of each flow sequence within the set time length;

[0133] The monitoring module 34 is used to determine the monitoring result of the corresponding flow sequence according to the probability of each variation coefficient sequence and the corresponding flow threshold range, wherein the flow threshold range varies according to the set confidence coefficient.

[0134] The network monitoring device provided in this embodiment solves the problems of the lack of a unified heterogeneous terminal port monitoring method and the inability to detect unknown risks or abnormal traffic in real time in the existing technology by introducing a complete network traffic collection, analysis and monitoring architecture. It can ensure seamless operation in different operating system environments and improve cross-platform adaptability and compatibility. At the same time, it can also collect network traffic data in real time and dynamically analyze and monitor abnormal traffic, realizing real-time monitoring of network traffic behavior, enhancing the flexibility and accuracy of network traffic monitoring, and avoiding the false alarm and missed alarm problems caused by fixed thresholds in traditional methods.

[0135] Optionally, the acquisition module 32 may be specifically configured to:

[0136] The flow data is analyzed, and flow data with the same source IP, destination IP, source port, and destination port are classified into the same flow sequence.

[0137] Optionally, the determining module 33 may specifically include:

[0138] An acquiring unit is configured to acquire a sliding window length for each traffic sequence, and determine a window variation coefficient value of the traffic sequence under the sliding window length according to a given variation coefficient calculation formula in combination with the window traffic data under the sliding window length;

[0139] a summarizing unit, configured to determine new window traffic data according to the sliding window length with a set step size, and re-determine the window variation coefficient value of the traffic sequence, and summarize the window variation coefficient values ​​to form a variation coefficient sequence of the traffic sequence;

[0140] a calculation unit, configured to determine an expected value of the coefficient of variation and a variance of the coefficient of variation sequence;

[0141] The threshold determination unit is used to determine the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation, and to determine the flow threshold range under the set time length in combination with a pre-set confidence coefficient.

[0142] Optionally, the threshold determination unit may further be used to:

[0143] Determine the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation in combination with Chebyshev's inequality;

[0144] Obtaining a threshold coefficient according to the confidence coefficient and the threshold coefficient determination formula;

[0145] According to the threshold coefficient, combined with the expected value of the coefficient of variation and the variance of the coefficient of variation, the flow threshold range under the set time length is determined.

[0146] Optionally, the monitoring module 34 may be specifically used to:

[0147] Determining at least one level of alarm threshold range based on the flow threshold range;

[0148] If the probability of the coefficient of variation sequence belongs to the flow threshold range, the flow sequence is considered to be in the normal flow range as a monitoring result;

[0149] If the probability of the coefficient of variation sequence belongs to one of the alarm threshold ranges, it is determined that the traffic sequence is in the abnormal traffic range, and the level corresponding to the alarm threshold range is determined as the abnormal level of the traffic sequence, and being in the abnormal traffic range and the corresponding abnormal level are determined as the monitoring results.

[0150] Optionally, the device may further include:

[0151] Anomaly analysis module: if the monitoring result of the traffic sequence indicates that the traffic sequence is abnormal, determine the network service information corresponding to the traffic sequence and perform network anomaly analysis;

[0152] Judgment module: records the analysis results of the network anomaly analysis and sends them to the anomaly review platform for anomaly review judgment.

[0153] Optionally, the exception analysis module can be used to:

[0154] Determine the service number information, port number information and IP information corresponding to the traffic sequence and use them as the network service information of the traffic sequence;

[0155] Using a pre-stored IP whitelist, the IP address in the IP information is judged as abnormal;

[0156] When the IP address is determined to be an abnormal IP, performing abnormal behavior determination on the service number information;

[0157] When it is determined that the service number information has abnormal behavior, determining the port number included in the port number information;

[0158] If the port number does not belong to the high-risk registered ports, the high-risk status of the port number is recorded and added to the high-risk registered ports; otherwise, the port number is blocked.

[0159] A network traffic monitoring device provided by an embodiment of the present invention can execute the network traffic monitoring method provided by any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.

[0160] Example 4

[0161] Figure 4 A schematic diagram of the structure of an electronic device 40 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0162] like Figure 4As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41. The memory stores a computer program that can be executed by the at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, ROM 42, and RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0163] Multiple components in the electronic device 40 are connected to the I / O interface 45, including an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0164] Processor 41 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. Processor 41 executes the various methods and processes described above, such as a method for monitoring network traffic.

[0165] In some embodiments, a method for monitoring network traffic may be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as a storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the method for monitoring network traffic described above may be performed. Alternatively, in other embodiments, the processor 41 may be configured to perform a method for monitoring network traffic in any other appropriate manner (e.g., by means of firmware).

[0166] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0167] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0168] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0169] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0170] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0171] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0172] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0173] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for monitoring network traffic, characterized in that: include: Obtain the system attribute information of the installed operating system and determine the matching monitoring service interface based on the system attribute information; Collecting flow data of the system over a set period of time through a monitoring service interface in combination with a set collection tool, and determining at least one flow sequence based on the flow data; Determine the probability of the coefficient of variation sequence and the flow threshold range of each flow sequence under the set time length; The monitoring result of the corresponding flow sequence is determined according to the probability of each variation coefficient sequence and the corresponding flow threshold range, wherein the flow threshold range is different according to the set confidence coefficient.

2. The method according to claim 1, characterized in that The determining at least one traffic sequence according to the traffic data includes: The flow data is analyzed, and flow data with the same source IP, destination IP, source port, and destination port are classified into the same flow sequence.

3. The method according to claim 1, characterized in that Determining the probability of the coefficient of variation sequence and the flow threshold range of each flow sequence under the set time length includes: For each traffic sequence, obtain the sliding window length, and determine the window variation coefficient value of the traffic sequence under the sliding window length according to a given variation coefficient calculation formula combined with the window traffic data under the sliding window length; Determine new window traffic data according to the sliding window length with a set step size, re-determine the window variation coefficient value of the traffic sequence, and summarize the window variation coefficient values ​​to form a variation coefficient sequence of the traffic sequence; Determining the expected value of the coefficient of variation and the variance of the coefficient of variation sequence; The probability of the coefficient of variation sequence of the flow sequence under the set time length is determined based on the expected value of the coefficient of variation and the variance of the coefficient of variation, and the flow threshold range under the set time length is determined in combination with a pre-set confidence coefficient.

4. The method according to claim 3, characterized in that Determining the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation, and determining the flow threshold range under the set time length in combination with a preset confidence coefficient, including: Determine the probability of the coefficient of variation sequence of the flow sequence under the set time length based on the expected value of the coefficient of variation and the variance of the coefficient of variation in combination with Chebyshev's inequality; The Chebyshev inequality is shown below: μ and σ 2 They represent the expected value of the coefficient of variation and the variance of the coefficient of variation respectively, and ε is the tolerance range, which represents the maximum distance that the probability of the coefficient of variation sequence deviates from its expectation; Obtaining a threshold coefficient according to the confidence coefficient and the threshold coefficient determination formula; The threshold coefficient determination formula is as follows: k is the threshold coefficient, α is the confidence coefficient; According to the threshold coefficient, combined with the expected value of the coefficient of variation and the variance of the coefficient of variation, the flow threshold range under the set time length is determined.

5. The method according to claim 1, wherein Determine the monitoring result of the corresponding flow sequence according to the probability of each variation coefficient sequence and the corresponding flow threshold range, including: Determining at least one level of alarm threshold range based on the flow threshold range; If the probability of the coefficient of variation sequence belongs to the flow threshold range, the flow sequence is considered to be in the normal flow range as a monitoring result; If the probability of the coefficient of variation sequence belongs to one of the alarm threshold ranges, it is determined that the traffic sequence is in the abnormal traffic range, and the level corresponding to the alarm threshold range is determined as the abnormal level of the traffic sequence, and being in the abnormal traffic range and the corresponding abnormal level are determined as the monitoring results.

6. The method according to claim 1, characterized in that Also includes: If the monitoring result of the traffic sequence indicates that the traffic sequence is abnormal, determining network service information corresponding to the traffic sequence and performing network anomaly analysis; The analysis results of the network anomaly analysis are recorded and sent to the anomaly review platform for anomaly review determination.

7. The method according to claim 6, characterized in that Determining the network service information corresponding to the traffic sequence and performing network anomaly analysis includes: Determine the service number information, port number information and IP information corresponding to the traffic sequence and use them as the network service information of the traffic sequence; Using a pre-stored IP whitelist, the IP address in the IP information is judged as abnormal; When the IP address is determined to be an abnormal IP, performing abnormal behavior determination on the service number information; When it is determined that the service number information has abnormal behavior, determining the port number included in the port number information; If the port number does not belong to the high-risk registered ports, the high-risk status of the port number is recorded and added to the high-risk registered ports; otherwise, the port number is blocked.

8. A network traffic monitoring device, characterized in that: include: A matching module is used to obtain the system attribute information of the installed operating system and determine the matching monitoring service interface based on the system attribute information; A collection module, configured to collect flow data of the system over a set period of time through a monitoring service interface in combination with a set collection tool, and determine at least one flow sequence based on the flow data; A determination module, configured to determine the probability of a coefficient of variation sequence and a flow threshold range of each flow sequence within the set time length; The monitoring module is used to determine the monitoring result of the corresponding flow sequence according to the probability of each variation coefficient sequence and the corresponding flow threshold range, wherein the flow threshold range is different according to the set confidence coefficient.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform the network traffic monitoring method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network traffic monitoring method according to any one of claims 1 to 7 when executed.

Citation Information

Patent Citations

  • Network security monitoring method, equipment, storage medium and device

    CN117544327A

  • Small program abnormal behavior management system fused with artificial intelligence

    CN120012078A

  • Machine learning-based data analyses for outlier detection

    US11537942B1

  • Unified multi-agent system for abnormality detection and isolation

    US20220327204A1

Cited By

  • Intelligent dynamic network bandwidth allocation method based on Linux

    CN122179397A

  • A Linux-based intelligent dynamic network bandwidth allocation method

    CN122179397B